| Name | Status | Filename | Description |
|---|
| X | MSPF.EXE | Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
|
| X | svchost.exe | Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
|
| X | mstdmc.exe | Added by Trojan-Downloader.Win32.Banload.cil MALWARE! Note: Located in \%WINDIR%\System32\ The startup name is empty This will make sure that it's start at startup. |
| X | msmapiax32.exe | Identified as a variant of the Rootkit.Win32.Agent.uj rootkit. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| X | msmapibx32.exe | Identified as a variant of the Rootkit.Win32.Agent.uj rootkit. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| | | Added by the W32/Sdbot-DHY, Worm! Read the link, allows remote access Note: located in \%WINDIR%\ Note: Use SDFix under supervision. |
| hamachi | U | hamachi.exe | Related to hamachi Instantly connect multiple computers in a VPN from LogMeIn Inc. Note: Located in \%Program Files%\Hamachi\ |
| Security Patch | X | scmss.exe | Added by the W32/RBOT-ZW WORM! Read the link, keylogger/password stealing trojan(s) involved. |
| WinCheck | X | services.exe | Added by the W32.Sober.V
WORM!
Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder. |
| Windows | X | services.exe | Added by the W32.Sober.X
WORM!
Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.) This worm file is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
|
| !1_pgaccount | Y | pgaccount.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
| !1_ProcessGuard_Startup | Y | procguard.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. |
| !AVG Anti-Spyware | U | avgas.exe | Related to AVG_Anti-Spyware from Grisoft. Note: Located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\ |
| !ewido | U | ewido.exe | Part of Ewido anti-spyware
|
| !NoLoad | U | winrecon.exe | Winrecon Read the link, keylogger/password stealing trojan(s) involved. - Commercial Keylogger |
| $EnterNet | U | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
| $sys$cmp | X | $sys$xp.exe | Added by the Backdoor.Ryknos.B
TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
Read the link, rootkit type stealth involved.
|
| $sys$crash | X | $sys$WeLoveMcCOL.exe | Added by the Welomoch
TROJAN!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY! |
| $sys$crash | X | $sys$sonyTimer.exe | Added by the Welomoch
TROJAN!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY! |
| $sys$crash | X | $sys$sos$sys$.exe | Added by the Welomoch
TROJAN!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY! |
| $sys$drv | X | $sys$drv.exe | Added by the Backdoor.Ryknos
TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
Read the link, rootkit type stealth involved.
|
| $Volumouse$ | U | volumouse.exe | Related to Volumouse from Nirsoft. Provides you a quick and easy way to control the sound volume on your system. Note: Located in C:\Program Files\Volumouse\ |
| $WindowsRegKey%update | X | IEXPLORE.EXE | Added by a W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually! |
| %cmpmixtitle% | ? | %cmpmixstr% | Possibly related to C-Media Mixer Control panel? |
| %FP%012-L2TP fts.exe | ? | fts.exe | 012.Net ISP software - what does it do and is it required? |