N | AOTray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
|
X | aouei | sysrtmvs.exe | "Chivio dialer"
|
Y | APC UPS Status | Display.exe | "APC PowerChute® Personal Edition status icon"
|
X | APcDefender | APcDefender.exe | "APcDefender rogue security software - not recommended |
X | APCProtect.exe | APCProtect.exe | "APCProtect rogue security software - not recommended |
X | APcSafe | APcSafe.exe | "APcSafe rogue security software - not recommended |
X | APcSecure | APcSecure.exe | "APcSecure rogue security software - not recommended |
U | APC_SERVICE | mainserv.exe | "APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
|
Y | apc_tray | apc_tray.exe | Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
|
X | APD123 | APD123.exe | "PacerD Media/Pacimedia.com adware"
|
X | aphex | aphex.exe | "Added by the IRCBOT-OH TROJAN!"
|
X | Api**.exe [* = random char] | Api**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X | Api**32.exe [* = random char] | Api**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X | API32 | api32.exe | "Added by the IRCBOT-B TROJAN!"
|
X | APIClass | lexplore_.exe | "Added by the MSNOPT-A TROJAN!"
|
X | APIMon | apimonx.exe | Added by the TIBSER.A downloader TROJAN!
|
X | APIMon | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN!
|
X | APIMon | msreg.exe | "Added by the DROPPER.Z TROJAN!"
|
X | apisvc.exe | apisvc.exe | "Added by a variant of the LAMEBOT TROJAN!"
|
U | APL | APL.exe | "Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup |
X | apmanager.exe | apmanager.exe | "AP Manager ransomware download manager - not recommended |
? | Apmsrv9x | APMSRV9X.EXE | "Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
|
U | Apoint | Apoint.exe | Touchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
|
X | App**32.exe [* = random char] | App**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X | App.EXEName | [path to worm] | "Added by the BODIRU WORM!"
|
X | ApPache System | ApPache.exe | "Added by the RBOT-YP BACKDOOR!"
|
U | Appcon | vAppCon.exe | "Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
|
X | appconn | appconn.exe | "Added by the CARGAO WORM!"
|
U | AppExtender | AppExtCB.exe | "Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
|
X | appis.exe | appis.exe | "Added by the AGENT-BC TROJAN!"
|
N | AppleSyncNotifier | AppleSyncNotifier.exe | "From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone |
X | AppletINIT | INITIATE.EXE | "Added by the AGOBOT.XV TROJAN!"
|
Y | Application | mdmsetsp.exe | "Aztech Labs modem driver"
|
X | Application | csrss.exe | "Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Application Adapter | abvsvc.exe | "Added by the CHECKOUT WORM!"
|
U | Application Explorer | Naldesk.exe | "Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
|
U | Application Explorer | NalView.exe | "Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
|
X | Application Explorer | appexplr.exe | "Added by the AGENT-NMO TROJAN!"
|
X | Application In System | Snxmsh.exe | "Added by the AGENT-LNV TROJAN!"
|
N | Application Launcher | Application Launcher.exe | "System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
|
X | Application Layer Browser | abgsvc.exe | "Added by the ULPM.FX TROJAN!"
|
X | Application Layer Gateway Service | algs.exe | "Added by the LINKBOT.M WORM!"
|
X | Application Layer Scheduler | agtsvc.exe | "Added by the IRCBOT.BJJ BACKDOOR!"
|
X | Application Layer Services | avrsvc.exe | "Added by the IRCBOT.BJM BACKDOOR!"
|
X | Application Manager | acnsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
X | Application Manager | apnsvc.exe | "Added by the SMALLTRO.FN TROJAN!"
|
X | ApplicationProtocolRun | smsbvl32.exe | "Added by the IRCBOT-CX TROJAN!"
|
U | AppPlus | AppPlus.exe | "AppPlus - ""menu bar or tray launcher that docks to your desktop |
Y | Apvxd | APVXDWIN.EXE | "Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
|
Y | Apvxdwin | APVXDWIN.EXE | "Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
|
Y | APVXDWIN | ClShield.exe | """Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam |
Y | Apwheel | Apwheel.exe | Wheel support for an Alps mouse
|
X | apyginapygin | simenu.exe | "Added by the SDBOT.BTR WORM!"
|
U | AQ3HelperStartUp | AQ3HEL~1.EXE | "ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
X | aqadcup.exe | aqadcup.exe | "Added by the AGENT.BG WORM!"
|
Y | Aqua Dock | Aqua Dock.exe | "Aqua Dock - 'free program that allows you to have an ""OS X"" style |
X | Aqujyjax | [path to file] | "Added by the RANCK-CQ TROJAN!"
|
X | Aqujyjax | aqujyjax.exe | "Added by the SDBOT-YC WORM!"
|
? | ArabLionZ Drive | ArabLionZ.Drive.exe | "ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
|
Y | ArcaCheck | ArcaCheck.exe | "Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
|
X | arcaderockstar | arcaderockstar32.exe | "Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean |
X | Archive | archive.exe | "Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
|
X | ARCHIVE CONTROL | fixupdattr.exe | "Added by the MYTOB.GU WORM!"
|
N | ArcSoft Connect | ACDaemon.exe | "Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia |
N | ArcSoft Connection Service | ACDaemon.exe | "Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia |
U | Arctosa | razerhid.exe | "Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
|
U | Ardamax Keylogger | akl.exe | "Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
|
N | ares | ares.exe | """Ares is a free open source file sharing program that enables users to share any digital file including images |
N | areslite | AresLite.exe | """Ares is a free open source file sharing program that enables users to share any digital file including images |
U | Argentum Backup | ab.exe | "Argentum Backup - a small backup program that lets you easily back up your documents and folders"
|
X | argq32 | csrss_32.exe | "Added by the RBOT-CPM WORM!"
|
X | Aritima | aritima.exe | "Added by the ARITIM WORM!"
|
U | ARMOR2NET | Armor2net.exe | "Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue |
X | ArmorDefender | ArmorDefender.exe | "ArmorDefender rogue security software - not recommended |
U | army logo | readmename.exe | "Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
|
X | aromis | aromis.exe | "Added by the NUWAR.JQ WORM!"
|
N | AROReminder | aro.exe | "Advanced Registry Optimizer - ""scan |
U | Arovax AntiSpyware | arovaxantispyware.exe | "Part of Arovax AntiSpyware from Arovax |
Y | Arovax Shield | ArovaxShield.exe | "Part of Arovax Shield from Arovax |
U | arovaxantispyware | arovaxantispyware.exe | "Part of Arovax AntiSpyware from Arovax |
Y | ArovaxShield | ArovaxShield.exe | "Part of Arovax Shield from Arovax |
U | ARPWRMSG | ARPWRMSG.EXE | """Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input |
U | Artera | arteraui.exe | "Artera Turbo Internet Accelerator - ""surf faster |
? | AS00 Gear511 | Gear511.exe | "Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
|
N | AS00_Gear511 | Gear511.exe | Netgear wireless LAN configuration utility
|
U | AS00_WN511B | WN511B.exe | "Netgear RangeMax NEXT wireless adapter configuration utility"
|
? | AS00_WPN511 | WPN511.exe | "NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
|
X | asam | asam.exe | "Added by the FAKEAV-BGU TROJAN!"
|
X | ASC-AntiSpyware | WinCleaner.exe | "WinCleaner 2009 rogue security software - not recommended |
X | ASC-AntiSpyware | WinAntivirus.exe | "Win Antivirus Vista/XP rogue security software - not recommended |
X | asc32 | asc 2.1.exe | "AntiSpyCheck rogue spyware remover - not recommended |
X | asccacA | asacsqgl.exe | "Added by the MULTIDRP.AA TROJAN!"
|
X | ASDd | ASDd.exe | "AntiSpywareDeluxe rogue security software - not recommended |
X | ASDPLUGIN | dsldbaccess.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | canada.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | france.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | fullgames.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | 100171be.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | 100176br.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | adult1.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | Austria.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | belgium_nm.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | czech.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | dbaccess.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | dslgeaccess.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | Finland.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | geaccess.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | mexico.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | netherlands.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | turkey.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | uk_nm.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | Xadult1.exe | "AsdPlug premium rate adult content dialer"
|
X | ASDPLUGIN | temp532.exe | "AsdPlug premium rate adult content dialer"
|
X | asdsaxcxz13 | dasxcsx13.exe | "Added by the LEGMIR-ARF TROJAN!"
|
X | asdx | xwinrpc32.exe | "Added by the AGOBOT.VO WORM!"
|
N | ASE Scheduler | ASE Scheduler.exe | "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU |
Y | Ashampoo AntiSpyWare 2 | AntiSpyWare2Guard.exe | "Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO |
Y | Ashampoo AntiSpyWare 2 Guard | AntiSpyWare2Guard.exe | "Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO |
Y | Ashampoo AntiVirus Service | GuardGui.exe | "System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
|
U | Ashampoo Core Tuner | ct.exe | "Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
|
Y | Ashampoo FireWall | FireWall.exe | "Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
|
Y | Ashampoo FireWall PRO | FireWall.exe | "Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
|
U | Ashampoo HDD Control Guard | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
U | Ashampoo Magical Defrag | aDefragCtrl.exe | "System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service |
U | Ashampoo Magical Optimizer Taskplaner | AMO_TA~1.EXE | "Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files |
U | Ashampoo Magical Optimizer Taskplaner | AMO_Taskplaner.exe | "Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files |
N | ashampoo Magical UnInstall | MagicalUnInstall.exe | "Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation |
U | Ashampoo PopUpBlocker | PopUpKiller.exe | "Ashampoo popup blocker |
N | ashampoo UnInstaller Watcher | UIWatcher.exe | "Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2 |
Y | ashAvast | ashAvast.exe | "Part of Avast antivirus"
|
X | ashcap | servirsess.exe | "SpySure spyware"
|
X | ashDip.exe | ashDip.exe | "Added by the DROPR-CZ TROJAN!"
|
Y | ashDisp | ashDisp.exe | "System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner |
X | ashDsp.exe | ashDsp.exe | "Added by a variant of the SDBOT WORM!"
|
X | ASHLT | Ashlt.exe | "Ashlt adware"
|
Y | ashMaiSv | ashmaisv.exe | "E-mail scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
|
X | Asia | easm.exe | "PurityScan adware"
|
X | Asicfc | icfca.exe | "Added by the AGENT.AAJE WORM!"
|
U | AsioReg | regsvr32.exe ctasio.dll | "ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
|
U | AsioThk32Reg | rregsvr32.exe ctasio.dll | "ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
|
U | ASK | rundll32.exe [path] ASK.dll rdl | "Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
X | asl | Aslru.exe | "Added by the BANCOS-CU TROJAN!"
|
U | ASM | ASMonitor.exe | "Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses |
U | Asmw Soft Popups Burner | popups burner.exe | "Popup blocker |
X | asnconsole | msasn.exe | "Added by the RBOT.EVU TROJAN!"
|
X | ASocksrv | SocksA.exe | "Added by the VB.CBW WORM!"
|
X | asp-srvc | asp-srvc.exe | "Added by the AGOBOT-KG WORM!"
|
X | ASP.NET State Service | csrss.exe | "Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | ASP.NET State Service | crsass.exe | "Added by the BANLOAD-M TROJAN!"
|
X | ASP.NET State Service | servicos..exe | "Added by the DADOBRA-I TROJAN!"
|
N | asp4tray | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
|
? | AspireService | AspireService.exe | "Found on Acer laptops |
Y | AspireTimeMachine | acertmb.exe | "System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP |
X | ASpyC | ASpyC.exe | "AntiSpyCheck rogue spyware remover - not recommended |
X | asr64_ldm.exe | asr64_ldm.exe | "Added by the Dr. Guard rogue security software - not recommended |
X | asrupdate.exe | asrupdate.exe | "Added by the VB.ATZ TROJAN!"
|
X | Ass and titties | CMD32.EXE | "Added by the SDBOT-GG BACKDOOR!"
