Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X%Windir%winnl.exewinnl.exe"Added by the KIDKITI TROJAN!"
X%Windir%winnm.exewinnm.exe"Added by the KIDKITI TROJAN!"
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@wincms.exe"Added by the RBOT.CBR WORM!"
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
Xantikewingate32.exe"Added by a variant of the RBOT WORM! See here"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
Xautowin32.exe"Added by an unidentified TROJAN! See here"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
XAVScanwinav.exeUnidentfied rogue security software
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
YClamWinClamTray.exe"ClamWin antivirus"
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwin.exe"Added by the VBS.RUNAUTO.G WORM!"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
?encapsulated command toolwintr.com"??"
XEnh Win Updtenhupdt.exe"Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFromine WinPopupwinpopup.exeInstant Messenger program
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XgetwinwinB_.exe"Added by the BANKER-HS TROJAN!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
Xgpmcewindow.exe"Added by the VB.CK WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
NGWInkMonitorGWInkMonitor.exe"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
XHhjg5jfd93dftdfwinlogan.exe"Added by the ERTFOR.A TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
UIBWin Background processIBackground.exe"IBackup for Windows"
UIBWin MonitorIBMonitor.exe"IBackup for Windows"
Xicq litewinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
UIE New Window Maximizeriemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XIpWinsipwins.exe"IPWins adware"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
Xjkdfj94kgdftdfwinlogan.exe"Added by the ZLOB.BZ TROJAN!"
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
XKAVFOXwin1ogoin.exe"Added by the GWGHOST-M TROJAN!"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
XKernel32Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
XKernelCheckwinser.exe"Added by the TSPY_LMIR.SL TROJAN!"
XKernelFaultCheckwinabc3.exe"Added by the NUBYS-A VIRUS!"
XKernelFaultCheckwinbin.exe"Added by the DLOADR-AAX TROJAN!"
Xkeywinxp.exe"Added by the BEAGLE.AG WORM!"
Xkey2winlog.exe"Added by the BAGLEDI-AL TROJAN!"
Xl44sys**winmine"Added by the VBS.LIDO WORM - where ** is a number between 33 and 44"
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
Xlnwin.exelnwin.exe"Added by the DLOADR-ATC TROJAN!"
XLoadwin32.exe"Added by the RUBBLE-A WORM!"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
Xload32winldra.exe"Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Xload=win32exec.exe"Added by the BITTER WORM!"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
ULoginwinlog.exe"Salfeld Child Control - parental control software"
XLogServicewincalc.exe"Added by the PAPROXY TROJAN!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
XLTM2winscan.exe"Added by the LITMUS-B TROJAN!"
XLTM2winvers16.exe"Added by the SMALL.ND TROJAN!"
YLTWinModem1ltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
XMCwintrims.exe"Added by the WINTRIM TROJAN!"
XMCWINTRIM.EXE"Added by the WINTRIM.A TROJAN!"
XmcafeeWin32.dll.vbs"Added by the CATCHER-B WORM!"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
NMcAfee Winguage??"Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications
XMD IE Pluginwiny.exeAdware
XMicr Update Systemupwin.exe"Added by the SDBOT.YS WORM!"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicroMix32WinCon.exe"Added by the VB-ECC TROJAN!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoftwindl32.exe"Added by the SDBOT-DCZ WORM!"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoftwinnn.exe"Added by the RANDEX.GGP WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft Command Cwinhost32.exe"Added by the SDBOT-BBA WORM!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft DLL Librarywinlib32.exe"Added by the ATNAS.A WORM!"
XMicrosoft Dll Managementwindll.exe"Added by the RBOT-MT WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Loginwinlogin.exe"Added by the RBOT-AJP WORM!"
XMicrosoft Loginswinlogins.exe"Added by the SPYBOT.BCZ WORM!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Rundllwindos.exe"Added by the SDBOT-WF WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementwinnt.exe"Added by the RBOT-MQ WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Managementwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XMicrosoft Security Managerwinamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Sound Technologywinsound.exe"Added by the RBOT-AGG WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft Stuff you knowwinslogin.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Synchronization ManagerWinLoginnn.exe"Added by the SPYBOT.FO WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization Managerwin.exe"Added by the SDBOT.AK WORM!"
XMicrosoft Synchronization Managerwinlogon32.exe"Added by the SDBOT.AEU WORM!"
XMicrosoft Synchronization Managerwincfg32.exe"Added by the SDBOT.DO WORM!"
XMicrosoft Synchronization Managerwin932.exe"Added by the SDBOT.AH WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewindows24.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewingrd32.exe"Added by the RBOT-DW WORM!"
XMicrosoft UpdateWinUpdate32.exe"Added by the RBOT-TI WORM!"
XMicrosoft Updatewinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatewinupdater.exe"Added by the RBOT.BIN WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft UpdateWINDOC.EXE"Added by the SDBOT.PF WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewindows32.exe"Added by the RBOT-BHQ WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32winin.exe"Added by the RBOT-ARR WORM!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Update 64 BITwinman32.exe"Added by the RBOT-AKI WORM!"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update ManagerWINRLS.EXE"Added by the RBOT-AF WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft Win UpdateWinUP.exe"Added by the RBOT-BPR WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windowsatup"Added by a variant of the RBOT WORM!"
XMicrosoft WindowsMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Windowsexplorar.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows[path to file]"Added by the BDOOR-LI BACKDOOR!"
XMicrosoft Windowsbootini.exe"Added by the VANEBOT-K WORM!"
XMicrosoft WindowsKernel.exe"Added by the EDIBARA-A VIRUS!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windowspwjbvphi.exe"Added by the RBOT-GQK WORM!"
XMicrosoft Windowswindets.com"Added by the FLOOD-EQ TROJAN!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Autowxcknautowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUIWindowz.exe"Added by the RANDEX.AEV WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playerwimp.exe"Added by the RBOT-FN WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UMicrosoft Windows SidebarSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatawindows.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WINGS32 ProtocolWinSGR32.exe"Added by the RBOT-APU WORM!"
XMicrosoft WinRaRwinrar.exe"Added by the RBOT-AEC WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft WinUpdatesyslx32.exe"Added by an unidentified VIRUS
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinupd32.exe"Added by the RBOT.MQ WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
XMicrosofts mediawingtp.exe"Added by the RBOT-VO WORM!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftUpdateWinUp32.exe"Added by an unidentified VIRUS
XMicrosoftUpdatewindll.exe"Added by the RBOT-IH WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosoftWindowsa@26m.exe"Added by the KILLPAR-B TROJAN!"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UMicrosoft® Windows® Operating SystemSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
NMicrosoft® Windows® Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
UMicrosoft® Windows® Operating SystemehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
NMicrosoft® Windows® Operating Systemstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosotufed Update 32windinit.exe"Added by the RBOT-CTJ WORM!"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Driverwindrive32.exe"Added by the SLINBOT.TT BACKDOOR!"
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMismowin32x.exe"Added by the RBOT-JP WORM!"
NMMCWINMGMTwinmgmt.exe"Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here"
Xmmxrunmswinindex.exe"TwoSeven spyware"
Xmobiswing[random].exe"Mobis adware"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
Xms ownagewinPE.exe"Added by the RBOT-AJL WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS Sys Securitymswin.pif"Added by the RBOT-APJ WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Unix Binarywin32ttb.exe"Added by the SPYBOT.OQ WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryWinGuard.exe"Added by the RBOT-ACL WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMS Windows Executor ProcessMSEXECP32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMS Windows procces 32msprocces.exe"Added by the RBOT-AEZ WORM!"
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMS WINS Binaryign32.pif"Added by the RBOT-ASB WORM!"
XMS Winsockmsws2_32.exe"Added by the AKBOT-A TROJAN!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSDN for Windows NTmsdn.exe"Added by a variant of the RBOT WORM!"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
XMSDN for Windows with NT'smsdn-nt.exe"Added by the RBOT-EWD WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMSIdllwinmp.exe"Added by a variant of the RBOT WORM!"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsnwinlogon.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XMSN Administration For Windowsmsnadp32.exe"Added by the BROPIA.W WORM!"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
XMsn Messengwindns.exe"Added by a variant of the RBOT WORM!"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
NMSN Search ToolbarWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMsn Updaterwindatemanager.exe"Added by the SDBOT.TS WORM!"
XMsnExplorerwinagent.exe"Added by the BDOOR-EQ BACKDOOR!"
XMSNMSGRRswin.batIRC backdoor TROJAN or WORM!
Xmsnntwinampb.exe"Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!"
Xmsnntwinampf.exeAdded by the SMALL.DTS TROJAN!
XMsnWinmessagewin.exe"Added by the BANCBAN-D TROJAN!"
NMSN® Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
XMSStartOptimizerWINUPD.EXE"Added by the DASMIN-E TROJAN!"
XMSWinmswin.exe"Added by the BANKER-CU TROJAN!"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
Nmswinextmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSWinlogonSynCor.exe"Added by the AGENT-FZL TROJAN!"
XMSWinlogonwinlogon.exe"Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMswinpid32mswinpid32.exeAdded by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMSWinupdwinupd.exe"Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMsWinVgrmsvgr.exe"Added by the MYTOB.LE WORM!"
XMS_NETD_WIN32netd32.EXE"Added by the RANDEX.F WORM!"
XMultimediawindebug.exe"Added by the VB-ERB WORM!"
Xmvsyswinaacsysiom.exe"Added by a variant of the SDBOT WORM!"
Xmysoftwinexplor.exe"Browser hijacker
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
XNAV Agentwinsnav.vbs"Added by the ANPES WORM!"
XNAV Auto Updatesnavwindows.exe"Added by a variant of the SDBOT WORM!"
NNB Windows PatternsWINDBKGND.EXE"Part of McAfee Nuts & Bolts. With Background Patterns
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
XNDIS Adapterwindows.exe"Added by the FORBOT-BR WORM!"
XNDIS AdapterWinman.exe"Added by the WOOTBOT.AG WORM!"
XNDplDeamonwinlogin.exe"Added by the RANDEX.E WORM!"
XNeroUpdater6.8winjava.exe"Added by the AGOBOT.AMK WORM!"
XNetWINREG.EXE"Added by the ASSASIN.D TROJAN!"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
UNetPatrolwinclient.exe"NetPatrol network monitoring software"
XNetworknetwin.exe"Added by the SILLYFDC-CG WORM!"
XNetwork Accesswinssh.exe"Added by a variant of the SDBOT WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Provisioning ServiceWinNPS.exeAdded by an unidentified WORM/TROJAN!
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
XNorton Personal Firewallwinmpts.exe"Added by the RBOT.ANT WORM!"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNorton Updaterwinset.exe"Added by a variant of the SPYBOT WORM!"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNT LM Security Support ProviderWinNTLM.exe"Added by a variant of the SDBOT WORM!"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTsocketNoeWinnt.exe"Added by the ATAKA-E TROJAN!"
Xnvc Win32nvcvc.exe"Added by the RBOT-ADD WORM!"
Xnvchostwinlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvCplwindowsp.exe"Added by a variant of the SDBOT WORM!"
XNvCplScanwinasp.exe"Added by the FORBOT.BZ WORM!"
XNVIDIA Media Center Librarywinlogon.exe"Added by the AUTORUN-AZK WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?OEPowerPlugswinoeinit.exe"??"
XOffica Monitor Secura Systemewinxp_sp3.exe"Added by a variant of the RBOT WORM!"
YOfficeScan95pccwin97.exe"Trend Micro antivirus OfficeScan"
XOKGOwinutade.exe"Added by the BANKER-EHZ TROJAN!"
YOneCareUIwinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XOptimize WindowsKuntilanak.exe"Added by the SILLYFDC WORM!"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XOS Securitymswind32.pif"Added by the RBOT-ASU WORM!"
XOSAwinword.exe"Added by the KANGAROO-A TROJAN!"
XPag Windows Monitorpag.exe"Added by the AGENT-EOT TROJAN!"
XPaRaY_VMwinlogon.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XPatches ValueWinGamed.exe"Added by the SDBOT.BR WORM!"
XPerforms peer to peer connectionWinPTTP.exe"Added by the RBOT-GMI WORM!"
XPmediawinsrvc.exe"Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!"
XPopMarkWinTask.exe"""Pop Marketing"" adware"
XPPPOEOEwinlite.exe"Added by the RBOT-AAN WORM!"
XPreInstall Windows[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
?ProgramWindowmore comp.exe"??"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
UQuick Hide Windowsqhw.exe"Quick Hide Windows from CronoSoft - ""provides a quick and easy way for home and office PC users to quickly get sensitive materials off the screen without closing programs or losing documents"""
XquickenWinrar.exe"CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!"
XQuicktime Mediaplayerwinmplyer32.exe"Added by the RBOT-PM WORM!"
XQuicktime Pro 3.0winuodps.exe"Added by the GAOBOT.BH WORM!"
XRandomWin32mgnwin32.exe"Added by the SDBOT-DV WORM!"
UReal Spy MonitorWinrsm.exe"Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
XRealTimeProtectorwinlogon.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
Xregdiitwinxp.exe"Added by the RUNAUTO.F WORM!"
Xregdiitwin.exe"Added by the VBSAUTO-A WORM!"
XRegDonewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XRegistry Checkupwinreg.exeAdded by an unidentified WORM or TROJAN!
XRegistry Checkup System326a MonitorWinregs326a.exe"Added by a variant of the SDBOT WORM!"
XRegistry Loaderwinhlpp32.exe"Added by the GAOBOT.AO WORM!"
XRegistry oidetwin32.exe"Added by the RBOT.BMT WORM!"
XRegistry Value Namewinapi32.exe"Added by a variant of the RBOT WORM!"
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XRegistryChkwinbackup.exe"Added by the MERTIAN WORM!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
URegRun WinBaitwinbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
XRemote Desktop Help Session ManagerWinRDH.exe"Added by a variant of the SDBOT WORM!"
XRemote Procedure Callwinrpc.exe"Added by the RBOT-KM WORM!"
XRemote Procedure Callwinsysrpc.exe"Added by the SDBOT-PS WORM!"
XRemote Procedure Call For Windows 32bitrpc.exe"Added by the RBOT-MD WORM!"
XRemote Procedure Callsmswinrpc.exe"Added by the RBOT.KJ WORM!"
XRemote Procedure Callsmswinc.exe"Added by the RBOT-IT WORM!"
XRemote Procedure Callswin.exe"Added by the SDBOT-QI WORM!"
XREMOVE MEwindos.exe"Added by the SDBOT.EE WORM!"
XROOT_Machinewinlogon.exe"Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
Xrpc Win32shost32.exe"Added by the RBOT-ABL WORM!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
XRPCall_WIN2KKurawas.exe"Added by the BHARAT.A WORM!"
Xrpcda Win32rpcda.exe"Added by the RBOT-AEE WORM!"
XRPCserr32gwinlogon.exe"Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gWINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRpcxWindows Extensionsrpcxwinex.exe"Added by the RBOT.ACP WORM!"
XRsWinlsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
XRsWinlsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xrun windowsservic.bat"Added by the REBOOT-AP TROJAN!"
Xrun32dllWINClock.exe"Added by an unidentified VIRUS
?run=win.ini"??"
Xrun=mouse_configurator.win"Added by the GAGGLE.E WORM!"
XRund1l32Winfi1e32.exe"Added by the MERTIAN WORM!"
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
XRundll32Windows.exe"Added by the QQPASS.E TROJAN!"
Xruningwin.exe"Added by the DELF-LC TROJAN!"
XRunProgwini.exe"Added by the OPTIX.04.D TROJAN!"
XRunWin[path to file]"Added by the BANKER-ES TROJAN!"
Xrunwin32runwin32.exe"Added by the ESEARCH-A TROJAN!"
XRUNWIN32runwin32.exe"Added by the VB-AET TROJAN!"
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
Xrunwinlogonwinlogon.exe"Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process
XSafeSafeWin.exe"Added by the FOCOSENHA TROJAN!"
XScheduIrwinagent.exe"Added by a variant of the SDBOT WORM!"
XSchedulerwinagent.exe"Added by the TACTSLAY.B TROJAN!"
Xsecure socket layerwins32a.exe"Added by an IRCBOT TROJAN!"
XSecurityWindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
XSecurity PatchWinUpdate32.exe"Added by the SDBOT-BM WORM!"
XSecurity PatchesWinLab32.exe"Added by the SDBOT-KB WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
XService MonitorWinOcx.exe"Added by the RBOT-AQJ WORM!"
XService Monitorwinxpser.exe"Added by the RBOT-BDF WORM!"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
XService SystemwindowsXP.exe"Added by the BANCOS-EL TROJAN!"
XServiceOptionMP3winamp.dll.exe"Added by the SAMSON-A TROJAN!"
XServiceswinread.exe"Added by an unidentified VIRUS
XServiceswindns.exe"Added by a variant of the RBOT WORM!"
Xserviceswindows32.exe"Added by the FLYVB-C WORM!"
XServices Start2odcwinst.exe"Added by the PYSKE-D WORM!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
XServicewinHide32.exe"Added by the MSNVB-D WORM!"
XSevicewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
NSFPvzSFPWin.EXEVerizon Online Support Center - prompts for online updates
USfWinStartInfosfWinStartupInfo.exeSFIRM32 Online Banking software
Xshccdewinssled.exe"Added by the BUZUS.CQMU TROJAN!"
XSheduIerwinagent.exe"Added by the BDOOR-EB BACKDOOR!"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
XShellWin32.dll.exe"Added by the VB.BTX TROJAN!"
XShell Tray WindowShellTraywnd.exe"Added by the STULTDOR-A TROJAN!"
NShockwave InitSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
XShutDownWindows"Rundll32.exe UserExitWindows"
NSideWinderTrayV4SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
USiS Windows KeyHookkeyhook.exe"Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
Xsis32winsos.exe"Added by the QQPASS.IA WORM!"
XSistray32win.bat"Added by the JUMPRED.A WORM!"
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
NSM56 Helper Win32 Utilitysm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XsmsgerWin.exe"Added by a variant of the SDBOT WORM!"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
XsoftIce Update 32wininits.exe"Added by the RBOT-ANB WORM!"
XSound SystemWinSound1.exe"Added by an unidentified VIRUS
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
Xspoolsvswincfy.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSpyExWinllogo.exe"Added by the PRSKEY-A WORM!"
XSpywareGuardwinproc32.exe"Startpage adware Trojan"
XSpywareGuardPluswinmm64.exeStartPage.ht homepage hijacker
Xsqserviceswins32.exe"Added by the PROGENT-B TROJAN!"
Xsrvwinlogon.exe"Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
USrv32WinSpyAgent4.exe"SpyAgent - monitoring software that creates records of everything people do on a computer
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
USrv32Winsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
Usrv32winwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself remove it"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
Xssgrate.exewinerdir.exe"Added by the MITGLIEDER.O TROJAN!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xssgrate.exewintems.exe"Added by the MITGLIEDER.Q TROJAN!"
XSSK Servicewinssk32.exe"Added by the SOBIG.E WORM!"
Xssms.exewinn.exe"Added by the SDBOT-DHE WORM!"
XStartwindows.vbsHomepage hijacker
XStart Uppingwindupds.exe"Added by the SDBOT.AFH WORM!"
XStart Uppingwindupdts.exe"Added by a variant of the RBOT WORM!"
NStart Wingman Profilerlwtest.exe"Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer
NStart Wingman ProfilerLWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed
XstartkeyRunWinRaR.exeAdded by a variant of the BIFROSE-LV TROJAN!
Xstartkeywin32i.exe"Added by the BIFROSE-R TROJAN!"
XstartkeywinampXP.exe"Added by the BIFROSE-OY TROJAN!"
Xstartkeywinlogin.exe"Added by the BIFROSE-PM TROJAN!"
XStartupWinlogonStartupUnidentified malware
Xstartwinstartwin.exe"Added by the ANTIMAN.A WORM!"
Xstartwindowskeyuserrundle2.exe"Added by the JAVAKILLER TROJAN!"
Xstup1db0t_win.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
XSvcH0stWINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvchostwinhost.exe"Added by the LOLAWEB.A TROJAN!"
Xsvchostwinhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xsvchostwin.exe"Added by the VBSAUTO-A WORM!"
Xsvchostwindowsrx.exe"Added by the AGOBOT-MZ WORM!"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
XSvcphpwinsslphp32.exe"Added by the AGOBOT-ABR WORM!"
XsvcsharewinampXP.exe"Added by the FUJACKS-J VIRUS!"
Xsvcwinprocess32[path to worm]"Added by the UPERING WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
Xsvwin32unninst32.exe"Added by the AGOBOT-NF WORM!"
USWdwinwd.exe"PC Security™ from Tropical Software - ""is the ultimate in computer security
XswingsysSWINGSYS.EXE"Added by the BANCOS-CX TROJAN!"
XSygate Personal FirewallWin32x.exe"Added by the RBOT-KZ WORM!"
XSygate Personal Firewallwins.exe"Added by the RBOT.AOB WORM!"
XSygate Personal Firewallwinxpstat.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallwin31243.exe"Added by a variant of the IRCBOT TROJAN!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
XSymantec Antivirus professionalwindows .exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalWinhp32.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalwinudp.exe"Added by a variant of the WOOTBOT WORM! See here"
XSymantec Security Routine Addon for Microsoft Windowsnavpxaw32.exe"Added by the AGOBOT-GJ TROJAN!"
Xsyncmanwinsync.exe"Added by the MANCSYN-A TROJAN!"
XSyntaxwindows32.exe"Added by the SDBOT.CQ WORM!"
XSys29win***32.exe [* = random char]"EliteBar adware"
Usys32cmdsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Usys32sqlsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XSysAwin***32.exe [* = random char]"EliteBar adware"
Xsysavwinav.exe"WinPC Antivirus rogue security software - not recommended
XSyscheckwin.htaBrowser hijacker
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSysctrlswin32dll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsysdirwinrun.exe"Added by the WINBUR.B WORM!"
Xsysdllwindll.exe"Added by the AUTORUN.ECT WORM!"
XSysInitwininit32.exe"Added by the XABOT WORM!"
XSysStartsyswin.exe 1"Added by the AUTORUN-EY WORM!"
XSystam13speedwin.exe"Added by the RBOT.GVH BACKDOOR!"
