| Type |
Caption |
Section |
File name |
Description |
 |
$WindowsRegKey%update |
|
IEXPLORE.EXE |
Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! Read more |
 |
<random characters> |
|
securewinload32x.exe |
Added by the Troj/OptixP-N worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
<random> |
|
svshost.exe |
Added by the W32/Kelvir-AX instant messaging worm and backdoor Trojan. Read more |
 |
(D1589445-4C2D-4827-6486-8C9674D8B206) |
|
dkxcj32.dll |
Added by the W32/Korgo-Z network worm.br /br /Uses CLSID: b(D1589445-4C2D-4827-6486-8C9674D8B206)/b. Read more |
 |
(default) |
|
[random filename].exe |
Added by the BLACKMAL WORM! Read more |
 |
(Default) |
|
NOTEPAD.exe |
Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor Read more |
 |
(default) |
|
taskdrv32.exe |
Added by the W32/Sdbot-DIC worm and IRC backdoor. Read more |
 |
(default) |
|
twunk_32.exe |
Added by the BLACKMAL.C WORM! Read more |
 |
(default) |
|
winhelp.exe |
Added by the BLACKMAL.C WORM! Read more |
 |
(L4r1$$4) (4nt1) (V1ruz) |
|
SP00Lsv32.pif |
Added by the W32/Assiral-B WORM! This worm will terminate processes and also install/run a file C:\WINDOWS\WinVBS.vbs to restrict user activity. Read more |
 |
*JanisRuckenbrodII |
|
janis.com |
Added by the POPS WORM! Read more |
 |
*security center |
|
secctr.exe |
Added by the SDBOT.BRO WORM! Read more |
 |
*windows update |
|
waurclt.exe |
Added by a variant of the WIN32.RBOT WORM! Read more |
 |
*windows update |
|
wkmst.exe |
Added by the SDBOT.AVD WORM! Read more |
 |
*windows update |
|
wrauclt.exe |
Added by the RBOT-QU WORM! Read more |
 |
*windows update |
|
wruaclt.exe |
Added by the W32/Rbot-QP worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wruauclt.exe |
Added by the W32/Rbot-SF worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wscxt.exe |
Added by an unidentified WORM! |
 |
*windows update |
|
wuacrlt.exe |
Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wuanclt.exe |
Added by the RBOT-PG WORM! Read more |