27th May, 2007
New items - 667
- .. - X - ABC2007.exe
-
[random characters] - X - rsbmsc.exe
-
[random name] - X - [random name].dll
-
[random name] - X - iexpl0ra.exe
-
[random name] - X - rundl13a.exe
-
[random name] - X - Servere.exe
-
_WinData - X - services.exe
-
00TCrdMain - Y - TCrdMain.exe
-
333 - X - svchost.exe
-
4da92ad5.exe - X - 4da92ad5.exe
-
9m - X - winlog0n.exe
-
Acrobat - X - acrmon32.exe
-
Acrobat Read - X - acroup32.exe
-
Acronis True Image - U - TimounterMonitor.exe
-
AcronisTimounterMonitor - U - TimounterMonitor.exe
-
Act! Preloader - U - Act8.exe
-
ActiveKeys.AAB635BD7D054a37A576 - U - akeys.exe
-
ActiveSync - X - wcescom32.exe
-
adirka - X - adirka.exe
-
AdKiller - U - AD Defender.exe
-
Adobe Acrobat - N - READER~1.EXE
-
AdobeReaderPro - X - updt.exe
-
AIMPro - U - aimpro.exe
-
akeys - U - akeys.exe
-
Allopassw - X - [path to trojan]
-
amd_dc_opt - Y - amd_dc_opt.exe
-
AMSG - U - Amsg.exe
-
AntiClicker - X - SVCHST32.EXE
-
Anti-Virus - X - [random filename].exe
-
AOLStart - X - AOLStart.exe
-
arcaderockstar - X - arcaderockstar32.exe
-
ASocksrv - X - SocksA.exe
-
AtiPanel - X - atip.exe
-
audi32 - X - audi32.exe
-
autorun - X - autorun.exe
-
AVantivirus - X - Avconsol.exe
-
AVG Anti-Virus system - Y - avgcc.exe
-
AVG7_CC - Y - avgcc.exe
-
AVP-SE - X - avp-32.exe
-
avptask - X - [path to trojan]
-
avptask - X - expl0rer.exe
-
Avptask - X - rund1132.exe
-
AwaySch - U - AwaySch.EXE
-
AzMixerSel - U - AzMixerSel.exe
-
bab - X - svchst32.exe
-
bal - X - SYSMONMS.EXE
-
BDAgent - U - bdagent.exe
-
BearFlix - U - BearFlix.exe
-
BellSouthAlertManager.exe - U - BellSouthAlertManager.exe
-
BIG - X - biggy.exe
-
BLF - X - blf.exe
-
boby - X - csrs.scr
-
Boot Check - X - bootchk.exe
-
browser - X - browse.exe
-
browser - X - deamon.exe
-
browser - X - msgaol.exe
-
BSserver - X - FileKan.exe
-
ccPrxy.exe - X - ccPrxy.exe
-
ccRegVfY - X - outIook.exe
-
CertificateRegistration - U - SafeSignCertReg.exe
-
CertStoreInit - Y - CertStoreInit
-
Chckup - X - Netverchk.exe
-
Check - X - Check.exe
-
chrono - U - chrono.exe
-
clfmon - X - clfmon.exe
-
clfmon - X - nvsvca32.exe
-
Client Server Runtime - X - [path to worm]
-
CLSRSS - X - LSACS.EXE
-
cmdbcs - X - cmdbcs.exe
-
Cobian Backup 8 interface - U - cbInterface.exe
-
CompanionWizard - N - compwiz.exe
-
Configuration Loadr - X - iexplore.exee
-
Connection Keeper - U - ConKeepM.exe
-
Copernic Desktop Search 2 - U - DesktopSearchService.exe
-
cpl - X - browse.exe
-
cpl - X - msgaol.exe
-
cryptoexpert - U - cexpert.exe
-
CtModule - X - CtModule.exe
-
D_V_T - ? - dvt.exe
-
DataKeeper - U - DataKeeper.exe
-
dcsm - N - dcsm.exe
-
Death.exe - X - Death.exe
-
debugger - X - help.pif
-
defragsys - X - svchost.exe
-
Desktop - X - Desktop.com
-
Development Environment - X - devenv.exe
-
dfgfdgrergd - X - [path to trojan]
-
Dispatcher - X - dispatcher.exe
-
dlcgmon.exe - U - dlcgmon.exe
-
DLLHost - X - dllhst.exe
-
DLM.exe - N - DLM.exe
-
Dm Hr - X - lpns.exe
-
DMHotKey - U - DMLoader.exe
-
DNS Service - X - dnssvc.exe
-
Document Manager - U - docmgr.exe
-
DRam prosessor - X - HWAPI.exe
-
DriveIcons - U - DriveIcon.exe
-
drvsyskit - X - hidr.exe
-
DxDialog - X - dxdlg32.exe
-
Dynamic DHCP - X - dydhcp.exe
-
EEventManager - N - EEventManager.exe
-
EMBASSY Trust Suite Secure Update - U - AutoUpdate.exe
-
ePower_DMC - U - ePower_DMC.exe
-
Eptr - X - nopdb.exe
-
