Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
YAHNSDAhnSD.exe"AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis"
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
XAmazingTensAmazingTens.exePremium rate adult content dialler
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
NBabylon TranslatorBabylon.exe"""Babylon-Pro is a powerful information tool that instantly provides relevant information
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
Xbargainsbargains.exe"BargainBuddy adware"
Xbargainsbargainbuddy.exe"BargainBuddy adware"
Xbegins0.exe"Added by the MYTOB-HE WORM!"
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
?btinstbtinst.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
XBullsEyebargains.exe"BargainBuddy adware"
XBullsEye Networkbargains.exe"BargainBuddy adware"
UButton Serverbttnserv.exe"Found on a Compaq PC
XCABCInstallCABCInstall.exe"Ignite Technologies (was CABC) content delivery software"
UCanonSolutionMenuCNSLMAIN.exe"
?cFosInst_Checkcfosinst.exe"cFos DSL Modem driver related. What does it do and is it required?"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
YCleanUpmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XComPlus Applicationstwain.exe"Added by the AGENT.AQO TROJAN!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XConsconsol32.exe"Hijacker - redirects to an adult content portal
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
XCreate A MonstercreateAMonster.exe"Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xcybansoscyban.exe"Added by the TATERF-V WORM!"
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
XDeluxeCommunicationsDxc.exe"Deluxe Communications adware - successor to SurfSideKick"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
UDimensionDimension.exe"Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames
UDimension4d4.exe"Dimension 4 - network time synchronization freeware - starts-up
XDinstdinst.exe"IMIServer/IEPlugin adware"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
?Dixons Insert DetectInsDetect.exe"Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XDm Hrlpns.exe"Added by the IRCBOT.WORM.61673 WORM!"
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
?DNS2GoClientdns2goclient.exe"DNS2Go is a Domain Name System that will make your computer accessible anytime
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
Xdnscleanerdnscleaner.exe"CoolWebSearch parasite variant"
XDNSEDNSE.exe"Part of rogue security tools
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
Xdownsdowns.exe"Added by the BCKDR-MNR TROJAN!"
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
?DSSSGENSdssagens.exe"??"
?Duane Reade Insert DetectInsDetect.exe"Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XDuwee wong CerbonCirebons.exe"Added by the BHARAT.A WORM!"
XDynamic Dns Binarydynitora.exe"Added by the RBOT-WT WORM!"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
XDynHttp Dns Binarydynizari.exe"Added by a variant of the RBOT WORM!"
UDynSiteDynSite.exe"DynSite - dynamic DNS client
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
Ueanthology_install.exeeanthology_install.exe"eAcceleration Stop-Sign security software related. Previously not recommended
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
?ENSMIX32.EXEENSMIX32.EXE"Sound card driver. Is it required?"
UEnsoniqMixerstarter.exe"Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
UExtraDNSExtraDNS.exe"ExtraDNS - DNS configuration tool"
?f23mxinsf23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
Xf2install.exef2install.exe"Added by the IEFEAT-I TROJAN!"
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFlash_Player_Installying.exe"Constructor VC2000 malware"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
Xguarnsetguarnset.exe"Adlogix adware"
UHardware Sensors Monitorhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
XHbinstHbinst.exe"Hotbar adware"
Xhhtnsnrnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
XHot InsideHottest Story Ever.exe"Added by the BHARAT.A WORM!"
XHotbarHbinst.exe"Hotbar adware"
UHP Instant Supportmatcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
UHSTranshstrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XHyper Startinstantmsgrs.exe"Added by the RBOT-NH WORM!"
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
UIJNetworkScanUtilityCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
XInitial Pageinstall.exeEasySearch browser hijack installer
?insCOA5insCOA5.exe"??"
XInsiderInsider.exe"Added by the AGENT.KMC TROJAN!"
UInstaAlertInstaAlert.exe"""Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
XInstafinderinstafinder.exe"TopSearch.D adware"
XInstaFinderKInstaFinderK inst.exe"InstaFinder adware"
XInstallInstall.exe"Added by the BANCBAN-HG TROJAN!"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
xinstall32install32.exe"Added by the NUCLEAR.DG BACKDOOR!"
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
UInstallBuddyIbtna.exe"InstallBuddy - automatically translates and installs your desktop documents
XInstallCleanerInstallCleaner.exe"Added by the ANYHOMB.F TROJAN!"
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstallerdial.exe"Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
UInstallstubinstallstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
XInstant Access"rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
XInstant Accessmwsrvacc.exe"InstantAccess premium rate adult content dialer"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XInstant Buzz DaemonIBDaemon.exe"Instant Buzz adware"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
Xinstant messengersinstantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
NInstant Update Centerreminder.exe"Event reminder for calendar dates
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
NInstantAccessINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInstantPleasureXXXinstantpleasurexxx.exeAdult content dialler
NInstantTrayPCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
Xinstitinstit.bat"Added by the OPASERV.H WORM!"
XinstitINSTIT.BAT"Added by the OPASERV.K WORM!"
?InstUtlR.exeInstUtlR.exe"??"
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
UIomega Disk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
NIomega Startup OptionsIMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
YIPinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XIpWinsipwins.exe"IPWins adware"
Xist service uninstall[random filename]"ISTBar adware related"
Xistinstall zazzer.exeistinstall zazzer.exeUnidentified adware downloader/installer
?Jessops Insert DetectInsDetect.exe"Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
UJMB36X IDE SetupJMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupxInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
XKernelCheckwinser.exe"Added by the TSPY_LMIR.SL TROJAN!"
NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
NKodak Picture Easy *.* Batch TransferPezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
Uktchnsnkktchnsnk.exeHP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
ULanSpeed2LanSpeed2.exeMonitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
YLASTinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
XLicense Managerlicense_manager.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
XLive-Helplmns.exe"Added by the RBOT-GHE WORM!"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
YLogitechCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YLogitechCommunicationsManagerCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
ULogitechVideo[inspector]InstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
ULogMeIn GUILogMeInSystray.exe"RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN
XLogonsaracsrss.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
ULogonStudiologonstudio.exe"WinCustomize LogonStudio - "Allows Windows XP users to edit
YLook 'n' Stoplooknstop.exe"Look 'n' Stop personal firewall"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
Xlspinsigps.exe"Detected by Kaspersky as the VB.KC TROJAN!"
XLTM2winscan.exe"Added by the LITMUS-B TROJAN!"
XLTM2msns6"Added by the LITMUS.C TROJAN!"
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
?lycosInsideLyc_SysTray.exe"Lycos eMail related - what does it do and is it required?"
?M Player Post Installerpostinstallm.exe"??"
XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exe"WhenU.Save adware"
NMacLicenseMacLic.exe"Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks"
NMagicalUnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
NMagUninstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
XMainStartsvcmfte32.exe"Added by the STINX-A TROJAN!"
