Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

Key:

  • L = Legit, O = Open to Debate, X = Malware/Bad
Startup Name Process Name Details
X FUS_Server (USEPigeonServer) FTPServer.exeAdded by the Troj/Hunpigon-RO TROJAN! Note: This trojan file is found in the System32 folder.
L FW Configuration Interpreter UmxCfg.exeTiny Firewall
L FW Event Manager UmxAgent.exeTiny Firewall
L FW Live Update umxlu.exeTiny Firewall
L FW Policy Manager UmxPol.exeTiny Firewall
L FW User to IP Address Translation umxuta.exeTiny Firewall
L FW User-Mode Helper (UmxFwHlp) UmxFwHlp.exeTiny Software Firewall User-Mode Helper. Made by Tiny Software Inc. A subsidiary of Computer_Associa
X fwnet64 (fwnet) fwnet64.exeAdded by Backdoor.SDBot.gen Note: This worm rojan is located in C:%WINDIR%
L FwSRService fwsrservice.exeCheckPoint SecuRemote
L GBPoll GBPoll.exeSeems to be Roxio GoBack related
X GCX Service GCXSRVC.EXEAdded by the RBOT.CUE WORM! Read the link rootkit type stealth involved.
L GEARSecurity GEARSEC.EXERelated to GEAR software.
L Gene6 FTP Server G6FTPSERVER.EXERelated to Gene6 Sarl. http://www.g6ftpserver.com/
X General Network Service winsocks32.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X generic host process (svchost) svchost.exeAdded by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Whic
Generic Host Process For Win32 Services (Generic Host
Generic Service for HID Keyboard Input Collections
L GFI LANguard System Integrity Monitor 3 agent service cfservice.exeGFI LANguard System Integrity Monitor is a utility that provides intrusion detection by checking whe
L GhostStartService GHOSTS~2.EXERelated to Norton. GHOSTSTARTSERVICE is the background support task/service for Ghost for Windows.
L Giga Pocket Hardware Detector shwserv.exeSony computers
X gldr gldr.exeTrojan Related
L Google Updater Service GoogleUpdaterService.exe(gusvc) - Google - commonly found in a location like this: C:\Program Files (x86)\Google\Common\Goog
L Google Updater Service (gusvc) GoogleUpdaterService.exeRelated to Google_Updater_Service Note: Located in C:Program FilesGoogleCommonGoogle Updater
L GoogleDesktopManager GoogleDesktopManager.exeRelated to Google_Desktop_Manager Note: Located in C:Program FilesGoogleGoogle Desktop Search
L GoToMyPC g2svc.exeRelated to Citrix Online
L GoverLAN Service (GOVsrv) GOVsrv.EXEOwner:PJ Technologies Inc. See_Here
X Gray (Pigeon) Scrsss.exeAdded by the Troj/GrayBrd-AM TROJAN! Note: This worm rojan file is found in the Windows or Winnt fol
X Gray_Pigeon (GrayPigeon) .exeAdded by the Troj/GrayBrd-EH TROJAN! Note: This worm rojan file is found in the Program Files folder
X Gray_Pigeon_Serve (GrayPigeonServer) G_Server.exeAdded by the Troj/Feutel-I or Troj/Feutel-AI TROJAN!
X Gray_Pigeon_Server (GrayPigeonServer) G_Server1.2.exeAdded by the Troj/GrayBrd-AP TROJAN! Note: This worm rojan file is found in the Windows or Winnt fol
X Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) G_Server2.0.exeAdded by the Troj/GrayBird-O TROJAN!
L GreenBorder Client Manager Service (clnt_ClientMan) ClientMan.exeRelated to GreenBorder Secure your browsing activities on the internet. Note: Located in C:Program F
L GridIron X-Factor After Effects Peer #1 (XFACTORAE1) xlr8d.exeRelated to GridIron Nucleo For digital post production professionals using Adobe® After Effects® on
O Groove Installer Service GrooveInstallerService.exe???
L GS30s GS30s.exeRelated to Gizmo!_Secure USB flash drive software by Crucial
X handle (handle) handle.exeAdded by the SDBOT.CDD WORM! Read the link rootkit type stealth involved.
X Handling the DHCP requests (DHCP Client) dhcpclient.exeMost likely a W32.Toxbot_variant
X Hardware Clock Driver (hwclock) hwclock.exeAdded by the W32/Hwbot-A WORM!
X Hardware Detection (Serv-U) svchost.exeReported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows proces
X Hardware Monitor Service (Hardware Monitor) mshms.exeAdded by the Troj/Wollf-A TROJAN!
L Hardware Monitoring Program (ADMService) admServ.exeRelated to Avocent Embedded Software and Solutions Division
L Harmony RSOBSERV.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
X haxdrv haxdrv.sysAdded by the Troj/Rootkit-U TROJAN! Read the link rootkit type stealth involved.
X hcalway hcalway.sysAdded by the PigSearch Adware. Read the link rootkit type stealth involved.
X hexadecimal (HexadecimaRepresentation) Edit.exeAdded by the W32/Sdbot-AAY WORM! Note: File name may be different. Read the link rootkit type stealt
L Hibernation hibserv.exeRelated to Compaq-Hewlett Packard hibernation service.
? HICOM LAN Bridge VCapiDrv (vcapidrv) vcapintsvc.exeCould be related to a new version of HICOM LAN Bridge?
X HID Output Service (HODSrv) hpsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Horario de Windows services.exeSpanish Windows 2000 windows time
X host (host) host.exeAdded by the Troj/GrayBrd-AR TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X host Service For Windows (mshost) mshost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Host Services (Host Services) myhost.exeAdded by the W32/Tilebot-AT WORM! Note: This worm rojan file is found in the Windows or Winnt folder
X Host Services (Host Services) svhosts.exeAdded by the W32/Tilebot-AC WORM! Note: This is not the legitimate Windows process svchost.exe (Noti
X Hotplug Devices Manager hotplug.exeAdded by the W32.Orpheus.A WORM!
L Houdini License Client (HoudiniServer) hserver.exeRelated to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:WINDOWSsystem32
L Houdini License Server (HoudiniLicenseServer) sesinetd.exeRelated to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:WINDOWSsystem32
L HP Configuration Interface Service HPConfig.exeHPConfig Module
L HP Hard Drive Thermal HDThermal.exeRelated to Hewlett-Packard company.
L HP OpenView Trace Service OVTrace.exeHP OpenView Internet Services
L HP Port Resolver hpbpro.exeRelated to Hewlett-Packard Company
L HP RF Device Service HpRfDev.exesupport for HP managing wireless devices
X hp service (Hpsys) hpsys.exeAdded by the W32/Codbot-AF WORM! Note: This service has nothing to do with HP. This worm rojan file
L HP Status hpb2ksrv.exeRelated to Hewlett-Packard Company
L HP Status Print hpbhksrv.exeRelated to Hewlett-Packard company.
L HP Status Server hpboid.exeRelated to Hewlett-Packard Company
L HP WMI Interface (hpqwmi) HPQWMI.exeRelated to Hewlett-Packard
? hpdj hpdj.exeMaybe HP related? Sits in TEMP folder.
X hpdriver hpdriver.sysAdded by the Troj/Rootkit-AA TROJAN! Note: This trojan file is found in the System32 folder. Read th
X HpPrinter hpserver.exeAdded by the Troj/CmjSpy-W Trojan!
L hpqwmiex hpqwmiex.exeRelated to HP_ProtectTools security manager
X HPR34K8 hpr34k8.sysAdded by the Troj/Rootkit-AA TROJAN! Read the link rootkit type stealth involved.
L HPWirelessMgr HPWirelessMgr.exeLocated in HP Notebook Utilities - guessing for wireless connection.
? huapeak huapeak.exeUnknown origin.
L Hummingbird Inetd (HCLInetd) inetd32.exeRelated to Hummingbird Ltd. - http://www.hummingbird.com/
L Hummingbird Jconfig Daemon (Jconfigd) jconfigdnt.exeRelated to Hummingbird Ltd. - http://www.hummingbird.com/
X HXD Service 100 (HackerDefender100) newka.exeVirus http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39265
X H_Server (H_Server) G_Server.exeAdded by the Troj/GrayBird-W TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X i386p I386P.SYSAdded by the Backdoor.Rustock TROJAN! Found in the System32drivers folder. Read the link rootkit typ
L IAA Event Monitor iaantmon.exeIntel related
L Iap Iap.exeRelated to Dell OpenManage Client Instrumentation.
L IBM Automatic Server Restart Executable (ibmasrex) ibmasrex.exeUnknown owner :Location C:WINDOWSsystem32ibmasrex.exe Related to IBM servers.
