Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

Key:

  • L = Legit, O = Open to Debate, X = Malware/Bad
Startup Name Process Name Details
L PestPatrol Remote ppRemoteService.exeRelated to PestPatrol products from Computer Associates International Inc.
X PEX pex.sysAdded by the Troj/RKFu-A TROJAN! Read the link rootkit type stealth involved.
L PGPsdkService PGPsdkServ.exePGP Software
L PGPserv PGPserv.exeRelated PGP Corp. http://www.pgp.com/
L PHAROS Distribution Agent (PSDistributionAgent) DistAgnt.exeRelated to Pharos_Science_ & Applications Inc. Pharos develops advanced GPS navigation and mobile lo
L Pharos Systems ComTaskMaster CTskMstr.exeRelated to Pharos_Systems print asset management. Note: Located in C:PROGRAM FILESPharosin
L Phoenix VCD Service (PhnxVCDService) PhnxCDSvr.exeRelated to Phoenix_Technologies
L Photoshop Elements Device Connect PhotoshopElementsDeviceConnect.exeRelated to Adobe photoshop.
L PI Message Subsystem (pimsgss) pimsgss.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
L PI Network Manager (pinetmgr) pinetmgr.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
L PI-Buffer Server (bufserv) bufserv.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
L PictureTaker PCTKRNT.SYSLANovation's PictureTaker Enterprise Edition 3.1 lets administrators create software update packages
X Pigeon (PigeonServer) GServer2.exeAdded by the Troj/GrayBrd-AK TROJAN! Note: This worm rojan file is found in the System (95/98/ME) or
X Pigeon_Server (PigeonServer) Server.exeAdded by the Backdoor.Graybird.R TROJAN! Note: This trojan file is found in the Windows or Winnt fol
Pinnacle Systems Media Service
L Pinnacle Systems tvtv Spooler (EpgSpooler) epgspo~2.exeRelated to Pinnacle Studio Plus.
L PIPC Log Server (pilogsrv) pilogsrv.exeRelated to OSI_Software Real-time Performance Management (RtPM) Platform. Note: located in C:Program
L Pixar Alfred Server 11.5.3 alfserver.exeRelated to Pixar_Alfred_Server Server includes all the tools required for rendering images for film
X PixelModule (pxlmdl) nvidcgui.exeAdded by the W32/Tilebot-GS WORM! Read the link rootkit type stealth involved.
L PLFlash DeviceIoControl Service IoctlSvc.exeRelated to PLFlash_DeviceIoControl Service from Prolific Technology Inc. Note: located in C:WindowsS
O PLSRemote Service (PLSRemoteSvc) PLSRemote.exeRISKWARE! or potentially unwanted application. This application may have been installed by your syst
L Plug and Play services.exeSpanish Windows 2000 Plug and Play
X Plug and Play Device Manager ($sys$DRMServer) $sys$DRMServer.exeThis is the Sony-BMG ROOTKIT! Do not try to manually remove this! For more information check Mark Ru
X plugin PLUGIN.EXEAdded by the SDBOT.BUH WORM! Read the link rootkit type stealth involved.
L pml
L pml
L Pml Driver HPHipm09.exeRelated to HP printers
L Pml Driver HPH11 HPHipm11.exeHP PML Driver for HP.s Photosmart printers.
L Pml Driver HPZ12 HPZipm12.exeRelated to HP printers.
L pmldriver hpz12
L PMounter PMounter.exePartition Mounter task installed with the Paragon Hard Disk Manager software. (answers that work)
L PMSveH PMSveH.exeRelated to Lenovo part or IBM ThinkVantage Note: Located in C:WINDOWSsystem32
X pnpext wmc.exeAdded by the Troj/LeechPie-D TROJAN! Note: The file wmc.exe is a legitimate remote administration to
X Policy Agent svchost.exe -k Policy AgentAdded by the Fuwudoor TROJAN!
L Pop-Up Stopper Anti-Spyware Service (PWISVC) PWISVC.EXERelated to Pop-Up_Stopper_Anti-Spyware from Panicware. Note: Located in C:Program FilesPanicwarePop-
L Port Reporter portreporter.exePort Reporter is a Microsft made utility information available dtsrvc.exeRelated to MagicTune by SAMSUNG.
L PostgreSQL Database Server 8.0 (pgsql-8.0) pg_ctl.exeRelated to PostgreSQL open source database.
X Power Manager (PowerManager) svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L PowerAlert UPS Engine paserver.exeRelated to IBM Power Management utililty.
