Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X%Windir%winnl.exewinnl.exe"Added by the KIDKITI TROJAN!"
X%Windir%winnm.exewinnm.exe"Added by the KIDKITI TROJAN!"
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@wincms.exe"Added by the RBOT.CBR WORM!"
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
Xantikewingate32.exe"Added by a variant of the RBOT WORM! See here"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
Xautowin32.exe"Added by an unidentified TROJAN! See here"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
XAVScanwinav.exeUnidentfied rogue security software
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
YClamWinClamTray.exe"ClamWin antivirus"
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwin.exe"Added by the VBS.RUNAUTO.G WORM!"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
?encapsulated command toolwintr.com"??"
XEnh Win Updtenhupdt.exe"Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
Xerghgjhgdrwindlhhl.exe"Added by the BEAGLE.BG WORM!"
Xerghgjhjgdrwindlhhl.exe"Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
Xerthegdrwindll2.exe"Added by the BEAGLE.CG WORM!"
Xerthgdrwindll.exe"Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFromine WinPopupwinpopup.exeInstant Messenger program
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvhst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
XgetwinwinB_.exe"Added by the BANKER-HS TROJAN!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
Xgpmcewindow.exe"Added by the VB.CK WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
NGWInkMonitorGWInkMonitor.exe"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
XHhjg5jfd93dftdfwinlogan.exe"Added by the ERTFOR.A TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
UIBWin Background processIBackground.exe"IBackup for Windows"
UIBWin MonitorIBMonitor.exe"IBackup for Windows"
Xicq litewinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
UIE New Window Maximizeriemaximizer.exe"IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
XIpWinsipwins.exe"IPWins adware"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
Xjkdfj94kgdftdfwinlogan.exe"Added by the ZLOB.BZ TROJAN!"
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
XKAVFOXwin1ogoin.exe"Added by the GWGHOST-M TROJAN!"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
XKernel32Kernel32.win"Added by the GAGGLE.D or GAGGLE.E WORMS!"
XKernelCheckwinser.exe"Added by the TSPY_LMIR.SL TROJAN!"
XKernelFaultCheckwinabc3.exe"Added by the NUBYS-A VIRUS!"
XKernelFaultCheckwinbin.exe"Added by the DLOADR-AAX TROJAN!"
Xkeywinxp.exe"Added by the BEAGLE.AG WORM!"
Xkey2winlog.exe"Added by the BAGLEDI-AL TROJAN!"
Xl44sys**winmine"Added by the VBS.LIDO WORM - where ** is a number between 33 and 44"
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
Xlnwin.exelnwin.exe"Added by the DLOADR-ATC TROJAN!"
XLoadwin32.exe"Added by the RUBBLE-A WORM!"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
Xload32winldra.exe"Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Xload=win32exec.exe"Added by the BITTER WORM!"
Xloadwinwinset.exe"Added by the QQPASS-I TROJAN!"
Xloadwinwinsys.exe"Added by the QQPASS-J TROJAN!"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
ULoginwinlog.exe"Salfeld Child Control - parental control software"
XLogServicewincalc.exe"Added by the PAPROXY TROJAN!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
XLTM2winscan.exe"Added by the LITMUS-B TROJAN!"
XLTM2winvers16.exe"Added by the SMALL.ND TROJAN!"
YLTWinModem1ltmsg.exe"Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
NMania Win RestoreRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
XMCwintrims.exe"Added by the WINTRIM TROJAN!"
XMCWINTRIM.EXE"Added by the WINTRIM.A TROJAN!"
XmcafeeWin32.dll.vbs"Added by the CATCHER-B WORM!"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
NMcAfee Winguage??"Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications
XMD IE Pluginwiny.exeAdware
XMicr Update Systemupwin.exe"Added by the SDBOT.YS WORM!"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicroMix32WinCon.exe"Added by the VB-ECC TROJAN!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoftwindl32.exe"Added by the SDBOT-DCZ WORM!"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoftwinnn.exe"Added by the RANDEX.GGP WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft Command Cwinhost32.exe"Added by the SDBOT-BBA WORM!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft DLL Librarywinlib32.exe"Added by the ATNAS.A WORM!"
XMicrosoft Dll Managementwindll.exe"Added by the RBOT-MT WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Loginwinlogin.exe"Added by the RBOT-AJP WORM!"
XMicrosoft Loginswinlogins.exe"Added by the SPYBOT.BCZ WORM!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Rundllwindos.exe"Added by the SDBOT-WF WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementwinnt.exe"Added by the RBOT-MQ WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Managementwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XMicrosoft Security Managerwinamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Sound Technologywinsound.exe"Added by the RBOT-AGG WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft Stuff you knowwinslogin.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Synchronization ManagerWinLoginnn.exe"Added by the SPYBOT.FO WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization Managerwin.exe"Added by the SDBOT.AK WORM!"
XMicrosoft Synchronization Managerwinlogon32.exe"Added by the SDBOT.AEU WORM!"
XMicrosoft Synchronization Managerwincfg32.exe"Added by the SDBOT.DO WORM!"
XMicrosoft Synchronization Managerwin932.exe"Added by the SDBOT.AH WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewindows24.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewingrd32.exe"Added by the RBOT-DW WORM!"
XMicrosoft UpdateWinUpdate32.exe"Added by the RBOT-TI WORM!"
XMicrosoft Updatewinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatewinupdater.exe"Added by the RBOT.BIN WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft UpdateWINDOC.EXE"Added by the SDBOT.PF WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewindows32.exe"Added by the RBOT-BHQ WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32winin.exe"Added by the RBOT-ARR WORM!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Update 64 BITwinman32.exe"Added by the RBOT-AKI WORM!"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update ManagerWINRLS.EXE"Added by the RBOT-AF WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft Win UpdateWinUP.exe"Added by the RBOT-BPR WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windowsatup"Added by a variant of the RBOT WORM!"
XMicrosoft WindowsMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Windowsexplorar.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows[path to file]"Added by the BDOOR-LI BACKDOOR!"
XMicrosoft Windowsbootini.exe"Added by the VANEBOT-K WORM!"
XMicrosoft WindowsKernel.exe"Added by the EDIBARA-A VIRUS!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windowspwjbvphi.exe"Added by the RBOT-GQK WORM!"
XMicrosoft Windowswindets.com"Added by the FLOOD-EQ TROJAN!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Autowxcknautowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUIWindowz.exe"Added by the RANDEX.AEV WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playerwimp.exe"Added by the RBOT-FN WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UMicrosoft Windows SidebarSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatawindows.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WINGS32 ProtocolWinSGR32.exe"Added by the RBOT-APU WORM!"
XMicrosoft WinRaRwinrar.exe"Added by the RBOT-AEC WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft WinUpdatesyslx32.exe"Added by an unidentified VIRUS
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinupd32.exe"Added by the RBOT.MQ WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
XMicrosofts mediawingtp.exe"Added by the RBOT-VO WORM!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftUpdateWinUp32.exe"Added by an unidentified VIRUS
XMicrosoftUpdatewindll.exe"Added by the RBOT-IH WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosoftWindowsa@26m.exe"Added by the KILLPAR-B TROJAN!"
UMicrosoft Windows Mobile Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UMicrosoft Windows Operating SystemSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
NMicrosoft Windows Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft Windows Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
UMicrosoft Windows Operating SystemehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
NMicrosoft Windows Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
NMicrosoft Windows Operating Systemstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
UMicrosoft Windows Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosotufed Update 32windinit.exe"Added by the RBOT-CTJ WORM!"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Driverwindrive32.exe"Added by the SLINBOT.TT BACKDOOR!"
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMismowin32x.exe"Added by the RBOT-JP WORM!"
NMMCWINMGMTwinmgmt.exe"Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here"
Xmmxrunmswinindex.exe"TwoSeven spyware"
Xmobiswing[random].exe"Mobis adware"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
Xms ownagewinPE.exe"Added by the RBOT-AJL WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS Sys Securitymswin.pif"Added by the RBOT-APJ WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Unix Binarywin32ttb.exe"Added by the SPYBOT.OQ WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryWinGuard.exe"Added by the RBOT-ACL WORM!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
Xms window update******.exe [* = random character]"Added by a variant of the RBOT WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMS Windows Executor ProcessMSEXECP32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMS Windows procces 32msprocces.exe"Added by the RBOT-AEZ WORM!"
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMS WINS Binaryign32.pif"Added by the RBOT-ASB WORM!"
XMS Winsockmsws2_32.exe"Added by the AKBOT-A TROJAN!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSDN for Windows NTmsdn.exe"Added by a variant of the RBOT WORM!"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
XMSDN for Windows with NT'smsdn-nt.exe"Added by the RBOT-EWD WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMSIdllwinmp.exe"Added by a variant of the RBOT WORM!"
XMSMSGSwinlogon.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
Xmsnwinlogon.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Media"
XMSN Administration For Windowsmsnadp32.exe"Added by the BROPIA.W WORM!"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
XMsn Messengwindns.exe"Added by a variant of the RBOT WORM!"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Registry loadermsmnwin.exe"Added by the KELVIR.FK WORM!"
NMSN Search ToolbarWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMsn Updaterwindatemanager.exe"Added by the SDBOT.TS WORM!"
XMsnExplorerwinagent.exe"Added by the BDOOR-EQ BACKDOOR!"
XMSNMSGRRswin.batIRC backdoor TROJAN or WORM!
Xmsnntwinampb.exe"Chinese originated adware - detected by Kaspersky as the AGENT.TL TROJAN!"
Xmsnntwinampf.exeAdded by the SMALL.DTS TROJAN!
XMsnWinmessagewin.exe"Added by the BANCBAN-D TROJAN!"
NMSN Toolbarmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSOleath32winss.exe"Added by the KATHER TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
XMSStartOptimizerWINUPD.EXE"Added by the DASMIN-E TROJAN!"
XMSWinmswin.exe"Added by the BANKER-CU TROJAN!"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
XMSWindowsUpdateSystern.exe"Added by the RBOT-AFD WORM!"
XMSWindowsUpdatemswinup.exe"Added by a variant of the SDBOT WORM!"
Nmswinextmswinext.exe"MSN Toolbar from version 4.* onwards (now known as Bing Bar from version 5.* onwards). This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XMSWinlogonSynCor.exe"Added by the AGENT-FZL TROJAN!"
XMSWinlogonwinlogon.exe"Added by the AGENT-FZM TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XMswinpid32mswinpid32.exeAdded by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMSWinupdwinupd.exe"Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMsWinVgrmsvgr.exe"Added by the MYTOB.LE WORM!"
XMS_NETD_WIN32netd32.EXE"Added by the RANDEX.F WORM!"
XMultimediawindebug.exe"Added by the VB-ERB WORM!"
