-
Notifications
You must be signed in to change notification settings - Fork 22
/
Invoke-ProcessScan.ps1
7776 lines (7730 loc) · 337 KB
/
Invoke-ProcessScan.ps1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
function Invoke-ProcessScan
{
<#
.SYNOPSIS
Performs a series of lookups against a known database of descriptions for process executeable names that the EQGRP leaked.
Author: Vincent Yiu (@vysecurity)
License: BSD 3-Clause
Required Dependencies: None
Optional Dependencies: None
.DESCRIPTION
Invoke-ProcessScan scans the list of running processes on the system and matches it back to a description as specified by the EQGRP Leak.
.PARAMETER SecurityOnly
Scan only for security related processes
.PARAMETER Path
Export a CSV to the following file path and name. (eg. C:\test.csv, local.csv)
.EXAMPLE
List all processes, do not save.
PS C:\> Invoke-ProcessScan -SecurityOnly $False
[*] Starting AV Scan
ProcessName Description
----------- -----------
cmdagent.exe !!! Comodo Firewall Pro !!!
system.exe !!! LanAgent Monitoring !!!
csrss.exe Client-Server Runtime Server Subsystem
csrss.exe Client-Server Runtime Server Subsystem
rundll32.exe Control Panel Helper
RegSrvc.exe Intel Communications Service
evteng.exe Intel EvtEng Module
lsass.exe Local Security Authority Server Subsystem
PresentationFontCache.exe Microsoft .NET Framework
conhost.exe Microsoft Console Windows Host
conhost.exe Microsoft Console Windows Host
dllhost.exe Microsoft DCOM DLL Host Process
spoolsv.exe Microsoft Printer Spooler Service
searchindexer.exe Microsoft search indexer
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
svchost.exe Microsoft Service Host Process (Check path in processdeep)
sqlwriter.exe Microsoft SQL Server
tabtip.exe Microsoft Tablet PC Module
winlogon.exe Microsoft Windows Logon Process
wmiprvse.exe Microsoft Windows Management Instrumentation
wmiprvse.exe Microsoft Windows Management Instrumentation
unsecapp.exe Microsoft Windows Management Instrumentation
unsecapp.exe Microsoft Windows Management Instrumentation
smss.exe Session Manager Subsystem
wininit.exe Vista background service launcher
dwm.exe Vista Desktop Window Manager
vmnetdhcp.exe VMnet DHCP service
vmware-authd.exe VMWare Authentication Module
vmnat.exe VMware NAT Service
WUDFHost.exe Windows Driver Foundation
WUDFHost.exe Windows Driver Foundation
explorer.exe Windows Explorer Shell
services.exe Windows Service Controller
wlanext.exe Windows Wireless LAN Framework
[*] Module Complete
.Example
List only security related processes and save them to a file
PS C:\> Invoke-ProcessScan -Path security.csv
[*] Starting AV Scan
ProcessName Description
----------- -----------
cmdagent.exe !!! Comodo Firewall Pro !!!
system.exe !!! LanAgent Monitoring !!!
[*] Data exported to security.csv
[*] Module Complete
.LINK
http://www.mdsec.co.uk
#>
Param (
[Parameter(Position = 0)]
[Boolean]
$SecurityOnly = $True,
[Parameter(Position = 1)]
[String]
$Path = $null
)
Write-Output "[*] Starting Process Scan"
if ($SecurityOnly){
Write-Output "[*] Scanning for Security related processes only"
}
$processlist = Get-Process
$processlist = $processlist | Select -Property ProcessName
$badprocs = "-1269619923.exe: ??? Backdoor.W32.Bionet ???
0.exe: ??? Trojan.W32.MyTob ???
000stthk.exe: Toshiba Hotkey Configuration
004.exe: ??? Trojan.W32.Randsom ???
005.exe: ??? Trojan.W32.Randsom ???
006.exe: ??? Trojan.W32.Randsom ???
007.exe: ??? Trojan.W32.Randsom ???
007ssinstall.exe: 007 Spy Software
008.exe: ??? Trojan.W32.Randsom ???
009.exe: ??? Trojan.W32.Randsom ???
00thotkey.exe: Toshiba Keyboard Helper
01dopewars_update.exe: ??? Adware.W32.Cydoor ???
01logo.exe: ??? Downloader.W32.Swizzor ???
1.exe: ??? Trojan.W32.Tooso ???
1004270.exe: ??? Download.Adware ???
1054571.exe: ??? Downloader.W32.Intexp ???
123bar.exe: ??? Spyware.W32.123bar ???
123dl.exe: ??? Spyware.W32.123bar ???
123downloadsuk[1].exe: 123Mania Hijacker
123hiddensender.exe: ??? 123 Hidden Sender Spyware ???
12nail.exe: ??? ABetterInternet Spyware ???
12popup.exe: 12Ghosts Popup-Killer
13.exe: ??? Backdoor.W32.Prorat ???
153.exe: ??? Dialer.W32.153 ???
180.exe: ??? 180SearchAssistant Spyware ???
180ax.exe: ??? TROJ.ISTZONE.H Virus Trojan ???
180pack6480.exe: ??? 180Solutions Spyware ???
180sa.exe: ??? 180SearchAssistant Spyware ???
180sainstaller.exe: ??? 180SearchAssistant Spyware ???
180sainstalleradperform.exe: 180Solutions Zango
180sainstallernusac.exe: 180SearchAssistant
180sainstallersca.exe: ??? 180Solutions Spyware ???
180sainstallersilsais1.exe: ??? 180SearchAssistant Spyware ???
180stuninstaller.exe: ??? 180Solutions Spyware ???
1950.exe: ??? Adware.W32.SpySheriff ???
1cv7.exe: Billing database software
1cv7s.exe: 1C v7 Enterprise Software
1cv8.exe: 1C v8 Enterprise Software
1xconfig.exe: SCM MicroSystems Helper
2.exe: ??? Trojan.W32.Lineage ???
2.sfx.exe.exe: ??? Trojan.W32.Lineage ???
2005.exe: ??? Backdoor.W32.2005-exe ???
202_app13.exe: ??? Adware.W32.PacerD ???
2eq.exe: ??? Downloader.W32.Swizzor ???
2GISTrayNotifier.exe: 2GIS Tray Icon (Russian telecom mapping software)
2portalmon.exe: 2wSysTray
2search.exe: ??? 2Search Spyware ???
3.exe: ??? Downloader.W32.Agent ???
30.exe: ??? 180Solutions Spyware ???
33.exe: ??? Adware.W32.WinTools ???
