Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
Xne.exe"Added by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Inc.""Machine WorksXaecces.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
Y#NAME?ZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
U$EnterNetEnternet.exe"Connection manager for the EnterNet ISP. You can also use RASPPOE"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X%Windir%winnl.exewinnl.exe"Added by the KIDKITI TROJAN!"
X%Windir%winnm.exewinnm.exe"Added by the KIDKITI TROJAN!"
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)NOTEPAD.exe"Added by the RUSTY WORM! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)twunk_32.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Bandookmsdll.exe"Added by an unidentified TROJAN - see here"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*MS Setup[random filename]"Virtumondo adware
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X*Security Centersecctr.exe"Added by the SDBOT.BRO WORM!"
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
?.NET configsysmon32.exe"??"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X.protectedN/A"Smitfraud variant"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
N/l:engN/A"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
N/sN/A"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
?00notify33NetBrowser.exe"Part of Best Network Security
?00saskdanewlock.exe saskda"Part of Access Manager
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
N1&1 EasyLoginEasyLogin.exe"1&1 EasyLogin - quick access to webhost 1&1's Control Panel
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"180solutions adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X196_150_ni196_150_ni.exe"WinFixer web installer - ""foistware""
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer - ""foistware""
X197_150_ni_7197_150_ni_7.exe"WinFixer web installer - ""foistware""
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
?1CmailSNETMAIL.EXE"??"
X1on11on1.exeAdult content dialler
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2020Downloadermssvr.exe"2020Search Toolbar"
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X2Searchmain.exe"2Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
Y3capplnk3capplnk.exeUS Robotics Modem driver
N3cdminic3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3CM Link3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it
Y3Cmlink3CmlinkW.exe"For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information"
?3Com LauncherLauncher.exe"Related to networking products from 3Com Corporation. What does it do and is it required?"
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
X3d_sound3d_sound.exe"Added by the RIADOS-A TROJAN!"
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
X4.68474E+12netdll32.exe"Added by the SDBOT-DEV WORM!"
X49U5T1N449U5T1N4.exe"Added by the KORRON.B WORM!"
X4wd!!!Natal!.pif"Added by the OPASERV.AI WORM!"
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
X6.54388E+16rkgnd.exe"ANG AntiVirus 09 rogue security software - not recommended
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X7.61125E+16angpd.exe"ANG AntiVirus 09 rogue security software - not recommended
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@RUNDLL.EXE"Added by the SPYBOT-DN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@wincms.exe"Added by the RBOT.CBR WORM!"
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
N@lohareminder.exe"Registration reminder for
Y@OnlineArmor GUIoaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
NA NoteA Note.exe"""A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"""
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-squared Anti-Dialera2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
?AAACLEANAAACLEAN.INF"??"
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
YABRegmonABregmon.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
UAcBtnMgr_X63AcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X73AcBtnMgr_X73.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X83AcBtnMgr_X83.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
NACDaemonACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
UAcer Assist Launcherlauncher.exe"Acer Assist - program that provides information about new updates or notices from Acer"
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UAcer ePower ManagementePowerTray.exe"Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks. Also appears as the Packard Bell PowerSave power management utility included on some of their notebook models - as Packard Bell is now owned by Acer"
UAcer ePower ManagementePowerTrayLauncher.exeLauncher for the Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
YAcer Launch ToolAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
XAceu[random filename]"PurityScan adware"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
YACMONACMON.exe"ASUS Splendid ""is a breathtaking innovation that brings the video viewing experience on PC to the next level. Built into the driver of ASUS graphics cards
UACMonitor_X63ACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X63.exeACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X73ACMonitor_X73.exe"Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
UACMonitor_X83ACMonitor_X83.exe"Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
UACMonitor_X84-X85ACMonitor_X84-X85.exe"Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
XAcontiaconti.exeAdult content dialler
XAcrobatacrmon32.exe"Added by the SMALL-ECT TROJAN!"
UAcrobat AssistantAcroTray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
?ActionAgentactionagent.exe"""A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client"". Is it required?"
NActivationActivation.exePart of Microsoft Money
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
UACWLIconACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UAd MuncherAdMunch.exe"Ad Muncher removes adverts
?Ad Online Guideadonlineguide.exe"??"
XAd-Eliminatorad-eliminator.exe"Ad-Eliminator rogue spyware remover - not recommended
UAd-MuncherADMUNCH.EXE"Ad Muncher removes adverts
UAD2KClientAD2KClient.exe"Executable for Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
UAdBinAdBin.exe"AdBin - ""Free and easy solution to managing your Window's hosts file. A fun way to block ads"""
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
Yadi CleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
Yadi DSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XAdKillerAD Defender.exe"Part of the Advanced Spyware Remover rogue spyware remover - not recommended
Xadlhidppsncc32.exe"Added by the SLAPER.AI TROJAN!"
XAdmanager ControllerAdManCtl.exe"Adware
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdministrator di DagoDago.exe"Added by the PUNYA-B WORM!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdobeManagerrundtl.exe"Added by the INJECT.IB TROJAN!"
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
UAdsGoneAdsgone.exe"AdsGone - pop-up stopper"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
Uadsnweadsnwe.exe"EmailSpyMonitor E-mail surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwkadsnwk.exe"Keylogger Spy Monitor keystroke logger/monitoring program - remove unless you installed it yourself!"
Uadsnwsadsnws.exe"ScreenSpyMonitor surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwyadsnwy.exe"Yahoo! Messenger Spy Monitor - ""spyware program that records Yahoo! Instant Messenger information on the computer and saves it to a log file"". Uninstall this software unless you put it there yourself"
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
UADUserMonADUserMon.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
XAdVantageAdVantage.exe"MediaAdVantage adware"
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
Xadvmon32advmon32.exe"Added by a variant of the CRYPTER.C TROJAN!"
UAdware Agentadware agent.exe"Adware Agent popup blocker"
XAdware PunisherAdwarePunisher.exe"Adware Punisher rogue spyware remover - not recommended
XAdware Punisher MonitorAdwarePunisher_monitor.exe"Adware Punisher rogue spyware remover - not recommended
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdware_ProNETAdware_Pro.exe"Adware Pro rogue security software - not recommended
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAELaunchAELaunch.exe"Audio Applications Launcher for the Philips Acoustic Edge soundcard"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
NAgentAgent.exe"Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this
XAgentalsys.exe"Added by the DREF-V VIRUS!"
Xagentppl.exe"Added by the DREF-U VIRUS!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
Xagent.exeagent.exe"Part of rogue security tools
?AgenteRemupd.exe"Part of an older version of Panda Antivirus. Is this an update reminder (guess because of the name)
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
YAHNSDAhnSD.exe"AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis"
?AHNUEAHNUE.exe"??"
NAHQInitahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
XAHUANACON.EXE"Added by the NACO.A WORM!"
UAi NapAiNap.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
?AidemHotKeyDVMAIN.EXE"Keyboard related"
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAim Pluginaimplugin.exe"Added by the GUAP-F WORM!"
XAIM reminderAIM reminder.exe"Added by the BUDDY.E TROJAN!"
NAim6AOLLaunch.exe"AOL Instant Messenger - start it when you want to use it"
NAimingClickAimingClick.exe"AimingClick from AimingTech. Web searching tool. Available via Start -> Programs"
UAimMonitorAimMonitor.exe"AIM Monitor Sniffer surveillance software for the AIM instant messenger. Uninstall this software unless you put it there yourself"
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
YAlaunchAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol.exe AutorunAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcoholAutomountaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
UAlcxMonitorAlcxmntr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
NAlienAutopsyTest_BS.exe"Alienware computer technical support software"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAll Sea screen saverTaskTray.exe"Free screensaver
XAll Sea web linkFWLink.exe"Free screensaver
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UAllSeeingEyease.exe"All-Seeing_Eye security software - ""monitors everything that takes place on your computer
UallSnapallSnap.exe"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XAlogrithm Link Queuealq.exe"Added by a variant of the SDBOT WORM!"
XAlphaAntalpha.exe"Alpha Antivirus rogue security software - not recommended
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
XAmazingTensAmazingTens.exePremium rate adult content dialler
UAMD PowerNow!GemBack.exe"
NAmerica Onlineaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
UAmIcoSinglunAmIcoSinglun.exe"Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN
UAModemLockDownModemLockDown.exe"ModemLockDown - allows you to supervise internet access by disabling the modem
YAmonAMON.EXE"Monitoring part of Eset's NOD32 virus-scanner"
YAmonitoramon.exe"Tiny Personal Firewall"
UAMO_Taskplaner.exeAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
NAMSNamsn.exe"aMSN Messenger is a multiplatform MSN messenger clone"
Xamsnamsn.exe"Added by the BANKER-BNZ TROJAN!"
NAnapod Manageranamgr.exe"Anapod Explorer from Red Chair Software ""is the most advanced Windows iPod® software available
Xanbv32nabv32.exe"Added by the TITOG.C WORM!"
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
Xangeleyesmsdll.exe"Added by the VB.PI TROJAN!"
Xanimalssanimalss.exe"Added by the AGOBOT-VE WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
?AnnotateCheckAnnCheck.exe"Genius Wizard Pen Tablet driver related. Is it required?"
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
NAnntextAnntext.exeCaere Pagekeeper text annotation server
UAnonymityGatewayAnonymity Gateway.exe"Anonymity Gateway - privacy protection tool that conceals IP address preventing your surfing habits and your internet activity form being tracked by websites or Internet Service Providers"
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
YANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
NAnti-Blaxx ManagerAnti-Blaxx.exe"Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives"
UAnti-keylogger checkantikey.exe"Anti-keylogger - protects against keylogger programs monitoring your keystrokes"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiAdd.exeAntiAdd.exe"AntiAdd rogue security software - not recommended
XAntiAIDAntiAID.exe"AntiAID rogue security software - not recommended
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Uantidialer.co.ukDialer_Watcher.exe"Dialer_Watcher is an application that allows you to detect dialers on your computer"
YAntiFreezeAntiFreeze.exe"AntiFreeze from Resplendence Software Projects - ""offers a last recourse when you find your computer in a hung state"". If your system has hung and AntiFreeze is running
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
Xantikewingate32.exe"Added by a variant of the RBOT WORM! See here"
XAntiKeepAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiKeep.exeAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiMalwareAntiMalware.exe"AntiMalware rogue security software - not recommended
XAntimalware Doctor.exeAntimalware Doctor.exe"Antimalware Doctor rogue security software - not recommended
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiMalwareSuiteAMS.exe"AntiMalwareSuite rogue security software - not recommended
XAntiMalware_ProNETAntiMalware_Pro.exe"AntiMalware Pro rogue security software - not recommended
UAntiPopUpAntiPopUp.exe"AntiPopUp for IE - pop-up stopper"
XAntiSpionagepgs.exe"AntiSpionage
XAntiSpionagePropgs.exe"AntiSpionagePro
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiSpy2008AntiSpy2008.exe"Antispy 2008 rogue spyware remover - not recommended
XAntiSpyBossasb32.exe"AntiSpyBoss rogue security software - not recommended
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
XAntiSpyKitAntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.2AntiSpyKit 5.2.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.3AntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyMonAntiSpyMon.exe"Antispyware Protector rogue security software - not recommended"
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntispySpiderantispyspider.exe"AntiSpySpider rogue spyware remover - not recommended
XAntispyStormAntispyStorm.exe"AntispyStorm rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware ProAntiSpyware Pro.exe"AntiSpyware Pro 2009 rogue spyware remover - not recommended
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot rogue spyware remover - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntispywareDAntispywareD.exe"AntiSpywareDeluxe rogue security software - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiSpywareSuitepgs.exe"AntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare family"
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiSpyZoneAntiSpyZone.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.5AntiSpyZone 4.5.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.6AntiSpyZone 4.6.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.9AntiSpyZone 4.9.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.1AntiSpyZone 5.1.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.4AntiSpyZone 5.4.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiTroyAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiTroy.exeAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue spyware remover - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntiVirGear 3.7AntiVirGear 3.7.exe"AntiVirGear rogue security software - not recommended
XAntiVirGear 3.8AntiVirGear 3.8.exe"AntiVirGear rogue security software - not recommended
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiVituSBase.exe"Added by the BAS.A WORM!"
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
Xanti_trojanti_troj.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the LODEAR.D TROJAN!"
UAnVirAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task ManagerAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
XAnvTrgrAnvTrgr.exe"AntivirusTrigger rogue security software - not recommended
UAny To-Do Listanytodo.exe"Any To-Do List ""the ultimate software solution to keep yourself organized and reminded"""
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UAnyDVDAnyDVD.exe"AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the ""U"" recommendation"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
XanythingATITAX.exe"Added by the FORBOT-DP WORM!"
UAnyTimeAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtDem.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAOL Companioncompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
?AOLCCACCAgnt.exe"AOL ISP software related
XAolConconfig.com"Added by the TAPLAK WORM!"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
XAornumaornum.exe"Installed along with
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAPIMonapimonx.exeAdded by the TIBSER.A downloader TROJAN!
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapmanager.exeapmanager.exe"AP Manager ransomware download manager - not recommended
UApointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApp.EXEName[path to worm]"Added by the BODIRU WORM!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
NApplication LauncherApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
Xara-key[random filename]"Added by the ANTINNY WORM!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
XArman[path to worm]"Added by the IRCBOT-TG WORM!"
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue
XArmorDefenderArmorDefender.exe"ArmorDefender rogue security software - not recommended
Uarmy logoreadmename.exe"Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
NAROReminderaro.exe"Advanced Registry Optimizer - ""scan
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
XArucer"rundll32 Arucer.dllArucer"
XArucer Dynamic Link Library"rundll32 Arucer.dllArucer"
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINbelgium_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINuk_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XAss and tittiesCMD32.EXE"Added by the SDBOT-GG BACKDOOR!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS TweakEnableastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
UasustweakenableATweak.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
XASWnkaswnk.exeAdult content dialler
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
UAthanAthan.exe"Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world"
UATI 2D ComponentAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
XATI Cpanelatiphexx.exe"Added by the AGOBOT-NV WORM!"
UATI Desktop ComponentATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
UATI Launchpadlaunchpd.exe"Convenient way to start all your Multimedia Center applications (DVD
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
XAtiCpanelatiphexx.exe"Added by the AGOBOT.IL WORM!"
UATIModeChangeAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XAtiPanelatip.exe"Added by the TACTSLAY.U TROJAN!"
YATIRmtWndrATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XATM Controladpn.exe"Added by the MMS.A WORM!"
NATnotesatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
UAtomSyncatomsync.exe"AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttunelAttunel.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneSystrayattune_st.exe"Aveo Attune automated helpdesk software - adware/spyware"
NaTuneratuner.exe"aTuner - tweak tool for GeForce based graphics cards"
UAU AgentAUagent.exe"Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon"
YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
XAudcntraudcntr.exe"Added by the GEMA TROJAN!"
?AudCtrl"RunDll32 AudCtrl.dll RCMonitor"
XAUDIOSOUND.exe"Added by the PLOYB-A TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
XAudiocntlaudiocntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
NAudioCommanderAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommander ApplicationAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
Xaudioinfaudioinf.exe"Added by a variant of the CRYPTER.C TROJAN!"
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
XAuth Starter Identstartauth.exe"Added by the RBOT-WP WORM!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
Xautowin32.exe"Added by an unidentified TROJAN! See here"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
XAuto Startdosin.exe"Added by the SDBOT-GO BACKDOOR!"
XAuto Startsndvol32.exe"Added by the SLINBOT.AX BACKDOOR!"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
Xautochk"rundll32.exe autochk.dll_IWMPEvents@16"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
Xautoloadcftmon.exe"Added by the SOCKS-E WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
UAutoMate5Am5HkWnd.exe"""Automate is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
Xautornautorn.exe"Added by the SILLYFDC.BCY WORM!"
Xautorunautorun.exe"Added by the AUTOM-B WORM!"
Xautorunsxs.exe"Added by the SMALLVBS-A WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
XAutoRunallrs.exe"Added by the MUDROP.LJ TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Xauto__antiav__keyantiav_exe.exe"Added by the BAGLEDI-AA TROJAN!"
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAVAntivir.exe"Antivir rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
NAvaFindAvaFind.exe"AvaFind file search utility"
Xavagent3974chnb8895.exe"AntiVirus ransomware security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
Xavcavmon.exeAdded by an unidentified TROJAN!
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_Runavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
YAVGntAVGnt.exe"AntiVir® PersonalEdition Classic antivirus. System Tray icon and control program"
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
YavinitAVINIT9X.EXE"Command Antivirus related"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
?AvMenuAVMenu.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required?"
YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
Yavxlniavxinit.exe"Anti-virus part of BitDefender virus scanner/firewall"
?Avxnews??"??"
UAWMONAd-Watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAWMONAd-Monitor.exe"F-Secure Anti-Spyware"
?AxFilter"Rundll32 AXFILTER.DLL Rundll32"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
XA_M_P_NETAntiMalwarePro.exe"AntiMalware Pro rogue security software - not recommended
NB.Readerremin.exe"Birthday Reminder 5.0 - as the name implies"
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
Xbabeie"rundll32 cnbabe.dll dllstartup"
NBabylon ClientBabylon.exe"Babylon-Pro is a powerful information tool that instantly provides relevant information
NBabylon TranslatorBabylon.exe"""Babylon-Pro is a powerful information tool that instantly provides relevant information
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBackdoor.NuAgentagent.exe"Added by the AGENT-DP TROJAN!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
NBackpack UDFbpudfmon.exe"Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackup4all OTB AgentB4AOTB.exe"""Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks
?BackupNotifybackupnotify.exe"HP Digital Imaging related. What does it do and is it required?"
XbalSYSMONMS.EXE"Added by the FAKEALERT TROJAN!"
XBand-Aid[path to file]"Added by the RANKY.O TROJAN!"
Ubandmonbandmon.exe"Rokario Bandwidth Monitor"
XBandookali.exe"Added by the EXEMAS-B TROJAN!"
NBandwidth Meter ProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBandwidth Monitor ProBandwidth Monitor Pro.exe"Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP"
NBandwidthMeterProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBanpopup by PratikBanpopup.exeBanpopup - popup killer
Xbantoolbantool.exe"Malware installed by different rogue security software including SpyKillerPro"
Xbantoolie_ban.exeDetected as the VB.PO TROJAN!
XBanyak_KerjaanTukang.exe"Added by the SILLYFDC.BDM WORM!"
XBar Ding loltAnaliz.exe"Added by the RBOT-RP WORM!"
Xbargainsbargains.exe"BargainBuddy adware"
Xbargainsbargainbuddy.exe"BargainBuddy adware"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
?Bart Stationstation.sbrt"Related to PeoplePC ISP. May be a dialler for dial-up accounts?"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
XBarThemebartent32.exe"Added by the AGOBOT-UG WORM!"
XBastioneAntiviruspgs.exe"BastioneAntivirus
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
UBatLogEx"rundll32.exe [path] BatLogEx.DLLStartBattLog"
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
?BBDialBT Broadband.exe"Part of BT Broandband - is it required?"
NBBLauncher.exeBBLauncher.exe"BounceBack Professional - back-up software"
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
NBCNTbcnt.exe"AWS Weatherbug related. What does it do?"
UBCSSyncBCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
YBDAgentbdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
YBDMConBdmcon.exe"BitDefender antivirus"
YBDNewsAgentbdnagent.exe"BitDefender antivirus - updater"
UBDRegionbrs.exe"Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
YBDSwitchAgentbdswitch.exe"Bitdefender 8 antivirus and firewall"
UBeatNik Internet ClockBeatNik.exe"BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
Xbegins0.exe"Added by the MYTOB-HE WORM!"
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
UBelkin Wireless USB UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UBelkin Wireless UtilityBelkinwcui.exe"Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
UBellSouthAlertManager.exeBellSouthAlertManager.exe"Related to BellSouth Alert Manager"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
XBenadril Alert Toolbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
UBGInfoBginfo.exe"BGinfo automatically displays relevant information about a Windows computer on the desktop's background
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
YBGNewsAgentbgnewsag.exe"BullGuard antivirus updater"
Xbgoomain.exebgoomain.exe"Baigoo.a malware"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
XBharatayudaGNB.exe"Added by the BHARAT.A WORM!"
UBHODemon 2.0BHODemon.exe"BHODemon ""protects you from unknown Browser Helper Objects (BHOs)
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
UBigPond ToolbarbpumTray.exe"Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
Xbikinibikini.exe"Added by the LOWZONE-CX TROJAN!"
NBillminderBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start -> Programs
Xbin32hpuppstub.exe"PrecisionPop adware"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XbingdianBingdian.vbs"Added by the BINGD WORM!"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
UBiomenumenusw.exe"Related to Sony VAIO - passwords
UBionix Wallpaper 5Bionix Wallpaper 5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionix Wallpaper 5beta.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBioniX Wallper.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionixWallpaper5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
?BisonHKBisonHK.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
UBitDefender for Yahoo! Messengeryahmon.exe"Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
XBittorrentbittorrent.exe"Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir%"
NBitTorrentbittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitTorrent DNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbittorrent.exebittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitWare Print Monitorbwprnmon.exe"FaxServe network fax software"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
UBJLaunchEXEBJLaunch.exe"Memory Card Utility for the Canon i470D
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
Ublinkxblinkx.exe"Blinkx Desktop ""Smart Folders"" software"
NBlitzz BWI715WLANmon.exeBlitzz Technology BWI715 Wireless PC modem connection monitor
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
UBLOG"rundll32.exe [path] BatLogEx.DLLStartBattLog"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
UBluetooth Connection AssistantLBTWiz.exe"Bluetooth connection manager for Logitech based bluetooth wireless products"
?Bluetooth HCI Monitor"RunDll32 HCIMNTR.DLLRunCheckHCIMode"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBmanBMan1.exeAbcsearch.com/DealHelper adware variant
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBMNbm.exe"Part of VirtualPCGuard
XBMNstrpmon.exe"Part of CleanPCTool
XBMNdcmon.exe"SystemDoctor rogue security software - not recommended
XBmonqbmonq.exe"Added by the CLICKER.HZ TROJAN!"
XBndt32Bndt32.exe"Added by the LACON WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
YBOCleanautostartBoclean.exe"NSClean's BOClean anti-trojan software"
UBOINC Managerboincmgr.exe"BOINC manager - ""controls the use of your computer's disk
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
Xbolenjabolenja.exe"Added by the WANTVI.BF TROJAN!"
Xbolenjxbolenjx.exe"Added by the ELDYCOW.O TROJAN!"
XBonzi Buddy??"Bonzi Buddy adware - see here for removal instructions"
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
NBookmarkCentralBMLauncher.exe"Bookmark Express - "offers a more flexible way to manage Web site bookmarks
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
XBoot Clientbootcli.exe"Added by the IRCBOT-ACF BACKDOOR!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot ManagerNjgal.exe"Added by the KILO TROJAN!"
XBoot Managerbootmng.exe"Added by a variant of the SPYBOT WORM!"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootWarnBootWarn.exe"From here: ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
?BostonBoston.exe"Part of the Boston Acoustics USB speaker systems. What does it do and is it required?"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
XBrave-SentryBraveSentry.exe"BraveSentry rogue security software - not recommended
XBraveSentryBraveSentry.exe"BraveSentry rogue security software - not recommended
UBreak_ReminderBREAK REMINDER.exe"Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBridge"rundll32.exe [path] Bridge.dllLoad"
YBrindys BriTrayBRITRAY.EXE"Main process for the following applications: GEDEX
Ubroadband medicmatcli.exe"NTL's Broadband Medic. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBroadband Wizardbbwiz.exe"Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs"
NBroadCamRunbroadCam.exe"BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
UBroadcom Wireless Manager UIbcmntray.exe"Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-SpizaetusnorBtok.exe"Added by the RONTOKBRO.B WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
XBron-Spizaetuseksplorasi.exe"Added by the RONTOKBRO.J WORM!"
XBron-SpizaetusElnorB.exe"Added by the RONTOKBRO.D WORM!"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
XBron-SpizaetusRakyatKelaparan.exe"Added by the BRONTOK-J or BRONTOK-L WORMS!"
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBRoNToKBRoNToK.exe"Added by the BRONTOK-CG WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Xbrowsers_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserdeamon.exe"Added by the TACTSLAY.C TROJAN!"
UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
XBrowserUpdateSched[random filename]"ZenoSearch adware"
?BsMntBsMnt.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBsx3"RunDLL32.EXE bs3.dllDllRun"
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XBT00003*hiklmnop27.exe"Added by the VB-VT TROJAN where * = 2
Nbtdnabtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbtdna.exebtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
?btinstbtinst.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
XBtvCbtvclean.exe"BroadcastPC adware"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
YBufferZoneCLIENTGUI.EXE"BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
NBug EliminatorBug_Elim.exe"Bug Eliminator - ""performs a complete health check on your computer safely
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XBullsEyebargains.exe"BargainBuddy adware"
XBullsEye Networkbargains.exe"BargainBuddy adware"
XBunxbeagle.exe"Added by the LEBREAT-E WORM!"
NBurnQuick QueueBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
UButton Serverbttnserv.exe"Found on a Compaq PC
NButtonKeyButtonKey.exe"CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
Nbwprnmon.exebwprnmon.exe"FaxServe network fax software"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
Xbxsx5"RunDLL32.EXE bsx5.dllDllRun"
Xbxxs5"RunDLL32.EXE bxxs5.dlldllrun"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
XByteDefenderByteDefender.exe"ByteDefender rogue security software - not recommended
?BZEnvironmentVariableCollectorBZEnvironmentVariableCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
?BZUtilizationCollectorBZUtilizationCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
UCA-AMAgentamagent.exe"Unicenter Asset Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery
XCABCInstallCABCInstall.exe"Ignite Technologies (was CABC) content delivery software"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
NCachemanCacheman.exe"Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up"
UCacheSentry ProCacheSentry Pro.exe"""CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
UCaddais BackupOnDemandBODMon.exe"Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
UCafeStationCafeStation.exe"""CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations
NCAgentCAgent.exe"Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents"
XcAgOu[filename].hta"Added by the KAKWORM WORM!"
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
NCal Reminder Shortcutcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
Xcalc"rundll32.exe calc.dll_IWMPEvents@0"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
UCalendarCalendar.exe"This entry can be added by PlainSight Desktop Calendar and older versions of Desktop iCalendar from Desksware and the older Calendar 200X - which is no longer supported by or available from the author"
?Calendar 200X Monitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
NCalendar 200X Remindercalendar.exe"Part of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays
?Calendar Monitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
UCalendarscopecs.exe"Calendarscope calendar software"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
YCallBumpingcbpopw.exe"Related to the Gazel 128 PCI ISDN adapter. Required if you use it"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
?calmonitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
?calmonitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
UCamenoCameno.exe"Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above"
UCamera Assistant Softwaretraybar.exeCamera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
?CameraApplicationLauncherCameraApplicationLaunchpadLauncher.exe"Supports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?"
UCameraAssistantCameraAssistant.exe"Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom
?CamMonitorhpqcmon.exe"From HP and related to digital imaging"
NCanadaCanada.exe"Known to be a dialler - but is it maliscous or clean?"
UCanarycanary-std.exe"Canary keystroke logger/monitoring program - remove unless you installed it yourself!"
Xcandycommand32.exe"Added by the RBOT-LV WORM!"
