| X | Reg Service | ipcfg.exe | "Added by the AGOBOT-SO WORM!"
|
| N | Reminder-hpcXXXXX | remind32.exe | HP CD-Writer Registration
|
| U | Remote Desktop Computing | marspc.exe | "Marspc Remote Desktop Computing"
|
| X | Remote Procedure Call | winrpc.exe | "Added by the RBOT-KM WORM!"
|
| X | Remote Procedure Call | winsysrpc.exe | "Added by the SDBOT-PS WORM!"
|
| X | Remote Procedure Call For Windows 32bit | rpc.exe | "Added by the RBOT-MD WORM!"
|
| X | Remote Procedure Calls | mswinrpc.exe | "Added by the RBOT.KJ WORM!"
|
| ? | roketpipe | rpclient.exe | "??"
|
| X | RPC | MSschost.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | RPC DCOM Vulnerability Patch | msgfix.exe | "Added by the RBOT.S WORM!"
|
| X | RPC Drivers | rpcall.exe | "Added by the SDBOT.FLY WORM!"
|
| X | RPC Patcher | [path to worm] | "Added by the BOLGI WORM!"
|
| X | RPC Service | [random filename] | "Added by the BDOOR-AAD BACKDOOR!"
|
| X | rpc Win32 | shost32.exe | "Added by the RBOT-ABL WORM!"
|
| X | rpc Win32 | spoolscv.exe | "Added by a variant of the RBOT WORM!"
|
| X | RPCall_WIN2K | Kurawas.exe | "Added by the BHARAT.A WORM!"
|
| X | RPCall_[ComputerName] | smhost.exe | "Added by the REDPLUT-B TROJAN!"
|
| X | rpcc | rpcc.exe | "Added by the SPAMMIT-E TROJAN!"
|
| X | rpcda Win32 | rpcda.exe | "Added by the RBOT-AEE WORM!"
|
| X | RPCInstall | [path to trojan] | "Added by the AGENT-DQM TROJAN!"
|
| X | RpcLocator | explorer.exe | "Added by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | RPCser32g | services.exe | "Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCser32g1 | services.exe | "Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCser32g3 | services.exe | "Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCser32g4 | services.exe | "Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserr32g | winlogon.exe | "Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserv32 | services.exe | "Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserv32g | services.exe | "Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserv32g | CSRSS.EXE | "Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserv32g | MSDEFR.EXE | "Added by the BOBAX.AD WORM!"
|
| X | RPCserv32g | NB32EXT2.EXE | "Added by the BOBAX.AD WORM!"
|
| X | RPCserv32g | WINLOGON.EXE | "Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| Y | RPCSS.exe | rpcss.exe | "Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se |
| X | RpcxWindows Extensions | rpcxwinex.exe | "Added by the RBOT.ACP WORM!"
|
| X | RSPC Driver | [random filename].exe | "Added by the RBOT-SN WORM!"
|
| X | RSPC Driver D | [random filename] | "Added by a variant of the RBOT WORM!"
|
| N | run= | pcfix2k.exe | pcfix2k splash screen
|
| X | RVP | bpc.exe | "BroadcastPC adware"
|
| X | SafePcAv | SafePcAv.exe | "SafePcAv rogue security software - not recommended |
| X | SafePCTool | SysRep.exe | "SafePCTool rogue system error and cleaning utility - not recommended |
| U | SafetyNet | ipcTray.exe | "Safety.Net from Netveda - ""offers Internet security |
| U | SafetyNet_Notifier | ipcLn.exe | "Safety.Net from Netveda - ""offers Internet security |
| U | Scan2pc | Scan2pc.exe | "Scan to PC application for the scanning function of multiple multifunction printers from Dell |
| X | SecurePcAv | SecurePcAv.exe | "SecurePcAv rogue security software - not recommended |
| X | SecurePCCleaner | GDC.exe | "SecurePCCleaner rogue privacy tool - not recommended |
| U | SecurePCSolutionsBootCheck | BootCheck.exe | "1 Click Fixer PLUS from Secure PC Solutions ""takes the guesswork out of locating and solving problems in the Windows registry"""
|
| X | Security Center | AppControl.exe | "Added by the SDBOT.CFT WORM!"
|
| N | SEPCSuite | SEPCSuite.exe | "System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
|
| X | SernellApp.pcx | csrss.exe | "Added by the BANCBAN-BJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
|
| X | Service Drivers | PC.EXE | "Added by the SDBOT-WK WORM!"
|
| X | Servicerepclient1 | SERVICES.EXE | "Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
| U | sfpc | sfpc.exe | "Spy4PC surveillance software. Uninstall this software unless you put it there yourself"
|
| U | SHPC32 | SHPC32.exe | Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
|
| X | SiS Mpc Service | mpcsvc.exe | "Added by the CIADOOR-CJ TROJAN!"