|
X | assistse | ASSISTSE.EXE | "CnsMin (Chinese Keywords) hijacker related"
|
X | AST | AST.exe | "AutoStarter parasite"
|
U | ASTART | astart.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
|
N | asTray | Astray.exe | "Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer"
|
N | Astro | Astro.exe | Checks for updates to Quicken on a system reboot
|
X | Astrum | Astrum.exe | "Astrum Antivirus Pro rogue security software - not recommended |
X | asus | asus.exe | "Added by the RBOT-OC WORM!"
|
? | ASUS Camera ScreenSaver | ASScrProlog.exe | "Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe |
N | ASUS Live Update | ALU.exe | ASUS Live Update utility for their motherboards
|
N | ASUS Probe | AsusProb.exe | ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
|
? | ASUS Screen Saver Protector | ASScrPro.exe | "Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe |
U | ASUS SmartDoctor | VGAProbe.exe | ASUS video card fan/thermal monitor
|
U | ASUS TweakEnable | astart.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
|
? | AsusACPIServer | AsAcpiSvr.exe | "Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
|
U | AsusEPCMonitor | AsEPCMon.exe | "Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
|
N | ASUSGamerOSD | GamerOSD.exe | "GamerOSD by ASUSTek - for ""real-time overclocking |
N | ASUSKey | V38SHELL.EXE | System tray Icon for quickly changing video modes
|
? | AsusStartupHelp | AsRunHelp.exe | "Unknown ASUS motherboard utility. What does it do and is it required?"
|
X | asussvc | asussvc.exe | "Added by the AGENT-FPB TROJAN!"
|
U | AsusTray | AsTray.exe | "Part of the ACPI driver for the Asus Eee PC range. Watches the sensors of the motherboard such as power and temperature"
|
U | asustweakenable | ATweak.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
|
N | ASUSWebStorage | ASUSWSDashBoard.exe | "System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
|
N | AsusWSDashBoard | ASUSWSDashBoard.exe | "System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
|
N | ASWDP | ASWDP.exe | "MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
|
X | ASWnk | aswnk.exe | Adult content dialler
|
U | AT&T Self Support Tool | matcli.exe | "AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
U | AT-Watch | ATWatch.exe | Anti-Trojan Watch - trojan detector
|
X | atapidrv | atapidrv.exe | "Added by the AGOBOT-SL WORM!"
|
U | atchk | atchk.exe | "AMT Status Message from Intel. Users can manage this |
X | atf.exe | pgs.exe | "Part of the PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
|
X | atf_reinstall | atf.exe | "Part of the AVSystemCare rogue security software - not recommended. See here"
|
U | Athan | Athan.exe | "Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world"
|
U | ATI 2D Component | Ati2mdxx.exe | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
|
X | ATI Active Graphics Card Monitor | atievx.exe | "Added by the IRCBOT-TL WORM!"
|
X | ATI AS Filter | msnse.exe | "Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines |
N | ATI CATALYST System Tray | CLI.exe SystemTray | "System Tray access to ATI's Catalyst Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
|
X | Ati Control Panel | atiphexx.EXE | "Added by the RBOT-BR WORM!"
|
X | ATI Cpanel | atiphexx.exe | "Added by the AGOBOT-NV WORM!"
|
U | ATI Desktop Component | ATIPTAXX.EXE | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution |
N | ATI DeviceDetect | ATIDtct.EXE | Utility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
|
X | ATI Display | ATIDisplay.exe | "Added by the BDOOR-AFH BACKDOOR!"
|
X | ATI Display Driver | atixd.exe | "Added by the RBOT-FOV WORM!"
|
X | Ati Display Settings | atividx.exe | "Added by the RBOT-GAS WORM!"
|
N | ATI GART Set-up Utility | Atigart.exe | "Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one |
U | ATI Launchpad | launchpd.exe | "Convenient way to start all your Multimedia Center applications (DVD |
X | ATI Rage3d Pro | AtiRage4dPro.exe | "Added by the AGOBOT-OG WORM!"
|
Y | ATI Remote Control | ATIRW.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it
|
Y | ATI Remote Control | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it
|
N | ATI Scheduler | Atisched.exe | Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
|
N | ATI Task Application | Atitkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
|
N | ATI Task Application (Atikey) | Atitask.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
|
U | ATI Technologies Inc. HydraVision Desktop Manager | HydraDM.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes |
U | ATI Technologies Inc. HydraVision Viewport | HydraMD.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates |
X | ATI Technology Startup | techstart.exe | "Added by the RBOT-AEU WORM!"
|
X | ATI Video Driver Control | atigfx.exe | "Added by the RBOT-FWL WORM!"
|
X | ATI Video Driver Control | btorrent.exe | "Added by a variant of the IRCBOT TROJAN!"
|
X | ATI VIDEO REGKEY | ati2vid.exe | "Added by the SDBOT.UR WORM!"
|
? | Ati2cwxx | Ati2cwxx.exe | "For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it"
|
X | Ati2evxx | Ati2evxx.com | Added by the BACKDOOR-CPC TROJAN!
|
X | ati2f104 | ati2f104.exe | "Added by the DLOADR-BBW TROJAN!"
|
U | Ati2mdxx | Ati2mdxx.exe | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
|
N | ATICCC | cli.exe runtime | "ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
|
N | ATICCC | CLIStart.exe | Puts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
|
X | AtiCpanel | atiphexx.exe | "Added by the AGOBOT.IL WORM!"
|
X | aticpaxx.exe | aticpaxx.exe | "Added by the RBOT-XP WORM!"
|
U | AtiCwd | AtiCwd.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
U | AtiCwd | AtiCwd32.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
U | AtiCwd | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
U | AtiCwd32 | AtiCwd.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
U | AtiCwd32 | AtiCwd32.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
U | AtiCwd32 | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
|
X | AtiDisplayDrv | atidrvxx.exe | "Added by the RBOT-VZ WORM!"
|
X | atidriver | reaIplayer.exe | "Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename |
N | AtiGart | Atigart.exe | "Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one |
N | AtiKey | AtiKey32.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
|
N | AtiKey | atiptkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Control Panel → Display
|
N | Atikey | Atitask.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
|
U | ATIMACE | MACE.exe | ATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) component
|
U | ATIModeChange | Ati2mdxx.exe | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
|
X | AtiPanel | atip.exe | "Added by the TACTSLAY.U TROJAN!"
|
X | atipatxx | atipatxx.exe | "Added by the SMALL-ED TROJAN!"
|
N | ATIPOLAB | ati2evxx.exe | "Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented |
U | ATIPOLAB | ati2evae.exe | ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
|
N | ATIPOLL | ati2evxx.exe | "Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented |
U | AtiPTA | Ati2ptxx.exe | "Control panel for the ATI series of video cards allowing access to such features as display resolution |
U | ATIPTA | ATIPTAXX.EXE | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution |
U | AtiPTA | Atiptaab.exe | "Control panel for the ATI series of video cards allowing access to such features as display resolution |
U | AtiPTAAA | Ati2ptxx.exe | "Control panel for the ATI series of video cards allowing access to such features as display resolution |
U | AtiPTAAA | ATIPTAXX.EXE | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution |
U | atiptaxx | Ati2ptxx.exe | "Control panel for the ATI series of video cards allowing access to such features as display resolution |
U | ATIPTAXX | ATIPTAXX.EXE | "Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution |
X | atiptext | atiptext.exe | "Added by the COSIAM-A TROJAN!"
|
U | AtiQiPcl | AtiQiPcl.exe | Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
|
Y | ATIRmtWndr | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it
|
U | ATISmart | ati2s9ag.exe | "ATI's ""SMARTGART"" |
U | AtiSound | csrss.exe | "WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
|
X | atisrc2 | windfind.exe | "Added by the WINDFIND-A TROJAN!"
|
X | ATITech | Active.exe | "Added by the ROAMER-A TROJAN!"
|
U | atitray | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings
|
U | AtiTrayTools | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings
|
X | atiupdate | ATIUPDATE5.EXE | "Added by the DEBESKI.A TROJAN!"
|
X | atiupdate | msshed32.exe | Added by the DELF.EP downloader TROJAN!
|
X | ATIUpdater | atiupdxx.exe | "Added by the RBOT-ABX WORM!"
|
X | Atiupdpl | atiupdpl.exe | "Added by the SMALL.AOS TROJAN!"
|
X | ativopen | ativopen.exe | Premium rate adult content dialler
|
Y | ATIX10 | atix10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it
|
U | ATKMEDIA | DMEDIA.EXE | "Driver for the media buttons on the front of some Asus laptops |
U | ATKOSD2 | ATKOSD2.exe | "On-screen display utility bundled with laptops from ASUS. If this utility is not installed then you will not be able to properly use other AsusTek utilities such as Splendid and Power Gear"
|
X | Atl**.exe [* = random char] | Atl**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X | Atl**32.exe [* = random char] | Atl**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
X | ATM Control | adpn.exe | "Added by the MMS.A WORM!"
|
N | ATnotes | atnotes.exe | Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
|
U | Atomic Time Synchronizer | TimeSync.exe | "TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
|
X | Atomic-x27 | Atomic-x27.exe | "Added by the KATOMIK-A WORM!"
|
X | Atomic-x27C | AtomicpartC.exe | "Added by the KATOMIK-A WORM!"
|
U | Atomic.exe | Atomic.exe | "Atomic Clock Sync - synchronizes your computer's time with the NIST time server"
|
N | Atomica | atomica.exe | "Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key"
|
U | AtomicTime | ATOMICTIME.EXE | "AtomicTime - utility that synchronizes your PC clock to an atomic clock"
|
U | AtomSync | atomsync.exe | "AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
|
U | Atrack | atrack.exe | "New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker |
U | Atray | Atray.exe | "Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons"
|
U | ATSpooler | AppsTraka.exe | "DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
|
U | ATTBroadbandUpdate | SAUpdate.exe | "Big Brother from Quest Software. System and network monitor"
|
U | ATTRedUpdate | AutoUpdate.exe | Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
|
X | AttuneClientEngine | attune_ce.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
X | AttuneContentUpdater | attune_cu.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
X | AttuneDiscovery | attune_di.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
X | Attunel | Attunel.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
X | AttuneSystray | attune_st.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
N | aTuner | atuner.exe | "aTuner - tweak tool for GeForce based graphics cards"
|
Y | atwtusb | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB)
|
X | AtxBrw | Iexplor.exe | """Pop Marketing"" adware"
|
U | au | DealioAu.exe | "Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products"
|
U | AU Agent | AUagent.exe | "Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon"
|
X | au.exe | au.exe | "Added by the BEAGLE.B WORM!"
|
Y | AUCBPNP | aucbnpn.exe | Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
|
X | Aucompat | Aucompat.exe | "Added by the GEMA TROJAN!"
|
X | Audcntr | audcntr.exe | "Added by the GEMA TROJAN!"
|
X | audi32 | audi32.exe | "Added by the RANCK-FL TROJAN!"
|
X | AUDIO | SOUND.exe | "Added by the PLOYB-A TROJAN!"
|
X | Audio Device Manager | winfp.exe | "Added by the IRCBOT-XS WORM!"
|
X | Audio Device Manager | WinNT.exe | "Added by the IRCBOT.USP BACKDOOR!"
|
X | Audio Device Manager | WNDXP.exe | "Added by the IRCBOT.AJL BACKDOOR!"
|
X | Audio Device Manager | sfhgj.exe | "Added by the IRCBOT-ZA BACKDOOR!"
|
X | audiocfg.exe | audiocfg.exe | Added by the VB.ATE WORM!
|
X | Audiocntl | audiocntl.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
N | AudioCommander | AudioCommander.exe | "System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation |
N | AudioCommander Application | AudioCommander.exe | "System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation |
N | AudioCommanderVista | AudioCommander.exe | "System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation |
N | AudioDeck | ADeck.exe | ADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
|
X | Audiodrv | audiodrv.exe | "Added by the CRYPTER-C TROJAN!"