Xmvsyswinaacsysiom.exe"Added by a variant of the SDBOT WORM!"
Xmysoftwinexplor.exe"Browser hijacker
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
XNAV Agentwinsnav.vbs"Added by the ANPES WORM!"
XNAV Auto Updatesnavwindows.exe"Added by a variant of the SDBOT WORM!"
NNB Windows PatternsWINDBKGND.EXE"Part of McAfee Nuts & Bolts. With Background Patterns
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
XNDIS Adapterwindows.exe"Added by the FORBOT-BR WORM!"
XNDIS AdapterWinman.exe"Added by the WOOTBOT.AG WORM!"
XNDplDeamonwinlogin.exe"Added by the RANDEX.E WORM!"
XNeroUpdater6.8winjava.exe"Added by the AGOBOT.AMK WORM!"
XNetWINREG.EXE"Added by the ASSASIN.D TROJAN!"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
UNetPatrolwinclient.exe"NetPatrol network monitoring software"
XNetworknetwin.exe"Added by the SILLYFDC-CG WORM!"
XNetwork Accesswinssh.exe"Added by a variant of the SDBOT WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Provisioning ServiceWinNPS.exeAdded by an unidentified WORM/TROJAN!
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
XNorton Personal Firewallwinmpts.exe"Added by the RBOT.ANT WORM!"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNorton Updaterwinset.exe"Added by a variant of the SPYBOT WORM!"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNT LM Security Support ProviderWinNTLM.exe"Added by a variant of the SDBOT WORM!"
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XNTSF MICROSOFT SYSTEMwinsis32.exe"Added by a variant of the RBOT WORM!"
XNTsocketNoeWinnt.exe"Added by the ATAKA-E TROJAN!"
Xnvc Win32nvcvc.exe"Added by the RBOT-ADD WORM!"
Xnvchostwinlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvCplwindowsp.exe"Added by a variant of the SDBOT WORM!"
XNvCplScanwinasp.exe"Added by the FORBOT.BZ WORM!"
XNVIDIA Media Center Librarywinlogon.exe"Added by the AUTORUN-AZK WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?OEPowerPlugswinoeinit.exe"??"
XOffica Monitor Secura Systemewinxp_sp3.exe"Added by a variant of the RBOT WORM!"
YOfficeScan95pccwin97.exe"Trend Micro antivirus OfficeScan"
XOKGOwinutade.exe"Added by the BANKER-EHZ TROJAN!"
YOneCareUIwinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XOptimize WindowsKuntilanak.exe"Added by the SILLYFDC WORM!"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XOS Securitymswind32.pif"Added by the RBOT-ASU WORM!"
XOSAwinword.exe"Added by the KANGAROO-A TROJAN!"
XPag Windows Monitorpag.exe"Added by the AGENT-EOT TROJAN!"
XPaRaY_VMwinlogon.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XPatches ValueWinGamed.exe"Added by the SDBOT.BR WORM!"
XPerforms peer to peer connectionWinPTTP.exe"Added by the RBOT-GMI WORM!"
XPmediawinsrvc.exe"Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!"
XPopMarkWinTask.exe"""Pop Marketing"" adware"
XPPPOEOEwinlite.exe"Added by the RBOT-AAN WORM!"
XPreInstall Windows[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
?ProgramWindowmore comp.exe"??"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
UQuick Hide Windowsqhw.exe"Quick Hide Windows from CronoSoft - ""provides a quick and easy way for home and office PC users to quickly get sensitive materials off the screen without closing programs or losing documents"""
XquickenWinrar.exe"CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!"
XQuicktime Mediaplayerwinmplyer32.exe"Added by the RBOT-PM WORM!"
XQuicktime Pro 3.0winuodps.exe"Added by the GAOBOT.BH WORM!"
XRandomWin32mgnwin32.exe"Added by the SDBOT-DV WORM!"
UReal Spy MonitorWinrsm.exe"Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
XRealTimeProtectorwinlogon.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
Xregdiitwinxp.exe"Added by the RUNAUTO.F WORM!"
Xregdiitwin.exe"Added by the VBSAUTO-A WORM!"
XRegDonewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XRegistry Checkupwinreg.exeAdded by an unidentified WORM or TROJAN!
XRegistry Checkup System326a MonitorWinregs326a.exe"Added by a variant of the SDBOT WORM!"
XRegistry Loaderwinhlpp32.exe"Added by the GAOBOT.AO WORM!"
XRegistry oidetwin32.exe"Added by the RBOT.BMT WORM!"
XRegistry Value Namewinapi32.exe"Added by a variant of the RBOT WORM!"
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XRegistryChkwinbackup.exe"Added by the MERTIAN WORM!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
URegRun WinBaitwinbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
XRemote Desktop Help Session ManagerWinRDH.exe"Added by a variant of the SDBOT WORM!"
XRemote Procedure Callwinrpc.exe"Added by the RBOT-KM WORM!"
XRemote Procedure Callwinsysrpc.exe"Added by the SDBOT-PS WORM!"
XRemote Procedure Call For Windows 32bitrpc.exe"Added by the RBOT-MD WORM!"
XRemote Procedure Callsmswinrpc.exe"Added by the RBOT.KJ WORM!"
XRemote Procedure Callsmswinc.exe"Added by the RBOT-IT WORM!"
XRemote Procedure Callswin.exe"Added by the SDBOT-QI WORM!"
XREMOVE MEwindos.exe"Added by the SDBOT.EE WORM!"
XROOT_Machinewinlogon.exe"Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
Xrpc Win32shost32.exe"Added by the RBOT-ABL WORM!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
XRPCall_WIN2KKurawas.exe"Added by the BHARAT.A WORM!"
Xrpcda Win32rpcda.exe"Added by the RBOT-AEE WORM!"
XRPCserr32gwinlogon.exe"Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gWINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRpcxWindows Extensionsrpcxwinex.exe"Added by the RBOT.ACP WORM!"
XRsWinlsass.exe"Added by the DELCANTI-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""12053"" subfolder"
XRsWinlsass.exe"Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""4350"" subfolder"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xrun windowsservic.bat"Added by the REBOOT-AP TROJAN!"
Xrun32dllWINClock.exe"Added by an unidentified VIRUS
?run=win.ini"??"
Xrun=mouse_configurator.win"Added by the GAGGLE.E WORM!"
XRund1l32Winfi1e32.exe"Added by the MERTIAN WORM!"
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
XRundll32Windows.exe"Added by the QQPASS.E TROJAN!"
Xruningwin.exe"Added by the DELF-LC TROJAN!"
XRunProgwini.exe"Added by the OPTIX.04.D TROJAN!"
XRunWin[path to file]"Added by the BANKER-ES TROJAN!"
Xrunwin32runwin32.exe"Added by the ESEARCH-A TROJAN!"
XRUNWIN32runwin32.exe"Added by the VB-AET TROJAN!"
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
Xrunwinlogonwinlogon.exe"Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process
XSafeSafeWin.exe"Added by the FOCOSENHA TROJAN!"
XScheduIrwinagent.exe"Added by a variant of the SDBOT WORM!"
XSchedulerwinagent.exe"Added by the TACTSLAY.B TROJAN!"
Xsecure socket layerwins32a.exe"Added by an IRCBOT TROJAN!"
XSecurityWindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
XSecurity PatchWinUpdate32.exe"Added by the SDBOT-BM WORM!"
XSecurity PatchesWinLab32.exe"Added by the SDBOT-KB WORM!"
XService Clientwinsvcli.exe"Added by an unidentified WORM or TROJAN! See here"
XService MonitorWinOcx.exe"Added by the RBOT-AQJ WORM!"
XService Monitorwinxpser.exe"Added by the RBOT-BDF WORM!"
XService Processwinset.exe"Added by a variant of the SPYBOT WORM!"
XService SystemwindowsXP.exe"Added by the BANCOS-EL TROJAN!"
XServiceOptionMP3winamp.dll.exe"Added by the SAMSON-A TROJAN!"
XServiceswinread.exe"Added by an unidentified VIRUS
XServiceswindns.exe"Added by a variant of the RBOT WORM!"
Xserviceswindows32.exe"Added by the FLYVB-C WORM!"
XServices Start2odcwinst.exe"Added by the PYSKE-D WORM!"
XServices32 Startupwin32dll.exe"Added by the SDBOT-XO WORM!"
XServicewinHide32.exe"Added by the MSNVB-D WORM!"
XSevicewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
NSFPvzSFPWin.EXEVerizon Online Support Center - prompts for online updates
USfWinStartInfosfWinStartupInfo.exeSFIRM32 Online Banking software
Xshccdewinssled.exe"Added by the BUZUS.CQMU TROJAN!"
XSheduIerwinagent.exe"Added by the BDOOR-EB BACKDOOR!"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
XShellWin32.dll.exe"Added by the VB.BTX TROJAN!"
XShell Tray WindowShellTraywnd.exe"Added by the STULTDOR-A TROJAN!"
NShockwave InitSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
XShutDownWindows"Rundll32.exe UserExitWindows"
NSideWinderTrayV4SWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
USiS Windows KeyHookkeyhook.exe"Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
Xsis32winsos.exe"Added by the QQPASS.IA WORM!"
XSistray32win.bat"Added by the JUMPRED.A WORM!"
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
NSM56 Helper Win32 Utilitysm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
XSmansaAppwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsmcservwinsrv.exe"Added by the AGOBOT-OU WORM!"
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
XSMSERIALSTARTERwin32st.exe"Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
XsmsgerWin.exe"Added by a variant of the SDBOT WORM!"
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
XsoftIce Update 32wininits.exe"Added by the RBOT-ANB WORM!"
XSound SystemWinSound1.exe"Added by an unidentified VIRUS
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
Xspoolsvswincfy.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSpyExWinllogo.exe"Added by the PRSKEY-A WORM!"
XSpywareGuardwinproc32.exe"Startpage adware Trojan"
XSpywareGuardPluswinmm64.exeStartPage.ht homepage hijacker
Xsqserviceswins32.exe"Added by the PROGENT-B TROJAN!"
Xsrvwinlogon.exe"Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
USrv32WinSpyAgent4.exe"SpyAgent - monitoring software that creates records of everything people do on a computer
USrv32WinSvchost.exe"Realtime-Spy keystroke logger/monitoring program - remove unless you installed it yourself!"
USrv32Winsysdiag.exe"SpyAgent surveillance software. Uninstall this software unless you put it there yourself"
Usrv32winwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself remove it"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
Xssgrate.exewinerdir.exe"Added by the MITGLIEDER.O TROJAN!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xssgrate.exewintems.exe"Added by the MITGLIEDER.Q TROJAN!"
XSSK Servicewinssk32.exe"Added by the SOBIG.E WORM!"
Xssms.exewinn.exe"Added by the SDBOT-DHE WORM!"
