Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

Key:

  • L = Legit, O = Open to Debate, X = Malware/Bad
Startup Name Process Name Details
X Windows Network Security Service (lsass) lsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows Networking Agent (Windows Networking Agent) msuls.exeAdded by the Troj/Kwoo-A TROJAN! Note: This worm rojan file is found in the System32 folder.
X Windows NT winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows NT Logon Application (WINLOGON) winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L Windows NT Session Manager smss.exeMicrosoft Windows NT Session Manager
X Windows NT Session Manager (SMSS) smss.exeAdded by the Backdoor.IRCBot.rh as identified by ewido. Note: This worm rojan is located in C:%WINDI
X Windows NT Session Managers smss.exeAdded by the W32/Sdbot-CPN WORM! Note: This worm rojan is located in C:%WINDIR% Note: not to be conf
X Windows Object Manager smss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
X Windows Object Manager lsass.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
X Windows Object Manager winlogon.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
X Windows Object Manager csrss.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
X Windows Object Manager services.exeW32.Banish.A@mm - Symantec Description: Randomly copied characteristics of an already existing servi
X Windows Overlay Components (Random).exeReported as the Trojan-Dropper.Win32.Agent.tb TROJAN! by Kaspersky Anti-Virus. Note: This trojan fil
X Windows Packet Driver (packet) packet.exeAdded by the Troj/Hwbot-C TROJAN! Note: This trojan file is found in the System32 folder.
X Windows PE Debugger lviss.exeAdded by the W32/Sdbot-COT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
X Windows Process Moniter (Windows Process Moniter) winmon.exeAdded by the SDBOT.BYV WORM! Also drops winmon.sys which is a root kit. Note: This worm file is foun
X Windows Process Viewer (The Windows Process Viewer) winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows Product Activation (wpa) wpa.exeAdded by the W32.Esbot.B WORM!
X Windows Produre Call (MSRPC) msrpc.exeAdded by the W32/Sdbot-AEI WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
Windows Protected Content Restoration Service
X Windows Reg Service lsyss.exeAdded by the W32/Tilebot-HH WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X Windows Register Control register.exeAdded by the W32/Tilebot-GO WORM! Note: This worm rojan is located in C:%WINDIR%
X Windows Remote Manager lsiss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
Windows Remote Procedure Call Monitoring Service
X Windows RPC Services (winrpc) winrpc.exeAdded by the W32.Spybot.ACDM WORM! Note: This worm file is found in the Windows or Winnt folder.
X Windows Security Drivers (csrs) svchost.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
X Windows Security Drivers (csrs) csrss.exeAdded by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n
X Windows Security Manager vcmon.exeAdded by the W32/Tilebot-IC WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X Windows Security Update secupd.exehttp://www.sophos.com/virusinfo/analyses/trojsepucb.html
X Windows Server Management Service netsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows Service Manager (WSCM) service.exeAdded by the Backdoor.Agent.zb as reported by ewido suite. Note: located in C:WindowsSystem (Win9x/M
X Windows Services Configuration lsvss.exeAdded by the Backdoor.SdBot.aad as identified by ewido.WRM! More here
X Windows Smrss Service svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows Smrss Service (Windows Smrss Service) smrss.exeAdded by the W32/Tilebot-X WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
X Windows Smrss Service (Windows Smrss Service) cmdpipe.exeAdded by the W32/Tilebot-AE WORM! Note: This worm rojan file is found in the Windows or Winnt folder
Windows Socket 2.0 Non-IFS Service Provider Support
X Windows Socket System Service wksrvs.exeAdded by the Troj/IRCBot-RC WORM! Note: This worm rojan is located in C:WindowsSystemdllcache (Win9x
X Windows Spooler (winspool32) spool.exeAdded by the W32/Sdbot-ADP WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
X Windows Sql Service For Windows 32 Bi (WinSql) winsql32.exeAdded by the W32/Forbot-FC WORM!
X Windows Stability Route (WSR) construct.exeAdded by the SDBOT.COO WORM! Read the link rootkit type stealth involved.
X Windows System Controller System.exeAdded by the WORM_SDBOT.BLC WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X Windows System Host sychost32.exeAdded by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR% More here
Windows System Service Framework (WSSF) (Windows System
X Windows System Tray (WINTRAY) wintray.exeAdded by the W32/Tilebot-EH WORM! Note: This worm file is found in the Windows or Winnt folder.
