Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Inc.""Machine WorksXaecces.exe
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
Mass""TelechipsUpatch.exe
Y#NAME?ZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
X$sys$cmp$sys$xp.exe"Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
?%cmpmixtitle%%cmpmixstr%"Possibly related to C-Media Mixer Control panel?"
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(Default)Mcafee.exe"Added by the AGENT.AY TROJAN! Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X*Security Centersecctr.exe"Added by the SDBOT.BRO WORM!"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe
X..ABC2007.exe"Added by the DLOADR-ASH TROJAN!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
?.NET configsysmon32.exe"??"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.protectedN/A"Smitfraud variant"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
?00saskdanewlock.exe saskda"Part of Access Manager
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1mrcmgr.exe"Added by the BANKER.RQK TROJAN!"
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1cla1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
U1cla.exe1cla.exe"1 Click & Lock from Softstack.com - ""a system tray security utility you can use to secure your desktop when you step away from your PC. It's secure and very easy-to-use. Just define a password
?1CmailSNETMAIL.EXE"??"
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
X27csrss32.exe"Added by the SLSORVE-D TROJAN!"
X2k6 updatzcrss3.exe"Added by the RBOT-CPD WORM!"
X2Searchmain.exe"2Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
Y3capplnk3capplnk.exeUS Robotics Modem driver
N3cdminic3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3CM Link3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it
Y3Cmlink3CmlinkW.exe"For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information"
?3Com LauncherLauncher.exe"Related to networking products from 3Com Corporation. What does it do and is it required?"
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
X3Dfx AccGFXACC.EXE"Added by the GIBE WORM!"
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
U3qdctl.exe3qdctl.exe"Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
X7X29C2X78Ysyss_.exe"Added by the AGENT-GMS TROJAN!"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@wincms.exe"Added by the RBOT.CBR WORM!"
N@Hoc ToolbarAtHoc.exe"One-click activated browsing toolbar used by various web-sites. See here for more info"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
?AAACLEANAAACLEAN.INF"??"
Xaacmeyfaacmeyf.exe"Added by the AF.20 TROJAN!"
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
?ab EazySchedulerezsched.exe"??"
NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
Xabcdefghabcdefgh.exe"EPJ TROJAN!"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
Uacaaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
Uaca.exeaca.exe"Access Controller - ""a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection
UAcBtnMgr_X63AcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X73AcBtnMgr_X73.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X83AcBtnMgr_X83.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
Uaccacc.exe"Advanced Call Center - ""full-featured yet easy-to-use answering machine software for your voice modem"""
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
YAccelerometerStAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAccessoriesPlusclockplus.exe"Clock Plus
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
Yaccrdsubaccrdsub.exe"ActivIdentity ActivClient - security software from ActivIdentity Corporation which ""enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login"""
UAcctMgrAcctMgr.exe"Norton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
Xaccwizz.exeaccwizz.exe"Added by the RULAND.A WORM!"
Xaccwizzz.exeaccwizzz.exe"Added by the RULAND.A WORM!"
NACDaemonACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
Xacdllib3bcdlmem.exe"Added by the MAILBOT-BA TROJAN!"
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize
?Ace bowsAce bows.exe"??"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
UAcer Assist Launcherlauncher.exe"Acer Assist - program that provides information about new updates or notices from Acer"
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UAcer ePower ManagementePowerTray.exe"Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks. Also appears as the Packard Bell PowerSave power management utility included on some of their notebook models - as Packard Bell is now owned by Acer"
UAcer ePower ManagementePowerTrayLauncher.exeLauncher for the Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
YAcer Launch ToolAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
UAcerGotoAcerGoto.exe"Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
XAceu[random filename]"PurityScan adware"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
YACMONACMON.exe"ASUS Splendid ""is a breathtaking innovation that brings the video viewing experience on PC to the next level. Built into the driver of ASUS graphics cards
UACMonitor_X63ACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X63.exeACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X73ACMonitor_X73.exe"Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
UACMonitor_X83ACMonitor_X83.exe"Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
UACMonitor_X84-X85ACMonitor_X84-X85.exe"Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
XAcontiaconti.exeAdult content dialler
Uacousticacoustic.exe"Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained"
Nacpartagpart11.exeProgram for finding trucks on-line
XAcrobatacrmon32.exe"Added by the SMALL-ECT TROJAN!"
UAcrobat AssistantAcroTray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
XAcrobat Readacroup32.exe"Added by the VANBOT-BQ TROJAN!"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
XAcroreadAcroRD32.exe"Added by the DLOADR-BDK TROJAN! Note - this is not the popular Adobe Reader"
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
?ActionAgentactionagent.exe"""A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client"". Is it required?"
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UACTIVBOARDABoard.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exe"ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
UActMakerActMak25.exe"""ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding
UActMakerActMaker25.exe"ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload"
UACTrayACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
UACUACU.exe"Atheros wireless Client Utility"
UACU_QSBACU.exe"Atheros wireless Client Utility"
UACWLIconACWLIcon.exe"Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
UAd Blockerblocker.exe"Ad Blocker - blocks popups
UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
UAd MuncherAdMunch.exe"Ad Muncher removes adverts
UAd-MuncherADMUNCH.EXE"Ad Muncher removes adverts
UAd-Protectad-protect.exe"Ad-Protect spyware and spam monitoring tool"
UAd-watchAd-watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAD2KClientAD2KClient.exe"Executable for Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAddClassAddClass.exe"CoolWebSearch Addclass parasite variant"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
Yadi CleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
Xadlhidppsncc32.exe"Added by the SLAPER.AI TROJAN!"
XAdmanager ControllerAdManCtl.exe"Adware
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
NAdobe AcrobatREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe AcrobatReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background
XAdobe Reader32Acrord32.exe"Added by the RBOT-BLC WORM! Note - this is not the popular Adobe Reader"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProchkdisk.exe"Added by the RBOT-BDV WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
XAdobe_Readeracrotray.exe"Added by the AGENT-LNS TROJAN! Note that the legitimate Adobe file (if installed) would normally be found in %ProgramFiles%\Adobe%\%ProgramName% (where %ProgramName% is Acrobat 9.0\Acrobat or Acrobat 7.0\Distillr for example) whereas this one is located in %ProgramFiles%\Adobe"
XAdobe_RLXccwap.exe"Added by the BCKDR-RCL TROJAN!"
XAdPopupdcf5678.exe"Added by the AGENT-FZ TROJAN!"
NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
UAdSubtractadsub.exe"AdSubtract blocks ads
Xadtech2005adtech2005.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xadtech2006adtech2006.exe"Detected by Kaspersky as the VB.KC WORM!"
XAdtools ServiceAdTools.exe"Windupdates Adware"
XAdult_ChatAdult_Chat.exeAdult content dialler
XAdult_Chat1Adult_Chat1.exeAdult content dialler
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
XAdwareKiller_schedulesschedules.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdwareProtectorAdwareProtector.exe"Part of rogue security tools
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAELaunchAELaunch.exe"Audio Applications Launcher for the Philips Acoustic Edge soundcard"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
UAEZBProcaptezbp.exe"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
XAHUANACON.EXE"Added by the NACO.A WORM!"
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
XAicatuaa.exe"PurityScan adware"
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAim Quick StartAim.exe"Added by the FORBOT-BB WORM! Note - this is not the popular AOL Instant Messenger utility"
NAim6AOLLaunch.exe"AOL Instant Messenger - start it when you want to use it"
NAimingClickAimingClick.exe"AimingClick from AimingTech. Web searching tool. Available via Start -> Programs"
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xaircityaircity.exe"Related to ""Prutect"" malware from e2Give"
YAirGCFGAirGCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
?AlarmWatcherAlarmWatcher.exe"Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?"
YAlaunchAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
XAlchemAlchem.exe"ClickAlchemy adware"
UAlcmtrALCMTR.EXE"Realtek Azalia Audio - Event Monitor
XAlcmtrMalware Doctor.exe"MalwareDoc rogue security software - not recommended
NAlcoholAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol 120%Alcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcohol.exe AutorunAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAlcoholAutomountaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?Alcom PCL CaptureFMW_PCAP.EXE"??"
