| Type |
Caption |
Section |
File name |
Description |
 |
[Various Names] |
|
_ctcp.exe |
Part of the Wareout infection as described A href="http://www.doxdesk.com/parasite/WareOut.html" rel="nofollow" target="_blank"here. |
 |
Bron-Spizaetus-5118REPM |
|
_default32142.pif |
Added by the W32/Brontok-R mass-mailing worm. Read more |
 |
[not used] |
|
_huytam_.exe |
Added by the Ssearch.biz and a-search.biz hijackers. |
 |
[not used] |
|
_Kerne1.exe |
Added by the Troj/Lineage-AN password-stealing Trojan for the online game Lineage. Read more |
 |
MEAOI Service |
|
_meaoi.exe |
Added by the W32/Tilebot-AM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. This infection also creates a Rootkit file in order to hide itself called %System%meaoi.sys. Read more |
 |
_ntrdlhost |
|
_ntrdlhost.exe |
A downloader TROJAN, Troj/Dloader-JV, adds this file. Read more |
 |
_ntrrescueservice |
|
_ntrrs.exe |
Added by the TROJ/DLOADER-JV TROJAN! Read more |
 |
(randomly chosen existing folder name) |
|
_setup.exe |
Added by the W32/Antinny-L Read more |
 |
sqlsrvd |
|
_sqlexec.exe |
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen. Read more |
 |
MS SQL Server Moniter |
|
_sqlsrvd.exe |
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen. Read more |
 |
_System_Run |
|
_svchost_.exe |
Added by the Troj/Lineage-Z password-stealing trojan for the online game Lineage. Read more |
 |
_tdiserv_ |
|
_tdicli_.exe |
Added by the W32.TDISERV.A WORM! Read more |
 |
windll32 |
|
_WIN32.EXE |
Added by the LEGMIR.AQ TROJAN! Read more |
 |
_x-Finder |
|
_x-Finder.exe |
Disconnects and redials an ISP modem to an adult content site |
 |
^`d}qZxu |
|
~`d}qzxu3zYF |
Added by the GAOBOT.GEN!POLY WORM! Read more |
 |
(default) |
|
~~.exe |
Added by the Troj/DownLdr-QR Trojan downloader. Read more |
 |
Regcheck |
|
~CAB001.EXE |
Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS! Read more |
 |
ZeroAds |
|
0 |
ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually Read more |
 |
Zonavirus |
|
0 |
Added by the KITRO.D (or ARGEN.A) WORM! Read more |
 |
begins |
|
0.exe |
Added by the W32/Mytob-HE mass-mailing worm and IRC backdoor. Read more |
 |
solid |
|
0.exe |
Added by the WORM_MYTOB.PP worm and IRC backdoor. Read more |