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
UCANoeCANoe32.exe"CANoe from Vector Informatik. Development and test tool for Engine Control Units (ECU) based upon the CAN
UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
UCanonMyPrinterBJMyPrt.exePrinter software for Canon Bubblejet printers
UCanonSolutionMenuCNSLMAIN.exe"
?CAP3ONCAP3ONN.EXE"Canon driver
UCAPingCAPing.exeCitibank Citianywhere software
YCaponCapon.exeCanon printer driver
YCaponCaponn.exeCanon printer driver
XCaptcha7rundll captcha.dll"Added by the TINY.WRE TROJAN!"
XCaptionMgr32crssr.exe"Added by the ZAR.A WORM!"
UCaptureAssistantCaptureAssistant.exe"Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text
NCarbonite BackupCarboniteUI.exe"""Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
Xcartaoconflicted.exe"Added by the DADOBRA-DV TROJAN!"
Xcartaokilling.exe"Added by the DLOADER-QN TROJAN!"
XCAS Clientcasclient.exe"CasinoClient adware"
UCasAgntCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCasino Royalejamesbond.exe"Added by the RBOT-FZO WORM!"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
XCAZNOVASCAZNOVAS.exe"Added by the CAZNO TROJAN!"
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
UCBWAttnCBWAttn.exe"Required for Bitware to answer incoming faxes
Xccagent.execcagent.exe"Control Center and Control Components rogue security software - not recommended
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XccAppsN/A"Added by the KANGAROO-A TROJAN!"
UCCD ManagerDDS.EXE"Project Labs Century CD manager for their CD/DVD storage device"
NCcdecode"rundll32.exe streamci StreamingDeviceSetup"
YCCDoctorLogonTestingccdoctor.exe"Checks your system to make sure it's configured properly for running IBM Rational ClearCase
YccenterCCenter.exe"RAV AntiVirus"
UCCleanerCCleaner.exe"CCleaner from Piriform Ltd. - ""is a freeware system optimization
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
UCCUTRAYICONCCU_TrayIcon.exe"Related to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®"
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
NCDInterceptorcdi.exeCD indexer for measuring the speed of CD players
UCDLoadersb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XCdnCtrcdnup.exe"CNNIC Update pest"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCdrom Controllercdromcntrl.exe"Added by the BATTRY-A TROJAN!"
UCDVAgentCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
Xcenter[random name]32.exe"Added by the BOFRA.A WORM!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
XCEventMgrCell.exe"Added by the BIFROSE-AK TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
NcfFncEnabler.execfFncEnabler.exe"Toshiba ""Config Free"" wireless network manager on their range of laptops"
Ycfgintprcfgintpr.exe"Configuration Interpreter - part of Tiny Personal Firewall V4"
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xcfgmgr52"RunDLL32.EXE cfgmgr52.dllDllRun"
UCFi ShellToys Utility ManagerCFiShlMan.exe"Manager for CFi ShellToys from Cool Focus International Ltd - which ""puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders
?cFosDNTcFosDNT.exe"cFos DSL Modem driver related. What does it do and is it required?"
?cFosInst_Checkcfosinst.exe"cFos DSL Modem driver related. What does it do and is it required?"
Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
XCftmon32afd.exe"Added by the AUTORUN-AUB WORM! The ""afd.exe"" file is located in %Windir%"
XCftmon32afd.exe"Added by the SCAR.AYWK TROJAN! The ""afd.exe"" file is located in %AppData%"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
?ChangeLineschngline.exe"??"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XChat loginchatlogin.exe"Added by the ANTINNY.F WORM!"
NChatangoChatango.exe"Chatango - ""allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions
NChcenterchcenter.exe"IMSI HiJaak - ""the easiest way to convert
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Ucheatmonitorstart.exe"CheatMonitor surveillance software. Uninstall this software unless you put it there yourself"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
Xcheckrunelite***32.exe [* = random char]"EliteBar adware"
Xcheckrunelitelsj32.exe"Added by the MULTIDR-ER TROJAN!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UCherryKeyManKeyMan.exe"Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys"
UChikkaDefaultChikkaLauncher.exe"Chikka PC text messanger and IM client"
UChilyClientChilyClient.exe"Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself"
Xchina11msnCHINA11MSN.EXE"Added by the ENVID.O WORM!"
XChinagnqvasdd.exe"Added by the SDBOT-SE WORM!"
UChineseStarcstar.exeChinese language support software
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
XCHK NTchkntf.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NCHKADMINCHKADMIN.EXE"Compaq Network Management System. When running
Xchkdrviemon.exe"Detected by Symantec as the ADCLICKER TROJAN!"
Xchoperunlli32.exe"Added by the QQPASS-U TROJAN!"
?ChronitelInitTVCHTVINIT.EXE"??"
Uchronochrono.exe"Chronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)."" Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
Xci1gntci1gnt.exe"Detected by Kaspersky as the AGENT.DHU TROJAN!"
YCingular Communication ManagerCingularCCM.exe"Cingular Communication Manager - now taken over by AT&T. ""provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
XCiodiagDECCONF.EXE"Added by the STRAT.EL TROJAN!"
XCirebonPunyaXXrocks.exe"Added by the BHARAT.A WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCitiVANCitiVAN.exe"Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again"
YClamWinClamTray.exe"ClamWin antivirus"
XClassesint1.exe"""Switch"" premium rate adult content dialler variant"
XClassesintl.exe"""Switch"" premium rate adult content dialler variant"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
NClean Access AgentCCAAgent.exe"Cisco Clean Access Agent from Cisco Systems
XClean Mgrcleanmg.exe"Added by the IRCBOT.BBO BACKDOOR!"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
XCleanatorCleanator.exe"Cleanator rogue privacy program - not recommended
?CleanEasyImgcleanall.exe"??"
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
UCleanTempCLEANT~1.EXE"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
UCleanTempCleanTemp.exe"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
NCleanupONICTASK.EXE"Internet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet"
YCleanUpmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
YCleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
?CleanupProgramcleanup.exe"Sony Vaio related - what does it do and is it required? Located in a C:\Sonysys folder"
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
Xclfmonclfmon.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmon.execlfmon.exe"Added by the AGENT-BJ TROJAN!"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
NClick Radio Tunerclickr~1.exe"ClickRadio - subscription service playing radio music via the internet"
NClick Tray CalendarClickT~1.EXE"ClickTray Calendar - shows holidays
NClickSight Launchercs.exe"Launcher for the ClickSight® marketing tool from ClickStream Technologies - which ""is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"""
XClickTheButtonCTB.EXE"ClickTheButton adware"
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XClickTheButtoncd_load.exe"Added by the DOWNLOADER-MY TROJAN!"
XCLICONFGCLICONFG.EXE"Added by the OPASERV.T WORM!"
UClient Access API Daemoncwbappcd.exe"IBM iSeries Client Access
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
UClient Access Taskbarcwbuitsk.exe"IBM iSeries Client Access taskbar
XClient Agentipxwping.exe"Added by the PPDOOR-N TROJAN!"
XClient Agentphotes.exe"Added by the PPDOOR-P TROJAN!"
XClient Agent[path to file]"Added by the PPDOOR-J TROJAN!"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClient Updatewup.exe"Added by the OPANKI.O WORM!"
YCliente DLODLOClientu.exe"Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
XClientMan1mscman.exe"ClientMan parasite variant"
NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
UCLMFrontPanelclmpanel.exe"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
XClock Manageramsngr.exe"Added by the SDBOT-XM TROJAN!"
XClockSyncSync.exe"ClockSync - synchronizes your system clock with an internet time server. It's by WhenU
UCloneCDCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
UCloneCDElbyCDFLElbyCheck.exe"From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
UCloneCDTrayCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
XCLSIDplugin.exeAdult content dialler
XCMAPPcmappclient.exe"CasClient adware - also detected as the CMAPP TROJAN!"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
Xcmd32configs.exe"Hijacker
Xcmdconcmdcon.exe"Added by the CRYPTER.A TROJAN!"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
NCmFlywaveNameCmFlywav.exe"Driver for Linksys Wireless-G Music Bridge"
UCMGrdianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
XCMManCMMan.exe"Added by the CMAPP TROJAN!"
XCmmon32Syscmmon32.exeAdded by the SMALL.CL TROJAN!
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
UCMSETTINGSctmn.exe"Part of NetNanny
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
?CmUCRRunCmUCReye.exe"Related to Medion Display Information. What does it do and is it required?"
XCn323cnfrm33.exe"Added by the MIMAIL.G WORM!"
XCn911ODBCJET.exe"Added by the BIFROSE-PR TROJAN!"
XCNBABECNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
Ncnetkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
XCnfrm32cnfrm.exe"Added by the MIMAIL.D WORM!"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
YCnwiDeviceAgentcnwida.exe"Part of the Canon imagePROGRAF W8400 printer management software"
YCnxAdslLCnxAdslL.exe"DLink
NCnxDslTaskBarCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
UCobianCobian.exe"Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian BackupCobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10Cobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 6CobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7CobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 ApplicationCobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8Cobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9Cobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitaCobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MoonCobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup BoletusCobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XCodeCleanCCIntro.exe"CodeClean rogue security software - not recommended"
UCodename Dashboarddashboard.exe"Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
UComAgentComAgent.exe"ComAgent - MDaemon's instant messaging client"
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
XCommandsystem.exe"Added by the GATECRASH.A or GATECRASH.B TROJANS!"
XCommandGotit.exe"Added by the TITOG WORM!"
XCOMMANDcommand.exe"Added by the QQPASS.E TROJAN!"
Xcommandjavaw.exe"Added by the AGOBOT-LG WORM!"
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
UCommand WorkStation 4cws 4.exe"EFI's Command WorkStation makes ""managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information"" - for high-end print environments"
Xcommand32command32.exe"Added by the LINEADI-A TROJAN!"
YCommon ClientccApp.exe"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XCommon Filestwain.exe"Added by the AGENT.BEA TROJAN!"
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCOMMUNICATORCommunicator.exe"Part of Microsoft Office Communicator
UComodo Launch Pad TrayCLPTray.exe"System Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware
UCompanion Modulecompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XCompanionWizardcompwiz.exe"Part of WinAntiVirusPro 2007 rogue security software (and possibly others) - not recommended
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
UCompaq Knowledge Centersilent.exe & matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UCompaq PK Daemoncpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use them
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
?CompaqHW Comp Managercpqhcm.exe"Running on a Compaq laptop - any ideas?"
NCompaqPrinTrayprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XComPlus Applicationstwain.exe"Added by the AGENT.AQO TROJAN!"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
?Concurreconcurre.exe"??"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
UConfigUtilityConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
Xconime.execonime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
NConmgrconmgr.exeStarts Winfax pro at startup
UConMgr.execonmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
XConnect2Partyconnect2party.exeAdult content dialler
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTAUTrayAppCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
UConnection KeeperConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
NConnection ManagerCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XConnectorSYS.EXE"Nunci premium rate dialer"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XConsconsol32.exe"Hijacker - redirects to an adult content portal
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
?Contactecontacte.exe"Some kind of driver?"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XContentEraserGDC.exe"ContentEraser rogue privacy tool - not recommended
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XContraviroContraviro.exe"Contraviro rogue security software - not recommended
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
UControl CenterCenter.exe"Associated with Hawking Technologies
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
YControlCenterctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
NControlCentreTrayXWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
UCoolMonCoolMon.exe"""CoolMon monitors vital system stats and almost anything else you wish to display on the desktop"""
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xcoolwebprogramclrssn.exe"CoolWebSearch Smartsearch parasite variant"
NCopernic Desktop SearchDesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
UCopy handlerCopy Handler.exe"Copy Handler lets you copy between hard disks
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
UCoreCenterCoreCenter.exe"MSI Core Center - motherboard utility for monitoring CPU speed
UCoreCenterCORECE~1.EXE"MSI Core Center - motherboard utility for monitoring CPU speed
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorel Photo DownloaderMediaDetect.exe"Related to Corel Photo Album"
NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorrectConnectCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
Xcosinecosine.exe"Added by the RBOT-SW WORM!"
UCostAwareniIPCApp.exe"NetInternals CostAware - download quota measuring tool"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
NCountry Selectpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
NCountrySelectionpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
?Coupon Offers??"??"
Xcouponicacouponica.exe"Adware - see here"
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
UCP32NOTCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
UCP4HPOTOneTouch.EXE"Supports the additional multimedia keys on HP/Compaq laptops which give single button press access to standard functions such as Mail
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
Xcpldeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xcpls_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Xcpntmgcnavpmc.exe"Added by the SIMCSS TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
NCPQINKAGENTcpqinkag.exe"That is the Compaq Ink Agent for some inkjet printers
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
XCPU Managercpumgr.exe"Added by the PANDEM.B WORM!"
UCPU Power MonitorCpuPowerMonitor.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme). Associated with the ""Energy Saving"" feature of AI Gear - which ""is a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features."" Part of AI Suite"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
XCPU Watcher"rundll32.exe cpu.dllload"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
NCPUMonCPUMon.exe"""CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area"""
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
XCr**.exe [* = random char]Cr**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XCr**32.exe [* = random char]Cr**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
UCRBroadCastingCRBroadCasting.exe"CardReader2 from On Track Inovations Ltd. USB Card Reader"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
XCreate A MonstercreateAMonster.exe"Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related"
NCreateCD_Reminderreminder.exeReminder to create system recovery CD/DVDs on a Sony Vaio laptop or desktop
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
XCrisysTec SentrySentry.exe"CrisysTec Sentry rogue privacy program - not recommended"
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
UCrossMenuCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menus
XCRP386 Networkingcrp386.exe"Added by the IRCBOT.N TROJAN!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
NCryptLoadRouterClient.exe"CryptLoad download manager"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
UCSINJECT.EXECSINJECT.EXE"Part of Quarterdeck/Norton CleanSweep. ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"""
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Xcsrssnwiz.exe"Added by the CHODE-J WORM!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
UCTCMonitorCTCMonitor.exe"Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office
XCTDrive"rundll32.exe drvmod.dllstartup"
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
Xctflog managerctflog.exe"Added by the DONBOMB.A TROJAN!"
