Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
X5-1-61-96members-area.exeAdult content dialler
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
YAccelerometerStAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAzMixerSelAzMixerSel.exe"Related to Realtek_Azalia Mixer Selector"
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
?Coupon Offers??"??"
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
Xdm[3 random letters].exedm[3 random letters].exe"Added by the RUINDEM TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
NDulux WeatherShield WeatherDeskweather.exe"Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
UEFI Hot Foldershffw.exe"""EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
XError Safeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XError Safe Freeuers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeFreeUERS.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERScwERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_Checkuwasers.exe"Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
?Executedelfolders.exe"??"
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
Xgrindersgrinders.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
UHalifaxHowardClusterskinkers.exe"""Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHML PowerSourcehmlsvc32.exe"Added by the SDBOT-XL WORM!"
XHMV PowerSourcehmusvc32.exe"Added by the SDBOT-YW WORM!"
UHot CornersHotc.exe"Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
Xicccomp[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
Xidlesam[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
Uigfxpersigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
Xiisversiisvers.exeAdded by an unidentified TROJAN or adware
XImage Remote Playerssysvn.exe"Added by a variant of the IRCBOT BACKDOOR!"
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
Xinstant messengersinstantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIntersoft Msngrintersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
Yiolo Personal FirewallioloFW.exe"iolo Personal Firewall"
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
UJob-oversigttaskmon.exe"Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
YKaspersky Anti-HackerKAVPF.exe"Kaspersky Anti-Hacker personal firewall - no longer available"
YKaspersky Anti-Virus MonitorAvpM.exe"Kaspersky Anti-Virus Lite - no longer available"
XKaspersky AntivirusKasperskyAV.exe"Added by a variant of the RBOT WORM!"
XKaspersky Email Securityjavaupd.exe"Added by the SWARLEY.A WORM!"
Xkaspersky32kasperskyLabs32.exe"Added by the RBOT-GOT WORM!"
XKasperskyAvkaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus"
XKasperskyAVEngKasperskyaveng.exe"Added by the NETSKY.V WORM!"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YKAVPersonal50Kav.exe"Kaspersky Anti-Virus Personal 5.0"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
Xkdmsx[8 random letters].exe"Added by the SDBOT.AIJ BACKDOOR!"
XL0adersfaxneti.exe"Added by a variant of the SDBOT TROJAN!"
XLayersecurity ServicemonitorLSSMON.EXE"Added by the BANKER.ZAQ TROJAN!"
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
NLenovoOobeOffersLenovoOobeOffers.exe"Displays product upgrades/offers from Lenovo on the first run of a new notebook/desktop. ""Oobe"" refers to the ""Out of box experience"""
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
XLinksys Modem Driverslinksys.exeAdded by the IRCBOT.VD WORM!
XLive PC CareLP[random characters].exe"Live PC Care rogue security software - not recommended
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLoadersHeIp.exe"Added by the SDBOT-ADB WORM!"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLTM2winvers16.exe"Added by the SMALL.ND TROJAN!"
XM S DVD DirectX Dll Driversmsxdl.exe"Added by the SDBOT-BJN WORM!"
XMalware Cleaner[random numbers].exe"Malware Cleaner rogue security software - not recommended
Xmceipww[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
XMDM Rock 4[8 random letters].exe"Added by the SDBOT.CHG BACKDOOR!"
XMembers area******.exe [* = random digit]Premium rate adult content dialer
NMessagerStarter FreeserveStartMessager.exeFreeserve Messenger
XMessenger91messengersystem.exe"Added by the RBOT-FPF WORM!"
XmessengerskinnerMessengerSkinner.exe"Messenger Skinner malware - uses a rootkit to hide executable files"
XMeTaLRoCk (irc.musirc.com) has sex with printersmetalrock-is-gay.exe"Added by the RANDEX.Q WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMicrosoftmixers.exe"Added by the AGOBOT-AHU WORM!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoft Directx clicksdirectxclickers.exe"Added by the RBOT-GHT WORM!"
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicroSoft Getway mqbol[12 random letters].exe"Added by the RBOT.GBA WORM!"
NMicrosoft Greetings RemindersMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft messenger sdmsngersd.exeAdded by an unidentified TROJAN!
XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
XMicrosoft Personal Firewallsbakw.exe"Added by the RBOT-KS WORM!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft Security Panagerszzoboony.exe"Added by the RBOT-AOI WORM!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updaterstskmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
NMicrosoft Works Calendar Reminderswkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftKsDrivers.bat"Added by the SHUTDOWN-F TROJAN!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicrsoft DerSystemuqieelpb.exe"Added by the RBOT-GRI WORM!"
UMirrorFolderShellmrfshl.exe"MirrorFolder backup software"
NMixerselmixersel.exeConfiguration for Realtek audio devices
UML1HelperStartUpML1HEL~1.EXE"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UML1HelperStartUpML1Helper.exe"ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
NMMReminderServiceMMReminderService.exe"Mind Manager from Mindjet - ""easy way to organize ideas and information"". Registration reminder"
UMonitor Apache ServersApacheMonitor.exePart of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
NMonstersoundtrayFreectrl.exeDiamond Multimedia sound card control panel
XMs BuildersWupated.exe"Added by the AGOBOT-SS WORM!"
XMS DirectX Sound Driversmsdrvdx.exe"Added by the RBOT.BCX WORM!"
XMS DVD DirectX Dll Driversmdxdl.exe"Added by the SDBOT-XI WORM!"
XMS DVD DirectX Sound Driversmsdrvdx.exe"Added by the SDBOT-XJ WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs Sound Driversmsdrv.exe"Added by the SDBOT-WR WORM!"
XMSIE ParsersMSIE32ab.exe"Added by the SDBOT.MV WORM!"
XMSMSGNER[4-8 random letters].exe"Added by the FOWLDO-GEN TROJAN!"
XMSNmsnmesengers.exe"Added by the RBOT-ME WORM!"
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMsn MessengersMSNMSGR.EXE"Added by the RBOT.KX WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSN UPDATERSvirtualmemory.exe"Added by the RBOT-JK WORM!"
XMsnMessengerSvcmsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSVersionINTERNETFEATURES.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
UMW1HelperStartUpMw1helper.exe"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UMW1HelperStartUpMW1HEL~1.EXE"ScreenScenes ""Magic Waterfall"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XMy Security EngineMS[random characters].exe"My Security Engine rogue security software - not recommended
XMy Security WallMS[random characters].exe"My Security Wall rogue security software - not recommended
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
NNetPerSecNetPerSec.exe"
NNetZIPFoldersnzfprop.exe"
XNeuerSchildpgs.exe"NeuerSchild
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNorton Personal Firewalljah.exe"Added by a variant of the SDBOT WORM!"
XNorton Personal Firewallnpfw.exe"Added by the RBOT-UI WORM!"
XNorton Personal Firewalllah.exe"Added by a variant of the RBOT WORM!"
XNorton Personal Firewallnpfw32.exe"Added by the RBOT-UQ WORM!"
YNorton Personal FirewallIntroWiz.exePart of Norton Personal Firewall or Norton Internet Security
XNorton Personal Firewallwinmpts.exe"Added by the RBOT.ANT WORM!"
XNvid[8 random charachters]Unidentified adware
XnVidia Application Driversnvidiav32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XnVidia Display Drivers (x86)nvsys86.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XnVidia DriversnVidiaDrvers.exe"Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card"
XNVidia Drivers[path to trojan]"Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
XnVidia System Driversnvsys32.exe"Added by an unidentified WORM or TROJAN! See here"
XNVIDIA Video driversvideo_32D.exe"Added by the AGOBOT.KV WORM!"
XNVIDIA Video driversvideo_32sD.exe"Added by the RBOT-BB WORM!"
XOffer Companionoffers.exeAdware
XOffersoffers.exeAdware
XOpen Service Driversopiater.exe"Added by a variant of the RBOT WORM!"
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XorderShellorder****.exe [* = random char]"Added by the DLOADR-UN TROJAN!"
?Packard Bell EverSafe Tray ControlTrayControl.exe"Packard Bell EverSafe software. What does it do
XPC Live GuardPC[random characters].exe"PC Live Guard rogue security software - not recommended
YPersFwPersFw.exe"Kerio or Tiny Personal Firewall"
UPersistenceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
XPersonal Anti MalwarePAM.exe"Unregistered version of Personal Anti Malware rogue security software - not recommended
XPersonal Anti Malware CenterAMC.exe"Registered version of Personal Anti Malware rogue security software - not recommended
XPersonal AntivirusPerAvir.exe"Personal Antivirus rogue security software - not recommended
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
XPersonal Defender 2009pdefendr.exe"Personal Defender 2009 rogue security software - not recommended
XPersonal Firewall V9Firewall-UpdateV9.exe"Added by the RBOT-BJR WORM!"
XPersonal Firwallptmedsrv.exe"Added by the SDBOT.XY WORM!"
XPersonal Security Center Monitorisc_ui.exe"Added by the FAKEALERT TROJAN!"
XPersonalAntiSpy Freepas.exe"PersonalAntiSpy rogue spyware remover - not recommended
XPersonalAVpav.exe"PersonalAV rogue security software - not recommended. Detected as the FAKEAV.FT TROJAN by Trend. Located in %ProgramFiles%\PersonalAV"
Xpersonalguardpersonalguard.exe"Personal Guard 2009 rogue security software - not recommended
Xpersonalprotectorpersonalprotector.exe"Personal Protector rogue security software - not recommended
XPersonalSecpsecurity.exe"Personal Security rogue security software - not recommended
XPersonSecuritypsecurity.exe"Personal Security rogue security software - not recommended
XPersSecuritypersonalsecurity.exe"Personal Security rogue security software - not recommended
XPersSecuritypsecurity.exe"Personal Security rogue security software - not recommended
UPhoneFree version 6.2PHONEF??.EXE"An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here"
UPMTpersonalmoneytree.exe"According to the web site Personal Money Tree is an automatic cash rebate program. Note: Not recommended"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
XPopup and Advertisement Killersadkillers.exe"Added by the RBOT-DDH WORM!"
Xpopuppersnewpop63.exe"Medload adware"
Xpopuppers64a64sddd.exe"Popuppers adware
Xpopuppers65[path to file]"Medload adware"
XPower Scanpowerscan.exe"Foistware by Integrated Search Technologies - the people behind ISTBar adware"
UPowerPanel Personal Edition User Interactionpppeuser.exe"CyberPower PowerPanel Personal Edition UPS Monitoring & Control Software - ""is included with CyberPower's products. This exclusive software allows control and monitoring of your UPS to provide protection for your computer system
?PowerSPowerS.exe"ProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?"
?PowerSetRegedit.exe /s ...PowerSet_8100_CU.REG"Appears to be Toshiba power management related"
NPowerStrippowerstrip.exe"PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings"
NPowerStripPSTRIP.EXE"PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings"
XPrinterSpool[path] RESTORE.EXE [path] SPOOL.EXE"Added by the ALADINZ.K TROJAN!"
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
Xproses[5 random letters].exe"Added by a variant of the RBOT WORM!"
XRegistryMonitor1igfxpers.exe"Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
XRequired Service Driversmicront.exe"Added by the RBOT-ABD WORM!"
Xreszrv[8 random letters].exe"Added by a variant of the SDBOT WORM! See here"
URetrieverSchedulerretrieverscheduler.exe"80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders
URivaTunerStartupDaemonRivaTuner.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTunerWrapper.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
XRPC Driversrpcall.exe"Added by the SDBOT.FLY WORM!"
