Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Autowxcknautowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUIWindowz.exe"Added by the RANDEX.AEV WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playerwimp.exe"Added by the RBOT-FN WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UMicrosoft Windows SidebarSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatawindows.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS windows Data list processMSDATLST.exeAdded by an unidentified WORM or TROJAN!
XMS Windows Executor ProcessMSEXECP32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Local DirectoryMSWLD32.exe"Added by a variant of the RBOT WORM!"
XMS Windows procces 32msprocces.exe"Added by the RBOT-AEZ WORM!"
XMS Windows Process ClassMSPRCSS32.exe"Added by the RBOT-YQ WORM!"
XMS Windows Process InitMSWPI32.exe"Added by the RBOT-ASQ WORM!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS Windows System AlertMSWSA32.exe"Added by the RBOT-BFN WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
XMSDN for Windows NTmsdn.exe"Added by a variant of the RBOT WORM!"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
XMSDN for Windows with NT'smsdn-nt.exe"Added by the RBOT-EWD WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWindows Syspgmspg32.exe"Added by the RBOT-TB WORM!"
NNB Windows PatternsWINDBKGND.EXE"Part of McAfee Nuts & Bolts. With Background Patterns
XNT Windows System Manager Loadercsrlss.exe"Added by the AGOBOT.OX WORM!"
XPag Windows Monitorpag.exe"Added by the AGENT-EOT TROJAN!"
XRemote Procedure Call For Windows 32bitrpc.exe"Added by the RBOT-MD WORM!"
XRpcxWindows Extensionsrpcxwinex.exe"Added by the RBOT.ACP WORM!"
USiS Windows KeyHookkeyhook.exe"Hotkey manager for Silicon Integrated Systems (SiS) based graphics chipsets - disable unless you use hotkeys"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
XSvchost Windows Remote Servicessvhost.exe"Added by the IRCBOT-IV WORM!"
Xsvhost windows servicessvhost8.exe"Added by the RBOT-WQ WORM!"
XSymantec Antivirus professionalwindows .exe"Added by a variant of the FORBOT WORM!"
XSystemWideHook for Windows NT%WinHook32.exe"Added by the MYDOOM.AC WORM!"
UWindows & Internet Cleaner ProWICleaner.exe"Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
XWindows (ICS) Spoolercrtss.exe"Added by a variant of the RBOT WORM!"
XWindows (random character)diskcheck.exe"Added by the SINGU.B TROJAN!"
XWindows .Net Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows 128 Modulewin128.exe"Added by the FORBOT-ES WORM!"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows 32 EditorWin32edit.exe"Added by the WOOTBOT.GQ WORM!"
XWindows 32 Rescuewin32resc.exe"Added by the FORBOT-EU WORM!"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
XWindows 32-bit DLL Integrity Verifierdllrun.exe"Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location"
UWindows Acceleratorssetup.exe"KeySpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XWindows Account Alternationwauclt.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Acer Serviceacersv.exe"Added by the IRCBOT.YFQ BACKDOOR!"
XWindows Actioncsrs.exe"Added by the SECCMU-A WORM!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows AdControlWinAdCtl.exeWindupdates adware variant
XWindows Additional GuardWI[random characters].exe"Windows Additional Guard rogue security software - not recommended
XWindows AdServiceWinAdServ.exeWindupdates adware variant
XWindows AdStatusWinStat.exe"Added by the BLESHARE!DR VIRUS!"
XWindows AdToolsWinAdTools.exeWindupdates adware variant
XWindows Anti VerifierWindows-Anti.exe"Added by the RBOT.ETT WORM!"
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti-Virus Built 32AntiVirus32.exe"Added by the SDBOT-BG WORM!"
XWindows APCI Verifierdhcpserv.exe"Added by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows API Control Taskapitsk32.exe"Added by the MYTOB.HI WORM!"
XWindows Application Layerwalg32.exe"Added by the AGOBOT.ATN WORM!"
XWindows Application Layer Gatewaywalg32.exe"Added by the AGOBOT-AAZ WORM!"
XWindows applications serverSysShield.exe"Added by the unregistered version of Personal Anti Malware rogue security software - not recommended
XWindows ARP Detectioncnvudlsp.exe"Added by the AGENT.LMW BACKDOOR!"
XWindows ARP Detectioncwinlogon.exe"Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ARP Detectioncxwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows ASN Servicerge.exe"Added by the RBOT-AOK WORM!"
XWindows ASN Service[random filename]"Added by the AGOBOT-TC WORM!"
XWindows ASN4 Servicesgamo.exe"Added by the RBOT-EHK WORM!"
XWindows Audiosnd.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Componentsnncsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Controlppnsvc.exe"Added by the HAM TROJAN!"
XWindows Audio Layernarsvc.exe"Added by the IRCBOT.AFT BACKDOOR!"
XWindows Audio Panelnppsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Audio Servicesndmic32.exe"Added by the ACKANTTA.C WORM!"
XWindows Audio Servicesjvm.exe"Added by the ACKANTTA.F WORM!"
XWindows Audio Startupnndsvc.exe"Added by the IRCBOT-AAE TROJAN!"
XWindows Audio Systemnndsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Authority Servicelsass.exe"Added by the KALEL-E WORM! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xwindows auto updatemsblast.exe"Added by the BLASTER.B WORM!"
Xwindows auto updatepenis32.exe"Added by the BLASTER (or MSBLAST.A) WORM!"
XWindows Auto Updatewinupdater.exe"Added by the SDBOT.TF WORM!"
XWindows auto updatebazzi.exe"Added by the AHKER.E WORM!"
XWindows auto updateLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Automatic Updatewuamgrder.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updaterwindrg.exe"Added by a variant of the RBOT WORM!"
XWindows Automatic Updatesdvldr.exe"Added by the RBOT.MF WORM!"
XWindows Automatical Updaterdcz.exe"Added by the RBOT.CXS WORM!"
XWindows AutomaticUpdaterrunddls.exe"Added by a variant of the RBOT WORM!"
Xwindows automationmslaugh.exe"Added by the BLASTER.E WORM!"
XWindows Automationmsdspr.exe"Added by the SOLAME.A WORM!"
XWindows Autostart Loadernotepad32.exe"Added by a variant of the RBOT WORM!"
XWindows backupsystemss.exe"Added by a variant of the SPYBOT WORM!"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Baþlangýç Dosyasýsistem.exe"Added by the MUZK WORM!"
XWindows Bootwinboot.exe"Added by the AGENT.HBD TROJAN!"
XWindows Bootwindowsboot.exe"Added by the IRCBOT.AZT BACKDOOR!"
XWindows Booterwinboot.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Booter!winbooter.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Bootupms-wks32.exe"Added by the RBOT-AFM WORM!"
XWindows BootupSystemwks32.exe"Added by a variant of the RBOT WORM!"
XWindows Bootuptask-mngr.exe"Added by the RBOT-AWP WORM!"
XWindows Browser Servicesbrowser128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser Servicesbrowser64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Browser ServicesBrowsr32.exe"Added by the IRCBOT.BUR BACKDOOR!"
XWindows Browser Servicesbrowsr64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows bypass security SMSS ServiceSbiCvy.exe"Added by the RBOT-GRF WORM!"
XWindows cfgascv.exe"Added by the AGOBOT-SZ BACKDOOR!"
XWindows Clean-Up ProWINDOWS CLEAN-UP PRO.Exe"Windows Clean-Up Pro spyware remover - not recommended
XWindows Cleaner Servicewinclean.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Clientclient.exe"Added by the BACKDR-AM BACKDOOR!"
XWindows Client Service 32csrss.exe"Added by the RBOT-ALB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a drivers\winsdriver subfolder"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows CODE Fix Msy Startupsmsyh32.exe"Added by the AGOBOT.AKK WORM!"
XWindows Commandwincmd.exe"Added by the RBOT.ANV WORM!"
XWindows Communicatorwincomm.exe"Added by the AGOBOT-BH WORM!"
XWindows Communicator for NT/XPosndyrn.exe"Added by the SDBOT-CPK WORM! Note - can terminate AV related processes"
XWindows Compliant[random filename]"Added by the RBOT-IR WORM!"
XWindows Computer Browserbcwsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Confwindowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ConfigSSYS.EXE"Added by the SPYBOT-DA WORM!"
XWindows Configwins.exe"Added by the SPYBOT.JR WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Configpvphost.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Configwinconfig.exe"Added by the IRCBOT.BAP BACKDOOR!"
XWindows ConfigZANBOR.EXE"Added by the SPYBOT-MH WORM!"
XWindows Config Connectionmsicll.exe"Added by the RBOT-EXQ WORM!"
XWindows Config LoaderWincfg32.exe"Added by the SILVERFTP TROJAN!"
XWindows Config Managerwinconf.exe"Added by the RBOT-AIT WORM!"
XWindows Config ManagerWincfgman32.exe"Added by the AGOBOT-AL BACKDOOR!"
XWindows Config Systemconfig.exe"Added by a variant of the SDBOT WORM!"
XWindows Configurationwsys32.exe"Added by the GAOBOT.FB WORM!"
XWindows Configurationwincfg32.exe"Added by the MYTOB.ED WORM!"
XWindows ConfigurationWINHUB.EXE"Added by the SPYBOT-CG WORM!"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Configuration Loadermsgfix.exe"Added by the SDBOT-NP WORM!"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWindows Configuratorwinconf.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Consolewkssvc.exe"Added by the SDBOT-DJX WORM!"
XWindows Console Componentwrasvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Monitor[path to worm]"Added by the KEDEBE WORM!"
XWindows Console MonitorgcasAV32.exe"Added by the KEDEBE-A WORM!"
XWindows Console Normswnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Console Sourcewnbsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows ControlControl.exe"Added by the GREK.A TROJAN! If there is another file with the same file name in the Windows folder
XWindows ControlAdWinCtlAd.exeWindupdates adware variant
XWindows Controls Centerwinudmr.exe"Added by the LAMER.AA BACKDOOR!"
XWindows Core Kernel Updatewin32bootcfg.exe"Added by the RANCK-EL TROJAN!"
XWindows CPU hostwinbog32.exe"Added by a variant of the RBOT WORM!"
XWindows Critical Alertwincrt.exe"Added by the ALEDO-A TROJAN!"
XWindows Custom ServicesCSRCS.EXE"Added by the SPYBOT-EI WORM!"
XWindows Data Serverautodisc.exe"Added by the SPYBOT-CB WORM!"
XWindows Data Server[random name].exe"Added by the SPYBOT-DS WORM!"
XWindows DatabaseWinDat.exeAdded by an unidentified WORM or TROJAN!
XWindows Databasewiinsvc.exe"Added by the AGOBOT-RU WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
XWindows DDE Loaderwindde32.exe"Added by the SDBOT-UZ WORM!"
XWindows debug loggingwinlogg.exe"Added by the RBOT-OY WORM!"
XWindows debug loggingwinloggs.exe"Added by the RBOT-QN WORM!"
XWindows Debuggerwindbg.exe"Added by the FORBOT-BY WORM!"
XWindows Debuggermsdbg32.exe"Added by a variant of the RBOT WORM!"
XWindows Debuggerwindbg32.exe"Added by the ZOTOB.L WORM!"
XWindows Debugging Toolsupdatecfg.exe"Added by the RBOT-AXU WORM!"
