Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
Xdllvirtual.exe"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.dll"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Inc.""Machine WorksXaecces.exe
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
Inc.""Miramar SystemsUatmsg.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
please"This is a virusXbigbadvirus.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
""[Ephemeral 2.4] by TreeHuggerX[path to worm]
""[Ephemeral 2.5] by TreeHuggerX[path to worm]
""[Ephemeral 2.x] by TreeHuggerX[path to worm]
Y#NAME?ZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
U$EnterNetEnternet.exe"Connection manager for the EnterNet ISP. You can also use RASPPOE"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$drv$sys$drv.exe"Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
?%cmpmixtitle%%cmpmixstr%"Possibly related to C-Media Mixer Control panel?"
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X%Windir%winnl.exewinnl.exe"Added by the KIDKITI TROJAN!"
X%Windir%winnm.exewinnm.exe"Added by the KIDKITI TROJAN!"
X'AdwarePro''AdwarePro'.exe"AdWarePro rogue security software - not recommended"
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
X(*)Runwin32API.exe"Homepage hijacker
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Systrsy.exe"Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X(Default)KEYBOARD.exe"Added by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)xtreme.exe"Added by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLMRun in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware
Y*Restorerstrui.exePart of Windows System Restore and added as a RunOnce registry entry. Leave alone
X*Security Centersecctr.exe"Added by the SDBOT.BRO WORM!"
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X.protectedN/A"Smitfraud variant"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
?00notify33NetBrowser.exe"Part of Best Network Security
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1mrcmgr.exe"Added by the BANKER.RQK TROJAN!"
X1KHATRA.exe"Added by the AUTOIT-BP WORM!"
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
?17779Proj2002N/A"??"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X2-suhartosuharto.exe"Added by the BRONTOK-CR WORM!"
X2020Downloadermssvr.exe"2020Search Toolbar"
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X27csrss32.exe"Added by the SLSORVE-D TROJAN!"
X2k6 updatzcrss3.exe"Added by the RBOT-CPD WORM!"
X2Searchmain.exe"2Search adware"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
?3Com LauncherLauncher.exe"Related to networking products from 3Com Corporation. What does it do and is it required?"
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
X4-gusdurgusdur.exe"Added by the BRONTOK-CR WORM!"
X456655explorer.exe"Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X5-1-61-96members-area.exeAdult content dialler
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
X6.54388E+16rkgnd.exe"ANG AntiVirus 09 rogue security software - not recommended
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g MIMO Wireless UtilityRaUI.exe"Wireless configuration utility for Railink 802.11g MIMO based products"
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
Y9xadiras9xadiras.exe"Allied Telesyn AT series router/modem related - apparently required"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@RUNDLL.EXE"Added by the SPYBOT-DN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
N@Hoc ToolbarAtHoc.exe"One-click activated browsing toolbar used by various web-sites. See here for more info"
N@lohareminder.exe"Registration reminder for
Y@OnlineArmor GUIoaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
X@tour_ww@tour_ww[1].exeAdult content dialler
XaMsSvrdll.vbs"Added by the MUTAFROG!INF WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-squareda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Ya-squareda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-squared Anti-Dialera2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
Ya2adguarda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Ya2guarda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
UA4ProxyA4Proxy.exe"Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites"
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
XA5118rj6321422.exe"Added by the BRONTOK-AK WORM and variants!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
?AAAKeyboard??"??"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide
XAaepopar.exe"PurityScan/Clickspring adware"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAappadprot.exe"AdBlaster adware"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
UAAWAd-Aware.exe"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"
UAAWTrayAAWTray.exe"System Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool"
?ab EazySchedulerezsched.exe"??"
UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
UABIT uGuruuGuru.exe"ABIT µGuru - on motherboards incorporating the µGuru processor this provides quick access to ""hardware monitoring
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
YABRegmonABregmon.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
UAbsolute Shielddseraser.exe"Absolute Shield Evidence Eliminator - internet history eraser"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XABsrabsr.exe"Added by the AUTOUPDER TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
UAbyssusrazerhid.exe"Razer Abyssus gaming mouse driver - required if you use the additional features and programmed keys/macros"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
UAcBtnMgr_X63AcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X73AcBtnMgr_X73.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X83AcBtnMgr_X83.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
YAccelerometerStAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAccessoriesPlusclockplus.exe"Clock Plus
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
Yaccrdsubaccrdsub.exe"ActivIdentity ActivClient - security software from ActivIdentity Corporation which ""enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login"""
UAcctMgrAcctMgr.exe"Norton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize
UAcer Assist Launcherlauncher.exe"Acer Assist - program that provides information about new updates or notices from Acer"
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UAcer ePower ManagementePowerTray.exe"Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks. Also appears as the Packard Bell PowerSave power management utility included on some of their notebook models - as Packard Bell is now owned by Acer"
UAcer ePower ManagementePowerTrayLauncher.exeLauncher for the Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
YAcer Launch ToolAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
UAcerGotoAcerGoto.exe"Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
XAceu[random filename]"PurityScan adware"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
UACMonitor_X63ACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X63.exeACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X73ACMonitor_X73.exe"Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
UACMonitor_X83ACMonitor_X83.exe"Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
UACMonitor_X84-X85ACMonitor_X84-X85.exe"Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
Nacpartagpart11.exeProgram for finding trucks on-line
XAcrobatacrmon32.exe"Added by the SMALL-ECT TROJAN!"
UAcrobat AssistantAcroTray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
XAcrobat Readacroup32.exe"Added by the VANBOT-BQ TROJAN!"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
XAcroreadAcroRD32.exe"Added by the DLOADR-BDK TROJAN! Note - this is not the popular Adobe Reader"
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
UActivboardMMKeybd.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UACTIVBOARDABoard.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
UActMakerActMak25.exe"""ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding
UActMakerActMaker25.exe"ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload"
UACTrayACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
UAd Arrestadarrest.exe"Ad Arrest IE popup killer from GameFools"
UAd Blockerblocker.exe"Ad Blocker - blocks popups
UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
UAd MuncherAdMunch.exe"Ad Muncher removes adverts
UAd-AwareAd-Aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAd-AwareAd-Aware.exe"Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
XAd-Eliminatorad-eliminator.exe"Ad-Eliminator rogue spyware remover - not recommended
UAd-MuncherADMUNCH.EXE"Ad Muncher removes adverts
UAd-Protectad-protect.exe"Ad-Protect spyware and spam monitoring tool"
NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdDestroyerAdDestroyer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
?addproxyaddproxy.exeRelated to Adobe Photoshop
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
XaDiradirss.exe"Added by the SPAMSRV-E TROJAN!"
YAdirasAdiras.exeADSL USB modem related
Xadirkaadirka.exe"Added by the TIBS-QT TROJAN!"
XAdKillerAD Defender.exe"Part of the Advanced Spyware Remover rogue spyware remover - not recommended
XADM Library Loaderadmlib32.exe"Added by a variant of the SDBOT TROJAN!"
XAdmanager ControllerAdManCtl.exe"Adware
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdministrator di DagoDago.exe"Added by the PUNYA-B WORM!"
?ADMTray.exeadmtray.exe"Part of Acer Empowering Technology. What does it do and is it required?"
NAdobe AcrobatREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe AcrobatReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
NAdobe ARMAdobeARM.exe"Adobe Reader Manager (ARM) - update/download manager added with Adobe Reader from version 9.2. Taken from the Adobe user forums - ""AdobeARM.exe is a part of new Adobe AcrobatReader updater. If you manage updates yourself
XAdobe Filter Platformafilterplatform.exe"Added by the RBOT-OP WORM!"
XAdobe Flash PlayerAdobeFP.exe"Added by the AUTORUN-BBP WORM!"
UAdobe Gamma LoaderAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
UAdobe Gamma Loader.exeAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background
XAdobe Reader32Acrord32.exe"Added by the RBOT-BLC WORM! Note - this is not the popular Adobe Reader"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
NAdobeARMAdobeARM.exe"Adobe Reader Manager (ARM) - update/download manager added with Adobe Reader from version 9.2. Taken from the Adobe user forums - ""AdobeARM.exe is a part of new Adobe AcrobatReader updater. If you manage updates yourself
XAdobeManagerrundtl.exe"Added by the INJECT.IB TROJAN!"
Xadobemgradobemgr.exe"Added by the ADCLICKER TROJAN!"
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProupdt.exe"Added by the IRCBOT-VQ WORM!"
XAdobeReaderProrruxdkf.exe"Added by the RBOT.ADF BACKDOOR!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProlxlfsprrj.exe"Added by the RBOT.BDZ BACKDOOR!"
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderProsubset.exe"Added by the RBOT.OCU WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProrvdjlefr.exe"Added by the RBOT-CQZ WORM!"
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
XAdobeReaderProlssas.exe"Added by the RBOT-CLB WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProchkdisk.exe"Added by the RBOT-BDV WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
XAdobe_Readeracrotray.exe"Added by the AGENT-LNS TROJAN! Note that the legitimate Adobe file (if installed) would normally be found in %ProgramFiles%\Adobe%\%ProgramName% (where %ProgramName% is Acrobat 9.0\Acrobat or Acrobat 7.0\Distillr for example) whereas this one is located in %ProgramFiles%\Adobe"
XAdobe_RLXccwap.exe"Added by the BCKDR-RCL TROJAN!"
Xadodemasteradodemaster.exe"Downloader of Korean origin
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
Xadprotadprot.exe"AdBlaster adware"
NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover
XAdsAlertAdsAlert.exe"AdsAlert rogue security software - not recommended"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
YADSMTrayADSMTray.exeASUS Data Security Manager provides password protected data encryption on ASUS notebooks
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
UAdSubtractadsub.exe"AdSubtract blocks ads
XAdtools ServiceAdTools.exe"Windupdates Adware"
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
UADUserMonADUserMon.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
UAdware Agentadware agent.exe"Adware Agent popup blocker"
XAdware PunisherAdwarePunisher.exe"Adware Punisher rogue spyware remover - not recommended
XAdware Punisher MonitorAdwarePunisher_monitor.exe"Adware Punisher rogue spyware remover - not recommended
XAdware SpyAdwareSpy.exe"AdwareSpy rogue adware remover - not recommended
UAdwareAlertAdwareAlert.Exe"Adware program
XAdwareDeleteadwaredelete.exe"AdwareDelete rogue adware remover - not recommended
XAdwareKiller_schedulesschedules.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareKiller_traytray.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdwareProtectorAdwareProtector.exe"Part of rogue security tools
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 rogue security software - not recommended
XAdwareSpyAdwareSpy4.exe"AdwareSpy rogue adware remover - not recommended
XAdware_ProNETAdware_Pro.exe"Adware Pro rogue security software - not recommended
XAdwarz Spy RemoverADWARZ.EXE"Added by the SPYBOT-EV WORM!"
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
UAESTFltrAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
?AeXSWDUsrAeXSWDUsr.exe"Altiris Express NS Client Manager software. Is it required?"
UAEZBProcaptezbp.exe"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
?AgenteRemupd.exe"Part of an older version of Panda Antivirus. Is this an update reminder (guess because of the name)
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
Uahfprogahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
XAhorreMemoriaSysRep.exe"AhorreMemoria rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XAHU[path to worm]"Added by the ANACON-B WORM!"
UAi Gear HelpGearHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
NAIM LoggerAIMLogger.exe"AIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM"
XAim Quick StartAim.exe"Added by the FORBOT-BB WORM! Note - this is not the popular AOL Instant Messenger utility"
XAIM reminderAIM reminder.exe"Added by the BUDDY.E TROJAN!"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
UAimMonitorAimMonitor.exe"AIM Monitor Sniffer surveillance software for the AIM instant messenger. Uninstall this software unless you put it there yourself"
UAIMProaimpro.exe"AIM Pro - secure instant messaging
NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xaircityaircity.exe"Related to ""Prutect"" malware from e2Give"
YAirGCFGAirGCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAKillerakiller.exe"Advertising Killer - popup stopper"
UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
?AlarmWatcherAlarmWatcher.exe"Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?"
NAlbum Fast StartABMTSR.EXE"Scanner software
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
UAlcmtrALCMTR.EXE"Realtek Azalia Audio - Event Monitor
XAlcmtrMalware Doctor.exe"MalwareDoc rogue security software - not recommended
NAlcohol.exe AutorunAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?Alcom PCL CaptureFMW_PCAP.EXE"??"
Xalcomrg.exealcomrg.exe"Added by the SDBOT-DNT WORM!"
UAlcWzrdALCWZRD.EXE"RealTek AlcWzrd Application
UAlcxMonitorAlcxmntr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
Xalerteralerter.exe"MAHA.F spyware"
XAlevirAlevir.exe"Added by the OPASERV-A WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAlexaToolbaralt.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.EB TROJAN!
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
?ALFY AccelleratorAlfyAC~1.exe"??"
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
Xalkasr?????.exe"Added by the BALKART TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAll Sea screen saverTaskTray.exe"Free screensaver
NAllerCalcAllerCalc.exe"AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAllToTrayALLTOTRAY.EXE"AlltoTray from DNTSoft - minimize any program to your System Tray"
XALMcsrss32.exe"Added by the ANACON-D VIRUS!"
XAlogrithm Link Queuealq.exe"Added by a variant of the SDBOT WORM!"
UAlogservAlogserv.exe"From McAfee VirusScan for logging scanning activities. In some cases
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UALServALServ.exeUtility that enables a user to control the volume and surround sound and select Pro Logic/Stereo on 2 satellite speakers and subwoofer of old Altec Lansing speaker systems. The right-side speaker has 4 controls on top providing same functionality
Xalt CTRL Shiftet3rd.exe"Added by the SDBOT-RH BACKDOOR!"