XSearchNavVersionsearchnavversion.exeSearchNav adware - IEFeatures/Popnav variant
USecureOnlineAccountNumbersSOAN.exe"Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions"
XSecurity AntivirusSA[random characters].exe"Security Antivirus rogue security software - not recommended
XSecurity GuardSG[random characters].exe"Security Guard rogue security software - not recommended
XSecurity Master AVSM[random characters].exe"Security Master AV rogue security software - not recommended
XService Driversmsnpg.exe"Added by the RBOT.BMD WORM!"
XService DriversPC.EXE"Added by the SDBOT-WK WORM!"
XService DriversCompt.exe"Added by the RBOT-ZJ WORM!"
XService Driversabl.exe"Added by the SDBOT-YX WORM!"
XService DriversMSNMEssenger.exe"Added by a variant of the RBOT WORM!"
XServices Managerssvcmanager.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSGPUpdatersgpUpdaters.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XSichererSchutzpgs.exe"SichererSchutz
Uskinkersskinkers.exe"Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's ""Desktop Ozzy"" and Arsenal's ""Desktop Wenger"" - see here. Leave enabled if you want to receive messages"
XSmart Virus EliminatorSM[random characters].exe"Smart Virus Eliminator rogue security software - not recommended
XSMSERIALWORKERSTARTshellexcon.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSoundMax Audio DriversSndMAX.exe"Added by a variant of the SDBOT WORM!"
XSpecialOffersSpecialOffers*.exe [* = digit]"SpecialOffers adware"
XSpecialOffersSpecialOffers.exe"SpecialOffers adware"
XSpoolerSubSystemProcessSpooI32.exe"Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
USuper X Desktop Version 3.4SXDesk.exe"Super X Desktop - virtual desktop manager"
Xsuperslutmsslut32.exe"Added by the SLUTER-A WORM!"
USuperSpamKiller ProSsk.exe"SuperSpamKiller Pro email spam blocker"
Xsupport-reverse-smileys[trojan filename]"Added by the LITEBOT TROJAN!"
XSwiftCleanerSwiftCleanerScanner.exe"SwiftCleaner rogue cleaning utility - not recommended
XSygaete Personal FirewallSyGate.exe"Added by the RBOT-GLX WORM!"
XSygate Personal 3svrv.exe"Added by the RBOT-XD WORM!"
XSygate Personal BlockStudio.exe"Added by the RBOT-TW WORM!"
XSygate Personal FirewallWin32x.exe"Added by the RBOT-KZ WORM!"
XSygate Personal Firewallsystem32.exe"Added by the RBOT.VI WORM!"
XSygate Personal Firewallsysgut.exe"Added by the SDBOT.WM WORM!"
XSygate Personal FirewallSygate.exe"Added by the RBOT-PN WORM!"
XSygate Personal FirewallMcafeeupdate.exe"Added by the RBOT.YN WORM!"
XSygate Personal FirewallSygate32.exe"Added by the RBOT.ATW WORM!"
XSygate Personal FirewallMSNSRV32.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallservice.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallt1ktik.exe"Added by the RBOT-VP WORM!"
XSygate Personal Firewallhost32.exe"Added by the RBOT.ALD WORM!"
XSygate Personal Firewallsexy.exe"Added by the RBOT-XY WORM!"
XSygate Personal Firewallsys.exe"Added by the RBOT-ZC WORM!"
XSygate Personal Firewallsyserror.exe"Added by the RBOT.UC WORM!"
XSygate Personal Firewallhostserv.exe"Added by the RBOT.BKO WORM!"
XSygate Personal Firewallmsnmsgrs.exe"Added by the RBOT.XN WORM!"
XSygate Personal FirewallSygat.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallwins.exe"Added by the RBOT.AOB WORM!"
XSygate Personal Firewallwinxpstat.exe"Added by a variant of the RBOT WORM!"
XSygate Personal FirewallSyga.exe"Added by the RBOT-AQD WORM!"
XSygate Personal Firewallsvchots.exe"Added by the RBOT.ABT WORM!"