EUP Service - X - eupsvc.exe
-
Exn - X - exn.exe
-
Explorer - X - Windows Explorer.exe
-
ExploreUpdSched - X - [random filename].exe
-
FASTTRACKNETVISION - X - NETVISION.exe
-
FinePrint Dispatcher v4 - U - fpdisp4.exe
-
FinePrint Dispatcher v4 - U - fpdisp4a.exe
-
FinePrint Dispatcher v5 - U - fpdisp5a.exe
-
firefox.exe - X - firefox.exe
-
FJTWAIN Setup - U - FjtwSetup.exe
-
Flash_Player_Install - X - ying.exe
-
FS6519 - X - FS6519.dll.vbs
-
FtLnSOP_setup - U - FtLnSOP.exe
-
Fucker - X - fucker.vbs
-
FusionHdtvTray - N - FusionHdtvTray.exe
-
FusionRC - U - FusionRC.exe
-
FusionRemote - U - FusionRc.exe
-
FusionTrayAgent - N - FusionHdtvTray.exe
-
FW Manager - X - fwcheck.exe
-
fzg - X - svhost32.exe
-
Game House - X - GameHouse.exe
-
Games Acceleration - X - svshost1.exe
-
gCac - X - gcac.exe
-
gdimx - X - gdimx.exe
-
GenericHostXP - X - WinLoaderXP.exe
-
go - X - cvir.exe
-
good - X - badvir.exe
-
Google Desktop - U - GoogleDesktop.exe
-
Google Updater - N - GOOGLE~1.EXE
-
GrooveMonitor - Y - GrooveMonitor.exe
-
gtydf - X - iisca.exe
-
gtydf - X - iscca.exe
-
HanUpdate - X - hanz.exe
-
Hardware Shell Detection - X - WinHSD.exe
-
HDAudio - X - hda.exe
-
hdlfoe df98ndf - X - svchots.exe
-
help - X - help.scr
-
Hotplug - U - hot_plug.exe
-
HPMVTray - U - HPMVTray.exe
-
httpd - X - browse.exe
-
httpd - X - deamon.exe
-
IESet - X - IExplorer.dll
-
ifp - X - ipf.exe
-
igndlm.exe - N - DLM.exe
-
Imatio - U - imation.exe
-
imonitor - X - [path to trojan]
-
Intec Service Drivers - X - [path to worm]
-
Intel system tool - X - svehost.exe
-
Intel(R) Common User Interface - U - hkcmd.exe
-
Intel(R) Common User Interface - N - igfxpers.exe
-
IntelAudioStudio - N - IntelAudioStudio.exe
-
Internal Memory File - X - sysintmemory.exe
-
Internet - X - nteusodp.exe
-
internet - X - winsas32.exe
-
Internet Connection Wizard - X - stisvsq1.exe
-
Internet Mail and News - X - msqdevl1.exe
-
Internet Security Service - X - msq32.exe
-
InternetExplorer2 - X - windows.exe
-
Intranet - X - intranet.exe
-
IntSys1 - X - [path to trojan]
-
ipxwshel - X - ipxwshel.exe
-
iscch - X - iscch.exe
-
ISPSERVICE - X - psycho.exe
-
isxa - X - isxa.exe
-
iTunesAgent - X - ita.exe
-
iut75 - X - uzcx.exe
-
ivy.exe - X - ivy.exe
-
Java Runtime Environment - X - jbuild.exe
-
Javascript - X - jscript.exe
-
jiahus - X - svchqs.exe
-
JMB36X Configure - U - JMRaidTool.exe
-
john315 - X - srrvc.exe
-
jon315 - X - [path to trojan]
-
Juno_uoltray - N - exec.exe
-
jusched - X - [path to trojan]
-
jusodl - X - severe.exe
-
JW Manager - X - jwmngr.exe
-
KAT - X - KAT.vbs
-
kernel32 - X - kernel32.dll.vbs
-
Kernel32 - X - svchosts.exe
-
KernelCheck - X - winser.exe
-
keyboard - X - [path to trojan]
-
KRNL - X - Kernl32.exe
-
Lcass - X - Lcass.exe
-
Letum - X - [path to worm]
-
lgm - X - lgm.exe
-
LifeCam - ? - LifeExp.exe
-
LifeDrive(tm) Manager - U - LifeDriveMgrTray.exe
-
Lingvo Launcher - U - Lvagent.exe
-
LingvoTraining - U - Tutor.exe
-
linkyuu - X - linkuyy.exe
-
Live-Help - X - lmns.exe
-
lnwin.exe - X - lnwin.exe
-
load - X - rundl132.exe
-
Local Service - X - services.exe
-
LocalSystem - X - svchost.exe
-
logg - X - logo_1.exe
-
Login - X - lala.exe
-
Logitech SetPoint - U - KHALMNPR.EXE
-
Logitech SetPoint - U - Setpoint.exe
-
LogService - X - lsrss.exe
-
lsass16 - X - lsass16.exe
-
LTM2 - X - lssas.exe
-
LTM2 - X - MSGSSV32.EXE
-
LTM2 - X - msns6
-
LTM2 - X - RundlI.exe
-
LTM2 - X - SVCHOST32.exe
-
LTM2 - X - SVCHOST˙.exe
-
LTM2 - X - winvers16.exe
-
lwjcjuti.exe - X - lwjcjuti.exe
-
lxbxmon.exe - ? - lxbxmon.exe
-
lxcrmon.exe - ? - lxcrmon.exe
-
lxctmon.exe - ? - lxctmon.exe
-
Macromedia 8 - X - Flash Player.exe
-
Malware-Wiped - N - Malware-Wiped.exe
-
MAV_check - N - mav_startupmon.exe
-
mbssm32 - U - mbssm32.exe
-
mcafee - X - Win32.dll.vbs
-
McAfee Online virus Scanner - X - avp.exe
-
melg34 - X - mdmd.exe
-
Messanger - X - browse.exe
-
mhs3 - X - mhs3.exe
-
Microsft Conf 32 - X - msaconf.exe
-
Microsft Security Monitor Process - X - mssmpp.exe
-
Microsoft - X - mixers.exe
-
Microsoft - X - msmsger.exe
-
Microsoft - X - MSUPDATE.exe
-
Microsoft - X - radnom.exe
-
Microsoft - X - rtvcscan.exe
-
Microsoft - X - taskbar.exe
-
Microsoft - X - updater.exe
-
Microsoft - X - windl32.exe
-
Microsoft (R) Windows Protocol Deployment Manager - X - [random].tmp
-
Microsoft Corp SSL Certificates - X - windowz.exe
-
Microsoft Corporaticn SQL Handler - X - sqlhandler.exe
-
Microsoft Corporation SYM monitor - X - mssym.exe
-
Microsoft Directx click - X - directxclick.exe
-
Microsoft Directx clicks - X - directxclickers.exe
-
Microsoft Directx push - X - directxpushup.exe
-
Microsoft Directxsp - X - directxbt.exe
-
Microsoft Directxspnew - X - directxnew.exe
-
Microsoft DLL Verifier - X - winavguard.exe
-
Microsoft DNSx - X - mdnex.exe
-
Microsoft explorer Update - X - internal.exe
-
Microsoft Genetic Procress - X - svchost.exe
-
Microsoft Installshield - X - nundll32.exe
-
Microsoft Lsass Center - X - telecomes.exe
-
Microsoft Management Console - X - lssas1.exe
-
Microsoft Nod32 Service - X - nood32.exe
-
Microsoft Office - X - msmsgr.exe
-
Microsoft Office Monitor - X - alg2k.exe
-
Microsoft Office Monitor - X - aql32.exe
-
Microsoft Office Quick Launcher - X - iau1.exe
-
Microsoft Security Monitor Process - X - mnsmp.exe
-
Microsoft Security Monitor Process - X - msmp.exe
-
Microsoft Services - X - module.exe
-
Microsoft Svchost local services - X - nzm23.exe
-
Microsoft System - X - mssys32.exe
-
Microsoft System - X - sys.exe
-
Microsoft System File - X - svchots.exe
-
Microsoft System Firewall 2006.2 - X - msmsgr.exe
-
Microsoft System Firewall 2006.2 - X - msnmsgr.exe
-
Microsoft System Firewall 2006.2 - X - reg32.exe
-
Microsoft System Init - X - mtmnr0.exe
-
Microsoft System Saver - X - [path to worm]
-
Microsoft System Security Agent - X - MSTSA.EXE
-
Microsoft Update - X - drive.exe
-
Microsoft Update - X - wangard.exe
-
Microsoft Update Device Drivers - X - wuauclt.exe
-
Microsoft Update Machine - X - winupdte.exe
-
Microsoft Values - X - igfkishc.exe
-
Microsoft Win Corp TLS Verification - X - mswintls.exe
-
Microsoft Windows Explorer - X - explorewin.exe
-
Microsoft Windows System Kernel - X - kernel32.exe
-
Microsoft WWW - X - free.exe
-
Microsoft(r) Windows(r) Operating System - U - ehTray.exe
-
Microsoft(r) Windows(r) Operating System - N - RunDLL32.exe [path] ehuihlp.dll, BootMediaCenter
-
Microsoft(r) Windows(r) Operating System - N - rundll32.exe [path] oobefldr.dll, ShowWelcomeCenter
-
MicrosoftWindows - X - a@26m.exe
-
Microtek Scanner Finder - U - ScannerFinder.exe
-
Micsoft-Published-Software - X - explrer.exe
-
Military Net Killer - X - MNK.exe
-
ml34 - X - [path to trojan]
-
Mlcr0s0ftf DDEs C0ntr0i - X - WAed.pif
-
mlibsysmc - X - comzcinc.exe
