| ? | iPrint LPT Redirector | nipplpte.exe | "Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
|
| N | iRis Active Monitor | winmon32.exe | "Iris Antivirus - discontinued |
| N | iRiS AntiVirus Active Monitor | WIMMUN32.exe | "Iris Antivirus - discontinued |
| ? | IRPMonitor | itcnmon.exe | "??"
|
| X | isamini.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| X | isamonitor.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| N | ISDN Monitor | Linksts.exe | "Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards |
| Y | JetAdmin Discovery Indicator | HPJETDSC.EXE | "HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry |
| U | jv16PT - Privacy Protector | Task.jvb | "jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer |
| Y | Kaspersky Anti-Virus Monitor | AvpM.exe | "Kaspersky Anti-Virus Lite - no longer available"
|
| X | Kazaa Download Accelerator Updater (required) | regsvr32 kdp****.dll [* = random char] | "SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
|
| U | Komunikator | tlen.exe | "Tlen - a Polish language instant messaging client"
|
| U | LANDeskInventoryClient | LDIScn32.exe | "LANDesk® Management Suite software component"
|
| U | LanguageMonitor | Oplmsb01.exe | OKI Printer language support monitor
|
| X | Layersecurity Servicemonitor | LSSMON.EXE | "Added by the BANKER.ZAQ TROJAN!"
|
| U | Lexmark X63 Button Monitor | ACMonitor_X63.exe | "Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
|
| U | Lexmark X73 Button Monitor | ACMonitor_X73.exe | "Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
|
| U | Lexmark X83 Button Monitor | ACMonitor_X83.exe | "Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
|
| U | Lexmark X84-X85 Button Monitor | ACMonitor_X84-X85.exe | "Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
|
| N | LifeScape Media Detector | PicasaMediaDetector.exe | "Media detector for Picasa's automatic photo organizer"
|
| U | LingvoTraining | Tutor.exe | "ABBYY Lingvo Electronic Dictionaries"
|
| X | Live update monitor | srvany32.exe | "Added by the AGOBOT.AFM WORM!"
|
| X | live update monitor | umxlu32.exe | "Added by the AGOBOT.ADK WORM!"
|
| N | LiveMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
|
| N | LMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
|
| X | Locator Service | [filename] | "Added by the AGOBOT-KY TROJAN!"
|
| U | LogitechVideo[inspector] | InstallHelper.exe | Entry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
|
| X | LogonAdministrator | imoet.exe | "Added by the RAHIWI.A WORM!"
|
| X | LogonAdministrator | CSRSS.EXE | "Added by the KORRON.B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
| U | LSPFix | LSPmonitor.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | LSPmonitor | LSPmonitor.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| X | Lssas Monitoring Startup | LSSAS.EXE | "Added by the RBOT.XJ WORM!"
|
| X | Malware Destructor 2009 | MD345d.exe | "Malware Destructor 2009 rogue security software - not recommended |
| X | MalwareMonitor | MalwareMonitor.exe | "MalwareMonitor rogue security software - not recommended"
|
| U | Manager Monitor | monitor.exe | "MindStorm AnalyzerPro from Secure Associates. ""A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"""
|
| N | Mania Win Restore | RESWIN.EXE | Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
|
| N | Mass storage check registry | "rundll32.exe MSDServ.dll | check registry" |
| U | MaxBlastMonitor | MaxBlastMonitor.exe | "Maxblast hard drive utility for Maxtor (Seagate) drives"
|
| Y | MaxtorCombo | ComboButton.exe | Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
|
| U | MaxtorOneTouch | OneTouch.exe | "Maxtor OneTouch Hard Drives/OneTouch Family hard disk backup software"
|
| U | MaxtorReg | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
|
| X | Mcafee Antivirus Monitoring System326 | VSStatmn326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | "Added by a variant of the RBOT WORM!"
|
| U | McAfee Backup and Restore | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee QuickClean Imonitor | Plguni.exe | "Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection |
| U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | "Instant Updater for McAfee's VirusScan |
| U | Media Card Companion Monitor | MCC Monitor.exe | "Monitor for Media Card Companion from ArcSoft. ""Automates the tedious processes associated with downloading and sharing files from digital cameras |
| N | MediaMonitor | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it
|
| X | mediamotor.exe | mmups.exe | "Added by the AGENT-BY TROJAN!"
|
| N | Memory Stick Monitor | MSTAT.exe | "Used with the Sony floppy disk adapter for memory sticks |
| U | Memory Stick Monitor | MSstat.exe | Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
|
| X | Microsft Security Monitor Process | cmh.exe | "Added by the EGGDROP.V WORM!"
|
| X | Microsft Security Monitor Process | mssmppp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsft Security Monitor Process | mssmpp.exe | "Added by the SDBOT-DJW WORM!"
|
| X | Microsofot x386 System Monitor | system32.exe | "Added by the WOOTBOT.M WORM!"
|
| X | Microsoft (R) Windows Protected Content Restoration Service | services.exe | "Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
|
| X | Microsoft .NET Confingurator | msnconf.exe | "Added by an unidentified VIRUS |
| X | Microsoft Calculator | calc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Connection Manager Monitor | cmmon.pif | "Added by the RBOT-AKV WORM!"
|
| X | Microsoft Corporation SYM monitor | mssym.exe | "Added by the RBOT-GDB WORM!"
|
| X | Microsoft CRT Monitor Manager | crtmon.exe | "Added by the ROBOTON.A WORM!"
|
| X | Microsoft Digital Cryptors | mdigits.exe | "Added by the SDBOT.LM WORM!"
|
| X | Microsoft DirktorWin | [random filename] | "Added by the SPYBOT.GEN3 TROJAN!"
|
| X | Microsoft DLL Monitor | dllmon32.exe | "Added by the AGENT.WP WORM!"
|
| X | Microsoft DLL Monitor | dllmon64.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Monitor | dllmonitor.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | microsoft hotmail monitor | mshotmon.exe | "Added by the MYTOB-FL WORM!"
|
| X | Microsoft Office Monitor | alg2k.exe | "Added by the SDBOT-CZO WORM!"
|
| X | Microsoft Office Monitor | aql32.exe | "Added by the RBOT-GCY TROJAN!"
|
| X | Microsoft Problem Doctor | windr128.exe | "Added by the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr32.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr64.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Restore | scrgrd.exe | "Added by the SPYBOT.BR WORM!"
|
| X | Microsoft Security Monitor Process | mssmp.exe | "Added by the RBOT-FUB WORM!"
|
| X | Microsoft Security Monitor Process | mnsmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | msmp.exe | "Added by the RBOT.GKQ WORM!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Security Monitor Process | lsas.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | msword.exe | "Added by the VIRUT.P VIRUS!"
|
| X | Microsoft Security Monitor Process | service.exe | "Added by the DELF.BERW BACKDOOR!"
|
| X | Microsoft Security Monitor Process | svcchost.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | windowsupdate.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | [random filename] | "Added by variants of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | com.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | exel.exe | "Added by the SDBOT.AFX BACKDOOR!"
|
| X | Microsoft Security Monitor Process | firewall.exe | "Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
|
| X | Microsoft Security Monitor Process | flash.exe | "Added by the EGGDROP.EE BACKDOOR!"
|
| X | Microsoft Security Monitor Process | hel.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | HelpMe.exe | "Added by the VB.BJO TROJAN!"
|
| X | Microsoft Security Monitor Process | kar.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | lindicracker.exe | "Added by the BIFROSE.GR BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mail.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssmpi32.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | nitty.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | ofice.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | point.exe | "Added by the IRCBOT.AVP BACKDOOR!"
|
| X | Microsoft Security Monitor Process | princ.exe | "Added by the HUPIGON.WTL TROJAN!"
|
| X | Microsoft Security Monitor Process | web.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | winsys32.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | winsyss32.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | word.exe | "Added by the EGGDROP.DC BACKDOOR!"
|
| X | Microsoft standard protector | winsocks5.exe | Added by the SMALL.CF TROJAN!
|
| X | Microsoft standard protector | [path to trojan] | "Added by the STOX-C TROJAN!"
|
| X | Microsoft System Monitor | monsys.exe | "Added by the IRCBOT-YV TROJAN!"
|
| X | Microsoft System Monitor | system.exe | "Added by the IRCBOT.AUT BACKDOOR!"
|
| X | Microsoft System Restore Configuration | CBRSS.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft task tray monitor | ctray.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft TCP/IP Connection Monitor | svchost32.exe | "Added by the RBOT.KS WORM!"
|
| X | Microsoft Update Emulator | kern-mxe.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Emulator | wuaddsff.exe | "Added by the RBOT-GX WORM!"
|
| X | Microsoft Viewer Monitor Manager | viewmon.exe | "Added by the XPAK.A TROJAN!"
|
| X | Microsoft Windows Communicator for NT/XP | wincomm.exe | "Added by the RBOT.ATH WORM!"
|
| X | Microsoft Windows Storage Machine Service | winms.exe | "Added by the RBOT-AHK WORM!"
|
| X | Microsoft Word | BootSector.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | monitor | monitor.exe | "Browser hijacker |
| U | Monitor | SD Monitor.exe | """Transfer data quickly between your memory card and your computer with SanDisk's Readers |
| X | Monitor | explor.exe | "Added by the AGOBOT-EF BACKDOOR!"
|
| ? | Monitor | Monitor.exe | "Related to the Philips SPC610NC & PixArt PAC207 webcams (and possibly others) and Leapfrog Connect Application. What does it do and is it required?"
|
| U | Monitor Apache Servers | ApacheMonitor.exe | Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
|
| X | Monitor calibration | AV1i.exe | "Anti-Virus-1 rogue security software - not recommended |
| U | Monitor Helper | monitor.exe | "MyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | Monitor Test | [random filename] | "Added by the SDBOT-NC WORM!"
|
| X | monitor1a | monitor1a.exe | "Added by the MSNAGEN-A TROJAN!"
|
| X | Monitoring Service | svchost.exe | "Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
|
| X | Monitormgt | Monitormgt.exe | "Added by the GEMA TROJAN!"
|
| U | MonitorSD | SDMonitor.exe | "Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| U | MotiveMonitor | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used by the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufacturer. For most users it's not required
|
| U | Motorola Desktop Suite | DesktopSuite.exe | "Related to Motorola Desktop Suite - PC software managing Motorola mobiles such as the A1000"
|
| U | Motorola Desktop Suite mRouter Config | mRouterConfig.exe | "Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth |
| U | Motor_Tracking_Tool | MTTool.exe | "Sweex Motion Tracking Webcam utility. ""The motion tracking function ensures that the camera can follow all your movements. So you can move and chat |
| N | MP3 CD Extractor | CD-Extractor.exe | """MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk"""
|
| U | MP_STATUS_MONITOR | monitr32.exe | Cannon Multi-Pass status monitor - your choice
|
| X | MS Internet Executor 32 | MSIXEC32.exe | "Added by the RBOT-AEQ WORM!"
|
| X | MS SyS Restore | sysrestore.exe | "Added by the RBOT.XM WORM!"
|
| X | MS Windows Executor Process | MSEXECP32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS Windows Local Directory | MSWLD32.exe | "Added by a variant of the RBOT WORM!"
|
| X | msconfigurator | ctfsdk.exe | "Added by the DELF-ALS TROJAN!"
|
| U | MSKDetectorExe | MSKDetct.exe | "Part of McAfee Spamkiller"
|
| X | MSN Tray Monitor | msnmsgr.exe | "Added by the SDBOT.FKX WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%\inetsrv"
|
| X | Msnarrator | msnarrator.exe | "Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware"
|
| U | MsnMonitor | MsnMonitor.exe | "MSN Messenger Monitor Sniffer surveillance software for the MSN instant messenger. Uninstall this software unless you put it there yourself"
|
| X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS!
|
| X | MSTask Monitor | mstaskmon.exe | "Added by the SDBOT-LU WORM!"
|
| X | My Web Search Bar Search Scope Monitor | m3SrchMn.exe | "MyWebSearch parasite"
|
| X | Narrator | ******.exe [* = random char] | "Added by the QOOLOGIC TROJAN!"
|
| U | Narrator | Narrator.exe | Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech
|
| U | Net Accelerator | NetAccelerator.exe | "Rizal NetAccelerator - ""Optimizing Dial-Up |
| U | NetAccelerator | NetAccel.exe | "NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster |
| X | Nettordinateur | GDC.exe | "Nettordinateur rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | Networks Configurator | NetConfs.exe | "Added by the RBOT-OX WORM!"
|
| N | NeuroSpeech OESpeaker | OEMonitor.exe | "Part of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not"
|
| N | Nikon Monitor | nkmonitor.exe | Monitors for a Nikon CoolPix camera being connected via USB port. As soon as it detects a CoolPix camera it executes the Nikon View software to enable the user to transfer images from the camera to the PC
|
| U | Nitro PDF Printer Monitor | NitroPDFPrinterMonitor.exe | "Printer monitor for Nitro PDF Professional from Nitro PDF |
| N | NkbMonitor.exe | NkbMonitor.exe | "Part of Nikon PictureProject - image management for Nikon digital cameras"
|
| X | NLS Monitor | nlsmon.exe | "Added by the RBOT-AXJ WORM!"
|
| U | NMBgMonitor | NMBgMonitor.exe | "Associated with Nero Scout |
| N | Nokia Connection Monitor | NclConf.exe | "Monitors the infrared port |
| N | Nokia Status Monitor | NclTray.exe | "Part of Nokia PC Suite version 5 - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" Monitors ports to see if a phone has been connected and provides System Tray access to the Connection Manager (and other PC Suite components if a phone is connected). Available via the Control Panel as ""Nokia Connection Manager"""
|
| U | NOMAD Detector | ctnmrun.exe | Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
|
| N | Norton Crashguard Monitor | cgmenu.exe | Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
|
| N | Norton Disk Doctor | Ndd32.exe | "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up |
| N | Norton Navigator Loader | nnloader.exe | "An older Norton utility for file management under Windows 95. More information here"
|
| N | Norton System Doctor | Sysdoc32.exe | "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up |
| U | NovastorSchedulerd | SCHENGD.EXE | NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
|
| ? | NPFMonitor | NPFMntor.exe | "Norton AntiVirus Firewall Install Monitor. What does it do and is it required?"
|
| N | NSystemMonitor | Symmon.exe | Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
|
| X | ntfsmonitorpro | ntfs64.exe | "Added by the FORBOT-EB WORM!"
|
| X | NVIDIA Display | DisplayMonitor.exe | "Added by the ABI.C WORM! Note - this is not a legitimate nVidia entry"
|
| U | NVIDIA System Monitor | NVMonitor.exe | "NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures |
| U | NVMonitor | NVMonitor.exe | "NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures |
| Y | Object Store Server | osserver.exe | "Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital |
| X | Offica Monitor Secura Systeme | winxp_sp3.exe | "Added by a variant of the RBOT WORM!"
|
| X | Office Monitor | adv32.exe | "Added by the SDBOT-CWO WORM!"
|
| X | Office Monitor | alg32.exe | "Added by the RBOT-GMM WORM!"
|
| X | Office Monitor | nvsvc86.exe | "Added by the IRCBOT.BVO BACKDOOR!"
|
| X | Office Monitor Secure Systema | absecure32.exe | "Added by the RBOT.FPW WORM!"
|
| X | Office Monitor Word Exel R | svch.exe | "Added by the DWNLDR-GWW TROJAN!"
|
| X | Office Monitor Word Exel R | u.exe | "Added by the SDBOT-DEE WORM!"
|
| X | Office Monitor Word Exel R | [trojan filename] | "Added by the IRCBOT-VX TROJAN!"
|
| X | Office Monitors | GoogleUpdater.exe | "Added by the RBOT-GKZ WORM! Note - this is not the updater for the popular Google tools"
|
| X | Office Monitorse | [path to worm] | "Added by the SDBOT-CZX WORM!"
|
| X | Offices Monitors | [path to worm] | "Added by the RBOT-GKO WORM!"
|
| X | Offices Monitorse | [path to worm] | "Added by the RBOT-GKO WORM!"
|
| X | Offices Monitorse | algose32.exe | "Added by the RBOT-GDD WORM!"
|
| Y | OfficeScanNT Monitor | pccntmon.exe | "Trend Micro OfficeScan Antivirus real-time scan monitor"
|
| X | OfficeWord Monitor | msn32.exe | "Added by the RBOT-GUE WORM!"
|
| X | OfficeWord Monitors | Offlce.exe | "Added by the IRCBOT.JZ TROJAN!"
|
| N | OM2_Monitor | FirstStart.exe | "Olympus Master 2 - digital camera management tools"
|
| N | OM2_Monitor | MMonitor.exe | "Olympus Master 2 - digital camera management tools"
|
| N | OM_Monitor | FirstStart.exe | "Olympus Master 1 - digital camera management tools"
|
| N | OM_Monitor | Monitor.exe | "Olympus Master 1 - digital camera management tools"
|
| N | One Touch Monitor | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | One Touch Monitor | 1tou~2.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | One Touch Monitor | ONETOU~2.EXE | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | OneTouch Monitor | OneTouchMon.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | OneTouchMonitor | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | OneTouchMonitor | 1tou~2.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | OneTouchMonitor | ONETOU~2.EXE | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| N | ONETOU~2 | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
|
| U | OnfolioStorage | onfserv.exe | """Onfolio is the complete solution for collecting |
| N | Operator | ?? | "Media Pilot operator |
| U | Operator | xtmop.exe | Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported
|
| U | Optus Cable Data Monitor | datamonitor.exe | "Allows Optus customers to monitor their actual data usage against Optus' ""data allowance limits"""
|
| U | OSSelectorReinstall | oss_reinstall.exe | "Related to Acronis Disk Director Suite"
|
| Y | OutpostMonitor | op_mon.exe | "Monitor for Outpost Firewall PRO (and Free) from Agnitum"
|
| U | PAC7302_Monitor | Monitor.exe | "Related to PixArt CMOS image sensors from PixArt Imaging Inc"
|
| X | Pag Windows Monitor | pag.exe | "Added by the AGENT-EOT TROJAN!"
|
| U | Pagis Schedule Monitor | Monitor.exe | Scheduler for the Pagis scanning suite from Scansoft (now Nuance)
|
| N | Pagis Scheduler | Monitor.exe | Scheduler for the Pagis scanning suite from Scansoft (now Nuance)
|
| X | PaintingRoom evidence monitor | paintingroom.exe | Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
|
| X | PaintingRoom smile monitor | paintingroom.exe | Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
|
| N | PAL Evidence Eliminator | Cleaner.exe | "PAL Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| X | PASMonitor | pbm.exe | "PersonalAntiSpy rogue spyware remover - not recommended |
| U | Password Door Loader | PDMonitor.exe | "Password Door - password protection software"
|
| ? | PCMCIA Resource Monitor | nvp2pmon.exe | "NVIDIA nForce P2P Driver. What does it do and is it required?"
|
| X | PcsProtector | PcsProtector.exe | "PcsProtector rogue security software - not recommended |
| U | pdfFactory Dispatcher v1 | fppdis1a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Dispatcher v2 | fppdis2a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Pro Dispatcher v1 | fppdis1.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Pro Dispatcher v3 | fppdis3a.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| X | Perfomance Monitor | davcsync.exe | "Added by the LAMUD-A WORM!"
|
| X | Personal Security Center Monitor | isc_ui.exe | "Added by the FAKEALERT TROJAN!"
|
| X | personalprotector | personalprotector.exe | "Personal Protector rogue security software - not recommended |
| U | Phone Connection Monitor | audevicemgr.exe | "Connection monitor part of the Sony Ericsson PC Suite mobile phone management utility for some models |
| N | Picasa Media Detector | PicasaMediaDetector.exe | "Media detector for Picasa's automatic photo organizer"
|
| N | PocketCam 3Mega Monitor | ICON.exe | Installed with the Aiptek PocketCam 3Mega digital camera. Automatically invokes an import process if the camera is connected and has media on it
|
| X | Popup Blocker System326a Monitoring | PopUpBlocker6a.exe | "Added by the RBOT.AUH WORM!"
|
| X | Popup Blocker System8 Monitoring | PopUpBlocker8.exe | "Added by a variant of the RBOT WORM!"
|
| U | Popup Terminator | GLADManager.exe | "Popup Terminator - pop-up killer"
|
| U | PopupEliminator | Popup Eliminator.exe | "Popup Eliminator - pop-up killer"
|
| X | Printer Monitor | webprinter.exe | "Added by the IRCBOT-Z TROJAN!"
|
| X | PrinterSpool | [path] RESTORE.EXE [path] SPOOL.EXE | "Added by the ALADINZ.K TROJAN!"
|
| X | Privacy Guarantor | PrivacyGuarantor.exe | "Privacy Guarantor rogue privacy program - not recommended |
| X | Privacy Protector | Privacy Protector.exe | "PrivacyProtector rogue privacy tool - not recommended |
| X | PrivacyConductor | GDC.exe | "PrivacyConductor rogue privacy tool - not recommended |
| X | PrivacyProtector Free | UPRP.exe | "PrivacyProtector rogue privacy tool - not recommended |
| U | Pro PCL Status Monitor | PENGSS.EXE | Xerox printer/fax/copier status monitor (PCL = printer control language)
|
| N | ProdikeysAutorun | Prodload.exe | "Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured |
| N | projselector | projselector.exe | Roxio Project Selector - can be started manually
|
| U | Propel Accelerator | PropelAC.exe | "Propel Internet Accelerator"
|
| X | Protected Storage | RUNDLL32.EXE MSSIGN30.DLL ondll_reg | "Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | Protector GB | protectgb.exe | "Added by the BANKER.EIE TROJAN!"
|
| U | PRPCMonitor | PRPCUI.exe | "Intel® SpeedStep™ interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power |
| X | PSCastor | PSCastor.exe | "Added by the PSCASTOR TROJAN!"
|
| ? | PSTORES | PSTORES.EXE | "Part of Windows Services Protected Storage?"
|
| X | Purgatory | Purga.exe | "Added by the PURGORY-B WORM!"
|
| N | QBCD autorun | autorun.exe | Quick Books CD
|
| Y | Rabo Session Monitor | RaboSessionMon.exe | "Related to RaboBank electronic banking software"
|
| U | RAID Event Monitor | Iaanotif.exe | "Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes |
| U | Rapid Restore | rrpcsb.exe | "XPoint ""Rapid Restore PC"" - ""a Managed Recovery solution that enables IT Administrators to protect the corporate image |
| Y | Raptor Mobile | vpnservices.exe | "Symantec VPN Client used to connect to corporate networks. If unchecked |
| X | RaptorDefence | RaptorDefence.exe | "RaptorDefence rogue security software - not recommended |
| X | Reactor3 | [random name]32.exe | "Added by the BOFRA.A WORM!"
|
| X | Reactor5 | [random name]32.exe | "Added by the BOFRA.D WORM!"
|
| X | Reactor6 | [random name]32.exe | "Added by the BOFRA.C WORM!"
|
| X | Reactor7 | [random name]32.exe | "Added by the BOFRA.B WORM!"
|
| X | Reactor8 | [random name]32.exe | "Added by the BOFRA.E WORM!"
|
| X | Reactor9 | [random name]32.exe | "Added by the BOFRA.E WORM!"
|
| U | Real Spy Monitor | Winrsm.exe | "Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | Realtek AC97 Audio - Event Monitor | ALCMTR.EXE | "Realtek Azalia Audio - Event Monitor |
| Y | Realtime Monitor | realmon.exe | "Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates"
|
| X | RealTimeProtector | winlogon.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
| X | Registry Checkup System326a Monitor | Winregs326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Registry Monitor | regmon.exe | "Added by the BCKDR-QKH BACKDOOR!"
|
| X | Registry Protector | regprotect.exe | "Added by the ARIVER.A WORM!"
|
| X | Registry System16 Checkup Monitor | SystemReg16.exe | "Added by a variant of the RBOT WORM!"
|
| X | Registry System166 Checkup Monitor | SystemReg166.exe | "Added by a variant of the RBOT WORM!"
|
| X | RegistryDoctor2008 | registrydoctor.exe | "RegistryDoctor2008 rogue registry cleaner - not recommended |
| X | RegistryMonitor | registry.pif | "Affilred adware"
|
| X | RegistryMonitor | sysfade.exe | "Added by the SYSFADE TROJAN!"
|
| X | RegistryMonitor1 | mljul1.exe | "Added by the SPAMBOT TROJAN!"
|
| X | RegistryMonitor1 | qtplugin.exe | "Added by the DELF-EZY TROJAN!"
|
| X | RegistryMonitor1 | igfxpers.exe | "Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
|
| X | RegistryMonitor1 | incognito.exe | "Added by the BUZUS.DAHY TROJAN!"
|
| X | Regmonitor | regmaping.exe | "Added by the BEAGLE.DO WORM!"
|
| X | Remote Access Monitor | rpgsvc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Remote Procedure Call Locator | RUNDLL32.EXE reg678.dll ondll_reg | "Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | Remote Storage Access | rmasvc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| Y | Remote Update Monitor | imonitor.exe | "Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer"
|
| U | Replicator | PTReplicator.exe | "Replicator from Karen's powertools. ""Automatically backup files |
| X | Restore | restore.exe | "Antispyware Shield Pro rogue security software - not recommended |
| X | Restore Operation | svchots.exe | "Added by a variant of the RBOT WORM!"
|
| U | RestoreDesktop | RestoreDesktop.exe | "Softwarium Restore Desktop ""is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change"""
|
| Y | RestoreIT! | VBPTASK.EXE | "RestoreIT! from FarStone - ""automatically backs up all files on your computer to a protected partition on your hard drive"""
|
| X | restorer32_a | restorer32_a.exe | "Added by the AGENT.CQQB TROJAN!"
|
| X | restorer64_a | restorer64_a.exe | "Added by the DLDR-BY TROJAN!"
|
| X | restory | restory.exe | "Added by the RETSAM TROJAN!"
|
| Y | RogueMonitor | RogueRemoverPRO.exe | "Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
|
| X | RpcLocator | explorer.exe | "Added by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| Y | RTMonitor | RTMonitor.exe | "Cheyenne (now eTrust) antivirus"
|
| U | Run Google Web Accelerator | GoogleWebAccWarden.exe | "Google Web Accelerator"
|
| U | Run Nintendo Wi-Fi USB Connector Registration Tool | NintendoWFCReg.exe | "Related to Wi-Fi USB Connector from Nintendo"
|
| U | Run StartupMonitor | StartupMonitor.exe | "Mike Lin's StartupMonitor |
| X | run= | mouse_configurator.win | "Added by the GAGGLE.E WORM!"
|
| U | RunNarrator | Narrator.exe | Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech
|
| X | SafetyCenter | protector.exe | "Safety Center rogue security software - not recommended |
| U | Samsung MJC-900 Series Monitor | "RUNDLL32.EXE SMMASHLL.DLL | AutoUpdatePnPValue" |
| ? | Scan Detector | Pmxdetect.exe | "Associated with PrimaScan scanners. Is it required?"
|
| N | Scanner Detector | SDetect.exe | "ScanSuite Scanner Detector - part of ScanWizard |
| U | scheduler_monitor | init_scheduler.exe | "Scheduler for ReaConverter advanced image converter"
|
| ? | SDClientMonitor | sdclientmonitor.exe | "Related to LANDesk Management Suite from LANDesk Software Ltd. What does it do and is it required?"
|
| X | Secure System | integitor.exe | "Added by the AGOBOT.ACI WORM!"
|
| X | Security Monitor | securemon.exe | "Added by the SLENFBOT.ABH WORM!"
|
| X | Service Monitor | msnfilen.exe | "Added by the RBOT-ALE WORM!"
|
| X | Service Monitor | javams32.exe | "Added by the DELF-NK TROJAN!"
|
| X | Service Monitor | javams64.exe | "Added by the SDBOT-AFO WORM!"
|
| X | Service Monitor | msnserve.exe | "Added by the SPYBOT.YQW WORM!"
|
| X | Service Monitor | WinOcx.exe | "Added by the RBOT-AQJ WORM!"
|
| X | Service Monitor | csnss.exe | "Added by the RBOT.EEH WORM!"
|
| X | Service Monitor | filen.exe | "Added by a variant of the RBOT WORM!"
|
| X | Service Monitor | winxpser.exe | "Added by the RBOT-BDF WORM!"
|
| X | ServiceAdministrator | SERVICES.EXE | "Added by the KORRON.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
| X | Services Administrator | localsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | spoolsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | svcadmin.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | svcman.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | svcrun.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | tcpsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Services Administrator | websvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | ServicesAdministrator | SERVICES.EXE | "Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process |
| X | SiS 6326 Accelerator | sis6326m.exe | "Added by the MSIC BACKDOOR!"
|
| U | Smart Connect Monitor | SCMon.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
|
| U | Smart Protector Pro | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| X | Smart Virus Eliminator | SM[random characters].exe | "Smart Virus Eliminator rogue security software - not recommended |
| X | smartprotector | smartprotector.exe | "Smart Protector rogue security software - not recommended |
| U | SmartProtector-Pro | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| X | SM_IAN | ian_monitor.exe | "AdvancedCleaner rogue security software - not recommended |
| U | Snapfish Media Detector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| U | SnapfishMediaDetector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| ? | SO5 Integrator Pass One | sointgr.exe | "StarOffice 5. See here for more details"
|
| ? | SO5 Integrator Pass Two | sointgr.exe | "StarOffice 5. See here for more details"
|
| U | Softany Monitor Control | MonitorControl.exe | "Softany Monitor Control - ""control your computer's monitor and screensaver"""
|
| ? | SoSyncMonitor | SoSyncMonitor.exe | "SuperOffice related. What does it do and is it required?"
|
| U | Spam Monitor | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| U | spamihilator | spamihilator.exe | "Spamihilator - spam filter"
|
| U | SpamMonitor | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| U | SpamMonitor Application | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| ? | SPC610NC_Monitor | Monitor.exe | "Related to the Philips SPC610NC webcam. What does it do and is it required?"
|
| N | SpeedBitVideoAccelerator | VideoAccelerator.exe | """SpeedBit Video Accelerator makes videos from YouTube and over 150 sites stream faster and play smoother by reducing buffering problems and video interruptions or hiccups"""
|
| U | SPSTEALT | SmartProtectorPro.exe | "Smart Protector Pro - internet privacy tool that erases tracks |
| U | SPSTEALT | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| ? | spstore | storesp.exe | "Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup"
|
| U | Spy Protector | SpyProtector.exe | "Included in the full version of Security Task Manager |
| X | Spy Protector | srcss.exe | "SpyProtector rogue security suite - not recommended |
| X | Spy Protector | lsascs.exe | "Spy Protector rogue security software - not recommended |
| X | SpyDevastator | SpyDevastator.exe | "SpyDevastator rogue security software - not recommended |
| X | SpyFighterMonitor | SpyFighter.exe | "SpyFighter spyware remover - not recommended |
| X | Spyinator | Spyinator.exe | "Spyinator rogue spyware remover - not recommended"
|
| X | SpyOnThis Monitor | SpyOnThisMonitor.exe | "SpyOnThis rogue spyware remover - not recommended"
|
| U | spyprodetector | spydetector.exe | Spyware Process Detector spyware remover
|
| Y | Spyware Doctor | spydoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| Y | Spyware Doctor | swdoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| X | Spyware Stormer | SpywareStormer.Exe | "Spyware Stormer spyware remover - not recommended |
| Y | Spyware X-terminator | SpywareX.exe | "Spyware X-terminator antispyware from StompSoft |
| X | spywareisolator | spywareisolator.exe | "SpywareIsolator rogue spyware remover - not recommended |
| Y | SpywareTerminator | SpywareTerminatorShield.exe | "Spyware Terminator's real-time protection. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| Y | SpywareTerminatorUpdate | SpywareTerminatorUpdate.exe | "Automatic updates for Spyware Terminator. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| U | Startup Manager Scanner | StartupMonitor.exe | "Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans |
| U | StartupMonitor | StartupMonitor.exe | "Mike Lin's StartupMonitor |
| N | Status Monitor | BrMfcWnd.exe | Brother scanner status monitor - can be started manually
|
| U | Status Monitor CLJ1500 | HPPOUMUI.exe | "Status monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status |
| N | Status Monitor XE | ENGSS.EXE | The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
|
| X | stealth.injector.exe | stealth.injector.exe | "Added by the THEALS.A WORM!"
|
| U | StillImageMonitor | Stimon.exe | "Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example |
| U | StorageGuard | sgtray.exe | "StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop) |
| X | StorageProtector | SysRep.exe | "StorageProtector rogue system error and cleaning utility - not recommended |
| U | StormCodec_Helper | StormSet.exe | "Storm Codec is a codec pack for Windows"
|
| X | svchost connection monitor | svchost32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | SvcManager | restore3.exe | "Added by the AGENT-DSS TROJAN!"
|
| U | Symantec NetDriver Monitor | SNDMon.exe | "Part of Symantec's LiveUpate (eg |
| X | Sysmon | SystemMonitor.exe | "Added by the NUJAMA-A WORM!"
|
| X | sysPersonalFirewall | tskm0nitor.exe | "Added by the SDBOT.APC WORM!"
|
| X | SysProtector | SysProtector.exe | "SysProtector rogue security software - not recommended |
| X | sysrestore32.exe | sysrestore32.exe | "Unknown malware detected by McAfee - see here"
|
| X | System Configurator32 | SYSTEMCFG.EXE | "Added by the AGOBOT-KS WORM!"
|
| X | System Doctor Free | systemdoc.exe | "SystemDoctor rogue security software - not recommended |
| X | System Efficiency Monitor | mscedit32.exe | "Added by the SDBOT.P TROJAN!"
|
| X | System Efficiency Monitor | mscommand.exe | "Added by the KWBOT.P WORM!"
|
| X | System Efficiency Monitor | msedit32.exe | "Added by the STEPH-B WORM!"
|
| X | System Efficiency Monitor | svchostx.exe | "Added by the KWBOT.E WORM!"
|
| N | System Mechanic Professional Update [Incinerator.dll] | SysMech4.exe /REREG: [path] Incinerator.dll | "Iolo System Mechanic ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again"
|
| U | System Monitor | SYSMON.EXE | "Comes with some Aopen motherboards. Monitors CPU temp |
| X | System Monitor | Sysmon16.exe | "Added by the SDBOT TROJAN!"
|
| X | System Monitoring | cute.exe | "Added by the RAHIWI.A WORM!"
|
| X | System Monitoring | Mooks.EXE | "Added by the BHARAT.A WORM!"
|
| X | System Monitoring | lsass.exe | "Added by the BRONTOK-BS WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
| X | System Protector | lsascs.exe | "System Protector rogue security software - not recommended |
| X | System Restore | svcnet.exe | "Added by the TIBICK WORM!"
|
| X | System Restore Data | [path] repcale.exe [path] beird.exe | "Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
|
| X | System Services Monitor | server.exe | "Bifrost malware"
|
| X | System Support | torrent.exe | "Added by a variant of the RBOT WORM!"
|
| X | System time updator | CSysTime.exe | "Added by the RANDEX.S WORM!"
|
| X | System Tray Monitor | tray.exe | "Added by the RBOT.UXR WORM!"
|
| X | SystemDoctor 2006 Free | sd2006.exe | "SystemDoctor rogue security software - not recommended |
| X | SystemDoctor Free | systemdoc.exe | "SystemDoctor rogue security software - not recommended |
| X | SystemMonitor | Sysmon32.exe | "Added by the AIDID.A WORM!"
|
| X | SystemTray Monitor | SysTraymon.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | taengtae | AutoRun.bat | "Added by the GATINA-B WORM!"
|
| X | TANG_INA_MO | AutoRun.bat | "Added by the FILUKIN.A WORM!"
|
| U | Task Catcher Monitor | tasktrap.exe | "Real-time monitor for Task Catcher from BillP Studios - which ""allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash"". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available"
|
| U | Task Catcher Real-Time Detector | tasktrap.exe | "Real-time monitor for Task Catcher from BillP Studios - which ""allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash"". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available"
|
| X | Task Monitoring Service | svchost.exe | "Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
|
| U | TaskMonitor | taskmon.exe | "The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users |
| Y | Tau monitor | Taumon.exe | """Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system"""
|
| U | tcmonitor | tcm.exe | "Part of The Cleaner from MooSoft - warns of changes to the registry"
|
| X | TCP Monitoring | LanNSvc.exe | "Added by the RANDEX.AAS WORM!"
|
| X | The Spy Guard Monitor | spyguard_monitor.exe | "The SpyGuard rogue spyware remover - not recommended |
| X | TheMonitor | [path to trojan] | "Added by the DLOADR-LO TROJAN!"
|
| X | TheMonitor | Duce6.exe | "YourEnhancement downloader"
|
| U | ThinkPad Presentation Director | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
|
| ? | Ticket API Monitor | tktmon.exe | "Syntegra Device Identification Logger. What does it do and is it required?"
|
| U | TimounterMonitor | TimounterMonitor.exe | "Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
|
| X | TkNetDriver Monitor | lexbce.exe | "Added by the SDBOT-ADF WORM!"
|
| N | TMMonitor | tmmonitor.exe | "System Tray access and sync monitor for TotalMedia from Arcsoft - ""an all-in-one multimedia application that allows you to access and work with digital photos |
| X | TmNetDriver Monitor | exbce.exe | "Added by the SDBOT-ABR WORM!"
|
| N | Tor | tor.exe | "Tor anonymous internet communication system. Shortcut available via Start -> Programs"
|
| X | tor anonymous proxy | tor32.exe | "Added by the SDBOT-ADR WORM!"
|
| X | Torjan Program | [path to trojan] | "Added by the LEGMIR-BO TROJAN!"
|
| X | Torjan Program | smss.exe | "Added by the WOWCRAFT.B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Torjan Program | WINLOGON.EXE | "Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Torrent Management Service | system32.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Torrent Management Service | TMANAGESVC.EX | "Added by a variant of the IRCBOT TROJAN!"
|
| U | TOSHIBA Volume Indicator | VolControl.exe | On-screen volume indicator for Toshiba notebooks
|
| U | TotalMedia Backup Monitor | uBBMonitor.exe | "ArcSoft's TotalMedia Backup - ""Backing up your precious photos |
| U | Track4WinMonitor | STMonitor.exe | "Track4Win Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
| U | TrojanShield Protector | Port.exe | "TrojanShield anti-hacker/anti-trojan software"
|
| X | TrojanSimulator | TSServ.exe | "Trojan Simulator security risk which simulates a trojan infection and may be used to verify whether a virus scanner can properly detect the file"
|
| N | TrueImageMonitor.exe | TrueImageMonitor.exe | "Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
|
| Y | TrueVector | VSMON.EXE | Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
|
| X | TrustDoctor | TrustDoctor.exe | "TrustDoctor rogue security software - not recommended |
| ? | Tukati | TukatiRedistributor.exe | "Tukati Digital Content Distribution. Is it required?"
|
| U | UCmore XP - The Search Accelerator | "rundll32.exe UCMTSAIE.dll | DllShowTB" |
| ? | UFD Monitor9382 | ufdlmon.exe | "Part of USB Flashdisk software - what does it do and is it required?"
|
| ? | Ulead AutoDetector | Monitor.exe | "Related to Ulead Systems Inc. programs. What does it do and is it required?"
|
| ? | Ulead AutoDetector v2 | monitor.exe | "Related to Ulead Systems Inc.. What does it do and is it required?"
|
| U | Ulead Memory Card Detector | Monitor.exe | "Ulead Memory Card Detector - ""Automatically starts datadownload when your card is inserted into a memory card reader"""
|
| U | UnHackMe Monitor | hackmon.exe | "UnHackMe allows you to detect and remove a new generation of 'invisible' Trojan programs called ""rootkits"""
|
| U | USB 3.0 Monitor | nusb3mon.exe | "Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds"
|
| X | USB Hardware Monitoring | USBhardware.exe | "Added by the RBOT-NN WORM!"
|
| X | USB Hardware326 Monitoring | USBhardware326.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | USB Hardware32c Monitoring | USBHARDWARE32C.EXE | "Added by the RBOT-UU WORM!"
|
| U | USBDetector | USBDetector.exe | USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
|
| U | USBDetector | UDetect.exe | USB tray icon/detection for external Belkin (and maybe other makes) under Win98
|
| U | USIUDF_Eject_Monitor | USISrv.exe | "Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present"
|
| U | UStorag | ustorage.exe | "U-Storage is application software running under Microsoft Windows |
| N | Ustorage | Ustorage.exe | "Maintenance tool (enable security functions) for a USB drive from Pretec"
|
| N | uTorrent | uTorrent.exe | "µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent |
| N | uTorrent.exe | uTorrent.exe | "µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent |
| U | Venturi Configurator | ventcfg.exe | "Venturi Wireless mobile broadband configuration utility"
|
| U | VERBATIM STORE 'N' G | verbatim store 'n' go.exe | "Loads the driver for the Verbatim Store'n'Go PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium"
|
| U | ViivMonitor | ViivMonitor.exe | "Related to Intel Media Share Software. ""Stream or download media files from your Intel® Core®2 Processor with Viiv® technology-based PC"""
|
| X | Virus Doctor | Vdoc[random].exe | "Virus Doctor rogue security software - not recommended |
| X | Virus Protector | [random].exe | "Virus Protector rogue security software - not recommended |
| X | VirusIsolator | VirusIsolator | "VirusIsolator rogue security software - not recommended |
| X | VirusIsolator.exe | VirusIsolator.exe | "VirusIsolator rogue security software - not recommended |
| U | WD Backup Monitor | uBBMonitor.exe | "WD Backup - customized version of ArcSoft's TotalMedia Backup for Western Digital external drives (see here)"
|
| X | Webcelerator | webcel.exe | "Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
|
| X | Website Administrator Info | webadmin.exe | "Added by the FORBOT-FY WORM!"
|
| N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
|
| X | Win Updator Services | ctfnom.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker
|
| X | WinDirectories | tdirs.exe | "Added by the VB-EPB VIRUS!"
|
| X | Window Monitor | winmon32.exe | "Added by the SDBOT.RT WORM!"
|
| X | Windows 32 Editor | Win32edit.exe | "Added by the WOOTBOT.GQ WORM!"
|
| U | Windows Accelerators | setup.exe | "KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | Windows Communicator | wincomm.exe | "Added by the AGOBOT-BH WORM!"
|
| X | Windows Communicator for NT/XP | osndyrn.exe | "Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
|
| X | Windows Configurator | winconf.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Windows Console Monitor | [path to worm] | "Added by the KEDEBE WORM!"
|
| X | Windows Console Monitor | gcasAV32.exe | "Added by the KEDEBE-A WORM!"
|
| X | Windows Defender Monitor | wdm*.exe | "Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
|
| X | Windows Fix | integator.exe | "Added by the SDBOT.ZAB WORM!"
|
| X | Windows Locator | wsass.exe | "Added by the IRCBOT.N TROJAN!"
|
| X | Windows Monitor | winmon.exe | "Added by the SDBOT.VB WORM!"
|
| X | Windows Monitor | arsetup.exe | Added by the SPAZBOX.A TROJAN!
|
| X | Windows Monitor Services | winmonitor.exe | "Added by the RBOT-XX WORM!"
|
| X | Windows Monitoring Service | winmon.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Networking Monitor | mdm.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Windows Networking Monitorin | xmdmx.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Networking Monitoring | mdm.exe | "Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Windows Office Monitor | emdm.exe | "Added by the RBOT.AFV BACKDOOR!"
|
| X | Windows Performance Monitor | wmscupd.exe | "Added by the IRCBOT_GEN WORM!"
|
| X | Windows Print Monitor Daemon | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Protected Storage | npssvc.exe | "Added by the IRCBOT.AUL BACKDOOR!"
|
| X | Windows Sound Emulator | snd32_win.exe | "Added by the ATNAS.A WORM!"
|
| X | Windows Storm-Memory Drivers | memorystorm.exe | "Added by the SLENFBOT.CO WORM!"
|
| X | Windows Stortup | svchost.exe | "Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows System Restore Configuration | Sblhost.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows System Restorer | SystemRestorer.exe | "Added by the DULOAD.C WORM!"
|
| X | Windows System Security Monitor | [4 random letters].exe | "Added by the PINKTON.A WORM!"
|
| X | Windows Task Manager Emulator | kennewr.exe | "Added by the SPYBOT-FA WORM!"
|
| X | windows update configurator | svghost.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | windows update configurator | explore.exe | "Added by the SDBOT.RY BACKDOOR!"
|
| X | Windows Update Monitoring Service | winupdt.exe | "Added by the RBOT-PL WORM!"
|
| X | Windows USB Monitor | servupdate.exe | "Added by the IRCBRUTE.AQ TROJAN!"
|
| U | WindowsTranslator | DWinTrsl.exe | "Delta Translator® English < > Portugese (Brazilian) version - ""an automatic |
| U | WindowsTranslator_Espanhol | DWinTrsl.exe | "Delta Translator® Spanish < > Portugese (Brazilian) version - ""an automatic |
| U | WinGate Engine Monitor | wgengmon.exe | "WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine |
| X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related
|
| U | WinPatrol Monitor | winpatrol.exe | "WinPatrol - ""Manage Startup programs |
| X | WinPCDoctor | SysRep.exe | "WinPCDoctor rogue system error and cleaning utility - not recommended |
| X | WinProtector | WinProtector.exe | "WinProtector rogue security software - not recommended |
| X | WinReanimator | WinReanimator.exe | "WinReanimator rogue security software - not recommended |
| X | winrestore1 | winrestore.exe | "Added by the KILLFIL-Q TROJAN!"
|
| X | WinRun | AutoRun.ini | "Added by the LOVELET-AD WORM!"
|
| X | WinUpdateAdministrator | CSRSS.EXE | "Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
|
| X | WinXP Processor Generator v1.2 | intspnsr32.exe | "Added by the SDBOT.LP WORM!"
|
| X | WinXProtector | WinXProtector.exe | "WinXProtector rogue security software - not recommended |
| U | WireLessMouse | StartAutorun.exe MouseDrv.exe | "Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries"
|
| U | Worm Detector | wd.exe | "Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam"
|
| U | WTIndicator | SchedInd.exe | "WinTask - software that automates a variety of routine tasks quickly and simply"
|
| U | X1FileMonitor.exe | X1FileMonitor.exe | "Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
|
| U | XPCMonitor | XPCMonitor.exe | "XPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| ? | YaAutoRepair | yrepair.dll | "Appears to be related to software from Yahoo China. What does it do and is it required?"
|
| U | YahooMonitor | YahooMonitor.exe | "Yahoo Messenger Monitor Sniffer surveillance software for the Yahoo! instant messenger. Uninstall this software unless you put it there yourself"
|
| U | Yumgo's Homepage Protector V1 | YumgoHomepageProtector.exe | "Yumgo's Homepage Protector"
|
| X | Zolero Translator | ZoleroTranslator.exe | "Zolero Translator - added by Clickspring |
| X | [32 random hex numbers] | badware-protector.exe | "Badware Protector rogue security software - not recommended |
| X | [Randomly chosen existing folder name] | _autorun.exe | "Added by the ANTINNY-L WORM!"
|
| X | [various names] | TorontoMail.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| N | µTorrent | uTorrent.exe | "µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent |
| N | µTorrent | bittorrent.exe | "BitTorrent file sharing client - from BitTorrent |