Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
Note the filename has a ""0"" rather than an upper case ""o"""
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
X%Temp%%Temp%delwdef2008.bat"WinDefender 2008 rogue privacy program - not recommended
X(Default)5640.exe"Added by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X..ABC2007.exe"Added by the DLOADR-ASH TROJAN!"
U0pit.exe"PrivateEye surveillance software. Uninstall this software unless you put it there yourself"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
U000StTHK000StTHK.exe"Toshiba Hot key functionality for the function keys (Fn-Esc
X0050726-007-i32-10050726-007-i32-1.exe"Added by the BANCBAN-EC TROJAN!"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
?00notify33NetBrowser.exe"Part of Best Network Security
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
?00saskdanewlock.exe saskda"Part of Access Manager
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U00THotkey00THotKey.exe"For Toshiba Satellite notebook series to use the front buttons
U00THotkeysystem32THotkey.exe"For Toshiba Satellite notebook series to use the front buttons
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X0_AVD32xzboot.exe"Added by the AGENT-IWI TROJAN!"
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"180solutions adware"
X180ax180ax.exe"180Search adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X180sa180sa.exe"180Search adware"
X196_150_ni196_150_ni.exe"WinFixer web installer - ""foistware""
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer - ""foistware""
X197_150_ni_7197_150_ni_7.exe"WinFixer web installer - ""foistware""
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
X2020Downloadermssvr.exe"2020Search Toolbar"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
X250kg250kg.exe"Added by the AUTORUN-TI WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g MIMO Wireless UtilityRaUI.exe"Wireless configuration utility for Railink 802.11g MIMO based products"
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X8254502482545024.exe"Added by the AGENT-MBV TROJAN!"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
Xadtech2005adtech2005.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xadtech2006adtech2006.exe"Detected by Kaspersky as the VB.KC WORM!"
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 rogue security software - not recommended
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xaimaol ml097eaimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NAlcohol 120%Alcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAntiSpy2008AntiSpy2008.exe"Antispy 2008 rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
YATIRmtWndrATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATIX10atix10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
NbackWeb-8876480backweb-8876480.exe"Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
Xbegins0.exe"Added by the MYTOB-HE WORM!"
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
UBHODemon 2.0BHODemon.exe"BHODemon ""protects you from unknown Browser Helper Objects (BHOs)
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
YBOC-420BOC420.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.20"
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBT00003*abcdefg23.exe"Added by the VB-VT TROJAN where * = 5
XBT00003*hiklmnop27.exe"Added by the VB-VT TROJAN where * = 2
?Calendar 200X Monitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
NCalendar 200X Remindercalendar.exe"Part of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
XCare20Care20.exe"TopMoxie adware"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
UCHotKeyMK9805.EXE"Enables special keys on Chicony keyboards. Special combinations include Internet
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
NClipmate6CLIPMT60.EXE"Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
Xcmt101cmt101.exe"Added by a variant of the CRYPTER.C TROJAN!"
UCobian Backup 10Cobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
UCPATR10CPATR10.EXE"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
NCplBTQ00CplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
NCreateCD50Createcd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCTFM0N.exeCTFM0N.exe"Added by the STARTPAGE.P TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
XCTin10CTin10.exe"Added by the BANCOS.E TROJAN!"
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
UCyber-Defender 2003uwcdsvr.exe"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
ND066UUtilityD066UUTY.EXETWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
NDAEMON Tools-1033daemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDanBtR270414DanBtR270414.exe"Added by the VB-NIB WORM!"
UDC300 Monitorcmonitor.exeMonitor for a Acer DC300 digital camera
UDeko550Deko550.exe"Associated with the Deko550 entry-level SD real-time graphics system from Avid Technology"
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
XDesktop Security 2010Desktop Security 2010.exe"Desktop Security 2010 rogue security software - not recommended
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
NDigiGuideclient01.exeTV guide and reminder
?Disable EHCInousb20.exe"??"
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
Xdjtopr1150.exedjtopr1150.exe"WebRebates adware"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NDLF_00000B00Vcdlf.exe"Known to cause problems with "Out of memory" errors (see here). Otherwise
Xdnamd140113.a.Stub.EXE"Added by the STUB_A TROJAN!"
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
Ndumprep 0 -kdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Ndumprep 0 -udumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
UDWQueuedReportingdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
Udwtrig20dwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
UE06DXLRD_7604703EDICT.EXE"Related to Microsoft Encarta dictionary functions"
NEarthLink ToolBar 5.0etoolbar.exe"EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
UeDonkey2000edonkey2000.exe"File sharing network - not recommended as the free version of this application should be avoided as it installs
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
UeFax DllCmd 4.0J2GDllCmd.exe"DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 4.0J2GTray.exe"System Tray access to version 4.0 of eFax Messenger from j2 Global Communications
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xefaxs ml097eefaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xei10.exeei10.exe"Added by the AGOBOT-NK WORM!"
Xemoc0reemo.exe"Added by the AGOBOT-AGE WORM!"
Xempine121307.exe"Delfin Media Viewer adware related"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C66 SeriesE_S4I0S2.EXE"Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3100E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status
UEPSON Stylus CX3200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5400E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo 2200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status
UEPSON Stylus Photo 825E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Xeth0 driverexec.exe"Added by the SPYBOT-Z WORM!"
Xexe lptt01exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xexe ml097eexe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
UE_S10IC2E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UE_S23E_SICN03.exe"Epson printer status monitor - for checking ink levels
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
UF5D7050v3Belkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UF5D8001Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
UF5D8011Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
UF5D8055v1Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
UF5D8071Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
UF5D9010Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
UF5D9050Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
Xf607f607.exe"Added by the URAT.B TROJAN!"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile0_0MD1.exe"Added by the DLOADER-OR TROJAN!"
Xfirewallfw_304.exe"Added by the BDOOR-JQ BACKDOOR!"