|
U | AudioDrvEmulator | DLLML.exe AudDrvEm.dll | "Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system |
N | AudioHQ | Ahqtb.exe | For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
|
X | AudioHQ | audiohq.exe | "Added by the BANKER-EHK TROJAN!"
|
N | AudioHQU | AHQTBU.EXE | System Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
|
X | audioinf | audioinf.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
X | AudioMan | Explorer.sm1 | "Added by the HUPIGON.IFZ BACKDOOR!"
|
X | audlmne32 | dcmsxe.exe | "Added by the MAILBOT-CF TROJAN!"
|
X | Audoi Device Loader | smssv.exe | "Added by the AGOBOT-ZY WORM!"
|
X | augmsg | AUGMSG.EXE | "Added by the SPYBOT-CO WORM!"
|
X | auloadplx | mplprogsm.exe | "Added by the SLAPER.K TROJAN!"
|
X | aupd | symcsvc.exe | "Added by the ABWIZ.D TROJAN!"
|
X | aupd | sysvcs.exe | "Added by the ABWIZ.C TROJAN!"
|
X | aupd | sywsvcs.exe | "Added by the ORSE-M TROJAN!"
|
Y | Aureal A3D Interactive Audio | sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled
|
Y | Aureal A3D Interactive Audio Init | A3dInit.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled
|
U | Auslogics BoostSpeed | boostspeed.exe | "System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed |
U | Auslogics BoostSpeed 4 | boostspeed.exe | "System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed |
X | ausvc | ausvc.exe | "Added by the AUTOUPDER TROJAN!"
|
X | Auth Starter Ident | startauth.exe | "Added by the RBOT-WP WORM!"
|
Y | Authentic-ID Toolbar | wintmr.exe | "System Tray access to Child Control parental control software by Salfield"
|
Y | Authentic-ID Toolbar | "rundll32.exe [path] ToolbarATL.dll | LoadTrayIcon" |
X | authz | authz.exe | "Added by an unidentified VIRUS |
X | auto | win32.exe | "Added by an unidentified TROJAN! See here"
|
X | auto | auto.exe | "Added by the DOQ.GEN.Y BACKDOOR!"
|
X | Auto CD-ROM Startup | cdaccess.exe | "Added by the SPYBOT.BLA WORM!"
|
U | Auto EPSON PictureMate Deluxe on X | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
U | Auto EPSON Stylus C45 Series on X | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C48 Series on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C48 Series on X | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C60 Series on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C62 Series on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C64 Series on X | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C82 Series on X | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C84 Series on X | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
U | Auto EPSON Stylus C87 Series on X | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX3200 on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status |
U | Auto EPSON Stylus CX3500 Series on X | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX3600 Series on X | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX3700 Series on X | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX3800 Series on X | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX4200 Series on X | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX4500 Series on X | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX4600 Series on X | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX4800 Series on X | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX5000 Series on X | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX5400 on X | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX5500 Series on X | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX6000 Series on X | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX6400 on X | E_S4I2L1.EXE | "Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status |
U | Auto EPSON Stylus CX6600 Series on X | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX6600 Series on X | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX7400 Series on X | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX7800 Series on X | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
U | Auto EPSON Stylus CX9400Fax Series on X | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
U | Auto EPSON Stylus D78 Series on X | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
U | Auto EPSON Stylus D88 Series on X | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
U | Auto EPSON Stylus DX3800 Series on X | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
U | Auto EPSON Stylus DX4800 Series on X | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
U | Auto EPSON Stylus DX6000 Series on X | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo 1400 Series on X | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo 820 Series on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R1800 on X | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R200 Series on X | E_S4I2H1.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R200 Series on X | E_S4I0H2.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R220 Series on X | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R2400 on X | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R2400 on X | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R260 Series on X | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R280 Series on X | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R300 Series on X | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R300 Series on X | E_S4I0F2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R320 Series on X | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R340 Series on X | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo R800 on X | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
U | Auto EPSON Stylus Photo RX420 Series on X | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo RX500 on X | E_S4I2K1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo RX600 on X | E_S4I2M1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo RX680 Series on X | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Photo RX700 Series on X | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
U | Auto EPSON Stylus Pro 7600 on X | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
X | Auto File System Conversion Utility | scricon.exe | "Added by the SDBOT.EYB WORM!"
|
X | auto repair system | qualityx.exe | "Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
|
U | Auto Run Software for Photo Frame | PhotoManager.exe | "Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
|
X | Auto Scroll Loader | ASCRLL.EXE | "Added by the SPYBOT-T WORM!"
|
X | Auto Start | dosin.exe | "Added by the SDBOT-GO BACKDOOR!"
|
X | Auto Start | sndvol32.exe | "Added by the SLINBOT.AX BACKDOOR!"
|
X | Auto Start | windos.exe | "Added by the SLINBOT.BO BACKDOOR!"
|
U | Auto Switch | TASKBAR.exe | Related to 2-port Bitronics AutoSwitch kit from Belkin
|
N | Auto T Bar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
|
X | Auto Updat | WindowsSys32.exe | "Added by a variant of the FORBOT WORM!"
|
X | Auto updat | crcss.exe | "Added by the SDBOT.AAG WORM!"
|
X | Auto updat | SysDebug.exe | "Added by the FORBOT-BA WORM!"
|
X | Auto Update | AUP.exe | Added by an unididentified WORM or TROJAN!
|
X | Auto Update | dma.exe | "Added by the RBOT-AVO WORM!"
|
X | Auto Update | svchost.exe | "Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Auto Updater | asclt.exe | "Added by the SLINBOT.CJ BACKDOOR!"
|
X | Auto Updates | svchost.exe | "Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Auto WinUpdate | taskmrg.exe | "Added by the RBOT-AFA WORM!"
|
X | AutoAdministrator | SERVICES.EXE | "Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
|
U | Autobar | autobar.exe | "Connect buttons on the keyboard for internet direct access |
N | AutoCAD | acstart17.exe | "Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
|
N | AutoCAD Startup Accelerator | acstart16.exe | "Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
|
N | AutoCAD Startup Accelerator | acstart17.exe | "Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
|
X | autochk | "rundll32.exe autochk.dll | _IWMPEvents@16" |
X | autochk | "rundll32.exe protect.dll | _IWMPEvents@16" |
U | autoclk | autoclk.exe | "Autoclik is a Windows utility ""that allows you to perform all mouse activity with absolutely no clicking"""
|
X | AutoDiscovery/AutoPurge (ADAP) Service | wmiadapi.exe | "Added by the RBOT.FLT WORM!"
|
N | AutoEA | Ahqrun.exe | For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
|
X | AUTOEXE | AUTOEXE.exe | "Added by the SEMAPI-A WORM!"
|
X | autoload | cftmon.exe | "Added by the SOCKS-E WORM!"
|
X | autoload | spooll.exe | "Added by the SILLYFDC WORM!"
|
X | autoload | windowsupdate.exe | "Added by the POLYCRYP.DY TROJAN!"
|
X | autoload | spool.exe | "Added by the AGENT-GSG TROJAN!"
|
X | Autoloaderaproposclient | Apropos_Client_Loader.exe | "AproposMedia adware"
|
X | Autoloaderaproposclient | cxtpls_loader.exe | "AproposMedia adware"
|
X | AutoLoaderEnvoloAutoUpdater | auto_update_loader.exe | "Envolo/AproposMedia adware updater"
|
N | AutoMate Task Service | automate.exe | "Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
|
U | AutoMate5 | Am5HkWnd.exe | """Automate is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes |
U | AutoMate6 | AMEM.exe | "AutoMate 6 for automating repetitive tasks"
|
X | Automated Windows Updates | wauclt.exe | "Added by the GAOBOT.AJD WORM!"
|
X | Automatic Defrag Manager | defrag.exe | "Added by the RBOT-AKE WORM!"
|
X | Automatic Microsoft Windows Updater | suchost.exe | "Added by the RBOT-EQ WORM!"
|
X | Automatic Updates | algs.exe | "Added by the IRCBOT-AAM TROJAN!"
|
X | Automatic Windows Updater | Update.exe | "Added by the GAOBOT.AO WORM!"
|
N | Automatically launches the United Devices Agent when you start your computer | UD.EXE | The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
|
X | autoMe | wscript.exe solution.vbs | "Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
|
X | autoMe | wscript.exe samok.vbs | "Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
|
X | Autopdate | Autopdate.exe | "Added by the RBOT-AGL WORM!"
|
N | AUTOPROP | REGPROP.EXE WMPADDIN.DLL | "Both the files are in the MS Office/Bots/FP_WMP directory. Apparently |
X | AUTOPROTECTU | navapq32.exe | Added by an unidentified WORM or TROJAN!
|
X | autorepair | dexs.exe | "Added by a variant of the SDBOT WORM!"
|
X | autorn | autorn.exe | "Added by the SILLYFDC.BCY WORM!"
|
U | Autoroute SMTP | AutoSmtp.exe | "Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
|
X | autorun | autorun.exe | "Added by the AUTOM-B WORM!"
|
X | autorun | sxs.exe | "Added by the SMALLVBS-A WORM!"
|
X | autorun | winmain.exe | Added by a variant of the DELF.CNS TROJAN!
|
X | AutoRun | allrs.exe | "Added by the MUDROP.LJ TROJAN!"
|
X | AUTORUN_VAL | AntiSpyCheck 2.1.exe | "AntiSpyCheck rogue spyware remover - not recommended |
X | AUTORUN_VAL | asc 2.1.exe | "AntiSpyCheck rogue spyware remover - not recommended |
? | AutoShutdown | pssvc.exe | "Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
|
U | AutoSizer | AUTOSIZER.EXE | "AutoSizer - utility that automatically maximizes windows when they're opened"
|
N | AutoSpell | autospel.exe | "AutoSpell - spell checker (version 6.*)"
|
N | AutoSpell 5 | ASWATC32.EXE | "AutoSpell - spell checker"
|
U | AutoSys | autosys.exe | "Winguardian surveillance software. Uninstall this software unless you put it there yourself"
|
N | autotbar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
|
N | AutoTKit | AUTOTKIT.EXE | On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled
|
N | autoupd | autoupd.exe | Raxco Software auto update utility
|
X | autoupd | autoupd.exe | "Added by an unidentified VIRUS |
X | autoupdate | "rundll32 DATADX.DLL | SHStart" |
X | AutoUpdate | smss.exe | "Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
|
X | Autoupdate Service | kaka.exe | "Added by the SYMPE-B TROJAN!"
|
X | AutoUpdate32 | services.exe | "Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
|
X | AutoUpdater | aupdate.exe | "Tinybar variant"
|
X | AutoUpdater | AutoUpdate.exe | "PeopleonPage foistware"
|
X | autoupdatev2 | autoupdatev2.exe | "Detected by Kaspersky as the AGENT.FQ TROJAN!"
|
X | AutoVirusProtection | ciscv.exe | "Added by a variant of the RBOT WORM!"
|
X | auto__antiav__key | antiav_exe.exe | "Added by the BAGLEDI-AA TROJAN!"
|
X | auto__hloader__key | hloader_exe.exe | "Added by the BAGLE.AB TROJAN!"
|
X | aux.exe | aux.exe | "Added by the ZINS TROJAN!"
|
X | auxAudioDevice | aux32.exe | "Added by the AIZU WORM!"
|
N | AUXXTRAY | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
|
X | AV | UPDATE-28062004.exe[25 blank spaces].vbs | "Added by the MIDFIN WORM!"
|
X | AV | Antivir.exe | "Antivir rogue security software - not recommended |
X | av | expressav.exe | "Express Antivirus 2009 rogue security software - not recommended |
X | AV AntiSpyware | ava.exe | "AV AntiSpyware rogue security software - not recommended |
X | AV Care | AvCare.exe | "AvCare rogue security software - not recommended |
X | AV Client | patch31345.exe | "Added by the MYDOOM.AD WORM!"