X Windows System32 (mswin32) MSUPD~.EXEAdded by the SDBOT.CCX WORM! Read the link rootkit type stealth involved.
X Windows Task Manager vcmon.exeAdded by the W32/Tilebot-HS WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X Windows Task Manager Service (tskman) task.exeAdded by the W32/Tilebot-R WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
X Windows Task Scheduler (MSTASK) mstask.exeAdded by an unidentified TROJAN! of the Sdbot family. Do not delete the mstask.exe file unless it's
X Windows Taskbar Manager (wtaskbarmngr) taskbarmngr.exeAdded by the W32/Sdbot-XB or W32/Rbot-ZO WORM! Note: This worm file is found in the Windows or Winnt
X Windows TCP/IP Socket Driver (winsck) csrss.exeAdded by TROJ_RANKY.HW TROJAN! Note: This worm rojan is located in C:%WINDIR%winsock This is not the
X Windows Terminal Services vcmon.exeAdded by the Haxdoor.Fam HAXDOOR! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
X Windows Time Sync (wservtime) csrs.exeAdded by the W32/Tilebot-N WORM! Note: This is not the legitimate Windows Process csrss.exe. (Which
X Windows Time Sync (wservtime) csrss.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L Windows Tracks Washer Registry Service (WTWService) washservice.exeAdded by Internet_Tracks_Washer Note: This is a Internet tracks cleaning tool.
X Windows UDP Communication (wudpcom) wudpcom.exeAdded by the IRC-Mocbot TROJAN! Note: This trojan file is found in the System32 folder.
X Windows Updata Server Server.exeAdded by the Troj/Feutel-K TROJAN!
X Windows Update (Windows Update) winupdmon.exeAdded by the W32/Tilebot-AR WORM! Read the link rootkit type stealth involved.
X Windows Update 32 (Win32) slsys.exeAdded by the W32/Forbot-FT WORM! Note: This worm rojan file is found in the System32 folder.
X Windows Update 32 (Win32) winlogons.exeAdded by the W32/Forbot-FI WORM!
X Windows Update 63 (ntupd64) shupd64.exeAdded by the W32/Forbot-GA WORM! Note: This worm rojan file is found in the System32 folder.
X Windows Update Client (WUClient) upnphost.exeAdded by the W32.Janx WORM!
X Windows Update Client (WUClient) pnphost.exeAdded by the W32.Janx WORM!
X Windows Update Client (WUClient) winpnp.exeAdded by the W32.Janx WORM!
X Windows Update Manager (UpdateManager) updmgr.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%upda
X Windows Update Manager Tool (UpdateManagerTool) updmangr.exeAdded by the Troj/Ranck-EO TROJAN! Note: This worm rojan is located in C:%WINDIR%update
X Windows Update Service wuamgrd.exeW32.SpyBot worm variant
X Windows Update Service cdfs.exeAdded by the W32/Tilebot-HG WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X Windows Update Service pwnsvc.exeAdded by the W32/Sdbot-ZW WORM! Read the link rootkit type stealth involved.
Windows Update Service (Microsoft Windows Update
X Windows update Service (updater) wisvcc.exeAdded by the Troj/Orse-G TROJAN! Note: This trojan file is found in the System32 folder.
X Windows update Service (updater) winsvc.exeAdded by the SPYBOT-DB WORM!
X Windows Update Service (UpdateSvc) wuauclt.exeAdded by an unknown variant of a (backdoor raanky) TROJAN! Note: This worm rojan is located in C:%WI
X Windows Updater (Win32Export) win64tyt.exeAdded by the W32/Sdbot-CNH WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X Windows Updater (Windows Updater) inetinfo.exeAdded by the Troj/Sdbot-AMX TROJAN! Read the link rootkit type stealth involved.
X Windows Updater (Windows Updater) msnlive.exeAdded by the W32/Tilebot-CN WORM! Read the link rootkit type stealth involved.
X Windows Updates (Windows Updates) Windowsupdates.exeAdded by the SDBOT.CLU WORM! Read the link rootkit type stealth involved.
X Windows UPnP Service (wupnp) wupnp.exeAdded by the W32.Esbot.D WORM! Note: This worm file is found in the System32 folder.
L Windows User Mode Driver Framework wdfmgr.exeRelated to Microsoft Windows media player 10 and above. http://www.liutilities.com/products/wintasks
X Windows VisFx Components (Random)Added by the Win32.Agent.mu Worm!
