X | MalwareBurn 7.1 | MalwareBurn 7.1.exe | "MalwareBurn rogue security software - not recommended |
X | MalwareWiped 6.1 | MalwareWiped 6.1.exe | "MalwareWipe rogue security software variant - not recommended |
X | MedGS | MEDGS1.exe | "PacerD_Media/Pacimedia.com adware"
|
N | MediaMonitor | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it
|
X | MediaPath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
U | MicroDialler | atdialler1.exe | "Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered"
|
X | Microsoft Configuration 35 | microsot1.exe | "Added by an unidentified TROJAN!"
|
X | Microsoft hren1 | mmhren1.exe | Added by a variant of the AGENT.IWW TROJAN!
|
X | Microsoft Management Console | lssas1.exe | "Added by the DLOADR-AWD TROJAN!"
|
X | Microsoft Office Quick Launcher | iau1.exe | "Added by the DLOADR-AWD TROJAN!"
|
X | Microsoft Security Management | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsoft Server Applacations | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsoft Service Tools | MStools1.exe | "Added by the RBOT-BHT WORM!"
|
X | Microsoft System | winamp1.exe | "Added by the SDBOT-UF WORM!"
|
X | Microsoft System Service | taskmgr1.exe | "Added by a variant of the SPYBOT WORM! See here"
|
X | Microsoft WinUpdate | Winamp61.exe | "Added by a variant of the RBOT WORM!"
|
X | Microsong | svchosts11.exe | "Added by the SDBOT-EV WORM!"
|
U | ML1HelperStartUp | ML1HEL~1.EXE | "ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
X | MS Agent Protection | ag1.exe | "Added by the IRCBOT.AZ BACKDOOR!"
|
X | MS Config Loader | svchos1.exe | "Added by the AGOBOT.R WORM!"
|
X | MS7531 | ms7531.exe | Homepage hijacker
|
X | msgb1 | msgb1.exe | Added by the DLUCA.GEN TROJAN!
|
X | MSN | services51651.exe | "Added by the IRCBOT-AAL TROJAN!"
|
X | mswspl | plugin1.exe | "Added by the SMALL.IQ TROJAN!"
|
X | Multimedia extensions | mservice1.exe | "Added by the DLOADR-AWD TROJAN!"
|
X | MusIRC (irc.music.com) client | musirc4.71.exe | "Added by the RANDEX.Q WORM!"
|
U | MW1HelperStartUp | MW1HEL~1.EXE | "ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
X | MyCometCursor | MYCOME~1.EXE | "Comet Cursor adware"
|
X | MyDailyHoroscope | MYDAIL~1.EXE | "MyDailyHoroscope foistware"
|
X | NAV Auto Prot | navprot1.exe | "Added by the RBOT.ZAC WORM!"
|
X | NAV Auto Protect | msfwe1.exe | "Added by a variant of the RBOT WORM!"
|
X | Nvt32 | complaint_7251.exe | "Added by the ARTIEF.B TROJAN!"
|
X | NZ01 | NZ01.exe | "Added by the SCAR-K TROJAN!"
|
X | Olympic | IE4321.exe | Adult content premium rate dialer - also detected as SMALL.CZ
|
N | OpenOffice.org x | QUICKS~1.EXE | "Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number"
|
Y | Orange Connection Kit | atdialler1.exe | "Part of the Orange Connection Kit - changes the dial-up for Orange Any Time if access problems are encountered"
|
N | PaltalkNetaware.exe | PALNETAW~1.EXE | Voice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start → Programs. Delete the shortcut in Start → Programs → StartUp as well otherwise it will be reinstated
|
N | PCSuiteTrayApplication | TRAYAP~1.EXE | "System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC |
N | PCSuiteTrayApplication | LAUNCH~1.EXE | "System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC |
U | pdfFactory Pro Dispatcher v1 | fppdis1.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
? | PFW_CfgEngine | PFWCFG~1.EXE | "Personal Firewall related?"
|
X | plite731 | plite731.exe | "Poplite A adware"
|
? | POWERR~1 | POWERR~1.exe | "Power monitoring?"
|
N | PROXOMITRON | PROXOM~1.EXE | "A free |
X | ps1 | ps1.exe | "PacerD Media/Pacimedia.com adware"
|
X | PSof1 | PSof1.exe | "PacerD Media/Pacimedia.com adware installer"
|
X | PSoft1 | psoft1.exe | "PacerD Media/Pacimedia.com adware installer"
|
X | psybnc server 3.1 | psybnc321.exe | "Added by the RBOT.ENI BACKDOOR!"
|
U | PVUnInst1 | PVUnInst1.exe | "Privacy View - privacy software that ensures that all your private computer files |
X | QdrModule11 | QdrModule11.exe | "Internet Speed Monitor adware related - see example here"
|
X | QdrPack11 | QdrPack11.exe | "Internet Speed Monitor adware related - see example here"
|
N | RecoverFromReboo | RECOVE~1.EXE | "Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched |
N | RecoverFromReboot | RECOVE~1.EXE | "Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched |
X | Regcheck | ~CAB001.EXE | "Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
|
U | RegisterDropHandler | REGIST~1.EXE | "Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
|
X | RegistryMonitor1 | mljul1.exe | "Added by the SPAMBOT TROJAN!"
|
U | REGIST~1 | REGIST~1.EXE | "Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
|
X | Requester | requester.11.exe | "Added by the MUQUEST TROJAN!"
|
X | Rund11 | Rund11.EXE | "Added by the MARIO-C WORM!"
|
X | Rundll32.exe | Proyecto1.exe | "Added by the GRUEL WORM!"
|
N | SafeInstall.exe | SAFEIN~1.EXE | Monitors a download and ensures an newer version of a file isn't replaced by an older one
|
N | SetiQueue | Setiqu~1.exe | "Provides work unit buffering for Seti@Home clients - see here for more details"
|
N | SetupICWDesktop | icwconn1.exe | Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
|
U | SK51 | SK51.EXE | "SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
|
U | sks-32 | SKS32P~1.EXE | "SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself"
|
N | Slingshot | SLINGS~1.EXE | "Atomica Slingshot - ""reference tool with access to dictionary and encyclopedia terms |
N | sMaRTcaPs | SMARTC~1.EXE | "sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock |
? | SNCT511 | vsnct511.exe | "Unidentified ""Snapshot Viewer""- what does it do and is it required?"
|
X | Sound System | WinSound1.exe | "Added by an unidentified VIRUS |
X | SpyCrush 3.1 | SpyCrush 3.1.exe | "SpyCrush rogue spyware remover - not recommended |
X | SpyLocked 4.1 | SpyLocked 4.1.exe | "Spylocked rogue spyware remover - not recommended |
X | SpywareGuard | deinst_qfe001.exe | "Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
|
U | STARTPAGE | start1.exe | "NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder"
|
X | STCLOA~1 | STCLOA~1.EXE | "SecondThought adware"
|
X | strtas | lock1.exe | "Added by the SDBOT-ADQ WORM!"
|
X | strtas | loc1.exe | "Added by the RBOT-AZU TROJAN!"
|
X | svchost1 | svchost1.exe | "Added by the AGOBOT.ZZ WORM!"
|
X | SYS2 | bad1.exe | "Added by the SILLYFDC-AP WORM!"
|
X | sysldtray | ld11.exe | "Added by the KOOBFACE.JG WORM!"
|
X | sysldtray | ld01.exe | "Added by the KOOBFACE.I WORM!"
|
X | SystemDrive | maxpaynow1.exe | "Added by the TIBS.BKU TROJAN!"
|
X | SysteZ | d1.exe | "Added by the MSNDIABLO.A WORM!"
|
X | SyZ | f1.exe | "Added by the MSNDIABLO.A WORM!"
|
X | Taskbell.exe | Rund1.exe | "Added by the YIPID TROJAN!"
|
N | TaskPlus | TASKPL~1.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
|
? | TB_setup | TB_ANI~1.EXE | "??"
|
U | TMESBS | TMESBS21.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
|
U | TMESBS.EXE | TMESBS21.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
|
U | TMESBS.EXE | TMESBS31.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
|
U | TMESRV.EXE | TMESRV11.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
|
U | TMESRV.EXE | TMESRV21.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
|
U | TMESRV.EXE | TMESRV31.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
|
U | TMESRV31 | TMESRV31.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
|
N | updatev01 | updatev01.exe | Ultra-networks.com software updater/downloader
|
X | USB 2.1 Driver | winupdate1.exe | "Added by a variant of the RBOT WORM!"
|
X | USB Driverz2 | msnplus1.exe | "Added by the SDBOT-XQ WORM!"
|
? | Utility Ping | UTILIT~1.EXE | "??"