XWindows Default Configurationsvchost.exe"Added by the DLOADER-U TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Default Serverwfdmgrsp.exe"Added by the IRCBOT.BCX BACKDOOR!"
XWindows Default Serverwinampa.exe"Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows Defenderwdc*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Addswda*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Monitorwdm*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWindows Defender Updaterwdu*.exe"Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
XWINDOWS DENEMEdeneme.exe"Added by the MYTOB-CR WORM!"
XWindows Desktop Controlerwindesktop.exe"Added by the SDBOT-XH WORM!"
XWindows Desktop Daemonwinpadg.exe"Added by a variant of the SPYBOT WORM!"
NWindows Desktop SearchWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. On earlier versions this entry also runs the indexing function at startup which indexes files and e-mails items so you can quickly find words and phrases (replaced by a service in later versions). Disabling this entry does not affect the normal operation and indexing will occur when you next perform a search
XWindows Dialup Servicedialup.exe"Added by the AGOBOT.AAH WORM!"
XWindows Disk Defragmenterwpabaln32.exe"Added by the BANCOS-ASJ TROJAN!"
XWindows Disk Managercmnvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Display Couplerdisplay.exe"Added by the IRCBOT-YS TROJAN!"
XWindows DLL hostwinupd32.exe"Added by a variant of the SPYBOT WORM!"
XWindows DLL Hostdllhost32.exeAdded by an unidentified WORM or TROJAN!
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderdefragfat32z.exe"Added by the LINKBOT.A WORM!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows DLL Loaderdefragfat32pi.exe"Added by the RBOT-QQ WORM!"
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows DLL Loaderdefragfatz.exe"Added by the LINKBOT.H WORM!"
XWindows DLL Loaderdefragfat32.exe"Added by the SDBOT-SS WORM!"
XWindows DLL Loaderdefragfat32abc.exe"Added by the RBOT-RG WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows DLL LoaderWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows DLL Loaderdefragfatx.exe"Added by the POEBOT-F WORM!"
XWindows DLL Serviceswinsvc32.exe"Added by the RBOT-ZF WORM!"
XWindows DLL Servicessvchost.exe"AGENT.H spyware. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XWindows DLL Servicessystem.exe"AGENT.H spyware"
XWindows DLL Trackerspoolsrv.exe"Added by a variant of the WOOTBOT WORM!"
XWindows DLL Verifierxptl.exe"Added by a variant of the RBOT WORM!"
XWindows DLL Verifierwindlls.exe"Added by the RBOT-AZQ WORM!"
XWindows DNSwindns.exe"Added by the SDBOT-XU WORM!"
XWindows DNS Daemonwindnsd.exe"Added by the WOOTBOT.AS WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows DOSdosw.exe"Added by the SALAY-A WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Download Managerwindlmngr.exeAdded by an unidentified TROJAN!
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Driver!windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Dynamic Library Cachedllcache.exe"Added by the INJECT-HT TROJAN!"
XWindows Dynamic Loading HeaderwinDLL32.exe"Added by a variant of the SDBOT WORM!"
XWindows Email Serverwmserv.exe"Added by the FOUNDU-AWORM!"
XWindows Enterprise DefenderWindowsEDefender.exe"Windows Enterprise Defender rogue security software - not recommended
XWindows Enterprise SuiteWE[random characters].exe"Windows Enterprise Suite rogue security software - not recommended
XWindows Essensialsmvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Event Detectionwecsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Providerwposvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Sectionsntsvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Event Servicewinserv.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Executablewinmys.exe"Added by the RBOT-ABO WORM!"
XWindows Executerbling.exe"Added by the SDBOT-DFT WORM!"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows ExpIorer[random filename]"Added by the RBOT-AKO WORM!"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
XWindows Explorerexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorerexplorer.pif"Added by the RBOT-AID WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorerexplorer32.exe"Added by a variant of the SDBOT WORM!"
XWindows ExplorerWindows Explorer.EXE"Added by the VB-EBA WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Explorer Keyexplorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
XWindows Explorer.exeExplorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Expresspci32b.exe"Added by the BUZUS.C TROJAN!"
XWindows Extensions for Win32winprgs32.exe"Added by the SDBOT.AFA WORM!"
NWindows Eyes??"For blind people
XWindows FAT 32WINFAT32B.exe"Added by the SPYBOT-AGT WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows File Protectionwinprotect.exe"Added by the AGOBOT.JB WORM!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows File Verification Servicewfvs.exeAdded by the RANKY.AC TROJAN!
XWindows File XP Managerwfdmgr.exe"Added by the SDBOT.XD TROJAN!"
XWindows FileSharing Servicemcwsvc.exe"Added by the IRCBOT.AJF BACKDOOR!"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows FirewalLsess.exe"Added by a variant of the RBOT WORM!"
XWindows FirewallWindowsFirewall.exe"Added by the MYTOB.AO WORM!"
XWindows Firewallsvchost.exe"Added by the PROXY-HT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Firewallipservice32.exe"Added by a variant of the RBOT WORM!"
XWindows Firewallrundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Firewall Logwinlog.exeAdded by an unidentified WORM or TROJAN!
XWindows Firewall Managermsfw.exe"Added by the RBOT.WR WORM!"
XWindows firewall managerchh.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows firewall managermsguard.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows Firewall Servicewfsvc.exe"Added by the IRCBOT-YL WORM!"
XWindows Firewall Updaterupdatees.exe"Added by the RBOT-GBX WORM!"
XWindows Firewall Updatercronos.exe"Added by the RBOT-GBY WORM!"
XWindows Firewall Updaterctfcom.exe"Added by the RBOT-GCB WORM!"
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Firewalllsphost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllsvvhost.exe"Added by a variant of the RBOT WORM!"
XWindows Firewalllwinmu.exe"Added by a variant of the RBOT WORM!"
XWindows Fixintegator.exe"Added by the SDBOT.ZAB WORM!"
XWindows Fixerwinfix.exe"Added by the VIRUT-I VIRUS!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows FormatAdWinForm.exeWindupdates adware variant
XWindows Frame Worksfrmwrks32.exe"Added by a variant of the RBOT WORM!"
XWindows Frameworkfrmwrk.exe"Added by the DWNLDR-GWV TROJAN!"
XWindows Frameworkscvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XWINDOWS FUCK BY CLASICfuck.exe"Added by the ZOTOB.H or ZOTOB.J WORMS!"
XWindows Gamma Displaywingamma.exe"Antivirus 2010 rogue security software - not recommended
XWindows Generic Procprocmsg.exe"Added by the ALLIM.B WORM!"
XWindows Generic Serviceswinsvc32.exe"Added by the AGOBOT-ZF BACKDOOR!"
XWindows Genuinesvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Genuine Validatewinservicessss.exe"Added by the IRCBOT.UUI BACKDOOR!"
XWindows Global Initngpsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows GMT32wingmt32.exe"Added by the MYTOB.KM WORM!"
XWindows Graphics Loaderswingraphics.exe"Added by the SPYBOT.JG WORM!"
XWindows GuardWAUMGRD.EXE"Added by the RBOT-GY WORM!"
XWindows Guard ProWindowsGP.exe"Windows Guard Pro rogue security software - not recommended
UWindows Guardianthehel1iawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
UWindows GuardianFawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
XWindows haz Layer[5 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Helpmailinfo.exe"Added by the MYTOB.JX WORM!"
XWindows HelpStney.exe"Added by the AGOBOT-VI WORM!"
XWindows Help Filewinhelper32.exe"Added by the SDBOT-QK TROJAN!"
XWindows Help Managersvchost32.exe"Added by the RBOT-OZ WORM!"
XWindows Help Servicewinhelpsv.exe"Added by the RBOT-LP WORM!"
XWindows Help Servicewinhlp.pif"Added by the RBOT-AKW WORM!"
?Windows Help SystemHelp.pif"??"
XWindows Helperwinhelp.exe"Added by the BANKER.APE TROJAN!"
XWindows Helperwsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Hijack Protectioncomngr.exe"Added by the AGENT-FYD TROJAN!"
XWindows Hijack Protection Systemcommngr.exe"Added by a variant of the AGENT-FYD TROJAN!"
XWindows his LayerpilotGame.exe"Added by the RBOT.GLX WORM!"
XWindows Hosthosts.exe"Added by the KELVIR.U WORM!"
XWindows Hostwinhost.exe"Added by the PRYSAT TROJAN!"
XWindows Host Booterhostbooter.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Host Devicehostsvc.exe"Added by the ZOOTY-A WORM!"
XWindows Host Namelmass.exe"Added by the GAOBOT.O WORM!"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows Host Servicehost.exe"Added by the KELVIR.AN WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Host Servicesvchosts32.exe"Added by the KELVIR.AW WORM!"
XWindows Host32 Starterhostserv.exe"Added by the SDBOT-WU WORM!"
XWindows Hostshosts.exe"Added by the KELVIR-O TROJAN!"
XWindows Hostswinhosts.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows HP Drivershpdmws.exe"Added by the SDBOT.AQU WORM!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows HTTP serviceswinhttps.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Icons Managerwicomgr.exe"Added by the RBOT-AIF WORM!"
XWINDOWS ID SYSTEMwID32.exe"Added by the MYTOB.LN WORM!"
XWindows Identifysysays.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Imagewintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
XWindows Image Acquisition (WIASC)WIAcs.exe"Added by the RIZO.A TROJAN!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows IncontextInSearch.exe"PacerD_Media/Pacimedia.com/Z-Quest adware installer"
XWindows Insecure[path to worm]"Added by the RBOT-FSM WORM!"
XWindows installerwinstall.exe"SpySheriff malware. For more information on registry key changes see SPYWAD-E"
XWindows Installerntdll.exeAdded by an unidentified WORM or TROJAN!
XWindows Installer 1msnconfig.exe"Added by the PURITYSCN.B TROJAN!"
XWindows Instruction Serviceswinstruct32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Internet Protocolwinproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
UWindows IP Securityipsec.exe"Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
XWindows IP Security Serviceipsecs.exe"Added by the RBOT.BPW WORM!"
XWindows IPv6 Driverswipv6.exe"Added by the SDBOT-VJ WORM!"
XWindows Java UpdateweatherBug32.exe"Added by a variant of the RBOT WORM!"
XWindows JavaScript DaemonWinjsd.exe"Added by the WOOTBOT.AF WORM!"
XWindows Kernel 64kernal64.exe"Added by the YIMP-B WORM!"
XWindows Kernel System Servicewkssvr.exe"Added by a variant of the RANDEX.GEL WORM!"
XWindows kev Messengermskev.exe"Added by the SDBOT-XV WORM!"
XWindows Keyboard Serviceswinkeyboard.exe"Added by the IRCBOT.AFS WORM!"
XWindows Keyboard Serviceswinkeybrd.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Keyboard Serviceswinkeybrd32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Livemsgnms.exe"Added by the XPACK.AV TROJAN!"
XWindows LiveWindowsLive.exe"Added by the REALBOT-A WORM!"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
XWindows Live Clientmsnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
UWindows Live Family Safety Filterfsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XWindows Live Managerwinlivemgr.exe"Added by the SHEUR.EB TROJAN!"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows live Messengermsn.com"Added by the IRCBOT-AAV WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Live Messengermsnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
XWindows Live Messenger[random].exe"Added by the RBOT-GVL WORM!"
XWindows Live Messengermsnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
XWindows Live Messenger 8.12ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
XWindows Live Messenger Addonwllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgs!wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
YWindows Live OneCarewinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows Live Servicerusrserv.exe"Added by the SMALL.LU BACKDOOR!"
XWindows live Supportwlmsngr.exe"Added by the RBOT-BKL WORM!"
UWindows Live SyncWindowsLiveSync.exe"Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - ""a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers"""
UWindows Live™ OneCare™ Family Safetyfssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
?Windows Loadwindows.com"??"
XWindows Loaderwstart32.exe"Added by the GAOBOT.CA WORM!"
XWindows LoaderwinServices.pif"Detected by Kaspersky as the CARDSPY.D TROJAN!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
Xwindows LoadxmWin_.exe"Added by the FODDER-A TROJAN!"
XWindows Local ISPwinthcr.exe"Added by the SDBOT.ENZ BACKDOOR!"
XWindows Local Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Local Spoolerlssas.exe"Added by the RBOT.BXQ WORM!"
XWindows Locatorwsass.exe"Added by the IRCBOT.N TROJAN!"
XWindows Log Agentwinlogon.exe"Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
XWindows Loggerwinlog.exe"Added by the NSHADOW-B TROJAN!"
XWindows loggingwinlogd.exe"Added by the RBOT-ON WORM!"
XWindows loggingasgasg.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Logical Adapterwsrsvc.exe"Added by the IRCBOT.ARU BACKDOOR!"
XWindows Logical Connectionwcnsvc.exe"Added by the VIRUT.AO VIRUS!"
XWindows Loginexplored.exe"Added by the GAOBOT.SY WORM!"
XWindows Loginwinlog.exe"Added by the AGOBOT.MG WORM!"
XWindows Loginlmss.exe"Added by the AGOBOT-JA WORM!"
XWindows Loginmsnmsgr.exe"Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Loginlogin.exe"Detected by NOD32 as a variant of the BIFROSE TROJAN!"
XWindows Loginlms.exe"Added by the AGOBOT-IC WORM!"
XWindows Login Folderwinzep.exe"Added by the AGOBOT-TZ WORM!"
XWindows Login Managerwinlogin.exe"Added by a variant of the SDBOT WORM!"
XWindows Login Securitywinlogin.pifAdded by an unidentified WORM or TROJAN!
XWindows Login Servicewinlog.exe"Added by the RBOT-AFN WORM!"
XWindows Login Servicewinlogin.pif"Added by the SDBOT-ACU WORM!"
XWindows Logonwinlogin.exe"Added by the SPYBOT-C TROJAN!"
XWindows Logonwinlogon.exe"Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
XWindows Logon ApplicationWinIogon.exe"Added by the LINKBOT.M WORM!"
XWindows Logon Applicationlogon.exe"Added by the POEBOT-J WORM!"
XWindows Logon Applicationservices.exe"Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Logon Applicationwin32help.exe"Added by the DELBOT-X WORM!"
XWindows Logon Applicationwinlogon.exe"Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process
XWindows Logon Applicationwinamp.exe"Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XWindows Logon Applicationedcwinlogon.exe"Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Applicatonedcwinlogon.exe"Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
XWindows Logon Managerlogon.exe"Added by a variant of the RBOT WORM!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon ProcedureSvchosta.exe"Added by a variant of the SPYBOT WORM!"
Xwindows logon procedurewinlogonpc.exe"Added by the WINLOGON TROJAN!"
XWindows Logon Servicewinlogon.pif"Added by the RBOT-AOU WORM!"
XWindows Logon Servicenapi32.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows LoL Layergqwdcr.exe"Added by the AGOBOT-AHS WORM!"
XWindows LoL Layerwin.exe"Added by the RBOT-FTO WORM!"
XWindows LoL Layer[random filename].exe"Added by the RBOT-GMD WORM!"
XWindows LoL Layerpyvnpt.exe"Added by the RBOT-GKV WORM!"
XWindows LoL Layerwinlolx.exe"Added by the RBOT-FOR WORM!"
XWindows LoL Layerazypbrx.exe"Added by the RBOT-GMZ WORM!"
XWindows LoL Layerblvpnmcny.exe"Added by the RBOT-GOR WORM!"
XWindows Lord Anti-Viruswinlord32.exe"Added by the SDBOT-GW WORM!"
XWindows Management Informantwmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
XWindows Management Instrumentationmwd.exe"Added by the GRAPS WORM!"
XWindows Management Instrumentation[path to file]"Added by the QEDS-A WORM!"
XWindows Management Instrumentationswinmg.exe"Added by the GAOBOT.GW WORM!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Managerwinmants.exe"Added by the MANTAS WORM!"
XWindows Managerwinsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Managertaskmgrs.exe"Added by the SILLYFDC.BBZ WORM!"
XWindows Manager ControlWINMUR32.EXE"Added by the AGOBOT-AR WORM!"
XWindows Manager Update Inctgb.exe"Added by the SDBOT-ACM WORM!"
XWindows mangementwinlogonn.exe"Added by the RANDEX.FC WORM!"
XWindows Media APwinmapp.exeAdded by an unidentified WORM or TROJAN!
XWindows Media APPwmapp.exeAdded by an unidentified WORM or TROJAN!
NWindows Media Center"RunDLL32.exe ehuihlp.dllBootMediaCenter"
XWindows Media Centersmss.exe"Added by the WARBOT TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Media Connect 2WMCCFG.exe"Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
XWindows Media Drivermsnger.exe"Added by a variant of the RBOT WORM!"
XWindows Media Loaderwmloader.exe"Added by a variant of the GAOBOT WORM!"
XWindows Media Playerwmediaplayer.exe"Added by the AGOBOT-NQ WORM!"
XWindows Media PlayerMediaPIayer.exe"Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
XWindows Media Player[random filename]"Added by a variant of the RBOT WORM!"
XWindows Media Playermsa.exe"Added by the RBOT-SI WORM!"
XWindows Media Playermcafe32.exe"Added by the RBOT-YO WORM!"
XWindows Media Playerwmplayer.exe"Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XWindows Media Player50cent.exe"Added by a variant of the RBOT WORM!"
XWindows Media Playermpwe.exe"Added by the RBOT-TT WORM!"
XWindows Media Playermsams.exe"Added by the RBOT.AHR WORM!"
XWindows Media Playervmmreg32.exe"Added by the AGENT.AQO TROJAN!"
XWindows Media Playermsass43.exe"Added by the RBOT-RT WORM!"
XWindows Media Playermpupdata.exe"Added by the SDBOT.BBG WORM!"
XWindows Media Playerwmplayerc.exe"Added by the SILLYFDC.DBG WORM!"
XWindows Media Player 3.6wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 3.6bWMPA36B.EXE"Added by the RBOT-VV WORM!"
XWindows Media Player 3.6dwmpa36d.exe"Added by the RBOT-YA WORM!"
XWindows Media Player 3.9wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Media Player 6.1.2wmplayer612.exe"Added by the RBOT.AIB BACKDOOR!"
XWindows Media Player Servicewmedia.exe"Added by the RBOT.213504 WORM!"
XWindows Media Player Update[random filename]"Added by the RBOT-ET WORM!"
NWindows Media Powerpoint HelperNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
XWindows Media Serverwmserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Media Server!wmserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows media servicecrvss.exe"Added by the SDBOT.VP WORM!"
XWindows media servicecrsss.exe"Added by the RBOT.ACY WORM!"
XWindows media serviceSygate32.exe"Added by the RBOT.ADE WORM!"
XWindows media servicescvrsss.exe"Added by the RBOT-MW WORM!"
XWindows Media SP.2.37[random filename]"Added by the LEMIR.C TROJAN!"
XWindows Media Updatercrease.exe"Added by the RBOT-ATI WORM!"
XWindows Media UpgradeNeUpgrade.exe"Added by the RBOT.BMF TROJAN!"
XWindows Media Utilitywmediautil.exe"Added by a variant of the SPYBOT WORM!"
XWindows Memory Driversmemretain.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Managerwindowsmem.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
XWindows Memory Sharingmemoryshr.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Memory Sharingmemshr.exe"Added by the IRCBOT.MC BACKDOOR!"
XWindows Messanger Control Centersvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centersvhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Messanger Control Centerwinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Messanger Control Centerwinsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows messengermessengers.exe"Added by the MYTOB.EI WORM!"
XWindows Messengermsnsmgs.exe"Added by the RBOT-ANJ WORM!"
XWindows Messengermsnmsg.exe"Added by the SPYBOT.BV WORM!"
XWindows Messenger 4.14landisc.exe"Added by the SDBOT-KR WORM!"
XWindows Messenger Connectwmdsvc.exe"Added by the SLENFBOT.S WORM!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Messenger Live MSNwinlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Messenger Messengerwinmsg.exe"Added by the VELKBOT.A WORM!"
XWindows Messenger Panelwbcsvc.exe"Added by the IRCBOT.ADA BACKDOOR!"
XWindows Messenger Servicewinsmsgr.exe"Added by the RBOT-VW WORM!"
XWindows Messenger Servicekaspersky.exe"Added by the MYTOB.HY WORM!"
XWindows Messenger Sharewmssvc.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Messenger Starterwmvsvc.exe"Added by the DELF.DAX TROJAN!"
XWindows MeTaLRoCk servicemetalrock.exe"Added by the TASTYRED TROJAN!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows Microsoft Service[random filename]"Added by the AGENT-HCD TROJAN!"
XWindows Microsoft Services[8 random letters].exe"Added by the KOLAB.AW WORM!"
XWindows Microsoft Updatewintask32.exe"Added by a variant of the SDBOT WORM!"
XWindows Microsoft Verifierwinauth23.exe"Added by a variant of the RBOT WORM!"
UWindows Mobile Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UWindows Mobile-based device managementwmdSync.exe"Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships
UWindows Mobile-based device managementwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XWindows mod VerifierWindows-mod.exe"Added by the RBOT.DSU WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWindow2.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindowsLogon.exe"Added by a variant of the SDBOT WORM!"
XWindows modez VerifierWwuamguard.exe"Added by the RBOT.EZJ WORM!"
XWindows modez Verifierwinlogom.exe"Added by a variant of the RBOT WORM!"
XWindows modez VerifierWindows-.exe"Added by the RBOT-DIO WORM!"
XWindows modez Verifiertaskmngr.exe"Added by a variant of the RBOT WORM!"
XWindows modez Verifierwinl0g0z.exe"Added by the RBOT-FNB WORM!"
XWindows modez Verifierwuamguard.exe"Added by the RBOT.EZJ BACKDOOR!"
XWindows Monitorwinmon.exe"Added by the SDBOT.VB WORM!"
XWindows Monitorarsetup.exeAdded by the SPAZBOX.A TROJAN!
XWindows Monitor Serviceswinmonitor.exe"Added by the RBOT-XX WORM!"
XWindows Monitoring Servicewinmon.exe"Added by a variant of the SDBOT WORM!"
XWindows More ChoiceTopContext.exe"ZQuest adware"
XWindows Mouse Serviceswinmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
XWindows Mouse Serviceswinmouse64.exe"Added by the IRCBOT.AIA BACKDOOR!"
XWindows Mouse Utilitiesmouseutils.exe"Added by the RBOT-ABU WORM!"
XWindows ms Driversmsnup32.exe"Added by the SDBOT-AAL WORM!"
XWindows MS Update 32fhm.exe"Added by the IRCBOT.GEN WORM!"
XWindows MS Update 32sucker.exe"Added by the FORBOT-GJ WORM!"
XWindows MS Update 32jebote.exe"Added by the FORBOT-GK WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows MSNMSN.msn"Added by the TRIXCU.A WORM!"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messangerlivemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows MSN Live Messengerwinlivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows MSN Live Messengerwinmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
XWindows MSN Updateswnd32.exe"Added by the IRCBOT-ABA TROJAN!"
XWindows MSN2 XPswchost.exe"Added by the KOLAB.AA WORM!"
XWindows MSX driverswinmsx.exe"Added by the RBOT-AYG TROJAN!"
XWindows Net Cfgservice.exe"Added by a variant of the RBOT WORM!"
XWindows NetDDewrmana32.exe"Added by the MYTOB.IM WORM!"
XWindows NetsWinNET.exe"Added by the RBOT-MO WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwingmt.exe"Added by a variant of the SDBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Network Firewallfirewall.exe"Added by the POEBOT-J WORM! Located in %System%"
XWindows Network Logonnpesvc.exe"Added by the AGENT.ERZ TROJAN!"
XWindows Network Servicewinvc32.exe"Added by the RBOT.RY WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Network ServiceRealteks.exe"Added by the RBOT-GTG WORM!"
XWindows Network Serviceswinnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Network Serviceswinnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Sessionnspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows Networking Monitormdm.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networking Monitorinxmdmx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networking Monitoringmdm.exe"Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networksnetcog.exe"Added by the MYTOB.FH WORM!"
XWindows Nivedia DriversysMGT.exe"Added by a variant of the RBOT WORM!"
XWindows NNT[path to trojan]"Added by the RANKY.E TROJAN!"
XWindows NTtwain.exe"Added by the AGENT.BEA TROJAN!"
XWindows NT 32ntlogin32.exe"Added by the RANDEX.BRD WORM!"
XWindows NT Loginntlogin32.exe"Added by the SDBOT.WG WORM!"
XWindows NT Login Session ManagerWNSM.EXE"Added by the RBOT.BIV WORM!"
XWindows NT Logon Applicationwinlogon.scr"Added by the RBOT-ALP WORM!"
XWindows NT Service Namewinshock.exe"Added by the RBOT-PK WORM!"
XWindows NT Service Namesvchcst.exe"Added by the RBOT-NV WORM!"
XWindows NT Session Managersess.exe"Added by a variant of the RBOT WORM!"
XWindows NT Update ManagerWINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
XWindows NTFS Volume Manage[6 random letters].exe"Added by the RBOT.EDL BACKDOOR!"
XWindows OEM Toolswinres32.exe"Added by the SPYBOT.FD WORM!"
XWindows Offical Netvvorksmywriter32.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Office Monitoremdm.exe"Added by the RBOT.AFV BACKDOOR!"
XWindows OLE Automation Serverole32aut.vbe"CoolWebSearch parasite variant"
XWindows Online Updaterdllman.exe"Added by the RBOT-TE WORM!"
XWindows pack Control Centertaskmam.exe"Added by the TOMETA-J TROJAN!"
XWindows Pcwinmgr.exe"Added by the BIBOT-A WORM!"
XWindows PC DefenderWP[random characters].exe"Windows PC Defender rogue security software - not recommended
XWindows PDGwinpdg.exe"Added by the RBOT-ADW WORM!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows PNPwinpnp.exe"Added by the RBOT-AKN WORM!"
XWindows PNP Serverpnpsrv.exe"Added by the RBOT-AKM WORM!"
XWindows Pool Managerpoolsc.exe"Added by the OBOT.CH WORM!"
XWindows Pool Setuppoolmc.exe"Added by the IRCBOT.RU BACKDOOR!"
XWindows Population Loggerwinpo32.exe"Added by the AGENT.YKR WORM!"
XWindows Portable Device DriversMSKSVRVS.EXE"Added by a TROJAN - see here"
XWindows Portable DevicesMSKSVRTSS.EXE"Added by the SPYBOT.APEO WORM!"
XWindows Print Monitor Daemon[random filename].exe"Added by a variant of the SDBOT WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Print SpoolerNavAgent32.exe"Added by an unidentified VIRUS
XWindows Print SpoolerSVEHOST.EXE"Added by the SPYBOT.H WORM!"
XWindows Printing DriverWinPrint.exe"Added by a variant of the RBOT WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Driverciadvs.exe"Added by the BUZUS-M TROJAN!"
XWindows Printing Driverciadvss.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Drivergpedits.exe"Added by the DCKEYG.A WORM!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Process Managerwinproc.exeAdded by an unidentified WORM or TROJAN!
XWindows Processe Managermspn32.exe"Added by the RBOT.AXO WORM!"
XWindows Proffesional SecurityWinSecure32.exe"Added by the AGOBOT.VA WORM"
XWindows Protected Storagenpssvc.exe"Added by the IRCBOT.AUL BACKDOOR!"
XWindows Protection SuiteWI[random characters].exe"Windows Protection Suite rogue security software - not recommended
XWindows Protectotboxide.exe"Added by a variant of the WOOTBOT WORM!"
XWindows Recavery Adwarelsass.exe"Added by an unidentified TROJAN - see here. Note - this is not the legitimate lsass.exe process
XWindows Recovery Consolerecovery.exe"Added by the RANSOM.FD WORM!"
XWindows Recylinder Checkzwdomsgemw.exe"Added by the RBOT-EGJ WORM!"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslncom.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWINDOWS REGISTER EDITregistr32.exeAdded by an unidentified WORM or TROJAN!
XWindows Register Settingssvmhost.exe"Added by a variant of the FORBOT WORM!"
XWindows Registerswinservicess.exe"Added by a variant of the SDBOT WORM!"
XWindows Registery Centersvhchosts.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Registrymsnmsg.exe"Added by a variant of the RBOT WORM!"
XWindows Registrywinhost.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Cleanerwinclean.exe"Added by a variant of the SPYBOT WORM!"
XWindows Registry Controlwinreg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Registry DLLwinregdll.exe"Added by the IRCBOT.FB BACKDOOR!"
XWindows Registry Express Loaderregexpress.exe"Added by the FORBOT-CJ WORM!"
XWindows Registry Managertasksmanagers.exe"Added by the MYTOB.ER WORM!"
XWindows Registry Name[random filename]"Added by the RBOT-AEB WORM!"
XWindows Registry Namewinses.exe"Added by the RBOT-ADB WORM!"
UWindows Registry Repair ProRegistryRepairPro.exe"Registry Repair Pro. ""Scans the Windows Registry for invalid or obsolete information in the registry"""
XWindows Registry Scanregscan32.exe"Added by the RBOT.KE WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Registry Scansvcdll.exe"Added by the RBOT-TP WORM!"
XWindows Registry Scanregscan23.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Scanregscan.exe"Added by the RBOT-HA WORM!"
XWindows Registry Scanwinmedia.exe"Added by the SPYBOT.GK WORM!"
XWindows Registry Securitycrss.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Registry Servicesregserv.exe"Added by the SLENFBOT.BB WORM!"
XWindows Registry Startupwind32.exe"Added by the AGOBOT-BZ WORM!"
XWindows Registry XPwinxptdl.exe"Added by the IRCBOT.AUN WORM!"
XWindows Relay Serviceipcbind.exe"Added by the DELFINJECT.F TROJAN!"
XWindows Relay Serviceirfnga.exe"Added by the DROPPER.ACO TROJAN!"
XWindows Remote Addressingwnpcgs.exe"Added by the DELF-EZN TROJAN!"
XWindows Remote Launcherwnpmcs.exe"Added by the IRCBOT.ASX BACKDOOR!"
XWindows Repairtoxikx.exe"Added by the SDBOT-ADL WORM!"
XWindows reportswchost.exe"Added by the SMALL-BD TROJAN!"
XWindows Rescue Systemwinsto.exe"Added by the SUURCH.CG TROJAN!"
XWindows Reverse Preperationwinrvp.exe"Added by the SLENFBOT.CB WORM!"
XWindows Reversed Virus Protectionwinrsvp.exe"Added by the SLENFBOT.HX WORM!"
Xwindows runsystem.exe"Added by the ICPASS-A WORM!"
XWindows Run-Time 64bitwin64rt.exe"Added by a variant of the RBOT WORM!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Running DLL Servicerundll128.exe"Added by the IRCBOT.XDH BACKDOOR!"
XWindows Running DLL Servicerundll64.exe"Added by the SLENFBOT.HV WORM!"
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime Proccess32RUNdll.exe"Added by the SDBOT.QW WORM!"
XWindows SAomniscient.exe"BLAZEFIND adware"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Scheduler!scheduler.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
NWindows SearchWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XWindows securesetver32.exe"Added by the SPYBOT.EP WORM!"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Secure FixiPodFixer.exe"Added by the WOOTBOT.BM BACKDOOR!"
XWindows Secure Layer[random filename]"Added by the RBOT.DRF WORM!"
XWindows Secure Messaging Systemmsnmsgrsrvc.exe"Added by the RBOT-RE WORM!"
XWindows Secure Servicesssms.exe"Added by the RBOT-GAR WORM!"
XWindows Secure talal32[7 random letters].exe"Added by the RBOT.HTP TROJAN!"
XWindows Secure Updatewinupser.exe"Added by the RBOT-GCG WORM!"
XWindows Secure UpdateWinSecUp.exe"Added by the RBOT-GCD WORM!"
XWindows Secure Updateload.exe"Added by the FORBOT-GU WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securetywurger.exe"Added by the AGOBOT-NC BACKDOOR!"
XWINDOWS SECURITYwingrd.exe"Added by a variant of the RBOT WORM!"
XWindows Securitywin.pif"Added by the RBOT-APT WORM!"
XWindows Securityms32.pif"Added by the RBOT-ARN WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Assistantrundll32.vbe"CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
XWindows Security Assistantwinsec.exe"CoolWebSearch parasite variant"
XWindows Security Authority Servicelsass.exe"Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process
XWindows Security Center Notification Appwscnfty.exe"Added by a variant of the RBOT WORM!"
XWindows Security Center Notification Applssxe.exe"Added by the RBOT-GKX WORM!"
XWindows Security Center Notification Applsesxes.exe"Added by the RBOT-GLR WORM!"
XWindows Security Center Notification Applseos.exe"Added by a variant of the RBOT-GLR WORM!"
XWindows Security Center Notification Applseesysecurex.exe"Added by a variant of the RBOT-GKX WORM!"
XWindows Security Controlwuaucls.exe"Added by the FORBOT-V WORM!"
XWindows Security Managerwinsecurity.exe"Added by the AGOBOT-KI WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security Managersvchost.exe"Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
XWindows Security Managersvhost.exe"Added by the GAOBOT.ALU WORM!"
XWindows Security Modulemodule.exe"Added by a variant of the RBOT WORM!"
XWindows Security Policylsass32.exe"Added by the AGOBOT-CR WORM!"
XWindows Security Service[random file name]"Added by the RBOT-ALV WORM!"
XWindows Security Servicearrdt.exe"Added by a variant of the RBOT WORM!"
XWindows Security Servicewindows.pif"Added by the RBOT-AMG WORM!"
XWindows Security SuiteWI[random characters].exe"Windows Security Suite rogue security software - not recommended
XWindows Security Survysvchosl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows Security Updatesecurity32.exe"Affilred adware"
XWindows Security Updatendsass.exe"Added by the RBOT.ESM BACKDOOR!"
XWindows Serv PatchMcaffe2005.exe"Added by a variant of the RBOT WORM!"
XWindows Servce Agent[random filename]"Added by a variant of the IRCBOT TROJAN!"
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWindows ServeAdWinServAd.exeWindupdates adware variant
XWindows Serverwinserv.exe"Added by the IRCBOT.AVM BACKDOOR!"
XWindows Server Client Verification Servicewscvs.exe"Added by the AGENT.AWC TROJAN!"
XWindows Server Driverssyssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Server Informationservinfo.exe"Added by the FORBOT-EN WORM!"
XWindows Server IP Verification Servicewsivs.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Server Peer Verification Servicewspvs.exe"Added by a variant of the RANKY TROJAN!"
XWindows Server!winsvr.exe"Added by the IRCBOT.AYC BACKDOOR!"
XWindows Servic2winsy.exe"Added by the RBOT-AIA WORM!"
XWindows servicewuamgrd.exe"Added by the RBOT-QW WORM!"
XWindows Servicedddd.exe"Detected by Kaspersky as Dialer.Salc
XWindows Serviceprvdi.exe"Malware - detected by Kaspersky as the SMALL.RD TROJAN!"
XWindows Servicevideo.exeAdded by an unidentified TROJAN!
XWindows Servicesvvhost.exe"Added by the AGOBOT-HL WORM!"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Servicepd7.exe"Added by the SMALL.VZ TROJAN!"
XWindows Servicedstart4.exeAdded by an unidentified TROJAN!
XWindows Servicepd14.exe"Adware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!"
XWindows Servicevideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
XWindows Serviceservices.exe"Added by the KALEL-A WORM! Note - this is not the legitimate services.exe process
XWindows ServiceWINSVC.EXE"Added by the SPYBOT-DH TROJAN!"
XWindows Servicer.exe"Added by a variant of the SMALL.VZ TROJAN!"
XWindows Servicewindowz.exe"Added by the SDBOT-AYI WORM! Note - dissables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)"
XWindows serviceiexpl0rer.exe"Added by the SDBOT.RO WORM!"
XWindows Serviceservice.exe"Added by the IRCBOT-ACV WORM!"
XWindows Servicesvchost.exe"Added by the SPYBOT-AW TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XWindows Service Ag3nt[6 random letters].exe"Added by the SDBOT.EZX TROJAN!"
XWindows Service Agccntjeqcfyo.exe"Added by the RBOT-GST WORM!"
XWindows Service Agccnt[random].exe"Added by the SDBOT-DHL WORM!"
XWindows Service Agccntrmizjgz.exe"Added by the SDBOT-SIM WORM!"
XWindows Service Agentczf.exe"Added by the RBOT-GAJ WORM!"
XWindows Service Agent[random filename].exe"Added by the IRCBOT-XE TROJAN!"
XWindows Service Agentagl23.exe"Added by the RBOT-GQU WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Service Agentdsass.exe"Added by the RBOT.MIRCO.BNG WORM!"
XWindows Service Agentmsnmagr.exe"Added by a variant of the SLAPER TROJAN!"
XWindows Service Agenttaskmgr32.exe"Added by the RBOT-GMN WORM!"
XWindows Service Agentwin32wins.exe"Added by the RBOT-LOL WORM!"
XWindows Service Agentwinup32.exe"Added by the RBOT-GQX WORM!"
XWindows Service Agentwinupds32.exe"Added by the RBOT-GQT WORM!"
XWindows Service Agentwit.exe"Added by the RBOT-GQV WORM!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Agentspoolvs.exe"Added by the RBOT-GXI WORM!"
XWindows Service Agentspools.exe"Added by the AGENT-GJF TROJAN!"
XWindows Service Agentmsngear.exe"Added by the RBOT.AHW BACKDOOR!"
XWindows Service Agentmsngerr.exe"Added by the RBOT.EOZ WORM!"
XWindows Service Agent[3 random letters].exe"Added by the AGENT.AMEB TROJAN - see examples here and here"
XWindows Service Agentcxfrru.exe"Added by the SDBOT.GAV WORM!"
XWindows Service Agentizszbayz.exe"Added by the KOLAB.TC WORM!"
XWindows Service Agentjnxrcyc.exe"Added by the RBOT.XAT BACKDOOR!"
XWindows Service Agentkafdprs.exe"Added by the IRCBOT.HDE BACKDOOR!"
XWindows Service Agentkrqbs.exe"Added by the IRCBRUTE.AZ TROJAN!"
XWindows Service Agentlcaqmsp.exe"Added by the RBOT.WFR BACKDOOR!"
XWindows Service Agentmsnmsgr.exe"Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows Service Agentmxjunj.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentndibbeu.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentnimcoo.exe"Added by the RBOT.EWV WORM!"
XWindows Service Agentnod32.exe"Added by the RBOT.BNG BACKDOOR!"
XWindows Service Agentsjbsm.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentsjbsmgm.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agenttjybssd.exe"Added by the RBOT.XVD BACKDOOR!"
XWindows Service Agentumvcnm.exe"Added by the RBOT.EMC BACKDOOR!"
XWindows Service Agentuqgpq.exe"Added by the SMALLTRO.II TROJAN!"
XWindows Service Agentvbsxkhk.exe"Added by the IRCBOT.AHX WORM!"
XWindows Service Agentwge23.exe"Added by the RBOT.HHK BACKDOOR!"
XWindows Service AgentWindo.exe"Added by the RBOT.NQS WORM!"
XWindows Service Agentywgma.exe"Added by the RBOT.DZT BACKDOOR!"
XWindows Service Agentwinupd32.exe"Added by the SDBOT.SYM WORM!"
XWindows Service AgentWinTcpip.exe"Added by the SPYBOT.AP WORM!"
XWindows Service Agentidvcqv.exe"Added by the AGOBOT-AJB WORM!"
XWindows Service Agent 32mrthd.exe"Added by the AGENT-GAQ TROJAN!"
XWindows Service Agnts[8 random letters].exe"Added by the SDBOT.BCQ WORM!"
XWindows Service Ajavjava128.exe"Added by the RBOT.BNG WORM!"
XWindows Service alge[random filename]"Added by the RBOT.GJO TROJAN!"
XWindows Service Controllerservices.exe"Added by the KALEL-B WORM! Note - this is not the legitimate services.exe process
XWindows Service Controller Agenttaksmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service DCuhpnjcjl.exe"Added by the RBOT-GLY WORM!"
XWindows Service ExecServiceLayer.exe"Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
XWindows Service Findwrfkuk.exe"Added by the IRCBOT-XZ TROJAN!"
XWindows Service helpwinservices.exe"Added by the DROPPER.TT TROJAN!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostsvchost.exe"Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Service Hostsvchost.exe"Added by the KALEL-C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Service Host Process[path to file]"Added by the EZIO-A WORM!"
XWindows Service HostingUSERINIT.exe"Added by the GOMMER-A WORM!"
XWindows Service Layerconfig.exe"Added by the RBOT.DDJ WORM!"
XWindows Service LoaderWindow.exe"Added by the RBOT-XO WORM!"
XWindows Service Managementsvcmngmt.exe"Added by the AGOBOT-NM WORM!"
XWindows Service Manageruserint32.exe"Added by the OSCABOT-C WORM!"
XWindows Service Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managermsgs.exe"Added by the OSCABOT-E WORM!"
XWindows Service Managermsnmrg.exe"Added by the OSCABOT-G WORM!"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managersvcmgr32.exe"Added by the OSCABOT-D WORM!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Service Managertaskmgr.exe"Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
XWindows Service Managerinitsvc.exe"Added by the RBOT-BWT WORM!"
XWindows Service oi worms[6 random letters].exe"Added by the SYSTEMHI.OS TROJAN!"
XWindows Service Pack 2WindowsSP2.exe"Added by the SDBOT-TQ WORM!"
XWindows Service Pack Auto Updatewinworks.exe"Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updatefiggaz.exe"Detected by Kaspersky as the AGENT.BT TROJAN!"
XWindows Service Pack Auto Updateballin.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Service Pack2svchhost.exe"Added by a variant of the RBOT WORM!"
XWindows Service Pack2WIN43.EXE"Added by the GAOBOT.G WORM!"
XWindows Service Supplywinsupply.exe"Added by the SLENFBOT.CZ WORM!"
XWindows Service Support CallSVSS32.EXE"Added by the RBOT-XQ WORM!"
XWindows Service SVsv32.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Service Threadssvcthreading.exe"Added by the SHEUR.AUM TROJAN!"
XWindows Service Threadssvcthreads.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows Service Updatecrsss.exe"Added by the SDBOT.CWX WORM!"
XWindows Service Updatemswsgs.exe"Added by the RBOT.FQB WORM!"
XWindows Service Utititywinsrvc.exe"Added by the RBOT-ASI WORM!"
XWindows Service XPXpFirewall.exe"Added by the MYTOB.AM WORM!"
XWindows Servicerxqobypik.exe"Added by the SDBOT-DFB WORM!"
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicessvchosts.exe"Added by the AGOBOT-KL TROJAN!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Serviceswinsvc32.exe"Added by the MYTOB-CB WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesspoolsvc.exe"Added by the SDBOT.CPZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesavsrv32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesservicez.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32edus.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesw32services.exe"Added by the AUTORUN-FT WORM!"
XWindows Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswinsysdll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinsyssrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Serviceswinudp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Servicessvhost33.exe"Added by the RBOT.AFN WORM!"
XWindows Servicesservices.exe"Added by the AGENT-MVC TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Agantregs32.exe"Added by the SDBOT-DIK WORM!"
XWindows Services Aganters[10 random letters].exe"Added by the RBOT.CUN WORM!"
XWindows Services Agentmsngears.exe"Added by the VB-EMS TROJAN!"
XWindows Services alges2[8 random letters].exe"Added by a variant of the RBOT WORM!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows Services Certificationsvccert.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows Services Guidesvcguides.exe"Added by the SHEUR.YS BACKDOOR!"
XWindows Services Hostsvchost.exe"Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows Services Hostssvhosts.exe"Added by the SDBOT-YH TROJAN!"
XWindows Services Ink Platform Tablet Input Subsystemwsiptis.exe"Added by the RBOT.APC WORM!"
XWindows Services Jogsvcjog.exe"Added by the AGENT.ALWZ WORM!"
XWindows Services Jogsvcjogg.exe"Added by the AGENT.QAF WORM!"
XWindows Services Jogersvcjoger.exe"Added by the RBOT.CAT WORM!"
XWindows Services Joggingsvcjogging.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services Jogingsvcjoging.exe"Added by the IRCBOT.AVI BACKDOOR!"
XWindows Services Layerwinlogz2.exe"Added by the RBOT-FZE WORM!"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Layersslms.exe"Added by the RBOT-GAH WORM!"
XWindows Services M7ctfmon32.exe"Added by the AGENT.WOH TROJAN!"
XWindows Services Towersvctowers.exe"Added by the IRCBOT.AGJ BACKDOOR!"
