| X | igamatu | atecaca.exe | "Added by the IRCBOT.R WORM!"
|
| U | InstallBuddy | Ibtna.exe | "InstallBuddy - automatically translates and installs your desktop documents |
| X | InternalSystray | Kazza.exe | "Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable |
| U | Internet Download Accelerator | ida.exe | "Internet Download Accelerator download manager"
|
| X | Internet Firewall Layer | tsqla.exe | "Added by a variant of the SPYBOT WORM!"
|
| N | Introducing Media Manager | SPLASHA.EXE | "MS Media Manager tour. Not required"
|
| Y | ISLP2STA | ISLP2STA.EXE | A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
|
| X | isxa | isxa.exe | "Added by the SMALL-EIV TROJAN!"
|
| X | iTunesAgent | ita.exe | "Added by the TACTSLAY.U TROJAN!"
|
| X | Java Runtime Value | runjava.exe | "Added by the RBOT-DDJ WORM!"
|
| X | JavaVM | java.exe | "Added by the MYDOOM.M WORM and variants! Note - not to be confused with the valid Windows ""java.exe"" which is located in %System% as this is located in %Windir%"
|
| X | javawsa.exe | javawsa.exe | "Added by the BANK-Y TROJAN!"
|
| N | KAZAA | kazaa.exe | "KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it"
|
| X | Kazaa lptt01 | kazaa.exe | "RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
|
| X | Kazaa ml097e | kazaa.exe | "RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
|
| X | lcvga | lcvga.exe | "Added by the HOSTOL-A TROJAN!"
|
| X | Lisa | Lisa.exe | "Added by the SCOM-D premium rate adult content dialler"
|
| X | load | KHATRA.exe | "Added by the ORBINA-A WORM!"
|
| X | LOAD32 | Lorena.exe | "Added by the MAPSON.C WORM!"
|
| X | load32 | 1111a.exe | "Added by the DUMARU.AH WORM!"
|
| X | load32 | netda.exe | "Added by the NIBU.E TROJAN!"
|
| X | load32 | winldra.exe | "Added by the NIBU.J BACKDOOR or DUMARU-BI TROJAN! Note - also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this keylogger"
|
| X | Login | lala.exe | "Added by the BUGSPR-A TROJAN!"
|
| X | LoveHebeA | vistaAA.exe | "Added by the LOZAVITA TROJAN!"
|
| X | LSA | lsa.exe | "Added by the SDBOT-YV WORM!"
|
| U | LWBKEYBOARD | KbdAp32A.exe | Keyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | LWBMOUSE | MOUSE32A.EXE | Mouse utility for a Lenovo brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | MachineTest | CMagesta.exe | "Added by the SDBOT-NE WORM!"
|
| N | MadExe | LaunchRA.exe | "Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell |
| X | Mapiyasha | Mapiyasha.exe | "Added by the SILLYFDC-DM WORM!"
|
| N | MECA | Meca.exe | "Meca cross-platform communications technology |
| X | Media Player | media.exe | "Added by the FLDMEDIA-A TROJAN!"
|
| X | Microsoft | winampaa.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft | symtea.exe | "Added by the SPYBOT.AMTE WORM!"
|
| X | Microsoft Client/Server Runtime Server Subsystem | csrssa.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Datalog Application | msdata.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft DLL | fumeta.exe | "Added by the RBOT-AUG WORM!"
|
| X | Microsoft Hyptertext Helper | mshtha.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Machine | winjava.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Machine | updata.exe | "Added by the RBOT-DJ WORM!"
|
| X | Microsoft Nvidia Video | nvidia.exe | "Added by a variant of the SDBOT WORM!"
|
| N | Microsoft Office | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Office quick launch | OSA.exe | "Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| N | Microsoft Office Startup | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft quick launch | OSA.exe | "Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| X | MicroSoft ssas3s1 | SADASDA.exe | "Added by the RBOT.URF WORM!"
|
| X | Microsoft Synchronization Manager | java.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Synchronization Manager | wmedia.exe | "Added by the SDBOT.BFC WORM!"
|
| X | Microsoft System Security Agent | MSTSA.EXE | "Added by the RBOT.CCM WORM!"
|
| X | Microsoft Telecoma Center | tellcoma.exe | "Added by the RBOT-AWX WORM!"
|
| X | Microsoft Update | phqghumea.exe | "Added by the SDBOT.AFO WORM!"
|
| X | Microsoft Update | imchemaoa.exe | "Added by the BANLOAD.KWQ TROJAN!"
|
| X | Microsoft Update 32 | neta.exe | "Added by the RBOT-AMI WORM!"
|
| X | Microsoft Update Win32a | winupdate32a.exe | "Added by the RBOT-LO WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windir32a.exe | "Added by a variant of the SDBOT.BHF WORM!"
|
| X | mmxrun | msosa.exe | Added by an unidentified TROJAN or WORM!
|
| X | monitor1a | monitor1a.exe | "Added by the MSNAGEN-A TROJAN!"
|
| U | Mouse 32A | Mouse32A.exe | Mouse utility. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | Mozila | mozila.exe | "Added by the DELBOT-AJ WORM!"
|
| N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers
|
| X | Mp3 Loader | Sysdata.EXE | "Added by the AVETTE-A VIRUS!"
|
| X | Mr_CoolFace_Game | Emma.exe | "Added by the ROMARIO-A WORM!"
|
| X | Ms Java for Windows NT | msi32java.exe | "Added by the VANEBOT-I WORM!"
|
| X | Ms Java for Windows NT | msjava.exe | "Added by the VANEBOT-E WORM!"
|
| X | MS LARISSA | MS_LARISSA.exe | "Added by the ASSIRAL.B WORM!"
|
| X | MS32DLL | ffqca.exe | "Added by the SDBOT-YD WORM!"
|
| X | msfindosa.exe | msfindosa.exe | "Added by the DOWNLOADER-BS TROJAN!"
|
| X | MS_LARISSA | MS_LARISSA.exe | "Added by the ASSIRAL WORM!"
|
| X | My Kazaa Gold | MyGoldKazaa.exe | "My Kazaa Gold - regarded as a scam by McAfee SiteAdvisor as you're paying for something which available for free elsewhere"
|
| X | Ncao | osoa.exe | "PurityScan adware"
|
| X | NeroUpdate Check | msjava.exe | "Added by the AGOBOT.AMH WORM!"
|
| X | NeroUpdater6.8 | winjava.exe | "Added by the AGOBOT.AMK WORM!"
|
| U | NetManageImport | nmcpdata.exe | "NetManage business software related"
|
| X | Netropa Internet Receiver | Netropa.exe | Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
|
| X | NeuroMedia(IESpeaker) | NeuroMedia.exe | "Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available"
|
| X | nisdisa | nisdisa.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| U | NliaClient | Netpia.exe | "Netpia NLIA System - ""In the existing Internet address system |
| X | NordBull | msa.exe | "Added by the DLOADR-CSV TROJAN!"
|
| X | Norton Auto Protect | nava.exe | Added by an unidentified WORM or TROJAN!
|
| X | Norton Updater | lsa.exe | "Added by a variant of the RBOT WORM!"
|
| X | Notn | wtta.exe | "PurityScan adware"
|
| X | novsvida.exe | novsvida.exe | "GlobalAccess dialer"
|
| X | nsdlua | nsdlua.exe | All-In-One Telcom - adult content dialler
|
| X | NTSF MICROSOFT SYSTEM | marya.exe | "Added by the RBOT-AXY WORM!"
|
| X | nwiz | KHATRA.exe | "Added by the ORBINA-A WORM!"
|
| N | Office Startup | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| U | OFFICEKB | kbdap32a.EXE | "Keyboard utility for a Micro Innovations brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard"
|
| X | OneMoreKey | xpa.exe | "XP Antivirus rogue security software - not recommended"
|
| X | p2snetis | comippwa.exe | "Added by the SPAMTOO-AL TROJAN!"
|
| U | pamela.exe | pamela.exe | "Pamela is a plug-in or add-on that adds features to Skype peer to peer voice service"
|
| X | Pantera | pantera.exe | "Added by the SDBOT.AYN WORM!"
|
| X | PC-Config32 | corona.exe | "Added by the CORONEX.A WORM!"
|
| U | PCRecSA | PCRecSA.exe | "Part of the IBM/XPoint Rapid Restore backup utility. If you choose |
| U | pdfFactory Dispatcher v1 | fppdis1a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Dispatcher v2 | fppdis2a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Pro Dispatcher v3 | fppdis3a.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| X | pointmania | pointmania.exe | "PointMania adware. File located in %Program Files%\pointmania"
|
| X | Popup Blocker System326a Monitoring | PopUpBlocker6a.exe | "Added by the RBOT.AUH WORM!"
|
| U | PP Gamma | ppgamma.exe | "Profile Prism software that allows monitor calibration and can generate ICC profiles for digital cameras"
|
| ? | Primsta | Primsta.exe | "Linksys Wireless CompactFlash Card driver related. Is it required?"
|
| U | PRISMSTA.EXE | PRISMSTA.EXE | Creates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
|
| X | Purgatory | Purga.exe | "Added by the PURGORY-B WORM!"
|
| ? | Queensla | Queensla.exe | "??"
|
| X | Rcsh | weaa.exe | "PurityScan adware"
|
| X | Registry Checkup System326a Monitor | Winregs326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Registry Value Name Start | MsPMSPSa.exe | "Added by a variant of the SDBOT WORM!"
|
| X | restorer32_a | restorer32_a.exe | "Added by the AGENT.CQQB TROJAN!"
|
| X | restorer64_a | restorer64_a.exe | "Added by the DLDR-BY TROJAN!"
|
| X | RosTika | RosTika.exe | "Added by the BRONTOK-BU WORM!"
|
| X | rpcda Win32 | rpcda.exe | "Added by the RBOT-AEE WORM!"
|
| X | run | mexica.exe | "Added by the AUTORUN.AEV WORM!"
|
| N | run= | fmedia.exe | FMedia FaxWorks related - can be run manually
|
| X | runner1 | tsitra.exe | "Added by the AGENT.ABFQ TROJAN!"
|
| X | Sakora | Sakora.exe | "Added by the GOWELES.A TROJAN!"
|
| X | secure socket layer | wins32a.exe | "Added by an IRCBOT TROJAN!"
|
| X | SeekmoSA | SeekmoSA.exe | "180Solutions.Seekmo adware variant - also see here"
|
| U | Sensiva | Sensiva.exe | "Symbol Commander makes the use of your PC |
| X | Services Controller | lsassa.exe | Added by the CIADOOR.122 VIRUS!
|
| X | Session Manager Subsystem | smssa.exe | "Added by the RBOT-AGS WORM!"
|
| X | sfita | sfita.exe | "Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware"
|
| N | Shareaza | Shareaza.exe | "Shareaza P2P client"
|
| U | Shareaza | bindata.exe | "Shareaza P2P client related"
|
| X | ShellN | isca.exe | "Added by the IBILL.Z TROJAN!"
|
| U | SIAPRO6 | sia.exe | "Steganos Internet Anonym privacy software"
|
| N | SigmatelSysTrayApp | stsystra.exe | System tray program for the Sigmatel Audio sound card. Often found on Dell computers
|
| N | Simplify Media | SimplifyMedia.exe | "Simplify Media media manager - ""enjoy songs from home while at work or from any WiFi location. Explore friends' music while they are online"""
|
| X | Skra | Skra.exe | Identified as a variant of the TrojanDownloader.Matcash malware
|
| U | sma | sma.exe | "SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| N | Smart Type Assistant | sta.exe | "Smart Type Assistant - a complex typing automation tool |
| ? | Smcsta.exe | Smcsta.exe | "SMC Networks wireless PCI card driver. Is it required?"
|
| X | Social Security Agency | rpcxsocsa.exe | "Added by a variant of the RBOT WORM!"
|
| ? | Soot | rcea.exe | "??"
|
| N | Spellex Anywhere | sa.exe | "Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used"
|
| ? | SprintPort | SprintPortA.exe | "Novatel wireless modem related. What does it do and is it required?"
|
| X | SpywareKilla | SpywareKilla.exe | "SpywareKilla spyware remover - not recommended |
| X | startkey | Mysia.exe | Added by the CEP TROJAN!
|
| X | statloads | pgjd83sa.exe | "Added by the SDBOT-UM WORM!"
|
| U | StayAlive | sa.exe | "StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen |
| U | STOPzilla | Stopzilla.exe | "StopZilla! - pop-up killer"
|
| N | Surveysa | surveysa.exe | "Found on Sony laptops |
| X | svcdata.exe | svcdata.exe | "Added by the SPYBOT.ZIF WORM!"
|
| X | svchosta | svchosta.exe | "Added by the SNIFFER-I TROJAN!"
|
| X | switp | switpa.exe | "OfferAgent adware"
|
| X | Sygate Peral Firewall | Syga.exe | "Added by the RBOT-AQK WORM!"
|
| X | Sygate Personal Firewall | Syga.exe | "Added by the RBOT-AQD WORM!"
|
| U | SymKeepAlive | CKA.exe | "Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive"
|
| X | Synchronization Agent | mobsynca.exe | "Added by the RANDEX-E WORM!"
|
| X | Sysqq | weiba.exe | "Added by the DELF-CFX TROJAN!"
|
| X | System | Atira.exe | "Added by the KOTIRA VIRUS!"
|
| X | System Database administration | systemDA.exe | "Added by the DERDERO.B WORM!"
|
| N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
|
| X | System Services | svcsenes32a.exe | "Added by the RBOT-AFG WORM!"
|
| X | system updata | updata.exe | "Added by the LINEAGE-C TROJAN!"
|
| X | System Update Service | wmiprvsa.exe | "Added by the AGOBOT-RG TROJAN!"
|
| X | SystemBoot | Mshta.exe ...filename.hta | Adult content dialler
|
| X | SystemMgr | Ir32_a.exe | "Added by the MAGANIA-OU TROJAN!"
|
| X | SystemMigration | WinMedia.exe | "Added by the KELVIR.EI WORM!"
|
| X | Systemtra | Systra.exe | "Added by the LOVGATE-W WORM!"
|
| X | Systes | jrdtifkkxbbsa.exe | "Added by the RBOT-ADC WORM!"
|
| U | SysW8 | csta.exe | "Clean Space internet evidence eliminator"
|
| X | T2W | Memoria.exe | "Added by the DROPPER.CYG TROJAN!"
|
| U | TapiTNA | TapiTNA.exe | "Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys"
|
| X | Taskman | KHATRA.exe | "Added by the AUTORUN-AKR WORM!"
|
| X | Taskmon driver | winampa.exe | "Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
|
| Y | tcactive | tca.exe | "Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage"
|
| X | Tdrb | ompa.exe | "PurityScan adware"
|
| ? | Tesla | TESLA.EXE | "??"
|
| X | TrustNinja | TrustNinja.exe | "TrustNinja rogue security software - not recommended |
| X | ttaa | tata.exe | "Added by the LINEAGE-T TROJAN!"
|
| X | twhe | wbta.exe | "PurityScan adware"
|
| Y | umxldra | umxldra.exe | "User mode executive module DLL loader - part of Tiny Personal Firewall V4"
|
| X | UpData | wupdata.exe | "Added by the IRCBOT-AA TROJAN!"
|
| X | UpdateMedia | UpdateMedia.exe | "MediaUpdate foistware"
|
| U | Upromise Update | UpromiseUa.exe | "Updater for the Upromise college savings program"
|
| X | USA | usa.exe | "USAntiSpy rogue security software - not recommended |
| Y | USRpdA | USRmlnkA.exe | Modem driver files from US Robotics
|
| ? | USRSTA | USRSTA.exe | "Wireless Card controller. What does it do and is it required?"
|
| ? | USRSTA.EXE | USRSTA.EXE | "Wireless Card controller. What does it do and is it required?"
|
| X | Ussi | rwsa.exe | "PurityScan adware"
|
| X | vbwg cute | aaa.exe | "Added by the VB-DZG TROJAN!"
|
| X | Vdat Update | lalaa.exe | "Added by a variant of the RBOT WORM!"
|
| U | VGAUtil | G-VGA.exe | "Gigabyte VGA Utility - access card options (application needs to be run at startup |
| N | Vidalia | Vidalia.exe | "Vidalia is a cross-platform GUI controller for the Tor anonymityn package. Using Vidalia |
| Y | Videora | Videora.exe | "Video Holding personal video downloading program"
|
| U | Virtuele Katja | VKatja.exe | "Virtuele Katja - have an attractive moviestar parade on your Desktop and help you search the Dutch ""Gouden Gids"" business directory too..."
|
| X | Virus Scan | virscana.exe | "Added by an unidentified VIRUS |
| X | VMware User Process | KHATRA.exe | "Added by the AUTOIT.K TROJAN!"
|
| X | vptraya analyzing | vptraya.exe | "Added by the RIZO.A TROJAN!"
|
| X | WebSUpdater | wupda.exe | "Added by the STARTPAGE.C TROJAN!"
|
| X | Win l5oahder | winampa.exe | "Added by a variant of the RBOT WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Win Server Updt | pxckdla.exe | "IEPlugin adware"
|
| X | Win32 LSA Driver | lsa.exe | "Added by the FORBOT-FJ WORM!"
|
| X | Win32 nvc | nvcva.exe | "Added by the RBOT-ABF WORM!"
|
| X | Winamp Media | qmedia.exe | "Added by the DIAZMON-A TROJAN!"
|
| X | Winamp media player | winapa.exe | "Added by an unidentified VIRUS |
| U | Winampa | WINAMPa.exe | "Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Winampa | winampa.exe | "Added by the AGOBOT-GS TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
|
| X | Winampa Agent | WINAMPA.EXE | "Added by the SPYBOT-BR WORM! Note - this is NOT the popular Winamp media player which is normally located in %ProgramFiles%\Winamp. This one is found in %System%"
|
| U | WinampAgent | WINAMPa.exe | "Loads the System Tray icon for the popular Winamp media player - see here. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs. Resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | WinDLL (asdfsa.exe) | "rundll32.exe asdfsa.exe | start" |
| X | Windows Default Server | winampa.exe | "Added by the IRCBOT.AUN WORM! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Windows Gamma Display | wingamma.exe | "Antivirus 2010 rogue security software - not recommended |
| X | Windows Logon Procedure | Svchosta.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Media Player | msa.exe | "Added by the RBOT-SI WORM!"
|
| X | Windows Media Player | mpupdata.exe | "Added by the SDBOT.BBG WORM!"
|
| X | Windows Media Player Service | wmedia.exe | "Added by the RBOT.213504 WORM!"
|
| X | Windows Registry Scan | winmedia.exe | "Added by the SPYBOT.GK WORM!"
|
| X | Windows Relay Service | irfnga.exe | "Added by the DROPPER.ACO TROJAN!"
|
| X | Windows Service Agent | ywgma.exe | "Added by the RBOT.DZT BACKDOOR!"
|
| X | Windows svchost | serviceaaa.exe | "Added by the PUSHBOT.ER WORM!"
|
| X | WINDOWS SYSTEM | beta.exe | "Added by the MYTOB.DF WORM!"
|
| X | WINDOWS SYSTEM | gothica.exe | "Added by the MYTOB.HU WORM!"
|
| X | Windows Update Center | W32RSA.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Workstation | msup32a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windoxs Update Center | W32RfSA.exe | "Added by a variant of the SDBOT WORM!"
|
| X | winla | winla.exe | "Added by the DLOADR-AQL TROJAN!"
|
| X | WinTools | WToolsA.exe | "Wintools adware"
|
| N | WLAN Status Tray Applet | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN
|
| N | WLANSTA.EXE | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN
|
| X | WNSI | rwsa.exe | "PurityScan adware"
|
| Y | WU713STA.EXE | WU713STA.EXE | Blitzz Technology wireless NIC adapter driver
|
| X | xdxqa | dewa.exe | "Added by the SDBOT-YB WORM!"
|
| X | XP Antivirus | xpa.exe | "XP Antivirus rogue security software - not recommended"
|
| X | Xplorer | KHATRA.exe | "Added by the AUTOIT.K TROJAN!"
|
| U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures Screensaver
|
| X | ZangoSA | ZangoSA.exe | "Zango Search Assistant adware"
|
| X | zupacha.exe | zupacha.exe | "Added by the DROPPER-QL TROJAN!"
|
| X | [32 random numbers] | xpa.exe | "XP Antivirus rogue security software - not recommended"
|
| X | [random name] | iexpl0ra.exe | "Added by the ULPM.BD TROJAN!"
|
| X | [random name] | rundl13a.exe | "Added by the GAMPASS-L TROJAN!"
|
| X | [various names] | corrida.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | pizda.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | {29123221-3AF8-488c-85DE-6B3EC59E8074} | netmedia.exe | "NetMedia adware"
|
| X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sxpgknrwva.exe | "Added by the FAKEALERT-AM TROJAN!"
|
| X | {42562052-EE17-4197-82C7-91CB2E4B0666} | sysrswva.exe | "Added by the FAKEALERT-AH TROJAN!"
|