XSystemserwin.exe"Added by the LDPINCH-BN TROJAN!"
XSystemWINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
XSystemwindowsps.exe"Added by a variant of the RBOT WORM!"
XSystemwinupd.exe"Added by a variant of the SDBOT WORM!"
XSYSTEMwindmupdr.exe"Added by a variant of the RBOT WORM!"
XSystemkernelwind32.exe"Added by the VXIDL.FT TROJAN!"
XSystemkernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
XsystemWinhelp.exe"Added by the IMAUT.CN WORM!"
XSystemwinipck.exe"Added by the RBOT-TK WORM!"
XSystem Checkwin_klr32.exe"Added by the DELF-DRA WORM!"
XSystem Document Applicationwins.exe"Added by the SDBOT.AUB WORM!"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Driverswingmt.exe"Added by the SDBOT-MG WORM!"
XSystem Information Managerwin.exe"Added by the SDBOT-MU WORM!"
XSystem Information ManagerwindowsNt.com"Added by the SDBOT-ND WORM!"
XSystem Managerwinsrv32.exeAdded by an unidentified WORM or TROJAN!
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XSystem Servicemsnwindows.exe"Added by the SPYBOT.YCL WORM!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystem32winds32.exe"Added by the DWNLDR-HFY TROJAN!"
Xsystem32lowinplay.exe"Added by the VB.FVJ TROJAN!"
XSystem32 Spoolwinint.exe"Added by the FORBOT-N WORM!"
XSystemAdministrationWincmp32.exe"Added by the ASYLUM TROJAN!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
XSystemMigrationWinMedia.exe"Added by the KELVIR.EI WORM!"
XSystemRegWINREG.EXE"Added by the DEWIN.A TROJAN!"
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
XSystemTraylsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
XSystemTrayWindowsupd.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemWideHook for Windows NT%WinHook32.exe"Added by the MYDOOM.AC WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
Xsysthreadwinkernal.exe"Added by the LIAMED WORM!"
Usystraywinlogin.exe"KidControl surveillance software. Uninstall this software unless you put it there yourself"
XSysWinSysWin.exe"Added by the IRCCONTACT TROJAN!"
Xsyswinv6.exe"Added by the AGENT-ECM TROJAN!"
Xsyswin.txt[3 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
Xsyswin32syswin32.exe"Added by a variant of the SPYBOT WORM!"
XSyswindowSyswindow.exe"Added by the COW TROJAN!"
Xsysygm64winrxd64.exe"Added by the IRCBOT-RK TROJAN!"
XT4skM4n4g3rWink3sk9.exe"Added by a variant of the IRCBOT TROJAN!"
XTarefas do Windowstaskexec.exe"Added by the AGENT-LSD TROJAN!"
XTask managerUPDATEWIN.exe"Added by the RBOT.BBS WORM!"
XTask Manager Win32taskmngr32.exe"Added by the RANCK-EX BACKDOOR!"
XTaskmon driverwinampa.exe"Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
XTEXTCONVwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XThEwind0s.exeAdded by an unidentified WORM or TROJAN!
Xthis freewinsyst.exe"Added by the MADAG.A WORM!"
XTorjan ProgramWINLOGON.EXE"Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UTouch ManagerWinLED.exeDell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
NTourwincool.exe"Annoying WinMe component that prompt you to play the %Windir%\Application Data\Microsoft\INTROCONTENT.HTA file - that plays a full screen version of the WinMe product preview and cannot be stopped until it finishes to my knowledge. That prompt will keep popping up after an install/reinstall of WinMe until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes - and don't bother deleting that entry as Windows puts it right back. Not only should you disable it from running
UTrack4WinMonitorSTMonitor.exe"Track4Win Monitor surveillance software. Uninstall this software unless you put it there yourself"
XTrayXwinppr32.exe"Added by the SOBIG.F WORM!"
XTsk Mng Hlpwins32.exe"Added by the AGOBOT-JB WORM!"
?Tweak ManagerWinManager.Exe"WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?"
XUndefinedwinter.exe"Added by the KILLAV.LW TROJAN!"
XUniversal Plug & Play devicesWinUPPD.exeAdded by an unidentified WORM/TROJAN!
XUpdade Windowswinlogom.exe"Added by the TONAX-A TROJAN!"
Xupdatewinis.exe"Added by the RBOT-VD WORM!"
XUPDATEWinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
XUpdateWinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
XUpdate Checkerwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XUpdate for Windows[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XUpdate Servicewinu32.exe"Added by the RBOT-MG WORM!"
Xupdate servicewinx.exe"Added by a variant of the RBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdateCheckwinstall.exe"Added by the SPYBOT-CY WORM!"
Xupdater32winload32.exe"Added by the CULT.M WORM!"
Xupdatewinupdate.exe"Added by a variant of the SDBOT WORM!"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XupdateWinssystrey.exe"Added by the RANDON WORM!"
Xupdatexwinwinxrpc.exe"Added by the AGOBOT-KJ WORM!"
Xupddateitwinit.exe"Added by the RBOT-MS WORM!"
XUpgrade Servicewinupd.exe"Added by the TOFGER-U TROJAN!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUpTimes serviceWinUp.exe"Added by the RBOT-AKB WORM!"
Xurudjeffniwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XUSB 2.1 Driverwinupdate1.exe"Added by a variant of the RBOT WORM!"
XUSB Devicewin32usb.exe"Added by the FORBOT-BQ WORM!"
XUSBHWINFOmac.exe"Added by the LOWZONE-I TROJAN!"
XUSBHWINFO[path to trojan]"Added by the LOWZONE-I TROJAN!"
XUSBHWINFOsst6.exe"Added by the LOWZONE-I TROJAN!"
Xuserinitwinlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xvbewin.vbe"Added by the LOSESLP-A WORM!"
Xvbwq cutewinnt.exe"Added by the MADAG.A WORM!"
XVideowinamp32.exe"Added by the AGOBOT-NG WORM!"
XVideo Poeswinii.exe"Added by the AGOBOT-CP WORM!"
XVideo Proceswinaps.exe"Added by the AGOBOT.HD WORM!"
XVideo Processwinasp.exe"Added by the AGOBOT-IS WORM!"
XVideo Processwincert32.exe"Added by the AGOBOT.JT WORM!"
XVideo Processwincrt32.exe"Added by the AGOBOT-GR WORM!"
XVideo Proeswinaii.exe"Added by the AGOBOT-FH WORM!"
XVIEW POINT DRIVERS FOR WIN32phqghu.exe"Added by a variant of the RBOT WORM!"
Xvirtualwinit.exe"Added by the MUGLY.A or MUGLY.B WORMS!"
Xvirtualwinprotect.exe"Added by the MUGLY.C WORM!"
Xvirtualwini.exe"Added by the RBOT-YX WORM!"
Xvirtual-iewinlogi.exe"Added by the RBOT-BJU WORM!"
Xvirtual-machinewinlogin.exe"Added by the RBOT-VU WORM!"
Xvirtual-machinewini.exe"Added by the RBOT-WR WORM!"
XVsamplewinxpsock.exe"Added by the SDBOT.BLK WORM!"
YVshwin32EXEVSHWIN32.EXEFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
XW1N32.DLLWINLOGON .exe"Added by the DROPPERFL.A TROJAN!"
XWCPCwintsvcc.exe"PurityScan adware"
XWCPIwintsvit.exe"PurityScan adware"
XWCPSWint**.exe [* = random char]"PurityScan adware"
XWCPTwintsvtr.exe"PurityScan adware"
XWEB DRIVERS FOR WIN32phqgh.exe"Added by a variant of the RBOT WORM!"
XWelcomewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
Xwinregedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
Xwinxwinxrpc32.exe"Added by the AGOBOT-MV WORM!"
Xwinxwinxrpc.exe"Added by the AGOBOT-MV WORM!"
XWINehshell.exe"Added by the MYTOB-CQ WORM!"
XWINwindows.exe"Added by the REATLE.C WORM!"
Uwinhomesec.exe"Related to the Sentry Parental Controls software"
XWin Antispyware Centerav.exe"Win Antispyware Center rogue security software - not recommended
XWin Antivir 2008Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended
XWin Antivirus 2008Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended
UWin Chimeswinchi~1.exe"WinChimes - enhancement software for the system clock that runs in the system tray"
XWin CommWinComm.exe"Added by the WINCOM TROJAN!"
XWin Commandcommand32.exe"Added by the AGOBOT.XQ WORM!"
XWin Configwinconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin CPUsysin.pif"Added by the RBOT-AXL WORM!"
Xwin ctl appwuctl.exe"Added by a variant of the SDBOT WORM!"
XWin Defragwindfrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defrag!windefrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defragsdefrag.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin Drivers SSLhpws.exe"Added by the IRCBOT.67098 WORM!"
XWin Drivers SSLTASKMAN4.exe"Added by a variant of the RBOT WORM!"
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin exe file managrcrss.exe"Added by the RBOT.CCI WORM!"
XWin FTPwintftp.exe"Added by the SDBOT-KE WORM!"
XWIN HOST PROCESSWIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
XWin I5oahder[worm filename]"Added by the AGOBOT-DS WORM!"
XWin INI 32msrp32.exe"Added by the RBOT-FZC WORM!"
XWin l5oahderwinampa.exe"Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
XWin Loginwinlogin.exe"Added by the RBOT-AWE WORM!"
XWin Microsoft 98win14.exe"Added by the RBOT-AKX WORM!"
?win namestat.exe"??"
XWin Net Wks32netwks32.exe"Added by the RBOT.AA WORM!"
XWin Patchntldr.exe"Added by the SDBOT-GS WORM!"
XWin Process Updateswinupdates.exe"Added by a variant of the SDBOT WORM!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Proxy32 Protocolbsvtem.exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin Securitymsw32.pif"Added by the RBOT-AQT WORM!"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWin Security 360WinSecurity360.exe"Win Security 360 rogue security software - not recommended
XWin Serverwinserv.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwupdt.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwinserver.exe"Added by a variant of the IMISERV TROJAN!"
XWin Server Updtpxckdla.exe"IEPlugin adware"
XWin SSLSP2s.exe"Added by the RBOT.BBI WORM!"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin StartupWINCFG32.EXE"Added by the SPYBOT-CL WORM!"
XWin Sync montrwinsyncupx.exe"Added by the RBOT.BYJ BACKDOOR!"
XWin TaskLoadermsgmr.exe"Added by the MYTOB.L WORM!"
Xwin updatewupda32.exe"Added by the SDBOT.J WORM!"
Xwin updatewapdate.exe"Added by a variant of the RBOT WORM!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
XWin Updatemsnmger.exe"Added by the RBOT-GDP WORM!"
Xwin updatewupdate.exe"Added by the RBOT-P BACKDOOR!"
XWin UpdaterWINUPDATER.EXE"Added by the RBOT.IP WORM!"
XWin Updator Servicesctfnom.exe"Added by a variant of the WOOTBOT WORM!"
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWIN USB 2.0winusb.exe"Added by a variant of the RBOT WORM!"
XWin USB 2.0 USB DriverHPPrint.exe"Added by the SPYBOT.DNB WORM!"
XWIN USB SUPPORTgrxsrv.exe"Added by a variant of the RBOT WORM!"
XWin Validation ApplicationDBExecCom.exe"Added by the VBSILLY-A WORM!"
XWin WinAmpwinamp.exe"Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%. This file is located in %System%"
Xwin************* [* = random digit]win*************.exe [* = random digit]"WINBO adware"
XWIN-BUGSFIXWIN-BUGSFIX.EXE"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
Xwin-xpnvsc32.exe"Added by the BROPIA.N WORM!"
Xwin-xpwinis.exe"Added by the BROPIA.N WORM!"
Xwin.exewin.exe"Added by the PODROP-C TROJAN!"
Uwin16.dllwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself
Xwin23.exewin23.exe"Added by the BIFROSE.BSJ BACKDOOR!"
XWin2Drv[worm filename]"Added by the WINTOO WORM!"
XWIN32WIN32.EXE"Added by the RATEGA TROJAN!"
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
Xwin32Setup_32.exe"Added by the EVILBOT.B TROJAN!"
XWin32Win32.exe"Added by the ISRAZ.A WORM!"
Xwin32winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
XWin32system32.vbs"Added by the SWERUN VIRUS!"
XWin32Game.exe.vbs"Added by the SCAFENE WORM!"
XWin32arsetup.exeAdded by the SPAZBOX.A TROJAN!
Xwin32winhost.exe"Added by the BROPIA.J WORM!"
XWin32winnnit.exe"Added by a variant of the SDBOT WORM!"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
XWin32sysmon.exe"Added by the MYTOB-HQ TROJAN!"
XWin32zaq.exe"Added by the RBOT-GCE WORM!"
XWin32 BiosWinbios.exe"Added by the SEMAPI-A WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWin32 Critical FileWin32.exe"Added by the RBOT-GUB WORM!"
XWIN32 DDOSSERdos.exe"Added by the KELVIR.F WORM!"
XWin32 Debug ManagerWin32Debug.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 Debug Managermicrosoftupd.exe"Added by the RBOT-GRJ WORM!"
XWin32 Device LoaderWin32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Driversysmls.exe"Added by the MYTOB.JH WORM!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 DRK Driverwdrk32.exe"Added by the WOOTBOT.CY WORM!"
XWin32 exe filewinstr32.exe"Added by a variant of the SPYBOT WORM!"
XWin32 ExplorerExplorer32.exe"StartPa-MN homepage hijacker"
XWin32 Firewall Driverwinfw.exe"Added by a variant of the RBOT WORM!"
XWin32 Firewall Driverswinfirewall.exe"Added by the WOOTBOT.GX WORM!"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWin32 Help32 Servicewin32help.exe"Added by the DELBOT-U WORM!"
XWin32 Infowindowsnfo.exe"Added by a variant of the IRCBOT TROJAN!"
XWin32 Information Servicecrsrs.exe"Added by the RINBOT.Y WORM!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 Kernel core componentKernel32.pif"Added by the MOKS VIRUS!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWin32 Ms Auto UpdaterAutomsUPD.exe"Added by a variant of the RBOT WORM!"
XWin32 NDISNdiswin.exe"Added by the RBOT.AMG WORM!"
XWin32 NDIS Driverxpndis.exe"Added by a variant of the RBOT WORM!"
XWin32 NDIS DriverNdistcp.exe"Added by the WOOTBOT.EU WORM!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 NT Adv Servicestaskmngr.exe"Added by the RBOT-ADE WORM!"
XWin32 nvcnvcva.exe"Added by the RBOT-ABF WORM!"
XWin32 NVIDIA DriverMSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
Xwin32 regeditmsn32.exeAdded by an unidentified WORM or TROJAN!
XWin32 Rundll LoaderRundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Security Protocolsecure32.exe"Added by the RBOT-ETI WORM!"
XWin32 Security Servicecrsss.exe"Added by the DELBOT-O WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32 Servicebazzi.exe"Added by the AHKER.E WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32 Servicesodbc32.exe"Added by the SPYBOT-EK WORM!"
XWin32 Serviceswuamngr.exe"Added by the SDBOT-N WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 Src Servicewin32src.exe"Added by the RBOT-SX WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
XWin32 Testbleatest.exe"Added by a variant of the RBOT WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWin32 Updatedl32.exeAdded by an unidentified WORM or TROJAN!
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32 USB Drivermvsecn.exe"Added by the FORBOT-BK WORM!"
XWin32 Usb Driversvhosint32.exe"Added by the FORBOT-BE or FORBOT-J WORMS!"
XWin32 Usb Driverusb32.exe"Added by the SDBOT-OV WORM!"
XWin32 Usb DriverAvpG.exe"Added by the FORBOT-BX WORM!"
XWin32 USB Driverrundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWin32 USB2wins32.exe"Added by a variant of the RBOT WORM!"
XWin32 USB2 Driverwin32usb.exe"Added by the SPYBOT.DHV WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32 USB2 Driversys32.exe"Added by the WOOTBOT.X WORM!"
XWin32 USB2 Driversys32snd.exe"Added by the FORBOT-AN WORM!"
XWin32 USB2 Driverwind32.exe"Added by the FORBOT-AH WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2 Driverupdatemgr.exe"Added by a variant of the FORBOT WORM!"
XWin32 USB2 Driverwinsnd32.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Drivermsn.exe"Added by the FORBOT-EX WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWin32 USB2 Driveralgg.exe"Added by the TIBS.BF WORM!"
XWin32 USB2 Driverusb2.exe"Added by the FORBOT-Y WORM!"
XWin32 USB2 Driverwinusb32.exe"Added by the FORBOT-M WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
XWin32 USB3 Driverwin32tool.exe"Added by a variant of the RBOT WORM!"
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
Xwin32.exewin32.exe"Added by the STARTPAGE TROJAN!"
XWin32.exeWin32.exe"Added by the AWQ.A TROJAN!"
XWin32.Exploit.mzHmzrun.exe"Added by the PAINTER TROJAN!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
Xwin3208022-1336687win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
XWin32BaseServiceMODWintask.exe"Added by the NAVIDAD WORM!"
Xwin32betawin32sys4.exe"Added by the BANKER-DA TROJAN!"
Xwin32clfwin32clf.exe"Added by an unidentified VIRUS
Xwin32debugwin32debug.exe"Added by the GUDEB WORM!"
XWin32DLLWin32DLL.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XWin32dllWin32dll.exe"Added by the BANPAES TROJAN!"
XWIN32DSclienttimer.exe"Eziin adware"
XWin32GKernel32.com"Added by the ESTRELLA TROJAN!"
XWin32GScandisk.com"Added by the ESTRELLA TROJAN!"
Xwin32gbwin32gb.exe"Added by the DLUCA-F TROJAN!"
XWin32Host Processwebemir.exe"Added by the TURGEN -A TROJAN!"
Xwin32infowin32info.exeAdult content dialler
Xwin32inisystroy.exe"Added by the IRC.ALADINZ.C TROJAN!"
XWIN32ioclienttimer.exe"Eziin adware"
Xwin32Kernelfindx.exe"Added by the BANLOA-EY TROJAN!"
XWin32KernelStartmicrosoft.exe"Added by the DELF-EWZ TROJAN!"
XWin32RServer.com"Added by the ESTRELLA TROJAN!"
XWIn32S Java DLLkavsvx.exe"Added by the AGOBOT-RZ WORM!"
Xwin32servdevicer.exe"Added by the CHECKOUT WORM!"
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servsystemdevices.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servvload.exe"iSearch adware"
Xwin32servvms1.exe"iSearch adware"
YWIN32SLWin32sl.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
XWIN32SNDSbanc.exeAdded by an unidentified WORM or TROJAN!
XWin32system[random filename]"Added by the DDV.B WORM!"
XWin32Systemwin32s.exe"Added by the MYDOOM.V WORM!"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWin32SysVxin.exe"Added by the FORBOT-EO WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
XWin32UpdaterKERNAL32.EXE"Added by the SPYBOT-OK WORM!"
Xwin32uswin32us.exeAll-In-One-Telcom (adult content dialler) variant
Xwin32usbdssrs.exe"Added by the RBOT-RA WORM!"
XWin32UsrWinCab.exe"Added by the DEDMIR-A WORM!"
XWIN32WNsystem_wc.exe"Eziin adware"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWin386Win386.exe"Added by the GOSUSUB VIRUS!"
XWin386sp32.dllHomepage hijacker. Not a dll but a regfile in disguise
XWIN3S2SNDSwinabsmod.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
XWIN3S2SNDSwiniprtx.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
XWin64 Compatibility Checkload win64.drv"CoolWebSearch parasite variant"
XWIN95DEFVIEW[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
Xwin98 DNSwingrd.exe"Added by a variant of the RBOT WORM!"
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
XWinAblewinable.exe"Added by the MATCASH.BG TROJAN!"
XWinAC v4klsuicbn.exe"Added by the FORBOT-CS WORM!"
UWinacsrWinacsr.exe"AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XwinactiveWINACTIVE.EXE"WinActive variant of the LOP.com hijacker"
XWinActiveJWinActiveJ.exeAdded by the ROTARRAN VIRUS!
XWinad ClientWinad.exeWinAd adware by eXact Advertising
XWinAdCnt.exeWinAdCnt.exe"Added by the BANKER-BU TROJAN!"
Xwinadmwinadm.exe"Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!"
?WinAgentWinAgent.exe"Standard Life Insurance program. Is it required at startup?"
XWinahlp.exeWinahlp.exe"Added by a variant of the VAGRNOCKER TROJAN!"
Xwinallapwinallap.exe"Added by the DELF.E TROJAN!"
Xwinallapuwinallapu.exe"Added by the DELF.E TROJAN!"
XWinammpmccm.exe"Added by the IRCBOT-HH BACKDOOR!"
XWinampwinamp.htaHijacker - re-directing to adult content sites. Note - this isn't the real Winamp
XWinampwinamp.exe"Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player"
XWinAMPwinamp62.exe"Added by the SDBOT-WN WORM!"
NWinampwinamp.exe"Winamp media player. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinamp Agentwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is ""winampa.exe"" - see here"
XWinamp Agentcvscc.exe"Added by the AGOBOT-GK WORM!"
XWinamp Mediaqmedia.exe"Added by the DIAZMON-A TROJAN!"
XWinamp media playerwinapa.exe"Added by an unidentified VIRUS
XWinamp Media Playerwinamap.exe"Added by the SDBOT.ACJM BACKDOOR!"
XWinamp Media Playerwinamp.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%"
XWinAmp Playerwinampp.exe"Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename"
XWinamp Player 6Winamp6.exe"Added by a variant of the SPYBOT WORM!"
UWinamp to Google Talkwinamptogoogletalk.exe"Winamp to Google Talk
XWinamp Updateyhn.exe"Added by the SDBOT-ACR WORM!"
UWinampaWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinampawinampa.exe"Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
XWinampa AgentWINAMPA.EXE"Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which is normally located in %ProgramFiles%\Winamp. This one is found in %System%"
UWinampAgentWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinAmpAgentMsexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentShch.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentsvchst.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentWinagent.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XWinAmpAgentsdhch.exe"Added by the TACTSLAY.B TROJAN!"
