| U | detect | idetect.exe | "iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled"
|
| ? | detect | turbodetect.exe | "??"
|
| N | Detector | detector.exe | "USB port detector for LG scanners. Sits in the System Tray |
| U | DetectorApp | DetectorApp.exe | "Related to Roxio MyDVD (was Sonic) DVD authoring software"
|
| U | Device Detector | DevDetect.exe | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
| N | Device Detector 2 | DevDtct2.exe | "Installed by various Olympus products |
| X | DevicePath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| U | Dialer Detect | dd.exe | "DialerDetect detects stealth installed premium rate diallers |
| N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
|
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | Direct X Direct3D | dxd3d.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Direct X Opengl | dxopengl.exe | "Added by a variant of the RBOT-CJ WORM!"
|
| X | direct3d.exe | direct3d.exe | "Added by the CERTIF-F TROJAN!"
|
| N | DirectCD | DirectCD.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
|
| X | Director Video | btnmgern.exe | "Added by the MYTOB-KL WORM!"
|
| Y | Directory Opus Desktop Dblclk | dopusrt.exe | "Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor |
| X | directs.exe | directs.exe | "Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | DirectX | ddhelp32.exe | "Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
|
| X | directx | Directx.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | Sqlexploit.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX | DirectX.exe | "Added by the BLAXE or LOGPOLE WORMS!"
|
| X | directx | NTCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | PipeCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX 32 | directx32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | DirectX Driver | stdhost.exe | "Added by the SDBOT.GVJ BACKDOOR!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX Video Driver | dxterm5.exe | "Added by the WILAB-A TROJAN!"
|
| X | DirectX64 | DirectXset.exe | "Added by the BROWNEY.A WORM!"
|
| X | DirectX9 | direct3d.exe | "Added by the AGENT.EAK TROJAN!"
|
| X | DirectX9 | svchost32.exe | "Added by the RBOT.AQG WORM!"
|
| X | DirectX9 Diag | dx9diag.exe | "Added by the RBOT-ALT WORM!"
|
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLA | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW.EXE | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| X | DocTor | Doctor.exe | "Added by the DOTOR.A WORM!"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| X | dpzProtect | n.vbe | "Added by the RUNAUTO.H WORM!"
|
| N | DriveSelect | driveselect.exe | "DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
|
| X | DrProtection | DrProtection.exe | "DrProtection rogue security software - not recommended"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | dstiosys | plsitctl.exe | "Added by the MAILBOT-BX TROJAN!"
|
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| X | DyFuCA Active Alert | actalert.exe | "Adult content dialler - see here"
|
| U | E06DXLRD_7604703 | EDICT.EXE | "Related to Microsoft Encarta dictionary functions"
|
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | EliteProtector | EliteProtector.exe | "EliteProtector rogue spyware remover - not recommended |
| ? | ElkCtrl | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | ETDWare | ETDCtrl.exe | Elantech smart-pad touchpad driver for the Asus Eee PC range
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| Y | ezShieldProtector for Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| U | FBDirect | FBDirect.exe | "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan |
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | File Protection Monitor | filemon.exe | "Added by a variant of the RBOT WORM!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
|
| N | Free DVD Direct | FreeDVDDirect.exe | "Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
|
| U | FRITZ!webProtect | FwebProt.exe | Firewall included in FRITZ! ISP DSL software
|
| N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
|
| ? | g3dctl | g3dctl.exe | "??"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | gfxtray | "rundll32 ctccw32.dll | findwnd" |
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| Y | gw port controller | PORTCT95.EXE | "From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties |
| U | H/PC Connection Agent | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| U | Hardware Doctor | Hwdoctor.exe | "Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds |
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| N | HCDetect | HCDetect.exe | "MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification |
| X | helpctl.exe | helpctl.exe | "Added by the GASLIDE TROJAN!"
|
| Y | HEProtect | HSockPE.exe | "Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
|
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | HotAction_hr | hotaction_hr.exe | "Added by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""HotAction_hr"""
|
| U | HP Laser Jet Director | hppdirector.exe | "System Tray icon that opens various functions such as copy |
| N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| U | HPGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| U | HPLaptopGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | HPU | ProvenTactics.exe | "Proven Internet Marketing software"
|
| X | HtProtect | AVprotect.exe | "Added by the NETSKY.L WORM!"
|
| U | IBM ThinkPad EasyEject Support Application | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad EasyEject Tray Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| U | IE Doctor | IEDoctor.exe | "IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily |
| ? | iHP-100 | iHPDetect.exe | "Drive Letter Searcher |
| U | Info Select | is.exe | "Info Select from Micro Logic - personal information manager"
|
| ? | InstallNAIProduct | SETUP.EXE | "Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
|
| X | intdctrr | idctup20.exe | "SafeSurfing adware variant"
|
| U | Intel Active Monitor | imontray.exe | "System tray monitoring of fans |
| U | Intel Product Number Utility | IntelProcNumUtility.exe | "Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
|
| X | internct | WinSocks5.exe | "Added by the GRAYBIRD.F TROJAN!"
|
| U | Internet Call Director | ICD.EXE | "TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
|
| X | Internet Connection Wizard | stisvsq.exe | "EasySearch adware"
|
| X | Internet Connection Wizard | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Internet Connection Wizard | stisvsq1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | InternetGetConnectedState | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetGetConnectedStateEx | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| N | Introduction-Registration | ?? | "For Compaq PC's. Should only run first time |
| X | IP Packet Redirect Service | ipredirect.exe | "Added by the FORBOT.SM WORM!"