XALTER DATA[path] repcale.exe [path] beird.exe"Added by the IRCFLOOD.CD TROJAN! Both files are located in %System%\ccdew"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UAMD PowerNow!GemBack.exe"
NAmerica Onlineaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
YAmonitoramon.exe"Tiny Personal Firewall"
UAMO_Taskplaner.exeAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
NAnapod Manageranamgr.exe"Anapod Explorer from Red Chair Software ""is the most advanced Windows iPod® software available
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
YANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
NAnti-Blaxx ManagerAnti-Blaxx.exe"Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives"
UAnti-keylogger checkantikey.exe"Anti-keylogger - protects against keylogger programs monitoring your keystrokes"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Uantidialer.co.ukDialer_Watcher.exe"Dialer_Watcher is an application that allows you to detect dialers on your computer"
YAntiFreezeAntiFreeze.exe"AntiFreeze from Resplendence Software Projects - ""offers a last recourse when you find your computer in a hung state"". If your system has hung and AntiFreeze is running
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
XAntiMalwareAntiMalware.exe"AntiMalware rogue security software - not recommended
XAntimalware Doctor.exeAntimalware Doctor.exe"Antimalware Doctor rogue security software - not recommended
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiMalwareSuiteAMS.exe"AntiMalwareSuite rogue security software - not recommended
XAntiMalware_ProNETAntiMalware_Pro.exe"AntiMalware Pro rogue security software - not recommended
XAntiSpionagePropgs.exe"AntiSpionagePro
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntispySpiderantispyspider.exe"AntiSpySpider rogue spyware remover - not recommended
XAntispyStormAntispyStorm.exe"AntispyStorm rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware ProAntiSpyware Pro.exe"AntiSpyware Pro 2009 rogue spyware remover - not recommended
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot rogue spyware remover - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntispywareDAntispywareD.exe"AntiSpywareDeluxe rogue security software - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiSpywareSuitepgs.exe"AntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare family"
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiTroyAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiTroy.exeAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue spyware remover - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntiVirGear 3.7AntiVirGear 3.7.exe"AntiVirGear rogue security software - not recommended
XAntiVirGear 3.8AntiVirGear 3.8.exe"AntiVirGear rogue security software - not recommended
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
Xanti_trojanti_troj.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the LODEAR.D TROJAN!"
UAnVirAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task ManagerAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
XAnvTrgrAnvTrgr.exe"AntivirusTrigger rogue security software - not recommended
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
UAnyTime OrganizerAtDem.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
NAO TrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
NAOL Fast StartAOL.exe"Fast Start loads the AOL integrated email
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
NAOLDialerAOLDial.exeAOL ISP software dialer - can be activated through a desktop shortcut
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
XAOLStartAOLStart.exe"Added by the KRAIMER.12 TROJAN!"
Xaolupdater.exeaolupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XAornumaornum.exe"Installed along with
NAOTrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Xaoueisysrtmvs.exe"Chivio dialer"
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
XAPCProtect.exeAPCProtect.exe"APCProtect rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapmanager.exeapmanager.exe"AP Manager ransomware download manager - not recommended
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApp.EXEName[path to worm]"Added by the BODIRU WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
NApplication LauncherApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xara-key[random filename]"Added by the ANTINNY WORM!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
YArcaCheckArcaCheck.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
Xarcaderockstararcaderockstar32.exe"Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArctosarazerhid.exe"Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
UArdamax Keyloggerakl.exe"Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
Naresares.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
NaresliteAresLite.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
Xargq32csrss_32.exe"Added by the RBOT-CPM WORM!"
XAritimaaritima.exe"Added by the ARITIM WORM!"
XArman[path to worm]"Added by the IRCBOT-TG WORM!"
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue
XArmorDefenderArmorDefender.exe"ArmorDefender rogue security software - not recommended
Uarmy logoreadmename.exe"Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
Xaromisaromis.exe"Added by the NUWAR.JQ WORM!"
NAROReminderaro.exe"Advanced Registry Optimizer - ""scan
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovax ShieldArovaxShield.exe"Part of Arovax Shield from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovaxShieldArovaxShield.exe"Part of Arovax Shield from Arovax
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UArteraarteraui.exe"Artera Turbo Internet Accelerator - ""surf faster
XArucer"rundll32 Arucer.dllArucer"
XArucer Dynamic Link Library"rundll32 Arucer.dllArucer"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
YAshampoo FireWallFireWall.exe"Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
YAshampoo FireWall PROFireWall.exe"Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
Xashcapservirsess.exe"SpySure spyware"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XaslAslru.exe"Added by the BANCOS-CU TROJAN!"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?AspireServiceAspireService.exe"Found on Acer laptops
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
Xasr64_ldm.exeasr64_ldm.exe"Added by the Dr. Guard rogue security software - not recommended
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
UASTARTastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
XAStartAStart"Added by the VB.AH TROJAN!"
NasTrayAstray.exe"Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer"
NAstroAstro.exeChecks for updates to Quicken on a system reboot
XAstrumAstrum.exe"Astrum Antivirus Pro rogue security software - not recommended
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
UASUS TweakEnableastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
NASUSGamerOSDGamerOSD.exe"GamerOSD by ASUSTek - for ""real-time overclocking
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
UAsusTrayAsTray.exe"Part of the ACPI driver for the Asus Eee PC range. Watches the sensors of the motherboard such as power and temperature"
NASUSWebStorageASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NAsusWSDashBoardASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
NATI CATALYST System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
NATI GART Set-up UtilityAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
XATI Rage3d ProAtiRage4dPro.exe"Added by the AGOBOT-OG WORM!"
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
NATICCCCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename
NAtiGartAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
YATIRmtWndrATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
Uatitrayatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
UAtiTrayToolsatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
XATIUpdateratiupdxx.exe"Added by the RBOT-ABX WORM!"
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XATM Controladpn.exe"Added by the MMS.A WORM!"
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
XAtomic-x27CAtomicpartC.exe"Added by the KATOMIK-A WORM!"
UAtrackatrack.exe"New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker
UAtrayAtray.exe"Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneSystrayattune_st.exe"Aveo Attune automated helpdesk software - adware/spyware"
NaTuneratuner.exe"aTuner - tweak tool for GeForce based graphics cards"
XAtxBrwIexplor.exe"""Pop Marketing"" adware"
XAudcntraudcntr.exe"Added by the GEMA TROJAN!"
?AudCtrl"RunDll32 AudCtrl.dll RCMonitor"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
NAudioCommanderAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommander ApplicationAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
XAudiodrvaudiodrv.exe"Added by the CRYPTER-C TROJAN!"
UAudioDrvEmulatorDLLML.exe AudDrvEm.dll"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
XAuth Starter Identstartauth.exe"Added by the RBOT-WP WORM!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
XAuto Startdosin.exe"Added by the SDBOT-GO BACKDOOR!"
XAuto Startsndvol32.exe"Added by the SLINBOT.AX BACKDOOR!"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
NAuto T Barautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
UAutobarautobar.exe"Connect buttons on the keyboard for internet direct access
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
Xautochk"rundll32.exe autochk.dll_IWMPEvents@16"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
Xautorepairdexs.exe"Added by a variant of the SDBOT WORM!"
Xautornautorn.exe"Added by the SILLYFDC.BCY WORM!"
UAutoroute SMTPAutoSmtp.exe"Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
Xautorunautorun.exe"Added by the AUTOM-B WORM!"
Xautorunsxs.exe"Added by the SMALLVBS-A WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
XAutoRunallrs.exe"Added by the MUDROP.LJ TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
UAutoSizerAUTOSIZER.EXE"AutoSizer - utility that automatically maximizes windows when they're opened"
Nautotbarautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Xauto__hloader__keyhloader_exe.exe"Added by the BAGLE.AB TROJAN!"
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVAntivir.exe"Antivir rogue security software - not recommended
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
YAvast!ashServ.exe"Main part of avast! Antivirus - including the resident protection
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAvast32Astart32.exe"Part of Avast! anti-virus software"
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_AMSVRAVGAMSVR.EXE"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
YAVG7_Runavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
UAVG8_TRAYavgtray.exe"System Tray access to and notifications for the 8.* series of internet security products from AVG Technologies - including Internet Security
UAVG9_TRAYavgtray.exe"System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security
Yavgamsvr.exeAvgamsvr.exe"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
YAVGCtrlAVGCtrl.exe"Part of AntiVir® PersonalEdition Classic antivirus"
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
YAvgserv9.exeAvgserv9.exe"Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
Uavgtrayavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVGuardAVGuard.exe"AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
XAvirTrAvirTr.exe"AntivirusTrigger rogue security software - not recommended
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
YAVKBarAVKBar.exe"GData AntiVirusKit Anti-virus"
YAVKTrayAVKTray.exe"System Tray access to the antivirus part of G Data range of internet security products"
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
XAvpravpr.exe"Added by the MYDOOM.AF WORM!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
Xavrlabsavrlabs.exe"VirusResponse Lab 2009 rogue security software - not recommended"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVSeguropgs.exe"AVSeguro
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
Xavserve2.exeavserve2.exe"Added by the SASSER.B or SASSER.C WORMS!"
Xavserve3.exeavserve3.exe"Added by the SASSER.G WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
NAvtrayAvtray.exe"Command Antivirus tray icon"
XAVTrayAVTray.exe"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
UAWMONAd-Monitor.exe"F-Secure Anti-Spyware"
?AxFilter"Rundll32 AXFILTER.DLL Rundll32"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
UAzMixerSelAzMixerSel.exe"Related to Realtek_Azalia Mixer Selector"
XA_M_P_NETAntiMalwarePro.exe"AntiMalware Pro rogue security software - not recommended
Ya2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
NB.Readerremin.exe"Birthday Reminder 5.0 - as the name implies"
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
Xbabeie"rundll32 cnbabe.dll dllstartup"
NBabylon TranslatorBabylon.exe"""Babylon-Pro is a powerful information tool that instantly provides relevant information
XBackdoor.NuAgentagent.exe"Added by the AGENT-DP TROJAN!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
Xbackup[path to worm]"Added by the AGOBOT-H WORM!"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackup Servicebackup.svcUnidentified adware
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
NBackworkBackwork.exe"Backwork trojan detector"
NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBadxHELLRAIDER.EXE"Added by the MINDCTRL.A BACKDOOR!"
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBakraIEHost.EXE"Added by the MULTIDR-AH TROJAN!"
NBandwidth Meter ProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBandwidth Monitor ProBandwidth Monitor Pro.exe"Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP"
NBandwidthMeterProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBanpopup by PratikBanpopup.exeBanpopup - popup killer
XBanyak_KerjaanTukang.exe"Added by the SILLYFDC.BDM WORM!"
XBar Ding loltAnaliz.exe"Added by the RBOT-RP WORM!"
Xbargainsbargains.exe"BargainBuddy adware"
Xbargainsbargainbuddy.exe"BargainBuddy adware"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
?Bart Stationstation.sbrt"Related to PeoplePC ISP. May be a dialler for dial-up accounts?"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
XBarThemebartent32.exe"Added by the AGOBOT-UG WORM!"
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBastioneAntiviruspgs.exe"BastioneAntivirus
XBatsecure2.bat"Added by the ZCREW.C TROJAN!"
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
UBatLogEx"rundll32.exe [path] BatLogEx.DLLStartBattLog"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
UBatteryBarbatterybar.exe"BatteryBar - displays battery usage
Ybatterymiserbatterymiser.exe"Battery Miser power management utility for LG Notebooks"
YBatteryMiser 5BatteryMiser5.exe"Battery Miser 5 power management utility for LG Notebooks"
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBayMgrDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
NBBC AlertsBBC_Alerts.exe"BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
?BBDialBT Broadband.exe"Part of BT Broandband - is it required?"
NBBLauncher.exeBBLauncher.exe"BounceBack Professional - back-up software"
NbbSysTraybbSysTray.exe"Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"""
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
?bcmwltrybcmwltry.exe"Broadcom Corporation Wireless Network Tray Applet. Is it required?"
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
Xbdfgergggasw.exe"Added by the SDBOT-RT WORM!"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
UBDRegionbrs.exe"Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
YBDWizRegbdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
UBearFlixBearFlix.exe"BearFlix is optimized for the fast download of video files"
NBearSharebearshare.exe"BearShare file sharing client. Versions known to include spyware - see here"
UBeatNik Internet ClockBeatNik.exe"BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
UBeFasterbefaster3.exe"BeFaster internet connection optimization tool"
Ubeidsystemtraybeidsystemtray.exe"Related to Belgium Identity Card card reader"
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
UBelkin Wireless USB UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UBelkin Wireless UtilityBelkinwcui.exe"Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
UBellSouthAlertManager.exeBellSouthAlertManager.exe"Related to BellSouth Alert Manager"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
?BELORVBIBELORVBI.exe"??"
XBenadril Alert Toolbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
XBestPopUpKillerBestPopupKiller.exe"Popup killer by Swanksoft - not recommended
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
Ybgbullguard.exe"Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster"
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
XBharatayudaGNB.exe"Added by the BHARAT.A WORM!"
UBHRBHR.exe"Browser Hijack Retaliator - recovers your browser after it has been hijacked by spyware
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
Xbigorisbigoris.exe"Added by the DORF-AZ TROJAN!"