X Windows Vista/NT Runtime Compatibility Service (ntrcs) nrcs.exeAdded by the Backdoor.Ranky.X Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WIND
X Windows web messenger Msmgs.exeAdded by the W32/Sdbot-BSL WORM! Note: This worm rojan is located in C:%WINDIR% folder.
Windows Windows Sheduler (Microsoft Windows Scheduled
Windows Workstation Service (Windows Workstation
X Windows Workstation Services windows.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Windows XP Advanced User Launcher WINLOGON.EXEAdded by the SDBOT.CPV WORM! Note: This is not the legitimate Windows process WINLOGON.EXE (Which is
L Windows XP FUS Manager DPFUSMgr.exeRelated to DigitalPersona Inc.
Windows XP Service Pack 2 Services (Windows XP Service
X windows32 windows32.exeAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm rojan is located in
X WindowsF (FRundlll) FRundlll.exeAdded by the Troj/GrayBird-Y TROJAN! Note: This trojan file is found in the System32 folder.
X windowsnetwork (windowsnetwork) winkernel32.exeAdded by the W32/Tilebot-BM WORM! Note: This worm file is found in the Windows or Winnt folder. Read
X WindowsNod (WinNod) winnod.exeAdded by the W32/Tilebot-CG WORM! Read the link rootkit type stealth involved.
X WindowsSecurityManager winsm.exeAdded by the W32.Antinny.AX WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP)
X WindowsService (WINSERVICE) service.exeAdded by the W32/Tilebot-K WORM! Note: This is not the legitimate Windows Process. (Which is found i
X WindowsSysBoo mvsql.exeAdded by the W32/Tilebot-AN WORM! Note: Located in C:%WINDIR% Disables the automatic startup of othe
X WindowsSysBoot (WindowsSysBoot) winsys.exeAdded by the W32/Rbot-ARJ WORM! Note: This worm file is found in the Windows or Winnt folder.
X WindowsSysBoot (WindowsSysBoot) winsysnet.exeAdded by the W32/Tilebot-AF WORM! Note: This worm rojan file is found in the Windows or Winnt folder
X WindowsVideo (WindowsVideo) waudio.exeAdded by the Troj/Dupa-B TROJAN! Note: This worm rojan file is found in the Windows or Winnt folder.
X Windws Backup XPBackup.exeDetected by Ewido as Backdoor.SdBot.xd. This worm file is found in the Windows or Winnt folder.
L WinEncrypt service (wencrservice) wentxp.exeCryptArchiver file folder and drive encryption software for Windows.
L WinFax PRO WFXSVC.EXESymantec Corporation
X winfws (winfws) winfws.exeAdded by the W32/Sdbot-ABA WORM! Read the link rootkit type stealth involved.
X Winlogin messenger winlogin.exeAdded by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system
X winlogo (winlogo) IEXPLORE.EXEAdded by the Troj/Singu-X TROJAN! Note: This worm rojan file is found in the System32 (NT/2000/XP) f
X Winlogon Notify: drct16 drct16.dllBelonging to Haxdoor??
X WinMan (winmngr) winmngr.exeAdded by the W32/Protoride-N WORM!
X WinMedia (WinMedia) msmedia32.exeAdded by the W32/Tilebot-BI WORM! Note: This worm file is found in the Windows or Winnt folder.
L Winpower Winpower.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
L Winpowermanager manager.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
L Winpowermonitor monitor.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
L WinpowerRMI wpRMI.exeRelated to InstallAnywhere ZeroG Software is now owned by Macrovision. Note: located in C:Program Fi
L WinPPPoverEthernet WrOS.EXERelated to Verizon OnLine ISP and iVasion a Routerware Company
L WinProxy WinProxy.exeWinProxy proxy server
X WinPwdReset WinPwdHelper.exeAdded by the Trojan.RBot TROJAN!
X WinRep (WinRep) WinRep.exeAdded by the W32/Rbot-AFW WORM! Read the link rootkit type stealth involved.
X WINS Client (RpcPatch) dllhost.exeAdded by the W32.Welchia WORM! **Note - This service will be set to start automatically
X Wins Update 32 (Win32) services32.exeAdded by the W32/Forbot-FN WORM! Note: This worm file is found in the System32 folder.
X wins(WINS) (wins) winscntrl.exeAdded by the W32/Tilebot-FT WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X WinSec32 (~~~~) dhcp.sysAdded by the Troj/Rawdoor-A TROJAN! Note: This trojan file is found in the System32 folder.
