|
| Name
| Process
| Details
|
| L | (PinnacleSys.MediaServer) | pmshost.exe | Related to Pinnacle_Systems Inc.
|
| X | .NET Framework Service | svchost.exe | Trojan-PSW.Win32.Sagic.15 Virus
|
| X | .NET Framework Service (.NET Connection Service) | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| L | Alerter | svchost.exe | Notifies selected users and computers of administrative alerts. If the service is stopped programs t |
| X | AppMgmt | svchost.exe -k AppMgmt | Added by the Fuwudoor TROJAN!
|
| L | AT Host Service | atnthost.exe | Related to WebEx
|
| L | Biometric Authentication Service | DpHost.exe | Related to DigitalPersona Inc.
|
| X | Browser | svchost.exe -k Browser | Added by the Fuwudoor TROJAN!
|
| L | BullGuard Email Monitoring (BsMailProxy) | svchost.exe | Related to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
|
| L | BullGuard File Monitoring (BsFileSpy) | svchost.exe | Related to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
|
| L | BullGuard Firewall (BsFirewall) | svchost.exe | Related to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
|
| L | BullGuard Main (BGMainSvc) | svchost.exe | Related to BullGuard Antivirus. Note: located in C:Program FilesBullGuard Software
|
| L | COM Host | comHost.exe | Related to Norton/Symantec Internet Security
|
| X | COM Message Transfer (mscommt) | svchost.exe -k mscommt | Added by the Troj/Dbit-A TROJAN!
|
| X | COM+ System Service (DLLHOST) | dllhost.exe | Added by the Backdoor.Win32.SdBot.xd as identified by Kaspersky TROJAN! Note: This worm rojan is loc |
| X | Compatibil) | svchost.exe | Added by the Troj/Keylog-AT TROJAN! Note: This is not the legitimate Windows process svchost.exe (Wh |
| X | Config Loader | scvhost.exe | several Agobot variants
|
| X | Disk Monitor Services (DiskMon32) | svchost.exe -k dmon | Added by the Hanmon TROJAN! Note: This trojan file is found in the System32 folder.
|
| X | dmserver | svchost.exe -k dmserver | Added by the Fuwudoor TROJAN!
|
| X | DNS Server (DNS Server) | svchost.exe | Added by the Troj/Feutel-Y TROJAN! Note: This is not the legitimate Windows Process. (Which is found |
| X | Dynamic Library Host (DLLHOSTS) | dllhost.exe | Added by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: Note: This worm rojan is loca |
| X | DynamicHost (DLHOST) | dlhost.exe | Added by the W32/Tilebot-BO WORM! Note: This worm file is found in the Windows or Winnt folder.
|
| X | generic host process (svchost) | svchost.exe | Added by the W32/Tilebot-BB WORM! Note: This is not the legitimate Windows process svchost.exe (Whic |
| X | Hardware Detection (Serv-U) | svchost.exe | Reported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows proces |
| X | host (host) | host.exe | Added by the Troj/GrayBrd-AR TROJAN! Note: This trojan file is found in the Windows or Winnt folder. |
| X | host Service For Windows (mshost) | mshost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| X | Host Services (Host Services) | myhost.exe | Added by the W32/Tilebot-AT WORM! Note: This worm rojan file is found in the Windows or Winnt folder |
| X | IPRIP (IPRIP) | svchost.exe -k netsvcs | Added by the Backdoor.Ripgof TROJAN! Read the link rootkit type stealth involved.
|
| X | kdc | svchost.exe -k kdc | Added by the Fuwudoor TROJAN!
|
| X | LmHosts | svchost.exe -k LmHosts | Added by the Fuwudoor TROJAN!
|
| X | Loader) | SVCHOST.EXE | Added by the RBOT.BZF WORM! Note: This is not the legitimate Windows process SVCHOST.EXE (Which is a |
| L | McAfee SiteAdvisor Service | McSvHost.exe | Mcafee Inc - commonly located at C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe |
| X | Messenger | svchost.exe -k Messenger | Added by the Fuwudoor TROJAN!
|
| X | Microsoft Agent | qxchost.exe | Added by the W32/Sdbot-CWP WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/ |
| X | Microsoft Agent | rschost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS |
| X | Microsoft Agent | snchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| X | Microsoft Agent | ffchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: Located in C:WindowsSystemdllcache (Win9 |
| X | Microsoft Agent | lpohost.exe | Added by the W32/Sdbot-CWQ WORM! Note: This worm rojan is located in C:%WINDIR%System32dllcache (XP/ |
| X | Microsoft Print Spooler (WINDRIVER) | scvhost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS |
| X | Microsoft Windows Update (Microsoft Update) | scvvhost.exe | Added by the W32/Forbot-FH WORM!
|
| X | MS Internet Countermeasures Framework (ICF) | System32:svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note DO NOT delete the svchost.exe file.
|
| X | MsHS64 or cvcworking setting (cvcWork or MsHS64) | syscvhost.exe or MsHS64.exe | Added by the W32/Tilebot-BU WORM! Note: This worm rojan file is found in the Windows or Winnt folder |
| X | NetLogon | svchost.exe -k NetLogon | Added by the Fuwudoor TROJAN!