UBigPond ToolbarbpumTray.exe"Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
NBillminderBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start -> Programs
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
UBionix Wallpaper 5Bionix Wallpaper 5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionix Wallpaper 5beta.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBioniX Wallper.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionixWallpaper5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
UBitDefender for Yahoo! Messengeryahmon.exe"Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
XBittorrentbittorrent.exe"Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir%"
NBitTorrentbittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitTorrent DNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbittorrent.exebittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitWare Print Monitorbwprnmon.exe"FaxServe network fax software"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
XBlockCheckerBlock-checker.exe"BlockChecker adware"
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockKeeperBlockKeeper.exe"BlockKeeper rogue security software - not recommended
XBlockProtector.exeBlockProtector.exe"BlockProtector rogue security software - not recommended
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
NBlockTrackerBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
XBlockWatcherBlockWatcher.exe"BlockWatcher rogue security software - not recommended
UBLOG"rundll32.exe [path] BatLogEx.DLLStartBattLog"
Ublsloaderblsloader.exe"BellSouth ISP Internet Tools"
NBlubsterBlubster.exe"Related to Blubster Music sharing service"
UBlue Frogbluefrog.exe"Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
?BlueLight_uoltrayexec.exe"Related to BlueLight Internet. What does it do and is it required?"
?Bluetooth HCI Monitor"RunDll32 HCIMNTR.DLLRunCheckHCIMode"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
NBMMLREFBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
NBMMLREF.EXEBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBMNstrpmon.exe"Part of CleanPCTool
UBMO MasterCard WalletEWALLET.EXE"The wallet conveniently stores billing
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
YBOCleanautostartBoclean.exe"NSClean's BOClean anti-trojan software"
UBOINC Managerboincmgr.exe"BOINC manager - ""controls the use of your computer's disk
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
Xboler.exesyser.exe"Added by the RBOT-AYS WORM!"
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
UBookmarkbookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
UBookmark.exebookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
NBookmarkCentralBMLauncher.exe"Bookmark Express - "offers a more flexible way to manage Web site bookmarks
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot ManagerNjgal.exe"Added by the KILO TROJAN!"
XBoot Managerbootmng.exe"Added by a variant of the SPYBOT WORM!"
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootCTRLbootctrl.exeAdded by an unidentified WORM or TROJAN!
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootWarnBootWarn.exe"From here: ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBortMedViruspgs.exe"BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
Uborzoiblg.exe"Borzoi surveillance software. Uninstall this software unless you put it there yourself"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
UBQTray.exeBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
XBrasilBrasil.exe"Added by the OPASERV.E WORM!"
XBrasilBRASIL.PIF"Added by the OPASERV.E WORM!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
Xbrastkbrastk.exe"Added by the DORF-BV TROJAN!"
XBrave-SentryBraveSentry.exe"BraveSentry rogue security software - not recommended
XBraveSentryBraveSentry.exe"BraveSentry rogue security software - not recommended
Xbraviaxbraviax.exe"Added by the FAKEALER.LE TROJAN!"
XBrcttrdb.exe"Detected by Kaspersky as the PURITYSCAN.Y TROJAN!"
UBreak_ReminderBREAK REMINDER.exe"Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBregbcre.exe"BroadcastPC adware variant"
XBregbptre.exe"BroadcastPC adware variant"
XBregbreg.exe"BroadcastPC adware"
XBridge"rundll32.exe [path] Bridge.dllLoad"
YBrindys BriTrayBRITRAY.EXE"Main process for the following applications: GEDEX
UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
Ubroadband medicmatcli.exe"NTL's Broadband Medic. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBroadband Wizardbbwiz.exe"Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs"
NBroadCamRunbroadCam.exe"BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
UBroadcom Wireless Manager UIbcmntray.exe"Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-SpizaetusnorBtok.exe"Added by the RONTOKBRO.B WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
XBron-Spizaetuseksplorasi.exe"Added by the RONTOKBRO.J WORM!"
XBron-SpizaetusElnorB.exe"Added by the RONTOKBRO.D WORM!"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
XBron-SpizaetusRakyatKelaparan.exe"Added by the BRONTOK-J or BRONTOK-L WORMS!"
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBRoNToKBRoNToK.exe"Added by the BRONTOK-CG WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Xbrowsermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowsers_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserdeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowser aidbrowseraid.exe"BrowserAid/BrowserPal foistware"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
YBrowser Hijack Blasterbhblaster.exe"Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard"
UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
XBrowser Paladblck.exe"BrowserAid/BrowserPal foistware"
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
XBrO_AcTBrO-AcT.exe"Added by the SILLYFDC-D WORM!"
Xbrwdiag[path to worm]"Added by the STRATIO-BN WORM!"
XBS Mediaplayerbsplyr.exe"Added by the RBOT-OU WORM!"
NBS Playerbsplayer.exe"BSplayer - A video player used to play avi
Nbsplayerbsplayer.exe"BSplayer - a video player used to play avi
XBsRteMemoteXZZ.exe"Added by the AUTORUN-AJU WORM!"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBsx3"RunDLL32.EXE bs3.dllDllRun"
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Ubtbb_wcm_McciTrayAppMcciTrayApp.exe"System tray access to Motive's Broadband 2.0 configuration and repair utility"
UBtcMaestroKMaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
UBtStartbtstart.exe"Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software"
UBTTrayBTTray.exe"System tray icon which shows the status of a Bluetooth wireless module (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Also allows access to explore bluetooth places
YBTUSRBDGBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
YBTUSRBDGFBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
NBuddyizerBuddyizer.exePart of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
YBufferZoneCLIENTGUI.EXE"BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
NBug EliminatorBug_Elim.exe"Bug Eliminator - ""performs a complete health check on your computer safely
XBugsDestroyerSysRep.exe"BugsDestroyer rogue system error and cleaning utility - not recommended
Ubugwatcher servicebugwatcher.exe"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
YBullGuardmgui.exe"Part of Bullguard antivirus"
YBullGuardBullGuard.exe"Part of BullGuard antivirus"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XBullsEyebargains.exe"BargainBuddy adware"
XBullsEye Networkbargains.exe"BargainBuddy adware"
?BullsEye TrackerBeTrack.exeBullseye - intelligent research assistant
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
Xburitosburitos.exeIdentified as a variant of the Downloader.FraudLoad.C malware
NBurnQuick QueueBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
UButton Serverbttnserv.exe"Found on a Compaq PC
UBuzMeRCUI.exe"Display Client for the BuzMe Internet Call Waiting Service"
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
Nbwprnmon.exebwprnmon.exe"FaxServe network fax software"
Xbxproxybxproxy.exe"Added by the BXPROXY TROJAN!"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
Xbxsx5"RunDLL32.EXE bsx5.dllDllRun"
Xbxxs5"RunDLL32.EXE bxxs5.dlldllrun"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
UBySoft FreeRAMFreeRAM.exe"""Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status
XByteDefenderByteDefender.exe"ByteDefender rogue security software - not recommended
?BZEnvironmentVariableCollectorBZEnvironmentVariableCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
?BZUtilizationCollectorBZUtilizationCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
NC-Media MixerMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
XC7[path to worm]"Added by the MEDIAKILL.A WORM!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
YCaAvTrayCAVTray.exe"eTrust™ EZ Antivirus system tray application from Computer Associates"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
YCacheMgrCacheMgr.exe"Sophos Antivirus Remote Update"
UCacheSentry ProCacheSentry Pro.exe"""CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
NCACStartercacstart.exeCash A Check - check writing software
NCahootWebcardCahootWebcard.exe"""The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details"". Run manually when needed"
NCal Reminder Shortcutcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
Xcalc"rundll32.exe calc.dll_IWMPEvents@0"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
UCalendarCalendar.exe"This entry can be added by PlainSight Desktop Calendar and older versions of Desktop iCalendar from Desksware and the older Calendar 200X - which is no longer supported by or available from the author"
?Calendar 200X Monitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
NCalendar 200X Remindercalendar.exe"Part of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays
?Calendar Monitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
UCalendarscopecs.exe"Calendarscope calendar software"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
?calmonitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
?calmonitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
UCamera Assistant Softwaretraybar.exeCamera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
UCamera DetectorCAMDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
UCamera DetectorCamdetect.exe"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
UCamera DetectorDEVDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
?CameraApplicationLauncherCameraApplicationLaunchpadLauncher.exe"Supports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?"
UCameraAssistantCameraAssistant.exe"Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom
NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
?CamMonitorhpqcmon.exe"From HP and related to digital imaging"
YCamWizardCamWizrd.exeLaunches the Logitech Camera Wizard on the first reboot after installing versions of Logitech QuickCam webcam software
UCanarycanary-std.exe"Canary keystroke logger/monitoring program - remove unless you installed it yourself!"
UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
UCanonMyPrinterBJMyPrt.exePrinter software for Canon Bubblejet printers
Ucapfupgradecapfupgrade.exe"CA Personal Firewall - part of the CA Internet Security Suite"
XCaptcha7rundll captcha.dll"Added by the TINY.WRE TROJAN!"
XCaptionMgr32crssr.exe"Added by the ZAR.A WORM!"
Xcapturecapture.exe"Added by the THEEF-B TROJAN!"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
UCaptureAssistantCaptureAssistant.exe"Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text
NCaptureBatCapture.exe"!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways
NCarbonite BackupCarboniteUI.exe"""Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
XCare20Care20.exe"TopMoxie adware"
UCare2GTUCare2GTU.exe"Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
Xcartao[path to file]"Added by the DLOADER-QD TROJAN!"
Xcartaoconflicted.exe"Added by the DADOBRA-DV TROJAN!"
Xcartaokilling.exe"Added by the DLOADER-QN TROJAN!"
Xcartaocartao.exe"Added by the BANKER-FA TROJAN!"
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XCasino Royalejamesbond.exe"Added by the RBOT-FZO WORM!"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
YCAVRIDCAVRID.exe"eTrust™ EZ Antivirus Real Time Infection Report from Computer Associates"
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
?CBWUserCBWDial.exe"Associated with Bitware that integrates fax
XCcaoregedit.exe"Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a ""mduu"" subfolder
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccApproutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XccctpHistoryJMTi.exe"Added by the GANBATE.A WORM!"
UCCD ManagerDDS.EXE"Project Labs Century CD manager for their CD/DVD storage device"
NCcdecode"rundll32.exe streamci StreamingDeviceSetup"
YCCDoctorLogonTestingccdoctor.exe"Checks your system to make sure it's configured properly for running IBM Rational ClearCase
YccenterCCenter.exe"RAV AntiVirus"
YCcEvtMgrccEvtMgr.exe"Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
XccEvtMrg.execcEvtMrg.exe"Added by the RBOT.GZ WORM!"
UCCleanerCCleaner.exe"CCleaner from Piriform Ltd. - ""is a freeware system optimization
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
UccProxyCCPROXY.EXE"Part of Norton Internet Security
XccPrxy.execcPrxy.exe"Added by the SHIPUP-H WORM!"
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
YccRegVfyccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
Xccrssmsdtc.exe"Added by the STAP-C WORM!"
YccSetMgrccSetMgr.exe"Part of Norton AntiVirus 2004. What does it do?"
XccStartccStart.exe"Added by the AGOBOT-IR WORM!"
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
Ucctraycctray.exe"Part of CA Internet Security Suite"
UccUpdMgrccUpdMgr.exe"In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!"
UCCUTRAYICONCCU_TrayIcon.exe"Related to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®"
UccWasheraolwasher.exe"Webroot Cache & Cookie Washer - cleaning browser tracks
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
NCD Storage Mastercdstorager.exe"CD Storage Master - a program designed to catalog CD information
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
Xcddrv32cddrv32.exe"Added by a variant of the CRYPTER.C TROJAN!"
NCDInterceptorcdi.exeCD indexer for measuring the speed of CD players
Ycdloadercdloader2.exe"From MagicJack - ""A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"""
UCDLoadersb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XCdnCtrcdnup.exe"CNNIC Update pest"
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
Xcdoosoftolhrwef.exe"Added by the AUTORUN-AAG WORM!"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XCdrom Controllercdromcntrl.exe"Added by the BATTRY-A TROJAN!"
NCDTrayCDTray.exe"On HP PCs
UCeEPOWERcepmtray.exe"Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed
XCekirge[path to worm]"Added by the KERGEZ.A WORM!"
Xcenter[random name]32.exe"Added by the BOFRA.A WORM!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
XCerbDivXx.exe"Added by the KEYLOG-LV TROJAN!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
UCertRegcertreg.exe"Related to Gemplus Card Reader"
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
Ycerttoolcerttool.exe"Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk)
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
XCEventMgrCell.exe"Added by the BIFROSE-AK TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
NcfFncEnabler.execfFncEnabler.exe"Toshiba ""Config Free"" wireless network manager on their range of laptops"
Ycfgintprcfgintpr.exe"Configuration Interpreter - part of Tiny Personal Firewall V4"
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xcfgmgr52"RunDLL32.EXE cfgmgr52.dllDllRun"
UCFi ShellToys Utility ManagerCFiShlMan.exe"Manager for CFi ShellToys from Cool Focus International Ltd - which ""puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
UCGServercgserver.exe"Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs"
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YCharter High-Speed Security Suitefspex.exe"Charter High-Speed Security Suite - security software in collaboration with F-Secure"
NChcenterchcenter.exe"IMSI HiJaak - ""the easiest way to convert
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Ucheatmonitorstart.exe"CheatMonitor surveillance software. Uninstall this software unless you put it there yourself"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
UCheckDialerChkDial.exe"Added by the CheckDialer modem connection monitoring tool"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
Xcheckrunelite***32.exe [* = random char]"EliteBar adware"
Xcheckrunelitelsj32.exe"Added by the MULTIDR-ER TROJAN!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
YCheckVCRIOMagic.exe"Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UCherryKeyManKeyMan.exe"Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys"
UChicoSyswebtmr.exe"Child Control parental control software"
UChikkaDefaultChikkaLauncher.exe"Chikka PC text messanger and IM client"
UChineseStarcstar.exeChinese language support software
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
XCHK Diskerchkdsker.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xchkdrviemon.exe"Detected by Symantec as the ADCLICKER TROJAN!"
Xchoperunlli32.exe"Added by the QQPASS-U TROJAN!"
NChristmas Music PlayerTTEST6.EXE"Christmas Music Player brings the music of the Christmas Holiday to your desktop"
?ChromeMarkkeysh.exe"Related to this. Don't know what keysh.exe does though and if it's required"
?ChronitelInitTVCHTVINIT.EXE"??"
Uchronochrono.exe"Chronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)."" Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
XCi Svrcisvr.exe"Added by the IRCBOT.AWN BACKDOOR!"
XCiaBackdoormsldr.comAdded by a VIRUS!
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
YCingular Communication ManagerCingularCCM.exe"Cingular Communication Manager - now taken over by AT&T. ""provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
XCirebonPunyaXXrocks.exe"Added by the BHARAT.A WORM!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
YClamWinClamTray.exe"ClamWin antivirus"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XClassesMSTAR2.EXE"""Switch"" premium rate adult content dialler variant"
XClassesmstart.exe"""Switch"" premium rate adult content dialler variant"
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XClean Mgrcleanmg.exe"Added by the IRCBOT.BBO BACKDOOR!"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
XCleanatorCleanator.exe"Cleanator rogue privacy program - not recommended
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
?CleanupProgramcleanup.exe"Sony Vaio related - what does it do and is it required? Located in a C:\Sonysys folder"
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
UCleverKeysCK.exe"CleverKeys - ""is free software that provides instant access to definitions at Dictionary.com
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClick Radio Tunerclickr~1.exe"ClickRadio - subscription service playing radio music via the internet"
NClick Tray CalendarClickT~1.EXE"ClickTray Calendar - shows holidays
NClickSight Launchercs.exe"Launcher for the ClickSight® marketing tool from ClickStream Technologies - which ""is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"""
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
UClient Access Taskbarcwbuitsk.exe"IBM iSeries Client Access taskbar
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xclipboard.execlipboard.exeAdded by an unidentified WORM or TROJAN!
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
Uclipdiaryclipdiary.exe"Clipdiary from Softvoile - ""Free Clipboard Manager for keeping the clipboard history"""
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
NClipTrakClipTrak.exe"
NClipTrakkerClipTrakker.exe"Cliptrakker - clipboard extender"
NCLISTARTCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
UCLMFrontPanelclmpanel.exe"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
XClock Manageramsngr.exe"Added by the SDBOT-XM TROJAN!"
UCloneCDCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
UCloneCDTrayCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
XClremmdc.exe"Added by the PURSCAN-AI TROJAN!"
XClrSchLoader[path to file]"ClearSearch adware"
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
?CM-SmWizardSmWizard.exe"SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
UCMGrdianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
Xcmrsfcmrsf.exe"Added by the DELF-HU TROJAN!"
Xcmrsscmrss.exe"Added by the DELF.DU TROJAN!"
Xcmrsscrmss.exe"Added by the DLOADER-EK TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
Xcmrstcmrst.exe"Added by the BANCOS.S TROJAN!"
Xcmrstcmrst.scr"Added by the DLOADER-FP TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
?CmUCRRunCmUCReye.exe"Related to Medion Display Information. What does it do and is it required?"
XCn323cnfrm33.exe"Added by the MIMAIL.G WORM!"
XCnfrm32cnfrm.exe"Added by the MIMAIL.D WORM!"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
NCnxDslTaskBarCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XCodeCleanCCIntro.exe"CodeClean rogue security software - not recommended"
UCodename Dashboarddashboard.exe"Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
Ucolorealcoloreal.exe"Makes colours sharper and brighter
NColorificHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCom+ Syscsrs.exe"Added by the FORBOT-BT WORM!"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
Ucom.codeode.cactusspamfiltercactusspamfilter.exe"Cactus Spam - free easy-to-use spam blocker"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
UComm Drivercommh32.exe"G Data ""PC Spion"". PC monitoring and surveilling software
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
UCommand WorkStation 4cws 4.exe"EFI's Command WorkStation makes ""managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information"" - for high-end print environments"
NCommCtrcommctr.exe"""Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!"". Available via Start -> Programs"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCOMMUNICATORCommunicator.exe"Part of Microsoft Office Communicator
UComodo FirewallCPF.exe"Comodo Firewall"
YCOMODO Firewall Procfp.exe"Comodo Firewall Pro"
UComodo Launch Pad TrayCLPTray.exe"System Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware
YCOMODO Memory Firewallcmf.exe"""Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack"""
XCompanionWizardcompwiz.exe"Part of WinAntiVirusPro 2007 rogue security software (and possibly others) - not recommended
UCompaq AlerterCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
UCompaq Knowledge Centersilent.exe & matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
?CompaqHW Comp Managercpqhcm.exe"Running on a Compaq laptop - any ideas?"
NCompaqPrinTrayprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
NCompaqSystraycpqpscp.exeCompaq System Tray icon
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
UComproRemoteComproRemote.exe"VideoMate TV tuner and capture card - remote control driver"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
XComTry Web Searcherwstray.exeComtry MP3 Downloader related - spyware
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
?Concurreconcurre.exe"??"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
NConmgrconmgr.exeStarts Winfax pro at startup
UConMgr.execonmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
XConnect2Partyconnect2party.exeAdult content dialler
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTAUTrayAppCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
UConnection KeeperConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
NConnection ManagerCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XConnectorSYS.EXE"Nunci premium rate dialer"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XContentEraserGDC.exe"ContentEraser rogue privacy tool - not recommended
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContraviroContraviro.exe"Contraviro rogue security software - not recommended
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
UControl CenterCenter.exe"Associated with Hawking Technologies
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
YControlCenterctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
NControlCentreTrayXWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCookie PalCPBRWTCH.EXE"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
UCookieJarCookiejar.exe"Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return. No longer being actively supported"
UCookiePatrolCookiePatrol.exe"CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NCoolwallpapercwm_tray.exe"Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers"
Xcoolwebprogramclrssn.exe"CoolWebSearch Smartsearch parasite variant"
NCopernic Desktop SearchDesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
UCopperheadrazerhid.exe"Razer Copperhead gaming mouse driver - required if you use the additional features and programmed keys/macros"
UCopy handlerCopy Handler.exe"Copy Handler lets you copy between hard disks
NCopyrightmwcpyrt.exeDisplays copyright information on IBM ThinkPads
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
XCore System Hardwaresyscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UCoreCenterCoreCenter.exe"MSI Core Center - motherboard utility for monitoring CPU speed
UCoreCenterCORECE~1.EXE"MSI Core Center - motherboard utility for monitoring CPU speed
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorel Photo DownloaderMediaDetect.exe"Related to Corel Photo Album"
NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
XCorelDraw ToolboxCorelDraw.exe"Added by the SDBOT-VZ WORM!"
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
?CORESYScoresys.exe"??"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
NCorrectConnectCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
UCostAwareniIPCApp.exe"NetInternals CostAware - download quota measuring tool"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
NCountry Selectpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
NCountrySelectionpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
?Coupon Offers??"??"
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
UCPATR10CPATR10.EXE"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba
UCPBrWtchCPBrWtch.exe"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
Xcplbrowse.exe"Added by the TACTSLAY.C TROJAN!"
?CPortPatchcppatch.exe"CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
UCPQAlertCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
UCPQEASYACCStartEAK.exe"Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XcprcprAdroar.com adware downloader
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCPU Managercpumgr.exe"Added by the PANDEM.B WORM!"
UCPU Power MonitorCpuPowerMonitor.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme). Associated with the ""Energy Saving"" feature of AI Gear - which ""is a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features."" Part of AI Suite"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
XCPU Watcher"rundll32.exe cpu.dllload"
Xcqlygworld_cup_.bat"Added by the WCUP.A WORM!"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
XCr**.exe [* = random char]Cr**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XCr**32.exe [* = random char]Cr**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
UCRBroadCastingCRBroadCasting.exe"CardReader2 from On Track Inovations Ltd. USB Card Reader"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
XCRCSScrcss.exe"Added by the IRCBOT-TH WORM!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
XCreate A MonstercreateAMonster.exe"Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related"
NCreateCDCreatecd.exeAdaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
NCreateCD50Createcd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
NCreateCD_Reminderreminder.exeReminder to create system recovery CD/DVDs on a Sony Vaio laptop or desktop
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative DetectorCTDetect.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
UCreativeMixerCTMIX32.EXE"Creative soundcard System Tray access to
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrisysTec SentrySentry.exe"CrisysTec Sentry rogue privacy program - not recommended"
XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
NCriticalUpdateWucrtupd.exe"MS Windows Critical Update Notification. If you want to keep Windows up-to-date
XCriticalUpdatewucrtupd.exe"Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
UCrossMenuCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menus
XCRP386 Networkingcrp386.exe"Added by the IRCBOT.N TROJAN!"
Xcrscrs.exe"Added by the AGOBOT-TJ WORM!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XCRSSCRSS.exe"Added by the AGOBOT-RM WORM!"
XCRSSlssas.exeAdded by an unidentified WORM or TROJAN!
Xcrssscrsss.exe"Added by the AUTORUN.FM WORM!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
XCrustydmcpl.exe"Added by the RUSTY WORM!"
Xcryptdlgcryptdlg.exeAdded by an unidentified TROJAN!
NCryptLoadRouterClient.exe"CryptLoad download manager"
Ucryptoexpertcexpert.exe"CryptoExpert from SecureAction Research. Advanced on the fly encryption system"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
Xcserv32cserv32.exe"Added by the STRATION.EC WORM!"
XCsimPlayerCsimPlayer.exe"Added by the KOOBFACE-AD WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Xcsrcscsrcs.exe"Added by the AGENT-HUA TROJAN!"
Xcsrscsrs.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xcsrsccsrsc.exe"Added by an unidentified VIRUS
XCSRSSCSRSS.EXE"Search page hijacker
XCsrsscsrss.exe"Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrsscsrss.exe"Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xcsrsscsrss.exe"Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssnwiz.exe"Added by the CHODE-J WORM!"
Ucsrsscsrss.exe"BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec"
XCsrssCSRSS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS"
Xcsrssssms.exeAdded by an unidentified malware
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
Xcsrss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XCSRSSUCSRSSU.exe"CoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!"
XCSRSSWCSRSSW.EXE"Added by the CWS-F TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
Xcssrscssrs.exe"Added by the BANCBAN-DW TROJAN!"
Xcssrss.execssrss.exe"Malware installed by different rogue security software including SpyKillerPro"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
UCTAPR2CTAPR2.exe"Console Launcher for the Creative Sound Blaster X-Fi series"
NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
UCTCMonitorCTCMonitor.exe"Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office
XCTDrive"rundll32.exe drvmod.dllstartup"
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
Xctflog managerctflog.exe"Added by the DONBOMB.A TROJAN!"
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
XctfmonmIRC.dll"Added by the DELBOT-E TROJAN!"
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
XctfnomrundIl32.exe"Added by the LEGMIR-AW TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
UCTHELPERCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XCTHelpercthelper.exe"Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
UCtrlVolCtrlVol.exe"Volume control key on Acer
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
?cttdpsrvcttdpsrv.exe"??"
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
NCurseClientCurseClient.exe"CurseClient add-on manager for World of Warcraft and Warhammer Online games"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
UCursorGizmoCursorGizmo.exe"Cursor Gizmo - cursor management utility"
NCursorXPCursorXP.exe"CursorXP from Stardock - tool for creating mouse cursors"
UCurtainCurtain.exe"Curtain (from Chaotic Visions) - ""is a Windows utility which gives you the power to hide any window or group of windows to your system tray"""
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
Xcvmonitor.execvmonitor.exe"Added by the SDBOT.BV WORM!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
Ncwbckvercwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ncwbsvstrcwbsvstr.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ucwcptraycwcptray.exe"Related to ContentWatch Parental Control internet filter"
Xcwriterucookw.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
Xcwritercwriter.exe"Part of PcRaiser
Xcximddlldfrmmd.exe"Added by the BUZUS.CQMU TROJAN!"
NCXMonHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
NCybercyberchk.exe"Part of Belkins ""Multimedia Cleaning Kit"" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after ""x"" amount of time has passed"
UCyber Trioshowmode.exe"From G-Tek Technologies. Allows you to set the PC in one of three modes
UCyber-Defender 2003uwcdsvr.exe"
NCyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
Xcyberfree.exe****.dat [* = random char]Unidentified adware
UCyberhawkCHTray.exe"Cyberhawk from Novatix. Protects against viruses
UCyberLat Ram CleanerCLRamCleaner.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UCyberLat Ram CleanerCyberLat Ram Cleaner 1.1.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
NCyberMedia AgentCMAGENT.EXE"Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge
UCyberPatrolNewcphq.exe"""CyberPatrol is one of the most powerful and popular client-based
XCyberWolfCyberWolf.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
XCyDoorCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
XCydoorUpdateCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
NCyphTrayCyphTray.exe"Cypherus - encryption software"
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
YD-Link Air UtilityAirCFG.exeD-Link Air PCI wireless driver and configuration utility
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus G Wireless UtilityAirPlus.exe"D-Link AirPlus G wireless configuration and monitoring utility"
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
XD3**.exe [* = random char]D3**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XD3**32.exe [* = random char]D3**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xdabrun"rundll32.exe dabapi.dllRundll32"
NDAEMON Tools ProDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTProAgent.exe"System Tray access to an older version of DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDaily Plannerdayplan.exe"Daily Planner - discontinued
XDaily Weather Forecastweather.exe"Added by the DLOADER-IP TROJAN!"