XStartwindows.vbsHomepage hijacker
XStart Uppingwindupds.exe"Added by the SDBOT.AFH WORM!"
XStart Uppingwindupdts.exe"Added by a variant of the RBOT WORM!"
NStart Wingman Profilerlwtest.exe"Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer
NStart Wingman ProfilerLWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed
XstartkeyRunWinRaR.exeAdded by a variant of the BIFROSE-LV TROJAN!
Xstartkeywin32i.exe"Added by the BIFROSE-R TROJAN!"
XstartkeywinampXP.exe"Added by the BIFROSE-OY TROJAN!"
Xstartkeywinlogin.exe"Added by the BIFROSE-PM TROJAN!"
XStartupWinlogonStartupUnidentified malware
Xstartwinstartwin.exe"Added by the ANTIMAN.A WORM!"
Xstartwindowskeyuserrundle2.exe"Added by the JAVAKILLER TROJAN!"
Xstup1db0t_win.exe"Added by a variant of the IRCBOT BACKDOOR!"
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
USurfinGuard Prowinsfcm.exe"SurfinGuard Pro from Finjan - internet protection software
XSvcH0stWINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvchostwinhost.exe"Added by the LOLAWEB.A TROJAN!"
Xsvchostwinhelp.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xsvchostwin.exe"Added by the VBSAUTO-A WORM!"
Xsvchostwindowsrx.exe"Added by the AGOBOT-MZ WORM!"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
XSvcphpwinsslphp32.exe"Added by the AGOBOT-ABR WORM!"
XsvcsharewinampXP.exe"Added by the FUJACKS-J VIRUS!"
Xsvcwinprocess32[path to worm]"Added by the UPERING WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
Xsvwin32unninst32.exe"Added by the AGOBOT-NF WORM!"
USWdwinwd.exe"PC Security™ from Tropical Software - ""is the ultimate in computer security
XswingsysSWINGSYS.EXE"Added by the BANCOS-CX TROJAN!"
XSygate Personal FirewallWin32x.exe"Added by the RBOT-KZ WORM!"
XSygate Personal Firewallwins.exe"Added by the RBOT.AOB WORM!"
XSygate Personal Firewallwinxpstat.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Firewallwin31243.exe"Added by a variant of the IRCBOT TROJAN!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
XSymantec Antivirus professionalwindows .exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalWinhp32.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalwinudp.exe"Added by a variant of the WOOTBOT WORM! See here"
XSymantec Security Routine Addon for Microsoft Windowsnavpxaw32.exe"Added by the AGOBOT-GJ TROJAN!"
Xsyncmanwinsync.exe"Added by the MANCSYN-A TROJAN!"
XSyntaxwindows32.exe"Added by the SDBOT.CQ WORM!"
XSys29win***32.exe [* = random char]"EliteBar adware"
Usys32cmdsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
Usys32sqlsys32win.exe"Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XSysAwin***32.exe [* = random char]"EliteBar adware"
Xsysavwinav.exe"WinPC Antivirus rogue security software - not recommended
XSyscheckwin.htaBrowser hijacker
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSysctrlswin32dll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsysdirwinrun.exe"Added by the WINBUR.B WORM!"
Xsysdllwindll.exe"Added by the AUTORUN.ECT WORM!"
XSysInitwininit32.exe"Added by the XABOT WORM!"
XSysStartsyswin.exe 1"Added by the AUTORUN-EY WORM!"
XSystam13speedwin.exe"Added by the RBOT.GVH BACKDOOR!"
XSystemserwin.exe"Added by the LDPINCH-BN TROJAN!"
XSystemWINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
XSystemwindowsps.exe"Added by a variant of the RBOT WORM!"
XSystemwinupd.exe"Added by a variant of the SDBOT WORM!"
XSYSTEMwindmupdr.exe"Added by a variant of the RBOT WORM!"
XSystemkernelwind32.exe"Added by the VXIDL.FT TROJAN!"
XSystemkernelwind64.exe"Added by the DLOADER.DJD TROJAN!"
XsystemWinhelp.exe"Added by the IMAUT.CN WORM!"
XSystemwinipck.exe"Added by the RBOT-TK WORM!"
XSystem Checkwin_klr32.exe"Added by the DELF-DRA WORM!"
XSystem Document Applicationwins.exe"Added by the SDBOT.AUB WORM!"
XSystem Document Applicationwinsvc32.exe"Added by the SDBOT-VA WORM!"
XSystem Driverswingmt.exe"Added by the SDBOT-MG WORM!"
XSystem Information Managerwin.exe"Added by the SDBOT-MU WORM!"
XSystem Information ManagerwindowsNt.com"Added by the SDBOT-ND WORM!"
XSystem Managerwinsrv32.exeAdded by an unidentified WORM or TROJAN!
XSystem Manager Updateswinsvc.exe"Added by the AGOBOT.AEM WORM!"
XSystem Servicemsnwindows.exe"Added by the SPYBOT.YCL WORM!"
XSystem Update Servicewinupd32.exe"Added by the ADTODA-A TROJAN!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Update2winlogon.exe"Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process
XSystem Update2winspool.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem Updates Managerwinserv32.exe"Added by the AGOBOT-AGA WORM!"
XSystem32winds32.exe"Added by the DWNLDR-HFY TROJAN!"
Xsystem32lowinplay.exe"Added by the VB.FVJ TROJAN!"
XSystem32 Spoolwinint.exe"Added by the FORBOT-N WORM!"
XSystemAdministrationWincmp32.exe"Added by the ASYLUM TROJAN!"
Xsystemdll.dllwinsys32.exe"Added by the DELF.CP BACKDOOR!"
XSystemMigrationWinMedia.exe"Added by the KELVIR.EI WORM!"
XSystemRegWINREG.EXE"Added by the DEWIN.A TROJAN!"
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
XSystemTraylsvhostwinlk.exe"Added by a variant of the SPYBOT WORM!"
XSystemTrayWindowsupd.exe"Added by a variant of the IRCBOT TROJAN!"
XSystemWideHook for Windows NT%WinHook32.exe"Added by the MYDOOM.AC WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
Xsysthreadwinkernal.exe"Added by the LIAMED WORM!"
Usystraywinlogin.exe"KidControl surveillance software. Uninstall this software unless you put it there yourself"
XSysWinSysWin.exe"Added by the IRCCONTACT TROJAN!"
Xsyswinv6.exe"Added by the AGENT-ECM TROJAN!"
Xsyswin.txt[3 random letters].exe"Added by a variant of the SPYBOT WORM! See here"
Xsyswin32syswin32.exe"Added by a variant of the SPYBOT WORM!"
XSyswindowSyswindow.exe"Added by the COW TROJAN!"
Xsysygm64winrxd64.exe"Added by the IRCBOT-RK TROJAN!"
XT4skM4n4g3rWink3sk9.exe"Added by a variant of the IRCBOT TROJAN!"
XTarefas do Windowstaskexec.exe"Added by the AGENT-LSD TROJAN!"
XTask managerUPDATEWIN.exe"Added by the RBOT.BBS WORM!"
XTask Manager Win32taskmngr32.exe"Added by the RANCK-EX BACKDOOR!"
XTaskmon driverwinampa.exe"Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
XTEXTCONVwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XThEwind0s.exeAdded by an unidentified WORM or TROJAN!
Xthis freewinsyst.exe"Added by the MADAG.A WORM!"
XTorjan ProgramWINLOGON.EXE"Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UTouch ManagerWinLED.exeDell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
NTourwincool.exe"Annoying WinMe component that prompt you to play the %Windir%\Application Data\Microsoft\INTROCONTENT.HTA file - that plays a full screen version of the WinMe product preview and cannot be stopped until it finishes to my knowledge. That prompt will keep popping up after an install/reinstall of WinMe until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes - and don't bother deleting that entry as Windows puts it right back. Not only should you disable it from running
UTrack4WinMonitorSTMonitor.exe"Track4Win Monitor surveillance software. Uninstall this software unless you put it there yourself"
XTrayXwinppr32.exe"Added by the SOBIG.F WORM!"
XTsk Mng Hlpwins32.exe"Added by the AGOBOT-JB WORM!"
?Tweak ManagerWinManager.Exe"WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?"
XUndefinedwinter.exe"Added by the KILLAV.LW TROJAN!"
XUniversal Plug & Play devicesWinUPPD.exeAdded by an unidentified WORM/TROJAN!
XUpdade Windowswinlogom.exe"Added by the TONAX-A TROJAN!"
Xupdatewinis.exe"Added by the RBOT-VD WORM!"
XUPDATEWinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
XUpdateWinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
XUpdate Checkerwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XUpdate for Windows[various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe
XUpdate Servicewinu32.exe"Added by the RBOT-MG WORM!"
Xupdate servicewinx.exe"Added by a variant of the RBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdateCheckwinstall.exe"Added by the SPYBOT-CY WORM!"
Xupdater32winload32.exe"Added by the CULT.M WORM!"
Xupdatewinupdate.exe"Added by a variant of the SDBOT WORM!"
XUpdateWin[random filename]"Added by the IRCBOT.AZW BACKDOOR!"
XupdateWinssystrey.exe"Added by the RANDON WORM!"
Xupdatexwinwinxrpc.exe"Added by the AGOBOT-KJ WORM!"
Xupddateitwinit.exe"Added by the RBOT-MS WORM!"
XUpgrade Servicewinupd.exe"Added by the TOFGER-U TROJAN!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
XUpTimes serviceWinUp.exe"Added by the RBOT-AKB WORM!"
Xurudjeffniwinlogon.exe"Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XUSB 2.1 Driverwinupdate1.exe"Added by a variant of the RBOT WORM!"
XUSB Devicewin32usb.exe"Added by the FORBOT-BQ WORM!"
XUSBHWINFOmac.exe"Added by the LOWZONE-I TROJAN!"
XUSBHWINFO[path to trojan]"Added by the LOWZONE-I TROJAN!"
XUSBHWINFOsst6.exe"Added by the LOWZONE-I TROJAN!"
Xuserinitwinlogon.exe"Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xvbewin.vbe"Added by the LOSESLP-A WORM!"
Xvbwq cutewinnt.exe"Added by the MADAG.A WORM!"
XVideowinamp32.exe"Added by the AGOBOT-NG WORM!"
XVideo Poeswinii.exe"Added by the AGOBOT-CP WORM!"
XVideo Proceswinaps.exe"Added by the AGOBOT.HD WORM!"
XVideo Processwinasp.exe"Added by the AGOBOT-IS WORM!"
XVideo Processwincert32.exe"Added by the AGOBOT.JT WORM!"
XVideo Processwincrt32.exe"Added by the AGOBOT-GR WORM!"
XVideo Proeswinaii.exe"Added by the AGOBOT-FH WORM!"