XCTFM0N.exeCTFM0N.exe"Added by the STARTPAGE.P TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
Xctfmomctfnom.exe"Added by the BCKDR-QTA BACKDOOR!"
Uctfmonctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
Xctfmoncftmon.exe"Added by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfmonmIRC.dll"Added by the DELBOT-E TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
UCTFMonctfmon.exe"Family KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""CTF"" sub-folder"
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XCTFMONwin.exe"Added by the VBS.RUNAUTO.G WORM!"
XCtfmonwmisys.exe"Added by the IRCBOT-ADS WORM!"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
XCtfmon.exectfmon32.exe"CoolWebSearch Ctfmon32 parasite variant"
Xctfmon.exectfmon.exe"Added by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
Uctfmon.exectfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmon.exectfmon.exe eminem.exe"Added by the BHARAT.A WORM!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XCTFMON32CTFMON32.EXE"CoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
Xctfmonactfmona.exe"Added by the DLOADR-BME TROJAN!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
Xctfmunctfmun.exe"Added by the AGENT.ACEZ TROJAN!"
Xctfnnonctfmon.exe"Added by the TURKOJAN.IL BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfnomrundIl32.exe"Added by the LEGMIR-AW TROJAN!"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
XCTin10CTin10.exe"Added by the BANCOS.E TROJAN!"
XCTMON.EXEcfmon.exe"Added by the CLCKR-AN TROJAN!"
UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
Xctpmonctpmon.exe"Registry Cleaner rogue - not recommended
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
NCTSyncU.exeCTSyncU.exe"Creative Sync Manager - synchronizes music tracks on your computer with your player"
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
YcuagentExeCuagent.exe"Command Antivirus related"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
NCurseClientCurseClient.exe"CurseClient add-on manager for World of Warcraft and Warhammer Online games"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
UCurtainCurtain.exe"Curtain (from Chaotic Visions) - ""is a Windows utility which gives you the power to hide any window or group of windows to your system tray"""
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcvmonitor.execvmonitor.exe"Added by the SDBOT.BV WORM!"
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
Ncwbinhlpcwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
NCXMonHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
Xcybansoscyban.exe"Added by the TATERF-V WORM!"
UCyber-Defender 2003uwcdsvr.exe"
Xcyberfree.exe****.dat [* = random char]Unidentified adware
UCyberLat Ram CleanerCLRamCleaner.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UCyberLat Ram CleanerCyberLat Ram Cleaner 1.1.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
NCyberMedia AgentCMAGENT.EXE"Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge
UCyberPatrolNewcphq.exe"""CyberPatrol is one of the most powerful and popular client-based
?CYNHKeyCYNHKey.exe"??"
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
YD-Link Air UtilityAirCFG.exeD-Link Air PCI wireless driver and configuration utility
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus G Wireless UtilityAirPlus.exe"D-Link AirPlus G wireless configuration and monitoring utility"
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
XD3**.exe [* = random char]D3**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XD3**32.exe [* = random char]D3**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xdabrun"rundll32.exe dabapi.dllRundll32"
NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
NDaemonDAEMON32.EXEPre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
Ndaemondaemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDaemondaemon.exe c daemon2.exe"Added by the SELOTIMA.A WORM!"
NDAEMON Toolsdaemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Litedaemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools LiteDTlite.exe"Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools ProDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTProAgent.exe"System Tray access to an older version of DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools-1033daemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDaily Plannerdayplan.exe"Daily Planner - discontinued
XDanBtR270414DanBtR270414.exe"Added by the VB-NIB WORM!"
UDancerDncLE.exe"Part of Microsoft Plus! Digital Media Edition - see here"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
XDarKNesS LsasSLsasS23.exeAdded by an unidentified WORM or TROJAN!
?DashIEN/A"Could be related to "Dash Power Shopping" tool bar in IE?"
Xdatamsngs.exe"Added by the RBOT-ADQ WORM!"
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
XData Protectiondatprot.exe"Data Protection rogue security software - not recommended
NDataCachingFlashKsk.exe"SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word
XDate Managerdatemanager.exe"Date Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
?DatecheckerN/A"Could be related to this?"
XDateMakerIntlDateMakerIntl.exePremium rate adult content dialler
XDateMngrDATEMNGR.EXE"Added by the SPYBOT-BR BACKDOOR!"
UDAZEL Delivery AgentDcDaemon.exe"Control and send documents
UDC300 Monitorcmonitor.exeMonitor for a Acer DC300 digital camera
XDC6dc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDC6_checkdc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
Xdc6_checkdcmon.exe"SystemDoctor rogue security software - not recommended
XDCE Managerdcemgr.exe"Added by the TUMAG TROJAN!"
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
NDDCActiveMenuDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
NDDCMDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
NDDCManDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
UDDLAgentDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
?DDTN/A"??"
UDDWMonddwmon.exe"Direct Disc Writer Event Monitor from TOSHIBA"
Xde32gende32gen.exe"Added by a variant of the CRYPTER.C TROJAN!"
NDeadAIM"rundll32.exe DeadAIM.ocm ExportedCheckODLs"
XDealHelperDowndownload.exe"DealHelper adware"
XDebugMonitordebugmonitor.exe"Added by the MYDOOM.BG WORM!"
UDeeEnEsDeeEnEs.exe"DeeEnEs - automatically updates a dynamic IP address when it changes"
XDeewooncntnkwd.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
UDefault ManagerDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDefault_Page_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefault_Search_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefendAPcDefendAPc.exe"DefendAPc rogue security software - not recommended
Xdefenderdefender25.exe"DollarRevenue adware"
Xdefenderdfndref_7.exe"DollarRevenue adware"
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
Xdefragm_checkdefragment.exe"CoolWebSearch parasite variant"
UDelaydelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
UDelayrundelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
NDell AlertDAMon.exe""Dell Alert" utility
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
UDell PanelMgrSSMMgr.exe"Monitors ink levels
UDell Photo AIO Printer 922dlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 942dlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 962dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor
YDell Webcam CentralWebcamDell.exe"Dell Webcam Central - webcam management software controlling aspects such as picture control
NDELL Webcam ManagerDellWMgr.exeDell Webcam Manager - Webcam management software provided on Dell PCs
NDell Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
YDellAutomatedPCTuneUpPTAgnt.exe"PC TuneUp from Dell - ""silently monitors your system
UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
UDellSupportCentersprtcmd.exe /P DellSupportCenter"Dell Support Center (provided by SupportSoft
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
XDeluxeCommunicationsDxc.exe"Deluxe Communications adware - successor to SurfSideKick"
?demondemon.exe"Part of the French Wanadoo ADSL extense pack. What does it do and is it required?"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
Xdesktopdesktop.ini.vbs"IE-Title malware"
UDesktop CalendarDesktop Calendar.exe"Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
UDesktop iCalendarCalendar.exe"Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather
UDesktop iCalendarDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendarDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop iCalendar LiteDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar Lite.exeDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar.exeDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
NDesktop WeatherTHE WEATHER CHANNEL.exe"Desktop Weather by The Weather Channel - provides current temperature
NDesktop Weather 3THE WEATHER CHANNEL.exe"Desktop Weather 3 by The Weather Channel - provides current temperature
UDesktopIconToyDesktopIconToy.exe"""Desktop Icon Toy is an easy to use desktop icon enhancement tool
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
XDeus CleanerDCleaner.exe"Deus Cleaner rogue system cleaner utility - not recommended"
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevelopment Environmentdevenv.exe"Added by the DELBOT-AH WORM!"
UDEventAgenteventagt.exeDEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDevice Hardwaredevicehnd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
XDevice Managerwfxmgr.exe"Added by the RBOT.AJU WORM!"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
Ydhcpagntdhcpagnt.exeIntel DSL modem driver - leave enabled or you'll have to re-install the drivers
?DHNUXBDHNUXB.exe"??"
Ndiagentdiagent.exeSystem Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
XDiagnosticdiagnostic.exe"Added by the ALPHA-C TROJAN!"
XDiagnostic Agentdiagent.exe"Added by the AGOBOT-CW WORM!"
XDialer"rundll32.exe MSA32CHK.dllReg"
UDialer Controldc.exe"Dialer-Control. Detects and protects from premium rate adult content diallers"
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
XDialNetmxt32.exeAdult content dialler
NDialog Box AssistantOSDEx.exe"Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
XDialUp Network ApplicationRnaap.exe"Added by a variant of the SDBOT WORM!"
UDiamondbackrazerhid.exe"Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
?DiamondviewDiamondview.exe"Manulife Financial Insurance program. Is it required at startup?"
XDigiDDigitalSound.exeAdware downloader
NDigiGuideCLIENT.EXETV guide and reminder
NDigiGuideclient01.exeTV guide and reminder
UDigisoft AntiDialerAntiDialer.exe"Digisoft AntiDialer"
NDigital Line DetectDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
XDigital Protectiondigprot.exe"Digital Protection rogue security software - not recommended
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases
XDigitalNamesDigitalNamesStart.exe"DigitalNames spyware variant"
NDigitalWizard MonitordwMon.exe"InstallShield's DigitalWizard - free
UDimensionDimension.exe"Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames
UDimension4d4.exe"Dimension 4 - network time synchronization freeware - starts-up
XDino3dino3.exeRelated to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
XDinstdinst.exe"IMIServer/IEPlugin adware"
XDirect settingssdchost.exe"Added by the DAEMONI-I TROJAN!"
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
XDirect X Opengldxopengl.exe"Added by a variant of the RBOT-CJ WORM!"
XDirector Videobtnmgern.exe"Added by the MYTOB-KL WORM!"
XdirectxNTCmd.exe"Added by the SDBOT.D TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
?Disable EHCInousb20.exe"??"
XDisableKeybaord"Rundll32.exe KeyboardDisable"
XDisableMouse"Rundll32.exe MouseDisable"
NDisc DetectorCtNotify.exe"For Creative sound cards. Detects when you insert a CD
?disc detectorqnetquestnotifty.exe"??"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
UDiscWizardMonitor.exeDiscWizardMonitor.exe"Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
UDisk CleanerDiskCleaner.Exe"Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
XDisk Managerdiskver.exe"Added by the RBOT.AQT WORM!"
XDisk Master[trojan name]"Added by the DISTER TROJAN! - a spam relayer"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDiskCheckmsdarkend.exeAdded by an unidentified WORM or TROJAN!
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
Xdiskinfdiskinf.exe"Added by the CRYPTER.A TROJAN!"
?DISKMON.EXEDISKMON.EXE"??"
NDisknagdisknag.exeDell program that reminds you to make your backup diskettes
XDiskstartSnt.exeAdult content dialler
UDiskSuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
UDisk_MonitorDisk_Monitor.exe"Multi-media
Xdisnisadisnisa.exe"Added by the DORF-AE WORM!"
Xdispenterdispenter.exe"Added by the AGENT-MKK TROJAN!"
NDisplay Settingshptasks.exe"Allows for the adjustment of the display for LCD screen
UDisplayFusionDisplayFusion.exe"DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much
NDisplayTrayIconTrayIcon.exe"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution
XDist-FBGeneveGDC.exe"NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDistributed Link Trackingascvt.exe"Added by the AGOBOT-GH BACKDOOR!"
Udistributed.net clientDNETC.EXE"Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
?Divamon.exeDivamon.exe"Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
Xdivxdivxenc.exe"Added by the SPBOT.B TROJAN!"
XDivXCodecNEWMAIL.exe"Added by the DELF-RQ BACKDOOR!"
?Dixons Insert DetectInsDetect.exe"Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
?DJSNetCNDJSNetCN.exe"""Symantec Licensing Detect Internet Connection""
XdKerneldKernel.exe"Added by the DECOY-A WORM!"
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
Udlccmon.exedlccmon.exeDell Photo AIO Printer 924 device monitor
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
Udlcdmon.exedlcdmon.exeDell Photo AIO Printer 944 device monitor
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
Udlcgmon.exedlcgmon.exeDell Photo AIO Printer 810 device monitor
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
Udlcjmon.exedlcjmon.exeDell Photo AIO Printer 964 device monitor
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
Udlcqmon.exedlcqmon.exeDell Photo AIO Printer 966 device monitor
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
Udlcxmon.exedlcxmon.exeDell Photo AIO Printer 926 device monitor
Udldtamondldtamon.exeDell AIO Printer V305 device monitor
Udldtmondldtmon.exeDell AIO Printer V305 device monitor
Udldtmon.exedldtmon.exeDell AIO Printer V305 device monitor
XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDlitedllmanager.exe"Added by the WOOTBOT.DN WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDll Linksvchoist.exe"Added by the AUTOSKY WORM!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLL Managerdllmngr32.exe"Added by a variant of the RBOT WORM!"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
NdlmMgrAdobeDownloadManager.exe"Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted
YDLO AgentDLOClientu.exe"Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
XDm Hrlpns.exe"Added by the IRCBOT.WORM.61673 WORM!"
Xdm***.exe [* = random char]dm***.exe [* = random char]"Wareout - malware masquerading as a spyware and dialer remover"
UDmwClientdmwclient.exe"DMW ""anti-cheating"" software for online gaming"
UDMXLauncherDMXLauncher.exe"Part of Dell's Media Experience
Xdm[3 random letters].exedm[3 random letters].exe"Added by the RUINDEM TROJAN!"
NDNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Xdnamd140113.a.Stub.EXE"Added by the STUB_A TROJAN!"
NDnarDnar.exe"Installed on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?"