Xalcomrg.exealcomrg.exe"Added by the SDBOT-DNT WORM!"
UAlcWzrdALCWZRD.EXE"RealTek AlcWzrd Application
UAlcxMonitorAlcxmntr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
UAlfaClock ClassicAlfaClock.exe"AlfaClock Free Edition from AlfaSoft Research Labs - ""enhances your taskbar clock (tray clock) with fully customizable clock display
UAlfaClock2AlfaClock2.exe"AlfaClock2 from AlfaSoft Research Labs -""enhances your tray clock functionality. Of course
?ALFY AccelleratorAlfyAC~1.exe"??"
Xalgchk.exealgchk.exe"Detected by Kaspersky as the VB.ATE TROJAN!"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
XAll Sea screen saverTaskTray.exe"Free screensaver
NAllerCalcAllerCalc.exe"AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually"
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XALMcsrss32.exe"Added by the ANACON-D VIRUS!"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
Xalt CTRL Shiftet3rd.exe"Added by the SDBOT-RH BACKDOOR!"
XALTER DATA[path] repcale.exe [path] beird.exe"Added by the IRCFLOOD.CD TROJAN! Both files are located in %System%\ccdew"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UALTOOLSAccessL.exe"ALTools family of PC utilities"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAMD PowerNow!GemBack.exe"
Yamd_dc_optamd_dc_opt.exe"
NAmerica Onlineaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAmerica Online *.* Tray Iconaoltray.exe"Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
UAmIcoSinglunAmIcoSinglun.exe"Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
UAModemLockDownModemLockDown.exe"ModemLockDown - allows you to supervise internet access by disabling the modem
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
?AnnotateCheckAnnCheck.exe"Genius Wizard Pen Tablet driver related. Is it required?"
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
UAnti-keylogger checkantikey.exe"Anti-keylogger - protects against keylogger programs monitoring your keystrokes"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Uantidialer.co.ukDialer_Watcher.exe"Dialer_Watcher is an application that allows you to detect dialers on your computer"
XAntimalware Doctor.exeAntimalware Doctor.exe"Antimalware Doctor rogue security software - not recommended
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAOL Companioncompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
?AOLCCACCAgnt.exe"AOL ISP software related
XAolConconfig.com"Added by the TAPLAK WORM!"
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
YAPC UPS StatusDisplay.exe"APC PowerChute® Personal Edition status icon"
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
XAPCProtect.exeAPCProtect.exe"APCProtect rogue security software - not recommended
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
NApplication LauncherApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
Xaqadcup.exeaqadcup.exe"Added by the AGENT.BG WORM!"
YAqua DockAqua Dock.exe"Aqua Dock - 'free program that allows you to have an ""OS X"" style
YArcaCheckArcaCheck.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
Xarcaderockstararcaderockstar32.exe"Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArctosarazerhid.exe"Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
Xargq32csrss_32.exe"Added by the RBOT-CPM WORM!"
XArucer"rundll32 Arucer.dllArucer"
XArucer Dynamic Link Library"rundll32 Arucer.dllArucer"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasc32asc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
Xashcapservirsess.exe"SpySure spyware"
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
?AspireServiceAspireService.exe"Found on Acer laptops
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XASpyCASpyC.exe"AntiSpyCheck rogue spyware remover - not recommended
XAss and tittiesCMD32.EXE"Added by the SDBOT-GG BACKDOOR!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
Xasussvcasussvc.exe"Added by the AGENT-FPB TROJAN!"
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAT-WatchATWatch.exeAnti-Trojan Watch - trojan detector
Uatchkatchk.exe"AMT Status Message from Intel. Users can manage this
UATI 2D ComponentAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
NATI CATALYST System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
XATI Cpanelatiphexx.exe"Added by the AGOBOT-NV WORM!"
UATI Desktop ComponentATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
UATI Launchpadlaunchpd.exe"Convenient way to start all your Multimedia Center applications (DVD
YATI Remote ControlATIRW.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
YATI Remote ControlATIX10.exeATI Remote Wonder™ - PC wireless remote control driver. Required if you use it
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
?Ati2cwxxAti2cwxx.exe"For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it"
XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
NATICCCCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
XAtiCpanelatiphexx.exe"Added by the AGOBOT.IL WORM!"
Xaticpaxx.exeaticpaxx.exe"Added by the RBOT-XP WORM!"
UAtiCwdAtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAti2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32Ati2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UATIMACEMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) component
UATIModeChangeAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
UAtiQiPclAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XATM Controladpn.exe"Added by the MMS.A WORM!"
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
XAtomic-x27Atomic-x27.exe"Added by the KATOMIK-A WORM!"
XAtomic-x27CAtomicpartC.exe"Added by the KATOMIK-A WORM!"
UAtomic.exeAtomic.exe"Atomic Clock Sync - synchronizes your computer's time with the NIST time server"
NAtomicaatomica.exe"Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key"
UAtomicTimeATOMICTIME.EXE"AtomicTime - utility that synchronizes your PC clock to an atomic clock"
UAtomSyncatomsync.exe"AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
UAtrackatrack.exe"New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
XAucompatAucompat.exe"Added by the GEMA TROJAN!"
XAudcntraudcntr.exe"Added by the GEMA TROJAN!"
?AudCtrl"RunDll32 AudCtrl.dll RCMonitor"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
XAudiocntlaudiocntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
NAudioCommanderAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommander ApplicationAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
NAudioDeckADeck.exeADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
Xautochk"rundll32.exe autochk.dll_IWMPEvents@16"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
Uautoclkautoclk.exe"Autoclik is a Windows utility ""that allows you to perform all mouse activity with absolutely no clicking"""
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
Xautoloadcftmon.exe"Added by the SOCKS-E WORM!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
NAutoSpell 5ASWATC32.EXE"AutoSpell - spell checker"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
XauxAudioDeviceaux32.exe"Added by the AIZU WORM!"
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
Xavagent3974chnb8895.exe"AntiVirus ransomware security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
Xavcavmon.exeAdded by an unidentified TROJAN!
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_CCavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG7_EMCavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
Yavgccavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
Yavgcc32avgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVGCtrlAVGCtrl.exe"Part of AntiVir® PersonalEdition Classic antivirus"
Yavgemcavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG_CCavgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVG_EMCAVGEMC.exe"AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
Yavpccavpcc.exe"Kaspersky Labs anti-virus"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
UAwatchAwatch.exe"Diagnosis tool that monitors DSL connections
UAwaySchAwaySch.EXE"Part of the IBM ThinkVantage Productivity Center. ""The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"""
UAWCAWC.exe"Advanced SystemCare from IObit - ""helps protect
UAWMONAd-Watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
Naxcmdaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
Xbabeie"rundll32 cnbabe.dll dllstartup"
NBabylon ClientBabylon.exe"Babylon-Pro is a powerful information tool that instantly provides relevant information
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
UBack2zipBack2zip.exe"Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up"
XBackdoor.NuAgentagent.exe"Added by the AGENT-DP TROJAN!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
NBackpack UDFbpudfmon.exe"Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
Xbackup[path to worm]"Added by the AGOBOT-H WORM!"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackup Servicebackup.svcUnidentified adware
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackup4all OTB AgentB4AOTB.exe"""Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
?BackupNotifybackupnotify.exe"HP Digital Imaging related. What does it do and is it required?"
NBackWebbackweb.exeAutomatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
NbackWeb-8876480backweb-8876480.exe"Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products
NBackworkBackwork.exe"Backwork trojan detector"
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBatsecure2.bat"Added by the ZCREW.C TROJAN!"
NBatchreg1N/A"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBayMgrDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
NBBC AlertsBBC_Alerts.exe"BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
NBBLauncher.exeBBLauncher.exe"BounceBack Professional - back-up software"
Ubcabca.exe"BeClean Agent - registry
UBCDetectbcdetect.exeBcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
?bcmwltrybcmwltry.exe"Broadcom Corporation Wireless Network Tray Applet. Is it required?"
NBCNTbcnt.exe"AWS Weatherbug related. What does it do?"
XBCPCbcpc.exe"BroadcastPC adware variant"
Xbcpc_cbcpc_c.exe"BroadcastPC adware variant"
UBCSSyncBCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
UBCTweakbctweak.exe"BlasterControl for Creative video cards - controls for desktop settings
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
NBCWipeTMbcwipetm.exe"BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task
XBDdc.exe"Added by the RASDOOR-A TROJAN!"
YBDMConBdmcon.exe"BitDefender antivirus"
YBDSwitchAgentbdswitch.exe"Bitdefender 8 antivirus and firewall"
UBeatNik Internet ClockBeatNik.exe"BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
UBelkin Wireless USB UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UBelkin Wireless UtilityBelkinwcui.exe"Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
NBHOCopBHOCop.exe"PC Magazine's
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
?BIOVCIPBIOVCIP.exe"??"
NBitCometBitComet.exe"BitComet P2P client - can be launched from Start -> Programs"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
Nbjcfdcdf.exe"BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
UBJLaunchEXEBJLaunch.exe"Memory Card Utility for the Canon i470D
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
NBlackIce Utilityblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
UBlockAdsblads.exe"A Tweak-XP component
XBlockCheckerBlock-checker.exe"BlockChecker adware"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockKeeperBlockKeeper.exe"BlockKeeper rogue security software - not recommended
XBlockProtector.exeBlockProtector.exe"BlockProtector rogue security software - not recommended
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
NBlockTrackerBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
XBlockWatcherBlockWatcher.exe"BlockWatcher rogue security software - not recommended
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
?BlueLight_uoltrayexec.exe"Related to BlueLight Internet. What does it do and is it required?"
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
UBluetooth Connection AssistantLBTWiz.exe"Bluetooth connection manager for Logitech based bluetooth wireless products"
?Bluetooth HCI Monitor"RunDll32 HCIMNTR.DLLRunCheckHCIMode"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBMNdcmon.exe"SystemDoctor rogue security software - not recommended
UBMO MasterCard WalletEWALLET.EXE"The wallet conveniently stores billing
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
YBOC-412BOC412.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.12"
YBOC-420BOC420.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.20"
YBOC-421BOC421.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.21"
YBOC-422BOC422.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.22"
YBOC-423BOC423.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.23"
YBOC-424BOC424.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.24"
YBOC-425BOC425.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.25"
YBOC-426BOC426.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.26"
YBOC-427BOC427.exe"Comodo BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.27"
YBOCleanautostartBoclean.exe"NSClean's BOClean anti-trojan software"
UBOINC Managerboincmgr.exe"BOINC manager - ""controls the use of your computer's disk
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
NBookmarkCentralBMLauncher.exe"Bookmark Express - "offers a more flexible way to manage Web site bookmarks
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot Checkbootchk.exe"Added by the DELBOT-AB WORM!"
XBoot Clientbootcli.exe"Added by the IRCBOT-ACF BACKDOOR!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootCTRLbootctrl.exeAdded by an unidentified WORM or TROJAN!
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Ubpcpost.exebpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XBPCV2BPCV2.exe"BroadcastPC adware"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
XBrcttrdb.exe"Detected by Kaspersky as the PURITYSCAN.Y TROJAN!"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBregbcre.exe"BroadcastPC adware variant"
Ubroadband medicmatcli.exe"NTL's Broadband Medic. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBroadCamRunbroadCam.exe"BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
UBroadcom Wireless Manager UIbcmntray.exe"Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
YBrowser Hijack Blasterbhblaster.exe"Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard"
UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
XBrowser Paladblck.exe"BrowserAid/BrowserPal foistware"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
XBrO_AcTBrO-AcT.exe"Added by the SILLYFDC-D WORM!"
NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XBT00003*abcdefg23.exe"Added by the VB-VT TROJAN where * = 5
Ubtbb_wcm_McciTrayAppMcciTrayApp.exe"System tray access to Motive's Broadband 2.0 configuration and repair utility"
UBtcMaestroKMaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
XBtvCbtvclean.exe"BroadcastPC adware"
YBufferZoneCLIENTGUI.EXE"BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
Ubugwatcher servicebugwatcher.exe"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
?BullsEye TrackerBeTrack.exeBullseye - intelligent research assistant
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
NBurnQuick QueueBQTray.exe"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility
UBuzMeRCUI.exe"Display Client for the BuzMe Internet Call Waiting Service"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
?BZEnvironmentVariableCollectorBZEnvironmentVariableCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
?BZUtilizationCollectorBZUtilizationCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
UC-Media Echo ControlEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
NC-Media MixerMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
UC2KCYB2K.EXECYBERsitter 2000 or 2001 - anti-adult content filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
Uc32cs2c32cs2.exe"Cyber Sentinel - internet filtering software"
XC7[path to worm]"Added by the MEDIAKILL.A WORM!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
UCA-AMAgentamagent.exe"Unicenter Asset Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery
YCaAvTrayCAVTray.exe"eTrust™ EZ Antivirus system tray application from Computer Associates"
XCabchkCabchk.exe"Added by the GEMA TROJAN!"
XCabchk32Cabchk32.exe"Added by the GEMA TROJAN!"
XCABCInstallCABCInstall.exe"Ignite Technologies (was CABC) content delivery software"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
NCachemanCacheman.exe"Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up"
YCacheMgrCacheMgr.exe"Sophos Antivirus Remote Update"
UCacheSentry ProCacheSentry Pro.exe"""CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
NCACStartercacstart.exeCash A Check - check writing software
UCaddais BackupOnDemandBODMon.exe"Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
UCADScads.exe"Cyber Sentinel - internet filtering software"
UCafeStationCafeStation.exe"""CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations
Ycafwccafw.exe"CA Personal Firewall - part of the CA Internet Security Suite"
NCAgentCAgent.exe"Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents"
XcAgOu[filename].hta"Added by the KAKWORM WORM!"
NCahootWebcardCahootWebcard.exe"""The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details"". Run manually when needed"
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
YCAISafeisafe.exe"Part of Computer Associates eTrust EZ Antivirus"
UCaISSDTcaissdt.exe"Computer Associates Dashboard Tray applet"
NCal Reminder Shortcutcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
Xcalc"rundll32.exe calc.dll_IWMPEvents@0"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
XCALC32CALC32.EXE"Added by the SPYBOT-EC WORM!"
UCalendarCalendar.exe"This entry can be added by PlainSight Desktop Calendar and older versions of Desktop iCalendar from Desksware and the older Calendar 200X - which is no longer supported by or available from the author"
?Calendar 200X Monitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
NCalendar 200X Remindercalendar.exe"Part of Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. Displays reminders for holidays
?Calendar Monitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
UCalendarscopecs.exe"Calendarscope calendar software"
Xcalkcalk.exe"Added by the STARTPA-FH TROJAN!"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
XCall32Call32.exe"Added by the SPAMMIT-H TROJAN!"
YCallBumpingcbpopw.exe"Related to the Gazel 128 PCI ISDN adapter. Required if you use it"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
?calmonitorcalmonitor.exe"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present but it appears to be related to the Calendar 200X Reminder entry - as disabling that entry via the program also disables this one"
?calmonitorcalmonitor"Background task for Calendar 200X by Joel Graffman - which is no longer supported or available from it's author. The exact purpose of this startup entry is unknown at present"
NCamCheckCamCheck.exe"NuCam camera software related"
UCamenoCameno.exe"Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above"
UCamera Assistant Softwaretraybar.exeCamera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
UCamera DetectorCAMDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
UCamera DetectorCamdetect.exe"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
UCamera DetectorDEVDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
?CameraApplicationLauncherCameraApplicationLaunchpadLauncher.exe"Supports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?"
UCameraAssistantCameraAssistant.exe"Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom
NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
?CamMonitorhpqcmon.exe"From HP and related to digital imaging"
YCamWizardCamWizrd.exeLaunches the Logitech Camera Wizard on the first reboot after installing versions of Logitech QuickCam webcam software
NCanadaCanada.exe"Known to be a dialler - but is it maliscous or clean?"
