| Type |
Caption |
Section |
File name |
Description |
 |
*windows update |
|
wruaclt.exe |
Added by the W32/Rbot-QP worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wruauclt.exe |
Added by the W32/Rbot-SF worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*windows update |
|
wuacrlt.exe |
Added by the W32/Rbot-QI worm. This infection connects to an IRC server where it waits for remote commands. Read more |
 |
*wmstu |
|
wmstu.exe |
Added by the W32/Rbot-TV worm. When started this infection connects to an IRC server where it waits for commands. This program starts in safe mode to make it more difficult to remove. Read more |
 |
*wuauclt.exe |
|
wmsvc.exe |
Added by the W32/Rbot-UG network worm. When started this infection connects to an IRC server where it waits for remote commands to execute. Read more |
 |
.svchost |
|
csrss.exe |
Added by a new Rbot variant. This infection when started connects to a remote IRC server where it waits for commands to execute. |
 |
AdobeReaderPro |
|
ntkernell32.exe |
Added by the W32/Rbot-ATY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
AIM Instant Message Cookies |
|
[random filenames] |
Added by the W32/Rbot-AFV worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. Read more |
 |
AntiVirus Update |
|
AntiVirus.exe |
Added by the W32/Rbot-HY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
AntiVirus Update |
|
msisvc.exe |
Added by the W32/Rbot-HX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
AntiVirus Update |
|
updates.exe |
Added by the W32/Rbot-JF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
anything |
|
ATITAX.exe |
Added by the W32/Forbot-DP worm. This infection connects to an IRC server where it waits for remote commands to execute. Read more |
 |
AOL Instant Messenger dll runtime |
|
MSAOL32dll.exe |
Added by the W32/Rbot-ATA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
asus |
|
asus.exe |
Added by the W32/Rbot-OC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. This infections logs your keystrokes to a file in your %System% folder called msreg.dll. Read more |
 |
Ati Control Panel |
|
atiphexx.EXE |
Added by the W32/Rbot-BR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
ATI Technology Startup |
|
techstart.exe |
Added by the W32/Rbot-AEU worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
ATIUpdater |
|
atiupdxx.exe |
Added by the W32/Rbot-ABX. This infection connects to an IRC server on startup where it waits for remote commands to execute. Read more |
 |
Auto Update |
|
dma.exe |
Added by the W32/Rbot-AVO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
Auto WinUpdate |
|
taskmrg.exe |
Added by the W32/Rbot-AFAworm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Automatic Defrag Manager |
|
defrag.exe |
Added by the W32/Rbot-AKE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. Read more |