Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XFat32 Microsoftfat32.exe"Added by the RBOT-EL WORM!"
Xhptoolsmicrosoft.exe"Added by a variant of the SDBOT WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
Xioroxxo microsoft suxsystem32.exe"Added by a variant of the RBOT WORM!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
Xmicrosoftmicrosoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftwuauclt.exe"Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoftguard.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftwcsntfy.exe"Added by the AGOBOT-AHT WORM!"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoftlsass.ppf"Added by the RBOT-GAA WORM!"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftmixers.exe"Added by the AGOBOT-AHU WORM!"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftradnom.exe"Added by the RBOT-GHO WORM!"
XMicrosoftrtvcscan.exe"Added by the RBOT-GGU WORM!"
XMicrosofttaskbar.exe"Added by a variant of the RBOT WORM!"
XMicrosoftupdater.exe"Added by the RBOT-GHP WORM!"
XMicrosoftwindl32.exe"Added by the SDBOT-DCZ WORM!"
XMicrosoftaim.exe"Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility"
XMicrosoftExplorerr.exe"Added by the IRCBOT-WG TROJAN!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoftmsngerf.exe"Added by the RBOT-GLW WORM!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoftrundll.exe"Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftwsim32.exe"Added by the RBOT-GTL WORM!"
XMicrosoftwplayer.exe"Added by the IRCBOT-ABP TROJAN!"
XMicrosoftmdms.exe"Added by the AGENT-GHY TROJAN!"
XMicrosoftExplorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoftinstall.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftinternetdat.exe"Added by the RBOT.ETY BACKDOOR!"
XMicrosoftntsvr.exe"Added by a variant of the RBOT WORM!"
XMicrosoftschost.exe"Added by the RBOT.FEH BACKDOOR!"
XMicrosoftsoundvol32.exe"Added by the RBOT.CIJ BACKDOOR!"
XMicrosoftsqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoftsystem32.exe"Added by the IRCBOT-ZZ WORM!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoftwinnn.exe"Added by the RANDEX.GGP WORM!"
XMicrosoftsymtea.exe"Added by the SPYBOT.AMTE WORM!"
XMicrosoftMicrosoftCorporation.exe"Added by the KILLFILES.AED TROJAN!"
XMicrosoftfirefox.exe"Added by the RBOT-GVJ TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft .NET Confinguratormsnconf.exe"Added by an unidentified VIRUS
XMicrosoft 16Bit Updatewuapdate16.exe"Added by the RBOT.CZ WORM!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
UMicrosoft ActiveSyncWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Admin ProtocalMSADNIN.exe"Added by a variant of the RBOT WORM!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Agentmdss32.exe"Added by the KEYLOG-AG TROJAN!"
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft ALG32 Protocolalg32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft ALGXP Protocolalg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft allmmall.exeWopla.ac malware variant
NMicrosoft Announcement ListenerAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft AntiSpywareBazzi.exe"Added by the AHKER.J WORM!"
XMicrosoft AntiSpywareKT06.pif"Added by the IRCBOT.GEN WORM!"
XMicrosoft AOL Instant MessengerMSAOL32.exe"Added by the RBOT-AAI WORM!"
XMicrosoft AOL32 Protocolaol32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Application Centermappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Application Managermsapl32.exe"Added by the BROPIA-AE TROJAN!"
XMicrosoft AUT UpdateMSlti32.exe"Added by the RBOT-X WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft auto updatewuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Bool ValueMV2.exe"Added by a variant of the RBOT WORM!"
XMicrosoft boot system cfg32actboost.exe"Added by the BROPIA.R WORM!"
UMicrosoft Broadband NetworkingMSBNTray.exeMicrosoft Broadband Networking Tray Application
XMicrosoft Browser ServicesBrwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Browser ServicesBrwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Buffer Appmsbuffer.exe"Added by the SLINBOT.NQ BACKDOOR!"
XMicrosoft Cab Managerexec.exe"Affilred adware"
XMicrosoft Cab Managercab.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Calculatorcalc.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft checkerMsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Clientmsclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Command Csshost.exe"Added by the RBOT-CMK WORM!"
XMicrosoft Command Cwinhost32.exe"Added by the SDBOT-BBA WORM!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Conf Ldrsysconf.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft ConfgKeyswurmgrd32.exe"Added by the RBOT-ARX WORM!"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configs 32msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Connection Manager Monitorcmmon.pif"Added by the RBOT-AKV WORM!"
XMicrosoft Control Centercrtl.exe"Added by the RBOT-VX WORM!"
XMicrosoft Core SupportMSxUP32.exe"Added by the RBOT-ANR WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp SQL Certificatessqlcer.exe"Added by the ZYBOT-C WORM!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMicrosoft Corp TLS Certificatesmsauth.exe"Added by the RBOT-GAC WORM!"
XMicrosoft Corp Updateswupdates.exe"Added by the RBOT-AUU WORM!"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporaticn SQL Handlersqlhandler.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Corporationjview.exe"Added by the RBOT-AOD WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Corporation SYM monitormssym.exe"Added by the RBOT-GDB WORM!"
XMicrosoft CP Web Managerwebcp.exe"Added by the IRCBOT.HP TROJAN!"
XMicrosoft CPU Over Heat ManagerCPU.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft CPXP Protocolcpxp.exe"Added by the RBOT.ATP WORM!"
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft CRT Monitor Managercrtmon.exe"Added by the ROBOTON.A WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft CSRSS32 Protocolcsrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft CSRSS386 Protocolcsrss386.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft CTF Loaderctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft Data Machinecsdata32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Database Handlermssql32.exe"Added by the RANDEX.AX WORM!"
XMicrosoft Datalog Applicationmsdata.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDE Controlwupades.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft Debug Servicedbgbgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
UMicrosoft Default ManagerDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
XMicrosoft Desktop Managermsdesk32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Development Debuggermsdev.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Device Managermsdevmgr32.exe"Added by the LATEDA.B TROJAN!"
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft Diagnosticmsdiag32.exe"Added by the RBOT-UC WORM!"
XMicrosoft Digital Clockmsclock.exe"Added by the NACKBOT-D WORM!"
XMicrosoft Digital Cryptorsmdigits.exe"Added by the SDBOT.LM WORM!"
XMicrosoft DirectXSpoolserv.exe"Added by the DINFOR WORM!"
XMicrosoft DirectXrasmngr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft DirectXPDSched.exe"Added by the SDBOT.CN WORM!"
XMicrosoft DirectXwuamgrd.exe"Added by the SDBOT.MY WORM!"
XMicrosoft DirectXtime123.exe"Added by the SDBOT.MD WORM!"
XMicrosoft Directxdirectxat.exe"Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft Directx clickdirectxclick.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directx clicksdirectxclickers.exe"Added by the RBOT-GHT WORM!"
XMicrosoft Directx pushdirectxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspdirectxbt.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspnewdirectxnew.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Disk Scannerscansdisk.exe"Added by the WOOTBOT.DT WORM!"
XMicrosoft DLLfumeta.exe"Added by the RBOT-AUG WORM!"
XMicrosoft Dllrunapidll.exe"Added by the RBOT-GRG WORM!"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL ExtensionsSystemDll.exe"Added by the RBOT-ADV WORM!"
XMicrosoft dll Host Servicewkssr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DLL Librarywinlib32.exe"Added by the ATNAS.A WORM!"
XMicrosoft Dll Managementwindll.exe"Added by the RBOT-MT WORM!"
XMicrosoft Dll Managermicrosoft32dll.exe"Added by the SHEUR.LH TROJAN!"
XMicrosoft DLL Managerdllmgr.exe"Added by the SDBOT-KJ WORM!"
XMicrosoft DLL Monitordllmon32.exe"Added by the AGENT.WP WORM!"
XMicrosoft DLL Monitordllmon64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Monitordllmonitor.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Dll Printer Managerdllpt.exe"Added by the SDBOT.BIH WORM!"
XMicrosoft DLL Serviceservicedll.exe"Added by the IRCBOT.OX BACKDOOR!"
XMicrosoft DLL Servicesvcdll.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft DLL Sourcedllsrc.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Verifierfile.exe"Added by the RBOT-AED WORM!"
XMicrosoft DLL Verifierchkfile.exe"Added by the RBOT-AOC WORM!"
XMicrosoft DLL Verifiercsrssv.exe"Added by the RBOT-ATK WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft DLL Verifierwns.exe"Added by the SPYBOT-LA WORM!"
XMicrosoft DLLSet32dllset32.exe"Added by the RBOT.OZ WORM!"
XMicrosoft DNS Host Resolutionhostres.exe"Added by the AGOBOT-MK BACKDOOR!"
XMicrosoft DNS Querymsdns.exe"Added by the AGENT-BS TROJAN!"
XMicrosoft DNSxmdnex.exe"Added by the DELBOT-AI WORM!"
XMicrosoft Documentkrisp.exe"Added by the SDBOT-RQ WORM!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMicrosoft Driverfaet.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft ErgoPackwserb32.exe"Added by the RBOT-RI WORM!"
XMicrosoft EV32 ServiceMSev32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Event EngineEvtEngn.exe"Added by the RBOT-XV WORM!"
XMicrosoft Excelmsexcel.exe"Added by the RBOT-TQ WORM!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Excellwuamngr32.exe"Added by the RBOT-QH WORM!"
XMicrosoft Executingmicrosoft.exe"Added by the AGOBOT.UV WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Explorerexplorer.pif"Added by the SDBOT-ACX WORM!"
XMicrosoft Explorerexplorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Explorer(64)explorer64.exe"Added by the SPYBOT-R WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Explorer2bitchbot.exe"Added by the SDBOT.EV WORM!"
XMicrosoft EXPLOREXP Protocolexplorexp.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Featuresms32cfg.exe"Added by the RBOT.HO WORM!"
XMicrosoft Featuresmsie.exe"Added by a variant of the RBOT WORM!"
XMicrosoft File Demand Managerwmgrdf.exe"Added by a variant of the RBOT WORM!"
NMicrosoft Find FastFindfast.exeFrom older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
XMicrosoft Firewallfirewallsp2.exe"Added by the RBOT-MC WORM!"
YMICROSOFT FIREWALL CLIENTISATRAY.EXE"MS Internet Security and Acceleration Server - see here"
XMicrosoft FixUppevblbvr.exe"Added by the RBOT.DWK WORM!"
XMicrosoft FixUpwnpzjpuw.exe"Added by a variant of the SDBOT WORM!"
Xmicrosoft frontpagetwain.exe"Added by the AGENT.AQO TROJAN!"
XMicrosoft Gamesgamemanager.exe"Added by the SPYBOT.AHQ WORM!"
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicroSoft Getway mqbol[12 random letters].exe"Added by the RBOT.GBA WORM!"
XMicrosoft Gina V EncryptionMSGINAV.EXE"Added by an unidentified VIRUS
NMicrosoft Greetings ReminderMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
NMicrosoft Greetings RemindersMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
NMicrosoft Greetings Workshop ReminderGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
XMicrosoft HDCP for NTmsdhcp.exe"Added by a variant of the RBOT WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help Supportmshelp32.exe"Addded by the KELVIR-BF WORM!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Helpdesk Sidemshelpdsk.exe"Added by the SPYBOT.ANJJ WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
Xmicrosoft hotmail monitormshotmon.exe"Added by the MYTOB-FL WORM!"
XMicrosoft hren1mmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft IE Execute shellIEExec.exe"Added by the ALADINZ.N TROJAN!"
XMicroSoft IE SasserISASS.EXE"Added by the SDBOT.MX WORM!"
XMicrosoft IISsyshost.exe"Added by the FRANCETTE WORM!"
XMicrosoft IIS[filename]"Added by the FRANCETTE-S WORM!"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft Inc.iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inc.iexplorer.exe..."Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Incroporatemfs.exe"Added by the RBOT-ANF WORM!"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
XMicrosoft Informationsecurenet.exe"Added by the SDBOT.AJM WORM!"
XMicrosoft Information Checkmicrosoft.exe"Added by the IRCBOT.AUH TROJAN!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Installshieldnundll32.exe"Added by the AGOBOT-AHZ WORM!"
XMicrosoft Instant Messengermsngmsngr32.exe"Added by the SPYBOTER.GEN TROJAN!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
UMicrosoft IntelliPointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft IntelliPointpoint32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft Intellitype Prospeedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
UMicrosoft IntelliType Proitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
UMicrosoft IntelliType Protype32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Internet Acceleration Utilityiau.exe"EasySearch adware"
XMicrosoft Internet Acceleration Utility[path to file]"Added by the AGENT-CX TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Internet Dumping Protocolinetdump.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Internet Firewallfirewall.exe"Added by the IRCBOT.MD BACKDOOR! Located in %System%"
XMicrosoft Internet Firewall ManagerGMT16.exe"Added by the RANDEX.AT WORM!"
XMicrosoft Internet Firewall Updateupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Internet Syncinginetsync.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft IPCsystem.exe"Added by the NULLBOT TROJAN!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft IT UpdateIEserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft IT UpdateRhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinemsjvm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual Machinejavavm.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft JavaVMmsjarun.exe"Added by the RBOT-JW WORM!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL BACKDOOR!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft LAN32 ProtocollanXp.exe"Added by the RBOT-SS WORM!"
XMicroSoft Legal ServiceSrb0ty.exe"Added by the SPYBOT.HW WORM!"
XMicroSoft Legal Syst3m32Syst3m32.exe"Added by the RBOT.UYL WORM!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft Locals466xagwxzy.exe"Added by the SPYBOT.EL WORM!"
UMicrosoft Location FinderLocationFinder.exe"Microsoft Location Finder ""is a client-side application that turns a regular WiFi enabled laptop
XMicrosoft Loginwinlogin.exe"Added by the RBOT-AJP WORM!"
XMicrosoft Loginswinlogins.exe"Added by the SPYBOT.BCZ WORM!"
XMicrosoft Logon User Interfacelogonnui.exe"Added by the RBOT-BCC WORM!"
XMicrosoft LSA layerMSLSA32.exe"Added by the RBOT-AKZ WORM!"
XMicrosoft Lsass CenterIsass.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Lsass Centertelecomes.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Lsass Managerlsass.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft LV[path to file]"Added by the BDOOR-BDL BACKDOOR!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft machineblah.exe"Added by a variant of the RBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Machineupdata.exe"Added by the RBOT-DJ WORM!"
XMicrosoft Machinetemp.exe"Added by the RBOT-FSQ WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft Managementlmas.exe"Added by the FORBOT-CZ WORM!"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Managermsmanager.exe"Added by the MYTOB.LF WORM!"
XMicrosoft Map PCmappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Mapped PCmappedpc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft Media Center Tray AppletehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
XMicrosoft Media Managermedman.exe"Added by the RBOT.EUZ WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft media servicesIassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Memory Dumping Protocolmemdump.exe"Added by the IRCBOT.BJK BACKDOOR!"
XMicrosoft Memory Flow Cycleflowcycle.exe"Added by the IRCBOT.WAD BACKDOOR!"
XMicrosoft Memory Flow Cycleflowcycles.exe"Added by the WAREZOV.AAK WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft messenger sdmsngersd.exeAdded by an unidentified TROJAN!
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft MicroP Protocolwdgmr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Ming Serviceming.exe"Added by the RBOT-AWS WORM!"
XMicrosoft Movie MakerMmaker.exe"Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program"
XMicrosoft MSGPLUS32 Protocolmsgplus32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Messengermsnmnsgr.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft MSNGR32 Protocolmsngr32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft msnserumsnseru.exe"Added by the RBOT-APB WORM!"
XMicrosoft MsnSTmsnst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Neser Experiencenese.exe"Added by the RBOT-YH WORM!"
XMicrosoft Netviewgesfm32.exe"Added by the RANDEX.C WORM!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Networkmsnet.exe"Added by the MOCKBOT.A WORM!"
XMicrosoft NetworkNetworksystem.exe"Added by the SDBOT-AAI WORM!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Network Neighbourhoodnetworknbh.exe"Added by the RBOT.DMN WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Networking Agent For SP2msnac32.exe"Added by the SPYBOT.PEN WORM!"
XMicrosoft Nod32 Servicenood32.exe"Added by the RBOT.EJP WORM!"
XMicrosoft Norotn Anti Virusmnhpot.exe"Added by the RBOT-GRO WORM!"
XMicrosoft Norton Antivirusnorton.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft NotePadnotepad.exe"Added by a variant of the RBOT WORM!"
XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Nvidia Videonvidia.exe"Added by a variant of the SDBOT WORM!"
NMicrosoft Officeosa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft OfficeMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
NMicrosoft OfficeOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Officelserv.exe"Added by the SDBOT.MH WORM!"
XMicrosoft OfficeMicrosoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Officemsoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
XMicrosoft OfficeNxcao.exe"Added by the RBOT-ZE WORM!"
XMicrosoft Officenxcxtpr.exe"Added by the RBOT-YG WORM!"
XMicrosoft Officesvxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoffice32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoff.exe"Added by the RAKER-C TROJAN!"
XMicrosoft Officemicrosoft.exe"Added by the BANKER-VF TROJAN!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemdm.exe"Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
UMicrosoft Office 2010BCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
NMicrosoft Office Fast CacheFastboot.exe"Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled"
UMicrosoft Office GrooveGROOVE.EXE"System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
XMicrosoft Office Monitoralg2k.exe"Added by the SDBOT-CZO WORM!"
XMicrosoft Office Monitoraql32.exe"Added by the RBOT-GCY TROJAN!"
NMicrosoft Office OneNoteONENOTEM.EXE"System Tray access to MS Office OneNote 2003 & 2007 - an electronic notebook that allows you to create free-form notes
NMicrosoft Office OneNote 2003 Quick LaunchONENOTEM.EXE"System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes
XMicrosoft Office quick launchOSA.exe"Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicrosoft Office Quick Launcheriau1.exe"Added by the DLOADR-AWD TROJAN!"
NMicrosoft Office Shortcut BarMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Office Studioscvhvst.exe"Added by the RANDEX.CST WORM!"
XMicrosoft OfficeXPofficeXP.exe"Added by the KILLAV.MA WORM!"
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicroSoft OneCareFreeS3x.exe"Added by the SDBOT-DJT WORM!"
XMicrosoft OpeionsIEXwe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Patch Updatebootini.exe"Added by the RBOT-FMN WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft PCHealth32[path to file]"Added by the NICE-A TROJAN!"
XMicrosoft PCHealth32NDDENB.exe"Added by the PWSYAHOO-A TROJAN!"
XMicrosoft PCI Managermspci.exe"Added by the RBOT.BBG WORM!"
NMicrosoft People Near Mep2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosoft Personal Firewallsbakw.exe"Added by the RBOT-KS WORM!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Procedure CallMSPCALL.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Process Managerprocess32.exe"Added by the CHECKOUT WORM!"
XMicrosoft Profile Managerprofile.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft PSTCP32 Datapstcp32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft QMGRmsnqmgr.exe"Added by the IRCBOT-S TROJAN!"
XMicrosoft quick launchOSA.exe"Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicrosoft RDLLsysconf32.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft Redirect[path to file]"Added by the BANKER-FW TROJAN!"
XMicrosoft Redirectsysten.exe"Added by the BANCOS-FO TROJAN!"
XMicrosoft Regestry Edit Managerregedit.exe"Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
XMicrosoft Regestry Managerregedit32.exe"Added by a variant of the IRCBOT.ARD WORM!"
XMicrosoft Regestry Managerregistry32.exe"Added by the IRCBOT.ARD WORM!"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicrosoft Registrycsrse.exe"Added by the RBOT-PC WORM!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Restorescrgrd.exe"Added by the SPYBOT.BR WORM!"
XMicrosoft Router Managerlinksys.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Router Managerrouter.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Rundllwindos.exe"Added by the SDBOT-WF WORM!"
XMicrosoft RuntimeCfgDll32.exe"Added by the RANDEX.BD WORM!"
XMicrosoft Safe Mode Managersafemode.exe"Added by the IRCBOT.HM BACKDOOR!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft sddcE Contoltaskmnegr.exe"Added by the RBOT-AUM WORM!"
XMicrosoft sddcE Contoltaskmn.exe"Added by the RBOT-BJZ WORM!"
XMicrosoft sdk tempsdktemp.exe"Added by the RBOT-ANP WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft security advisermssadv.exe"Microsoft Security Adviser rogue security software - not recommended"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Security Centerwcsntfy.exe"Added by the SDBOT.BYD WORM!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
YMicrosoft Security Essentialsmsseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Managementwinnt.exe"Added by the RBOT-MQ WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Managementwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XMicrosoft Security Managementwuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementbling.exe"Added by the RBOT.XL WORM!"
XMicrosoft Security Managementsp2fix.exe"Added by the RBOT.UB WORM!"
XMicrosoft Security Managerwinamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processlsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Monitor Processcom.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processexel.exe"Added by the SDBOT.AFX BACKDOOR!"
XMicrosoft Security Monitor Processfirewall.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
XMicrosoft Security Monitor Processflash.exe"Added by the EGGDROP.EE BACKDOOR!"
XMicrosoft Security Monitor Processhel.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosoft Security Monitor Processkar.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processlindicracker.exe"Added by the BIFROSE.GR BACKDOOR!"
XMicrosoft Security Monitor Processmail.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Security Monitor Processnitty.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processofice.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processpoint.exe"Added by the IRCBOT.AVP BACKDOOR!"
XMicrosoft Security Monitor Processprinc.exe"Added by the HUPIGON.WTL TROJAN!"
XMicrosoft Security Monitor Processweb.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processword.exe"Added by the EGGDROP.DC BACKDOOR!"
XMicrosoft Security Panager[filename]"Added by the RBOT-ANL WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft Security Panagerszzoboony.exe"Added by the RBOT-AOI WORM!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Security Systemmssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
XMicrosoft Security Updatesecurity32.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Serverrserv.exe"Added by the AGOBOT.AVS WORM!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Server Applacationscli.exe"Added by the RBOT-GAQ WORM!"
XMicrosoft Server ApplicationSound.exe"Added by the RBOT-NE WORM!"
Xmicrosoft server baselass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Processsvhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicerundll.exe"Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft Serviceservice.exe"Added by the IRCBOT-XX BACKDOOR!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft servicecssrs.exe"Added by the STARTP-DC TROJAN!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service 32sysddm32.exe"Added by the SDBOT.AKC WORM!"
XMicrosoft Service Access ManagerAccess.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Service Bootsboot.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Execution Managerexecute.exe"Added by a variant of the IRCBOT TROJAN! See here"
XMicrosoft Service firewall Managerfirewall.exe"Added by a variant of the SDBOT BACKDOOR! Located in %System%"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerservice32.exe"Added by the IRCBOT.WDW BACKDOOR!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicrosoft Serviceslsserv.exe"Added by an unidentified VIRUS
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Servicesservices.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicez Managerservicemgrz.exe"Added by the RBOT-ASN WORM!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Sinsupodjiwjf.exe"Added by the RBOT-DN WORM!"
XMicrosoft Softwaresysinfo33.exe"Added by the RBOT.LS WORM!"
Xmicrosoft software****.exe [* = random char]Added by an unidentified WORM or TROJAN!
XMicrosoft softwarecdaccess.exe"Added by the RBOT.ABK WORM!"
XMicrosoft Software Updatenmon.exe"Added by the RBOT.HZ WORM!"
XMicrosoft Sound Driversound32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Sound Technologywinsound.exe"Added by the RBOT-AGG WORM!"
NMicrosoft Sound Volume Toolmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
XMicrosoft Soundssoundman.exe"Added by the RBOT-GCI WORM!"
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Special offerinfoebay.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicroSoft ssadsadas3s1eXtream.exe"Added by the SPYBOT.ZK TROJAN!"
XMicroSoft ssadssjdhasjadas3s1kdjfsdklfjsl.exe"Added by the SDBOT.AEX WORM!"
XMicroSoft ssas3s1SADASDA.exe"Added by the RBOT.URF WORM!"
XMicrosoft SSISVRI32 Protocolssisvri.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft standard protector[path to trojan]"Added by the STOX-C TROJAN!"
XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
NMicrosoft Sticky Notesstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
XMicrosoft Stuff you knowwinslogin.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Sum32sum32.exe"Added by the RBOT-YW WORM!"
XMicrosoft Supportsys32ms.exe"Added by the RBOT-AHI WORM!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft SVCmssvc.exe"Added by the BIFROSE-UQ TROJAN!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft Syn ManagerManager.exe"Added by the SDBOT.BEF WORM!"
XMicrosoft Synchronization Managerasgard.exe"Added by the SDBOT-AEA WORM!"
XMicrosoft Synchronization Managerbot.exe"Added by the SDBOT.IH WORM!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managerslhost.exe"Added by the SDBOT.YH WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization ManagerWinLoginnn.exe"Added by the SPYBOT.FO WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization ManagerxXx.exe"Added by the SDBOT-KZ WORM!"
XMicrosoft Synchronization Manager___synmgr.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Synchronization Manageral.exe"Added by the OPTXPRO.132 TROJAN!"
XMicrosoft Synchronization Managerwin.exe"Added by the SDBOT.AK WORM!"
XMicrosoft Synchronization Managerjava.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft Synchronization Managerwinlogon32.exe"Added by the SDBOT.AEU WORM!"
XMicrosoft Synchronization Managersvxhost.exe"Added by the SDBOT-ZU WORM!"
XMicrosoft Synchronization Managerwincfg32.exe"Added by the SDBOT.DO WORM!"
XMicrosoft Synchronization Managerscreen.exe"Added by the SDBOT-ACO WORM!"
XMicrosoft Synchronization Managerdevldr32.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
XMicrosoft Synchronization Managerexplorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Synchronization Managerfirewire.exe"Added by the SDBOT-AFC WORM!"
XMicrosoft Synchronization Managerwmedia.exe"Added by the SDBOT.BFC WORM!"
XMicrosoft Synchronization Managerwin932.exe"Added by the SDBOT.AH WORM!"
XMicrosoft Synchronization Managermircup.exe"Added by the SDBOT.BQD WORM!"
UMicrosoft Synchronization Managermobsync.exe"Microsoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline
XMicrosoft Synchronization Manageralien.exe"Added by the SDBOT-MV BACKDOOR!"
XMicrosoft Synchronization Managermicrosoft.exe"Added by the SDBOT-OM WORM!"
XMicrosoft Synchronization Manager 2svhostc.exe"Added by the SLINBOT.ST WORM!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicroSoft sys3s1h4ckn3t.exe"Added by the RBOT.QTY WORM!"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
XMicrosoft Systemsys.exe"Added by the RBOT.AKI WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Administrationsystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System CheckupCool.exe"Added by the DONK.B WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System CheckupKeymgr.exe"Added by the DONK.M WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft System Monitorsystem.exe"Added by the IRCBOT.AUT BACKDOOR!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft system Valuesys57.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft Task Messenger Configtaskmgsr.exe"Added by the SDBOT-JK WORM!"
XMicrosoft task tray monitorctray.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Task32 Protocoltaskmgr32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Taskmanager Updaterkeyboard.exe"Added by the RBOT-ALU WORM!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecom Centertellecom.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Telecoma Centertellcoma.exe"Added by the RBOT-AWX WORM!"
XMicrosoft Telecoms Centertelcoms.exe"Added by the IRCBOT.GEN WORM!"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Time Managerdveldr.exe"Added by the RBOT-HQ WORM!"
XMicroSoft Toolbarkey.exe"Added by the RBOT-AEW WORM!"
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft TTL Verifiermsttl.exe"Added by the RBOT-GAP WORM!"
XMicrosoft Uwuamkopxp.exe"Added by the RBOT-AHC WORM!"
XMicrosoft UMA UpdateMSuma32.exe"Added by the RBOT.FS WORM!"
XMICROSOFT UNPACCKER SYSTEMunpak32.exe"Added by a variant of the RBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updat3mswkst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoft.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updateascdl.exe"Added by the GAOBOT.SY WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updateautomgr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemediap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoftx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft UpdateMslti32.exe"Added by the RBOT-LX WORM!"
XMicrosoft Updatemuamgrd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatenavmgrd.exe"Added by the SDBOT.DP TROJAN!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft UpdateVPC32.EXE"Added by the AGOBOT.XM WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewuamgrd.exe"Added by the RBOT-LK WORM!"
XMicrosoft Updatewuammgr32.exe"Added by the RBOT-AW WORM!"
XMicrosoft Updatewudmate.exe"Added by the RBOT.AP WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatewuamgrd32.exe"Added by the RBOT.ZB WORM!"
XMicrosoft UpdateNAV.exe"Added by the RBOT-IV WORM!"
XMicrosoft Updatesystemi32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft Updatewebm.exe"Added by the SDBOT.WK WORM!"
XMicrosoft Updatewuagrd.exe"Added by the RBOT-FK WORM!"
XMicrosoft Updateaaupdt.exe"Added by the RBOT-RQ WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatewauguard.exe"Added by the RBOT.AEE WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewserv32.exe"Added by the RBOT.AF WORM!"
XMicrosoft Updatewtm32.exe"Added by the RBOT-AQ WORM!"
XMicrosoft Updatewumgrd.exe"Added by the SDBOT-KY WORM!"
XMicrosoft Updatewuampd.exe"Added by the RBOT-UT WORM!"
XMicrosoft Updatemsupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft UpdateBotnet.exe"Added by the RBOT.AFL WORM!"
XMicrosoft Updatesghost.exe"Added by the SDBOT.AKV WORM!"
XMicrosoft Updateupdate_w.exe"Added by the RBOT-EW WORM!"
XMicrosoft Updatewindows24.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewingrd32.exe"Added by the RBOT-DW WORM!"
XMicrosoft Updatewssvr.exe"Added by the RBOT-OD WORM!"
XMicrosoft Updatewuamagr32.exe"Added by the SPYBOT.CG WORM!"
XMicrosoft UpdateWinUpdate32.exe"Added by the RBOT-TI WORM!"
XMicrosoft Updatewkfix.exe"Added by the RBOT-ABZ WORM!"
XMicrosoft UpdateKkk.exe"Added by the RBOT-AHL WORM!"
XMicrosoft Updatemcupdate.exe"Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
XMicrosoft UpdateMicr0s0ft.exe"Added by the AGOBOT.AAR WORM!"
XMicrosoft UpdateMsnmsngr.exe"Added by the RBOT.BQS WORM!"
XMicrosoft Updatemsupdate32.exe"Added by the SPYBOT.LZ WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesys.exe"Added by the RBOT-AJ WORM!"
XMicrosoft Updateup2dat5.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatewinupdater.exe"Added by the RBOT.BIN WORM!"
XMicrosoft Updatewuamk0032.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamk032.exe"Added by the RBOT-AHD WORM!"
XMicrosoft Updatewuamk0p32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamkop.exe"Added by the RBOT-AFI WORM!"
XMicrosoft Updatewuamkop32.exe"Added by the RBOT.BGU WORM!"
XMicrosoft Updatewuampkd.exe"Added by the SDBOT.BBX WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft Updatewuamgrd3.exe"Added by the RBOT-AMC WORM!"