IBM CICS Transaction Gateway
L IBM CICS Universal Client (CICSClient) cclserv.exeRelated to IBM Corp.
L IBM Enterprise Extender (ldlcserv) ldlcserv.exeRelated to IBM Corp. - http://www.anti-spy.info/process/ldlcserv.exe.html
L IBM HDD APS Logging Service (TPHDEXLGSVC) TPHDEXLG.EXERelated to IBM's Active_Protection_System Made by the IBM_Corporation The file associated with this
L IBM KCU Service TpKmpSVC.exerelated to IBM ThinkPad
L IBM Mobility Client DHCP Control (artdhcp) artdhcp.exeRelated to IBM_Mobility_Client DHCP Control Note: Located in C:Program FilesIBMMobility Client
L IBM MQSeries amqsvc.exeIBM WebSphere® MQ to exchange information across different platforms
L IBM PM Service ibmpmsvc.exePower management driver for IBM laptops
L IBM PSA Access Driver Control PsaSrv.exerelated to Professional Services Automation (PSA) from SharpOWL
L IBM Rapid Restore Ultra Service rrpcsb.exerelated to Xpoint Technologies
L IBM Trace Facility (TrcBoot) trcboot.exeRelated to IBM Corp.
L IBM User Verification Manager uvmserv.exeRelated to IBM_User_Verification_Manager (UVM) secure logon interface. Note: located in C:Program Fi
IBM WebSphere Application Server V5 - server1
L ICONICS License Server (GenRegistrar) (GenRegistrar) GenRegistrarServer.exeRelated to ICONICS Inc. Visualization and Automation software products
X ICQ Update Service (ICQUPD) kpsf.sysDetected as Backdoor.HackDefender. Rootkit type stealth involved.
L ICRAplus ICRAplus.exeRelated to ICRAplus internet filter parental control etc. Note: Located in C:Program FilesICRAplusIC
X icrss manager 32bit (icrss) icrss.exeAdded by the W32/Rbot-FZB WORM! Note: Located in C:WINDOWSsystem
L icservice - ONTRACK Data International Inc. icserv.exeRelated to SuperAdBlocker
L iD2 Smart Card Server (id2scaps) id2scaps.exeiD2 is a client product that brings security user authentication and digital signatures to standard
X ieupdater (Microsoft IE Updater) ieupdate.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Document
X iexplorer (iexplorer) iexplorer.exeAdded by the Troj/Singu-U TROJAN! Note: This trojan file is found in the System32 folder
L IgniteService.exe IgniteService.exeRelated to Accenture_Media_Viewer
Image Converter video recording monitor for VAIO
X ImagePath (win32ssr) win32ssr.exeAdded by the W32/Sdbot-AMA WORM! Read the link rootkit type stealth involved.
L IMail FINGER Server (FINGRD32) FINGRD32.exeRelated to Ipswitch Inc. Network Management.
L IMail IMAP4 Server (IMAP4D32) IMAP4D32.exeRelated to Ipswitch Inc. Network Management.
L IMail LDAP Service (OpenLDAP-slapd) slapd.exeRelated to Ipswitch Inc. Network Management.
L IMail Monitor Service (IMONITOR) IMonitor.exeRelated to Ipswitch Inc. Network Management.
L IMail POP3 Server (POP3D32) POP3D32.exeRelated to Ipswitch Inc. Network Management.
L IMail PWD Server (PSERVE) PSERVE.exeRelated to Ipswitch Inc. Network Management.
L IMail Queue Manager Service (QUEUEMGR) queuemgr.exeRelated to Ipswitch Inc. Network Management.
L IMail SMTP Server (SMTPD32) smtpd32.exeRelated to Ipswitch Inc. Network Management.
L IMail Sys Logger Service (SYSLOGD) SYSLOGD.exeRelated to Ipswitch Inc. Network Management.
L IMail Web Calendar Service (IWEBCAL) IWebCal.exeRelated to Ipswitch Inc. Network Management.
L IMail Web Service (IWEBMSG) iwebmsg.exeRelated to Ipswitch Inc. Network Management.
L IMail WHOIS Server (WHOISD32) WHOISD32.exeRelated to Ipswitch Inc. Network Management.
L IMAPI CD-Burning COM Service ImapiRox.exeIMAPI CD-Burning COM Service
L IMountSRV IMountSRV.exeRelated to Paragon hard_disk_manager
L Inbound Distributor Service inbounddistributorservice.exeRelated to Inbound_Logistics
L InCD File System InCDsrv.exeInCD Packet Writer related.
