Global Search

Not sure what a file is? Sort through the possibilities with a quick search of all of the lists.
Or get more accurate results by browsing and searching by list.
CLSID List Results
BHOs, Toolbars, SHs, Explorer Bars

CLSID Name Filename Description Status
{ACBD7024-CF3C-495F-9840-244CD16A5826}Data Collector Toolbarsvchost.dllParasite connecting to letectvi.cz - detected by AntiVir as TR/BHO.HMX BHO
{CAC068F3-A608-406B-8581-458788A67694}Webaccsvchost.dll91Cast adwareX BHO
{F12E3C8F-924C-4447-9D8A-ED97A28C8C8C}Data Collector Toolbarsvchost.dllParasite connecting to letectvi.cz - detected by AntiVir as TR/BHO.HMX BHO
{3A4E6FF3-BF59-446E-9DC8-731BCE2F349A}IE 4.x-5.x BHO in ObjectPascalsvchost.dllPWSteal.Tarno.P trojanX BHO
{FC37E818-6FBF-42F7-8CDE-72B890F493D9}�����msnetres.dll, msnetre.dll, svchost.dllUnidentified parasite of Chinese origin - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!X BHO

Startup List Results
Startup Entry

Name Filename Description Status
Windows Default Configurationsvchost.exeAdded by the Troj/Dloader-U Trojan! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate svchost.exe file which is always found in \%WINDIR%\System32\ - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!X
zztpsvchost.exeAdded by the Trojan.Tannick.B Trojan! Note: Located in \%WINDIR%\System32\zztp\ Note: Do not remove the legitimate svchost.exe file which is always found in \%WINDIR%\System32\ - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!X
[filename]svchost.scrAdded by the Troj/Banker-CC Trojan! Note: Located in \%WINDIR%\System32\X
_svchost.consvchost.comAdded by the W32.Erkez.C@mm WORM! Note: Located in \%WINDIR%\System32\X
F-Secure 2005svchost.exeAdded by the Troj/Bifrose-CH TROJAN! Note: Located in \%WINDIR%\ Note: Do not remove the legitimate svchost.exe file which is always found in \%WINDIR%\System32\ - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!X

O20 List Results
AppInit_DLLs & Winlogon Notify

Name Filename Description Status
svchost.dll%SYSDIR%\svchost.dllPurityScanX AppInit_DLLs
O23 List Results
Windows Services

Name Filename Description Status
Service de l’Assistant Compatibilité des programmes (PcaSvc)svchost.exeRelated to Program Compatibility Assistant Service This service provides support for the Program Compatibility Assistant (PCA). PCA monitors programs installed and run by the user and detects known compatibility problems. Note: This service on Vista - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the service name with the filename \%WINDIR%\%System%\PcaSvc.dllL
Gestion des clés et des certificats d'intégrité (hkmsvc)svchost.exeRelated to Health Key and Certificate Management Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service. Note: This service on Vista - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the service name with the filename \%WINDIR%\%System%\hkmsvc.dllL
Modules de génération de clés IKE et AuthIP (IKEEXT)svchost.exeRelated to IKE and AuthIP IPsec Keying Modules The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Note: This service on Vista - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the service name with the filename \%WINDIR%\%System%\IKEEXT.dllL
Assistance IP (iphlpsvc)svchost.exeRelated to IP Helper Provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. Note: This service on Vista - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the service name with the filename \%WINDIR%\%System%\iphlpsvc.dllL
Mappage de découverte de topologie de la couche de liaison (lltdsvc)svchost.exeRelated to [url=http://wiki.blackviper.com/wiki/Link-Layer_Topology_Discovery_Mapper]Link-Layer Topology Discovery Mapper[/url Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. Note: This service on Vista - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the service name with the filename \%WINDIR%\%System%\lltdsvc.dllL

Drivers List Results
Driver Entry

Name Filename Description Status
okosrvSvchOst.eXEAdded by the TrojanProxy:Win32/Koobface.gen!GX
NcbServicesvchost.exeRelated to the xxxCXTuner.sysxxx A connection broker is a software program that allows the end-user to connect to an available desktop from Microsoft Corporation. Note: This service is run the the service hostL
WindowsDriversvchost.exeAdded by the Infostealer trojan, detected by Kaspersky antivirus as Trojan-Dropper.Win32.Agent.gupxX
eventchksvchost.exeAdded by the svchost.exe Worm.Generic.24677 Note: Do not remove the legitimate (svchost.exe) file which is always found in \%Windir%\%System%\X
Host Generic Processsvchost.exeInfostealer trojan, detected by Microsoft as "Trojan:Win32/Malex.gen!E" Note: Do not remove the legitimate (svchost.exe) file which is always found in \%Windir%\%System%\X

Active Setup List Results
Active Setup - Installed Component

CLSID Name Filename Description Status
{2BF41072-B2B1-21C1-B5C1-0305F4155515}(no name)svchost.exe, svchost.pif , iexplore.exe, Ma0ya0.exe, system.exe, system2.exe, R_Server.exe, svchost.exe, svohcst.exe, other filenamesInfostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.Scar - see here, here or hereX
{0BBA3D30-AC6B-D6A7-AA17-10DAF6CA2F9C}(no name)svchost.exeInfostealer trojan, detected by Microsoft as Worm:Win32/Ainslot.A - also see hereX
{55CLT5SP-KK4F-28DW-CR5L-B36Y66V74KUB}(no name)Svchost.exeInfostealer trojan, detected by Microsoft as Worm:Win32/Rebhip.A - also see hereX
{DF6ABFA9-F098-6014-8967-4DBEB7B2F2CA}(no name)svchost.exeInfostealer trojan, detected by Microsoft as Worm:Win32/Ainslot.A - also see hereX
{5L40LKFR-QBYF-67Q8-B2U8-5W03312WUDQ8}(no name)svchost.exeInfostealer trojan, detected by Microsoft as Worm:Win32/Rebhip.A - also see hereX

Powered by SystemLookup Engine. © 2008-2018 BrightFort. All Rights Reserved. | Privacy Policy | Terms of Use