XMicrosoft UpdateWudates.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatems.exe"Added by the SDBOT.CC WORM!"
XMicrosoft Updatewuagmsd.exe"Added by the RBOT-AX WORM!"
XMicrosoft Updatecmss.exe"Added by the RBOT-ATQ WORM!"
XMicrosoft Updatewuamgrb.exe"Added by the RBOT-AZE WORM!"
XMicrosoft UpdateWINDOC.EXE"Added by the SDBOT.PF WORM!"
XMicrosoft Updatephqghumea.exe"Added by the SDBOT.AFO WORM!"
XMicrosoft Updatesystem32.exe"Added by the RBOT.IS WORM!"
XMicrosoft Updatebling.exe"Added by the RBOT-AVK WORM!"
XMicrosoft UpdateSygate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updateupdate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft Updatedevmks32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updatemixer.exe"Added by the RBOT-AIR WORM!"
XMicrosoft Updatetaskmgr32.exe"Added by the RBOT-CV WORM!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updatewangard.exe"Added by the RBOT-LH WORM!"
XMICROSOFT UPDATEWUAGTRD.EXE"Added by the RBOT-CJ WORM!"
XMicrosoft Updatespool.exe"Added by the AGENT-GJC TROJAN!"
XMicrosoft Updatebnmveqfts.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatedqbxhupdt"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Updateenule.exe"Added by the IRCBOT.DU BACKDOOR!"
XMicrosoft Updateexplorer.exe"Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Updateimchemaoa.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatelivemessenger.com"Added by the ADLOAD-LN TROJAN!"
XMicrosoft Updatemsnmsgl.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatennwyaupdt"Added by the RBOT.RHK BACKDOOR!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updaterundll32.dll"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Updatewuamgrdx.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatewutr.exe"Added by the SPYBOT.AAR WORM!"
XMicrosoft UpdateSetPoints.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Updatesystem.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updatemsgn.exe"Added by the RBOT.RQ BACKDOOR!"
XMicrosoft Updatewuamgrd16.exe"Added by the RBOT-BQ WORM!"
XMicrosoft Updatewindows32.exe"Added by the RBOT-BHQ WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 23spoolvs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32explore32.exe"Added by the SPYBOT.CYM WORM!"
XMicrosoft Update 32MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32[path to file]"Added by the RBOT-AJJ WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update 32servic.exe"Added by the RBOT-AXN WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32mssetup32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32wiit.exe"Added by the RBOT-AMS WORM!"
XMicrosoft Update 32explorer.exe"Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update 32network.exe"Added by the RBOT-ARZ WORM!"
XMicrosoft Update 32om4r.exe"Added by the RBOT-AQP WORM!"
XMicrosoft Update 32winin.exe"Added by the RBOT-ARR WORM!"
XMicrosoft Update 32wuinit.exe"Added by the AGOBOT-UE WORM!"
XMicrosoft Update 32neta.exe"Added by the RBOT-AMI WORM!"
XMicrosoft Update 32spoolvs.exe"Added by the RBOT-BBQ WORM!"
XMicrosoft Update 32rundll32.exe"Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe
XMicrosoft Update 32taskMangr.exe"Added by the RBOT.AIE BACKDOOR!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update 33init.exe"Added by the RBOT-ATT WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Update 64 BITwinman32.exe"Added by the RBOT-AKI WORM!"
XMicrosoft Update 64 BITschvost.exe"Added by the RBOT.CAU WORM!"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Update Deviceflolo.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update DLLrxxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Emulatorkern-mxe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Emulatorwuaddsff.exe"Added by the RBOT-GX WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machineservicz.exe"Added by the RBOT-HU WORM!"
XMicrosoft Update MachineSP2.exe"Added by the SPYBOT.FP WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinememstat.exe"Added by the RBOT-OM WORM!"
XMicrosoft Update Machinentce.exe"Added by the RBOT-FA WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Update Machinewuawx.exe"Added by the RBOT-CE WORM!"
XMicrosoft Update Machinezonealarm.exe"Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
XMicrosoft Update Machinesystemll.exe"Added by the RBOT-JT WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinewuamgd.exe"Added by the SDBOT.HQ WORM!"
XMicrosoft Update Machinewupdt32x.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelinux.exe"Added by the RBOT-IM WORM!"
XMicrosoft Update Machinelmrss.exe"Added by the RBOT-DY WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewuamgrd.exe"Added by the RBOT-HE WORM!"
XMicrosoft Update Machinewuagrd.exe"Added by the RBOT-GF WORM!"
XMicrosoft Update MachineLANWAKE.EXE"Added by the RBOT-QZ WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update MachineWUAMGRDXS.EXE"Added by the RBOT-GL WORM!"
XMicrosoft Update Machinecrss32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft Update Machineqwerty.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineSystemnt.exe"Added by the RBOT.DA WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinetaskmngrs.exe"Added by the RBOT-CR WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewuamgard.exe"Added by the SPYBOT.CS WORM!"
XMicrosoft Update Machinewupdate32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTMEMSER.EXE"Added by the RBOT-NQ WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update Machineserviz.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTASKMAN4.EXE"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewftestb.exe"Added by the RBOT-AFZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinejkfrnz.exe"Added by the RBOT-GOZ WORM!"
XMicrosoft Update Machinewlimyc.exe"Added by the RBOT-GQN WORM!"
XMicrosoft Update Machinexagwxzy.exe"Added by the RBOT.S WORM!"
XMicrosoft Update Machinejkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Machinepaxrxo.exe"Added by the PUSHBOT.A WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Update Machinesyadpo.exe"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Update Machinesystemi.exe"Added by the BUZUS.JKU TROJAN!"
XMicrosoft Update Machinethvfyq.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machineubthec.exe"Added by the AGENT.AWZ TROJAN!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update Machinegbhglj.exe"Added by the IRCBOT-ZJ TROJAN!"
XMicrosoft Update Machinewuamgdr.exe"Added by the RBOT-IO BACKDOOR!"
XMicrosoft Update ManagerWINRLS.EXE"Added by the RBOT-AF WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Update Managerscvideo.exe"Added by the SDBOT-CVP TROJAN!"
XMicrosoft Update MecheneUpdatez.exe"Added by the RBOT-GI WORM!"