L InCD Helper InCDsrv.exeInCD Packet Writer service from Nero Burning ROM (Ahead Software)
L Independent Management Architecture (IMAService) ImaSrv.exeRelated to Citrix MetaFrame
X Index Service (b3) dllhost32.exeAdded by the WORM_AGOBOT.CH WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X Indexing Helps (Indexingbox) svchest.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X Indexing The System Files (Indexing Service) winupdatez.exewinupdatez.exe
L Infrastructure) cm.exeRelated to Trend Micro Inc.
L Inicio de sesión red lsass.exeSpanish Windows 2000 net logon
X InstallDriver Service (ISDS) csscv.exeAdded by the W32/Sdbot-CPL WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%W
L InstallDriver Table Manager IDriverT.exeRelated to Macrovision Corporation.
L InstallShield Licensing Service InstallShield Licensing Service.exeRelated to InstallShield_Licensing_Service from Macrovision. Create high-quality software installati
L Instantáas de volumen vssvc.exeVolume Shadow Copy Service found in Windows XP and 2003.
L Instrumental de administracióe Windows WinMgmt.exeSpanish Windows 2000 windows management instrumentation
L Intel Alert Handler hndlrsvc.exeRelated to Intel Corp.
L Intel Alert Originator iao.exeRelated to Intel Corp.
L Intel CI Manager CiMgrLdr.exeRelated to Intel Corp.
L Intel Client Instrumentation for DMI (ni_nic) ni_nic.exeIntel Client Instrumentation for DMI
L Intel File Transfer xfr.exeRelated to Intel Corp.
L Intel IIDS IIDS.exeRelated to Intel Corp.
L Intel Local Scheduler Service LOCALSCH.EXEPart of LANDesk Management Suite.
L Intel NCS NetService (NetSvc) NetSvc.exeIntel NCS NetService
L Intel PDS pds.exeRelated to Intel Corp.
L Intel QIP Client Service QIPCLNT.EXEPart of LANDesk Management Suite.
L Intel SSM ssm.exeRelated to Intel Corp.
L Intel Targeted Multicast tmcsvc.exePart of LANDesk Management Suite.
L Intel(R) NMS NMSSvc.exeNIC Management Service - diagnostics program for Intel Pro family network cards
L Intel® Active Monitor (imonNT) imonnt.exehttp://www.liutilities.com/products/wintaskspro/processlibrary/imonnt/
L Intel® NMS NMSSvc.exeRelated to Intel Corp.
L Intel® Desktop Utilities Service (iHCService) IDUServ.exeRelated to Intel® Desktop_Utilities service from OSA Technologies. Inc. Note: Located in C:Program F
L Intel® Quick Resume Technology Drivers (ELService) ELService.exeRelated to Intel® _Quick_Resume_Technology Drivers. Note: Located in C:Program FilesIntelIntelDHInte
L Interbase Guardian ibguard.exeInterbase database server related
L InterBase InterClient Server interserver.exeInterbase database server related
L InterBase Server ibserver.exeInterbase database server
L Internet Connection Monitor Engine ICMNT.EXEUser reports that it's for a Home Router from Deerfield Communications www.deerfield.com/
X Internet Explorer (Internet Explorer) Internet.exeAdded by the Troj/Feutel-AA TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
L Internet Proxy InternetProxy.exeRelated to ICRAplus internet filter parental control etc. Note: Located in C:Program FilesICRAplusIC
X Internet Service Manager (INETSVC) INETSVC.EXEAdded by the Backdoor.Win32.SdBot.xd detected by Kaspersky More: Here Note: This worm rojan is locat
X Internet TCP Protocol (Win_ad) TCPServer.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsw
X internew (internew) system.exeAdded by the Troj/Cmjspy-BN TROJAN!
L InterPlot IMF Printer Driver Service pidrpcs.exeInterPlot device drivers - See Here InterPlot/Overview.htm
X Intespention (Win32) IEXPLORE.exeAdded by the W32/Forbot-FL WORM!
X Intranet Service (IntranetService) intranet.exeOwner:Brought to you by the Bandwidth Bandits. Location: C:WINDOWSSYSTEM32intranet.exe
L InVircible Scheduler (IVScheduler) IVSCHED.EXESecurity software package to protect personal computers and PC networks. Owner: NetZ Computing Ltd.