XWindows Services Towersvctowing.exe"Added by the SLENFBOT.LA WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWindows Serviece Agents[8 random letters].exe"Added by the AGENT.BHR TROJAN!"
XWindows Servserserviser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Session Managersmss32.exe"Added by a variant of the RBOT WORM!"
XWindows Session Manager Subsystemsmss.exe"Added by the KALEL-B WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
?Windows shellwin70.exe"??"
XWindows Shellshell.exe"Added by the MYTOB-CA WORM!"
XWindows Shelltaskgmr.exe"Added by the MYTOB.BV WORM!"
XWindows Shell Library Loaderload shell.dll"CoolWebSearch parasite variant"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWINDOWS SKYsky.exe"Added by the MYTOB.CH WORM!"
XWindows Smart Managersmart.exe"Added by the RBOT-SL WORM!"
XWindows SMB Managersmb32.exe"Added by the RBOT-BHZ WORM!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWindows Socket ProcedureWinSock32.exe"Added by the RBOT-FMX WORM!"
XWindows Softwarehbsppe.exe"Added by the RBOT-GLL WORM!"
XWindows Soundsvdhost.exe"Added by the SDBOT.EFX BACKDOOR!"
XWindows Sound DriverSndMon32.exe"Added by a variant of the SPYBOT WORM!"
XWindows Sound Emulatorsnd32_win.exe"Added by the ATNAS.A WORM!"
XWindows Sound ManagerSndMon32.exe"Added by the FORBOT-BU WORM!"
XWindows Sound ManagerSndMon16.exe"Added by a variant of the FORBOT WORM!"
XWindows Sound Managersound.exe"Added by the AGOBOT-CD WORM!"
XWindows Sound Managergearsec.exe"Added by the PUSHBOT.DF WORM!"
XWindows Sound VerifierWinIp32.exe"Added by the RBOT-FMO WORM!"
XWindows SP2 Firewallwfirewall7.exe"Added by a variant of the RBOT WORM!"
XWindows SP2 UpdateSp2update.exe"Added by the WOOTBOT.BS WORM!"
XWindows SP2 Version Loadwuauclt32.exe"Added by the GAOBOT.CX WORM!"
XWindows SP4directCC.exe"Added by the RBOT-ACX WORM!"
XWindows Spoolwinspool.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Spool Serverspoolsrv.exe"Added by the SDBOT-ACT WORM!"
XWindows SpoolaPrint Servicespoolasrv.exe"Added by the SDBOT-AYD WORM!"
XWindows SpoolerSPOOLSRV.EXE"Added by the SPYBOT.P WORM!"
XWindows Spoolerspoolsv32.exeAdded by an unidentified WORM or TROJAN!
XWindows Spoolerwinsplr.exe"Added by the SHEUR.ANX TROJAN!"
XWindows Spooler Control Serviceqwidh.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Spooler Servicesspool.exe"Added by the AGOBOT-AMO WORM!"
XWindows SpoolPrint Servicespoolersrv.exe"Added by the SDBOT-ZT WORM!"
XWindows Spools SVwinsv.exe"Added by the RBOT-AUQ WORM!"
XWindows spoolservr Servicespoolservr.exe"Added by the SDBOT-AAN WORM!"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows Spoolsrv Servicespoolmsv.exe"Added by the SDBOT-ZS WORM!"
Xwindows spoolsrv servicespoolssv.exe"Added by the SDBOT-AWV WORM!"
XWindows Spoolsurf Servicespoolsurf.exe"Added by the SDBOT-ZZ WORM!"
XWindows SpooltPrint Servicespooltsrv.exe"Added by the SDBOT-AYE WORM!"
XWindows Spoolvvv Servicespoolvvv.exe"Added by the SDBOT-AAW WORM!"
XWindows spyware removerWindows-spyware.exe"Added by the SystemPoser TROJAN!"
XWindows sq Driverswinmsn32.exe"Added by the RBOT-ADI WORM!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
XWindows Sql Service For Windows 32 Bitwinsql32.exe"Added by the FORBOT-FC WORM!"
XWindows SRS Clientwinsrs.exe"Added by the RBOT-BXQ WORM!"
XWindows SRT Clientwinsrt.exe"Added by the RBOT-BFR WORM!"
XWindows SSH Clientwinssh.exe"Added by the RBOT-AXC WORM!"
XWindows SSL Filewinssv.exe"Added by the WOOTBOT.CA WORM!"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
XWindows Stand Sound DriversSounddrv.exe"Added by the SDBOT-XF WORM!"
XWindows Standard Securty[random 3-letter filename]"Added by the RBOT-ALF WORM!"
XWindows Start Server 2000traficy.exe"Added by the RBOT-AHM WORM!"
XWindows Startupwinsta~1.exe"GoHip foistware"
XWindows Startupwinstartup.exe"GoHip foistware"
XWindows StartupWdrun32.exe"Added by the GAOBOT.AO WORM!"
XWindows Startupservices21.exe"Added by the AGOBOT-MX WORM!"
XWindows StartupWinsys32.exe"Added by the RBOT.AAB WORM!"
XWindows Startup 32 Bitssysrun32.exeAdded by a variant of the DARKSUN TROJAN!
YWindows SteadyState - Bubble MessagesBubble.exe"Part of Windows SteadyState
YWindows SteadyState - Session Timer Notify (UI)SCTUINotify.exe"Part of Windows SteadyState
XWindows Storm-Memory Driversmemorystorm.exe"Added by the SLENFBOT.CO WORM!"
XWindows Stortupsvchost.exe"Added by the TOGER-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Streams Serverlocalsrv.exe"Added by the SDBOT.LN WORM!"
XWindows Subsyswinload.exe"Added by the NETSPREE.C WORM!"
UWindows Supervisorwinspvr.exe"Windows Supervisor surveillance software. Uninstall this software unless you put it there yourself"
XWINDOWS SVCwinsvc.exe"Added by the MYTOB-EY WORM!"
XWindows svchostavserv.exe"Added by the PUSHBOT.FM WORM!"
XWindows svchostctfmon32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows svchosthappy2008.exe"Added by the PUSHBOT.AM WORM!"
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWindows svchostserviceaaa.exe"Added by the PUSHBOT.ER WORM!"
XWindows svchostservicean.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows svchostsvchost.exe"Added by the IRCBOT-ZQ WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows svchostups.exe"Added by the PUSHBOT.A WORM!"
XWindows svchostupss.exe"Added by the PUSHBOT.GJ WORM!"
XWindows svchostserviceam.exe"Added by the PUSHBOT.EY WORM!"
XWindows svchostsvchostx.exe"Added by the PUSHBOT.CC WORM!"
XWindows Svchost Authorityslsass.exe"Added by the RBOT-UA WORM!"
XWindows Svshost Service Update 32svcsshost32.exe"Added by the FORBOT-GD WORM!"
XWindows SYN Control Centerwinmnon32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows SyncroAdSyncroAd.exeWindupdates adware variant
XWindows SysNotifymssecc.exe"Added by the AGENT-GFR TROJAN!"
XWINDOWS SYSTEMbeta.exe"Added by the MYTOB.DF WORM!"
XWINDOWS SYSTEMdcomuser.exe"Added by the MYTOB.EO WORM!"
XWINDOWS SYSTEMlf66prc.exe"Added by the MYTOB.GC WORM!"
XWINDOWS SYSTEMmsdev32.exe"Added by the MYTOB.EH WORM!"
XWINDOWS SYSTEMnec.exe"Added by the MYTOB-L WORM and variants!"
XWINDOWS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMninfoie.exe"Added by the MYTOB-EP WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB-CX WORM!"
XWINDOWS SYSTEMskybotx.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMsmoc.exe"Added by the MYTOB.FU WORM!"
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWINDOWS SYSTEMtest.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest2.exe"Added by the MYTOB.DJ WORM!"
XWINDOWS SYSTEMtest3.exe"Added by the MYTOB.DV WORM!"
XWINDOWS SYSTEMwdns33.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMwin.exe.exe"Added by the MYTOB.FA WORM!"
XWINDOWS SYSTEMwinaup.exe"Added by the MYTOB-DN WORM!"
XWINDOWS SYSTEMwinligon.exe"Added by the MYTOB.EP WORM!"
XWINDOWS SYSTEMwinmon.exe"Added by the MYTOB.GB WORM!"
XWINDOWS SYSTEMwinNTsys32.exe"Added by the MYTOB-DM WORM!"
XWINDOWS SYSTEMwinsvc32.exe"Added by the MYTOB.HH WORM!"
XWindows SystemWINSYS.exe"Added by the RBOT-AEF WORM!"
XWINDOWS SYSTEMwinsys33.exe"Added by the MYTOB.EK WORM!"
XWINDOWS SYSTEMwinvnc.exe"Added by the MYTOB.EU WORM!"
XWINDOWS SYSTEMwinxpserv.exe"Added by the MYTOB-BQ WORM!"
XWINDOWS SYSTEMxxx.exe"Added by the MYTOB.CZ WORM!"
XWindows Systemwinsys32.exe"Added by the MYTOB-IS WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.JU WORM!"
XWINDOWS SYSTEMbotzor.exe"Added by the ZOTOB WORM!"
XWINDOWS SYSTEMgothica.exe"Added by the MYTOB.HU WORM!"
XWINDOWS SYSTEMmsnl.exe"Added by the MYTOB.IK WORM!"
XWINDOWS SYSTEMper.exe"Added by the ZOTOB.C WORM!"
XWINDOWS SYSTEMtwunk_65.exe"Added by the MYTOB-EG WORM!"
XWINDOWS SYSTEMservce.exe"Added by the MYTOB-EI WORM!"
XWINDOWS SYSTEMservises.exe"Added by the ZOTOB-I WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWINDOWS SYSTEMmsn32.exe"Added by the MYTOB-FX WORM!"
XWINDOWS SYSTEMsky.exe"Added by the MYTOB.LB WORM!"
XWINDOWS SYSTEMWin32IMAPSVR.exe"Added by the MYTOB-FQ or MYTOB-FU WORMS!"
XWINDOWS SYSTEMwinsvc.exe"Added by the MYTOB.LM WORM!"
XWINDOWS SYSTEMmswins.exe"Added by the MYTOB.DP WORM!"
XWINDOWS SYSTEMmtrnqs.exe"Added by the MYTOB.IG WORM!"
XWINDOWS SYSTEMlogic.exe"Added by the MYTOB.IC WORM!"
XWINDOWS SYSTEMctech.exe"Added by the MYTOB-KD WORM!"
XWINDOWS SYSTEMefefefe.exe"Added by the MYTOB-KH WORM!"
XWINDOWS SYSTEMsvchost2.exe"Added by the MYTOB.OZ WORM!"
XWINDOWS SYSTEMskybot.exe"Added by the MYTOB.EB WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWindows Systemsystem.exe"Added by the MYTOB-GN WORM!"
XWindows System 32winsys_32.exe"Added by the RBOT-FTR WORM!"
XWindows System 32-Bat Servicewin32bat.exe"Added by the MYTOB.FI WORM!"
XWindows System BackupSysBackup.exeUnidentified malware
XWINDOWS SYSTEM By FEnRwindasz-updote.exe"Added by the MYTOB.LR WORM!"