-
Mobipocket Reader Notifications - U - readernotify.exe
-
moviemk - X - moviemk.exe
-
Mozila - X - mozila.exe
-
MPNet - X - mpn.exe
-
mppdds - X - mppdds.exe
-
mppds - X - mppds.exe
-
mrsvctr - X - mrsvctr.exe
-
MS Config - X - msdconfig.exe
-
MS Domain Name System - X - MSWDNS32.exe
-
Ms sock for Windows NT - X - winser.exe
-
MS32DLL - X - achi.dll.vbs
-
MS32DLL - X - Bha.dll.vbs
-
msccrt - X - msccrt.exe
-
Msconfig - X - icpldrvx.exe
-
msconfig - X - msconfig.com
-
Msgsvc32 - X - [worm filename]
-
mshtmll - X - mshtmll.dll
-
MSKAGENTEXE - U - MskAgent.exe
-
MSMSGNER - X - [4-8 random letters].exe
-
MSN Messanger - X - msnmsgsmn.exe
-
MSN MESSENGER 9.0 - X - messengerr.exe
-
MsnExplorer - X - msnexploren.exe
-
MsnExplorer - X - sdhch.exe
-
msnmsgq32 - X - msnmsgq32.exe
-
msnmsgq32 - X - sssasasb32.exe
-
MsnMsgr - X - msnmsgr.exe
-
MSNS PLUS XP2 - X - msdupd.exe
-
msnsyslog - N - msnappm.exe
-
MSPetServ - X - PET32.EXE
-
msrdc - X - msrdc.exe
-
MSService_v1.0 - X - realsched.exe
-
MSService_v1.0 - X - vfp02.exe
-
mssync20 - X - mssync20.exe
-
mstds.exe - X - mstds.exe
-
mstsdsc.exe - X - mstsdsc.exe
-
msvccc66 - X - svcchosst.exe
-
mswiz32 - X - mswiz32.exe
-
mule_st_key - X - flec006.exe
-
Multimedia extensions - X - mservice1.exe
-
myMh2 - X - iexpl0re.exe
-
MyShares - X - MyShares.exe
-
MyTam - X - MyTam.exe
-
nClient - X - cnen.exe
-
Ndtstat - X - Ndtstat.exe
-
NET DEMON - X - ndemon.exe
-
Netbeans - X - netbeans.exe
-
NETGEAR WG111T Smart Wizard - U - wlan111t.exe
-
Network Service - X - MccTrayApp.exe
-
Nfo - X - nfomon.exe
-
NI.UWA7P_0001_N91M0809 - N - winantiviruspro2007freeinstall[1].exe
-
Nod32 Service - X - alserv32.exe
-
Norton Antiviral Scanner - X - navscnr.exe
-
Norton Antivirus Updater - X - nortonav.exe
-
Norton System - X - csrs.scr
-
nortonp - X - nortonp.exe
-
Nortons AVS Systems - X - arse.exe
-
NotePad - X - [worm filename]
-
Notepad - X - ntoepad.exe
-
NVRotateSysTray - ? - nvsysrot.dll
-
nvsvca32 - X - clfmon.exe
-
OESET - X - setup60.exe
-
Office - X - Office.exe
-
Office Monitorse - X - [path to worm]
-
Office SturtUp - X - osa9.exe
-
Offices Monitors - X - [path to worm]
-
Offices Monitorse - X - [path to worm]
-
Offices Monitorse - X - algose32.exe
-
OpwareSE4 - N - OpwareSE4.exe
-
Oracle Web-to-Go - U - webtogo.exe
-
OutpostFeedBack - Y - feedback.exe
-
p2p networking - X - p2pnetworking.exe
-
ParetoLogic Anti-Spyware - U - Pareto_AS.exe
-
pas_check - N - pasmon.exe
-
PC Doc Pro - 3.1 - U - pcdocpro.exe
-
PC Pitstop Optimize Scheduler - U - PCPOptimize.exe
-
PC2X - X - initial.bat
-
PCPOptimize - U - PCPOptimize.exe
-
PdaNet Desktop - U - PdaNetPC.exe
-
pdfFactory Dispatcher v1 - U - fppdis1a.exe
-
pdfFactory Pro Dispatcher v3 - U - fppdis3a.exe
-
Performs peer to peer connection - X - WinPTTP.exe
-
Persistence - N - igfxpers.exe
-
PhiBtn - Y - PhiBtn.exe
-
PingTimeout Institution - X - internal.exe
-
pnvifj - X - jusodl.exe
-
POP Manager - X - popmgr.exe
-
PowerPanel Personal Edition User Interaction - U - pppeuser.exe
-
PrU Async Service - X - [path to worm]
-
PSC main - X - sttool32.exe
-
PSCMain - X - pscmain2.exe
-
PWRESET - U - pwreset.exe
-
QlbCtrl - U - QlbCtrl.exe
-
QQ.exe - X - QQ.exe
-
Quick Heal Firewall Pro - U - qhfw.exe
-
qwertybot.exe - X - qwertybot.exe
-
RAID Event Monitor - U - iaanotif.exe
-
Rainlendar2 - U - Rainlendar2.exe
-
Random Interface Network - X - rst.exe