YDNE Binding Watchdog"rundll dnes.dll DnDneCheckBindings"
YDNE DUN Watchdog"rundll dnes.dll DnDneCheckDUN13"
XDNHelper32DNHlp32.exeAdded by an unidentified WORM or TROJAN!
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
?DNS2GoClientdns2goclient.exe"DNS2Go is a Domain Name System that will make your computer accessible anytime
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
Xdnscleanerdnscleaner.exe"CoolWebSearch parasite variant"
XDNSEDNSE.exe"Part of rogue security tools
?DNXVCdnxvc.exe"??"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
NDocuMagix InitPWATCH.EXE"PaperMaster is an application for the PC designed to automate the process of organizing
UDocument Managerdocmgr.exe"Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
?Doingdoing.exe"??"
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
UDon't Panicdontpanicdemodp.exe"30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
UDon't Panic Pop-Up Stopperdpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
UDon't Panic!DP.EXE"Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
XDontworrymysaym.exe"Added by the SDBOT-RC WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
NDoUWantItduwi.exeDoUWantIt - online shopping assistant. Start it manually
XDowmingzuDowmingzu.dll.vbs"Added by the SOLOW-E WORM!"
Xdownhlp32.exe"Added by the DLOADER.BG TROJAN!"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
UDown2HomeDown2Home.exe"Down2Home - ""monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"""
NDownload Accelerator Manager Free Editiondam.exe"Download Accelerator Manager Free Edition from Tensons Corp"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownload PlusDownloadPlus.exe"DownloadPlus adware"
NDownload WonderDownloadWonder.exe"Download Wonder from Forty Software. Download manager for resuming downloads
NDownloadAcceleratorDAP.EXE"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadWaredw.exe"DownloadWare adware"
XDownloadWare EngineDwe.exe"DownloadWare adware"
Xdownsdowns.exe"Added by the BCKDR-MNR TROJAN!"
XDownxzDownxz.bat"Added by the MYDOOM.W WORM"
YDpAgentdpagent.exe"Part of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for example"
NDPAgntDPAgnt.exe"digitalPersona fingerprint scanner"
YDPASDPASNT.exe"DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
YDpcnavdpcnav.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
XdpzProtectn.vbe"Added by the RUNAUTO.H WORM!"
NDrag'n'Drop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
NDragnDrop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
XDRam Monitor 23tskman3.exe"Added by a variant of the RBOT WORM!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDRan posessorDAP.exe"Added by a variant of the SDBOT WORM!"
XDrAntispyDrAntispy.exe"DrAntiSpy rogue security software - not recommended"
?dregfixph_finder.exe"??"
Xdrin[path to trojan]"Added by the SMALL.DPB TROJAN!"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
XDriveCleaner FreeUDC.exe"DriveCleaner rogue security software - not recommended
XDriveDefenderGDC.exe"DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
Udrkly16j"rundll32.exe drkly16j.dll ServiceCheck"
UdRMON SmartAgentSmartAgt.exe"Part of the network monitoring program group for 3Com NIC cards. See here for more info"
XDrProtectionDrProtection.exe"DrProtection rogue security software - not recommended"
UDrvIconDrvIcon.exe"""Vista Drive Icon changes the drive icons shown in Windows ""My Computer""
?DrvListnrDrvListnr.exe"Analog Devices SoundMAX soundcard related. What does it do and is it required?"
Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
UDrvMon.exeDrvMon.exe"Alcor drive monitor software"
Xdrvnetwdrvnetw.exe"Added by the BROGGER-B TROJAN!"
Xdrvrmanagerdrvrquery32.exe"Added by the BOOHOO WORM!"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
Xdrv_st_keyhidn.exe"Added by the BEAGLE.FF WORM!"
XDrWatsondrwatson_.exe"Added by the LOHAV-S TROJAN!"
XDrWatsondrwatson_32.exe"Added by the LOHAV-S TROJAN!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
NDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
NDSL Monitorspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
YDSLagentexeDSLagent.exe"Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
Ydslmondslmon.exeSagem DSL modem related. Apparently needed to detect the modem
YDSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSSdssagent.exe"Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
?DSSSGENSdssagens.exe"??"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UDT 11Mbps WLAN PC Card StationDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT 11Mbps WLAN USB StationDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
NDTAgentDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
UDualCoreCenterStartUpDualCoreCenter.exe"Unified control center for overclocking both the graphics card and the CPU
?Duane Reade Insert DetectInsDetect.exe"Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XDuwee wong CerbonCirebons.exe"Added by the BHARAT.A WORM!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
?DVDAgentDVDAgent.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
NDVDLauncherDVDLauncher.exe"Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
NDVDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
UdvHighMemcfgmng32.exe"Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
YDvpInitExeDvpinit.exe"Command Antivirus related"
UDVSyncdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
UDWHeartbeatMonitorDWHeartbeatMonitor.exeDWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
NDwlClientsupport.exeDownload manager for Dell support alerts
Xdwqblwppx.exe[random].exe"Okcashbackmall adware"
Xdwqblwpvl.exe[random].exe"Okcashbackmall adware"
Xdwqblwrsq.exe[random].exe"Okcashbackmall adware"
UDWQueuedReportingdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
XDW_Startrwwnw64d.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
XDxsys*.exe [* = random number]"Added by the DEXTER.A WORM!"
Xdxdiag diagnosemsidxdia.exe"Added by a variant of the RBOT WORM!"
Xdxdll32ntxdll.exe"Added by the GAOBOT.CPX WORM!"
XDxLoadDX3DRndr.exe"Added by the GIBE.B WORM!"
XDynamic DHCPdydhcp.exe"Added by the RINBOT.B TROJAN!"
XDynamic Dns Binarydynitora.exe"Added by the RBOT-WT WORM!"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
XDynamic Link Library loaderLoader32.exe"Added by the KOL TROJAN!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
XDynHttp Dns Binarydynizari.exe"Added by a variant of the RBOT WORM!"
UDynSiteDynSite.exe"DynSite - dynamic DNS client
UDynu Basic Clientdynubas.exe"Dynu online dynamic IP update client. Useful when using a dial up modem"
UE-colorIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
NE-Color RegistrationSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
XE-nrgyPlusE-nrgyPlus.exe"Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
Ue-Surveiller Stationestation.exe"ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
NE6TaskPanelTaskPanl.exe"Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
XEac Downloaddownload.exe"Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
UEACLEANeaclean.exe"For Compaq PC's. Easy Access button support for the keyboard"
XEac_Cnrycanary.exe"Added by the CANARY TROJAN!"
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
UEanthologyAppEANTHO~1.EXE"eAcceleration Stop-Sign security software related. Previously not recommended
UEanthologyAppeanthology.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanthology_install.exeeanthology_install.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertsys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertEANTHO~1.EXE"eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted
Ueanth_system_patchersys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
NEarthLink ToolBar 5.0etoolbar.exe"EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar
NEasy Start Buttonesb.exeProvides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
XEasyDates_nlEasyDates_nl.exeAdult content dialler
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup
NEasyNetworkMcENUI.exe"McAfee's EasyNetwork user interface - ""enables secure file sharing
XEasySpywareCleanerEasySpywareCleaner.exe"EasySpywareCleaner rogue spyware remover - not recommended
UEasySync ProXCPCMenu.exe"""IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAutoDetect.exe"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasyTuneIIIEasyTune.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneVGUI.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
UeBayToolbareBayTBDaemon.exe"eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
NeBotDownloadWizard.exe"eBot from Digital River - ""helps ensure your computer always has the latest technology
UECentergtb.exeDell E-Center/Google Toolbar related
NECenterEULALauncher.exeEnd User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
?EDFcsndiscfcsn.exe"Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
UeDonkey2000edonkey2000.exe"File sharing network - not recommended as the free version of this application should be avoided as it installs
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
UEee DockingEee Docking.exe"Intuitive shortcuts for easy access to digital content
NEEventManagerEEventManager.exe"Part of the Epson Creativity Suite supplied with their multi-function printer/scanners
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications
NeFax Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
UeFax Tray MenuJ2GTray.exe"System Tray access to eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.3J2GTray.exe"System Tray access to version 3.3 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.5J2GTray.exe"System Tray access to version 3.5 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 4.0J2GTray.exe"System Tray access to version 4.0 of eFax Messenger from j2 Global Communications
NeFax.com Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
UEFI Job Monitor"[path] efjm.dllrun"
Xegikugunapolecy.exe"Added by the SDBOT.AOE WORM!"
UEicon NetworksLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
UEicon TechnologyLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
Xeixfichina.bat"Added by the WCUP.A WORM!"
UELBERTRicoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
UELBERT_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
UElectron MicroscopeEMIII.exe"Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home
XElementElement.txt"Added by the ELEM TROJAN!"
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
NelmElmenv.exe"ViaTech eLicense for securing
XELNKProxysmproxy.exe"Surfmonkey adware"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
UELSBLaunchELSBLaunch.exe"EarthLink SpamBlocker"
UeMachines eBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
YEmail Protectionemlproxy.exe"AntiVirus Quick Heal - E-mail protection"
YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
XeMessengeremsn.exe"Added by the RBOT.AHO BACKDOOR!"
Xempine121307.exe"Delfin Media Viewer adware related"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
?Empowering Technology LaunchereAPLauncher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
?EmpoweringTechnologyFramework.Launcher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
NeMusicClient SystrayeMusicClient.exe"eMusic MP3 download software"
NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
XenBrowser[name of file]"WINBO adware"
?encapsulated command toolwintr.com"??"
NEncarta Dictionary QuickshelfQSHLFED.EXE"Provides quick access to Encarta's Dictionary features?"
NENCMONITORmonitor.exeThe Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
NEncoder AgentWMENCAGT.EXE"MS Windows Media Encoder
UEncompass_ENCMONTRENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
?ENCSurfsurfboard.exe"??"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
XEnergyPlugInEnergyPlugin.exe"EnergyPlugin adware variant"
Uenginecs2enginecs2.exe"Cyber Sentinel - internet filtering software"
YEngUtilEngUtil.exe"Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine
XEnh Win Updtenhupdt.exe"Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
Xenhance32enhance32.exe"Added by the CRYPTER.A TROJAN!"
NEnigmaPopupStopEnigmaPopupStop.exe"Part of Enigma SpyHunter - not recommended
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
?ENSMIX32.EXEENSMIX32.EXE"Sound card driver. Is it required?"
UEnsoniqMixerstarter.exe"Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
UEntbloess 2Entbloess2.exe"Related to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Exposé
UEnterprise HarmonyrsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
UEnterra Icon KeeperIcnKeepr.exe"Icon Keeper - ""tool to save and restore icon positions on the desktop"""
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
YEnvyHFCPLEnMixCPL.exe"VIA Envy24 PCI Audio Controller driver"
UeonemngeOneMng.exe"eOne Manager
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UePowerManagementePM.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Status Monitor 3E_[various].EXE"Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C45 SeriesE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C66 SeriesE_S4I0S2.EXE"Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status
UEPSON Stylus C67 SeriesE_FATIAAL.EXE"Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C87 SeriesE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3100E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status
UEPSON Stylus CX3200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5400E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo 2200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status
UEPSON Stylus Photo 825E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
UEpsonPhotoStarterEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this
XEptrnopdb.exeAdded by an unidentified WORM or TROJAN!
?EquipmenEquipmen.exe"??"
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceeRAgent.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
XErrCleanSysRep.exe"ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
NError NukerErrorNuker.exe"ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required"
Xerrorhandlererrorhandler.exe"ErrorHandler adware"
XErrorProtector Freeertmain.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
UERUNT AutoBackupAUTOBACK.EXE"ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
UeSnipsClientGW.exe"eSnips Client Gateway from eSnips"
XEspecialDeneca.bat"Added by the DELUZ VIRUS!"
NESPN BottomLinebline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop
?ESS DaemonEssd.exe"Related to an ESS based soundacard. Is it required?"
?ESSNDSYSESSNDSYS.EXE"Related to an ESS based soundacard. Is it required?"
UEssSpkPhoneessspk.exe"ESS Technologies Call waiting
?eSupIniteSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
Xetbrunelit***32.exe [* = random char]"EliteBar adware"
UeTCertMangereTCrtMng.exe"eToken Certificate Manager from Aladdin Knowledge Systems
NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEthernet Linkingethernet.exe"Added by a variant of the IRCBOT TROJAN!"
XEtrafficJavaRun.exe"TopMoxie adware"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XeTrust Realtime Monitorrealmon.exe"Added by the LAZAR.B TROJAN!"
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
?Event Logeventlog.exe"??"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Reminderpmremind.exe"Event reminder for calendar dates
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
Neventmgreventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Xeventwvreventwvr.exe"Added by the COSIAM_G TROJAN!"
UEVGAPrecisionEVGAPrecision.exe"EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible
UEvidence Cleanerecleaner.exe"Evidence Cleaner cleans up tracks left by your PC and Internet activities"
NEvidence Eliminatoree.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
UEvoluent Mouse ManagerEvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
UEvtMgr6Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
Yewido anti-spywareewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
XEwthtasn.exe"PurityScan adware"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
NExcite PlatformExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
?Excite Private Messenger Pipex8impipe.exe"??"
NExciteAssistantEXEASSISTANT.EXE"With Excite Assistant
XExeName32Warm.scr"Added by the SCOLD WORM!"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
UExif LauncherExiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
UExif LauncherQuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
?exmonhpimoniter.exe"Some kind of hp digital camera maybe or a photo smart connection probe?"
XExnexn.exe"Added by the IRCBOT.RJ WORM!"
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
NExtender Resource MonitorRMSysTry.exe"Related to Windows Media Center from Microsoft"
XExternal DependenciesExternal.exe"Added by the MYTOB.EC WORM!"
XExtra AntivirusExtraAV.exe"Extra Antivirus rogue security software - not recommended
UExtraDNSExtraDNS.exe"ExtraDNS - DNS configuration tool"
NExtraFilmHemmaAgentAgent.exe"ExtraFilm Photo Assistant"
?Extranet AutoDialAutoExt.exeNortel Networks Contivity Extranet Switching Software
?ExxtremeHelperDemonexxdemon.exe"Creative Exxtreme graphics card related?"
NEye Tide Launcheroneeyetideone.exeNascar wallpaper
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
UEZ-DUB FinderEZ-DUB.exe"Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
Nezagentezagent.exe"EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
NEzButtonEzButton.EXEEZbutton is a quick launcher for the Media player app that comes with certain laptops
UEZEJMNAPEzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
?EZNORUNEZNORUN.EXE"Easy Internet related?"
NEzPrintezprint.exe"Lexmark Fast Pics - helps users of their printers to enhance
YezPS_PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UEzTunedthtml.exe"EzTune from Gateway. Rebranded version of Display Tune from Portrait Displays
XeZulaMaineZulaMain.exe"eZula TopText adware"
XeZuluMaineZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
UE_S23E_SICN03.exe"Epson printer status monitor - for checking ink levels
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
Xfftkclean.exe"FlashEnhancer adware"
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
YF-Secure TNBTNBUtil.exe"F-Secure antivirus"
?f23mxinsf23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
Xf2install.exef2install.exe"Added by the IEFEAT-I TROJAN!"
UF5D7050v3Belkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UF5D8001Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
UF5D8011Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
UF5D8055v1Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
UF5D8071Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
UF5D9010Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
UF5D9050Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
?fapmonfapmon.exe"Fair Access Policy monitor for DirecPC/DirecWay internet access"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
XFast Searchsvcnv.exe"Homepage
XFast startNtut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
UFastTVSyncFastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
Xfcrunfc.exe"Added by the CAMPURF WORM!"
XFCEngineFCEngine.exe"CASClient adware"
XFCManFCMan.exe"FCHelp adware"
XFdaemon securityfsecur.exe"Added by the SDBOT.KXO WORM!"
XFdr Command Modulesp2.exe"Added by the SDBOT.WP WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
XFestplattenReinigerGDC.exe"FestplattenReiniger
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XFile-Sharing Wizardshwizard.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFileFreedom_Pluginwtm.exe"FileFreedom peer-to-peer sharing program"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilenfilen.exe"Added by the VBNAM-A WORM!"
Xfilenamefilename.exe"Added by the VB.FSY TROJAN!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFindfind.exe"Added by the OPANKI WORM!"
NFind FastFindfast.exeFrom older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
Xfindfastfindfast.exe"Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
Xfindfast.exefindfast.exeIdentified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
XFindHack[path to worm]"Added by the KELVIR-BA WORM!"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFirevall Administratingrndll.exe"Added by the PUSHBOT-B WORM!"
XFirewallwmlaunch .exe"Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
XFirewallwmlaunch .exe"Added by the ELIPTER.D WORM!"
XFirewallctfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
Xfirewall 2008logoneui.exe"Added by the SILLYFDC WORM!"
XFirewall Administratinginfocard.exe"Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
Xfirewall_antifirewall_anti.exe"Added by the NETDENY-B TROJAN!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFirst Home Pagehttp://find.naupoint.com"Naupoint browser hijacker"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
XFixnicevcvw.exe"Added by the SDBOT TROJAN!"
UFjMenuFjMenu.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
NfkSysMonfksysmon.exe"fkWrae SysMon - system monitor - ""displays the current memory consumption
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Mediaskxs��'�'%''msn'�%'fix''.exe"Added by the AGENT.ZOY TROJAN!"
?FLASH32#NAME?"??"
UFlashEncFlashEnc.exe"Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission
XFlashget Download ManagerFlashget.exe"Added by the RBOT-AGZ WORM!"
NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
XFlash_Player_Installying.exe"Constructor VC2000 malware"
XFlenCPYflencpy.exe"FlashEnhancer adware"
UFlingRunfling.exe"Fling - free FTP software from NCH Software"
UFLMMEDIONMOUSEmouse32a.exeMouse utility for a Medion branded Fellowes mouse
XFlnCPYflncpy.exe"FlashEnhancer adware"
XFLooDNeTFLooDeR.exe"Added by the ENDOOL TROJAN!"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
Xflpycntlflpycntl.exe"Added by the CRYPTER.C TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
Xfmnwebassistfmnwebassist.exeAdware popup generator
Xfnmwebassistfnmwebassist.exe"WinPL adware"
Xfofficenm.exe"Added by the DELF-CB TROJAN!"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
XFontboot.exe"Added by the AGENT-LZW TROJAN!"
XFont Viewerfontviewer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFontFixfontfix.exe"Added by an unidentified VIRUS
NfontnavFontNav.exe"Font Navigator from Bitstream Inc. - a font management utility"
XFontsLoaderldfnt32.htaUnidentified malware
XFONTVIEWFONTVIEW.EXE"Added by the OPASERV.T WORM!"
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
XForceShow"rundll32.exe QaBar.dllForceShowBar"
NForget Me NotAGRemind.exe"Calendar reminder part of Broderbund's American Greetings® CreataCard®"
UforteManagerdthtml.exe"forteManager from LG. Rebranded version of Display Tune from Portrait Displays
YFortiClientFortiClient.exe"Fortinet security systems are the new generation of real time network protection systems"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
NFotoStation Easy AutoLaunchFotoStation Easy AutoLaunch.exeInstalled with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
Xfoxdhfoxdhend.exe"Added by the MENGHUAN TROJAN!"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
XFramework module libraryinfocard.exe"Added by the BUZUS.AYX TROJAN!"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NFree Download Managerfdm.exe"""Free Download Manager"" - see here"
?Free Downloads Monitorfdcmon.exe"??"
XFreeAttentioneqsefeqe.exeAdded by an unidentified WORM or TROJAN!
NFreebie NotesFreebieNotes.exe"Freebie Notes by Power Soft - create electronic notes (stickers)"
UFreeMemVn2FreeMem.exe"FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
NFreePDF Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFreePDF_Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFriendlyWebQuick-LaunchSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
?FRITZ!DSL StartcenterStCenter.exe"FRITZ! ISP software ""StartCenter"" User interface that allows you to manage
NFromine WinPopupwinpopup.exeInstant Messenger program
Xfrunderc32xz.exeAdded by an unidentified TROJAN!
Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
XFS Agentfagent.exe"Added by the VOLVER-B TROJAN!"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Xfstsvc"rundll32.exe fstsvc.dllstart"
Xftkftkclean.exe"FlashEnhancer adware"
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
NFTPManagerFTPDM.exe"""Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another
Uftutil2"rundll32.exe ftutil2.dll SetWriteCacheMode"
UFujitsu Hotkey UtilityIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
UFujitsu MenuFjMnuIco.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
XFunFun.exe"Added by the COIDUNG-A WORM!"
NFusionHdtvTrayFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
UFusionRCFusionRC.exe"Remote control manager for DVICO FusionHDTV"
UFusionRemoteFusionRc.exe"Remote control manager for DVICO FusionHDTV"
NFusionTrayAgentFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
YFveNotifyfveNotify.exe"Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista
XFW Managerfwcheck.exe"Added by the DELBOT-H WORM!"
XFWDMON.EXEfwdmon.exe"Added by the PROXY-S TROJAN!"
Yfwenc.exefwenc.exe"Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up
XFwr Command Modulefwr.exe"Added by the SDBOT-PP WORM!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
Xgabougoolnounina.exe"Added by the AGENT-JVX TROJAN!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
Xgah95on6gah95on6.exe"ShopAtHome/SAHagent adware"
UGainwardTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
XGames Accelerationsvshost.exe"EasySearch adware"
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTB"Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
NGameSpotkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
Xgangstagangsta.exe"Added by the RIMA.A BACKDOOR!"
UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
NGateway Extended WarrantyGWCares.exeGateway Extended Warranty reminder
UGazelDisplaygsyno.exe"BT Digital Access USB - Gazel ISDN installation System Tray icon"
YGBMHome7AgentGBMAgent.exe"Genie Backup Manager Home 7 - backup software"
YGBMLite7AgentGBMAgent.exe"Genie Backup Manager Lite 7 - backup software"
YGBMPro7AgentGBMAgent.exe"Genie Backup Manager Pro 7 - backup software"
YGBSpaceManSpaceMan.exe"GreenBorder - secure your browsing activities on the internet"
?GCC Remindergccrem.exe"Associated with AcraMax Greeting Card Creator. Is it a registration reminder?"
XGddlib"rundll32.exe gddlib.dllstart"
Xgdien32gdien32.exe"Added by the SINGU-P TROJAN!"
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
Xgencrootgencroot.exe"Added by the SDBOT-AED WORM!"
UGene USB MonitorUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
XGeneral AntivirusGenAvir.exe"General Antivirus rogue security software - not recommended
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xgeneral ml097egeneral.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
YGenie USB MonitorUSBmonitor.exePort monitor for an external USB hard drive. Required to enable access to the drive
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
YGetcaInfoMyCa.exe"Monitor for a Belkin USB Wireless adapter"
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UGetRight - Tray Icongetright.exe"Entry added with older versions of the GetRight download manager from Headlight Software
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XgetwinwinB_.exe"Added by the BANKER-HS TROJAN!"
Xgfxtray"rundll32 ctccw32.dllfindwnd"
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
UGiganews AcceleratorGiganewsAccelerator.exe"Giganews Accelerator from Giganews
YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
XGinaDllntgina.dll"Added by the ANIG.A WORM!"
?GisdnLoggisdnlog.exe"BT Digital Access USB"
XGLF Network Lan MonitorNPFMNTOR.exe"Added by the RBOT-AGY WORM!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
?gluongluon.exe"In a gluon/bin sub-directory"
UGnetmousgnetmous.exe"Genius mouse driver - required if you use non-standard Windows driver features"
UGNETMOUSEgnetmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
?gnubgnub.exe"??"
XGo And Startsvdll32.exe"Added by the RBOT.AI BACKDOOR!"
XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
UGoBackGBMenu.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGoBack Tray IconGBTray.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
XGoldenAntiSpypgs.exe"GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
UGoogle IME AutoupdaterGooglePinyinDaemon.exe"Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
NGoogleDCClientGoogleDCC.exe"Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser
UGoogleToolbarNotifierGoogleToolbarNotifier.exe"Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
Xgotnewupdate000.exegotnewupdate000.exe"Added by the FAKEAV-BGA TROJAN!"
UGoTrustedGoTrusted Secure Tunnel.exe"""GoTrusted is the fast
Xgovurarope"Rundll32.exe retasevo.dlls"
XGPLv3[random name].dll"Vundo adware"
Xgpmcewindow.exe"Added by the VB.CK WORM!"
XGraphic Loaderntvdm32.exe"Added by a variant of the RBOT WORM!"
XGraphic Updateopenglx.exe"Added by the IRCBOT.AMU WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
XGreatDefenderGreatDefender.exe"GreatDefender rogue security software - not recommended
XGreatDefender.exeGreatDefender.exe"GreatDefender rogue security software - not recommended
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
XGremlinintrenat.exe"Added by the DOOMJUICE WORM!"
Xgrgtgvgb.exe[random].exe"Added by the AGENT-EBF TROJAN!"
Xgrindersgrinders.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
UGrooveMonitorGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
UGrooveMonitor UtilityGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
UGroupWise PDA Connect - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - GrpWseAgnt.exe"GroupWise PDA Connect PDA synchronisation utility - from Novell"
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
NGrpConvgrpconv.exe"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
NGsiconexeGsicon.exe"ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
?GsiFinal"rundll32 gspndll.dllpostInstall final"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
NGSOrganizerGSOrganizer.exe"GoldenSection Organizer (now WinOrganizer - personal information manager)"
XGuardCenterGuardCenter.exe"GuardCenter rogue security software - not recommended"
YGuardGui ApplicationGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UGuardianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
Xguarnsetguarnset.exe"Adlogix adware"
UGuruNetGuruNet.exe"GuruNet lets you click on any word on your screen to get the relevant information you want"
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
Xgvagfxjrundll32 ...gvagfxj.dll"Unidentified adware
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
NGWInkMonitorGWInkMonitor.exe"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink
Xgwizntsystem.exe"Added by the NITWIZ.A TROJAN!"
UH/PC Connection AgentWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
Xhachimitsu-lemonhachimitsu-lemon.exe"Added by the HACHILEM TROJAN!"
Xhagentavp.exe"Added by the ""Herman Agent"" remote access TROJAN!"
UHalifaxHowardClusterskinkers.exe"""Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
UHaMFrontPanelhampanel.exe"Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget
UHandy Backup 3.9hbagent.exe"Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
XHanUpdatehanz.exe"Added by the RBOT-GLJ WORM!"
NHard Disk SentinelHDSentinel.exe"Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
UHardware Sensors Monitorhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
UHarmony 98 - CasioOrgCasAgnt.exe"Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XHATAPE[path to trojan]"Added by the BANKER-QF TROJAN!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
UHawking HWU54G UtilityHWU54G.exe"Wireless management utility for the HWU54G Mini Wireless-G USB Adapter from Hawking Technologies
UHawking Wireless UtilityHWU8DD.exe"Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies
XHbinstHbinst.exe"Hotbar adware"
NHC Reminderhc.exe"For Compaq PC's. Help Compiler
Xhcenhcen.exe"Added by the SMALL.LR TROJAN!"
Uhcentertgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Uhcenterhcenter.exe"Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Xhclean32.exehclean32.exe"Wareout - malware masquerading as a spyware and dialer remover"
UHcontrolhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
UHControlUserHControlUser.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
UHDDControlGuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UHDDControlGuard.exeHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
Xhe3bbcff"rundll32.exe he3bbcff.dllEnableRunDLL32"
Xhe3e3fc4"rundll32.exe he3e3fc4.dllEnableRunDLL32"
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
XHelloInthello3.exe"Added by the CASAL.A TROJAN!"