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
XDanBtR270414DanBtR270414.exe"Added by the VB-NIB WORM!"
UDancerDncLE.exe"Part of Microsoft Plus! Digital Media Edition - see here"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
Xdarkimgst.scr"Added by the BANCOS.U TROJAN!"
Xdarkimgrt.scr"Added by the BANCBAN-FH TROJAN!"
Xdarkcsrs.scr"Added by the BANCBAN-GT or BANCBAN-GU TROJANS!"
XDarkDevil.Grasiele.BRGrasiele.VBS"Added by the LEMBRA WORM!"
XDarKNesS LsasSLsasS23.exeAdded by an unidentified WORM or TROJAN!
?DashBarStatedashIE"??"
XData Layer 2datalayer.exe"Added by the RBOT-BNF WORM! Note - do not confuse with the legitimate Nokia file sharing the same filename - this one is located in %System%"
NData LifeGuardBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital's series of hard drives
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
XData Protectiondatprot.exe"Data Protection rogue security software - not recommended
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
XData789Regedit.exe ....data789.tmpHomepage hijacker
XDATABASE MySql[path] repcale.exe [path] beird.exe"Added by the RANDON-AL WORM! Both files are often located in %System%\qsws"
XDataHealerDataHealer.exe"DataHealer rogue security software - not recommended
UDataKeeperDataKeeper.exe"PowerQuest DataKeeper (now owned by Symantec) backup software"
YDataLayerDataLayer.exe"Part of Nokia PC Suite version 5 - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" Required by the Nokia status/connection monitor (NclTray.exe)"
YDataLayerDATALA~1.EXE"Part of Nokia PC Suite version 5 - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" Required by the Nokia status/connection monitor (NclTray.exe)"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word
XDate Managerdatemanager.exe"Date Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
?DatecheckerN/A"Could be related to this?"
XDateMakerIntlDateMakerIntl.exePremium rate adult content dialler
XDateMngrDATEMNGR.EXE"Added by the SPYBOT-BR BACKDOOR!"
UDAZEL Delivery AgentDcDaemon.exe"Control and send documents
Xdbar_starterstarter.exe"Deskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com"
Ndbservdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
UDC300 Monitorcmonitor.exeMonitor for a Acer DC300 digital camera
XDC6dc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDC6_checkdc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDCE Managerdcemgr.exe"Added by the TUMAG TROJAN!"
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
Xddeprocddeproc.exe"Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
UddhelperW815DM.EXE"Enuff Parental Control Software by Akrontech"
XDDiallerDDialler.exeAdult content dialler
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
NDeadAIM"rundll32.exe DeadAIM.ocm ExportedCheckODLs"
XDealHelperBrwsrdhbrwsr.exe"DealHelper adware"
XDealHelperDowndownload.exe"DealHelper adware"
XDealHelperUpdateDHUpdt.exe"DealHelper adware"
UDeathAdderrazerhid.exe"Razer DeathAdder gaming mouse driver - required if you use the additional features and programmed keys/macros"
XDebuggerdbg32.exe"Added by the MYTOB-FW WORM!"
XDebuggerexplorer32dbg.exe"Added by the CWS-M TROJAN!"
XDebuggeriexplore_dbg.exe"Added by the CWS-M TROJAN!"
Xdebuggerhelp.pif"Added by the DELF-DRA WORM!"
XDebugMonitordebugmonitor.exe"Added by the MYDOOM.BG WORM!"
Xdeejayforboo.exe"Added by the FORBOT-AY WORM!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
UDefault ManagerDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDefault_Page_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefault_Search_URLhttp://find.naupoint.com"Naupoint browser hijacker"
Xdefenderdefender25.exe"DollarRevenue adware"
Xdefenderdfndref_7.exe"DollarRevenue adware"
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?deferguidefergui.exe"Related to IBM Standard Software Installer. What does it do and is it required?"
UDefMgrDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
Xdefragm_checkdefragment.exe"CoolWebSearch parasite variant"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
UDefragTaskBardefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
UdefragTaskBar.exedefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
UDelaydelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
UDelayrundelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
NDelayShredShrCL.EXEMcAfee Shredder - not required at startup. You can run it manually via McAfee Security Center
?delcabdeltreew.exe C:cabs"??"
XDelete Meworm.exe"Added by the DOOMHUNTER WORM!"
UDeleteHistoryFreedhf.exe"Delete History Free - ""Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"""
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
NDell AlertDAMon.exe""Dell Alert" utility
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
UDell PanelMgrSSMMgr.exe"Monitors ink levels
UDell Photo AIO Printer 922dlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 942dlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 962dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor
YDell Webcam CentralWebcamDell.exe"Dell Webcam Central - webcam management software controlling aspects such as picture control
NDELL Webcam ManagerDellWMgr.exeDell Webcam Manager - Webcam management software provided on Dell PCs
NDell Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
UDellSupportCentersprtcmd.exe /P DellSupportCenter"Dell Support Center (provided by SupportSoft
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
?delstartdelstart.exe"Reportedly part of BT ISP software - what does it do and is it required in startup?"
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
UDeltaIITaskbarAppDeltaIITray.exe"System Tray access to the Delta Control Panel for the M-Audio Delta series of PCI audio cards"
NDeltTraydeltray.exe"System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut
XDELXP Protocoldelxp.exe"Added by a variant of the SDBOT WORM!"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
UDepFrezfrzstate.exe"Deep Freeze from Faronics Coporation. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
XDesiredesires.exeAdult content dialler
?desk-top-servicedesk-top-service.exe"??"
XDeskAd ServiceDeskAdServ.exe"DeskAd.Service adware"
NDeskColorDESKCOLOR.EXEProvides transparent icon text backgrounds and coloured icon text
Udesksaverdesksaver.exe"Part of Advanced Desktop Shield
UDeskSaverDeskSaver.exe"DeskSaver from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". The Pro version also includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
UDeskSaver ProDeskSaver.exe"DeskSaver Pro from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". Includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
Udesksaver.exedesksaver.exe"Part of Advanced Desktop Shield
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
NDesktop ArchitectDATRAY.EXE"Desktop theme manager available
YDesktop ArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktop CalendarDesktop Calendar.exe"Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
UDesktop iCalendarCalendar.exe"Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather
UDesktop iCalendarDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendarDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop iCalendar LiteDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar Lite.exeDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar.exeDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop Maestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktop Maestro Vista TrayRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
XDesktop Searchdesktop.exe"iSearch adware"
XDesktop Security 2010Desktop Security 2010.exe"Desktop Security 2010 rogue security software - not recommended
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
NDesktop WeatherTHE WEATHER CHANNEL.exe"Desktop Weather by The Weather Channel - provides current temperature
NDesktop Weather 3THE WEATHER CHANNEL.exe"Desktop Weather 3 by The Weather Channel - provides current temperature
NDesktop Weather 3THEWEA~1.EXE"Desktop Weather 3 by The Weather Channel - provides current temperature
YDesktopArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktopMaestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktopMaestroRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
Ndesktopmgrdesktopmgr.exe"Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
Xdestroyb11destroyb11.exe"Added by the DELF-KO TROJAN!"
?detectturbodetect.exe"??"
NDetectordetector.exe"USB port detector for LG scanners. Sits in the System Tray
UDetectorAppDetectorApp.exe"Related to Roxio MyDVD (was Sonic) DVD authoring software"
XDeus CleanerDCleaner.exe"Deus Cleaner rogue system cleaner utility - not recommended"
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevelopment Environmentdevenv.exe"Added by the DELBOT-AH WORM!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UDevice DetectorDevDetect.exe"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
NDevice Detector 2DevDtct2.exe"Installed by various Olympus products
XDevice Hardwaredevicehnd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managerwfxmgr.exe"Added by the RBOT.AJU WORM!"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Driverdevicesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
XDevicePathProyecto1.exe"Added by the GRUEL WORM!"
XDevicePathRoot.exe"Added by the GRUEL WORM!"
UDevicesolesvr.exe"Salfeld Child Control - parental control software"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Udevldr16devldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Udevldr16.exedevldr16.exe"Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
Xdgtstartdgtstart.exe"DigitalNames.g adware"
Udguarddguard.exe"eAcceleration Stop-Sign security software related. Previously not recommended
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDialer"rundll32.exe MSA32CHK.dllReg"
UDialer Controldc.exe"Dialer-Control. Detects and protects from premium rate adult content diallers"
UDialer Detectdd.exe"DialerDetect detects stealth installed premium rate diallers
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
NDialog HelperPDDLGHLP.EXE"Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs"
XDialUp Network ApplicationRnaap.exe"Added by a variant of the SDBOT WORM!"
XDiam prlaeroqedrhg.exe"Added by the SDBOT-DEU WORM!"
UDiamondbackrazerhid.exe"Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
XDIECOXcsrss.exe"Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XDieselRecalculate.exe"Added by the LAZAR TROJAN!"
UDigisoft AntiDialerAntiDialer.exe"Digisoft AntiDialer"
UDigiSrvDigiSrv.exe"Related to camera software from DigitalDreams"
NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
YDigital Patrol Update 5update.exe"Digital Patrol - ""a powerful anti trojan scanner
XDigital Protectiondigprot.exe"Digital Protection rogue security software - not recommended
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases
XDigitalNamesDigitalNamesStart.exe"DigitalNames spyware variant"
NDigitalWizardISWizard.exe"InstallShield's DigitalWizard - free
NDigitalWizard MonitordwMon.exe"InstallShield's DigitalWizard - free
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
NDIGStreamdigstream.exe"DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
XDir1caKe"Added by the CAKE WORM!"
XDirect settingssdchost.exe"Added by the DAEMONI-I TROJAN!"
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
XDirect X Direct3Ddxd3d.exe"Added by a variant of the SDBOT WORM!"
XDirect X Opengldxopengl.exe"Added by a variant of the RBOT-CJ WORM!"
Xdirect3d.exedirect3d.exe"Added by the CERTIF-F TROJAN!"
NDirectCDDirectCD.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
XDirector Videobtnmgern.exe"Added by the MYTOB-KL WORM!"
YDirectory Opus Desktop Dblclkdopusrt.exe"Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor
Xdirects.exedirects.exe"Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
UDIRECTVDSLDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
XDirectXddhelp32.exe"Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
XdirectxDirectx.exe"Added by the SDBOT.D TROJAN!"
XdirectxSqlexploit.exe"Added by the SDBOT.D TROJAN!"
XDirectXDirectX.exe"Added by the BLAXE or LOGPOLE WORMS!"
XdirectxNTCmd.exe"Added by the SDBOT.D TROJAN!"
XdirectxPipeCmd.exe"Added by the SDBOT.D TROJAN!"
XDirectX 32directx32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
XDirectX Video Driverdxterm5.exe"Added by the WILAB-A TROJAN!"
XDirectX64DirectXset.exe"Added by the BROWNEY.A WORM!"
XDirectX9direct3d.exe"Added by the AGENT.EAK TROJAN!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
XDirectX9 Diagdx9diag.exe"Added by the RBOT-ALT WORM!"
XDirecXDirecX.exe"Added by the AGOBOT-HU BACKDOOR!"
UDirkeyDirkey.exe"Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders"
XDirLockerdirlock.exe"Added by the AUTORUN-AMS WORM!"
XDisableKeybaord"Rundll32.exe KeyboardDisable"
XDisableMouse"Rundll32.exe MouseDisable"
NDisc DetectorCtNotify.exe"For Creative sound cards. Detects when you insert a CD
?disc detectorqnetquestnotifty.exe"??"
?DISCoverDISCover.exe"Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
UDiscWizardMonitor.exeDiscWizardMonitor.exe"Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
UDisk CleanerDiskCleaner.Exe"Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
XDisk KeeperSECURITY.EXE"Daosearch adware"
XDisk Managerdiskver.exe"Added by the RBOT.AQT WORM!"
XDisk Master[trojan name]"Added by the DISTER TROJAN! - a spam relayer"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDiskCheckmsdarkend.exeAdded by an unidentified WORM or TROJAN!
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
XDiskRetterSysRep.exe"DiskRetter
XDiskstartCode.exeAdult content dialler
XDiskstartcat.exeMS-Connect dialler
XDiskstarthit.exeAdult content dialler
XDiskstartSnt.exeAdult content dialler
UDiskSuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
UDisk_MonitorDisk_Monitor.exe"Multi-media
XDispatcherdispatcher.exe"Added by the DLOADR-AS TROJAN!"
Xdispenterdispenter.exe"Added by the AGENT-MKK TROJAN!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
NDisplayTrayIconTrayIcon.exe"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDistributed Link Trackingascvt.exe"Added by the AGOBOT-GH BACKDOOR!"
Udistributed.net clientDNETC.EXE"Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
XDivx4 codecdevldr32.exe"Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
?Dixons Insert DetectInsDetect.exe"Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
Xdjtopr1150.exedjtopr1150.exe"WebRebates adware"
XdKerneldKernel.exe"Added by the DECOY-A WORM!"
YDkServiceDkService.exe"From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Ydlatfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
YDLADLACTRLW.EXE"Drive letter access to a UDF packet writer for CD-RW - from HP
YDLACTRLWDLACTRLW.EXE"Drive letter access to a UDF packet writer for CD-RW - from HP
YDLACTRLW.EXEDLACTRLW.EXE"Drive letter access to a UDF packet writer for CD-RW - from HP
NDlaTrayDlatray.exe"System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
Xdlderdlder.exe"Dlder spyware. Also creates a fake ""explorer.exe"" file and can be installed via versions of Grokster
XDlDir1caKe"Added by the CAKE WORM!"
?DLForcerExeDLForcerEXE.exe"??"
