Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
X(Default)winbas12.exe"Adware
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X0050726-007-i32-10050726-007-i32-1.exe"Added by the BANCBAN-EC TROJAN!"
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
X11.exe"Added by the ESTEEMS TROJAN!"
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1mrcmgr.exe"Added by the BANKER.RQK TROJAN!"
X1KHATRA.exe"Added by the AUTOIT-BP WORM!"
X1addit.exe"Added by the SDBOT-RI WORM!"
N1&1 EasyLoginEasyLogin.exe"1&1 EasyLogin - quick access to webhost 1&1's Control Panel
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
N12Voip12Voip.exe"12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"180solutions adware"
X180ax180ax.exe"180Search adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X180sa180sa.exe"180Search adware"
X1916435341.exe1916435341.exe"Added by the DLOADR-AXU TROJAN!"
X196_150_ni196_150_ni.exe"WinFixer web installer - ""foistware""
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer - ""foistware""
X197_150_ni_7197_150_ni_7.exe"WinFixer web installer - ""foistware""
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1cla1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
U1cla.exe1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
?1CmailSNETMAIL.EXE"??"
X1on11on1.exeAdult content dialler
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
X1u71u7.exe"Added by the MURBAC-A TROJAN!"
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
?39ELTFH25Z8SKFEzg1q5.exe"Seems to be associated with software by Resplendence SP ?"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
X4.68474E+12netdll32.exe"Added by the SDBOT-DEV WORM!"
X49U5T1N449U5T1N4.exe"Added by the KORRON.B WORM!"
X4k51k44k51k4.exe"Added by the BRONTOK-BH WORM!"
X5-1-61-96members-area.exeAdult content dialler
X5-2-46-1125-2-46-112.exe"Adult content pop-up dialler. Removal instructions here"
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
X5whgue215whgue21.exe"ClearSearch adware"
X6.54388E+16rkgnd.exe"ANG AntiVirus 09 rogue security software - not recommended
X7.61125E+16angpd.exe"ANG AntiVirus 09 rogue security software - not recommended
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g MIMO Wireless UtilityRaUI.exe"Wireless configuration utility for Railink 802.11g MIMO based products"
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X@tour_ww@tour_ww[1].exeAdult content dialler
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
XA5118rj6321422.exe"Added by the BRONTOK-AK WORM and variants!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
Xa9z1eizA1eatulabov.exe"Added by the AGENT-GWD TROJAN!"
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
Nacpartagpart11.exeProgram for finding trucks on-line
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
NAdobe AcrobatREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
XAdult_Chat1Adult_Chat1.exeAdult content dialler
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
NAlcohol 120%Alcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?ALFY AccelleratorAlfyAC~1.exe"??"
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1.EXEAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyZone 5.1AntiSpyZone 5.1.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
XAPD123APD123.exe"PacerD Media/Pacimedia.com adware"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
Xasc32asc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
YATIRmtWndrATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATIX10atix10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBIOS1BIOS1.EXE"Added by the OPASERV.T WORM!"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
NBlitzz BWI715WLANmon.exeBlitzz Technology BWI715 Wireless PC modem connection monitor
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
UBlueSoleilBLUESO~1.EXE"BlueSoleil Bluetooth wireless manager from IVT Corporation"
XBmanBMan1.exeAbcsearch.com/DealHelper adware variant
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
YBOC-412BOC412.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.12"
YBOC-421BOC421.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.21"
UBootStatusBOOTST~1.EXE"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XccExecutebootcfg1.exe"Added by the NEMSI-B VIRUS!"
Xcd1cd1.exePremium rate adult content dialler
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
Xchina11msnCHINA11MSN.EXE"Added by the ENVID.O WORM!"
Xci1gntci1gnt.exe"Detected by Kaspersky as the AGENT.DHU TROJAN!"
NCIOche7e1~1.exe"ChatItOut webcam chat program"
XClassesint1.exe"""Switch"" premium rate adult content dialler variant"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
UCleanTempCLEANT~1.EXE"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
NClick Radio Tunerclickr~1.exe"ClickRadio - subscription service playing radio music via the internet"
NClick Tray CalendarClickT~1.EXE"ClickTray Calendar - shows holidays
XClientMan1mscman.exe"ClientMan parasite variant"
Xcmt101cmt101.exe"Added by a variant of the CRYPTER.C TROJAN!"
XCn911ODBCJET.exe"Added by the BIFROSE-PR TROJAN!"
UCobian Backup 10Cobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
UCoreCenterCORECE~1.EXE"MSI Core Center - motherboard utility for monitoring CPU speed
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCP888M1CP888M1.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPATR10CPATR10.EXE"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
XCTin10CTin10.exe"Added by the BANCOS.E TROJAN!"
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
UCyberLat Ram CleanerCyberLat Ram Cleaner 1.1.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
Xd9fw5i91pd9fw5i91p.exe"Added by the AGENT-GIW BACKDOOR!"
NDAEMON Tools-1033daemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDanBtR270414DanBtR270414.exe"Added by the VB-NIB WORM!"
Xdaskgfkkcx15dasdsaads15.exe"Added by the ONLINEG-Q TROJAN!"
NData LifeGuardBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital's series of hard drives
YDataLayerDATALA~1.EXE"Part of Nokia PC Suite version 5 - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" Required by the Nokia status/connection monitor (NclTray.exe)"
UddhelperW815DM.EXE"Enuff Parental Control Software by Akrontech"
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
XDesktop Security 2010Desktop Security 2010.exe"Desktop Security 2010 rogue security software - not recommended
NDesktop Weather 3THEWEA~1.EXE"Desktop Weather 3 by The Weather Channel - provides current temperature
Xdestroyb11destroyb11.exe"Added by the DELF-KO TROJAN!"
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
XDevicePathProyecto1.exe"Added by the GRUEL WORM!"
Udevldr16devldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Udevldr16.exedevldr16.exe"Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
NDigiGuideclient01.exeTV guide and reminder
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases
XDir1caKe"Added by the CAKE WORM!"
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
Xdjtopr1150.exedjtopr1150.exe"WebRebates adware"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDlDir1caKe"Added by the CAKE WORM!"
Xdnamd140113.a.Stub.EXE"Added by the STUB_A TROJAN!"
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDot1XCfgDot1XCfg.exe"Added by the AGOBOT.EA TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
Udrkly16j"rundll32.exe drkly16j.dll ServiceCheck"
Xdsadlsa14dsakfsak14.exe"Added by the ONLINEG-P TROJAN!"
UDT 11Mbps WLAN PC Card StationDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT 11Mbps WLAN USB StationDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
NDXM6Patch_981116p_981116.exe"Win32 cabinet self extractor. More info here"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
UEanthologyAppEANTHO~1.EXE"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertEANTHO~1.EXE"eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted
UEasySync Pro - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEC21EZQ.EXE"Related to EC21 ""the world's largest B2B marketplace to facilitate online trades between exporters and importers from all around the world"""
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
UeFax 4.1J2GDllCmd.exe"DLL Command Utility for version 4.1 of eFax Messenger from j2 Global Communications
UeFax 4.1J2GTray.exe"System Tray access to version 4.1 of eFax Messenger from j2 Global Communications
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xei10.exeei10.exe"Added by the AGOBOT-NK WORM!"
Xempine121307.exe"Delfin Media Viewer adware related"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
Xemre1emre1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C45 SeriesE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus CX3100E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status
UEPSON Stylus CX3200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UEPSON Stylus CX5400E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo 2200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status
UEPSON Stylus Photo 825E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
XEsohEsoh123.exe"Added by the AGOBOT.FF WORM!"
Xexe lptt01exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xexp1orer.exeexp1orer.exe"Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
UE_S10IC2E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UE_S4I2F1E_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UE_S4I2G1E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UE_SOEIC1E_SOEIC1.exe"Epson Status Monitor 3 - for monitoring printer status
Uf1Tray.exeF1TRAY.EXE"System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
UF5D8001Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
UF5D8011Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
UF5D8055v1Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
UF5D8071Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
UF5D9010Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
Xfaslkakj11kjgagklj11.exe"Added by the LEGMIE-ARE TROJAN!"
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile0_0MD1.exe"Added by the DLOADER-OR TROJAN!"
XFile1Dia Claro.htm"Added by the DLOADER-OR TROJAN!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
UFooBar 1.0FooBar.exe"FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
XFS6519FS6519.dll.vbs"Added by the SOLOW.B WORM!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
Xgadkgak12fsafsakx12.exe"Added by the ONLINEG-N TROJAN!"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGetModule18GetModule18.exe"Internet Speed Monitor adware related - see example here"
XGetModule19GetModule19.exe"Internet Speed Monitor adware related - see example here"
XGetModule21GetModule21.exe"Internet Speed Monitor adware related - see example here"
XGetPack18GetPack18.exe"Internet Speed Monitor adware related - see example here"
XGetPack19GetPack19.exe"Internet Speed Monitor adware related - see example here"
XGetPack21GetPack21.exe"Internet Speed Monitor adware related - see example here"
Xgf1.0.0.2ggf.exe"Added by the EDFON.A TROJAN!"
XGlock Suite 1.1glock32.exe"Added by the TINY.GV TROJAN!"
XGLSetIT32msiexec16.exe"Added by the OPTIX PRO TROJAN!"
NGoogle UpdaterGOOGLE~1.EXE"Downloads and installs updates for Google applications (Google Earth
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
XG_Server1.2.exeG_Server1.2.exe"Added by the GRAYBIRD-Z TROJAN!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHELLBOT TEST1hellbot.exe"Added by the MYDOOM.BO WORM!"
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHermes MessengerDGDRHE~1.EXE"A LAN messenger alternative to WinPopUp - Digital Dreams Software"
XHighKey1HighKey1.exe"Detected by AVG as GENERIC12.LHE - see here"
UHitwarePKLiteHITWAR~1.EXE"Hitware Popup Killer Lite"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
?hp 1000 firmwarefwdl.exe"HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?"
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb11.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb12.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb13.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHpha1monHpha1mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
Nhpoddt01.exeN/A"Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software
Uhpoddt01.exehpotdd01.exe"Detection of new imaging
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
?I81SHELLI81SHELL.exe"Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard"
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiedwa104iedwa104.exe"Added by the DLOADR-BBW TROJAN!"
Xiestartiexp1orer.exe"Added by the NEMOG.C TROJAN!"
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?iHP-100iHPDetect.exe"Drive Letter Searcher
NIMEKRMIG6.1IMEKRMIG.EXE"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
XIMJPMIG6.1HelpCat.exe"Added by the BESVERIT WORM!"
UIMJPMIG8.1IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
Xim_autornim_1.exe"Added by the IMAV.A WORM!"
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
NInstantAccessINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
Xintell321.exeintell321.exe"Added by the SPYJACK-B TROJAN!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
UInternet Disk CleanerCLEARH~1.EXE"""Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Security 2010IS2010.exe"Internet Security 2010 rogue security software - not recommended
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
NInterTrust Quick Startit_cpq~1.exe"InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
UIomega Automatic Backup 1.0.1ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
UipsecdialerIPSECD~1.EXE"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UIr41_32.axregsvr32.exe Ir41_32.ax"Intel® Indeo® video 4.4 Decompression Filter related. The ""Ir41_32.ax"" file is located in %System%"
XJava VM v6.91jav.bat"Added by the DWNLDR-HLL TROJAN!"
Xjohn315srrvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj315srvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj3155srvcc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjon315[path to trojan]"Added by the MAILBOT-BI TROJAN!"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
Ujv16PT - Privacy ProtectorTask.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer
UJv16pt Network Residentjv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjxef1104jxef1104.exe"Added by the XIPI-A WORM!"
?Jzi16jzi16.exe"??"
XKAVFOXwin1ogoin.exe"Added by the GWGHOST-M TROJAN!"
XKazaa lptt01kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
YKB891711KB891711.exe"Installed by the Windows KB891711 critical update
YKB918547KB918547.EXE"Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only"
UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
Xkernel12.exekernel12.exeAdded by an unidentified WORM or TROJAN!
XKey1Rlid.exe"Added by the LIXY TROJAN!"
XKiamat Sudah Dekat_16_04ISASS.exe"Added by the PAHATIA.B WORM!"
UKM9801UMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
XKr0n1CKr0n1C.exe"Added by the BRONTOK-BO WORM!"
Xkvern16.dllregsvr32.exe kvern16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""kvern16.dll"" file is found in %System%"
XL4r1$$aL4r1$$a.pif"Added by the ASSIRAL-C WORM!"
XlaltinL90112201.Stub.exe"Delfin Media Viewer adware related"
ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
ULANMessage ProLANMES~1.exe"LANMessage Pro - ""a powerful tool for communicating with other people on your office/home network"""
ULaplink PDASync 3.1 - PocketPCAUTODE~1.EXE"Laplink PDASync for Windows Mobile Pocket PC - PDA synchronisation utility"
ULaplink PDASync 3.1 - ScheduleSyncScheduleSync.exe"Laplink PDASync for ScheduleSync - PDA synchronisation utility"
ULexmark 1200 Serieslxczbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 1200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 3100 Serieslxbrbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark X1100 Serieslxbkbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X1100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark X125 Settings UtilityLEX125SU.exeSettings utility for the Lexmark X125 printer
ULexmark X5100 Serieslxbabmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X5100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark X6100 Serieslxbfbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
Xli-rcash00001vldial.exe"Added by the Vl TROJAN!"
Xli01f948"rundll32.exe li01f948.dllEnableRunDLL32"
XLife FireWall Update1FireWall-Update1.exe"Added by the RBOT-ARS WORM!"
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
XLimpetexplorer16.exe"Added by the RBOT-AJD WORM!"
Xlk3h1[path to file]"Added by the MOSUCK-G TROJAN!"
Xload_Kerne1.exe"Added by the LINEAGE-AN TROJAN!"
XloadKerne121.exe"Added by the LINEAGE-ON TROJAN!"
XloadKerne1211.exe"Added by the LINEAGE-DY TROJAN!"
Xloadrundl132.exe"Added by the LOOKED-CK WORM!"
Xload321111a.exe"Added by the DUMARU.AH WORM!"
Xload=a1g.exe"Added by the ATAK.B WORM!"
Yload=01comm32.exe"Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions
Xload=Kerne14.exe"Added by the LINEAGE-BA TROJAN!"
XLoadab1explorer.exe"Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMect1explorer.exe"Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
Xlogglogo_1.exe"Added by the PWFUZZ-A WORM!"
ULogitech Harmony Remote Software 7HARMON~1.EXE"Logitech
NLogitechQuickCamRibbonQuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
XLogonrepclient1CSRSS.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
XLprLpr123.exe"Added by the REMPSTEAL password stealer TROJAN!"
XLpr123Lpr123.exe"Added by the REMPSTEAL password stealer TROJAN!"
NLS120 Superdisk??"Supposed to accelerate transfer rate on LS-120
Xlsass16lsass16.exe"Added by the BANKER-BXX TROJAN!"
XLTM2winvers16.exe"Added by the SMALL.ND TROJAN!"
YLTWinModem1ltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
Xmain16main16.exe"Added by the CRYPTER.A TROJAN!"
XMalwareBurn 7.1MalwareBurn 7.1.exe"MalwareBurn rogue security software - not recommended
XMalwareWiped 6.1MalwareWiped 6.1.exe"MalwareWipe rogue security software variant - not recommended
Xmaskridermaskrider2001.vbs"Added by the SOLOW-G WORM!"
XMedGSMEDGS1.exe"PacerD_Media/Pacimedia.com adware"
XMedia Player Updatexpsp1mfh.exe"Added by a variant of the RBOT WORM!"
XMedia Plug x.1.2msdm.exeAdded by the MULDROP.352 VIRUS!
NMediaMonitorMediam~1.exeInstalled by Smartdisk MVP CD burning software. Software will work fine without it
XMediaPathProyecto1.exe"Added by the GRUEL WORM!"
XMessenger Explorerm41n.exe"Added by the SDBOT-SA BACKDOOR!"
XMessenger91messengersystem.exe"Added by the RBOT-FPF WORM!"
UMFP1815_S2PScan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
UMicroDialleratdialler1.exe"Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered"
XMicrofinder lptt01mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft 16Bit Updatewuapdate16.exe"Added by the RBOT.CZ WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft DirectXtime123.exe"Added by the SDBOT.MD WORM!"
XMicroSoft Getway mqbol[12 random letters].exe"Added by the RBOT.GBA WORM!"
XMicrosoft hren1mmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!
XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Internet Firewall ManagerGMT16.exe"Added by the RANDEX.AT WORM!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
UMicrosoft Office 2010BCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
XMicrosoft Office Quick Launcheriau1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Security Managementwuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicroSoft ssadsadas3s1eXtream.exe"Added by the SPYBOT.ZK TROJAN!"
XMicroSoft ssadssjdhasjadas3s1kdjfsdklfjsl.exe"Added by the SDBOT.AEX WORM!"
XMicroSoft ssas3s1SADASDA.exe"Added by the RBOT.URF WORM!"
XMicroSoft sys3s1h4ckn3t.exe"Added by the RBOT.QTY WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatewuamgrd16.exe"Added by the RBOT-BQ WORM!"
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMicroszoft Update Mach1nezssvchst.exe"Added by the RBOT-ED WORM!"
UML1HelperStartUpML1HEL~1.EXE"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UML1HelperStartUpML1Helper.exe"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Nmmptim1mmpti.exeMpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
XMonitor calibrationAV1i.exe"Anti-Virus-1 rogue security software - not recommended
Xmonitor1amonitor1a.exe"Added by the MSNAGEN-A TROJAN!"
Xmotoinmm15201518.Stub.exe"Delfin Promulgate adware variant"
XMozilla FirefoxF1REF0X.EXE"Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers ""1"" and ""0"" in place of upper case ""i"" and ""o"" respectively"
XMS Agent Protectionag1.exe"Added by the IRCBOT.AZ BACKDOOR!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMS lsass Startuplsass135.exe"Added by the RBOT.WM WORM!"
XMS OfficeOffice10.exe"Added by the VB.DT TROJAN!"
XMS Sound Config 16bitsndcfg16.exe"Added by the SDBOT.MB TROJAN!"
XMS-Connectmsite18.exe"Adult content dialler - see here"
XMS7531ms7531.exeHomepage hijacker
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
Xmsgb1msgb1.exeAdded by the DLUCA.GEN TROJAN!
XMsgsrv16Msgsrv16.exe"Added by the DELF family of TROJANS!"
XMsgtraysys16.exeAdded by an unknown VIRUS!
Xmsigdisk10.exe"Added by the BANBRA-KF TROJAN!"
XMslogon lptt01mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMSNmsn16.exe"Added by the SDBOT-VN WORM!"
XMSNservices51651.exe"Added by the IRCBOT-AAL TROJAN!"
XMSN MessengerPIC1324.exe"Added by the CHOKE.C WORM!"
XMSN servicemsnmgr16.exe"Added by a variant of the RBOT WORM!"
XMSN servicemsnmsgr16.exe"Added by the RBOT-RZ WORM!"
XMSN6.1 Auto-Updaterv6msn.exe"Added by the AUTORUN-MM WORM!"
XMSNMSGRS1swed.batIRC backdoor TROJAN or WORM!
Xmsrundllmsrund1l32.exe"Added by the BINGHE TROJAN!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmswsplplugin1.exe"Added by the SMALL.IQ TROJAN!"
XMSxmlHpr"RUNDLL32.EXE [path] msxm192z.dllw"
XMsy1 Startupsmsyj32.exe"Added by the AGOBOT-QQ WORM!"
Xmsys lptt01msys.exe"RapidBlaster variant (in a ""Msyss"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
NMusic01 ServerMusic01 Server.exe"J River Media Jukebox"
XMusIRC (irc.music.com) clientmusirc4.71.exe"Added by the RANDEX.Q WORM!"
UMW1HelperStartUpMw1helper.exe"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UMW1HelperStartUpMW1HEL~1.EXE"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XMy SupervisorMSup1bf7.exe"My Supervisor rogue system suite - not recommended
XMyCometCursorMYCOME~1.EXE"Comet Cursor adware"
XMyDailyHoroscopeMYDAIL~1.EXE"MyDailyHoroscope foistware"
XNAV Auto Protnavprot1.exe"Added by the RBOT.ZAC WORM!"
XNAV Auto Protectmsfwe1.exe"Added by a variant of the RBOT WORM!"
XNBInstallMBDownloader_876919.exe"Added by the MIRAR_D TROJAN!"
?nbustrce1Dnbustrce1D.exe"Device driver
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
XNero Updater.6.12wmp9.exe"Added by the AGOBOT-AAG WORM!"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
UNETGEAR WG111T Smart Wizardwlan111t.exe"Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL NewDotNetStartup"
XNewsgroup lptt01newsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.GA6PU_0001_N108E1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6PU_0001_N120C2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6P_0001_N105E2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GA6P_0001_N111C1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115C0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115E0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122E0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_2001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GDCDE_0001_N122C1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.GDC_0001_N111C1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GDC_0001_N122C1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GES_0001_N122C2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UAVIFR_0001_N105M2404[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UGA6PH_0001_N122M2910[path to file]"Installer for the AntiVirusAskeladd rogue security software - see here"
XNI.UGA6PK_0001_N122M1302[path to file]"Installer for the VirusForsvar Danish rogue security software - see here"
XNI.UGA6PL_0001_N108M2808[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PL_0001_N120M1302[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PM_0001_N108M2108[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M1202[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M3010[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PT_0001_N108M2208[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M1202[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M2910[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PU_0001_N108M1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M1202[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PV_0001_N108M0207[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M1202[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6P_0001_N105M2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N111M1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N115M0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N119M1510[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N120M1710[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0007_N125M2002[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6P_1001_N122M0402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_1002_N122M1402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4001_N122M2111[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4444_N122M2811[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5001_N122M1902[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5555_N122M0312[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGDC1_0001_N119M0911[path to file]"Installer for the FilterProgram rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0307[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0511[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M1712[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCDE_0001_N111M3007[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCDE_0001_N122M1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M0307[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M1812[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCNL_0001_N111M3007[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M1912[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M3011[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCPL_0001_N108M0207[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCPL_0001_N122M2012[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCRU_0001_N111M0208[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCRU_0001_N122M2012[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCTH_0001_N122M1712[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDCTR_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N111M1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M0502[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2603[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2610[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2802[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2811[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0002_N108M1007[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0003_N108M2407[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGESF_0001_N122M0201[path to file]"Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N105M0405[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M0303[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M2911[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESM_0001_N122M0303[path to file]"Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N108M2006[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M0303[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M2811[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M3010[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGES_0001_N108M2006setup_en.exe"Installer for the MyContentAssistant rogue privacy tool"
XNI.UGES_0001_N122M0502[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2111[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2602[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2603[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0002_N108M1607[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5LP_0001_0614UWFX5LP_0001_0614NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0715UWFX5LP_0001_0715NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0802UWFX5LP_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0803UWFX5LP_0001_0803NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer 2006 web installer - ""foistware""
NNorton Ghost 10.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
XNotepad lptt01notepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
XNTFS16ntfs16.exe"Added by the RBOT-LY WORM!"
NNuance OmniPage 17-reminderEreg.exe Ereg.ini"Registration reminder for Ominpage version 17 from Nuance"
XNumerical Xtermz Agent1x32.exe"Added by the RBOT-FWX WORM!"
XNvCp1Do[path to trojan]"Added by the DWNLDR-GWE TROJAN! The most common filename seen is ""smss.exe"" - which is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
Xnvd32 lptt01nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NNVIDIA nForce APU1 UtilitiesNVATray.exe"nVidia's nForce Audio Processing Unit (APU)- ""provides 3D positional audio and DirectX 8.0 compatibility
Unvsvc16nvsvc16.exe"MySuperSPy surveillance software. Uninstall this software unless you put it there yourself"
XNvt32complaint_7251.exe"Added by the ARTIEF.B TROJAN!"
XNZ01NZ01.exe"Added by the SCAR-K TROJAN!"
?officejet 6100hposol08.exeAssociated with a HP PSC2110 (and maybe others) all-in-one machine
XOlympicIE4321.exeAdult content premium rate dialer - also detected as SMALL.CZ
NOne Touch Monitor1tou~2.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOneTouchMonitor1tou~2.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NONETOU~21tou~2.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOP12 ReminderEreg.exe ereg.ini"Registration reminder for OmniPage from Nuance (was ScanSoft)"
NOpenOffice.org xQUICKS~1.EXE"Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number"
XOptim1regdtopt.exe"Added by the RAMVICRYPE TROJAN!"
NOpware12Opware12.exe"OmniPage from Nuance (was Scansoft) - version 12. If running
NOpware14Opware14.exe"OmniPage from Nuance (was Scansoft) - version 14. If running
NOpware15Opware15.exe"OmniPage from Nuance (was Scansoft) - version 15. If running
YOrange Connection Kitatdialler1.exe"Part of the Orange Connection Kit - changes the dial-up for Orange Any Time if access problems are encountered"
UOrigRage128TweakerRAGE128TWEAK.EXEThird party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UP17Helper"Rundll32 P17.dll P17Helper"
?P17Helper"Rundll32 SPIRun.dll RunDLLEntry"
?P17RunE"RunDll32 P17RunE.dllRunDLLEntry"
NPaltalkNetaware.exePALNETAW~1.EXEVoice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start → Programs. Delete the shortcut in Start → Programs → StartUp as well otherwise it will be reinstated
XPC Antispyware 2010PC_Antispyware2010.exe"PC Antispyware 2010 rogue security software - not recommended
UPC Doc Pro - 3.1pcdocpro.exe"PC Doc Pro (now Win Doc Pro) - system health check and fix utility"
NPCSuiteTrayApplicationTRAYAP~1.EXE"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPCSuiteTrayApplicationLAUNCH~1.EXE"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
UPd71PanPd71Pan.Exe"Audiotrak Prodigy 7.1 sound card control panel"
UpdfFactory Dispatcher v1fppdis1a.exe"FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Pro Dispatcher v1fppdis1.exe"FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UPDUiP6210DMonPDUiP6210DMon.exe"Memory Card Utility for the Canon PIXMA iP6210D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPeerGuardianPeerGuardian_1.99b_pr14.exe"PeerGuardian - IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists
XPeqBL100PEQBL100.exe"Added by the ENVID.D WORM!"
XPest-Patrol 2.1.0Pest-Patrol.exe"Pest-Patrol rogue security software - not recommended
UPetit Larousse 2001HIPL2000Popup.exePopup dictionary tool
?PFW_CfgEnginePFWCFG~1.EXE"Personal Firewall related?"
Xplite731plite731.exe"Poplite A adware"
Xpopsrv146popsrv146.exe"AproposMedia adware"
XPowerPrifile"rundl132 kenel.dll PowerProfileEnable"
?POWERR~1POWERR~1.exe"Power monitoring?"
?PowerSetRegedit.exe /s ...PowerSet_8100_CU.REG"Appears to be Toshiba power management related"
Xpppp12.exe"Added by the DWNLDR-HXV TROJAN!"
NPP3100bflatbed.exe"Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan
NPPort10reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 10 from Scansoft (now Nuance)"
NPPort11reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 11 from Scansoft (now Nuance)"
NPPort12reminderEreg.exe Ereg.ini"Registration reminder for PaperPort version 12 from Nuance"
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
Yproxim_orinoco_11abgorinoco.exe"Proxim ORiNOCO 11a/b/g PCI Card wireless configuration utility"
NPROXOMITRONPROXOM~1.EXE"A free
Xps1ps1.exe"PacerD Media/Pacimedia.com adware"
XPSof1PSof1.exe"PacerD Media/Pacimedia.com adware installer"
XPSoft1psoft1.exe"PacerD Media/Pacimedia.com adware installer"
Xpsybnc server 3.1psybnc321.exe"Added by the RBOT.ENI BACKDOOR!"
XpsyBNC-2.1.4 Client ServerpsyBNC215.exe"Added by a variant of the RBOT WORM!"
XPTRGMYGK"rundll32.exe ptmg1v.dll DllRunMain"
UPurgativePURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
UPVUnInst1PVUnInst1.exe"Privacy View - privacy software that ensures that all your private computer files
Np_981116p_981116.exe"Win32 cabinet self extractor. More info here"
NQ152404wsript.exe Q152404.VBSAppears to run Scandisk at bootup on NEC PCs
XQdrModule10QdrModule10.exe"Internet Speed Monitor adware"
XQdrModule11QdrModule11.exe"Internet Speed Monitor adware related - see example here"
XQdrModule12QdrModule12.exe"Internet Speed Monitor adware related - see example here"
XQdrModule13QdrModule13.exe"Internet Speed Monitor adware related - see example here"
XQdrModule15QdrModule15.exe"Internet Speed Monitor I adware"
XQdrModule16QdrModule16.exe"Internet Speed Monitor adware related - see example here"
XQdrModule17QdrModule17.exe"Internet Speed Monitor I adware"
XQdrPack10QdrPack10.exe"Internet Speed Monitor H adware"
XQdrPack11QdrPack11.exe"Internet Speed Monitor adware related - see example here"
XQdrPack12QdrPack12.exe"Internet Speed Monitor adware related - see example here"
XQdrPack13QdrPack13.exe"Internet Speed Monitor adware related - see example here"
XQdrPack14QdrPack14.exe"Internet Speed Monitor adware related - see example here"
XQdrPack15QdrPack15.exe"Internet Speed Monitor adware related - see example here"
XQdrPack16QdrPack16.exe"Internet Speed Monitor adware related - see example here"
XQdrPack17QdrPack17.exe"Internet Speed Monitor adware related - see example here"
NQuickCam10QuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
NQuickCam10.exeQuickCam10.exe"Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled
NQuickFinder SchedulerQFSCHD100.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
NQuickFinder SchedulerQFSCHD110.EXE"Used in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
NQuickFinder SchedulerQFSCHD130.EXE"Used in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
UQwest 11n Wireless WPS ToolWpsCenter.exeWireless configuration utility for the Qwest 11N 150MB USB wireless adapter
Xrate.exei11r54n4.exe"Added by the BEAGLE-I WORM!"
Xrate.exei1ru74n4.exe"Added by the BEAGLE.E WORM and variants!"
XRavshellrund1132.exe"Added by the AGENT.OKZ TROJAN!"
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
Xravtaskrund1132.exe"Added by the DLOADER.IYT TROJAN!"
Xrb32 lptt01rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XRDLLRunDll16.exe"Added by the SDBOT.F TROJAN!"
?readericon10readericon10.exe"Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required?"
XRealP1ayer[path to file]"Added by the RPLAY.A TROJAN! Note that the name has a number ""1"" in place of the second lower case ""L"""
Xrealplay lptt01realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
XRecommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}RH.DLL"SmartPops search hijacker"
NRecoverFromRebooRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
Xreg1.regvuamgard.exe"Added by a variant of the IRCBOT TROJAN!"
XRegcheck~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
URegisterDropHandlerREGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
URegistryclass0117[random].exe"Blackbox captures emails and chat logs
XRegistry System16 Checkup MonitorSystemReg16.exe"Added by a variant of the RBOT WORM!"
XRegistry System166 Checkup MonitorSystemReg166.exe"Added by a variant of the RBOT WORM!"
XRegistryMonitor1mljul1.exe"Added by the SPAMBOT TROJAN!"
XRegistryMonitor1qtplugin.exe"Added by the DELF-EZY TROJAN!"
XRegistryMonitor1igfxpers.exe"Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
XRegistryMonitor1incognito.exe"Added by the BUZUS.DAHY TROJAN!"
UREGIST~1REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
XRegrorundll132.exe"Added by the OKARAG TROJAN!"
YRegx10EXEATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
XRequesterrequester.11.exe"Added by the MUQUEST TROJAN!"
XrforceEXP1ORER.EXE"Added by the DROPPER.KN TROJAN! Note the number ""1"" in the filename rather than letter ""L"". It also drops another file named DEVICEMAP.SYS which is the ROOTKIT.O TROJAN!"
NRoxWatchTrayRoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
NRoxWatchTray10RoxWatchTray10.exe"System Tray access to managing the ""Watched Folders""
XRPCser32g1services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuby13Ruby13.exe"Added by the MEXER.E WORM!"
XRuby14Ruby14.exe"Added by the FIGHTRUB-A WORM!"
Yrun=smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
XRund11Rund11.EXE"Added by the MARIO-C WORM!"
Xrund1132rund1132.exe"Added by the DOPBOT-A WORM!"
XRund1132.exeRund1132.exe"Added by the STARTPA-HS TROJAN!"
XRund1l32Winfi1e32.exe"Added by the MERTIAN WORM!"
XRundll16Rundll16.exe"Added by a number of VIRUSES
URundll32 P17"Rundll32 P17.dll P17Helper"
XRundll32.exeProyecto1.exe"Added by the GRUEL WORM!"
XRundll32_8"rundll32.exe 1.dll DllRunServer"
Xrunner1updater.exeAdded by the CRYPT.ULPM.GEN TROJAN!
Xrunner1retadpu.exe"Added by the AGENT.SLZ TROJAN!"
Xrunner1mrofinu.exe"Added by the AGENT.CZC TROJAN!"
Xrunner1retadpu[random digits].exe"Added by the SMALL.CTV TROJAN!"
Xrunner1tsitra.exe"Added by the AGENT.ABFQ TROJAN!"
Xrunner1faceback.exe"Added by the DLOADR-BSX TROJAN!"
XRuntt1Internat.exe"Added by the LINEAGE-R TROJAN!"
XRuntt1Internet.exe"Added by the LINEAGE-Q TROJAN!"
Xryan1918servidevice.exe"Added by the RBOT-GVR WORM!"
Xryyrundl132.exe"Added by the PWS-ANA TROJAN!"
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
Xs9201as2008xp.exe"AntiSpyware XP 2008 rogue spyware remover - not recommended
Xs9201asproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
NSafeInstall.exeSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
XSAHBundleshop1003.exe"ShopAtHomeSelect parasite"
XSB13miniRYZO32.EXE"Added by the SPYBOT-EJ WORM!"
Xscains030109.Stub.exe"Delfin Media Viewer adware related"
Xsck121helpsyss.exeAdded by a variant of the MAILBOT TROJAN!
XSearchSettersearchsetter[1].exeBrowser hijacker - redirecting to FindWhateverNow.com
Xsecbootvtd 16.exe"Added by the HAXDOOR-AE TROJAN!"
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
XSecurity essentials 2010SE2010.exe"Security Essentials 2010 rogue security software - not recommended
XService Pack 1[random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe
XServicerepclient1SERVICES.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
Xservices32mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
Xservices32mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
NSetiQueueSetiqu~1.exe"Provides work unit buffering for Seti@Home clients - see here for more details"
NSetupICWDesktopicwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
XSex Terisst01b.exe"Added by the REPAD WORM!"
XShedule Connectionarpo412.exe"Added by the PPDOOR-R WORM!"
XShellwmedia16.exe"Added by the GOLDUN TROJAN!"
XShellExplorer.exe sound_drive16.exe"Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""sound_drive16.exe"" file is located in %System%"
XShellibm00001.dll"Added by the TORPIG-Q TROJAN!"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
Xsi91e44b"rundll32.exe si91e44b.dll EnableRunDLL32"
USinus 1054 data WLAN ManagerWifiusb.exeWireless management utility for the T-Com Sinus 1054 Data WLAN adapter
YSiS7012UtilitySiSAudUt.exeSiS Corporation sound card driver
?SISAM10MSISAM10M.exe"??"
USK51SK51.EXE"SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
USK9910DMSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Usks-32SKS32P~1.EXE"SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself"
Xslack12mfcee.exe"Added by a variant of the SDBOT WORM!"
NSlingshotSLINGS~1.EXE"Atomica Slingshot - ""reference tool with access to dictionary and encyclopedia terms
NSM1BGSM1BG.EXEUSB driver for downloading from within Napster and iTunes to portable MP3 players. Only required at startup if you use it all the time - otherwise start it manually when required
NSM1NINTSM1NINT.exeCypress USB Mass Storage Driver Notification Icon Application - tray notification for Cypress base memory sticks and external storage devices for Win98
NsMaRTcaPsSMARTC~1.EXE"sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock
?SNCT511vsnct511.exe"Unidentified ""Snapshot Viewer""- what does it do and is it required?"
Usndmi13vsndmi13.exe"Driver for DualCam cameras - that combine the best features of a digital still camera and a webcam"
XSound SystemWinSound1.exe"Added by an unidentified VIRUS
Xsounddrvsndbdrv3104.exe"CoolWebSearch parasite variant"
?SPC610NC_MonitorMonitor.exe"Related to the Philips SPC610NC webcam. What does it do and is it required?"
USpeedport W 100 Stick WLAN ManagerWifiusb.exeWireless management utility for the Speedport W 100 Stick WLAN USB stick
XSpees1speedy.scr"Added by the OPASERV.Y WORM!"
Xspoo1svspoo1sv.exe"Added by the SOULJET TROJAN!"
XSpool lptt01spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpybott lptt01spybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpyClean1ClickSpyClean.exe"1 Click Spy Clean uses a database that was stolen from SpybotS&D. Not recommended
XSpyCrush 3.1SpyCrush 3.1.exe"SpyCrush rogue spyware remover - not recommended
XSpyLocked 4.1SpyLocked 4.1.exe"Spylocked rogue spyware remover - not recommended
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
XSpywareguard lptt01Spywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?sr1exeupdtSup3.exe"Found on a Dell computer in Documents and Settings\All Users\Application Data\DellAlert2"
Usrv32winwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself remove it"
Xstaeck12mfcee.exeAdded by an unidentified WORM or TROJAN!
Xstaeck122mfceee.exeAdded by an unidentified WORM or TROJAN!
USTARTPAGEstart1.exe"NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder"
XStartwd"rundll32.exe wd081025.dllHook"
UStatus Monitor CLJ1500HPPOUMUI.exe"Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status
XSTCLOA~1STCLOA~1.EXE"SecondThought adware"
XStreamAppliancewuauclt14.exe"Added by the RBOT-GMB WORM!"
XStreamAppliancewuauclt16.exe"Added by the RBOT-GME WORM!"
Xstrtaslock1.exe"Added by the SDBOT-ADQ WORM!"
Xstrtasloc1.exe"Added by the RBOT-AZU TROJAN!"
Xstup138762763.exe"Added by the FIRESPY-A TROJAN! It will attempt to register the dropped component as a Firefox plugin and begin monitoring the user's browsing habits
Xstup1db0t_win.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSunJavaUpdaterv13javaupdater.exe"Added by the ROUTROBOT WORM!"
XSunJavaUpdateSched10jushed.exe"Added by the ACKANTTA.F WORM!"
XSunJavaUpdateSched132jschd.exe"Added by the AUTORUN-AQY WORM!"
XSunJavaUpdateSched16jvshed.exe"Added by the ACKANTTA.G WORM!"
Xsupernews12newsd32.exe"Adware
XSurfer lptt01surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSVCH0STspoo1sv.exe"Added by the VB-HF TROJAN!"
Xsvchostrundll16.exe"Added by the STARTPA-PB TROJAN!"
Xsvchost1svchost1.exe"Added by the AGOBOT.ZZ WORM!"
XSvcHostov1rg1n.exe"Added by the AGOBOT-TK WORM!"
Xsvhost1mdsn.exe"Added by the VB-EPK TROJAN!"
XSyBot v2.1 By Sky-DancerHPSV.exe"Added by the ZOTOB.I WORM!"
XSygate Personal Firewallt1ktik.exe"Added by the RBOT-VP WORM!"
XSygate Personal Firewallwin31243.exe"Added by a variant of the IRCBOT TROJAN!"
XSYS1system.exe"Added by the SILLYFDC-AP WORM!"
XSYS1explorar.exe"Added by the SILLYFDC.BDJ WORM!"
XSYS2bad1.exe"Added by the SILLYFDC-AP WORM!"
Xsys201sys209.exe"Added by the STARTPA-ZY TROJAN!"
Xsyscon lptt01syscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsysfbtraybill102.exe"Added by the VB-ENI TROJAN!"
Xsysfbtraybill106.exe"Added by the MDROP-CLV TROJAN!"
Xsysftray2bolivar19.exe"Added by the KOOBFACE.I WORM!"
Xsysint16sysint16.exe"Added by the CRYPTER.A TROJAN!"
Xsysldtrayld11.exe"Added by the KOOBFACE.JG WORM!"
Xsysldtrayld10.exe"Added by the FAKEAV-UD TROJAN!"
Xsysldtrayld12.exe"Added by the KOOBFACE.V WORM!"
Xsysldtrayld01.exe"Added by the KOOBFACE.I WORM!"
Xsysldtrayld15.exe"Added by the AGENT-LNH TROJAN!"
Xsysldtrayld14.exe"Added by the VIRUT.CE VIRUS!"
Xsysldtrayld16.exe"Added by the AGENT-MMO TROJAN!"
XSyslog lptt01Syslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XsysMett1explorer.exe"Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
Xsysmon12[various filenames]"Wareout - malware masquerading as a spyware and dialer remover"
XSysStartsyswin.exe 1"Added by the AUTORUN-EY WORM!"
XSystam13f1r5st83.exe"Added by the IRCBOT-YM WORM!"
XSystam13exp.exe"Added by the RBOT.ESD BACKDOOR!"
XSystam13first.exe"Added by the RBOT.GND BACKDOOR!"
XSystam13resx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystam13speedwin.exe"Added by the RBOT.GVH BACKDOOR!"
XSystemkernels1118.exe"Added by a variant of the SDBOT WORM!"
XSYSTEMRUNDLL16.exe"Added by the DELF-EW BACKDOOR!"
XSystem Loaderapsyst19b.exe"Added by the AGOBOT-AT BACKDOOR!"
XSystem MonitorSysmon16.exe"Added by the SDBOT TROJAN!"
XSystem132Csrtss.exe"Added by the LANFILT-I TROJAN!"
Xsystem16system16.exe"Added by the BANCBAN-OB BACKDOOR!"
XSystem4224411Virus"Added by the CAGER.A WORM!"
XSystem4224411Systemdll.exe"Added by the YUSUFALI-B WORM!"
XSystem51616msnmsgesser.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
XSystemDrivemaxpaynow1.exe"Added by the TIBS.BKU TROJAN!"
Xsystemrd11host.exe"Added by the VB-GX TROJAN!"
XSystemSv12newmaxxsv234.exe"Added by the TIBS-TS TROJAN!"
XSystemSv121n2ewma1xxsv234.exe"Added by the TIBS.TJ TROJAN!"
XSystemToolskernels1118.exe"Added by the SMALL.DGK TROJAN!"
XSysteZd1.exe"Added by the MSNDIABLO.A WORM!"
Xsys_Runtt1explorer.exe"Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
Xsys_up1svchostsys.exe"Added by the MULTIDR-FL TROJAN!"
XSyZf1.exe"Added by the MSNDIABLO.A WORM!"
XSyzmy3exp1orer.exe"Added by the LINEAG-AIO TROJAN! Note the number ""1"" in the filename"
UT-Com WLAN ManagerTS154USB.exeWireless management utility for the T-Com Sinus 154 Data II WLAN adapter
NTaskbar Display Controls"RunDLL deskcp16.dll QUICKRES_RUNDLLENTRY"
XTaskbell.exeRund1.exe"Added by the YIPID TROJAN!"
Xtaskmngr lptt01taskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NTaskPlusTASKPL~1.EXETask and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
?TB_setupTB_ANI~1.EXE"??"
XTencent QQ"Rund1132.exe qq.dll Rundll32"
XTesting 123msdata.dat"Added by the NITS.A WORM!"
Xtlcupdate911.jsHijacker installer
Xtlz47681727.exeAdded by an unidentified TROJAN!
UTMESBSTMESBS21.EXEUtility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
UTMESBS.EXETMESBS21.EXEUtility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
UTMESBS.EXETMESBS31.EXEUtility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on
UTMESRV.EXETMESRV11.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV.EXETMESRV21.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV.EXETMESRV31.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
UTMESRV31TMESRV31.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
XTok-Cirrhatus-1464br3951on.exe"Added by the BRONTOK.AD WORM!"
XTok-Cirrhatus-1959br4941on.exe"Added by the BRONTOK-J WORM!"
XTok-Cirrhatus-1959[random].exe"Added by the BRONTOK-CF WORM!"
XTok-Cirrhatus-1959sarcsv711224030r.exe"Added by the BRONTOK-R WORM!"
XTok-Cirrhatus-1959sarcyesbron.com"Added by the BRONTOK-R WORM!"
XTok-Cirrhatus-2454br5931on.exe"Added by the BRONTOK.AD WORM!"
XTok-Cirrhatus-2784br6591on.exe"Added by the BRONTOK-L WORM!"
XTotal PC Defender 2010Total PC Defender 2010.exe"Total PC Defender rogue security software - not recommended
YTrueMobile 1150 Client Managercmdel.exe"Client Manager for the Dell TrueMobile 1150 Series PC Card - ""a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"""
UTweak UI 1.33 deutsch"RUNDLL32.EXE TWEAKUI.CPL TweakMeUp"
Xtwunk servicetwunk16.exe"Added by the RBOT.BAT WORM!"
XUADC_104911963UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_599141581UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_815790765UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUltra Edit v5.1ultraedit.exe"Added by the SDBOT-RK WORM!"
Xunldr16unldr16.exe"Added by a variant of the CRYPTER.C TROJAN!"
XUpdate ver 1.0Swap.exe"Added by the SWAP-C WORM!"
Nupdatev01updatev01.exeUltra-networks.com software updater/downloader
NUPDATE~1updatemgr.exe"Once a month
XUSB 2.1 Driverwinupdate1.exe"Added by a variant of the RBOT WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XUSB Driverz2msnplus1.exe"Added by the SDBOT-XQ WORM!"
XUSB Fix 1.1wuservices.exe"Added by a variant of the SDBOT WORM!"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
?Utility PingUTILIT~1.EXE"??"
NUVS10 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
NUVS11 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
NUVS12 PreloaduvPL.exePart of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this
YV128IID"Rundll32.exe v128iitw.dll STB_InitTweak"
?V128IITV??"Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?"
Uva10keyva10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
XVCMnet11VCMnet11.exe"Windows AFA Internet Enhancement - a browser hijacker
UVeo Velocity Connectstim11.exeSupport software for the Veo Velocity Connect webcam
Xvern16.dllregsvr32.exe vernn16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""vernn16.dll"" file is found in %System%"
XVideo ProcessMS32x16.exe"Added by the RBOT.RH WORM!"
XVideo ProcessAvg123.exe"Added by the AGOBOT-MS WORM!"
XVirusHeal 4.1VirusHeal 4.1.exe"VirusHeal rogue security software - not recommended
XVnrBlock21VnrBlock21.exe"Internet Speed Monitor adware"
XVnrPack15VnrPack15.exe"Zeno Search Assistant adware"
XVnrPack16VnrPack16.exe"Zeno Search Assistant adware"
XVnrPack17VnrPack17.exe"Internet Speed Monitor adware related - see example here"
XVRT1VRT1.EXE"Added by the VIRUT.CE VIRUS!"
?VX1000vVX1000.exe"Associated with Microsoft's VX-1000 LifeCam webcams. What does it do and is it required?"
XW1N32.DLLWINLOGON .exe"Added by the DROPPERFL.A TROJAN!"
UW815DMW815DM.exe"Enuff Parental Control Software by Akrontech"
UWallPaperWALLPA~1.EXE"Wallpaper Changer - wallpaper manager that can change your background images on every startup"
UWatch1200UBWATCH.EXEButton press monitor for the Mustek 1200 UB Scanner
NWaveTop Receiver 1N/A"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
Xwblogonubpr01.exe"Added by the AGENT-HFI TROJAN!"
NWebposition Gold 2wpsche~1.exe"Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
?WebServerVBI_SE~1.EXE"Related to a Pinnacle sound card. What does it do and is it needed?"
UWebshotswebsho~1.exe"Webshots - software that displays photos as your screensaver and wallpaper
UWG111v2 Smart Wizard Wireless SettingRtlWake.exe"Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
YWG511WLUWG511WLU.exeNetgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
UWhatPulseWHATPU~1.EXE"WhatPulse keeps track of your keystrokes
UWin Chimeswinchi~1.exe"WinChimes - enhancement software for the system clock that runs in the system tray"
XWin Microsoft 98win14.exe"Added by the RBOT-AKX WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
Uwin16.dllwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
Xwin3208022-1336687win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
Xwin32servvms1.exe"iSearch adware"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NWINCINEMAMGRWINCIN~1.EXE"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
XWindir Workingwuaumqr1.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows 128 Modulewin128.exe"Added by the FORBOT-ES WORM!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Live Messenger 8.12ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Media Player 6.1.2wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
XWindows Messenger 4.14landisc.exe"Added by the SDBOT-KR WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Running DLL Servicerundll128.exe"Added by the IRCBOT.XDH BACKDOOR!"
XWindows Servicepd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
XWindows Service Ajavjava128.exe"Added by the RBOT.BNG WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Sound ManagerSndMon16.exe"Added by a variant of the FORBOT WORM!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows Startupwinsta~1.exe"GoHip foistware"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
XWindows Updatewinupupdate1.exe"Added by the RBOT-UV WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Updtee MgnrW1NT45K.exe"Added by the MYTOB.DC WORM!"
XWindows WKS Serviceswkssvr1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Workstation Service [5.1-2600]windrm.exe"Added by the RBOT-CNY WORM!"
Xwindows16windows16.exe"Added by the VB-XU TROJAN!"
XWindowsDs1.exe"Added by the MSNDIABLO.A WORM!"
XWINDOWSflashbrgsqldata1.exe"Added by a variant of the AGENT-IC TROJAN!"
XWindowsFZA5281300.so"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowsKa1.exe"Added by the MSNDIABLO.A WORM!"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsUpd1WindowsUpd1.exe"VirtuMonde adware"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWinFavoritesWinFavorites.exe1Loudmarketing.com adware downloader
XWinhelpwinhe1p.exe"Added by the QQPASS.E TROJAN!"
XwinntR1winntR1.exe"Added by the AGENT.CJZO TROJAN and variants"
XWinProfilesndcfg16.exe"Added by the SNDC.A WORM!"
Xwinrestore1winrestore.exe"Added by the KILLFIL-Q TROJAN!"
XWINRUN zW1NT45K.exe"Added by the MYTOB.BL WORM!"
XWinSecwinsec16.exe"Added by the AGOBOT.ZF WORM!"
XWinsock2 wqr1sWUAUMQR1.EXE"Added by the SPYBOT.KD WORM!"
Xwinsockdriverwinsock4.1.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWinSpywareProtect (ver. 5.1)WinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
XWinStart001WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStart001.EXEWinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinsta~1winsta~1.exe"GoHip foistware"
XWinSth16WinSth16.exe"Added by the CAKE WORM!"
XWinSvc16.exeWinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinSysM371662M.exe"Added by the WINKO.AO WORM!"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
XWinSysW371662L.exe"Added by the WINKO.AO WORM!"
XWinUsrWinUsr.exe K1S2"Added by the CLUNK.A WORM!"
Xwinwan lptt01winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWINX16winx16.exe"Added by the AGOBOT-LS WORM!"
XWinXPplugin1.exeAdded by the Downloader-JW TROJAN!
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
XWinzip Applicationwinzip81.exe"Added by the RBOT-BKZ WORM!"