Xhelloworldnb32ext2.exe"Added by the MYDOOM.BV WORM!"
Xhelloworldnb32ext3.exe"Added by the MYTOB.JT WORM!"
Xhelloworld3nb32ext4.exe"Added by the RITDOOR.A WORM!"
XHelpWizardnil.exe"Added by the BANCOS-BCZ TROJAN!"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
XHELPERgreece_nm.exe"AsdPlug premium rate adult content dialer variant"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHELPERnew_zealand.exe"AsdPlug premium rate adult content dialer variant"
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
XHELPERcanada.exe"AsdPlug premium rate adult content dialer variant"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
Xhelper.dllrundll32.exe [path] helper.dll"CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
Xhen[filename].exe"Added by the TARNO.G TROJAN!"
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
UHermes MessengerDGDRHE~1.EXE"A LAN messenger alternative to WinPopUp - Digital Dreams Software"
XHewlett Packard Managerhpmanager.exe"Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
NHewlett Packard RecorderRemind32.exeHP multifunction registration
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XHhjg5jfd93dftdfwinlogan.exe"Added by the ERTFOR.A TROJAN!"
Xhhtnsnrnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
?HiberMonitorHCount.exe"??"
UHibernationhib32.exe"Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
Xhidenhiden.exe"Added by the AGENT-IW TROJAN!"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHideStyleAnte Browse Trust.exe"IE toolbar taking you to Lop.com. If the exe is running
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
XHidup_SusahPembantu.exe"Added by the SILLYFDC.BDM WORM!"
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
YHighPoint ATA RAID Management Softwareraidman.exe"HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
UHijackThis startup scanHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
XHKEYokrunlli32.exe"Added by the QQPASS-U TROJAN!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
XHLcleanuphlsetup2.exe"LinkReplacer/FFinder adware"
UHmonitorHmonitor.exeHardware sensor monitoring program. Only required if you overclock your system and want to check on the status
Xhohohhahaournik.com"Added by the IRCFLOOD.AL BACKDOOR!"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
?HomeCentre WakeUpLGWAKEUP.EXE"Associated with the no longer supported Xerox HomeCentre printer/scanner"
XHomeland NetworkHomelandNetwork.exeHomeland Network Notifier - pops ads
Xhomepage.monitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
UHondaHelperHondaHelper.exe"Part of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod® in you car"
?Honorhonor.exe"??"
UHornetMonitorMntrHrnt.exe"Hornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network"
YHorngTech4Dbally4d.exeHorngTech 4D mouse driver
XHostN/A"Added by the POPDIS or STARTPAGE.F TROJANS!"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UHostManagerAOLHostManager.exe"Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
XHostname Manager Serverhost32srv.exe"Added by a variant of the RBOT WORM!"
XHostren.exeHostren.exe"Added by PWS.BANKER.F
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
UHot CornersHotc.exe"Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
XHOT FIXQOching.exe"Added by the WOOTBOT.VH WORM!"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
XHot InsideHottest Story Ever.exe"Added by the BHARAT.A WORM!"
UHot Key Kbd 2690 DaemonSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XHotAction_hrhotaction_hr.exe"Added by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""HotAction_hr"""
XHotbarHbinst.exe"Hotbar adware"
XHotbarHbOEAddOn.exe"Hotbar adware"
XHotbarOEOEAddOn.exe"Hotbar adware"
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
Xhotfixmsnnmaneger.exe"Added by the WOOTBOT.AF WORM!"
UHOTFOON2hotfoon4.exe"Related to Hotfoon - a developer and provider of Internet Telephony technology based on LTP (Lightweight Telephony Protocol)"
NHotSync Managerhotsync.exeInstalled when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
XHPmon.exe"Added by the SILLYFDC WORM!"
UHP AutoIndexerhppautoindexer.exe"Installed by HP multi-function printer driver software
Xhp centerBACKWEB-*****.exe"See here - ""messaging service that automatically sends you support information
Nhp center UIShadowBar.exe"User Interface for HP Center - see here"
NHP Component Managerhpcmpmgr.exe"Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
UHP Digital Imaging Monitorhpqtra08.exe"System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera
UHP Display Settingshpdisply.exe"Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
UHP Gaming Keyboardrazerhid.exeHP VoodooDNA Gaming Keyboard (powered by Razer) driver - required if you use the additional features and programmed keys/macros
NHP Image Zone Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
NHP Info Express??"On HP PCs
UHP Instant Supportmatcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
?HP Network Registry Agenthpnra.exe"??"
XHP Photo ManagerHPPhotoManager.exe"Added by the SDBOT.AXU WORM!"
NHP Precision Scanhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
NHP Presentation ReadyPresRdy.exeHP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
UHP RecordNow??"From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."""
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
UHP SchedIndexerhppschedindexer.exe"Installed by HP multi-function printer driver software
?hp Silent ServiceHpSrvUI.exe"HP related"
NHP Simple TraxHpcron.exeSupplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
UHP TV NowHpTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
?HP Visualize InitHpVisIni.exe"HP Visualize software related. What does it do and is it required?"
NHP-Aio FlightRemind32.exeHP multifunction registration
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAIO_PrintFolderMgrhpoopm07.exe"Directly from HP: "This process has one purpose - detects if the device moves to a different port
UHPDAgentHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Nhpgs2wndhpgs2wnd.exe"Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
UHpha1monHpha1mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHpha2monHpha2mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.1 to 3.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHpha3monHpha3mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.3.138 to 3.4.13 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon03hphmon03.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. Known to cause 100% CPU load in some cases. Only needed if you use this feature
UHPHmon04hphmon04.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 4.0 to 4.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
Uhphmon05hphmon05.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 5.0 to 5.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon06hphmon06.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 6.0 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
UHPLogiFinderhp_finder.exeHP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
XHPNThpdll.exe"Malware downloader - detected by Kaspersky as the VB.KU TROJAN!"
Nhpoddt01.exeN/A"Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software
XHpPrinterhpserver.exe"Added by the CMJSPY-W TROJAN!"
?hpqcmonhpqcmon.exe"From HP and related to digital imaging"
?hpqSRMonhpqSRMon.exe"Related to HP Digital Imaging products. What does it do and is it required?"
UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
?hpScannerFirstBootscannerfb.exe"HP scanner related"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
NHPUProvenTactics.exe"Proven Internet Marketing software"
UhpWirelessAssistantHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
XHP_runnerfront.exe"Added by the SILLYFDC WORM!"
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
UHSONHSON.exeToshiba HotStart button support for instant-on entertainment on their laptops
UHSTranshstrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
?HsuGuiControlHsuGuiControl.exe"Part of the Starband Internet satellite client. What does it do and is it required?"
UHtinpdor.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
XHTTP Tunneling Servermstunnel.exe"Added by the RBOT.EDL WORM!"
Xhttp://www.lienvandekelder.beLienVandeKelder.exe"Added by the MYTOB-AZ WORM!"
Xhttp://www.lienvandekelder.beLien Van de Kelder.exe"Added by the MYTOB-AP WORM and variants!"
Xhttp://www.lienvandekelder.beLien Vande Kelder.exe"Added by the MYTOB-AQ WORM!"
Xhttp://www.lienvandekelder.beLien vd Kelder.exe"Added by the MYTOB-M WORM!"
Xhttp://www.lienvandekelder.beLien.exe"Added by the MYTOB-CZ WORM!"
Xhttp://www.lienvandekelder.beLientjeuh.exe"Added by the MYTOB-P WORM!"
Xhttp://www.lienvandekelder.beLienVdK.exe"Added by the MYTOB-U WORM!"
Xhttp://www.lienvandekelder.beVan de Kelder Lien.exe"Added by the MYTOB-BF WORM!"
Xhttp://www.lienvandekelder.beWe Love Lien Van de Kelder.exe"Added by the MYTOB-CV WORM!"
Xhttp://www.lienvandekelder.comLien Van de Kelder.exe"Added by the MYTOB-EQ WORM!"
Xhttp://www.lienvandekelder.com/LienVandeKelder.exe"Added by the MYTOB-EO WORM!"
Xhttpdc_pan.exeAdded by a variant of the DELF-A TROJAN!
Xhttpddeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpds_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpddeamon.exe"Added by the TACTSLAY.C TROJAN!"
UHughesNet Toolsmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XHvewsveqmgANACON.EXE"Added by the NACO.A WORM!"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
Xhxadsec[path to trojan]"Added by the ADCLICK-AP TROJAN!"
UHydarVisionDesktopManagerdesk95.exe"ATI's HydraVision desktop management software
UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionDesktopManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UHydraVisionViewportviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionViewPortHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XHyper Startinstantmsgrs.exe"Added by the RBOT-NH WORM!"
XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
XI am not Ranky. I am eTunnel!disney.exeAdded by an unidentified WORM or TROJAN!
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
Ui8kfanguii8kfangui.exeGraphical interface for fan speed control
UIAAnotifIaanotif.exe"Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes
XIamnacho On Irc.MusIrc.com Is a Homosexual!XBox64.exe"Added by the RANDEX.Y WORM!"
?IaNvSrvIaNvSrv.exe"Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
Xibin[path to trojan]"Added by the PERDA-C TROJAN!"
YIBM Client Securitycerttool.exe"Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk)
NIBM Client Security Softwarecsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
YIBM Password Managerpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
NIBM RecordNow!RecordNow.exe"IBM customized version of the RecordNow! CD-writing utility from Sonic Solutions"
UIBM ThinkPad EasyEject Support ApplicationEzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NIBM ThinkPad EasyEject Tray UtilityEZEJTRAY.EXE"System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NIBM ThinkPad Tray UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
UIBM ThinkPad UtilityNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
UIBM TrackPoint Accessibility Featurestp4ex.exe"Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound""
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
?Ibmmon.exeIbmmon.exe"??"
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
?IBMUltraBayHotSwapSoundIBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
UIBWin Background processIBackground.exe"IBackup for Windows"
UIBWin MonitorIBMonitor.exe"IBackup for Windows"
UiCalendarCalendar.exe"Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather
Xicccomp[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
XICcontroliccontrol.exe"ICcontrol premium rate adult content dialer"
Xicdd7ee6"rundll32.exe icdd7ee6.dllEnableRunDLL32"
Xicddefff"rundll32.exe icddefff.dllEnableRunDLL32"
NICH Syntheusexe.exe"Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
UiCleaniClean.exe"IEClean - ""advanced
XICManagementmsic32.exe"Added by the MSIC BACKDOOR!"
NiCnNAG.EXE"iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy
NIcon AnimationHDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
NIcon Hearit 95hearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
NIcon Hearit 98hearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIcon ml097eicon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Yiconcacheicon.bat"Related to the Vista Customization Pack"
YICONCLNTiconclnt.exe"APC PowerChute® Personal Edition tray icon"
UICONDESKICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
NIconoidIconoid.exe"Iconoid is a desktop icon manager"
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
XICQICQNET.vbs"Added by the GORMLEZ-A WORM!"
XICQ Agenticq6.exe"Added by the AGENT-FZJ TROJAN!"
XICQ Center[path to worm]"Added by the RANDIN WORM!"
XICQ Hacking ProICQpro.exe"Added by a variant of the NETSPY TROJAN!"
Xicq litewinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XICQ Lite MessengerICQLITE.EXE"Added by an unidentified VIRUS
XICQ Messenger 2002ICQ2002.exe"Added by the SDBOT-ABL WORM!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
UICQMonitorICQMonitor.exe"ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself"
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Visual InterDevczvslmqb.exe"Added by the RBOT-AYP WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
UICSDCLT"rundll32.exe Icsdclt.dll ICSClient"
NID CommanderIDCom.exeCaller ID utility for identifying incoming telephone numbers
Xidecntlidecntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xidlesam[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
NIDManIDMan.exe"Internet Download Manager - download files faster
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
NIDW Logging Toolidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
UIE New Window Maximizeriemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIE**.exe [* = random char]IE**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIE**32.exe [* = random char]IE**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIE-Securityiescan.exe"IE-Security rogue spyware remover - not recommended
XIE-Securitywdscan.exe"IE-Security rogue spyware remover - not recommended
XIE6porn.pif"Added by the RBOT-ATF WORM!"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIEAgent update checkiewatch.exe"Added by the BOMKA TROJAN!"
UIECleanAuxIeboot6.exe"IEClean by Kevin McAleavy - cookie manager
XIEengineIEeng.exe"STARTPAG.AI hijacker"
XIEFeaturesInternetfeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XIehelpersyslaunch.exeOutwar adware downloader
Xiel2cde8"rundll32.exe iel2cde8.dllEnableRunDLL32"
Xielcaabe"rundll32.exe ielcaabe.dllEnableRunDLL32"
XieupdateMCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XiExplore Iniie4uini.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
Nigndlm.exeDLM.exe"IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin
XIinliptl.exe"PurityScan adware"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
UIJNetworkScanUtilityCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
UiKeyWorksIKEYMAIN.EXE"A4Tech wireless keyboard driver and utility"
UIKLrundll32.exe [path] IKL.dll"IKL surveillance software. Uninstall this software unless you put it there yourself"
?ILO_Office_ManagerIntEdReg.exe /OFFMAN"Intense Educational Ltd - Language Office Software. Is it required?"
NiM Start CenteriM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
XImage"rundll32 [path] [trojan filename]Install"
XImage Remote Playerssysvn.exe"Added by a variant of the IRCBOT BACKDOOR!"
NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
XImagePathtaskbarmngr.exe"Added by the SDBOT-XB WORM!"
