Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
ME""MS Java Applets for Windows NTXjavaapplets.exe
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
NAlbum Fast StartABMTSR.EXE"Scanner software
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
NBBC AlertsBBC_Alerts.exe"BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootStatusBOOTST~1.EXE"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it
?BTSETBOOTKEYBTSetBootKey.exe"Related to a USB Bluetooth adaptor. What does it do and is it required?"
UBtStartbtstart.exe"Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software"
NBudgetSipBudgetSip.exe"BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
UChatStatChatStat.exe"ChatStat from ChatStat Technologies
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
UClient Access Taskbarcwbuitsk.exe"IBM iSeries Client Access taskbar
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XContentServicewinservn.exe"PurityScan adware - see here"
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCStsc.exe"Cyber Security rogue security software - not recommended
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
?CTSchedCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
NCTSyncU.exeCTSyncU.exe"Creative Sync Manager - synchronizes music tracks on your computer with your player"
UCTsysVolCTSYSVOL.exeCreative sound card volume controls
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
Xdgtstartdgtstart.exe"DigitalNames.g adware"
Xdirects.exedirects.exe"Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDRam Monitor 23tskman3.exe"Added by a variant of the RBOT WORM!"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XDrWatsondrwatson_.exe"Added by the LOHAV-S TROJAN!"
XDrWatsondrwatson_32.exe"Added by the LOHAV-S TROJAN!"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
UDVDBitSetDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
Xfastsmellfastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
XFontsLoaderldfnt32.htaUnidentified malware
NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
Xfstsvc"rundll32.exe fstsvc.dllstart"
UFujitsu Hotkey UtilityIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
UFujitsu MenuFjMnuIco.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
NGet Smilegetsmile.exePuts smilie faces in your E-mail. Run manually when required
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
XGotSmileyGotSmiley.exe"GotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xgwizntsystem.exe"Added by the NITWIZ.A TROJAN!"
Xhachimitsu-lemonhachimitsu-lemon.exe"Added by the HACHILEM TROJAN!"
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
NHoliday LightsHoliday Lights.exe"Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
Xhostservhostserv.exe"Added by the RBOT.BPZ WORM!"
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
NHotSync Managerhotsync.exeInstalled when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
XHot_TartsHot_Tarts.exeAdult content dialler
XHot_Tarts_**Hot_Tarts_**.exePremium rate adult content dialer (where * is a random char)
XHot_Tarts_AuHot_Tarts_Au.exePremium rate adult content dialler
XHot_Tarts_mcHot_Tarts_mc.exe"HotTarts adult content dialer"
NHP JetSpeed AutostartAUTOSTART.EXEAutostart executable for the old multiplayer game HP Jetspeed
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb11.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb12.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb13.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsbolhpztsbol.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Xhtssv32.exehtssv32.exe"Added by a variant of the SDBOT TROJAN!"
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
?IBMUltraBayHotSwapSoundIBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
Nietsrietsr.exe"IEClean by Kevin McAleavy - cookie manager
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
Xigfxtrassvchots.exe"Added by the AUTORUN-AIW WORM!"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XINETinetsync.exe"Meplex adware"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
XInternetShieldInternetShield.exe"InternetShield rogue security software - not recommended
UInternetSpyInternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
YIntuit SyncManagerIntuitSyncManager.exe"Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
NISDN MonitorLinksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
XIST Serviceistsvc.exe"ISTBar adware"
YISTraypctsTray.exe"System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
NItsDeductiblePopUpItsDeductible.exe"ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
Xjutsujutsu.exe"Added by the RBOT-LS WORM!"
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
ULaplink PDASync 3.0 - LtNts4NtsAgnt.exe"Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
XLetsRock[path to trojan]"Added by the RANKY.Y BACKDOOR!"
XLetsSearchLetsSearch.exe"BrowserAid/BrowserPal foistware"
Nlhttseng"rundll32.exe ..lhttseng.inf RemoveCabinet"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLinkstslinksts.exe"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards
XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
ULoadFujitsuQuickTouchQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
XLotsOfGames"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfJokes"rundll32.exe MSA64CHK.dllDllMostrar"
XLSASS Authoritylshosts32.exe"Added by the SDBOT-UY TROJAN!"
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
NLTSMMSGLTSMMSG.exe"Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook
XLTSMSGShell32.exe"Added by the LEMIR.B TROJAN!"