|
| X | Network Connections Sharing (RpcTftpd) | svchost.exe | Added by the W32.Welchia WORM! **Note - This service will be set to start manually
|
| X | Network DDE DSMA (NetDDEdsma) | svchost.exe | Added by the W32/Sdbot-BMG WORM! Note: This is not the legitimate Windows Process. (Which is found i |
| X | ntmssvc | svchost.exe -k ntmssvc | Added by the Fuwudoor TROJAN!
|
| X | NVIDIA Driver ServiceĦĦ (NVSv ) | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| L | PCHost | pchost.exe | Related to PCHost
|
| X | Policy Agent | svchost.exe -k Policy Agent | Added by the Fuwudoor TROJAN!
|
| X | Power Manager (PowerManager) | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| X | Process) | svchost.exe | Added by the W32/Tilebot-DM WORM! Note: This worm rojan is located in C:%WINDIR% folder.Note: This i |
| X | ProtectedStorage | svchost.exe -k ProtectedStorage | Added by the Fuwudoor TROJAN!
|
| X | RasAt (Remote Connection) | svchost.exe | Added by the Troj/Singu-AF TROJAN!
|
| L | Rockwell Application Services (RsvcHost) | RsvcHost.exe | Related to Rockwell_Automation Inc. FactoryTalk suite
|
| X | Server Management Service | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| X | Service Hosts (ServiceHost) | shost.exe | Added by the W32/Rbot-AXG WORM! Note: This worm file is found in the Windows or Winnt folder.
|
| X | serviceMangr (tcphost.exe) | TCPHOST.EXE | Added by the SDBOT.CSG WORM! Read the link rootkit type stealth involved.
|
| X | stchost.exe (moto) | stchost.exe | Added by the Troj/Vixup-L TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
|
| X | svahost | svahost.exe | Added by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm rojan is lo |
| X | SVC Module (SVC Module) | svchost.exe | Added by the W32/Sdbot-ADG WORM! Note: This is not the legitimate Windows Process. (Which is found i |
| X | svchost | SVCHOST.EXE | Added by the SDBOT.CNK WORM! Note: This is not the legitimate Windows process svchost.exe (Which is |
| X | svchost.exe (moto) | svchost.exe | Added by the Troj/Agent-MD TROJAN! Note: This worm rojan is located in C:%WINDIR%
|
| X | svchost.exe (svchost.exe) | svchost.exe | Added by the Troj/GrayBird-X TROJAN! Note: This trojan file is found in the Windows or Winnt folder. |
| X | System Event Messaging | svchost.exe | Seems to be viral
|
| X | taskmng (svchost) | svchost.exe | Added by the W32/Tilebot-AW WORM! Read the link rootkit type stealth involved.
|
| X | TrkSvr | svchost.exe -k TrkSvr | Added by the Fuwudoor TROJAN!
|
| X | TrkWks | svchost.exe -k TrkWks | Added by the Fuwudoor TROJAN!
|
| L | Unicenter Remote Control Host (rcHost) | rcHost.exe | Related to Unicenter_Remote_Control_Host From Computer Associates Note: Located in C:BA_MGMTTNGRCORC |
| X | W32Time | svchost.exe -k W32Time | Added by the Fuwudoor TROJAN!
|
| X | Win32 Kernel Update (Win32Kernel) | win32host.exe | Added by the W32/Tilebot-FE WORM! Note: This worm file is found in the Windows or Winnt folder. Allo |
| X | Windows Configuration Backup Service (CfgBackupSvc) | svchost.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm rojan is located in C:%WINDIR%CONF |
| X | Windows Configuration Manager (ConfigMgr) | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS |
| X | Windows Host Services (DLLHOST32) | dllhost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:WindowsS |
| X | Windows Kernel | svchost.exe | Added by the HackerDefender SDBot TROJAN! ROOTKIT INFECTION Note: This worm rojan is located in C:Wi |
| X | Windows Kernel (Windows Kernel) | svchost.exe | Added by the W32/Rbot-ANO WORM! Note: This is not the legitimate Windows Process. (Which is found in |
| ? | Windows LAN Service Manager | svchost.exe | Unknow origin
|
| X | Windows Management (Windows Management) | svchost.exe | Added by the Troj/Feutel-AN WORM! Note: This is not the legitimate Windows process(Which is always f |
| X | Windows Network Mapping Service (NetMap) | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. This worm rojan is located in C:%WINDIR%system |
| X | Windows Security Drivers (csrs) | svchost.exe | Added by an unknown TROJAN! Note: This has nothing to do with Microsoft Windows Update and this is n |
| X | Windows Smrss Service | svchost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm rojan is located in C:%WINDIR% |
| X | Windows Update Client (WUClient) | upnphost.exe | Added by the W32.Janx WORM!
|
| X | Windows Update Client (WUClient) | pnphost.exe | Added by the W32.Janx WORM!
|
| X | WINS Client (RpcPatch) | dllhost.exe | Added by the W32.Welchia WORM! **Note - This service will be set to start automatically
|
| X | WksPatch | Svchost.exe | Added by the W32.Welchia.B or W32.Welchia.C or W32.Welchia.D or W32.Welchia.K WORM! **Note - Service |