| Name | Status | Filename | Description |
|---|
| U.S. Robotics Wireless LAN Service (wltrysvc) | L | WLTRYSVC.EXE | Related to wireless networking for U.S. Robotics wireless network cards. Note: Located in \%WINDIR%\System32\ |
| UDP Sub Packet Classifier (UDPSPC) | X | MSUDPSPC.EXE | Added by the SDBOT.CBF
WORM!
Read the link, rootkit type stealth involved.
|
| UDS Environment Manager 5.0.14 | L | nodemgr.exe | Related to Forte_4GL_System from Sun Microsystems, Inc. |
| UDS Environment Manager 5.1.3 | L | nodemgr.exe | Related to Forte_4GL_System from Sun Microsystems, Inc. |
| UDS Repository Manager 5.0.14 | L | rpserver.exe | Related to Forte_4GL_System from Sun Microsystems, Inc. |
| UDS Repository Manager 5.1.3 | L | rpserver.exe | Related to Forte_4GL_System from Sun Microsystems, Inc. |
| UFD Command Service (UFDSVC) | L | ufdsvc.exe | USB flash drive driver |
| Ulead Burning Helper | L | ULCDRSvr.exe | Ulead DVD Burning Service |
| Ulead Burning Helper (UleadBurningHelper) | L | ULCDRSvr.exe | Related to Ulead_DVD_workshop allows the writing to DVD and CD media. |
| Unicenter Message Queuing Server (CA-MessageQueuing) | L | cam.exe | Related to Computer Associates, Inc. |
| Unicenter Remote Control Host (rcHost) | L | rcHost.exe | Related to Unicenter_Remote_Control_Host From Computer Associates
Note: Located in C:\BA_MGMT\TNGRCO\RCO60\ |
| Unicenter Software Delivery (SDService) | L | SDSERV.EXE | Related to Unicenter Asset Management by Computer_Associates |
| Unicenter_Localise | O | srvany.exe | Microsoft Windows application which allows an executable to be run as a service. If you have installed this service, fine, otherwise investigage. Can be used to load Malware. |
| Uninterruptible Power Supply (UPS) | L | ups.exe | power management application from APC PowerChute. |
Universal Plug and Play Device Configuration (UPnP Configuration) | X | upnp.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located C:\%WINDIR%\System32\ |
| Universal Printer NT Service | X | upnt.exe | W32/Rbot-GKP |
| Universal Serial Bus Control Protocol (pnpext) | X | smrs.exe | Added by the Troj/Bdoor-JD
TROJAN!
|
| Unknown | ? | wisptis.exe | |
| Unknown owner | L | wtxregds.exe | part of development software for microprocessors. |
| Uno Installer (UnoInstallerService) | L | UnoInst.exe | Related to M-Audio_Uno device which is a gateway between usb and midi cables. Note: Located in \%Program Files%\M-Audio Uno\ |
| UnrealIRCd | L | wircd.exe | Related to UnrealIRCd |
| updates | X | services.exe | Added by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\win32\ (XP/WinNT/2K) |
| UpgradeToolTFTPService (crmtftp) | L | crmtftp.exe | Related to CiscoWorks_Small_Network_Management Note: Located in \%Program Files%\CISCOS~1\UPGRAD~1\ |
| UPnPDevService | X | upnpmngr.exe | Added by the Troj/Small-DMW TROJAN! Note: This worm\trojan is located in C:\Program Files\Common Files\PnpManager\ |
| UPnPService | L | UPnPService.exe | Related to UPnPService from Magix_AG Note: Located in \%Program Files%\Common Files\MAGIX Shared\UPnPService\ |
| UPS | X | ups32.exe -v | Added by the W32/Mofei-H
WORM!
|
| UPS - APC PowerChute plus (UPS) | L | ups.exe | power management application from APC PowerChute. |
| UPS - UPSentry Service (UPSentry_Smart) | L | upsd.exe | Related ro Belkin_Bulldog Plus control software for the UPS (Uninterrupted Power Supply) via a serial or USB link. Note: Located in C:\Program Files\Belkin Bulldog Plus\ |
| UPS Service (CyberPowerUPS) | L | upssrv.exe | Cyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner." |
| UPSMONService | L | UPSMON_Service.Exe | Related to UPSMON Power Management Software. Made by Powercom_USA
This file is found in the Program Files\UPSMON folder.
|
| US30Service | L | US30Service.exe | Related to Everstrike Software. Folder protection tool. |
| USB Device | X | win32usb.exe | http://www.sophos.com/virusinfo/analyses/w32forbotbq.html |
| USB sks2drvr (sks2drvr) | X | sks2drvr.sys | Added by the Backdoor.Haxdoor.G
TROJAN!
Note: This trojan file should be found in the System32 folder. The file sksdll.dll will be found with this one.
Read the link, rootkit type stealth involved. |
| USB sksDRVR2 (sksdrvr2) | X | sksdrvr2.sys | Added by the Troj/Haxdoor-AL
TROJAN! Note: This trojan file is found in the System32 folder. |
| USBDeviceService | L | USBDeviceService.exe | Related to USBDeviceService Module belongs to Sonic MyDVD or Sonic MyDVD LE. Note: Located in \%Program Files%\Sonic\DigitalMedia LE v7\MyDVD LE\ |
| USBest Service Zero (UTSCSI) | L | UTSCSI.EXE | Related to USBest PQI Card Drive (USB). Note: Located in C:\%WINDIR%\System32 (XP/WinNT/2K) |
| USBMate | L | usbmate.exe | Related to Belkin_USB products. Note: located in C:\Program Files\Belkin\Belkin Power Management Software\ |
| USBTest (USBTest) | X | USBTest.sys | Added by the Troj/RKPort-Fam
TROJAN! Note: This trojan file is found in the System32\drivers folder. Dropped by Troj/Lecna-D
and Troj/Lecna-F
Read the link, rootkit type stealth involved.
|
| USEndpoint | L | Tuner.exe | Related to Marimba_US_Endpoint solutions. Now owned by BMC Software, Inc. Note: Located in \%Program Files%\Marimba\Marimba US EndPoint Tuner\ |
| User Initialization (usrinit32) | X | userinit.exe | Added by the IRC/BackDoor.SdBot2.QV as detected by Avast AVG. TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ folder. Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) |
| User Mode Driver-Manager | X | wdfmgrr.exe | Added by the W32/Sdbot-ZN WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| User Profile Hive Cleanup (UPHClean) | L | uphclean.exe | uphclean.exe is a process belonging to Microsoft's User profile cleanup service. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems. |
| user32 | X | user32.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| Userinit Logon Verification (UsrInitVerif) | X | userinit.exe | Added by the W32/Tilebot-EV
WORM!
Located in the Windows or Winnt folder.
|
Users service for disk management requests (Logical Disk Manager Users Service) | X | chkdsk32.exe | Troj/Telemot-C
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (Vista/XP/WinNT/2K) |
| UStorage Server Service | L | UStorSrv.exe | Related to OTi Imation Disk Manager II |
| Utilità di pianificazione di LiveUpdate automatico | L | ALUSchedulerSvc.exe | Related to to the Symantec LiveUpdate service which updates your Symantec products periodically. |
| uxtbsu94 | X | uxtbsu94.sys | Troj/Agent-FYV
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) |
| uytghytrfdewz | X | mnso.exe | Troj/PWS-ANX
Note:Located in %Temp% |
| uytghytrfdewz | X | (random characters).sys | Troj/Lineag-AI
Note: Located in %Temp%
|