Xfirewall 2008logoneui.exe"Added by the SILLYFDC WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
UFLMK08KBMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keys
UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFooBar 1.0FooBar.exe"FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG0mezG0mez.vbs"Added by the GORMLEZ-A WORM!"
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xgeneral ml097egeneral.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGetModule20GetModule20.exe"Internet Speed Monitor adware related - see example here"
XGetModule30GetModule30.exe"Internet Speed Monitor adware related"
XGetPack20GetPack20.exe"Internet Speed Monitor adware related - see example here"
Xgf1.0.0.2ggf.exe"Added by the EDFON.A TROJAN!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
Xgotnewupdate000.exegotnewupdate000.exe"Added by the FAKEAV-BGA TROJAN!"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
XHot 8.0 Livehot.exe"Added by the BANKER.EIE TROJAN!"
XHOT FIXE0chis.exe"Added by the HUPIGON.JTY TROJAN!"
UHot Key Kbd 2690 DaemonSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
?hp 1000 firmwarefwdl.exe"HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?"
XHP DeskjetHP_DeskJet_500.exe"Added by the FORBOT-DA WORM!"
UHP Digital Imaging Monitorhpqtra08.exe"System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera
NHP Image Zone Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
NHP Photosmart Premier Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
Nhpaiodevicehpodev07.exe"Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
NHPAIO_PrintFolderMgrhpoopm07.exe"Directly from HP: "This process has one purpose - detects if the device moves to a different port
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPHmon03hphmon03.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. Known to cause 100% CPU load in some cases. Only needed if you use this feature
UHPHmon04hphmon04.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 4.0 to 4.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
Uhphmon05hphmon05.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 5.0 to 5.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon06hphmon06.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 6.0 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
NHPHUPD04hphupd04.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD05hphupd05.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD06hphupd06.exeHP software update checker and wizard launcher. Available via the Start menu
NHPHUPD07hphupd07.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD08hphupd08.exeHP software update checker and wizard launcher. Available via Start -> Programs
Nhpoddt01.exeN/A"Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software
Uhpoddt01.exehpotdd01.exe"Detection of new imaging
Nhpodlb08hpodlb08.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Xhriiexpl0re.exe"Added by the DLOADER.MAQ TROJAN! Note the number ""0"" in the filename"
XhuigeziSP00LSV.EXE"Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIcon ml097eicon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XICQ Messenger 2002ICQ2002.exe"Added by the SDBOT-ABL WORM!"
Xiedwa104iedwa104.exe"Added by the DLOADR-BBW TROJAN!"
XIEXPL0RERIEXPL0RER.EXE"Added by the AGOBOT-QL WORM!
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?iHP-100iHPDetect.exe"Drive Letter Searcher
XIMJPMIG8.2msime80.exe"Added by the VB-CYJ TROJAN!"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
Xintdctrridctup20.exe"SafeSurfing adware variant"
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Security 2010IS2010.exe"Internet Security 2010 rogue security software - not recommended
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
UIomega Automatic Backup 1.0.1ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
UIP Changer 2.0IPChanger.exe"IP Changer 2.0 from Plustech Inc - network configuration management tool"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPO3IP Operator 2005.exe"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
XJVM0JVM0.exe"Added by the BANLOA-AX TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjxef1104jxef1104.exe"Added by the XIPI-A WORM!"
YKAVPersonal50Kav.exe"Kaspersky Anti-Virus Personal 5.0"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
XKazaa lptt01kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
XKazaa ml097ekazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
XKerne0223Kerne0223.exe"Added by the LEGMIR-ZA TROJAN!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
Xkernel44.dll"taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
Nkernelfaultcheckdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Nkernelfaultcheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XKiamat Sudah Dekat_16_04ISASS.exe"Added by the PAHATIA.B WORM!"
UKM9801UMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
UKONICA MINOLTA magicolor 2400W STDMSTMON_S.EXEKonica Minolta Magicolor 2400W colour printer monitor
XKr0n1CKr0n1C.exe"Added by the BRONTOK-BO WORM!"
XKV2005word.EXE"Added by the VB-IW TROJAN!"
Xkv3000lover.vbe"Added by the ZSYANG.B WORM!"
UKX509kx509_kfwk5.exe"Kerberos Secure Authentication for Windows"
XL0adersfaxneti.exe"Added by a variant of the SDBOT TROJAN!"
XlaltinL90112201.Stub.exe"Delfin Media Viewer adware related"
ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
?LanzarL2007[path] setup.exe"??"
ULaplink PDASync 3.0 - LtNts4NtsAgnt.exe"Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
NLaunch Context 5.0Launch.exe"Context - electronic dictionary"
XLaunch Norton AntiVirus 2000jorgf.exe"Added by the RBOT-AUI WORM!"
NLDMbackweb-8876480.exe"Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products
ULexmark 1200 Serieslxczbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 1200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 2200 Serieslxbvbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 2200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 3100 Serieslxbrbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 4200 Serieslxbmbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 4200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 5000 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 5200 serieslxbtbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 5200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 6500 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 7600 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 9300 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X1100 Serieslxbkbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X1100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark X5100 Serieslxbabmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X5100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark X5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X6100 Serieslxbfbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
Xli-rcash00001vldial.exe"Added by the Vl TROJAN!"
Xli01f948"rundll32.exe li01f948.dllEnableRunDLL32"
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
NLine Speed Meter V3.0LineSpeedMeter.exe"LineSpeedMeter - detect the download and upload speed of your internet connection"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
Nload=adw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Yload=01comm32.exe"Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
NLogitech Desktop Messengersetup-8876480.exe"Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products
NLogitechQuickCamRibbonQuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
NLS120 Superdisk??"Supposed to accelerate transfer rate on LS-120
XLTM2MSGSRV320.EXE"Added by the LITMUS.C TROJAN!"
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
?Main Executable (HP)HP05T0R5.exe"HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
XMalware Catcher 2009MCatcher.exe"Malware Catcher 2009 rogue security software - not recommended
XMalware Destructor 2009MD345d.exe"Malware Destructor 2009 rogue security software - not recommended
XMalwareBurn 7.0MalwareBurn 7.0.exe"MalwareBurn rogue security software - not recommended
Xmaskridermaskrider2001.vbs"Added by the SOLOW-G WORM!"
XMi7sft sdceb0yz.exe"Added by the RBOT.CWG WORM!"
XMicr0s0ft Ms D0smsdx.exe"Added by the RBOT-AON WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicroCQ0explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMicrofinder lptt01mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrofinder ml097emcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft AntiSpywareKT06.pif"Added by the IRCBOT.GEN WORM!"
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL BACKDOOR!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicroSoft Legal ServiceSrb0ty.exe"Added by the SPYBOT.HW WORM!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
UMicrosoft Office 2010BCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
NMicrosoft Office OneNote 2003 Quick LaunchONENOTEM.EXE"System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft UpdateMicr0s0ft.exe"Added by the AGOBOT.AAR WORM!"
XMicrosoft Updatewuamk0032.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamk032.exe"Added by the RBOT-AHD WORM!"
XMicrosoft Updatewuamk0p32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
Xmicrosoft xdaemon 2.0xdaemon.exe"Added by the DELF.D TROJAN!"
Xmicrosoft420microsoft420.exe"Added by the MENACE.B WORM!"
NMicrosoft® Works 7.0wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
Xml00!.exeml00!.exe"Malware
XMlcr0s0ftf DDEs C0ntr0iWAed.pif"Added by the RBOT-BJW WORM!"
Xmmnext06trjdwnl.dll"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
Xmotoinmm15201518.Stub.exe"Delfin Promulgate adware variant"
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
XMozilla FirefoxF1REF0X.EXE"Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers ""1"" and ""0"" in place of upper case ""i"" and ""o"" respectively"
XMS AntiSpyware 2009msas2009.exe"MS AntiSpyware 2009 rogue spyware remover - not recommended
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS MSN Menssenger 7.0MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
XMS OfficeOffice10.exe"Added by the VB.DT TROJAN!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsigdisk10.exe"Added by the BANBRA-KF TROJAN!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
XMslogon lptt01mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMslogon ml097emslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMsn 8.0 Livemsn.exe"Added by the BANKER.EIE TROJAN!"
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMSN MESSENGER 9.0messengerr.exe"Added by a variant of the RBOT WORM!"
NMSN Webcam Recorderml20gui.exe"""MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"""
UMSPY2002ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMsServermsfir80.exe"Added by the VB-CYJ TROJAN!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssync20mssync20.exe"Added by the LDPINC-QC TROJAN!"
XMSVBVM60MSVBVBM60.pif"Added by the SCOLD-B WORM!"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
Xmsys lptt01msys.exe"RapidBlaster variant (in a ""Msyss"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMS_update_0704_KB74073.exeMS_update_0704_KB74073.exe"Added by a variant of the UPDATEKB TROJAN!"
Xmule_st_keyflec006.exe"Added by the BAGLE.AV TROJAN!"
NMusic01 ServerMusic01 Server.exe"J River Media Jukebox"
?Mustek MDC 3000Mounter.exe"Related to software for the Mustek MDC 3000 digital camera - what does it do and is it required?"
XmyMh2iexpl0re.exe"Added by the AGENT.HWE TROJAN! Note the number ""0"" in the filename"
XNameIexplorer0.exe"Added by the THREADSYS TROJAN!"
Xnana2009nana2009.exe"Added by the POISON.PG BACKDOOR!"
Xnavman_20sysnav32.exe"Hijacker
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
YNettGain2000WgwMngr.exe"Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution
YNettGain2000 VerifierNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speed
XNewsgroup lptt01newsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNewsgroup ml097enewsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.GA6PU_0001_N108E1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6PU_0001_N120C2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6P_0001_N105E2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GA6P_0001_N111C1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115C0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115E0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122E0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_2001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GDCDE_0001_N122C1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.GDC_0001_N111C1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GDC_0001_N122C1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GES_0001_N122C2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UAVIFR_0001_N105M2404[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UGA6PH_0001_N122M2910[path to file]"Installer for the AntiVirusAskeladd rogue security software - see here"
XNI.UGA6PK_0001_N122M1302[path to file]"Installer for the VirusForsvar Danish rogue security software - see here"
XNI.UGA6PL_0001_N108M2808[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PL_0001_N120M1302[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PM_0001_N108M2108[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M1202[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M3010[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PT_0001_N108M2208[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M1202[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M2910[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PU_0001_N108M1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M1202[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PV_0001_N108M0207[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M1202[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6P_0001_N105M2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N111M1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N115M0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N119M1510[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N120M1710[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0007_N125M2002[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6P_1001_N122M0402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_1002_N122M1402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4001_N122M2111[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5001_N122M1902[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5555_N122M0312[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGDC1_0001_N119M0911[path to file]"Installer for the FilterProgram rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0307[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0511[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M1712[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCDE_0001_N111M3007[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCDE_0001_N122M1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M0307[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M1812[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCNL_0001_N111M3007[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M1912[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M3011[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCPL_0001_N108M0207[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCPL_0001_N122M2012[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCRU_0001_N111M0208[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCRU_0001_N122M2012[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCTH_0001_N122M1712[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDCTR_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N111M1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M0502[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2603[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2610[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2802[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2811[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0002_N108M1007[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0003_N108M2407[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGESF_0001_N122M0201[path to file]"Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N105M0405[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M0303[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M2911[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESM_0001_N122M0303[path to file]"Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N108M2006[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M0303[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M2811[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M3010[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGES_0001_N108M2006setup_en.exe"Installer for the MyContentAssistant rogue privacy tool"
XNI.UGES_0001_N122M0502[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2111[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2602[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2603[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0002_N108M1607[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0614UWFX5LP_0001_0614NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0715UWFX5LP_0001_0715NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0802UWFX5LP_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0803UWFX5LP_0001_0803NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer 2006 web installer - ""foistware""
XNJG40NJG40.EXE"Added by the BANCOS.D TROJAN!"
UNo-IP DUCDUC20.exe"Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available"
XNod3d2 Free antivirusN0D32KRN.EXE"Added by the RBOT-ABQ WORM!"
XNorton Antivirus 2004SYMANTECAV2.EXE"Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV!"
XNorton Antivirus 7.0a[path to file]"Added by the PERDA-B or RANCK-CT TROJANS!"
NNorton Ghost 10.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
NNorton Ghost 9.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
XNotepad lptt01notepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
XNotepad ml097enotepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
Xntechinn20050308.exe"Delfin Media Viewer adware related"
XNumerical Xterm Agent0x32.exe"Added by the RBOT-FWP WORM!"
Xnvd32 lptt01nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xnvd32 ml097envd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UnwssSp0.exe"SpyOutside surveillance software. Uninstall this software unless you put it there yourself"
XNZ01NZ01.exe"Added by the SCAR-K TROJAN!"
UOEM02Mon.exeOEM02Mon.exe"Creative Live! Cam Console Auto Launcher"
?OEM07Mon.exeOEM07Mon.exe"Related to Live Camera Console Auto Launcher by Creative Technology LTD. What does it do and is it required?"
XOESETsetup60.exe"Added by the WAREZDL.28672 TROJAN!"
?officejet 6100hposol08.exeAssociated with a HP PSC2110 (and maybe others) all-in-one machine
NOneNote 2007 Screen Clipper and LauncherONENOTEM.EXE"System Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
XOPQFileregedit.exe /s ...rad03FA6.tmpUnsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
XP Antispyware 09pas.exe"P Antispyware 09 rogue security software - not recommended
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UP3000x_S2PScanToPc.exeDell Laser MFP 1600N network application for scanning files to the PC
UPAC7302_MonitorMonitor.exe"Related to PixArt CMOS image sensors from PixArt Imaging Inc"
NPalo Alto Software Update Manager 8.0PAS8_UD.exe"Update manager for small business planning software from Palo Alto Software - such as Business Plan Pro
NPaperPort PTDpptd40nt.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
XPC Antispyware 2010PC_Antispyware2010.exe"PC Antispyware 2010 rogue security software - not recommended
XPC Security 2009PC_Security2009.exe"PC Security 2009 rogue security software - not recommended
XPCMM2007RTpcmm2007.exe"PC MightyMax 2007 rogue security software - not recommended
UPD0620 STISvcP0620Pin.dllCreative Technology Ltd installation plug-in related
UPDUiP6000DMonPDUiP6000DMon.exe"Memory Card Utility for the Canon PIXMA iP6000D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPDUiP6000DTskbrPDUiP6000DTskbr.exe"Memory Card Utility for the Canon PIXMA iP6000D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPDUiP6210DMonPDUiP6210DMon.exe"Memory Card Utility for the Canon PIXMA iP6210D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPDUiP6220DMonPDUiP6220DMon.exe"Memory Card Utility for the Canon PIXMA iP6220D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPDUiP6600DMonPDUiP6600DMon.exe"Memory Card Utility for the Canon PIXMA iP6600D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPDUiP6700DMonPDUiP6700DMon.exe"Memory Card Utility for the Canon PIXMA iP6600D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
XPeqBL100PEQBL100.exe"Added by the ENVID.D WORM!"
XPerfect Defender 2009pdfndr.exe"Perfect Defender 2009 rogue security software - not recommended
NPerfectPrintpfppop70.exePrint engine used by Corel WordPerfect 7 and Presentations 7
XPersonal Defender 2009pdefendr.exe"Personal Defender 2009 rogue security software - not recommended
XPest-Patrol 2.1.0Pest-Patrol.exe"Pest-Patrol rogue security software - not recommended
UPetit Larousse 2001HIPL2000Popup.exePopup dictionary tool
UPFM3.0PFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device
UPFM30PFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device
Uphc700vphc700.exe"Related to the Philips SPC700NC web camera"
UPhilips PhotoFrame ManagerPFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device
UPHIME2002ATINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
UPHIME2002ASyncTINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
XPHIME2004CCTFMDN.exe"Added by the DLOADR-AMV TROJAN!"
?PLFFAPHotfixQ0306270.exe"Prolific Technology Inc. USB Flash Disk driver - is it required in startup?"
Xpop06appop06ap2.exe"MediaMotor adware"
Xpop06apeltthiselt.exe"ZenoSearch adware"
XPower-Antivirus-2009Power-Antivirus-2009.exe"Power Antivirus 2009 rogue security software - not recommended
XPowerProfilemfcp30.exe"Added by the RINDAS-A TROJAN!"
?PowerSetRegedit.exe /s ...PowerSet_8100_CU.REG"Appears to be Toshiba power management related"
UPP2000 InstaupdatePPInupdt.exeProtector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
YPP2000 Real Time ScanPPVstop.exeProtector Plus anti-virus software - real time scanner
YPP2000 Taskbar ControlPPTbc.exeProtector Plus anti-virus software - system tray access
NPP3100bflatbed.exe"Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan
NPPort10reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 10 from Scansoft (now Nuance)"
Npptd40ntpptd40nt.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
NPrintkey2000printkey2000.exeScreen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
XPro Antispyware 2009proas2009.exe"Pro AntiSpyware 2009 rogue spyware remover - not recommended
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
XProof Defender 2009pdfndr.exe"Proof Defender 2009 rogue security software - not recommended
XProtected StorageRUNDLL32.EXE MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
UPUAC v2.0.7Puac.exe"""Peter's Ultimate Alarm Clock"""
UPurgativePURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
NQ152404wsript.exe Q152404.VBSAppears to run Scandisk at bootup on NEC PCs
XQdrModule10QdrModule10.exe"Internet Speed Monitor adware"
XQdrPack10QdrPack10.exe"Internet Speed Monitor H adware"
NQSort2000QSORT.EXEUtility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"
NQuickCam10QuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
NQuickCam10.exeQuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
NQuickFinder SchedulerQFSCHD100.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
NQuickFinder SchedulerQFSCHD110.EXE"Used in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
NQuickFinder SchedulerQFSCHD130.EXE"Used in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
XQuickInstallPackCLN_2009FreeInstall.exe"Installed and used by rogue security products such as Cleaner2009
XQuicktime Pro 3.0winuodps.exe"Added by the GAOBOT.BH WORM!"