34yf28fg.exe: ??? 180Solutions Spyware ???
360Amigo.exe: 360Amigo System Speedup
360leakfixer.exe: !!! 360_Safe !!!
360rp.exe: !!! 360 Antivirus !!!
360RP.exe: !!! 360 Antivirus !!!
360rp.exe: !!! 360 Antivirus !!!
360RP.exe: !!! 360 Antivirus !!!
360Safe.exe: !!! 360_Safe !!!
360safe.exe: !!! 360_Safe !!!
360SD.exe: !!! 360 Antivirus !!!
360sd.exe: !!! 360 Antivirus !!!
360tray.exe: !!! 360_Safe !!!
38.exe: 75175 Port Changer Port Changer
3capplnk.exe: 3capplnk
3cdminic.exe: 3cdminic
3cmcnkw.exe: ??? Unknown ???
3cmlnkw.exe: 3cmlnkw
3dClip.exe: 3D Clipboard
3deepctl.exe: 3Deep e-colour
3dfxman.exe: ??? Unknown ???
3dldemon.exe: 3DLabsHelperDemon
3dlman.exe: 3Dlabs Taskbar Display Manager
3dm2.exe: 3DM 2 Web Interface
3dxsrv.exe: 3DxWare Driver
3p_1.exe: ??? Spyware.W32.DyFuCA ???
44088711.exe: ??? Adware.W32.VirtualBouncer ???
470760544.jpg.exe: ??? Backdoor.W32.AimBot ???
4C0F.tmp: ??? W32/Sdbot.worm.gen.y ???
4C0F.tmp: ??? W32/Sdbot.worm.gen.y ???
50cent.exe: ??? Backdoor.W32.Rbot ???
5mrtg.exe: MRTG Launcher
6010RMT.exe: TV Card Remote Control Device Monitor
63mm.exe: ??? Adware.W32.DelFin ???
666.exe: ??? Trojan.W32.MyTob ???
713962.exe: ??? Adware.W32.ESyndicate ???
74BE16.EXE: ??? W32/Autorun.worm.ev ???
7a3ce975.exe: ??? Trojan.W32.AIMVision ???
7i24IISMonitor.exe: IIS Monitor
7nail.exe: ??? ABetterInternet Spyware ???
7uqj7z9a.exe: ??? Adtomi Spyware ???
7WAY.EXE: 7Way Email Checker
8169DIAG.exe: Realtek Diagnostics Utility
8nail.exe: ??? ABetterInternet Spyware ???
959AC.com: ??? W32/Sality.y - malware ???
[system process]: System Idle Process
_avpm.exe: Anti virus?
_koss.exe: SIEMENS
_simpcmon.exe: Siemens Simatic Net process
a.exe: ??? Potential Malware ???
a0011142.exe: ??? Adware.W32.VirtualBouncer ???
a006.exe: ??? Adware.W32.Claria ???
a0067423.exe: ??? Adware.W32.Claria ???
a0067428.exe: ??? Adware.W32.Claria ???
a4proxy.exe: A4Proxy
a64sddd.exe: ??? Adware.W32.Network1 ???
a65d.exe: ??? Downloader.W32.Intexp ???
aagnmsvc.exe: SIEMENS
AASUpdates.exe: Alfa Active Services
aawservice.exe: !!! Lavasoft Ad-Aware !!!
ab.exe: Argentum Backup
abbyynewsreader.exe: ABBYY Community Agent
abg-aceh.exe: ??? Trojan.W32.Boetac ???
aboard.exe: Activboard Application
abonent.exe: InterSystems MSM Workstation
abox.exe: ??? Spyware.W32.Abox ???
abrir_cartao.exe: ??? Dialer.W32.Downloader ???
abs.exe: ??? Trojan.Esteems.E ???
AbsoluteFTP.EXE: Absolute FTP
absr.exe: ??? Backdoor.Autoupder Virus Virus Trojan ???
abyssws.exe: AbyssWebServer
ACAAS.exe: !!! AhnLab !!!
acad.exe: AutoCAD 2009
ACAEGMgr.exe: !!! AhnLab !!!
acaif.exe: !!! AhnLab !!!
ACAIS.exe: !!! AhnLab !!!
acbtnmgr_xxx.exe: AcBtnMgr_Xxx
accagnt.exe: AOL Computer Check-Up
accelerate.exe: Accelerate
accelerometerST.exe: HP Systemtray
access members area.exe: ??? Dialer.W32.GBDialer ???
access.exe: ??? Adware.InstantAccess Spyware ???
accoca.exe: ActiveIdentity, credential Mngr
Account.exe: Payvast Accounting System
accrdsub.exe: ActiveIdentity, credential Mngr
acctmgr.exe: !!! Symantec !!!
AcctMgr.exe: !!! Symantec !!!
accwiz.exe: Microsoft Accessibility Wizard Module
ACDSee11.exe: ACDSee 11.0
ACDSee32.exe: ACDSee Image Management Software
acespy331t.exe: ??? Ace Spy Spyware ???
acevents.exe: ActiveIdentity, credential Mngr
aclient.exe: !!! Altiris remote login client !!!
AClntUsr.EXE: !!! Altiris Client !!!
aclservice.exe: ??? Trojan.Gurepirls ???
acmonitor_xxx.exe: Jetsoft for Lexmark
acombo3d.exe: Acombo3dmouse
aconti.exe: ??? aconti trojan ???
aconti.exe: ??? aconti trojan ???
acprfmgrsvc.exe: Ac Profile Manager Service
acroaum.exe: Adobe Acrobat Updater
acrobat elements.exe: Adobe Acrobat Elements
Acrobat.exe: Adobe Acrobat
acrobat.exe: Adobe Acrobat
acrobat_sl.exe: Adobe Acrobat Speed Launcher
acrodist.exe: Adobe Acrobat Distiller
AcroRd32.exe: Adobe Acroread
acrord32.exe: Acrobat Reader
AcroRd32Info.exe: Adobe Reader
acrotray.exe: Acrobat Assistant
AcroTray.exe: Adobe Acrobat Helper
ACS.exe: ??? Unknown ???
acs.exe: Atheros Wireless LAN
ACS_ACSC_Logmaint.exe: AP/ACS Switch Control
ACS_ALH_Exec.exe: AP/ACS Switch Control
acs_alog_bufman.exe: AP/ACS Switch Control
acs_alog_main.exe: AP/ACS Switch Control
acs_alog_seclog.exe: AP/ACS Switch Control
acs_alog_sysmon.exe: AP/ACS Switch Control
ACS_CHB_ClockSyncService.exe: AP/ACS Switch Control
ACS_CHB_HeartBeat.exe: AP/ACS Switch Control
ACS_CHB_HeartBeatChild.exe: AP/ACS Switch Control
acs_dsdaemon.exe: AP/ACS Switch Control
acs_emf_server.exe: AP/ACS Switch Control
ACS_FCH_Server.exe: AP/ACS Switch Control
ACS_FCR_Server.exe: AP/ACS Switch Control
ACS_MSD_service.exe: AP/ACS Switch Control
ACS_MSD_service.exe: AP/ACS Switch Control
acs_nsf_server.exe: AP/ACS Switch Control
ACS_PRC_ClusterControl.exe: AP/ACS Switch Control
ACS_PRC_EventAnalyser.exe: AP/ACS Switch Control
ACS_PRC_IspService.exe: AP/ACS Switch Control
ACS_RTR_service.exe: AP/ACS Switch Control
ACS_SFC_Recovery.exe: AP/ACS Switch Control
ACS_SSU_Monitor.exe: AP/ACS Switch Control
acs_ssu_monitor.exe: AP/ACS Switch Control
ACS_USA_SyslogAnalyser.exe: AP/ACS Switch Control
acsd.exe: Aol Connectivity Service
ACSPostUnitSrv.exe: Access Supervisory Controller
acsvc.exe: Access Connections Main Service
act.exe: Microsoft Application Center Test
actalert.exe: ??? DYFUCA.H Spyware ???
actionagent.exe: Dell OpenManage Client Instrumentation
activation.exe: activation
activeds.exe: ??? Adsrve Spyware ???
activeeyes.exe: ActiveEyes
activemenu.exe: ??? ActiveMenu Spyware ???
activeplus.exe: ??? ActivePlus Spyware ???
activex_300_it.exe: ??? Downloader.W32.Small ???
activitydisk.exe: SmartSoft ActivityDisk
actmovie.exe: Microsoft Active Movie
actray.exe: ThinkVantage access connections status icon
actserv.exe: Radmin Activation Server
actualspy.exe: ??? spyware.w32.ActualSpy ???
actx1.exe: ??? Adware.W32.AdClicker ???
acu.exe: Atheros Client Utility
acwlicon.exe: ThinkVantage wireless status icon
ad-aware.exe: ??? Ad-aware Anti-Spyware ???
Ad-Aware2007.exe: !!! Lavasoft Ad-Aware !!!
ad-watch.exe: Ad-watch
Ad-Watch.exe: Lavasoft Ad-Aware
ad.exe: ??? Adware.W32.sqwire ???
ad2kclient.exe: AD2KClient
AD_Sync.exe: Active Directory Synch
adaware.exe: ??? foobin lptt01 ???
adblck.exe: ??? BrowserPal Spyware ???
adblock.exe: PC Power Suite
adblocker.exe: 3B Ad Blocker Pro
adbltzun.exe: ??? ABetterInternet Spyware ???
adc.exe: XemiCo Active desktop calendar
addestroyer.exe: ??? AddDestroyer Spyware ???
addestroyerinner.exe: ??? Adware.W32.PacerD ???
addictivetech.exe: ??? Dialer.W32.Downloader ???
addrbook.exe: addrbook
AddressExport.exe: !!! 360_Safe !!!
adg.exe: ADG
adgjdet.exe: ADGJdet
adiras.exe: ADSL USB Modem Helper
adl_dh.exe: ??? Adware.W32.DealHelper ???
adl_mteststub.exe: ??? Adware.W32.DelFin ???
adlinstallwin32.exe: ??? Adware.W32.AdLogix ???
admanctl.exe: Admanager Controller
AdManCtl.exe: ??? Admanager Controller Spyware ???
admillikeep.exe: ??? Admilli Service Adware Spyware ???
admilliserv.exe: ??? Admilli Service Adware Spyware ???
admin.exe: Microsoft Mail Admin Program
ADMIN.EXE: Microsoft Mail Admin Program
Administrator.exe: !!! Entensys UserGate 5 !!!
AdminServer.exe: !!! Panda !!!
AdminW.exe: CCMail Admin Program
admlib32.exe: ??? ADM Library Loader ???
admunch.exe: Ad-Muncher
adobe gamma loader.exe: Adobe Gamma Loader
Adobe_Updater.exe: Adobe Updater
AdobeARM.exe: Adobe ARM 1.0
adobedownloadmanager.exe: Adobe Download Manager
adobelm_cleanup.0001: Adobe Acrobat Cleanup Agent
adobelmsvc.exe: Adobe System Level Service Utility
adobes.exe: ??? AdobeA ???
AdobeUpdateManager.exe: Adobe Update Manager
adobeupdatemanager.exe: Adobe Update Manager
adp.exe: ??? adp Spyware ???
adp8035.exe: ??? Adware.W32.BargainBuddy ???
adperform180safull.exe: ??? 180Solutions Spyware ???
adservice.exe: Active Disk Service
adsetup.silent.1.13.exe: ??? Spyware.W32.BHO ???
adsgone.exe: AdsGone
AdskCleanup.0001: AutoCAD 2009
adskscsrv.exe: Autodesk Licensing Service
adsl autoconnect.exe: ADSL Autoconnect
adss.exe: ADSS
adstatkeep.exe: ??? AdStatus Service Spyware ???
adstatserv.exe: ??? Adstat Internet Explorer Hijacker Spyware ???
adsub.exe: AdSubtract
AdtAgent.exe: Microsoft Audit Collection services
adtech2005.exe: ??? Adware.W32.Adtech ???
adtech2006.exe: ??? Trojan-Clicker.Win32.VB.kc ???
adtray.exe: ADQuickAccess
ADTVScheduleAgent.exe: TV Expert Publisher Schedule Agent
ADTVScheduleAgent.exe: TV Expert Publisher Schedule Agent
adupdater.exe: ??? Adware.W32.AdLogix ???
adusermon.exe: Active Disk User Monitor
adv.exe: ??? Adware.W32.BargainBuddy ???
Advanced-CPU-Load.exe: Solarwinds tool
advapi.exe: ??? Advapi ???
advchk.exe: Advanced Tools Check
adx.exe: ??? Adware.W32.BargainBuddy ???
AEADISRV.EXE: Andrea Filters APO Access Service
aelaunch.exe: AELaunch
aes_afp_server.exe: AP/AES Switch Control
aes_cdh_server.exe: AP/AES Switch Control
aes_dbo_server.exe: AP/AES Switch Control
AESecurityService.exe: MS Content Management Service
aestsrv.exe: Andrea Filters APO Access Service
AeXAgentUIHost.exe: !!! Altiris Agent !!!
aexnsagent.exe: !!! Altiris Agent !!!
AeXNSAgent.exe: !!! Altiris Agent !!!
AeXNSRcvSvc.exe: !!! Altiris !!!
aexplore.exe: AOL Explorer
aexsvc.exe: !!! Altiris !!!
aexswdusr.exe: !!! Altiris Express NS Client Manager !!!
afaagent.exe: adaptec raid controller
afaagent.exe: Adaptec SMBE Raid Controller
afcdpsrv.exe: Acronis CDP
aflogvw.exe: !!! AhnLab Spy Zero !!!
afwServ.exe: !!! Avast Firewall Service !!!
agdbserver.exe: HP OpenView
agent.exe: Dell Agent
agentsrv.exe: Replica Remote Server Files
AgentSVC.exe: Citrix VM Server
agentsvr.exe: Microsoft Agent Server
AGENTSVR.EXE: Microsoft Agent Server
agfaclnk.exe: AgfaCLnk
agntsrvc.exe: Oracle process
agntsvc.exe: Oracle process
agquickp.exe: ActivCard Gold
agrsmmsg.exe: Agere Systems Software Modem Driver
AGRSMMSG.exe: Agere Systems Software Modem Driver
agrsmsvc.exe: Agere Soft Modem Call Progress Service
agsatellite.exe: AGSatellite
agtnt.exe: Axent Intruder Alert?
agtrep.exe: HP OpenView
agtserv.exe: Atomica Online Service
AgtServ.exe: Atomica Online Service
ahadp.exe: ??? Adware.W32.BargainBuddy ???
ahfp.exe: Advanced Hide Folders
ahnrpt.exe: !!! AhnLab Spy Zero !!!
ahnsd.exe: !!! AhnLab !!!
ahnsdsv.exe: !!! AhnLab !!!
ahqinit.exe: Soundblaster AHQInit
Ahqtb.exe: SoundBlaster Audio HQ
AHQTB.EXE: SoundBlaster Audio HQ
ahqtb.exe: AudioHQ
aiepk.exe: Another Internet Explorer Popup Killer
aiepk2.exe: Another IE Popup Killer
AIM.EXE: AOL Instant Messenger
aim.exe: AOL Instant Messenger
aim6.exe: AOL Service Libraries
aim95.exe: AOL Instant Messenger
aimaol.exe: ??? aimaol lptt01 ???
aimingclick.exe: AimingClick
AIMS_M~1.EXE: ArcIMS Monitor
AIMS_T~1.EXE: ArcIMS Monitor
airgcfg.exe: d-link airplus g
airplus.exe: WLAN Adapter Utility
airpluscfg.exe: D-Link AirPlus Xtreme G Wireless LAN Monitor
airsvcu.exe: Media Manager Indexer
ait: AIT Advanced Intelligent Tape)
ajrpbi.exe: ??? Adware.W32.DealHelper ???
AKELPAD.EXE: Total Commander
akiller.exe: AKiller
al_ads~1.exe: Active Defense Shield
alarm.app.exe: Alarm Manager
AlarmApp.exe: Alarmapp
alarmapp.exe: Palm Desktop Alarm Application
alarmgen.exe: HP OpenView
alarmhost.exe: IS3 Satcom/Telecom Software
alarmwatcher.exe: Synaptics cPad
alaunch.exe: Acer Launch Tool
alcfdrtm.exe: Realtek Audio Module
alchem.exe: ??? Adware.ClickAlchemy ???
Alchem.exe: ??? Adware.ClickAlchemy Spyware ???
alcmtr.exe: Realtek Event Monitor
alcwzrd.exe: RealTek Audio Driver Component
ALCWZRD.EXE: RealTek Audio Driver Component
alcxmntr.exe: AlcxMonitor
aldaemon.exe: Avance Daemon Application
ALERT.EXE: !!! CA eTrust Integrated Threat Management 8.1/CA Jinchen Kill !!!
alerter: Windows Alerter Service
AlertingEngine.exe: SolarWinds Orion
alertServer.exe: Backup Exec 8.x Alert Server
alertserver.exe: Backup Exec 7.x/8.x Alert Server
AlertSvc.exe: !!! Symantec !!!
ALERTSVC.EXE: !!! Symantec !!!
alertsvc.exe: !!! Symantec !!!
alevir.exe: ??? Opaserv-A Worm ???
AlfaActiveServices.exe: Alfa Active Services
alg.exe: Application Layer Gateway Service
alg32.exe: *** DISABLEVALOR ***
almappx.exe: Siemens License Manager run script siemens.eps)
ALMon.exe: !!! Sophos Anti-Virus !!!
almsrvx.exe: Siemens Step7 process
almsrvx.exe: Siemens WinCC process
AlmXpmgr.exe: Siemens WinCC process
almxptray.exe: almxptray
alogserv.exe: !!! McAfee VirusScan Activity Log Server !!!
AlogServ.exe: !!! McAfee VirusScan Activity Log Server !!!
alp2plib.exe: ??? Adware.W32.DelFin ???
alsvc.exe: !!! Sophos Anti-Virus AutoUpdate !!!
ALsvc.exe: !!! Sophos Anti-Virus AutoUpdate !!!
alt.exe: ProcView
ALUNotify.exe: !!! Symantec !!!
alunotify.exe: !!! Symantec !!!
ALUpdate.exe: !!! Sophos Anti-Virus AutoUpdate !!!
aluschedulersvc.exe: !!! Symantec !!!
AluSchedulerSvc.exe: !!! Symantec !!!
am32.exe: Action Manager 32
ambroker.exe: MCI GUI or Employer eServices
AMGRSRVC.EXE: NAI Alert Manager
amgrsrvc.exe: NAI Alert Manager
AmIMaple.exe: Keyboard Layout Switcher
amoumain.exe: Wireless mouse driver
amovie.ocx: ActiveMovie Control
amp2pl.exe: ??? Adware.W32.P2PNetworking ???
amqhasmn.exe: GTS diplomatic comms system
amqmsrvn.exe: GTS diplomatic comms system
amqmtbrn.exe: GTS diplomatic comms system
amqpcsea.exe: GTS diplomatic comms system
amqrmppa.exe: IBM WebSphere MQ
amqrrmfa.exe: GTS diplomatic comms system
amqsvc.exe: GTS diplomatic comms system
amqxssvn.exe: GTS diplomatic comms system
amqzdmaa.exe: IBM WebSphere MQ
amqzfuma.exe: GTS diplomatic comms system
amqzlaa0.exe: GTS diplomatic comms system
amqzllp0.exe: GTS diplomatic comms system
amqzxma0.exe: GTS diplomatic comms system
AMService.exe: Force Computers GmbH AM Services
AmService.exe: Force Computers GmbH AGM18 Cloner
amswmagt: !!! CA eTrust Integrated Threat Management 8.1 !!!
anbmserv.exe: Acer Empowering Manager
angelex.exe: ??? Adware.W32.BargainBuddy ???
anonantispyware.exe: ??? Anonymizer Anti-Spyware ???
anote.exe: ActiveNote
ANS.exe: SC Alarm Notification Service
ANSProxyServer.: SC ANS Proxy Server
ANSProxyServer.exe: Switch Commander Application
answers.exe: 1-Click Answers Client
anti_troj.exe: ??? Trojan.W32.Lodear ???
antiarp.exe: !!! 360_Safe !!!
antiav.exe: ??? Rusty\@m Worm ???
antiav_exe.exe: ??? Trojan.Lodav.A/B Trojan ???
AntigenIMC.exe: Microsoft Antigen for Exchange
AntigenInternet.exe: Microsoft Antigen for Exchange
AntigenMonitor.exe: Microsoft Antigen for Exchange
AntigenRealtime.exe: Microsoft Antigen for Exchange
AntigenService.exe: Microsoft Antigen for Exchange
AntigenStore.exe: Microsoft Antigen for Exchange
antirelay.exe: AntiRelay antispam program
antispy.exe: ??? Adware.W32.VirtualBouncer ???
antivirus update.exe: ??? W32.Erkez.G\@mm Worm ???
antivirus32.exe: ??? Trojan.W32.Opanki ???
antivirusgold.exe: ??? Adware.W32.AntivirusGold ???
AntStatsServ.exe: Microsoft Antigen for Exchange
AnVir.exe: !!! AnVir.exe !!!
anvshell.exe: ASUS Display Driver
anydvd.exe: SlySoft AnyDVD
aocbhm.exe: ??? Adware.W32.DealHelper ???
aol.exe: AOL.EXE Hoax
AOLacsd.exe: AOL Connection Driver
aolacsd.exe: AOL Connection Driver
aoldial.exe: AOL Unassisted Dialler
AOLDial.exe: AOL Unassisted Dialler
aolhos~1.exe: AOL Host Manager
Aolnsrvr.exe: Intel Server Manager
AOLServiceHost.exe: AOL Service Host
aolservicehost.exe: AOL Service Host
aolsoftware.exe: AOL Service Libraries
aolsp scheduler.exe: AOLSP Scheduler
aolspscheduler.exe: ??? AOL Spyware Protection ???
aolssc.exe: AOL Service Libraries
aoltbServer.exe: AOL toolbar
aoltpspd.exe: AOL TopSpeed
aoltray.exe: Aoltray
aoltsmon.exe: AOL TopSpeed Component
aom.exe: Adobe WebUpdater
aornum.exe: ??? Aornum Spyware ???
ap0.exe: ??? Backdoor.W32.bifrose ???
ap2.exe: ??? Backdoor.W32.bifrose ???
ap9h4qmo.exe: ??? ShopAtHomeSelect Spyware ???
AP_Mgr.exe: Infosec Continent Client VPN
Apache.exe: Apache Webserver
apache.exe: Apache Webserver
apachemonitor.exe: Apache HTTP Server
apcht2kw.exe: Apache Web Server
apclclient.exe: SC AutoPatch process
apclservice.exe: SC AutoPatch Notification Service
apcommunication: SC AutoPatch process
apcommunication.exe: Switch Commander Application
apcsystray.exe: APC PowerChute
apd123.exe: ??? Adware.W32.PacerD ???
apdproxy.exe: Adobe Photoshop Album
apev.exe: ??? Adware.W32.Cashback ???
aphost.exe: !!! TrendMicro Infrastructure !!!
api.exe: Novell Groupwise?
apmediumscan.ex: SC AutoPatch Medium Scan
apntex.exe: Alps Pointing-device Driver
apoint.exe: Alps Pointing-device Driver
app.exe: ??? Adware.W32.RapidBlaster ???
AppleMobileDeviceService.exe: Apple Mobile Device Service
ApplicationUpdater.exe: Application Updater
appmgr.exe: Microsoft Application Manager
appservices.exe: Appservices
appsetup.exe: ??? Downloader.W32.Small ???
APPSR1.EXE: R-Style Application Server1
APPSRV.EXE: R-Style Applicatin Server?
AppSvc32.exe: !!! Symantec !!!
aps.exe: !!! Outpost Security !!!
apsubjectcontro: SC AutoPatch process
apsubjectcontrol.exe: Switch Commander Application
apsvcae.exe: BMC Remedy Action Request System
aptaskhandler.e: SC AutoPatch Task Handler
aptaskhandler.exe: Switch Commander Application
aptezbp.exe: Aptezbp
apvxdwin.exe: !!! Panda Internet Security !!!
aq3setupstandard.exe: ??? Adware.W32.Claria ???
aqadcup.exe: ??? Backdoor.Agent.bg ???
aqagent.exe: Adaptec Application Quiesce Agent
aquariumdesktop.exe: Stardock Aquarium Desktop
AquariumDesktop.exe: Stardock Aquarium Desktop
aradmin.exe: AR Remedy Ticket
ARCGIS.EXE: ArcGIS Mapping Software
archive.exe: ??? BW-based Spyware ???
ArchService.exe: IS3 Satcom/Telecom Software
arcmdbd.exe: BMC Remedy Action Request System
arcpd.exe: Adaptec SMBE Raid Controller
arcsas.exe: SAS Raid Driver
aremaild.exe: AR Remedy Ticket
ares.exe: Ares Peer-to-peer File Sharing
arflashd.exe: Remedy AR System (HelpDesk)
ARGUS.EXE: Argus FIDONet Mailer?
armon32.exe: Access Ramp Monitor
armon32a.exe: AccessRamp Monitor
armonitor.exe: BMC Remedy Action Request System
ARP.EXE: ARP.EXE Adress resolution command
arplugin.exe: BMC Remedy Action Request System
arpwrmsg.exe: AlwaysReady Power Message APP
arr.exe: ??? Dialer.Lohan ???
arr.exe: ??? Dialer.Lohan ???
arr.exe: ??? Dialer.Lohan ???
arrecond.exe: BMC Remedy Action Request System
arserver.exe: Remedy ARServer
arservice.exe: Media Center Away Mode Service
arsvcdsp.exe: BMC Remedy Action Request System
arupdate.exe: ??? Adware.W32.AdRoar ???
ARUpdate.exe: ??? Adroar Spyware ???
arupld32.exe: ??? Arupld32 Spyware ???
aruser.exe: Remedy AR System (HelpDesk)
as.exe: Ascentive ActiveSpeed
ASA.exe: Avaya Site Administration
AsAlert.exe: BrightStor ARCserve Backup
ASC.EXE: Access Supervisory Controller
ASCDBAgentSrv.exe: Access Supervisory Controller
ASCPassSrv.exe: Access Supervisory Controller
ASCPassTemplate.exe: Access Supervisory Controller
ASCPhotoEditorS.exe: Access Supervisory Controller
ASCReaderSrv.exe: Access Supervisory Controller
ASCService.exe: Access Supervisory Controller
ASCTieCheckerSr.exe: Access Supervisory Controller
ASCWiperSrv.exe: Access Supervisory Controller
asd.exe: SC process
asdscsvc.exe: ARCserveIT Discovery Service
ASDscSvc.exe: ARCserveIT Discovery Service
asfagent.exe: Intel Alert Standard Format Console
ASFAgent.exe: Dell OpenManage software
asfpprov.exe: Intel Server Manager
asfproxy.exe: Intel Server Manager
asghost.exe: Cognizance Identity and Access Management
ashAvast.exe: !!! Avast !!!
ashBug.exe: !!! Avast !!!
ashChest.exe: !!! Avast !!!
ashCmd.exe: !!! Avast !!!
ashdisp.exe: !!! Avast !!!
ashDisp.exe: !!! Avast !!!
ashDisp.exe: !!! Avast !!!
ashEnhcd.exe: !!! Avast !!!
ashLogV.exe: !!! Avast !!!
ashmaisv.exe: !!! Avast !!!
ashMaiSv.exe: !!! Avast !!!
ashPopWz.exe: !!! Avast !!!
ashQuick.exe: !!! Avast !!!
ashserv.exe: !!! Avast !!!
ashServ.exe: !!! Avast !!!
ashSimp2.exe: !!! Avast !!!
ashSimpl.exe: !!! Avast !!!
ashSkPcc.exe: !!! Avast !!!
ashSkPck.exe: !!! Avast !!!
ashUpd.exe: !!! Avast !!!
ashwebsv.exe: !!! Avast !!!
ashWebSv.exe: !!! Avast !!!
askernel.exe: Aluria AntiVirus
asm.exe: ??? AltNet Spyware ???
ASMGR.exe: ARCserve
asmonitor.exe: ??? Spyware.w32.ActualSpy ???
asmproserver.exe: Adaptec Storage Manager Pro Server
ASMProServer.exe: Adaptec Storage Manager Pro Server
aspi_me.exe: Adaptec ASPI Driver
aspnet_admin.exe: Microsoft ASP.NET Admin Service
aspnet_state.exe: ASP State Service
aspnet_wp.exe: Microsoft asp.net
ASPNET_WP.exe: Microsoft asp.net
AsrSrvc.Exe: AsrSrvc
asrsrvc.exe: AsrSrvc
ASS.exe: SC Alarm Storage Service
astart.exe: ASUS TweakEnable
asupport.exe: !!! TrendMicro !!!
asuskbservice.exe: ASUS Keyboard Service
asusprob.exe: ASUS Motherboard Probe
aswDisp.exe: !!! Avast !!!
aswRegSvr.exe: !!! Avast !!!
aswServ.exe: !!! Avast !!!
aswupdsv.exe: !!! Avast !!!
aswUpdsv.exe: !!! Avast !!!
aswUpdSv.exe: !!! Avast !!!
aswWebSv.exe: !!! Avast !!!
ASYNC.EXE: Microsoft Mail Connector?
at.exe: AT.EXE NT Scheduling Command
atchk.exe: Intel Management Technology Status Messages
atchksrv.exe: Intel Management Technology System Status Service
Athan.exe: Islamasoft Prayer Time Calculator and Reminder
athoc.exe: \@hoc Browsing
ati2cwad.exe: ATI Display Adapter Assistant
ati2cwxx.exe: ATI Display Adapter Assistant
ati2evxx.exe: ATI External Event Utility EXE Module
ati2mdxx.exe: ATI Technologies Process
ati2plab.exe: Ati2plab
ati2plxx.exe: ATI Display Adapter Assistant
ati2ptxx.exe: ATI Display Adapter Assistant
ati2s9ag.exe: ATI Display Adapter Assistant
ati2sgag.exe: ATI Display Adapter Assistant
aticwd32.exe: Aticwd32
atidtct.exe: ATI Device Detection Application
atieclxx.exe: ATI Graphics Control Panel
atiesrxx.exe: AMD External Events Utility
atievxx.exe: ATI External Event Utility
ATIevxx.exe: ATI External Event Utility
atipta.exe: ??? W32/Antinny-G Virus ???
atiptaab.exe: ATI Utilitiy
atiptaxx.exe: ATI Video Control Software
atirw.exe: ATI Remote Wonder
atisched.exe: ATI Video Player
atitask.exe: ATI utility
atiupdate.exe: ??? Adtomi Spyware ???
atix10.exe: ATI Remote Wonder Helper
atkkbservice.exe: ASUS Keyboard Service
atkosd.exe: ASUS ACPI Control Driver
atlcustom.exe: ??? Adware.W32.GoGoTools ???
atmclk.exe: ??? Adware.W32.SpyFalcon ???
atrack.exe: Alert Tracker task
AtrsHost.exe: !!! Altiris !!!
AtService.exe: Fingerpint
AtSvc.Exe: NT Scheduling Service
ATSVC.EXE: NT Scheduling Service
atsvc.exe: NT Scheduling Service
atwsctsk.exe: !!! AhnLab V3 Internet Security !!!
atwtusb.exe: Aiptek Graphics Tablet USB)
audevicemgr.exe: Sony Ericsson Phone Connection Monitor
AudiDllHost.exe: SC process
audiodg.exe: Vista audio device graph isolation
audition.exe: Adobe Audition
aufile~1.exe: Teleca File Manager Server
aupdate.exe: Automatic LiveUpdate
aupdate_uninstall.exe: ??? Adware.W32.RapidBlaster ???
aupdrun.exe: !!! Agnirum Outpost Firewall !!!
aurareco.exe: ??? ABetterInternet Spyware ???
aurora(1).exe: ABetterInternet Spyware
aurora-wise1.exe: ??? ABetterInternet Spyware ???
aurora.exe: ??? Aurora Spyware ???
aurora1).exe: ??? ABetterInternet Spyware ???
aus.exe: !!! Outpost Security !!!
ause3-decoded.exe: ??? Spyware.W32.ClientMan ???
ause3.exe: ??? Spyware.W32.ClientMan ???
ausvc.exe: ??? Backdoor.Autoupder virus. Virus Trojan ???
Auth8021x.exe: !!! CA Jinchen KILL / eTrust Antivirus !!!
authfw.exe: Authentium Firewall SDK
authsrv.exe: Internet Authentication Service IAS)
AUTHSRV.EXE: Internet Authentication Service IAS)
autobar.exe: HP Digital Imaging Helper
AutoCfg.exe: Eudora AutoCfg Service
autochk.exe: Autochk
autodown.exe: AntiVirus AutoUpdater
autoexec.exe: ??? Downloader.W32.Haxdoor ???
autoheal.exe: ??? Adware.W32.BargainBuddy ???
autolaunch.exe: Iomega HotBurn Pro
automove.exe: ??? 2nd Thought Spyware ???
AutoPowerOn.exe: Auto Power-On & Shutdown 2.04
autoreg.exe: US Robotics Registration
autorun.exe: Autorun Executable
AutorunRemover.exe: PC Optimizer
autotbar.exe: HP AutoView Toolbar
autotkit.exe: HP Helper Process
autoup.exe: !!! AhnLab !!!
autoupdate.exe: AT&T Hardware Autoupdate
autoupdatev2.exe: ??? Adware.W32.AdClicker ???
aux32.exe: ??? W32.Aizu.G Worm ???
av.exe: ??? W32/Alphx.worm.a ???
av_cleaner.exe: Symantec Brightmail Antispam
avadmin.exe: !!! AVIRA Personal Edition Classic !!!
avant.exe: Avant Browser
AvastSvc.exe: !!! Avast !!!
AvastUI.exe: !!! Avast GUI !!!
avcenter.exe: !!! Avira !!!
avcenter.exe: !!! Avira !!!
avcmd.exe: AntiVir Command Line Scanner for Windows
avconfig.exe: !!! Avira !!!
avconfig.exe: !!! Avira !!!
avconsol.exe: !!! McAfee VirusScan Scheduler !!!
Avconsol.exe: !!! McAfee VirusScan Scheduler !!!
avengine.exe: !!! Panda Anti-Virus !!!
AVENGINE.exe: !!! Panda Internet Security !!!
avEngine.exe: !!! Avast !!!
AVerHIDReceiver.exe: AVerMedia BDA TV Tuner
AVerQuick.exe: AVerMedia BDA TV Tuner
AVerRemote.exe: AVerMedia BDA TV Tuner
AVerScheduleService.exe: AVerMedia BDA TV Tuner
avesvc.exe: !!! Avira !!!
avesvc.exe: !!! Avira !!!
AVExch32.exe: Network Associates GroupShield Exchange
avfwsvc.exe: !!! AVIRA Personal Edition Classic !!!
avgam.exe: !!! AVG 8/8.5 !!!
avgamsvr.exe: !!! AVG !!!
avgas.exe: !!! AVG !!!
avgcc.exe: !!! AVG !!!
avgcc32.exe: !!! AVG !!!
AVGCHSVX.EXE: !!! AVG Internet Security !!!
AVGCSRVX.EXE: !!! AVG Internet Security !!!
avgcsrvx.exe: !!! AVG 8.5 !!!
avgctrl.exe: !!! AVG !!!
avgdiag.exe: !!! AVG !!!
avgemc.exe: !!! AVG !!!
avgfws8.exe: !!! AVG !!!
avgfws9.exe: !!! AVG 9.0 FW !!!
avgfwsrv.exe: !!! AVG !!!
avghalsb.exe: ??? 180Solutions Spyware ???
AVGIDSAgent.exe: !!! AVG 8.5/9.0 IDS !!!
AVGIDSMonitor.exe: !!! AVG 8.5/9.0 IDS !!!
AVGIDSUI.exe: !!! AVG 8.5 IDS !!!
AVGIDSWatcher.exe: !!! AVG 8.5 IDS !!!
avginet.exe: !!! AVG !!!
avgmsvr.exe: !!! AVG !!!
avgnsx.exe: !!! AVG 8/8.5 !!!
AVGNSX.EXE: !!! AVG Internet Security !!!
avgnt.exe: !!! Avira !!!
avgnt.exe: !!! Avira !!!
avgregcl.exe: !!! AVG Registry Cleaner !!!
avgrssvc.exe: !!! AVG !!!
avgrsx.exe: !!! AVG Anti-Virus !!!
avgscanx.exe: !!! AVG !!!
avgserv.exe: !!! AVG !!!
avgserv9.exe: !!! AVG !!!
avgsystx.exe: !!! AVG SysTools !!!
avgtray.exe: !!! AVG Anti-Virus !!!
avguard.exe: !!! Avira AntiVir !!!
avgupd.exe: !!! AVG !!!
avgupdln.exe: !!! AVG !!!
avgupsvc.exe: !!! AVG !!!
avgupsvc.exe: !!! AVG !!!
avgvv.exe: !!! AVG !!!
avgw.exe: !!! AVG !!!
avgw.exe: !!! AVG !!!
avgwb.dat: !!! AVG !!!
avgwdsvc.exe: !!! AVG Anti-Virus !!!
avgwizfw.exe: !!! AVG !!!
AVKProxy.exe: !!! G Data Internet Security 2007 !!!
AVKService.exe: !!! G Data Internet Security 2007 !!!
AVKTray.exe: !!! G Data Internet Security 2007 !!!
AVKWCtl.exe: !!! G Data Internet Security 2007 !!!
avltmain.exe: !!! Panda Titanium !!!
avmailc.exe: !!! Avira !!!
avmailc.exe: !!! Avira !!!
avmcdlg.exe: !!! Avira !!!
avmcdlg.exe: !!! Avira !!!
AVMon32.exe: GroupShield Monitor
avmserv.exe: AltaVista Mail Server
avnotify.exe: !!! Avira !!!
avnotify.exe: !!! Avira !!!
avp.exe: !!! Kaspersky !!!
AVP.exe: !!! Kaspersky !!!
AVP.EXE: !!! Kaspersky !!!
avpcc.exe: !!! Kaspersky !!!
AVPDTAgt.exe: !!! Kaspersky Lab Deployment Tool Agent !!!
avpexec.exe: !!! Kaspersky !!!
avpm.exe: !!! Kaspersky !!!
AvpM.exe: !!! Kaspersky !!!
avpncc.exe: !!! Kaspersky !!!
avps.exe: !!! Kaspersky !!!
avps.exe: !!! Kaspersky !!!
avpupd.exe: !!! Kaspersky !!!
avrmtctr.exe: VAIO Zone Remote Commander
avscan.exe: !!! Avira !!!
avscan.exe: !!! Avira !!!
avsched32.exe: AVSCHED32
avserve.exe: ??? W32/Sasser.a ???
avserve2.exe: ??? W32.Sasser.B/C.Worm ???
avserver.exe: !!! Kerio Winroute Firewall !!!
avshadow.exe: !!! Avira !!!
Avsynmgr.exe: !!! McAfee VirusScan Synchronization Manager !!!
avsynmgr.exe: !!! McAfee VirusScan Synchronization Manager !!!
Avtask.exe: !!! Panda !!!
avwebgrd.exe: !!! AVIRA Personal Edition Classic !!!
avwupsrv.exe: AntiVir Software Update Service for Windows
awe61.exe: Possibly an ORACLE program
awhost32.exe: pcAnywhere Host Service
AWHOST32.EXE: pcAnywhere Host Service
awrem32.exe: PCAnywhere Remote Control Module
awwvcfg.exe: CA Unicenter Network & Systems Management
axlbridge.exe: QuickBooks Module
axlbri~1.exe: QuickBooks Module
b2search_v17.exe: ??? Spyware.W32.BHO ???
b9.exe: Firetrust Benign
babylon.exe: Babylon Translator
Babylon.exe: Babylon Translator
backdoor.prorat.13.exe: ??? Backdoor.W32.Prorat ???
backdoor.prorat.13_(57).exe: ??? Backdoor.W32.Prorat ???
backdoor.prorat.13_57).exe: ??? Backdoor.W32.Prorat ???
backitup.exe: Ahead Back It Up
BackItUp.exe: Ahead Back It Up
BackLog.exe: InterSect Alliance SNARE BackLog Service
BackupNetworkCoordinator.exe: Novosoft Handy Backup
BackupNetworkWorkstation.exe: Novosoft Handy Backup
backupnotify.exe: HP Digital Imaging Component
backweb-137903.exe: HP center
backweb-8876480.exe: Logitech Desktop Messenger
backweb.exe: Automatic Update Program
backWeb.exe: ??? Backweb Adware Spyware ???
BacsTray.exe: Broadcom Advanced Control Suite
bacstray.exe: Broadcom Advanced Control Suite
bagent.exe: Quicken Scheduled Updates
BAMService.exe: MSC BAM Services
Bandoo.exe: Bandoo Toolbar
Bandwidth-Gauges.exe: Solarwinds tool
banmanpro.exe: ??? Adware.W32.BanManPro ???
bargain3.exe: ??? Adware.W32.BargainBuddy ???
bargain4.exe: ??? Adware.W32.BargainBuddy ???
bargainbuddy.exe: ??? Adware.W32.BargainBuddy ???
bargains.exe: ??? Bargains Spyware ???
barsum.exe: Reksoft Barsoom Billing
BarsumCollector.exe: Reksoft Barsoom Billing
bartshel.exe: BartShell Module
BAS-AS.exe: Blackberry software
BAS-NCC.exe: Blackberry software
bascstray.exe: Advanced Control Suite Tray
basebrd.exe: Intel Server Management
basfipm.exe: !!! Broadcom ASF IP monitoring service !!!
bash.exe: Cygwin Console
bass.exe: ??? Unknown ???
batserv2.exe: ??? Trojan.W32.LOCKSKY ???
bb.exe: ??? Backdoor.W32.Rbot ???
BBAttachMonitor.exe: Blackberry software
BBAttachServer.exe: BlackBerry software
bbchk.exe: ??? Adware.W32.BargainBuddy ???
BBConvert.exe: BlackBerry software
BBConvert.exe: BlackBerry software
BBConvert.exe: BlackBerry software
BBConvert.exe: BlackBerry software
bbdevmgr.exe: RIM handheld device manager
bbgdfvdd.exe: ??? W32.Sober.V@mm ???
bbi8015.exe: ??? Adware.W32.BargainBuddy ???
bbi8018.exe: ??? Adware.W32.BargainBuddy ???
bbi8024.exe: ??? Adware.W32.BargainBuddy ???
bbi8032.exe: ??? Adware.W32.BargainBuddy ???
bblauncher.exe: BounceBack
bbnt.exe: Big Brother SNM Client
bboy.exe: ??? Kernel ???
bbui.exe: AOL DSL Status Monitor
bcaaa-120.exe: Blue Coat Authentication and Authorization Agent proxy
bcaaa-130.exe: Blue Coat Authentication and Authorization Agent proxy
bcaaa.exe: Blue Coat Authentication and Authorization Agent proxy
bcaaa_20.exe: Blue Coat Authentication and Authorization Agent proxy
bcb.exe: Borland C++ Builder
bcmntray.exe: Broadcom Network Adapter Wireless Network Tray Applet
bcmsmmsg.exe: BCMSMMSG
BcmSqlStartupSvc.exe: Sql for Outlook 2007
bcmwltry.exe: bcmwltry
BCResident.exe: BC Wipe
bcresident.exe: Jetico BestCrypt
Bct.exe: SC Controller
Bctsched.exe: SC Scheduler
bctstack.exe: SC serial port server
BCU.exe: DeviceVM Browser Configuration Utility
BCUService.exe: DeviceVM Browser Configuration Utility
bcuyfz.exe: ??? Spyware.W32.DyFuCA ???
bcveserv.exe: Jetico BestCrypt Volume Encryption
bdagent.exe: !!! BitDefender Security Suite !!!
BDARemote.exe: USB Video TV Device
bdc.exe: !!! BitDefender Security Suite !!!
bdl14108.exe: ??? 2nd Thought Spyware ???
bdlite.exe: !!! BitDefender Security Suite !!!
bdmcon.exe: !!! BitDefender Security Suite !!!
bdmcon.exe: !!! BitDefender Security Suite !!!
bdnagent.exe: BitDefender News Agent
bdoesrv.exe: Bitdefender 8 Anti-Virus