| Name | Status | Filename | Description |
|---|
| Microsoft Windows System32 | X | winservs.exe | Added by the W32/Tilebot-GU WORM! Note: This worm\trojan is located in C:\%WINDIR%
Also been identified with the filename: winsysdir.exe |
| Microsoft Windows System32 | X | windll32.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Microsoft Windows Update | X | wuautcl.exe | Troj/Spybot-NQ Read the link, allows remote access |
| Microsoft Windows Update (Microsoft Update) | X | scvvhost.exe | Added by the W32/Forbot-FH
WORM!
|
| Microsoft Windows Update (Microsoft Windows Update) | X | msconfig32.exe | Added by the W32/Tilebot-P
WORM!
Read the link, rootkit type stealth involved.
|
| Microsoft Windows Update (msupdate) | X | csrss.exe | Added by an unknown TROJAN!, Note: This has nothing to do with Microsoft Windows Update and this is not the legitimate Windows Process csrss.exe. (Which is found in the System32 folder.) This trojan file (csrss.exe) is found in the Windows or Winnt folder. |
Microsoft Windows Validation Service (Windows Validation Service) | X | devldr32.exe | Added by a variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs devldr32.exe file. Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| MicroSoft Windowz Update (MsFtUpd) | X | MsFtUpdateXP.exe | Added by the W32/Tilebot-BL
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
|
| Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) | X | wmiapsrv.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ NOT TO BE confused with C:\WINDOWS\System32\wbem\wmiapsrv.exe which is a Microsoft application |
| Microsoft XP TCP Ack Timing | X | winxptcp.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Microsoft(R) Windows(R) Operat (Microsoft Corporation) | X | iexplorer.exe | Added by the Troj/Feutel-W
TROJAN!
Note: This is not the legitimate Windows Process (iexplore.exe) which is found in the Program Files\Internet Explorer folder. (Notice the difference in the spelling.) This trojan file (iexplorer.exe) is found in the System32\Internet Explorer folder. |
| microsoftdvdhelp (MicrosoftDVD) | X | msdvd.exe | Added by the W32/Rbot-AWQ
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved. |
| Microsoftkeysd | X | systemwin32.exe | |
| MilShieldCleaner | L | ShieldService.exe | Related to Mil_Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities. Note: Located in C:\Program Files\Mil Incorporated\Mil Shield\ |
| MindRetrieve Engine (MindRetrieve) | L | MindRetrieve.exe | MindRetrieve
Appears to be a personal desktop search engine.
|
| MindStorm Agent | L | srvpxa.exe | Related to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices. |
| MindStorm AnalyzerPro Controller | L | srvctr.exe | Related to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices. |
| MindStorm AnalyzerPro Correlation Engine | L | srvcor.exe | Related to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices. |
| MindStorm Controller | L | srvctr.exe | Related to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices. |
| MindStorm Correlation Engine | L | srvcor.exe | Related to MindStorm_AnalyzerPro from Secure Associates. A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices. |
| Mini USB Driver | X | svñhîst.exe | Troj/Proxy-CY Note: Located in %windir%\system32 Read the link, allows remote access |
| MINIServer (MiNiService) | X | MiniServer.exe | Added by the Troj/LittleW-E
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder.
