Home > General > Troj_malagent.fp


Q152404 wsript.exe Q152404.VBS N Appears to run Scandisk at bootup on NEC PCs quicken Winrar.exe X CoolWebSearch parasite variant. RegDone winlogon.exe X Added by the NEVEG.A WORM! This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return MSUpdate wupd.exe X Added by the ALADINZ.M TROJAN! Microsoft System Checkup Wnetlib.exe X Added by the DONK.C WORM! http://songstersoftware.com/general/troj-vb-aml.html

OEPowerPlugs winoeinit.exe ? ?? Microsoft Updaters Pros WINDLL32XP.EXE X Added by the SPYBOTTER.GEN VIRUS! Windows Startup winsta~1.exe X GoHip foistware Windows Startup winstartup.exe X GoHip foistware Windows Startup Wdrun32.exe X Added by the GAOBOT.AO WORM! winhlp32.exe winhlp32.exe X Added by a variant of the EASTO.A TROJAN!

When the downloads have finished, click on Settings. Serv-U wssdsu.exe X Added by the MANIFEST TROJAN! Note - this is NOT the Winamp Media Player (WinAmpa.exe) Winamp media player winapa.exe X Added by an unidentified VIRUS, WORM or TROJAN!

  1. Microsoft IT Update win43.exe X Added by the RBOT-SA WORM!
  2. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
  3. Available as an individual download or as part of Object Desktop.
  4. Normally it won't set itself up to run unless the user specifically adds it to startup winpopup winupie.exe X Adware by Tradeexit.com WinProt Winprot.exe X Added by the CHUPACABRA TROJAN!

Windows Logon winlogin.exe X Added by the SPYBOT-C TROJAN! Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. Rund1l32 Winfi1e32.exe X Added by the MERTIAN WORM! Winhost wintt.exe X Added by the LOLAWEB.B TROJAN!

winmatrix.exe WinMatrixXP.exe U WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop WinMem WinMem.exe U WinMem Cleaner - part SSK Service winssk32.exe X Added by the SOBIG.E WORM! Allows you to back up your system with one click WDInfo wdinfo.exe X Adult content dialler wdskctl wdskctl.exe X IEPlugin spyware wdwctrl wdwctrl.exe X Added by the DLUCA.E TROJAN! Useful utility that deletes safe to remove files, cookies, browsing history, etc.

WG511WLU WG511WLU.exe Y Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card WGWLocalManager WGWLocalManager.exe U Part of Flash-Networks NettGain2000 product. Winahlp.exe Winahlp.exe X Added by a variant of the VAGRNOCKER TROJAN! However, it looks like Kapersky found some problems. Microsoft Windows Updater WINIUPDATES.EXE X Added by the RBOT-KK WORM!

c:\documents and settings\Owner\Application Data\addon.dat c:\program files\altcmd c:\program files\altcmd\uninstall.bat c:\program files\Bifrost c:\program files\Bifrost\klog.dat c:\windows\Downloaded Program Files\setup.inf c:\windows\system32\kmd.exe c:\windows\system32\ms.dll c:\windows\system32\ntnet.drv c:\windows\system32\system32.dll c:\windows\system32\tmp.reg E:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2008-11-27 to 2008-12-27 ))))))))))))))))))))))))))))))) . Windows Update Client wuclient.exe X Added by the SMALL-RN TROJAN! ComTry Web Searcher wstray.exe X Comtry MP3 Downloader related - spyware Config Loadr winsys32.exe X Added by the AGOBOT-HN WORM! WindowsUpd WindowsUpd4.exe X VirtuMonde adware WindowsUpd1 WindowsUpd1.exe X VirtuMonde adware WindowsUpd2 WindowsUpd2.exe X VirtuMonde adware WindowsUpdate windows_update.exe X Added by the LOFNI WORM!

Microsoft Update Machine wuagrd.exe X Added by the RBOT-GF WORM! http://songstersoftware.com/general/troj-agent-cac.html Change the Files of type to Text file (.txt) before clicking on the Save button. WinProxy WinProxy.EXE U "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" winpsd winpsd.exe X Added by the MYDOOM.Q WORM! What Kaspersky found is in the System Restore cache which won't harm you unless you restore the system to an infected date, and will be cleared shortly when we are done

WinDriv32 WinDriv32.exe X Added by the SMALL-BA TROJAN! Windows System Manager winsystem.exe X Added by the RBOT-AN WORM! uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = localhost;*.local TCP: {F843C0CE-CE64-4A2B-83C8-BBDBCFF3AA37} =, FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\68d1fesc.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - check over here Software that optimizes your web browser and is also advertising spyware that you can find out about here webHancer Survey Companion whSurvey.exe X WebHancer foistware - traffic measurement service that uses

blah service winupdate.exe X Added by the GAOBOT.BIA WORM! Windows Update Client Service windrvl32.exe X Added by the AGOBOT-MM TROJAN! Join our site today to ask your question.

This site is completely free -- paid for by advertisers and donations.

The scan will begin and "Scan in progress" will show at the top. WinDSNX Win????.exe X Added by the DNSX TROJAN! Both files are needed to run WeBlocker. Make sure it is set to Instant Notification, then click Subscribe.

SkynetRevenge winlogon.scr X Added by the NETSKY.AA WORM! Touch Manager WinLED.exe U Dell keyboard utility. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. this content NB Windows Patterns WINDBKGND.EXE N Part of McAfee Nuts & Bolts.

Please note that this infection should not be confused with the legitimate Windows file located at %System%\wininit.exe.