| Type |
Caption |
Section |
File name |
Description |
 |
<Random GUID> |
|
mst32init.exe |
Added by the Troj/Hazif-A password-stealing Trojan. This infection will also create the files c:\windowsnetiu1.dll and c:\windows\system32\netiu1.dllbr /br /Uses CLSID: bRandom/b. Read more |
 |
(0C81EA61-20F8-4DDC-81BF-AF0923078398) |
|
msctr.dll |
Added by the Troj/Bankhof-E password-stealing Trojan. This infection installs the file C:\Windows\System32\rdrlib.dll.br /br /Uses CLSID: b(0C81EA61-20F8-4DDC-81BF-AF0923078398)/b. Read more |
 |
.mscdsr |
|
lsvchost.exe |
Added by the Troj/Bdoor-CR backdoor trojan. This infection listens on an IRC server awaiting commands. Read more |
 |
456655 |
|
Explorer.exe |
Added by the Troj/Bifrose-DF Trojan. This infection should not be confused with the legitimate Microsoft file C:\Windows\Explorer.exe. Read more |
 |
AntiVirus Update |
|
AntiVirus.exe |
Added by the W32/Rbot-HY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
AntiVirus Update |
|
msisvc.exe |
Added by the W32/Rbot-HX trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
AntiVirus Update |
|
updates.exe |
Added by the W32/Rbot-JF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Application Management Browser |
|
smss.exe |
Added by the Troj/Comhush-A Trojan. This infection should not be confused with the legitimate smss.exe found in the C:\Windows\System32 (%System%)folder. Read more |
 |
asus |
|
asus.exe |
Added by the W32/Rbot-OC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. This infections logs your keystrokes to a file in your %System% folder called msreg.dll. Read more |
 |
Ati Control Panel |
|
atiphexx.EXE |
Added by the W32/Rbot-BR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
auto__antiav__key |
|
antiav_exe.exe |
Added by the Troj/BagleDl-AA Trojan. This infection also creates the file %System%antiav_dll.dll. Read more |
 |
auto__hloader__key |
|
hloader_exe.exe |
Added by the Troj/BagleDl-W Trojan. This infection also creates the following file %System%hloader_dll.dll. Read more |
 |
AVPX TCP |
|
AVPX32.SYS |
Added by the Troj/Haxdoor-Y backdoor trojan. This infection uses rootkit technology to hide itself from being seen. Read more |
 |
avpx32 |
|
avpx32.dll |
Added by the Troj/Haxdoor-Y backdoor trojan. This infection uses rootkit technology to hide itself from being seen. Read more |
 |
AVPX64 TCP |
|
AVPX64.SYS |
Added by the Troj/Haxdoor-Y backdoor trojan. This infection uses rootkit technology to hide itself from being seen. Read more |
 |
bbc |
|
imsins.exe |
Added by the Troj/Hupigon-U Trojan. This infection also installs the files C:\Windows\imsins.dll and C:\Windows\imsins_Hook.DLL. Read more |
 |
bbdjmrxcX |
|
[random filename] |
Added by the Troj/Ranck-AX proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
bcnswsx |
|
(path to file) |
Added as result of a Ranck-AJ trojan infection Read more |
 |
bdffefqes32 |
|
[random filename] |
Added by the Troj/Ranck-Z proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. Read more |
 |
Bios Protector |
|
vmaocesza.exe |
Added by the W32/Rbot-EU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |