| U | CheckIt 86 | CheckIt86.exe | "CheckIt 86 popup blocker"
|
| Y | CheckMsgPlus | "MsgPlusH.dll | VerifyInstallation" |
| X | checkrun | elite***32.exe [* = random char] | "EliteBar adware"
|
| X | checkrun | elitelsj32.exe | "Added by the MULTIDR-ER TROJAN!"
|
| X | CheckScan32 | regload16.exe | "Added by the AEBOT.K WORM!"
|
| ? | checktime | ct.exe | "Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?"
|
| Y | CheckVCR | IOMagic.exe | "Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)"
|
| X | CheckWinPerf | perfinfo.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| N | Client Access Check Version | cwbckver.exe | "Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop |
| U | CloneCDElbyCDFL | ElbyCheck.exe | "From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
|
| X | Critical Update Check | battlenet.exe | "Added by the DELF-LB TROJAN!"
|
| Y | CSAV_CheckViruses | vchk.exe | "Command Antivirus related"
|
| X | CSCRS Value Check | MsPMSPSd.exe | "Added by a variant of the SDBOT WORM!"
|
| Y | CSScheduleCheck | SCHWIZEX.EXE | "Part of ConfigSafe - lets you identify changes to the registry |
| U | CTCheck | CTCheck.exe | "Associated with the ZEN range of MP3 players from Creative Technology Ltd. A visitor recommended the ""U"" status but what does it do?"
|
| N | Cyber-shot Viewer Media Check Tool | SPUVolumeWatcher.exe | "Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
|
| N | Cyber-shot Viewer Media Check Tool | SPUVOL~1.EXE | "Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
|
| X | Datcheck | datcheck.exe | "Added by the KEYPANIC TROJAN!"
|
| ? | Datechecker | N/A | "Could be related to this?"
|
| X | DC6_Check | uwasdc.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| X | DC6_check | dc6_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | dc6_check | dcmon.exe | "SystemDoctor rogue security software - not recommended |
| X | defragm_check | defragment.exe | "CoolWebSearch parasite variant"
|
| X | Disk Check | chkdsk32.exe | "Added by the IM TROJAN!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| X | DriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| ? | DVDCheck | DVDCheck.exe | "Related to an Intervideo program. What does it do and is it required in startup?"
|
| U | Elbycheck | ElbyCheck.exe | "From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| Y | eRecoveryService | check.exe | "Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_Check | uwasers.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| X | FaltCheck | allps.exe | "Added by the AGENT.RAP TROJAN!"
|
| N | filehippo.com | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | FileHippo.com Update Checker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
|
| X | FW Manager | fwcheck.exe | "Added by the DELBOT-H WORM!"
|
| U | HP Health Check Schedule | HPHC_Scheduler.exe | HP Health Check Scheduler from Hewlett-Packard
|
| X | IEAgent update check | iewatch.exe | "Added by the BOMKA TROJAN!"
|
| N | iecheck | iecheck.exe | "Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2"
|
| X | IECheck | MSDTCs.exe | "Added by the TIRBOT-D WORM!"
|
| X | IECheck | xpssl.exe | "Added by the TIRBOT-E WORM!"
|
| X | IECheck | mssvp.exe | "Added by the TIRBOT-G WORM!"
|
| ? | immcheck.exe | immcheck.exe | "Related to I-FORCE driver for force feedback steering wheel?"
|
| ? | Intense Registry Service | IntEdReg.exe /CHECK | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| Y | InterCheck Monitor | Icmon.exe | "Part of Sophos ant-virus sofware"
|
| Y | InterCheckMonitor | ICMON.EXE | "Part of Sophos anti-virus sofware"
|
| X | jucheck | jucheck.exe | "Added by the SCRIMGE.O WORM!"
|
| X | Kernal Fault Check | ntosrkl.exe | "Added by a variant of the SDBOT WORM!"
|
| X | KernelCheck | sys****.exe [* = digit] | Added by an unidentified TROJAN!
|
| X | KernelCheck | winser.exe | "Added by the TSPY_LMIR.SL TROJAN!"
|
| N | kernelfaultcheck | dumprep 0 -k | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
| N | kernelfaultcheck | dumprep 0 -u | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
| X | KernelFaultCheck | ptool32.exe | "Added by the LEGMIR-BN TROJAN!"
|
| X | KernelFaultCheck | msime.exe | "Added by the TINY-P TROJAN!"
|
| X | KernelFaultCheck | tell32.exe | "Added by the LEGMIR-BF TROJAN!"
|
| X | KernelFaultCheck | winabc3.exe | "Added by the NUBYS-A VIRUS!"
|
| X | KernelFaultCheck | winbin.exe | "Added by the DLOADR-AAX TROJAN!"
|
| X | Kernel_check | wmiprvse.exe | "Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
|
| Y | Keyboard Preload Check | Preload.exe | Millenium Multi-Function Keyboard driver
|
| X | Krnlcheck | csrss.exe | "Added by the BOTNACHALA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | List checker 32 BIT | list32.exe | "Added by the RBOT-AHO WORM!"
|
| X | LoadPowerScheme | rundll32.exe powerprof.dll CheckPowerProfile | "Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| U | LPMailChecker | LPMLCHK.exe | "Part of Lenovo's ThinkVantage® Productivity Center on their ThinkPad notebooks or ThinkCentre desktops. Checks for incoming e-mail and blinks the ThinkVantage button LED"
|
| X | Mail_Check | Mail_Check.exe | "Added by the PANOIL.C WORM!"
|
| N | Mass storage check registry | "rundll32.exe MSDServ.dll | check registry" |
| X | MAV_check | mav_startupmon.exe | "Part of the WinAntiVirus Pro 2007 rogue security software - not recommended |
| X | Memory Check | memore.exe | "Added by the KILLAV.C TROJAN!"
|
| X | Microsoft checker | MsPMSPTv.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Information Check | microsoft.exe | "Added by the IRCBOT.AUH TROJAN!"
|
| X | Microsoft System Checkup | Cool.exe | "Added by the DONK.B WORM!"
|
| X | Microsoft System Checkup | Wnetlib.exe | "Added by the DONK.C WORM!"
|
| X | Microsoft System Checkup | dbnetlib.exe | "Added by the DONK.L WORM!"
|
| X | Microsoft System Checkup | Keymgr.exe | "Added by the DONK.M WORM!"
|
| X | Microsoft System Checkup | inetman.exe | "Added by the DONK.O WORM!"
|
| X | Microsoft System Checkup | ntsysmgr.exe | "Added by the DONK.S WORM!"
|
| X | Microsoft System Checkup | ntsysman.exe | "Added by the SDBOT-QW WORM!"
|
| X | Microsoft System Checkup | libsysmgr.exe | "Added by the SDBOT-CAF WORM!"
|
| X | Microsoft System Checkup | sysmgr.exe | "Added by the SDBOT-OO TROJAN!"
|
| X | Microsoft System Checkup | netapi32.exe | "Added by the DONK-E WORM!"
|
| X | Microsoft System Checkup | wnetmgr.exe | "Added by the DONK.Q WORM!"
|
| X | Microsoft System Checkup | libsys32.exe | "Added by the SDBOT-ACK WORM!"
|
| X | Microsoft System Checkup | netlogin32.exe | "Added by the SDBOT-GN BACKDOOR!"
|
| X | Microsoft Windows DLL 32-BIT | msncheck32.exe | "Added by the SDBOT-XX WORM!"
|
| X | msadcheck | msadcheck32.exe | "Browser hijacker |
| X | mscheck | rundll32.exe wincheck071008.dll mymain | "Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
|
| X | MSN Checker | msnchecker.exe | "Added by the SDBOT-AGB WORM!"
|
| X | mspaint.exe | check32.exe | "Added by the AGENT.AH TROJAN!"
|
| X | MS_Update Check | wdfmgr.exe | "Added by the AGOBOT-TB WORM!"
|
| X | NAVCheck | navchk.exe | Premium rate adult content dialer
|
| X | NAVCheck | shman.exe | Premium rate adult content dialer
|
| X | Nero Checker | nerocheck.exe | "Added by the PROXY-X TROJAN! Note - this is not related to ""Nero Burning Rom"" CD writing software"
|
| U | NeroCheck | nerocheck.exe | Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
|
| X | NeroCheck | regedit.exe | "Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD/DVD burning program. Also |
| X | NeroFileCheck | msjavam32.exe | "Added by the AGOBOT.AKM WORM!"
|
| U | NeroFilterCheck | NeroCheck.exe | Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
|
| X | NeroUpdate Check | msjava.exe | "Added by the AGOBOT.AMH WORM!"
|
| X | NetReach | nrcheck.exe | "Added by an unidentified VIRUS |
| X | Nokia Check | nokiacheck.exe | "Added by the RBOT.CDC WORM!"
|
| N | NomdCheck | nomdchek.exe | Part of Intel's Native Audio
|
| ? | Norton Program Scheduler Event Checker | npscheck.exe | "Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker"
|
| ? | NPS Event Checker | npscheck.exe | "Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker"
|
| X | NSCheck | NSCHECK.EXE | "MarketScore parasite - ActiveX control used to download premium-rate dialers"
|
| X | Ntcheck | mapserver.exe | "Added by the TOMPAI-B WORM!"
|
| Y | OBRCheck | check.exe | "Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| N | OEXCheck | EA2Check.exe | "Express Assist from AJSystems.com. Utility for use with Outlook Express to backup |
| Y | OfficeGuard RegChecker | ogrc.exe | "Kaspersky Labs anti-virus"
|
| X | opsql update check | opsql.exe | "Added by the RBOT-ACJ WORM!"
|
| U | osCheck | osCheck.exe | "Part of Norton Antivirus. Initiates a quick scan (at startup) of the portions of the OS Symantec currently (as defined by the most recent updates downloaded onto the host computer) thinks are most susceptible to infection. This scan is not necessary for proper operation of Norton Antivirus"
|
| X | PAS_Check | udcpas.exe | "Part of the DriveCleaner rogue security software - not recommended |
| X | pas_check | pasmon.exe | "SystemDoctor rogue security software - not recommended |
| X | PC-Checkup | PCCheckUp.exe | "Installed by SpeedItUp without permission |
| X | pctp_check | startmon.exe | "Part of the PcTurboPro rogue system optimization tool - not recommended |
| N | Photo Express Calendar Checker SE | CALCHECK.EXE | "If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper |
| U | PhotoExplosionCalCheck | calcheck.exe | "Calendar management feature of Nova Development's Photo Explosion"
|
| N | Picture Motion Browser Media Check Tool | SPUVolumeWatcher.exe | "Part of the Sony Picture Uility software supplied with Sony camera/camcorder products. Automatically invokes an import process if the camera/camcorder is connected and has media on it"
|
| Y | PinnacleDriverCheck | PSDrvCheck.exe | "Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
|
| X | PostSetupCheck | Rundll32.exe atgban.dll | "TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""atgban.dll"" file is found in %System%"
|
| X | postSetupCheck | Rundll32.exe gzmrt.dll | "TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""gzmrt.dll"" file is found in %System%"
|
| X | PostSetupCheck | Rundll32.exe cpmsky.dll | "TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
|
| U | PPMemCheck | ppmemcheck.exe | "PPMemCheck - used to be part of PestPatrol before CA's acquisition"
|
| N | Precision Time Clock Checker | PrecisionTime.exe | Precision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
|
| Y | PSDrvCheck | PSDrvCheck.exe | "Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
|
| Y | QH Office 2K Check | O2KCHECK.EXE | "Quick Heal Anti-Virus MS Office documents virus checker"
|
| ? | RAMConnectionChecker | RAMConnChecker.exe | "Part of Remote Access Manager (RAM) for Nortel Networks - which ""combines an intuitive |
| U | RCScheduleCheck | RCSCHED.EXE | "Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
|
| X | RealPlayer Ath Check | rnathchk.exe | "Added by the MYTOB.AG WORM!"
|
| X | RealPlayer Ath Check | mathchk.exe | "Added by the MYDOOM-AJ WORM!"
|
| ? | Reg Check | lpt.exe | "Related to Supanet ISP software - what does it do and is it required?"
|
| X | Regcheck | ~CAB001.EXE | "Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
|
| X | regcheck | [path to file] | "Added by the SERVPAM TROJAN!"
|
| X | Registry Checker | Regrun.exe | "Added by the SDBOT TROJAN!"
|
| X | Registry Checkup | winreg.exe | Added by an unidentified WORM or TROJAN!
|
| X | Registry Checkup System326a Monitor | Winregs326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Registry Integrity Checker | regintmon.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Registry Integritycheck | WCPDT.EXE | "Added by the AGOBOT-RF WORM!"
|
| X | Registry Startup Check | checkreg.exe | "Added by the REMLOAD-A or DANMEC-B TROJANS!"
|
| X | Registry System16 Checkup Monitor | SystemReg16.exe | "Added by a variant of the RBOT WORM!"
|
| X | Registry System166 Checkup Monitor | SystemReg166.exe | "Added by a variant of the RBOT WORM!"
|
| X | RegistryCheck | "rundll32.exe chkreg.dll | CheckRegistry" |
| X | scheck45 | scheck45.exe | Related to unknown malware - hidden installer associated with it
|
| ? | SDJobCheck | triggusr.exe | "Part of CA Unicenter Software Delivery - manage software across various systems |
| X | SDR6V_Check | udcsdr.exe | "Part of the DriveCleaner rogue security software - not recommended |
| X | SDR6_Check | udcsdr.exe | "Part of the DriveCleaner rogue security software - not recommended |
| U | SecurePCSolutionsBootCheck | BootCheck.exe | "1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
|
| X | Sheduler | nerocheck.exe | "Added by the TACTSLAY.B TROJAN!"
|
| U | SoloSysCheck | Syscheck.exe | "Solo antivirus System Integrity Check - Monitors system registry |
| U | SpyCop ScanCheck | MAIN.EXE | "SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
|
| X | SQConfigChecker | cc.exe | "Xupiter SQWire toolbar related. Use Spybot S&D |
| X | SQUpdatesChecker | uc.exe | "Xupiter SQWire toolbar related. Use Spybot S&D |
| X | svhoost | checksys.exe | Added by a downloader TROJAN of Chinese origin!
|
| X | SymantecFilterCheck | svhost.exe | "Added by the BANKER-EEO TROJAN!"
|
| X | SymantecFilterCheck | gmilogof.exe | "Added by the BANKER-EKC TROJAN!"
|
| X | SymantecFilterCheck | [path to trojan] | "Added by the BANKER-EIN TROJAN!"
|
| X | SymantecFilterCheck | bsyys.scr | "Added by the BANLOAD.DZC TROJAN!"
|
| X | Syscheck | win.hta | Browser hijacker
|
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
|
| U | SysCheck32 | sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
| X | System Boot Check | sysload3.exe | "Added by the FUBALCA WORM!"
|
| U | System Check | "Rundll32.exe SysDll32.dll | SystemCheck" |
| X | system check | updater.exe | Unidentified adware downloader
|
| X | System Check | win_klr32.exe | "Added by the DELF-DRA WORM!"
|
| X | System Checking | wasul.exe | "Added by the RBOT.BHM WORM!"
|
| X | System Security Checker | ssc.exe | "Added by the IRCBOT-WI TROJAN!"
|
| X | System Update2 | webcheck.exe | "Added by the AUTOTROJ-C TROJAN!"
|
| X | System32Check | [random].exe | "Added by the CHAST-A TROJAN!"
|
| X | SystemCheck | Systemcheck.exe | "Added by the LAVITS WORM!"
