Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

Key:

  • L = Legit, O = Open to Debate, X = Malware/Bad
Startup Name Process Name Details
L RSLinx RSLINX.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
L RSLinx Enterprise (RSLinxNG) RSLinxNG.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
X Rtkit Rtkit.exeAdded by the Backdoor.Rtkit TROJAN! Read the link rootkit type stealth involved.
L Run RunOnce ShipUPS.EXE RunOnce.exeRelated to UPS WorldShip shipping software
X rundll.exe rundll.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X rundll.exe msngrsm.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X rundll.exe msn93.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X rundll32 (rundll32) rundll32.exeAdded by the Troj/Feutel-Q TROJAN!
X rundll32.exe lsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L Rupsd Rupsd.exeRelated to Mega_System Technologies Inc.
L Rupsmon RupsMon.exeRelated to Mega System Technologies Inc.
L RVS CommCenter (RvsCC) RVSCC.EXELegit Fax/Digital Answering Machine/Telephony service. Owner Unknown . Located in C:Program FilesTel
L RVS Installer (RVSINST) RVSINST.EXELegit Fax/Digital Answering Machine/Telephony service. Owner: RVS Datentechnik GmbH MŘnchen. Located
X Rwx (Rwx2005) svhosts.exeAdded by the Troj/Subzero-B Trojan!
X r_server service.exeAdded by the Troj/Remadm-G TROJAN! Note: This is not the legitimate Windows process services.exe (No
L SafeGuard Easy Client (SgeClient) SgeClient.exeRelated to SafeGuard_Easy Hard Disk Encryption from Utimaco. Note: Located in C:Program FilesUtimaco
L SafeGuard Easy Workstation Server (WksCfgSrv) WksCfgSrv.exeRelated to SafeGuard_Easy Hard Disk Encryption from Utimaco. Note: Located in C:Program FilesUtimaco
L SafeGuard SGLOG Player (SgLogPlayer) SgLogPlayer.exeRelated to SafeGuard_Easy Hard Disk Encryption from Utimaco. Note: Located in C:WINDOWSsystem32
L SafeNet IKE Service (IREIKE) IreIKE.exeRelated to Microsoft Virtual Private Network Client.
L SafeNet Monitor Service (IPSECMON) IPSecMon.exeRelated to Microsoft Corp. Feature of the Layer Two Tunneling Protocol (L2TP).
L Samsung Update Plus SLUBackgroundService.exeRelated to Samsung_AV_Station instant Playback of music photos videos.
X SAMSvc (Security Account Manager) SAMSvc.exeAdded by the W32/Tilebot-DL WORM!
L Sandboxie Service (SandboxU) SandboxieServer.exeRelated to SandBoxie Sand box application. Data may flow from the hard disk into the sandbox. But da
L Sandra Data Service RpcDataSrv.exeSiSoftware Sandra Lite 2005
L Sandra Service RpcSandraSrv.exeSiSoftware Sandra Lite 2005
L Sansa Updater Service (SansaService) SansaSvr.exeRelated to Sansa_Updater Service from Sandisk. Note: Located in C:Program FilesSanDiskSansa Updater
L SAVRoam SavRoam.exeRelated to Norton/Symantec AntiVirus
L SAVScan SAVScan.exeRelated to Norton/Symantec AntiVirus.
X sbchosy.bat sbchosy.batAdded by the Troj/GrayBir-AA TROJAN! Note: This trojan file is found in the WindowsProgram Files or
L SBHookSvc SBHookSvc.exeRelated to Motive_Communications Broadband service. Note: Located in C:PROGRAM FILESNETASSISTANTSMAR
X SCA (Service Control Application) SYSTEM.EXEUnknown virus
X scheduler (schedul3.exe) schedul3.exeAdded by the W32/Rbot-AVX TROJAN! Note: This worm rojan file is found in the Windows or Winnt folder
L schscnt schscnt.exeRelated to Command AntiVirus for Windows Component made by Command Software Systems Inc. Which merge
X SCNDmem (winlow) winlow.sysAdded by the Troj/Haxdoor-AF TROJAN!
L ScriptBlocking Service (SBService) SBServ.exeRelated to Norton/Symantec AntiVirus.
L ScsiAccess ScsiAccess.EXEAlcohol Software's CD/DVD writing application
X SCSMS32 (SCSMS) scmsm32.exeAdded by the SDBOT.CCN or SDBOT.CEZ WORM! Read the link rootkit type stealth involved.
L SCWatch 4.0 scwatch4.exeRelated to White Canyon - protect against identity theft software. - http://www.whitecanyon.com/inde
L SDJB Manager sdjbmgr.exePanasonicSD-JukeboxV3
X sdktemp Microsoft.exeAdded by the SDBOT.CGM WORM! Read the link rootkit type stealth involved.
X sdktemp (sdktemp) SDKTEMP.EXEAdded by the W32/Tilebot-A WORM! Read the link rootkit type stealth involved.
X sdktemp (sdktemp) axdcfasb.exeAdded by the W32/Sdbot-AGI WORM! Read the link rootkit type stealth involved.
L SDPAUMS server service sdpasvc.exeMatsushita Electric Industrial Co.Ltd.
L SDService SDService.exeRelated to Spyware_Detector from Max Secure. Note: Located in C:Program FilesSpywareDetector
L Seagate Page Server (pageserver) pageserver.exeRelated to Seagate Page Server. Now owned by Business_Objects Note: Located in C:Program FilesSeagat
L Seagate Web Component Server (WebCompServer) WebCompServer.exeRelated to Seagate Web Component Server. Now owned by Business_Objects Note: Located in C:Program Fi
L Search Engine Commando Schedule Service ScheduleService.exeRelated to Search Engine Commando
X Secondary .NET Framework (SVSNET) svsnet.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Secure Port Server (Server Administrator) omaws32.exeRelated to Dell Open Management system. http://www.what-process.com/process-info.aspx?p=omaws32.exe
X Secure SSL System (Secure) securessl.exeAdded by the Haxdoor.Fam HAXDOOR! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
X Security Accounts Center (Security Accounts Center) windowo.exeAdded by the Troj/Bckdr-AWQ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X Security Agent (scagent) scagent.exeAdded by the Troj/Dload-LV TROJAN! Note: This worm rojan is located in C:WindowsSystem (Win9x/Me) C:
X Security Logs Service (SLSVS) SM1OGSVC.EXEAdded by the Troj/Tenant-A TROJAN! Note: This trojan file is found in the System32 folder.
L Security Platform Management Service (IFXSpMgtSrv) IFXSPMGT.exeRelated to Security_Platform_Management Service from Infineon Technologies. Note: Located in C:WINDO
X Security) elRecvr.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:Windows
Securom User Access for Windows 2000 and Windows XP a
L SecuROM User Access Service UAService7.exeUsed by virtual CD programs like Alcohol to access CD images protected by SecureROM.
L SentinelProtectionServer spnsrvnt.exeRelated to one of the SafeNet_Inc programs or services.
L Sentry 2020 SentryService.exewww.softwinter.com
X SerDgeonServer (SerDry_igeon_Server) IExplore.exeAdded by the Troj/Feutel-AC TROJAN! Note: This is not the legitimate Windows process IExplore.exe (W
O Serv-U FTP Server ServUDaemon.exeRelated to Serv-U an FTP Server note Reference:
X Server 2.0 (Server 2.0) Server.exeAdded by the Troj/GrayBrd-AN TROJAN! Note: This worm rojan file is found in the Windows or Winnt fol
X Server Management Service svchost.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
L Server) TSLLkSrv.exeRelated to Transparent_Screen_Lock from Esm Software. Secure your workstation or server with Passwor
X Service Service.exeAdded by the Haxdoor.Fam HAXDOOR! Note: Located in C:WindowsSystem (Win9x/Me) C:%WINDIR%System32 (XP
X Service Service.exeAdded by the Troj/SrchSpy-A TROJAN! Note: This is not the legitimate Windows process services.exe (N
X SERVICE (WINDOWS) spoolsvc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X Service 8 (Service Filter) smncs.exeAdded by the W32/Tilebot-CK WORM! which attempts to spread to remote network shares and messaging ap
X Service Cache Terminal (SVCTERM) svscache.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
X Service Cvasvr (Service Cvas) csvas.exeSpyware Worm reported as Backdoor.Win32.SdBot.aad by Kaspersky Anti-Virus
L Service de lancement de WlanCfg (Wlancfg) wlancfg.exeDriver for wireless router. Owner: Inventel-Found in C:Program FilesInventelGateway
X Service Framework (WSSF)) alg.exeAdded by the W32/Tilebot-BT WORM! Note: This worm rojan file is found in the Windows or Winnt folder
X Service Hosts (ServiceHost) shost.exeAdded by the W32/Rbot-AXG WORM! Note: This worm file is found in the Windows or Winnt folder.
X Service Logon Protocol (SVSLOG) svslogon.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X Service name: Messenger 514.exeTrojan.Esteems.D See Symantec Location C:WindowsSystem32 (XP) C:WinntSystem32 (NT2000)
X Service name: Messenger zone-h.ddo.jp.exe -k netsvcsTrojan.Esteems.C See Symantec Location: C:WinntSystem32 ( NT/2000) or C:WindowsSystem32 (XP).
X Service name: Messenger system32.exeSee Symantec Trojan.Esteems.B Location: CWindowssystemsystem32.exe (9XME) or CWindows or Winntsystem
X Service Scheduler scheduler.exeW32/Agobot-PH See Sophos Unknown owner: Location: C:WINDOWSSystem32scheduler.exe -service
L Service) NHOSTSWC.EXERelated to Danware NetOp products
X Service) winlogon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR%
X Service) services.exeAdded by the W32/Tilebot-FW WORM! Note: This is not the legitimate Windows process (Which is always
X Service) services.exeAdded by the W32/Sdbot-AWW WORM!
X Service) gencroot.exeAdded by the Troj/HacDef-X TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
L Service) NHOSTSVC.EXERelated to Danware NetOp products Note: Located in C:Program FilesDanware DataNetOp Remote ControlHO
X Service) winlogon.exeAdded by the W32/Tilebot-FR WORM!Note: This is not the legitimate Windows process (Which is always f
? Service) ceisvc.exeSeems to be legit belongs to this company Ce-infosys_suite It will be left as unknown until more is
L Service1 windowsserviceexample.exeRelated to Microsoft .Net Application. VB.NET_Forums
X Service32 (Service Sequence) services32.exeAdded by the W32/Tilebot-C WORM! Read the link rootkit type stealth involved.
X Service: Microsoft Net API (NETAPI) ntps.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: This worm rojan is l
X Service: Network Client (nwclnta) netclna.exeTroj/Boxed-I. Owner:Unknown. Location: C:WINDOWSsystem32 etclna.exe
L ServiceLayer ServiceLayer.exeRelated to Nokia Connectivity Library software. Note: located in C:Program FilesCommon FilesPCSuiteS
X serviceMangr (tcphost.exe) TCPHOST.EXEAdded by the SDBOT.CSG WORM! Read the link rootkit type stealth involved.
X Services an controller-settings services.exeAdded by the W32/Tilebot-HY WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X services32 (Content List Management Sub System) services32.exeAdded by the W32/Esbot-B WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
X Servicess_Server Servicess.exeA variant of the Feutel/Hupigon infection. Note: rootkit type stealth involved.
L Servicio COM de grabaci├│e CD de IMAPI imapi.exeRelated to recording of CDs.
L Servicio de alerta services.exeSpanish Windows 2000 alert service.
L Servicio de ayuda TCP/IP NetBIOS services.exeSpanish Windows 2000 Help service TPC/IP NetBIOS
L Servicio de fax faxsvc.exeSpanish Windows 2000 fax service
L Servicio del administrador de discos l├│os dmadmin.exeSpanish Windows 2000 logical disk manager administrative service
L Servicio RunAs services.exeSpanish Windows 2000 RunAs service
L Servidor services.exeSpanish Windows 2000 server
L Servizio Norton AntiVirus Auto-Protect navapsvc.exeRelated to Norton Antivirus
X settings SETTINGS.EXEAdded by the SDBOT.CHY WORM! Read the link rootkit type stealth involved.
L SF FrontLine Drivers Auto Removal (v1) (sfrem01) sfrem01.exeRelated to SF_FrontLine Drivers Auto Removal from Star-Force. Note: Located in C:WINDOWSsystem32
X SFTRANSFER (SFTRANSFER) (Unknown at this time.)Added by the Backdoor.Brakkeshell TROJAN! Note: In the Description field under Services it wil show
L SFUSVC SFUSVC.exeKYOCERA_MITA Scanner File Utility used with Kyocera Mita scanners/faxes. Note: located in C:Program
L SgeCtl SGECTL.EXEUtimaco Safewares SAFEGUARD
L Shavlik HFNetChkPro Service HFNetChkProService.exeHFNetChkPro distributes Microsoft patches to client machines
X Shell Software Detection (ShellSWDetection) shellsw.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS
L Shiva VPN Client icsrv.exeRelated to Eicon Networks Corporation
L SigmaTel Audio Service (STacSV) stacsv.exeRelated to SigmaTel_Audio_Service Part of the C-Major Audio driver. Note: Located in C:Program Files
L Sigmatel PassThru (PassThru) passthru.exeRelated to Sigmatel
L SiS WirelessLan Service (SiSWLSvc) SiSWLSvc.exeRelated to Sis_Wireless_Lan LAN controller
L Sistema de ayuda de tarjeta inteligente SCardSvr.exeSpanish Windows 2000 smart card helper
L SiteAdvisor Service SAService.exeRelated to SiteAdvisor Service from McAfee. Note: Located in C:Program FilesSiteAdvisor[4 digits num
L SiteMinder Authentication Service (SmServAuth) Service_AuthSrvr.exeRelated to Cold_Fusion from Macromedia inc.
L SiteMinder Authorization Service (SmServAz) Service_AzSrvr.exeRelated to Cold_Fusion from Macromedia inc.
X Skype Messenger (Skype) skype32.exeAdded by the W32.Mytob.ML WORM! Note: This worm file is found in the System32 folder. Read the link
L Sleepy service.exeRelated to Sashazur LLC A utililty to prevents computer use at night. For schools libraries business
L SlimServer (slimsvc) slim.exeRelated to SlimServer Note: Located in C:Program FilesSlimServerserver
X SLMDriver (SLMDriver) slm32.sysAdded by the Troj/Rootkit-AA TROJAN! Note: This trojan file is found in the System32 folder. Read th
L SLPMONX slpservice.exeRelated to Seiko Printers. Provides additional configuration options for these devices. Note: locate
L SMART Board Service SMARTBoardService.exeRelated to SMART Technologies inc.
X Smart Card Client (SCardClnt) SCardClnt.exeAdded by the W32/Codbot-K WORM! Note: located in C:WindowsSystem (Win9x/Me) C:WinntSystem32 (XP/WinN
X Smart Card Helper scardsvr32.exeAdded by the W32.Femot_worm! . NOTE: do not confuse this with the legitimate Smart Card Helper servi
L SmartGenie (LxrSGe10s) LxrSge10s.exeRelated to SmartGenie_toolbar customizable toolbar offers many helpful research tools making it poss
L SmartLinkService slmdmsr.exeslmdmsr.exe installed alongside Smartlink communication products and offers additional support to th
L SmartLinkService (SLService) slserv.exeslserv.exe is installed alongside Smartlink communication products and offers additional support to
L SmartTrust Smart Card Server (Smartscaps) Smartscaps.exePlatform for integrating security functions with mobile services. For more information Click_Here
L SmartWiService SmartWiService.exeRelated to Sony_SmartWi SmartWi technology is the seamless integration of three wireless technologie
SMBus Upgrade Service for Windows 2000 and above
X SMONITOR SMONITOR.SYSAdded by the TROJ_ROOTKIT.V TROJAN! Read the link rootkit type stealth involved.
X SMS Help Center (SMS32) smss32.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%
X smsc smsc.exeAdded by the W32/Tilebot-GW WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X smscc smscc.exeAdded by the W32/Sdbot-CPG WORM! Note: This worm rojan is located in C:%WINDIR%
X smsmanger smsmanger.exeAdded by the Backdoor.SdBot.xd as identified by ewido. Note: This worm rojan is located in C:%WINDIR
X SMSS (SMSS) smss.exeAdded by the W32/Tilebot-V WORM! Note: This worm file is found in the Windows or Winnt folder.
L SMTP Capture smtpcap.exeRelated to NSi's AutoStore from Notable Solutions Inc. Capture documents and securely saving the con
X Snake SockProxy Service (SkServer) wuauserv.exeVariant of Troj/VB-ZD See Sophos
L SNARE SnareCore.EXERelated to InterSect_Alliance Open Source agents to provide a log collection analysis reporting and
L SnareIIS SnareIIS.EXERelated to InterSect_Alliance Open Source agents to provide a log collection analysis reporting and
X SndDRV (MS Sound Driver) (SndDRV) snddrv.exeAdded by the W32/Rbot-BSC WORM! Note: This worm file is found in the System32 folder.
L SNMPTrapd Service snmptrapd.exeRelated to MKS_Toolkit
L Snoop Free Service (SnoopFreeSvc) SnoopFreeSvc.exeAnti-keylogging software made by SnoopFree_Software._
X Socks-Cap (Sc32Inch) Sc32Inch.exeAdded by WORM_SDBOT.DIN WORM! Rookit infection Note: located in C:WindowsSystem (Win9x/Me) C:%WINDIR
L Softex OmniPass Service Omniserv.exeRelated to Softex OmniPass security solution which handles passwords on your computer.
L Softex OmniPass Service Omniserv.exesecure password management software
L Software Jukebox v2.0 Service Software Jukebox v2.0 Service File.exeRelated to BlueLabelle Jukebox v2.0 from MPEGX.com
L Software Secure Service (SSISvr32) ssisvr32.exeRelated to Software_Secure service. Enables students to take an exam in a secure environment using M
L SolidPDFConverterReadSpool (ScReadSpool) SolidPdfService.exeRelated to Solid_Converter_PDF from VoyagerSoft - Turn your PDFs into documents you can edit.
L SonicStage SCSI Service (SSScsiSV) SSScsiSV.exeRelated to Sony Corp.
L SonicStageMonitoring SonicStageMonitoring.exeRelated to Sony GigaPocket multimedia entertainment center.
L SonicWALL Agent Service swAgent.exeRelated to Network Associates Inc.
L SonicWall VPN Client Service RampartSvc.exeSonicWall client for VPN access.
L Sony SCSI Helper Service SonySCSIHelperService.exeRelated to Related to Sony Corporation.
L Sony SPTI Service (SPTISRV) Sptisrv.exeRelated to Sony Corporation
L Sony SPTI Service for DVE (ICDSPTSV) IcdSptSv.exeRelated to Sony SPTI Service Note: Sony Inc. Located in C:%WINDIR%System32 (XP/WinNT/2K)
L Sony TV Tuner Controller halsv.exeSony computers
L Sony TV Tuner Controller halsv.exeSony computers
L Sony TV Tuner Manager RM_SV.exeSony computers
L Sony TVTA Manager SMceMan.exeRelated to Sony Corporation.
L Sophos Agent ManagementAgentNT.exeRelated to Sophos AntiVirus protection software.
L Sophos Anti-Virus SWEEPSRV.SYSBy Sophos Plc
L Sophos Anti-Virus (SAVService) SavService.exeRelated to Sophos AntiVirus protection software.
L Sophos Anti-Virus (SWEEPSRV.SYS) SWEEPSRV.SYSSophos Virus protection program. http://www.sophos.com/support/knowledgebase/article/378.html
L Sophos Anti-Virus Network SWNETSUP.EXEBy Sophos Plc
L Sophos Anti-Virus status reporter (SAVAdminService) SAVAdminService.exeRelated to Sophos AntiVirus protection software.
L Sophos Anti-Virus Update SWUPDATE.EXEBy Sophos Plc
L Sophos AutoUpdate Agent AutoUpdateAgentNT.exeRelated to Sophos AntiVirus protection software.
L Sophos AutoUpdate Service ALsvc.exeRelated to Sophos AntiVirus protection software. Auto Update service.
L Sophos Cache Manager (CacheMgr) cachemgr.exeRelated to Sophos AntiVirus protection software. Remove Update service.
L Sophos Message Router RouterNT.exeRelated to Sophos AntiVirus protection software.
X Sound Sservice Driver (Sound Service) cfmon.exeSee Here
SoundMAX Agent Service (SoundMAX Agent Service
L SP Software Installer sp_SWIns.exeSmartPipes SecureSite is a scalable reliable and secure software platform for the creation and manag
L SPBBCSvc SPBBCSvc.exeRelated to Symantec Internet security suite and assists in keeping your computer up to date from Int
X spdcheck SPDCHECK.EXEAdded by the SDBOT.BZE WORM! Read the link rootkit type stealth involved.
L Spectrum24 Event Monitor S24EvMon.exeIntel Corporation
L Speed Disk service nopdb.exeNorton Speed Disk
L spkrmon spkrmon.exeSoundMAX SpeakerMonitor service
L SPM License Server (spmd) spmd.exeRelated to SPM_License from mental images GmbH. RealityServer« is the unique server-based scalable i
L spmgr spmgr.exeRelated to Sony VAIO/ASUS laptops and provides additional configuration options for these devices. T
X spool SPOOLLV.EXEAdded by the SDBOT.CTI WORM! Note: This worm file is found in the System32 folder. (NT/2000/XP) Read
X spool spoollv.exeAdded by the W32/Sdbot-AES WORM! Note: This worm rojan file is found in the Windows or Winnt folder.
X Spool SubSystem App lsass.exeAdded by the W32/Tilebot-HD WORM! Note: This worm rojan is located in C:%WINDIR% folder. Note: This
X SpoolService spolsv.exe -servicePossibly added by a W32/Agobot variant.
X spoolv spoolv.sysAdded by the TROJ_ROOTKIT.S TROJAN! Read the link rootkit type stealth involved.
L Spss License Manager (SpssLM) spss_lmd.exehttp://www.spss.com/spss/licensing.htm
X Spy-Keylogger (SpyKeyloggerService) skls.exeIdentified as Spyware.SpyKeylogger SPYWARE! Spyware.SpyKeylogger is a security risk that records key
L SpyDetectSVC SpywareDetectorSVC.exeSpyware Detector Adware/Spyware remover - initially considerered a rogue program. The latest version
O SpywareCleanerService SCService.exeOwner:Secure Computer LLC. May show as Unknown owner. Related to Spyware Cleaner Note: Not recommend
L SQL Server (MSSQLSERVER) sqlservr.exeRelated to Microsoft_SQL_server suite.
L SQL Server Agent (MSSQLSERVER) (SQLSERVERAGENT) SQLAGENT90.EXERelated to Microsoft_SQL_Server_Agent
X sql-smss sql-smss.exeAdded by the W32/Tilebot-GI WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X sqldps sqldps.exeAdded by the W32/Tilebot-GV WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X sqlmanagement sqlmanagement.exeAdded by the W32/Tilebot-GB WORM! Note: This worm rojan is located in C:%WINDIR% folder.
X sqlserver (sqlserver) sqlserv.exeAdded by the SDBOT.BZO WORM! Read the link rootkit type stealth involved.