UCanarycanary-std.exe"Canary keystroke logger/monitoring program - remove unless you installed it yourself!"
Xcandycommand32.exe"Added by the RBOT-LV WORM!"
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
UCANoeCANoe32.exe"CANoe from Vector Informatik. Development and test tool for Engine Control Units (ECU) based upon the CAN
UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
UCanonMyPrinterBJMyPrt.exePrinter software for Canon Bubblejet printers
UCanonSolutionMenuCNSLMAIN.exe"
?CAP3ONCAP3ONN.EXE"Canon driver
Ycapfasemcapfasem.exe"CA Personal Firewall - part of the CA Internet Security Suite"
NCapfaxcapfax.exe"PhoneTools fax software"
Ucapfupgradecapfupgrade.exe"CA Personal Firewall - part of the CA Internet Security Suite"
UCAPingCAPing.exeCitibank Citianywhere software
YCaponCapon.exeCanon printer driver
YCaponCaponn.exeCanon printer driver
XCaptcha7rundll captcha.dll"Added by the TINY.WRE TROJAN!"
XCaptionMgr32crssr.exe"Added by the ZAR.A WORM!"
Xcapturecapture.exe"Added by the THEEF-B TROJAN!"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
UCaptureAssistantCaptureAssistant.exe"Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text
NCaptureBatCapture.exe"!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways
NCarbonite BackupCarboniteUI.exe"""Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
XCare20Care20.exe"TopMoxie adware"
UCare2GTUCare2GTU.exe"Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
Xcartao[path to file]"Added by the DLOADER-QD TROJAN!"
Xcartaoconflicted.exe"Added by the DADOBRA-DV TROJAN!"
Xcartaokilling.exe"Added by the DLOADER-QN TROJAN!"
Xcartaocartao.exe"Added by the BANKER-FA TROJAN!"
XCAS Clientcasclient.exe"CasinoClient adware"
XCas2Stubcas2stub.exe"CasinoClient adware"
UCasAgntCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
Xcaseyvideocaseyvideo.exeMalware causing adult content popups
Xcaseyvideo[*] [* = digit]caseyvideo[*].exe [* = digit]Malware causing adult content popups
XCashBackcashback.exe"Part of eXact Advertising Software
XCashFiestaCashfiesta.exe"CASHFIESTA.A pay-per-surf adware"
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XCasino Royalejamesbond.exe"Added by the RBOT-FZO WORM!"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
XCasStubcasstub.exe"Added by the CASS-A TROJAN!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
YCAVRIDCAVRID.exe"eTrust™ EZ Antivirus Real Time Infection Report from Computer Associates"
YCAVSCAVS.exe"Cheyenne (now eTrust) antivirus"
XCAZNOVASCAZNOVAS.exe"Added by the CAZNO TROJAN!"
XCBACK.EXECBACK.EXE"Added by the PENTA-A TROJAN!"
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
UCBWAttnCBWAttn.exe"Required for Bitware to answer incoming faxes
UCBWHostCBWHost.exe"Required for Bitware to answer incoming faxes
?CBWUserCBWDial.exe"Associated with Bitware that integrates fax
XCC2KUIcomet.exe"Comet Cursor adware"
Xccagent.execcagent.exe"Control Center and Control Components rogue security software - not recommended
XCcaoregedit.exe"Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a ""mduu"" subfolder
YccAppccApp.exe"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XccAppWMADZ.EXE"Added by the RBOT-LJ WORM!"
XccApp.EXE"Added by the RBOT-LJ WORM!"
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccAppexample.exe"TwoSeven spyware"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccApproutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XccAppsN/A"Added by the KANGAROO-A TROJAN!"
XccAppsccApps.exe"Added by the KANGAROO-B WORM!"
XccctpHistoryJMTi.exe"Added by the GANBATE.A WORM!"
UCCD ManagerDDS.EXE"Project Labs Century CD manager for their CD/DVD storage device"
NCcdecode"rundll32.exe streamci StreamingDeviceSetup"
XccDHCP32ccDHCP32.exe"Added by the AGOBOT-HJ WORM!"
YCCDoctorLogonTestingccdoctor.exe"Checks your system to make sure it's configured properly for running IBM Rational ClearCase
YccenterCCenter.exe"RAV AntiVirus"
YCcEvtMgrccEvtMgr.exe"Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
XccEvtMrg.execcEvtMrg.exe"Added by the RBOT.GZ WORM!"
XccExecutebootcfg1.exe"Added by the NEMSI-B VIRUS!"
XccHelpccHelp.hta"Searchq adware"
UCCleanerCCleaner.exe"CCleaner from Piriform Ltd. - ""is a freeware system optimization
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XccpAppslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UccProxyCCPROXY.EXE"Part of Norton Internet Security
XccPrxy.execcPrxy.exe"Added by the SHIPUP-H WORM!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
YccRegVfyccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
Xccrssmsdtc.exe"Added by the STAP-C WORM!"
YccSetMgrccSetMgr.exe"Part of Norton AntiVirus 2004. What does it do?"
XccStartccStart.exe"Added by the AGOBOT-IR WORM!"
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
Xccsvit.execcsvit.exe"Added by the STARTPA-HP TROJAN!"
Ucctraycctray.exe"Part of CA Internet Security Suite"
XccUpdateccUpdate.exe"Added by the AGOBOT.YS WORM!"
UccUpdMgrccUpdMgr.exe"In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!"
UCCUTRAYICONCCU_TrayIcon.exe"Related to Traybar Launcher from Intel Corporation belonging to Intel® Viiv®"
UccWasheraolwasher.exe"Webroot Cache & Cookie Washer - cleaning browser tracks
UCCWC7aac.exe"Moleculesoft Cache
UCCWC7Iidxl.exe"Moleculesoft Cache
UCCWC7sstealth.exe"Moleculesoft Cache
YCCWinTraywintmr.exe"System Tray access to Child Control parental control software by Salfield"
NCD Storage Mastercdstorager.exe"CD Storage Master - a program designed to catalog CD information
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
Xcd1cd1.exePremium rate adult content dialler
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
XCdcompatCdcompat.exe"Added by the GEMA TROJAN!"
Xcddrv32cddrv32.exe"Added by a variant of the CRYPTER.C TROJAN!"
NCDInterceptorcdi.exeCD indexer for measuring the speed of CD players
Ycdloadercdloader2.exe"From MagicJack - ""A softphone device that allows you to attach an analog phone into the PC so you can have a traditional-style phone system in your house without any monthly charge"""
UCDLoadersb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xcdmmslpoklpllsm.exe"Added by the TEDIJINI-A TROJAN!"
XCdnCtrcdnup.exe"CNNIC Update pest"
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
Xcdoosoftolhrwef.exe"Added by the AUTORUN-AAG WORM!"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XCdrom Controllercdromcntrl.exe"Added by the BATTRY-A TROJAN!"
Xcdscds.exe"Added by the SPYMON TROJAN!"
XCDSpeed.exeCDSpeed.exe"Added by the IRCBOT.AEX BACKDOOR!"
NCDTrayCDTray.exe"On HP PCs
UCDVAgentCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
UCeEKEYCeEKey.exeHot Key utility included on Toshiba Satellite laptops
UCeEPOWERcepmtray.exe"Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed
?CeicCeic.exe"??"
XCekirge[path to worm]"Added by the KERGEZ.A WORM!"
Xcenter[random name]32.exe"Added by the BOFRA.A WORM!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
?CEPAwsot.exe"??"
XCerbDivXx.exe"Added by the KEYLOG-LV TROJAN!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
UCertRegcertreg.exe"Related to Gemplus Card Reader"
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
Ycerttoolcerttool.exe"Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk)
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
XCEventMgrCell.exe"Added by the BIFROSE-AK TROJAN!"
NCFDCFD.exe"BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
NcfFncEnabler.execfFncEnabler.exe"Toshiba ""Config Free"" wireless network manager on their range of laptops"
Xcfgboostcfgboot.exeAdded by an unidentified WORM or TROJAN!