NDLHelperEXEWATCH.exeDownload helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDlitedllmanager.exe"Added by the WOOTBOT.DN WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDLL Managerdllmngr32.exe"Added by a variant of the RBOT WORM!"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDllCacherv2dllcachev2.exe"Added by the LATEDA TROJAN!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDllLoaderlssas.exe"Added by the BDOOR-JE BACKDOOR!"
XDlloadkiller.exe"Added by the KILLAV-FK TROJAN!"
Xdllregdllreg.exe"Added by the CRYPTER.A TROJAN!"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
NdlmMgrAdobeDownloadManager.exe"Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted
XDm Hrlpns.exe"Added by the IRCBOT.WORM.61673 WORM!"
XDM mgrdm_mgr.exe"Added by the JITTAR TROJAN!"
Xdm***.exe [* = random char]dm***.exe [* = random char]"Wareout - malware masquerading as a spyware and dialer remover"
NDMASchedulerDMAScheduler.exe"Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program
UDMHotKeyDMLoader.exeHotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
NDMILDRdmildr.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
Xdmloaderdmloader.exe"Added by a variant of the RBOT WORM!"
UDMXLauncherDMXLauncher.exe"Part of Dell's Media Experience
Xdm[3 random letters].exedm[3 random letters].exe"Added by the RUINDEM TROJAN!"
XDM_serverdmserver.exe"Comet Cursor adware"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
NDnarDnar.exe"Installed on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?"
YDNE Binding Watchdog"rundll dnes.dll DnDneCheckBindings"
YDNE DUN Watchdog"rundll dnes.dll DnDneCheckDUN13"
XDNHelper32DNHlp32.exeAdded by an unidentified WORM or TROJAN!
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
Xdnscleanerdnscleaner.exe"CoolWebSearch parasite variant"
XDocTorDoctor.exe"Added by the DOTOR.A WORM!"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
UDocument Managerdocmgr.exe"Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
XDOGStartGSDOGST.EXE"Added by an unidentified VIRUS
XDokterFixSysRep.exe"DokterFix
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
UDon't Panic Pop-Up Stopperdpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
XDontworrymysaym.exe"Added by the SDBOT-RC WORM!"
NDoroServerDoroServer.exe"Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
NDownload Accelerator Manager Free Editiondam.exe"Download Accelerator Manager Free Edition from Tensons Corp"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
NDownload WonderDownloadWonder.exe"Download Wonder from Forty Software. Download manager for resuming downloads
NDownloadAcceleratorDAP.EXE"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadWaredw.exe"DownloadWare adware"
XDownloadWare EngineDwe.exe"DownloadWare adware"
Xdpcproxydpcproxy.exe"Added by the GOLDENP-A TROJAN!"
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
YDpcstartdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
Ndptrackerdptracker.exe"CamTrack webcam software that enhances the way people video chat"
UDpUtilTEDTray.exe"Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device"
XdpzProtectn.vbe"Added by the RUNAUTO.H WORM!"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
XDr. Guarddrguard.exe"Dr. Guard rogue security software - not recommended
NDrag'n'Drop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
NDrag-to-DiscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
?DragDropDragDrop.exe"??"
NDragnDrop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
XDRam Monitor 23tskman3.exe"Added by a variant of the RBOT WORM!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosessorplscd.exe"Added by the RBOT.CYA WORM!"
XDRam prosessorHWAPI.exe"Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDRan posessorDAP.exe"Added by a variant of the SDBOT WORM!"
XDrAntispyDrAntispy.exe"DrAntiSpy rogue security software - not recommended"
XDrCacheMSTDC.EXE"Added by the BDOOR-JM BACKDOOR!"
Xdreamsserver.exe"Added by a variant of the SDBOT WORM!"
XDrefIWSysDrefIWv2.exe"Added by the DREF-C WORM!"
XDrefIWSysDref.exe"Added by the DREF-D WORM!"
?dregfixph_finder.exe"??"
NDrgToDscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
?dried.exedried.exe"??"
Xdrin[path to trojan]"Added by the SMALL.DPB TROJAN!"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
XDriveCleaner FreeUDC.exe"DriveCleaner rogue security software - not recommended
XDriveDefenderGDC.exe"DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
UDriveLEDOODLed.exe"O&O DriveLED - hard disk monitoring and crash prevention"
XDrivergbot.exe"Added by the JUNTADOR.K TROJAN!"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
NDriverMaxdevices.exe"DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
NDriveSelectdriveselect.exe"DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
Udrkly16j"rundll32.exe drkly16j.dll ServiceCheck"
XDRM Upgradedrmupgd.exe"Added by the IRCBOT.AWU BACKDOOR!"
UdRMON SmartAgentSmartAgt.exe"Part of the network monitoring program group for 3Com NIC cards. See here for more info"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XdrmuW95Mm.exeHomepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
XDrmupgdsDrmupgds.exe"Maxfiles adware"
Xdrocherd.exeAdult content dialler
XDropSpam Lifestyledslifestyle.exe"Dropspam adware"
XDrProtectionDrProtection.exe"DrProtection rogue security software - not recommended"
Xdrvddll.exedrvddll.exe"Added by the BEAGLE.AP WORM!"
XDrvddll_exedrvddll.exe"Added by the BEAGLE.X WORM!"
UDrvIconDrvIcon.exe"""Vista Drive Icon changes the drive icons shown in Windows ""My Computer""
?DrvListnrDrvListnr.exe"Analog Devices SoundMAX soundcard related. What does it do and is it required?"
Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
UDrvMon.exeDrvMon.exe"Alcor drive monitor software"
Xdrvnetwdrvnetw.exe"Added by the BROGGER-B TROJAN!"
Xdrvr32hdrvr32h.exe"Added by an unidentified VIRUS
Xdrvrmanagerdrvrquery32.exe"Added by the BOOHOO WORM!"
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
Xdrvsys.exedrvsys.exe"Added by the BEAGLE.W WORM!"
Xdrvsyskithidr.exe"Added by the BAGLE.HR WORM!"
Xdrvsyskithldrrr.exe"Added by the BAGLE.QU TROJAN!"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
Xdrv_st_keyhidn.exe"Added by the BEAGLE.FF WORM!"
XDrWatsondrwatson_.exe"Added by the LOHAV-S TROJAN!"
XDrWatsondrwatson_32.exe"Added by the LOHAV-S TROJAN!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
YDrwebschedulerDrwebscd.exe"DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications
XDR_SDR_S.exe"IstBar adware"
NDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
NDSL Monitorspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
XDsmSerdsm.exe"Added by the SERFLOG.B WORM!"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UDT 11Mbps WLAN PC Card StationDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT 11Mbps WLAN USB StationDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
NDU MeterDUMETER.EXE"Hagel Technologies internet bandwidth monitor"
UDualCoreCenterStartUpDualCoreCenter.exe"Unified control center for overclocking both the graphics card and the CPU
?Duane Reade Insert DetectInsDetect.exe"Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
NDulux WeatherShield WeatherDeskweather.exe"Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
Xdumprepspoolc.exe"Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
Xdumprepdump-k.exe"Added by the BUZUS-U WORM!"
Xdumprepdump.exe"Added by the CODOX-A WORM!"
Ndumprep 0 -kdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Ndumprep 0 -udumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XDuwee wong CerbonCirebons.exe"Added by the BHARAT.A WORM!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
XDVD Upgradedvdupgd.exe"Added by a variant of the IRCBOT BACKDOOR!"
Ndvd43DVD43_Tray.exe"DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
NDVDLauncherDVDLauncher.exe"Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
NDVDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
NDVDTrayDVDTray.exeHP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
NDVDUpgradeDVDUpgrd.exe"Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
YdvprptDvprpt.exe"Command Antivirus related"
Xdvraudiodvraudio.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
NDW4Weather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW4DesktopWeather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW6DesktopWeather.exe"Desktop Weather 6 by The Weather Channel - provides current temperature
UDWHeartbeatMonitorDWHeartbeatMonitor.exeDWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
NDwlClientsupport.exeDownload manager for Dell support alerts
Xdwqblwppx.exe[random].exe"Okcashbackmall adware"
Xdwqblwpvl.exe[random].exe"Okcashbackmall adware"
Xdwqblwrsq.exe[random].exe"Okcashbackmall adware"
UDWQueuedReportingdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
NdwStartFireWall.exe"The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
Udwtrig20dwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
XDW_Startrwwnw64d.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
XDxsys*.exe [* = random number]"Added by the DEXTER.A WORM!"
NDXDllRegExedxdllreg.exe"Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it"
XDxLoadDX3DRndr.exe"Added by the GIBE.B WORM!"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
XDyFuCA Active Alertactalert.exe"Adult content dialler - see here"
XDynamic Dns Binarydynitora.exe"Added by the RBOT-WT WORM!"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
XDynamic Link Library loaderLoader32.exe"Added by the KOL TROJAN!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
XDynHttp Dns Binarydynizari.exe"Added by a variant of the RBOT WORM!"
XE-Cardecard.exe"Added by the YODI WORM!"
UE-colorIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
NE-Color RegistrationSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
XE-nrgyPlusE-nrgyPlus.exe"Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
Ue-Surveiller Stationestation.exe"ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
UE06DXLRD_7604703EDICT.EXE"Related to Microsoft Encarta dictionary functions"
NEA CoreCore.exe"Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
XEac_Cnrycanary.exe"Added by the CANARY TROJAN!"
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
YEAFRCliStartEAFRCliStart.exe"Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
Ueanth_critical_update_alertsys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertEANTHO~1.EXE"eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted
Ueanth_system_patchersys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
NEAPCISETUPwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
NEarthLink ToolBar 5.0etoolbar.exe"EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar
NEasy CD CreatorRoxAssist.exe"Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize
NEasy Start Buttonesb.exeProvides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
UEasyKeyboardLoggerEasyKeyboardLogger.exe"EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup
NEasyNetworkMcENUI.exe"McAfee's EasyNetwork user interface - ""enables secure file sharing
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
XeasyServServer.exe"Added by the EASYSERV TROJAN!"
XEasySpywareCleanerEasySpywareCleaner.exe"EasySpywareCleaner rogue spyware remover - not recommended
UEasySync ProXCPCMenu.exe"""IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAutoDetect.exe"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
XeBay ToolbarEBAYTBAR.EXE"eBay Toolbar - reportes as spyware as it "phones home""
UeBayToolbareBayTBDaemon.exe"eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
UeBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
NeBotDownloadWizard.exe"eBot from Digital River - ""helps ensure your computer always has the latest technology
UECentergtb.exeDell E-Center/Google Toolbar related
NECenterEULALauncher.exeEnd User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
Xeckoclaro.exe"Added by the DLOADR-AQJ TROJAN!"
UeDataSecurity LoadereDSloader.exe"Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons
Nedexteredexter.exe"eDexter supplements internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser"
NEDLoaderDTLoader.exeEffective Desktop from MiniStars Software - desktop management software no longer being supported
UEDRestore??"Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
UEdwizardEdwizard.exe"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
XEechhoor.exe"PurityScan adware"
NEEventManagerEEventManager.exe"Part of the Epson Creativity Suite supplied with their multi-function printer/scanners
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
UeFax 4.1J2GTray.exe"System Tray access to version 4.1 of eFax Messenger from j2 Global Communications
UeFax 4.2J2GTray.exe"System Tray access to version 4.2 of eFax Messenger from j2 Global Communications
UeFax 4.3J2GTray.exe"System Tray access to version 4.3 of eFax Messenger from j2 Global Communications
UeFax 4.4J2GTray.exe"System Tray access to version 4.4 of eFax Messenger from j2 Global Communications
NeFax Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
UeFax Tray MenuJ2GTray.exe"System Tray access to eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.3J2GTray.exe"System Tray access to version 3.3 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.5J2GTray.exe"System Tray access to version 3.5 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 4.0J2GTray.exe"System Tray access to version 4.0 of eFax Messenger from j2 Global Communications
NeFax.com Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
UEFI Hot Foldershffw.exe"""EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select
UEFI Job Monitor"[path] efjm.dllrun"
UehTrayehtray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
UehTray.exeehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
UEicon NetworksLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
XeKerberoseKerberos.exe"eKerberos rogue security software - not recommended"
UELBERTRicoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
UELBERT_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
UElectron MicroscopeEMIII.exe"Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
UeLerteLert.exe"eLert Emergency Notification System by Kennected Software - ""is an internet based public notification system designed to get emergency and non-emergency information out to the public quickly
XEliteProtectorEliteProtector.exe"EliteProtector rogue spyware remover - not recommended
?ElkCtrlElkCtrl.exeEntry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
XELNKProxysmproxy.exe"Surfmonkey adware"
YElsaCapiCtlRcapi.exe"Assumed to stand for Remote Common Application Programming Interface (RCAPI)
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
UeMachines eBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
YEmail Protectionemlproxy.exe"AntiVirus Quick Heal - E-mail protection"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
XeMessengeremsn.exe"Added by the RBOT.AHO BACKDOOR!"
UEMMeterEMMeter.exe"""Express Meter lets you track and manage software usage so you can avoid purchasing and supporting applications that aren't being used
Xemoc0reemo.exe"Added by the AGOBOT-AGE WORM!"
?Empowering Technology LaunchereAPLauncher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
?EmpoweringTechnologyFramework.Launcher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
Xemre1emre1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
NeMuleAutoStartemule.exe"eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project
NeMusicClient SystrayeMusicClient.exe"eMusic MP3 download software"
NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
XenBrowser[name of file]"WINBO adware"
?encapsulated command toolwintr.com"??"
NEncarta Dictionary QuickshelfQSHLFED.EXE"Provides quick access to Encarta's Dictionary features?"
NENCMONITORmonitor.exeThe Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
NEncoder AgentWMENCAGT.EXE"MS Windows Media Encoder
UEncompass_ENCMONTRENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
?ENCSurfsurfboard.exe"??"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
XEnergyPlugInEnergyPlugin.exe"EnergyPlugin adware variant"
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UEnsoniqMixerstarter.exe"Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
UEnterprise HarmonyrsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
UEnterra Icon KeeperIcnKeepr.exe"Icon Keeper - ""tool to save and restore icon positions on the desktop"""
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UePowerManagementePM.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UePower_DMCePower_DMC.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
UePrompterePrompter.exe"ePrompter - E-mail notification software"
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Status Monitor 3E_[various].EXE"Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C45 SeriesE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C66 SeriesE_S4I0S2.EXE"Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status
UEPSON Stylus C67 SeriesE_FATIAAL.EXE"Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C87 SeriesE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
UEpsonPhotoStarterEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this
XEptrnopdb.exeAdded by an unidentified WORM or TROJAN!
XEQArticleEQArticle.exe"EQArticle adware"
Xeraseplgeraseplg.exe"Added by the GENOME.AQUV TROJAN!"
UErasereraser.exe"Eraser - ""an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns"". This entry starts the Scheduler with Windows and provides a System Tray icon for on-demand access. Located in %ProgramFiles%\Eraser"
Uerasereraser.exe"Part of Evidence Exterminator
Ueraser.exeeraser.exe"Part of Evidence Exterminator
YeRecoveryServicecheck.exe"Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceeRAgent.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
NEregreg32.exe"EReg is a software registration tool incorporated on products such as those by Broderbund
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
?ermerm.exe"??"
XErocaEroca.exe"Insider.i adware"
Xeros.exeeros.exeAdult content dailler
XErrCleanSysRep.exe"ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XErreurChasseurSysRep.exe"ErreurChasseur
NError NukerErrorNuker.exe"ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required"
XError Safeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XError Safe Freeuers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorFixErrorFix.exe"ErorrFix rogue system error and cleaning utility - not recommended
XErrorGuardErrorGuard.exe"ErrorGuard rogue spyware remover - not recommended
Xerrorhandlererrorhandler.exe"ErrorHandler adware"
XErrorProtector Freeertmain.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
XErrorRepairToolErrorRepairTool.exe"ErrorRepairTool rogue system error and cleaning utility - not recommended"
XErrorSafeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeFreeUERS.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorWizErrorWiz.exe"ErrorWiz rogue system error and cleaning utility - not recommended
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERScwERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_Checkuwasers.exe"Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
Xerthgdrsvc.exe"Added by the BEAGLE.BN or BEAGLE.BP WORM!"
Xerthgdr2svc23.exe"Added by the BAGLE.CG WORM!"
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Xertyuoprttrwq.exe"Added by the AUTORUN-APA WORM!"
UERUNT AutoBackupAUTOBACK.EXE"ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots
Xerwghjjrjtucbcg.exe"Added by the SMALL.CUL TROJAN!"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
YeSafe ProtectESPWatch.exe"eSafe from Aladdin - internet security for gateway and E-mail servers"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
XEScorcherescorcher.exe"Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
XEsphortu.exe"PurityScan adware"
XETB Testeretbtest.exe"Added by the RBOT-ABR WORM!"
Xetbrunelit***32.exe [* = random char]"EliteBar adware"
UeTCertMangereTCrtMng.exe"eToken Certificate Manager from Aladdin Knowledge Systems
UETDWareETDCtrl.exeElantech smart-pad touchpad driver for the Asus Eee PC range
Xeth0 driverexec.exe"Added by the SPYBOT-Z WORM!"
NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEthernet Linkingethernet.exe"Added by a variant of the IRCBOT TROJAN!"
XEtrafficJavaRun.exe"TopMoxie adware"
YeTrust EZ Firewallefpeadm.exe"eTrust EZ Firewall"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XeTrust Realtime Monitorrealmon.exe"Added by the LAZAR.B TROJAN!"
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
UEudoraEudora.exe"Eudora from Qualcomm allows you to receive and send Internet e-mails"
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
UEuroGlotEuroGlot.exe"Euroglot - ""multilanguage translating system
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Reminderpmremind.exe"Event reminder for calendar dates
UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
Neventmgreventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Xeventwvreventwvr.exe"Added by the COSIAM_G TROJAN!"
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
UEVGAPrecisionEVGAPrecision.exe"EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible
UEvidence Cleanerecleaner.exe"Evidence Cleaner cleans up tracks left by your PC and Internet activities"
NEvidence Eliminatoree.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
UEvoluent Mouse ManagerEvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
UEvtMgr6Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
NeWare StartupiWareStart.exe"eWare iWare task bar. Not required"
Yewido anti-spywareewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
Xewrgetujgeurge.exe"Added by the AUTOINF-AK WORM!"
Xewupdaterewupdater.exe"EasyWebSearch adware updater"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
NExcite PlatformExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
?Excite Private Messenger Pipex8impipe.exe"??"
XExecUserExecUser.exe"Added by a variant of the RBOT WORM!"
?Executedelfolders.exe"??"
XExeName32Warm.scr"Added by the SCOLD WORM!"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
UExif LauncherExiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
UExif LauncherQuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
UExitKillerEkiller.exe"Exit Killer - automatically closes pop-up windows in your browser"
?exmonhpimoniter.exe"Some kind of hp digital camera maybe or a photo smart connection probe?"
Xexp1orer.exeexp1orer.exe"Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
XexplerUpdadv.exe"Added by the QQPASS-N TROJAN!"
Xexplord.exeexplord.exe"Added by the DLOADR-AYW TROJAN!"
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreExplorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
Xexploreff.exeexploreff.exe"Added by the FINFANSE TROJAN!"
Xexplorep.exeexplorep.exe"Added by the LINEAG-I TROJAN!"
Uexplorerexplorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorershellexpl.exe"Added by the SHELDOR TROJAN!"
Xexplorerexpl32.exe"Added by the RATSOU TROJAN!"
XExplorer[path to worm]"Added by the AUTEX WORM!"
XExplorershellexp.exe"Added by the AGENT-ZY TROJAN!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XEXPLORERsys.exe"Added by the SILLYFDC-A TROJAN!"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
Xexplorerexplorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
XEXPLOREREXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
Xexplorerexplorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
XExplorer Loaderexplr32.exe"Added by the AGOBOT.N WORM!"
XExplorer Loaderexplorerl.exe"Added by the SDBOT-ADI WORM!"
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XExplorer32Expl32.exe"Added by the HACKTACK.B TROJAN!"
XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
XExplorerTaskexplorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
UExpress ClickYesClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt
NExtender Resource MonitorRMSysTry.exe"Related to Windows Media Center from Microsoft"
XExternal DependenciesExternal.exe"Added by the MYTOB.EC WORM!"
XExtra AntivirusExtraAV.exe"Extra Antivirus rogue security software - not recommended
UExtraDNSExtraDNS.exe"ExtraDNS - DNS configuration tool"
NExtraFilmHemmaAgentAgent.exe"ExtraFilm Photo Assistant"
?Extranet AutoDialAutoExt.exeNortel Networks Contivity Extranet Switching Software
?ExxtremeHelperDemonexxdemon.exe"Creative Exxtreme graphics card related?"
NEye Tide Launcheroneeyetideone.exeNascar wallpaper
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
YEZ Firewallca.exe"eTrust EZ Armor Internet Security"
UEZ-DUB FinderEZ-DUB.exe"Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
NEZEJTRAYEZEJTRAY.EXE"System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NezHelperezHelper.exe"Part of the ezPeer+ ezHelper music sharing program."
?EZNORUNEZNORUN.EXE"Easy Internet related?"
NEzPrintezprint.exe"Lexmark Fast Pics - helps users of their printers to enhance
YezShieldProtector for PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UEZSMART Appezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
YF-Secure TNBTNBUtil.exe"F-Secure antivirus"
Uf1Tray.exeF1TRAY.EXE"System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
UFabrik Ultimate Backup Statusfabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
Xfarkrishfarkrish.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
Xfarmmextfarmmext.exe"VX2.Transponder parasite updater/installer related"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
NFAST DefragFAST2.EXE"FastDefrag defragmenting software"
XFast Searchsvcnv.exe"Homepage
XFast startNtut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
NFastTrack AcceleratorSPEED UP.EXE"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
NFastUserfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
NFastUsrfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
XFat32 Microsoftfat32.exe"Added by the RBOT-EL WORM!"
UFatpipe Dialerfpdialer.exeDailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Ufatrecovfatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
UFBDirectFBDirect.exe"Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSearchSearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
Xfcrunfc.exe"Added by the CAMPURF WORM!"
XFdaemon securityfsecur.exe"Added by the SDBOT.KXO WORM!"
XFdr Command Modulesp2.exe"Added by the SDBOT.WP WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
Ufeedreader.exefeedreader.exe"""Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"""
Xfeelalrightmirc.exe"Added by the IRCFLOOD-M WORM!"
UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
UFellowes ProxyR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
UFerrariWallPaperFerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
XFestplattenReinigerGDC.exe"FestplattenReiniger
Xff[path to worm]"Added by the RBOT-XL WORM!"
Xffisffisearch.exe"iSearch adware"
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
XFhzepgyiHELLRAIDER.EXE"Added by the MINDCTRL.A BACKDOOR!"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XFile Systemtaskmqrs.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XFile Systemtaskmqr.exe"Added by the RBOT.BWQ WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFile-Sharing Wizardshwizard.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFile1Dia Claro.htm"Added by the DLOADER-OR TROJAN!"
XFileFreedom_Pluginwtm.exe"FileFreedom peer-to-peer sharing program"
Nfilehippo.comUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
NFileHippo.com Update CheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
UFilterGatefiltergate.exe"Filtergate internet filtering software - filters sounds
UFilterguardFiltrgrd.exe"An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian
XFilterProgramGDC.exe"FilterProgram rogue privacy tool - not recommended
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
XFindHack[path to worm]"Added by the KELVIR-BA WORM!"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFireFoxfirefox.exe"Added by the RBOT-ATP WORM! Note - this is not the popular FireFox web browser and is located in %System%"
XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
UFirefox PreloaderFirefoxPreloader.exe"Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
Xfirefox.exefirefox.exe"Added by the BANKER-EBO TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
YFirePodFIREPOD.EXE"Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFirevall Administratingrndll.exe"Added by the PUSHBOT-B WORM!"
Xfirewalfirewal.exe"Added by the BANCBAN-QY TROJAN!"
XFirewallwmlaunch .exe"Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
XFirewallwmlaunch .exe"Added by the ELIPTER.D WORM!"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
XFirewallFirewall.bat"Added by the YPSAN.G WORM!"
Xfirewallfw_304.exe"Added by the BDOOR-JQ BACKDOOR!"
XFirewallctfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
Xfirewallfirewall.exe"Added by the SURO-A TROJAN!"
Xfirewall 2008logoneui.exe"Added by the SILLYFDC WORM!"
XFirewall Administratinginfocard.exe"Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall PolicyMidiDef32.exe"Added by the PIEBOT-A TROJAN!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
XFirewall.exeFirewall.exe"Added by the AGENT.AGL BACKDOOR! Located in %System%"
YFireWall.exeFireWall.exe"Ashampoo® Firewall PRO and Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG. Located in an Ashampoo related sub-directory of %ProgramFiles%"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
YFirewallGUIFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
UFirewallStartupFirewallstartup.exe"Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean
XFirewallSvrFirewallSvr.exe"Added by the NETSKY.X or NETSKY.Y WORMS!"
Xfirewall_antifirewall_anti.exe"Added by the NETDENY-B TROJAN!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFirst Home Pagehttp://find.naupoint.com"Naupoint browser hijacker"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Player2[path to worm]"Added by the IRCBOT.PD WORM!"
XFlashget Download ManagerFlashget.exe"Added by the RBOT-AGZ WORM!"
XFlashGuardFlashGuard.exe"Added by the AUTOIT.AL WORM!"
NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
XFlash_Player_Installying.exe"Constructor VC2000 malware"
UFlingRunfling.exe"Fling - free FTP software from NCH Software"
UFLMBROWSERMOUSEmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMTRUSTMOUSEmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
XFLooDNeTFLooDeR.exe"Added by the ENDOOL TROJAN!"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
UFmctrlTrayFmctrl.EXEGenius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
UFMStartFmstart.exe"GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolder Viewfolderview.exe"Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
XFolderRaper[path to worm]"Added by the VB.GOZ WORM!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
XFont Viewerfontviewer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFontsLoaderldfnt32.htaUnidentified malware
UFooBar 1.0FooBar.exe"FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
YFoolProofSweep??"Part of FoolProof Security PC security software from SmartStuff"
NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
XForceShow"rundll32.exe QaBar.dllForceShowBar"
NForget Me NotAGRemind.exe"Calendar reminder part of Broderbund's American Greetings® CreataCard®"
UforteManagerdthtml.exe"forteManager from LG. Rebranded version of Display Tune from Portrait Displays
YFortiClientFortiClient.exe"Fortinet security systems are the new generation of real time network protection systems"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
UFourthDayFourthDay.exe"The Fourth Day - ""astronomical clock and almanac for your system tray"""
Xfoxrxjhfoxrxjh.exe"Added by the GWGHOST-T TROJAN!"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
YFP Loaderloadfp.exe"FoolProof Security - PC security software from SmartStuff"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
XFrameWork 2.5FrameWork.exe"Added by the RBOT-FMW WORM! Note - can terminate AV related processes"
XFramework module libraryinfocard.exe"Added by the BUZUS.AYX TROJAN!"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NFrapsFRAPS.EXE"Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting
NFree Download Managerfdm.exe"""Free Download Manager"" - see here"
?Free Downloads Monitorfdcmon.exe"??"