XWinAnonymousGDC.exe"WinAnonymous rogue privacy tool - not recommended
XWinAntiSpyware 2005was5.exe"WinAntiSpyware 2005 rogue spyware remover - not recommended
XWinAntiSpyware 2006was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Freewas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Scannerwas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2007was7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntiSpyware 2007 Freewas7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntispyware2008WinAntispyware2008.exe"WinAntiSpyware 2008 rogue spyware remover - not recommended
XWinAntivirusAVSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XWinAntiVirus Pro 2007WinAv.exe"WinAntiVirus Pro 2007 rogue security software - not recommended
XWinAntiVirusPro2006WinAV.exe"WinAntiVirus Pro 2006 rogue security software - not recommended
XWinApiwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XWINAPLOGUPDWINAPLOGUPD.EXE"Added by the CAPSIDE-C WORM!"
XWinappwinpup32.exeProduces popup ads to adult content sites
XWinApp32msapp.exe"Added by the RSBOT TROJAN!"
UWinAppLogsvchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinAuthwinlogon.exe"Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinAvXWinAvX.exe"Added by the VIRANTIX TROJAN!"
XWinAvXWinAvXX.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the SPYWAD-AR TROJAN!"
XWinAwkWinAwk.exe"Added by the SDBOT-AYF WORM!"
UWinBackup SchedulerWbsched.exe"LIUtilities WinBackup scheduler - backup software"
UWinBarWinBar.exe""WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls""
Xwinbar.pifpacke.pif"Added by the RBOT-AVI WORM!"
XWinbedwinbed.exeHijacker
XWinbinswchost.exe"Added by the RBOT.CLS WORM!"
Xwinbin32win32exe.exe"Added by the RBOT-ZL WORM!"
XWinBlueSoftWinBlueSoft.exe"WinBlueSoft rogue spyware remover - not recommended
Xwinbo32winbo32.exe"Added by the RBOT-GRU WORM!"
Xwinbootwinboot.exe"Added by the BANLOAD-W TROJAN!"
Xwinbotwinbot.exe"Added by the MIDRUG-A TROJAN!"
UWinBrushwinbrush.exe"WinBrush - ""handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories
XWinButlerWinButler.exeIdentified as a variant of the Trojan-Dropper.Agent.DKN malware
Xwincfgsyscnfg.exe"Added by an unidentified VIRUS
XWinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
XWinCheckWinCheck.exe"Added by the PWS-CY TROJAN!"
XWinCheckservices.exe"Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
XWinCheckcheck.exe"Added by the DELBOT-Y WORM!"
Uwinchkwinchk.exe"RemoteSpy surveillance software. Uninstall this software unless you put it there yourself"
Xwinchostwinchost.exe"Added by the DLOADER-PO TROJAN!"
NWINCINEMAMGRWINCIN~1.EXE"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NWinCinemaMgrWinCinemaMgr.exe"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
UWINCINEMAMGRWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
Xwincleanwinclean.exe"Added by the AGENT.GXR TROJAN!"
Xwincls"rundll32.exe wincls.dllstart"
Xwincmapwincmapp.exe"CasClient adware variant - also detected as the CMAPP TROJAN!"
UWinColorReminderWinColorReminder.exe"The Microsoft Color Control Panel Applet for Windows XP ""helps you manage Windows color settings in one place."" Part of the Pro Imaging Powertoys"
Xwincomvbrun6win.exe"Added by the AGOBOT-AFK WORM!"
XWinConfig9324wincfgkop9.exe"Added by the RBOT.BVD WORM!"
Xwinconnvbrun6nt.exe"Added by the AGOBOT-AEI BACKDOOR!"
XWinCore32.exeWinCore32.exe"Added by the CLICKER-EN TROJAN!"
Xwincrt.exe[path to worm]"Added by the STRATIO-HA WORM!"
XWinCRT32wincrt32.exe"Added by the DOGBOT-D WORM!"
XWinCSRSSMSGRT32.EXE"Added by the REWINDO-A TROJAN!"
Xwinctlwinctl.exe"Added by the IRCBOT-YI TROJAN!"
XWINCXwincore332.exe"Added by the AGOBOT-MG WORM!"
XWind Logd Fileservicelogd.exe"Added by a variant of the RBOT WORM!"
XWind OptimizerWindOptimizer.exe"Wind Optimizer rogue system optimization tool - not recommended
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
XWind Securitymswi32.pif"Added by the RBOT-ARH WORM!"
Xwind.exewind.exe"Added by the MITGLIEDER.BD TROJAN!"
XWIND0WSWIND0WS.exe"Added by the SPYBOT.DQ WORM!"
XWIND0WSmella.bat"Added by the ALLEM WORM!"
XWind0wswordpad.exe"Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
XWind0ws Ser7ice Agentcolwindos.exe"Added by the RBOT-GQO TROJAN!"
XWind0ws Sharingssprotecter.exe"Added by the RBOT-AHW WORM!"
XWind32Wind32.exeIdentified as a variant of the Backdoor.Win32.Poison.avs malware
XWinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field"
NWinDateswindates.exe"WinDates is a calendar
Xwindbswinxtc.exe"Added by the AGOBOT-WD WORM!"
XWindewinde.exe"Added by the DLUCA TROJAN!"
XwindefWin32sp.vbs"Added by the ANPES WORM!"
Xwindefwindef.exe"Added by the WURMARK-O WORM!"
Xwindefenderwindefender.exe"Added by the AGENT.BYH TROJAN!"
XWinDefender 2008WDefDemo.exe"WinDefender 2008 rogue privacy program - not recommended
XWinDefender2009windef.exe"WinDefender 2009 rogue security software - not recommended
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
XWinDevilsWinDevils.exe"Added by the BRONTOK-BS WORM!"
Xwindhost.exeosrwin32.exe"Added by the BANKER-CB TROJAN!"
Xwindhost.exewindhost.exe"Added by the BANKER-BV TROJAN!"
Xwindhost.exewinos.exe"Added by the PWSAGENT-A WORM!"
Xwindirwinrun.exe"Added by the WINBUR.B WORM!"
XWindir Workingwuaumqr1.exe"Added by a variant of the IRCBOT TROJAN!"
XWinDirectoriestdirs.exe"Added by the VB-EPB VIRUS!"
XWindllWindll.exe"Added by the TRYNOMA TROJAN!"
UWINDLLWSYS.EXE"STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes
Xwindllwindll32.exe"Added by the ASTEF or RESPAN WORMS!"
Xwindllwindotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
XWinDLL (algs.exe)"rundll32.exe algs.exestart"
XWinDLL (aqls32.exe)aqls32.exe"Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""aqls32.exe"" file is found in %System%"
XWinDLL (asdfsa.exe)"rundll32.exe asdfsa.exestart"
XWinDLL (bee.dll)"rundll32.exe bee.dllstart"
XWinDLL (bix.exe)"rundll32.exe bix.exestart"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (ctfmonm.exe)"rundll32.exe ctfmonm.exestart"
XWinDLL (dasda.com)"rundll32.exe dasda.comstart"
XWinDLL (diem.exe)"rundll32.exe diem.exestart"
XWinDLL (dlfksdld.exe)"rundll32.exe dlfksdld.exestart"
XWinDLL (jbi32.dll)"rundll32.exe jbi32.dllstart"
XWinDLL (lcass.exe)"rundll32.exe lcass.exestart"
XWinDLL (mysnlive.exe)"rundll32.exe mysnlive.exestart"
XWinDLL (ProsFix.exe)ProsFix.exe"Added by a variant of the IRCBOT BACKDOOR! The ""ProsFix.exe"" file is found in %System%"
XWinDLL (qwex.dll)"rundll32.exe qwex.dllstart"
XWinDLL (redyLive.exe)"rundll32.exe redyLive.exestart"
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWinDLL (service.exe)service.exe"Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
XWinDLL (slmss.exe)"rundll32.exe slmss.exestart"
XWinDLL (slsass.exe)"rundll32.exe slsass.exestart"
XWinDLL (smaprnter.exe)"rundll32.exe smaprnter.exestart"
XWinDLL (smms.exe)"rundll32.exe smms.exestart"
XWinDll (sslms.exe)"rundll32.exe sslms.exestart"
XWinDLL (start0s.exe)"rundll32.exe start0s.exestart"
XWinDLL (steam.dll)"rundll32.exe steam.dllstart"
XWinDLL (svc.exe)"rundll32.exe svc.exestart"
XWinDLL (svchost.dll)"rundll32.exe svchost.dllstart"
XWinDLL (sysx32.dll)"rundll32.exe sysx32.dllstart"
XWinDLL (tepmlayer.exe)"rundll32.exe tepmlayer.exestart"
XWinDLL (tmp.exe)"rundll32.exe tmp.exestart"
XWinDLL (tock24.dll)"rundll32.exe tock24.dllstart"
XWinDLL (tqurity.exe)"rundll32.exe tqurity.exestart"
XWinDLL (v4mon.dll)"rundll32.exe v4mon.dllstart"
XWinDLL (vdm32.dll)"rundll32.exe vdm32.dllstart"
XWinDLL (vxd32.dll)"rundll32.exe vxd32.dllstart"
XWinDLL (wchshield.exe)"rundll32.exe wchshield.exestart"
XWinDLL (wimimi.exe)"rundll32.exe wimimi.exestart"
XWinDLL (windns32.dll)"rundll32.exe windns32.dllstart"
XWinDLL (wingatey32.exe)"rundll32.exe wingatey32.exestart"
XWinDLL (wintmp.exe)"rundll32.exe wintmp.exestart"
XWinDLL (Wseclayer.exe)"rundll32.exe Wseclayer.exestart"
XWinDLL (wsync32.dll)"rundll32.exe wsync32.dllstart"
XWinDLL (xvd32.dll)"rundll32.exe xvd32.dllstart"
XWindll.exeWindll.exe"Added by the STEALER TROJAN!"
XWindll32Windll32.exe"Added by the MSNPWS TROJAN!"
XWinDll32_WIN32.EXE"Added by the LEGMIR.AQ TROJAN!"
Xwindllsys32.exewindllsys32.exe"Added by a variant of the MITGLIE-A TROJAN!"
XWinDNSwindns32.exe"Added by the GAOBOT.WX WORM!"
XWindo Servic Agenalirexe.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindo Servic Agent 32xagw.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindoes Kernelkernel32.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
XWindoFixWindoFix.exe"WindoFix rogue system error utility"
XWindos Seres Agnts[worm filename].exe"Added by the RBOT-GUN WORM!"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
XWindow LoaderDos32.exe"Added by the GAOBOT.AO WORM!"
XWindow Monitorwinmon32.exe"Added by the SDBOT.RT WORM!"
XWindow Msn Live Messangermsnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindow UDP Control Servicwinlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindow upadatepe2.exe"Added by a variant of the RBOT WORM!"
UWindow WasherwwDisp.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
Xwindow.exewindow.exe"Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!"
Xwindow2ssvchost.exe"Added by the IRCBOT.H TROJAN!"
Xwindow2ieupdate.exe"Added by the FORBOT-BM WORM!"
UWindowBlindswbload.exe"WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
XWindowEnhancerWinex.exe"SCBar foistware variant"
XWindowfdgfds DasdLL Verifierwinupdatr.exe"Added by the AGOBOT.HZ WORM!"
XWindowfdgfds DasdLL Verifiew[path to worm]"Added by the RBOT-GGX WORM!"
XWindowfdgfds DLL fgfdg VerifierWindowsdldfglcheckkk.exe"Added by the RBOT.CSP WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
UWindowFXwfxload.exe"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
Xwindownwiusyt.exe"Added by the QQPASS-M TROJAN!"
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field"
XWindowsKernel32.exe"Added by the TENDOOLF.A WORM!"
XWindowsmsdos98.exeAdded by the PWSTEAL TROJAN!
XWindowsWindows.exe"Added by the KAZMOR.A
XWindowsexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwindows[path to trojan]"Added by the AIMWIN TROJAN!"
Xwindowshkey.exe"Added by the GAOBOT.AFW WORM!"
Xwindowssystem copy.exe"Added by the SALGA.A WORM!"
XWindowsgearsec.exe"Added by the STUBBOT-B WORM!"
XWindowsrun.exe"Added by the SPYBOT.OFN WORM!"
XWindowssystem.exe"Added by the SPYBOT.OBB WORM!"
XWINDOWSwindows.exe"Added by the MONBOT-A TROJAN!"
XWindowsservices.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity"
XWINDOWSjif.exe"Added by the MYTOB.MK WORM!"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindowsservices.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Windows"" subfolder"
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwindowssvchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWINDOWSymssgr.exe"Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft\Internet Connection Firewall (ICF)"
XWindowstaskmngr.exe"Added by a variant of the SDBOT WORM!"
XWindowsCfreer.exe"Added by the CULLER-C WORM!"
XWindowsZser.exe"Added by the CULLER-D WORM!"
XWindowsspoovlss.exe"Added by an unidentified WORM or TROJAN! See here"
XwindowsVBSyS.vbs"Added by the ROCK-D WORM!"
UWindowsWpcUmi.exe"Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
UWindows & Internet Cleaner ProWICleaner.exe"Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows (random character)diskcheck.exe"Added by the SINGU.B TROJAN!"
XWindows .Net Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows 128 Modulewin128.exe"Added by the FORBOT-ES WORM!"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows 32 EditorWin32edit.exe"Added by the WOOTBOT.GQ WORM!"
XWindows 32 Rescuewin32resc.exe"Added by the FORBOT-EU WORM!"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
XWindows 32-bit DLL Integrity Verifierdllrun.exe"Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location"
UWindows Acceleratorssetup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XWindows Account Alternationwauclt.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows Actioncsrs.exe"Added by the SECCMU-A WORM!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows AdControlWinAdCtl.exeWindupdates adware variant
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows AdServiceWinAdServ.exeWindupdates adware variant
XWindows AdStatusWinStat.exe"Added by the BLESHARE!DR VIRUS!"
XWindows AdToolsWinAdTools.exeWindupdates adware variant
XWindows Anti VerifierWindows-Anti.exe"Added by the RBOT.ETT WORM!"
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti-Virus Built 32AntiVirus32.exe"Added by the SDBOT-BG WORM!"
XWindows APCI Verifierdhcpserv.exe"Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Application Layerwalg32.exe"Added by the AGOBOT.ATN WORM!"
XWindows Application Layer Gatewaywalg32.exe"Added by the AGOBOT-AAZ WORM!"
XWindows applications serverSysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
XWindows ARP Detectioncnvudlsp.exe"Added by the AGENT.LMW BACKDOOR!"
XWindows ARP Detectioncwinlogon.exe"Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ARP Detectioncxwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ASN Servicerge.exe"Added by the RBOT-AOK WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows ASN4 Servicesgamo.exe"Added by the RBOT-EHK WORM!"
XWindows Audiosnd.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Audio Layernarsvc.exe"Added by the IRCBOT.AFT BACKDOOR!"
XWindows Audio Panelnppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Servicesndmic32.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Servicesjvm.exe"Added by the ACKANTTA.F WORM!"
XWindows Audio Startupnndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
XWindows Audio Systemnndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xwindows auto updatemsblast.exe"Added by the BLASTER.B WORM!"
Xwindows auto updatepenis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
XWindows Auto Updatewinupdater.exe"Added by the SDBOT.TF WORM!"
XWindows auto updatebazzi.exe"Added by the AHKER.E WORM!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Automatic Updatewuamgrder.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updaterwindrg.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Automatical Updaterdcz.exe"Added by the RBOT.CXS WORM!"
XWindows AutomaticUpdaterrunddls.exe"Added by a variant of the RBOT WORM!"
Xwindows automationmslaugh.exe"Added by the BLASTER.E WORM!"
XWindows Automationmsdspr.exe"Added by the SOLAME.A WORM!"
XWindows Autostart Loadernotepad32.exe"Added by a variant of the RBOT WORM!"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Baþlangýç Dosyasýsistem.exe"Added by the MUZK WORM!"
XWindows Bootwinboot.exe"Added by the AGENT.HBD TROJAN!"
XWindows Bootwindowsboot.exe"Added by the IRCBOT.AZT BACKDOOR!"
XWindows Booterwinboot.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Booter!winbooter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Bootupms-wks32.exe"Added by the RBOT-AFM WORM!"
XWindows BootupSystemwks32.exe"Added by a variant of the RBOT WORM!"
XWindows Bootuptask-mngr.exe"Added by the RBOT-AWP WORM!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser ServicesBrowsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
XWindows Browser Servicesbrowsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows cfgascv.exe"Added by the AGOBOT-SZ BACKDOOR!"
XWindows Clean-Up ProWINDOWS CLEAN-UP PRO.Exe"Windows Clean-Up Pro spyware remover - not recommended
XWindows Cleaner Servicewinclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Clientclient.exe"Added by the BACKDR-AM BACKDOOR!"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Commandwincmd.exe"Added by the RBOT.ANV WORM!"
XWindows Communicatorwincomm.exe"Added by the AGOBOT-BH WORM!"
XWindows Communicator for NT/XPosndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows Computer Browserbcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Confwindowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ConfigSSYS.EXE"Added by the SPYBOT-DA WORM!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows ConfigZANBOR.EXE"Added by the SPYBOT-MH WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Config Managerwinconf.exe"Added by the RBOT-AIT WORM!"
XWindows Config ManagerWincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Configuratorwinconf.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ControlControl.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
XWindows ControlAdWinCtlAd.exeWindupdates adware variant
XWindows Controls Centerwinudmr.exe"Added by the LAMER.AA BACKDOOR!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows CPU hostwinbog32.exe"Added by a variant of the RBOT WORM!"
XWindows Critical Alertwincrt.exe"Added by the ALEDO-A TROJAN!"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows Data Serverautodisc.exe"Added by the SPYBOT-CB WORM!"
XWindows Data Server[random name].exe"Added by the SPYBOT-DS WORM!"
XWindows DatabaseWinDat.exeAdded by an unidentified WORM or TROJAN!
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows DDE Loaderwindde32.exe"Added by the SDBOT-UZ WORM!"
XWindows debug loggingwinlogg.exe"Added by the RBOT-OY WORM!"
XWindows debug loggingwinloggs.exe"Added by the RBOT-QN WORM!"
XWindows Debuggerwindbg.exe"Added by the FORBOT-BY WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggerwindbg32.exe"Added by the ZOTOB.L WORM!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Default Serverwfdmgrsp.exe"Added by the IRCBOT.BCX BACKDOOR!"
XWindows Default Serverwinampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows Defenderwdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Addswda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Monitorwdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWINDOWS DENEMEdeneme.exe"Added by the MYTOB-CR WORM!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Desktop Daemonwinpadg.exe"Added by a variant of the SPYBOT WORM!"
NWindows Desktop SearchWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
XWindows Dialup Servicedialup.exe"Added by the AGOBOT.AAH WORM!"
XWindows Disk Defragmenterwpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
XWindows Disk Managercmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Display Couplerdisplay.exe"Added by the IRCBOT-YS TROJAN!"
XWindows DLL hostwinupd32.exe"Added by a variant of the SPYBOT WORM!"
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderdefragfat32z.exe"Added by the LINKBOT.A WORM!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows DLL Loaderdefragfat32pi.exe"Added by the RBOT-QQ WORM!"
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows DLL Loaderdefragfatz.exe"Added by the LINKBOT.H WORM!"
XWindows DLL Loaderdefragfat32.exe"Added by the SDBOT-SS WORM!"
XWindows DLL Loaderdefragfat32abc.exe"Added by the RBOT-RG WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows DLL Loaderdefragfatx.exe"Added by the POEBOT-F WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows DLL Verifierxptl.exe"Added by a variant of the RBOT WORM!"
XWindows DLL Verifierwindlls.exe"Added by the RBOT-AZQ WORM!"
XWindows DNSwindns.exe"Added by the SDBOT-XU WORM!"
XWindows DNS Daemonwindnsd.exe"Added by the WOOTBOT.AS WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows DOSdosw.exe"Added by the SALAY-A WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Driver!windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Dynamic Library Cachedllcache.exe"Added by the INJECT-HT TROJAN!"
XWindows Dynamic Loading HeaderwinDLL32.exe"Added by a variant of the SDBOT WORM!"
XWindows Email Serverwmserv.exe"Added by the FOUNDU-AWORM!"
XWindows Enterprise DefenderWindowsEDefender.exe"Windows Enterprise Defender rogue security software - not recommended
XWindows Enterprise SuiteWE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
XWindows Essensialsmvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Event Detectionwecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Providerwposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Sectionsntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Executablewinmys.exe"Added by the RBOT-ABO WORM!"
XWindows Executerbling.exe"Added by the SDBOT-DFT WORM!"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
XWindows Explorerexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorerexplorer.pif"Added by the RBOT-AID WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorerexplorer32.exe"Added by a variant of the SDBOT WORM!"
XWindows ExplorerWindows Explorer.EXE"Added by the VB-EBA WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Explorer Keyexplorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
XWindows Explorer.exeExplorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Expresspci32b.exe"Added by the BUZUS.C TROJAN!"
XWindows Extensions for Win32winprgs32.exe"Added by the SDBOT.AFA WORM!"
NWindows Eyes??"For blind people
XWindows FAT 32WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows File Protectionwinprotect.exe"Added by the AGOBOT.JB WORM!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows File XP Managerwfdmgr.exe"Added by the SDBOT.XD TROJAN!"
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows FirewalLsess.exe"Added by a variant of the RBOT WORM!"
XWindows FirewallWindowsFirewall.exe"Added by the MYTOB.AO WORM!"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewallipservice32.exe"Added by a variant of the RBOT WORM!"
XWindows Firewallrundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Firewall Logwinlog.exeAdded by an unidentified WORM or TROJAN!
XWindows Firewall Managermsfw.exe"Added by the RBOT.WR WORM!"
XWindows firewall managerchh.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows firewall managermsguard.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows Firewall Servicewfsvc.exe"Added by the IRCBOT-YL WORM!"
XWindows Firewall Updaterupdatees.exe"Added by the RBOT-GBX WORM!"
XWindows Firewall Updatercronos.exe"Added by the RBOT-GBY WORM!"
XWindows Firewall Updaterctfcom.exe"Added by the RBOT-GCB WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsphost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllwinmu.exe"Added by a variant of the RBOT WORM!"
XWindows Fixintegator.exe"Added by the SDBOT.ZAB WORM!"
XWindows Fixerwinfix.exe"Added by the VIRUT-I VIRUS!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows FormatAdWinForm.exeWindupdates adware variant
XWindows Frame Worksfrmwrks32.exe"Added by a variant of the RBOT WORM!"
XWindows Frameworkfrmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
XWindows Frameworkscvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XWINDOWS FUCK BY CLASICfuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
XWindows Gamma Displaywingamma.exe"Antivirus 2010 rogue security software - not recommended
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Global Initngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows GMT32wingmt32.exe"Added by the MYTOB.KM WORM!"
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows GuardWAUMGRD.EXE"Added by the RBOT-GY WORM!"
XWindows Guard ProWindowsGP.exe"Windows Guard Pro rogue security software - not recommended
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
UWindows GuardianFawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows haz Layer[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Helpmailinfo.exe"Added by the MYTOB.JX WORM!"
XWindows HelpStney.exe"Added by the AGOBOT-VI WORM!"
XWindows Help Filewinhelper32.exe"Added by the SDBOT-QK TROJAN!"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Help Servicewinhlp.pif"Added by the RBOT-AKW WORM!"
?Windows Help SystemHelp.pif"??"
XWindows Helperwinhelp.exe"Added by the BANKER.APE TROJAN!"
XWindows Helperwsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Hijack Protectioncomngr.exe"Added by the AGENT-FYD TROJAN!"
XWindows Hijack Protection Systemcommngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
XWindows his LayerpilotGame.exe"Added by the RBOT.GLX WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Hostwinhost.exe"Added by the PRYSAT TROJAN!"
XWindows Host Booterhostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Namelmass.exe"Added by the GAOBOT.O WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows HP Drivershpdmws.exe"Added by the SDBOT.AQU WORM!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows HTTP serviceswinhttps.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Icons Managerwicomgr.exe"Added by the RBOT-AIF WORM!"
XWINDOWS ID SYSTEMwID32.exe"Added by the MYTOB.LN WORM!"
XWindows Identifysysays.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Imagewintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
XWindows Image Acquisition (WIASC)WIAcs.exe"Added by the RIZO.A TROJAN!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows installerwinstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
XWindows Installerntdll.exeAdded by an unidentified WORM or TROJAN!
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Internet Protocolwinproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
UWindows IP Securityipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
XWindows IP Security Serviceipsecs.exe"Added by the RBOT.BPW WORM!"
XWindows IPv6 Driverswipv6.exe"Added by the SDBOT-VJ WORM!"
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows JavaScript DaemonWinjsd.exe"Added by the WOOTBOT.AF WORM!"
XWindows Kernel 64kernal64.exe"Added by the YIMP-B WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows kev Messengermskev.exe"Added by the SDBOT-XV WORM!"
XWindows Keyboard Serviceswinkeyboard.exe"Added by the IRCBOT.AFS WORM!"
XWindows Keyboard Serviceswinkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Livemsgnms.exe"Added by the XPACK.AV TROJAN!"
XWindows LiveWindowsLive.exe"Added by the REALBOT-A WORM!"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
XWindows Live Clientmsnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
UWindows Live Family Safety Filterfsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XWindows Live Managerwinlivemgr.exe"Added by the SHEUR.EB TROJAN!"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows live Messengermsn.com"Added by the IRCBOT-AAV WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Live Messengermsnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
XWindows Live Messenger[random].exe"Added by the RBOT-GVL WORM!"
XWindows Live Messengermsnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
XWindows Live Messenger 8.12ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
XWindows Live Messenger Addonwllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgs!wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
YWindows Live OneCarewinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows Live Servicerusrserv.exe"Added by the SMALL.LU BACKDOOR!"
XWindows live Supportwlmsngr.exe"Added by the RBOT-BKL WORM!"
UWindows Live SyncWindowsLiveSync.exe"Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - ""a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers"""
UWindows Live™ OneCare™ Family Safetyfssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
?Windows Loadwindows.com"??"
XWindows Loaderwstart32.exe"Added by the GAOBOT.CA WORM!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
Xwindows LoadxmWin_.exe"Added by the FODDER-A TROJAN!"
XWindows Local ISPwinthcr.exe"Added by the SDBOT.ENZ BACKDOOR!"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
XWindows Locatorwsass.exe"Added by the IRCBOT.N TROJAN!"
XWindows Log Agentwinlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XWindows Loggerwinlog.exe"Added by the NSHADOW-B TROJAN!"
XWindows loggingwinlogd.exe"Added by the RBOT-ON WORM!"
XWindows loggingasgasg.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Logical Adapterwsrsvc.exe"Added by the IRCBOT.ARU BACKDOOR!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Loginexplored.exe"Added by the GAOBOT.SY WORM!"
XWindows Loginwinlog.exe"Added by the AGOBOT.MG WORM!"
XWindows Loginlmss.exe"Added by the AGOBOT-JA WORM!"
XWindows Loginmsnmsgr.exe"Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Loginlogin.exe"Detected by NOD32 as a variant of the BIFROSE TROJAN!"
XWindows Loginlms.exe"Added by the AGOBOT-IC WORM!"
XWindows Login Folderwinzep.exe"Added by the AGOBOT-TZ WORM!"
XWindows Login Managerwinlogin.exe"Added by a variant of the SDBOT WORM!"
XWindows Login Securitywinlogin.pifAdded by an unidentified WORM or TROJAN!
XWindows Login Servicewinlog.exe"Added by the RBOT-AFN WORM!"
XWindows Login Servicewinlogin.pif"Added by the SDBOT-ACU WORM!"
XWindows Logonwinlogin.exe"Added by the SPYBOT-C TROJAN!"
XWindows Logonwinlogon.exe"Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
XWindows Logon ApplicationWinIogon.exe"Added by the LINKBOT.M WORM!"
XWindows Logon Applicationlogon.exe"Added by the POEBOT-J WORM!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
XWindows Logon Applicationwinlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process
XWindows Logon Applicationwinamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XWindows Logon Applicationedcwinlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Applicatonedcwinlogon.exe"Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Managerlogon.exe"Added by a variant of the RBOT WORM!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
Xwindows logon procedurewinlogonpc.exe"Added by the WINLOGON TROJAN!"
XWindows Logon Servicewinlogon.pif"Added by the RBOT-AOU WORM!"
XWindows Logon Servicenapi32.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows LoL Layergqwdcr.exe"Added by the AGOBOT-AHS WORM!"
XWindows LoL Layerwin.exe"Added by the RBOT-FTO WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows LoL Layerpyvnpt.exe"Added by the RBOT-GKV WORM!"
XWindows LoL Layerwinlolx.exe"Added by the RBOT-FOR WORM!"
XWindows LoL Layerazypbrx.exe"Added by the RBOT-GMZ WORM!"
XWindows LoL Layerblvpnmcny.exe"Added by the RBOT-GOR WORM!"
XWindows Lord Anti-Viruswinlord32.exe"Added by the SDBOT-GW WORM!"
XWindows Management Informantwmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
XWindows Management Instrumentationmwd.exe"Added by the GRAPS WORM!"
XWindows Management Instrumentation[path to file]"Added by the QEDS-A WORM!"
XWindows Management Instrumentationswinmg.exe"Added by the GAOBOT.GW WORM!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Managerwinmants.exe"Added by the MANTAS WORM!"
XWindows Managerwinsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Managertaskmgrs.exe"Added by the SILLYFDC.BBZ WORM!"
XWindows Manager ControlWINMUR32.EXE"Added by the AGOBOT-AR WORM!"
XWindows Manager Update Inctgb.exe"Added by the SDBOT-ACM WORM!"
XWindows mangementwinlogonn.exe"Added by the RANDEX.FC WORM!"
XWindows Media APwinmapp.exeAdded by an unidentified WORM or TROJAN!
XWindows Media APPwmapp.exeAdded by an unidentified WORM or TROJAN!
NWindows Media Center"RunDLL32.exe ehuihlp.dllBootMediaCenter"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Media Drivermsnger.exe"Added by a variant of the RBOT WORM!"
XWindows Media Loaderwmloader.exe"Added by a variant of the GAOBOT WORM!"
XWindows Media Playerwmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
XWindows Media PlayerMediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermcafe32.exe"Added by the RBOT-YO WORM!"
XWindows Media Playerwmplayer.exe"Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XWindows Media Player50cent.exe"Added by a variant of the RBOT WORM!"
XWindows Media Playermpwe.exe"Added by the RBOT-TT WORM!"
XWindows Media Playermsams.exe"Added by the RBOT.AHR WORM!"
XWindows Media Playervmmreg32.exe"Added by the AGENT.AQO TROJAN!"
XWindows Media Playermsass43.exe"Added by the RBOT-RT WORM!"
XWindows Media Playermpupdata.exe"Added by the SDBOT.BBG WORM!"
XWindows Media Playerwmplayerc.exe"Added by the SILLYFDC.DBG WORM!"
XWindows Media Player 3.6wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 3.6bWMPA36B.EXE"Added by the RBOT-VV WORM!"
XWindows Media Player 3.6dwmpa36d.exe"Added by the RBOT-YA WORM!"
XWindows Media Player 3.9wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 6.1.2wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
NWindows Media Powerpoint HelperNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
XWindows Media Serverwmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Server!wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows media servicecrvss.exe"Added by the SDBOT.VP WORM!"
XWindows media servicecrsss.exe"Added by the RBOT.ACY WORM!"
XWindows media serviceSygate32.exe"Added by the RBOT.ADE WORM!"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Media Updatercrease.exe"Added by the RBOT-ATI WORM!"
XWindows Media UpgradeNeUpgrade.exe"Added by the RBOT.BMF TROJAN!"
XWindows Media Utilitywmediautil.exe"Added by a variant of the SPYBOT WORM!"
XWindows Memory Driversmemretain.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Managerwindowsmem.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
XWindows Memory Sharingmemoryshr.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Memory Sharingmemshr.exe"Added by the IRCBOT.MC BACKDOOR!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows messengermessengers.exe"Added by the MYTOB.EI WORM!"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messengermsnmsg.exe"Added by the SPYBOT.BV WORM!"
XWindows Messenger 4.14landisc.exe"Added by the SDBOT-KR WORM!"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Messenger Live MSNwinlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Messengerwinmsg.exe"Added by the VELKBOT.A WORM!"
XWindows Messenger Panelwbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Messenger Servicekaspersky.exe"Added by the MYTOB.HY WORM!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messenger Starterwmvsvc.exe"Added by the DELF.DAX TROJAN!"
XWindows MeTaLRoCk servicemetalrock.exe"Added by the TASTYRED TROJAN!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows Microsoft Verifierwinauth23.exe"Added by a variant of the RBOT WORM!"
UWindows Mobile Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UWindows Mobile-based device managementwmdSync.exe"Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships
UWindows Mobile-based device managementwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XWindows mod VerifierWindows-mod.exe"Added by the RBOT.DSU WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWindow2.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindowsLogon.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWwuamguard.exe"Added by the RBOT.EZJ WORM!"
XWindows modez Verifierwinlogom.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindows-.exe"Added by the RBOT-DIO WORM!"
XWindows modez Verifiertaskmngr.exe"Added by a variant of the RBOT WORM!"
XWindows modez Verifierwinl0g0z.exe"Added by the RBOT-FNB WORM!"
XWindows modez Verifierwuamguard.exe"Added by the RBOT.EZJ BACKDOOR!"
XWindows Monitorwinmon.exe"Added by the SDBOT.VB WORM!"
XWindows Monitorarsetup.exeAdded by the SPAZBOX.A TROJAN!
XWindows Monitor Serviceswinmonitor.exe"Added by the RBOT-XX WORM!"
XWindows Monitoring Servicewinmon.exe"Added by a variant of the SDBOT WORM!"
XWindows More ChoiceTopContext.exe"ZQuest adware"
XWindows Mouse Serviceswinmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
XWindows Mouse Serviceswinmouse64.exe"Added by the IRCBOT.AIA BACKDOOR!"
XWindows Mouse Utilitiesmouseutils.exe"Added by the RBOT-ABU WORM!"
XWindows ms Driversmsnup32.exe"Added by the SDBOT-AAL WORM!"
XWindows MS Update 32fhm.exe"Added by the IRCBOT.GEN WORM!"
XWindows MS Update 32sucker.exe"Added by the FORBOT-GJ WORM!"
XWindows MS Update 32jebote.exe"Added by the FORBOT-GK WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows MSNMSN.msn"Added by the TRIXCU.A WORM!"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messangerlivemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows MSN Live Messengerwinlivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows MSN Live Messengerwinmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
XWindows MSN Updateswnd32.exe"Added by the IRCBOT-ABA TROJAN!"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows MSX driverswinmsx.exe"Added by the RBOT-AYG TROJAN!"
XWindows Net Cfgservice.exe"Added by a variant of the RBOT WORM!"
XWindows NetDDewrmana32.exe"Added by the MYTOB.IM WORM!"
XWindows NetsWinNET.exe"Added by the RBOT-MO WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwingmt.exe"Added by a variant of the SDBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Network Firewallfirewall.exe"Added by the POEBOT-J WORM! Located in %System%"
XWindows Network Logonnpesvc.exe"Added by the AGENT.ERZ TROJAN!"
XWindows Network Servicewinvc32.exe"Added by the RBOT.RY WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Network ServiceRealteks.exe"Added by the RBOT-GTG WORM!"
XWindows Network Serviceswinnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Network Serviceswinnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Sessionnspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows Networking Monitormdm.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networking Monitorinxmdmx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networking Monitoringmdm.exe"Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networksnetcog.exe"Added by the MYTOB.FH WORM!"
XWindows Nivedia DriversysMGT.exe"Added by a variant of the RBOT WORM!"
XWindows NNT[path to trojan]"Added by the RANKY.E TROJAN!"
XWindows NTtwain.exe"Added by the AGENT.BEA TROJAN!"
XWindows NT 32ntlogin32.exe"Added by the RANDEX.BRD WORM!"
XWindows NT Loginntlogin32.exe"Added by the SDBOT.WG WORM!"
XWindows NT Login Session ManagerWNSM.EXE"Added by the RBOT.BIV WORM!"
XWindows NT Logon Applicationwinlogon.scr"Added by the RBOT-ALP WORM!"
XWindows NT Service Namewinshock.exe"Added by the RBOT-PK WORM!"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows NT Session Managersess.exe"Added by a variant of the RBOT WORM!"
XWindows NT Update ManagerWINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
XWindows NTFS Volume Manage[6 random letters].exe"Added by the RBOT.EDL BACKDOOR!"
XWindows OEM Toolswinres32.exe"Added by the SPYBOT.FD WORM!"
XWindows Offical Netvvorksmywriter32.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Office Monitoremdm.exe"Added by the RBOT.AFV BACKDOOR!"
XWindows OLE Automation Serverole32aut.vbe"CoolWebSearch parasite variant"
XWindows Online Updaterdllman.exe"Added by the RBOT-TE WORM!"
XWindows pack Control Centertaskmam.exe"Added by the TOMETA-J TROJAN!"
XWindows Pcwinmgr.exe"Added by the BIBOT-A WORM!"
XWindows PC DefenderWP[random characters].exe"Windows PC Defender rogue security software - not recommended
XWindows PDGwinpdg.exe"Added by the RBOT-ADW WORM!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows PNPwinpnp.exe"Added by the RBOT-AKN WORM!"
XWindows PNP Serverpnpsrv.exe"Added by the RBOT-AKM WORM!"
XWindows Pool Managerpoolsc.exe"Added by the OBOT.CH WORM!"
XWindows Pool Setuppoolmc.exe"Added by the IRCBOT.RU BACKDOOR!"
XWindows Population Loggerwinpo32.exe"Added by the AGENT.YKR WORM!"
XWindows Portable Device DriversMSKSVRVS.EXE"Added by a TROJAN - see here"
XWindows Portable DevicesMSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Print SpoolerNavAgent32.exe"Added by an unidentified VIRUS
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Printing DriverWinPrint.exe"Added by a variant of the RBOT WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Driverciadvs.exe"Added by the BUZUS-M TROJAN!"
XWindows Printing Driverciadvss.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Drivergpedits.exe"Added by the DCKEYG.A WORM!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Process Managerwinproc.exeAdded by an unidentified WORM or TROJAN!
XWindows Processe Managermspn32.exe"Added by the RBOT.AXO WORM!"
XWindows Proffesional SecurityWinSecure32.exe"Added by the AGOBOT.VA WORM"
XWindows Protected Storagenpssvc.exe"Added by the IRCBOT.AUL BACKDOOR!"
XWindows Protection SuiteWI[random characters].exe"Windows Protection Suite rogue security software - not recommended
XWindows Protectotboxide.exe"Added by a variant of the WOOTBOT WORM!"
XWindows Recavery Adwarelsass.exe"Added by an unidentified TROJAN - see here. Note - this is not the legitimate lsass.exe process
XWindows Recovery Consolerecovery.exe"Added by the RANSOM.FD WORM!"
XWindows Recylinder Checkzwdomsgemw.exe"Added by the RBOT-EGJ WORM!"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslncom.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWINDOWS REGISTER EDITregistr32.exeAdded by an unidentified WORM or TROJAN!
XWindows Register Settingssvmhost.exe"Added by a variant of the FORBOT WORM!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Registrymsnmsg.exe"Added by a variant of the RBOT WORM!"
XWindows Registrywinhost.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Cleanerwinclean.exe"Added by a variant of the SPYBOT WORM!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Registry DLLwinregdll.exe"Added by the IRCBOT.FB BACKDOOR!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Registry Managertasksmanagers.exe"Added by the MYTOB.ER WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Registry Namewinses.exe"Added by the RBOT-ADB WORM!"
UWindows Registry Repair ProRegistryRepairPro.exe"Registry Repair Pro. ""Scans the Windows Registry for invalid or obsolete information in the registry"""
XWindows Registry Scanregscan32.exe"Added by the RBOT.KE WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Registry Scansvcdll.exe"Added by the RBOT-TP WORM!"
XWindows Registry Scanregscan23.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Scanregscan.exe"Added by the RBOT-HA WORM!"
XWindows Registry Scanwinmedia.exe"Added by the SPYBOT.GK WORM!"
XWindows Registry Securitycrss.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Registry Servicesregserv.exe"Added by the SLENFBOT.BB WORM!"
XWindows Registry Startupwind32.exe"Added by the AGOBOT-BZ WORM!"
XWindows Registry XPwinxptdl.exe"Added by the IRCBOT.AUN WORM!"
XWindows Relay Serviceipcbind.exe"Added by the DELFINJECT.F TROJAN!"
XWindows Relay Serviceirfnga.exe"Added by the DROPPER.ACO TROJAN!"
XWindows Remote Addressingwnpcgs.exe"Added by the DELF-EZN TROJAN!"
XWindows Remote Launcherwnpmcs.exe"Added by the IRCBOT.ASX BACKDOOR!"
XWindows Repairtoxikx.exe"Added by the SDBOT-ADL WORM!"
XWindows reportswchost.exe"Added by the SMALL-BD TROJAN!"
XWindows Rescue Systemwinsto.exe"Added by the SUURCH.CG TROJAN!"
XWindows Reverse Preperationwinrvp.exe"Added by the SLENFBOT.CB WORM!"
XWindows Reversed Virus Protectionwinrsvp.exe"Added by the SLENFBOT.HX WORM!"
Xwindows runsystem.exe"Added by the ICPASS-A WORM!"
XWindows Run-Time 64bitwin64rt.exe"Added by a variant of the RBOT WORM!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Running DLL Servicerundll128.exe"Added by the IRCBOT.XDH BACKDOOR!"
XWindows Running DLL Servicerundll64.exe"Added by the SLENFBOT.HV WORM!"
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime Proccess32RUNdll.exe"Added by the SDBOT.QW WORM!"
XWindows SAomniscient.exe"BLAZEFIND adware"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Scheduler!scheduler.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
NWindows SearchWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XWindows securesetver32.exe"Added by the SPYBOT.EP WORM!"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Secure FixiPodFixer.exe"Added by the WOOTBOT.BM BACKDOOR!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Secure talal32[7 random letters].exe"Added by the RBOT.HTP TROJAN!"
XWindows Secure Updatewinupser.exe"Added by the RBOT-GCG WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure Updateload.exe"Added by the FORBOT-GU WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securetywurger.exe"Added by the AGOBOT-NC BACKDOOR!"
XWINDOWS SECURITYwingrd.exe"Added by a variant of the RBOT WORM!"
XWindows Securitywin.pif"Added by the RBOT-APT WORM!"
XWindows Securityms32.pif"Added by the RBOT-ARN WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Assistantrundll32.vbe"CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
XWindows Security Assistantwinsec.exe"CoolWebSearch parasite variant"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Center Notification Appwscnfty.exe"Added by a variant of the RBOT WORM!"
XWindows Security Center Notification Applssxe.exe"Added by the RBOT-GKX WORM!"
XWindows Security Center Notification Applsesxes.exe"Added by the RBOT-GLR WORM!"
XWindows Security Center Notification Applseos.exe"Added by a variant of the RBOT-GLR WORM!"
XWindows Security Center Notification Applseesysecurex.exe"Added by a variant of the RBOT-GKX WORM!"
XWindows Security Controlwuaucls.exe"Added by the FORBOT-V WORM!"
XWindows Security Managerwinsecurity.exe"Added by the AGOBOT-KI WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Security Modulemodule.exe"Added by a variant of the RBOT WORM!"
XWindows Security Policylsass32.exe"Added by the AGOBOT-CR WORM!"
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Security Servicearrdt.exe"Added by a variant of the RBOT WORM!"
XWindows Security Servicewindows.pif"Added by the RBOT-AMG WORM!"
XWindows Security SuiteWI[random characters].exe"Windows Security Suite rogue security software - not recommended
XWindows Security Survysvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows Security Updatesecurity32.exe"Affilred adware"
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"
XWindows Serv PatchMcaffe2005.exe"Added by a variant of the RBOT WORM!"
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWindows ServeAdWinServAd.exeWindupdates adware variant
XWindows Serverwinserv.exe"Added by the IRCBOT.AVM BACKDOOR!"
XWindows Server Client Verification Servicewscvs.exe"Added by the AGENT.AWC TROJAN!"
XWindows Server Driverssyssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Server Informationservinfo.exe"Added by the FORBOT-EN WORM!"
XWindows Server IP Verification Servicewsivs.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Server Peer Verification Servicewspvs.exe"Added by a variant of the RANKY TROJAN!"
XWindows Server!winsvr.exe"Added by the IRCBOT.AYC BACKDOOR!"
XWindows Servic2winsy.exe"Added by the RBOT-AIA WORM!"
XWindows servicewuamgrd.exe"Added by the RBOT-QW WORM!"
XWindows Servicedddd.exe"Detected by Kaspersky as Dialer.Salc
XWindows Serviceprvdi.exe"Malware - detected by Kaspersky as the SMALL.RD TROJAN!"
XWindows Servicevideo.exeAdded by an unidentified TROJAN!
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Servicepd7.exe"Added by the SMALL.VZ TROJAN!"
XWindows Servicedstart4.exeAdded by an unidentified TROJAN!
XWindows Servicepd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
XWindows Servicevideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
XWindows Serviceservices.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Servicer.exe"Added by a variant of the SMALL.VZ TROJAN!"
XWindows Servicewindowz.exe"Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Serviceservice.exe"Added by the IRCBOT-ACV WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agccntjeqcfyo.exe"Added by the RBOT-GST WORM!"
XWindows Service Agccnt[random].exe"Added by the SDBOT-DHL WORM!"
XWindows Service Agccntrmizjgz.exe"Added by the SDBOT-SIM WORM!"
XWindows Service Agentczf.exe"Added by the RBOT-GAJ WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agentagl23.exe"Added by the RBOT-GQU WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agenttaskmgr32.exe"Added by the RBOT-GMN WORM!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service Agentwinup32.exe"Added by the RBOT-GQX WORM!"
XWindows Service Agentwinupds32.exe"Added by the RBOT-GQT WORM!"
XWindows Service Agentwit.exe"Added by the RBOT-GQV WORM!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agentcxfrru.exe"Added by the SDBOT.GAV WORM!"
XWindows Service Agentizszbayz.exe"Added by the KOLAB.TC WORM!"
XWindows Service Agentjnxrcyc.exe"Added by the RBOT.XAT BACKDOOR!"
XWindows Service Agentkafdprs.exe"Added by the IRCBOT.HDE BACKDOOR!"
XWindows Service Agentkrqbs.exe"Added by the IRCBRUTE.AZ TROJAN!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Agentmxjunj.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentndibbeu.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentnimcoo.exe"Added by the RBOT.EWV WORM!"
XWindows Service Agentnod32.exe"Added by the RBOT.BNG BACKDOOR!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agenttjybssd.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentumvcnm.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentuqgpq.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentvbsxkhk.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agentwge23.exe"Added by the RBOT.HHK BACKDOOR!"
XWindows Service AgentWindo.exe"Added by the RBOT.NQS WORM!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows Service Agentwinupd32.exe"Added by the SDBOT.SYM WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows Service Agentidvcqv.exe"Added by the AGOBOT-AJB WORM!"
XWindows Service Agent 32mrthd.exe"Added by the AGENT-GAQ TROJAN!"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service Ajavjava128.exe"Added by the RBOT.BNG WORM!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service DCuhpnjcjl.exe"Added by the RBOT-GLY WORM!"
XWindows Service ExecServiceLayer.exe"Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Service LoaderWindow.exe"Added by the RBOT-XO WORM!"
XWindows Service Managementsvcmngmt.exe"Added by the AGOBOT-NM WORM!"
XWindows Service Manageruserint32.exe"Added by the OSCABOT-C WORM!"
XWindows Service Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managermsgs.exe"Added by the OSCABOT-E WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcmgr32.exe"Added by the OSCABOT-D WORM!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertaskmgr.exe"Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Service Pack 2WindowsSP2.exe"Added by the SDBOT-TQ WORM!"
XWindows Service Pack Auto Updatewinworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updatefiggaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updateballin.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Service Pack2WIN43.EXE"Added by the GAOBOT.G WORM!"
XWindows Service Supplywinsupply.exe"Added by the SLENFBOT.CZ WORM!"
XWindows Service Support CallSVSS32.EXE"Added by the RBOT-XQ WORM!"
XWindows Service SVsv32.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Service Threadssvcthreads.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Service XPXpFirewall.exe"Added by the MYTOB.AM WORM!"
XWindows Servicerxqobypik.exe"Added by the SDBOT-DFB WORM!"
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesservicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesw32services.exe"Added by the AUTORUN-FT WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Servicesservices.exe"Added by the AGENT-MVC TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Layerwinlogz2.exe"Added by the RBOT-FZE WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Services M7ctfmon32.exe"Added by the AGENT.WOH TROJAN!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows Serviece Agents[8 random letters].exe"Added by the AGENT.BHR TROJAN!"
XWindows Servserserviser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Session Managersmss32.exe"Added by a variant of the RBOT WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
?Windows shellwin70.exe"??"
XWindows Shellshell.exe"Added by the MYTOB-CA WORM!"
XWindows Shelltaskgmr.exe"Added by the MYTOB.BV WORM!"
XWindows Shell Library Loaderload shell.dll"CoolWebSearch parasite variant"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWINDOWS SKYsky.exe"Added by the MYTOB.CH WORM!"
XWindows Smart Managersmart.exe"Added by the RBOT-SL WORM!"
XWindows SMB Managersmb32.exe"Added by the RBOT-BHZ WORM!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWindows Socket ProcedureWinSock32.exe"Added by the RBOT-FMX WORM!"
XWindows Softwarehbsppe.exe"Added by the RBOT-GLL WORM!"
XWindows Soundsvdhost.exe"Added by the SDBOT.EFX BACKDOOR!"
XWindows Sound DriverSndMon32.exe"Added by a variant of the SPYBOT WORM!"
XWindows Sound Emulatorsnd32_win.exe"Added by the ATNAS.A WORM!"
XWindows Sound ManagerSndMon32.exe"Added by the FORBOT-BU WORM!"
XWindows Sound ManagerSndMon16.exe"Added by a variant of the FORBOT WORM!"
XWindows Sound Managersound.exe"Added by the AGOBOT-CD WORM!"
XWindows Sound Managergearsec.exe"Added by the PUSHBOT.DF WORM!"
XWindows Sound VerifierWinIp32.exe"Added by the RBOT-FMO WORM!"
XWindows SP2 Firewallwfirewall7.exe"Added by a variant of the RBOT WORM!"
XWindows SP2 UpdateSp2update.exe"Added by the WOOTBOT.BS WORM!"
XWindows SP2 Version Loadwuauclt32.exe"Added by the GAOBOT.CX WORM!"
XWindows SP4directCC.exe"Added by the RBOT-ACX WORM!"
XWindows Spoolwinspool.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Spool Serverspoolsrv.exe"Added by the SDBOT-ACT WORM!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows SpoolerSPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
XWindows Spoolerspoolsv32.exeAdded by an unidentified WORM or TROJAN!
XWindows Spoolerwinsplr.exe"Added by the SHEUR.ANX TROJAN!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWindows spoolservr Servicespoolservr.exe"Added by the SDBOT-AAN WORM!"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows Spoolsurf Servicespoolsurf.exe"Added by the SDBOT-ZZ WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Spoolvvv Servicespoolvvv.exe"Added by the SDBOT-AAW WORM!"
XWindows spyware removerWindows-spyware.exe"Added by the SystemPoser TROJAN!"
XWindows sq Driverswinmsn32.exe"Added by the RBOT-ADI WORM!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows Sql Service For Windows 32 Bitwinsql32.exe"Added by the FORBOT-FC WORM!"
XWindows SRS Clientwinsrs.exe"Added by the RBOT-BXQ WORM!"
XWindows SRT Clientwinsrt.exe"Added by the RBOT-BFR WORM!"
XWindows SSH Clientwinssh.exe"Added by the RBOT-AXC WORM!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
XWindows Stand Sound DriversSounddrv.exe"Added by the SDBOT-XF WORM!"
XWindows Standard Securty[random 3-letter filename]"Added by the RBOT-ALF WORM!"
XWindows Start Server 2000traficy.exe"Added by the RBOT-AHM WORM!"
XWindows Startupwinsta~1.exe"GoHip foistware"
XWindows Startupwinstartup.exe"GoHip foistware"
XWindows StartupWdrun32.exe"Added by the GAOBOT.AO WORM!"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
XWindows Startup 32 Bitssysrun32.exeAdded by a variant of the DARKSUN TROJAN!
YWindows SteadyState - Bubble MessagesBubble.exe"Part of Windows SteadyState
YWindows SteadyState - Session Timer Notify (UI)SCTUINotify.exe"Part of Windows SteadyState
XWindows Storm-Memory Driversmemorystorm.exe"Added by the SLENFBOT.CO WORM!"
XWindows Stortupsvchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Streams Serverlocalsrv.exe"Added by the SDBOT.LN WORM!"
XWindows Subsyswinload.exe"Added by the NETSPREE.C WORM!"
UWindows Supervisorwinspvr.exe"Windows Supervisor surveillance software. Uninstall this software unless you put it there yourself"
XWINDOWS SVCwinsvc.exe"Added by the MYTOB-EY WORM!"
XWindows svchostavserv.exe"Added by the PUSHBOT.FM WORM!"
XWindows svchostctfmon32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows svchosthappy2008.exe"Added by the PUSHBOT.AM WORM!"
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWindows svchostservicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows svchostsvchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostups.exe"Added by the PUSHBOT.A WORM!"
XWindows svchostupss.exe"Added by the PUSHBOT.GJ WORM!"
XWindows svchostserviceam.exe"Added by the PUSHBOT.EY WORM!"
XWindows svchostsvchostx.exe"Added by the PUSHBOT.CC WORM!"
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWindows SYN Control Centerwinmnon32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows SyncroAdSyncroAd.exeWindupdates adware variant
XWindows SysNotifymssecc.exe"Added by the AGENT-GFR TROJAN!"
XWINDOWS SYSTEMbeta.exe"Added by the MYTOB.DF WORM!"
XWINDOWS SYSTEMdcomuser.exe"Added by the MYTOB.EO WORM!"
XWINDOWS SYSTEMlf66prc.exe"Added by the MYTOB.GC WORM!"
XWINDOWS SYSTEMmsdev32.exe"Added by the MYTOB.EH WORM!"
XWINDOWS SYSTEMnec.exe"Added by the MYTOB-L WORM and variants!"
XWINDOWS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMninfoie.exe"Added by the MYTOB-EP WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB-CX WORM!"
XWINDOWS SYSTEMskybotx.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMsmoc.exe"Added by the MYTOB.FU WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWINDOWS SYSTEMtest.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest2.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest3.exe"Added by the MYTOB.DV WORM!"
XWINDOWS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMwin.exe.exe"Added by the MYTOB.FA WORM!"
XWINDOWS SYSTEMwinaup.exe"Added by the MYTOB-DN WORM!"
XWINDOWS SYSTEMwinligon.exe"Added by the MYTOB.EP WORM!"
XWINDOWS SYSTEMwinmon.exe"Added by the MYTOB.GB WORM!"
XWINDOWS SYSTEMwinNTsys32.exe"Added by the MYTOB-DM WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWindows SystemWINSYS.exe"Added by the RBOT-AEF WORM!"
XWINDOWS SYSTEMwinsys33.exe"Added by the MYTOB.EK WORM!"
XWINDOWS SYSTEMwinvnc.exe"Added by the MYTOB.EU WORM!"
XWINDOWS SYSTEMwinxpserv.exe"Added by the MYTOB-BQ WORM!"
XWINDOWS SYSTEMxxx.exe"Added by the MYTOB.CZ WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.JU WORM!"
XWINDOWS SYSTEMbotzor.exe"Added by the ZOTOB WORM!"
XWINDOWS SYSTEMgothica.exe"Added by the MYTOB.HU WORM!"
XWINDOWS SYSTEMmsnl.exe"Added by the MYTOB.IK WORM!"
XWINDOWS SYSTEMper.exe"Added by the ZOTOB.C WORM!"
XWINDOWS SYSTEMtwunk_65.exe"Added by the MYTOB-EG WORM!"
XWINDOWS SYSTEMservce.exe"Added by the MYTOB-EI WORM!"
XWINDOWS SYSTEMservises.exe"Added by the ZOTOB-I WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWINDOWS SYSTEMmsn32.exe"Added by the MYTOB-FX WORM!"
XWINDOWS SYSTEMsky.exe"Added by the MYTOB.LB WORM!"
XWINDOWS SYSTEMWin32IMAPSVR.exe"Added by the MYTOB-FQ or MYTOB-FU WORMS!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWINDOWS SYSTEMmtrnqs.exe"Added by the MYTOB.IG WORM!"
XWINDOWS SYSTEMlogic.exe"Added by the MYTOB.IC WORM!"
XWINDOWS SYSTEMctech.exe"Added by the MYTOB-KD WORM!"
XWINDOWS SYSTEMefefefe.exe"Added by the MYTOB-KH WORM!"
XWINDOWS SYSTEMsvchost2.exe"Added by the MYTOB.OZ WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.EB WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWindows Systemsystem.exe"Added by the MYTOB-GN WORM!"
XWindows System 32winsys_32.exe"Added by the RBOT-FTR WORM!"
XWindows System 32-Bat Servicewin32bat.exe"Added by the MYTOB.FI WORM!"
XWindows System BackupSysBackup.exeUnidentified malware
XWINDOWS SYSTEM By FEnRwindasz-updote.exe"Added by the MYTOB.LR WORM!"
XWINDOWS SYSTEM Cleanerh3.exe"Added by the MYTOB.EQ WORM!"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System DefenderWS[random characters].exe"Windows System Defender rogue security software - not recommended
XWINDOWS SYSTEM Dnswindsns.exe"Added by the MYTOB.EY WORM!"
XWINDOWS SYSTEM DNSPOOLhbmail.exe"Added by the MYTOB.FW WORM!"
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindows System Filecmxp.exe"Added by the SPYBOT.KHO WORM!"
XWINDOWS SYSTEM FILEwinload.exe"Added by the MYTOB.DK WORM!"
XWindows System GatewaySPOOLER.EXE"Added by a variant of the RBOT WORM!"
XWindows System Guardegun.exe"Added by the AGENT-NHY TROJAN!"
XWindows System Guardmsdn.exe"Added by the FAKEAV-BJD TROJAN!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows System Initwinit32.exe"Added by a variant of the RBOT WORM!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows System ManagerCRSL.EXE"Added by the SDBOT.MG WORM!"
XWindows System Managersysconf.exe"Added by the MYTOB.AL WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Managercrssm.exe"Added by the RBOT-AFH WORM!"
XWINDOWS SYSTEM MANAGERspoolsvc.exe"Added by the MYTOB-LY WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
XWINDOWS SYSTEM MEMORY LOADERmemloader.exe"Added by the MYTOB-IN WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
Xwindows system notepadwnpsm.exe"Added by a variant of the RBOT WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System RestorerSystemRestorer.exe"Added by the DULOAD.C WORM!"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindows System Securitywinmp.exe"Added by the RBOT.IV WORM!"
XWindows System Securitysys32.pif"Added by the RBOT-AOL WORM!"
XWindows System Security Monitor[4 random letters].exe"Added by the PINKTON.A WORM!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
Xwindows system servicewinsock.exe"Added by the RBOT-MR WORM!"
XWindows System Servicewnuserv.exe"Added by the SPYBOT.ANDM WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows System SuiteWS[random characters].exe"Windows System Suite rogue security software - not recommended
UWindows System Traymsni.exe"Iambigbrother monitoring software"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWINDOWS SYSTEM UPDATExDcc.exe"Added by the MYOTB-EH WORM!"
XWindows System Update Toolsupds.exe"Added by the VANBOT.CX BACKDOOR!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System32windowsp.exe"Added by the MYTOB.GD WORM!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindows System32clsas32.exe"Added by the RBOT-AZO WORM!"
XWindows System32explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
XWindows System32System32.exe"Added by the SDBOT-ALI WORM!"
XWindows SYSTEM32Realplayer.exe"Added by the SPYBOT.ZH WORM!"
XWindows System32wingrd32.exe"Added by a variant of the RBOT WORM!"
XWindows System32windows32.exe"Added by the RBOT-FPB WORM!"
XWindows System32 Driverclsass32.exe"Added by the SDBOT-AGG WORM!"
XWindows System32 Kernelsystem32.exe"Added by the SDBOT-AAT WORM!"
XWindows SystemDllSYSTEMDLL.EXE"Added by the AGOBOT-LP WORM!"
XWINDOWS SYSTEMnservicces.exe"Added by the MYTOB-EL WORM!"
XWindows Systemnmgstagmr.exe"Added by the MYTOB.S WORM!"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
XWindows SYStryspoolsvr.exe"Added by the SDBOT.GN BACKDOOR!"
XWindows SYStrysystry.exe"Added by the SDBOT-E WORM!"
XWindows Sz Hostwinshvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Task ManagerACCOUNT_DETAILS.DOC.exe"Added by the QUATERS.A WORM!"
XWindows Task Managertaskmgn.exe"Added by the AGENT-CIP BACKDOOR!"
XWindows Task Managertaskmrg.exe"Added by the MYTOB.AV WORM!"
XWindows Task Managertaskgmr.exe"Added by the MYTOB.BJ WORM!"
XWindows Task Managertaskmg.exe"Browser hijacker - identified by DrWeb antivirus as ""Trojan.StartPage.601"""
XWindows Task Managertaskmngr.exe"Added by the RBOT-ANM WORM!"
XWindows Task Manager Emulatorkennewr.exe"Added by the SPYBOT-FA WORM!"
XWindows Task Mgrmstasks.exe"Added by the IRCBOT.UN BACKDOOR!"
XWindows Task Mgr!mstasker.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindows Task Schedulerasijdie.exeAdded by an unidentified WORM or TROJAN!
XWindows Task Service (32-bits)tasksys.exe"Added by the DREFIR.D WORM!"
XWindows TaskAdWintaskad.exeWindupdates adware variant
XWindows Taskbar Managerinternat.exe"Added by the PROTORIDE-H WORM!"
XWindows Taskbar Manager[path to file]"Added by the PROTORIDE.B WORM!"
XWindows Taskbar Systemtasksys.exe"Added by a variant of the SDBOT WORM!"
XWindows Taskmanagerlsassx.exe"Added by the KELVIR.E WORM!"
XWindows Taskmanageriexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Taskmanagerservice.exe"Added by the PUSHBOT.OR WORM!"
XWindows Taskmanagersvchost.exe"Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Taskmanagertaskmrg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Taskmanagertaskngr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Taskmanagertskmngr.exe"Added by the IRCBOT.DHR BACKDOOR!"
XWindows Taskmanagerwdtsvc.exe"Added by the PUSHBOT.AU WORM!"
XWindows Taskmanagerwinpifviewer.exe"Added by the PUSHBOT.BB WORM!"
XWindows Taskmanagerwinrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Taskmanagertaskxphost.exe"Added by the PUSHBOT.BI WORM!"
XWindows Taskmanager Datacsrrss.exe"Added by the RBOT-BBH WORM!"
XWindows TaskManager Servicewindns32.exe"Added by the AGOBOT-JP WORM!"
XWindows TCP/IPwintcp.exe"Added by the AGOBOT-ZH WORM!"
XWindows Telnet Serverwintel.exe"Added by the AGOBOT-MW WORM!"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
XWindows Terminal Managerrmbsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows Timewinmgr.exe"Added by the RBOT-XC WORM!"
XWindows Time ServerTimeSRV.exe"Added by the SPYBOT.DNC WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows TMSVPHOST.exe"Added by a variant of the RBOT WORM!"
XWindows TMrundlI32.exe"Added by the RBOT.EL BACKDOOR!"
XWindows TMwindowssys32.exe"Added by a variant of the RBOT WORM!"
XWindows TMWinxSys.exe"Added by a variant of the RBOT WORM!"
XWindows TMpdpatbcyj.exe"Added by the RBOT.FEF WORM!"
XWindows TMSyss.exe"Added by the RBOT.ADF BACKDOOR!"
XWindows Tracking Clientctwsvc.exe"Added by the AGENT-GMB TROJAN!"
XWindows UDPwinudp.exe"Added by the IRCBOT.GAT WORM!"
XWindows UDP Controlwinudspm.exe"Added by a variant of the SDBOT WORM! See here"
XWindows UDP Control Centerauth.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control CenterehSched.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerfxstaller.exe"Added by the AGENT-IEE TROJAN!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows UDP Control Centermsnmngs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centermsnpd.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centertmps.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinlive32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinmsn.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinrofl32.exe"Added by the LDPINCH-RZ TROJAN!"
XWindows UDP Control Centerwinudpmg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgrs.exe"Added by the DROPPER.CMV TROJAN!"
XWindows UDP Control Centerwinudpmsgr.exe"Added by the SDBOT.GAV WORM!"
XWindows UDP Control Centerwinupmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinuscn32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgr.exe"Added by the DLOADR-HQL TROJAN!"
XWindows UDP Control Centerfxsteller.exe"Added by the IRCBOT-J BACKDOOR!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows UDP Control Centerwinmgrs.exe"Added by the PUSHBOT.MY WORM!"
XWindows UDP Control Managerwinudpmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Upaterundll.exe"Added by the HAKO TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
Xwindows updateuddater.exe"Added by the LEOX TROJAN!"
XWindows Updatewudate.exe"Added by the AGOBOT.ML WORM!"
XWindows Updatewupdate.exe"Wengs adware"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows UpdateWuamgrd.exe"Added by a variant of the SPYBOT WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Updatehost32.exe"Added by the RBOT-GU WORM!"
Xwindows updatewuraclt.exe"Added by the RBOT-PO WORM!"
Xwindows updateWuanclt.exe"Added by the RBOT.XZ WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updateebay.exe"Added by the GAOBOT.BUU WORM!"
XWindows Updatewindows.exe"Added by the RBOT-RB WORM!"
Xwindows updatewuaurlt.exe"Added by the RBOT.ADG WORM!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinmguard.exe"Added by the RBOT-EM WORM!"
XWindows Updatewuampd.exe"Added by the RBOT.UM WORM!"