XWINDOWS SYSTEM Cleanerh3.exe"Added by the MYTOB.EQ WORM!"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System ConfigurationWinfrw.exe"Added by the SOLUFINA TROJAN or the DOMWIS-J WORM!"
XWindows System Configurationwincfg.exe"Added by the AGOBOT.OP WORM!"
XWindows System ConfigurationWINCFG32.EXE"Added by the AGOBOT-TE WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows System ConfigurationWINSYS32.exe"Added by the SDBOT.AXK WORM!"
XWindows System DefenderWS[random characters].exe"Windows System Defender rogue security software - not recommended
XWINDOWS SYSTEM Dnswindsns.exe"Added by the MYTOB.EY WORM!"
XWINDOWS SYSTEM DNSPOOLhbmail.exe"Added by the MYTOB.FW WORM!"
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindows System Filecmxp.exe"Added by the SPYBOT.KHO WORM!"
XWINDOWS SYSTEM FILEwinload.exe"Added by the MYTOB.DK WORM!"
XWindows System GatewaySPOOLER.EXE"Added by a variant of the RBOT WORM!"
XWindows System Guardegun.exe"Added by the AGENT-NHY TROJAN!"
XWindows System Guardmsdn.exe"Added by the FAKEAV-BJD TROJAN!"
XWindows System Guardmsng.exe"Added by the EGGDROP-BO WORM!"
XWindows System Guardmsns.exe"Added by the DWNLDR-IGD TROJAN!"
XWindows System Initwinit32.exe"Added by a variant of the RBOT WORM!"
XWindows System Managerwinsystem.exe"Added by the RBOT-AN WORM!"
XWindows System ManagerCRSL.EXE"Added by the SDBOT.MG WORM!"
XWindows System Managersysconf.exe"Added by the MYTOB.AL WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWindows System Managercrssm.exe"Added by the RBOT-AFH WORM!"
XWINDOWS SYSTEM MANAGERspoolsvc.exe"Added by the MYTOB-LY WORM!"
XWindows System Managerwinsysmgr.exe"Added by the IRCBOT.BJG BACKDOOR!"
XWindows System Manager Loadersmsls.exe"Added by the AGOBOT.TF WORM!"
XWindows System Manager Procwinsmc.exe"Added by the RBOT.JH WORM!"
XWINDOWS SYSTEM MEMORY LOADERmemloader.exe"Added by the MYTOB-IN WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
Xwindows system notepadwnpsm.exe"Added by a variant of the RBOT WORM!"
XWindows System Restore ConfigurationSblhost.exe"Added by a variant of the SPYBOT WORM!"
XWindows System RestorerSystemRestorer.exe"Added by the DULOAD.C WORM!"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindows System Securitywinmp.exe"Added by the RBOT.IV WORM!"
XWindows System Securitysys32.pif"Added by the RBOT-AOL WORM!"
XWindows System Security Monitor[4 random letters].exe"Added by the PINKTON.A WORM!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
Xwindows system servicewinsock.exe"Added by the RBOT-MR WORM!"
XWindows System Servicewnuserv.exe"Added by the SPYBOT.ANDM WORM!"
XWindows System Service[worm filename]"Added by the RBOT.XG WORM!"
XWindows System SuiteWS[random characters].exe"Windows System Suite rogue security software - not recommended
UWindows System Traymsni.exe"Iambigbrother monitoring software"
XWindows System Trayswhost.exe"Added by an unidentified VIRUS
XWINDOWS SYSTEM UPDATExDcc.exe"Added by the MYOTB-EH WORM!"
XWindows System Update Toolsupds.exe"Added by the VANBOT.CX BACKDOOR!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System32windowsp.exe"Added by the MYTOB.GD WORM!"
XWindows System32winsys32.exe"Added by the SDBOT-AHS WORM!"
XWindows System32clsas32.exe"Added by the RBOT-AZO WORM!"
XWindows System32explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
XWindows System32System32.exe"Added by the SDBOT-ALI WORM!"
XWindows SYSTEM32Realplayer.exe"Added by the SPYBOT.ZH WORM!"
XWindows System32wingrd32.exe"Added by a variant of the RBOT WORM!"
XWindows System32windows32.exe"Added by the RBOT-FPB WORM!"
XWindows System32 Driverclsass32.exe"Added by the SDBOT-AGG WORM!"
XWindows System32 Kernelsystem32.exe"Added by the SDBOT-AAT WORM!"
XWindows SystemDllSYSTEMDLL.EXE"Added by the AGOBOT-LP WORM!"
XWINDOWS SYSTEMnservicces.exe"Added by the MYTOB-EL WORM!"
XWindows Systemnmgstagmr.exe"Added by the MYTOB.S WORM!"
XWindows Systems16winjews16.exe"Added by the SDBOT-CXT WORM!"
XWindows SYStryspoolsvr.exe"Added by the SDBOT.GN BACKDOOR!"
XWindows SYStrysystry.exe"Added by the SDBOT-E WORM!"
XWindows Sz Hostwinshvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Task ManagerACCOUNT_DETAILS.DOC.exe"Added by the QUATERS.A WORM!"
XWindows Task Managertaskmgn.exe"Added by the AGENT-CIP BACKDOOR!"
XWindows Task Managertaskmrg.exe"Added by the MYTOB.AV WORM!"
XWindows Task Managertaskgmr.exe"Added by the MYTOB.BJ WORM!"
XWindows Task Managertaskmg.exe"Browser hijacker - identified by DrWeb antivirus as ""Trojan.StartPage.601"""
XWindows Task Managertaskmngr.exe"Added by the RBOT-ANM WORM!"
XWindows Task Manager Emulatorkennewr.exe"Added by the SPYBOT-FA WORM!"
XWindows Task Mgrmstasks.exe"Added by the IRCBOT.UN BACKDOOR!"
XWindows Task Mgr!mstasker.exe"Added by the IRCBOT.OE BACKDOOR!"
XWindows Task Schedulerasijdie.exeAdded by an unidentified WORM or TROJAN!
XWindows Task Service (32-bits)tasksys.exe"Added by the DREFIR.D WORM!"
XWindows TaskAdWintaskad.exeWindupdates adware variant
XWindows Taskbar Managerinternat.exe"Added by the PROTORIDE-H WORM!"
XWindows Taskbar Manager[path to file]"Added by the PROTORIDE.B WORM!"
XWindows Taskbar Systemtasksys.exe"Added by a variant of the SDBOT WORM!"
XWindows Taskmanagerlsassx.exe"Added by the KELVIR.E WORM!"
XWindows Taskmanageriexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Taskmanagerservice.exe"Added by the PUSHBOT.OR WORM!"
XWindows Taskmanagersvchost.exe"Added by the IMBOT.AC WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Taskmanagertaskmrg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Taskmanagertaskngr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Taskmanagertskmngr.exe"Added by the IRCBOT.DHR BACKDOOR!"
XWindows Taskmanagerwdtsvc.exe"Added by the PUSHBOT.AU WORM!"
XWindows Taskmanagerwinpifviewer.exe"Added by the PUSHBOT.BB WORM!"
XWindows Taskmanagerwinrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Taskmanagertaskxphost.exe"Added by the PUSHBOT.BI WORM!"
XWindows Taskmanager Datacsrrss.exe"Added by the RBOT-BBH WORM!"
XWindows TaskManager Servicewindns32.exe"Added by the AGOBOT-JP WORM!"
XWindows TCP/IPwintcp.exe"Added by the AGOBOT-ZH WORM!"
XWindows Telnet Serverwintel.exe"Added by the AGOBOT-MW WORM!"
XWindows Temperate Serviceswintmp.exe"Added by the SLENFBOT.ZW WORM!"
XWindows Terminal Managerrmbsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows Timewinmgr.exe"Added by the RBOT-XC WORM!"
XWindows Time ServerTimeSRV.exe"Added by the SPYBOT.DNC WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows TMSVPHOST.exe"Added by a variant of the RBOT WORM!"
XWindows TMrundlI32.exe"Added by the RBOT.EL BACKDOOR!"
XWindows TMwindowssys32.exe"Added by a variant of the RBOT WORM!"
XWindows TMWinxSys.exe"Added by a variant of the RBOT WORM!"
XWindows TMpdpatbcyj.exe"Added by the RBOT.FEF WORM!"
XWindows TMSyss.exe"Added by the RBOT.ADF BACKDOOR!"
XWindows Tracking Clientctwsvc.exe"Added by the AGENT-GMB TROJAN!"
XWindows UDPwinudp.exe"Added by the IRCBOT.GAT WORM!"
XWindows UDP Controlwinudspm.exe"Added by a variant of the SDBOT WORM! See here"
XWindows UDP Control Centerauth.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control CenterehSched.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerfxstaller.exe"Added by the AGENT-IEE TROJAN!"
XWindows UDP Control Centerinstaller.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows UDP Control Centermsnmngs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centermsnpd.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centermswinudpmgr32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows UDP Control Centertaksmrg.exe"Added by the AGENT.WOH TROJAN!"
XWindows UDP Control Centertmps.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinlive32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinmsn.exe"Added by the SDBOT.EBA BACKDOOR!"
XWindows UDP Control Centerwinrofl32.exe"Added by the LDPINCH-RZ TROJAN!"
XWindows UDP Control Centerwinudpmg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgrs.exe"Added by the DROPPER.CMV TROJAN!"
XWindows UDP Control Centerwinudpmsgr.exe"Added by the SDBOT.GAV WORM!"
XWindows UDP Control Centerwinupmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinuscn32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwinudpmgr.exe"Added by the DLOADR-HQL TROJAN!"
XWindows UDP Control Centerfxsteller.exe"Added by the IRCBOT-J BACKDOOR!"
XWindows UDP Control Centermsnsmsgrs.exe"Added by the PUSHBOT.MF WORM!"
XWindows UDP Control Centerwinmgrs.exe"Added by the PUSHBOT.MY WORM!"
XWindows UDP Control Managerwinudpmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Upaterundll.exe"Added by the HAKO TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Update[filename]"Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
Xwindows updateuddater.exe"Added by the LEOX TROJAN!"
XWindows Updatewudate.exe"Added by the AGOBOT.ML WORM!"
XWindows Updatewupdate.exe"Wengs adware"
Xwindows updatesychost.exe"Added by the LEOX.B WORM!"
XWindows UpdateWuamgrd.exe"Added by a variant of the SPYBOT WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows Updatehost32.exe"Added by the RBOT-GU WORM!"
Xwindows updatewuraclt.exe"Added by the RBOT-PO WORM!"
Xwindows updateWuanclt.exe"Added by the RBOT.XZ WORM!"
XWindows Updatesvchosts.exe"Added by the FRUCTA TROJAN!"
XWindows Updateebay.exe"Added by the GAOBOT.BUU WORM!"
XWindows Updatewindows.exe"Added by the RBOT-RB WORM!"
Xwindows updatewuaurlt.exe"Added by the RBOT.ADG WORM!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinmguard.exe"Added by the RBOT-EM WORM!"
XWindows Updatewuampd.exe"Added by the RBOT.UM WORM!"
Xwindows updatewuarclt.exe"Added by the RBOT-OF WORM!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemsnwinsb.exe"Added by the RBOT-AAH WORM!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
Xwindows updateMicrosoft.exe"Added by the LMIR.A TROJAN!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
Xwindows updatemsnsever.exe"Added by the RBOT-AHN WORM!"
XWindows Updatetaskmr.exe"Added by the MYTOB-GZ WORM!"
XWindows Updateupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Updatewininfo.exe"Added by the MYTOB.GA WORM!"
XWindows Updatewinlogin.exe"Added by the BANKER-DV TROJAN!"
XWindows Updatemsnupdates.exe"Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
XWindows Updateqtask.exe"Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here"
Xwindows updatereal.exe"Added by the LEGMIR-AU WORM!"
XWindows Updatewindowsx.exe"Added by the BANCD-A TROJAN!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatewupdmgr.exe"Added by the BANCBAN-FC TROJAN and variants!"
XWindows Updatecsrss.exe"Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows UpdateXPLoogNT.exe"Added by the BANCD-B TROJAN!"
XWindows Updateinstall.exe"Added by the BANKER-IB TROJAN!"
XWindows Updatemsi.exe"Added by the BANKER-XB TROJAN!"
XWindows UpdateSqltob.exe"Added by the DASHER.A WORM!"
Xwindows updatelogonuit.exe"Added by the LEGMIR-AO TROJAN!"
XWindows Updateavkir.exe"Added by the RBOT-GJP WORM!"
XWindows Updateeasypwnt.exe"Added by a variant of the SDBOT WORM!"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows UpdateSecretStub.exe"Added by the SRAMLER.C WORM!"
XWindows UpdateWinload.exe"Added by the DEDMIR-A WORM!"
XWindows Updatetaskngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updateusnsvc.exe"Added by the KOBOT-C WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWindows UpdateMcAfee.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
XWindows UpdateMcAfee3.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatemsnsa32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Updatewuauclt32.exe"Added by the SDBOT.DHY WORM!"
XWindows Updatedllhostup.exe"Added by the BANCBAN-NB TROJAN!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Updatesysdrv.exe"Added by the AGENT-IYE TROJAN!"
XWindows Updatewinupupdate1.exe"Added by the RBOT-UV WORM!"
XWindows Updateklass.exe"Added by the BIFROSE-ZH TROJAN!"
XWindows UpdatewinlogonEvt.exe"Added by the VB-DXM TROJAN!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
XWindows Updatefdos.exe"Added by the RBOT-COG WORM!"
XWindows Updateleak32x.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows updatemsb32.exe"Added by the GAOBOT.CG WORM!"
XWindows updatesvdhost.exe"Added by the GAOBOT.CG WORM!"
XWindows Updatetskmngr.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows Updatewindb32.exe"Added by the AGENT.ALY BACKDOOR!"
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update 32winlogons.exe"Added by the FORBOT-FI WORM!"
XWindows Update 32rempss.exe"Added by the FORBOT-FW WORM!"
XWindows Update 32slsys.exe"Added by the FORBOT-FT WORM!"
XWindows update 32bitwinupd32.exe"Added by the SDBOT.BE WORM!"
XWindows Update 63shupd64.exe"Added by the FORBOT-GA WORM!"
XWindows Update 64nbupd64.exe"Added by a variant of the FORBOT WORM!"
XWindows Update 64WinV.exe"Added by the FORBOT-FP WORM!"
XWindows Update Auto Updatewuaumgr.exe"Added by a variant of the SPYBOT WORM!"
XWindows Update Automatic Updates[path to backdoor]"Added by the VBBOT.AM BACKDOOR!"
XWindows Update Automationwinuptdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwaucult.exe"Added by a variant of the RBOT WORM!"
XWindows Update AutoUpdate Clientwuauclt.exe"Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process
XWindows Update AutoUpdate Client Productwuauct.exe"Added by the AGOBOT.ACL WORM!"
XWindows Update Centersvthx.exe"Added by the STUBBOT.A WORM!"
XWindows Update CenterW32RSA.exeAdded by an unidentified WORM or TROJAN!
XWindows Update Checksyslodr.exe"Added by the SMALL.LU TROJAN!"
XWindows Update Checker[random filename]Adware downloader trojan
XWindows Update Checkermsupdte32.exe"Added by the SDBOT-AEF WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Clientwuclient.exe"Added by the SMALL-RN TROJAN!"
XWindows Update Client Servicewindrvl32.exe"Added by the AGOBOT-MM TROJAN!"
XWindows update configsvhost.exe"Added by the SDBOT-PF WORM!"
Xwindows update configuratorsvghost.exe"Added by a variant of the SPYBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows Update Dravendraven.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Update Firewall Systemctfmoom.exe"Added by the RBOT-GAN WORM!"
XWindows Update Firewall Systemwinmsfw.exe"Added by the RBOT-EEO WORM!"
XWindows Update Firewall Systemctfmom.exe"Added by the SPYBOT.ANDM WORM!"
XWindows Update GUI Executable x32xwupdategux32.exe"Added by the RBOT.CXY WORM!"
XWindows Update Hostwinupsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows Update IPv6 LayerWIN32IPV6.EXE"Added by the RBOT.DUD WORM!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdmngr.exe"Added by the RANDEX.BTB WORM!"
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Managerbootwiz.exeAdded by the MYBOT WORM!
XWindows Update ManagerWindowsUpdateManager.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Update Manager for NTwupdmgr32.exe"Added by the SDBOT.AH WORM!"
Xwindows update microsoftupdatem.exe"Added by the RBOT-CHE WORM!"
XWindows Update Monitoring Servicewinupdt.exe"Added by the RBOT-PL WORM!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Servicecsrs.exe"Added by the AGOBOT-NI WORM!"
XWindows Update Servicesmcg.exe"Added by the SDBOT.QY WORM!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Serviceupdate32.pif"Added by the RBOT-ALC WORM!"
XWindows Update Servicetrest.exeIdentified by BitDefender as a variant of the PEED TROJAN!
XWindows Update Servicewmiprvse32.exe"Added by the AGOBOT.NI WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Update Servicemsupdate32.exe"Added by the DLOADR-CRJ TROJAN!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update serviceswins32svcs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Serviceswinupdate32.exe"Added by a variant of the RBOT WORM!"
XWindows Update Softwaresystem.exe"TOFGER.BX spyware"
XWindows Update SP3Windat.EXE"Added by the RBOT-GTS WORM!"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Update Systemmswins.exe"Added by the IRCBOT.DN WORM!"
XWindows Update System Shellsvhostcs32.exe"Added by the RBOT-AAZ WORM!"
XWindows Update V6[random filename]"Added by the RBOT-KT WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updatedupdatr.exe"Added by the RBOT-AYB WORM!"
XWindows Updaterwupdmgr32.exe"Added by a variant of the DOS.AUTOCAT TROJAN!"
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows Updatersvigost.exe"Added by the RBOT-VS WORM!"
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updatersdsys.exe"Added by the FORBOT-JG WORM!"
XWindows Updater Onlinewinupdatexx.exe"Added by a variant of the RBOT WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Service Managerwinupdatr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
Xwindows updaterswinupdats.exe"Added by the SPYBOT-IS WORM!"
XWindows Updateslsassx.exe"Added by a variant of the SDBOT WORM!"
XWindows Updateswinupd32.exe"Added by the MYTOB.CE WORM!"
XWindows Updatesw32dns.exe"Added by the SDBOT-BFW WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows Updating Serviceupdating.pif"Added by the RBOT-ALW WORM!"
XWindows Updtee MgnrW1NT45K.exe"Added by the MYTOB.DC WORM!"
XWindows Upgrate Utilitywinulty.exe"Added by the AUTORUN-ASR WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows USB 2.0 Driverusb2ctrl.exe"Added by the RBOT-BIW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB controlerwinusb.exe"Added by the RBOT-HR WORM!"
XWindows USB Driver SupportWindowsusb.exe"Added by a variant of the SPYBOT WORM!"
XWindows USB Hub Managerusbhub.exe"Added by the RBOT-BJX WORM!"
XWindows USB Monitorservupdate.exe"Added by the IRCBRUTE.AQ TROJAN!"
XWindows USB Printerexe.exe"Added by a variant of the RBOT WORM!"
XWindows USB Printerunqgod.exe"Added by the RBOT.BKC BACKDOOR!"
XWindows USB Printerxqteby.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows USB Service666.exe"Added by the MYTOB.AR WORM!"
XWindows USB v3wsvc.exe"Added by a variant of the SDBOT WORM!"
XWindows USBDmsifirewall.exeAdded by an unidentified WORM or TROJAN!
XWindows User Mode Driver Managerwdfmrg.exe"Added by the SDBOT-ZN WORM!"
XWindows User Starterwinuser32.exe"Added by the RBOT.SN WORM!"
NWindows Version Checkver_chk.exe"Version checker for CyberAudioLibrary - ""a new way to exchange information through the Internet"""
XWindows Version Servicesysvers.exe"Added by the SLENFBOT.IF WORM!"
XWindows Version Servicesysvers32.exe"Added by the SLENFBOT.HZ WORM!"
XWindows videovide_32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Video Acquisition (WVA)wvsvc.exe"Added by the AGOBOT.YM WORM!"
XWindows Video Componentwvcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Video Driversvideons32.exe"Added by the GAOBOT.AZT WORM!"
XWindows Video DriversVIDEONS3.EXE"Added by the AGOBOT-KZ BACKDOOR!"
XWindows Video Inputviwsvc.exe"Added by the SLENFBOT.GS WORM!"
XWindows Virtual Managervmnat.exe"Added by the SILLYFDC.BCB WORM!"
XWindows Virtual Serviceswinvirtual.exe"Added by the SLENFBOT.IE WORM!"
XWindows Virtual Serviceswinvirtual32.exe"Added by the SLENFBOT.IB WORM!"
XWindows Virus Controlplou.exe"Added by the SDBOT-ACZ WORM!"
XWindows Virus Scannerwinvsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Vista Corparation Agent Serviceswinxp_sp3.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Volume Controlongsvc.exe"Added by the SLENFBOT.DZ WORM!"
XWindows Web Serviceslocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicesspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Servicestcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Web Serviceswebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Winhlp32 Stub Servicewinhlp32.pif"Added by the AIMBOT.AH TROJAN!"
XWindows WKSwsass.exe"Added by the SDBOT-DK WORM!"
XWindows WKS Serviceswkssvr1.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows WMF Fixwinfix.exe"Added by the RBOT-FTQ WORM!"
XWindows Workstationmpci.exe"Added by a variant of the RBOT WORM!"
XWindows Workstationmsup32a.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindows Workstation Servicewkssvc.exe"Added by the IRCBOT-AAI WORM!"
XWindows Workstation Service (32-bits)wkssvc32.exe"Added by a variant of the SDBOT WORM!"
XWindows Workstation Service [5.1-2600]windrm.exe"Added by the RBOT-CNY WORM!"
XWindows Workstation Start Servicemslanmgr.exe"Added by a variant of the RBOT WORM!"
XWindows Xpnortonguard.exe"Added by the MYTOB-DZ WORM!"
XWindows xpWins.exe"Added by the RBOT.VH BACKDOOR!"
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindows Xp Service Pack 2svchost.exe"Added by the XPLOS-A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XWindows XP SP2 KeyGenWindows XP SP2 KeyGen.exe"Added by the TIBICK-C WORM!"
XWindows Zero Spoolernmvcs.exe"Added by the SLENFBOT.JQ WORM!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.