Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X ools.exetools.exe"FastFind adware variant"
Xsystem32.exe"Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field"
Xpathex.exe"Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field"
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
XMSPF.EXE"Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.exe"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.dll"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xajsha5.exe"Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field"
Xne.exe"Added by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
Xgbpm.exe"Added by the DLOADR.ZZD WORM! Note - has a blank entry under the Startup Item/Name field"
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
Y!ewidoewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
main dri"Xwininfo.exe
U"aimb.exe"" -h"aimb.exe"IMSufSentinel is a spy program which can record IM conversations
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Inc.""Machine WorksXaecces.exe
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
Inc.""Miramar SystemsUatmsg.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
Mass""TelechipsUpatch.exe
please"This is a virusXbigbadvirus.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
""[Ephemeral 2.4] by TreeHuggerX[path to worm]
""[Ephemeral 2.5] by TreeHuggerX[path to worm]
""[Ephemeral 2.x] by TreeHuggerX[path to worm]
Y#NAME?ZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
U$EnterNetEnternet.exe"Connection manager for the EnterNet ISP. You can also use RASPPOE"
X$sys$cmp$sys$xp.exe"Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$drv$sys$drv.exe"Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
U$Volumouse$volumouse.exe"Volumouse from Nirsoft. ""Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"""
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
?%cmpmixtitle%%cmpmixstr%"Possibly related to C-Media Mixer Control panel?"
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X%Temp%%Temp%delwdef2008.bat"WinDefender 2008 rogue privacy program - not recommended
X%Windir%winnl.exewinnl.exe"Added by the KIDKITI TROJAN!"
X%Windir%winnm.exewinnm.exe"Added by the KIDKITI TROJAN!"
X'AdwarePro''AdwarePro'.exe"AdWarePro rogue security software - not recommended"
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)NOTEPAD.exe"Added by the RUSTY WORM! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)twunk_32.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(Default)Systrsy.exe"Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)syspol.exe"Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(Default)5640.exe"Added by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Mcafee.exe"Added by the AGENT.AY TROJAN! Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)fada.exe"Added by the VB.HEI TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run
X(Default)Default.exe"Added by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\RunOnce & HKCU\RunOnce in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)KEYBOARD.exe"Added by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)xtreme.exe"Added by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLMRun in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Bandookmsdll.exe"Added by an unidentified TROJAN - see here"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
Y*Restorerstrui.exePart of Windows System Restore and added as a RunOnce registry entry. Leave alone
X*Security Centersecctr.exe"Added by the SDBOT.BRO WORM!"
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X*zggjmydzggjmyd.exe"Added by the AFCORE.O BACKDOOR!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X..ABC2007.exe"Added by the DLOADR-ASH TROJAN!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
?.NET configsysmon32.exe"??"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X.protectedN/A"Smitfraud variant"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
N/l:engN/A"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
N/sN/A"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
U0pit.exe"PrivateEye surveillance software. Uninstall this software unless you put it there yourself"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
U000StTHK000StTHK.exe"Toshiba Hot key functionality for the function keys (Fn-Esc
X0050726-007-i32-10050726-007-i32-1.exe"Added by the BANCBAN-EC TROJAN!"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
?00notify33NetBrowser.exe"Part of Best Network Security
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
?00saskdanewlock.exe saskda"Part of Access Manager
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U00THotkey00THotKey.exe"For Toshiba Satellite notebook series to use the front buttons
U00THotkeysystem32THotkey.exe"For Toshiba Satellite notebook series to use the front buttons
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X0_AVD32xzboot.exe"Added by the AGENT-IWI TROJAN!"
X11.exe"Added by the ESTEEMS TROJAN!"
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1mrcmgr.exe"Added by the BANKER.RQK TROJAN!"
X1KHATRA.exe"Added by the AUTOIT-BP WORM!"
X1addit.exe"Added by the SDBOT-RI WORM!"
N1&1 EasyLoginEasyLogin.exe"1&1 EasyLogin - quick access to webhost 1&1's Control Panel
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
N12Voip12Voip.exe"12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"180solutions adware"
X180ax180ax.exe"180Search adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X180sa180sa.exe"180Search adware"
X1916435341.exe1916435341.exe"Added by the DLOADR-AXU TROJAN!"
X196_150_ni196_150_ni.exe"WinFixer web installer - ""foistware""
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer - ""foistware""
X197_150_ni_7197_150_ni_7.exe"WinFixer web installer - ""foistware""
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1cla1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
U1cla.exe1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
?1CmailSNETMAIL.EXE"??"
X1on11on1.exeAdult content dialler
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
X1u71u7.exe"Added by the MURBAC-A TROJAN!"
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2-suhartosuharto.exe"Added by the BRONTOK-CR WORM!"
X2020Downloadermssvr.exe"2020Search Toolbar"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
X250kg250kg.exe"Added by the AUTORUN-TI WORM!"
X252winmgr.exe"Added by the LEGMIR-AT TROJAN!"
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X27csrss32.exe"Added by the SLSORVE-D TROJAN!"
X27msm32.exe"Added by the SLSORVE-E TROJAN!"
X2k6 updatzcrss3.exe"Added by the RBOT-CPD WORM!"
X2Searchmain.exe"2Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
X3-habibiehabibie.exe"Added by the BRONTOK-CR WORM!"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
X3868253238682532.exe"Added by the AGENT-MCM TROJAN!"
?39ELTFH25Z8SKFEzg1q5.exe"Seems to be associated with software by Resplendence SP ?"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
Y3capplnk3capplnk.exeUS Robotics Modem driver
N3cdminic3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3CM Link3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it
Y3Cmlink3CmlinkW.exe"For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information"
?3Com LauncherLauncher.exe"Related to networking products from 3Com Corporation. What does it do and is it required?"
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
X3Dfx AccGFXACC.EXE"Added by the GIBE WORM!"
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3D Mouse driver
X3d_sound3d_sound.exe"Added by the RIADOS-A TROJAN!"
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
U3qdctl.exe3qdctl.exe"Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup
Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
X4-gusdurgusdur.exe"Added by the BRONTOK-CR WORM!"
X4.68474E+12netdll32.exe"Added by the SDBOT-DEV WORM!"
X456655explorer.exe"Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X49U5T1N449U5T1N4.exe"Added by the KORRON.B WORM!"
X4da92ad5.exe4da92ad5.exe"Added by the DLOADR-WZ TROJAN!"
X4k51k44k51k4.exe"Added by the BRONTOK-BH WORM!"
U4oDKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
X4wd!!!Natal!.pif"Added by the OPASERV.AI WORM!"
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X5-1-61-96members-area.exeAdult content dialler
X5-2-46-1125-2-46-112.exe"Adult content pop-up dialler. Removal instructions here"
X5-megawatimegawati.exe"Added by the BRONTOK-CR WORM!"
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
X5whgue215whgue21.exe"ClearSearch adware"
X6-susilo bsby.exe"Added by the BRONTOK-CR WORM!"
X6.54388E+16rkgnd.exe"ANG AntiVirus 09 rogue security software - not recommended
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X666Ska.exe"Added by the PIPES TROJAN!"
X678lsas32.exe"Added by the SLSORVE-B TROJAN!"
X7.61125E+16angpd.exe"ANG AntiVirus 09 rogue security software - not recommended
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
X7f8ez****.exe 9idf"Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder"
X7X29C2X78Ysyss_.exe"Added by the AGENT-GMS TROJAN!"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g MIMO Wireless UtilityRaUI.exe"Wireless configuration utility for Railink 802.11g MIMO based products"
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X8254502482545024.exe"Added by the AGENT-MBV TROJAN!"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
Y9xadiras9xadiras.exe"Allied Telesyn AT series router/modem related - apparently required"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@RUNDLL.EXE"Added by the SPYBOT-DN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
X@sysload.exe"Added by the DELF-EL TROJAN!"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
X@wincms.exe"Added by the RBOT.CBR WORM!"
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
N@Hoc ToolbarAtHoc.exe"One-click activated browsing toolbar used by various web-sites. See here for more info"
N@lohareminder.exe"Registration reminder for
Y@OnlineArmor GUIoaui.exe"System Tray access to and main user interface for the Online Armor range of security tools from Tall Emu Pty Ltd. The free version incorporates a firewall
X@tour_ww@tour_ww[1].exeAdult content dialler
Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
Xajesse.exe"Added by the MELO-A WORM!"
XaMsSvrdll.vbs"Added by the MUTAFROG!INF WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
NA NoteA Note.exe"""A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"""
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-squareda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Ya-squareda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-squared Anti-Dialera2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
Ya2adguarda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Ya2guarda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
UA4ProxyA4Proxy.exe"Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites"
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
XA5118rj6321422.exe"Added by the BRONTOK-AK WORM and variants!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
Xa9z1eizA1eatulabov.exe"Added by the AGENT-GWD TROJAN!"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xaaaaaa.exe"Added by the POISON.PG BACKDOOR!"
?AAACLEANAAACLEAN.INF"??"
?AAAKeyboard??"??"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide
Xaacmeyfaacmeyf.exe"Added by the AF.20 TROJAN!"
XAaepopar.exe"PurityScan/Clickspring adware"
UAAKaak.exe"Advanced Anti-Keylogger - ""Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"""
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAaouamee.exe"PurityScan adware"
XAappadprot.exe"AdBlaster adware"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
XAASSKK2LSASS.EXE"Added by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
UAAWAd-Aware.exe"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"
UAAWTrayAAWTray.exe"System Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool"
?ab EazySchedulerezsched.exe"??"
Xabassabass.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
Xabcdefghabcdefgh.exe"EPJ TROJAN!"
UABIT uGuruuGuru.exe"ABIT µGuru - on motherboards incorporating the µGuru processor this provides quick access to ""hardware monitoring
NABITEQabiteq.exe"Monitoring utility for ABIT Motherboards. Displays system voltages
XAboxAbox.exe"Adultbox adware"
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
YABRegmonABregmon.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
UAbsolute Shielddseraser.exe"Absolute Shield Evidence Eliminator - internet history eraser"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XABsrabsr.exe"Added by the AUTOUPDER TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
UAbyssusrazerhid.exe"Razer Abyssus gaming mouse driver - required if you use the additional features and programmed keys/macros"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
Uacaaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
Uaca.exeaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
UAcBtnMgr_X63AcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X73AcBtnMgr_X73.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X83AcBtnMgr_X83.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
Uaccacc.exe"Advanced Call Center - ""full-featured yet easy-to-use answering machine software for your voice modem"""
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
YAccelerometerStAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAccessoriesPlusclockplus.exe"Clock Plus
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
Yaccrdsubaccrdsub.exe"ActivIdentity ActivClient - security software from ActivIdentity Corporation which ""enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login"""
UAcctMgrAcctMgr.exe"Norton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
Xaccwizz.exeaccwizz.exe"Added by the RULAND.A WORM!"
Xaccwizzz.exeaccwizzz.exe"Added by the RULAND.A WORM!"
NACDaemonACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
Xacdllib3bcdlmem.exe"Added by the MAILBOT-BA TROJAN!"
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize
?Ace bowsAce bows.exe"??"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
UAcer Assist Launcherlauncher.exe"Acer Assist - program that provides information about new updates or notices from Acer"
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UAcer ePower ManagementePowerTray.exe"Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks. Also appears as the Packard Bell PowerSave power management utility included on some of their notebook models - as Packard Bell is now owned by Acer"
UAcer ePower ManagementePowerTrayLauncher.exeLauncher for the Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
YAcer Launch ToolAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
UAcerGotoAcerGoto.exe"Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
XAceu[random filename]"PurityScan adware"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
YACMONACMON.exe"ASUS Splendid ""is a breathtaking innovation that brings the video viewing experience on PC to the next level. Built into the driver of ASUS graphics cards
UACMonitor_X63ACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X63.exeACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X73ACMonitor_X73.exe"Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
UACMonitor_X83ACMonitor_X83.exe"Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
UACMonitor_X84-X85ACMonitor_X84-X85.exe"Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
XAcontiaconti.exeAdult content dialler
Uacousticacoustic.exe"Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained"
Nacpartagpart11.exeProgram for finding trucks on-line
XAcrobatacrmon32.exe"Added by the SMALL-ECT TROJAN!"
UAcrobat AssistantAcroTray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
XAcrobat Readacroup32.exe"Added by the VANBOT-BQ TROJAN!"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
XAcroreadAcroRD32.exe"Added by the DLOADR-BDK TROJAN! Note - this is not the popular Adobe Reader"
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
?ActionAgentactionagent.exe"""A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client"". Is it required?"
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UACTIVBOARDABoard.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exe"ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
UActMakerActMak25.exe"""ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding
UActMakerActMaker25.exe"ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload"
UACTrayACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
UACUACU.exe"Atheros wireless Client Utility"
UACU_QSBACU.exe"Atheros wireless Client Utility"
UACWLIconACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UAd Arrestadarrest.exe"Ad Arrest IE popup killer from GameFools"
UAd Blockerblocker.exe"Ad Blocker - blocks popups
UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
UAd MuncherAdMunch.exe"Ad Muncher removes adverts
?Ad Online Guideadonlineguide.exe"??"
UAd-AwareAd-Aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAd-AwareAd-Aware.exe"Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
XAd-Eliminatorad-eliminator.exe"Ad-Eliminator rogue spyware remover - not recommended
UAd-MuncherADMUNCH.EXE"Ad Muncher removes adverts
UAd-Protectad-protect.exe"Ad-Protect spyware and spam monitoring tool"
UAd-watchAd-watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAD2KClientAD2KClient.exe"Executable for Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
UAdBinAdBin.exe"AdBin - ""Free and easy solution to managing your Window's hosts file. A fun way to block ads"""
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAddClassAddClass.exe"CoolWebSearch Addclass parasite variant"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
UAdDeleteAdDelete.exeBanner advertisment blocker
XAdDestroyerAdDestroyer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
?addproxyaddproxy.exeRelated to Adobe Photoshop
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
?ADGADG.exe" SoundBlaster Audigy related?"
NADGJdetADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Yadi CleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
Yadi DSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XaDiradirss.exe"Added by the SPAMSRV-E TROJAN!"
YAdirasAdiras.exeADSL USB modem related
Xadirkaadirka.exe"Added by the TIBS-QT TROJAN!"
XAdKillerAD Defender.exe"Part of the Advanced Spyware Remover rogue spyware remover - not recommended
Xadlhidppsncc32.exe"Added by the SLAPER.AI TROJAN!"
XADM Library Loaderadmlib32.exe"Added by a variant of the SDBOT TROJAN!"
XAdmanager ControllerAdManCtl.exe"Adware
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdministrator di DagoDago.exe"Added by the PUNYA-B WORM!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
?ADMTray.exeadmtray.exe"Part of Acer Empowering Technology. What does it do and is it required?"
XAdobeAdobe.exe"Added by an unidentified VIRUS
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
Xadobegam.exeAdded by an unidentified WORM or TROJAN!
XAdobesysbat32.exe"Added by the LOWZONES.T TROJAN!"
XAdobezteam.exeAdded by an unidentified TROJAN!
NAdobe AcrobatREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe AcrobatReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
NAdobe ARMAdobeARM.exe"Adobe Reader Manager (ARM) - update/download manager added with Adobe Reader from version 9.2. Taken from the Adobe user forums - ""AdobeARM.exe is a part of new Adobe AcrobatReader updater. If you manage updates yourself
XAdobe Filter Platformafilterplatform.exe"Added by the RBOT-OP WORM!"
XAdobe Flash PlayerAdobeFP.exe"Added by the AUTORUN-BBP WORM!"
UAdobe Gamma LoaderAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
UAdobe Gamma Loader.exeAdobe Gamma Loader.exe"Adjusts monitor colours across all programs
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background
XAdobe Reader32Acrord32.exe"Added by the RBOT-BLC WORM! Note - this is not the popular Adobe Reader"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdobeAadobes.exe"Added by the FLOOD.BA TROJAN!"
NAdobeARMAdobeARM.exe"Adobe Reader Manager (ARM) - update/download manager added with Adobe Reader from version 9.2. Taken from the Adobe user forums - ""AdobeARM.exe is a part of new Adobe AcrobatReader updater. If you manage updates yourself
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdobeManagerrundtl.exe"Added by the INJECT.IB TROJAN!"
Xadobemgradobemgr.exe"Added by the ADCLICKER TROJAN!"
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProupdt.exe"Added by the IRCBOT-VQ WORM!"
XAdobeReaderProrruxdkf.exe"Added by the RBOT.ADF BACKDOOR!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProlxlfsprrj.exe"Added by the RBOT.BDZ BACKDOOR!"
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderProsubset.exe"Added by the RBOT.OCU WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProrvdjlefr.exe"Added by the RBOT-CQZ WORM!"
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
XAdobeReaderProlssas.exe"Added by the RBOT-CLB WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProchkdisk.exe"Added by the RBOT-BDV WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
XAdobe_Readeracrotray.exe"Added by the AGENT-LNS TROJAN! Note that the legitimate Adobe file (if installed) would normally be found in %ProgramFiles%\Adobe%\%ProgramName% (where %ProgramName% is Acrobat 9.0\Acrobat or Acrobat 7.0\Distillr for example) whereas this one is located in %ProgramFiles%\Adobe"
XAdobe_RLXccwap.exe"Added by the BCKDR-RCL TROJAN!"
Xadodemasteradodemaster.exe"Downloader of Korean origin
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
Xadpadp.exe"Spyware installed by Net2Phone
XAdPopupdcf5678.exe"Added by the AGENT-FZ TROJAN!"
Xadprotadprot.exe"AdBlaster adware"
NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover
XAdsAlertAdsAlert.exe"AdsAlert rogue security software - not recommended"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
UAdsGoneAdsgone.exe"AdsGone - pop-up stopper"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
YADSMTrayADSMTray.exeASUS Data Security Manager provides password protected data encryption on ASUS notebooks
Uadsnweadsnwe.exe"EmailSpyMonitor E-mail surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwkadsnwk.exe"Keylogger Spy Monitor keystroke logger/monitoring program - remove unless you installed it yourself!"
Uadsnwsadsnws.exe"ScreenSpyMonitor surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwyadsnwy.exe"Yahoo! Messenger Spy Monitor - ""spyware program that records Yahoo! Instant Messenger information on the computer and saves it to a log file"". Uninstall this software unless you put it there yourself"
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
YADSSADSS.exe"ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied"
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
UAdSubtractadsub.exe"AdSubtract blocks ads
Xadtech2005adtech2005.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xadtech2006adtech2006.exe"Detected by Kaspersky as the VB.KC WORM!"
XAdtools ServiceAdTools.exe"Windupdates Adware"
?ADUadu.exe"Related to Cisco Aironet wireless products. What does it do and is it required?"
XAdultXAdultX.exeAdult content dialler and hijacker
XAdult_ChatAdult_Chat.exeAdult content dialler
XAdult_Chat1Adult_Chat1.exeAdult content dialler
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
UADUserMonADUserMon.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
XAdVantageAdVantage.exe"MediaAdVantage adware"
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
XAdvapiAdvapi.exe"Added by the NETDEVIL.12 WORM!"
NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
Xadvmon32advmon32.exe"Added by a variant of the CRYPTER.C TROJAN!"
UAdware Agentadware agent.exe"Adware Agent popup blocker"
XAdware PunisherAdwarePunisher.exe"Adware Punisher rogue spyware remover - not recommended
XAdware Punisher MonitorAdwarePunisher_monitor.exe"Adware Punisher rogue spyware remover - not recommended
XAdware SpyAdwareSpy.exe"AdwareSpy rogue adware remover - not recommended
UAdwareAlertAdwareAlert.Exe"Adware program
XAdwareDeleteadwaredelete.exe"AdwareDelete rogue adware remover - not recommended
XAdwareKiller_schedulesschedules.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareKiller_traytray.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdwareProtectorAdwareProtector.exe"Part of rogue security tools
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 rogue security software - not recommended
XAdwareSpyAdwareSpy4.exe"AdwareSpy rogue adware remover - not recommended
XAdware_ProNETAdware_Pro.exe"Adware Pro rogue security software - not recommended
XAdwarz Spy RemoverADWARZ.EXE"Added by the SPYBOT-EV WORM!"
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
?Aeiwlsta.exeAeiwlsta.exe"IBM High Rate Wireless LAN Adapter driver. Is it required?"
NAELaunchAELaunch.exe"Audio Applications Launcher for the Philips Acoustic Edge soundcard"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
UAESTFltrAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
?AeXSWDUsrAeXSWDUsr.exe"Altiris Express NS Client Manager software. Is it required?"
UAEZBProcaptezbp.exe"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
Xafskfask8fsfjasj8.exe"Added by the ONLINEG-L TROJAN!"
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
NAgentAgent.exe"Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this
XAgentalsys.exe"Added by the DREF-V VIRUS!"
Xagentppl.exe"Added by the DREF-U VIRUS!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
Xagent.exeagent.exe"Part of rogue security tools
?AgenteRemupd.exe"Part of an older version of Panda Antivirus. Is this an update reminder (guess because of the name)
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
Xagpagp32.exe"Added by the GAOBOT.SY WORM!"
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
Uahfpahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
Uahfprogahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
YAHNSDAhnSD.exe"AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis"
?AHNUEAHNUE.exe"??"
XAhorreMemoriaSysRep.exe"AhorreMemoria rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xahostahost.exe"Added by a variant of the SDBOT WORM!"
NAHQInitahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
XAhstiebs.exe"PurityScan adware"
XAHU[path to worm]"Added by the ANACON-B WORM!"
XAHUANACON.EXE"Added by the NACO.A WORM!"
Xahui32.exeahui32.exe"Added by the CERTIF-M TROJAN!"
UAi Gear HelpGearHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi NapAiNap.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
XAicatuaa.exe"PurityScan adware"
XAidattuh.exe"PurityScan adware"
XAidaeetu.exe"PurityScan adware"
?AidemHotKeyDVMAIN.EXE"Keyboard related"
?AidemHotKeyKEYAPP.EXE"Keyboard related"
Uaiepkaiepk2.exe"Another IE Popup Killer - pop-up stopper"
NAIMaim.exe"AOL Instant Messenger. If connected to the internet
UAIMAIM+.exeAIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
NAIM LoggerAIMLogger.exe"AIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM"
XAim Pluginaimplugin.exe"Added by the GUAP-F WORM!"
XAim Quick StartAim.exe"Added by the FORBOT-BB WORM! Note - this is not the popular AOL Instant Messenger utility"
XAIM reminderAIM reminder.exe"Added by the BUDDY.E TROJAN!"
NAim6AOLLaunch.exe"AOL Instant Messenger - start it when you want to use it"
NAim6aim6.exe"AOL Instant Messenger - start it when you want to use it"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xaimaol ml097eaimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NAimingClickAimingClick.exe"AimingClick from AimingTech. Web searching tool. Available via Start -> Programs"
UAimMonitorAimMonitor.exe"AIM Monitor Sniffer surveillance software for the AIM instant messenger. Uninstall this software unless you put it there yourself"
UAIMProaimpro.exe"AIM Pro - secure instant messaging
NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xaircityaircity.exe"Related to ""Prutect"" malware from e2Give"
YAirGCFGAirGCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
Uakeysakeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
UAKillerakiller.exe"Advertising Killer - popup stopper"
Ualaala.exe"Access Lock - ""an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program
Uala.exeala.exe"Access Lock - ""an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program
UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
?AlarmWatcherAlarmWatcher.exe"Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?"
YAlaunchAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NAlbum Fast StartABMTSR.EXE"Scanner software
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
XAlchemAlchem.exe"ClickAlchemy adware"
UAlcmtrALCMTR.EXE"Realtek Azalia Audio - Event Monitor
XAlcmtrMalware Doctor.exe"MalwareDoc rogue security software - not recommended
NAlcoholAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol 120%Alcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol.exe AutorunAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcoholAutomountaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?Alcom PCL CaptureFMW_PCAP.EXE"??"
Xalcomrg.exealcomrg.exe"Added by the SDBOT-DNT WORM!"
UAlcWzrdALCWZRD.EXE"RealTek AlcWzrd Application
UAlcxMonitorAlcxmntr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
Xalerteralerter.exe"MAHA.F spyware"
XAlevirAlevir.exe"Added by the OPASERV-A WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
NAlexaalexa.exe"Related to Alexa. Note - collects and stores information about the web pages you view
XAlexaToolbaralt.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.EB TROJAN!
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
UAlfaClock ClassicAlfaClock.exe"AlfaClock Free Edition from AlfaSoft Research Labs - ""enhances your taskbar clock (tray clock) with fully customizable clock display
UAlfaClock2AlfaClock2.exe"AlfaClock2 from AlfaSoft Research Labs -""enhances your tray clock functionality. Of course
?ALFY AccelleratorAlfyAC~1.exe"??"
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
XALG32ALG32.EXE"Added by the STARTPAGE.K hijacker"
Xalgchk.exealgchk.exe"Detected by Kaspersky as the VB.ATE TROJAN!"
XALGUALGU.EXE"Added by the CWS-I TROJAN!"
XALGU.exeALGU.exe"Added by the STARTPAGE.O TROJAN!"
Xalgv.exealgv.exe"Added by the AUTORUN-BEA WORM!"
UALi5289ALi5289.exe"Related to Uli Integrated Drivers from Uli Electronics Inc"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
NAlienAutopsyTest_BS.exe"Alienware computer technical support software"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
Xalkasr?????.exe"Added by the BALKART TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAll Sea screen saverTaskTray.exe"Free screensaver
XAll Sea web linkFWLink.exe"Free screensaver
NAllerCalcAllerCalc.exe"AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UAllSeeingEyease.exe"All-Seeing_Eye security software - ""monitors everything that takes place on your computer
UallSnapallSnap.exe"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAllToTrayALLTOTRAY.EXE"AlltoTray from DNTSoft - minimize any program to your System Tray"
XALMcsrss32.exe"Added by the ANACON-D VIRUS!"
XAlogrithm Link Queuealq.exe"Added by a variant of the SDBOT WORM!"
UAlogservAlogserv.exe"From McAfee VirusScan for logging scanning activities. In some cases
UALPassALPass.exe"ALPass password manager"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XAlphaAntalpha.exe"Alpha Antivirus rogue security software - not recommended
XAlphaAVAlphaAV.exe"Alpha Antivirus rogue security software - not recommended
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
UALServALServ.exeUtility that enables a user to control the volume and surround sound and select Pro Logic/Stereo on 2 satellite speakers and subwoofer of old Altec Lansing speaker systems. The right-side speaker has 4 controls on top providing same functionality
Xalt CTRL Shiftet3rd.exe"Added by the SDBOT-RH BACKDOOR!"
XALTER DATA[path] repcale.exe [path] beird.exe"Added by the IRCFLOOD.CD TROJAN! Both files are located in %System%\ccdew"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UALTOOLSAccessL.exe"ALTools family of PC utilities"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
XAmazingTensAmazingTens.exePremium rate adult content dialler
UAMD PowerNow!GemBack.exe"
Yamd_dc_optamd_dc_opt.exe"
NAmerica Onlineaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
UAmIcoSinglunAmIcoSinglun.exe"Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
UAModemLockDownModemLockDown.exe"ModemLockDown - allows you to supervise internet access by disabling the modem
YAmonAMON.EXE"Monitoring part of Eset's NOD32 virus-scanner"
YAmonitoramon.exe"Tiny Personal Firewall"
UAMO_Taskplaner.exeAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1.EXEAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
UAMSGAmsg.exe"Part of the IBM ThinkVantage Productivity Center. ""The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"""
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
NAMSNamsn.exe"aMSN Messenger is a multiplatform MSN messenger clone"
Xamsnamsn.exe"Added by the BANKER-BNZ TROJAN!"
Xamvaamvo.exe"Added by the SILLYFDC-BR WORM!"
NAnapod Manageranamgr.exe"Anapod Explorer from Red Chair Software ""is the most advanced Windows iPod® software available
Xanbv32nabv32.exe"Added by the TITOG.C WORM!"
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
Xangeleyesmsdll.exe"Added by the VB.PI TROJAN!"
Xanimalssanimalss.exe"Added by the AGOBOT-VE WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
?AnnotateCheckAnnCheck.exe"Genius Wizard Pen Tablet driver related. Is it required?"
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
NAnntextAnntext.exeCaere Pagekeeper text annotation server
UAnonymityGatewayAnonymity Gateway.exe"Anonymity Gateway - privacy protection tool that conceals IP address preventing your surfing habits and your internet activity form being tracked by websites or Internet Service Providers"
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
YANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
NAnti-Blaxx ManagerAnti-Blaxx.exe"Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives"
UAnti-keylogger checkantikey.exe"Anti-keylogger - protects against keylogger programs monitoring your keystrokes"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiAdd.exeAntiAdd.exe"AntiAdd rogue security software - not recommended
XAntiAIDAntiAID.exe"AntiAID rogue security software - not recommended
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Uantidialer.co.ukDialer_Watcher.exe"Dialer_Watcher is an application that allows you to detect dialers on your computer"
YAntiFreezeAntiFreeze.exe"AntiFreeze from Resplendence Software Projects - ""offers a last recourse when you find your computer in a hung state"". If your system has hung and AntiFreeze is running
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
Xantikewingate32.exe"Added by a variant of the RBOT WORM! See here"
XAntiKeepAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiKeep.exeAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiMalwareAntiMalware.exe"AntiMalware rogue security software - not recommended
XAntimalware Doctor.exeAntimalware Doctor.exe"Antimalware Doctor rogue security software - not recommended
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue security software - not recommended
XAntiMalwareSuiteAMS.exe"AntiMalwareSuite rogue security software - not recommended
XAntiMalware_ProNETAntiMalware_Pro.exe"AntiMalware Pro rogue security software - not recommended
UAntiPopUpAntiPopUp.exe"AntiPopUp for IE - pop-up stopper"
XAntiSpionagepgs.exe"AntiSpionage
XAntiSpionagePropgs.exe"AntiSpionagePro
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiSpy2008AntiSpy2008.exe"Antispy 2008 rogue spyware remover - not recommended
XAntiSpyBossasb32.exe"AntiSpyBoss rogue security software - not recommended
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
XAntiSpyKitAntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.2AntiSpyKit 5.2.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.3AntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyMonAntiSpyMon.exe"Antispyware Protector rogue security software - not recommended"
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntispySpiderantispyspider.exe"AntiSpySpider rogue spyware remover - not recommended
XAntispyStormAntispyStorm.exe"AntispyStorm rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware ProAntiSpyware Pro.exe"AntiSpyware Pro 2009 rogue spyware remover - not recommended
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot rogue spyware remover - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntispywareDAntispywareD.exe"AntiSpywareDeluxe rogue security software - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiSpywareSuitepgs.exe"AntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare family"
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiSpyZoneAntiSpyZone.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.5AntiSpyZone 4.5.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.6AntiSpyZone 4.6.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.9AntiSpyZone 4.9.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.1AntiSpyZone 5.1.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.4AntiSpyZone 5.4.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiTroyAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiTroy.exeAntiTroy.exe"AntiTroy rogue security software - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue spyware remover - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntiVirGear 3.7AntiVirGear 3.7.exe"AntiVirGear rogue security software - not recommended
XAntiVirGear 3.8AntiVirGear 3.8.exe"AntiVirGear rogue security software - not recommended
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiVituSBase.exe"Added by the BAS.A WORM!"
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
Xanti_trojanti_troj.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the LODEAR.D TROJAN!"
UAnVirAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task ManagerAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
XAnvTrgrAnvTrgr.exe"AntivirusTrigger rogue security software - not recommended
UAny To-Do Listanytodo.exe"Any To-Do List ""the ultimate software solution to keep yourself organized and reminded"""
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UAnyDVDAnyDVD.exe"AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the ""U"" recommendation"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
XanythingATITAX.exe"Added by the FORBOT-DP WORM!"
UAnyTimeAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtDem.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
NAO TrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Yaolavp.exe"AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory"
NAOLAOL.exe"Fast Start loads the AOL integrated email
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAOL Companioncompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
NAOL Fast StartAOL.exe"Fast Start loads the AOL integrated email
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
?AOLCCACCAgnt.exe"AOL ISP software related
XAolConconfig.com"Added by the TAPLAK WORM!"
NAOLDialerAOLDial.exeAOL ISP software dialer - can be activated through a desktop shortcut
NAolFixAolFix.exe"Run on Gateway Astra computers
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
XAOLStartAOLStart.exe"Added by the KRAIMER.12 TROJAN!"
Xaolupdater.exeaolupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XAornumaornum.exe"Installed along with
NAOTrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Xaoueisysrtmvs.exe"Chivio dialer"
YAPC UPS StatusDisplay.exe"APC PowerChute® Personal Edition status icon"
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
XAPCProtect.exeAPCProtect.exe"APCProtect rogue security software - not recommended
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
XAPD123APD123.exe"PacerD Media/Pacimedia.com adware"
Xaphexaphex.exe"Added by the IRCBOT-OH TROJAN!"
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAPI32api32.exe"Added by the IRCBOT-B TROJAN!"
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
XAPIMonapimonx.exeAdded by the TIBSER.A downloader TROJAN!
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
UAPLAPL.exe"Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup
Xapmanager.exeapmanager.exe"AP Manager ransomware download manager - not recommended
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UApointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApp.EXEName[path to worm]"Added by the BODIRU WORM!"
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
Xappis.exeappis.exe"Added by the AGENT-BC TROJAN!"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
NApplication LauncherApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UAppPlusAppPlus.exe"AppPlus - ""menu bar or tray launcher that docks to your desktop
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
YApwheelApwheel.exeWheel support for an Alps mouse
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xaqadcup.exeaqadcup.exe"Added by the AGENT.BG WORM!"
YAqua DockAqua Dock.exe"Aqua Dock - 'free program that allows you to have an ""OS X"" style
XAqujyjax[path to file]"Added by the RANCK-CQ TROJAN!"
XAqujyjaxaqujyjax.exe"Added by the SDBOT-YC WORM!"
Xara-key[random filename]"Added by the ANTINNY WORM!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
YArcaCheckArcaCheck.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
Xarcaderockstararcaderockstar32.exe"Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArctosarazerhid.exe"Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
UArdamax Keyloggerakl.exe"Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
Naresares.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
NaresliteAresLite.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
Xargq32csrss_32.exe"Added by the RBOT-CPM WORM!"
XAritimaaritima.exe"Added by the ARITIM WORM!"
XArman[path to worm]"Added by the IRCBOT-TG WORM!"
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue
XArmorDefenderArmorDefender.exe"ArmorDefender rogue security software - not recommended
Uarmy logoreadmename.exe"Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
Xaromisaromis.exe"Added by the NUWAR.JQ WORM!"
NAROReminderaro.exe"Advanced Registry Optimizer - ""scan
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovax ShieldArovaxShield.exe"Part of Arovax Shield from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovaxShieldArovaxShield.exe"Part of Arovax Shield from Arovax
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UArteraarteraui.exe"Artera Turbo Internet Accelerator - ""surf faster
XArucer"rundll32 Arucer.dllArucer"
XArucer Dynamic Link Library"rundll32 Arucer.dllArucer"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
Xasamasam.exe"Added by the FAKEAV-BGU TROJAN!"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasc32asc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
XASDdASDd.exe"AntiSpywareDeluxe rogue security software - not recommended
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINbelgium_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINuk_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
YAshampoo FireWallFireWall.exe"Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
YAshampoo FireWall PROFireWall.exe"Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
YashAvastashAvast.exe"Part of Avast antivirus"
Xashcapservirsess.exe"SpySure spyware"
XashDip.exeashDip.exe"Added by the DROPR-CZ TROJAN!"
YashDispashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
XashDsp.exeashDsp.exe"Added by a variant of the SDBOT WORM!"
XASHLTAshlt.exe"Ashlt adware"
YashMaiSvashmaisv.exe"E-mail scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAsiaeasm.exe"PurityScan adware"
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XaslAslru.exe"Added by the BANCOS-CU TROJAN!"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?AspireServiceAspireService.exe"Found on Acer laptops
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XASpyCASpyC.exe"AntiSpyCheck rogue spyware remover - not recommended
Xasr64_ldm.exeasr64_ldm.exe"Added by the Dr. Guard rogue security software - not recommended
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
XAss and tittiesCMD32.EXE"Added by the SDBOT-GG BACKDOOR!"
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
XASTAST"Added by the VB.AH TROJAN!"
XASTAST.exe"AutoStarter parasite"
UASTARTastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
XAStartAStart"Added by the VB.AH TROJAN!"
NasTrayAstray.exe"Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer"
NAstroAstro.exeChecks for updates to Quicken on a system reboot
XAstrumAstrum.exe"Astrum Antivirus Pro rogue security software - not recommended
Xasusasus.exe"Added by the RBOT-OC WORM!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
UASUS TweakEnableastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
NASUSGamerOSDGamerOSD.exe"GamerOSD by ASUSTek - for ""real-time overclocking
NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
Xasussvcasussvc.exe"Added by the AGENT-FPB TROJAN!"
UAsusTrayAsTray.exe"Part of the ACPI driver for the Asus Eee PC range. Watches the sensors of the motherboard such as power and temperature"
UasustweakenableATweak.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
NASUSWebStorageASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NAsusWSDashBoardASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NASWDPASWDP.exe"MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
XASWnkaswnk.exeAdult content dialler
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAT-WatchATWatch.exeAnti-Trojan Watch - trojan detector
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
Uatchkatchk.exe"AMT Status Message from Intel. Users can manage this
Xatf.exepgs.exe"Part of the PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
UAthanAthan.exe"Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world"
UATI 2D ComponentAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
NATI CATALYST System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
XATI Cpanelatiphexx.exe"Added by the AGOBOT-NV WORM!"
UATI Desktop ComponentATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
XATI DisplayATIDisplay.exe"Added by the BDOOR-AFH BACKDOOR!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
NATI GART Set-up UtilityAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
UATI Launchpadlaunchpd.exe"Convenient way to start all your Multimedia Center applications (DVD
XATI Rage3d ProAtiRage4dPro.exe"Added by the AGOBOT-OG WORM!"
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
?Ati2cwxxAti2cwxx.exe"For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it"
XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
UAti2mdxxAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
NATICCCCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
XAtiCpanelatiphexx.exe"Added by the AGOBOT.IL WORM!"
Xaticpaxx.exeaticpaxx.exe"Added by the RBOT-XP WORM!"
UAtiCwdAtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAti2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32Ati2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename
NAtiGartAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
NAtiKeyAtiKey32.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NAtiKeyatiptkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Control Panel → Display
NAtikeyAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATIMACEMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) component
UATIModeChangeAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XAtiPanelatip.exe"Added by the TACTSLAY.U TROJAN!"
Xatipatxxatipatxx.exe"Added by the SMALL-ED TROJAN!"
NATIPOLABati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
NATIPOLLati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
UAtiPTAAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UATIPTAATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
UAtiPTAAtiptaab.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UAtiPTAAAAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UAtiPTAAAATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
UatiptaxxAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UATIPTAXXATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
Xatiptextatiptext.exe"Added by the COSIAM-A TROJAN!"
UAtiQiPclAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
YATIRmtWndrATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
Uatitrayatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
UAtiTrayToolsatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
XatiupdateATIUPDATE5.EXE"Added by the DEBESKI.A TROJAN!"
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
XATIUpdateratiupdxx.exe"Added by the RBOT-ABX WORM!"
XAtiupdplatiupdpl.exe"Added by the SMALL.AOS TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
YATIX10atix10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
UATKMEDIADMEDIA.EXE"Driver for the media buttons on the front of some Asus laptops
UATKOSD2ATKOSD2.exe"On-screen display utility bundled with laptops from ASUS. If this utility is not installed then you will not be able to properly use other AsusTek utilities such as Splendid and Power Gear"
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XATM Controladpn.exe"Added by the MMS.A WORM!"
NATnotesatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
XAtomic-x27Atomic-x27.exe"Added by the KATOMIK-A WORM!"
XAtomic-x27CAtomicpartC.exe"Added by the KATOMIK-A WORM!"
UAtomic.exeAtomic.exe"Atomic Clock Sync - synchronizes your computer's time with the NIST time server"
NAtomicaatomica.exe"Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key"
UAtomicTimeATOMICTIME.EXE"AtomicTime - utility that synchronizes your PC clock to an atomic clock"
UAtomSyncatomsync.exe"AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
UAtrackatrack.exe"New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker
UAtrayAtray.exe"Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttunelAttunel.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneSystrayattune_st.exe"Aveo Attune automated helpdesk software - adware/spyware"
NaTuneratuner.exe"aTuner - tweak tool for GeForce based graphics cards"
Yatwtusbatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
XAtxBrwIexplor.exe"""Pop Marketing"" adware"
UauDealioAu.exe"Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products"
UAU AgentAUagent.exe"Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon"
Xau.exeau.exe"Added by the BEAGLE.B WORM!"
YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
XAucompatAucompat.exe"Added by the GEMA TROJAN!"
XAudcntraudcntr.exe"Added by the GEMA TROJAN!"
?AudCtrl"RunDll32 AudCtrl.dll RCMonitor"
Xaudi32audi32.exe"Added by the RANCK-FL TROJAN!"
XAUDIOSOUND.exe"Added by the PLOYB-A TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
XAudiocntlaudiocntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
NAudioCommanderAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommander ApplicationAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioDeckADeck.exeADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
XAudiodrvaudiodrv.exe"Added by the CRYPTER-C TROJAN!"
UAudioDrvEmulatorDLLML.exe AudDrvEm.dll"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
NAudioHQAhqtb.exeFor Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
XAudioHQaudiohq.exe"Added by the BANKER-EHK TROJAN!"
NAudioHQUAHQTBU.EXESystem Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
Xaudioinfaudioinf.exe"Added by a variant of the CRYPTER.C TROJAN!"
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
XaugmsgAUGMSG.EXE"Added by the SPYBOT-CO WORM!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
XAuth Starter Identstartauth.exe"Added by the RBOT-WP WORM!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
Xauthzauthz.exe"Added by an unidentified VIRUS
Xautowin32.exe"Added by an unidentified TROJAN! See here"
Xautoauto.exe"Added by the DOQ.GEN.Y BACKDOOR!"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
XAuto Startdosin.exe"Added by the SDBOT-GO BACKDOOR!"
XAuto Startsndvol32.exe"Added by the SLINBOT.AX BACKDOOR!"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
NAuto T Barautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto updatSysDebug.exe"Added by the FORBOT-BA WORM!"
XAuto UpdateAUP.exeAdded by an unididentified WORM or TROJAN!
XAuto Updatedma.exe"Added by the RBOT-AVO WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
UAutobarautobar.exe"Connect buttons on the keyboard for internet direct access
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
Xautochk"rundll32.exe autochk.dll_IWMPEvents@16"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
Uautoclkautoclk.exe"Autoclik is a Windows utility ""that allows you to perform all mouse activity with absolutely no clicking"""
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
XAUTOEXEAUTOEXE.exe"Added by the SEMAPI-A WORM!"
Xautoloadcftmon.exe"Added by the SOCKS-E WORM!"
Xautoloadspooll.exe"Added by the SILLYFDC WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
Xautoloadspool.exe"Added by the AGENT-GSG TROJAN!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
UAutoMate5Am5HkWnd.exe"""Automate is the Leading Software for Automation of front and back-office business processes.It provides all the tools necessary to completely automate business processes
UAutoMate6AMEM.exe"AutoMate 6 for automating repetitive tasks"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAutopdateAutopdate.exe"Added by the RBOT-AGL WORM!"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
Xautorepairdexs.exe"Added by a variant of the SDBOT WORM!"
Xautornautorn.exe"Added by the SILLYFDC.BCY WORM!"
UAutoroute SMTPAutoSmtp.exe"Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
Xautorunautorun.exe"Added by the AUTOM-B WORM!"
Xautorunsxs.exe"Added by the SMALLVBS-A WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
XAutoRunallrs.exe"Added by the MUDROP.LJ TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
UAutoSizerAUTOSIZER.EXE"AutoSizer - utility that automatically maximizes windows when they're opened"
NAutoSpellautospel.exe"AutoSpell - spell checker (version 6.*)"
NAutoSpell 5ASWATC32.EXE"AutoSpell - spell checker"
UAutoSysautosys.exe"Winguardian surveillance software. Uninstall this software unless you put it there yourself"
Nautotbarautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
NAutoTKitAUTOTKIT.EXEOn HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled
Nautoupdautoupd.exeRaxco Software auto update utility
Xautoupdautoupd.exe"Added by an unidentified VIRUS
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
Xautoupdatev2autoupdatev2.exe"Detected by Kaspersky as the AGENT.FQ TROJAN!"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Xauto__antiav__keyantiav_exe.exe"Added by the BAGLEDI-AA TROJAN!"
Xauto__hloader__keyhloader_exe.exe"Added by the BAGLE.AB TROJAN!"
Xaux.exeaux.exe"Added by the ZINS TROJAN!"
XauxAudioDeviceaux32.exe"Added by the AIZU WORM!"
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAVAntivir.exe"Antivir rogue security software - not recommended
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
NAvaFindAvaFind.exe"AvaFind file search utility"
Xavagent3974chnb8895.exe"AntiVirus ransomware security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
YAvast!ashServ.exe"Main part of avast! Antivirus - including the resident protection
Yavast!ashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAvast32Astart32.exe"Part of Avast! anti-virus software"
Xavcavmon.exeAdded by an unidentified TROJAN!
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
YAVG IDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_AMSVRAVGAMSVR.EXE"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
YAVG7_CCavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG7_EMCavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG7_Runavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
UAVG8_TRAYavgtray.exe"System Tray access to and notifications for the 8.* series of internet security products from AVG Technologies - including Internet Security
UAVG9_TRAYavgtray.exe"System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security
Yavgamsvr.exeAvgamsvr.exe"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgasavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
Yavgccavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
Yavgcc32avgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVGCtrlAVGCtrl.exe"Part of AntiVir® PersonalEdition Classic antivirus"
Yavgemcavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
YAVGIDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
YAVGIDSUIAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
YAVGntAVGnt.exe"AntiVir® PersonalEdition Classic antivirus. System Tray icon and control program"
YAvgserv9.exeAvgserv9.exe"Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
Uavgtrayavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVGuardAVGuard.exe"AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
YAVG_CCavgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVG_EMCAVGEMC.exe"AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XAvimgtAvimgt.exe"Added by the GEMA TROJAN!"
XAvimgt32Avimgt32.exe"Added by the GEMA TROJAN!"
YavinitAVINIT9X.EXE"Command Antivirus related"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
XAvirTrAvirTr.exe"AntivirusTrigger rogue security software - not recommended
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
YAVKBarAVKBar.exe"GData AntiVirusKit Anti-virus"
YAVKTrayAVKTray.exe"System Tray access to the antivirus part of G Data range of internet security products"
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
?AvMenuAVMenu.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required?"
YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
Yavpavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavpavp.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
XAVP-SEavp-32.exe"Added by the AGOBOT.FS WORM!"
Xavpaavpo.exe"Added by the LEGMIR-ARK TROJAN!"
Yavpccavpcc.exe"Kaspersky Labs anti-virus"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
XAvpMAvpM.exe"Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in %Windir%\pchealth\UploadLB\Config"
Xavpmsavpms.exe"Added by the ONLINEGAMES.CPV TROJAN!"
XAvpravpr.exe"Added by the MYDOOM.AF WORM!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
Xavrlabsavrlabs.exe"VirusResponse Lab 2009 rogue security software - not recommended"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVSeguropgs.exe"AVSeguro
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
Xavserve2.exeavserve2.exe"Added by the SASSER.B or SASSER.C WORMS!"
Xavserve3.exeavserve3.exe"Added by the SASSER.G WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
Xavtapiavtapi.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
NAvtrayAvtray.exe"Command Antivirus tray icon"
XAVTrayAVTray.exe"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVupdate32 UpdateAVupdate32.exe"Added by the RBOT.CNI TROJAN!"
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
YAVWUpd32AVWUPD32.EXE"AntiVir® PersonalEdition Classic - updater"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
YAvxliveavxlive.exe"Bullguard or BitDefender antivirus"
Yavxlniavxinit.exe"Anti-virus part of BitDefender virus scanner/firewall"
?Avxnews??"??"
UAwatchAwatch.exe"Diagnosis tool that monitors DSL connections
UAwaySchAwaySch.EXE"Part of the IBM ThinkVantage Productivity Center. ""The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"""
UAWCAWC.exe"Advanced SystemCare from IObit - ""helps protect
Nawhost32awhost32.exe"Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file
UAWMONAd-Watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAWMONAd-Monitor.exe"F-Secure Anti-Spyware"
XAwoasmmo.exe"PurityScan adware"
XAwolaAwola.exe"Awola rogue spyware remover - not recommended"
XAwola6Awola6.exe"Awola AntiSpyware 6.0 rogue spyware remover - not recommended
Uawpliteawplite.exe"AllWallpapers Lite desktop wallpaper changer"
?AWUSGSTAAWUSGSTA.exe"Reportedly related to a USB Wifi Adapter - is it required at startup?"
UawxDTools"awxDTools.dll awxRegisterDll"
Naxcmdaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?AxFilter"Rundll32 AXFILTER.DLL Rundll32"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
UAzMixerSelAzMixerSel.exe"Related to Realtek_Azalia Mixer Selector"
Yazmodemazexe.exe"Aztech Labs modem driver"
XA_M_P_NETAntiMalwarePro.exe"AntiMalware Pro rogue security software - not recommended
?a_vpdvpd.exe"Located in an IBMTOOLS\VPD sub-directory. What does it do and is it required?"
Ya2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
Xb.exeb.exe"Added by the SDBOT.BND WORM!"
NB.Readerremin.exe"Birthday Reminder 5.0 - as the name implies"
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
Xb3dUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
Ub9B9.exe"FireTrust Benign - allows you to receive e-mail which is safe from viruses
Xb99msmm.exe"ClientMan parasite variant"
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
Xbabeie"rundll32 cnbabe.dll dllstartup"
NBabylon ClientBabylon.exe"Babylon-Pro is a powerful information tool that instantly provides relevant information
NBabylon TranslatorBabylon.exe"""Babylon-Pro is a powerful information tool that instantly provides relevant information
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
UBack2zipBack2zip.exe"Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up"
XBackdoor.NuAgentagent.exe"Added by the AGENT-DP TROJAN!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
NBackpack UDFbpudfmon.exe"Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
Xbackup[path to worm]"Added by the AGOBOT-H WORM!"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackup Servicebackup.svcUnidentified adware
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackup4all OTB AgentB4AOTB.exe"""Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
?BackupNotifybackupnotify.exe"HP Digital Imaging related. What does it do and is it required?"
NBackWebbackweb.exeAutomatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
NbackWeb-8876480backweb-8876480.exe"Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products
NBackworkBackwork.exe"Backwork trojan detector"
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBADDATEBADDATE.EXE"Added by an unidentified VIRUS
XBadxHELLRAIDER.EXE"Added by the MINDCTRL.A BACKDOOR!"
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBakraIEHost.EXE"Added by the MULTIDR-AH TROJAN!"
XbalSYSMONMS.EXE"Added by the FAKEALERT TROJAN!"
XBand-Aid[path to file]"Added by the RANKY.O TROJAN!"
Ubandmonbandmon.exe"Rokario Bandwidth Monitor"
XBandookali.exe"Added by the EXEMAS-B TROJAN!"
NBandwidth Meter ProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBandwidth Monitor ProBandwidth Monitor Pro.exe"Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP"
NBandwidthMeterProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBanpopup by PratikBanpopup.exeBanpopup - popup killer
Xbantoolbantool.exe"Malware installed by different rogue security software including SpyKillerPro"
Xbantoolie_ban.exeDetected as the VB.PO TROJAN!
XBanyak_KerjaanTukang.exe"Added by the SILLYFDC.BDM WORM!"
XBar Ding loltAnaliz.exe"Added by the RBOT-RP WORM!"
Xbargainsbargains.exe"BargainBuddy adware"
Xbargainsbargainbuddy.exe"BargainBuddy adware"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
?Bart Stationstation.sbrt"Related to PeoplePC ISP. May be a dialler for dial-up accounts?"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
XBarThemebartent32.exe"Added by the AGOBOT-UG WORM!"
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBastioneAntiviruspgs.exe"BastioneAntivirus
XBatsecure2.bat"Added by the ZCREW.C TROJAN!"
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
UBatLogEx"rundll32.exe [path] BatLogEx.DLLStartBattLog"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
UBatteryBarbatterybar.exe"BatteryBar - displays battery usage
Ybatterymiserbatterymiser.exe"Battery Miser power management utility for LG Notebooks"
YBatteryMiser 5BatteryMiser5.exe"Battery Miser 5 power management utility for LG Notebooks"
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
UBAUSBBAUSB.exe"Boston Acoustics Audio
Xbawindobawindo.exe"Added by the BEAGLE.AR or BEAGLE.AU WORMS!"
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBayMgrDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
UBayswapbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
NBBC AlertsBBC_Alerts.exe"BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
?BBDialBT Broadband.exe"Part of BT Broandband - is it required?"
NBBLauncher.exeBBLauncher.exe"BounceBack Professional - back-up software"
NbbSysTraybbSysTray.exe"Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"""
Ubbuibbui.exeAOL DSL status monitor displaying a red/green icon indicating if you have a connection
Ubcabca.exe"BeClean Agent - registry
UBCDetectbcdetect.exeBcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
?bcmwltrybcmwltry.exe"Broadcom Corporation Wireless Network Tray Applet. Is it required?"
NBCNTbcnt.exe"AWS Weatherbug related. What does it do?"
XBCPCbcpc.exe"BroadcastPC adware variant"
Xbcpc_cbcpc_c.exe"BroadcastPC adware variant"
UBCSSyncBCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
UBCTweakbctweak.exe"BlasterControl for Creative video cards - controls for desktop settings
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
NBCWipeTMbcwipetm.exe"BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task
XBDdc.exe"Added by the RASDOOR-A TROJAN!"
YBDAgentbdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
Xbdfgergggasw.exe"Added by the SDBOT-RT WORM!"
YBDMConBdmcon.exe"BitDefender antivirus"
YBDNewsAgentbdnagent.exe"BitDefender antivirus - updater"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
UBDRegionbrs.exe"Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
YBDSwitchAgentbdswitch.exe"Bitdefender 8 antivirus and firewall"
YBDWizRegbdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
UBearFlixBearFlix.exe"BearFlix is optimized for the fast download of video files"
NBearSharebearshare.exe"BearShare file sharing client. Versions known to include spyware - see here"
UBeatNik Internet ClockBeatNik.exe"BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
XBeegees Updatebeegees.exe"Added by the SDBOT-ADK WORM!"
?BEEIbeei.exe"??"
UBeFasterbefaster3.exe"BeFaster internet connection optimization tool"
Xbegins0.exe"Added by the MYTOB-HE WORM!"
?BEHLBEHL.exe"??"
?BEHLOBEHLO.exe"??"
Ubeidsystemtraybeidsystemtray.exe"Related to Belgium Identity Card card reader"
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
UBelkin Wireless USB UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UBelkin Wireless UtilityBelkinwcui.exe"Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
UBellSouthAlertManager.exeBellSouthAlertManager.exe"Related to BellSouth Alert Manager"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
?BELORVBIBELORVBI.exe"??"
?Belsta.exeBelsta.exe"Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?"
XBeltBelt.exe"VX2.Transponder parasite updater/installer related"
XBenadril Alert Toolbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
XBestPopUpKillerBestPopupKiller.exe"Popup killer by Swanksoft - not recommended
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
XBeSys[path to file]"BeSys adware"
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XBF4Pbf4p.exe"Added by the IRCBOT.GEN WORM!"
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
Ybgbullguard.exe"Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster"
UBGInfoBginfo.exe"BGinfo automatically displays relevant information about a Windows computer on the desktop's background
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
YBGNewsAgentbgnewsag.exe"BullGuard antivirus updater"
Xbgoomain.exebgoomain.exe"Baigoo.a malware"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
XBharatayudaGNB.exe"Added by the BHARAT.A WORM!"
NBHOCopBHOCop.exe"PC Magazine's
UBHODemon 2.0BHODemon.exe"BHODemon ""protects you from unknown Browser Helper Objects (BHOs)
UBHRBHR.exe"Browser Hijack Retaliator - recovers your browser after it has been hijacked by spyware
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
XBIGbiggy.exe"Added by the DELBOT-AG WORM!"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
?BigDogPathVM_STI.EXE"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
NbigfixBIGFIX.EXE"BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs
Xbiglowbiglow.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
Xbigorisbigoris.exe"Added by the DORF-AZ TROJAN!"
UBigPond ToolbarbpumTray.exe"Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
Xbikinibikini.exe"Added by the LOWZONE-CX TROJAN!"
XBillGatesLoh.exeBillGatesLoh.exe"Added by the AGENT-FZO TROJAN!"
NBillminderBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start -> Programs
Xbin32hpuppstub.exe"PrecisionPop adware"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XbingdianBingdian.vbs"Added by the BINGD WORM!"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
UBiomenumenusw.exe"Related to Sony VAIO - passwords
UBionix Wallpaper 5Bionix Wallpaper 5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionix Wallpaper 5beta.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBioniX Wallper.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionixWallpaper5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
XBiosBios32.exe"Added by an unidentified VIRUS
Xbiosbios.exe"Added by the BANCBAN-PW TROJAN!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBIOS1BIOS1.EXE"Added by the OPASERV.T WORM!"
?BIOVCIPBIOVCIP.exe"??"
?BisonHKBisonHK.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
NBitCometBitComet.exe"BitComet P2P client - can be launched from Start -> Programs"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
UBitDefender for Yahoo! Messengeryahmon.exe"Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
XBittorrentbittorrent.exe"Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir%"
NBitTorrentbittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitTorrent DNAbtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbittorrent.exebittorrent.exe"BitTorrent file sharing client - from BitTorrent
NBitWare Print Monitorbwprnmon.exe"FaxServe network fax software"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
Nbjcfdcdf.exe"BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
UBJLaunchEXEBJLaunch.exe"Memory Card Utility for the Canon i470D
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
NBlackIce Utilityblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Ubladsblads.exe"A Tweak-XP component
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
Nbldbubgbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
XBLFblf.exe"Added by the DELBOT-M WORM!"
Ublinkxblinkx.exe"Blinkx Desktop ""Smart Folders"" software"
NBlitzz BWI715WLANmon.exeBlitzz Technology BWI715 Wireless PC modem connection monitor
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
UBlockAdsblads.exe"A Tweak-XP component
XBlockCheckerBlock-checker.exe"BlockChecker adware"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockKeeperBlockKeeper.exe"BlockKeeper rogue security software - not recommended
XBlockProtector.exeBlockProtector.exe"BlockProtector rogue security software - not recommended
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
NBlockTrackerBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
XBlockWatcherBlockWatcher.exe"BlockWatcher rogue security software - not recommended
UBLOG"rundll32.exe [path] BatLogEx.DLLStartBattLog"
Ublsloaderblsloader.exe"BellSouth ISP Internet Tools"
Xblssblss.exe"Added by the BLARUL TROJAN!"
NBLSTAPPblstapp.exePuts access to Creative's BlasterControl in the System Tray
NBlubsterBlubster.exe"Related to Blubster Music sharing service"
UBlue Frogbluefrog.exe"Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
?BlueLight_uoltrayexec.exe"Related to BlueLight Internet. What does it do and is it required?"
UBlueSoleilBLUESO~1.EXE"BlueSoleil Bluetooth wireless manager from IVT Corporation"
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
UBluetooth Connection AssistantLBTWiz.exe"Bluetooth connection manager for Logitech based bluetooth wireless products"
?Bluetooth HCI Monitor"RunDll32 HCIMNTR.DLLRunCheckHCIMode"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xbmbm.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBmanBMan1.exeAbcsearch.com/DealHelper adware variant
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
NBMMLREFBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
NBMMLREF.EXEBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBMNbm.exe"Part of VirtualPCGuard
XBMNstrpmon.exe"Part of CleanPCTool
XBMNdcmon.exe"SystemDoctor rogue security software - not recommended
UBMO MasterCard WalletEWALLET.EXE"The wallet conveniently stores billing
XBmonqbmonq.exe"Added by the CLICKER.HZ TROJAN!"
NBMupdateBMupdate.exe"Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example
Xbmwbmw.exe"Added by the AGOBOT.BBV BACKDOOR!"
Xbmzbmz.exe"180Search adware"
XBndt32Bndt32.exe"Added by the LACON WORM!"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
Xboat32boat32.exe"Added by a variant of the RBOT WORM!"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
YBOC-412BOC412.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.12"
YBOC-420BOC420.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.20"
YBOC-421BOC421.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.21"
YBOC-422BOC422.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.22"
YBOC-423BOC423.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.23"
YBOC-424BOC424.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.24"
YBOC-425BOC425.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.25"
YBOC-426BOC426.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.26"
YBOC-427BOC427.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.27"
YBOCleanautostartBoclean.exe"NSClean's BOClean anti-trojan software"
UBOINC Managerboincmgr.exe"BOINC manager - ""controls the use of your computer's disk
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
Xbolenjabolenja.exe"Added by the WANTVI.BF TROJAN!"
Xbolenjxbolenjx.exe"Added by the ELDYCOW.O TROJAN!"
Xboler.exesyser.exe"Added by the RBOT-AYS WORM!"
UbombshelBOMB32.EXEPart of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
XBonzi Buddy??"Bonzi Buddy adware - see here for removal instructions"
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
Xbooboo.exe"Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
UBookmarkbookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
UBookmark.exebookmark.exe"System Tray access to Power Favorites by Desksware - which ""is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer
NBookmarkCentralBMLauncher.exe"Bookmark Express - "offers a more flexible way to manage Web site bookmarks
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xbootboot.exe"Added by the PUPPET-A TROJAN! Located in the %System%"
UBootBoot.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
XBoot Checkbootchk.exe"Added by the DELBOT-AB WORM!"
XBoot Clientbootcli.exe"Added by the IRCBOT-ACF BACKDOOR!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot Kbootk.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot ManagerNjgal.exe"Added by the KILO TROJAN!"
XBoot Managerbootmng.exe"Added by a variant of the SPYBOT WORM!"
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootCTRLbootctrl.exeAdded by an unidentified WORM or TROJAN!
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
Xbootpd.exebootpd.exe"Added by the AGENT-DT TROJAN!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootStatusBOOTST~1.EXE"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it
UBootWarnBootWarn.exe"From here: ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBortMedViruspgs.exe"BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
Uborzoiblg.exe"Borzoi surveillance software. Uninstall this software unless you put it there yourself"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
?BostonBoston.exe"Part of the Boston Acoustics USB speaker systems. What does it do and is it required?"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
Ubpcpost.exebpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XBPCV2BPCV2.exe"BroadcastPC adware"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
UBPKbpk.exe"Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
UBQTray.exeBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
XBrasilBrasil.exe"Added by the OPASERV.E WORM!"
XBrasilBRASIL.PIF"Added by the OPASERV.E WORM!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
Xbrastkbrastk.exe"Added by the DORF-BV TROJAN!"
XBrave-SentryBraveSentry.exe"BraveSentry rogue security software - not recommended
XBraveSentryBraveSentry.exe"BraveSentry rogue security software - not recommended
Xbraviaxbraviax.exe"Added by the FAKEALER.LE TROJAN!"
XBrcttrdb.exe"Detected by Kaspersky as the PURITYSCAN.Y TROJAN!"
UBreak_ReminderBREAK REMINDER.exe"Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBregbcre.exe"BroadcastPC adware variant"
XBregbptre.exe"BroadcastPC adware variant"
XBregbreg.exe"BroadcastPC adware"
XBridge"rundll32.exe [path] Bridge.dllLoad"
YBrindys BriTrayBRITRAY.EXE"Main process for the following applications: GEDEX
UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
Ubroadband medicmatcli.exe"NTL's Broadband Medic. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBroadband Wizardbbwiz.exe"Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs"
NBroadCamRunbroadCam.exe"BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
UBroadcom Wireless Manager UIbcmntray.exe"Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-SpizaetusnorBtok.exe"Added by the RONTOKBRO.B WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
XBron-Spizaetuseksplorasi.exe"Added by the RONTOKBRO.J WORM!"
XBron-SpizaetusElnorB.exe"Added by the RONTOKBRO.D WORM!"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
XBron-SpizaetusRakyatKelaparan.exe"Added by the BRONTOK-J or BRONTOK-L WORMS!"
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBRoNToKBRoNToK.exe"Added by the BRONTOK-CG WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Xbrowsermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowsers_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserdeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowser aidbrowseraid.exe"BrowserAid/BrowserPal foistware"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
YBrowser Hijack Blasterbhblaster.exe"Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard"
UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
XBrowser Paladblck.exe"BrowserAid/BrowserPal foistware"
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
XBrO_AcTBrO-AcT.exe"Added by the SILLYFDC-D WORM!"
Xbrwdiag[path to worm]"Added by the STRATIO-BN WORM!"
XBS Mediaplayerbsplyr.exe"Added by the RBOT-OU WORM!"
NBS Playerbsplayer.exe"BSplayer - A video player used to play avi
NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
?BsMntBsMnt.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Nbsplayerbsplayer.exe"BSplayer - a video player used to play avi
XBsRteMemoteXZZ.exe"Added by the AUTORUN-AJU WORM!"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBsx3"RunDLL32.EXE bs3.dllDllRun"
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XBT00003*abcdefg23.exe"Added by the VB-VT TROJAN where * = 5
XBT00003*hiklmnop27.exe"Added by the VB-VT TROJAN where * = 2
Ubtbb_wcm_McciTrayAppMcciTrayApp.exe"System tray access to Motive's Broadband 2.0 configuration and repair utility"
UBtcMaestroKMaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
Nbtdnabtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
Nbtdna.exebtdna.exe"""BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download
?btinstbtinst.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
?BTSETBOOTKEYBTSetBootKey.exe"Related to a USB Bluetooth adaptor. What does it do and is it required?"
UBtStartbtstart.exe"Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software"
UBTTrayBTTray.exe"System tray icon which shows the status of a Bluetooth wireless module (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Also allows access to explore bluetooth places
YBTUSRBDGBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
YBTUSRBDGFBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
XBTVbtv.exe"BroadcastPC adware"
XBtvCbtvclean.exe"BroadcastPC adware"
YBubbleBubble.exe"Part of Windows SteadyState
NBuddyizerBuddyizer.exePart of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
NBudgetSipBudgetSip.exe"BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
YBufferZoneCLIENTGUI.EXE"BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
NBug EliminatorBug_Elim.exe"Bug Eliminator - ""performs a complete health check on your computer safely
XBugsDestroyerSysRep.exe"BugsDestroyer rogue system error and cleaning utility - not recommended
Ubugwatcher servicebugwatcher.exe"
NBuildBUbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XBuildLabwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XBuildLabslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
Xbulkbulk.exe"Added by the AGOBOT-ACR WORM!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
YBullGuardmgui.exe"Part of Bullguard antivirus"
YBullGuardBullGuard.exe"Part of BullGuard antivirus"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XBullsEyebargains.exe"BargainBuddy adware"
XBullsEye Networkbargains.exe"BargainBuddy adware"
?BullsEye TrackerBeTrack.exeBullseye - intelligent research assistant
XBunxbeagle.exe"Added by the LEBREAT-E WORM!"
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
Xburitosburitos.exeIdentified as a variant of the Downloader.FraudLoad.C malware
NBurnQuick QueueBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
UButton Serverbttnserv.exe"Found on a Compaq PC
NButtonKeyButtonKey.exe"CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut"
NBuzmeBmui.exe"Buzme by RingCentral
UBuzMeRCUI.exe"Display Client for the BuzMe Internet Call Waiting Service"
UBuzof.exebuzof.exe"Buzof from Basta Computing "enables you to automatically answer
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
Nbwprnmon.exebwprnmon.exe"FaxServe network fax software"
Xbxproxybxproxy.exe"Added by the BXPROXY TROJAN!"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
Xbxsx5"RunDLL32.EXE bsx5.dllDllRun"
Xbxxs5"RunDLL32.EXE bxxs5.dlldllrun"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
UBySoft FreeRAMFreeRAM.exe"""Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status
XByteDefenderByteDefender.exe"ByteDefender rogue security software - not recommended
?BZEnvironmentVariableCollectorBZEnvironmentVariableCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
?BZUtilizationCollectorBZUtilizationCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
NC-Media MixerMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
UC2KCYB2K.EXECYBE