|
| MioNet Service (MioNet) | L | MioNetManager.exe | Related to MioNet from MioNet now owned by Western Digital. Access any file on your remote MioNet computer from another MioNet computer. Note: Located in \%Program Files%\MioNet\ |
| Miramar AppleTalk File Server | L | ATSERVER.EXE | Related to Miramar_AppleTalk_File_Server Now owned by Pure Networks, Inc. PC MACLAN will permit the transfer of data from PC to Mac. Note: Located in \%Program Files%\Miramar\PC MACLAN\ |
| Miramar AppleTalk Print Server | L | ATSPOOL.EXE | Related to Miramar_AppleTalk_Print_Server Now owned by Pure Networks, Inc. PC MACLAN will permit the transfer of data from PC to Mac. Note: Located in \%Program Files%\Miramar\PC MACLAN\ |
| MirraSync Service (Mirra.Service) | L | mirra.service.exe | Related to Mirra_Server from Seagate Tech. Persornal server. Note: Located in \%Program Files%\mirra\ |
| Miscrosoft Updates Service 4 | X | msupd4.exe | Trojan-Downloader.Win32.Agent.gn |
| Miscrosoft Updates Service 5 | X | msupd5.exe | Trojan. TROJ_LODMEDUD.A |
| MkSUpdateInt | L | MkSUpdateInt.exe | ArcaVir an AntiVirus software from Poland. A procuct of ArcaBit Sp. z o.o |
| MkS_Scan | L | mks_scan.exe | ArcaVir an AntiVirus software from Poland. A product of ArcaBit Sp. z o.o |
| mks_vir antivirus monitor (MksVirMonSvc) | L | mksmonsv.exe | ArcaVir an AntiVirus software from Poland. A product of ArcaBit Sp. z o.o |
| MLKKBDNTDriver | O | MLKKBDNTService.exe | Unknown |
| MMX Virtualization Service | X | mmx464.sys | Added by the Goldun.J
TROJAN!
Read the link, rootkit type stealth involved.
|
| MMX2 Virtualization Service | X | mmx464.sys | Added by the Goldun.J
TROJAN!
Read the link, rootkit type stealth involved.
|
| MNSFramework | L | MNSFramework.exe | Mobile Net Switch
enables you to use your computer on more than one network with the click of a button.
Note: Located in C:\WINDOWS\system32 (XP NT) |
| MobilePre Installer (MobilePreInstallerService) | L | MPInst.exe | Related to MobilePre_Installer USB Bus-powered Preamp and audio interface from M-Audio. Note: Located in \%Program Files%\M-Audio MobilePre\Install\ |
| Mobility Client (ArtourService) | L | artsvc.exe | Related to IBM_Mobility_Client Note: Located in C:\Program Files\IBM\Mobility Client\ |
| MobilityService | L | MobilityService.exe | Related to Modibily_Service from Acer. Note: Located in \%ROOT%\Acer\Mobility Center\ |
| MOBSYNC | X | MOBSYNC.EXE | Added by the SDBOT.CNT
WORM!
Read the link, rootkit type stealth involved.
|
| modlb (modlb) | X | modlb.exe | Added by the W32/Tilebot-BF
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
|
| mondrv (mondrv) | X | mondrv.sys | Added by the TROJ_ROOTKIT.M
TROJAN!
Read the link, rootkit type stealth involved.
|
| MONDV | X | MONDV.SYS | Added by the Troj/Rootkit-Z
TROJAN!
Read the link, rootkit type stealth involved.
|
| MonSvcNT | L | MonSvcNT.exe | Related to AhnLab Monitor service from AhnLab, Inc. Note: Located in \%Program Files%\AhnLab\V3\ |
| Morrin Thumbnail Synchronized Service 5 (MrnTS_Sync5) | ? | MrnTS_Sync5.exe | From Morrin Corporation?
http://forums.spywareinfo.com/index.php?act=ST&f=18&t=43573 |
Motor de Spy Sweeper de Webroot (WebrootSpySweeperService) | L | SpySweeper.exe | Related to Webroot Sortwre inc. Spyware protection software. Note: Located in \%Program Files%\Webroot\Spy Sweeper\ |
| Motorola Digital Audio Player Manager | L | MotorolaDAP.exe | Related to Motorola Inc. Motorola Digital Audio Player. |
| Mouse Button Monitor (mousebm) | X | mousebm.exe | Added by the W32.Esbot.A
WORM!
|
| Mouse Click Monitor (mousecm) | X | mousecm.exe | Added by the W32/Sdbot-ZQ
Worm!
|
| Mouse Cursor Monitor (mousecrm) | X | mousecrm.exe | Added by the W32/Sdbot-ABQ
WORM!
|
| Mouse Hardware Sync (mousehs) | X | mousehs.exe | Added by the Troj/Bdoor-HU WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |