X | IPOT USB Service DRIVER | hpsebc087.exe | "Added by the SDBOT-WA WORM!"
|
X | IPOT USB Service DRV32 | hpsebc08.exe | "Added by the SDBOT-WH WORM!"
|
N | Java(TM) Platform SE Auto Updater 2 0 | jusched.exe | "Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
|
X | JavaUpdate0.07 | [filename] | "Added by the JUPDATE TROJAN!"
|
X | JVM0 | JVM0.exe | "Added by the BANLOA-AX TROJAN!"
|
X | JVM0.12 | [random filename] | "Added by the TEADOOR-A TROJAN!"
|
X | JVM0.14 | [random filename] | "Added by the TEADOOR-B TROJAN!"
|
X | jxef1104 | jxef1104.exe | "Added by the XIPI-A WORM!"
|
Y | KAVPersonal50 | Kav.exe | "Kaspersky Anti-Virus Personal 5.0"
|
X | KAVPersonal90 | wscntfy.exe | "Added by the BANKER-FZ TROJAN!"
|
X | Kazaa lptt01 | kazaa.exe | "RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
|
X | Kazaa ml097e | kazaa.exe | "RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
|
U | KE9801 | DriBat32.exe | KE9801 multimedia keyboard driver - required if you use the multimedia keys
|
X | Kerne0223 | Kerne0223.exe | "Added by the LEGMIR-ZA TROJAN!"
|
X | kernel system daemon | ACTIVAT0R.exe | "Added by the RANDEX.AW WORM!"
|
X | kernel44.dll | "taskkill /f /fi ""PID ge 0"" /im *" | "Added by the VBS.LIDO WORM!"
|
N | kernelfaultcheck | dumprep 0 -k | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
N | kernelfaultcheck | dumprep 0 -u | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
X | Kiamat Sudah Dekat_16_04 | ISASS.exe | "Added by the PAHATIA.B WORM!"
|
U | KM9801U | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
|
U | KONICA MINOLTA magicolor 2400W STD | MSTMON_S.EXE | Konica Minolta Magicolor 2400W colour printer monitor
|
X | Kr0n1C | Kr0n1C.exe | "Added by the BRONTOK-BO WORM!"
|
X | KV2005 | word.EXE | "Added by the VB-IW TROJAN!"
|
X | kv3000 | lover.vbe | "Added by the ZSYANG.B WORM!"
|
U | KX509 | kx509_kfwk5.exe | "Kerberos Secure Authentication for Windows"
|
X | L0aders | faxneti.exe | "Added by a variant of the SDBOT TROJAN!"
|
X | laltin | L90112201.Stub.exe | "Delfin Media Viewer adware related"
|
U | LanguageMonitor | Oplmsb01.exe | OKI Printer language support monitor
|
? | LanzarL2007 | [path] setup.exe | "??"
|
U | Laplink PDASync 3.0 - LtNts4 | NtsAgnt.exe | "Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
|
N | Launch Context 5.0 | Launch.exe | "Context - electronic dictionary"
|
X | Launch Norton AntiVirus 2000 | jorgf.exe | "Added by the RBOT-AUI WORM!"
|
N | LDM | backweb-8876480.exe | "Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products |
U | Lexmark 1200 Series | lxczbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark 1200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark 2200 Series | lxbvbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark 2200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark 3100 Series | lxbrbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark 4200 Series | lxbmbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark 4200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark 5000 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark 5200 series | lxbtbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark 5200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark 5400 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark 6500 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark 7600 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark 9300 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark X1100 Series | lxbkbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark X1100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark X5100 Series | lxbabmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark X5100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
U | Lexmark X5400 Series Fax Server | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
|
U | Lexmark X6100 Series | lxbfbmgr.exe | """Lexmark Scan & Copy Control Program"" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan |
X | li-rcash00001 | vldial.exe | "Added by the Vl TROJAN!"
|
X | li01f948 | "rundll32.exe li01f948.dll | EnableRunDLL32" |
X | Life Personal Firewall | FirewallingV10.exe | "Added by the RBOT-BKF WORM!"
|
N | Line Speed Meter V3.0 | LineSpeedMeter.exe | "LineSpeedMeter - detect the download and upload speed of your internet connection"
|
X | LiveUpdate | [Windows username]05.exe | "Added by the LINEAGE TROJAN!"
|
N | load= | adw30.exe | After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
|
Y | load= | 01comm32.exe | "Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions |
X | loadMecq0 | explorer.exe | "Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
|
N | Logitech Desktop Messenger | setup-8876480.exe | "Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products |
N | LogitechQuickCamRibbon | QuickCam10.exe | "Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled |
N | LS120 Superdisk | ?? | "Supposed to accelerate transfer rate on LS-120 |
X | LTM2 | MSGSRV320.EXE | "Added by the LITMUS.C TROJAN!"
|
X | M1cr0s0ft S3rcurity | systemconfig.exe | "Added by the RBOT.BKB WORM!"
|
X | M1cr0s0ft Upd4t4zS | update32.exe | "Added by the RBOT-MI WORM!"
|
? | MacDrive7.0.4TimeOutPatch | TimeOutPatch.EXE | "Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
? | Main Executable (HP) | HP05T0R5.exe | "HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
|
X | Malware Catcher 2009 | MCatcher.exe | "Malware Catcher 2009 rogue security software - not recommended |
X | Malware Destructor 2009 | MD345d.exe | "Malware Destructor 2009 rogue security software - not recommended |
X | MalwareBurn 7.0 | MalwareBurn 7.0.exe | "MalwareBurn rogue security software - not recommended |
X | maskrider | maskrider2001.vbs | "Added by the SOLOW-G WORM!"
|
X | Mi7sft sdce | b0yz.exe | "Added by the RBOT.CWG WORM!"
|
X | Micr0s0ft Ms D0s | msdx.exe | "Added by the RBOT-AON WORM!"
|
X | Micr0s0ft Upd4t4z | svchost32.exe | "Added by the RBOT.ALF WORM!"
|
X | MicroCQ0 | explorer.exe | "Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
|
X | Microfinder lptt01 | mcf.exe | "RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Microfinder ml097e | mcf.exe | "RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | MICROSFT ANTIVIRUS UPDATE SUPPORT | [random 10-letter filename].EXE | "Added by the RBOT-AQA WORM!"
|
X | Microsft Corporation Version 2001.12.4414 | comrel.exe | "Added by a variant of the SDBOT TROJAN!"
|
X | Microsft Corporation Version 2002.12.2414 | comserv.exe | "Added by a variant of the SLAPER TROJAN!"
|
X | Microsft Windows Adapter 5.1.3013 | [random filename] | "Added by the SMALL.HIT TROJAN!"
|
X | Microsoft Agent | svch0st.exe | "Added by the VB-DRO WORM!"
|
X | Microsoft AntiSpyware | KT06.pif | "Added by the IRCBOT.GEN WORM!"
|
X | Microsoft Help | svh0st.exe | "Added by a variant of the SPYBOT WORM!"
|
U | Microsoft IME 2002 | IMJPMIG.EXE | "Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails |
X | Microsoft Internet | expl0rer.exe | "Added by a variant of the SPYBOT WORM!"
|
X | Microsoft Keyboard Enhance 2.0. | iasrecst.exe | "Added by the BCKDR-QIL BACKDOOR!"
|
X | Microsoft Keyboard Enhance V2.0 | iasrecst.exe | "Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
|
X | MicroSoft Legal Service | Srb0ty.exe | "Added by the SPYBOT.HW WORM!"
|
X | Microsoft Network Host | svc0host.exe | "Added by the SDBOT-AEN WORM!"
|
U | Microsoft Office 2010 | BCSSync.exe | "Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
|
N | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | "System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes |
X | Microsoft System Firewall 2006.2 | msmsgr.exe | "Added by a variant of the SDBOT WORM!"
|
X | Microsoft System Firewall 2006.2 | msnmsgr.exe | "Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
X | Microsoft System Firewall 2006.2 | reg32.exe | "Added by a variant of the SDBOT WORM!"
|
X | Microsoft System Init | mtmnr0.exe | "Added by the SDBOT.BR TROJAN!"
|
X | Microsoft Update | Micr0s0ft.exe | "Added by the AGOBOT.AAR WORM!"
|
X | Microsoft Update | wuamk0032.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsoft Update | wuamk032.exe | "Added by the RBOT-AHD WORM!"
|
X | Microsoft Update | wuamk0p32.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsoft Update Loaders 2005 | winusers.exe | "Added by the RBOT-AIQ WORM!"
|
X | Microsoft Update Loaders 2006 | winusersystem32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
X | Microsoft Update Machine | expl0rer.exe | "Added by the SDBOT.OK WORM!"
|
X | Microsoft Update Machine | system03.exe | "Added by the RBOT-NM WORM!"
|
X | Microsoft Updating Machine | sysc0de.exe | "Added by the RBOT.RB WORM!"
|
X | MicroSoft Wind0ws Updater | winsupdater.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsoft Windows | mstask0.exe | "Added by the SDBOT.FQ WORM!"
|
X | Microsoft Windows 2000 | Winupdsdgm.exe | "Added by the GAOBOT.AO WORM!"
|
X | Microsoft Windows Expl0rer | expl0rer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Microsoft Windows Visual V2.0 | msiutil.exe | "Added by the DELF.JPH TROJAN!"
|
X | Microsoft Windows WKS Service | mstask0.exe | "Added by the SDBOT.FV WORM!"
|
X | Microsoft WinUpdate | mntcgf032.exe | "Added by the RBOT-PF WORM!"
|
X | Microsoft WinUpdate | svh0st.exe | "Added by the SPYBOT.DL WORM!"
|
X | microsoft xdaemon 2.0 | xdaemon.exe | "Added by the DELF.D TROJAN!"
|
X | microsoft420 | microsoft420.exe | "Added by the MENACE.B WORM!"
|
N | Microsoft® Works 7.0 | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
|
X | Micrsoft Internet Explorer | IEXPL0RE.EXE | "Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
|
X | ml00!.exe | ml00!.exe | "Malware |
X | Mlcr0s0ftf DDEs C0ntr0i | WAed.pif | "Added by the RBOT-BJW WORM!"
|
X | mmnext06 | trjdwnl.dll | "Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
|
X | Modulo 00FE0F01 Host Internet | syschost.exe | "Added by the DELF-KW TROJAN!"
|
N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs
|
X | motoin | mm15201518.Stub.exe | "Delfin Promulgate adware variant"
|
X | Mozilla Firebird v0.8 Internet Browser | netstats.exe | "Added by the IRCBOT.MC TROJAN!"
|
X | Mozilla Firefox | F1REF0X.EXE | "Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers ""1"" and ""0"" in place of upper case ""i"" and ""o"" respectively"
|
X | MS AntiSpyware 2009 | msas2009.exe | "MS AntiSpyware 2009 rogue spyware remover - not recommended |
X | MS MSN Menssenger 7.0 | MSMSN7.exe | "Added by the RBOT-ACA WORM!"
|
X | MS MSN Menssenger 7.0 | MSEXPORT.exe | "Added by a variant of the SDBOT WORM!"
|
X | MS Office | Office10.exe | "Added by the VB.DT TROJAN!"
|
X | MS Unix Binary | Norton2005Update.exe | "Added by a variant of the RBOT WORM!"
|
X | MS USB 2.0 Windows Support | msusb32.exe | "Added by a variant of the RBOT WORM!"
|
X | mscheck | rundll32.exe wincheck071008.dll mymain | "Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
|
X | Msconfig lptt01 | msconfig.exe | "RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
|
X | Msconfig ml097e | msconfig.exe | "RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
|
X | msig | disk10.exe | "Added by the BANBRA-KF TROJAN!"
|
X | MSkernel32 | System.exe 4820 | "Added by the TUXDER BACKDOOR!"
|
X | Mslogon lptt01 | mslogon.exe | "RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Mslogon ml097e | mslogon.exe | "RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Msn 8.0 Live | msn.exe | "Added by the BANKER.EIE TROJAN!"
|
X | MSN 9.0 Plus | [random letters].exe | "Added by the RBOT-ALY WORM!"
|
X | MSN MESSENGER 9.0 | messengerr.exe | "Added by a variant of the RBOT WORM!"
|
N | MSN Webcam Recorder | ml20gui.exe | """MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"""
|
U | MSPY2002 | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
X | MsServer | msfun80.exe | "Added by the VB-CYG WORM!"
|
X | MsServer | msfir80.exe | "Added by the VB-CYJ TROJAN!"
|
X | MSService_v1.0 | realsched.exe | "EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
|
X | MSService_v1.0 | vfp02.exe | "NewWeb adware"
|
X | mssurfer lptt01 | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | mssurfer ml097e | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | mssync20 | mssync20.exe | "Added by the LDPINC-QC TROJAN!"
|
X | MSVBVM60 | MSVBVBM60.pif | "Added by the SCOLD-B WORM!"
|
X | MSVersion | clrschp038.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
X | msys lptt01 | msys.exe | "RapidBlaster variant (in a ""Msyss"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | MS_update_0704_KB74073.exe | MS_update_0704_KB74073.exe | "Added by a variant of the UPDATEKB TROJAN!"
|
X | mule_st_key | flec006.exe | "Added by the BAGLE.AV TROJAN!"
|
N | Music01 Server | Music01 Server.exe | "J River Media Jukebox"
|
? | Mustek MDC 3000 | Mounter.exe | "Related to software for the Mustek MDC 3000 digital camera - what does it do and is it required?"
|
X | myMh2 | iexpl0re.exe | "Added by the AGENT.HWE TROJAN! Note the number ""0"" in the filename"
|
X | Name | Iexplorer0.exe | "Added by the THREADSYS TROJAN!"
|
X | nana2009 | nana2009.exe | "Added by the POISON.PG BACKDOOR!"
|
X | navman_20 | sysnav32.exe | "Hijacker |
X | NC1565 | winntsrv -l -p10001 -d -e cmd.exe -L | "Added by the NEWLEY-A WORM!"
|
? | NetFxUpdate_v1.0.3705 | netfxupdate.exe | "Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
|
Y | NettGain2000 | WgwMngr.exe | "Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution |
Y | NettGain2000 Verifier | NettGain2000 Verifier.exe | Part of the Starband satellite client that attempts to optimize your satellite connection to increase speed
|
X | Newsgroup lptt01 | newsgroup.exe | "RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Newsgroup ml097e | newsgroup.exe | "RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | NI.ERS_9999_N91S3108 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
X | NI.GA6PU_0001_N108E1308 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
X | NI.GA6PU_0001_N120C2910 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
X | NI.GA6P_0001_N105E2704 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N108E1606 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
X | NI.GA6P_0001_N111C1707 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N115C0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N115E0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N122C0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N122C2210 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N122C2802 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_0001_N122E0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.GA6P_2001_N108E1606 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
X | NI.GDCDE_0001_N122C1912 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
X | NI.GDC_0001_N111C1909 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.GDC_0001_N122C1912 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.GES_0001_N122C2610 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UAVIFR_0001_N105M2404 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
X | NI.UERSM_0001_N68M1602 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
X | NI.UGA6PH_0001_N122M2910 | [path to file] | "Installer for the AntiVirusAskeladd rogue security software - see here"
|
X | NI.UGA6PK_0001_N122M1302 | [path to file] | "Installer for the VirusForsvar Danish rogue security software - see here"
|
X | NI.UGA6PL_0001_N108M2808 | [path to file] | "Installer for the VirusSchlacht Swedish rogue security software - see here"
|
X | NI.UGA6PL_0001_N120M1302 | [path to file] | "Installer for the VirusSchlacht Swedish rogue security software - see here"
|
X | NI.UGA6PM_0001_N108M2108 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
X | NI.UGA6PM_0001_N122M1202 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
X | NI.UGA6PM_0001_N122M3010 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
X | NI.UGA6PT_0001_N108M2208 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
X | NI.UGA6PT_0001_N122M1202 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
X | NI.UGA6PT_0001_N122M2910 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
X | NI.UGA6PU_0001_N108M1308 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
X | NI.UGA6PU_0001_N120M1202 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
X | NI.UGA6PU_0001_N120M2910 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
X | NI.UGA6PV_0001_N108M0207 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
X | NI.UGA6PV_0001_N122M1202 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
X | NI.UGA6PV_0001_N122M2910 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
X | NI.UGA6P_0001_N105M2704 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N111M1707 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N115M0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N119M1510 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N120M1710 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N122M0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N122M2210 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0001_N122M2802 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_0007_N125M2002 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
X | NI.UGA6P_1001_N122M0402 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_1002_N122M1402 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_4001_N122M2111 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_5001_N122M1902 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGA6P_5555_N122M0312 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
X | NI.UGDC1_0001_N119M0911 | [path to file] | "Installer for the FilterProgram rogue privacy tool - see here"
|
X | NI.UGDCCZ_0001_N122M0307 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
X | NI.UGDCCZ_0001_N122M0511 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
X | NI.UGDCCZ_0001_N122M1712 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
X | NI.UGDCDE_0001_N111M3007 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
X | NI.UGDCDE_0001_N122M1912 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
X | NI.UGDCGR_0001_N122M0307 | [path to file] | "Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
|
X | NI.UGDCGR_0001_N122M1812 | [path to file] | "Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
|
X | NI.UGDCNL_0001_N111M3007 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
X | NI.UGDCNL_0001_N122M1912 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
X | NI.UGDCNL_0001_N122M3011 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
X | NI.UGDCPL_0001_N108M0207 | [path to file] | "Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
|
X | NI.UGDCPL_0001_N122M2012 | [path to file] | "Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
|
X | NI.UGDCRU_0001_N111M0208 | [path to file] | "Installer for the SanitarDiska Romanian rogue privacy tool - see here"
|
X | NI.UGDCRU_0001_N122M2012 | [path to file] | "Installer for the SanitarDiska Romanian rogue privacy tool - see here"
|
X | NI.UGDCTH_0001_N122M1712 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
X | NI.UGDCTR_0001_N108M0407 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N108M0407 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N111M1909 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M0502 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M1912 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M2603 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M2610 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M2802 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0001_N122M2811 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGDC_0002_N108M1007 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
X | NI.UGDC_0003_N108M2407 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
X | NI.UGESF_0001_N122M0201 | [path to file] | "Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
|
X | NI.UGESL_0001_N105M0405 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
X | NI.UGESL_0001_N122M0303 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
X | NI.UGESL_0001_N122M2911 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
X | NI.UGESM_0001_N122M0303 | [path to file] | "Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
|
X | NI.UGESV_0001_N108M2006 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
X | NI.UGESV_0001_N122M0303 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
X | NI.UGESV_0001_N122M2811 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
X | NI.UGESV_0001_N122M3010 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
X | NI.UGES_0001_N108M2006 | setup_en.exe | "Installer for the MyContentAssistant rogue privacy tool"
|
X | NI.UGES_0001_N122M0502 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UGES_0001_N122M2111 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UGES_0001_N122M2602 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UGES_0001_N122M2603 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UGES_0001_N122M2610 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UGES_0002_N108M1607 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
X | NI.UWA6P_0001_N56M1001 | WinAntiVirusPro2006Installer.exe | "Installer for the WinAntiVirus Pro 2006 rogue security software"
|
X | NI.UWA6P_0001_N69M0303 | WinAntiVirusPro2006Installer[1].exe | "Installer for the WinAntiVirus Pro 2006 rogue security software"
|
X | NI.UWA6P_0001_N73M1004 | WinAntiVirusPro2006FreeInstall.exe | "Installer for the WinAntiVirus Pro 2006 rogue security software"
|
X | NI.UWA6P_0001_N91M1807 | WinAntiVirusPro2006FreeInstall[1].exe | "Installer for the WinAntiVirus Pro 2006 rogue security software"
|
X | NI.UWA7P_0001_N91M0809 | WinAntiVirusPro2007FreeInstall.exe | "Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
|
X | NI.UWAS5LP_0001_0811 | UWAS5LP_0001_0811NetInstaller.exe | "Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended |
X | NI.UWAS6_0001_N57M1312 | WinAntiSpyware2006FreeInstall.exe | "Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended |
X | NI.UWAS6_0001_N68M2301 | UWAS6_0001_N68M2301NetInstaller.exe | "Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended |
X | NI.UWFX5 | WinFixer2005ScannerInstall.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX5LP_0001_0614 | UWFX5LP_0001_0614NetInstaller.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX5LP_0001_0715 | UWFX5LP_0001_0715NetInstaller.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX5LP_0001_0802 | UWFX5LP_0001_0802NetInstaller.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX5LP_0001_0803 | UWFX5LP_0001_0803NetInstaller.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX5V_0001_0802 | UWFX5V_0001_0802NetInstaller.exe | "WinFixer 2005 web installer - ""foistware"" |
X | NI.UWFX6_0001_N68M2301 | UWFX6_0001_N68M2301NetInstaller.exe | "WinFixer 2006 web installer - ""foistware"" |
X | NJG40 | NJG40.EXE | "Added by the BANCOS.D TROJAN!"
|
U | No-IP DUC | DUC20.exe | "Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available"
|
X | Nod3d2 Free antivirus | N0D32KRN.EXE | "Added by the RBOT-ABQ WORM!"
|
X | Norton Antivirus 2004 | SYMANTECAV2.EXE | "Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV!"
|
X | Norton Antivirus 7.0a | [path to file] | "Added by the PERDA-B or RANCK-CT TROJANS!"
|
N | Norton Ghost 10.0 | GhostTray.exe | "Norton Ghost tray icon - the application can be launched manually"
|
N | Norton Ghost 9.0 | GhostTray.exe | "Norton Ghost tray icon - the application can be launched manually"
|
X | Notepad lptt01 | notepad.exe | "RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
|
X | Notepad ml097e | notepad.exe | "RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
|
X | nsvcin | n20050308.exe | "Delfin Media Viewer adware related"
|
X | ntechin | n20050308.exe | "Delfin Media Viewer adware related"
|
X | Numerical Xterm Agent | 0x32.exe | "Added by the RBOT-FWP WORM!"
|
X | nvd32 lptt01 | nvd32.exe | "RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | nvd32 ml097e | nvd32.exe | "RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
U | nwss | Sp0.exe | "SpyOutside surveillance software. Uninstall this software unless you put it there yourself"
|
X | NZ01 | NZ01.exe | "Added by the SCAR-K TROJAN!"
|
U | OEM02Mon.exe | OEM02Mon.exe | "Creative Live! Cam Console Auto Launcher"
|
? | OEM07Mon.exe | OEM07Mon.exe | "Related to Live Camera Console Auto Launcher by Creative Technology LTD. What does it do and is it required?"
|
X | OESET | setup60.exe | "Added by the WAREZDL.28672 TROJAN!"
|
? | officejet 6100 | hposol08.exe | Associated with a HP PSC2110 (and maybe others) all-in-one machine
|
N | OneNote 2007 Screen Clipper and Launcher | ONENOTEM.EXE | "System Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes |
X | OpenGL Drivers | 0penGLD.exe | "Added by the YIMP-A WORM!"
|
X | OPQFile | regedit.exe /s ...rad03FA6.tmp | Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
|
X | P Antispyware 09 | pas.exe | "P Antispyware 09 rogue security software - not recommended |
X | P0w3rF1Y | svchost.exe | "Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
U | P3000x_S2P | ScanToPc.exe | Dell Laser MFP 1600N network application for scanning files to the PC
|
U | PAC7302_Monitor | Monitor.exe | "Related to PixArt CMOS image sensors from PixArt Imaging Inc"
|
N | Palo Alto Software Update Manager 8.0 | PAS8_UD.exe | "Update manager for small business planning software from Palo Alto Software - such as Business Plan Pro |
N | PaperPort PTD | pptd40nt.exe | "Part of Nuance (ScanSoft) PaperPort - ""scan |
X | PC Antispyware 2010 | PC_Antispyware2010.exe | "PC Antispyware 2010 rogue security software - not recommended |
X | PC Security 2009 | PC_Security2009.exe | "PC Security 2009 rogue security software - not recommended |
X | PCMM2007RT | pcmm2007.exe | "PC MightyMax 2007 rogue security software - not recommended |
U | PD0620 STISvc | P0620Pin.dll | Creative Technology Ltd installation plug-in related
|
U | PDUiP6000DMon | PDUiP6000DMon.exe | "Memory Card Utility for the Canon PIXMA iP6000D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
U | PDUiP6000DTskbr | PDUiP6000DTskbr.exe | "Memory Card Utility for the Canon PIXMA iP6000D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
U | PDUiP6210DMon | PDUiP6210DMon.exe | "Memory Card Utility for the Canon PIXMA iP6210D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
U | PDUiP6220DMon | PDUiP6220DMon.exe | "Memory Card Utility for the Canon PIXMA iP6220D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
U | PDUiP6600DMon | PDUiP6600DMon.exe | "Memory Card Utility for the Canon PIXMA iP6600D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
U | PDUiP6700DMon | PDUiP6700DMon.exe | "Memory Card Utility for the Canon PIXMA iP6600D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
|
X | PeqBL100 | PEQBL100.exe | "Added by the ENVID.D WORM!"
|
X | Perfect Defender 2009 | pdfndr.exe | "Perfect Defender 2009 rogue security software - not recommended |
N | PerfectPrint | pfppop70.exe | Print engine used by Corel WordPerfect 7 and Presentations 7
|
X | Personal Defender 2009 | pdefendr.exe | "Personal Defender 2009 rogue security software - not recommended |
X | Pest-Patrol 2.1.0 | Pest-Patrol.exe | "Pest-Patrol rogue security software - not recommended |
U | Petit Larousse 2001 | HIPL2000Popup.exe | Popup dictionary tool
|
U | PFM3.0 | PFM30.exe | "Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device |
U | PFM30 | PFM30.exe | "Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device |
U | phc700 | vphc700.exe | "Related to the Philips SPC700NC web camera"
|
U | Philips PhotoFrame Manager | PFM30.exe | "Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device |
U | PHIME2002A | TINTSETP.EXE | "Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails |
U | PHIME2002ASync | TINTSETP.EXE | "Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails |
X | PHIME2004C | CTFMDN.exe | "Added by the DLOADR-AMV TROJAN!"
|
? | PLFFAP | HotfixQ0306270.exe | "Prolific Technology Inc. USB Flash Disk driver - is it required in startup?"
|
X | pop06ap | pop06ap2.exe | "MediaMotor adware"
|
X | pop06apelt | thiselt.exe | "ZenoSearch adware"
|
X | Power-Antivirus-2009 | Power-Antivirus-2009.exe | "Power Antivirus 2009 rogue security software - not recommended |
X | PowerProfile | mfcp30.exe | "Added by the RINDAS-A TROJAN!"
|
? | PowerSet | Regedit.exe /s ...PowerSet_8100_CU.REG | "Appears to be Toshiba power management related"
|
U | PP2000 Instaupdate | PPInupdt.exe | Protector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
|
Y | PP2000 Real Time Scan | PPVstop.exe | Protector Plus anti-virus software - real time scanner
|
Y | PP2000 Taskbar Control | PPTbc.exe | Protector Plus anti-virus software - system tray access
|
N | PP3100b | flatbed.exe | "Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan |
N | PPort10reminder | Ereg.exe ereg.ini | "Registration reminder for PaperPort version 10 from Scansoft (now Nuance)"
|
N | pptd40nt | pptd40nt.exe | "Part of Nuance (ScanSoft) PaperPort - ""scan |
N | Printkey2000 | printkey2000.exe | Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
|
X | Pro Antispyware 2009 | proas2009.exe | "Pro AntiSpyware 2009 rogue spyware remover - not recommended |
X | Program Access Service | [10 random letters].exe | "Added by the RBOT.GJJ WORM!"
|
X | Proof Defender 2009 | pdfndr.exe | "Proof Defender 2009 rogue security software - not recommended |
X | Protected Storage | RUNDLL32.EXE MSSIGN30.DLL ondll_reg | "Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
U | PUAC v2.0.7 | Puac.exe | """Peter's Ultimate Alarm Clock"""
|
U | Purgative | PURGATIVE100.EXE | AIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
|
N | Q152404 | wsript.exe Q152404.VBS | Appears to run Scandisk at bootup on NEC PCs
|
X | QdrModule10 | QdrModule10.exe | "Internet Speed Monitor adware"
|
X | QdrPack10 | QdrPack10.exe | "Internet Speed Monitor H adware"
|
N | QSort2000 | QSORT.EXE | Utility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"
|
N | QuickCam10 | QuickCam10.exe | "Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled |
N | QuickCam10.exe | QuickCam10.exe | "Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled |
N | QuickFinder Scheduler | QFSCHD100.exe | Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
|
N | QuickFinder Scheduler | QFSCHD110.EXE | "Used in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
|
N | QuickFinder Scheduler | QFSCHD130.EXE | "Used in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
|
X | QuickInstallPack | CLN_2009FreeInstall.exe | "Installed and used by rogue security products such as Cleaner2009 |
X | Quicktime Pro 3.0 | winuodps.exe | "Added by the GAOBOT.BH WORM!"
|
U | QWS3270 Sessions | sessions.exe | QWS3270 Secure terminal emulation software
|
N | RaConfig2500 | RaConfig2500.exe | "RaLink wireless LAN configuration utility"
|
X | ravshell | expl0rer.exe | "Added by the DLOADER.MAR TROJAN!"
|
X | Ravshell | svch0st.exe | "Added by the NSPM.PU TROJAN! Notice the digit ""0"" in the filename rather than the lower case ""O"""
|
X | ravshell | iexpl0re.exe | "Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
|
X | ravtask | svch0st.exe | "Added by the LINEAG-AIN TROJAN!"
|
X | ravtask | iexpl0re.exe | "Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
|
X | rb32 lptt01 | rb32.exe | "RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | rb32 ml097e | rb32.exe | "RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | readdb40 | "rundll32.exe readdb40.dll | EnableRunDLL32" |
? | readericon10 | readericon10.exe | "Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required?"
|
X | realone_nt2003 | moniker.exe | "Added by the SNONE.A WORM!"
|
X | realplay lptt01 | realplay.exe | "RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
|
X | realplay ml097e | realplay.exe | "RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
|
X | RebateNation0 | RebateNation0.exe | "RebateNation adware"
|
X | Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | RH.DLL | "SmartPops search hijacker"
|
X | Recycle Bin Handler 2005 | system.exe | "Added by the BDOOR-HO BACKDOOR!"
|
U | reg2.0 | SVCH0ST.EXE | "eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | Regcheck | ~CAB001.EXE | "Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
|
U | Registry | class0117[random].exe | "Blackbox captures emails and chat logs |
X | RegistryDoctor2008 | registrydoctor.exe | "RegistryDoctor2008 rogue registry cleaner - not recommended |
X | REGRUN | winfix22490.exe | "Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
|
Y | Regx10EXE | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it
|
X | Remove 54tr10 | smss.exe | "Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
|
U | ResChanger2004 | ResChanger2004.exe | EVGA graphic card utility providing easy access to display settings
|
N | RFX_auto_upgrade | rundll32.exe npvpg005.dll | "A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
|
U | rmoc3260.dll OCX | regsvr32.exe rmoc3260.dll | "A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The ""rmoc3260.dll"" file is found in %System%"
|
X | Roam04 | ActiveX.exe | "Added by the ROAMER-A TROJAN!"
|
N | RoxWatchTray | RoxWatchTray10.exe | "System Tray access to managing the ""Watched Folders"" |
N | RoxWatchTray10 | RoxWatchTray10.exe | "System Tray access to managing the ""Watched Folders"" |
X | Run05 | rundll_32.exe | "Added by the BANCOS-DT TROJAN!"
|
X | rundll32 | svchs0t.exe | "Added by the PWSTEAL-E TROJAN!"
|
X | Rundll32_7 | "rundll32.exe MSIEFR40.DLL | DllRunServer" |
X | Rundll32_8 | "rundll32.exe inetp60.dll | DllRunServer" |
X | RUNLOAD | l0ad.exe | "PurityScan/Clickspring adware"
|
X | S0undMan | svch0st.exe | "Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | s9201 | av2008xp.exe | "Antivirus 2008 XP rogue security software - not recommended |
X | s9201 | as2008xp.exe | "AntiSpyware XP 2008 rogue spyware remover - not recommended |
X | s9201 | asproxp.exe | "AntiSpyware Pro XP rogue spyware remover - not recommended |
X | Safeguard 2009 | sf2009.exe | "Safeguard 2009 rogue spyware remover - not recommended |
X | SAHBundle | shop1003.exe | "ShopAtHomeSelect parasite"
|
U | Samsung MJC-900 Series Monitor | "RUNDLL32.EXE SMMASHLL.DLL | AutoUpdatePnPValue" |
U | Say The Time 5.0 | SAYTIME.EXE | "This program has audio cues for the system clock in male and female voices |
X | SBR2009F | SystemBooster2009.exe | "SystemBooster2009 rogue system suite - not recommended |
Y | SC3300CC | SC3300CC.exe | SiPix digital camera Twain device driver
|
X | scain | s030109.Stub.exe | "Delfin Media Viewer adware related"
|
N | ScanSoft OmniPage SE 4.0-reminder | Ereg.exe ereg.ini | "Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
|
N | ScreenHunter 4.0 Free | ScreenHunter.exe | """ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
|
U | Scroll-In-Mouse V2.0 | SCROLL.EXE | "Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
|
X | SDKcore Update Components2 | SDKC0R3.exe | "Added by the RBOT-ABA WORM!"
|
X | sdkupdate22 | SDK0mCORE.exe | "Added by the FORBOT-DT WORM!"
|
X | SDKz0r | SDKc55rezzz2.exe | "Added by the SDBOT-UN WORM!"
|
U | sds20 | svchost.exe | "InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
|
U | Second Copy 2000 | SecCopy.exe | "Related to Second Copy? - a files/folders backup utility"
|
U | SecureItPro | Secureitpro470p.exe | "SecureIt Pro - lock your computer when you're not there |
X | Security 2009 | Security2009.exe | "Security 2009 rogue security suite - not recommended |
X | Security essentials 2010 | SE2010.exe | "Security Essentials 2010 rogue security software - not recommended |
X | SecurityScanner | ss2008.exe | "Security Scanner 2008 rogue security software - not recommended |
X | septpop06apsept | septpop06apsept.exe | "MediaMotor.Popupwithcast adware"
|
X | Server Backbone | server05.exe | "Added by the RBOT-ZM WORM!"
|
X | ServiceHost | svch0st.exe | "Added by the VB.HE VIRUS!"
|
X | Services004 | [worm filename] | "Added by the BUGBROS WORM!"
|
X | services32 | mc-110-12-0000079.exe | Added by the TrojanDownloader.Agent.rv TROJAN!
|
X | services32 | mc-58-12-0000120.exe | """Shorty"" adware - also detected as the AGENT.FD TROJAN!"
|
X | services32 | mc-58-12-0000140.exe | """Shorty"" adware - also detected as the AGENT.FD TROJAN!"
|
X | Sex Teris | st01b.exe | "Added by the REPAD WORM!"
|
X | Shell | ibm0000*.exe [* = digit] | "Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe |
X | Shell | ibm00001.dll | "Added by the TORPIG-Q TROJAN!"
|
X | shoket | svchs0t.exe | "Added by the WOWPWS-E TROJAN!"
|
? | ShowIcon_Justrams_USB Product Driver v2.12r012 | shwicon.exe | "Related to Just Rams USB product driver. Is it required?"
|
? | ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 | shwicon.exe | "Card reader for memory cards from digital cameras. Is it required? "
|
U | SIA2006 | SIA2006.exe | "Part of Steganos Internet Anonym privacy software"
|
U | Sinus 1054 data WLAN Manager | Wifiusb.exe | Wireless management utility for the T-Com Sinus 1054 Data WLAN adapter
|
Y | SiS7012Utility | SiSAudUt.exe | SiS Corporation sound card driver
|
? | SISAM10M | SISAM10M.exe | "??"
|
U | SK60 | SK60.EXE | "SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
|
U | SK9910DM | SK9910DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
X | Smart Antivirus-2009.exe | Smart Antivirus-2009.exe | "Smart Antivirus 2009 rogue security software - not recommended |
X | sms_msn40 | sms_msn40.exe | Added by an unknown WORM or TROJAN infection
|
X | sounddrv | sndbdrv3104.exe | "CoolWebSearch parasite variant"
|
X | SP00LSV | Sp00lsv.exe | "Added by the GRAYBIRD.E TROJAN!"
|
? | SPC610NC_Monitor | Monitor.exe | "Related to the Philips SPC610NC webcam. What does it do and is it required?"
|
U | Speedport W 100 Stick WLAN Manager | Wifiusb.exe | Wireless management utility for the Speedport W 100 Stick WLAN USB stick
|
X | Spool lptt01 | spool.exe | "RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Spool ml097e | spool.exe | "RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | SpyBlocs3.0 | SpyBlocs3.0.exe | "SpyBlocs spyware remover - not recommended |
X | Spybott lptt01 | spybott.exe | "RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Spybott ml097e | spybott.exe | "RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | SpyLocked 4.0 | SpyLocked 4.0.exe | "Spylocked rogue spyware remover - not recommended |
X | SpywareGuard | deinst_qfe001.exe | "Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
|
X | Spywareguard lptt01 | Spywareguard.exe | "RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Spywareguard ml097e | Spywareguard.exe | "RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | SpywareRemover2009 | SR.exe | "SpywareRemover 2009 rogue spyware remover - not recommended |
X | Start aThx Roll | f0mered.exe | "Added by the RBOT.AAV WORM!"
|
Y | Start RF Wireless Mouse | cm20.exe | Yuanxun Electronics RF wireless mouse driver
|
X | Startwd | "rundll32.exe wd081025.dll | Hook" |
U | Status Monitor CLJ1500 | HPPOUMUI.exe | "Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status |
X | strtas | l074.exe | "Added by the AGENT-II TROJAN!"
|
X | stup1db0t | _win.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
X | suck | l0ad.exe | "PurityScan adware"
|
X | SunJavaUpdateSched10 | jushed.exe | "Added by the ACKANTTA.F WORM!"
|
X | Surfer lptt01 | surfer.exe | "RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Surfer ml097e | surfer.exe | "RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | SV00LSV | SV00LSV.EXE | "Added by the GRAYBIRD-C TROJAN!"
|
X | SvcH0st | msexploren.exe | "Added by the BACKDOOR-CGZ TROJAN!"
|
X | SvcH0st | SHCH.EXE | "Added by the BDOOR-EB BACKDOOR!"
|
X | SvcH0st | SVCHST.EXE | "Added by the BDOOR-EB BACKDOOR!"
|
X | SvcH0st | WINAGENT.EXE | "Added by the BDOOR-EB BACKDOOR!"
|
X | SVCH0ST | spoo1sv.exe | "Added by the VB-HF TROJAN!"
|
X | SVCH0ST | SVCH0ST.EXE | "Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | SvcH0st | msnexploren.exe | "Added by the TACTSLAY.B TROJAN!"
|
X | SvcH0st | sdhch.exe | "Added by the TACTSLAY.B TROJAN!"
|
X | SVCH0ST.EXE | SVCH0ST.EXE | "Added by the BANCBAN-HT TROJAN!"
|
X | SVCH0TS | sp00lvs.exe | "Added by the LINEAGE-AZ TROJAN!"
|
X | svchost | Svch0st.exe | "Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | svtcin | n20050308.a.Stub.EXE | "Added by the N20050308 TROJAN!"
|
U | SW20 | sw20.exe | "Related to MSI's Dynamic Overclocking Technology"
|
X | Symantec Antivirus professional | f0dns.exe | "Added by the FORBOT-GT WORM!"
|
N | Symantec Fax Starter Edition Port | OLFSNT40.EXE | Offers a virtual printer as a fax machine. Can be run via a desktop shortcut
|
X | sys008 | sys008.exe | "Hijacker |
X | sys009 | sys009.exe | "Added by the STARTPA-ZB TROJAN!"
|
X | sys201 | sys209.exe | "Added by the STARTPA-ZY TROJAN!"
|
X | SysAntivirus 2009 | sysav.exe | "SysAntivirus 2009 rogue security software - not recommended |
X | syscon lptt01 | syscon.exe | "RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | syscon ml097e | syscon.exe | "RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | sysfbtray | bill102.exe | "Added by the VB-ENI TROJAN!"
|
X | sysfbtray | bill106.exe | "Added by the MDROP-CLV TROJAN!"
|
X | sysldtray | ld02.exe | "Added by the KOOBFACE.BG WORM!"
|
X | sysldtray | ld03.exe | "Added by the KOOBFACE.CA WORM!"
|
X | sysLDtray | ld08.exe | "Added by the AGENT-JSV TROJAN!"
|
X | sysldtray | ld09.exe | "Added by the AGENT-KFI TROJAN!"
|
X | sysldtray | ld10.exe | "Added by the FAKEAV-UD TROJAN!"
|
X | sysldtray | ld01.exe | "Added by the KOOBFACE.I WORM!"
|
X | sysldtray | ld04.exe | "Added by the KOOBFACE WORM!"
|
X | sysldtray | ld06.exe | "Added by the KOOBFACE WORM!"
|
X | sysldtray | ld07.exe | "Added by the KOOBFACE WORM!"
|
X | Syslog lptt01 | Syslog.exe | "RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | Syslog ml097e | Syslog.exe | "RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | sysPersonalFirewall | tskm0nitor.exe | "Added by the SDBOT.APC WORM!"
|
X | System | system.exe (74295303) | "Added by the VB-IU WORM!"
|
X | System | WINL0G0N.EXE | "Added by the BANCOS-DB TROJAN!"
|
X | System | IEXPL0RE.EXE | "Added by the VB.KS WORM! Note the number ""0"" in the filename"
|
X | System Service | exp0lrer.exe | "Added by a variant of the RBOT WORM!"
|
X | System Service | b4db0yz.exe | "Added by the RBOT-CLO WORM!"
|
X | SystemBooster2009 | sbr_updater.exe | "SystemBooster2009 rogue system suite - not recommended |
X | SystemDoctor 2006 Free | sd2006.exe | "SystemDoctor rogue security software - not recommended |
X | SystemOptimizer2008 | main.exe | "SystemOptimizer2008 rogue optimization utility - not recommended |
X | Systems | svch0st.exe | "Added by the MYDOOM.BI WORM!"
|
X | taskmngr lptt01 | taskmngr.exe | "RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | taskmngr ml097e | taskmngr.exe | "RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
N | TaskPlus | TASKPLUS0.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
|
N | Telemeter 3.0 | telemeter3.exe | Internet connection bandwidth meter from a user ISP
|
X | ThE | wind0s.exe | Added by an unidentified WORM or TROJAN!
|
X | Tok-Cirrhatus-1959sarc | sv711224030r.exe | "Added by the BRONTOK-R WORM!"
|
X | Total PC Defender 2010 | Total PC Defender 2010.exe | "Total PC Defender rogue security software - not recommended |
X | Total Protect 2009 | pcpc_starter.exe | "Total Protect 2009 rogue security software - not recommended |
X | TotalSecure2009 | scan.exe | "Total Secure 2009 rogue security software - not recommended |
X | trackerx90.th.gs | anti_data_exe_by_trackerx90.exe | "Added by the BCKDR-QIT BACKDOOR!"
|
N | Transcode360 | Transcode360Tray.exe | "Designed for WinXP Media Center Edition 2005 and the Xbox 360 |
U | Traymin900 | Tray900.exe | Related to the Philips SPC webcam - System Tray manager for Personal 900 series camera
|
Y | Trend Micro AntiVirus 2007 | tavui.exe | "Part of Trend Micro AntiVirus 2007"
|
Y | TrueMobile 1150 Client Manager | cmdel.exe | "Client Manager for the Dell TrueMobile 1150 Series PC Card - ""a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"""
|
X | tsvcin | n20050308.exe | "Delfin Media Viewer adware related"
|
X | UADC_104911963 | UADCcw.exe | "AdvancedCleaner rogue security software - not recommended |
X | UADC_3240389055 | UADCcw.exe | "AdvancedCleaner rogue security software - not recommended |
X | UADC_3769470239 | UADCcw.exe | "AdvancedCleaner rogue security software - not recommended |
X | UADC_4242084050 | UADCcw.exe | "AdvancedCleaner rogue security software - not recommended |
X | UADC_815790765 | UADCcw.exe | "AdvancedCleaner rogue security software - not recommended |
N | Ulead Photo Express x.0 Calendar | calcheck.exe | "Ulead Calendar Checker - part of Ulead Photo Express |
N | Uniblue RegistryBooster 2009 | RegistryBooster.exe | "RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean |
X | Update | UPDATE-28062004.exe[25 blank spaces].vbs | "Added by the MIDFIN WORM!"
|
X | update | r00t.exe | "Added by the RBOT-ACO WORM!"
|
X | UPDATE | WinUpdater5.0.vbs | "Added by the GORMLEZ-A WORM!"
|
X | Update ver 1.0 | Swap.exe | "Added by the SWAP-C WORM!"
|
N | updatev01 | updatev01.exe | Ultra-networks.com software updater/downloader
|
X | UpdateXpSp | MS045-XP2.exe | "Added by the IRCBOT.NY TROJAN!"
|
U | Upromise0 | Upromise0.exe | "Upromise college savings program"
|
Y | UPSentry 2000 | upsd.exe | Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
|
X | USB 2.0 Driver | updateXPSPC.exe | "Added by the AGOBOT-RJ WORM!"
|
X | USB 2.0 Driver | Winsys32.exe | "Added by the AGOBOT-QM WORM!"
|
X | USB 2.0 Driver | updateXP.exe | "Added by the AGOBOT-QP WORM!"
|
X | USB 2.0 Driver | winsystem.exe | "Added by the AGOBOT-QS WORM!"
|
X | USB 2.0 Driver | UpdateXPSP.exe | "Added by the AGOBOT-QD WORM!"
|
U | USB 3.0 Monitor | nusb3mon.exe | "Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds"
|
X | USB2.0 | usb-hi.exe | "Added by the AGENT.US WORM!"
|
N | UserFaultCheck | dumprep 0 -u | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
X | userinit | choo_003956f4 | "Added by the PEED.16896 TROJAN!"
|
X | USERINTERFACE REPORT3R | M0USE.exe | "Added by the MYTOB.HS WORM!"
|
N | USRobotics 802.11g Wireless Network Utility | USRWLANG.exe | "USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities |
N | UVS10 Preload | uvPL.exe | Part of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
|
U | V0220Mon.exe | V0220Mon.exe | "Creative Live! Cam Console Auto Launcher"
|
U | V0230Mon.exe | V0230Mon.exe | "Creative Live! Cam Console Auto Launcher"
|
Y | V0250Mon.exe | V0250Mon.exe | Part of Creative Webcam Launcher
|
U | va10key | va10key.exe | Only required if you use the 10 kay bay unit with a Sony Vaio laptop
|
X | ValueS0ft | [random filename] | "Added by a variant of the SPYBOT WORM! See here"
|
X | VBS_AUTO_UPDATE | 0548656X.vbs | "Added by the GORMLEZ-A WORM!"
|
? | VDI Manager (HP) | HPO0VDX05.exe | "HP (Hewlett-Packard) related. Now - what does it do?"
