| Type |
Caption |
Section |
File name |
Description |
 |
Windows DLL Services |
|
winsvc32.exe |
Added by the W32/Rbot-ZF WORM/IRC backdoor Trojan! Read more |
 |
Windows Domain Name Drivers |
|
windns.exe |
Added by the W32/Forbot-EP WORM/IRC backdoor Trojan to thee Windows system folder,and is as a new service called "IEXPLORER-Drivers" with a display name of "Windows Domain Name Drivers". Read more |
 |
Windows Firewall |
|
FIREWAL1.EXE |
Added by the W32/Rbot-DB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Firewalll |
|
scvhost.exe |
Added by the W32/Rbot-EK trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also attempts to terminate various processes including other infections. Read more |
 |
Windows Guard |
|
WAUMGRD.EXE |
Added by the W32/Rbot-GY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Media Player |
|
tihtaf.exe |
Added by the W32/Rbot-CU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Media Player Update |
|
PACKARD.EXE |
Added by the W32/Rbot-ET trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection also creates a hosts file to block your accessing of security websites as well as the termination of antivirus programs. Read more |
 |
Windows Monitor Services |
|
winmonitor.exe |
The W32/Rbot-XX WORM/IRC backdoor Trojan adds this, allowing unauthorized remote access and termination of processes, DoS attack participation, and downloads/executes other files. Read more |
 |
Windows NT Service Name |
|
svchcst.exe |
Added by the W32/Rbot-NV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. These infections are usually capable of logging keystrokes, retrieve cd keys, and flood other computers. Read more |
 |
Windows Registers |
|
Svchosts.exe |
Added by the W32/Rbot-HV trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection will also attempt to harvest keystrokes and cd keys from your computer. Read more |
 |
Windows Registry Scan |
|
regscan.exe |
Added by the W32/Rbot-HA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Server Information |
|
servinfo.exe |
Added by the W32/Forbot-EN WORM/IRC backdoor Trojan, which also starts a new service "Windows ExplorerTM" with a display name of "Windows Server Information". Read more |
 |
Windows Service |
|
slserv32.exe |
Added by the W32/Rbot-KO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can will terminate antivirus programs to avoid detection. Read more |
 |
Windows Task Manager-Emulator |
|
ukenme.exe |
Added by the W32/Rbot-CF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Task Manager-Emulator |
|
uswtme.exe |
Added by the W32/Rbot-CG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |
 |
Windows Taskmanager |
|
lsassx.exe |
Added by the W32/Rbot-WX WORM and IRC backdoor Trojan, and found in the Windows system folder. Read more |
 |
Windows Time |
|
tmservice.exe |
Added by the W32/Rbot-YK WORM/IRC backdoor Trojan! Read more |
 |
Windows Time |
|
winmgr.exe |
The W32/Rbot-XC WORM/backdoor Trojan adds this and allows malicious remote access by way of the IRC network. Read more |
 |
Windows Update Service |
|
wuacltl.exe |
Added by the W32/Rbot-KB trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection can log keystrokes and sniff traffic on your network. Read more |
 |
Windows USB controler |
|
winusb.exe |
Added by the W32/Rbot-HR trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. Read more |