XVIEW POINT DRIVERS FOR WIN32phqghu.exe"Added by a variant of the RBOT WORM!"
Xvirtualwinit.exe"Added by the MUGLY.A or MUGLY.B WORMS!"
Xvirtualwinprotect.exe"Added by the MUGLY.C WORM!"
Xvirtualwini.exe"Added by the RBOT-YX WORM!"
Xvirtual-iewinlogi.exe"Added by the RBOT-BJU WORM!"
Xvirtual-machinewinlogin.exe"Added by the RBOT-VU WORM!"
Xvirtual-machinewini.exe"Added by the RBOT-WR WORM!"
XVsamplewinxpsock.exe"Added by the SDBOT.BLK WORM!"
YVshwin32EXEVSHWIN32.EXEFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
XW1N32.DLLWINLOGON .exe"Added by the DROPPERFL.A TROJAN!"
XWCPCwintsvcc.exe"PurityScan adware"
XWCPIwintsvit.exe"PurityScan adware"
XWCPSWint**.exe [* = random char]"PurityScan adware"
XWCPTwintsvtr.exe"PurityScan adware"
XWEB DRIVERS FOR WIN32phqgh.exe"Added by a variant of the RBOT WORM!"
XWelcomewinconfig.exe"Added by the GIP.113.B1 TROJAN!"
Xwinregedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
Xwinxwinxrpc32.exe"Added by the AGOBOT-MV WORM!"
Xwinxwinxrpc.exe"Added by the AGOBOT-MV WORM!"
XWINehshell.exe"Added by the MYTOB-CQ WORM!"
XWINwindows.exe"Added by the REATLE.C WORM!"
Uwinhomesec.exe"Related to the Sentry Parental Controls software"
XWin Antispyware Centerav.exe"Win Antispyware Center rogue security software - not recommended
XWin Antivir 2008Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended
XWin Antivirus 2008Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended
UWin Chimeswinchi~1.exe"WinChimes - enhancement software for the system clock that runs in the system tray"
XWin CommWinComm.exe"Added by the WINCOM TROJAN!"
XWin Commandcommand32.exe"Added by the AGOBOT.XQ WORM!"
XWin Configwinconfig.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin CPUsysin.pif"Added by the RBOT-AXL WORM!"
Xwin ctl appwuctl.exe"Added by a variant of the SDBOT WORM!"
XWin Defragwindfrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defrag!windefrag.exe"Added by a variant of the SDBOT WORM! See here"
XWin Defragsdefrag.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWin Drivers SSLhpws.exe"Added by the IRCBOT.67098 WORM!"
XWin Drivers SSLTASKMAN4.exe"Added by a variant of the RBOT WORM!"
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin exe file managrcrss.exe"Added by the RBOT.CCI WORM!"
XWin FTPwintftp.exe"Added by the SDBOT-KE WORM!"
XWIN HOST PROCESSWIN HOST PROCESS.EXE"Added by the KEYLOGGER.CLONE TROJAN!"
XWin I5oahder[worm filename]"Added by the AGOBOT-DS WORM!"
XWin INI 32msrp32.exe"Added by the RBOT-FZC WORM!"
XWin l5oahderwinampa.exe"Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
XWin Loginwinlogin.exe"Added by the RBOT-AWE WORM!"
XWin Microsoft 98win14.exe"Added by the RBOT-AKX WORM!"
?win namestat.exe"??"
XWin Net Wks32netwks32.exe"Added by the RBOT.AA WORM!"
XWin Patchntldr.exe"Added by the SDBOT-GS WORM!"
XWin Process Updateswinupdates.exe"Added by a variant of the SDBOT WORM!"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN prosessor16[random filename].exe"Added by a variant of the SDBOT WORM!"
XWin Proxy32 Protocolbsvtem.exe"Added by a variant of the SDBOT WORM!"
XWin Secure Update[random filename]"Added by the RBOT-AGI WORM!"
XWin Securitymsw32.pif"Added by the RBOT-AQT WORM!"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWin Security 360WinSecurity360.exe"Win Security 360 rogue security software - not recommended
XWin Serverwinserv.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwupdt.exe"Added by the IMISERV.A TROJAN!"
XWin Server Updtwinserver.exe"Added by a variant of the IMISERV TROJAN!"
XWin Server Updtpxckdla.exe"IEPlugin adware"
XWin SSLSP2s.exe"Added by the RBOT.BBI WORM!"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
XWin StartupWINCFG32.EXE"Added by the SPYBOT-CL WORM!"
XWin Sync montrwinsyncupx.exe"Added by the RBOT.BYJ BACKDOOR!"
XWin TaskLoadermsgmr.exe"Added by the MYTOB.L WORM!"
Xwin updatewupda32.exe"Added by the SDBOT.J WORM!"
Xwin updatewapdate.exe"Added by a variant of the RBOT WORM!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
XWin Updatemsnmger.exe"Added by the RBOT-GDP WORM!"
Xwin updatewupdate.exe"Added by the RBOT-P BACKDOOR!"
XWin UpdaterWINUPDATER.EXE"Added by the RBOT.IP WORM!"
XWin Updator Servicesctfnom.exe"Added by a variant of the WOOTBOT WORM!"
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWIN USB 2.0winusb.exe"Added by a variant of the RBOT WORM!"
XWin USB 2.0 USB DriverHPPrint.exe"Added by the SPYBOT.DNB WORM!"
XWIN USB SUPPORTgrxsrv.exe"Added by a variant of the RBOT WORM!"
XWin Validation ApplicationDBExecCom.exe"Added by the VBSILLY-A WORM!"
XWin WinAmpwinamp.exe"Added by the RBOT.AGF WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%. This file is located in %System%"
Xwin************* [* = random digit]win*************.exe [* = random digit]"WINBO adware"
XWIN-BUGSFIXWIN-BUGSFIX.EXE"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
Xwin-xpnvsc32.exe"Added by the BROPIA.N WORM!"
Xwin-xpwinis.exe"Added by the BROPIA.N WORM!"
Xwin.exewin.exe"Added by the PODROP-C TROJAN!"
Uwin16.dllwin16dll.exe"Screenspy captures screenshots silently. If you didn't install this yourself
Xwin23.exewin23.exe"Added by the BIFROSE.BSJ BACKDOOR!"
XWin2Drv[worm filename]"Added by the WINTOO WORM!"
XWIN32WIN32.EXE"Added by the RATEGA TROJAN!"
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
Xwin32Setup_32.exe"Added by the EVILBOT.B TROJAN!"
XWin32Win32.exe"Added by the ISRAZ.A WORM!"
Xwin32winsrv32.exe"Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites"
Xwin32WinSetup.exe"Added by the EVILBOT.B TROJAN!"
XWin32system32.vbs"Added by the SWERUN VIRUS!"
XWin32Game.exe.vbs"Added by the SCAFENE WORM!"
XWin32arsetup.exeAdded by the SPAZBOX.A TROJAN!
Xwin32winhost.exe"Added by the BROPIA.J WORM!"
XWin32winnnit.exe"Added by a variant of the SDBOT WORM!"
XWin32msnsrv.exe"Added by a variant of the SDBOT WORM!"
XWin32sysmon.exe"Added by the MYTOB-HQ TROJAN!"
XWin32zaq.exe"Added by the RBOT-GCE WORM!"
XWin32 BiosWinbios.exe"Added by the SEMAPI-A WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Configurationvideosd32.exe"Added by the SDBOT.TT WORM!"
XWin32 Configurationdllhelp.exe"Added by the SDBOT.UL WORM!"
XWin32 Configurationmplayer.exe"Added by the FORBOT-BZ WORM!"
XWin32 Consolecmd.exe"Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWin32 Critical FileWin32.exe"Added by the RBOT-GUB WORM!"
XWIN32 DDOSSERdos.exe"Added by the KELVIR.F WORM!"
XWin32 Debug ManagerWin32Debug.exe"Added by a variant of the WOOTBOT WORM!"
XWin32 Debug Managermicrosoftupd.exe"Added by the RBOT-GRJ WORM!"
XWin32 Device LoaderWin32ldr.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Driversysmls.exe"Added by the MYTOB.JH WORM!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 DRK Driverwdrk32.exe"Added by the WOOTBOT.CY WORM!"
XWin32 exe filewinstr32.exe"Added by a variant of the SPYBOT WORM!"
XWin32 ExplorerExplorer32.exe"StartPa-MN homepage hijacker"
XWin32 Firewall Driverwinfw.exe"Added by a variant of the RBOT WORM!"
XWin32 Firewall Driverswinfirewall.exe"Added by the WOOTBOT.GX WORM!"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWin32 Help32 Servicewin32help.exe"Added by the DELBOT-U WORM!"
XWin32 Infowindowsnfo.exe"Added by a variant of the IRCBOT TROJAN!"
XWin32 Information Servicecrsrs.exe"Added by the RINBOT.Y WORM!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 Kernel core componentKernel32.pif"Added by the MOKS VIRUS!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWin32 Ms Auto UpdaterAutomsUPD.exe"Added by a variant of the RBOT WORM!"
XWin32 NDISNdiswin.exe"Added by the RBOT.AMG WORM!"
XWin32 NDIS Driverxpndis.exe"Added by a variant of the RBOT WORM!"
XWin32 NDIS DriverNdistcp.exe"Added by the WOOTBOT.EU WORM!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 NT Adv Servicestaskmngr.exe"Added by the RBOT-ADE WORM!"
XWin32 nvcnvcva.exe"Added by the RBOT-ABF WORM!"
XWin32 NVIDIA DriverMSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
Xwin32 regeditmsn32.exeAdded by an unidentified WORM or TROJAN!
XWin32 Rundll LoaderRundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 Security Protocolsecure32.exe"Added by the RBOT-ETI WORM!"
XWin32 Security Servicecrsss.exe"Added by the DELBOT-O WORM!"
Xwin32 security updates downloadertskmngr.exe"Added by a variant of the SDBOT WORM! See here"
XWin32 Servicebazzi.exe"Added by the AHKER.E WORM!"
XWin32 Service[trojan filename]"Added by the AGENT-GBO TROJAN!"
XWin32 Servicesodbc32.exe"Added by the SPYBOT-EK WORM!"
XWin32 Serviceswuamngr.exe"Added by the SDBOT-N WORM!"
XWin32 Services Configwinwkys.exe"Added by the RBOT.BKY WORM!"
XWin32 Services1wuamngr1.exe"Added by the SDBOT-PV WORM!"
XWin32 Src Servicewin32src.exe"Added by the RBOT-SX WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
Xwin32 system serverwinserver.exe"Added by the DERMON-A TROJAN!"
XWin32 System Spoolspoolsvc.exe"Added by the SDBOT.UK WORM!"
XWin32 Testbleatest.exe"Added by a variant of the RBOT WORM!"