Xwindows updatewuarclt.exe"Added by the RBOT-OF WORM!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
Xwindows updateMicrosoft.exe"Added by the LMIR.A TROJAN!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatetaskmr.exe"Added by the MYTOB-GZ WORM!"
XWindows Updateupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updatewininfo.exe"Added by the MYTOB.GA WORM!"
XWindows Updatewinlogin.exe"Added by the BANKER-DV TROJAN!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Updateqtask.exe"Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here"
Xwindows updatereal.exe"Added by the LEGMIR-AU WORM!"
XWindows Updatewindowsx.exe"Added by the BANCD-A TROJAN!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatewupdmgr.exe"Added by the BANCBAN-FC TROJAN and variants!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows UpdateXPLoogNT.exe"Added by the BANCD-B TROJAN!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindows Updatemsi.exe"Added by the BANKER-XB TROJAN!"
XWindows UpdateSqltob.exe"Added by the DASHER.A WORM!"
Xwindows updatelogonuit.exe"Added by the LEGMIR-AO TROJAN!"
XWindows Updateavkir.exe"Added by the RBOT-GJP WORM!"
XWindows Updateeasypwnt.exe"Added by a variant of the SDBOT WORM!"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows UpdateSecretStub.exe"Added by the SRAMLER.C WORM!"
XWindows UpdateWinload.exe"Added by the DEDMIR-A WORM!"
XWindows Updatetaskngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWindows UpdateMcAfee.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
XWindows UpdateMcAfee3.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Updatewuauclt32.exe"Added by the SDBOT.DHY WORM!"
XWindows Updatedllhostup.exe"Added by the BANCBAN-NB TROJAN!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Updatesysdrv.exe"Added by the AGENT-IYE TROJAN!"
XWindows Updatewinupupdate1.exe"Added by the RBOT-UV WORM!"
XWindows Updateklass.exe"Added by the BIFROSE-ZH TROJAN!"
XWindows UpdatewinlogonEvt.exe"Added by the VB-DXM TROJAN!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
XWindows Updatefdos.exe"Added by the RBOT-COG WORM!"
XWindows Updateleak32x.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows updatemsb32.exe"Added by the GAOBOT.CG WORM!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows Updatetskmngr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows Updatewindb32.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
XWindows Update 32rempss.exe"Added by the FORBOT-FW WORM!"
XWindows Update 32slsys.exe"Added by the FORBOT-FT WORM!"
XWindows update 32bitwinupd32.exe"Added by the SDBOT.BE WORM!"
XWindows Update 63shupd64.exe"Added by the FORBOT-GA WORM!"
XWindows Update 64nbupd64.exe"Added by a variant of the FORBOT WORM!"
XWindows Update 64WinV.exe"Added by the FORBOT-FP WORM!"
XWindows Update Auto Updatewuaumgr.exe"Added by a variant of the SPYBOT WORM!"
XWindows Update Automatic Updates[path to backdoor]"Added by the VBBOT.AM BACKDOOR!"
XWindows Update Automationwinuptdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwaucult.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwuauclt.exe"Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process
XWindows Update AutoUpdate Client Productwuauct.exe"Added by the AGOBOT.ACL WORM!"
XWindows Update Centersvthx.exe"Added by the STUBBOT.A WORM!"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Update Checksyslodr.exe"Added by the SMALL.LU TROJAN!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update Checkermsupdte32.exe"Added by the SDBOT-AEF WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Clientwuclient.exe"Added by the SMALL-RN TROJAN!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows Update Dravendraven.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Update Firewall Systemctfmoom.exe"Added by the RBOT-GAN WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Firewall Systemctfmom.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Update GUI Executable x32xwupdategux32.exe"Added by the RBOT.CXY WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update IPv6 LayerWIN32IPV6.EXE"Added by the RBOT.DUD WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdmngr.exe"Added by the RANDEX.BTB WORM!"
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Managerbootwiz.exeAdded by the MYBOT WORM!
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Update Manager for NTwupdmgr32.exe"Added by the SDBOT.AH WORM!"
Xwindows update microsoftupdatem.exe"Added by the RBOT-CHE WORM!"
XWindows Update Monitoring Servicewinupdt.exe"Added by the RBOT-PL WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows Update SP3Windat.EXE"Added by the RBOT-GTS WORM!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updatedupdatr.exe"Added by the RBOT-AYB WORM!"
XWindows Updaterwupdmgr32.exe"Added by a variant of the DOS.AUTOCAT TROJAN!"
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows Updatersvigost.exe"Added by the RBOT-VS WORM!"
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updatersdsys.exe"Added by the FORBOT-JG WORM!"
XWindows Updater Onlinewinupdatexx.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Service Managerwinupdatr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows Updateswinupd32.exe"Added by the MYTOB.CE WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows Updating Serviceupdating.pif"Added by the RBOT-ALW WORM!"
XWindows Updtee MgnrW1NT45K.exe"Added by the MYTOB.DC WORM!"
XWindows Upgrate Utilitywinulty.exe"Added by the AUTORUN-ASR WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows USB 2.0 Driverusb2ctrl.exe"Added by the RBOT-BIW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB controlerwinusb.exe"Added by the RBOT-HR WORM!"
XWindows USB Driver SupportWindowsusb.exe"Added by a variant of the SPYBOT WORM!"
XWindows USB Hub Managerusbhub.exe"Added by the RBOT-BJX WORM!"
XWindows USB Monitorservupdate.exe"Added by the IRCBRUTE.AQ TROJAN!"
XWindows USB Printerexe.exe"Added by a variant of the RBOT WORM!"
XWindows USB Printerunqgod.exe"Added by the RBOT.BKC BACKDOOR!"
XWindows USB Printerxqteby.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows USB Service666.exe"Added by the MYTOB.AR WORM!"
XWindows USB v3wsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows USBDmsifirewall.exeAdded by an unidentified WORM or TROJAN!
XWindows User Mode Driver Managerwdfmrg.exe"Added by the SDBOT-ZN WORM!"
XWindows User Starterwinuser32.exe"Added by the RBOT.SN WORM!"
NWindows Version Checkver_chk.exe"Version checker for CyberAudioLibrary - ""a new way to exchange information through the Internet"""
XWindows Version Servicesysvers.exe"Added by the SLENFBOT.IF WORM!"
XWindows Version Servicesysvers32.exe"Added by the SLENFBOT.HZ WORM!"
XWindows videovide_32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Video Acquisition (WVA)wvsvc.exe"Added by the AGOBOT.YM WORM!"
XWindows Video Componentwvcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Video Driversvideons32.exe"Added by the GAOBOT.AZT WORM!"
XWindows Video DriversVIDEONS3.EXE"Added by the AGOBOT-KZ BACKDOOR!"
XWindows Video Inputviwsvc.exe"Added by the SLENFBOT.GS WORM!"
XWindows Virtual Managervmnat.exe"Added by the SILLYFDC.BCB WORM!"
XWindows Virtual Serviceswinvirtual.exe"Added by the SLENFBOT.IE WORM!"
XWindows Virtual Serviceswinvirtual32.exe"Added by the SLENFBOT.IB WORM!"
XWindows Virus Controlplou.exe"Added by the SDBOT-ACZ WORM!"
XWindows Virus Scannerwinvsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Volume Controlongsvc.exe"Added by the SLENFBOT.DZ WORM!"
XWindows Web Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Winhlp32 Stub Servicewinhlp32.pif"Added by the AIMBOT.AH TROJAN!"
XWindows WKSwsass.exe"Added by the SDBOT-DK WORM!"
XWindows WKS Serviceswkssvr1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows WMF Fixwinfix.exe"Added by the RBOT-FTQ WORM!"
XWindows Workstationmpci.exe"Added by a variant of the RBOT WORM!"
XWindows Workstationmsup32a.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindows Workstation Servicewkssvc.exe"Added by the IRCBOT-AAI WORM!"
XWindows Workstation Service (32-bits)wkssvc32.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Service [5.1-2600]windrm.exe"Added by the RBOT-CNY WORM!"
XWindows Workstation Start Servicemslanmgr.exe"Added by a variant of the RBOT WORM!"
XWindows Xpnortonguard.exe"Added by the MYTOB-DZ WORM!"
XWindows xpWins.exe"Added by the RBOT.VH BACKDOOR!"
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows XP SP2 KeyGenWindows XP SP2 KeyGen.exe"Added by the TIBICK-C WORM!"
XWindows Zero Spoolernmvcs.exe"Added by the SLENFBOT.JQ WORM!"
XWindows-SystemSystem32.exe"Added by the LOGPOLE.C WORM!"
XWindows-TCP-IPrfkampig.exe"Added by the GIPMA TROJAN!"
XWindows-Xdatewuamclt32.exe"Added by the SPYBOT.AMUV WORM!"
XWindows-XP-Service-Packxpspz.exe"Added by the SDBOT-AAC WORM!"
Xwindows16windows16.exe"Added by the VB-XU TROJAN!"
XWindows32rundll.exe"Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Win9x/Me system file of the same name as described here"
Xwindows32windows32.exe"Added by the VB-XU TROJAN!"
XWindows32wuuaclt.exe"Added by the BRATLE.B WORM!"
XWindows32win.exe"Added by the AGOBOT-KN WORM!"
XWindows32system.exeUnknown malware
XWindows32 Configuration Loadermsrf32.exe"Added by the SDBOT-ABX WORM!"
XWindows32 Messenger Servicemsmsgv.exe"Added by the RBOT.ANS WORM!"
XWindows32 Net Databasemsnd32.exe"Added by the RBOT-AAL WORM!"
XWindows32 Serivceswinser32.exe"Added by the SPYBOT.AAF WORM!"
XWindows32KernelStartwks.exe"Added by the LAPURD TROJAN!"
YWindows7FirewallControlWindows7FirewallControl.exe"Windows 7 Firewall Control from Sphinx Software - ""Protects your applications from undesirable network incoming and outgoing activity
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWindowsAgentWindowsAgent.exe"Added by the GOP.G WORM!"
XWindowsAgentsysexhook.exe"Added by the GOP keyboard logger/TROJAN!"
XWindowsAPI.DLLServer5.exe"Added by the ""Fear and Hope"" TROJAN!"
XWindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
XWindowsBackupWINDOWSBACKUP.EXE"Added by the STANG WORM!"
XWindowsBoolaimplg.exe"Added by the SDBOT-CNG WORM!"
XWindowsCRCwscrc.exe"Added by the SDBOT-VU WORM!"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWindowsDs1.exe"Added by the MSNDIABLO.A WORM!"
XWindowsDiskEvtsvcsvh32.exe"Added by the NANINF.D TROJAN!"
XWindowsDiskLogcstsm.exe"Added by the STINX-C or STINX-D TROJANS!"
XWindowsExplorercsrss.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsFileSystemwinsfs32.exe"Added by the RBOT-FMQ WORM!"
XWindowsFileSystemcidaemon32.exe"Added by the RBOT-FSP WORM!"
XWindowsFirewalllsass.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsFirewallSvcwinsvcup.exe"Added by a variant of the SDBOT WORM!"
XWINDOWSflashbrgsqldata1.exe"Added by a variant of the AGENT-IC TROJAN!"
XWindowsFSwinfs.exe"Added by the AGOBOT-BO WORM!"
XWindowsfwvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XWindowsfwwindowsfw.exe"Added by the AGOBOT-TA WORM!"
XWindowsFYwp.exe"Part of a ""Security IGuard"" parasite infestation - also detected as DESKTOPHIJACK"
XWindowsFYbsw.exe"Added by a variant of the DESKTOPHIJACK TROJAN! For removal see here"
XWindowsFY[path to trojan]"Added by the FAKEALE-E TROJAN!"
XWindowsFZ[path to file]"Added by the DESKTOPHIJACK VIRUS! Also see DESKTOPHIJACK.B TROJAN!"
XWindowsFZA5281300.so"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowsFZzloader3.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowsHiverpcc.exe"Added by the DLENA-A TROJAN!"
XWindowsInstaller[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XWindowsIPRelaywinipsvc.exe"Added by the IRCBOT-AAA WORM!"
XWindows�UpdatesUpdate.exe"Added by the RBOT.TRA BACKDOOR!"
XWindowsKa1.exe"Added by the MSNDIABLO.A WORM!"
XWindowsKeyUpdatemaster.exe"Added by the JOSAM WORM!"
XWindowsMGMWinmgm32.exe"Added by the SOBIG.A WORM and LALA.C TROJAN!"
Xwindowsmpwindowsmp.exe"Added by the AUTORUN-DP WORM!"
XWindowsNT CWServicesCWServices.com"Detected by Bitdefender as the AGENT.AGDK TROJAN! See here"
XWindowsNT ServicesServices.com"Detected by Bitdefender as the DELF.OFC TROJAN! See here"
XWindowsProtocolLoglsadst.exe"Added by the NANINF.C TROJAN!"
XWindowsReg% update[random filename].exe"Added by the RBOT-HH WORM!"
XWindowsRegistration[random filename]"Added by the RBOT-NO WORM!"
XWindowsRegKey Autoupdate[random filename]"Added by a variant of the RBOT WORM!"
XWindowsRegKey upd4te2d4te*********.exe [* = random char]"Added by the RBOT.XQ WORM!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewindns.exe"Added by the RBOT.IE WORM!"
XWindowsRegKey updatewinupdatexx.exe"Added by the RBOT.LW WORM!"
XWindowsRegKey update[random filename]"Added by the RBOT.QT WORM!"
XWindowsRegKey updatesvchoosts.exe"Added by the RBOT.ADB WORM!"
XWindowsRegKey updatesvchostc.exe"Added by the RBOT.IF WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
XWindowsRegKey updateWindowsup.exe"Added by the SDBOT.PU WORM!"
XWindowsRegKey updateWINUPDATES.EXE"Added by the RBOT-MM WORM!"
XWindowsRegKey updaterkbuouoxfl.exe"Added by the RBOT-OO WORM!"
XWindowsRegKey updatewinsys.exe"Added by the RBOT-JY WORM!"
XWindowsRegKey updatewinupdat32.exe"Added by the RBOT-AGW WORM!"
XWindowsRegKey update XPwindexv1.exe"Added by the RBOT-ABM WORM!"
XWindowsRegKey%$ updatemsi332.exe"Added by the RBOT-IX WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
XWindowsRegKeys updatewinsysi.exe"Added by the SDBOT.WE WORM!"
XWindowss Service Agentmssngear.exe"Added by the RBOT.KGU BACKDOOR!"
XWindowsService[random name].dll"Added by the VUNDO-X TROJAN!"
XWindowsServicesHservicedhs.exe"Added by the AGOBOT-JD WORM!"
XWindowsServicesStartupsvchost.exe"Added by the ECUP WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XWindowsSetup[path to trojan]"Added by the EZBOT TROJAN!"
XWindowsSp2sp2.exe"Added by the POSSE WORM!"
XWindowsSystem32asper.exe"Added by the AGENT-EFP TROJAN!"
XWindowsSystem32svchosts.exe"Added by the AGENT-EDA TROJAN!"
XWindowsSystem32[path to worm]"Added by the SDBOT-DFG WORM!"
XWindowsSystem32msnmssgr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msn_kilo.exe"Added by the AGENT.ALY BACKDOOR!"
XWindowsSystem32msnmgaer.exe"Added by the AGENT.ALY BACKDOOR!"
Xwindowstime.exewindowstime.exe"Added by the DLOADR-AQV TROJAN!"
UWindowsTranslatorDWinTrsl.exe"Delta Translator® English < > Portugese (Brazilian) version - ""an automatic
UWindowsTranslator_EspanholDWinTrsl.exe"Delta Translator® Spanish < > Portugese (Brazilian) version - ""an automatic
XWindowsUpdWindowsUpd4.exe"VirtuMonde adware"
XWindowsUpd1WindowsUpd1.exe"VirtuMonde adware"
XWindowsUpd2WindowsUpd2.exe"VirtuMonde adware"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
XWindowsUpdatesvchost.exe"Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XwindowsupdateRPC[RANDOM CHARACTERS].exe"Added by the IRCBOT.B TROJAN!"
XWindowsUpdateUSRINIT.EXE"Added by the MADDIS.B WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsUpdatesvchost.exe"Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindowsUpdatewinnnint.exeAdded by an unidentified WORM or TROJAN!
XWindowsUpdate[path to file]"Added by the DUPA-B TROJAN!"
XWindowsUpdatesvchostw.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdateNzil.exe"Added by the CULLER-C WORM!"
XWindowsUpdateStrad.exe"Added by the CULLER-D WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
XWindowsupdatewupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWinDOwsUPdatesmss.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsUpdatesvdhost.exe"Added by the AGOBOT-BP WORM!"
XWindowsUpdatetwain.exe"Added by the AGENT.BEA TROJAN!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsUpdate Servicewuautlc.exe"Added by the RBOT-NR WORM!"
XWindowsupdate Servicecsrss.exe"Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie
XWindowsUpdatecrsscrss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdateDirectdupadirect.exe"Added by the DUPA-C TROJAN!"
XWindowsUpdatelsassslsasss.exe"Added by a variant of the AGENT-HZ TROJAN!"
XWindowsUpdatem1[path to file]"Added by the AGENT-AAJ TROJAN!"
XWindowsUpdatem2svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindowsUpdateManagerwupdmng.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindowsUpdateNTsvwhost.exe"Added by the SHELLOT-B TROJAN!"
XWindowsUpdateRregserv.exe"Added by the COBFINN_B TROJAN!"
XWindowsUpdatesvchostsssvchostss.exe"Added by the AGENT-HZ TROJAN!"
XWindowsUpdatev4w32gins.exe"Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\)
XWindowsUpdatewinsecwinsec.exe"Added by a variant of the AGENT-HZ TROJAN!"
NWindowsWelcomeCenter"rundll32.exe oobefldr.dllShowWelcomeCenter"
XWindowsXP ModuleDirectX3D.exe"Malware
XWindowsXp Securityspool.exe"Added by the RBOT-GRK WORM!"
XWindowsXP Updatewindowsxpupdate.exe"Added by the RBOT-PB WORM!"
XWindowsXPservsvcnxp32.exe"Addee by the NANINF-A TROJAN!"
Xwindowsxxxwindowsxxx.exe"Added by the DUBING-A TROJAN!"
Xwindowsxxx2windowsxxx2.exe"Added by the DUBING-A TROJAN!"
XWindows_LowLevel_Security_Corelsass.exe"Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair"
XWindows_Protectwinsystem.exe"Added by a variant of the RBOT WORM!"
XWindows_Protectwinregal.exe"Added by a variant of the RBOT WORM!"
XWindows_Protectlsas.exe"Added by the RBOT.ARO WORM!"
XWindows_Protectwincontrol32.exe"Added by the RBOT-ADK WORM!"
XWindows_SerivceSERVICE.exe"Added by the WOOTBOT.AH WORM!"
XWindows_Updatessvthost.exe"Added by a variant of the SPYBOT WORM!"
XWindows_VXDuser32.exe"Added by the PPORT TROJAN!"
XWindowz[original worm filename].vbs"Added by the NUKIP WORM!"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindowz Update V2.0updater.exe"Added by the YODO-C WORM!"
XWindow_Protectwinsi32.exe"Added by a variant of the RBOT WORM!"
XWindoxs Update CenterW32RfSA.exe"Added by a variant of the SDBOT WORM!"
XWinDrg32windrg32.exe"Added by the DRUDGEBOT.A WORM!"
XWinDriv32WinDriv32.exe"Added by the SMALL-BA TROJAN!"
XWinDriver Configurationwindrvconf.exe"Added by the AGOBOT-LX TROJAN!"
XWinDrivesWinDrives.EXE"Added by the SMALL.DIG WORM!"
XWINDRUNtaskgmrs.exe"Added by the MYTOB-BT WORM!"
Xwindrvwindrv32.exe"Added by an unidentified VIRUS
XWinDrvwindrvx.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XWinds Sers Agts[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWinds Sersc Agtsrzrzncrtz.exe"Added by the RBOT-GTV WORM!"
UWinDSL MTU-AdjustWinDSL_MTU.exeAdjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
?WinDSL_MTUWinDSL_MTU.exe"May be realted to Tiscali broadband
XWinDSNXWin****.exe [* = random char]"Added by the DSNX TROJAN!"
UWindstream Broadband Check-up Centermatcli.exe"Part of the Windstream Broadband service from AllTel. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xwindtbswinsysvc"Added by the AGOBOT-NH WORM!"
XWindUpdates[path to trojan]"Added by the AGENT.BF TROJAN!"
XWindUpdatesWinUpdt.exeWindupdates adware variant
UWINDVDpatchCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
NWinDVR SchSvrSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NWinDVRCtrlWinDVRCtrl.exeControl center software for an AOpen VA1000 TV tuner card
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
XWinDynManageramsnmsg.exe"Added by the SDBOT-IA BACKDOOR!"
Xwinenvwinenv.exe"Added by a variant of the SDBOT WORM!"
XWinEssentialKeyhost.exeHijacker - hailing from jraun.com
XWinEssentialkeyword.exe"Jraun adware"
XWineWorkWineWork.exe"Added by the BANCOS.AB TROJAN!"
XWinExlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XWinExecWinexec.exe.vbs"Added by the AINESEY.A WORM!"
XWinExecWinExec.exe"Added by the FALUS-A WORM!"
XWinExecLsass.exe"Added by the CRUTLE-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinExec32WinExec32.exe"Added by the KAZWIN WORM!"
XWinexec32windhelp32.exe"Added by the AGENT-HKU TROJAN!"
Xwinexecswinexecs.exe"Added by the SILLYFDC.BBB WORM!"
UWinFast ScheduleWfwiz.exeLeadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
UWinfast2KLoadDefault"rundll32.exe wf2kcpl.dllDllLoadDefaultSettings"
UWinFastDTVDTVSchdl.exe"Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc"
UWinfast_2KWF2K.EXESystem Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card
UWinFast_Gamma"Rundll32.exe wfcpl.dll DllLoadGammaRampSettings"
UWinFast_Taskbar"rundll32.exe wftask.dll WFDllLoadDefaultSettings"
XWinFavoritesWinFavorites.exe1Loudmarketing.com adware downloader
NWinFax PROFAXMNG32.EXE"WinFax PRO from Symantec - fax management software"
NWinFax PRO ControllerWFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
YWinFaxAppPortStarterwfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
XWinFireWF.exe"Added by the DELF-SY TROJAN!"
XWinFix servicersswjzgp.exe"Added by the RBOT-FAE WORM!"
XWinFixer 2005wfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer 2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer helperwfxcwr.exe"WinFixer web installer - ""foistware""
XWinFixer service[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinFixer2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
XWinFixer2006uwfx6.exe"WinFixer 2006 web installer - ""foistware""
XWinFixer_2005uwfx5.exe"WinFixer 2005 web installer - ""foistware""
UWinFlipWinFlip.exe"WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon
UWinFlip.exeWinFlip.exe"WinFlip from Tokyo Downstairs - a 'Flip-3D' task switcher alternative to the standard Alt+Tab on Windows XP that adds the equivalent 'Aero' feature from Windows 7 and Vista. You can either click on the tray icon
XWinFlyer32.dllWinFlyer32.dll"Added by the WINFLYER TROJAN!"
Xwinfontwinfont.exe"Added by the DEATH TROJAN!"
Xwinformwinform.exe"Added by the PWS-ALB TROJAN!"
UWinFoxV2WF2K.EXESystem Tray application that starts up the Winfox utility for a Leadtek Winfast graphics card to restore settings. Can be started manually via Start → Control Panel → Display. Only needed if you wish to run things like the hardware monitor or overclock your card
XWinFXcssrs.exe"Added by the AGOBOT.FX WORM!"
XWinFXcssrs.exe"Added by the GAOBOT.CD WORM!"
XWinFXlsas.exe"Added by the GAOBOT.CD WORM!"
UWinGate Engine Monitorwgengmon.exe"WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine
XWinGate initializeWinGate.exe"Added by the LOVGATE.F WORM!"
Xwingerver2.0.exewingerver2.0.exe"Added by the GRAYBRD-AE TROJAN!"
Xwingowingo.exe"Added by the BEAGLE.AW or BEAGLE.AV WORMS!"
Xwingo[various filenames]"Added by the BAGLE-AU WORM!"
NWinGuage ProWGPRO32.EXE"Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications
YWinguardWGFE95.EXE"Dr Solomon's Virex antivirus"
Xwinguardwingrd32.exe"Added by a variant of the RBOT WORM!"
XWinGuardwinguard.exe"Added by the AGOBOT-OQ WORM! The file is located in %System%"
UWinGuardWinguard.exe"Winguard Popup Remover - pop-up stopper. The file is located in %ProgramFiles%\Winguard Popup Remover"
UWinGuard Prowgp.exe"Winguard Pro"
NWinHacker"rundll32.exe wh95.dll HackMe"
XWinhelpwinhe1p.exe"Added by the QQPASS.E TROJAN!"
XWinHelpWinHelp.exe"Added by the LOVGATE.F WORM! Note - this file is located in %System% whereas the valid one is located in %Windir%"
XWinHelprealsched.exe"Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
XWinhelpTkBellExe.exe..."Added by the LOVGATE.Z WORM!"
Xwinhelpdns32.exe"Added by a variant of the RBOT WORM!"
XwinhelpUpdadv.exe"Added by the QQPASS-N TROJAN!"
XWinhelpTkBellExe.exe"Added by the LOVGATE.E WORM!"
Xwinhlp.exewinhlp.exe"Added by the FORMGLIEDER TROJAN!"
Xwinhlp3.exewinhlp3.exe"Added by a variant of the EASTO.A TROJAN!"
XWinhlp32Wscript.exe Msexec32.vbs"Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
Xwinhlp32.exewinhlp32.exe"Added by the EASTO.A TROJAN!"
Xwinhlpp32.exewinhlpp32.exe"Added by the GAOBOT.SY WORM!"
XWinhostwintt.exe"Added by the LOLAWEB.B TROJAN!"
XWinhostwin.exe"Added by the DLOADER-AP TROJAN!"
XWinhostyahoo.exe"Added by the DELF-KM TROJAN!"
XWinhostwinhost.exe"Added by the REATLE.F WORM!"
Xwinhost.exewinhost.exe"Added by the LOHAV-R TROJAN!"
Xwinhost32.exewinhost32.exe"Added by the TABDIM TROJAN!"
XWinHoundWinHound.exe"WinHound spyware remover - not recommended
XWiniBlueSoftWiniBlueSoft.exe"WiniBlueSoft rogue security software - not recommended
XWinIeRunwinierun.exe"Added by the RNWATCH-A WORM!"
XWiniFighterWiniFighter.exe"WiniFighter rogue security software - not recommended
XWinIFixerWinIFixer.exe"WinIFixer rogue security software - not recommended
XWiniGuardWiniGuard.exe"WiniGuard rogue security software - not recommended. There are number of variants in this family sharing the same user interface - see here"
Xwinimagewvsvc.exe"Added by the RBOT.TX WORM!"
XWinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
Xwininetwininet.exe"Added by the STUBBOT-C WORM!"
Xwininet.dllregperf.exe"Added by the ZLOB TROJAN and variants!"
Xwininet32wininet32.exe"Added by the RAZNEW-A TROJAN!"
Xwininetdwininetd.exe"Added by the WINET TROJAN!"
XWinini.dllwinini.vbs"Added by the STARTP-M TROJAN!"
XWinini32winini32.exe"Added by the AGOBOT-J WORM!"
Xwininitwininit.exe"Added by the WOLLF.16 TROJAN!"
XWinInitWin86.exe"Added by the SMALL-PB TROJAN!"
Xwinintwinint.exe"Added by the SDBOT-ADA WORM!"
XwinIogomwinIogom.exe"Added by the BANCBAN-ML TROJAN!"
Xwinipsecwinipsec.exeUnidentified malware
UWinIRXHelperWinIRXHelper.exe"MSI Media Center Deluxe software - see here"
Xwiniswinis.exe"Added by the RBOT-WI WORM!"
XWiniShieldWiniShield.exe"WiniShield rogue security software - not recommended
XWinjava xmldirx9.exe"Added by the HAXDOOR ROOTKIT!"
XWink*.exeWink*.exe [* = random char]"Added by a variant of the KLEZ WORM!"
UWinkb6winkb6.exe"Part of We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content
XWinKernelWinKer.exe"Added by the MIRAB or SERVIDOR TROJANS!"
XWinKernel[path to virus]"Added by the PLEA VIRUS!"
Xwinkernel32wWin32.com"Added by the BANSAP TROJAN!"
UWinKeywinkey.exe"Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system
Xwinlawinla.exe"Added by the DLOADR-AQL TROJAN!"
Xwinldr[path to file]"Added by the VIDLO-P TROJAN!"
XwinldrRechnung.pdf.exe"Added by the ACS TROJAN!"
Uwinlgnwinsplg.exe"Related to the Sentry Parental Controls software"
Xwinlgz2winlgz2.exe"Added by the KILLFIL-Q TROJAN!"
Xwinlibs.exewinlibs.exe"Added by the EVAMAN.C WORM!"
XWinLibUpdatelibupdate.exe"Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
XWinLibUpdate32libupdate32.exeAdded by the BIONET.405 TROJAN!
XWinLibUpdtelibupdte.exe"Added by the BIONET.318 TROJAN!"
XWinlinkwinlink32.exe"Added by the GAOBOT.AAY WORM!"
XWinlmewindll.exe"Added by the GOP.F WORM!"
UWinLoadWinload.exe"PCTattletale is a surveillance software program that monitors user activity
Xwinloadwinload.exe"Added by the AGENT-GNY TROJAN! Note - the file is located in %ProgramFiles%\Internet Explorer"
XWinLoader[random filename]"Added by variants of the SUBSEVEN TROJAN!"
Xwinlocatorupdateupdatewinlocator.exeLocator adult content toolbar related
Xwinlogwinlog.exe"Added by the GAOBOT.DF WORM!"
Xwinlogwindowxs.exe"Added by the SDBOT-KT BACKDOOR!"
Xwinlog managerwinlog.exe"Added by the DONBOMB.A TROJAN!"
Xwinlog.exewinlog.exe"Added by the BCKDR-RBJ TROJAN!"
XWINLOG0NWINLOG0N.EXE"Added by the MYDOOM.BI WORM!"
XWinLoginwinlogin.exe"Added by the AGOBOT-IX WORM!"
Xwinloginwin32x.exe"Browser hijacker
XwinloginReadMe.exe"Added by the SILLYFDC.BBT WORM!"
XWinlogin.exelog.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xwinlogin.exelogfile.exeAdded by the AGENT.AH TROJAN!
Xwinlogin.exemspaint.exeAdded by a variant of the AGENT.AH TROJAN!
XWinlogin.exesteam.exeAdded by a variant of the AGENT.AH TROJAN!
Xwinlogins.exewinlogins.exe"Added by the OPTIX.H BACKDOOR!"
Xwinlogoffwinlogoff.exe"Added by the AGOBOT-TR WORM!"
Xwinlogonwinlogin.exe"Added by the RANDEX.E WORM!"
Xwinlogonwinlogon.exe"Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogonmsreg32.exe"Added by the SDBOT.EO WORM!"
Xwinlogonwinlogon32.exe"Added by the MASLAN.C WORM!"
Xwinlogonwpwlogon.exeAdded by an unidentified WORM or TROJAN!
XWINLOGONwscript.exe WINLOGON.vbs"Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
XWinlogonLsass.exe"Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwinlogonnvchost.exeAdded by an unidentified WORM or TROJAN!
XWinlogonWINLOGON.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process
Xwinlogonsystem.exeAdded by a variant of the DELF.CNS TROJAN!
Xwinlogoncleanmg.exe"Added by the AGENT-ICR TROJAN!"
XWinlogonscssrr.exe"Added by the AGENT-LXB TROJAN!"
Xwinlogon serviceurx.exe"Added by the SPYBOT.EN WORM!"
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
XWinlogon.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
Xwinlogon.exehelper.exe"Added by the FAKESPY-A TROJAN!"
Xwinlogon.exemsole32.exe"Adware
Xwinlogon32_[path to file]"Added by the RULAND.A WORM!"
XWinLogonndwinlogonnd.exe"Added by the AGENT-NNQ TROJAN!"
Xwinlogon_userccIsass.exe"Added by the SILLYFDC.BBT WORM!"
XWinlogunwinlogin.exe"Added by the P2LOAD-C WORM!"
XWinLsassservicec.exe"Added by the SCANE WORM!"
XWinLsass[path to trojan]"Added by the SCANE WORM!"
Xwinltmpvwinln.exe"Added by the TCXMEDI-C TROJAN!"
Xwinltmpvwutop.exe"Added by the TCXMEDI-C TROJAN!"
XWinmainwinmain.exe"One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder
XWinManagewmanage.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
?WinManagerschost.exe"??"
Uwinmatrix.exeWinMatrixXP.exe"WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop"
XWinMedwinmed.exe"Added by the AGENT.AIRF TROJAN!"
XWinMedia[path to trojan]"Added by the ZEROBE-A TROJAN!"
XWinMediamsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinMedia32winmedia32.exe"Added by the YABE.F TROJAN!"
UWinMemWinMem.exe"WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system"
XWinMenssagewinmax.exe"Added by the BANCOS.B TROJAN!"
XWinMenssagewinmaxy.exe"Added by the BANCOS TROJAN!"
XWinMessengersyshost.exe"Added by the OPANKI-E WORM!"
NWinMgmtWinMgmt.exe"Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here"
Xwinmgmtwmiprvse.exe"Added by the AGENT-GHP TROJAN!"
Xwinmgmt32.exewinmgmt32.exe"Added by the LUZIA.AD TROJAN!"
XWINMGRtaskgmgr.exe"Added by the MYTOB.AN WORM!"
XWinMgrwinmgr32.exe"Added by the VB-EDY TROJAN!"
XWinmgr.exescvhost.exe"Added by the AGOBOT.AFG WORM!"
XWinMgr32winmgr32.exe"Added by the MIMAIL.P WORM!"
XWinMineD4NG3.vbs"Added by the BISCUIT.A WORM!"
XWinMngndllhost.exe"Added by the SIVION-A TROJAN! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\system"
Xwinmngr.exe[path to trojan]"Added by the AGENT-ZB TROJAN!"
Ywinmodemwmexe.exe"Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
XWinmon32winmon32.exe"Added by the RBOT-OQ WORM!"
XWinMoviePlugInWinMoviePlugIn.exe"Sfonditalia adult content premium rate dialer"
XWinmsgwinwork.exe"Added by the GAOBOT.GEN!POLY WORM!"
XWinMsgwinmsgr.exe"Added by the DLOADR-AS TROJAN!"
XWinmsgwinwork8.exe"Added by the AGOBOT-GC WORM!"
XWinMsrv32WinMsrv32.exe"Added by the GAOBOT.AFJ WORM!"
NWinMXWinMX.exe"WinMX file sharing application"
Nwinmysqladminwinmysqladmin.exeStarts the MySQL database admin tool
NWinMySQLadmin Toolwinmysqladmin.exeStarts the MySQL database admin tool
Xwinnetwinnet.exe"CommonName Toolbar spyware. To uninstall see here"
XWinNetDDE[random characters].exe"Added by the NETDEPIX.B TROJAN!"
XWinNiteniteaim.exe"Added by the OPANKI.B WORM!"
Xwinnloadwinnload.COM"Added by the DOWNLD-ABG TROJAN!"
?Winnov MenuWnvMenu.Exe"Winnov Video Capture Card related. What does it do and is it required?"
?Winnov RemoteWnvRsvr.Exe"Winnov Video Capture Card related. What does it do and is it required?"
?Winnov StatusWvStatus.Exe"Winnov Video Capture Card related. What does it do and is it required?"
Xwinnsvcmsvc.exe"Added by the PWS.O TROJAN!"
Xwinntwinnt.exe"Added by the MONA-E WORM!"
XWinNTWinNT.com"Added by the AUTOSKY WORM!"
Xwinnt DNS identwuamgrd32.exe"Added by the RBOT-BAU WORM!"
Xwinnt DNS identiexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xwinnt DNS identpidchk32.exe"Added by the RBOT-ACY WORM!"
Xwinnt DNS identwindowxp.exe"Added by a variant of the RBOT WORM!"
Xwinnt DNS identWinupd32.exe"Added by the RBOT.AVU WORM!"
Xwinnt DNS identwinupdate32.exe"Added by a variant of the RBOT WORM!"
Xwinnt DNS identwuamgrd33.exe"Added by a variant of the RBOT WORM!"
XWinnt DNS identwindowsp.exe"Added by the RBOT.BAL WORM!"
XWinnt DNS identmsnmsrg.exe"Added by the RBOT.BVQ WORM!"
XwinNT updatcwupgrd.exe"Added by a variant of the RBOT WORM!"
Xwinnt2winnt2.exe"Added by the AGENT.CJZO TROJAN and variants"
Xwinnt3winnt3.exe"Added by the AGENT.CJZO TROJAN and variants"
Xwinnt4winnt4.exe"Added by the AGENT.CJZO TROJAN and variants"
Xwinnt5winnt5.exe"Added by the AGENT.CJZO TROJAN and variants"
Xwinnt6winnt6.exe"Added by the AGENT.CJZO TROJAN and variants"
XWinNtBBWinntBB.exe"Added by the DULOAD.C WORM!"
XwinntR1winntR1.exe"Added by the AGENT.CJZO TROJAN and variants"
XwinntR2winntR2.exe"Added by the AGENT.CJZO TROJAN and variants"
XWinnupwin32nls.exe"Added by a variant of the SPYBOT WORM!"
Xwinocx32winocx32.exe"Added by the PROTORIDE.I WORM!"
XWINOWS SYSTEMwinnt.exe"Added by the MYTOB.ID WORM!"
XWINPwinmic.exe"Added by the SPYBOT-EB WORM!"
XWinpackwinpack.exe"Adware - detected by Kaspersky as the AGENT.GG TROJAN!"
XWinPatch Protectionwinpatch.exeAdded by an unidentified WORM or TROJAN!
UWinPatrolwinpatrol.exe"WinPatrol - ""Manage Startup programs
YWinPatrol ExplorerWinPatrolEx.exe"Part of WinPatrol"
UWinPatrol Monitorwinpatrol.exe"WinPatrol - ""Manage Startup programs
XWinPCDoctorSysRep.exe"WinPCDoctor rogue system error and cleaning utility - not recommended
XWinPerformanceWinPerformance.lnk"Windows Performance rogue optimization utility - not recommended"
Xwinphonics7536vbsystem35.exe setups.exe vb.vb"Added by a variant of the MUTIN-C TROJAN!"
Xwinpipewinpipe.exeBrowser hijacker redirecting to wow-access.com
UWinPLOSIONWinPlosion.exe"""WinPLOSION allows you to immediately view and select from all the windows running on your computer
XWinPN32winpn32.exe"Added by the AGOBOT-FJ WORM!"
YWinPoetWinPPPoverEthernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
Xwinpolwinpol.exe"Added by the AGENT.IWD TROJAN!"
YWinpoochWinpooch.exe"""Winpooch is a Windows watchdog
XWinPopwinpop.exe"Brudevic A adware"
NWinPopupWINPOPUP.EXE"Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95
Xwinpopupwinupie.exeAdware by Tradeexit.com
NWinpowerWinpower.exe"Part of InstallAnywhere from Zero G Software
XWinProc32winproc32.exe"Added by the AGOBOT-4 WORM!"
XWinprocer32 Updatewinprocer32.exe"Added by the RBOT.GW WORM!"
Xwinprocessor Updatewinprocessor.exe"Added by the RBOT.IO WORM!"
XWinProfileCommand.exe"Added by the BUDDY.E TROJAN!"
XWinProfilesndcfg16.exe"Added by the SNDC.A WORM!"
Xwinprofileiexpiore.exeAdded by a variant of the MONCHER WORM!
XWinProfileiexpIore.exe"Added by the CHUM-C TROJAN!"
XWinProtWinprot.exe"Added by the CHUPACABRA TROJAN!"
XWinProtserver.exe"Added by the CHUPACABRA TROJAN!"
Xwinprotectwin32.exe"Added by the MUGLY.E WORM!"
Xwinprotectwinprotect.exe"Added by the SDBOT-SB WORM!"
Xwinprotectionccsrss.exe"Added by the SILLYFDC.BBT WORM!"
XWinProtectorWinProtector.exe"WinProtector rogue security software - not recommended
UWinProxyWinProxy.EXE""WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP""
XWinproxy PersonalWINPROXY.EXE"Added by the SDBOT.BMF WORM!"
Xwinpsdwinpsd.exe"Added by the MYDOOM.Q WORM!"
XWinPWD Managerwpwdmgr.exe"Added by the RBOT-AUT WORM!"
Xwinrapidwinrapid.exe"Added by a variant of the RBOT WORM!"
Xwinrarwinrar.exe"CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!"
XWinRaR ServiceWinrarCO.comAdded by an unidentified WORM/TROJAN!
Xwinrarshellwinrarshell32.exe"Added by the SALIRA TROJAN!"
XWinReaderread.exe"Added by the DELBOT-V WORM!"
XWinReanimatorWinReanimator.exe"WinReanimator rogue security software - not recommended
XwinRegwinReg.exe"Added by the YAHA.H or YAHA.J WORMS!"
XWinRegournik.com"Added by the IRCFLOOD.AL BACKDOOR!"
XWinReg32 serviceholqdnoxpmeu.exe"Added by a variant of the SDBOT WORM!"
Xwinregsrvwinregsrv.exe"Added by the SYNRG TROJAN!"
Xwinreg_32svchosst.exe"Added by the BANCOS-CE TROJAN!"
Xwinreg_32[path to trojan]"Added by the BANKER-DB TROJAN!"
Xwinreg_32sysdll.exe"Added by the DLOADER-IJ TROJAN!"
Xwinreg_32Vc030405.exe"Added by the BANCOS-CT TROJAN!"
UWINREMOTEWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
XWinres32vis[path to worm]"Added by the THRAX.A WORM!"
Xwinrestore1winrestore.exe"Added by the KILLFIL-Q TROJAN!"
Xwinreupswinreups.exe"Added by a variant of the RBOT WORM!"
UWinRollwinroll.exe"WinRoll - a small utility that allows you to ""make a window roll into its title bar
Xwinrootwinsn.exe"Added by the QQPASS.IA WORM!"
Nwinroutewinroute.exe"Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process
XWinRPCwinrpcmx.exe"Added by the BANKER-EEI TROJAN!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xwinrunwinrun.exe"Added by the WINBUR.B WORM!"
XWINRUNtaskgmr32.exe"Added by the MYTOB.AP WORM!"
XWINRUNsvchost32.exe"Added by the MYTOB-AI WORM!"
XWINRUNtaskgmr.exe"Added by the MYTOB-BX WORM!"
XWinRunAutoRun.ini"Added by the LOVELET-AD WORM!"
XWINRUNTASKMGR32.exe"Added by the MYTOB.AX WORM!"
XWINRUN zW1NT45K.exe"Added by the MYTOB.BL WORM!"
XWinRunnersWinDrivers.exe"Added by the DULOAD.C WORM!"
XWins Loader5Gadu-Gadu.exe"Added by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-Gadu"
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWins Update 32services32.exe"Added by the FORBOT-FN WORM!"
XWins32 Onlinecfgpwnz.exe"Added by the BROPIA.R WORM!"
XWinScMngrwinsmc.exe"Added by the SDBOT-BPZ WORM!"
XWinSecwinsec16.exe"Added by the AGOBOT.ZF WORM!"
Xwinsecurewinsecure.exe"Browser hijacker
XWinSecure[random].exe"Added by the AGENT-LR TROJAN!"
XWinsecure AntivirusSecureantivirus.exe"Added by a variant of the SPYBOT WORM!"
XWinSecureAvpgs.exe"WinSecureAv rogue security software - not recommended
XWinSecured32ssmr.exe"Added by a variant of the FORBOT WORM!"
XWinSecurityuninstall.exe"Added by the SILLYFDC.BCJ WORM!"
XWinservWinserv.ila"Added by the NODMIN WORM!"
XwinserverServer.txt.vbs"Added by the DELTAD.A WORM!"
XWinservicewinmain.exeAdult content related malware
Xwinservicesvchost.exe"Added by the CVK BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""services"" sub-folder"
XWinServicehosth.exe"Added by the DWNLDR-FUX TROJAN!"
XWinServiceTtt.exe"Added by the MSNVB-D WORM!"