UImageTunedthtml.exe"ImageTune from Hyundai ImageQuest. Rebranded version of Display Tune from Portrait Displays
NiMarkup ClientiUtil.exe"Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
UImatioimation.exe"Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive"
XIMEconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
UImgIconImgIcon.exe"Displays Iomega icons in Explorer/My Computer
XImMsntimed.exe"Added by the WEBDOR.AK TROJAN!"
UImonitorPlguni.exe"Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection
Ximonitor[path to trojan]"Added by the IMONI-A TROJAN!"
UIMONTRAYimontray.exe"System tray monitoring of fans
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UIMVUIMVUClient.exe"IMVU chat client that allows you to create ""your own avatars who chat in animated 3D scenes"""
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
Xim_autornim_1.exe"Added by the IMAV.A WORM!"
Xim_autornim_2.exe"Added by the BAGLEDL-BO TROJAN!"
YInCDincd.exe"Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3)
NIncMailIncMail.exe"""IncrediMail is an advanced
Xincognitoincognito.exe"Added by an unidentified WORM or TROJAN! See here"
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
XIncredible KeyloggerAdvKeylog.exe"IncredibleKeylogger spyware"
NIncredimailincredimail.exe""IncrediMail is an advanced
NIncredimailIncMail.exe"""IncrediMail is an advanced
XIndex Servicedllhost32.exe"Added by the AGOBOT.CH WORM!"
UIndex WasherWashIdx.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
?IndexerIndexer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
XIndexindicatorIndexindicator.exe"Added by the LAZAR TROJAN!"
NIndexSearchIndexSearch.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
UIndexTrayIndexTray.exe"Part of
UIndicatorUtyIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XINETinetsync.exe"Meplex adware"
XInet DataBaseInetdbs.exe"Added by the QEDS WORM!"
XInet Deliveryinetdl.exe"Inet Delivery adware"
XInet Deliveryinetdl_2.exe"Inet Delivery adware"
XInetapiNetapi.exe"Added by the NETDEVIL.14 TROJAN!"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
Uinetcntrlinetcntrl.exeBsafe Online - internet filter
?InetConfinetconf.exe"??"
UInetdINETD32.EXE"Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
Uinetinfo.exeinetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
Xinetinfomon managerinetinfomon.exe"Added by the DONBOMB.A TROJAN!"
Xinetmgrinetmgr.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XInfeStopInfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
XINFO DATAapc.exe"Added by the RANDON.B WORM!"
UInfo Selectis.exe"Info Select from Micro Logic - personal information manager"
XInfo32xInfo32x.exe"Added by the GEMA TROJAN!"
XInfoData"rundll32.exe ********.dllrealset [* = random char]"
UInfoPenMSNInfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
?Infoplay.exeInfoplay.exe"Written by New Media Properties
XInformation Updateiu.exe"Detected by Kaspersky as the CENTIM.CH TROJAN!"
UInfra-red MonitorIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
Xinfusinfus.exeAdult content dialler
UInfuzerInfuzer.exe"Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XInit[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XInit32Init32.exe"Added by the WINEX.A TROJAN!"
XInitial Pageinstall.exeEasySearch browser hijack installer
YInitialize8x88x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
Xinixsminix32.exe"Added by the AGENT.CKQX TROJAN!"
Xinjobinjobs.exe"Added by the BINJO TROJAN!"
NInk MonitorInkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
NInkWatchInkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
XInomsnmoo.exe"Added by the RBOT-DPM WORM!"
YInoRPCInoRpc.exe"Associated with eTrust Antivirus/InoculateIT"
YInoRTInoRT9x.exe"Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage"
UInoTaskInoTask.exe"Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
?insCOA5insCOA5.exe"??"
XInsiderInsider.exe"Added by the AGENT.KMC TROJAN!"
UInstaAlertInstaAlert.exe"""Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
XInstafinderinstafinder.exe"TopSearch.D adware"
XInstaFinderKInstaFinderK inst.exe"InstaFinder adware"
XInstallInstall.exe"Added by the BANCBAN-HG TROJAN!"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
xinstall32install32.exe"Added by the NUCLEAR.DG BACKDOOR!"
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
UInstallBuddyIbtna.exe"InstallBuddy - automatically translates and installs your desktop documents
XInstallCleanerInstallCleaner.exe"Added by the ANYHOMB.F TROJAN!"
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstallerdial.exe"Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
UInstallstubinstallstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
XInstant Access"rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
XInstant Accessmwsrvacc.exe"InstantAccess premium rate adult content dialer"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XInstant Buzz DaemonIBDaemon.exe"Instant Buzz adware"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
Xinstant messengersinstantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
NInstant Update Centerreminder.exe"Event reminder for calendar dates
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
NInstantAccessINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInstantPleasureXXXinstantpleasurexxx.exeAdult content dialler
NInstantTrayPCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
Xinstitinstit.bat"Added by the OPASERV.H WORM!"
XinstitINSTIT.BAT"Added by the OPASERV.K WORM!"
?InstUtlR.exeInstUtlR.exe"??"
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
Xintdctrridctup20.exe"SafeSurfing adware variant"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
UIntegardTrayIntegardTray.exe"System Tray access to Integardparental control software from Race River Corp"
UIntel Active Monitorimontray.exe"System tray monitoring of fans
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
XIntel Drivercsrs.exe"Added by a variant of the SDBOT WORM!"
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
UIntel PDSpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
UIntel Product Number UtilityIntelProcNumUtility.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
NIntel PROSet Tray Iconpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XIntel system toolhookdump.exe"Added by the SPYRE-H TROJAN!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
XIntel system worksiis.exe"Added by the RBOT.QGA WORM!"
UIntel(R) Common User Interfaceigfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfacehkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
Xintel32.exeintel32.exe"Added by the SmitFraud alias SPYJACK-B TROJAN!"
UIntelAPMClientamclient.exe"LANDesk® Management Suite software component"
NIntelAudioStudioIntelAudioStudio.exe"""Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience"". Audio utility supplied with some Intel motherboards"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xintell32.exeintell32.exe"Added by the SmitFraud alias Desktophijack.C TROJAN!"
Xintell321.exeintell321.exe"Added by the SPYJACK-B TROJAN!"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XIntelliflag_be.exeIntelliflag_be.exe"Intelliflag spyware"
UIntelliPointpoint32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
UIntelliPointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
UIntellitypetype32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
UIntelMEMIntelMEM.exe"Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore
XIntelprcAas3lovu.exe"Added by the SILLYFDC-CG WORM!"
UIntelProcNumUtilitycpunumber.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
YIntelWirelessifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInterceptedSystem[path to worm]"Added by the ANACON-B WORM!"
YInterCheck MonitorIcmon.exe"Part of Sophos ant-virus sofware"
YInterCheckMonitorICMON.EXE"Part of Sophos anti-virus sofware"
XInterdllInterdll.exe"Added by the DELF family of TROJANS!"
XInternal[trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
XInternalregedit.exe /s c[month number]"Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir%
XInternal Memory Filesysintmemory.exe"Added by the RBOT-GKT WORM!"
XInternalSystrayKazza.exe"Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable
Xinternatinternat.exe"Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XInternatsystray.exe"Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
XInternatmsgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
XInternat[trojan filename]"Added by the CMJSPY-Y TROJAN!"
XInternat Confbootconf.exe"Homepage hijacker
Ninternat.exeinternat.exe"Microsoft language selection icon in system tray
XInternat.exeinternat.exe"Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a ""?"" icon wheras this version resides in %windir% and has a ZIP icon"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XInternetInternet.exe"Added by the PWS-CS TROJAN!"
XInternetrecruit.exe"Added by the RBOT-AJG WORM!"
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
XInternetnteusodp.exe"Added by the RBOT-GFJ WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
Xinternetlsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XInternetalm7tas.exe"Added by a variant of the RBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet AntivirusIAvir.exe"Internet Antivirus rogue security software - not recommended
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
UInternet Call DirectorICD.EXE"TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
UInternet Call ManagerICM.EXE"Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Connection Wizardstisvsq.exe"EasySearch adware"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Content PublisherICP.EXE"Added by the RBOT-UD WORM!"
UInternet Disk CleanerCLEARH~1.EXE"""Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
UInternet Download Acceleratorida.exe"Internet Download Accelerator download manager"
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Exploreriexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet ExplorerIExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorerhttp.exe"Added as part of a new potential CWS infection
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet ExplorerIEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
XInternet Explorertwain.exe"Added by the AGENT.BEA TROJAN!"
XInternet Explorer Agentiexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
UInternet History EraserHERASER.exe"Internet History Eraser - deletes your browsing tracks"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Mail and Newsmsqdevl.exe"EasySearch adware"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Optimizeroptimize.exe"Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInternet Security 2010IS2010.exe"Internet Security 2010 rogue security software - not recommended
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet SendMore log.exeUnidentfied adware
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
YInternet Sharing Serveriss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
XInternet Suspentionstory.exe"Added by the WOOTBOT.HV WORM!"
NInternet SweeperSweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
UInternet TimerITIMER.exe"Shareware dial-up connection call cost calculator from Ratsoft"
XInternet Washer Proiw.exe"Internet Washer manages temporary browser files
XInternet.exeInternet.exe"Added by the MAGICCALL VIRUS!"
Xinternet.exeyinyin3345.vbs"Added by the YINI MACRO!"
XInternet2 Optimizerwkfix.exe"Added by a variant of the RBOT WORM!"
NInternetCallsInternetCalls.exe"InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetExplorer32iexplore32.exe"Added by the RBOT-GRA WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
XInternetShieldInternetShield.exe"InternetShield rogue security software - not recommended
UInternetSpyInternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
XInternetWasherProiw.exe"Internet Washer manages temporary browser files
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInternet_Explorer.exeInternet_Explorer.exe"Added by the BANKER-END TROJAN!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
UInternodeUsagemum.exeAustralian ISP's free monthly download meter
XInterntInternt.exe"Added by the PEEPER or CARUFAX.A TROJANS!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIntersoft Msngrintersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
NInterTrust Quick Startit_cpq~1.exe"InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NInterVoipInterVoip.exe"InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UInterWARNinterwarn.exe"InterWARN by Storm Alert Inc. Provides customized
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIntmgrIntmgr.exe"Added by the GEMA TROJAN!"
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
XIntranetintranet.exe"Added by the CHIMOZ.AC TROJAN!"
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
XIntrenatIntrenat.exe"Added by the LEMIR.E TROJAN!"
NIntroducing Media ManagerSPLASHA.EXE"MS Media Manager tour. Not required"
NIntroduction-Registration??"For Compaq PC's. Should only run first time
XIntruderAlertia99.exe"Intruder Alert '99 from Bonzi - spyware"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
YIntuit SyncManagerIntuitSyncManager.exe"Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync
UInventory ScanLDISCN32.EXE"LANDesk® Management Suite software component"
NiobiiobiClient.exe"iobi Home - a mail/voice service by Verizon"
Yiolo AntiVirusioloAV.exe"iolo AntiVirus"
Yiolo Personal FirewallioloFW.exe"iolo Personal Firewall"
UIolo Task AgentTask_Agent.exe"Iolo System Mechanic Task Agent. Scheduled maintenance"
UIomega Disk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega ImIconXPimiconxp.exe"Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system
?Iomega QuickSyncQuicksync.exe"??"
NIomega Startup OptionsIMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
NIomegaWareCOMMANDER.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
UIomon98.exeIomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
UIP Changer 2.0IPChanger.exe"IP Changer 2.0 from Plustech Inc - network configuration management tool"
XIP**.exe [* = random char]IP**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIP**32.exe [* = random char]IP**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
NiPalmmon.exe"Installed with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded"
XIPC Connectionipcconn.exe"Added by the RBOT-AEG WORM!"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
XIpCtrlipcon32.exe"Added by an unidentified VIRUS
?IPHSendIPHSend.exe"AOL related. What does it do and is it required?"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
YIPinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
?iPlusAgent2iAgent2.exe"Related to iriver portable media products. What does it do and is it required?"
Xipmon.exeipmon.exe"Added by the RECERV or R3C.B TROJANS!"
XIpNetworkipnetwork.exeMaxifiles adware
XIpnukerIpnuker.vbs"Added by the INKER.B WORM!"
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
UiPodManageriPodManager.exe"Apple iPod® management software for the iPod® player - updates
Uipointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
?iPrint LPT Redirectornipplpte.exe"Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
NiPrint Trayiprntctl.exe"Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
XipruniPY.exe"iProtectYou spyware"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
YIPSecMonIPSecMon.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
XIpWinsipwins.exe"IPWins adware"
Xipyjywoniz.exe"Added by the SDBOT.BQD WORM!"
Xiqmanager.exeiqmanager.exe"IQ-Manager ransomware copyright scanner - not recommended
Xirassyncirasyncd.exe"IRASSync adware"
Xirc sessionsessionmgr.exe"Added by the SDBOT-ACE WORM!"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
NiRiS AntiVirus Active MonitorWIMMUN32.exe"Iris Antivirus - discontinued
UIRIS_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
UIRIS_XRX_S2PScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
UIrMonIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
?IRPMonitoritcnmon.exe"??"
Xirssyncdirssyncd.exe"SafeSurfing adware variant"
XIrwftp[path to trojan]"Added by the BANCOS-AP TROJAN!"
Xirwftpftpmon.exe"Added by the BANCBAN-BO TROJAN!"
Xisamini.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
Xisamonitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XIsassRenascimentoIssas.exe"Added by the BANKER.GAX TROJAN!"
NISDN MonitorLinksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
UISDNwatchIWatch.exe"FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
XiSecurity applet"rundll32.exe iSecurity.cplSecurityMonitor"
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
UiSpyNOWispynow.exe"iSpyNOW - remote monitoring and surveillance software"
NIsReminderISPopup.exe"Related to GuardWare iShield - this is the registration reminder for the trial version
XISSinet.exe"Meplex adware"
XissEnc32SvrissEnc32.exe"Added by a variant of the RBOT WORM!"