XWin32 Updatesvchosts.exe"Added by a variant of the SDBOT WORM!"
XWin32 Updatedl32.exeAdded by an unidentified WORM or TROJAN!
Xwin32 update servicesvchostt.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32 USB Drivermvsecn.exe"Added by the FORBOT-BK WORM!"
XWin32 Usb Driversvhosint32.exe"Added by the FORBOT-BE or FORBOT-J WORMS!"
XWin32 Usb Driverusb32.exe"Added by the SDBOT-OV WORM!"
XWin32 Usb DriverAvpG.exe"Added by the FORBOT-BX WORM!"
XWin32 USB Driverrundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWin32 USB2wins32.exe"Added by a variant of the RBOT WORM!"
XWin32 USB2 Driverwin32usb.exe"Added by the SPYBOT.DHV WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32 USB2 Driversys32.exe"Added by the WOOTBOT.X WORM!"
XWin32 USB2 Driversys32snd.exe"Added by the FORBOT-AN WORM!"
XWin32 USB2 Driverwind32.exe"Added by the FORBOT-AH WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2 Driverupdatemgr.exe"Added by a variant of the FORBOT WORM!"
XWin32 USB2 Driverwinsnd32.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Drivermsn.exe"Added by the FORBOT-EX WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWin32 USB2 Driveralgg.exe"Added by the TIBS.BF WORM!"
XWin32 USB2 Driverusb2.exe"Added by the FORBOT-Y WORM!"
XWin32 USB2 Driverwinusb32.exe"Added by the FORBOT-M WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
XWin32 USB3 Driverwin32tool.exe"Added by a variant of the RBOT WORM!"
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XWin32 Word Servicesmsword32.exe"Added by a variant of the RBOT WORM!"
Xwin32.exewin32.exe"Added by the STARTPAGE TROJAN!"
XWin32.exeWin32.exe"Added by the AWQ.A TROJAN!"
XWin32.Exploit.mzHmzrun.exe"Added by the PAINTER TROJAN!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
Xwin3208022-1336687win3208022-1336687.exe"Added by the VB-CFG TROJAN!"
XWin32BaseServiceMODWintask.exe"Added by the NAVIDAD WORM!"
Xwin32betawin32sys4.exe"Added by the BANKER-DA TROJAN!"
Xwin32clfwin32clf.exe"Added by an unidentified VIRUS
Xwin32debugwin32debug.exe"Added by the GUDEB WORM!"
XWin32DLLWin32DLL.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
XWin32dllWin32dll.exe"Added by the BANPAES TROJAN!"
XWIN32DSclienttimer.exe"Eziin adware"
XWin32GKernel32.com"Added by the ESTRELLA TROJAN!"
XWin32GScandisk.com"Added by the ESTRELLA TROJAN!"
Xwin32gbwin32gb.exe"Added by the DLUCA-F TROJAN!"
XWin32Host Processwebemir.exe"Added by the TURGEN -A TROJAN!"
Xwin32infowin32info.exeAdult content dialler
Xwin32inisystroy.exe"Added by the IRC.ALADINZ.C TROJAN!"
XWIN32ioclienttimer.exe"Eziin adware"
Xwin32Kernelfindx.exe"Added by the BANLOA-EY TROJAN!"
XWin32KernelStartmicrosoft.exe"Added by the DELF-EWZ TROJAN!"
XWin32RServer.com"Added by the ESTRELLA TROJAN!"
XWIn32S Java DLLkavsvx.exe"Added by the AGOBOT-RZ WORM!"
Xwin32servdevicer.exe"Added by the CHECKOUT WORM!"
Xwin32servservicesetup.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servsystemdevices.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
Xwin32servvload.exe"iSearch adware"
Xwin32servvms1.exe"iSearch adware"
YWIN32SLWin32sl.exe"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
XWIN32SNDSbanc.exeAdded by an unidentified WORM or TROJAN!
XWin32system[random filename]"Added by the DDV.B WORM!"
XWin32Systemwin32s.exe"Added by the MYDOOM.V WORM!"
XWin32SystemMonitor***.exe [* = random char]Browser hijacker
XWin32SysVxin.exe"Added by the FORBOT-EO WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
XWin32UpdaterKERNAL32.EXE"Added by the SPYBOT-OK WORM!"
Xwin32uswin32us.exeAll-In-One-Telcom (adult content dialler) variant
Xwin32usbdssrs.exe"Added by the RBOT-RA WORM!"
XWin32UsrWinCab.exe"Added by the DEDMIR-A WORM!"
XWIN32WNsystem_wc.exe"Eziin adware"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWin386Win386.exe"Added by the GOSUSUB VIRUS!"
XWin386sp32.dllHomepage hijacker. Not a dll but a regfile in disguise
XWIN3S2SNDSwinabsmod.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
XWIN3S2SNDSwiniprtx.exe"Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX""
XWin64 Compatibility Checkload win64.drv"CoolWebSearch parasite variant"
XWIN95DEFVIEW[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
Xwin98 DNSwingrd.exe"Added by a variant of the RBOT WORM!"
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
XWinAblewinable.exe"Added by the MATCASH.BG TROJAN!"
XWinAC v4klsuicbn.exe"Added by the FORBOT-CS WORM!"
UWinacsrWinacsr.exe"AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XwinactiveWINACTIVE.EXE"WinActive variant of the LOP.com hijacker"
XWinActiveJWinActiveJ.exeAdded by the ROTARRAN VIRUS!
XWinad ClientWinad.exeWinAd adware by eXact Advertising
XWinAdCnt.exeWinAdCnt.exe"Added by the BANKER-BU TROJAN!"
Xwinadmwinadm.exe"Browser hijacker - redirecting to Search-World.net. Related to the SMALL.AEX TROJAN!"
?WinAgentWinAgent.exe"Standard Life Insurance program. Is it required at startup?"
XWinahlp.exeWinahlp.exe"Added by a variant of the VAGRNOCKER TROJAN!"
Xwinallapwinallap.exe"Added by the DELF.E TROJAN!"
Xwinallapuwinallapu.exe"Added by the DELF.E TROJAN!"
XWinammpmccm.exe"Added by the IRCBOT-HH BACKDOOR!"
XWinampwinamp.htaHijacker - re-directing to adult content sites. Note - this isn't the real Winamp
XWinampwinamp.exe"Added by the AGOBOT.XI WORM! Note - this is NOT the popular Winamp media player"
XWinAMPwinamp62.exe"Added by the SDBOT-WN WORM!"
NWinampwinamp.exe"Winamp media player. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinamp Agentwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player. The valid filename for the Winamp Agent is ""winampa.exe"" - see here"
XWinamp Agentcvscc.exe"Added by the AGOBOT-GK WORM!"
XWinamp Mediaqmedia.exe"Added by the DIAZMON-A TROJAN!"
XWinamp media playerwinapa.exe"Added by an unidentified VIRUS
XWinamp Media Playerwinamap.exe"Added by the SDBOT.ACJM BACKDOOR!"
XWinamp Media Playerwinamp.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of %ProgramFiles%"
XWinAmp Playerwinampp.exe"Added by the RBOT-AQI WORM! Note - this is NOT the popular Winamp media player which has a different filename"
XWinamp Player 6Winamp6.exe"Added by a variant of the SPYBOT WORM!"
UWinamp to Google Talkwinamptogoogletalk.exe"Winamp to Google Talk
XWinamp Updateyhn.exe"Added by the SDBOT-ACR WORM!"
UWinampaWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinampawinampa.exe"Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
XWinampa AgentWINAMPA.EXE"Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which is normally located in %ProgramFiles%\Winamp. This one is found in %System%"
UWinampAgentWINAMPa.exe"Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
XWinAmpAgentMsexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentShch.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentsvchst.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentWinagent.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XWinAmpAgentsdhch.exe"Added by the TACTSLAY.B TROJAN!"
XWinAnonymousGDC.exe"WinAnonymous rogue privacy tool - not recommended
XWinAntiSpyware 2005was5.exe"WinAntiSpyware 2005 rogue spyware remover - not recommended
XWinAntiSpyware 2006was6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Freewas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2006 Scannerwas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
XWinAntiSpyware 2007was7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntiSpyware 2007 Freewas7.exe"WinAntiSpyware 2007 rogue spyware remover - not recommended"
XWinAntispyware2008WinAntispyware2008.exe"WinAntiSpyware 2008 rogue spyware remover - not recommended
XWinAntivirusAVSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XWinAntiVirus Pro 2007WinAv.exe"WinAntiVirus Pro 2007 rogue security software - not recommended
XWinAntiVirusPro2006WinAV.exe"WinAntiVirus Pro 2006 rogue security software - not recommended
XWinApiwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XWINAPLOGUPDWINAPLOGUPD.EXE"Added by the CAPSIDE-C WORM!"
XWinappwinpup32.exeProduces popup ads to adult content sites
XWinApp32msapp.exe"Added by the RSBOT TROJAN!"
UWinAppLogsvchost.exe"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XWinAuthwinlogon.exe"Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWinAvXWinAvX.exe"Added by the VIRANTIX TROJAN!"
XWinAvXWinAvXX.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the SPYWAD-AR TROJAN!"
XWinAwkWinAwk.exe"Added by the SDBOT-AYF WORM!"
UWinBackup SchedulerWbsched.exe"LIUtilities WinBackup scheduler - backup software"
UWinBarWinBar.exe""WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls""
Xwinbar.pifpacke.pif"Added by the RBOT-AVI WORM!"
XWinbedwinbed.exeHijacker
XWinbinswchost.exe"Added by the RBOT.CLS WORM!"
Xwinbin32win32exe.exe"Added by the RBOT-ZL WORM!"
XWinBlueSoftWinBlueSoft.exe"WinBlueSoft rogue spyware remover - not recommended
Xwinbo32winbo32.exe"Added by the RBOT-GRU WORM!"
Xwinbootwinboot.exe"Added by the BANLOAD-W TROJAN!"
Xwinbotwinbot.exe"Added by the MIDRUG-A TROJAN!"
UWinBrushwinbrush.exe"WinBrush - ""handy tool that keep your privacy and make your system clean. It works by cleaning up your tracks (document histories
XWinButlerWinButler.exeIdentified as a variant of the Trojan-Dropper.Agent.DKN malware
Xwincfgsyscnfg.exe"Added by an unidentified VIRUS
XWinCheckservices.exe"Added by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the ""Startup Item"" field"
XWinCheckWinCheck.exe"Added by the PWS-CY TROJAN!"
XWinCheckservices.exe"Added by the SOBER.S WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft"
XWinCheckcheck.exe"Added by the DELBOT-Y WORM!"
Uwinchkwinchk.exe"RemoteSpy surveillance software. Uninstall this software unless you put it there yourself"
Xwinchostwinchost.exe"Added by the DLOADER-PO TROJAN!"
NWINCINEMAMGRWINCIN~1.EXE"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NWinCinemaMgrWinCinemaMgr.exe"WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
UWINCINEMAMGRWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
Xwincleanwinclean.exe"Added by the AGENT.GXR TROJAN!"
Xwincls"rundll32.exe wincls.dllstart"
Xwincmapwincmapp.exe"CasClient adware variant - also detected as the CMAPP TROJAN!"
UWinColorReminderWinColorReminder.exe"The Microsoft Color Control Panel Applet for Windows XP ""helps you manage Windows color settings in one place."" Part of the Pro Imaging Powertoys"
Xwincomvbrun6win.exe"Added by the AGOBOT-AFK WORM!"
XWinConfig9324wincfgkop9.exe"Added by the RBOT.BVD WORM!"
Xwinconnvbrun6nt.exe"Added by the AGOBOT-AEI BACKDOOR!"
XWinCore32.exeWinCore32.exe"Added by the CLICKER-EN TROJAN!"
Xwincrt.exe[path to worm]"Added by the STRATIO-HA WORM!"
XWinCRT32wincrt32.exe"Added by the DOGBOT-D WORM!"
XWinCSRSSMSGRT32.EXE"Added by the REWINDO-A TROJAN!"
Xwinctlwinctl.exe"Added by the IRCBOT-YI TROJAN!"
XWINCXwincore332.exe"Added by the AGOBOT-MG WORM!"
XWind Logd Fileservicelogd.exe"Added by a variant of the RBOT WORM!"
XWind OptimizerWindOptimizer.exe"Wind Optimizer rogue system optimization tool - not recommended
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
XWind Securitymswi32.pif"Added by the RBOT-ARH WORM!"
Xwind.exewind.exe"Added by the MITGLIEDER.BD TROJAN!"
XWIND0WSWIND0WS.exe"Added by the SPYBOT.DQ WORM!"
XWIND0WSmella.bat"Added by the ALLEM WORM!"
XWind0wswordpad.exe"Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
XWind0ws Ser7ice Agentcolwindos.exe"Added by the RBOT-GQO TROJAN!"
XWind0ws Sharingssprotecter.exe"Added by the RBOT-AHW WORM!"
XWind32Wind32.exeIdentified as a variant of the Backdoor.Win32.Poison.avs malware
XWinDataservices.exe"Added by the SOBER-AD WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\PoolData and note the space at the beginning of the ""Startup Item"" field"
NWinDateswindates.exe"WinDates is a calendar
Xwindbswinxtc.exe"Added by the AGOBOT-WD WORM!"
XWindewinde.exe"Added by the DLUCA TROJAN!"
XwindefWin32sp.vbs"Added by the ANPES WORM!"
Xwindefwindef.exe"Added by the WURMARK-O WORM!"
Xwindefenderwindefender.exe"Added by the AGENT.BYH TROJAN!"
XWinDefender 2008WDefDemo.exe"WinDefender 2008 rogue privacy program - not recommended
XWinDefender2009windef.exe"WinDefender 2009 rogue security software - not recommended
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
XWinDevilsWinDevils.exe"Added by the BRONTOK-BS WORM!"
Xwindhost.exeosrwin32.exe"Added by the BANKER-CB TROJAN!"
Xwindhost.exewindhost.exe"Added by the BANKER-BV TROJAN!"
Xwindhost.exewinos.exe"Added by the PWSAGENT-A WORM!"
Xwindirwinrun.exe"Added by the WINBUR.B WORM!"
XWindir Workingwuaumqr1.exe"Added by a variant of the IRCBOT TROJAN!"
XWinDirectoriestdirs.exe"Added by the VB-EPB VIRUS!"
XWindllWindll.exe"Added by the TRYNOMA TROJAN!"
UWINDLLWSYS.EXE"STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes
Xwindllwindll32.exe"Added by the ASTEF or RESPAN WORMS!"
Xwindllwindotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
XWinDLL (algs.exe)"rundll32.exe algs.exestart"
XWinDLL (aqls32.exe)aqls32.exe"Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""aqls32.exe"" file is found in %System%"
XWinDLL (asdfsa.exe)"rundll32.exe asdfsa.exestart"
XWinDLL (bee.dll)"rundll32.exe bee.dllstart"
XWinDLL (bix.exe)"rundll32.exe bix.exestart"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (ctfmonm.exe)"rundll32.exe ctfmonm.exestart"
XWinDLL (dasda.com)"rundll32.exe dasda.comstart"
XWinDLL (diem.exe)"rundll32.exe diem.exestart"
XWinDLL (dlfksdld.exe)"rundll32.exe dlfksdld.exestart"
XWinDLL (jbi32.dll)"rundll32.exe jbi32.dllstart"
XWinDLL (lcass.exe)"rundll32.exe lcass.exestart"
XWinDLL (mysnlive.exe)"rundll32.exe mysnlive.exestart"
XWinDLL (ProsFix.exe)ProsFix.exe"Added by a variant of the IRCBOT BACKDOOR! The ""ProsFix.exe"" file is found in %System%"
XWinDLL (qwex.dll)"rundll32.exe qwex.dllstart"
XWinDLL (redyLive.exe)"rundll32.exe redyLive.exestart"
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWinDLL (service.exe)service.exe"Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
XWinDLL (slmss.exe)"rundll32.exe slmss.exestart"
XWinDLL (slsass.exe)"rundll32.exe slsass.exestart"
XWinDLL (smaprnter.exe)"rundll32.exe smaprnter.exestart"
XWinDLL (smms.exe)"rundll32.exe smms.exestart"
XWinDll (sslms.exe)"rundll32.exe sslms.exestart"
XWinDLL (start0s.exe)"rundll32.exe start0s.exestart"
XWinDLL (steam.dll)"rundll32.exe steam.dllstart"
XWinDLL (svc.exe)"rundll32.exe svc.exestart"
XWinDLL (svchost.dll)"rundll32.exe svchost.dllstart"
XWinDLL (sysx32.dll)"rundll32.exe sysx32.dllstart"
XWinDLL (tepmlayer.exe)"rundll32.exe tepmlayer.exestart"
XWinDLL (tmp.exe)"rundll32.exe tmp.exestart"
XWinDLL (tock24.dll)"rundll32.exe tock24.dllstart"
XWinDLL (tqurity.exe)"rundll32.exe tqurity.exestart"
XWinDLL (v4mon.dll)"rundll32.exe v4mon.dllstart"
XWinDLL (vdm32.dll)"rundll32.exe vdm32.dllstart"
XWinDLL (vxd32.dll)"rundll32.exe vxd32.dllstart"
XWinDLL (wchshield.exe)"rundll32.exe wchshield.exestart"
XWinDLL (wimimi.exe)"rundll32.exe wimimi.exestart"
XWinDLL (windns32.dll)"rundll32.exe windns32.dllstart"
XWinDLL (wingatey32.exe)"rundll32.exe wingatey32.exestart"
XWinDLL (wintmp.exe)"rundll32.exe wintmp.exestart"
XWinDLL (Wseclayer.exe)"rundll32.exe Wseclayer.exestart"
XWinDLL (wsync32.dll)"rundll32.exe wsync32.dllstart"
XWinDLL (xvd32.dll)"rundll32.exe xvd32.dllstart"
XWindll.exeWindll.exe"Added by the STEALER TROJAN!"
XWindll32Windll32.exe"Added by the MSNPWS TROJAN!"
XWinDll32_WIN32.EXE"Added by the LEGMIR.AQ TROJAN!"
Xwindllsys32.exewindllsys32.exe"Added by a variant of the MITGLIE-A TROJAN!"
XWinDNSwindns32.exe"Added by the GAOBOT.WX WORM!"
XWindo Servic Agenalirexe.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindo Servic Agent 32xagw.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindoes Kernelkernel32.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
XWindoFixWindoFix.exe"WindoFix rogue system error utility"
XWindos Seres Agnts[worm filename].exe"Added by the RBOT-GUN WORM!"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
XWindow LoaderDos32.exe"Added by the GAOBOT.AO WORM!"
XWindow Monitorwinmon32.exe"Added by the SDBOT.RT WORM!"
XWindow Msn Live Messangermsnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
XWindow service[random filename]"Added by the RBOT-ACH WORM!"
XWindow UDP Control Servicwinlogon.exe"Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindow upadatepe2.exe"Added by a variant of the RBOT WORM!"
UWindow WasherwwDisp.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
Xwindow.exewindow.exe"Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS!"
Xwindow2ssvchost.exe"Added by the IRCBOT.H TROJAN!"
Xwindow2ieupdate.exe"Added by the FORBOT-BM WORM!"
UWindowBlindswbload.exe"WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
XWindowEnhancerWinex.exe"SCBar foistware variant"
XWindowfdgfds DasdLL Verifierwinupdatr.exe"Added by the AGOBOT.HZ WORM!"
XWindowfdgfds DasdLL Verifiew[path to worm]"Added by the RBOT-GGX WORM!"
XWindowfdgfds DLL fgfdg VerifierWindowsdldfglcheckkk.exe"Added by the RBOT.CSP WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
UWindowFXwfxload.exe"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
Xwindownwiusyt.exe"Added by the QQPASS-M TROJAN!"
XWindowRegKey updatewins.exe"Added by the SPYBOT.I WORM!"
XWindowsservices.exe"Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the ""Startup Item"" field"
XWindowsKernel32.exe"Added by the TENDOOLF.A WORM!"
XWindowsmsdos98.exeAdded by the PWSTEAL TROJAN!
XWindowsWindows.exe"Added by the KAZMOR.A
XWindowsexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwindows[path to trojan]"Added by the AIMWIN TROJAN!"
Xwindowshkey.exe"Added by the GAOBOT.AFW WORM!"
Xwindowssystem copy.exe"Added by the SALGA.A WORM!"
XWindowsgearsec.exe"Added by the STUBBOT-B WORM!"
XWindowsrun.exe"Added by the SPYBOT.OFN WORM!"
XWindowssystem.exe"Added by the SPYBOT.OBB WORM!"
XWINDOWSwindows.exe"Added by the MONBOT-A TROJAN!"
XWindowsservices.exe"Added by the SOBER-Z WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity"
XWINDOWSjif.exe"Added by the MYTOB.MK WORM!"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindowsservices.exe"Added by the DLOADR-GW TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Windows"" subfolder"
XWindowssmss.exe"Added by the BANCBAN-QF TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xwindowssvchost.exe"Added by the SLOMIRC-A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWINDOWSymssgr.exe"Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft\Internet Connection Firewall (ICF)"
XWindowstaskmngr.exe"Added by a variant of the SDBOT WORM!"
XWindowsCfreer.exe"Added by the CULLER-C WORM!"