-
Random Interface Network Manager - X - rinsv.exe
-
Rapdatybs - X - ravseteyns.exe
-
rasman - X - rasman32.exe
-
ravshell - X - expl0rer.exe
-
Ravshell - X - explore3.exe
-
Ravshell - X - IEXPLORER.EXE
-
Ravshell - X - rund1132.exe
-
Ravshell - X - svch0st.exe
-
ravtask - X - rund1132.exe
-
ravtask - X - svch0st.exe
-
Realaudio Player - X - realaudio32.exe
-
Recoveru system - X - svchast.exe
-
Registry Protector - X - regprotect.exe
-
Registry Service - X - resvs.exe
-
RegPowerClean - N - RegPowerClean.exe
-
Remote Desktop Help Session Manager - X - WinRDH.exe
-
Rg2catbd - X - Rg2catbd.exe
-
rmdrfje.dll - X - rundll32.exe [path] rmdrfje.dll
-
Rollback - U - RollbackTray.exe
-
Rr2 - X - rundll32.exe
-
rsmb - X - rsmb.exe
-
rtasks - N - rtasks.exe
-
RtHDVCpl - U - RtHDVCpl.exe
-
RunDll32 essprops - Y - RunDll32 essprops.cpl, TaskbarIconWnd
-
runner1 - X - updater.exe
-
rx - X - explore.exe
-
S - X - svhost.exe
-
SANS Service - X - sansv.exe
-
SBCSTray - U - SBCSTray.exe
-
Scandsk2 - X - scandsk2.exe
-
ScanRegistry - X - update.exe
-
Scheduler - X - msnexploren.exe
-
Scheduler - X - sdhch.exe
-
Scheduler - X - svchst.exe
-
sctrlmgr - X - sescmgr.exe
-
SDTray - U - SDTrayApp.exe
-
SearchNet_Up - X - ServeUp.exe
-
Secure Socket Layer Certification - X - sslcert.exe
-
Secure System - X - integitor.exe
-
Security Service - X - secsvc.exe
-
Security Service Process - X - svhost.exe
-
serrv - X - serrv.exe
-
Server Runtime Process - X - wbemstest.exe
-
Services - X - iexploler.exe
-
Services - X - iexpolere.exe
-
Servicewin - X - Hide32.exe
-
SES Service - X - sesvc.exe
-
SetDefaultPrinter - Y - cloaker.exe
-
SetPoint - U - Setpoint.exe
-
Shadow - Y - Shadow.exe
-
Shell - X - ibm00001.dll
-
Shelldaemon - X - Shelldaemon.exe
-
ShellN - X - isca.exe
-
Shockwave Support - X - FlashPlayer.exe
-
Sidebar - U - sidebar.exe
-
SigmatelSysTrayApp - N - sttray.exe
-
SiS Mpc Service - X - mpcsvc.exe
-
SkypeStartup - X - Skype.exe
-
slack12 - X - mfcee.exe
-
SM56 Helper Win32 Utility - N - sm56hlpr.exe
-
Smiley District - X - plugin.exe
-
soundmix - X - soundmix.exe
-
Spark - U - Spark.exe
-
spoolsv - X - spoclsv.exe
-
SpyHealer - N - SpyHealer.exe
-
SpyHeals - X - SpyHeals.exe
-
SpywareLocked - N - SpywareLocked.exe
-
SpywareLocked 3.5 - N - SpywareLocked 3.5.exe
-
SRS Audio Sandbox - U - SRSSSC.exe
-
sssasasb32 - X - msnmsgq32.exe
-
staeck12 - X - mfcee.exe
-
StartCCC - N - CLIStart.exe
-
startemdoit - X - [path to trojan]
-
startkey - X - antivir.exe
-
StdAFX - X - stdafx.exe
-
StreamAppliance - X - wuauclt14.exe
-
StreamAppliance - X - wuauclt16.exe
-
supdate2.dll - X - rundll32.exe [path] supdate2.dll
-
superproxy - X - superproxy.exe
-
SvcH0st - X - msnexploren.exe
-
SvcH0st - X - sdhch.exe
-
svchctrl - X - svchctrl.exe
-
svchos - X - svchos.exe
-
SVCHOST - X - MDM.EXE
-
Svchost - X - svchots.exe
-
svchost - X - ying.exe
-
svchost.exe - X - swchost.exe
-
SvcManager - X - restore3.exe
-
Sygaete Personal Firewall - X - SyGate.exe
-
Sygate Personal Firewall - X - svchots.exe
-
Symantec Antivirus professional - X - dfrgfrat.exe
-
Symantec Secure Server - X - svrhost.exe
-
SymantecFilterCheck - X - svhost.exe
-
Symmetrical Network - X - symmec.exe
-
Synaptics Pointing Device Driver - U - SynTPEnh.exe
-
sys33 - X - sys33.exe
-
SysATW - X - sysatw.exe
-
Sysctrls - X - winupdate.exe
-
sysemls - X - sysem.exe
-
Sysmon - X - SystemMonitor.exe
-
SysmonLog - X - mslog.exe
-
Syss - X - ehuupdate.exe
-
Sys-Stat - X - wuapdxe.exe
-
System - X - OeApi.vbs
-
System - X - Updaterun.exe
-
System - X - Zap.exe
-
System Boot Check - X - sysload3.exe
-
System Check - X - win_klr32.exe
-
System Support - X - torrent.exe
-
System32 - X - [worm filename]
-
SystemMgr - X - Ir32_a.exe
-
Systems - X - sescmgr.exe
-
Systems - X - spoolsvc.exe
-
Systems - X - sysmon.exe
-
systemscroot - X - systembin.exe
-
System-Stat - X - systats.exe
-
systr - X - SYSERVER.exe
-
systr2 - X - SERVICE.exe
-
Systray - X - KAT.vbs
-
SysTray - X - svhost.exe
-
syswin - X - v6.exe
-
SyztMy - X - expiorer.exe
-
talk - X - talk.bat
-
Task Manager - X - svchost.exe
-
Task Manager - X - taskmng.exe
-
taskmgr - X - [path to trojan]
-
taskmgr - X - taskmanager.exe
-
TaskSwitchXP - U - TaskSwitchXP.exe
-
TCP Internet Services - X - TCPSVC32.EXE
-
tcpipmon - X - tcpipmon.exe
-
Terminal Services - X - mstscc.exe
-
Think-Adz - X - [random filename].exe
-
TimounterMonitor - U - TimounterMonitor.exe
-
TivoNotify - ? - TiVoNotify.exe
-
Top Tilecom - X - Tilecomtop.com
-
Topic lnternet - X - lnternet32.exe
-
TPwrMain - Y - TPwrMain.EXE
-
Tray - X - rundll32.exe
-
Traymin900 - U - Tray900.exe
-
Trend Micro AntiVirus 2007 - Y - tavui.exe
-
TRIXX - U - TRIXX.exe
-
tsrv - X - t2serv.exe
-
tsrv - X - tsrv.exe
-
TurBo - X - System.Trubo.vbs
-
TV878 Remote Control - U - C7XRCtl.exe
-
Uniblue SpyEraser - U - spyeraser.exe
-
Update - X - hanz.exe
-
Updates from HP - N - Updates from HP.exe
-
UpromiseRemindU - U - wjview ...Code
-
upxdn - X - upxdn.exe
-
upxdnd - X - upxdnd.exe
-
userinit - X - choo_003956f4
-
userinit - X - ntos.exe
-
uvnx - X - uvcx.exe
-
uvnx - X - uvnx.exe
-
UVS10 Preload - U - uvPL.exe
-
uwa7pcw - N - uwa7pcw.exe
-
V0250Mon.exe - Y - V0250Mon.exe
-
VaCtrls - X - v7
-
VirusRescue - N - VirusRescue.exe
-
VisualTaskTips - U - VisualTaskTips.exe
-
VisualTooltip - U - VisualToolTip.exe
-
vmnetdhcp - X - vmnetdhcp.exe
-
vst - X - vstkmgr.exe
-
VX Audio - X - vxaudio.exe
-
VX1000 - ? - vVX1000.exe
-
VX3000 - ? - vVX3000.exe
-
VX6000 - ? - vVX6000.exe
-
W1N32.DLL - X - WINLOGON .exe
-
W32SYS - X - w32sys.exe
-
WarReg_PopUp - N - WarReg_PopUp.exe
-
wgs3 - X - wgs3.exe
-
WGV - X - WGV.exe
-
Win Process Updates - X - winupdates.exe
-
Win Prosess0r - X - [random filename]
-
Win Update - X - msnmger.exe
-
Win32 - X - sysmon.exe
-
Win32 - X - zaq.exe
-
Win32 FireWire Driver - X - CTHELPER32.EXE
-
Win32 Help32 Service - X - win32help.exe
-
Win32 Information Service - X - crsrs.exe
-
Win32 Information Service - X - crsss.exe
-
Win32 Security Service - X - crsrs.exe
-
Win32 Update - X - dl32.exe
-
Winamp Media - X - qmedia.exe
-
WinAmpAgent - X - msnexploren.exe
-
WinAmpAgent - X - sdhch.exe
-
WinAntiVirus Pro 2007 - N - WinAV.exe
-
WinCheck - X - check.exe
-
WinData - X - services.exe
-
WinDLL (csmss.exe) - X - rundll32.exe [path] CSMSS.EXE
-
Windowfdgfds DasdLL Verifiew - X - [path to worm]
-
Windows (ICS) Spooler - X - crtss.exe
-
Windows Critical Alert - X - wincrt.exe
-
Windows Desktop Search - U - WindowsSearch.exe
-
Windows Driver Foundation - X - MTVSCMXT.EXE
-
Windows Guard - X - WAUMGRD.EXE
-
Windows Insecure - X - [path to worm]
-
Windows IP Security Service - X - ipsecs.exe
-
Windows Login - X - lmss.exe
-
Windows Logon Application - X - win32help.exe
-