XMalware Defensemdefense.exe"Malware Defense rogue security software - not recommended
XMatrixScreenSavermss.exeUnidentified malware
XMbarInstall[random filename]"Mirar adware"
Xmbssm32monstu.exe"Detected by AVG as the AGENT.CNM TROJAN - see here"
XMcafee Anti ScanNortonScn.exe"Added by a variant of the RBOT WORM!"
YMcAfee Application Installermcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
UMcAfee.InstantUpdate.MonitorRuLaunch.exe"Instant Updater for McAfee's VirusScan
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
Ymcappinsmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XMDNMDNS.exe"Added by the SPYBOT.JPB WORM!"
XMDNSservice.exe"Mirar adware variant"
XMedia Transfer Protocalsmsstc.exe"Added by a variant of the IRCBOT TROJAN!"
UMediaButtonsMediaButtons.exe"Supports the eject button on the front on the Dell Studio Hybrid desktop. If disabled
UMediafour Mac Volume NotificationsMACVNTFY.EXE"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
XMediaLoads Installerdw.exe"Medialoads adware"
UMegaPanelHSTrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
UMemMonstermemmnstr.exe"MemMonster - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NMGA_CD_Installmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
XMi7sft sdceMNSQ.exe"Added by the RBOT.DMU WORM!"
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftinstall.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft AOL Instant MessengerMSAOL32.exe"Added by the RBOT-AAI WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft Disk Scannerscansdisk.exe"Added by the WOOTBOT.DT WORM!"
XMicrosoft DLL ExtensionsSystemDll.exe"Added by the RBOT-ADV WORM!"
XMicrosoft DLL Verifierwns.exe"Added by the SPYBOT-LA WORM!"
XMicrosoft DNS Host Resolutionhostres.exe"Added by the AGOBOT-MK BACKDOOR!"
XMicrosoft DNS Querymsdns.exe"Added by the AGENT-BS TROJAN!"
XMicrosoft DNSxmdnex.exe"Added by the DELBOT-AI WORM!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Installshieldnundll32.exe"Added by the AGOBOT-AHZ WORM!"
XMicrosoft Instant Messengermsngmsngr32.exe"Added by the SPYBOTER.GEN TROJAN!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Loginswinlogins.exe"Added by the SPYBOT.BCZ WORM!"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft MSN Messengermsnmnsgr.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft msnserumsnseru.exe"Added by the RBOT-APB WORM!"
XMicrosoft MsnSTmsnst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
XMicrosoft OpeionsIEXwe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Server Applacationscli.exe"Added by the RBOT-GAQ WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Sinsupodjiwjf.exe"Added by the RBOT-DN WORM!"
XMicrosoft Sound Technologywinsound.exe"Added by the RBOT-AGG WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft Stuff you knowwinslogin.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WINGS32 ProtocolWinSGR32.exe"Added by the RBOT-APU WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicsorosft Security Centerwcnsfty.exe"Added by the RBOT-AHU WORM!"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
?MM Installsetup.exe"Possibly Money Manager from Moneysoft?"
Xmnklinsmnklins.exe"VX2.Transponder parasite updater/installer related"
UMNSMNS.exe"Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings
Xmnsamnso.exe"Added by the LINEAG-AI TROJAN!"
Xmnsvcmnsvc.exe"Added by the AUTOUPDER TROJAN!"
Xmnsvcspmnsvcsp.exe"Added by an unidentified VIRUS
UMobipocket Reader Notificationsreadernotify.exe"Part of Mobipocket Reader - ""Store all your eBooks
XMONPluginSrIvcsn3monap23.exe"Added by a variant of the RBOT WORM!"
NMonstersoundtrayFreectrl.exeDiamond Multimedia sound card control panel
Xmousedrive.exeinstantmsgrs.exe"Added by the FORBOT-ER WORM!"
NMovielink Manager Uninstallmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
UMPEOCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XMS Domain Name Server DeamonMSDNSD32.exe"Added by the RBOT-CMZ WORM!"
XMS Domain Name SystemMSWDNS32.exe"Added by the RBOT-GKY WORM!"
?MS management consolemms.exe"Suspicious as the legitimate ""Microsoft Management Console"" is ""mmc.exe"" and not ""mms.exe"" and doesn't normally run at startup"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS MSN Menssenger 7.0MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS Unix Binarymsmq2inst.exe"Added by the RBOT-YF WORM!"
XMS Unix Binarymsnq3insller.exe"Added by the RBOT.GXH BACKDOOR!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS WINS Binaryign32.pif"Added by the RBOT-ASB WORM!"
XMS Winsockmsws2_32.exe"Added by the AKBOT-A TROJAN!"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
XMSNctfmoons.exe"Added by the SPYBOT.HI WORM!"
Xmsnmsnsvc.exe"Added by a variant of the SDBOT WORM!"
XMSNmsnsgr.exeAdded by an unidentified WORM or TROJAN!
XMSNinstall.exe"Added by the AGENT-GDO TROJAN!"
XMSN File Sharing Wizardmsnsharewiz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Messengwindns.exe"Added by a variant of the RBOT WORM!"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMsn Servmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicermsnsrv.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Servicermsnservicer.exe"Added by the SLENFBOT.PQ WORM!"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMSN Settingsmsnsettings.exe"Added by the IRCBOT.AWH BACKDOOR!"
XMSN Settings Managermsnsetmg.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Softwaremsnsoftware.exe"Added by the IRCBOT.AWD BACKDOOR!"
XMsn Startupmsnstartup.exe"Added by the ARBOT.AA WORM!"
XMsn Updatermsnplugins.exe"Added by the RBOT-HS WORM!"
XMSN User Servermsnserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Service!msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Svcmsnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMSNPluginSrvcsp6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSNS PLUS XP2msdupd.exe"Added by the RBOT-BCE WORM!"
Xmsnsched2msnsched2.exe"Added by the SPYBOT.NNT WORM!"
Xmsnscr.exemsnscr.exe"Added by the CERTIF-P TROJAN!"
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
Xmsnsgsmsnsgs.exe"Added by the CHEUKO-B TROJAN!"
Xmsnshedmsnshed.exe"Added by the RBOT-YN WORM!"
XmsnsmgrMsnMsr.exe"Added by the LOONY-N TROJAN!"
Nmsnsyslogmsnappm.exe"Related to Messenger Applications. When you uninstall the trial version the msnappm keeps saying (You have xx days left) this is adware and it very annoying"
XMSNSysRestorepc32.exeAdded by a variant of the MASTAK VIRUS!
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
XMSPluginSrvcp3.exe"Added by the RBOT-WV WORM!"
UMSPY2002ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMultimedia extensionsmservice.exe"EasySearch adware"
XMultimedia extensions[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
UMyEmoticonsMYEMOTICONS.EXE"MyEmoticons from Persona Ltd - add icons (emoticons) to your E-mail"
Umynswwntsrv.exe"Net Screen Watcher surveillance software. Uninstall this software unless you put it there yourself"
XMyVBAppinstall.exe"Detected as Generic Downloader.s by McAfee
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
XNAV Agentwinsnav.vbs"Added by the ANPES WORM!"
XNAV Auto Protectdnsserv.exe"Added by a variant of the SDBOT WORM!"
NNB Windows PatternsWINDBKGND.EXE"Part of McAfee Nuts & Bolts. With Background Patterns
XNBInstallMBDownloader_876919.exe"Added by the MIRAR_D TROJAN!"
NNCS_SSCsinsm32.exeSame as CleanSweep Smart Sweep-Internet Sweep
XNDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XNDplDeamonnstask32.exe"Added by the RANDEX.E WORM!"
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
XNetbeansnetbeans.exe"Added by the DELBOT-R WORM!"
UNetscapeInstallService.exeRelated to Netscape installation
UNetShow Powerpoint HelperNSPPTHLP.EXE"If disabled
NNetStat LiveNsl.exe"AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data"
XNetwork Accesswinssh.exe"Added by a variant of the SDBOT WORM!"
XNetwork Connectionsinternat.exe"Added by the VB-ZD TROJAN!"
XNetwork SecurityNSecurity.exe"Added by the IRCBOT.AAV WORM!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
NnForce Tray Optionssstray.exenVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
XNI.USYPSysProtectScannerInstall.exe"Installer for the SysProtect rogue security software
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5UWFX5NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0614UWFX5LP_0001_0614NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0715UWFX5LP_0001_0715NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0802UWFX5LP_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0803UWFX5LP_0001_0803NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5TUWFX5TNetInstaller.exe"Added by the DOWNLDR-BO TROJAN!"
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer 2006 web installer - ""foistware""
XNielsen NetRatingsinsight.exe"NetRatings Premeter spyware"
XNLS MonBoardNSBARD.EXE"Added by the SPYBOT.T TROJAN!"
UNNSvcnnsvc.exe"Net Nanny internet filter. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XNoDNSNoDNS.exe"Added by the CLICKER.WI TROJAN!"
YNokia Software Updaternsu_ui_client.exe"Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices"
UNokKernel installNok_install.exe"Installer for the NokNet Workstation Monitor surveillance software. Uninstall this software unless you put it there yourself"
UNorton Program Schedulernsched32.exe"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNorton Updaterwinset.exe"Added by a variant of the SPYBOT WORM!"
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
XnortonsantivirusccEvtMngr.exe"Added by the HZDOOR-A TROJAN!"
XNSns.exe"Added by the AGOBOT-HS WORM!"
XNSCheckNSCHECK.EXE"MarketScore parasite - ActiveX control used to download premium-rate dialers"
Xnscntrlnscntrl.exe"Added by the DLOAD-DC TROJAN!"
Xnsdcmd servicesnsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xnsdluansdlua.exeAll-In-One Telcom - adult content dialler
Xnsdrivernssys32.exe"NetShagg adware"
Xnsense.exe"Added by the AGOBOT-ML WORM!"
UNsengineNsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
UNSHelperaexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
UNSKNSK.exe"Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
UNSRKeyNSRTray.exe"System Tray access to Norton Save & Restore backup utility"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
Xnstatnetstat.exeAdult content dialler
XNSupdateNSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
Ynsu_ui_clientnsu_ui_client.exe"Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices"
Ynsu_ui_client.exensu_ui_client.exe"Utility that only runs once after installing the Nokia Software Updater which is used to update the operating system (or firmware) for selected Nokia mobile devices"
XNsvnsvsvc.exe"Delfin Promulgate adware"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
XNsvdrnsvdr.exeAdult content dialler
Unsysnsys.exe"NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xnsys32nsys32.exe"Added by the AGOBOT-SU WORM!"
NNSystemMonitorSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
Xntupdatednsvc.exe"Added by the SDBOT-TC WORM!"
UNUAgentInstallPathNU_Install.exe"Installer associated with Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself"
Xodnexodbns.exe"Added by the AGENT-MPM TROJAN!"
Xodnexyodbnsy.exe"Added by the VESLORUKI.DWJ TROJAN!"
YOneCareUIwinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XOnSrvrOnSrvr.exeOnWebMedia adware
XOpen Siteopnste.exe"OpenSite adware"
XOpen Siteopensite.exe"OpenSite adware"
UOpenDNS UpdateOpenDNS Updater.exe"Updater for OpenDNS which ""is a free service that works for networks of all sizes
NOperations Typhoon Rising RegistrationNOVG.EXE"Joint Operations registration reminder"
UOSSelectorReinstalloss_reinstall.exe"Related to Acronis Disk Director Suite"
XOutLooksInSane.exe"Added by the SWOOP TROJAN!"
Xoverinstallpgs.exe"Part of VirtualPCGuard
UPanasonic Communications UtilityMfpscdl.exe"Port manager for Panasonic Panafax fax_machines"
YPAVFNSVRPavFnSvr.exe"Part of Panda Antivirus and Internet Security"
UPCMagInstaback2InstaBack.exe"
XPersonSecuritypsecurity.exe"Personal Security rogue security software - not recommended
XPingTimeout Institutionpingchek.exe"Added by the SDBOT-VY WORM!"
XPingTimeout Institutioninternal.exe"Added by the SDBOT.BMH WORM!"
UPlainSight Desktop CalendarCalendar.exe"PlainSight Desktop Calendar by Desksware - ""It can display Microsoft® Outlook® data
XPmediawinsrvc.exe"Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!"
UPNSetupPNSetup.exe"PopNot - pop-up killer"
XPofatchnstrue.exe"Added by the RANDEX.Z WORM!"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
UPP2000 InstaupdatePPInupdt.exeProtector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
XPreInstall Windows[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
YPrevxOnePXConsole.exe"Prevx intrusion prevention software"
XPrint Schedulerusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XPrnShareWscript.exe prn_share.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""prn_share.vbs"" file is located in %System%"
UPrnSys ExecutablePrnSys.exe"Print screen utility bundled with some HP printer software - not required
XProtectionsProtEX32.exe"Ultimate SecuritySuite rogue malware remover - not recommended
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
UPurge with Current OptionsPURGEIE.EXE"PurgeIE from Assistance & Resources for Computing
UPVUnInst1PVUnInst1.exe"Privacy View - privacy software that ensures that all your private computer files
UPyroTranspyrobatchftp.exe"""PyroBatchFTP lets you transfer files to/from FTP/SFTP servers in an automatic and unattended way through a simple to learn batch/script language"""
YQCDriverInstallerLqdsw.exe"Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart
?QueenslaQueensla.exe"??"