|
X | VCMnet11 | VCMnet11.exe | "Windows AFA Internet Enhancement - a browser hijacker |
U | Veo Velocity Connect | stim11.exe | Support software for the Veo Velocity Connect webcam
|
X | VirusHeal 4.1 | VirusHeal 4.1.exe | "VirusHeal rogue security software - not recommended |
X | VnrBlock21 | VnrBlock21.exe | "Internet Speed Monitor adware"
|
X | VRT1 | VRT1.EXE | "Added by the VIRUT.CE VIRUS!"
|
U | WallPaper | WALLPA~1.EXE | "Wallpaper Changer - wallpaper manager that can change your background images on every startup"
|
X | wblogon | ubpr01.exe | "Added by the AGENT-HFI TROJAN!"
|
N | Webposition Gold 2 | wpsche~1.exe | "Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
|
? | WebServer | VBI_SE~1.EXE | "Related to a Pinnacle sound card. What does it do and is it needed?"
|
U | Webshots | websho~1.exe | "Webshots - software that displays photos as your screensaver and wallpaper |
U | WhatPulse | WHATPU~1.EXE | "WhatPulse keeps track of your keystrokes |
U | Win Chimes | winchi~1.exe | "WinChimes - enhancement software for the system clock that runs in the system tray"
|
X | Win32 Services1 | wuamngr1.exe | "Added by the SDBOT-PV WORM!"
|
X | win32servv | ms1.exe | "iSearch adware"
|
N | WINCINEMAMGR | WINCIN~1.EXE | "WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
X | Windir Working | wuaumqr1.exe | "Added by a variant of the IRCBOT TROJAN!"
|
X | Windows Internet Protocol | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Startup | winsta~1.exe | "GoHip foistware"
|
X | Windows Startup | services21.exe | "Added by the AGOBOT-MX WORM!"
|
X | WINDOWS SYSTEM SCALPE | scalpe91.exe | "Added by the MYTOB-HI WORM!"
|
X | Windows Update | winupupdate1.exe | "Added by the RBOT-UV WORM!"
|
X | Windows Update Checker | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows WKS Services | wkssvr1.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | WindowsD | s1.exe | "Added by the MSNDIABLO.A WORM!"
|
X | WINDOWSflashbrg | sqldata1.exe | "Added by a variant of the AGENT-IC TROJAN!"
|
X | WindowsK | a1.exe | "Added by the MSNDIABLO.A WORM!"
|
X | WindowsRegKey update XP | windexv1.exe | "Added by the RBOT-ABM WORM!"
|
X | WindowsUpd1 | WindowsUpd1.exe | "VirtuMonde adware"
|
X | winntR1 | winntR1.exe | "Added by the AGENT.CJZO TROJAN and variants"
|
X | Winsock2 wqr1s | WUAUMQR1.EXE | "Added by the SPYBOT.KD WORM!"
|
X | winsockdriver | winsock4.1.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
X | WinStart001 | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
X | WinStart001.EXE | WinStart001.exe | "From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words |
X | Winsta~1 | winsta~1.exe | "GoHip foistware"
|
X | WinXP | plugin1.exe | Added by the Downloader-JW TROJAN!
|
X | Winzip Application | winzip81.exe | "Added by the RBOT-BKZ WORM!"
|
X | www.symantec.com | oz11111.exe | "Added by the MYDOOM.W WORM"
|
U | X-Cleaner Freeware | XCLEAN~1.EXE | "X-Cleaner Freeware - ""cookie cleaning |
U | X1 | X1.exe | "Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
|
X | Xcpy1 | Xcpy1.exe | "FlashEnhancer adware"
|
X | Xordate | wuauclt11.exe | "Added by the RBOT-GLI WORM!"
|
U | XTNDConnect PC - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
N | Yahoo! Pager | YAHOOM~1.EXE | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
X | Zango TvTimes | ZANGOT~1.EXE | "ZangoSearch adware"
|
N | ZSSnp211 | ZSSnp211.exe | "Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
|
X | [12 random characters] | cabview1.exe | "IeDriver adware variant"
|
X | [12 random characters] | advpack1.exe | "IeDriver adware variant"
|
X | [12 random characters] | cmpbk321.exe | "IeDriver adware variant"
|
X | [12 random characters] | bthserv1.exe | "IeDriver adware variant"
|
X | [various names] | TForm1.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | UserSp1.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
X | [various names] | exe81.exe | "MediaMotor adware"
|