| Type |
Caption |
Section |
File name |
Description |
 |
Wdqvsst |
|
[random filename] |
Added by the Troj/Ranck-BT proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
Web Service |
|
[random filename] |
Added by the Trojan.Admincash infection! Read more |
 |
Window Server |
|
Sererver.exe |
Added by the Troj/Feutel-BB backdoor Trojan. This infection also creates the files C:\Windows\Sererver.DLL, C:\Windows\SererverKey.DLL, and C:\Windows\Sererver_HOOk.DLL. Read more |
 |
Windows |
|
smss.exe |
Added by the Troj/Bancban-OF Internet banking trojan. This infection should not be confused with the legitimate Microsoft file c:\windows\system32\smss.exe. Read more |
 |
windows 2004 |
|
CSRSS.exe |
Added as result of a Troj/Banker-DY trojan infection Read more |
 |
Windows DLL Loader |
|
defragfatx.exe |
Added by the W32/Poebot-F trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
Windows DLL Loader |
|
radeonfx.exe |
Added by the W32/Poebot-E trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. Read more |
 |
Windows Fire Walls |
|
twunk_18.exe |
Added by the Troj/GrayBrd-AT backdoor Trojan. This infection also creates the file c:\windows\system32\gywnly.dat. Read more |
 |
Windows Firewall |
|
FIREWAL1.EXE |
Added by the W32/Rbot-DB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Firewalll |
|
scvhost.exe |
Added by the W32/Rbot-EK trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate various processes including other infections. Read more |
 |
Windows Guard |
|
WAUMGRD.EXE |
Added by the W32/Rbot-GY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Internet Server |
|
ntdlr.exe |
Added by the Troj/Feutel-CH Trojan. This infection also creates the files C:\Windows\ntdlr.dll and C:\Windows\ntdlr_Hook.DLL. Read more |
 |
Windows Media Player |
|
tihtaf.exe |
Added by the W32/Rbot-CU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Media Player Update |
|
PACKARD.EXE |
Added by the W32/Rbot-ET trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also creates a hosts file to block your accessing of security websites as well as the termination of antivirus programs. Read more |
 |
Windows NT |
|
[random filename] |
Added by the Troj/Ranck-M proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
Windows NT Service Name |
|
svchcst.exe |
Added by the W32/Rbot-NV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. Read more |
 |
Windows Registers |
|
Svchosts.exe |
Added by the W32/Rbot-HV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection will also attempt to harvest keystrokes and cd keys from your computer. Read more |
 |
Windows Registry Scan |
|
regscan.exe |
Added by the W32/Rbot-HA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Service |
|
slserv32.exe |
Added by the W32/Rbot-KO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can will terminate antivirus programs to avoid detection. Read more |
 |
Windows Task Manager-Emulator |
|
ukenme.exe |
Added by the W32/Rbot-CF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |