| Name | Status | Filename | Description |
|---|
| handle (handle) | X | handle.exe | Added by the SDBOT.CDD
WORM!
Read the link, rootkit type stealth involved.
|
| Handling the DHCP requests (DHCP Client) | X | dhcpclient.exe | Most likely a W32.Toxbot_variant
|
| HanWangTablet | L | JWPEN.exe | Related to HanWang_Tablet Hanwang Writing Tablet gives you the power to quickly input handwriting Chinese and Japanese into Microsoft Word, Excel, PowerPoint, MSN, ICQ, WPS and over 100 other software applications easily and pleasurably. Note: Located in \%WINDIR%\System32\ |
| Hardware Clock Driver (hwclock) | X | hwclock.exe | Added by the W32/Hwbot-A
WORM!
|
| Hardware Detection (Serv-U) | X | svchost.exe | Reported by Kaspersky Anti-Virus as Win32.Serv-U.gen Note: This is not the legitimate Windows process (Which is always found in the System32 folder). This file is found in the System32\drivers\etc\data\ folder.
|
| Hardware Monitor Service (Hardware Monitor) | X | mshms.exe | Added by the Troj/Wollf-A
TROJAN!
|
| Hardware Monitoring Program (ADMService) | L | admServ.exe | Related to Avocent Embedded Software and Solutions Division |
| Harmony | L | RSOBSERV.EXE | Related to Rockwell_Automation Inc. FactoryTalk suite |
| HASP License Manager (hasplms) | L | hasplms.exe | Related to HASP_License Manager from Aladdin Knowledge Systems. HASP HL is a USB Hardware Key or Dongle based software copy protection solution. Note: Located in \%WINDIR%\System32\ |
| HauppaugeTVServer | L | HCWTVServer.exe HCWTVS~1.EXE | Related to TVServer from Hauppauge Computer Works, Inc. Note: Located in \%Program Files%\WinTV\ |
| haxdrv | X | haxdrv.sys | Added by the Troj/Rootkit-U
TROJAN!
Read the link, rootkit type stealth involved.
|
| hcalway | X | hcalway.sys | Added by the PigSearch
Adware.
Read the link, rootkit type stealth involved.
|
| HDD Information Service (HDDSvc) | L | HDDSvc.exe | Related to HDD_Information Service from Altrixsoft.com Note: Located in \%WINDIR%\System32\ |
| HDDlife HDD Access service | L | hldasvc.exe | Related to Hard_disk Access service. Reads S.M.A.R.T. data from all of your hard drives and allows you to see clearly the health and resources of your disks. Note: Located in \%Program Files%\BinarySense\ |
| Health Key and Certificate Management (hkmsvc) | L | kmsvc.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Help and Support (helpsvc) | X | ineters.exe | Identified as Malware.Gen Note: Located in \%WINDIR%\System32\ |
| Help and Support Service (hasvc) | X | usnsvc.exe | Added by a variant of the SDBOT Note: Located in \%WINDIR%\ Note: Use SDFix under supervision. |
| hexadecimal (HexadecimaRepresentation) | X | Edit.exe | Added by the W32/Sdbot-AAY
WORM!
Note: File name may be different.
Read the link, rootkit type stealth involved.
|
| HF30Service | L | HF30Service.exe | Related to Lock_Folder Password protection for files, folders, and drives. Note: Located in c:\Program Files\Everstrike Software\Hide Folder 3.1\ |
| hgz | X | Hacker.com.cn.exe | Added by a variant of the Troj/Feutel-CJ TROJAN Note: This worm\trojan is located in C:\%WINDIR%\HgzServer\ Folder. |
| Hibernation | L | hibserv.exe | Related to Compaq-Hewlett Packard hibernation service. |
| HICOM LAN Bridge VCapiDrv (vcapidrv) | ? | vcapintsvc.exe | Could be related to a new version of HICOM LAN Bridge? |
| HID Input Service WIN32 (HID_Input_Service_WIN32) | X | msiexecu.exe | Added by the Troj/Raser-AS TROJAN!
Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Creates this file SndSystem.sys which acts as a rootkit. |
| HID Output Service (HODSrv) | X | hpsvc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| HiPath Cardserver (FMCardService) | L | FMCardServ.exe | Related to HiPath service from Siemens. Note: Located in \%Program Files%\Siemens\HiPathCardManager\ |
| HIPS Configuration Interpreter (UmxCfg) | L | UmxCfg.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Event Manager (UmxAgent) | L | UmxAgent.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Firewall Helper (UmxFwHlp) | L | UmxFwHlp.exe | Related to HIPS_Firewall Helper Service CA (Computer Associate) Host Intrusion Prevention System. Note: Located in \%Program Files%\CA\SharedComponents\HIPSEngine\ |
| HIPS Policy Manager (UmxPol) | L | UmxPol.exe | Tiny Firewall |
| HiWired Client Core Service (HiWiredCore) | L | HiWired.Client.Core.exe | Related to HiWired_Service from HiWired, Inc. On-line PC services. Note: Located in \%Program Files%\HiWired\PC Check & Connect\ |
| Horario de Windows | L | services.exe | Spanish Windows 2000 "windows time" |
| host (host) | X | host.exe | Added by the Troj/GrayBrd-AR
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder. |
| Host Process for Win32 Services | X | svchost.exe | Added by a variant of the SDBOT Note: Located in \%WINDIR%\system\ Note: Use SDFix under supervision. |
| host Service For Windows (mshost) | X | mshost.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Host Services (Host Services) | X | svhosts.exe | Added by the W32/Tilebot-AC
WORM!