XWinServiceWinServ.exe"Added by the SKOWOR-O WORM!"
UWinService32ssmgr.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
UWinService32svchost.exe"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
XWinServicesWinServices.exe"Added by the YAHA.K or YAHA.M WORMS!"
Xwinservicesbootvfy.exeAdded by an unidentified WORM or TROJAN!
Xwinservitcassl.exe"Added by the RBOT.ASG WORM!"
Xwinservnwinservn.exe"PurityScan adware"
Xwinservswinservs.exe"PurityScan adware"
XWinSetBrowseBasicUpdate.dll.vbs"Added by the BISCUIT.A WORM!"
Xwinsfcwinsfc.exe"Added by the WISFC VIRUS!"
XWinshellremote.exe"Added by the MYTOB.LJ WORM!"
Xwinshellwindll32lib.exe"Added by the BAGLE-DM WORM!"
?Winshoewuadfdqr.exe"Probably an unidentified VIRUS! Adds itself to 3 registry ""Run"" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed"
Xwinshost.exewinshost.exe"Added by the TOOSO WORM and variants!"
Xwinshow[path to trojan]"Added by the VB-DXP TROJAN!"
XWinShowUpdatecopy [path] winshow.new [path] winshow.dll"Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version"
XWinSigNetXP.exe"Added by the BANKER-FN TROJAN!"
XWinSistemTunggul.vbs"Added by the VBS.STEMCLOVER WORM!"
XWinsk system Loaderwinsk.exe"Added by the AGOBOT-IZ WORM!"
Xwinskypewinskype.exe"Added by the BROGGER-C TROJAN!"
UWinSLWinSL.exe"StarLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Xwinsocksvch0st.exe"Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock driverwinnt64.exe"Added by the SPYBOT-DR WORM!"
XWinsock Drivernvscv32.exe"Added by the AGOBOT-FD WORM!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock driverwin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinsock drivertcpmngr.exe"Added by the SPYBOT-CK WORM!"
XWinsock driverwinupdate32.exe"Added by the SPYBOT-JZ TROJAN!"
XWinsock StartupMain2.exe"Added by a variant of the SDBOT WORM!"
Xwinsock.clientwinsock.exe"Added by the DIABLO-M TROJAN!"
Xwinsock2netsvr.exe"Added by the AGOBOT.LY WORM!"
XWinsock2 dllsW32DLL.EXE"Added by the SPYBOT-CS BACKDOOR!"
XWinsock2 driverSDJOIJE.EXE"Added by the SPYBOT.DR TROJAN!"
XWinsock2 driverMIRC32.exe"Added by the SPYBUZZ TROJAN!"
XWinsock2 driverkgzgjkpcw.exe"Added by the SDBOT.T TROJAN!"
XWinsock2 driverZONEALARM.EXE"Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program"
XWinsock2 driverwincfg.scr"Added by the SPYBOT-E TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock2 driverSPOLSV.EXE"Added by the SPYBOT-CM WORM!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsock2 driversysreq.exe"Added by the SPYBOT-CC WORM!"
XWinsock2 driverWUAUMQR.EXE"Added by the SPYBOT-DP WORM!"
XWinsock2 driverwincfg.exe"Added by the SPYBOT.CO WORM!"
XWinsock2 driversvchorsst.exe"Added by the SPYBOT-EE WORM!"
XWinsock2 driverSYSTEM32.EXE"Added by the SPYBOT-EG WORM!"
XWinsock2 driverdllcfg32.exe"Added by the SPYBOT.AG WORM!"
XWinsock2 driverCFTMON.EXE"Added by a variant of the IRCBOT BACKDOOR!"
XWinsock2 driverntsys32.exe"Added by the SPYBOT-DD WORM!"
XWinsock2 driverWINNT32.EXE"Added by the SPYBOT-CN WORM!"
XWinsock2 driverPAC.EXE"Added by the SPYBOT-ET WORM!"
XWinsock2 driverwinsock2.exe"Added by the SPYBOT-CT BACKDOOR!"
XWinsock2 drivermmtask5.exe"Added by the SPYBOT-CD WORM!"
XWinsock2 driverWWEUMQR.EXE"Added by the SPYBOT-BY WORM!"
XWinsock2 driverIEXPLORE .EXE"Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XWinsock2 driverWINSOUND.EXE"Added by the SPYBOT-H WORM!"
XWinsock2 LoaderWICONF.EXE"Added by the SDBOT-LA WORM!"
XWinsock2 wqr1sWUAUMQR1.EXE"Added by the SPYBOT.KD WORM!"
XWinsock2.dllWINLODR.SCR"Added by an unidentified VIRUS
XWinsock32 driverTESTING.EXE"Added by the SPYBOT-B WORM!"
XWinsock32 driversystem32.exe"Added by the IRCBOT-VT TROJAN!"
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwin32server.exe"Added by the BACKDOOR-AZV TROJAN!"
XWinsock32driverZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
XWinsock32driverZoneLockup.exe"Added by the HACARMY.D TROJAN!"
XWinsock32driverwin32server.exe"Added by the HACARMY.F TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinsock6 MIC driverieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
Xwinsockdrivertskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
Xwinsockdriverwinsock2.2.exe"Added by a variant of the SPYBOT WORM!"
Xwinsockdriveriexplor.exe"Added by the BLATIC.A WORM!"
Xwinsockdriverwinsock3.exe"Added by the SPYBOT-DO WORM!"
Xwinsockdriverbot.exe"Added by the WARPIGS-D WORM!"
Xwinsockdriverwinsock4.1.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xwinsockdriverwinsock2.exe"Added by the SPYBOT-AC WORM!"
XWinSocketComponentnthost.exe"Added by an unidentified VIRUS
XWinsocks2 drivermznmgr.exe"Added by a variant of the SDBOT WORM!"
UWINSOS VERIFYWINSOS.EXE"WinSOS - ""deletes spyware
XWinSP[path] REGEDIT.EXE -s [path] sysreg.reg"Added by the STARTPA-ME TROJAN!"
XWINSP00LWINSP00L.EXE"Added by the AGENT.XAB TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
Xwinspd32dllwinspd32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWinSPFwindrv32.exe"Added by the MYDOOM.T WORM!"
XWinSPFwinspf32.exe"Added by the MYDOOM.S WORM!"
XWinsplwinsplx.exe"Added by a variant of the TROLL-A TROJAN!"
Xwinsplogwsmmlog.exe"Added by the MAILBOT-CA TROJAN!"
XWinspoolspoolsvr.exe"Added by a variant of the SDBOT WORM!"
XWinSpyControlpgs.exe"WinSpyControl rogue security software - not recommended. A member of the AVSystemCare family"
XWinSpyDemoWinSpyDemo.exe"WinSpy rogue spyware remover - not recommended"
XWinSpyKillerWinSpyKiller.exe"WinSpyKiller rogue spyware remover - not recommended
XWinSpywareProtectWinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
XWinSpywareProtect (ver. 5.1)WinSpywareProtect.exe"WinSpywareProtect rogue security software - not recommended
XWinSrvkn0x.exe"Added by the HOBBIT.F WORM!"
XWinSrvSHIZZLE.EXE"Added by the HOBBIT.C WORM!"
XWinsrvwinsrv.exe"Added by the OPASERV.T WORM!"
Xwinsrvwinsrv.exe"Added by the NETSNAK-B TROJAN!"
Xwinsrv3services.exe"Added by the NAFBOT-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Ywinssnotifywinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWinsSystemsyssmss.exe"Added by the DELF.IG TROJAN!"
XWinStabilizerWinStabilizer.exe"Added by the AGOBOT-SW WORM!"
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWinStartservices.exe"Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the ""Startup Item"" field"
XWinStartWinStart.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStartWscript.exe WinStart.vbs"Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
XWinStartwinstart32.exe"Added by the PUROL WORM!"
XWinStartWinStart.pif"Added by the CONE.E WORM!"
Xwinstartwinstart.exe"Added by the SCKEYLO-AB TROJAN!"
XWinStart001WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
XWinStart001.EXEWinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words
Xwinstatswinstats.exe"Added by the GARGAFX TROJAN!"
XWinsta~1winsta~1.exe"GoHip foistware"
XWinSth16WinSth16.exe"Added by the CAKE WORM!"
XwinstroRUN32DLL.exe"Added by the FTP_ANA TROJAN!"
Xwinsupdaterwinsupdater.exe"Added by the ALCRA-F WORM!"
Xwinsupdatesysmngr64winsys64mnger.exe"Added by the RBOT-BAG WORM!"
XWinSvc16.exeWinSvc16.exe"Added by the SDBOT.FQ TROJAN!"
Xwinsvc32winsvc32.exe"Added by the IRCBOT-AEG WORM!"
Xwinsvc32.exewinsvc32.exe"Added by the GREPAGE TROJAN!"
XWinsvrmsupd******.exe [*= random digit]Added by the INJECT.163 TROJAN!
XWinsvr[random filename].exe"Added by the ADCLICK-DK TROJAN!"
XWinsvr managerDDEsvr.exe"Added by the TIRBOT-C WORM!"
Xwinsy32.exewinsy32.exe"CoolWebSearch parasite variant"
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
UWinsysWinsys.exe"Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself"
XWINSYS[path to trojan]"Added by the GOLDPLAY TROJAN!"
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
XWinSyswinmgmt.com"Added by the VB.EIW WORM!"
XWinSyssystem.exe"Added by the DAPROSY WORM!"
XWinSys32Winsys32.exe"Added by the CIGIVIP TROJAN or RECKUS WORM!"
Xwinsys32 Driverwinsys32.exe"Added by the LOONY-O TROJAN!"
UWinSysAppMonWinSysRM.exe"Home & Family Content Filter related. See here"
Xwinsysban[path to trojan]"Added by the CLICKER-CD TROJAN!"
UWinSysChecksb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinSysM371662M.exe"Added by the WINKO.AO WORM!"
XWinSysModule[path to trojan]"Added by the AGENT-DIQ TROJAN!"
XWinSysStartUpWKbLwTaskSystemDll.Exe"Added by the BACKZAT.G WORM!"
XWinSyst32winsyst32.exe"Added by the MORB WORM!"
XWinSystemwinsystem.exe"Added by the WHITEBAIT WORM!"
UWinSystemWinSystems.exe"CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinsystemFreevideo5.EXE"Added by the AGENT.FZS WORM!"
Xwinsystem.syssmss.exe"Added by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the ""Startup Item"" field"
XWinSystemswinsystems16.exe"Added by the SDBOT-CZT WORM!"
Xwinsystems25winsystems.exe"Added by the RBOT-CNZ WORM!"
Xwinsysupd[path to trojan]"Added by the STARTPA-NI TROJAN!"
XWinSysW371662L.exe"Added by the WINKO.AO WORM!"
XWINTwcp****.exe [* = random char]"PurityScan adware"
XWINTwcp**.exe [* = random char]"PurityScan adware"
XWinTaskWintask.exe"Added by the HIPO or LEMIR.F TROJANS!"
XWINTASKtaskgmr.exe"Added by the MYTOB.I WORM and variants!"
XWINTASKtaskgamr.exe"Added by the MYTOB.AU WORM!"
XWINTASKsys32.exe"Added by the MYTOB.K WORM!"
XWINTASKmsmgrxp.exe"Added by the MYTOB.AQ WORM!"
XWINTASKiexplorer.exe"Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWINTASKtaskgmr32.exe"Added by the MYTOB.BU WORM!"
XWINTASKmsvhost.exe"Added by the MYTOB-AR WORM!"
XWINTASKt4skmgr.exe"Added by the MYTOB-AK WORM!"
XWINTASKtaskfile.exe"Added by the MYTOB.EF WORM!"
XWINTASKtaskgm.exe"Added by the MYTOB-AO WORM!"
XWINTASKtaskgmrs.exe"Added by the MYTOB.DH WORM!"
XWINTASKyahooicons.exe"Added by the MYTOB-HM WORM!"
XWINTASKt4skgmr.exe"Added by the MYTOB.CM WORM!"
XWINTASK DLLjusched32.exe"Added by the MYTOB.AI WORM!"
XWINTASK DLL32smsrss.exe"Added by the MYTOB.BS WORM!"
XWINTASK DLL32updatewin"Added by the MYTOB.NI WORM!"
XWinTask driverwintask.exe"Added by the DLOADER-NA TROJAN!"
XWINTASK32taskgmr32.exe"Added by the MYTOB.BN WORM!"
XWINTASK32taskgmrr.exe"Added by the MYTOB.FX WORM!"
Xwintask32Jwintask.com"Added by the NAFBOT-A WORM!"
XWINTASKMANAGERtaskgmr.exe"Added by the MYTOB-AF WORM!"
XWINTASKMGRccsrs.exe"Added by the MYTOB.Q WORM!"
XWINTASKMGRsp2winfix.exe"Added by the MYTOB.KJ WORM!"
XWINTASKStaskgmr.exe"Added by the MYTOB.BO WORM!"
XWINTASKSwinxpro.exe"Added by the MYTOB.EZ WORM!"
XWinTasks DLL Library (32-bits)winkll.exe"Added by the RBOT-AJZ WORM!"
UWinTasks Traybarwintasks.exe"WinTasks - ""Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task
Xwintasks.exewintasks.exe"Added by the EVAMAN WORM!"
XWintbp.exewintbp.exe"Added by the ZOTOB.E WORM!"
XWintbpx.exewintbpx.exe"Added by the ZOTOB.F WORM!"
Uwintectivewintective.exe"Wintective logs keystrokes
XWintelUpdate[path to trojan]"Added by the SMALL-EKW TROJAN!"
Xwinterhappy.exe"Added by the SDBOT-YF WORM!"
NWintercooler ProWINCOOL.EXE"Wintercooler Pro - utility that monitors CPU usage
Xwinthelpwinthelp.exe"Associated with the AdvancedCleaner rogue security software - see here. Removal instructions here"
NWinTidyWinTidy.exe"Desktop icon manager from
XWintimeWintime.exe"Added by the HARNIG TROJAN!"
UWinTimewintime.exe"WinTime - change desktop icons' color and font"
NWintime WtxploadWxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
XWintlmsdred.exeIdentified as a variant of the Trojan-Spy.Win32.Agent.cch malware
Xwintnask32.exewintnask32.exe"Added by the RBOT-AFP WORM!"
Xwintnl.exewintnl.exe"Added by a variant of the ZOTOB.K WORM!"
Xwintnpx.exewintnpx.exe"Added by the ZOTOB.H WORM!"
XWinToolsWToolsA.exe"Wintools adware"
NWinTOTAL Schedulerguru.exeWinTOTAL Real estate appraisal software related
XWinTouchWinTouch.exe"Detected by Kaspersky as the AGENT.BUO TROJAN!"
XWinTraywintray.exe"Added by the LEGUARDIEN.B TROJAN!"
Xwintsk32dllwintsk32dll.exe"Added by the RBOT-AAJ WORM!"
Xwinudll.exewinudll.exe"Added by the MITGLIE-CE TROJAN!"
Xwinuiz.exe"Added by the KONDELI TROJAN!"
XWinUpsvchost.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""4350"" sub-folder"
Xwinupated.exewinupated.exe"Added by a variant of the SDBOT WORM!"
Xwinupd"RUNDLL32.EXE [random value].dll _mainRD"
Xwinupdwinupd.exe"SearchNew adware"
Xwinupd.exewinupd.exe"Added by the BEAGLE.M or BEAGLE.N WORMS!"
XWinUPD32explorer.exe"Added by an unidentified VIRUS
Xwinupdatwinupdat.exe"Added by the CANBOT.A WORM!"
XWinUpdateRBSKQQBO.EXE"Added by the VBSWG2B.A WORM!"
XWinUpdatewmbem.exe"Added by the REVCUSS.B TROJAN!"
XWinUpdateupdsys.exe"Added by a variant of the RBOT WORM!"
Xwinupdatewinupdate.exe"Added by the ALCAN.B WORM!"
XWinUpdatesvhost.exe"Added by a variant of the SDBOT WORM!"
XWinUpdatesvchots.exe"Added by the SMALL.GXJ TROJAN!"
Xwinupdatejusched.exe"Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
XWinupdatelsas.exe"Added by the COSPET.JR TROJAN!"
XWinupdate Enginewupeng.exe"MalwareCrush rogue security software - not recommended
XWinUpdate Loadermsnnm.exe"Added by the REVCUSS.C TROJAN!"
XWinupdate Servicewinxp.exe"Added by the SPYBOT.IR WORM!"
Xwinupdate.exewinupdate.exe"Added by the RADO TROJAN!"
Xwinupdate.regwinupdate.exe"Added by the SPYBOT.EAS WORM!"
Xwinupdate2846vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
Xwinupdate86.exewinupdate86.exe"Added by the FAKEAV-AHQ TROJAN!"
XWinUpdateAdministratorCSRSS.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
XWinUpdateBbreatle.exe"Added by the BRATLE.AWORM!"
Xwinupdateconn[path to file]"Added by the COMBRA-A WORM!"
Xwinupdateconn_Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWinupdateewinsvcc.exe"Added by the AGENT.AN TROJAN!"
Xwinupdatefiv_[path to file]"Added by the COMBRA.C WORM!"
UWinUpdateProtectioncsrss.exe"EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
XWinUpdaterupdate.exe"Added by the STARTPAGE.C TROJAN!"
Xwinupdateswinupdates.exe"Added by the ALCRA-B WORM!"
Xwinupdate_[path to file]"Added by the COMDOR.A WORM!"
XWinUpdatingWinUpdating.exe"Added by the AGENT-GSC TROJAN!"
XWinUPDbcwinupdbc.exe"Added by the BANKER-DSN TROJAN!"
XWinUpdsvwinupdsv.exe"Added by the DROPO MACRO!"
XwinupdtRUNDLL32.EXE [random.dll]"Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder"
Xwinupdtlwinupdtl.exe"SecondThought adware"
XWinUpgrader[path to trojan]"Added by the AGENT-DZ TROJAN!"
XWinUPPD.exe[random filename]Added by an unidentified WORM/TROJAN!
Xwinurwinrun.exe"Added by the WINUR.B WORM!"
Xwinusb.dllwinguard.exe"Added by the FORBOT-CN WORM!"
XWinUser32Kusr32wink.exeAdded by the HK TROJAN!
XWinUsrWinUsr.exe K1S2"Added by the CLUNK.A WORM!"
UWinUtilities Memory OptimizerToolMemoryOptimizer.exe"""WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!"" MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XWinux Piriax ServicePH32.EXE"Added by the RANDEX.G WORM!"
Xwinversionwinversion.exe"Browser hijacker
UWinVNCWinVNC.exe"WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet. Now superseded by RealVNC"
XWinVNCiexplorer.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xwinvxd32winvxd32.exe"Added by the GABLOLIZ.A WORM!"
Xwinwan lptt01winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinwan ml097ewinwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinwebSecurityWinwebSecurity.exe"Winweb Security rogue security software - not recommended
Xwinwordwinword.exe"Added by the TORPID-C TROJAN!"
XWINWORD.exeWINWORD.exe"Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name
XWinWorksvstmgr.exe"Added by the AGOBOT.ACJ WORM!"
Xwinwsl.exewinwsl.exe"Added by the ZOTOB-J WORM!"
XWinX Security CenterWinX Security Center.exe"WinX Security Center rogue security software - not recommended
XWINX16winx16.exe"Added by the AGOBOT-LS WORM!"
XWinXDefenderWinXDefender.exe"WinXDefender rogue spyware remover - not recommended
XWinxDiagUpdateWinxDiagUpdate"Added by the RBOT.BWQ BACKDOOR!"
XwinXP33.exe"Added by the ANPES WORM!"
XWinXPplugin1.exeAdded by the Downloader-JW TROJAN!
XWinXPcsrss.exe"Added by the BANCOS-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP\Tools"
Xwinxpwinxp.exe"Added by the BRONTOK-DN WORM!"
XWinXP fix[path to file]"Added by the RANKY.P TROJAN!"
XWinXP Processor Generator v1.2intspnsr32.exe"Added by the SDBOT.LP WORM!"
XWinxp updateCappp.exe"Added by the RBOT.DKO WORM!"
XWinXp Updaterwinxp32.exe"Added by the RBOT-HG WORM!"
XWinXP-98CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
Xwinxpdll32.exewinxpdll32.exeAdded by a variant of the SMALL downloader TROJAN!
XWinXPHomeplugin2.exe"Added by the malicious INOR.T SCRIPT!"
UWinXPLoad"Rundll32 LoadDll LoadExe WinXPLoad.exe"
XWinXProtectorWinXProtector.exe"WinXProtector rogue security software - not recommended
XWinXPServicelsass.exe"Added by the ZAPCHAS-AS TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Lavan"" subfolder"
XWinXPServicetaksmgr.exeIdentified as a variant of the IRC/Flood.tool malware
XWinXPServiceTskdbg.exe"Added by the MDROP-BPQ TROJAN!"
XWinXPServicectfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"
XWinXPServicemirc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinXPServicenero.exe"Added by the IRCFLOOD.AG BACKDOOR! Note - this is not the Nero CD/DVD burning software by Ahead Software which is normally located in %ProgramFiles%\Ahead\Nero. This file is found in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
XWinXPServicetaksmgr.exe"Added by the KIRSUN.A BACKDOOR! The file is located in the root directory
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %Windir%\Fonts"
XWinXPServicewacult.exe"Added by the KIRSUN.A BACKDOOR! The file is located in %System%\mnut"
XWinXpUpdate32WinXpUpdate32.exe"Added by the AGENT.YWL WORM!"
Xwinxpusbdwinxp64.exe"Added by a variant of the RBOT WORM!"
Xwinystems25winystems.exe"Added by a variant of the SDBOT WORM!"
XWinz Firewall[random filename].exe"Added by a variant of the SDBOT WORM!"
XWinZap Checkwinzbp.exe"Added by the RBOT-AWZ WORM!"
Xwinzip[path to trojan]"Added by the BANCOS.G or BANCOS.K TROJANS! Note - this is not part of the popular WinZip file compression utility"
XWinzip[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
Xwinzipwinzip.exe"Added by the RBOT.BDA WORM! Note - this is not part of the popular WinZip file compression utility"
Xwinzipir_ftp.exe"Added by the BANCBAN-S TROJAN!"