|
| Y | slipcore | slipcore.exe | "Core module for Slipstream - internet acceleration through compression/decompression techniques |
| Y | SlipStream | slipcore.exe | "Core module for Slipstream - internet acceleration through compression/decompression techniques |
| U | Smartalec | pcaccel.exe | "Smartalec PC Accelerator - system optimization utility"
|
| U | SmartPCXL | pcaccel.exe | "Smartalec PC Accelerator - system optimization utility"
|
| U | SmpcSys | SmpSys.exe | """Set Up My PC"" utility supplied with some Packard Bell computers"
|
| X | Social Security Agency | rpcxsocsa.exe | "Added by a variant of the RBOT WORM!"
|
| N | Sony Ericsson PC Suite | Application Launcher.exe | "System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
|
| N | Sony Ericsson PC Suite | SEPCSuite.exe | "System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
|
| X | SP2 data | [path] repcale.exe [path] apc.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\winstat"
|
| ? | SPC610NC_Monitor | Monitor.exe | "Related to the Philips SPC610NC webcam. What does it do and is it required?"
|
| N | spc_w | hcm.exe | "NetZero Search Enhancement related"
|
| N | spc_w | blspc.exe | "NetZero Search Enhancement related"
|
| N | spc_w | nzspc.exe | "NetZero Search Enhancement related"
|
| U | Speaking Clock Deluxe | SpClDlx.exe | "Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date |
| U | SpeedUpMyPC | speedupmypc.exe | "Older version of SpeedUpMyPC from Uniblue - which ""lets you monitor and control all your PC resources with easy |
| X | Srv RPCrom | NClienti386.exe | "Added by the WATSOON.A TROJAN!"
|
| X | Start CurePCSolution | CurePCSolution.exe | "CurePCSolution spyware remover - not recommended |
| X | SuspenzorPC | GDC.exe | "SuspenzorPC Czech rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | Sysmon | rpcmon.exe | "Added by the RANDEX.ATX WORM!"
|
| X | Sysmppcvppp | SysTdSvr.dll | "Generic2.PQG adware"
|
| X | SysSearch | Regedit.exe -s pcsearch.reg | "Added by the STARTPAGE-FN TROJAN! Note that regedit.exe is a legitimate Microsoft file and shouldn't be deleted. The ""pcsearch.reg"" file is located in %Windir%"
|
| X | System | winipck.exe | "Added by the RBOT-TK WORM!"
|
| X | System Restore Data | [path] repcale.exe [path] beird.exe | "Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
|
| X | System Setup | rpcxcmod.exe | Added by an unidentified WORM or TROJAN!
|
| X | System Update | mssetupconf.exe | "Added by the RBOT.DLC WORM!"
|
| X | System32 PCI Manager | syspci32.exe | "Added by the RBOT-AFR WORM!"
|
| X | Systems Restart | spchost.exe | Added by an unidentified WORM or TROJAN!
|
| X | tcp checker | tcpcheck.exe | "Added by the VBBOT-A TROJAN!"
|
| X | TempCom | [randomname].com | "Added by the TRAXG WORM!"
|
| X | Total PC Defender | Total PC Defender.exe | "Total PC Defender rogue security software - not recommended |
| X | Total PC Defender 2010 | Total PC Defender 2010.exe | "Total PC Defender rogue security software - not recommended |
| X | Total Protect 2009 | pcpc_starter.exe | "Total Protect 2009 rogue security software - not recommended |
| X | tpcupdater | updatetc.exe | "Antivirus XP 2008 rogue security software - not recommended"
|
| X | TurvaPC | GDC.exe | "TurvaPC Finnish rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | uga6pcw | uga6pcw.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| U | Uniblue SpeedUpMyPC | SpeedUpMyPC.exe | "Older version of SpeedUpMyPC from Uniblue - which ""lets you monitor and control all your PC resources with easy |
| U | UniblueSpeedUpMyPC | Launcher.exe | "SpeedUpMyPC 2009 from Uniblue - which ""lets you monitor and control all your PC resources with easy |
| X | UnSpyPC | UnSpyPC.exe | "UnSpyPC spyware remover - not recommended |
| N | UpConfgVer | UpgConf.exe | "Part of Panda Antivirus and Internet Security. Purpose unclear |
| X | UPCTPcw | UPCTPcw.exe | "Part of the PcTurboPro rogue system optimization tool - not recommended |
| X | updatexwin | winxrpc.exe | "Added by the AGOBOT-KJ WORM!"
|
| X | uprpcw | uprpcw.exe | "PrivacyProtector rogue privacy tool - not recommended |
| X | USB 2.0 Driver | updateXPSPC.exe | "Added by the AGOBOT-RJ WORM!"
|
| N | USB2Check | PCLECoInst.dll | "Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system"
|
| X | UserInit StartUp | rpcxuisu.exe | "Added by a variant of the SDBOT WORM!"