XWindowsZser.exe"Added by the CULLER-D WORM!"
XWindowsspoovlss.exe"Added by an unidentified WORM or TROJAN! See here"
XwindowsVBSyS.vbs"Added by the ROCK-D WORM!"
UWindowsWpcUmi.exe"Notifications from the Parental Controls feature in Windows Vista. Note - disabling this entry does not disable Parental Controls and prevent it monitoring a users activity. On the controller account it prevents the pop-up on from displaying messages such as ""Reminder: View the Parental Controls activity report"". On the user account it prevents the warning messages appearing such as access has been denied and the Parental Controls icon appearing on the System Tray"
UWindows & Internet Cleaner ProWICleaner.exe"Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows (random character)diskcheck.exe"Added by the SINGU.B TROJAN!"
XWindows .Net Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows 128 Modulewin128.exe"Added by the FORBOT-ES WORM!"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows 32 EditorWin32edit.exe"Added by the WOOTBOT.GQ WORM!"
XWindows 32 Rescuewin32resc.exe"Added by the FORBOT-EU WORM!"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
XWindows 32-bit DLL Integrity Verifierdllrun.exe"Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location"
UWindows Acceleratorssetup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XWindows Account Alternationwauclt.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows Actioncsrs.exe"Added by the SECCMU-A WORM!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows AdControlWinAdCtl.exeWindupdates adware variant
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows AdServiceWinAdServ.exeWindupdates adware variant
XWindows AdStatusWinStat.exe"Added by the BLESHARE!DR VIRUS!"
XWindows AdToolsWinAdTools.exeWindupdates adware variant
XWindows Anti VerifierWindows-Anti.exe"Added by the RBOT.ETT WORM!"
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti-Virus Built 32AntiVirus32.exe"Added by the SDBOT-BG WORM!"
XWindows APCI Verifierdhcpserv.exe"Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Application Layerwalg32.exe"Added by the AGOBOT.ATN WORM!"
XWindows Application Layer Gatewaywalg32.exe"Added by the AGOBOT-AAZ WORM!"
XWindows applications serverSysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
XWindows ARP Detectioncnvudlsp.exe"Added by the AGENT.LMW BACKDOOR!"
XWindows ARP Detectioncwinlogon.exe"Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ARP Detectioncxwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ASN Servicerge.exe"Added by the RBOT-AOK WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows ASN4 Servicesgamo.exe"Added by the RBOT-EHK WORM!"
XWindows Audiosnd.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Audio Layernarsvc.exe"Added by the IRCBOT.AFT BACKDOOR!"
XWindows Audio Panelnppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Servicesndmic32.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Servicesjvm.exe"Added by the ACKANTTA.F WORM!"
XWindows Audio Startupnndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
XWindows Audio Systemnndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xwindows auto updatemsblast.exe"Added by the BLASTER.B WORM!"
Xwindows auto updatepenis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
XWindows Auto Updatewinupdater.exe"Added by the SDBOT.TF WORM!"
XWindows auto updatebazzi.exe"Added by the AHKER.E WORM!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Automatic Updatewuamgrder.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updaterwindrg.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Automatical Updaterdcz.exe"Added by the RBOT.CXS WORM!"
XWindows AutomaticUpdaterrunddls.exe"Added by a variant of the RBOT WORM!"
Xwindows automationmslaugh.exe"Added by the BLASTER.E WORM!"
XWindows Automationmsdspr.exe"Added by the SOLAME.A WORM!"
XWindows Autostart Loadernotepad32.exe"Added by a variant of the RBOT WORM!"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Balang Dosyassistem.exe"Added by the MUZK WORM!"
XWindows Bootwinboot.exe"Added by the AGENT.HBD TROJAN!"
XWindows Bootwindowsboot.exe"Added by the IRCBOT.AZT BACKDOOR!"
XWindows Booterwinboot.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Booter!winbooter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Bootupms-wks32.exe"Added by the RBOT-AFM WORM!"
XWindows BootupSystemwks32.exe"Added by a variant of the RBOT WORM!"
XWindows Bootuptask-mngr.exe"Added by the RBOT-AWP WORM!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser ServicesBrowsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
XWindows Browser Servicesbrowsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows cfgascv.exe"Added by the AGOBOT-SZ BACKDOOR!"
XWindows Clean-Up ProWINDOWS CLEAN-UP PRO.Exe"Windows Clean-Up Pro spyware remover - not recommended
XWindows Cleaner Servicewinclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Clientclient.exe"Added by the BACKDR-AM BACKDOOR!"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Commandwincmd.exe"Added by the RBOT.ANV WORM!"
XWindows Communicatorwincomm.exe"Added by the AGOBOT-BH WORM!"
XWindows Communicator for NT/XPosndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows Computer Browserbcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Confwindowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ConfigSSYS.EXE"Added by the SPYBOT-DA WORM!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows ConfigZANBOR.EXE"Added by the SPYBOT-MH WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Config Managerwinconf.exe"Added by the RBOT-AIT WORM!"
XWindows Config ManagerWincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Configuratorwinconf.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ControlControl.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
XWindows ControlAdWinCtlAd.exeWindupdates adware variant
XWindows Controls Centerwinudmr.exe"Added by the LAMER.AA BACKDOOR!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows CPU hostwinbog32.exe"Added by a variant of the RBOT WORM!"
XWindows Critical Alertwincrt.exe"Added by the ALEDO-A TROJAN!"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows Data Serverautodisc.exe"Added by the SPYBOT-CB WORM!"
XWindows Data Server[random name].exe"Added by the SPYBOT-DS WORM!"
XWindows DatabaseWinDat.exeAdded by an unidentified WORM or TROJAN!
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows DDE Loaderwindde32.exe"Added by the SDBOT-UZ WORM!"
XWindows debug loggingwinlogg.exe"Added by the RBOT-OY WORM!"
XWindows debug loggingwinloggs.exe"Added by the RBOT-QN WORM!"
XWindows Debuggerwindbg.exe"Added by the FORBOT-BY WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggerwindbg32.exe"Added by the ZOTOB.L WORM!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Default Serverwfdmgrsp.exe"Added by the IRCBOT.BCX BACKDOOR!"
XWindows Default Serverwinampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows Defenderwdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Addswda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Monitorwdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWINDOWS DENEMEdeneme.exe"Added by the MYTOB-CR WORM!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Desktop Daemonwinpadg.exe"Added by a variant of the SPYBOT WORM!"
NWindows Desktop SearchWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
XWindows Dialup Servicedialup.exe"Added by the AGOBOT.AAH WORM!"
XWindows Disk Defragmenterwpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
XWindows Disk Managercmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Display Couplerdisplay.exe"Added by the IRCBOT-YS TROJAN!"
XWindows DLL hostwinupd32.exe"Added by a variant of the SPYBOT WORM!"
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderdefragfat32z.exe"Added by the LINKBOT.A WORM!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows DLL Loaderdefragfat32pi.exe"Added by the RBOT-QQ WORM!"
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows DLL Loaderdefragfatz.exe"Added by the LINKBOT.H WORM!"
XWindows DLL Loaderdefragfat32.exe"Added by the SDBOT-SS WORM!"
XWindows DLL Loaderdefragfat32abc.exe"Added by the RBOT-RG WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows DLL Loaderdefragfatx.exe"Added by the POEBOT-F WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows DLL Verifierxptl.exe"Added by a variant of the RBOT WORM!"
XWindows DLL Verifierwindlls.exe"Added by the RBOT-AZQ WORM!"
XWindows DNSwindns.exe"Added by the SDBOT-XU WORM!"
XWindows DNS Daemonwindnsd.exe"Added by the WOOTBOT.AS WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows DOSdosw.exe"Added by the SALAY-A WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Driver!windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Dynamic Library Cachedllcache.exe"Added by the INJECT-HT TROJAN!"
XWindows Dynamic Loading HeaderwinDLL32.exe"Added by a variant of the SDBOT WORM!"
XWindows Email Serverwmserv.exe"Added by the FOUNDU-AWORM!"
XWindows Enterprise DefenderWindowsEDefender.exe"Windows Enterprise Defender rogue security software - not recommended
XWindows Enterprise SuiteWE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
XWindows Essensialsmvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Event Detectionwecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Providerwposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Sectionsntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Executablewinmys.exe"Added by the RBOT-ABO WORM!"
XWindows Executerbling.exe"Added by the SDBOT-DFT WORM!"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
XWindows Explorerexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorerexplorer.pif"Added by the RBOT-AID WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorerexplorer32.exe"Added by a variant of the SDBOT WORM!"
XWindows ExplorerWindows Explorer.EXE"Added by the VB-EBA WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Explorer Keyexplorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
XWindows Explorer.exeExplorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Expresspci32b.exe"Added by the BUZUS.C TROJAN!"
XWindows Extensions for Win32winprgs32.exe"Added by the SDBOT.AFA WORM!"
NWindows Eyes??"For blind people
XWindows FAT 32WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows File Protectionwinprotect.exe"Added by the AGOBOT.JB WORM!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows File XP Managerwfdmgr.exe"Added by the SDBOT.XD TROJAN!"
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows FirewalLsess.exe"Added by a variant of the RBOT WORM!"
XWindows FirewallWindowsFirewall.exe"Added by the MYTOB.AO WORM!"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewallipservice32.exe"Added by a variant of the RBOT WORM!"
XWindows Firewallrundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Firewall Logwinlog.exeAdded by an unidentified WORM or TROJAN!
XWindows Firewall Managermsfw.exe"Added by the RBOT.WR WORM!"
XWindows firewall managerchh.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows firewall managermsguard.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows Firewall Servicewfsvc.exe"Added by the IRCBOT-YL WORM!"
XWindows Firewall Updaterupdatees.exe"Added by the RBOT-GBX WORM!"
XWindows Firewall Updatercronos.exe"Added by the RBOT-GBY WORM!"
XWindows Firewall Updaterctfcom.exe"Added by the RBOT-GCB WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsphost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllwinmu.exe"Added by a variant of the RBOT WORM!"
XWindows Fixintegator.exe"Added by the SDBOT.ZAB WORM!"
XWindows Fixerwinfix.exe"Added by the VIRUT-I VIRUS!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows FormatAdWinForm.exeWindupdates adware variant
XWindows Frame Worksfrmwrks32.exe"Added by a variant of the RBOT WORM!"
XWindows Frameworkfrmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
XWindows Frameworkscvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XWINDOWS FUCK BY CLASICfuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
XWindows Gamma Displaywingamma.exe"Antivirus 2010 rogue security software - not recommended
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Global Initngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows GMT32wingmt32.exe"Added by the MYTOB.KM WORM!"