|
X | VFW Encoder/Decoder Settings | RUNDLL32.exe MSSIGN30.DLL ondll_reg | "Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
X | VirRL2009 | VirRL2009.exe | "VirusResponse Lab 2009 rogue security software - not recommended"
|
X | Virus Shield 2009 | VShield.exe | "Virus Shield 2009 rogue security software - not recommended |
X | VirusRemover2008 | VRM2008.exe | "VirusRemover2008 rogue security software - not recommended |
X | VirusRemover2009 | VRM2009.exe | "VirusRemover2009 rogue security software - not recommended |
X | VirusResponseLab2009 | VirusResponseLab2009.exe | "VirusResponse Lab 2009 rogue security software - not recommended |
X | VirusRL2009 | VirusRL2009.exe | "VirusResponse Lab 2009 rogue security software - not recommended"
|
X | VnrBlock20 | VnrBlock20.exe | "Berlinads adware"
|
X | VnrPack20 | VnrPack20.exe | "Internet Speed Monitor adware related - see example here"
|
N | VortexTray | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
|
? | VX1000 | vVX1000.exe | "Associated with Microsoft's VX-1000 LifeCam webcams. What does it do and is it required?"
|
? | VX3000 | vVX3000.exe | "Associated with Microsoft's VX-3000 LifeCam webcams. What does it do and is it required?"
|
? | VX6000 | vVX6000.exe | "Associated with Microsoft's VX-6000 LifeCam webcams. What does it do and is it required?"
|
X | w02db700.dll | [random filename] | "ZenoSearch adware"
|
X | W32PluginsDownloaderXMLHTTPSelfClearing7520 | wiper.exe | "Added by the PROXYSER-M TROJAN!"
|
U | Watch | 1200UBWATCH.EXE | Button press monitor for the Mustek 1200 UB Scanner
|
U | Watson Subscriber for SENS Network Notifications | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
X | wblogon | ubpr01.exe | "Added by the AGENT-HFI TROJAN!"
|
X | WebCpr0 | WebCpr0.exe | "WebRebates adware"
|
X | WebRebates0 | WebRebates0.exe | "WebRebates adware"
|
X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | "Web Savings From Ebates Software |
N | wextract_cleanup0 | "advpack.dll | DelNodeRunDLL32 [path] [filename].TMP" |
Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application
|
? | WildTangent CDA | "RUNDLL32.exe cdaEngine0400.dll | cdaEngineMain" |
X | Win Antivir 2008 | Win Antivir 2008.exe | "Win Antivir 2008 rogue security software - not recommended |
X | Win Antivirus 2008 | Win Antivirus 2008.exe | "Win Antivirus 2008 rogue security software - not recommended |
X | Win Prosess0r | [random filename] | "Added by the RBOT-BIT WORM!"
|
X | Win Security 360 | WinSecurity360.exe | "Win Security 360 rogue security software - not recommended |
X | WIN USB 2.0 | usbsystem.exe | Added by an unidentified WORM of TROJAN!
|
X | WIN USB 2.0 | winusb.exe | "Added by a variant of the RBOT WORM!"
|
X | Win USB 2.0 USB Driver | HPPrint.exe | "Added by the SPYBOT.DNB WORM!"
|
X | Win32 USB2.0 Driver | 386.exe | "Added by the IRCBOT.D WORM!"
|
X | Win32 USB2.0 Driver | rundll16.exe | "Added by the WOOTBOT.H WORM!"
|
X | Win32 USB2.0 Driver | w32usb2.exe | "Added by the SPYBOT.DN WORM!"
|
X | Win32 USB2.0 Driver | service.exe | "Added by the SDBOT-QF WORM!"
|
X | win3208022-1336687 | win3208022-1336687.exe | "Added by the VB-CFG TROJAN!"
|
X | win32_i lptt01 | win32_i.exe | "RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | win32_i ml097e | win32_i.exe | "RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | WinAntiSpyware 2005 | was5.exe | "WinAntiSpyware 2005 rogue spyware remover - not recommended |
X | WinAntiSpyware 2006 | was6.exe | "WinAntiSpyware 2006 rogue spyware remover - not recommended |
X | WinAntiSpyware 2006 Free | was6.exe | "WinAntiSpyware 2006 rogue spyware remover - not recommended |
X | WinAntiSpyware 2006 Scanner | was6.exe | "WinAntiSpyware 2006 rogue spyware remover - not recommended |
X | WinAntiSpyware 2007 | was7.exe | "WinAntiSpyware 2007 rogue spyware remover - not recommended"
|
X | WinAntiSpyware 2007 Free | was7.exe | "WinAntiSpyware 2007 rogue spyware remover - not recommended"
|
X | WinAntispyware2008 | WinAntispyware2008.exe | "WinAntiSpyware 2008 rogue spyware remover - not recommended |
X | WinAntiVirus Pro 2007 | WinAv.exe | "WinAntiVirus Pro 2007 rogue security software - not recommended |
X | WinAntiVirusPro2006 | WinAV.exe | "WinAntiVirus Pro 2006 rogue security software - not recommended |
X | WIND0WS | WIND0WS.exe | "Added by the SPYBOT.DQ WORM!"
|
X | WIND0WS | mella.bat | "Added by the ALLEM WORM!"
|
X | Wind0ws | wordpad.exe | "Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
|
X | Wind0ws Ser7ice Agent | colwindos.exe | "Added by the RBOT-GQO TROJAN!"
|
X | Wind0ws Sharing | ssprotecter.exe | "Added by the RBOT-AHW WORM!"
|
X | WinDefender 2008 | WDefDemo.exe | "WinDefender 2008 rogue privacy program - not recommended |
X | WinDefender2009 | windef.exe | "WinDefender 2009 rogue security software - not recommended |
X | WinDLL (start0s.exe) | "rundll32.exe start0s.exe | start" |
X | Windows 2004 | csrss.exe | "Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
|
X | Windows Framework | scvh0st.exe | "Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
|
X | Windows Internet Protocol | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Media Player | 50cent.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows modez Verifier | w1nz0zz0.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows modez Verifier | winl0g0z.exe | "Added by the RBOT-FNB WORM!"
|
X | Windows NT Update Manager | WINL0G0N.exe | "Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
|
X | Windows Serv Patch | Mcaffe2005.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows service | iexpl0rer.exe | "Added by the SDBOT.RO WORM!"
|
X | Windows Service Agent | co0l.exe | "Added by the RBOT-GQY WORM!"
|
X | Windows Services Aganters | [10 random letters].exe | "Added by the RBOT.CUN WORM!"
|
X | Windows Services Layer | winl0g0.exe | "Added by the RBOT-FZQ WORM!"
|
X | Windows Services Update | svch0st.exe | "Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
? | Windows shell | win70.exe | "??"
|
X | Windows Start Server 2000 | traficy.exe | "Added by the RBOT-AHM WORM!"
|
X | Windows svchost | happy2008.exe | "Added by the PUSHBOT.AM WORM!"
|
X | WINDOWS SYSTEM | expI0rer.exe | "Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
|
X | Windows Update | MSDEVS30.exe | Added by the SPYBOT.AHC WORM!
|
X | Windows update 2005 | [random filename] | "Added by the RBOT.ARP WORM!"
|
X | Windows Update Checker | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Update Checker | deinst_qfe002.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Update Manager | Winlog0n.exe | "Added by the AGENT-BO TROJAN!"
|
X | Windows Update Service | SP00ISS.exe | "Added by the SDBOT-ZH WORM!"
|
X | Windows Update Service 2004/2005 | systemupdate.exe | "Added by the RBOT-JE WORM!"
|
X | Windows USB 2.0 Driver | usbtskmgr.exe | "Added by the RBOT-BKG WORM!"
|
X | Windows USB 2.0 Driver | usb2ctrl.exe | "Added by the RBOT-BIW WORM!"
|
X | Windows USB 2.0 Driver | usbservice.exe | "Added by the RBOT-BLF WORM!"
|
X | Windows Workstation Service [5.1-2600] | windrm.exe | "Added by the RBOT-CNY WORM!"
|
X | WindowsFZ | A5281300.so | "Variant of the SmitFraud alias FAKEALE-C TROJAN!"
|
X | Windowz Update V2.0 | Explorer.exe | "Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
X | Windowz Update V2.0 | updater.exe | "Added by the YODO-C WORM!"
|
Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
|
X | WinFixer 2005 | wfx5.exe | "WinFixer 2005 web installer - ""foistware"" |
X | WinFixer 2006 | uwfx6.exe | "WinFixer 2006 web installer - ""foistware"" |
X | WinFixer2005 | uwfx5.exe | "WinFixer 2005 web installer - ""foistware"" |
X | WinFixer2006 | uwfx6.exe | "WinFixer 2006 web installer - ""foistware"" |
X | WinFixer_2005 | uwfx5.exe | "WinFixer 2005 web installer - ""foistware"" |
X | wingerver2.0.exe | wingerver2.0.exe | "Added by the GRAYBRD-AE TROJAN!"