Note: This is not the legitimate Windows process svchost.exe (Notice the difference in the spelling.) This worm\trojan file (svhosts.exe) is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Host Services (Host Services) | X | myhost.exe | Added by the W32/Tilebot-AT
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| Hosts AOL Network Update Services (AOL Update Service) | X | aolup.exe | Added by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\System32\ |
| Hotplug Devices Manager | X | hotplug.exe | Added by the W32.Orpheus.A WORM! |
| Hotspot Shield Service (HotspotShieldService) | L | openvpnas.exe | Related to Hotspot_Shield helps secure your computer, your anonymity and your online communications when using free wi-fi. Note: Located in C:\Program Files\Hotspot Shield\bin\ |
| Hotspot Shield Tray Service (HssTrayService) | L | HssTrayService.EXE | Related to Hotspot_Shield helps secure your computer, your anonymity and your online communications when using free wi-fi. Note: Located in C:\Program Files\Hotspot Shield\bin\ |
| Houdini License Client (HoudiniServer) | L | hserver.exe | Related to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:\WINDOWS\system32\ |
| Houdini License Server (HoudiniLicenseServer) | L | sesinetd.exe | Related to Houdini_License_Server from Side Effects Software Inc. Note: Located in C:\WINDOWS\system32\ |
| HP Configuration Interface Service (HPConfig) | L | HPConfig.exe | HPConfig Module |
| HP Configuration Service (HPConfig) | L | HPConfig.exe | Related to HP config. |
| HP Hard Drive Thermal (HDThermal) | L | HDThermal.exe | Related to Hewlett-Packard company. |
| HP Health Check Service | L | hphc_service.exe | Related to HP_Health_Check Service. Note: Located in \%Program Files%\Hewlett-Packard\HP Health Check\ |
| HP Insight Event Notifier (CIMnotify) | L | cimntfy.exe | Related to HP products |
| HP Insight Foundation Agents (CqMgHost) | L | cqmghost.exe | Related to HP products |
| HP Insight NIC Agent (CpqNicMgmt) | L | cpqnimgt.exe | Related to HP products |
| HP Insight Server Agents (CqMgServ) | L | cqmgserv.exe | Related to HP products |
| HP Insight Storage Agents (CqMgStor) | L | cqmgstor.exe | Related to HP products |
| HP OpenView Trace Service | L | OVTrace.exe | HP OpenView Internet Services |
| HP Port Resolver | L | hpbpro.exe | Related to Hewlett-Packard Company |
| HP ProLiant Remote Monitor Service (CpqRcmc) | L | CpqRcmc.exe | Related to HP_ProLiant_Remote_Monitor_Service Note: This file is located in C:\%WINDIR%\ |
| HP ProLiant System Shutdown Service (sysdown) | L | sysdown.exe | Related to HP products |
| HP ProtectTools Device Locking / Auditing (FLCDLOCK) | L | flcdlock.exe | Related to ProtectTools from Hewlett-Packard Development Co. Locking Device. Note: Located in \%WINDIR%\System32\ |
| HP RF Device Service (HpRfDev) | L | HpRfDev.exe | support for HP managing wireless devices |
| hp service (Hpsys) | X | hpsys.exe | Added by the W32/Codbot-AF
WORM!
Note: This service has nothing to do with HP. This worm\trojan file is found in the System32 folder. |
| HP Status | L | hpb2ksrv.exe | Related to Hewlett-Packard Company |
| HP Status Print | L | hpbhksrv.exe | Related to Hewlett-Packard company. |
| HP Status Server | L | hpboid.exe | Related to Hewlett-Packard Company |
| HP System Management Homepage (SysMgmtHp) | L | smhstart.exe | Related to HP products |
| HP Version Control Agent (cpqvcagent) | L | vcagent.exe | Related to HP products |
| HP Web Jetadmin | L | hpwebjetd.exe | Related to HP WebJetAdmin software, used to configure and monitor network print servers. |
| HP WMI Interface (hpqwmi) | L | HPQWMI.exe | Related to Hewlett-Packard |
| hpdj | ? | hpdj.exe | Maybe HP related? Sits in TEMP folder. |
| hpdj | L | hpztsb04.exe | Hewlett Packard printer toolbox, sits in taskbar. Path to executable file - %windir%\system32\spool\drivers\w32x86\3\ |
| hpdriver | X | hpdriver.sys | Added by the Troj/Rootkit-AA
TROJAN!
Note: This trojan file is found in the System32 folder.
Read the link, rootkit type stealth involved.
|
| HpPrinter | X | hpserver.exe | Added by the Troj/CmjSpy-W
Trojan!
|
| hpqwmiex | L | hpqwmiex.exe | Related to HP_ProtectTools security manager |
| HPR34K8 | X | hpr34k8.sys | Added by the Troj/Rootkit-AA
TROJAN!
Read the link, rootkit type stealth involved.
|
| HPWirelessMgr | L | HPWirelessMgr.exe | Located in HP Notebook Utilities - guessing for wireless connection. |
| HTTP SSL (HTTPFilter) | L | lsass.exe | Related to Application_Isolation_Mode_Functions Microsoft IIS 6.0. Note: Located in C:\%WINDIR%\System32\ |
| huapeak | ? | huapeak.exe | Unknown origin. |
| Human Interface Device Access (hidserv) | L | svchost.exe -k LocalSystemNetworkRestricted | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Hummingbird Inetd (HCLInetd) | L | inetd32.exe | Related to Hummingbird Ltd. - http://www.hummingbird.com/ |
| Hummingbird Jconfig Daemon (Jconfigd) | L | jconfigdnt.exe | Related to Hummingbird Ltd. - http://www.hummingbird.com/ |
| HXD Service 100 (HackerDefender100) | X | newka.exe | Virus
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39265 |
| H_Server (H_Server) | X | G_Server.exe | Added by the Troj/GrayBird-W
TROJAN!
Note: This trojan file is found in the Windows or Winnt folder. |