NQuickenSEMessageQsemsg.exeQuicken option
XQuickInstallPackQuickInstallPack.exe"Installed and used by rogue security products such as Cleaner2009
XQuickInstallPackCLN_2009FreeInstall.exe"Installed and used by rogue security products such as Cleaner2009
UQWS3270 Sessionssessions.exeQWS3270 Secure terminal emulation software
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRapdatybsravseteyns.exe"Added by the PWS-ACP TROJAN!"
YRaptor Mobilevpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
XReal-TensReal-Tens.exe"DownloadWare adware"
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XRegptmensREGPTMENS.EXE"Added by the BANCOS-ED TROJAN!"
Xrelinsoncmdno.exe"Added by the DROPPER-PS TROJAN!"
Nreminder-ScanSoft Product Registrationremind32.exeRegistration reminder for ScanSoft products such as PaperPort
XRemote Procedure Callwinsysrpc.exe"Added by the SDBOT-PS WORM!"
?RjLyraInstallersetup.exe"??"
XRPCInstall[path to trojan]"Added by the AGENT-DQM TROJAN!"
XRpcxWindows Extensionsrpcxwinex.exe"Added by the RBOT.ACP WORM!"
Xrtkernsw[random filename]"Added by a variant of the SLAPER TROJAN!"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xrunsrun.exe"Added by the RBOT-BWF WORM!"
XRunSearvicestread.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunsqlrunsql.exe"Added by the DELF.ZWK TROJAN!"
XrunSubvalues[path to file]"Added by the DLOADER-QY TROJAN!"
Xrunsvcrunsvc.exe"Added by the SMALL-CF TROJAN!"
URunSysd32RunSysd32.exeDesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
NSafeInstall.exeSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
USansaDispatchSansaDispatch.exe"Sansa Updater - ""The Sansa Updater is an application that checks for the latest firmware updates then downloads and installs the firmware to your Sansa device"""
XSaveDefenseSaveDefense.exe"SaveDefense rogue security software - not recommended
XSBIinstall_sbd_**.exe"Installer for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code
YScanner File UtilityNsCatCom.exe"Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation"
XScanRegistrynsrvnt.exe"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"
NScanSoft OmniPage SE 4.0-reminderEreg.exe ereg.ini"Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
NScanSoft PaperPort 7 Registration ReminderNAVBrowser.EXE"Registration reminder for PaperPort 7 from Scansoft (now Nuance)"
NScanSoft PDF Professional 4-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 4 from Scansoft (now Nuance)"
XScanSpywareScanner.exe"ScanSpyware rogue security software - not recommended
XScanSpyware v3.2Scanner.exe"ScanSpyware rogue security software - not recommended
XScanSpyware v3.5Scanner.exe"ScanSpyware rogue security software - not recommended
UScanSys32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XScreen Saverscrnsaver.scr"Added by the RBOT-AGP WORM!"
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
XSDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XSdScans**stup_tmp.#32"Added by the SDSCAN.A TROJAN - where ** are random upper case letters"
Xsecure socket layerwins32a.exe"Added by an IRCBOT TROJAN!"
USecurePCSolutionsBootCheckBootCheck.exe"1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
XSemanticInsightSemanticInsight.exe"RXToolbar adware. Software that displays pop-up/pop-under advertisements when the primary user interface is not visible"
USensivaSensiva.exe"Symbol Commander makes the use of your PC
XServer Runtime Errorunsec.exe"Added by the SDBOT-DFA WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
XService Monitormsnserve.exe"Added by the SPYBOT.YQW WORM!"
XService Monitorcsnss.exe"Added by the RBOT.EEH WORM!"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
XServiceswindns.exe"Added by a variant of the RBOT WORM!"
XServices Start2odcwinst.exe"Added by the PYSKE-D WORM!"
USfWinStartInfosfWinStartupInfo.exeSFIRM32 Online Banking software
Usginstsginst.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Xshccdewinssled.exe"Added by the BUZUS.CQMU TROJAN!"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
XShell Extensionspollsv.exe"Added by the LOVGATE.Z WORM!"
XSiS Dnsdnssvc.exe"Added by the DLOADER-UE TROJAN!"
Xsis32winsos.exe"Added by the QQPASS.IA WORM!"
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
NSmileyconssmileycons.exe"Smileycons - free smileys
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSNInstall[various filenames]"Spy Sheriff/SpywareNO malware
NSnsiconSnsicon.exeLaunches a screensaver program from Second Nature
XSNSS.EXESNSS.EXE"Nunci premium rate dialer"
YSOFTinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XSound SystemWinSound1.exe"Added by an unidentified VIRUS
XSpam Blocker for Outlook ExpressSBInst.exe"Hotbar adware"
USpyware Nuker InstallerSpywareNukerInstaller.exe"Spyware remover by TrekBlue. Previously not recommended but the latest version was delisted here"
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
XSQInstallerSQInstaller.exe"Xupiter SQWire toolbar related. Use Spybot S&D
Xsqserviceswins32.exe"Added by the PROGENT-B TROJAN!"
USRUUninstallmsiexec.exeSymantec Network Driver Update - part of LiveUpdate
XSrv32 spool servicerunsrv32.exe"Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
XSSK Servicewinssk32.exe"Added by the SOBIG.E WORM!"
XStartupWinlogonStartupUnidentified malware
YStartup ScanSensor.EXE"AntiVirus Quick Heal - scheduling agent"
Xstcinstallerid53.exe"Added by the SCTHOUGHT.L TROJAN!"
UStopSignSsTsMon"sstsmon.dll VerifyStatus"
UStopSignStatusstopsinfo.dll"eAcceleration Stop-Sign security software related. Previously not recommended
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
YSunProtectionServerSunProtectionServer.exe"CounterSpy antispyware software"
YSunServerSunServer.exe"CounterSpy antispyware software"
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
Xsvwin32unninst32.exe"Added by the AGOBOT-NF WORM!"
XSygate Personal FirewallMSNSRV32.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallwins.exe"Added by the RBOT.AOB WORM!"
XSymantec Antivirus professionaldyndns.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalf0dns.exe"Added by the FORBOT-GT WORM!"
XSymantec Antivirus professionalflushdns.exe"Added by a variant of the FORBOT WORM!"
Xsyncmanwinsync.exe"Added by the MANCSYN-A TROJAN!"
?SynSetupSynTP.tmp RunOnce.exe"Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
XSysnetsnuninst.exeUnidentified adware
USysSenseSysSense.exe"""SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray"". Google AdSense account required"
XSystem Applications Profilesap.exe"Added by the RBOT-QF WORM!"
XSystem Document Applicationwins.exe"Added by the SDBOT.AUB WORM!"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Failure Statisticcnstat.exe"Added by the RBOT-LF WORM!"
XSystem Managerwinsrv32.exeAdded by an unidentified WORM or TROJAN!
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XSystem Security Updatersvsmons.exe"Added by the RBOT-OW WORM!"
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystembootmsnsngr.exe"Added by a variant of the RBOT WORM!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
USystemServicensserver.exe"NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsystrans[path to trojan]"Added by the STARTPA-GZ TROJAN!"
XsystrasxCONSOLES.EXE"Added by the SDBOT-NW WORM!"
UT3ConsoleT3Console.exe"Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data"
XTClock.exetclock_install.exe"TClock - distributed and installed without user permission by other rogue software or malware. TClock contains no uninstall facility through Windows. As TClock is of dubious origin and usefulness
XTCP MonitoringLanNSvc.exe"Added by the RANDEX.AAS WORM!"
?Tesco Insert DetectInsDetect.exe"Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
NTextbridge Instant Access OCRtelepath.exe"TextBridge from Nuance (was Scansoft). OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs"
?TheMainStartN/A"??"
UThinkVantage Access ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UThinkVantage Access ConnectionsACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
Xthis freewinsyst.exe"Added by the MADAG.A WORM!"
UTivoTransferTivoTransfer.exe"Tivo Transfer Service. TiVo Desktop is an easy-to-use application that lets you publish and share digital music
UTMA distributioncfinst.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
XToolbarInstallMirarSetup.exe"Mirar adware"
XTransaction Taskerstdhost.exe"Added by the SDBOT.HNK BACKDOOR!"
NTranscode360Transcode360Tray.exe"Designed for WinXP Media Center Edition 2005 and the Xbox 360
UTransparentTransparentW.exe"Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop
UTransparentTransparentD.exe"Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop
UTransparentTransparentB.exe"Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop
UTransparentIconstranicon.exe"A Tweak-XP component (only in the registered version)
Utranstasktranstask.exe"A Tweak-XP component
Xtransys"rundll32.exe transys.dllstart"
XTrojanTrojanS_P.exe"Added by the AGENT-CQ TROJAN!"
UTrojanScannerTrjscan.exe"Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed"
XTrojansFilterpgs.exe"TrojansFilter rogue security software - not recommended. A member of the AVSystemCare family"
XTrojansFiltrepgs.exe"TrojansFiltre
UTrojanShieldInit.exe"TrojanShield"
UTrojanShield ProtectorPort.exe"TrojanShield anti-hacker/anti-trojan software"
XTrojanSimulatorTSServ.exe"Trojan Simulator security risk which simulates a trojan infection and may be used to verify whether a virus scanner can properly detect the file"
UTSClientMSIUninstallertscuinst.vbs"Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
XTsk Mng Hlpwins32.exe"Added by the AGOBOT-JB WORM!"
?TSServiceNSSERVICE.EXE"??"
Xtvs_retvs_re_inst.exe"BroadcastPC adware"
UTVTunerLibTVTLInstTool.exeRelated to Sony installer tool for Sony TV tuner library
Xuninstalregsvr32 image.dll"CoolWebSearch parasite variant. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""image.dll"" file is found in %System%"
XUninstall****upd.exeAdult content based screen saver where **** can be any number
NUninstallAbilityuability.exe"UninstallAbility free uninstaller"
XUninstallHLPreUninstallHL.exe"LinkReplacer/FFinder adware"
XUninstallQLPreUninstallQL.exe"LinkReplacer/FFinder adware"
XUninstall_TBPSTBuninst.exe"WebSearch Toolbar - HuntBar hijacker
XUnSpyPCUnSpyPC.exe"UnSpyPC spyware remover - not recommended
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
XUpdateCheckwinstall.exe"Added by the SPYBOT-CY WORM!"
XupdateWinssystrey.exe"Added by the RANDON WORM!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
YUSB SECURITY DEVICE CoInstallerJupitCo.exe"ButterflyMedia USB Flash drive related - required for the password security feature to work"
NUSB2CheckPCLECoInst.dll"Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
XUser Servicerusnsrvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Managerusnsharen.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Serverusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Servicesusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XUser Sharing Wizardusnshare.exe"Added by the SLENFBOT.DF WORM!"
XUserfile Sharing Servusnsrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUserfile Sharing Serverusnserv.exe"Added by a variant of the IRCBOT TROJAN!"
Xusnsvc.exeusnsvc.exe"Added by the SPYBOT.AMD WORM!"
XUssiwnscpit.exe"PurityScan adware"
YUTILsInstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
?Verizon Custom Uninstall TrackingInstallHelper.exe"Verizon related installation tracker. What does it do and is it required?"
UVerizonServicepoint.exeVerizonServicepoint.exe"Part of Verizon Online Support Manager"
UVirtual DimensionVirtualDimension.exe"Virtual Dimension by Typz - ""a free
UVirtualDimension.exeVirtualDimension.exe"Virtual Dimension by Typz - ""a free
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended
XVirusScannermnsys.exe"Added by the SDBOT-AFQ WORM!"
XVITAL BOOT PROCESStaskmnsgr.exe"Added by the Rbot-VY WORM!"
?VMConsole.exeVMConsole.exe"Sony VAIO Media Console - installed on the VAIO Media Integrated Server PCs. What does it do and is it required?"
UVOBIDInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
UVoodooBanshee"rundll32.exe 3DBBps.dll BansheeLoadSettings"
XW32PluginsDownloaderXMLHTTPSelfClearing7520wiper.exe"Added by the PROXYSER-M TROJAN!"
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
XWDNS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWDNS SYSTEMskybotx.exe"Added by the MYTOB-BY WORM!"
XWDNS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWeb-cameinst[path to trojan]"Added by the RANCK-BP TROJAN!"
XWebInstallWebInstall.exeClipGenie adware downloader
XWebInstall2WebInstall.exeClipGenie adware downloader
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWin Security 360WinSecurity360.exe"Win Security 360 rogue security software - not recommended
XWin Serverwinserv.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwinserver.exe"Added by a variant of the IMISERV TROJAN!"
XWin Sync montrwinsyncupx.exe"Added by the RBOT.BYJ BACKDOOR!"
Xwin32winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 exe filewinstr32.exe"Added by a variant of the SPYBOT WORM!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWin32 USB2wins32.exe"Added by a variant of the RBOT WORM!"
XWin32 USB2 Driverwinsnd32.exe"Added by a variant of the SDBOT WORM!"
Xwin98 DNSwingrd.exe"Added by a variant of the RBOT WORM!"
XWinDLL (windns32.dll)"rundll32.exe windns32.dllstart"
XWinDNSwindns32.exe"Added by the GAOBOT.WX WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindows AdStatusWinStat.exe"Added by the BLESHARE!DR VIRUS!"
XWindows applications serverSysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DNSwindns.exe"Added by the SDBOT-XU WORM!"
XWindows DNS Daemonwindnsd.exe"Added by the WOOTBOT.AS WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows Essensialsmvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Extensions for Win32winprgs32.exe"Added by the SDBOT.AFA WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Icons Managerwicomgr.exe"Added by the RBOT-AIF WORM!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows installerwinstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
XWindows Installerntdll.exeAdded by an unidentified WORM or TROJAN!
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
YWindows Live OneCarewinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Management Instrumentationmwd.exe"Added by the GRAPS WORM!"
XWindows Management Instrumentation[path to file]"Added by the QEDS-A WORM!"
XWindows Management Instrumentationswinmg.exe"Added by the GAOBOT.GW WORM!"
XWindows Managerwinsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
NWindows Media Powerpoint HelperNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Network Sessionnspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows NT Login Session ManagerWNSM.EXE"Added by the RBOT.BIV WORM!"
XWindows NT Service Namewinshock.exe"Added by the RBOT-PK WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Proffesional SecurityWinSecure32.exe"Added by the AGOBOT.VA WORM"
XWindows Recovery Consolerecovery.exe"Added by the RANSOM.FD WORM!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registry Namewinses.exe"Added by the RBOT-ADB WORM!"
XWindows Rescue Systemwinsto.exe"Added by the SUURCH.CG TROJAN!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Assistantwinsec.exe"CoolWebSearch parasite variant"
XWindows Security Managerwinsecurity.exe"Added by the AGOBOT-KI WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows ServeAdWinServAd.exeWindupdates adware variant
XWindows Serverwinserv.exe"Added by the IRCBOT.AVM BACKDOOR!"
XWindows Server!winsvr.exe"Added by the IRCBOT.AYC BACKDOOR!"
XWindows Servic2winsy.exe"Added by the RBOT-AIA WORM!"
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Service Supplywinsupply.exe"Added by the SLENFBOT.CZ WORM!"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Socket ProcedureWinSock32.exe"Added by the RBOT-FMX WORM!"
XWindows Spoolwinspool.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Spoolerwinsplr.exe"Added by the SHEUR.ANX TROJAN!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWindows Sql Service For Windows 32 Bitwinsql32.exe"Added by the FORBOT-FC WORM!"
XWindows SRS Clientwinsrs.exe"Added by the RBOT-BXQ WORM!"
XWindows SRT Clientwinsrt.exe"Added by the RBOT-BFR WORM!"
XWindows SSH Clientwinssh.exe"Added by the RBOT-AXC WORM!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWindows Startupwinsta~1.exe"GoHip foistware"
XWindows Startupwinstartup.exe"GoHip foistware"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
UWindows Supervisorwinspvr.exe"Windows Supervisor surveillance software. Uninstall this software unless you put it there yourself"
XWINDOWS SVCwinsvc.exe"Added by the MYTOB-EY WORM!"
XWINDOWS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWindows SystemWINSYS.exe"Added by the RBOT-AEF WORM!"
XWINDOWS SYSTEMwinsys33.exe"Added by the MYTOB.EK WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWindows System 32winsys_32.exe"Added by the RBOT-FTR WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWINDOWS SYSTEM Dnswindsns.exe"Added by the MYTOB.EY WORM!"
XWINDOWS SYSTEM DNSPOOLhbmail.exe"Added by the MYTOB.FW WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
Xwindows system servicewinsock.exe"Added by the RBOT-MR WORM!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindows Sz Hostwinshvc.exe"Added by a variant of the SDBOT WORM!"
XWindows TaskManager Servicewindns32.exe"Added by the AGOBOT-JP WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Video Driversvideons32.exe"Added by the GAOBOT.AZT WORM!"
XWindows Video DriversVIDEONS3.EXE"Added by the AGOBOT-KZ BACKDOOR!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows xpWins.exe"Added by the RBOT.VH BACKDOOR!"
XWindows32 Serivceswinser32.exe"Added by the SPYBOT.AAF WORM!"
XWindowsFileSystemwinsfs32.exe"Added by the RBOT-FMQ WORM!"
XWindowsFirewallSvcwinsvcup.exe"Added by a variant of the SDBOT WORM!"
XWindowsInstaller[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XWindowsRegKey updatewindns.exe"Added by the RBOT.IE WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
UWindowsTranslatorDWinTrsl.exe"Delta Translator® English < > Portugese (Brazilian) version - ""an automatic
UWindowsTranslator_EspanholDWinTrsl.exe"Delta Translator® Spanish < > Portugese (Brazilian) version - ""an automatic
XWindowsUpdatev4w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindows_Protectwinsystem.exe"Added by a variant of the RBOT WORM!"
XWindow_Protectwinsi32.exe"Added by a variant of the RBOT WORM!"
Xwindtbswinsysvc"Added by the AGOBOT-NH WORM!"
Xwinhelpdns32.exe"Added by a variant of the RBOT WORM!"
Uwinlgnwinsplg.exe"Related to the Sentry Parental Controls software"
Xwinlogins.exewinlogins.exe"Added by the OPTIX.H BACKDOOR!"
XWinMenssagewinmax.exe"Added by the BANCOS.B TROJAN!"
XWinMenssagewinmaxy.exe"Added by the BANCOS TROJAN!"
Xwinnsvcmsvc.exe"Added by the PWS.O TROJAN!"
Xwinnt DNS identwuamgrd32.exe"Added by the RBOT-BAU WORM!"
Xwinnt DNS identiexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xwinnt DNS identpidchk32.exe"Added by the RBOT-ACY WORM!"
Xwinnt DNS identwindowxp.exe"Added by a variant of the RBOT WORM!"
Xwinnt DNS identWinupd32.exe"Added by the RBOT.AVU WORM!"
Xwinnt DNS identwinupdate32.exe"Added by a variant of the RBOT WORM!"
Xwinnt DNS identwuamgrd33.exe"Added by a variant of the RBOT WORM!"
XWinnt DNS identwindowsp.exe"Added by the RBOT.BAL WORM!"
XWinnt DNS identmsnmsrg.exe"Added by the RBOT.BVQ WORM!"
Xwinrootwinsn.exe"Added by the QQPASS.IA WORM!"
XWins Loader5Gadu-Gadu.exe"Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu"
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWins Update 32services32.exe"Added by the FORBOT-FN WORM!"
XWins32 Onlinecfgpwnz.exe"Added by the BROPIA.R WORM!"
XWinScMngrwinsmc.exe"Added by the SDBOT-BPZ WORM!"
XWinSecwinsec16.exe"Added by the AGOBOT.ZF WORM!"
Xwinsecurewinsecure.exe"Browser hijacker
XWinSecure[random].exe"Added by the AGENT-LR TROJAN!"
XWinsecure AntivirusSecureantivirus.exe"Added by a variant of the SPYBOT WORM!"
XWinSecureAvpgs.exe"WinSecureAv rogue security software - not recommended
XWinSecured32ssmr.exe"Added by a variant of the FORBOT WORM!"
XWinSecurityuninstall.exe"Added by the SILLYFDC.BCJ WORM!"
XWinservWinserv.ila"Added by the NODMIN WORM!"
XwinserverServer.txt.vbs"Added by the DELTAD.A WORM!"
XWinservicewinmain.exeAdult content related malware
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
XWinServiceTtt.exe"Added by the MSNVB-D WORM!"
XWinServiceWinServ.exe"Added by the SKOWOR-O WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
Xwinservitcassl.exe"Added by the RBOT.ASG WORM!"
Xwinservnwinservn.exe"PurityScan adware"
Xwinservswinservs.exe"PurityScan adware"
XWinSetBrowseBasicUpdate.dll.vbs"Added by the BISCUIT.A WORM!"
Xwinsfcwinsfc.exe"Added by the WISFC VIRUS!"
XWinshellremote.exe"Added by the MYTOB.LJ WORM!"
Xwinshellwindll32lib.exe"Added by the BAGLE-DM WORM!"
?Winshoewuadfdqr.exe"Probably an unidentified VIRUS! Adds itself to 3 registry ""Run"" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed"
Xwinshost.exewinshost.exe"Added by the TOOSO WORM and variants!"
Xwinshow[path to trojan]"Added by the VB-DXP TROJAN!"
XWinShowUpdatecopy [path] winshow.new [path] winshow.dll"Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version"
XWinSigNetXP.exe"Added by the BANKER-FN TROJAN!"
XWinSistemTunggul.vbs"Added by the VBS.STEMCLOVER WORM!"
XWinsk system Loaderwinsk.exe"Added by the AGOBOT-IZ WORM!"
Xwinskypewinskype.exe"Added by the BROGGER-C TROJAN!"
UWinSLWinSL.exe"StarLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xwinsocksvch0st.exe"Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock driverwinnt64.exe"Added by the SPYBOT-DR WORM!"
XWinsock Drivernvscv32.exe"Added by the AGOBOT-FD WORM!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock driverwin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinsock drivertcpmngr.exe"Added by the SPYBOT-CK WORM!"
XWinsock driverwinupdate32.exe"Added by the SPYBOT-JZ TROJAN!"
XWinsock StartupMain2.exe"Added by a variant of the SDBOT WORM!"
Xwinsock.clientwinsock.exe"Added by the DIABLO-M TROJAN!"
Xwinsock2netsvr.exe"Added by the AGOBOT.LY WORM!"
XWinsock2 dllsW32DLL.EXE"Added by the SPYBOT-CS BACKDOOR!"
XWinsock2 driverSDJOIJE.EXE"Added by the SPYBOT.DR TROJAN!"
XWinsock2 driverMIRC32.exe"Added by the SPYBUZZ TROJAN!"
XWinsock2 driverkgzgjkpcw.exe"Added by the SDBOT.T TROJAN!"
XWinsock2 driverZONEALARM.EXE"Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program"
XWinsock2 driverwincfg.scr"Added by the SPYBOT-E TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock2 driverSPOLSV.EXE"Added by the SPYBOT-CM WORM!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsock2 driversysreq.exe"Added by the SPYBOT-CC WORM!"
XWinsock2 driverWUAUMQR.EXE"Added by the SPYBOT-DP WORM!"
XWinsock2 driverwincfg.exe"Added by the SPYBOT.CO WORM!"
XWinsock2 driversvchorsst.exe"Added by the SPYBOT-EE WORM!"
XWinsock2 driverSYSTEM32.EXE"Added by the SPYBOT-EG WORM!"
XWinsock2 driverdllcfg32.exe"Added by the SPYBOT.AG WORM!"
XWinsock2 driverCFTMON.EXE"Added by a variant of the IRCBOT BACKDOOR!"
XWinsock2 driverntsys32.exe"Added by the SPYBOT-DD WORM!"
XWinsock2 driverWINNT32.EXE"Added by the SPYBOT-CN WORM!"
XWinsock2 driverPAC.EXE"Added by the SPYBOT-ET WORM!"
XWinsock2 driverwinsock2.exe"Added by the SPYBOT-CT BACKDOOR!"
XWinsock2 drivermmtask5.exe"Added by the SPYBOT-CD WORM!"
XWinsock2 driverWWEUMQR.EXE"Added by the SPYBOT-BY WORM!"
XWinsock2 driverIEXPLORE .EXE"Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XWinsock2 driverWINSOUND.EXE"Added by the SPYBOT-H WORM!"
XWinsock2 LoaderWICONF.EXE"Added by the SDBOT-LA WORM!"
XWinsock2 wqr1sWUAUMQR1.EXE"Added by the SPYBOT.KD WORM!"
XWinsock2.dllWINLODR.SCR"Added by an unidentified VIRUS
XWinsock32 driverTESTING.EXE"Added by the SPYBOT-B WORM!"
XWinsock32 driversystem32.exe"Added by the IRCBOT-VT TROJAN!"
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwin32server.exe"Added by the BACKDOOR-AZV TROJAN!"
XWinsock32driverZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
XWinsock32driverZoneLockup.exe"Added by the HACARMY.D TROJAN!"
XWinsock32driverwin32server.exe"Added by the HACARMY.F TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinsock6 MIC driverieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
Xwinsockdrivertskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
Xwinsockdriverwinsock2.2.exe"Added by a variant of the SPYBOT WORM!"
Xwinsockdriveriexplor.exe"Added by the BLATIC.A WORM!"
Xwinsockdriverwinsock3.exe"Added by the SPYBOT-DO WORM!"
Xwinsockdriverbot.exe"Added by the WARPIGS-D WORM!"
Xwinsockdriverwinsock4.1.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xwinsockdriverwinsock2.exe"Added by the SPYBOT-AC WORM!"
XWinSocketComponentnthost.exe"Added by an unidentified VIRUS
XWinsocks2 drivermznmgr.exe"Added by a variant of the SDBOT WORM!"
UWINSOS VERIFYWINSOS.EXE"WinSOS - ""deletes spyware
XWinSP[path] REGEDIT.EXE -s [path] sysreg.reg"Added by the STARTPA-ME TROJAN!"
XWINSP00LWINSP00L.EXE"Added by the AGENT.XAB TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
Xwinspd32dllwinspd32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWinSPFwindrv32.exe"Added by the MYDOOM.T WORM!"
XWinSPFwinspf32.exe"Added by the MYDOOM.S WORM!"