Xltssvc"rundll32.exe ltssvc.dllstart"
Xltwobformatsys.exe"Added by the SERFLOG.A WORM!"
YLXBSCATS"rundll32 [path] LXBStime.dll _RunDLLEntry@16"
YLXBTCATS"rundll32 [path] LXBTtime.dll _RunDLLEntry@16"
YLXBUCATS"rundll32 [path] LXBUtime.dll _RunDLLEntry@16"
YLXBXCATS"rundll32 [path] LXBXtime.dll _RunDLLEntry@16"
YLXBYCATS"rundll32 [path] LXBYtime.dll _RunDLLEntry@16"
YLXCCCATS"rundll32 [path] LXCCtime.dll _RunDLLEntry@16"
ULXCDCATS"rundll32 [path] LXCDtime.dll _RunDLLEntry@16"
YLXCECATS"rundll32 [path] LXCEtime.dll _RunDLLEntry@16"
YLXCFCATS"rundll32 [path] LXCFtime.dll _RunDLLEntry@16"
YLXCGCATS"rundll32 [path] LXCGtime.dll _RunDLLEntry@16"
YLXCJCATS"rundll32 [path] LXCJtime.dll _RunDLLEntry@16"
YLXCQCATS"rundll32 [path] LXCQtime.dll _RunDLLEntry@16"
YLXCRCATS"rundll32 [path] LXCRtime.dll _RunDLLEntry@16"
YLXCTCATS"rundll32 [path] LXCTtime.dll _RunDLLEntry@16"
YLXCYCATS"rundll32 [path] LXCYtime.dll _RunDLLEntry@16"
YLXDBCATS"rundll32 [path] LXDBtime.dll _RunDLLEntry@16"
YLXDCCATS"rundll32 [path] LXDCtime.dll _RunDLLEntry@16"
YLXDDCATS"rundll32 [path] LXDDtime.dll _RunDLLEntry@16"
YLXDICATS"rundll32 [path] LXDItime.dll _RunDLLEntry@16"
ULXDJCATS"rundll32 [path] LXDJtime.dll _RunDLLEntry@16"
XMaxAlertsmax.exeBonzi MaxALERT - spyware
YMcAfee Managed Desktop AgentMYAGTSVC.EXE"Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
YMCTskShdmctskshd.exe"Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online and used to schedule tasks such as automatic updates
UMDGetStartedMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
UMDGetStarted.exeMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XMedia Servermsdts.exe"Added by a variant of the IRCBOT TROJAN!"
UMediafour MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XMessengerntsubsys.exe"Added by the SDBOT.BGE WORM!"
XMessenger Protocolnetsender.exe"Added by the SDBOT-ACC WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoftntsvr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Digital Cryptorsmdigits.exe"Added by the SDBOT.LM WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Syncinginetsync.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft Updatebnmveqfts.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft UpdateSetPoints.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Updaterstskmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updateswgcptsud.exe"Added by the RBOT-GTF WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windowswindets.com"Added by the FLOOD-EQ TROJAN!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WordBootSector.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
XMicrosofts mediawingtp.exe"Added by the RBOT-VO WORM!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Security Manager****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosofts Updatezcmsssr.exe"Added by an unidentified VIRUS
XMicrosofts Updatezexploirez.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrosoftShellShellcomm.exe"Added by the BANCBAN-QG TROJAN!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSourceSafelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSysSPOOLSYS.exe"Added by the TARNO.N TROJAN!"
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMircosoft Sockets SP2mssck.exe"Added by the MYTOB.ET WORM!"
YMMTASKmmtask.tsk"A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI
XMoreResultsMoreResults.exe"MoreResults adware"
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
NMozilla Quick LaunchNetscp6.exeNetscape 6 and Mozilla browsers
Xmptsgsvc.exemptsgsvc.exe"Hacker Tool - detected by DiamondCS TDS-3 anti-trojan as ""HackTool.Win32.Hidd.j"""
XMQT Svcmqtsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Hostsmsthosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs task managertskmgr.exe"Added by the SDBOT.CCD WORM!"
XMS taskbarnts.exe"Added by the RBOT-AGB WORM!"
XMS taskmanagertskmgr.exe"Added by the RBOT-AKA WORM!"
XMS Updatessyshosts.exe"Added by the MYDOOM.Y WORM!"
XMs Valud LoaderSvhots.exe"Added by the AGOBOT-SP WORM!"