Windows Logon Application - X - winlogon.exe
-
Windows LoL Layer - X - [random filename].exe
-
Windows LoL Layer - X - pyvnpt.exe
-
Windows LoL Layer - X - winlolx.exe
-
Windows Media Center - N - RunDLL32.exe [path] ehuihlp.dll, BootMediaCenter
-
Windows Media Upgrade - X - NeUpgrade.exe
-
Windows modez Verifier - X - taskmngr.exe
-
Windows modez Verifier - X - winl0g0z.exe
-
Windows Net Cfg - X - service.exe
-
Windows Portable Device Drivers - X - MSKSVRVS.EXE
-
Windows Portable Devices - X - MSKSVRTSS.EXE
-
Windows Process - X - win_update.exe
-
Windows Secure Update - X - WinSecUp.exe
-
Windows Security Center Notification Appls - X - sxe.exe
-
Windows Security Center Notification Applse - X - sxes.exe
-
Windows Service DC - X - uhpnjcjl.exe
-
Windows Service Manager - X - taskmgr.exe
-
Windows Software - X - hbsppe.exe
-
Windows System - X - winsys32.exe
-
Windows System Manager - X - CRSL.EXE
-
Windows Update - X - avkir.exe
-
Windows Update - X - WindowsUpdate.exe
-
Windows Update AutoUpdate Client - X - waucult.exe
-
Windows Update GUI Executable x32x - X - wupdategux32.exe
-
WindowsRegKey update - X - rkbuouoxfl.exe
-
WindowsRegKey update - X - winsys.exe
-
WindowsRegKey update - X - winupdat32.exe
-
WindowsSystem32 - X - asper.exe
-
WindowsSystem32 - X - svchosts.exe
-
WindowsUpdate - X - svchostw.exe
-
WindowsUpdate renew - X - iexplore.exe
-
WindowsUpdatem2 - X - svchost.exe
-
WindowsUpdateR - X - regserv.exe
-
WinFastDTV - U - DTVSchdl.exe
-
WinFlyer32.dll - X - WinFlyer32.dll
-
winform - X - winform.exe
-
WinMsg - X - winmsgr.exe
-
winnt - X - winnt.exe
-
WinPatrol Explorer - Y - WinPatrolEx.exe
-
winpol - X - winpol.exe
-
WinReader - X - read.exe
-
WinRPC - X - winrpcmx.exe
-
WinService - X - Ttt.exe
-
Winsock2 driver - X - dllcfg32.exe
-
WinSystems - X - winsystems16.exe
-
WinWorks - X - vstmgr.exe
-
Wkyo86 - X - [path to worm]
-
wms3 - X - wms3.exe
-
WNSO - X - WNSO.exe
-
wow - X - Launcher.exe
-
WPCUMI - Y - WpcUmi.exe
-
wsttrs - X - wsttrs.exe
-
wsvbs - X - wsvbs.exe
-
WUpdate - X - 1037v.exe
-
xloadnet - X - xloadnet.exe
-
xor - X - svshost.exe
-
Xordate - X - wuauclt10.exe
-
Xordate - X - wuauclt11.exe
-
Xordate - X - wuauclt12.exe
-
Xordate - X - wuauclt13.exe
-
Yahoo Messenger - X - svchost32.exe
-
Yahoo Messengger - X - RVHOST.exe
-
Yahoo Messengger - X - SSVICHOSST.exe
-
Yahoo! Pager - N - YAHOOM~1.EXE
-
yemarvd - X - sysmon.exe
-
YeppStudioAgent - N - SamsungMediaStudioAgent.exe
-
YhooUapdates - X - ymssmsgs.exe
-
YhooUpdates - X - ymsmsgs.exe
-
ying - X - ying.exe
-
Y'z Shadow - U - YzShadow.exe
-
Y'z Toolbar - U - YzToolBar.exe
-
Z - X - zmon.exe
-
ZNN - X - znnsvc.exe
-
zone alarm security - X - zlclint.exe
-
Zooming - U - ZoomingHook.exe
-
zSecurity Service - X - szsvc.exe
-
(blank) - X - dllvirtual.dll
-
(blank) - X - dllvirtual.exe
-
(blank) - X - dllvirtual.js
Changed items - 57
- Adobe Reader Speed Launch (READER~1.EXE) - Name changed
-
Advanced DHTML Enable ([path to trojan]) - Hyperlink and description changed
-
ATICCC (CLIStart.exe) - Status (N) and description changed
-
browser (s_menu.exe) - Command changed
-
CLISTART (CLIStart.exe) - Status (N) and description changed
-
cpl (s_menu.exe) - Command changed
-
dlbcserv (dlbcserv.exe) - Status (N) and description changed
-
dlcdmon.exe (dlcdmon.exe) - Status (U) and description changed
-
ehTray (ehTray.exe) - Description changed
-