NFree DVD DirectFreeDVDDirect.exe"Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
UFree Key Loggerfreekeylogger.exe"Free Key Logger keystroke logger/monitoring program - remove unless you installed it yourself!"
UFree Ram Optimizerfro.exe"Free Ram Optimizer monitors your memory
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
XFreeAttentioneqsefeqe.exeAdded by an unidentified WORM or TROJAN!
NFreebie NotesFreebieNotes.exe"Freebie Notes by Power Soft - create electronic notes (stickers)"
NFreeCallFreeCall.exe"FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
YFreedomFreedom.exe"Freedom Internet Security & Privacy - anti-virus
UFreeMem ProFMEMPRO.EXE"FreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeMemVn2FreeMem.exe"FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
NFreePDF Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFreePDF_Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
UFreeRAM XPFreeRAM XP Pro *.exe"FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeRAM XPFreeRAM XP Pro.exe"FreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
Xfreestylelockx.exe"Added by the RBOT-ATH WORM!"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
Xfreexstylelockbar.exe"Added by the LOXBOT.D WORM!"
Xfreexstylelockbr.exe"Added by the LOXBOT.C WORM!"
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
UFresh Desktopfreshdesktop.exe"Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
Nfreshclamfreshclam.exe"Auto update agent of the open source Clamwin virus scanner"
?frgukshdrkmck.exe"??"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFriendlyWebQuick-LaunchSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
UFRISK FP-SchedulerF-Sched.exe"Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
?FRITZ!DSL StartcenterStCenter.exe"FRITZ! ISP software ""StartCenter"" User interface that allows you to manage
UFRITZ!webProtectFwebProt.exeFirewall included in FRITZ! ISP DSL software
NFromine WinPopupwinpopup.exeInstant Messenger program
Xfroodytimoty.exeAdded by an unidentified malware
XFrskfrsk.exeUnidentified adware downloader trojan
Xfrunderc32xz.exeAdded by an unidentified TROJAN!
YFRW_EXEFRW.EXE"ConSeal Signal9 firewall - now McAfee Personal firewall"
Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
?FSDPSRVFSDPSRV.exe"??"
Xfsdsft[path to backdoor]"Added by the RANKY.S BACKDOOR!"
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
Ufsservfserv.exe"Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
Xfstsvc"rundll32.exe fstsvc.dllstart"
UFSWebServerfsws.exe"Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
XFTPGraberFTPGraber.exe"Added by the DLOADER-DT TROJAN!"
NFTPManagerFTPDM.exe"""Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another
?FtpServer.exeFtpServer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
Uftutil2"rundll32.exe ftutil2.dll SetWriteCacheMode"
XFUFUvirus.exe"Added by the VB-EJC TROJAN!"
XFuckerfucker.vbs"Added by the CATCHER-A WORM!"
UFujitsu Hotkey UtilityIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
XFUKLBARbar.exe"PurityScan adware"
NFullAudioWMPImporter.exeUsed to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
NFusionHdtvTrayFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
UFusionRCFusionRC.exe"Remote control manager for DVICO FusionHDTV"
UFusionRemoteFusionRc.exe"Remote control manager for DVICO FusionHDTV"
NFusionTrayAgentFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
XFW Managerfwcheck.exe"Added by the DELBOT-H WORM!"
XFwr Command Modulefwr.exe"Added by the SDBOT-PP WORM!"
Nfwrastrcfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
Ufwservicefwservice"eAcceleration Stop-Sign security software related. Previously not recommended
XFXieloader.exeAdded by the SMALL.RR TROJAN!
XFxoekmmiyhart.exe"Added by the SDBOT-CZQ WORM!"
Ufxredirfxredir.exeCanon MultiPASS fax redirector
Xf~ara32.exe"Added by the CAY TROJAN!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
UGainwardTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Xgamepatcher.scr"Added by the PSW-ED TROJAN!"
NGame DeviceJOYUPDRV.EXEGenius game controller profile activator
NGameDriveGDTask.exe"GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
XGames Accelerationsvshost.exe"EasySearch adware"
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTB"Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
NGameTrackerGTLite.exe"GameTracker - ""Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"""
UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
XgaSrvgaSrv.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XgaSrvegaSrve.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
NGateway Extended WarrantyGWCares.exeGateway Extended Warranty reminder
XGatorgator.exe"Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XGator eWalletgator.exe"Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
YGBMPro7AgentGBMAgent.exe"Genie Backup Manager Pro 7 - backup software"
UGBTrayGBTray.exe"System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
YgcasServgcasServ.exe"Giant Antipsyware - now superseded by Microsoft's Windows Defender"
XgcasServrealsched.exe"Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
?GCC Remindergccrem.exe"Associated with AcraMax Greeting Card Creator. Is it a registration reminder?"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
XGDAX[path to backdoor]"Added by the RANKY.K TROJAN!"
XGddlib"rundll32.exe gddlib.dllstart"
YGDFirewallTrayGDFirewallTray.exe"System Tray access to the firewall part of G Data range of internet security products"
UGDMgr.exegdmgr.exe"GuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer"
NGDriveGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
NGEARsecgearsec.exeInstalled by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
NGemStRmWGemStRmW.exe"For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card
Xgencrootgencroot.exe"Added by the SDBOT-AED WORM!"
UGene USB MonitorUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
XGeneral AntivirusGenAvir.exe"General Antivirus rogue security software - not recommended
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xgeneral ml097egeneral.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
YGenie USB MonitorUSBmonitor.exePort monitor for an external USB hard drive. Required to enable access to the drive
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UGetRightGetRight.exe"GetRight from Headlight Software - shareware download manager for resuming downloads and choosing multiple download locations. The Pro version adds uploading and other features. Earlier 4.x versions included ads
UGetRight - Tray Icongetright.exe"Entry added with older versions of the GetRight download manager from Headlight Software
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
Xgfxtray"rundll32 ctccw32.dllfindwnd"
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
UGiganews AcceleratorGiganewsAccelerator.exe"Giganews Accelerator from Giganews
YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
XGLF Network Lan MonitorNPFMNTOR.exe"Added by the RBOT-AGY WORM!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
XGlobalFlagACERACER.exe"Added by the VB.BL WORM!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
Xgocvir.exe"Added by the SILOV-A WORM!"
XGo And Startsvdll32.exe"Added by the RBOT.AI BACKDOOR!"
XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
UGoBackGBTray.exe"System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGoBack Tray IconGBTray.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
Xgoidrgoidr.exe"Goidr adware"
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
XGolumservices.exe"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process
Xgolummservices.exe"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
Xgoodbadvir.exe"Added by the SILOV-B WORM!"
UGoogle Desktop SearchGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
NGoogle Earth ViewerGOOGLEMAPS.EXE"Google Earth ""combines satellite imagery
UGoogle IME AutoupdaterGooglePinyinDaemon.exe"Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
UGoogle Quick Search BoxGoogleQuickSearchBox.exe"Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
Xgoogle toolbarggtb32.exe"Added by the AGOBOT-RR WORM!"
NGoogle UpdaterGOOGLE~1.EXE"Downloads and installs updates for Google applications (Google Earth
NGoogle UpdaterGoogleUpdater.exe"Downloads and installs updates for Google applications (Google Earth
UGoogleQuickSearchBoxGoogleQuickSearchBox.exe"Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
UGoogleToolbarNotifierGoogleToolbarNotifier.exe"Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
XGoogleUpdater3GoogleMapper.exe"Added by the ROUTROBOT WORM!"
UGoTrustedGoTrusted Secure Tunnel.exe"""GoTrusted is the fast
Xgouday.exereadme.exe"Added by the BEAGLE.C WORM!"
Xgovurarope"Rundll32.exe retasevo.dlls"
XGP Updatergpupdater.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XGPLv3[random name].dll"Vundo adware"
Xgqgqqgergqgeqegl.exe"Added by the SDBOT-CLJ WORM!"
NGRAgra.exe"Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up
?gramdate2Stop.exe"??"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XGraphic Loaderntvdm32.exe"Added by a variant of the RBOT WORM!"
XGraphic Updateopenglx.exe"Added by the IRCBOT.AMU WORM!"
XGraphics_default.pif"Added by the AUTOSKY WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
UGravis Appawareloaderdbserver.exe"Looks like it's associated with Gravis game controllers and the Keyset Manager
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
?GrdSys32GrdSys32.exe"X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
XGreatDefenderGreatDefender.exe"GreatDefender rogue security software - not recommended
XGreatDefender.exeGreatDefender.exe"GreatDefender rogue security software - not recommended
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
XGremlinintrenat.exe"Added by the DOOMJUICE WORM!"
Xgrgtgvgb.exe[random].exe"Added by the AGENT-EBF TROJAN!"
Xgrindersgrinders.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
NGroksterGrokster.exe"Grokster Peer-To-Peer File Sharing program"
YGroove Virtual OfficeGroove.exe"""Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings
UGrooveMonitorGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
UGrooveMonitor UtilityGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
UGroupWise PDA Connect - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - GrpWseAgnt.exe"GroupWise PDA Connect PDA synchronisation utility - from Novell"
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
NGrpConvgrpconv.exe"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
?GsiFinal"rundll32 gspndll.dllpostInstall final"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
NGSOrganizerGSOrganizer.exe"GoldenSection Organizer (now WinOrganizer - personal information manager)"
YgStartgStart.exegStart GPS software from Garmin
XGStartupGMT.exe"Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
UGTVRecGTVRec.exe"Part of Got All Media - control your TV tuner and other utilities from your PC"
Xgtydfggrrgg.exe"Added by the DLOADR-AZK TROJAN!"
UGuardGuard.exe"Related to Phoenix Technologies Core Managed Environment (cME) Integration and Certification program"
XGuard ProVH339.exe"Guard Pro rogue security software - not recommended
XGuardCenterGuardCenter.exe"GuardCenter rogue security software - not recommended"
YGuardGui ApplicationGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UGuardianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
XGuardPcs.exeGuardPcs.exe"GuardPcs rogue security software - not recommended
XGuardWWWGuardWWW.exe"GuardWWW rogue security software - not recommended
Xguarnsetguarnset.exe"Adlogix adware"
XGURLgurl.exe"GURLWatcher spyware"
UGuruNetGuruNet.exe"GuruNet lets you click on any word on your screen to get the relevant information you want"
Xgvagfxjrundll32 ...gvagfxj.dll"Unidentified adware
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
NGWInkMonitorGWInkMonitor.exe"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink
Xgwizarpl.exe"Detected by F-Prot as W32/Downloader-Sml-based"
XG_Server.exeG_Server.exe"Added by the FEUTEL-C TROJAN!"
XG_Server1.2.exeG_Server1.2.exe"Added by the GRAYBIRD-Z TROJAN!"
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
UHaburazerhid.exe"Microsoft Habu (by Razer) gaming mouse driver - required if you use the additional features and programmed keys/macros"
UHalifaxHowardClusterskinkers.exe"""Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
UHaMFrontPanelhampanel.exe"Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget
NHard Disk SentinelHDSentinel.exe"Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
UHardware DoctorHwdoctor.exe"Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
XHardware Profilehxdef.exe"Added by the LOVGATE.AB WORM!"
XHardware Profilehxdef.exe..."Added by the LOVGATE.Z WORM!"
UHardware Sensors Monitorhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
UHarehare.exe"Hare - improve and optimize performance of desktop/laptop PCs"
UHarmony 98 - CasioOrgCasAgnt.exe"Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XHataDuzelticisiSysRep.exe"HataDuzelticisi
XHATAPE[path to trojan]"Added by the BANKER-QF TROJAN!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
UHawking Wireless UtilityHWU8DD.exe"Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies
NHC Reminderhc.exe"For Compaq PC's. Help Compiler
Uhcentertgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
Uhcenterhcenter.exe"Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
UHcontrolhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
UHControlUserHControlUser.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
Nhcsystrayhc_tray.exe"Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
UHDDControlGuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UHDDControlGuard.exeHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
NHDtrayHDtray.exePhilips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
Xhe3bbcff"rundll32.exe he3bbcff.dllEnableRunDLL32"
Xhe3e3fc4"rundll32.exe he3e3fc4.dllEnableRunDLL32"
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhelloservhelloserv.exe"Added by the ZHELATI.BHA WORM!"
Xhelloworldnb32ext2.exe"Added by the MYDOOM.BV WORM!"
Xhelloworldnb32ext3.exe"Added by the MYTOB.JT WORM!"
Xhelloworld3nb32ext4.exe"Added by the RITDOOR.A WORM!"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XHelpWizardnil.exe"Added by the BANCOS-BCZ TROJAN!"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
XHelpereschlp.exe"Added by the BLASTER.T WORM!"
XHELPERgreece_nm.exe"AsdPlug premium rate adult content dialer variant"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHELPERnew_zealand.exe"AsdPlug premium rate adult content dialer variant"
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
XHELPERcanada.exe"AsdPlug premium rate adult content dialer variant"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
XHELPERtemp532.exe"AsdPlug premium rate adult content dialer variant"
Xhelper.dllrundll32.exe [path] helper.dll"CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
YHEProtectHSockPE.exe"Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
Xherjekherjek.exe"Added by the NUWAR.APJ WORM!"
UHermes MessengerDGDRHE~1.EXE"A LAN messenger alternative to WinPopUp - Digital Dreams Software"
XHewlett Packard Managerhpmanager.exe"Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
NHewlett Packard RecorderRemind32.exeHP multifunction registration
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
Yhffsrvhffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Yhffsrv.exehffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
Xhhtnsnrnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
?HiberMonitorHCount.exe"??"
UHibernationhib32.exe"Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHideStyleAnte Browse Trust.exe"IE toolbar taking you to Lop.com. If the exe is running
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"