UQWS3270 Sessionssessions.exeQWS3270 Secure terminal emulation software
NRaConfig2500RaConfig2500.exe"RaLink wireless LAN configuration utility"
Xravshellexpl0rer.exe"Added by the DLOADER.MAR TROJAN!"
XRavshellsvch0st.exe"Added by the NSPM.PU TROJAN! Notice the digit ""0"" in the filename rather than the lower case ""O"""
Xravshelliexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
Xravtasksvch0st.exe"Added by the LINEAG-AIN TROJAN!"
Xravtaskiexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
Xrb32 lptt01rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xrb32 ml097erb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xreaddb40"rundll32.exe readdb40.dll EnableRunDLL32"
?readericon10readericon10.exe"Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required?"
Xrealone_nt2003moniker.exe"Added by the SNONE.A WORM!"
Xrealplay lptt01realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
Xrealplay ml097erealplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
XRebateNation0RebateNation0.exe"RebateNation adware"
XRecommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}RH.DLL"SmartPops search hijacker"
XRecycle Bin Handler 2005system.exe"Added by the BDOOR-HO BACKDOOR!"
Ureg2.0SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
XRegcheck~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
URegistryclass0117[random].exe"Blackbox captures emails and chat logs
XRegistryDoctor2008registrydoctor.exe"RegistryDoctor2008 rogue registry cleaner - not recommended
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
YRegx10EXEATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
UResChanger2004ResChanger2004.exeEVGA graphic card utility providing easy access to display settings
NRFX_auto_upgraderundll32.exe npvpg005.dll"A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
Urmoc3260.dll OCXregsvr32.exe rmoc3260.dll"A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The ""rmoc3260.dll"" file is found in %System%"
XRoam04ActiveX.exe"Added by the ROAMER-A TROJAN!"
NRoxWatchTrayRoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
NRoxWatchTray10RoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
XRun05rundll_32.exe"Added by the BANCOS-DT TROJAN!"
Xrundll32svchs0t.exe"Added by the PWSTEAL-E TROJAN!"
XRundll32_7"rundll32.exe MSIEFR40.DLL DllRunServer"
XRundll32_8"rundll32.exe inetp60.dll DllRunServer"
XRUNLOADl0ad.exe"PurityScan/Clickspring adware"
XS0undMansvch0st.exe"Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
Xs9201as2008xp.exe"AntiSpyware XP 2008 rogue spyware remover - not recommended
Xs9201asproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XSafeguard 2009sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
XSAHBundleshop1003.exe"ShopAtHomeSelect parasite"
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
USay The Time 5.0SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
XSBR2009FSystemBooster2009.exe"SystemBooster2009 rogue system suite - not recommended
YSC3300CCSC3300CC.exeSiPix digital camera Twain device driver
Xscains030109.Stub.exe"Delfin Media Viewer adware related"
NScanSoft OmniPage SE 4.0-reminderEreg.exe ereg.ini"Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
NScreenHunter 4.0 FreeScreenHunter.exe"""ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
UScroll-In-Mouse V2.0SCROLL.EXE"Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
XSDKcore Update Components2SDKC0R3.exe"Added by the RBOT-ABA WORM!"
Xsdkupdate22SDK0mCORE.exe"Added by the FORBOT-DT WORM!"
XSDKz0rSDKc55rezzz2.exe"Added by the SDBOT-UN WORM!"
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
USecond Copy 2000SecCopy.exe"Related to Second Copy? - a files/folders backup utility"
USecureItProSecureitpro470p.exe"SecureIt Pro - lock your computer when you're not there
XSecurity 2009Security2009.exe"Security 2009 rogue security suite - not recommended
XSecurity essentials 2010SE2010.exe"Security Essentials 2010 rogue security software - not recommended
XSecurityScannerss2008.exe"Security Scanner 2008 rogue security software - not recommended
Xseptpop06apseptseptpop06apsept.exe"MediaMotor.Popupwithcast adware"
XServer Backboneserver05.exe"Added by the RBOT-ZM WORM!"
XServiceHostsvch0st.exe"Added by the VB.HE VIRUS!"
XServices004[worm filename]"Added by the BUGBROS WORM!"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
Xservices32mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
Xservices32mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
XSex Terisst01b.exe"Added by the REPAD WORM!"
XShellibm0000*.exe [* = digit]"Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe
XShellibm00001.dll"Added by the TORPIG-Q TROJAN!"
Xshoketsvchs0t.exe"Added by the WOWPWS-E TROJAN!"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
USIA2006SIA2006.exe"Part of Steganos Internet Anonym privacy software"
USinus 1054 data WLAN ManagerWifiusb.exeWireless management utility for the T-Com Sinus 1054 Data WLAN adapter
YSiS7012UtilitySiSAudUt.exeSiS Corporation sound card driver
?SISAM10MSISAM10M.exe"??"
USK60SK60.EXE"SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
USK9910DMSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XSmart Antivirus-2009.exeSmart Antivirus-2009.exe"Smart Antivirus 2009 rogue security software - not recommended
Xsms_msn40sms_msn40.exeAdded by an unknown WORM or TROJAN infection
Xsounddrvsndbdrv3104.exe"CoolWebSearch parasite variant"
XSP00LSVSp00lsv.exe"Added by the GRAYBIRD.E TROJAN!"