|
X | AV Industry | patch31345.exe | "Added by the MYDOOM.AD WORM!"
|
X | AV UpDate | Update.exe | "Added by the FUROOT-A TROJAN!"
|
X | AV7 | antivirus7.exe | "Antivirus7 rogue security software - not recommended |
N | AvaFind | AvaFind.exe | "AvaFind file search utility"
|
X | avagent3974 | chnb8895.exe | "AntiVirus ransomware security software - not recommended |
X | AVantivirus | Avconsol.exe | "Added by the MSNVB-D WORM!"
|
X | avast | troyan.exe | "Added by the SMALL.CZ TROJAN!"
|
Y | Avast! | ashServ.exe | "Main part of avast! Antivirus - including the resident protection |
Y | avast! | ashDisp.exe | "System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner |
Y | avast! Antivirus | ashDisp.exe | "System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner |
Y | avast! Web Scanner | Ashwebsv.exe | "Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
|
Y | Avast32 | Astart32.exe | "Part of Avast! anti-virus software"
|
X | avc | avmon.exe | Added by an unidentified TROJAN!
|
U | AvconsoleEXE | Avconsol.exe | From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
|
X | AveoAttune | atmdlusr.exe | "Aveo Attune automated helpdesk software - adware/spyware"
|
U | AVFX Engine | StartFX.exe | "Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
|
X | AvG | svchost323.exe | "Added by the RBOT-ZA WORM!"
|
Y | AVG Anti-Spyware | avgas.exe | "System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
Y | AVG Anti-Virus system | avgcc.exe | "System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled |
Y | AVG Anti-Virus System | avgemc.exe | "E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry |
Y | AVG Anti-Virus System | avgw.exe | "This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
|
X | Avg Antivirus | icpldrvx.exe | "Added by the BANKER.BYU TROJAN!"
|
X | AVG AntiVirus Scanner | avgscnx.exe | "Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
|
X | AVG AntiVirus Updater | avgwusv.exe | "Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
|
X | AVG Grisoft Updater | updater.exe | "Added by the AGOBOT-OT WORM!"
|
Y | AVG IDS | AVGIDSUI.exe | "System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web |
U | AVG Internet Security | avgtray.exe | "System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security |
Y | AVG7_AMSVR | AVGAMSVR.EXE | "This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
|
Y | AVG7_CC | avgcc.exe | "System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled |
Y | AVG7_EMC | avgemc.exe | "E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry |
Y | AVG7_Run | avgw.exe | "This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
|
U | AVG8_TRAY | avgtray.exe | "System Tray access to and notifications for the 8.* series of internet security products from AVG Technologies - including Internet Security |
U | AVG9_TRAY | avgtray.exe | "System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security |
Y | avgamsvr.exe | Avgamsvr.exe | "This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
|
Y | avgas | avgas.exe | "System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
Y | avgcc | avgcc.exe | "System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled |
Y | avgcc32 | avgcc32.exe | "System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests |
Y | AVGCtrl | AVGCtrl.exe | "Part of AntiVir® PersonalEdition Classic antivirus"
|
Y | avgemc | avgemc.exe | "E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry |
Y | avgfwsrv | AVGFWSRV.EXE | "Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks |
Y | AVGIDS | AVGIDSUI.exe | "System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web |
Y | AVGIDSUI | AVGIDSUI.exe | "System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web |
Y | avgmsvr.exe | avgmsvr.exe | "AVG Anti-Virus 7.0 related"
|
Y | AVGnt | AVGnt.exe | "AntiVir® PersonalEdition Classic antivirus. System Tray icon and control program"
|
Y | Avgserv9.exe | Avgserv9.exe | "Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
|
U | avgtray | avgtray.exe | "System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security |
Y | AVGuard | AVGuard.exe | "AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
|
X | avguard3876 | 000b09274b.exe | "AntiVirus ransomware security software - not recommended |
Y | AVG_CC | avgcc32.exe | "System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests |
Y | AVG_EMC | AVGEMC.exe | "AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
|
Y | AVG_RegCleaner | AVGREGCL.exe | "Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
|
X | avidrv | drvsc.exe | "Detected by Kaspersky as the AGENT.PH TROJAN!"
|
X | Avimgt | Avimgt.exe | "Added by the GEMA TROJAN!"
|
X | Avimgt32 | Avimgt32.exe | "Added by the GEMA TROJAN!"
|
Y | avinit | AVINIT9X.EXE | "Command Antivirus related"
|
X | Avira Anti-Virus Pro 2008 | explorear.exe | Added by an unidentified WORM or TROJAN!
|
X | AvirTr | AvirTr.exe | "AntivirusTrigger rogue security software - not recommended |
Y | AVK Mail Checker | AVKPop.exe | "eXtendia AVK AntiVirus email checker"
|
Y | AVKBar | AVKBar.exe | "GData AntiVirusKit Anti-virus"
|
Y | AVKTray | AVKTray.exe | "System Tray access to the antivirus part of G Data range of internet security products"
|
Y | AvMaiSrv | Avmaisrv.exe | "Part of Avast! anti-virus software - E-mail scanner"
|
X | AVManager | csrss.exe | "Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
|
? | AvMenu | AVMenu.exe | "Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required?"
|
Y | AVMWlanClient | wlangui.exe | Related to broadband products from avm.de
|
X | avnort | formatsys.exe | "Added by the SERFLOG.A WORM!"
|
X | avnort | msmbw.exe | "Added by the SERFLOG.A WORM!"
|
X | avnort | serbw.exe | "Added by the SERFLOG.A WORM!"
|
Y | avp | avp.exe | "Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
|
X | avp | avp.exe | "Detected by Kaspersky as the ALPHABET.B TROJAN!"
|
X | avp | win*.tmp.exe [* is a number] | Added by a variant of the ALPHABET TROJAN!
|
X | avp | xar6000v7.exe | "Detected by Kaspersky as the ALPHABET.B TROJAN!"
|
X | AVP-SE | avp-32.exe | "Added by the AGOBOT.FS WORM!"
|
X | avpa | avpo.exe | "Added by the LEGMIR-ARK TROJAN!"
|
Y | avpcc | avpcc.exe | "Kaspersky Labs anti-virus"
|
X | avpl | Antivirus.exe | "AntiVirus Plasma rogue security software - not recommended |
X | AvpM | AvpM.exe | "Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in %Windir%\pchealth\UploadLB\Config"
|
X | avpms | avpms.exe | "Added by the ONLINEGAMES.CPV TROJAN!"
|
X | Avpr | avpr.exe | "Added by the MYDOOM.AF WORM!"
|
X | AVPSrv | AVPSrv.exe | "Added by the ONLINE-GEN TROJAN!"
|
X | avptask | expl0rer.exe | "Added by the AGENT.JJO TROJAN!"
|
X | Avptask | rund1132.exe | "Added by the AGENT.PKZ TROJAN!"
|
X | AvpWx | WErcx.exe | "Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
|
X | avrlabs | avrlabs.exe | "VirusResponse Lab 2009 rogue security software - not recommended"
|
X | avscan | avscan.exe | "Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
|
X | AVScan | winav.exe | Unidentfied rogue security software
|
X | AvScan | avscan.exe | "Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
|
X | avscan | Usbconeted.exe | "Added by the PROVIS-A TROJAN!"
|
Y | AVSCHED32 | AVSched32.exe | "AntiVir® PersonalEdition Classic - antivirus"
|
Y | AVSchedScan | SCHSC9X.EXE | "Command Antivirus related"
|
X | AVScheduler | AVSCHSVC.EXE | "Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended |
X | AVSeguro | pgs.exe | "AVSeguro |
X | AvSer | dsm.exe | "Added by the SERFLOG.B WORM!"
|
X | AvSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
X | AvSer | svosm.exe | "Added by the SERFLOG.B WORM!"
|
X | AvSer | sysup.exe | "Added by the SERFLOG.B WORM!"
|
X | avserve.exe | avserve.exe | "Added by the SASSER WORM!"
|
X | avserve2.exe | avserve2.exe | "Added by the SASSER.B or SASSER.C WORMS!"
|
X | avserve3.exe | avserve3.exe | "Added by the SASSER.G WORM!"
|
U | AVStation premium | AVStation agent.exe | "Related to Samsung AV Station - instant playback of music |
X | AVSTRT | navpsrvc.exe | "Added by the FORBOT-EF WORM!"
|
X | AVSystemCare | pgs.exe | "AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
X | avtapi | avtapi.exe | "Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" |
N | Avtray | Avtray.exe | "Command Antivirus tray icon"
|
X | AVTray | AVTray.exe | "Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended |
X | AVupdate32 Update | AVupdate32.exe | "Added by the RBOT.CNI TROJAN!"
|
? | AVWLPSTA | AVWLPSTA.exe | "PRISM Status Tray Applet - but what is it for and is it required?"
|
Y | AVWUpd32 | AVWUPD32.EXE | "AntiVir® PersonalEdition Classic - updater"
|
Y | avx communicator | xcommsur.exe | "Anti-virus part of BitDefender virus scanner/firewall"
|
Y | Avxlive | avxlive.exe | "Bullguard or BitDefender antivirus"
|
Y | avxlni | avxinit.exe | "Anti-virus part of BitDefender virus scanner/firewall"
|
? | Avxnews | ?? | "??"
|
U | Awatch | Awatch.exe | "Diagnosis tool that monitors DSL connections |
U | AwaySch | AwaySch.EXE | "Part of the IBM ThinkVantage Productivity Center. ""The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"""
|
U | AWC | AWC.exe | "Advanced SystemCare from IObit - ""helps protect |
N | awhost32 | awhost32.exe | "Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file |
U | AWMON | Ad-Watch.exe | "Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
|
U | AWMON | Ad-Monitor.exe | "F-Secure Anti-Spyware"
|
X | Awoa | smmo.exe | "PurityScan adware"
|
X | Awola | Awola.exe | "Awola rogue spyware remover - not recommended"
|
X | Awola6 | Awola6.exe | "Awola AntiSpyware 6.0 rogue spyware remover - not recommended |
U | awplite | awplite.exe | "AllWallpapers Lite desktop wallpaper changer"
|
? | AWUSGSTA | AWUSGSTA.exe | "Reportedly related to a USB Wifi Adapter - is it required at startup?"
|
U | awxDTools | "awxDTools.dll | awxRegisterDll" |
N | axcmd | axcmd.exe | "Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition |
? | AxFilter | "Rundll32 AXFILTER.DLL | Rundll32" |
U | AXIS Print System DriverScanner | DriverScanner.exe | "Part of AXIS Print System from AXIS Communications - ""adds printer discovery |
U | AXIS Print System DriverServer | DriverServer.exe | "Part of AXIS Print System from AXIS Communications - ""adds printer discovery |
U | AXIS Print System TrayIcon | TrayIcon.exe | "System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery |
X | AXPDefender | AXPDefender.exe | "Advanced XP Defender rogue security software - not recommended |
X | AXPFixer | AXPFixer.exe | "AdvancedXPFixer rogue security software - not recommended |
X | AXVenore | AXVenore.exe | "Added by an unidentified TROJAN - see here"
|
U | AzMixerSel | AzMixerSel.exe | "Related to Realtek_Azalia Mixer Selector"
|
Y | azmodem | azexe.exe | "Aztech Labs modem driver"
|
X | A_M_P_NET | AntiMalwarePro.exe | "AntiMalware Pro rogue security software - not recommended |
? | a_vpd | vpd.exe | "Located in an IBMTOOLS\VPD sub-directory. What does it do and is it required?"
|
Y | a² | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
N | B'sCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
|
X | b.exe | b.exe | "Added by the SDBOT.BND WORM!"