Ycfgintprcfgintpr.exe"Configuration Interpreter - part of Tiny Personal Firewall V4"
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xcfgmgr52"RunDLL32.EXE cfgmgr52.dllDllRun"
Ncfgwizcfgwiz.exe"Introduced with Norton Anti-Virus 2002
UCFi ShellToys Utility ManagerCFiShlMan.exe"Manager for CFi ShellToys from Cool Focus International Ltd - which ""puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders
?cFosDNTcFosDNT.exe"cFos DSL Modem driver related. What does it do and is it required?"
?cFosInst_Checkcfosinst.exe"cFos DSL Modem driver related. What does it do and is it required?"
UcFosSpeedcFosSpeed.exe"cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly"
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
XCftmon32afd.exe"Added by the AUTORUN-AUB WORM! The ""afd.exe"" file is located in %Windir%"
XCftmon32afd.exe"Added by the SCAR.AYWK TROJAN! The ""afd.exe"" file is located in %AppData%"
Xcfycfy.exe"Surfenhance.com SearchForIt adware variant"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
UCGServercgserver.exe"Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs"
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XCgywincgywin32.exe"Added by the RBOT-AEI WORM!"
UChamClockChamClock.exe"Chameleon Clock - system tray clock replacement"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
?ChangeLineschngline.exe"??"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YCharter High-Speed Security Suitefspex.exe"Charter High-Speed Security Suite - security software in collaboration with F-Secure"
XChat loginchatlogin.exe"Added by the ANTINNY.F WORM!"
NChatangoChatango.exe"Chatango - ""allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions
UChatStatChatStat.exe"ChatStat from ChatStat Technologies
NChcenterchcenter.exe"IMSI HiJaak - ""the easiest way to convert
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Xchcp.exechcp.exe"Added by the SDBOT.BMH BACKDOOR!"
Xche32che.ocx.vbs"Added by the ADENU-B VIRUS!"
XCheatleGigaByte.exe"Added by the SHODI.B VIRUS!"
Ucheatmonitorstart.exe"CheatMonitor surveillance software. Uninstall this software unless you put it there yourself"
XCheckCheck.exe"Added by the VB-DRN WORM!"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
UCheck&GetCheck&Get.exe"Check&Get from ActiveURLs. Manages your browser bookmarks and favorites. Monitors Web sites for changes and updates
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
UCheckDialerChkDial.exe"Added by the CheckDialer modem connection monitoring tool"
XCheckdiskmscas.exe"Added by the VAGON-A TROJAN!"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
UCheckItToolBox.exe"CheckIt Toolbox from
UCheckIt 86CheckIt86.exe"CheckIt 86 popup blocker"
YCheckMsgPlus"MsgPlusH.dll VerifyInstallation"
Xcheckrunelite***32.exe [* = random char]"EliteBar adware"
Xcheckrunelitelsj32.exe"Added by the MULTIDR-ER TROJAN!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
?checktimect.exe"Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?"
YCheckVCRIOMagic.exe"Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UCherryKeyManKeyMan.exe"Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys"
XchiCkiechiCkie.exe"Added by the CHIKO WORM!"
UChicoSyswebtmr.exe"Child Control parental control software"
UChikkaDefaultChikkaLauncher.exe"Chikka PC text messanger and IM client"
UChilyClientChilyClient.exe"Chily Employee Activity Monitoring surveillance software. Uninstall this software unless you put it there yourself"
Xchina11msnCHINA11MSN.EXE"Added by the ENVID.O WORM!"
XChinagnqvasdd.exe"Added by the SDBOT-SE WORM!"
UChineseStarcstar.exeChinese language support software
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
XCHK Diskerchkdsker.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCHK NTchkntf.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NCHKADMINCHKADMIN.EXE"Compaq Network Management System. When running
XChkDiskchk_disk.exeAdded by an unidentified WORM or TROJAN!
Xchkdrviemon.exe"Detected by Symantec as the ADCLICKER TROJAN!"
Xchkdskautoexec.bat"Added by the ANPES WORM!"
UChkMailChkMail.exeMail-checking program supplied with Acer notebooks
UChoiceMailCHOICEMAIL.EXE"ChoiceMail from DigiPortal Software. Block spam with an Email firewall"
XChokeChoke.exe -blahhh"Added by the CHOKE WORM!"
Xchoperunlli32.exe"Added by the QQPASS-U TROJAN!"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
UCHotKeymhotkey.exe"Enables special keys on Chicony keyboards. Special combinations include Internet
UCHotKeyMK9805.EXE"Enables special keys on Chicony keyboards. Special combinations include Internet
UCHotKeyzHotkey.exe"Enables special keys on Chicony keyboards. Special combinations include Internet
NChristmas Music PlayerTTEST6.EXE"Christmas Music Player brings the music of the Christmas Holiday to your desktop"
?ChromeMarkkeysh.exe"Related to this. Don't know what keysh.exe does though and if it's required"
?ChronitelInitTVCHTVINIT.EXE"??"
Uchronochrono.exe"Chronograph is a simple utility that synchronizes internal computer clock to the atomic time. Chronograph automatically maintains correct time using atomic clock servers of the National Institute of Standards and Technology (NIST)."" Shows seconds and shows the date without having to hover the mouse. Shows a calendar when hovered over"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
XCi Svrcisvr.exe"Added by the IRCBOT.AWN BACKDOOR!"
Xci1gntci1gnt.exe"Detected by Kaspersky as the AGENT.DHU TROJAN!"
XCiaBackdoormsldr.comAdded by a VIRUS!
Xcihost.execihost.exe"Added by the LINST TROJAN!"
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
YCingular Communication ManagerCingularCCM.exe"Cingular Communication Manager - now taken over by AT&T. ""provides a robust set of wireless communication tools for businesses and individuals. With wireless access to email
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
NCIOche7e1~1.exe"ChatItOut webcam chat program"
XCiodiagDECCONF.EXE"Added by the STRAT.EL TROJAN!"
XCirebonPunyaXXrocks.exe"Added by the BHARAT.A WORM!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
XCissiCissi.exe"Added by the CISSI.A WORM!"
UCitiUCSCitiUCS.exe"Citibank Virtual Account Numbers - ""With this free service for Citi cardmembers
NCitiVANCitiVAN.exe"Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again"
Xcjbcjb.exe"Added by the AGENT.ALZE TROJAN!"
Xcjbcjb*.exe"Added by a variant of the AGENT.ALZE TROJAN - where * is a random digit and the file is located in %ProgramFiles%\cjb"
XCJETCJet.exe"FFToolBar adware toolbar"
YCjstcomCjstcom.exeCanon printer BJ status language monitor
YClamWinClamTray.exe"ClamWin antivirus"
XClassesint1.exe"""Switch"" premium rate adult content dialler variant"
XClassesintl.exe"""Switch"" premium rate adult content dialler variant"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XClassesMSTAR2.EXE"""Switch"" premium rate adult content dialler variant"
XClassesmstart.exe"""Switch"" premium rate adult content dialler variant"
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
Xclcbt.execlcbt.exe"Added by the AGENT.CBA TROJAN!"
Xclcl3clcl3.exeAdded by the AGENT.ES TROJAN!
Xclcl7clcl7.exe"Added by a variant of the Covert Sys Exec TROJAN!"
UCLCLSetCLCL.exeCLCL clipboard caching utility
NClean Access AgentCCAAgent.exe"Cisco Clean Access Agent from Cisco Systems
XClean Mgrcleanmg.exe"Added by the IRCBOT.BBO BACKDOOR!"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
XCleanatorCleanator.exe"Cleanator rogue privacy program - not recommended
?CleanEasyImgcleanall.exe"??"
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
UCleanTempCLEANT~1.EXE"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
UCleanTempCleanTemp.exe"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
NCleanupONICTASK.EXE"Internet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet"
YCleanUpmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
YCleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
?CleanupProgramcleanup.exe"Sony Vaio related - what does it do and is it required? Located in a C:\Sonysys folder"
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
UCleverKeysCK.exe"CleverKeys - ""is free software that provides instant access to definitions at Dictionary.com
Xclfmonclfmon.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmon.execlfmon.exe"Added by the AGENT-BJ TROJAN!"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClick Radio Tunerclickr~1.exe"ClickRadio - subscription service playing radio music via the internet"
NClick Tray CalendarClickT~1.EXE"ClickTray Calendar - shows holidays
NClickMeClickMe.exe"ClickM ""JOKE"" program"
UClickoffClickoff.exe"Clickoff automatically dismisses annoying dialog boxes"
NClickSight Launchercs.exe"Launcher for the ClickSight® marketing tool from ClickStream Technologies - which ""is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"""
XClickTheButtonCTB.EXE"ClickTheButton adware"
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XClickTheButtoncd_load.exe"Added by the DOWNLOADER-MY TROJAN!"
XCLICONFGCLICONFG.EXE"Added by the OPASERV.T WORM!"
UClient Access API Daemoncwbappcd.exe"IBM iSeries Client Access
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
UClient Access Taskbarcwbuitsk.exe"IBM iSeries Client Access taskbar
XClient Agentipxwping.exe"Added by the PPDOOR-N TROJAN!"
XClient Agentphotes.exe"Added by the PPDOOR-P TROJAN!"
XClient Agent[path to file]"Added by the PPDOOR-J TROJAN!"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClient Updatewup.exe"Added by the OPANKI.O WORM!"
YCliente DLODLOClientu.exe"Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
XClientMan1mscman.exe"ClientMan parasite variant"
NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xclipboard.execlipboard.exeAdded by an unidentified WORM or TROJAN!
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
Uclipdiaryclipdiary.exe"Clipdiary from Softvoile - ""Free Clipboard Manager for keeping the clipboard history"""
NClipMate5xClipMt5x.exe"Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
NClipmate6CLIPMT60.EXE"Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
NClipMate7ClipMate.exe"Clip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard"
NClipomaticClipomatic.exe"Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
NClipTrakClipTrak.exe"
NClipTrakkerClipTrakker.exe"Cliptrakker - clipboard extender"
NCLISTARTCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
UCLMFrontPanelclmpanel.exe"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
XClock Manageramsngr.exe"Added by the SDBOT-XM TROJAN!"
XClockSyncSync.exe"ClockSync - synchronizes your system clock with an internet time server. It's by WhenU
UClockWiseCLOCKWISE.EXE"ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates
UClocXClocX.exe"ClocX - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms etc?"
UCloneCDCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
UCloneCDElbyCDFLElbyCheck.exe"From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
UCloneCDTrayCloneCDTray.exe"System tray for the now discontinued CloneCD. The only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
XClremmdc.exe"Added by the PURSCAN-AI TROJAN!"
XClrSchLoader[path to file]"ClearSearch adware"
XCLSIDcom.exeAdult content dialler
XCLSIDdll.exeAdult content dialler
XCLSIDmsgplus.exeAdult content dialler
XCLSIDplugin.exeAdult content dialler
XCLSIDsed.exeAdult content dialler
XCLSIDmsgplus.exePremium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
Xcls_pack.execls_pack.exe"Added by the Malware Defense rogue security software. Also detected as the FAKEAV-AQB TROJAN!"
UClUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
?CM-SmWizardSmWizard.exe"SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
Ucmacma.exe"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
XCMAPPcmappclient.exe"CasClient adware - also detected as the CMAPP TROJAN!"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
XCmdcmd32.exe"Added by the TANKED WORM!"
Xcmd32configs.exe"Hijacker
Xcmd64cmd64.exe"CoolWebSearch Msconfd parasite variant"
Xcmdbcscmdbcs.exe"Added by the LINEAG-GKW TROJAN!"
Xcmdconcmdcon.exe"Added by the CRYPTER.A TROJAN!"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
XCmdShell.exeCmdShell.exe"Added by the BCKDR-QHY BACKDOOR!"
XCMEcme.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XCmeSYSCMEsys.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XCmeUPDCMEupd.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XCMFibulaCMFibula.exe"CASClient adware"
NCmFlywaveNameCmFlywav.exe"Driver for Linksys Wireless-G Music Bridge"
UCMGrdianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
UCMGShieldUICMGShieldUI.exe"UI for CMG (CREDANT Mobile Guardian) Shield from Credant Technologies. ""The CMG Shield resides on devices and external media to enforce security policies even if the device is disconnected from the network."" Used to protect sensitive corporate on laptops
XCMManCMMan.exe"Added by the CMAPP TROJAN!"
XCmmon32Syscmmon32.exeAdded by the SMALL.CL TROJAN!
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmrsfcmrsf.exe"Added by the DELF-HU TROJAN!"
Xcmrsscmrss.exe"Added by the DELF.DU TROJAN!"
Xcmrsscrmss.exe"Added by the DLOADER-EK TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
Xcmrstcmrst.exe"Added by the BANCOS.S TROJAN!"
Xcmrstcmrst.scr"Added by the DLOADER-FP TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
XCMSallycallmesally.exe"Added by the CASAL.A TROJAN!"
UCMSETTINGSctmn.exe"Part of NetNanny
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsssystem.exe"Added by a variant of the RBOT WORM!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCMSystemCMSystem.exe"CASClient adware"
Xcmt101cmt101.exe"Added by a variant of the CRYPTER.C TROJAN!"
?CmUCRRunCmUCReye.exe"Related to Medion Display Information. What does it do and is it required?"
Xcmutilcmutil.exe"Added by the AGENT-DFN TROJAN!"
Xcmx32cmx32.exe"Added by the GEMA.D TROJAN!"
XCn323cnfrm33.exe"Added by the MIMAIL.G WORM!"
XCn911ODBCJET.exe"Added by the BIFROSE-PR TROJAN!"
XCNBABECNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
Ncnetkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
XCnfrm32cnfrm.exe"Added by the MIMAIL.D WORM!"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
YCnwiDeviceAgentcnwida.exe"Part of the Canon imagePROGRAF W8400 printer management software"
YCnxAdslLCnxAdslL.exe"DLink
NCnxDslTaskBarCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
UCobBUCobBU.exe"Cobian Backup versions 6 and 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobianCobian.exe"Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian BackupCobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10Cobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 6CobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7CobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 ApplicationCobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8Cobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9Cobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitaCobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MoonCobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup BoletusCobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
Ucobuicobui.exe"System Tray access to Cobian Backup versions 6 and 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XCodeCleanCCIntro.exe"CodeClean rogue security software - not recommended"
UCodename Dashboarddashboard.exe"Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework
?COEMsgDisplayCOEMsgDisplay.exe"Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?"
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
Ucolorealcoloreal.exe"Makes colours sharper and brighter
NColorificHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCom+ Syscsrs.exe"Added by the FORBOT-BT WORM!"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
XCOM++ Systemsuchost.exe"Added by the LOVGATE-F WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
NCOM-IPCOMIP.EXECOM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
Ucom.codeode.cactusspamfiltercactusspamfilter.exe"Cactus Spam - free easy-to-use spam blocker"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
UComAgentComAgent.exe"ComAgent - MDaemon's instant messaging client"
Xcombo.execombo.exe"Added by the CHIMO-C TROJAN!"
Xcombop.execombop.exe"Added by the BOWFEED-A TROJAN!"
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
XCOMCFGcomcfg.exe"Added by the TOADCOM.A TROJAN!"
Xcomctl32comctl32.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
UComm Drivercommh32.exe"G Data ""PC Spion"". PC monitoring and surveilling software
XCommandsystem.exe"Added by the GATECRASH.A or GATECRASH.B TROJANS!"
XCommandGotit.exe"Added by the TITOG WORM!"
XCOMMANDcommand.exe"Added by the QQPASS.E TROJAN!"
Xcommandjavaw.exe"Added by the AGOBOT-LG WORM!"
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
UCommand WorkStation 4cws 4.exe"EFI's Command WorkStation makes ""managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information"" - for high-end print environments"
Xcommand32command32.exe"Added by the LINEADI-A TROJAN!"
NCommCtrcommctr.exe"""Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!"". Available via Start -> Programs"
YCommon ClientccApp.exe"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XCommon Filestwain.exe"Added by the AGENT.BEA TROJAN!"
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCOMMUNICATORCommunicator.exe"Part of Microsoft Office Communicator
UComodo FirewallCPF.exe"Comodo Firewall"
YCOMODO Firewall Procfp.exe"Comodo Firewall Pro"
UComodo Launch Pad TrayCLPTray.exe"System Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware
YCOMODO Memory Firewallcmf.exe"""Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack"""
UCompanion Modulecompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XCompanionWizardcompwiz.exe"Part of WinAntiVirusPro 2007 rogue security software (and possibly others) - not recommended
UCompaq AlerterCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
NCompaq DMIcpqdmi.exeCompaq version of the Desktop Management Interface
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
UCompaq Knowledge Centersilent.exe & matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
UCompaq PK Daemoncpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use them
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
?CompaqHW Comp Managercpqhcm.exe"Running on a Compaq laptop - any ideas?"
NCompaqPrinTrayprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
NCompaqSystraycpqpscp.exeCompaq System Tray icon
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XComPlus Applicationstwain.exe"Added by the AGENT.AQO TROJAN!"
UComproRemoteComproRemote.exe"VideoMate TV tuner and capture card - remote control driver"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
UCompuSpyCompuSpy.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
NCOMSMDEXEcomsmd.exe3Com tray icon
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
XComTry Web Searcherwstray.exeComtry MP3 Downloader related - spyware
Xcomxtcomxt.exe"Added by the COMXT TROJAN!"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
?Concurreconcurre.exe"??"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
UConfigUtilityConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
Xconime.execonime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
NConmgrconmgr.exeStarts Winfax pro at startup
UConMgr.execonmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
XConnect2Partyconnect2party.exeAdult content dialler
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTAUTrayAppCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
UConnection KeeperConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
NConnection ManagerCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XConnectorSYS.EXE"Nunci premium rate dialer"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XConsconsol32.exe"Hijacker - redirects to an adult content portal
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
?Contactecontacte.exe"Some kind of driver?"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XContentEraserGDC.exe"ContentEraser rogue privacy tool - not recommended
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XContraviroContraviro.exe"Contraviro rogue security software - not recommended
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
UControl CenterCenter.exe"Associated with Hawking Technologies
XControl handler***********.exe [* = random char]"CoolWebSearch parasite variant"
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
YControlCenterctlcntr.exe"Part of Lenovo's (IBM) ThinkVantage Fingerprint Software - used on laptops and keyboards with integrated fingerprint readers"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
NControlCentreTrayXWCTray.exe"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCookie Cop 2CookieCop.exe"
UCookie PalCPBRWTCH.EXE"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
UCookieJarCookiejar.exe"Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return. No longer being actively supported"
UCookiePatrolCookiePatrol.exe"CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition"
UCookieWallcookie.exe"CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return"
Xcookwcookw.exe"Part of the ErrClean rogue system error and cleaning utility - not recommended. See here"
UCool Deskcdesk.exe"Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
UCoolMonCoolMon.exe"""CoolMon monitors vital system stats and almost anything else you wish to display on the desktop"""
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UCoolSwitchtaskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
NCoolwallpapercwm_tray.exe"Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers"
Xcoolwebprogramclrssn.exe"CoolWebSearch Smartsearch parasite variant"
NCopernic Desktop SearchDesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
UCopperheadrazerhid.exe"Razer Copperhead gaming mouse driver - required if you use the additional features and programmed keys/macros"
UCopy handlerCopy Handler.exe"Copy Handler lets you copy between hard disks
NCopyrightmwcpyrt.exeDisplays copyright information on IBM ThinkPads
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
XCore System Hardwaresyscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UCoreCenterCoreCenter.exe"MSI Core Center - motherboard utility for monitoring CPU speed
UCoreCenterCORECE~1.EXE"MSI Core Center - motherboard utility for monitoring CPU speed
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorel Photo DownloaderMediaDetect.exe"Related to Corel Photo Album"
NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
XCorelDraw ToolboxCorelDraw.exe"Added by the SDBOT-VZ WORM!"
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
?CORESYScoresys.exe"??"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
NCorrectConnectCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
Xcosinecosine.exe"Added by the RBOT-SW WORM!"
UCostAwareniIPCApp.exe"NetInternals CostAware - download quota measuring tool"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
NCountry Selectpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
NCountrySelectionpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
?Coupon Offers??"??"
Xcouponicacouponica.exe"Adware - see here"
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
UCP32NOTCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
UCP4HPOTOneTouch.EXE"Supports the additional multimedia keys on HP/Compaq laptops which give single button press access to standard functions such as Mail
NCP888M1CP888M1.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
UCPATR10CPATR10.EXE"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba
UCPBrWtchCPBrWtch.exe"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
YCPD_EXECPD.EXEFirewall bundled with McAfee VirusScan 6.*
Xcpldeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xcplmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xcpls_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xcplbrowse.exe"Added by the TACTSLAY.C TROJAN!"
NCplBTQ00CplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Xcpntmgcnavpmc.exe"Added by the SIMCSS TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
?CPortPatchcppatch.exe"CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
YCPQAcDcCPQAcDc.exeCompaq PowerCon power management software for laptops
UCPQAlertCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
YCPQCalibCPQCalib.exeCompaq PowerCon power management software for laptops
NCPQDFWAGCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
UCPQEASYACCcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UCPQEASYACCStartEAK.exe"Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Ucpqeauicpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Ucpqekkcpqek.exe"For Compaq PC's. Easy Access button support for the keyboard"
XCPQHotKeyshotkeysvc.exe"Added by the RBOT-XA WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
NCPQINKAGENTcpqinkag.exe"That is the Compaq Ink Agent for some inkjet printers
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
NCpqsetCpqset.exeDefault settings software in Hewlett Packard notebook
YCPQSTUTFIXstutfix.exe"For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton"
UCPQTEAMcpqteam.exeThis program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration Tool
XcprcprAdroar.com adware downloader
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCPU Idlecpuidlexp.exe"Added by the AGOBOT-BW WORM!"
UCpu Level Up helpCpuLevelUpHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
XCPU Managercpumgr.exe"Added by the PANDEM.B WORM!"
UCPU Power MonitorCpuPowerMonitor.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme). Associated with the ""Energy Saving"" feature of AI Gear - which ""is a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features."" Part of AI Suite"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
XCPU Watcher"rundll32.exe cpu.dllload"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
UCPUcoolCpucool.exeProgram to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
NCPUMonCPUMon.exe"""CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area"""
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
Xcpythidep.exe"Added by the MIRJACK-A TROJAN!"
Xcqlygworld_cup_.bat"Added by the WCUP.A WORM!"
?CQSCP2PSCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
XCr**.exe [* = random char]Cr**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XCr**32.exe [* = random char]Cr**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
UCRBroadCastingCRBroadCasting.exe"CardReader2 from On Track Inovations Ltd. USB Card Reader"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
XCRCSScrcss.exe"Added by the IRCBOT-TH WORM!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
XCreate A MonstercreateAMonster.exe"Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related"
NCreateCDCreatecd.exeAdaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
NCreateCD50Createcd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
NCreateCD_Reminderreminder.exeReminder to create system recovery CD/DVDs on a Sony Vaio laptop or desktop
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative DetectorCTDetect.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
UCreativeMixerCTMIX32.EXE"Creative soundcard System Tray access to
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrisysTec SentrySentry.exe"CrisysTec Sentry rogue privacy program - not recommended"
XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
NCriticalUpdateWucrtupd.exe"MS Windows Critical Update Notification. If you want to keep Windows up-to-date
XCriticalUpdatewucrtupd.exe"Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
UCrossMenuCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menus
XCRP386 Networkingcrp386.exe"Added by the IRCBOT.N TROJAN!"