XSygate Personal Firewallwin31243.exe"Added by a variant of the IRCBOT TROJAN!"
XSygate Personal Firewall Startservices32.exe"Added by the RBOT-MB WORM!"
XSygate Personal Firewall Startservic.exe"Added by the RBOT-RY WORM!"
XSygate Personal Portcrss.exe"Added by the RBOT-PX WORM!"
XSygate Personal Port Blockervolume.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
XSygate Personals Firewallsccsrn.exe"Added by a variant of the RBOT WORM!"
XSygates Personal Firewallsygs.exe"Added by the RBOT.XB WORM!"
XSynchronization Managerrservers.exe"Added by the FORBOT-FM WORM!"
XSysDefendersSysDefenders.exe"SysDefenders rogue security software - not recommended
XSysgate Personal Firewallsyst3ms.exe"Added by a variant of the IRCBOT TROJAN!"
XsysPersonalFirewallmsnmssgr.exe"Added by a variant of the RBOT WORM!"
XsysPersonalFirewallsystem.exe"Added by the WOOTBOT.FH WORM!"
XsysPersonalFirewalltskm0nitor.exe"Added by the SDBOT.APC WORM!"
XSystem DefenderWS[random characters].exe"System Defender rogue security software - not recommended
XSystem Device Versionsystemdv.exe"Added by a variant of the RBOT WORM!"
XSystem Driverswingmt.exe"Added by the SDBOT-MG WORM!"
XSystem Driverscpsq32.exe"Added by the SDBOT.AXH WORM!"
XSystem Driverssysdrv32.exe"Added by the AGOBOT-ZX WORM!"
XSystem File Driversnvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
XSystem Security Updatersvsmons.exe"Added by the RBOT-OW WORM!"
XSystemBMessengerStopper.exe"MessStopper adware"
Xsyswin.txt[3 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
XTaesk managerstase.pif"Added by the RBOT-AYK TROJAN!"
Utgcmdprovidersbctgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
YTiny Personal Firewallpersfw.exe"Tiny Personal Firewall"
XTrojan Guarder Gold VersionTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
Xttool[random numbers].exe"Added by the BCKDR-QII BACKDOOR! The filename seen most often is ""9129837.exe"""
XUERScwUERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
XUniversal Plug & Play devicesWinUPPD.exeAdded by an unidentified WORM/TROJAN!
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
Xuserusers.exe"Added by the AUTORUN-AMK WORM!"
XUser Servicesusersvc.exe"Added by the REVCUSS.A TROJAN!"
XUserSystem[filename]"CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
Uversatoversato.exe"""Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards"
Xverseverse.exe"Added by the STAP-C WORM!"
XVersionVersion.exe"JRAUN adware variant"
XVersionmanage.exe"JRAUN adware variant"
Xversion[random].exe"DealHelper adware"
XVidiaDrivers[path to trojan]"Added by the RANKY.U TROJAN!"
XVIEW POINT DRIVERSphqghum.exe"Added by the RBOT.BRX WORM!"
XVIEW POINT DRIVERS FOR WIN32phqghu.exe"Added by a variant of the RBOT WORM!"
XVirus-Burstersvirus-bursters.exe"VirusBursters rogue security software - not recommended
XVirusBurstersvirusbursters.exe"VirusBursters rogue security software - not recommended
XVolcano Security SuiteVS[random characters].exe"Volcano Security Suite rogue security software - not recommended
UVPCUserServicesVMUSrvc.exe"Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC
NvTunerStartUpvTuner.exe"vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet""
UWallpaperSSWallpaperSS.exe"Wallpaper Slideshow LT from gPhotoShow.com - ""a great utility for displaying your favorite photos as your desktop wallpaper"""
NWeatherscopeWeatherscope.exe"WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XWeatherStudio DesktopWeatherStudio Desktop.exe"WeatherStudio adware"
XWEB DRIVERS FOR WIN32phqgh.exe"Added by a variant of the RBOT WORM!"
Xwersdsdoriot.exe"Added by the JECT.C TROJAN!"
Xwersds.exedoriot.exe"Added by the BAGLEDI-A TROJAN!"
NWhitephonePersonalWhitePhonePersonal.exe"WhitePhone Personal from Voice Commerce Group - ""provides free PC to PC calls globally and access to low cost calls to phones worldwide."" Free internet telephony utility using the VoIP (Voice over Internet Protocol). No longer appears to be available"
XWin Drivers SSLhpws.exe"Added by the IRCBOT.67098 WORM!"
XWin Drivers SSLTASKMAN4.exe"Added by a variant of the RBOT WORM!"
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 Firewall Driverswinfirewall.exe"Added by the WOOTBOT.GX WORM!"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Enterprise SuiteWE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows haz Layer[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows HP Drivershpdmws.exe"Added by the SDBOT.AQU WORM!"
XWindows IPv6 Driverswipv6.exe"Added by the SDBOT-VJ WORM!"
XWindows Memory Driversmemretain.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows messengermessengers.exe"Added by the MYTOB.EI WORM!"
XWindows Messenger Servicekaspersky.exe"Added by the MYTOB.HY WORM!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows ms Driversmsnup32.exe"Added by the SDBOT-AAL WORM!"
XWindows MSX driverswinmsx.exe"Added by the RBOT-AYG TROJAN!"
XWindows NTFS Volume Manage[6 random letters].exe"Added by the RBOT.EDL BACKDOOR!"
XWindows PC DefenderWP[random characters].exe"Windows PC Defender rogue security software - not recommended
XWindows Portable Device DriversMSKSVRVS.EXE"Added by a TROJAN - see here"
XWindows Protection SuiteWI[random characters].exe"Windows Protection Suite rogue security software - not recommended
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Managertasksmanagers.exe"Added by the MYTOB.ER WORM!"
XWindows Reverse Preperationwinrvp.exe"Added by the SLENFBOT.CB WORM!"
XWindows Reversed Virus Protectionwinrsvp.exe"Added by the SLENFBOT.HX WORM!"
XWindows Secure talal32[7 random letters].exe"Added by the RBOT.HTP TROJAN!"
XWindows Security SuiteWI[random characters].exe"Windows Security Suite rogue security software - not recommended
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWindows Server Driverssyssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Serviece Agents[8 random letters].exe"Added by the AGENT.BHR TROJAN!"
XWindows SP2 Version Loadwuauclt32.exe"Added by the GAOBOT.CX WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows sq Driverswinmsn32.exe"Added by the RBOT-ADI WORM!"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
XWindows Stand Sound DriversSounddrv.exe"Added by the SDBOT-XF WORM!"
XWindows Storm-Memory Driversmemorystorm.exe"Added by the SLENFBOT.CO WORM!"
XWindows System DefenderWS[random characters].exe"Windows System Defender rogue security software - not recommended
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindows System Security Monitor[4 random letters].exe"Added by the PINKTON.A WORM!"
XWindows System SuiteWS[random characters].exe"Windows System Suite rogue security software - not recommended
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
NWindows Version Checkver_chk.exe"Version checker for CyberAudioLibrary - ""a new way to exchange information through the Internet"""
XWindows Version Servicesysvers.exe"Added by the SLENFBOT.IF WORM!"
XWindows Version Servicesysvers32.exe"Added by the SLENFBOT.HZ WORM!"
XWindows Video Driversvideons32.exe"Added by the GAOBOT.AZT WORM!"
XWindows Video DriversVIDEONS3.EXE"Added by the AGOBOT-KZ BACKDOOR!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWinds Sers Agts[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWinds Sersc Agtsrzrzncrtz.exe"Added by the RBOT-GTV WORM!"
XWinNetDDE[random characters].exe"Added by the NETDEPIX.B TROJAN!"
XWinproxy PersonalWINPROXY.EXE"Added by the SDBOT.BMF WORM!"