Xmsappts32msappts32.exe"Added by the ELBURRO-A TROJAN!"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
XMshostsMshosts.exe"Added by the STARTPAG.CF TROJAN!"
XMSMNTMTSMSMNTMTS.EXE"Added by the BANKER-GZ TROJAN!"
XMSNnetstats.exe"Added by the IRCBOT.UXP WORM!"
XMSPetServPET32.EXE"Added by the IRCBOT-VE WORM!"
Xmstsdsc.exemstsdsc.exe"Added by the CIMUZ-CD TROJAN!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
YMyCIO Agent Servicemyagtsvc.exe"Part of the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
Umynswwntsrv.exe"Net Screen Watcher surveillance software. Uninstall this software unless you put it there yourself"
XMyPointsPointAlertwjview ...MyPointsPointAlertrun.exe"""With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles"". Dubious privacy policy"
XMyTotalSearch Email Pluginmtsoemon.exe"MyTotalSearchBar adware"
NNB Common Dialog EnhancementsCOMDLGEX.EXE"Part of McAfee Nuts & Bolts. With Common Dialog Enhancements
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
XNdtstatNdtstat.exeAdded by a variant of the BANLOAD family of TROJANS!
XNero.ma***.exe [*** = 2 to 3 digits]"Added by the JONBARR.D WORM!"
UNeroHomeFirstStartNMFirstStart.exe"Associated with Nero Scout
XNET Bios Statsntbstats.exe"Added by the SDBOT-ZX WORM!"
XNET protection systemnetst.exe"Added by the RIZO.A TROJAN!"
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
UNetscapeInstallService.exeRelated to Netscape installation
NNetscape MessengerNETSCAPE.EXE"In Netscape 6 (I know for sure with 6.2.1
NNetscp6Netscp6.exeNetscape 6
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNetServicentsvc.exe"Added by the QQPASS-DU TROJAN!"
Xnetservicesrecall.exe"Added by the WOOTBOT.D WORM!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
UNetShow Powerpoint HelperNSPPTHLP.EXE"If disabled
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
NNetStat LiveNsl.exe"AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data"
XNetSurfageAssureGDC.exe"NetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
Xnetsv32netsv32.exe"Added by the SDBOT-PX WORM!"
Xnetsv32sv.exe"Added by the DELF.CCD TROJAN!"
XNetwork Service Managernetsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
XNetworks ControlerNetsis.exe"Added by the RBOT-NG WORM!"
XNI.USYPSysProtectScannerInstall.exe"Installer for the SysProtect rogue security software
UNMFirstStartNMFirstStart.exe"Associated with Nero Scout
?nMTaskBarServicenMtsk.exe"Taskbar control for ISDN NetMod modem. What does it do and is it required?"
NNokia FastStartNokiaMusic.exe"Part of the Nokia Music music manager. ""With Nokia Music
XNorton Personal Firewallwinmpts.exe"Added by the RBOT.ANT WORM!"
Xnstatnetstat.exeAdult content dialler
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
XNt System Protocolntsystem.exe"Added by the RBOT.DSB TROJAN!"
XNTSet32services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32"
XNTSF Microsoft Systemfylez.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwntsf.exe"Added by the RBOT.ATC WORM!"
XNTSF MICROSOFT SYSTEMfufffy.exe"Added by the RBOT-AEL WORM!"
XNTSF MICROSOFT SYSTEMntssf.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTSF MICROSOFT SYSTEMmarya.exe"Added by the RBOT-AXY WORM!"
XNTSF MICROSOFT SYSTEMsysman.exe"Added by the RBOT.EDP WORM!"
Xntsmodntsmod.exe"Adware downloader/installer
XNTsocketNoeWinnt.exe"Added by the ATAKA-E TROJAN!"
XNTSpoolNTSpool.exe"Added by the AGENT-GPY TROJAN!"
XNTsrv.exeNTsrv.exe"Added by a variant of the SERVU-O TROJAN!"
XNtsysvntsysv.exe"Added by the MIFENG-E TROJAN!"
XNumerical Xterm Agents2x32.exe"Added by the RBOT-FWY WORM!"
XNvCplScannetstat32.exe"Added by the SDBOT.BRL WORM!"
XOesisrts.exe"PurityScan adware"
NOM2_MonitorFirstStart.exe"Olympus Master 2 - digital camera management tools"
NOM_MonitorFirstStart.exe"Olympus Master 1 - digital camera management tools"
XOptimum OnlineNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity
UPartSealPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
NPC Pitstop Optimize ReminderReminder.exe"Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2"
UPC Pitstop Optimize SchedulerPCPOptimize.exe"Scheduler for the Optimize system optimization utility from PC Pitstop"
NPCPitstop Registration ReminderReminder.exe"Registration reminder for the Exterminate antimalware package from PC Pitstop"
UPCPitStopEraserPCPitStopErase.exe"""PC PitStop Erase is both a free privacy scanner and paid tracks cleaner"""
Upctspkpctspk.exeUsed for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
YpctsTraypctsTray.exe"System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
YpctsTray.exepctsTray.exe"System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
UPDUiP6000DTskbrPDUiP6000DTskbr.exe"Memory Card Utility for the Canon PIXMA iP6000D photo printer - which allows ""your computer to access the memory card reader feature of your printer"""
UPerfectSuitedthtml.exe"PerfectSuite™ from ViewSonic. Rebranded version of Display Tune from Portrait Displays
Xpestsweeperpestsweeper.exe"PestSweeper rogue security software - not recommended
XPex Sound DriverToday's Results.vbs"Added by the TRODE-A WORM!"
Xpex Sound driver 2Today's Results.vbs"Added by the TRODE-A WORM!"
UPHIME2002ATINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
UPHIME2002ASyncTINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
NPivotSoftwarewpctrl.exe"PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
NPMTSHOOTpmtshoot.exeMS tool for troubleshooting power management problems
Xpnpsvc_lockstartsvs.exeBrowser hijacker
XPoints Managerpoints manager.exe"Altnet TopSearch adware"
XPostSetupCheckRundll32.exe atgban.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""atgban.dll"" file is found in %System%"
XpostSetupCheckRundll32.exe gzmrt.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""gzmrt.dll"" file is found in %System%"
XPostSetupCheckRundll32.exe cpmsky.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
Xpostsospost.exe"Added by the TATERF-Z WORM!"
XprinterSpyAssaultScanner.exe"SpyAssault spyware remover - not recommended
NPrintScreenUNWISE.EXE"Gadwin PrintScreen - utility to capture
NPrintscreen 95PRT95MIN.EXE"Printscreen 95 - utility to capture
UPrintSpoolerlass.exe"Win-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
XPrintSpoolSvSystem.exe"Added by the BDOOR-S BACKDOOR!"
XProtectSoldierProtectSoldier.exe"ProtectSoldier rogue security software - not recommended
XProtocolEventTskcsrwjd.exe"Added by the STINX-N TROJAN!"
Xprutsctprutsct.exe"Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications
NPtsnoopPtsnoop.exe"These descriptions I've come across - all valid as far as I can see :- (1) Program installed with some modems that monitors the COM ports for the modem driver. Not required from what I've read - may need a registry edit to get rid of it (2) Backdoor trojan virus that copies itself as PTSNOOP.EXE -see here for more info(3) Apparently the people who put it out claim it's a driver for a Voice modems (don't know who they are though - Ed) Note: If using AOL and you disable this you may lose your connection or lock up (4) Can also be an older Logitech scanner program. Remove from the Win.ini tab under Load='path'PTSNOOP and the System.ini tab under drivers='path'ptrtkr.drb. Can cause parallel port conflicts big time dragging system resources way down when a conflict exists (5) Allows audio monitoring of modem phone dialling tones and can be useful if you have connection problems (6) Karen Kenworthy's Snooper - ""logs the start and stop time of all programs run under Windows"""
XPTSShellPTSShell.exe"Added by the WINKO.AO WORM!"
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
NQTSTUB.EXEQtstub.exePart of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders
XQTSvcmsocfg.exePremium rate adult content dialler
XQTSvcnavchk.exePremium rate adult content dialler
XQTSvcshman.exePremium rate adult content dialler
XQTSvcssvr.exePremium rate adult content dialler
XRavUptetsagetlke.exe"Added by the QQPASS-AK TROJAN!"
NRealJukeboxSystraytsystray.exeSystem Tray icon for RealJukebox
XRegeditregedits.exe"Added by the BANCBAN-QV TROJAN!"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
XRemote Terminal Taskrtsbsvc.exe"Added by the IRCBOT.AUZ BACKDOOR!"
XRestore Operationsvchots.exe"Added by a variant of the RBOT WORM!"
URNBOStartsentstrt.exeProgram used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
XRSyncnetsync.exe"SafeSurfing adware"
?RTStartMuteN/A"??"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
Xrunner1retadpu[random digits].exe"Added by the SMALL.CTV TROJAN!"
Xrunner1tsitra.exe"Added by the AGENT.ABFQ TROJAN!"
XRVC6Playertskdbg.exe"Added by the ZAPCHAS-M TROJAN!"
USAGENTSERVICESagent.exe"TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself"
YScriptSentryScriptsentry.exe"Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly"
Xsdchosts32vbdd.exeAdded by the RANKY.AG TROJAN!
XSDKcore Update Components2SDKC0R3.exe"Added by the RBOT-ABA WORM!"
USecretSmileysss.exe"""Secret Smileys is an add-on for AIM that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations
XSecurity Accounts Manager SMsamsm.exe"Added by the SPYBOT.JE WORM!"
Xserpeformatsys.exe"Added by the SERFLOG.A WORM!"
XService Hostsvchosts.exe"PornCleanser spyware"
XservicesSvchosts.exe"Added by the SDBOT-N TROJAN!"
XServices Administratornetsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices Management Clientsservc.exe"Added by the RIZO.A TROJAN!"
XServices Managementsservcs.exe"Added by the RBOT-GUC WORM!"
XSicherheitsToolSysRep.exe"SicherheitsTool
USightSpeedSightSpeed.exe"SightSpeed Video Chat - ""lets you connect with all your friends and family easily. Make video calls
NSigmatelSysTrayAppstsystra.exeSystem tray program for the Sigmatel Audio sound card. Often found on Dell computers
XSilentSoftech[worm filename]"Added by the SILLYFDC-BL WORM!"
XSilentSoftechSilentSo.exe"Added by the AUTORUN-ANU WORM!"
NSimcastSimcastAlerts.exe"Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say"
XSmartSecuritySmartSecurity.exe"Smart Security rogue security software - not recommended
USmartSync ProSmartSync.exe"Related to CompanionLink Software Inc. Synchronization solutions for ACT!
XsoftIce Update 32wininits.exe"Added by the RBOT-ANB WORM!"
XSoftSafenessSoftSafeness.exe"SoftSafeness rogue security software - not recommended
XSoftSoldierSoftSoldier.exe"SoftSoldier rogue security software - not recommended
XSoftStrongholdSoftStronghold.exe"SoftStronghold rogue security software - not recommended
USoftStuff Wallpaper Changersoftstrt.exe"AzureBay wallpaper changer"
Xsounoftssounofts.exe"Added by the AGOBOT-ND WORM!"
XsountskmanagersountaskmgrAdded by an unidentified WORM or TROJAN!
NSpeed racerCTSRReg.exeSoftware for a Creative sound card
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
USprint SmartViewSprintSV.exe"Sprint SmartView wireless connectivity manager which supports cards from multiple manufacturers including Intel
USpybot-S&DSpybotSD.exe"Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck
USpybotSDSpybotSD.exe"Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck
YSpybotSD TeaTimerTeaTimer.exe"Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options
USpybotSnDSpybotSD.exe"Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck
XSpywareSoftStopSpywareSoftStop.exe"SoftStop rogue security software - not recommended"
YSR AgentAGENTSVC.EXE"Related to Secure Resolutions - desktop virus protection"
?sr1exeupdtSup3.exe"Found on a Dell computer in Documents and Settings\All Users\Application Data\DellAlert2"
XStart It Uppingsvchosets.exe"Added by a variant of the RBOT WORM!"
XStart Uppingwindupdts.exe"Added by a variant of the RBOT WORM!"
XStart Uppingssvcchosts.exe"Added by the SDBOT.VY WORM!"
XstartkeyCKOTS.exe"Added by the BIFROSE-HM TROJAN!"
UStartSecurDocSDPin.exe"SecurDoc from WinMagic Inc - ""Provides full disk encryption to protect sensitive information stored on laptops
UStartStopSTARTSTOP.EXE"StartStop from TFI Technology - startup manager"
UStartSurfingSTARTS.exe"Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows
UStationPlaylistStudioSPLStudio.exe"StationPlaylist Studio - ""simple to use on-air broadcast playback software for the studio and/or DJ"" for small to medium sized radio broadcasters
XStatisticsstatslist.exe"Added by the OPANKI-S WORM!"
UStopSignSsTsMon"sstsmon.dll VerifyStatus"
USTOPzilla ServiceSZNTSVC.EXE"StopZilla! - pop-up killer"
XStsiwnujdss2.exe"Added by the SDBOT-YI WORM!"
Xstxrmsgmsmstats.exe"Added by the IRCBOT-AE TROJAN!"
USunasdtservSunasdtserv.exe"CounterSpy by Sunbelt Software - adware/spyware protection"
XSunJavaUpdatSchedspoolsv.exe"Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
USuNotificationsuatshut.exe"ShadowSurfer - ""provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode system state no matter what changes have occurred to your PC"""
XSVCH0TSsp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
XSvchostsvchots.exe"Added by the RBOT.ADK WORM!"
Xsvchostssvchosts.exe"Added by the BANCBAN-DC or BANKER-ED TROJANS!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
Xsvchosts.exesvchosts.exe"Added by the AGOBOT-JN WORM!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
XSvhost Service Serversvhostser.exe"Added by a variant of the RBOT WORM! See here"
XSygate Personal Firewallhostserv.exe"Added by the RBOT.BKO WORM!"
XSygate Personal Firewallsvchots.exe"Added by the RBOT.ABT WORM!"
XSync Serverdrwatsoon.exe"Added by the WATSOON.A TROJAN!"
XsysFonts.exe"Added by the AUTORUN.BUK WORM!"
XsysPersonalFirewalltskm0nitor.exe"Added by the SDBOT.APC WORM!"
XSystem ManagerUser Documents.exe"Added by the VB.GF VIRUS!"
XSystem Presets[temp name].exe"Added by the HOSTINF-A WORM!"
XSystem Rebootrebootsys.exe"Added by the RBOT-WU WORM!"
XSystem StatsSystemStats.exe"Added by a variant of the WOOTBOT WORM!"
XSystem-Statsystats.exe"Added by the SDBOT.RA WORM!"
XSystem132Csrtss.exe"Added by the LANFILT-I TROJAN!"
XSystemNetworkNETSERV.EXEAdded by the NETCONTROL VIRUS!
Xsystwtraytwitty**.exe [** = random digits]"Added by the KOOBFACE.C WORM!"
Xsys_up1svchostsys.exe"Added by the MULTIDR-FL TROJAN!"
UT-Com WLAN ManagerTS154USB.exeWireless management utility for the T-Com Sinus 154 Data II WLAN adapter
XTablet Tasktabletsk32.exe"Added by the RBOT-AJB WORM!"
XTapisystss.exeAdded by the SMALL TROJAN!
XTask Debuggertskdbg.exe"Added by the AGOBOT-KK WORM!"
XTask Helpwualcts.exe"Added by a variant of the RBOT WORM!"
XTask Managertskmngr.exe"Added by the RBOT-GOU WORM!"
XTaskManager Load ModuleTSKMNGR32.EXE"Added by the SPYBOT.I WORM!"
XTaskmgrtskmgr32.exeHomepage hi-jacker
Xtattatss.exe"Delfin Promulgate adware variant"
XTcp Application Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
XText Tray Servicetstray.exe"Added by the SILLYFDC.BCC WORM!"
UTgsetsitetgfix.exe"See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
UThrustTSRTMTMTSR.exe"Thrustmaster Thrustmapper - ""t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"""
XTimeSink Add ClientTSADBOT.EXEAdvertising spyware
UTINTSETPTINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
NTkBell.Exeevntsvc.exe"Application Scheduler installed along with RealOne Player. Once installed
NTkBellExeevntsvc.exe"Application Scheduler installed along with RealOne Player. Once installed
Utlntsvrtlntsvr.exe"Microsoft program associated with Telnet"
XTmntsrv32Tmntsrv32.exe"Added by the STARTPAGE.O TROJAN!"
UTMTMTSRTMTMTSR.exe"Thrustmaster Thrustmapper - ""t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"""
XTok-Cirrhatus-[4 random digits]br[4 random digits]on.exe"Added by the BRONTOK-M WORM!"
?TomcatStartuphpbpsttp.exe"Apache Tomcat web server
?TomcatStartup 2.5hpbpsttp.exe"Apache Tomcat web server
UTrackpointSrvdaemon.exe"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
UTrackpointSrvtp4serv.exeSupports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
UTrackPointSrvtp4mon.exe"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
XTrojanSimulatorTSServ.exe"Trojan Simulator security risk which simulates a trojan infection and may be used to verify whether a virus scanner can properly detect the file"
XTrueFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
NTrueSync Launchertstool.exe"Starfish TrueSync - for synchronization between Windows platforms and popular devices
XTrustSoldierTrustSoldier.exe"TrustSoldier rogue security software - not recommended
XTrustyHound-TSTrustyHound-TS.exe"TrustyHound spyware"
XTStsc.exe"Total Security rogue security software - not recommended
Xtsatsm.exe"TargetSaver adware"
XTsa2tsm2.exe"TargetSaver adware"
XTsAdbotTSADBOT.EXETimeSink Add Client - advertising spyware
?TSBxLogonTMESBS2.EXE"Found on a Toshiba laptop. May be related to TMESBS?"
UTSClientMSIUninstallertscuinst.vbs"Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
Xtservtserv.exe"Added by the STRATION.AD WORM!"
UTSE_PLUtilPLBkMon.exe"Prolific USB Flash Disk Log On Application"
XTsk Mng Hlpwins32.exe"Added by the AGOBOT-JB WORM!"
Xtskdbgtskdbg.exe"Added by the FLOOD.E TROJAN!"
XTsklisttsklist32.exe"Detected by Kaspersky as the BANCOS.SP TROJAN!"
UTSkrMainTSkrMain.exe"TOSHIBA Accelerometer Utilities - hardware utilities that work with the motion sensors built into their Tablet PCs. Detect the way you are holding it at any given moment
XTsltsl.exe"Uploader-R adware"
XTsl2tsl2.exe"TargetSaver adware"
?TSMAgentTSMAgent.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
NTSMsgerTSMsger.exe"Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
Ntsnp2stdtsnp2std.exeDigital camera related
Ytsnpstd3tsnpstd3.exe"Related to Sonix Inc. Camera Monitor MFC Application"
?TSPowerspower.drv"Found on a Toshiba laptop. Related to power management?"
Xtsrvt2serv.exe"Added by the WAREZOV.AT WORM!"
Xtsrvtsrv.exe"Added by the WAREZOV.W WORM!"
?TSServiceNSSERVICE.EXE"??"
Xtsvcinn20050308.exe"Delfin Media Viewer adware related"
Xtsxregedlt.exe"Added by the SDBOT-KA BACKDOOR! Note the lower case ""L"" in place of the lower case ""I"" in the command"
?tsyssmontsyssmon.exe"Found in a Toshiba\sysstability directory"
XTSystem[trojan filename]"Added by the NSYS-A TROJAN!"
XTTS Synctesttts.exe"Added by the SDBOT.BVA WORM!"
UTweak UI 1.33 deutsch"RUNDLL32.EXE TWEAKUI.CPL TweakMeUp"
UUCmore XP - The Search Accelerator"rundll32.exe UCMTSAIE.dll DllShowTB"
XUltimateServicesultsvcs.exe"Added by the AGENT-LGT TROJAN!"
UUniPrintSetDfltSettings.exe"Drivers for Uniprint
XUpdatestatsUpdatestats.exe"Statblaster adware"
XUpdateStatsUpdateStats.exe"SeekSeek search hijacker related - see here"
YUrtSvcExeUrt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
UVAIO RecoveryPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
Xvaluenamesvchosts.exe"Added by a variant of the SDBOT WORM!"
XVhosts Protectionvhosts.exeAdded by an unidentified WORM or TROJAN!
XVideo Card Driver (do not remove)tsasi.exe"Added by the SPYBOT-EF WORM!"
XVideo Processnetsvcs.exe"Added by the AGOBOT.LH WORM!"
XVideo Processntsystm.exe"Added by the GAOBOT.ZX WORM!"
Xvirtual-machinesvchosts.exe"Added by the RBOT-US WORM!"
YVrBootScanVRBScan.exe"Boot scan feature of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal
Xvschostvschosts.exe"Added by the VIPSY-A TROJAN!"
XVxD Driver Initializationntsvxd.exe"Added by the SDBOT-LW WORM!"
XWAPIwts**.exe [* = random char]"PurityScan adware"
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
Xwaultswaults.exe"Added by the BIFROSE.L BACKDOOR!"
XWCPCwintsvcc.exe"PurityScan adware"
XWCPIwintsvit.exe"PurityScan adware"
XWCPTwintsvtr.exe"PurityScan adware"
UWebshotsWebshots Tray.exe"Webshots - software that displays photos as your screensaver and wallpaper
UWebshotswebsho~1.exe"Webshots - software that displays photos as your screensaver and wallpaper
UWebshotsLauncher.exe"Webshots - software that displays photos as your screensaver and wallpaper
UWebshotsWebshotsTray.exe"Webshots - software that displays photos as your screensaver and wallpaper
NWetSockwetsock.exe"RoboMagic Wetsock - weather reporting in the System Tray"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
Xwindllwindotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
XWindos Seres Agnts[worm filename].exe"Added by the RBOT-GUN WORM!"
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Sectionsntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Managerwinmants.exe"Added by the MANTAS WORM!"
XWindows NetsWinNET.exe"Added by the RBOT-MO WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
XWindows Portable DevicesMSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Printing Drivergpedits.exe"Added by the DCKEYG.A WORM!"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Serviece Agents[8 random letters].exe"Added by the AGENT.BHR TROJAN!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Startup 32 Bitssysrun32.exeAdded by a variant of the DARKSUN TROJAN!
XWINDOWS SYSTEMwinNTsys32.exe"Added by the MYTOB-DM WORM!"
XWindows Task Service (32-bits)tasksys.exe"Added by the DREFIR.D WORM!"
XWindows Taskmanagertskmngr.exe"Added by the IRCBOT.DHR BACKDOOR!"
XWindows Taskmanagerwdtsvc.exe"Added by the PUSHBOT.AU WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows UpdateSecretStub.exe"Added by the SRAMLER.C WORM!"
XWindows Updatetskmngr.exe"Added by the AGENT.ALY BACKDOOR!"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Workstation Service (32-bits)wkssvc32.exe"Added by a variant of the SDBOT WORM!"
XWindowsDiskLogcstsm.exe"Added by the STINX-C or STINX-D TROJANS!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWinds Sers Agts[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWinds Sersc Agtsrzrzncrtz.exe"Added by the RBOT-GTV WORM!"
YWinFaxAppPortStarterwfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
Xwinsock2netsvr.exe"Added by the AGOBOT.LY WORM!"
XWinsock2 driverntsys32.exe"Added by the SPYBOT-DD WORM!"
Xwinsockdrivertskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
Xwinstatswinstats.exe"Added by the GARGAFX TROJAN!"
XWinTasks DLL Library (32-bits)winkll.exe"Added by the RBOT-AJZ WORM!"
Xwintsk32dllwintsk32dll.exe"Added by the RBOT-AAJ WORM!"
XWinUpdatesvchots.exe"Added by the SMALL.GXJ TROJAN!"
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
XWinXPServiceTskdbg.exe"Added by the MDROP-BPQ TROJAN!"
XWNSAwnsts**.exe [* = random char]"PurityScan adware"
Xword pairbopotsvr.exe"Added by the SHED-A TROJAN!"
XWTSCwapisvcc.exe"PurityScan adware"
XWTSIwapisvit.exe"PurityScan adware"
XWTSSwapi**.exe [* = random char]"PurityScan adware"
XWTSTwapisvtr.exe"PurityScan adware"
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
YXoftSpyXoftSpy.exe"XoftSpy antispyware software by Pareto Logic"
UXTNDConnect PC - LtNts4NtsAgnt.exe"(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
XXTServiceUpdateXTServiceUpdate.exehahame.net adware downloader
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"
XYahoo Messenggerscvshosts.exe"Added by the TRAX-A WORM!"
UYahoo! WidgetsYahooWidgets.exe"Yahoo! Widgets lets you run little files called Widgets that can do pretty much whatever you want them to"
X[12 random characters]catsrvps.exe"IeDriver adware variant"
X[32 random hex numbers]tsc.exe"Total Security rogue security software - not recommended
X[default]DrWatson32.exe"Added by the DREMN TROJAN!"
X[random characters]systs.exe"Added by the AGENT-GDC TROJAN!"
X[random][random]tssd.exe"Antivirus Suite and AntiSpyware Soft rogue security software - not recommended
X[various filenames]qtsks.exeAdded by the WEBDOR.Y TROJAN
X[various names]svchostss.exe"Added by a variant of the RBOT WORM!"
X[various names]ms-its.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]panel_its.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]utsgmon.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]WhatsNewBot.exe"Wareout - malware masquerading as a spyware and dialer remover"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.