|
N | B.Reader | remin.exe | "Birthday Reminder 5.0 - as the name implies"
|
X | b3d | BDEsecureinstall.exe | "B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
|
X | b3dUpdate | Zupdate.exe | "Associated with B3d Projector foistware - see here"
|
U | b9 | B9.exe | "FireTrust Benign - allows you to receive e-mail which is safe from viruses |
X | b99 | msmm.exe | "ClientMan parasite variant"
|
X | bab | svchst32.exe | "Added by the AGENT.Q TROJAN!"
|
N | Babylon Client | Babylon.exe | "Babylon-Pro is a powerful information tool that instantly provides relevant information |
N | Babylon Translator | Babylon.exe | """Babylon-Pro is a powerful information tool that instantly provides relevant information |
U | Back2zip | Back2zip.exe | "Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up"
|
X | Backdoor.NuAgent | agent.exe | "Added by the AGENT-DP TROJAN!"
|
X | Background Intelligent Transfer Service | [path] rundll32.exe | "Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process |
U | BackgroundSwitcher | bgswitch.exe | "Originally included with Microsoft's XP PowerToys (but now withdrawn - see here |
U | BackgroundSwitcher | BackgroundSwitcher.exe | "John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
|
N | Backpack UDF | bpudfmon.exe | "Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
|
U | Backup NOW! Scheduler | Schdlr32.exe | "Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled |
X | Backup One | smbguard.exe | "Added by the SDBOT-MI WORM!"
|
X | BackUp Windows 2009 | [random].exe | "Added by the AGENT-LUJ TROJAN!"
|
U | Backup4all OTB Agent | B4AOTB.exe | """Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks |
U | BackupExecScheduler | besch.exe | "Veritas ""Back Up My PC"" software"
|
? | BackupNotify | backupnotify.exe | "HP Digital Imaging related. What does it do and is it required?"
|
N | BackWeb | backweb.exe | Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
|
N | backWeb-8876480 | backweb-8876480.exe | "Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products |
N | Backwork | Backwork.exe | "Backwork trojan detector"
|
U | BACPI10 | bacpi10a.exe | "Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
|
N | BacsTray | BacsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
|
X | BADDATE | BADDATE.EXE | "Added by an unidentified VIRUS |
X | Badx | HELLRAIDER.EXE | "Added by the MINDCTRL.A BACKDOOR!"
|
X | BagleAV | csrss.exe | "Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Bakra | IEHost.EXE | "Added by the MULTIDR-AH TROJAN!"
|
X | bal | SYSMONMS.EXE | "Added by the FAKEALERT TROJAN!"
|
U | bandmon | bandmon.exe | "Rokario Bandwidth Monitor"
|
X | Bandook | ali.exe | "Added by the EXEMAS-B TROJAN!"
|
N | Bandwidth Meter Pro | BandwidthMeterPro.exe | "System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
|
U | Bandwidth Monitor Pro | Bandwidth Monitor Pro.exe | "Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP"
|
N | BandwidthMeterPro | BandwidthMeterPro.exe | "System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
|
U | Banpopup by Pratik | Banpopup.exe | Banpopup - popup killer
|
X | bantool | bantool.exe | "Malware installed by different rogue security software including SpyKillerPro"
|
X | bantool | ie_ban.exe | Detected as the VB.PO TROJAN!
|
X | Banyak_Kerjaan | Tukang.exe | "Added by the SILLYFDC.BDM WORM!"
|
X | Bar Ding lolt | Analiz.exe | "Added by the RBOT-RP WORM!"
|
X | bargains | bargains.exe | "BargainBuddy adware"
|
X | bargains | bargainbuddy.exe | "BargainBuddy adware"
|
X | BaRloNdDiLhep | services.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
U | Bart Station | PPCOLink.exe | Dialer for PeoplePC ISP
|
X | BarTheme | bartent32.exe | "Added by the AGOBOT-UG WORM!"
|
N | bascstray | BascsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
|
X | BastioneAntivirus | pgs.exe | "BastioneAntivirus |
U | BatInfEx | "rundll32.exe [path] BatInfEx.dll | BMMAutonomicMonitor" |
U | BatLogEx | "rundll32.exe [path] BatLogEx.DLL | StartBattLog" |
X | BatSrv | batserv2.exe | "Detected by Kaspersky as the LOCKSY.M WORM!"
|
U | Battery Scope | batmgr.exe | Monitors battery levels on a notebook/laptop PC
|
U | BatteryBar | batterybar.exe | "BatteryBar - displays battery usage |
Y | batterymiser | batterymiser.exe | "Battery Miser power management utility for LG Notebooks"
|
Y | BatteryMiser 5 | BatteryMiser5.exe | "Battery Miser 5 power management utility for LG Notebooks"
|
U | BAUSB | BAUSB.exe | "Boston Acoustics Audio |
X | bawindo | bawindo.exe | "Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
|
U | Bayden SlickRun | sr.exe | """SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords) |
U | BayMgr | DockApp.exe | Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
|
U | Bayswap | bayswap.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
|
U | Bayswap2 | TbUpdate.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
|
N | BBC Alerts | BBC_Alerts.exe | "BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
|
U | BBC News alerts | skinkers.exe | "BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
|
? | BBDial | BT Broadband.exe | "Part of BT Broandband - is it required?"
|
N | BBLauncher.exe | BBLauncher.exe | "BounceBack Professional - back-up software"
|
N | bbSysTray | bbSysTray.exe | "Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"""
|
U | bbui | bbui.exe | AOL DSL status monitor displaying a red/green icon indicating if you have a connection
|
U | bca | bca.exe | "BeClean Agent - registry |
U | BCDetect | bcdetect.exe | Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
|
Y | BCMDMMSG | bcmdmmsg.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems
|
U | BCMHal | "rundll32.exe bcmhal9x.dll | bcinit" |
Y | BCMSMMSG | BCMSMMSG.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems
|
? | bcmwltry | bcmwltry.exe | "Broadcom Corporation Wireless Network Tray Applet. Is it required?"
|
N | BCNT | bcnt.exe | "AWS Weatherbug related. What does it do?"
|
X | BCPC | bcpc.exe | "BroadcastPC adware variant"
|
X | bcpc_c | bcpc_c.exe | "BroadcastPC adware variant"
|
U | BCSSync | BCSSync.exe | "Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
|
U | BCTweak | bctweak.exe | "BlasterControl for Creative video cards - controls for desktop settings |
X | Bcvsrv32 | bcvsrv32.exe | "Added by the GAOBOT.BQJ WORM!"
|
X | Bcvsrv32 | he3.exe | "Added by the AGOBOT.AKB WORM!"
|
X | Bcvsrv32 | msxml22.exe | "Added by the AGOBOT.AKH WORM!"
|
X | Bcvsrv32 | msc32.exe | "Added by the AGOBOT.AKD WORM!"
|
X | Bcvsrv32 | msbvd32.exe | "Added by the AGOBOT-SR WORM!"
|
X | Bcvsrv32 | system2.exe | "Added by the AGOBOT-PU BACKDOOR!"
|
N | BCWipeTM | bcwipetm.exe | "BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task |
X | BD | dc.exe | "Added by the RASDOOR-A TROJAN!"
|
Y | BDAgent | bdagent.exe | "BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
|
X | bdfger | gggasw.exe | "Added by the SDBOT-RT WORM!"
|
Y | BDMCon | Bdmcon.exe | "BitDefender antivirus"
|
Y | BDNewsAgent | bdnagent.exe | "BitDefender antivirus - updater"
|
Y | BDOESRV | bdoesrv.exe | "Bitdefender 8 antivirus and firewall"
|
U | BDRegion | brs.exe | "Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
|
Y | BDSwitchAgent | bdswitch.exe | "Bitdefender 8 antivirus and firewall"
|
Y | BDWizReg | bdwizreg.exe | "Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules |
U | BearFlix | BearFlix.exe | "BearFlix is optimized for the fast download of video files"
|
N | BearShare | bearshare.exe | "BearShare file sharing client. Versions known to include spyware - see here"
|
U | BeatNik Internet Clock | BeatNik.exe | "BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
|
X | Beawver | saqevre.exe | "Added by a variant of the RANKY TROJAN!"
|
X | BedreigingsMonitoor | pgs.exe | "BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
|
X | Beegees Update | beegees.exe | "Added by the SDBOT-ADK WORM!"
|
? | BEEI | beei.exe | "??"
|
U | BeFaster | befaster3.exe | "BeFaster internet connection optimization tool"
|
X | begins | 0.exe | "Added by the MYTOB-HE WORM!"
|
? | BEHL | BEHL.exe | "??"
|
? | BEHLO | BEHLO.exe | "??"
|
U | beidsystemtray | beidsystemtray.exe | "Related to Belgium Identity Card card reader"
|
U | Belgacom | sprtcmd.exe /P Belgacom | "Self-help support tool for Belgacom broadband users (provided by SupportSoft |
U | Belkin F5D8013 N Wireless Notebook Card Utility | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
|
U | Belkin F5D8053 N Wireless USB Adapter Utility | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
|
U | Belkin F5D8073 N Wireless ExpressCard Adapter Utility | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
|
N | Belkin PCMCIA WLAN Monitor | monitorbk.exe | Belkin USB Network Adapter Management utility - can be started manually
|
U | Belkin Wireless G Notebook Card Client Utility | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
|
U | Belkin Wireless USB Utility | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
|
U | Belkin Wireless Utility | Belkinwcui.exe | "Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
|
U | BellSouthAlertManager.exe | BellSouthAlertManager.exe | "Related to BellSouth Alert Manager"
|
U | BelNotify | "rundll32.exe [path] NPBelv32.dll | RunDll32_BelNotify" |
? | BELORVBI | BELORVBI.exe | "??"
|
? | Belsta.exe | Belsta.exe | "Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?"
|
X | Belt | Belt.exe | "VX2.Transponder parasite updater/installer related"
|
X | Benadril Alert Tool | benadrilalert.exe | Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
|
X | BeschermingsTool | SysRep.exe | "BeschermingsTool |
U | BestCrypt Auto Open | BestCrypt.exe | "BestCrypt from Jetico |
X | BestPopUpKiller | BestPopupKiller.exe | "Popup killer by Swanksoft - not recommended |
X | BestsellerAntivirus | pgs.exe | "BestsellerAntivirus rogue security software - not recommended |
U | BestSync 2008 | BestSyncApp.exe | "System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives |
X | beta | svchost.exe | "Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
|
X | BF4P | bf4p.exe | "Added by the IRCBOT.GEN WORM!"
|
X | bfxtray | [path to trojan] | "Added by the AGENT-GEB TROJAN!"
|
Y | bg | bullguard.exe | "Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster"
|
U | BGInfo | Bginfo.exe | "BGinfo automatically displays relevant information about a Windows computer on the desktop's background |
U | BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMBgMonitor.exe | "Associated with Nero Scout |
Y | BGNewsAgent | bgnewsag.exe | "BullGuard antivirus updater"
|
X | bgoomain.exe | bgoomain.exe | "Baigoo.a malware"
|
N | bgsmsnd | bgsmsnd.exe | Printer driver to generate PDF files from any program
|
X | Bharatayuda | GNB.exe | "Added by the BHARAT.A WORM!"
|
N | BHOCop | BHOCop.exe | "PC Magazine's
U | BHODemon 2.0 | BHODemon.exe | "BHODemon ""protects you from unknown Browser Helper Objects (BHOs) |
U | BHR | BHR.exe | "Browser Hijack Retaliator - recovers your browser after it has been hijacked by spyware |
U | BI1HelperStartUp | BI1HEL~1.EXE | "ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
X | BIE | "Rundll32.exe [path] BDSrHook.dll | Rundll32" |
X | BIG | biggy.exe | "Added by the DELBOT-AG WORM!"
|
N | BigDog303 | VM303_STI.EXE | "Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
|
N | BigDog305 | VM305_STI.EXE | "Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
|
? | BigDogPath | VM_STI.EXE | "Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
|
X | BigfileSearch | BigfileSearch.exe | "BigfileSearch adware. File located in %Program Files%\BigfileSearch"
|
N | bigfix | BIGFIX.EXE | "BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs |
X | biglow | biglow.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
X | bigoris | bigoris.exe | "Added by the DORF-AZ TROJAN!"
|
U | BigPond Toolbar | bpumTray.exe | "Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
|
N | BigPondCable | bpcable.exe | Telstra Bigpond Cable login software - can be started manually
|
Y | BigPondWirelessBroadbandCM | BigPond_CM.exe | "Related to BigPond_Wireless_Broadband Service by Telstra"
|
X | bikini | bikini.exe | "Added by the LOWZONE-CX TROJAN!"
|
X | BillGatesLoh.exe | BillGatesLoh.exe | "Added by the AGENT-FZO TROJAN!"
|
N | Billminder | Billmind.exe | Can be setup in Quicken to remind user of due payments. Available via Start -> Programs
|
X | bin32hpu | ppstub.exe | "PrecisionPop adware"
|
N | Bing Bar | mswinext.exe | "Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
|
? | Bingo Charm | charms.exe | "Some kind of screen icon kind of like desk flag |
U | Biomenu | menusw.exe | "Related to Sony VAIO - passwords |
U | Bionix Wallpaper 5 | Bionix Wallpaper 5.exe | "BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
|
U | BioniXWallpaper | Bionix Wallpaper 5beta.exe | "BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
|
U | BioniXWallpaper | BioniX Wallper.exe | "BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
|
U | BioniXWallpaper | BionixWallpaper5.exe | "BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
|
X | Bios | Bios32.exe | "Added by an unidentified VIRUS |
X | bios | bios.exe | "Added by the BANCBAN-PW TROJAN!"
|
X | BIOS XP Loader | [random filename] | "Added by the RBOT-IC WORM!"
|
X | BIOS1 | BIOS1.EXE | "Added by the OPASERV.T WORM!"
|
? | BIOVCIP | BIOVCIP.exe | "??"
|
? | BisonHK | BisonHK.exe | "Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer |
Y | BisonInst0402 | BR040286.exe | "Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
|
N | BitComet | BitComet.exe | "BitComet P2P client - can be launched from Start -> Programs"
|
Y | BitDefender 12 | bdwizreg.exe | "Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules |
Y | BitDefender 2009 | IEShow.exe | "Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames |
Y | BitDefender 2009 | bdagent.exe | "BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
|
Y | BitDefender Antiphishing Helper | IEShow.exe | "Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames |
X | BitDefender Antivirus | BITDEFENDERX.EXE | "Added by a variant of the SPYBOT WORM!"
|
Y | BitDefender Communicator | xcommsvr.exe | "BitDefender antivirus"
|
U | BitDefender for MSN Messenger | msnmon.exe | "Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
|
U | BitDefender for Yahoo! Messenger | yahmon.exe | "Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
|
Y | BitDefender Live! Init | bdinit.exe | "BitDefender antivirus"
|
Y | BitDefender Scan Server | bdss.exe | "BitDefender antivirus"
|
Y | BitDefender Virus Shield | vsserv.exe | "BitDefender antivirus"
|
Y | bitdefenderlive | avxlive.exe | "Main program of BitDefender virus scanner/firewall"
|
U | BitDefender_P2P_Startup | BitDefender_P2P_Startup.exe | "Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
|
X | Bittorrent | bittorrent.exe | "Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir%"
|
N | BitTorrent | bittorrent.exe | "BitTorrent file sharing client - from BitTorrent |
N | BitTorrent DNA | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
N | bittorrent.exe | bittorrent.exe | "BitTorrent file sharing client - from BitTorrent |
N | BitWare Print Monitor | bwprnmon.exe | "FaxServe network fax software"
|
N | BJ Printer Status Monitor | Cjstsr.exe | Canon BJ printer status monitor
|
N | BJ Status Monitor 5xx | CJSTRxx.EXE | Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
|
N | bjcfd | cdf.exe | "BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
|
U | BJLaunchEXE | BJLaunch.exe | "Memory Card Utility for the Canon i470D |
U | BJPD HID Control | TVMon.exe | "Related to Canon Photo viewer"
|
N | BlackBerryAutoUpdate | RIMAutoUpdate.exe | "Automatic updates for BlackBerry smartphones |
N | BlackICE PC Protection | blackice.exe | "Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
|
N | BlackIce Utility | blackice.exe | "Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
|
U | blads | blads.exe | "A Tweak-XP component |
X | blah service | winupdate.exe | "Added by the GAOBOT.BIA WORM!"
|
X | blah service | winsysengine.exe | "Added by the RBOT-KI WORM!"
|
X | blah service | internet.exe | "Added by a variant of the RBOT WORM!"
|
X | blah service | smnp.exe | "Added by the RBOT.IZ WORM!"
|
X | blah service | msnmsgrr.exe | "Added by the RBOT.PZ WORM!"
|
X | blah service | tazkmgr.exe | "Added by the RBOT.UA WORM!"
|
X | blah service | FaLeH.exe | "Added by the RBOT-AES WORM!"
|
X | blah service | microsoft.exe | "Added by a variant of the RBOT WORM!"
|
X | blah service | evosys.exe | "Added by a variant of the RBOT WORM!"
|
X | blah service | win32.exe | "Added by the RBOT-AXO WORM!"
|
X | Blah service | CCAPPS32.EXE | "Added by the RBOT.TV WORM!"
|
X | blah services | iczw.exe | "Added by the RBOT-GMP WORM!"
|
X | blahh service | msengine.exe | "Added by a variant of the RBOT WORM!"
|
X | blahx service | msnjompa.exe | "Added by the SDBOT.AML WORM!"
|
X | Blank AntiViri | AUT0EXEC.BAT StartUp | "Added by the BRONTOK-CJ WORM!"
|
N | BlazeChanger | FBZPaper.exe | "Ember graphic file viewer |
? | BlazeServoTool | MediaDetector.exe | "Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
|
N | bldbubg | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system
|
X | BLF | blf.exe | "Added by the DELBOT-M WORM!"
|
U | blinkx | blinkx.exe | "Blinkx Desktop ""Smart Folders"" software"
|
N | Blitzz BWI715 | WLANmon.exe | Blitzz Technology BWI715 Wireless PC modem connection monitor
|
X | BLMessagingIntegration | blengine.exe | "BuddyLinks adware"
|
U | BlockAds | blads.exe | "A Tweak-XP component |
X | BlockChecker | Block-checker.exe | "BlockChecker adware"
|
X | BlockDefense | BlockDefense.exe | "BlockDefense rogue security software - not recommended |
X | Blocker System611 Monitoring | PopUpBlocker611.exe | "Added by the RBOT.BLJ WORM!"
|
X | BlockKeeper | BlockKeeper.exe | "BlockKeeper rogue security software - not recommended |
X | BlockProtector.exe | BlockProtector.exe | "BlockProtector rogue security software - not recommended |
X | BlockScanner | BlockScanner.exe | "BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
|
N | BlockTracker | BlockTracker.exe | If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
|
X | BlockWatcher | BlockWatcher.exe | "BlockWatcher rogue security software - not recommended |
U | BLOG | "rundll32.exe [path] BatLogEx.DLL | StartBattLog" |
U | blsloader | blsloader.exe | "BellSouth ISP Internet Tools"
|
X | blss | blss.exe | "Added by the BLARUL TROJAN!"
|
N | BLSTAPP | blstapp.exe | Puts access to Creative's BlasterControl in the System Tray
|
N | Blubster | Blubster.exe | "Related to Blubster Music sharing service"
|
U | Blue Frog | bluefrog.exe | "Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive"
|
? | BlueLight_uoltray | exec.exe | "Related to BlueLight Internet. What does it do and is it required?"
|
U | BlueSoleil | BLUESO~1.EXE | "BlueSoleil Bluetooth wireless manager from IVT Corporation"
|
U | BlueSpace NE | BlueSpaceNE.exe | """BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
|
X | Bluetooth Config | btwindin32.exe | "Added by the SDBOT-DFN WORM!"
|
U | Bluetooth Connection Assistant | LBTWiz.exe | "Bluetooth connection manager for Logitech based bluetooth wireless products"
|
U | BluetoothAuthenticationAgent | "rundll32.exe irprops.cpl | |
U | BluetoothAuthenticationAgent | "rundll32.exe bthprops.cpl | |
U | blueyonder Instant Support Tool | matcli.exe | "Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
X | bm | bm.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
N | BMail Installation | FTP_back.exe | "Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
|
X | Bman | BMan1.exe | Abcsearch.com/DealHelper adware variant
|
N | BMMLREF | BMMLREF.EXE | "Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
|
N | BMMLREF.EXE | BMMLREF.EXE | "Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
|
U | BMMMONWND | "rundll32.exe [path] BatInfEx.dll | BMMAutonomicMonitor" |
X | BMN | bm.exe | "Part of VirtualPCGuard |
X | BMN | strpmon.exe | "Part of CleanPCTool |
X | BMN | dcmon.exe | "SystemDoctor rogue security software - not recommended |
U | BMO MasterCard Wallet | EWALLET.EXE | "The wallet conveniently stores billing |
X | Bmonq | bmonq.exe | "Added by the CLICKER.HZ TROJAN!"
|
N | BMupdate | BMupdate.exe | "Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example |
X | bmw | bmw.exe | "Added by the AGOBOT.BBV BACKDOOR!"
|
X | bmz | bmz.exe | "180Search adware"
|
X | Bndt32 | Bndt32.exe | "Added by the LACON WORM!"
|
X | Bnexe | [random filename] | "Added by the KITRO.D (or ARGEN.A) WORM!"
|
U | BO1HelperStartUp | BO1HEL~1.EXE | "ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
U | BO1HelperStartUp | Bo1helper.exe | "ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
X | Boarddata | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
|
X | boat32 | boat32.exe | "Added by a variant of the RBOT WORM!"
|
Y | BOC-412 | BOC412.exe | "NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.12"
|
Y | BOC-420 | BOC420.exe | "NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.20"
|
Y | BOC-421 | BOC421.exe | "NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.21"
|
Y | BOC-422 | BOC422.exe | "NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.22"
|
Y | BOC-423 | BOC423.exe | "Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.23"
|
Y | BOC-424 | BOC424.exe | "Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.24"
|
Y | BOC-425 | BOC425.exe | "Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.25"
|
Y | BOC-426 | BOC426.exe | "Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.26"
|
Y | BOC-427 | BOC427.exe | "Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.27"
|
Y | BOCleanautostart | Boclean.exe | "NSClean's BOClean anti-trojan software"
|
U | BOINC Manager | boincmgr.exe | "BOINC manager - ""controls the use of your computer's disk |
U | Boingo Wireless Utility | Icon###XXX#X#.exe | "Starts the Boingo Wireless utility |
X | bolenja | bolenja.exe | "Added by the WANTVI.BF TROJAN!"
|
X | bolenjx | bolenjx.exe | "Added by the ELDYCOW.O TROJAN!"
|
X | boler.exe | syser.exe | "Added by the RBOT-AYS WORM!"
|
U | bombshel | BOMB32.EXE | Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
|
X | BONZI Task Switcher | Taskswitch.exe | "Added by the SPYBOT.DTR WORM!"
|
X | boo | boo.exe | "Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN!"
|
X | BookedSpace | "RunDLL32.EXE bs2.dll | DllRun" |
U | Bookmark | bookmark.exe | "System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer |
U | Bookmark.exe | bookmark.exe | "System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer |
N | BookmarkCentral | BMLauncher.exe | "Bookmark Express - "offers a more flexible way to manage Web site bookmarks |
N | BookMarkSink | syncit.exe | Bookmark synchronization utility
|
N | BookMarkSync | syncit.exe | "Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks |
N | BookMarkSync2It | sync2it.exe | "Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks |
U | Boost XP Service | bxservice.exe | "Boost XP from Systweak - WinXP tweaking utility"
|
U | BoostSpeed | boostspeed.exe | "System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed |
X | boot | boot.exe | "Added by the PUPPET-A TROJAN! Located in the %System%"
|
U | Boot | Boot.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
X | Boot Check | bootchk.exe | "Added by the DELBOT-AB WORM!"
|
X | Boot Client | bootcli.exe | "Added by the IRCBOT-ACF BACKDOOR!"
|
X | Boot Config | bootconfig.exe | "Added by the FLOOD-EV TROJAN!"
|
X | Boot K | bootk.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Boot Manager | Njgal.exe | "Added by the KILO TROJAN!"
|
X | Boot Manager | bootmng.exe | "Added by a variant of the SPYBOT WORM!"
|
X | Boot Server | bootserver.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Boot Service | bootservice.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Boot Service | bootsv.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Boot Verify | bootvfy.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | BootClean | smartdrv.exe | "Added by the LURKA-A VIRUS!"
|
X | BootCTRL | bootctrl.exe | Added by an unidentified WORM or TROJAN!
|
X | BootLoader | BootLoader.exe.vbs | "Added by the WATERWORKS WORM!"
|
X | bootpd.exe | bootpd.exe | "Added by the AGENT-DT TROJAN!"
|
? | Boots Insert Detect | InsDetect.exe | "Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
X | BootsCfg | wscript.exe [path] Date.POP.vbs | "Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
X | BootsCfg | wscript.exe [path] All Users.vbs | "Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
X | BootsCfg | wscript.exe [path] All Users.vbe | "Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
X | BootsCfg | wscript.exe Install.log.vbs | "Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
|
X | bootsec | NAVSSE.exe | "Added by the FORBOT-CY WORM!"
|
Y | BootSkin Startup Jobs | BootSkin.exe | "Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
|
U | BootStatus | BOOTST~1.EXE | "Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it |
U | BootWarn | BootWarn.exe | "From here: ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus |
X | boot_reg | svchot.exe | "Added by the BANCBAN-BQ TROJAN!"
|
X | BortMedVirus | pgs.exe | "BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
|
U | borzoi | blg.exe | "Borzoi surveillance software. Uninstall this software unless you put it there yourself"
|
N | Bose Wave/PC Monitor | wavepcmonitor.exe | "System Tray access for this system (more info on the system here). Available via Start -> Programs"
|
X | BossIdea | winlogin.exe | "Added by the LINEAGE-I TROJAN!"
|
? | Boston | Boston.exe | "Part of the Boston Acoustics USB speaker systems. What does it do and is it required?"
|
X | Bot Loader | svchostt.exe | "Added by the GAOBOT.ALV WORM!"
|
X | Bouncer RunStartup | bouncer.exe | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
X | Bouncer RunStartup | LiveUpdate.exe | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
X | boy lovers of bsd | ilikeboys.exe | "Added by the MYTOB.LY WORM!"
|
U | bpcpost.exe | bpcpost.exe | MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
|
X | BPCV2 | BPCV2.exe | "BroadcastPC adware"
|
X | BPCv2 re | bpc2 re inst.exe | "BroadcastPC adware variant"
|
U | BPK | bpk.exe | "Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
N | BPServer | G6FTPSrv.exe | "BulletProof FTP Server"
|
U | BQTray.exe | BQTray.exe | "System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility |
X | Brasil | Brasil.exe | "Added by the OPASERV.E WORM!"
|
X | brastk | brastk.exe | "Added by the DORF-BV TROJAN!"
|
X | Brave-Sentry | BraveSentry.exe | "BraveSentry rogue security software - not recommended |
X | BraveSentry | BraveSentry.exe | "BraveSentry rogue security software - not recommended |
X | braviax | braviax.exe | "Added by the FAKEALER.LE TROJAN!"
|
X | Brct | trdb.exe | "Detected by Kaspersky as the PURITYSCAN.Y TROJAN!"
|
U | Break_Reminder | BREAK REMINDER.exe | "Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here"
|
Y | Bredbandsbolaget | servicecenter.exe | "Related to the Brebband Swedish Broadband provider"
|
X | Breg | bcre.exe | "BroadcastPC adware variant"
|
X | Breg | bptre.exe | "BroadcastPC adware variant"
|
X | Breg | breg.exe | "BroadcastPC adware"
|
X | Bridge | "rundll32.exe [path] Bridge.dll | Load" |
Y | Brindys BriTray | BRITRAY.EXE | "Main process for the following applications: GEDEX |
U | BrmfRmPA | BrmfRmPA.exe | Brother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
|
U | broadband medic | matcli.exe | "NTL's Broadband Medic. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
N | Broadband Wizard | bbwiz.exe | "Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs"
|
N | BroadCamRun | broadCam.exe | "BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
|
U | Broadcom Wireless Manager UI | bcmntray.exe | "Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
|
N | Broadcom Wireless Manager UI | wltray.exe | System tray access to wireless LAN card configuration options
|
X | Bron-Spizaetus | CVT.exe | "Added by the RONTOKBRO WORM!"
|
X | Bron-Spizaetus | norBtok.exe | "Added by the RONTOKBRO.B WORM!"
|
X | Bron-Spizaetus | bronstab.exe | "Added by the RONTOKBRO.C WORM!"
|
X | Bron-Spizaetus | eksplorasi.exe | "Added by the RONTOKBRO.J WORM!"
|
X | Bron-Spizaetus | ElnorB.exe | "Added by the RONTOKBRO.D WORM!"
|
X | Bron-Spizaetus | sempalong.exe | "Added by the BRONTOK-E WORM!"
|
X | Bron-Spizaetus | RakyatKelaparan.exe | "Added by the BRONTOK-J or BRONTOK-L WORMS!"
|
X | Bron-Spizaetus-5118REPM | komodo-6321422.exe | "Added by the BRONTOK-R WORM!"
|
X | Bron-Spizaetus-cfgmktoq | bbm-qotkmgfc.exe | "Added by the BRONTOK-M WORM!"
|
X | Bron-Spizaetus-cfgmmnru | bbm-urnmmgfc.exe | "Added by the BRONTOK-N WORM!"
|
X | BRoNToK | BRoNToK.exe | "Added by the BRONTOK-CG WORM!"
|
X | BrowseProxy | FindService.exe | "Actual Names (AdvSearch) Internet Keywords parasite"
|
X | browser | msgaol.exe | "Added by the TACTSLAY.C TROJAN!"
|
X | browser | s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
X | browser | browse.exe | "Added by the TACTSLAY.C TROJAN!"
|
X | browser | deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
X | browser aid | browseraid.exe | "BrowserAid/BrowserPal foistware"
|
X | Browser Help Svc | BHSV.EXE | "Added by the RBOT-AVQ WORM!"
|
Y | Browser Hijack Blaster | bhblaster.exe | "Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard"
|
U | Browser Launcher | Commandr.exe | Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
|
X | Browser Pal | adblck.exe | "BrowserAid/BrowserPal foistware"
|
U | Browser Sentinel | BrowserSentinel.exe | "Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer |
N | BrowserWebCheck | loadwc.exe | Checks to make sure that IE is still your default browser
|
X | BrO_AcT | BrO-AcT.exe | "Added by the SILLYFDC-D WORM!"
|
X | BS Mediaplayer | bsplyr.exe | "Added by the RBOT-OU WORM!"
|
N | BS Player | bsplayer.exe | "BSplayer - A video player used to play avi |
N | BsCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
|
? | BsMnt | BsMnt.exe | "Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer |
X | Bsoft lppt01 | Bsoft.exe | "RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
N | bsplayer | bsplayer.exe | "BSplayer - a video player used to play avi |
X | BsRte | MemoteXZZ.exe | "Added by the AUTORUN-AJU WORM!"
|
X | BSserver | FileKan.exe | "Added by the VB.CBW WORM!"
|
X | BSVCHOST | SVCH0ST.EXE | "Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
|
X | Bsx3 | "RunDLL32.EXE bs3.dll | DllRun" |
U | BT Broadband Basic Help | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
U | BT Broadband Desktop Help | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
U | BT Broadband Help | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
X | BT00003* | abcdefg23.exe | "Added by the VB-VT TROJAN where * = 5 |
X | BT00003* | hiklmnop27.exe | "Added by the VB-VT TROJAN where * = 2 |
U | btbb_wcm_McciTrayApp | McciTrayApp.exe | "System tray access to Motive's Broadband 2.0 configuration and repair utility"
|
U | BtcMaestro | KMaestro.exe | Multimedia keyboard manager. Required if you use the multimedia keys
|
N | btdna | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
N | btdna.exe | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
? | btinst | btinst.exe | "Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
|
U | BTModemProtection | BTModemProtection.exe | "BT Privacy Online modem protection software |
X | btmsre.exe | btmsre.exe | "Added by the SDBOT.AM WORM!"
|
U | BTopenworld | DialBTYahoo.exe | BT Yahoo! internet connection manager
|
? | BTSETBOOTKEY | BTSetBootKey.exe | "Related to a USB Bluetooth adaptor. What does it do and is it required?"
|
U | BtStart | btstart.exe | "Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software"
|
U | BTTray | BTTray.exe | "System tray icon which shows the status of a Bluetooth wireless module (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Also allows access to explore bluetooth places |
Y | BTUSRBDG | BtUsrBdg.exe | "Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
|
Y | BTUSRBDGF | BtUsrBdg.exe | "Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
|
X | BTV | btv.exe | "BroadcastPC adware"
|
X | BtvC | btvclean.exe | "BroadcastPC adware"
|
Y | Bubble | Bubble.exe | "Part of Windows SteadyState |
N | Buddyizer | Buddyizer.exe | Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
|
N | BudgetSip | BudgetSip.exe | "BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
U | BUFFALO Power Save Utility for HD | HDManage.exe | "Power Save utility for Buffalo backup hard discs"
|
Y | BufferZone | CLIENTGUI.EXE | "BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
|
N | Bug Eliminator | Bug_Elim.exe | "Bug Eliminator - ""performs a complete health check on your computer safely |
X | BugsDestroyer | SysRep.exe | "BugsDestroyer rogue system error and cleaning utility - not recommended |
U | bugwatcher service | bugwatcher.exe | "
N | BuildBU | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system
|
X | BuildLab | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
X | BuildLab | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
X | BuildLabs | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
X | BuildLabs | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
X | bulk | bulk.exe | "Added by the AGOBOT-ACR WORM!"
|
U | Bulldog Service | upsd.exe | Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
|
N | BulletProof FTP Server | bpftpserver.exe | "BulletProof FTP Server"
|
Y | BullGuard | mgui.exe | "Part of Bullguard antivirus"
|
Y | BullGuard | BullGuard.exe | "Part of BullGuard antivirus"
|
U | BullGuard Update | avxlive.exe | "Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
|
Y | BullGuard XComm | XCOMMSVR.EXE | "Part of Bullguard antivirus"
|
Y | BullGuardInit | AVXINIT.EXE | "Part of Bullguard antivirus"
|
Y | BullguardoptIn | bulldownload.exe | "Part of Bullguard antivirus"
|
X | BullsEye | bargains.exe | "BargainBuddy adware"
|
X | BullsEye Network | bargains.exe | "BargainBuddy adware"
|
? | BullsEye Tracker | BeTrack.exe | Bullseye - intelligent research assistant
|
X | Bunx | beagle.exe | "Added by the LEBREAT-E WORM!"
|
X | buohxqtfswb | gcjydr.exe | "Added by the AGENT-NRC TROJAN!"
|
X | buritos | buritos.exe | Identified as a variant of the Downloader.FraudLoad.C malware
|
N | BurnQuick Queue | BQTray.exe | "System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility |
U | Button Server | bttnserv.exe | "Found on a Compaq PC |
N | ButtonKey | ButtonKey.exe | "CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut"
|
N | Buzme | Bmui.exe | "Buzme by RingCentral |
U | BuzMe | RCUI.exe | "Display Client for the BuzMe Internet Call Waiting Service"
|
U | Buzof.exe | buzof.exe | "Buzof from Basta Computing "enables you to automatically answer |
X | BVWORSFM | bvworsfm.exe | "Added by the DLUCA-AD TROJAN!"
|
N | bwprnmon.exe | bwprnmon.exe | "FaxServe network fax software"
|
X | bxproxy | bxproxy.exe | "Added by the BXPROXY TROJAN!"
|
X | bxproxy | [random].dll | "SoftStop rogue security software - not recommended"
|
X | bxsx5 | "RunDLL32.EXE bsx5.dll | DllRun" |
X | bxxs5 | "RunDLL32.EXE bxxs5.dll | dllrun" |
X | Bymer.Scanner | Wininit.exe | "Added by the BYMER WORM!"
|
X | Bymer.Scanner | Msinit.exe | "Added by the BYMER WORM!"
|
U | BySoft FreeRAM | FreeRAM.exe | """Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status |
X | ByteDefender | ByteDefender.exe | "ByteDefender rogue security software - not recommended |
? | BZEnvironmentVariableCollector | BZEnvironmentVariableCollector.exe | "Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
|
? | BZUtilizationCollector | BZUtilizationCollector.exe | "Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
|
U | C-Media Echo Control | EchoCtrl.exe | C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
|
N | C-Media Mixer | Mixer.exe | C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
|
U | C2K | CYB2K.EXE | CYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
|
U | c32cs2 | c32cs2.exe | "Cyber Sentinel - internet filtering software"
|
U | C:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exe | CritProc.exe | "KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
|
U | C:Program FilesNetMeterNetMeter.exe | NetMeter.exe | """Net Meter is a small |
X | C:WINDOWSasam.exe | asam.exe | "Added by the PEACOMM.E TROJAN!"
|
X | C:WINDOWSIEXPLOR.EXE | IEXPLOR.EXE | """Pop Marketing"" adware"
|
X | C:WINDOWSsystem32SetupCmd.exe | SetupCmd.exe | "Detected by Kaspersky as the AGENT.AAW TROJAN!"
|
X | C:WINDOWSWinTask.exe | WinTask.exe | """Pop Marketing"" adware"
|
U | CA-AMAgent | amagent.exe | "Unicenter Asset Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery |
Y | CaAvTray | CAVTray.exe | "eTrust™ EZ Antivirus system tray application from Computer Associates"
|
X | Cabchk | Cabchk.exe | "Added by the GEMA TROJAN!"
|
X | Cabchk32 | Cabchk32.exe | "Added by the GEMA TROJAN!"
|
X | CABCInstall | CABCInstall.exe | "Ignite Technologies (was CABC) content delivery software"
|
X | Cable Modem Adapter | WindowsSec.exe | "Added by the WOOTBOT.A WORM!"
|
U | CacheBoost | trayicon.exe | "CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers |
N | Cacheman | Cacheman.exe | "Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up"
|
Y | CacheMgr | CacheMgr.exe | "Sophos Antivirus Remote Update"
|
U | CacheSentry Pro | CacheSentry Pro.exe | """CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
|
N | CACStarter | cacstart.exe | Cash A Check - check writing software
|
U | Caddais BackupOnDemand | BODMon.exe | "Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing |
U | Cadenza | CdzSvc.exe | "Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
|
U | CADS | cads.exe | "Cyber Sentinel - internet filtering software"
|
U | CafeStation | CafeStation.exe | """CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations |
Y | cafwc | cafw.exe | "CA Personal Firewall - part of the CA Internet Security Suite"
|
N | CAgent | CAgent.exe | "Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents"
|
N | CahootWebcard | CahootWebcard.exe | """The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details"". Run manually when needed"
|
X | caidiysetup | diynetsetupuni.exe | "DIYNet adware"
|
Y | CAISafe | isafe.exe | "Part of Computer Associates eTrust EZ Antivirus"
|
U | CaISSDT | caissdt.exe | "Computer Associates Dashboard Tray applet"
|
N | Cal Reminder Shortcut | calrem.exe | Produces a pop-up reminder of events scheduled using the MS Office Calendar
|
X | calc | "rundll32.exe [path] ntuser.dll | _IWMPEvents@0" |
X | calc | "rundll32.exe calc.dll | _IWMPEvents@0" |
X | Calc Microsoft Windows | wincalc.exe | Added by an unidentified WORM or TROJAN!
|
X | CALC32 | CALC32.EXE | "Added by the SPYBOT-EC WORM!"
|
U | Calendar | Calendar.exe | "This entry can be added by PlainSight Desktop Calendar and older versions of Desktop iCalendar from Desksware and the older Calendar 200X - which is no longer supported by or available from the author"
|
? | Calendar 200X Monitor | calmonitor.exe | "Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
|
N | Calendar 200X Reminder | calendar.exe | "Part of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays |
U | Calendarscope | cs.exe | "Calendarscope calendar software"
|
X | calk | calk.exe | "Added by the STARTPA-FH TROJAN!"
|
X | Call Function System32 | sddriver.exe | "Added by a variant of the SDBOT TROJAN!"
|
X | Call32 | Call32.exe | "Added by the SPAMMIT-H TROJAN!"
|
Y | CallBumping | cbpopw.exe | "Related to the Gazel 128 PCI ISDN adapter. Required if you use it"
|
U | CallCenter Main Application | V3calmcp.exe | """V3 Inc. CallCenter is a free 32-bit |
U | CallCenter Printer Interface | V3faxecp.exe | """V3 Inc. CallCenter is a free 32-bit |
N | CallControl | ftctrl32.exe | "FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed |
? | calmonitor | calmonitor.exe | "Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
|
N | CamCheck | CamCheck.exe | "NuCam camera software related"
|
U | Cameno | Cameno.exe | "Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above"
|
U | Camera Assistant Software | traybar.exe | Camera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
|
U | Camera Detector | CAMDET~*.EXE | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
U | Camera Detector | Camdetect.exe | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
U | Camera Detector | DEVDET~*.EXE | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
? | CameraApplicationLauncher | CameraApplicationLaunchpadLauncher.exe | "Supports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?"
|
U | CameraAssistant | CameraAssistant.exe | "Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom |
N | Camio Viewer x | IXApplet.exe | Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
|
? | CamMonitor | hpqcmon.exe | "From HP and related to digital imaging"
|
Y | CamWizard | CamWizrd.exe | Launches the Logitech Camera Wizard on the first reboot after installing versions of Logitech QuickCam webcam software
|
N | Canada | Canada.exe | "Known to be a dialler - but is it maliscous or clean?"
|
U | Canary | canary-std.exe | "Canary keystroke logger/monitoring program - remove unless you installed it yourself!"
|
X | candy | command32.exe | "Added by the RBOT-LV WORM!"
|
X | candynet | Taskmsg.exe | "Added by the RBOT-NA WORM!"
|
U | CANoe | CANoe32.exe | "CANoe from Vector Informatik. Development and test tool for Engine Control Units (ECU) based upon the CAN |
U | Canon MultiPASS Status Monitor | monitr32.exe | Cannon Multi-Pass status monitor - your choice
|
? | Canon PC1200 iC D600 iR1200G Status Window | CAPM1LAK.EXE | "Cannon printer related - is it required in startup?"
|
N | Canon Printer Monitor BJCxxx | Cjstlst.exe | Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs
|
U | CanonMyPrinter | BJMyPrt.exe | Printer software for Canon Bubblejet printers
|
U | CanonSolutionMenu | CNSLMAIN.exe | "
? | CAP3ON | CAP3ONN.EXE | "Canon driver |
Y | capfasem | capfasem.exe | "CA Personal Firewall - part of the CA Internet Security Suite"
|
N | Capfax | capfax.exe | "PhoneTools fax software"
|
U | capfupgrade | capfupgrade.exe | "CA Personal Firewall - part of the CA Internet Security Suite"
|
U | CAPing | CAPing.exe | Citibank Citianywhere software
|
Y | Capon | Capon.exe | Canon printer driver
|
Y | Capon | Caponn.exe | Canon printer driver
|
X | CaptionMgr32 | crssr.exe | "Added by the ZAR.A WORM!"
|
X | capture | capture.exe | "Added by the THEEF-B TROJAN!"
|
N | Capture Express 2000 | capexp.exe | "Capture Express - screen capture utility"
|
U | CaptureAssistant | CaptureAssistant.exe | "Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text |
N | CaptureBat | Capture.exe | "!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways |
N | Carbonite Backup | CarboniteUI.exe | """Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
|
N | Card Monitor | REGCNT09.exe | For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
|
? | CardScan AutoSync | CSyncCfg.exe | "Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
|
X | Care20 | Care20.exe | "TopMoxie adware"
|
U | Care2GTU | Care2GTU.exe | "Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is |
U | carpserv | carpserv.exe | "Associated with Zoltrix and Conexant modems - enables the internal modem speaker |
X | CARPserver | CARPserver.exe | "Added by the BANKER-AN TROJAN!"
|
U | CARPservice | carpserv.exe | "Associated with Zoltrix and Conexant modems - enables the internal modem speaker |
X | cartao | conflicted.exe | "Added by the DADOBRA-DV TROJAN!"
|
X | cartao | killing.exe | "Added by the DLOADER-QN TROJAN!"
|
X | cartao | cartao.exe | "Added by the BANKER-FA TROJAN!"
|
X | CAS Client | casclient.exe | "CasinoClient adware"
|
X | Cas2Stub | cas2stub.exe | "CasinoClient adware"
|
U | CasAgnt | CasAgnt.exe | Program by Extended Systems which allows you to sync your Casio PDA with your PC
|
X | Casdvqwa | bmqnzkg.exe | "Added by the RANDEX.BE WORM!"
|
X | caseyvideo | caseyvideo.exe | Malware causing adult content popups
|
X | caseyvideo[*] [* = digit] | caseyvideo[*].exe [* = digit] | Malware causing adult content popups
|
X | CashBack | cashback.exe | "Part of eXact Advertising Software |
X | CashFiesta | Cashfiesta.exe | "CASHFIESTA.A pay-per-surf adware"
|
N | Cashsurfers Cashbar Navigator | Cashbar.Exe | "Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
|
X | CashToolbar | MSCStat.exe | "Added by the DOWNLOADER-MY TROJAN!"
|
X | CashToolbar | svchost.exe | "BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
X | Casino Royale | jamesbond.exe | "Added by the RBOT-FZO WORM!"
|
X | Cassandra | [10 to 14 random char]THD.EXE | "Added by the KREPPER-AI TROJAN!"
|
X | Cassandra | cassandra.exe | "SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
|
X | CasStub | casstub.exe | "Added by the CASS-A TROJAN!"
|
X | Catalyst Control Centre | atixvdm.exe | "Added by the RBOT.DMW TROJAN!"
|
X | catsrv | catsrv.exe | "Added by the PAPLOK TROJAN!"
|
Y | CAVRID | CAVRID.exe | "eTrust™ EZ Antivirus Real Time Infection Report from Computer Associates"
|
Y | CAVS | CAVS.exe | "Cheyenne (now eTrust) antivirus"
|
X | CAZNOVAS | CAZNOVAS.exe | "Added by the CAZNO TROJAN!"
|
X | CBACK.EXE | CBACK.EXE | "Added by the PENTA-A TROJAN!"
|
U | cbInterface | cbInterface.exe | "System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
|
X | cbvcs | urretnd.exe | "Added by the FRETHOG-C WORM!"
|
U | CBWAttn | CBWAttn.exe | "Required for Bitware to answer incoming faxes |
U | CBWHost | CBWHost.exe | "Required for Bitware to answer incoming faxes |
? | CBWUser | CBWDial.exe | "Associated with Bitware that integrates fax |
X | CC2KUI | comet.exe | "Comet Cursor adware"
|
X | | | | |