UWireless PCI Card Configuration UtilityWMP11Cfg.exe"Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
Xwm41a398"rundll32.exe wm41a398.dll EnableRunDLL32"
Xwmplayervergon1885.exe"Added by the BRONTOK-DG WORM!"
NWordPerfect Office 1215Registration.exe"Corel WordPerfect Office 12 registration wizard"
Xworknote1[filename].exe"Added by the MEETOT WORM!"
XWSAConfiguration1csass.exe"Added by the AGOBOT.WH WORM!"
YWU713STA.EXEWU713STA.EXEBlitzz Technology wireless NIC adapter driver
XWUpdate1037v.exe"Added by the CLAGGER-AR TROJAN!"
YWUSB11B.exeWUSB11B.exeLinksys WUSB11 WLAN USB adapter
Xwww.symantec.comoz11111.exe"Added by the MYDOOM.W WORM"
UX-Cleaner FreewareXCLEAN~1.EXE"X-Cleaner Freeware - ""cookie cleaning
UX1X1.exe"Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
UX1 System TrayX1Systray.exe"Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
XX10WeaxWTHRTRAY.EXE"WeatherCheck - ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads
UX1FileMonitor.exeX1FileMonitor.exe"Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
Xxccinitrundll33.exe xccdf16_090131a.dll"Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
Xxccinitrundll33.exe xccdf16_090305a.dll"Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
XXcpy1Xcpy1.exe"FlashEnhancer adware"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
XXordatewuauclt10.exe"Added by the RBOT-GKN WORM!"
XXordatewuauclt11.exe"Added by the RBOT-GLI WORM!"
XXordatewuauclt12.exe"Added by the RBOT-GLQ WORM!"
XXordatewuauclt13.exe"Added by the RBOT-GLM WORM!"
UXTNDConnect PC - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
Xxzkadsfk10afslkfasl10.exe"Added by the ONLINEG-R TROJAN!"
Xx[Number from 1 to 7]x[Number from 1 to 7].exe"Added by the DADOBRA-A TROJAN!"
Xy1959sarsv711224030r.exe"Added by the BRONTOK-AK WORM and variants!"
Xy1959saryesbron.com"Added by the BRONTOK-AK WORM and variants!"
?Yahoo HP Reminder 1.1yr.exe"??"
NYahoo! PagerYAHOOM~1.EXE"System tray access to an older version of the Yahoo! Messenger instant messenger"
Xyahoo_toolbar lptt01yahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YYTrayMagic Lite 1YTRAYMAGIC.EXE"YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored"
UYumgo's Homepage Protector V1YumgoHomepageProtector.exe"Yumgo's Homepage Protector"
XZango TvTimesZANGOT~1.EXE"ZangoSearch adware"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
NZSSnp211ZSSnp211.exe"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
X[12 random characters]avifile5.exe"IeDriver adware variant"
X[12 random characters]bootvid4.exe"IeDriver adware variant"
X[12 random characters]browser8.exe"IeDriver adware variant"
X[12 random characters]atitvo32.exe"IeDriver adware variant"
X[12 random characters]autodisc.exe"IeDriver adware variant"
X[12 random characters]cabview1.exe"IeDriver adware variant"
X[12 random characters]advpack1.exe"IeDriver adware variant"
X[12 random characters]batmeter.exe"IeDriver adware variant"
X[12 random characters]bidispl2.exe"IeDriver adware variant"
X[12 random characters]asferror.exe"IeDriver adware variant"
X[12 random characters]catsrvps.exe"IeDriver adware variant"
X[12 random characters]admparse.exe"IeDriver adware variant"
X[12 random characters]audiosrv.exe"IeDriver adware variant"
X[12 random characters]bootvid2.exe"IeDriver adware variant"
X[12 random characters]cmpbk321.exe"IeDriver adware variant"
X[12 random characters]ADPTIF67.exe"IeDriver adware variant"
X[12 random characters]asycfilt.exe"IeDriver adware variant"
X[12 random characters]ati2dvag.exe"IeDriver adware variant"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[12 random characters]blackbox.exe"IeDriver adware variant"
X[12 random characters]browser5.exe"IeDriver adware variant"
X[12 random characters]bthserv1.exe"IeDriver adware variant"
X[12 random characters]camocx28.exe"IeDriver adware variant"
X[12 random characters]CAMOCX74.exe"IeDriver adware variant"
X[12 random characters]capesnpn.exe"IeDriver adware variant"
X[14 random numbers]mradll.exe"Green AV rogue security software - not recommended
X[14 random numbers]rwg.exe"Green AV rogue security software - not recommended
X[random name]rundl13a.exe"Added by the GAMPASS-L TROJAN!"
X[various names]10010.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]321102.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]cmon14.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]Shaitan1678.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]sysconf16.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]sysmon12.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]TForm1.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]UserSp1.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]exe81.exe"MediaMotor adware"
X_Cat1nmmst.exe"Added by the SMALL.SD TROJAN!"
U{0228e555-4f9c-4e35-a3ec-b109a192b4c2}gnotify.exe"Google Gmail Notifier. Alerts you when you have new Gmail messages"
U{1290A33C-85F5-4164-A1BE-7DD299D4986A}PBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"
X{12EE7A5E-0674-42f9-A76B-000000004D00}"rundll32.exe stlb2.dll DllRunMain"
X{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}sysqkmwfedz.exe"Added by the FAKEALERT-AH TROJAN!"
X{1C-CC-C5-54-ZN}dwdsregt.exe"ZenoSearch adware"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysavxjgdu.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysawpbkvnq.exe"Added by the FAKEALERT-AH TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysxhtcwbse.exe"Added by the FAKEALERT-AM TROJAN!"
X{2CF0B992-5EEB-4143-99C0-5297EF71F444}"rundll32.exe stlbdist.dllDllRunMain"
X{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"rundll32.exe stlbupdt.DLLDllRunMain"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Added by the FAKEALERT-AH TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}sxjecknqhu.exe"Added by the FAKEALERT-AM TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syspyukrazv.exe"Added by the FAKEALERT-AH TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syssfzvakqg.exe"Added by the FAKEALERT-AM TROJAN!"
X{7DD4A7AC-A3F1-4495-884A-7947C5B89108}sysahbecjh.exe"Added by the FAKEALERT-AM TROJAN!"
U{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}XPlay.exe"Xplay 3 from Mediafour Corporation - ""expands what you can do with any iPod
X{9754B85A-3B34-4969-BE1F-CD03227E9470}syszweuas.exe"Added by the FAKEALERT-AM TROJAN!"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}sysatjsicj.exe"Added by the FAKEALERT-AM TROJAN!"
X{B081DB1F-4EE6-4021-9DD4-8B300F0D636D}syssngbeh.exe"Added by the FAKEALERT-AH TROJAN!"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
X{B3B48B54-C0EC-4705-8EE8-1981AEF656A7}sysjcyrq.exe"Added by the FAKEALERT-AH TROJAN!"
X{C0FB7D08-056E-1033-0501-03020730002c}Update.exe"Added by the AGENT-EOG TROJAN!"
X{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}sysfbdgv.exe"Added by the FAKEALERT-AM TROJAN!"
X{C599792D-C6D9-461d-93CA-B48BFF8E37B1}sysfdyev.exe"Added by the FAKEALERT-AM TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysutrnez.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysabmpmfr.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysnxcphmgy.exe"Added by the FAKEALERT-AH TROJAN!"
X{E4785213-3EFE-4c26-A9B4-332440E31F6F}sysrxmfdksp.exe"Added by the FAKEALERT-AH TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.