Xcrscrs.exe"Added by the AGOBOT-TJ WORM!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XCRSSCRSS.exe"Added by the AGOBOT-RM WORM!"
XCRSSlssas.exeAdded by an unidentified WORM or TROJAN!
Xcrssscrsss.exe"Added by the AUTORUN.FM WORM!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
XCrustydmcpl.exe"Added by the RUSTY WORM!"
Xcryptdlgcryptdlg.exeAdded by an unidentified TROJAN!
NCryptLoadRouterClient.exe"CryptLoad download manager"
Ucryptoexpertcexpert.exe"CryptoExpert from SecureAction Research. Advanced on the fly encryption system"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCStsc.exe"Cyber Security rogue security software - not recommended
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XCseccs.exe"Cyber Security rogue security software - not recommended
Ncsecwizcsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
Xcserv32cserv32.exe"Added by the STRATION.EC WORM!"
XCsimPlayerCsimPlayer.exe"Added by the KOOBFACE-AD WORM!"
UCSINJECT.EXECSINJECT.EXE"Part of Quarterdeck/Norton CleanSweep. ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"""
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Xcsoftoksoftok.exe"Added by the QQPASS.G TROJAN!"
Xcsoscsos.exe"Added by the SDBOT-DFE WORM!"
Xcsrcscsrcs.exe"Added by the AGENT-HUA TROJAN!"
Xcsrscsrs.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xcsrsccsrsc.exe"Added by an unidentified VIRUS
XCSRSSCSRSS.EXE"Search page hijacker
XCsrsscsrss.exe"Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrsscsrss.exe"Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xcsrsscsrss.exe"Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssnwiz.exe"Added by the CHODE-J WORM!"
Ucsrsscsrss.exe"BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec"
XCsrssCSRSS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS"
Xcsrssssms.exeAdded by an unidentified malware
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
Xcsrss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XCSRSSUCSRSSU.exe"CoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!"
XCSRSSWCSRSSW.EXE"Added by the CWS-F TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
Ncssauthcssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
YCSScheduleCheckSCHWIZEX.EXE"Part of ConfigSafe - lets you identify changes to the registry
Xcssrscssrs.exe"Added by the BANCBAN-DW TROJAN!"
Xcssrss.execssrss.exe"Malware installed by different rogue security software including SpyKillerPro"
XcsssCsss.exe"Added by the BALICK TROJAN!"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
Yctct.exect.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
UCTAPR2CTAPR2.exe"Console Launcher for the Creative Sound Blaster X-Fi series"
NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
UCTCheckCTCheck.exe"Associated with the ZEN range of MP3 players from Creative Technology Ltd. A visitor recommended the ""U"" status but what does it do?"
UCTCMonitorCTCMonitor.exe"Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office
XCTDrive"rundll32.exe drvmod.dllstartup"
NCTDVDDetCTDVDDet.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
Xctf.exectf.exeAdded by a variant of the BIFROSE TROJAN!
Xctflog managerctflog.exe"Added by the DONBOMB.A TROJAN!"
XCTFM0N.exeCTFM0N.exe"Added by the STARTPAGE.P TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
Xctfmomctfnom.exe"Added by the BCKDR-QTA BACKDOOR!"
Uctfmonctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
Xctfmoncftmon.exe"Added by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfmonmIRC.dll"Added by the DELBOT-E TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
UCTFMonctfmon.exe"Family KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""CTF"" sub-folder"
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XCTFMONwin.exe"Added by the VBS.RUNAUTO.G WORM!"
XCtfmonwmisys.exe"Added by the IRCBOT-ADS WORM!"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
XCtfmon.exectfmon32.exe"CoolWebSearch Ctfmon32 parasite variant"
Xctfmon.exectfmon.exe"Added by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
Uctfmon.exectfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmon.exectfmon.exe eminem.exe"Added by the BHARAT.A WORM!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XCTFMON32CTFMON32.EXE"CoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
Xctfmonactfmona.exe"Added by the DLOADR-BME TROJAN!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
Xctfmunctfmun.exe"Added by the AGENT.ACEZ TROJAN!"
Xctfnnonctfmon.exe"Added by the TURKOJAN.IL BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfnomrundIl32.exe"Added by the LEGMIR-AW TROJAN!"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
Xcthelpcthelp.exe"Added by the SDBOT TROJAN!"
UCTHELPERCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XCTHelpercthelper.exe"Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
XCTin10CTin10.exe"Added by the BANCOS.E TROJAN!"
XCtModuleCtModule.exe"Added by the CLICKER-EG TROJAN!"
XCTMON.EXEcfmon.exe"Added by the CLCKR-AN TROJAN!"
UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
Xctpmonctpmon.exe"Registry Cleaner rogue - not recommended
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
UCtrlVolCtrlVol.exe"Volume control key on Acer
?CTSchedCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
NCTSyncU.exeCTSyncU.exe"Creative Sync Manager - synchronizes music tracks on your computer with your player"
UCTsysVolCTSYSVOL.exeCreative sound card volume controls
?cttdpsrvcttdpsrv.exe"??"
XCTUpdatectupdclt.exe"Added by the RBOT-ABG WORM!"
NCTxfiHlpCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
XCtykd[path to file]"SMALL.SN spyware"
NCTZDetec.exeCTZDetec.exe"Auto-detect feature of Creative Media Lite which assists you in managing your music
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
YcuagentExeCuagent.exe"Command Antivirus related"
XCueX44Dago.exe"Added by the PUNYA-B WORM!"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
Xcuocuo.exe"Added by the BUGBEAR.A WORM!"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
NCurseClientCurseClient.exe"CurseClient add-on manager for World of Warcraft and Warhammer Online games"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
UCursorGizmoCursorGizmo.exe"Cursor Gizmo - cursor management utility"
NCursorXPCursorXP.exe"CursorXP from Stardock - tool for creating mouse cursors"
UCurtainCurtain.exe"Curtain (from Chaotic Visions) - ""is a Windows utility which gives you the power to hide any window or group of windows to your system tray"""
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
NCuteMXCuteMX.EXEFile sharing utility
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcvmonitor.execvmonitor.exe"Added by the SDBOT.BV WORM!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
UCWcw4.exe"Chat Watch ""is a monitoring and logging software for online chat and instant messaging programs"""
UCWatchcw.exe"ChatWatch - chat monitoring tool"
Ncwbckvercwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ncwbinhlpcwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ncwbsvstrcwbsvstr.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?cwbwlwizcwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Cwcdschk.exeCwcdschk.exe"IBM Thinkpad related?"
Ucwcptraycwcptray.exe"Related to ContentWatch Parental Control internet filter"
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
Xcwriterucookw.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
Xcwritercwriter.exe"Part of PcRaiser
Ucwupdatecwupdate.exe"ContentProtect from ContentWatch - internet filter"
Xcximddlldfrmmd.exe"Added by the BUZUS.CQMU TROJAN!"
NCXMonHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
Xcybansoscyban.exe"Added by the TATERF-V WORM!"
NCybercyberchk.exe"Part of Belkins ""Multimedia Cleaning Kit"" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after ""x"" amount of time has passed"
UCyber Trioshowmode.exe"From G-Tek Technologies. Allows you to set the PC in one of three modes
UCyber-Defender 2003uwcdsvr.exe"
NCyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
Xcyberfree.exe****.dat [* = random char]Unidentified adware
UCyberhawkCHTray.exe"Cyberhawk from Novatix. Protects against viruses
UCyberLat Ram CleanerCLRamCleaner.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UCyberLat Ram CleanerCyberLat Ram Cleaner 1.1.exe"CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
NCyberMedia AgentCMAGENT.EXE"Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge
UCyberPatrolNewcphq.exe"""CyberPatrol is one of the most powerful and popular client-based
XCyberWolfCyberWolf.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
XCyDoorCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
XCydoorUpdateCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
?CYNHKeyCYNHKey.exe"??"
NCyphTrayCyphTray.exe"Cypherus - encryption software"
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
YD-Link Air UtilityAirCFG.exeD-Link Air PCI wireless driver and configuration utility
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
Y