?SPC610NC_MonitorMonitor.exe"Related to the Philips SPC610NC webcam. What does it do and is it required?"
USpeedport W 100 Stick WLAN ManagerWifiusb.exeWireless management utility for the Speedport W 100 Stick WLAN USB stick
XSpool lptt01spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpool ml097espool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpyBlocs3.0SpyBlocs3.0.exe"SpyBlocs spyware remover - not recommended
XSpybott lptt01spybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpybott ml097espybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpyLocked 4.0SpyLocked 4.0.exe"Spylocked rogue spyware remover - not recommended
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
XSpywareguard lptt01Spywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareguard ml097eSpywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareRemover2009SR.exe"SpywareRemover 2009 rogue spyware remover - not recommended
XStart aThx Rollf0mered.exe"Added by the RBOT.AAV WORM!"
YStart RF Wireless Mousecm20.exeYuanxun Electronics RF wireless mouse driver
XStartwd"rundll32.exe wd081025.dllHook"
UStatus Monitor CLJ1500HPPOUMUI.exe"Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status
Xstrtasl074.exe"Added by the AGENT-II TROJAN!"
Xstup1db0t_win.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xsuckl0ad.exe"PurityScan adware"
XSunJavaUpdateSched10jushed.exe"Added by the ACKANTTA.F WORM!"
XSurfer lptt01surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSurfer ml097esurfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSV00LSVSV00LSV.EXE"Added by the GRAYBIRD-C TROJAN!"
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stWINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
XSVCH0STspoo1sv.exe"Added by the VB-HF TROJAN!"
XSVCH0STSVCH0ST.EXE"Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XSvcH0stsdhch.exe"Added by the TACTSLAY.B TROJAN!"
XSVCH0ST.EXESVCH0ST.EXE"Added by the BANCBAN-HT TROJAN!"
XSVCH0TSsp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
XsvchostSvch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xsvtcinn20050308.a.Stub.EXE"Added by the N20050308 TROJAN!"
USW20sw20.exe"Related to MSI's Dynamic Overclocking Technology"
XSymantec Antivirus professionalf0dns.exe"Added by the FORBOT-GT WORM!"
NSymantec Fax Starter Edition PortOLFSNT40.EXEOffers a virtual printer as a fax machine. Can be run via a desktop shortcut
Xsys008sys008.exe"Hijacker
Xsys009sys009.exe"Added by the STARTPA-ZB TROJAN!"
Xsys201sys209.exe"Added by the STARTPA-ZY TROJAN!"
XSysAntivirus 2009sysav.exe"SysAntivirus 2009 rogue security software - not recommended
Xsyscon lptt01syscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsyscon ml097esyscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsysfbtraybill102.exe"Added by the VB-ENI TROJAN!"
Xsysfbtraybill106.exe"Added by the MDROP-CLV TROJAN!"
Xsysldtrayld02.exe"Added by the KOOBFACE.BG WORM!"
Xsysldtrayld03.exe"Added by the KOOBFACE.CA WORM!"
XsysLDtrayld08.exe"Added by the AGENT-JSV TROJAN!"
Xsysldtrayld09.exe"Added by the AGENT-KFI TROJAN!"
Xsysldtrayld10.exe"Added by the FAKEAV-UD TROJAN!"
Xsysldtrayld01.exe"Added by the KOOBFACE.I WORM!"
Xsysldtrayld04.exe"Added by the KOOBFACE WORM!"
Xsysldtrayld06.exe"Added by the KOOBFACE WORM!"
Xsysldtrayld07.exe"Added by the KOOBFACE WORM!"
XSyslog lptt01Syslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSyslog ml097eSyslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XsysPersonalFirewalltskm0nitor.exe"Added by the SDBOT.APC WORM!"
XSystemsystem.exe (74295303)"Added by the VB-IU WORM!"
XSystemWINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
XSystemIEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
XSystem Serviceexp0lrer.exe"Added by a variant of the RBOT WORM!"
XSystem Serviceb4db0yz.exe"Added by the RBOT-CLO WORM!"
XSystemBooster2009sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
XSystemDoctor 2006 Freesd2006.exe"SystemDoctor rogue security software - not recommended
XSystemOptimizer2008main.exe"SystemOptimizer2008 rogue optimization utility - not recommended
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
Xtaskmngr lptt01taskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xtaskmngr ml097etaskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NTaskPlusTASKPLUS0.EXETask and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
NTelemeter 3.0telemeter3.exeInternet connection bandwidth meter from a user ISP
XThEwind0s.exeAdded by an unidentified WORM or TROJAN!
XTok-Cirrhatus-1959sarcsv711224030r.exe"Added by the BRONTOK-R WORM!"
XTotal PC Defender 2010Total PC Defender 2010.exe"Total PC Defender rogue security software - not recommended
XTotal Protect 2009pcpc_starter.exe"Total Protect 2009 rogue security software - not recommended
XTotalSecure2009scan.exe"Total Secure 2009 rogue security software - not recommended
Xtrackerx90.th.gsanti_data_exe_by_trackerx90.exe"Added by the BCKDR-QIT BACKDOOR!"
NTranscode360Transcode360Tray.exe"Designed for WinXP Media Center Edition 2005 and the Xbox 360
UTraymin900Tray900.exeRelated to the Philips SPC webcam - System Tray manager for Personal 900 series camera
YTrend Micro AntiVirus 2007tavui.exe"Part of Trend Micro AntiVirus 2007"
YTrueMobile 1150 Client Managercmdel.exe"Client Manager for the Dell TrueMobile 1150 Series PC Card - ""a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"""
Xtsvcinn20050308.exe"Delfin Media Viewer adware related"
XUADC_104911963UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_3240389055UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_3769470239UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_4242084050UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_815790765UADCcw.exe"AdvancedCleaner rogue security software - not recommended
NUlead Photo Express x.0 Calendarcalcheck.exe"Ulead Calendar Checker - part of Ulead Photo Express
NUniblue RegistryBooster 2009RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
XUpdateUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xupdater00t.exe"Added by the RBOT-ACO WORM!"
XUPDATEWinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
XUpdate ver 1.0Swap.exe"Added by the SWAP-C WORM!"
Nupdatev01updatev01.exeUltra-networks.com software updater/downloader
XUpdateXpSpMS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
UUpromise0Upromise0.exe"Upromise college savings program"
YUPSentry 2000upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
XUSB 2.0 DriverupdateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 DriverupdateXP.exe"Added by the AGOBOT-QP WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XUSB 2.0 DriverUpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
UUSB 3.0 Monitornusb3mon.exe"Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds"
XUSB2.0usb-hi.exe"Added by the AGENT.US WORM!"
NUserFaultCheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Xuserinitchoo_003956f4"Added by the PEED.16896 TROJAN!"
XUSERINTERFACE REPORT3RM0USE.exe"Added by the MYTOB.HS WORM!"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
NUVS10 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
UV0220Mon.exeV0220Mon.exe"Creative Live! Cam Console Auto Launcher"
UV0230Mon.exeV0230Mon.exe"Creative Live! Cam Console Auto Launcher"
YV0250Mon.exeV0250Mon.exePart of Creative Webcam Launcher
Uva10keyva10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XVBS_AUTO_UPDATE0548656X.vbs"Added by the GORMLEZ-A WORM!"
?VDI Manager (HP)HPO0VDX05.exe"HP (Hewlett-Packard) related. Now - what does it do?"
XVFW Encoder/Decoder SettingsRUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XVirRL2009VirRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended"
XVirus Shield 2009VShield.exe"Virus Shield 2009 rogue security software - not recommended
XVirusRemover2008VRM2008.exe"VirusRemover2008 rogue security software - not recommended
XVirusRemover2009VRM2009.exe"VirusRemover2009 rogue security software - not recommended
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended
XVirusRL2009VirusRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended"
XVnrBlock20VnrBlock20.exe"Berlinads adware"
XVnrPack20VnrPack20.exe"Internet Speed Monitor adware related - see example here"
NVortexTrayau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?VX1000vVX1000.exe"Associated with Microsoft's VX-1000 LifeCam webcams. What does it do and is it required?"
?VX3000vVX3000.exe"Associated with Microsoft's VX-3000 LifeCam webcams. What does it do and is it required?"
?VX6000vVX6000.exe"Associated with Microsoft's VX-6000 LifeCam webcams. What does it do and is it required?"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32PluginsDownloaderXMLHTTPSelfClearing7520wiper.exe"Added by the PROXYSER-M TROJAN!"
UWatch1200UBWATCH.EXEButton press monitor for the Mustek 1200 UB Scanner
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
Xwblogonubpr01.exe"Added by the AGENT-HFI TROJAN!"
XWebCpr0WebCpr0.exe"WebRebates adware"
XWebRebates0WebRebates0.exe"WebRebates adware"
XWebSavingsFromEbates0WebSavingsFromEbates0.exe"Web Savings From Ebates Software
Nwextract_cleanup0"advpack.dll DelNodeRunDLL32 [path] [filename].TMP"
Ywfxsnt40wfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application
?WildTangent CDA"RUNDLL32.exe cdaEngine0400.dll cdaEngineMain"
XWin Antivir 2008Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended
XWin Antivirus 2008Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWin Security 360WinSecurity360.exe"Win Security 360 rogue security software - not recommended
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWIN USB 2.0winusb.exe"Added by a variant of the RBOT WORM!"
XWin USB 2.0 USB DriverHPPrint.exe"Added by the SPYBOT.DNB WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
Xwin3208022-1336687win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinAntiSpyware 2005was5.exe"WinAntiSpyware 2005 rogue spyware remover - not recommended
XWinAntiSpyware 2006was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Freewas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Scannerwas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2007was7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntiSpyware 2007 Freewas7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntispyware2008WinAntispyware2008.exe"WinAntiSpyware 2008 rogue spyware remover - not recommended
XWinAntiVirus Pro 2007WinAv.exe"WinAntiVirus Pro 2007 rogue security software - not recommended
XWinAntiVirusPro2006WinAV.exe"WinAntiVirus Pro 2006 rogue security software - not recommended
XWIND0WSWIND0WS.exe"Added by the SPYBOT.DQ WORM!"
XWIND0WSmella.bat"Added by the ALLEM WORM!"
XWind0wswordpad.exe"Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
XWind0ws Ser7ice Agentcolwindos.exe"Added by the RBOT-GQO TROJAN!"
XWind0ws Sharingssprotecter.exe"Added by the RBOT-AHW WORM!"
XWinDefender 2008WDefDemo.exe"WinDefender 2008 rogue privacy program - not recommended
XWinDefender2009windef.exe"WinDefender 2009 rogue security software - not recommended
XWinDLL (start0s.exe)"rundll32.exe start0s.exestart"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows Frameworkscvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Media Player50cent.exe"Added by a variant of the RBOT WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows modez Verifierwinl0g0z.exe"Added by the RBOT-FNB WORM!"
XWindows NT Update ManagerWINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
XWindows Serv PatchMcaffe2005.exe"Added by a variant of the RBOT WORM!"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
?Windows shellwin70.exe"??"
XWindows Start Server 2000traficy.exe"Added by the RBOT-AHM WORM!"
XWindows svchosthappy2008.exe"Added by the PUSHBOT.AM WORM!"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows USB 2.0 Driverusb2ctrl.exe"Added by the RBOT-BIW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows Workstation Service [5.1-2600]windrm.exe"Added by the RBOT-CNY WORM!"
XWindowsFZA5281300.so"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindowz Update V2.0updater.exe"Added by the YODO-C WORM!"
YWinFaxAppPortStarterwfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
XWinFixer 2005wfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer 2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer_2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
Xwingerver2.0.exewingerver2.0.exe"Added by the GRAYBRD-AE TROJAN!"
XWINLOG0NWINLOG0N.EXE"Added by the MYDOOM.BI WORM!"
Xwinreg_32Vc030405.exe"Added by the BANCOS-CT TROJAN!"
Xwinsocksvch0st.exe"Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWinsock32driverZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
XWINSP00LWINSP00L.EXE"Added by the AGENT.XAB TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
XWinSrvkn0x.exe"Added by the HOBBIT.F WORM!"
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWinStart001WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStart001.EXEWinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinwan lptt01winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinwan ml097ewinwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin_supp00.exeWin Const.exe"Added by the ASSASIN-H TROJAN!"
UWorkPace 3.0workpace.exe"WorkPace - stress injury prevention software"
XWorkstation Ver 5.0vmware.exe"Added by the RBOT-AHB WORM!"
XWSAConfigurationmsnote30.exe"Added by the AGOBOT-KF BACKDOOR!"
XWUpdate1037v.exe"Added by the CLAGGER-AR TROJAN!"
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
XX10WeaxWTHRTRAY.EXE"WeatherCheck - ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads
Xxccinitrundll33.exe xccdf16_090131a.dll"Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
Xxccinitrundll33.exe xccdf16_090305a.dll"Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
YXircWinModem4ltcm000c.exe"WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
XXordatewuauclt10.exe"Added by the RBOT-GKN WORM!"
XXP Antispyware 2009XP_AntiSpyware.exe"XP AntiSpyware 2009 rogue spyware remover - not recommended
XXP-C300C3ACXP-C300C3AC.EXE"Added by the AUTORUN.EHW WORM!"
Xxp32winxpupdater02.exe"Added by the MOSUCK-A TROJAN!"
Xxupiterstartup2003xupiterstartup2003.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
Xxzkadsfk10afslkfasl10.exe"Added by the ONLINEG-R TROJAN!"
Xy1959sarsv711224030r.exe"Added by the BRONTOK-AK WORM and variants!"
XYahoo2000Anti.exe"Added by the RBOT.ATK WORM!"
XYahoo2000Anti.exe"Added by an unknown Malware
Xyahoo_toolbar lptt01yahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xyahoo_toolbar ml097eyahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UZeroAds0"ZeroAds - culls ads
UZeroAdsLAS0Ads.exe"ZeroAds - culls ads
XZonavirus0"Added by the KITRO.D (or ARGEN.A) WORM!"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
Xzvb0dl2X8ttNVUKZ.exe"Added by the AGENT-LMN TROJAN!"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[32 random numbers]av2009.exe"AntiVirus 2009 rogue security software - not recommended
X[32 random numbers]av360.exe"Antivirus 360 rogue security software - not recommended
X[random name]iexpl0ra.exe"Added by the ULPM.BD TROJAN!"
X[various names]10010.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]321102.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]br0ken.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]defect08.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]Dest068.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]prgsys0984.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]80d0.exe"MediaMotor adware"
U{0228e555-4f9c-4e35-a3ec-b109a192b4c2}gnotify.exe"Google Gmail Notifier. Alerts you when you have new Gmail messages"
X{05CD0D77-4947-4a56-94FA-0DF0DC644D7B}sysqyzwud.exe"Added by the FAKEALERT-AM TROJAN!"
U{1290A33C-85F5-4164-A1BE-7DD299D4986A}PBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"
X{12EE7A5E-0674-42f9-A76B-000000004D00}"rundll32.exe stlb2.dll DllRunMain"
X{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}sysqkmwfedz.exe"Added by the FAKEALERT-AH TROJAN!"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysavxjgdu.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysawpbkvnq.exe"Added by the FAKEALERT-AH TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysxhtcwbse.exe"Added by the FAKEALERT-AM TROJAN!"
X{2CF0B992-5EEB-4143-99C0-5297EF71F444}"rundll32.exe stlbdist.dllDllRunMain"
X{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"rundll32.exe stlbupdt.DLLDllRunMain"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Added by the FAKEALERT-AH TROJAN!"
X{7DD4A7AC-A3F1-4495-884A-7947C5B89108}sysahbecjh.exe"Added by the FAKEALERT-AM TROJAN!"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}syszweuas.exe"Added by the FAKEALERT-AM TROJAN!"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}sysatjsicj.exe"Added by the FAKEALERT-AM TROJAN!"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sxnwhbvrzc.exe"Added by the FAKEALERT-AM TROJAN!"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sysqrnxstju.exe"Added by the FAKEALERT-AM TROJAN!"
X{B081DB1F-4EE6-4021-9DD4-8B300F0D636D}syssngbeh.exe"Added by the FAKEALERT-AH TROJAN!"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
X{B3B48B54-C0EC-4705-8EE8-1981AEF656A7}sysjcyrq.exe"Added by the FAKEALERT-AH TROJAN!"
X{B7-7D-D0-08-ZN}dwdsregt.exe"Added by the AGENT-GBC TROJAN!"
X{BAAA759D-56F0-428c-B8DA-827EA3B08C2C}sysawechod.exe"Added by the FAKEALERT-AH TROJAN!"
X{C0FB7D08-056E-1033-0501-03020730002c}Update.exe"Added by the AGENT-EOG TROJAN!"
X{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}sysfbdgv.exe"Added by the FAKEALERT-AM TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysutrnez.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysabmpmfr.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysnxcphmgy.exe"Added by the FAKEALERT-AH TROJAN!"
X{E4785213-3EFE-4c26-A9B4-332440E31F6F}sysrxmfdksp.exe"Added by the FAKEALERT-AH TROJAN!"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sxpjbwvahn.exe"Added by the FAKEALERT-AM TROJAN!"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sysyeabdgfp.exe"Added by the FAKEALERT-AM TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.