| Name | Status | Filename | Description |
|---|
| Gray_Pigeon (GrayPigeon) | X | G_Server2.0.exe | Troj/Hupigon-CH Note: Located in %windir% Read the link, allows remote access |
| Gray_Pigeon_Serve (GrayPigeonServer) | X | G_Server.exe | Added by the Troj/Feutel-I
or Troj/Feutel-AI
TROJAN!
|
| Gray_Pigeon_Server (GrayPigeonServer) | X | G_Server1.2.exe | Added by the Troj/GrayBrd-AP
TROJAN!
Note: This worm\trojan file is found in the Windows or Winnt folder.
|
| Gray_Pigeon_Server1.236 (GrayPigeonServer1.236) | X | G_Server1.236.exe | Troj/Hupigon-RW Read the link, allows remote access |
| Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) | X | G_Server2.0.exe | Added by the Troj/GrayBird-O
TROJAN!
|
| GreenBorder Client Manager Service (clnt_ClientMan) | L | ClientMan.exe | Related to GreenBorder Secure your browsing activities on the internet. Note: Located in C:\Program Files\GreenBorder\ |
| greenstdSystem32 | X | greenstd.exe | Unclassified.Spyware.61
Note: Located in %system%\ |
| GridIron X-Factor After Effects Peer #1 (XFACTORAE1) | L | xlr8d.exe | Related to GridIron Nucleo For digital post production professionals using Adobe® After Effects® on a multi-processor or new multi-core computer |
| Groove Audit Service (GrooveAuditService) | L | GrooveAuditService.exe | Related to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\ |
| Groove Installer Service (GrooveInstallerService) | L | GrooveInstallerService.exe | Related to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\ |
| GrooveRunOnceInstaller | L | GrooveRunOnceInstaller.exe | Related to Groove_Manager_Server from IBM allows administrators with onsite servers to audit Groove client activities Note: Located in \%Program Files%\Groove Networks\Groove\Bin\ |
| Group Policy Client (gpsvc) | L | gpapi.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| GS30s | L | GS30s.exe | Related to Gizmo!_Secure USB flash drive software by Crucial |
| handle (handle) | X | handle.exe | Added by the SDBOT.CDD
WORM!
Read the link, rootkit type stealth involved.
|
| Handling the DHCP requests (DHCP Client) | X | dhcpclient.exe | Most likely a W32.Toxbot_variant
|
| HanWangTablet | L | JWPEN.exe | Related to HanWang_Tablet Hanwang Writing Tablet gives you the power to quickly input handwriting Chinese and Japanese into Microsoft Word, Excel, PowerPoint, MSN, ICQ, WPS and over 100 other software applications easily and pleasurably. Note: Located in \%WINDIR%\System32\ |
| Hardware Clock Driver (hwclock) | X | hwclock.exe | Added by the W32/Hwbot-A
WORM!
|
| Hardware Detection (Serv-U) | X | svchost.exe | Reported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This file is found in the System32\drivers\etc\data\ folder.
|
| Hardware Monitor Service (Hardware Monitor) | X | mshms.exe | Added by the Troj/Wollf-A
TROJAN!
|
| Hardware Monitoring Program (ADMService) | L | admServ.exe | Related to Avocent Embedded Software and Solutions Division |
| Harmony | L | RSOBSERV.EXE | Related to Rockwell_Automation Inc. FactoryTalk suite |
| HASP License Manager (hasplms) | L | hasplms.exe | Related to HASP_License Manager from Aladdin Knowledge Systems. HASP HL is a USB Hardware Key or Dongle based software copy protection solution. Note: Located in \%WINDIR%\System32\ |
| HauppaugeTVServer | L | HCWTVServer.exe HCWTVS~1.EXE | Related to TVServer from Hauppauge Computer Works, Inc. Note: Located in \%Program Files%\WinTV\ |
| haxdrv | X | haxdrv.sys | Added by the Troj/Rootkit-U
TROJAN!
Read the link, rootkit type stealth involved.
|
| hcalway | X | hcalway.sys | Added by the PigSearch
Adware.
Read the link, rootkit type stealth involved.
|
| HDD Information Service (HDDSvc) | L | HDDSvc.exe | Related to HDD_Information Service from Altrixsoft.com Note: Located in \%WINDIR%\System32\ |
| HDDlife HDD Access service | L | hldasvc.exe | Related to Hard_disk Access service. Reads S.M.A.R.T. data from all of your hard drives and allows you to see clearly the health and resources of your disks. Note: Located in \%Program Files%\BinarySense\ |
| Health Key and Certificate Management (hkmsvc) | L | kmsvc.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Help and Support (helpsvc) | X | ineters.exe | Identified as Malware.Gen Note: Located in \%WINDIR%\System32\ |
| Help and Support Service (hasvc) | X | usnsvc.exe | Added by a variant of the SDBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| hexadecimal (HexadecimaRepresentation) | X | Edit.exe | Added by the W32/Sdbot-AAY
WORM!
Note: File name may be different.
Read the link, rootkit type stealth involved.
|
| HF30Service | L | HF30Service.exe | Related to Lock_Folder Password protection for files, folders, and drives. Note: Located in c:\Program Files\Everstrike Software\Hide Folder 3.1\ |
| hgz | X | Hacker.com.cn.exe | Added by a variant of the Troj/Feutel-CJ TROJAN Note: This worm\trojan is located in C:\%WINDIR%\HgzServer\ Folder. |
| Hibernation | L | hibserv.exe | Related to Compaq-Hewlett Packard hibernation service. |
| HICOM LAN Bridge VCapiDrv (vcapidrv) | ? | vcapintsvc.exe | Could be related to a new version of HICOM LAN Bridge? |
| HID Input Service WIN32 (HID_Input_Service_WIN32) | X | msiexecu.exe | Added by the Troj/Raser-AS TROJAN!
Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Creates this file SndSystem.sys which acts as a rootkit. |
| HID Output Service (HODSrv) | X | hpsvc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| HiPath Cardserver (FMCardService) | L | FMCardServ.exe | Related to HiPath service from Siemens. Note: Located in \%Program Files%\Siemens\HiPathCardManager\ |
| HIPS Configuration Interpreter (UmxCfg) | L | UmxCfg.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Event Manager (UmxAgent) | L | UmxAgent.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Firewall Helper (UmxFwHlp) | L | UmxFwHlp.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Policy Manager (UmxPol) | L | UmxPol.exe | Tiny Firewall |
| HiWired Client Core Service (HiWiredCore) | L | HiWired.Client.Core.exe | Related to HiWired_Service from HiWired, Inc. On-line PC services. Note: Located in \%Program Files%\HiWired\PC Check & Connect\ |
| Horario de Windows | L | services.exe | Spanish Windows 2000 "windows time" |
| host (host) | X | host.exe | Added by the Troj/GrayBrd-AR
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder. |
| Host Process for Win32 Services | X | svchost.exe | Added by a variant of the SDBOT Note: Located in \%WINDIR%\system\ Note: Use SDFix under supervision. |
| host Service For Windows (mshost) | X | mshost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Host Services (Host Services) | X | svhosts.exe | Added by the W32/Tilebot-AC
WORM!
Note: This is not the legitimate Windows process svchost.exe (Notice the difference in the spelling.) This worm\trojan file (svhosts.exe) is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Host Services (Host Services) | X | myhost.exe | Added by the W32/Tilebot-AT
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Hosts AOL Network Update Services (AOL Update Service) | X | aolup.exe | Added by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\ |