XWinRunnersWinDrivers.exe"Added by the DULOAD.C WORM!"
Xwinversionwinversion.exe"Browser hijacker
UXemiComputers SchedulerScheduler.exe"Smooth Program Scheduler from XemiComputers ""will start any program you want at a scheduled time"""
Xxswdmse[8 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
XXTN Service Driverswinxtn.exe"Added by the SDBOT-YK WORM!"
XXupiter StartupXupiterStartup.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
Xxupiterstartup2003xupiterstartup2003.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D
XYahoo MessenggerIEXPLORERS.exe"Added by the AUTOIT.DH TROJAN!"
XZtgServerSwitchserver.vbsZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
X[12 random characters]avifile5.exe"IeDriver adware variant"
X[12 random characters]bootvid4.exe"IeDriver adware variant"
X[12 random characters]browser8.exe"IeDriver adware variant"
X[12 random characters]atitvo32.exe"IeDriver adware variant"
X[12 random characters]autodisc.exe"IeDriver adware variant"
X[12 random characters]cabview1.exe"IeDriver adware variant"
X[12 random characters]advpack1.exe"IeDriver adware variant"
X[12 random characters]batmeter.exe"IeDriver adware variant"
X[12 random characters]bidispl2.exe"IeDriver adware variant"
X[12 random characters]asferror.exe"IeDriver adware variant"
X[12 random characters]catsrvps.exe"IeDriver adware variant"
X[12 random characters]admparse.exe"IeDriver adware variant"
X[12 random characters]audiosrv.exe"IeDriver adware variant"
X[12 random characters]bootvid2.exe"IeDriver adware variant"
X[12 random characters]cmpbk321.exe"IeDriver adware variant"
X[12 random characters]ADPTIF67.exe"IeDriver adware variant"
X[12 random characters]asycfilt.exe"IeDriver adware variant"
X[12 random characters]ati2dvag.exe"IeDriver adware variant"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[12 random characters]blackbox.exe"IeDriver adware variant"
X[12 random characters]browser5.exe"IeDriver adware variant"
X[12 random characters]bthserv1.exe"IeDriver adware variant"
X[12 random characters]camocx28.exe"IeDriver adware variant"
X[12 random characters]CAMOCX74.exe"IeDriver adware variant"
X[12 random characters]capesnpn.exe"IeDriver adware variant"
X[14 random numbers]mradll.exe"Green AV rogue security software - not recommended
X[14 random numbers]rwg.exe"Green AV rogue security software - not recommended
X[3-4 random letters]nslookup.exe"PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder"
X[3-4 random letters]Srv32[path to file]"Added by the BANCSADE-A TROJAN!"
X[32 random hex numbers]tsc.exe"Total Security rogue security software - not recommended
X[32 random hex numbers]badware-protector.exe"Badware Protector rogue security software - not recommended
X[32 random numbers]av2009.exe"AntiVirus 2009 rogue security software - not recommended
X[32 random numbers]av360.exe"Antivirus 360 rogue security software - not recommended
X[32 random numbers]AVS.exe"Antivirus Sentry rogue security software - not recommended
X[32 random numbers]xpa.exe"XP Antivirus rogue security software - not recommended"
X[32 random numbers]total.exe"Total Antivirus rogue security software - not recommended
X[random characters]securewinload32x.exe"Added by the OPTIXP-N TROJAN!"
X[random characters]rsbmsc.exe"Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
X[random characters]_default[random].pif"Added by the BRONTOK-AI WORM and variants!"
X[random characters]j[random].exe"Added by the BRONTOK-AI WORM and variants!"
X[random characters]sv[random].exe"Added by the BRONTOK-AI WORM and variants!"
X[random characters]yesbron.com"Added by the BRONTOK-AI WORM and variants!"
X[random characters]systs.exe"Added by the AGENT-GDC TROJAN!"
X[random characters]xvassdf.exe"Added by the AUTORUN-BAD WORM!"
X[various names]UserSp1.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.