| X | cesmain.dll | "Rundll32.exe [path] cmail.dll | Rundll32" |
| X | Cmpnt | mainsv.exe | "Added by the TOMPAI-C TROJAN!"
|
| Y | cnfgCav | CMain.exe | "Part of Comodo Antivirus"
|
| X | CU2 | VCMain.exe | Associated with the Surf Sidekick adware and should be removed
|
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | explorer | main.vbe | "Added by the SHUSH-A WORM!"
|
| X | eZulaMain | eZulaMain.exe | "eZula TopText adware"
|
| X | eZuluMain | eZuluMain.exe | Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
|
| U | hpWirelessAssistant | HPWAMain.exe | Wireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
|
| U | iKeyWorks | IKEYMAIN.EXE | "A4Tech wireless keyboard driver and utility"
|
| U | KADxMain | KADxMain.exe | "System Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction |
| U | MAIN | main.exe | "SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
|
| ? | Main Executable (HP) | HP05T0R5.exe | "HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
|
| X | main16 | main16.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | main32 | main32.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | MainDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MainStart | svcmfte32.exe | "Added by the STINX-A TROJAN!"
|
| X | mainviewex | mainviewex.exe | "Added by the GEMA.D TROJAN!"
|
| X | main_module | drvmmx32.exe | "Added by the DILA TROJAN!"
|
| X | Microsoft Domain Controller | mstc.exe | "Added by the NUGACHE.A WORM!"
|
| X | MS Domain Name Server Deamon | MSDNSD32.exe | "Added by the RBOT-CMZ WORM!"
|
| X | MS Domain Name System | MSWDNS32.exe | "Added by the RBOT-GKY WORM!"
|
| X | mscheck | rundll32.exe wincheck071008.dll mymain | "Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
|
| X | MSNMESENGER | Main.exe | "Added by the PRORAT TROJAN!"
|
| X | PcRaiser | main.exe | "PcRaiser rogue optimization utility - not recommended"
|
| N | Performance Center | ApcMain.exe | "Ascentive Performance Center - not recommended |
| N | Picaboo | PicabooMain.exe | "Picaboo - ""Easily create stunning photo books and cards with your digital photos"""
|
| ? | PMCS | PMC.Service.Main.exe | "Related to MediaCenterService from Pinnacle Systems. What does it do and is it required?"
|
| X | PSC main | sttool32.exe | "Added by the OBFUSCATED.EV TROJAN!"
|
| X | PSCMain | pscmain2.exe | "Added by the OBFUSCATED.EV TROJAN!"
|
| X | Remote Access Domain | rswsvc.exe | "Added by the IRCBOT.BFA TROJAN!"
|
| Y | RfwMain | rfwmain.exe | "Rising antivirus"
|
| N | Scheduled Maintenance | Scheduled_Maintenance.exe | "Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs"
|
| U | SpyCop ScanCheck | MAIN.EXE | "SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
|
| Y | SpywareGuard | sgmain.exe | """SpywareGuard provides a real-time protection solution against spyware"""
|
| ? | stgclean | w32main2.exe | "Related to IBM Standard Software Installer. What does it do and is it required?"
|
| U | SuperCool Compress Backup | Main.exe | ""SuperCool Zip Backup software is a data backup |
| X | SysMain | buff.exe | "Added by the AGENT-ECW TROJAN!"
|
| X | SystemOptimizer2008 | main.exe | "SystemOptimizer2008 rogue optimization utility - not recommended |
| ? | TheMainStart | N/A | "??"
|
| U | TPSmain | TPSMain.exe | Toshiba Power Saver - associated with Toshiba laptops/desktops. Manages the power save function to make sure that the system goes to a power saver mode when not used
|
| Y | TPwrMain | TPwrMain.EXE | Power management software for Toshiba laptops
|
| U | TSkrMain | TSkrMain.exe | "TOSHIBA Accelerometer Utilities - hardware utilities that work with the motion sensors built into their Tablet PCs. Detect the way you are holding it at any given moment |
| X | Ultimate System Guard | MainFAVProj.exe | "Ultimate System Guard rogue security software - not recommended |
| X | VelocidadSimple | scrmain.exe | VelocidadSimple rogue optimization utility - not recommended
|
| U | WheelMouse | 4DMAIN.EXE | "Mouse software for ""Fellowes"" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide"
|
| U | WheelMouse | AMOUMAIN.EXE | "A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features"
|
| X | Windows Domain Name Drivers | windns.exe | "Added by the FORBOT-EP WORM!"
|
| X | Winmain | winmain.exe | "One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder |
| X | Winservice | winmain.exe | Adult content related malware
|
| X | Winsock Startup | Main2.exe | "Added by a variant of the SDBOT WORM!"
|
| X | wow64main.exe | wow64main.exe | "Added by the ALUREON.BT TROJAN!"
|
| X | YDTMain.exe | YDTMain.exe | "180solutions adware"
|
| X | zsmscc | rundll32.exe zsmscc071001.dll mymain | "Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
|
| X | zsmscc | rundll32.exe mycc071208.dll mymain | "Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
|
| X | _WinMain | winexec.exe | "Added by the DLOADER-XX TROJAN!"
|