|
X | WINLOG0N | WINLOG0N.EXE | "Added by the MYDOOM.BI WORM!"
|
X | winreg_32 | Vc030405.exe | "Added by the BANCOS-CT TROJAN!"
|
X | winsock | svch0st.exe | "Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | Winsock32driver | ZoneAlarmPr0.exe | "Added by the HACKARMY-B TROJAN!"
|
X | WINSP00L | WINSP00L.EXE | "Added by the AGENT.XAB TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
|
X | WinSrv | kn0x.exe | "Added by the HOBBIT.F WORM!"
|
X | WinStar | IEXPL0RE.exe | "Added by the WOSRIST A TROJAN!"
|
X | WinStart001 | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
X | WinStart001.EXE | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
X | winsyslog lptt01 | winsyslog.exe | "RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | winwan lptt01 | winwan.exe | "RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | winwan ml097e | winwan.exe | "RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | win_supp00.exe | Win Const.exe | "Added by the ASSASIN-H TROJAN!"
|
U | WorkPace 3.0 | workpace.exe | "WorkPace - stress injury prevention software"
|
X | Workstation Ver 5.0 | vmware.exe | "Added by the RBOT-AHB WORM!"
|
X | WSAConfiguration | msnote30.exe | "Added by the AGOBOT-KF BACKDOOR!"
|
X | WUpdate | 1037v.exe | "Added by the CLAGGER-AR TROJAN!"
|
U | X10 Device Network Service | x10nets.exe | Belongs to X10 video streaming device(s)
|
X | X10Weax | WTHRTRAY.EXE | "WeatherCheck - ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads |
X | xccinit | rundll33.exe xccdf16_090131a.dll | "Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
|
X | xccinit | rundll33.exe xccdf16_090305a.dll | "Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
|
Y | XircWinModem4 | ltcm000c.exe | "WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
|
X | XMLmedia 10.0 | wmsdkns.exe | "Added by the FAKEALERT TROJAN!"
|
X | Xordate | wuauclt10.exe | "Added by the RBOT-GKN WORM!"
|
X | XP Antispyware 2009 | XP_AntiSpyware.exe | "XP AntiSpyware 2009 rogue spyware remover - not recommended |
X | XP-C300C3AC | XP-C300C3AC.EXE | "Added by the AUTORUN.EHW WORM!"
|
X | xp32win | xpupdater02.exe | "Added by the MOSUCK-A TROJAN!"
|
X | xupiterstartup2003 | xupiterstartup2003.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
X | xzkadsfk10 | afslkfasl10.exe | "Added by the ONLINEG-R TROJAN!"
|
X | y1959sar | sv711224030r.exe | "Added by the BRONTOK-AK WORM and variants!"
|
X | Yahoo2000 | Anti.exe | "Added by the RBOT.ATK WORM!"
|
X | Yahoo2000 | Anti.exe | "Added by an unknown Malware |
X | yahoo_toolbar lptt01 | yahoo_toolbar.exe | "RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X | yahoo_toolbar ml097e | yahoo_toolbar.exe | "RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
U | ZeroAds | 0 | "ZeroAds - culls ads |
U | ZeroAds | LAS0Ads.exe | "ZeroAds - culls ads |
X | Zonavirus | 0 | "Added by the KITRO.D (or ARGEN.A) WORM!"
|
X | zsmscc | rundll32.exe zsmscc071001.dll mymain | "Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
|
X | zsmscc | rundll32.exe mycc071208.dll mymain | "Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
|
X | zvb0dl2X8tt | NVUKZ.exe | "Added by the AGENT-LMN TROJAN!"
|
X | [12 random characters] | atl91036.exe | "IeDriver adware variant"
|
X | [32 random numbers] | av2009.exe | "AntiVirus 2009 rogue security software - not recommended |
X | [32 random numbers] | av360.exe | "Antivirus 360 rogue security software - not recommended |
X | [random name] | iexpl0ra.exe | "Added by the ULPM.BD TROJAN!"
|
X | [various names] | 10010.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | 321102.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | br0ken.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | defect08.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | Dest068.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | prgsys0984.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | 80d0.exe | "MediaMotor adware"
|
U | {0228e555-4f9c-4e35-a3ec-b109a192b4c2} | gnotify.exe | "Google Gmail Notifier. Alerts you when you have new Gmail messages"
|
X | {05CD0D77-4947-4a56-94FA-0DF0DC644D7B} | sysqyzwud.exe | "Added by the FAKEALERT-AM TROJAN!"
|
U | {1290A33C-85F5-4164-A1BE-7DD299D4986A} | PBKScheduler.exe | "Scheduler for CyberLink PowerBackup - archiving/backup utility"
|
X | {12EE7A5E-0674-42f9-A76B-000000004D00} | "rundll32.exe stlb2.dll | DllRunMain" |
X | {157627A6-2A10-4aa1-B97F-90B8DC6F24AC} | sysqkmwfedz.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {29123221-3AF8-488c-85DE-6B3EC59E8074} | netmedia.exe | "NetMedia adware"
|
X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sxpgknrwva.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sysavxjgdu.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sysawpbkvnq.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sysxhtcwbse.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {2CF0B992-5EEB-4143-99C0-5297EF71F444} | "rundll32.exe stlbdist.dll | DllRunMain" |
X | {2CF0B992-5EEB-4143-99C2-5297EF71F44B} | "rundll32.exe stlbupdt.DLL | DllRunMain" |
X | {357AA41A-B7A8-4632-A27D-5B980B25CF43} | [path to svchost.exe] | "Added by the SMALL-AQ TROJAN!"
|
X | {357AA41A-B7A8-4632-A27D-5B980B25CF43} | services.exe | "FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
|
X | {357AA41A-B7A8-4632-A27D-5B980B25CF43} | [path to trojan] | "Added by the SMALL-EP TROJAN!"
|
X | {42562052-EE17-4197-82C7-91CB2E4B0666} | sysrswva.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {7DD4A7AC-A3F1-4495-884A-7947C5B89108} | sysahbecjh.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {9754B85A-3B34-4969-BE1F-CD03227E9470} | syszweuas.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {9754B85A-3B34-4969-BE1F-CD03227E9470} | sysatjsicj.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4} | sxnwhbvrzc.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4} | sysqrnxstju.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {B081DB1F-4EE6-4021-9DD4-8B300F0D636D} | syssngbeh.exe | "Added by the FAKEALERT-AH TROJAN!"
|
U | {B179023B-6238-4499-8F26-CD73E9D90E0A} | MacDrive.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
X | {B3B48B54-C0EC-4705-8EE8-1981AEF656A7} | sysjcyrq.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {B7-7D-D0-08-ZN} | dwdsregt.exe | "Added by the AGENT-GBC TROJAN!"
|
X | {BAAA759D-56F0-428c-B8DA-827EA3B08C2C} | sysawechod.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {C0FB7D08-056E-1033-0501-03020730002c} | Update.exe | "Added by the AGENT-EOG TROJAN!"
|
X | {C2220120-1C24-4a79-BA7A-DDCBFC209DB3} | sysfbdgv.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {DD651081-A909-45ad-BD71-2335B0ADE043} | sysutrnez.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {DD651081-A909-45ad-BD71-2335B0ADE043} | sysabmpmfr.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {DD651081-A909-45ad-BD71-2335B0ADE043} | sysnxcphmgy.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {E4785213-3EFE-4c26-A9B4-332440E31F6F} | sysrxmfdksp.exe | "Added by the FAKEALERT-AH TROJAN!"
|
X | {F758F78B-0885-490e-AA3C-4A38D28B0240} | sxpjbwvahn.exe | "Added by the FAKEALERT-AM TROJAN!"
|
X | {F758F78B-0885-490e-AA3C-4A38D28B0240} | sysyeabdgfp.exe | "Added by the FAKEALERT-AM TROJAN!"
|