|
| X | SystemCheck | services.exe | "Added by the SOBER-M WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Config\system"
|
| X | SystemCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | SystemCheck | SysCheckBop32.exe | "WINBO adware"
|
| U | Systemcheck | sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
| X | SystemChecker | Syschk.exe | "Added by the GALIL.F WORM!"
|
| X | SystemDriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | tcp checker | tcpcheck.exe | "Added by the VBBOT-A TROJAN!"
|
| U | Trojancheck 6 Guard | tcguard.exe | "TrojanCheck anti-trojan software"
|
| ? | TypeRegChecker | TypeRegChecker.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| N | Ulead Calendar Checker | CalCheck.exe | "Ulead Calendar Checker - part of Ulead Photo Express - automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually"
|
| N | Ulead Photo Express Calendar Checker | calcheck.exe | "If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper |
| N | Ulead Photo Express x.0 Calendar | calcheck.exe | "Ulead Calendar Checker - part of Ulead Photo Express |
| X | Update Checker | winlog.exe | "Added by the IRCBOT-TJ TROJAN!"
|
| X | Update Checker | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | UpdateCheck | winstall.exe | "Added by the SPYBOT-CY WORM!"
|
| N | UpdateChecker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | USB2Check | PCLECoInst.dll | "Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
|
| N | UserFaultCheck | dumprep 0 -u | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
| X | VirusCheckII | AVIRCHK.EXE | "Added by the DASMIN TROJAN!"
|
| Y | VOBRegCheck | VOBRegCheck.exe | "Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
|
| Y | VSOCheckTask | mcmnhdlr.exe | "Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically |
| X | WA6PM_Check | udcwap.exe | "Part of the DriveCleaner rogue security software - not recommended |
| X | WA6PV_Check | udcwap.exe | "Part of the DriveCleaner rogue security software - not recommended |
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | "WashAndGo - temp file cleaner"
|
| X | was_check | PASmon.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| ? | WatchDog | DVDCheck.exe | "Related to an Intervideo program. What does it do and is it required in startup?"
|
| X | WCheckUp | WCheckUp.exe | "Barok keylogger and password stealer"
|
| X | WebCheck | WebCheck.pif | "Added by the CONE.C or CONE.F WORMS!"
|
| X | Win64 Compatibility Check | load win64.drv | "CoolWebSearch parasite variant"
|
| X | WinCheck | services.exe | "Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
|
| X | WinCheck | WinCheck.exe | "Added by the PWS-CY TROJAN!"
|
| X | WinCheck | services.exe | "Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
|
| X | WinCheck | check.exe | "Added by the DELBOT-Y WORM!"
|
| X | Windowfdgfds DLL fgfdg Verifier | Windowsdldfglcheckkk.exe | "Added by the RBOT.CSP WORM!"
|
| X | Windows (random character) | diskcheck.exe | "Added by the SINGU.B TROJAN!"
|
| X | Windows Recylinder Check | zwdomsgemw.exe | "Added by the RBOT-EGJ WORM!"
|
| X | Windows Update Check | syslodr.exe | "Added by the SMALL.LU TROJAN!"
|
| X | Windows Update Checker | [random filename] | Adware downloader trojan
|
| X | Windows Update Checker | msupdte32.exe | "Added by the SDBOT-AEF WORM!"
|
| X | Windows Update Checker | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
| X | Windows Update Checker | deinst_qfe002.exe | Added by a variant of the Win32.Small TROJAN!
|
| N | Windows Version Check | ver_chk.exe | "Version checker for CyberAudioLibrary - ""a new way to exchange information through the Internet"""
|
| U | Windstream Broadband Check-up Center | matcli.exe | "Part of the Windstream Broadband service from AllTel. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| U | WinSysCheck | sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
| X | WinZap Check | winzbp.exe | "Added by the RBOT-AWZ WORM!"
|
| N | WMC_RebootCheck | unregmp2.exe | "Corrects problems with installations of Windows Media Player from version 9 onwards - see here and search for ""unregmp2.exe"""
|
| X | [various names] | StatusCheck.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _WinCheck | services.exe | "Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
|