XMicrosoft Update Modulerundll24.exe"Added by the RBOT-PS WORM!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Security Patchmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Update Timewuam.exe"Added by the RBOT-M WORM!"
XMicrosoft Update USB2wuammgrd32.exe"Added by the RBOT-ADT WORM!"
XMicrosoft Update v2.6lxxex.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft Update32wuamgrd32.exe"Added by the RBOT-PU WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatervbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updaterwuamgrds.exe"Added by the RBOT.A WORM!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updater v2[path to worm]"Added by the AUTORUN-BCI WORM!"
XMicrosoft UPDATER32lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
XMicrosoft UPDATER32LSASS32.EXE"Added by the RANDEX.AR WORM!"
XMicrosoft Updaterstskmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Updatessystemc32.exe"Added by the RBOT-GR WORM!"
XMicrosoft Updateswkssvr.exe"Added by the RBOT.R WORM!"
XMicrosoft Updateswkssvrs.exe"Added by the RBOT-EB WORM!"
XMicrosoft Updateswuamgrd.exe"Added by the RBOT-CO WORM!"
XMicrosoft Updateswtemp32.exe"Added by the RBOT-AHQ WORM!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updateswgcptsud.exe"Added by the RBOT-GTF WORM!"
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates 2 USBwgafixer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updates 5 USBsp3fixer.exe"Added by the RBOT-ADS WORM!"
XMicrosoft UpdateS Machinewgrd.exe"Added by the RBOT-FI WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatingnavguard.exe"Added by the RBOT.HW WORM!"
XMicrosoft Updatingsyswr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatingwuamguards.exe"Added by the RBOT-BY WORM!"
XMicrosoft Updating Clientwebsvc.exe"Added by the RBOT.AQ WORM!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicrosoft Updattingmiroupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpMachinedoezs.exe"Added by the RBOT.BCT WORM!"
XMicrosoft upnp Updatemsie.exe"Added by the RBOT-LQ WORM!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Urlmonurlmon.exe"Added by the AGENT-GOO TROJAN!"
XMicrosoft USA Plugusaplug.exe"Added by the RBOT-DVC WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
NMicrosoft Utility StartupOSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Valuesigfkishc.exe"Added by the RBOT-GLO WORM!"
XMicrosoft VertupdateMSvert32.exe"Added by the MYTOB-CY WORM!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Video Drivervideodrv.exe"Added by the SDBOT-AGP WORM!"
XMicrosoft Viewer Monitor Managerviewmon.exe"Added by the XPAK.A TROJAN!"
XMicrosoft Virtual Service Managervservice32.exe"Added by the MSNWORM.T WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Vista Upgrade Validation Servicecfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Visual Applicationvpcrtf.exe"Added by the IRCBOT-XJ TROJAN!"
XMicrosoft Visual Debugermdm.exe"Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicroSoft Visual SPigxdfdfds.com"Added by the SDBOT.GAV WORM!"
XMicroSoft Visual SP2igfxsrvc32.exe"Added by the SDBOT.GAV WORM!"
XMicrosoft Visual Studioplscdksxg.exe"Added by the RBOT-AWV WORM!"
XMicrosoft Visual Studio VSAvarpc32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Web CP Managerwebcp32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Web Devicewdevice.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft web updatewebmsn.exe"Added by the RBOT-EMQ WORM!"
UMicrosoft Webserversvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft Win UpdateWinUP.exe"Added by the RBOT-BPR WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windowsatup"Added by a variant of the RBOT WORM!"
XMicrosoft WindowsMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Windowsexplorar.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows[path to file]"Added by the BDOOR-LI BACKDOOR!"
XMicrosoft Windowsbootini.exe"Added by the VANEBOT-K WORM!"
XMicrosoft WindowsKernel.exe"Added by the EDIBARA-A VIRUS!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windowspwjbvphi.exe"Added by the RBOT-GQK WORM!"
XMicrosoft Windowswindets.com"Added by the FLOOD-EQ TROJAN!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Autowxcknautowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUIWindowz.exe"Added by the RANDEX.AEV WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playerwimp.exe"Added by the RBOT-FN WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UMicrosoft Windows SidebarSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatawindows.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WINGS32 ProtocolWinSGR32.exe"Added by the RBOT-APU WORM!"
XMicrosoft WinRaRwinrar.exe"Added by the RBOT-AEC WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft WinUpdatesyslx32.exe"Added by an unidentified VIRUS
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinupd32.exe"Added by the RBOT.MQ WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
XMicrosoft WMmswm32.exe"Added by the BCKDR-AM BACKDOOR!"
XMicrosoft WordBootSector.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
XMicrosoft Word ProfissionalJava Plug In close.exe"Added by the BANKER-EL TROJAN!"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
NMicrosoft Works Calendar Reminderswkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
NMicrosoft Works PortfolioWksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file. Can be prevented from starting from a setting within Portfolio
NMicrosoft Works Update Detectionwkdetect.exeChecks for updates to MS Works
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft WPCEmail[path to trojan]"Added by the SNIFFER-N TROJAN!"
XMicrosoft WWW[path to trojan]"Added by the AGENT-DRI TROJAN!"
XMicrosoft WxdateSyswu32.exe"Added by the SPYBOT.HZ WORM!"
XMicrosoft X Updatewuamkoppnp.exe"Added by the RBOT-ANI WORM!"
Xmicrosoft xdaemon 2.0xdaemon.exe"Added by the DELF.D TROJAN!"
XMicrosoft XML Servicemsxmlx.exe"Added by the RBOT.KS WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft XPSP Protocolxp386.exe"Added by a variant of the RBOT WORM!"
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft xpsp2xpsp2.exe"Added by the SDBOT-YQ WORM!"
XMicrosoft's System ModuleSysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
XMicrosoft(R) System Managersysmgr.exe"Added by the AGENT.QTR TROJAN!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-software****.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft-Updatewngard.exe"Added by the RBOT-JV WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
XMicrosoft.exe[random].exe"Added by a variant of the IRCBOT TROJAN!"
Xmicrosoft.exemicrosoft.exe"Added by the GOLDUN-GB TROJAN!"
XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
Xmicrosoft420microsoft420.exe"Added by the MENACE.B WORM!"
XMicrosoft64antiv.exe"Added by the SOBER WORM!"