X winsock32 (winsock32.exe) winsock32.exeAdded by the W32/Rbot-FMX WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X winspd32dll (winspd32.exe) winspd32.exeAgobot Variant
L WinSSHD winsshd.exeBitvise's SSH Server
L WinTab Service WtSrv.exeWindows tablet service driver
L Wintab32 Wintab32.exeWintab Digitizer Services 32-bit Server App. This file is installed with the driver for the AceCAD d
X WinTools for IE service WToolsS.exeRelated to Adware.Huntbar. Advertising program
X wintroters (wintroters) wintroters.exeAdded by the Troj/GrayBrd-AJ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X winupd winupd.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Win_Pigeon_Server (Win_Pigeon_Server) Win_Server.exeAdded by the Troj/Feutel-N TROJAN!
X Wireless Connection Configuration (wificonf) mscarrt32.exeAdded by the W32/Oscabot-K WORM!
X WksPatch Svchost.exeAdded by the W32.Welchia.B or W32.Welchia.C or W32.Welchia.D or W32.Welchia.K WORM! **Note - Service
X wkssvc (Windows Kernel Serivce) wkssvc.exeAdded by the W32/Sdbot-AOR WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X wkssvc (Windows Kernel Serivce) AIMClient.exeAdded by the W32/Tilebot-DP WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X Wlan1934 (Wlan1934) wlan1934.sysAdded by the Troj/Dloader-TB TROJAN!
L WLANKEEPER WLKeeper.exeRelated to Intel Corporation
X wlmsngr wlmsngr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windows
L WLTRYSVC wltrysvc.exeltrysvc.exe is a process belonging to the Broadcom Corporation Wireless Network Tray Applet which in
L WLTRYSVC bcmwltry.exeRelated to wireless networking in Dell computers
X WmDmPsp sysdtc32.exeAdded by the Ircbot_Gen Worm! Note: SYSDTC32.EXE may use 13 or more path and file names read the lin
X WMFhotfix912840 (Microsoft Windows WMF hotfix 192840) enu-hotfix912840.exeAdded by the WORM_OPANKI.CG Note: This worm rojan is located in C:%WINDIR% folder. &VName=WORM_OPANK
L WMI Performance Adapter (WmiApSrv) wmiapsrv.exeRelated to Microsoft_WMI performance adapter which collects information regarding performance. Note:
X wmp wmp.exe and wmp.cfgSee Viruslist Owner unknown : C:Program FilesWindows Media Player
? wnjfuo
L Wonderware NetDDE Helper (WWNetDDE) wwnetdde.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
L Wonderware SuiteLink (slssvc) slssvc.exeRelated to ArchestrA Software architecture for the integration of your automation systems.
X wordpad (wordpad) wordpad.exeAdded by the W32.Spybot.WON WORM! Note: This is not the legitimate Windows application Wordpad.exe.
X Work Station Development (NTDEV) ntdev.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X Working Network Connections hicom.exeTrojan-Proxy.Win32.Agent.cx
X Working Network Connections (TY164) hicom.exeAdded by the Troj/Chimo-F TROJAN!
X Workstation (MSDCSRV32) mssrv.exeAdded by the PWSteal.Drorar TROJAN! Note: This trojan file is found in the Program FilesCommon Files
L Workstation Manager (ZFDWM) wm.exeRelated to Novell_Workstation_Manager From Novell Inc. Note: Located in C:Program FilesNovellENwork
X Workstation NetLogon Service randomCoolWebSearch malware
X Workstation NetLogon Service ( 11Fßä #•ºÄÖ`I) (Random).exeCoolWebSearch malware.
X Workstation NetLogon Service (11Fßä #•ºÄÖ`I) (Random)32.exeCoolWebSearch malware.
X Workstation NetLogon Service(11Fß#·ºÄ`I) crzw32.exeCoolWebSearch HiJacker Service R1=res:xxxx.dll/sp.html
X Workstation Service Library (Microsoft Locator Service) wkssvc.exeAdded by the W32/Sdbot-ABE WORM! Read the link rootkit type stealth involved.
X WPA svchosts.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L WPS Scanner Service (WPSScannerSvc) WPSScannerSvc.exeRelated to Skyhook_Wireless Wi-Fi positionning system. Note: Located in C:Program FilesSkyhook Wirel
X WRM CPU drive (wrmdrv) WRMDRV.SYSAdded by the GOLDUN.B WORM!