L PowerPanel Personal Edition Service (ppped) ppped.exeRelated to CyberPower dependable line of uninterruptible power supplies. Note: Located in C:Program
L PowerUtility TV Recording Reservation (PUSCSRVC) PUSCSRVCBas.exeRelated to FUJITSU LIMITED
L PPPoE Service pppoeservice.exeRelated to the Internet Provider High Speed Services (ISP)
L PreEmpt (qfcoresvc) loadsvc.exeRelated to preEmpt Active System Hardening. Made by PivX Solutions Inc. This file should be found in
L Prevx Agent (PREVXAgent) PXAgent.exeRelated to Prevx Ltd. Antivirus and software protection.
L Prime95 Service PRIME95.EXEHelp Universities to find Prime_Numbers The user should decide it's participation.
X Print Spool Handler (Print Spooler) spooler.exeAdded by the W32/Codbot-X WORM! Note: This worm file is found in the System32 folder.
L Print Spooler (Spooler) spoolsv.exeUsed for Fax and Printing. Unknown owner :Location: C:WINDOWSsystem32spoolsv.exe
X Print Spooler Manager (prntspman) spoolsvr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X Print Spooler Service (SpoolSvc201) sklrr7yvxzac.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Print Spooler Service (SpoolSvc203) cjnr4r4ngyrk.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Print Spooler Service (SpoolSvc204) nlkfev7exne.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Print Spooler Service (SpoolSvc205) mlsdf8h8183934.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Print Spooler Service (SpoolSvc206) mlsdf8hiloswaejo.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Print Spooler Service (SpoolSvc207) sklrr7y7497903.exeAdded by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in Note
X Printer Spooler (printspool) spooler32.exeAdded by the W32/Sharp-L WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
L PrismXL PRISMXL.SYSLanovation Prism Deploy package http://www.lanovation.com/
L PrismXL PRISMXL.SYSThe PrismXL service lets the Client deploy Tasks on a target computer regardless of the current user
L PrivacyView Service (PVService) PVService.exeRelated to Privacy_View software encrypts files folders and Internet files. File is normally located
L Private Folder Service (prfldsvc) PrfldSvc.exePrivate Folder 1.0 was released by Microsoft on the 6th July but Microsoft officially withdrew its s
L Privilege Win32 Server PLServ.exeRelated to Aladdin Knowledge Systems. Located in the Windows or WinntSystem32 folder.
X Procedure Distribution Service prsvr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Process Activity Monitor (paamsrv) paamsrv.exeActivity Monitor belonging to the Privacy Expert Suite Software from Acronis.
X Process) svchost.exeAdded by the W32/Tilebot-DM WORM! Note: This worm rojan is located in C:%WINDIR% folder.Note: This i
X ProcessEnumerator32 (pe32) fi49.exeAdded by the W32/Sdbot-ACN WORM! Read the link rootkit type stealth involved.
L ProductivIT Service TEKS_Service.exeRelated to DynTeck Inc.
X Professional) server.exeAdded by the Troj/Singu-W TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X Professional) QQ.exeAdded by the Troj/BlackHol-C TROJAN!
L Proficy HMI/SCADA iFIX server (FIX) fixsrv.exeRelated to Related to GE_Fanuc_Automation enable you to act in real-time to optimize productivity an
L Proficy Licensing (CCFLIC0) CCFLIC0.exeRelated to GE_Fanuc_Automation enable you to act in real-time to optimize productivity and increase
L Programador de tareas MSTask.exeSpanish Windows 2000 task scheduler
L ProgramCheckerPro (sassvc) sassvc.exeRelated to ProgramChecker Tool to analyze validate authenticate and research the programs that run o
L Prolific HotFix Q0306270 HotFixQ0306270.exeHotFix Q0306270 Prolific Technology Inc. USB Flash Disk
L Promise Array Message Server (RAIDmSvr) MsgSvr.exeRelated Promise Technology Inc. RAID Message Server
L Promise FastTrak Log Service (FastTrakSvc) FtrakSvc.exeReported as a RAID driver program by Promise_Technology_Inc
X Protected Exchange (MainService) loadsvc.exeAdded by the Troj/Urbin-C TROJAN!
X ProtectedStorage svchost.exe -k ProtectedStorageAdded by the Fuwudoor TROJAN!
L Protector Plus Anti-virus Monitor Service PPAVMon.exeRelated to Proland Software. - http://www.pspl.com/
L Protector Plus Service PPServ.exeRelated to Proland Software. - http://www.pspl.com/
L Protector Suite Virtual Token vtserver.exeRelated to UPEK biometric protector suite
L Proveedor de asistencia de seguridad LM de Windows NT lsass.exeSpanish Windows 2000 NT LM security support provider
L Provides three management service (FreeBSD) dev32.exeFreeBSD is an advanced operating system for x86 compatible. It is derived from BSD the version of UN
L ProxyServer Service (ProxyServerService) rtpxsr.exeRelated to IBM Rational Software Development Platform
PRTG 4 Service - Paessler Router Traffic Grapher
L ptssvc - KODAK ptssvc.exeinstalled alongside the drivers for Kodak's range of digital cameras
L Pure Networks Net2Go Service (nmraapache) nmraapache.exeRelated to Pure_Networks_Net2Go Service from Pure Networks Inc. Note: Located in C:Program FilesPure
L Pure Networks Network Magic Service (nmservice) nmsrvc.exeRelated to Network_Magic home network managing program. Made by Pure Networks Inc.
L Pure Networks Router Manager (pnrouter) pnroutsv.exeRelated to Network_Magic home network managing program. Made by Pure Networks Inc.
L PurgeIE XP Service (PurgeIEservice) PurgeIE_Service.exeRelated to Assistance_&_Resources for Computing Inc. PurgeFox is a utility program specifically desi
L PurgPro XP Service PurgPro_Service.exePurgeIE service
L Qbik WinGate Engine WinGate.exeWinGate is a proxy/firewall solution
L QBReminderFlash QBReminder.exeRelated to Intuit_QuickBooks application.
L QCONSVC QCONSVC.exe IBM Access Connection Manager. Runs as a service. If you don't use the program change the service t
X QoS RSVP accdes service (Qor) ftplanServer.exeAdded by the Troj/Feutel-U TROJAN!
X qtask (qtask.exe) qtask.exeAdded by the SDBOT.CQX WORM! Read the link rootkit type stealth involved.
L Quick Heal Helper Service WSC (qhwscsvc) qhwscsvc.exeQuick_Heal Next Generation anti-virus protection for your PC.
L Quick Heal Helper Service WSC (ScanWscS) scanwscs.exeRelated to AntiVirus_Quick Heal Virus protection. Note: located in C:Program FilesQUICKH~1
L Quick Heal Online Protection QHONSVC.EXEQuick_Heal Next Generation anti-virus protection for your PC.
QuickBooks Online Backup Launcher (QuickBooks Online
L QuickBooks Online Backup RegCap (OLRegCap) OLRegCap.EXERelated to Intuit Inc. QuickBook - http://www.intuit.com/
L QuickBooksDB QBDBMgrN.exeRelated to QuickBooks_Database from Intuit Inc. Note: Located in C:Program FilesIntuitQUICKB~1
L Qwik-Fix (qfcoresvc) qfloadsvc.exeRelated to preEmpt Active System Hardening. Made by PivX Solutions Inc. This file should be found in
L R2d2 Kernel Authority KAuthS.exeRelated to R2D2 Software a Windows service that manages desktops and programs. Without it no desktop
X RA Server Slave.exeBackdoor.RA virus http://www.avp.ch/avpve/trojan/backdoor/ra.stm Better alternatives are PC Anywhere
L RA Server (Slave) Slave.exeRelated to RA_Server from TWD Industries. allows remote desktop administration over a TCP/IP network
L Rabo Comm Server RaboCommSrv.exeRelated to the Rabobank telebanking (Netherlands)
L Radan Licence Server radlicence2.exeRadan Sheet Metal CADCAM Software
L RadClock RadClock.exeATI/Radeon Video Card Setting Tweaking Utility
L Radialpoint Service fws.exeRelated to RadialPoint
L RadioSvr RadioSvr.exeHP support for managing wireless devices
X raid (raid) raid.sysAdded by the Troj/NtRootK-O TROJAN! Read the link rootkit type stealth involved.
L RapApp rapapp.exeBlack Ice Firewall related
X RasAt (Remote Connection) svchost.exeAdded by the Troj/Singu-AF TROJAN!
L Rational ClearQuest Mail Service mailservice.exeRelated to IBM_Rational_ClearQuest
L Rational Cred Manager (cccredmgr) cccredmgr.exeRelated to IBM_Rational_ClearCase
L Rational Lock Manager (LockMgr) lockmgr.exeRelated to IBM_Rational_ClearCase
L Rational Test Agent Service rtpsvc.exeRelated to IBM_Rational_Software Development Platform
L RaySat_3dsmax8 Server (mi-raysat_3dsmax8) raysat_3dsmax8server.exeRelated to Autodesk® _3ds_Max
L RdnaoFlSvc naofsvc.exeRelated to Naomi an advanced internet filtering program.
X rdriv (rdriv) rdriv.sysAdded by the Troj/Rootkit-W TROJAN! Read the link rootkit type stealth involved.
X Realplus (Realplus) sserver.exeAdded by the Troj/Paltus-A TROJAN! Note: This trojan file is found in the System32 folder.
L Reflection Line Printer Daemon lpdserv.exeRelated to http://www.wrq.com/
L Reflection Servers rninetd.exeRelated to http://www.wrq.com/
L Reflection TimeSync rtsserv.exeRelated to WRQ Inc. http://www.wrq.com/products/reflection/
L regdefend regdefend.sysSee Ghostsecurity Location: C:Program FilesRegDefend egdefend.sys
X Regedits Helps (Windows Regedit Helps) iesetup.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windowsi
L Registro de sucesos services.exeSpanish Windows 2000 event logger
L Registros y alertas de rendimiento smlogsvc.exeSpanish Windows 2000 performance logs and alerts
X Registry Editor (Regedit) regedit.exeAdded by the W32/Codbot-U TROJAN! Note: This is not the regedit application that comes with Windows.
L Registry Management Service (RegManServ) RegManServ.exeRelated to Complete_PC_Care from WinCleaner. Note: Located in C:Program FilesAdvanced Registry Docto
X Registry Manager Service (MS Registry Service) MSRMS32.exeAdded by the W32/Rbot-AKP WORM!
L RegService RegService.exeRelated to Intel Corp. http://www.intel.com/network/connectivity/trans/xircom.htm
L RegSrvc RegSrvc.exeIntel PROset
X regstrmon regstrmon.exeAddeD by the WORM_RBOT.ADA WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X remon (remon) remon.sysAdded by the Troj/RKFu-A TROJAN! Read the link rootkit type stealth involved.
L Remote Access Controller 4 (RAC) (racsvc) racsvc.exeRelated to Dell Open Manage NT Utilities program that allows remote access and control of a computer
L Remote Administrator Service r_server.exepart of a remote administrator application that allows a user to work on one or more remote computer
X Remote Administrator Service (r_server) r_server.exeAdded by the Troj/Remadm-J TROJAN! Note: This trojan file is found in Program Files ealRealOne Playe
X Remote Administrator Service (r_server) systemram.exeAdded by the Troj/Radnag-B Trojan!
X Remote Debug Services smsc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
O Remote HID Service lvhidsvc.exeRemote access service by Philips Inc. Legitimate but remote access could be considered dangerous unl
L Remote management (Novell WUser Agent) wuser32.exeRelated to Novel Inc.
X Remote Map Manager lssc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X Remote Media Player lsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Remote Packet Capture Protocol v.0 (experimental) rpcapd.exeRelated to Winpcap (Windows Packet Capture Library)
X Remote Procedure Call (RPC) Client (RpcClient) rpcclient.exeAdded by the W32/Codbot-L WORM!
X Remote Procedure Call (RPC) Helper randomCoolWebSearch malware
X Remote Procedure Call (RPC) Locator (Locator) rpclocator.exeAdded by the W32/Codbot-Q WORM!
X Remote Procedure Call (RPC) Monitoring (Rpcmon) Rpcmon.exeAdded by the W32/Codbot-T WORM!
L Remote Procedure Call (RPC) Net (Rpcnet) Rpcnet.exeRelated to Laptop_Retriever
X Remote Procedure Call (RPC) Relocator (RpcRelocator) relocater.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X Remote Procedure Call (RPC) Remote (RpcRemotes) remote.exeAdded by the W32/Mytob-EW WORM! or Troj/Agent-FB TROJAN! Note: This worm rojan file is found in the
X Remote Procedure Call (RPC) Service (RpcSssvc) RpcSs.exeAdded by the W32/Cuebot-J WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
X Remote Procedure Call System(RPCS) (RpcSe) Rpcse.exeAdded by the Troj/Mdrop-BMK TROJAN! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (
X Remote Reader Machine ssmc.exeAdded by the Backdoor.SdBot.avk as detected by ewido. More here
L Remote Record Service (RemoteRecord) remoterecordclient.exeRelated to MSN_TV Note: Located in c:program filesmicrosoft corporationmsn remote record service
X Remote Services Manager (RSMSS) (Trojan file name)Added by the Troj/Bckdr-BBK TROJAN!
L Remote Solver for COSMOSFloWorks 2006 StandAloneSlv.exeRelated to COSMOS_FloWorks From COSMOS. CAD program. Note: Located in C:Program FilesSolidWorksCOSMO
L Remote Task Manager service (RTM) RTMService.exeRelated to Remote_Task_Manager remote control suite. Note: Located in C:Program FilesRemote Task Man
X Remote TCP Services vcmon.exeAdded by the W32/Tilebot-HX WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%
X Remote Terminal (RemoteTerminal) mscp.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%
X Remote Windows Services vcmon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Remotely Possible/32 (RP32Service) rp32serv.exeRelated to Avalan now owned by Computer Associates International Inc. http://ca.com/products/
L RemotelyAnywhere RemotelyAnywhere.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program FilesRemo
L RemotelyAnywhere Maintenance Service (RAMaint) RaMaint.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program FilesRemo
X RemoteRegBck regsvc.exeAdded by Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: located in C:WINDOWS. No
X Removale Sorage (RemovaleSorage) G_Server.exeAdded by the Troj/Feutel-AT TROJAN! Note: This trojan file is found in the System32 folder.
X Required Service Drivers micront.exeAdded by the W32/Rbot-ABD WORM! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:%WI
O Reset 5 srvany.exeUnknown owner: Location C:WindowsSystem32srvany.exe In this case srvany.exe is loading resetservice.
L Resource Manager Mail (ResourceManagerMail) MailService.exeRelated to Citrix Systems Inc.
X restore (restore) restore.exeAdded by the SDBOT.CFD WORM! Read the link rootkit type stealth involved.
L Retrospect Helper rthlpsvc.exeRelated to Dantz Development Corporation
L Retrospect Launcher retrorun.exeRelated to Dantz Development Corporation
L Retrospect WD Service wdsvc.exeRelated to Dantz Development Corporation
L RevUDFService RevUDF.exeRelated to Iomega_Corp provider of a number of backup data solutions
L Rio MSC Manager RioMSC.exeRelated to Digital Networks North America.
X Rll enhanced drive (mfm) msrll.exeAdded by the Troj/Jtram-E TROJAN! Note: This trojan file is found in the System32mfm folder.
L RoamMgr RoamMgr.exeIntel PROset
L Rockwell Application Services (RsvcHost) RsvcHost.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell Directory Multiplexer (RNADirMultiplexor) RNADirMultiplexor.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell Directory Server (RNADirectory) RnaDirServer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell Event Multiplexer (EventClientMultiplexer) EventClientMultiplexer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell HMI Activity Logger RsActivityLogServ.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell HMI Diagnostics HMIDIAGNOSTICSLSTADAPT.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
L Rockwell Tag Server TagSrv.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
X rofl (rofl) rofl.sysAdded by the Troj/RKPort-Fam TROJAN! This is a rootkit!
L Roger Wilco Base Station rwbs.exeRelated to IGN_Entertainment Inc. Required to operate the Wilco Base Station.
L Roxio Hard Drive Watcher RoxWatch.exeRelated to Roxio_Inc
L Roxio Hard Drive Watcher 9 (RoxWatch9) RoxWatch9.exeRelated to Roxio_Inc
L Roxio UPnP Renderer 9 RoxioUPnPRenderer9.exeRelated to Roxio_Inc
L Roxio Upnp Server 9 RoxioUpnpService9.exeRelated to Roxio_Inc
L RoxMediaDB RoxMediaDB.exeRelated to Roxio_Inc
L RoxMediaDB9 RoxMediaDB9.exeRelated to Roxio_Inc
L RoxUpnpRenderer RoxUpnpRenderer.exeRelated to Roxio_Inc
L RoxUpnpServer RoxUpnpServer.exeRelated to Roxio_Inc
X RPC Debug Control (RPCDB) csts.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm rojan is lo
X RPC+ Service Provider (RPCSS+) rpcss_pl.exeTrojan. - http://www.what-process.com/process-info.aspx?p=rpcss_pl.exe
X RpcRemotes remote.exeAdded by the W32/Fanbot-J WORM! Note: This worm file is found in the System32 folder. Be sure to che