L iolo System Guard IoloSGCtrl.exeRelated to System_Mechanic by Iolo
L Iomega Active Disk ADService.exeRelated to Iomega Corporation
L Iomega Activity Disk2 ActivityDisk.exeActivityDisk Iomega Corporation SmartSoft ActivityDisk
L Iomega App Services AppServices.exeIomega related
L IomegaAccess IOMEGAACCESS.EXErelated to Iomega Backup
L ION Java Daemon 2.0 ion_srv.exeRelated to ITT_Visual_Information_Solutions ION Script is a powerful tool for creating Web-based IDL
L ION Java Daemon 6.1 ion_srv.exeRelated to ITT_Visual_Information_Solutions ION Script is a powerful tool for creating Web-based IDL
X Ip4Sec (Ip4Sec) ip.sysAdded by the Satiloler.E TROJAN! Read the link rootkit type stealth involved.
L iPassConnectEngine iPassConnectEngine.exeRelated to iPassConnect Universal Client. iPass addresses the needs of both users and IT by making s
L iPod Service iPodService.exeRelated to Apple iPod.
L iPodSrv iPodSrv.exeRelated to iPod Apple software. Note: located in C:Program FilesiPodin in Windows 2000/XP/2003.
X IPRIP (IPRIP) svchost.exe -k netsvcsAdded by the Backdoor.Ripgof TROJAN! Read the link rootkit type stealth involved.
L IPS Core Service (IPSSVC) IPSSVC.EXEA VPN client service found in Lenovo Thinkpad. Note: located in C:WINDOWSsystem32
L Ipswitch WS_FTP Queue (ftpqueue) ftpsched.exeRelated to Part of WS_FTP Pro from Ipswitch. Note: Located in C:Program FilesWS_FTP Pro
X IPtable ipconfig32.exeAdded by the W32/Tilebot-AP WORM! Note: This worm file is found in the Windows or Winnt folder.
X IPv6 Helper Driver csass.exeAdded by the AGOBOT.TC WORM!
L IrBridge User-Level Interface (USRBRIDG) usrbridg.exeRelated to the Extended Systems infrared port made by Extended_Systems Inc. This file should be loca
L ISAM SMT Service (ISAMsmt) isamsmt.exeRelated to IBM Global Services - http://www.anti-spy.info/process/isamsmt.exe.html
L iSeries Access for Windows Remote Command (Cwbrxd) CWBRXD.EXERelated to IBM Corporation. http://www.ibm.com/
X ISEXEng angelex.exeBargain Buddy variant
L ISSI EZUpdate (ISSIMon) issimsvc.exeRelated to Ibm_Global_Services Used internally by IBM for automatic updating of software and microso
L ISSvc ISSVC.exeRelated to Norton Internet Security
X Italian Grand Prix grand.exeAdded by the W32/Spybot-MK WORM! Note: C:%WINDIR%System32dllcache (XP/WinNT/2K)
X iTunes Music Service (iTunesMusic) iTunesMusic.exeAdded by W32.Spybot.NLX WORM! Rootkit Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32
L Ixia Endpoint (IxiaEndpoint) endpoint.exeAdded by Ixia_Endpoint Note: Located in C:PROGRA~1NetIQEndpoint
L Jaguar jagsrv.exeRelated to Sybase_EAServer Note: Located in C:SybaseEAServerin
X Java development Services windows.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Java development Services logins32.exeAdded by the W32/Tilebot-HC WORM! Note: This worm rojan is located in C:%WINDIR% folder. Steal infor
X Java inetice realetin.exeAdded by the Troj/Bckdr-PQM TROJAN! Note: This worm rojan is located in C:Program FilesCommon FilesM
X Java Sun Scheduler (JUSCHED) jusched.exeAdded by the W32/Sdbot-CQC WORM! Note: This worm rojan is located in C:%WINDIR% folder. More here
X JavaPlatform64 JavaPlatformAdded by the W32/Kassbot-M WORM! Note: Located in C:%WINDIR%
X JiurlPortHide (JiurlPortHide) JiurlPortHide.sysAdded by the Troj/Progent-A TROJAN!
L jsdaemon jsdaemon.exeRelated to fax service from JetFax Inc.
L Juniper Network Connect Service (dsNcService) dsNcService.exeRelated to Juniper Networks Inc. Networking Platform.
X K4NV k4nv.exeAdded by a variant of the Trojan.K4NV.Process WORM! Note: located in C:WINDOWSk4nv.exe