| Status Code | Name | Command | Description |
| X | @tour_ww | @tour_ww[1].exe | Adult content dialler |
| N | @loha | reminder.exe | Registration reminder for @loha@home E-mail utility |
| N | @Hoc Toolbar | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info |
| X | @ | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| X | (default) | winhelp.exe | Added by the BLACKMAL.C WORM! |
| X | (default) | twunk_32.exe | Added by the BLACKMAL.C WORM! |
| X | (default) | [random filename].exe | Added by the BLACKMAL WORM! |
| X | (Default) | NOTEPAD.exe | Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor |
| X | (Default) | Shania.vbs | Added by the SHANIA TROJAN! |
| X | (Default) | media_driver.exe | Added by the TUPEG VIRUS! |
| X | (*)Run | win32API.exe | Homepage hijacker, see here (* = any digit) |
| X | (*)API Machine | winSOCKS.exe | Homepage hijacker, see here (* = any digit) |
| X | $WindowsRegKey%update | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
|
| ? | $EnterNet | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
| N | !NoLoad | winrecon.exe | WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| Y | !1_ProcessGuard_Startup | procguard.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
| Y | !1_pgaccount | pgaccount.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
| Y | !1_pgaccount | pgaccount.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
| Y | !1_ProcessGuard_Startup | procguard.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
| N | !NoLoad | winrecon.exe | WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
| ? | $EnterNet | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
| X | $WindowsRegKey%update | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
|
| X | (*)API Machine | winSOCKS.exe | Homepage hijacker, see here (* = any digit) |
| X | (*)Run | win32API.exe | Homepage hijacker, see here (* = any digit) |
| X | (Default) | media_driver.exe | Added by the TUPEG VIRUS! |
| X | (Default) | Shania.vbs | Added by the SHANIA TROJAN! |
| X | (Default) | NOTEPAD.exe | Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor |
| X | (default) | [random filename].exe | Added by the BLACKMAL WORM! |
| X | (default) | twunk_32.exe | Added by the BLACKMAL.C WORM! |
| X | (default) | winhelp.exe | Added by the BLACKMAL.C WORM! |
| X | @ | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| N | @Hoc Toolbar | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info |
| N | @loha | reminder.exe | Registration reminder for @loha@home E-mail utility |
| X | @tour_ww | @tour_ww[1].exe | Adult content dialler |