| Type |
Caption |
Section |
File name |
Description |
 |
*windows update |
|
wuacrlt.exe |
Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wuanclt.exe |
Added by the RBOT-PG WORM! Read more |
 |
*windows update |
|
wuanclt.exe |
Added by the RBOT-PG WORM! Read more |
 |
*windows update |
|
wuaucrlt.exe |
Added by the SPYBOT.HUR WORM! Read more |
 |
*windows update |
|
wuraclt.exe |
Added by the RBOT-PO WORM! Read more |
 |
*windows update |
|
wurauclt.exe |
Added by the RBOT-SY WORM! This file runs in safe mode as well making it slightly harder to remove. Read more |
 |
*wmstu |
|
wmstu.exe |
Added by the W32/Rbot-TV worm. When started this infection connects to an IRC server where it waits for commands. This program starts in safe mode to make it more difficult to remove. Read more |
 |
*wuauclt.exe |
|
wmsvc.exe |
Added by the W32/Rbot-UG network worm. When started this infection connects to an IRC server where it waits for remote commands to execute. Read more |
 |
*wuauclt.exe |
|
wxmct.exe |
Added by an unidentified WORM or TROJAN! |
 |
.msfupdate |
|
msveup.exe |
Added by the W32.ALLOCUP.A WORM! Read more |
 |
.Prog |
|
services.exe |
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! Read more |
 |
.Prog |
|
winlogon.exe |
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! Read more |
 |
0utlook express |
|
*****.exe (where * = random char) |
Added by the W32/RBOT-CC WORM! Read more |
 |
1 |
|
addit.exe |
Added by the W32/Sdbot-RI worm. When started, this infection will connect to a remote IRC server and wait for commands to execute. Read more |
 |
123456 |
|
rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl |
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number Read more |
 |
128 Module |
|
win128.exe |
Added by the W32/Forbot-ES WORM/backdoor Trojan, which allows unauthorized access to the PC using the IRC network and registration of a new service process "Windows 128 Module". Read more |
 |
2k6 updatz |
|
crss3.exe |
Added by the W32/Rbot-CPD worm and IRC backdoor. Read more |
 |
3D Text |
|
3D Text.scr |
Added by the JERMY.A WORM! Read more |
 |
3Dfx Acc |
|
GFXACC.EXE |
Added by the GIBE WORM! Read more |
 |
4wd!!! |
|
Natal!.pif |
Added by the OPASERV.AI WORM! Read more |