X WS2IFSL (Unknown)Added by the Trojan.Riler.E TROJAN!
X wsmv(wsmv) (wsmv) wmsv.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X wto (wto) G_Server2.0.exeAdded by the Troj/GrayBrd-BN TROJAN!
X wuam WUAMPR.EXEAdded by the SDBOT.CKP WORM! It also drops the file X5.SYS detected by Trend Micro as TROJ_ROOTKIT.S
L WUOLservice (WUOLService) WUOLService.exeRelated to Novel Inc.
L WUSB54Gv2SVC WLService.exeRelated to Linksys Wireless-G USB Wireless Network Monitor
X Wut Nigga syswork.exeW32/Forbot-FZ will add this the display name is: Working System Analyzer
L WZCBDL Service WZCBDLS.exeFile associated with D-link software
L X10 Device Network Service (x10nets) x10nets.exeX10 video streaming devices. This program is non-essential process to the running of the system but
X X5 X5.SYSAdded by the TROJ_ROOTKIT.S TROJAN! Read the link rootkit type stealth involved.
X xadz randomRelated to Backdoor.Exdis
X XCP CD Proxy (CD_Proxy) CDProxyServ.exeThis is the Sony-BMG ROOTKIT! Do not try to manually remove this! For more information check Mark Ru
L xElevate Service xElevate_a4c3.exeThe Boeing Company (internal use)
L xElevate Service xElevate_a4c3.exeFor Internal Use - The Boeing Company
X XP Backup (Smart XP) smtxp.exeAdded by a variant of Backdoor.Win32.SdBot.aad TROJAN! Note: This worm rojan is located in C:Windows
L Xpoint Admin Server (XPadminServer) xpadmin.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:Program Filesxpointxpadmin fold
L Xpoint Agent Server (xpAgentServer) Xpagent.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:PROGRA~1xpointagent folder.
L Xpoint PCRadmin Server (PCRadminServer) pcradmin.exePart of the IBM/XPoint Rapid Restore utility. File is found in the C:Program FilesXpointPE folder.
X xprtect (xprtect) xprtect.sysAdded by Adware-DigitalNames
L XtreamLok License Manager xl.exeRelated to XtreamLok prevents software being reverse engineered. Note: Located in C:%WINDIR%System32
X XXXCodec Service (XXXCodec Acceleration Service) casrv.exeAdded by Trojan-Downloader.Win32.Small.czh Identified by Kaspersky. TROJAN! Undesirable service as i
X Yahoo Updater (Updater) Messenger.exeAdded by the W32/Forbot-FU WORM! Note: This worm rojan file is found in the System32 (NT/2000/XP) fo
X yak tw (yak tw) yak_tw.exeAdded by the Backdoor.Graybird.M TROJAN!
L YATS32 Service (YATS32) yats32.exerelated to YATS32 Time Synchronization applications for desktop or corporate LANs.
L YEDIEx YEDIEx.exeRelated to Y-E_Data ExpressCard Reader
X Yndbybmh Yndbybmh.sysAdded by the Backdoor.Darkmoon.B TROJAN! Note: This trojan file is found in the System32drivers fold
L YPCService YPCSER~1.EXERelated to Yahoo
X yvlymxmnibna yvly.exeMalware service presumably random filename is service name reversed
X yvlymxmnibna - Unknown owner - mxmnibnayvly.exeMalware servicepresumably randomfilename is service name reversed
X Ywvpysxl (Ywvpysxl) Ywvpysxl.sysAdded by the Troj/Psupda-A TROJAN!
X YY_Serer (YY_Sererwin) YY_Serer.exeAdded by the Troj/GrayBird-S TROJAN!
X ZESOFT zeta.exeRelated to BargainBuddy/BullsEye variant. Also appears often with VX2
X ZESOFT zeta.exeSeems to be a BargainBuddy/BullsEye variant. Also appears often with VX2...
L ZipToA ZipToA.exeRelated to Iomega Backup
L ZipToA ZipToA.exerelated to Iomega Backup
X zonealarm (iexplorer) Removeme.EXEAdded by the W32/Forbot-BG WORM!
X Zykheptd Zykheptd.dllAdded by the Backdoor.Hesive.B TROJAN! Read the link rootkit type stealth involved.
X zzzxIPSPEC zzzxt2llso.exe
X zzzxIPSPEC_1 (zzzxIPSPEC_1) zzzx[random characters].exeAdded by the Netdepix.B TROJAN!