Error Safe (ers.exe) - Status (N) changed
-
ERS (ers_startupmon.exe) - Status (N) changed
-
ERS_check (ers_startupmon.exe) - Status (N) changed
-
erscw (erscw.exe) - Status (N) changed
-
Freedom (Freedom.exe) - Description changed
-
hkcmd (hkcmd.exe) - Status (U) and description changed
-
HotKeysCmds (hkcmd.exe) - Status (U) and description changed
-
httpd (s_menu.exe) - Command changed
-
igfxtray (igfxtray.exe) - Description changed
-
Intel(R) Common User Interface (igfxtray.exe) - Description changed
-
Kernel and Hardware Abstraction Layer (KHALMNPR.EXE) - Description changed
-
Logitech Hardware Abstraction Layer (KHALMNPR.EXE) - Description changed
-
LSvr (LSvr.exe) - Description changed
-
LTDMgr (LTDMgr.exe) - Description changed
-
Messanger (s_menu.exe) - Command changed
-
Mgabg (Mgabg.exe) - Status (U) and description changed
-
ms (svhost32.exe) - Hyperlink and description changed
-
Msbackups (backups.exe) - Description changed
-
MSKAGENTEXE (MskAgent.exe) - Description changed
-
NI.UERSM_0001_N68M1602 (UERSM_0001_N68M1602NetInstaller.exe) - Status (N) changed
-
Opware12 (Opware12.exe) - Description changed
-
Opware14 (Opware14.exe) - Description changed
-
Opware15 (Opware15.exe) - Description changed
-
OpwareSE2 (OpwareSE2.exe) - Description changed
-
pdfFactory Dispatcher v2 (fppdis2a.exe) - Hyperlink and description changed
-
pdfFactory Pro Dispatcher v1 (fppdis1.exe) - Status (U), hyperlink and description changed
-
Persistence (igfxpers.exe) - Description changed
-
pmr (pmr.exe) - Description changed
-
PPCRunonce (PPCRunOnce.exe) - Status (U) and description changed
-
Rainlendar (Rainlendar.exe) - Hyperlink changed
-
RavAV (RavMon.exe) - Description changed
-
RavAV (RavMonE.exe) - Hyperlink and description changed
-
Remote (Remote.exe) - Status (U) and description changed
-
Servicio Local (svhost.exe) - Hyperlink and description changed
-
SetPoint (Setpoint.exe) - Description changed
-
SigmatelSysTrayApp (stsystra.exe) - Status (N) changed
-
Sm56acl (sm56hlpr.exe) - Description changed
-
Smserial (sm56hlpr.exe) - Status (N) and description changed
-
sr64 ([path to trojan]) - Description changed
-
SSBkgdUpdate (SSBkgdupdate.exe) - Description changed
-
TvrRemote (Remote.exe) - Description changed
-
Windows modez Verifier (Window2.exe) - Hyperlink and description changed
-
Windows modez Verifier (winlogom.exe) - Hyperlink and description changed
-
Windows Service (WINSVC.EXE) - Description changed
-
xy (svhost32.exe) - Hyperlink and description changed
-
(MSPF.EXE) - Description changed
-
(pathex.exe) - Description changed
-
(svchost.exe) - Description changed
Removed - 10
- hphupd04 - N - hphupd04.exe - Covered by HPHUPD** generic entry
- HPHUPD05 - ? - hphupd05.exe - Covered by HPHUPD** generic entry
- HPHUPD06 - N - hphupd06.exe - Covered by HPHUPD** generic entry
- kernel32 - X - kernel32.exe - Already covered by CHODE-I
- MSKAGENTEXE - U - MskAgent.exe - Duplicate
- starter - X - scvhosting.exe - Already covered by SDBOT.RU
- StartMenu - X - s_menu.exe - TACTSLAY.C duplicate
- WindowsRegKey update - X - [random filename] - SPYBOT.GP - already covered by RBOT.QT
- WindowsRegKey update - X - 16winupdate32.exe - Already covered by RBOT.QT
- WindowsRegKey update - X - windup.exe - Already covered by RBOT.QT
Other
- Revised the GAIN/Gator entries
- Corrected hundreds of other "moved" or "broken" links