| Type |
Caption |
Section |
File name |
Description |
 |
!1_pgaccount |
|
pgaccount.exe |
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly Read more |
 |
!1_ProcessGuard_Startup |
|
procguard.exe |
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks Read more |
 |
$sys$cmp |
|
$sys$xp.exe |
Added by the Troj/Stinx-F backdoor Trojan. Troj/Stinx-F may be stealthed on an infected system by exploiting Sony DRM (Digital Rights Management) software. Read more |
 |
$sys$crash |
|
$sys$sonyTimer.exe |
Added by the Trojan.Welomoch Trojan. Read more |
 |
$sys$crash |
|
$sys$sos$sys$.exe |
Added by the Trojan.Welomoch Trojan. Read more |
 |
$sys$crash |
|
$sys$WeLoveMcCOL.exe |
Added by the Trojan.Welomoch Trojan. Read more |
 |
$sys$drv |
|
$sys$drv.exe |
Added by the Backdoor.Ryknos Trojan backdoor that attempts to utilize the SecurityRisk.First4DRM security risk to hide itself on the compromised computer. It also adds a registry key at HKEY_CURRENT_USERWkbpsevaXImgvkwkbpXSmj`kswXGqvvajpRavwmkjXVqj Read more |
 |
$Windows Time |
|
G_Server.exe |
Added by the Troj/Feutel-BI Trojan backdoor. Read more |
 |
<random CLSID> |
|
PREFX.DLL |
Added by the TROJ_DROPPER.EI Trojan dropper.br /br /Uses CLSID: brandom CLSID/b. Read more |
 |
<Random CLSID> |
|
ssvchost.com |
Added by the Troj/BluEye-D backdoor Trojan.br /br /Uses CLSID: bRandom CLSID/b. Read more |
 |
<Random GUID> |
|
mst32init.exe |
Added by the Troj/Hazif-A password-stealing Trojan. This infection will also create the files c:\windowsnetiu1.dll and c:\windows\system32\netiu1.dllbr /br /Uses CLSID: bRandom/b. Read more |
 |
<random> |
|
svshost.exe |
Added by the W32/Kelvir-AX instant messaging worm and backdoor Trojan. Read more |
 |
<randomly chosen CLSID> |
|
msshell.dll |
Added by the Troj/Vipgsm-AB Trojan.br /br /Uses CLSID: brandomly chosen CLSID/b. Read more |
 |
<special characters> |
|
myserver.exe |
Added by the Troj/Dropper-BR Trojan. Read more |
 |
®Windows Update |
|
svchosts.exe |
Added by the FRUCTA TROJAN! Read more |
 |
(04ED35B6-9A10-4EB3-9C1E-66B2CFA5AC77) |
|
windir32.dll |
Added by the Troj/Lineage-JA Trojan.br /br /Uses CLSID: b(04ED35B6-9A10-4EB3-9C1E-66B2CFA5AC77)/b. Read more |
 |
(0C81EA61-20F8-4DDC-81BF-AF0923078398) |
|
msctr.dll |
Added by the Troj/Bankhof-E password-stealing Trojan. This infection installs the file C:\Windows\System32\rdrlib.dll.br /br /Uses CLSID: b(0C81EA61-20F8-4DDC-81BF-AF0923078398)/b. Read more |
 |
(109DFD46-20F3-0D29-0600-010804010205) |
|
rundll16.exe |
Added by the Troj/Delf-LV Trojan.br /br /Uses CLSID: b(109DFD46-20F3-0D29-0600-010804010205)/b. Read more |
 |
(1DC4096D-5B5F-479C-BC9C-EB70E4F613B3) |
|
MSA13g5.dll |
Added by the Troj/Lineage-DW password-stealing Trojan for the online game Lineage.br /br /Uses CLSID: b(1DC4096D-5B5F-479C-BC9C-EB70E4F613B3)/b. Read more |
 |
(23246306-E6FB-4869-88ED-B4D4B5041EC1) |
|
mscom32.dll |
Added by the Troj/Agent-KZ downloader Trojan.br /br /Uses CLSID: b(23246306-E6FB-4869-88ED-B4D4B5041EC1)/b. Read more |