|
| X | uwa6pcw | uwa6pcw.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | uwa7pcw | uwa7pcw.exe | "Part of the WinAntiVirus Pro 2007 rogue security software - not recommended |
| X | videopci | videopci.exe | "Added by the AGENT-W TROJAN!"
|
| X | VirtualPCGuard | pgs.exe | "VirtualPCGuard rogue security software - not recommended |
| N | VoipCheap | VoipCheap.exe | "VoipCheap - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| N | VoipCheapCom | VoipCheapCom.exe | "VoipCheapCom - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| U | VPCUserServices | VMUSrvc.exe | "Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC |
| X | wa7pcw | wa7pcw.exe | "WinAntiVirus Pro 2007 rogue security software - not recommended"
|
| X | wa7pcw | wa7pcw.exe | "Part of the WinAntiVirus Pro 2007 rogue security software - not recommended |
| X | WCPC | wintsvcc.exe | "PurityScan adware"
|
| U | Whitney2_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier
|
| U | WHITNEY2_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer
|
| U | WhitneyXerox_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer
|
| U | WHITNEY_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers
|
| X | win | xwinxrpc32.exe | "Added by the AGOBOT-MV WORM!"
|
| X | win | xwinxrpc.exe | "Added by the AGOBOT-MV WORM!"
|
| U | Windows | WpcUmi.exe | "Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
|
| X | Windows APCI Verifier | dhcpserv.exe | "Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
|
| X | Windows driver update | Ipconfig32.exe | "Added by the SDBOT-JV WORM!"
|
| X | Windows Express | pci32b.exe | "Added by the BUZUS.C TROJAN!"
|
| X | windows logon procedure | winlogonpc.exe | "Added by the WINLOGON TROJAN!"
|
| X | Windows More Choice | TopContext.exe | "ZQuest adware"
|
| X | Windows Pc | winmgr.exe | "Added by the BIBOT-A WORM!"
|
| X | Windows PC Defender | WP[random characters].exe | "Windows PC Defender rogue security software - not recommended |
| X | Windows Relay Service | ipcbind.exe | "Added by the DELFINJECT.F TROJAN!"
|
| X | Windows Remote Addressing | wnpcgs.exe | "Added by the DELF-EZN TROJAN!"
|
| X | Windows Workstation | mpci.exe | "Added by a variant of the RBOT WORM!"
|
| X | WindowsHive | rpcc.exe | "Added by the DLENA-A TROJAN!"
|
| X | windowsupdate | RPC[RANDOM CHARACTERS].exe | "Added by the IRCBOT.B TROJAN!"
|
| X | WinPCDoctor | SysRep.exe | "WinPCDoctor rogue system error and cleaning utility - not recommended |
| X | WinRPC | winrpcmx.exe | "Added by the BANKER-EEI TROJAN!"
|
| X | Winsock2 driver | kgzgjkpcw.exe | "Added by the SDBOT.T TROJAN!"
|
| X | WIP Config GUI | Winipcfgs.exe | "Added by the RBOT-CN WORM!"
|
| U | Wireless PCI Card Configuration Utility | WMP11Cfg.exe | "Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| U | Wireless-G Notebook Adapter Utility | WPC54CFG.EXE | "Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)"
|
| N | Wpctrl | wpctrlnt.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | Wpctrl | wpctrl95.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | wpctrl95 | wpctrlnt.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | wpctrl95 | wpctrl95.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| U | WPCUMI | WpcUmi.exe | "Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
|
| Y | WPCycle.exe | WpCycleWin.exe | "Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end |
| X | WSAConfiguration | rpcxmn32.exe | "Added by the AGOBOT.ABG WORM!"
|
| X | XP Cleaner | xpc.exe | "XP Cleaner rogue cleaning utility - not recommended |
| ? | xpcfg | xpcfg.exe | "??"
|
| ? | Xpclient | xpclient.exe | "Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required?"
|
| U | XPCMonitor | XPCMonitor.exe | "XPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | XPCPHOST Settings | xpcphost.exe | "Added by a variant of the RBOT WORM!"
|
| U | XTNDConnect PC | XCPCMenu.exe | "XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - 3CmPlm | Autodet.exe | "3Com Palm PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - CasioOrg | CasAgnt.exe | "Casio Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - ErPhn2 | ErTray.exe | "Sony Ericsson IrMC (Infrared Mobile Connectivity) phones and smartphones specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - LtNts4 | NtsAgnt.exe | "(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - MyPalm | MPTray.exe | "Palm OS specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | Xtrem parental control | pcx.exe | ParentXtreme - surveillance software. Uninstall this software unless you put it there yourself
|
| U | YPC | ypc.exe | "Yahoo Parental controls - ""Let you decide what type of sites and Yahoo! services your kids can access"""
|