XWinsplwinsplx.exe"Added by a variant of the TROLL-A TROJAN!"
Xwinsplogwsmmlog.exe"Added by the MAILBOT-CA TROJAN!"
XWinspoolspoolsvr.exe"Added by a variant of the SDBOT WORM!"
XWinSpyControlpgs.exe"WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family"
XWinSpyDemoWinSpyDemo.exe"WinSpy rogue spyware remover - not recommended"
XWinSpyKillerWinSpyKiller.exe"WinSpyKiller rogue spyware remover - not recommended
XWinSpywareProtectWinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
XWinSpywareProtect (ver. 5.1)WinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
XWinSrvkn0x.exe"Added by the HOBBIT.F WORM!"
XWinSrvSHIZZLE.EXE"Added by the HOBBIT.C WORM!"
XWinsrvwinsrv.exe"Added by the OPASERV.T WORM!"
Xwinsrvwinsrv.exe"Added by the NETSNAK-B TROJAN!"
Xwinsrv3services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Ywinssnotifywinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
XWinStabilizerWinStabilizer.exe"Added by the AGOBOT-SW WORM!"
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
XWinStartWinStart.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStartWscript.exe WinStart.vbs"Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
XWinStartwinstart32.exe"Added by the PUROL WORM!"
XWinStartWinStart.pif"Added by the CONE.E WORM!"
Xwinstartwinstart.exe"Added by the SCKEYLO-AB TROJAN!"
XWinStart001WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStart001.EXEWinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
Xwinstatswinstats.exe"Added by the GARGAFX TROJAN!"
XWinsta~1winsta~1.exe"GoHip foistware"
XWinSth16WinSth16.exe"Added by the CAKE WORM!"
XwinstroRUN32DLL.exe"Added by the FTP_ANA TROJAN!"
Xwinsupdaterwinsupdater.exe"Added by the ALCRA-F WORM!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
XWinSvc16.exeWinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
Xwinsvc32winsvc32.exe"Added by the IRCBOT-AEG WORM!"
Xwinsvc32.exewinsvc32.exe"Added by the GREPAGE TROJAN!"
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWinsvr managerDDEsvr.exe"Added by the TIRBOT-C WORM!"
Xwinsy32.exewinsy32.exe"CoolWebSearch parasite variant"
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
UWinsysWinsys.exe"Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself"
XWINSYS[path to trojan]"Added by the GOLDPLAY TROJAN!"
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
XWinSyswinmgmt.com"Added by the VB.EIW WORM!"
XWinSyssystem.exe"Added by the DAPROSY WORM!"
XWinSys32Winsys32.exe"Added by the CIGIVIP TROJAN or RECKUS WORM!"
Xwinsys32 Driverwinsys32.exe"Added by the LOONY-O TROJAN!"
UWinSysAppMonWinSysRM.exe"Home & Family Content Filter related. See here"
Xwinsysban[path to trojan]"Added by the CLICKER-CD TROJAN!"
UWinSysChecksb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinSysM371662M.exe"Added by the WINKO.AO WORM!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
XWinSysStartUpWKbLwTaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
XWinSyst32winsyst32.exe"Added by the MORB WORM!"
XWinSystemwinsystem.exe"Added by the WHITEBAIT WORM!"
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinsystemFreevideo5.EXE"Added by the AGENT.FZS WORM!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"
Xwinsysupd[path to trojan]"Added by the STARTPA-NI TROJAN!"
XWinSysW371662L.exe"Added by the WINKO.AO WORM!"
XWINTASKyahooicons.exe"Added by the MYTOB-HM WORM!"
XWinupdateewinsvcc.exe"Added by the AGENT.AN TROJAN!"
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
Xwin_supp00.exeWin Const.exe"Added by the ASSASIN-H TROJAN!"
XWireless ConectionsWireConnect.exe"Added by the SDBOT-VF WORM!"
XWireless ConnectionsWIRECONNECT.EXE"Added by the SDBOT-VM WORM!"
NWireless Consolewcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 2wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWireless Console 3wcourier.exe"ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
NWLAN Status Tray AppletWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
NWLANSTA.EXEWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
XWLWinWINSYS.EXE"Added by the NAVER.A WORM!"
XWMI Standard Event Consumer - Scriptingscrcons32.exe"Added by the RBOT-GRD WORM!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
UWMPNSCFGWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XWN Serviceswnsvc.exe"Added by the KBBOT-A TROJAN!"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
XWNSCwnsin**.exe [* = random char]"PurityScan adware"
XWnsck2 driverwlogf.exe"Added by the SPYBOT-AF WORM!"
XWNSIwnscp**.exe [* = random char]"PurityScan adware"
XWNSIrwsa.exe"PurityScan adware"
XWNSOWNSO.exe"Baidu.SoBar adware"
XWNSTwnsapi**.exe [* = random char]"PurityScan adware"
Xwntlgnswntlgns.exe"CoolWebSearch parasite variant"
Xwormexewinstart.exe"Added by the EARLYBIRD WORM!"
XWPSVC Serviceswpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWXcmeinst[path to file]"Added by the RANCK-CD TROJAN!"
XxInsIDExInsIDE.exe"Added by the ADLOAD.BH TROJAN! Note - this should not be confused with the valid IDE configuration utility from JMicron Technology which is normally located in %Windir%\RaidTool and uses the same filename. This one is located in %ProgramFiles%\xInsIDE"
UxInsIDExInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
?xkstartup"RunDll32 InstZ82.dll SetUsbPrinterPort"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
XXNSearchAssistantSrchAsst.exeiWon Search Assistant - spyware
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpstatwinlogins.exe"Added by the RBOT-AAR WORM!"
UXtreamLok License Managerxl.exe"License manager for xLok (XtreamLok) - prevents software being reverse engineered"
Xx~{{dybelx~{{dy8%nsn"Added by the AGOBOT.DQ WORM!"
XYahoo Instant MessengarYahooMsgr.exe"Added by the SDBOT.GEN TROJAN!"
UYou've Got Pictures Screensaverygpsstra.exeAOL You've Got Pictures Screensaver
UZipDisk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
XZNNznnsvc.exe"Added by the SDBOT-DAA WORM!"
XZolero TranslatorZoleroTranslator.exe"Zolero Translator - added by Clickspring
XZonesoft Cleanerrnsys.exe"Added by a variant of the SDBOT WORM!"
?zzzCamlnSuitelllsetup.exe 46***"??"
X[3-4 random letters]nslookup.exe"PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder"
X[random name]w?nspool.exe"PurityScan adware"
X[trojan filename]Install.exe"Added by the BANCBAN-FS TROJAN!"
X[various names]ActionScr.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]install2.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]NsCplTray.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]NSYSCPLSTR.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]openstre.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]scanSYS.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_WinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status"
X_winsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.