YMicrosoftAntiSpywareCleanergcASCleaner.exe"Microsoft Antipsyware - now superseded by Microsoft's Windows Defender"
XMicrosoftCorpflashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftCorpjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftCorpmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftCorpregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrosoftCorpsecurebind.exe"Added by the INJECT TROJAN!"
XMicrosoftCorpsysdiag64.exe"Added by a the AUTOINF-AB WORM!"
XMicrosoftCorptraymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftCorpupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftCorpwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftf DDEs ContDLLrune.pif"Added by the RBOT-AGF WORM!"
XMicrosoftf DDEs ContrDLrunm.pif"Added by the RBOT-AFQ WORM!"
XMicrosoftf DDEs Controllxes.exe"Added by the RBOT.BOF WORM!"
XMicrosoftf DDEs Controlwees.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlsoff.pif"Added by the RBOT-AKH WORM!"
XMicrosoftf DDEs Controlwhy-.exe"Added by the RBOT-AMV WORM!"
XMicrosoftf DDEs Controlmsnn.exe"Added by the RBOT-AXT WORM!"
XMicrosoftf DDEs ControlFEnR.exe"Added by the RBOT-AIM WORM!"
XMicrosoftf DDEs Controlw33s.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlwaes.exe"Added by a variant of the RBOT WORM!"
XMicrosoftkeysdsystemproc.exe"Added by the FORBOT-BI WORM!"
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoftkeysdslass32.exe"Added by a variant of the RBOT WORM!"
XMicrosoftKsDrivers.bat"Added by the SHUTDOWN-F TROJAN!"
Xmicrosoftm eegs cuntrolloor.pif"Added by a variant of the RBOT WORM!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
XMicrosoftmsn32.exemicrosoftmsn32.exe"Added by the CERTIF-C TROJAN!"
XMicrosoftMultimediaTaskMmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
XMicrosoftNAPCflashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftNAPCjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftNAPCmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftNAPCregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrosoftNAPCsecurebind.exe"Added by the INJECT TROJAN!"
XMicrosoftNAPCsysdiag64.exe"Added by a the AUTOINF-AB WORM!"
XMicrosoftNAPCtraymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftNAPCupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftNAPCwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMicrosoftOEMsmvss.exe"Added by the DEDLER-G TROJAN!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
XMicrosofts mediawingtp.exe"Added by the RBOT-VO WORM!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Security Manager****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosofts Updatezcmsssr.exe"Added by an unidentified VIRUS
XMicrosofts Updatezexploirez.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrosoftShellShellcomm.exe"Added by the BANCBAN-QG TROJAN!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSourceSafelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSysSPOOLSYS.exe"Added by the TARNO.N TROJAN!"
XMicrosoftUpdatesyshelper.exe"Added by the WOOTBOT.AC WORM!"
XMicrosoftUpdateWinUp32.exe"Added by an unidentified VIRUS
XMicrosoftUpdateMicrosoftUpdate.exe"Added by the BANKER-EHC TROJAN!"
XMicrosoftUpdatewindll.exe"Added by the RBOT-IH WORM!"
XMicrosoftUpdateRBuilder.exe"Added by the DLOADR-BMV TROJAN!"
XMicrosoftUpdatesvhest.exe"Added by the RBOT-ES WORM!"
XMicrosoftUpdatedownnew.exe"Added by the TANTO-D TROJAN!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
XMicrosoftUpdatessyshelped.exe"Added by the FORBOT-AZ WORM!"
XMicrosoftValuesyscnfg.exe"Added by an unidentified VIRUS
XMicrosoftvirussysoverload.exe"Added by the FORBOT-AL WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosoftWindowsa@26m.exe"Added by the KILLPAR-B TROJAN!"
XMicrosoftXP Service Pack 2servicepack2.exe"Added by the RBOT.EMC WORM!"
XMicrosoftz turn Controlaexl.exe"Added by the SDBOT.BCO WORM!"
XMicrosoftz turn Controlread.pif"Added by the RBOT-AFS WORM!"
XMicrosoft©iexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrosoft© PID LexPIDLex.exe"Added by the NIOVADOOR TROJAN!"
XMicrosoft© System MapperSysMap.exe"Added by the MAPSY TROJAN!"
XMicrosoft« ActiveX Debugger NTsetdebugnt.exe"Added by the BANCOS-CZ TROJAN!"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UMicrosoft® Windows® Operating SystemSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
NMicrosoft® Windows® Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
UMicrosoft® Windows® Operating SystemehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
NMicrosoft® Windows® Operating Systemstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
NMicrosoft® Works 7.0wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
NMicrosoft® Works 8wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
XMMicrosoft Security Managementinetforn.exe"Added by the RBOT.AFZ WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Microsoft Socket DeamonMSSCKD32.exe"Added by a variant of the RBOT WORM!"
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMSLogMicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
XNT MICROSOFT SVCDntvsvcd.exe"Added by a variant of the RBOT WORM!"
XNTFSS Microsoft Systemfilees.exe"Added by the RBOT.GAB WORM!"
XNTFSS MICROSOFT SYSTEMfiless.exe"Added by the RBOT.AXZ WORM!"
XNTSF Microsoft Systemfylez.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwntsf.exe"Added by the RBOT.ATC WORM!"
XNTSF MICROSOFT SYSTEMfufffy.exe"Added by the RBOT-AEL WORM!"
XNTSF MICROSOFT SYSTEMntssf.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"
XPublic Microsoft ODBCODBC32*.exe [* = random char]"Added by the MASLAN.D WORM!"
XSOUNDMAN Microsoft Helpsoun.pif"Added by the RBOT-AIU WORM!"
XSymantec Security Routine Addon for Microsoft Windowsnavpxaw32.exe"Added by the AGOBOT-GJ TROJAN!"
XsystemMicrosoft Office.exe"Added by the BANCBAN-LH TROJAN!"
XSystem Microsoft Coresmc.exe"Added by the RIZO.A TROJAN!"
XWin Microsoft 98win14.exe"Added by the RBOT-AKX WORM!"
XWin32 Debug Managermicrosoftupd.exe"Added by the RBOT-GRJ WORM!"
XWin32KernelStartmicrosoft.exe"Added by the DELF-EWZ TROJAN!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows Microsoft Verifierwinauth23.exe"Added by a variant of the RBOT WORM!"
Xwindows updateMicrosoft.exe"Added by the LMIR.A TROJAN!"
Xwindows update microsoftupdatem.exe"Added by the RBOT-CHE WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.