| Type |
Caption |
Section |
File name |
Description |
 |
BIOS XP Loader |
|
[random] |
Added by the W32/Rbot-IC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Bmsnwss |
|
[random filename] |
Added by the Troj/Ranck-BK proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
bootpd.exe |
|
bootpd.exe |
Identified by Kapersky as Trojan.Win32.StartPage.vk. This infections hijacks popular search engines to another site and hijacks your start page to Premium Search which is a locally stored .html file. |
 |
BS Mediaplayer |
|
bsplyr.exe |
Added by the W32/Rbot-OU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. Read more |
 |
ccApp.exe |
|
ccApp.exe |
Added by the W32/Rbot-HJ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Compliant |
|
compliant.exe |
Added by the W32/Rbot-LB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection terminates certain processes and logs keystrokes to a file called syste.txt. Read more |
 |
ControlPanel |
|
popcorn64.exe rundll.dll,LoadMouseProfile |
Added by the Troj/Dloader-OI downloader trojan. When removing this infection, you only want to remove the popcorn64.exe file. Read more |
 |
ctfmonn |
|
[random filename] |
Added by the Troj/Ranck-O proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
dark |
|
imgst.scr |
Added by the Troj/Bancban-CK password-stealing trojan. This infections targets customers of Brazilian banks. Read more |
 |
demm386.exe |
|
DEMM386.EXE |
Added by the W32/Rbot-EO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
dfasack |
|
[random filename] |
Added by the Troj/Ranck-BE proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
DiskEventChk |
|
smszac32.exe |
Added by the Troj/Stinx-H Trojan. This infection also creates the files Temp442.bat and Temp952.bat. Read more |
 |
Dll Service Manager. |
|
SVSHOST.EXE |
Added by the W32/Robot-A backdoor trojan. When started this infection connects to an IRC server where it waits for remote commands. Read more |
 |
DNSCacheBoost |
|
dnsping.exe |
Added by the Troj/DNSBust-A trojan. This infection modifies your dns servers that your computer uses in order to redirect popular sites to an address of its choice. Read more |
 |
doc |
|
doc.exe |
Added by the W32/Agobot-PJ trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. This infection will add entries to your HOSTS file, so the hosts file should be restored after cleaning this infection. Read more |
 |
DriverModule |
|
csrnvrt.exe |
Added by the Troj/Stinx-Q backdoor Trojan. This infection also creates the files 557.bat and 989.bat in your Temp directory. Read more |
 |
dvb03a |
|
dvb03a.dll |
Added by the Troj/Haxdoor-CF Trojan. This infection is stealthed/hidden by the dvb06a.sys rootkit. Read more |
 |
Extra Logs and Alerts |
|
rsn.exe |
Added by the Troj/Keylog-AU keylogging Trojan. This infection also installs the files c:\windows\system32\fixapi.exe, c:\windows\system32\hotkey.exe, c:\windows\system32\rcxx.tmp, and c:\windows\system32\kbdmy.dll. Read more |
 |
f3dsl |
|
LSD_F3.DLL |
Added by the Troj/Goldun-G password stealing trojan. If you have this infection you should change all your passwords. Read more |
 |
Fat32 Microsoft |
|
fat32.exe |
Added by the W32/Rbot-EL trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate various processes including other infections. Read more |