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows GuardWAUMGRD.EXE"Added by the RBOT-GY WORM!"
XWindows Guard ProWindowsGP.exe"Windows Guard Pro rogue security software - not recommended
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
UWindows GuardianFawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows haz Layer[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Helpmailinfo.exe"Added by the MYTOB.JX WORM!"
XWindows HelpStney.exe"Added by the AGOBOT-VI WORM!"
XWindows Help Filewinhelper32.exe"Added by the SDBOT-QK TROJAN!"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Help Servicewinhlp.pif"Added by the RBOT-AKW WORM!"
?Windows Help SystemHelp.pif"??"
XWindows Helperwinhelp.exe"Added by the BANKER.APE TROJAN!"
XWindows Helperwsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Hijack Protectioncomngr.exe"Added by the AGENT-FYD TROJAN!"
XWindows Hijack Protection Systemcommngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
XWindows his LayerpilotGame.exe"Added by the RBOT.GLX WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Hostwinhost.exe"Added by the PRYSAT TROJAN!"
XWindows Host Booterhostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Namelmass.exe"Added by the GAOBOT.O WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows HP Drivershpdmws.exe"Added by the SDBOT.AQU WORM!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows HTTP serviceswinhttps.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Icons Managerwicomgr.exe"Added by the RBOT-AIF WORM!"
XWINDOWS ID SYSTEMwID32.exe"Added by the MYTOB.LN WORM!"
XWindows Identifysysays.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Imagewintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
XWindows Image Acquisition (WIASC)WIAcs.exe"Added by the RIZO.A TROJAN!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows installerwinstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
XWindows Installerntdll.exeAdded by an unidentified WORM or TROJAN!
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Internet Protocolwinproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
UWindows IP Securityipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
XWindows IP Security Serviceipsecs.exe"Added by the RBOT.BPW WORM!"
XWindows IPv6 Driverswipv6.exe"Added by the SDBOT-VJ WORM!"
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows JavaScript DaemonWinjsd.exe"Added by the WOOTBOT.AF WORM!"
XWindows Kernel 64kernal64.exe"Added by the YIMP-B WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows kev Messengermskev.exe"Added by the SDBOT-XV WORM!"
XWindows Keyboard Serviceswinkeyboard.exe"Added by the IRCBOT.AFS WORM!"
XWindows Keyboard Serviceswinkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Livemsgnms.exe"Added by the XPACK.AV TROJAN!"
XWindows LiveWindowsLive.exe"Added by the REALBOT-A WORM!"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
XWindows Live Clientmsnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
UWindows Live Family Safety Filterfsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XWindows Live Managerwinlivemgr.exe"Added by the SHEUR.EB TROJAN!"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows live Messengermsn.com"Added by the IRCBOT-AAV WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Live Messengermsnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
XWindows Live Messenger[random].exe"Added by the RBOT-GVL WORM!"
XWindows Live Messengermsnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
XWindows Live Messenger 8.12ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
XWindows Live Messenger Addonwllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgs!wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
YWindows Live OneCarewinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows Live Servicerusrserv.exe"Added by the SMALL.LU BACKDOOR!"
XWindows live Supportwlmsngr.exe"Added by the RBOT-BKL WORM!"
UWindows Live SyncWindowsLiveSync.exe"Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - ""a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers"""
UWindows Live OneCare Family Safetyfssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
?Windows Loadwindows.com"??"
XWindows Loaderwstart32.exe"Added by the GAOBOT.CA WORM!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
Xwindows LoadxmWin_.exe"Added by the FODDER-A TROJAN!"
XWindows Local ISPwinthcr.exe"Added by the SDBOT.ENZ BACKDOOR!"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
XWindows Locatorwsass.exe"Added by the IRCBOT.N TROJAN!"
XWindows Log Agentwinlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XWindows Loggerwinlog.exe"Added by the NSHADOW-B TROJAN!"
XWindows loggingwinlogd.exe"Added by the RBOT-ON WORM!"
XWindows loggingasgasg.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Logical Adapterwsrsvc.exe"Added by the IRCBOT.ARU BACKDOOR!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Loginexplored.exe"Added by the GAOBOT.SY WORM!"
XWindows Loginwinlog.exe"Added by the AGOBOT.MG WORM!"
XWindows Loginlmss.exe"Added by the AGOBOT-JA WORM!"
XWindows Loginmsnmsgr.exe"Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Loginlogin.exe"Detected by NOD32 as a variant of the BIFROSE TROJAN!"
XWindows Loginlms.exe"Added by the AGOBOT-IC WORM!"
XWindows Login Folderwinzep.exe"Added by the AGOBOT-TZ WORM!"
XWindows Login Managerwinlogin.exe"Added by a variant of the SDBOT WORM!"
XWindows Login Securitywinlogin.pifAdded by an unidentified WORM or TROJAN!
XWindows Login Servicewinlog.exe"Added by the RBOT-AFN WORM!"
XWindows Login Servicewinlogin.pif"Added by the SDBOT-ACU WORM!"
XWindows Logonwinlogin.exe"Added by the SPYBOT-C TROJAN!"
XWindows Logonwinlogon.exe"Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
XWindows Logon ApplicationWinIogon.exe"Added by the LINKBOT.M WORM!"
XWindows Logon Applicationlogon.exe"Added by the POEBOT-J WORM!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
XWindows Logon Applicationwinlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process
XWindows Logon Applicationwinamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XWindows Logon Applicationedcwinlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Applicatonedcwinlogon.exe"Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Managerlogon.exe"Added by a variant of the RBOT WORM!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
Xwindows logon procedurewinlogonpc.exe"Added by the WINLOGON TROJAN!"
XWindows Logon Servicewinlogon.pif"Added by the RBOT-AOU WORM!"
XWindows Logon Servicenapi32.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows LoL Layergqwdcr.exe"Added by the AGOBOT-AHS WORM!"
XWindows LoL Layerwin.exe"Added by the RBOT-FTO WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows LoL Layerpyvnpt.exe"Added by the RBOT-GKV WORM!"
XWindows LoL Layerwinlolx.exe"Added by the RBOT-FOR WORM!"
XWindows LoL Layerazypbrx.exe"Added by the RBOT-GMZ WORM!"
XWindows LoL Layerblvpnmcny.exe"Added by the RBOT-GOR WORM!"
XWindows Lord Anti-Viruswinlord32.exe"Added by the SDBOT-GW WORM!"
XWindows Management Informantwmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
XWindows Management Instrumentationmwd.exe"Added by the GRAPS WORM!"
XWindows Management Instrumentation[path to file]"Added by the QEDS-A WORM!"
XWindows Management Instrumentationswinmg.exe"Added by the GAOBOT.GW WORM!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Managerwinmants.exe"Added by the MANTAS WORM!"
XWindows Managerwinsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Managertaskmgrs.exe"Added by the SILLYFDC.BBZ WORM!"
XWindows Manager ControlWINMUR32.EXE"Added by the AGOBOT-AR WORM!"
XWindows Manager Update Inctgb.exe"Added by the SDBOT-ACM WORM!"
XWindows mangementwinlogonn.exe"Added by the RANDEX.FC WORM!"
XWindows Media APwinmapp.exeAdded by an unidentified WORM or TROJAN!
XWindows Media APPwmapp.exeAdded by an unidentified WORM or TROJAN!
NWindows Media Center"RunDLL32.exe ehuihlp.dllBootMediaCenter"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Media Drivermsnger.exe"Added by a variant of the RBOT WORM!"
XWindows Media Loaderwmloader.exe"Added by a variant of the GAOBOT WORM!"
XWindows Media Playerwmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
XWindows Media PlayerMediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermcafe32.exe"Added by the RBOT-YO WORM!"
XWindows Media Playerwmplayer.exe"Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XWindows Media Player50cent.exe"Added by a variant of the RBOT WORM!"
XWindows Media Playermpwe.exe"Added by the RBOT-TT WORM!"
XWindows Media Playermsams.exe"Added by the RBOT.AHR WORM!"
XWindows Media Playervmmreg32.exe"Added by the AGENT.AQO TROJAN!"
XWindows Media Playermsass43.exe"Added by the RBOT-RT WORM!"
XWindows Media Playermpupdata.exe"Added by the SDBOT.BBG WORM!"
XWindows Media Playerwmplayerc.exe"Added by the SILLYFDC.DBG WORM!"
XWindows Media Player 3.6wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 3.6bWMPA36B.EXE"Added by the RBOT-VV WORM!"
XWindows Media Player 3.6dwmpa36d.exe"Added by the RBOT-YA WORM!"
XWindows Media Player 3.9wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 6.1.2wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
NWindows Media Powerpoint HelperNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
XWindows Media Serverwmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Server!wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows media servicecrvss.exe"Added by the SDBOT.VP WORM!"
XWindows media servicecrsss.exe"Added by the RBOT.ACY WORM!"
XWindows media serviceSygate32.exe"Added by the RBOT.ADE WORM!"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Media Updatercrease.exe"Added by the RBOT-ATI WORM!"
XWindows Media UpgradeNeUpgrade.exe"Added by the RBOT.BMF TROJAN!"
XWindows Media Utilitywmediautil.exe"Added by a variant of the SPYBOT WORM!"
XWindows Memory Driversmemretain.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Managerwindowsmem.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
XWindows Memory Sharingmemoryshr.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Memory Sharingmemshr.exe"Added by the IRCBOT.MC BACKDOOR!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows messengermessengers.exe"Added by the MYTOB.EI WORM!"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messengermsnmsg.exe"Added by the SPYBOT.BV WORM!"
XWindows Messenger 4.14landisc.exe"Added by the SDBOT-KR WORM!"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Messenger Live MSNwinlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Messengerwinmsg.exe"Added by the VELKBOT.A WORM!"
XWindows Messenger Panelwbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Messenger Servicekaspersky.exe"Added by the MYTOB.HY WORM!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messenger Starterwmvsvc.exe"Added by the DELF.DAX TROJAN!"
XWindows MeTaLRoCk servicemetalrock.exe"Added by the TASTYRED TROJAN!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows Microsoft Verifierwinauth23.exe"Added by a variant of the RBOT WORM!"
UWindows Mobile Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UWindows Mobile-based device managementwmdSync.exe"Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships
UWindows Mobile-based device managementwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XWindows mod VerifierWindows-mod.exe"Added by the RBOT.DSU WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWindow2.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindowsLogon.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWwuamguard.exe"Added by the RBOT.EZJ WORM!"
XWindows modez Verifierwinlogom.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindows-.exe"Added by the RBOT-DIO WORM!"
XWindows modez Verifiertaskmngr.exe"Added by a variant of the RBOT WORM!"
XWindows modez Verifierwinl0g0z.exe"Added by the RBOT-FNB WORM!"
XWindows modez Verifierwuamgu