|
| X | IPC Connection | ipcconn.exe | "Added by the RBOT-AEG WORM!"
|
| X | IpCtrl | ipcon32.exe | "Added by an unidentified VIRUS |
| N | IPPDetect | IPP4Detect.exe | "Part of Presto! Mr.Photo - ""an ideal program for creating |
| ? | iPrint LPT Redirector | nipplpte.exe | "Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
|
| N | iPrint Tray | iprntctl.exe | "Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
|
| U | iProtectYou | ip.exe | "iProtectYou - internet filtering/parental control and network monitoring software"
|
| N | iRis Active Monitor | winmon32.exe | "Iris Antivirus - discontinued |
| N | iRiS AntiVirus Active Monitor | WIMMUN32.exe | "Iris Antivirus - discontinued |
| Y | ISTray | pctsTray.exe | "System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
|
| N | ItsDeductiblePopUp | ItsDeductible.exe | "ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
|
| N | IW ControlCenter | iwctrl.exe | "Pinnacle Systems InstantWrite enables you to use your CD-R |
| U | iwctrl | iwctrl.exe | "Pinnacle Systems InstantWrite enables you to use your CD-R |
| U | IW_Drop_Icon | iwctrl.exe | "Pinnacle Systems InstantWrite enables you to use your CD-R |
| X | java-plugin | javasctp.exe | "Added by the VB.AMX TROJAN!"
|
| ? | Jessops Insert Detect | InsDetect.exe | "Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Jet Detection | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
|
| U | jv16PT - Privacy Protector | Task.jvb | "jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer |
| U | KBD MediaCenter | MEDIACTR.EXE | Multimedia keyboard manager. Required if you use the multimedia keys
|
| X | kernctl32 | "rundll32 kctl32.dll | initialize" |
| U | Kernel and Hardware Abstraction Layer | KHALMNPR.EXE | "Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| X | kernel system daemon | ACTIVAT0R.exe | "Added by the RANDEX.AW WORM!"
|
| N | Kodak Picture Easy *.* Batch Transfer | PezDownload.exe | "Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
|
| N | Kodak Picture Transfer Software | pts.exe | Looks for Kodak camera connection and media insertion. Available via Start -> Programs
|
| U | LG Direct Media Button Service | LGDMEBTN.exe | "Supports the Direct Media button on LG Notebooks that support it - such as the S1 PRO EXPRESS DUAL. Pressing this button launches the application for watching movies or listening to music"
|
| U | LicCtrl | "rundll32.exe MMFS.DLL | Service" |
| N | LifeScape Media Detector | PicasaMediaDetector.exe | "Media detector for Picasa's automatic photo organizer"
|
| X | Live PC Care | LP[random characters].exe | "Live PC Care rogue security software - not recommended |
| X | LiveProtect | LiveProtect.exe | "System Live Protect rogue security software - not recommended |
| U | LMgrOSD | OSDCtrl.exe | "OSD (on-screen-display) utility - part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound |
| X | load | ctftpscr32.exe | "Added by the AGENT-FPN TROJAN!"
|
| X | LoadDBackUp | BcTool.exe | "Added by the GIBE WORM!"
|
| X | loadMect1 | explorer.exe | "Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
|
| X | Local Internet Connection | LIC.exe | "Added by the SDBOT-YA WORM!"
|
| X | Logical Disk Detection | mrisvc.exe | "Added by the IRCBOT.AOW BACKDOOR!"
|
| N | Logitech . Product Registration | eReg.exe | "Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice |
| ? | Logitech Camera Software | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| U | Logitech Hardware Abstraction Layer | KHALMNPR.EXE | "Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| ? | LogitechCameraService(E) | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| U | LogitechVideo[inspector] | InstallHelper.exe | Entry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
|
| Y | Logoff | SCTUINotify.exe | "Part of Windows SteadyState |
| N | Lotus QuickStart | smartctr.exe | "Lotus central application |
| Y | LXCCCATS | "rundll32 [path] LXCCtime.dll | _RunDLLEntry@16" |
| Y | LXCTCATS | "rundll32 [path] LXCTtime.dll | _RunDLLEntry@16" |
| U | lxctmon.exe | lxctmon.exe | Lexmark 5400 Series printer device monitor
|
| Y | LXDCCATS | "rundll32 [path] LXDCtime.dll | _RunDLLEntry@16" |
| X | M S DVD DirectX Dll Drivers | msxdl.exe | "Added by the SDBOT-BJN WORM!"
|
| X | Malware Destructor 2009 | MD345d.exe | "Malware Destructor 2009 rogue security software - not recommended |
| X | ManageProtocolCtrl | csmsv.exe | "Added by the LOOKSKY.B TROJAN!"
|
| N | Matrox Color Control | hgcctl95.exe | For Matrox video cards. Quick access to changing colors
|
| N | Matrox Control Center | mgactrl.exe | For Matrox video cards. Quick access to settings
|
| U | MBMon | "Rundll32 CTMBHA.DLL | MBMon" |
| X | McAfee Antivirus Protection | mcafeeAV.exe | "Added by a variant of the RBOT WORM!"
|
| X | Mcafee Auto Protect | mcafeshield.exe | "Added by the RBOT-UH WORM!"
|
| Y | McAfee Family Protection | mfp.exe | "McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content |
| X | McAfee Windows Protection | mcafee32.exe | "Added by a variant of the SPYBOT WORM!"
|
| Y | MCTskShd | mctskshd.exe | "Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online and used to schedule tasks such as automatic updates |
| U | MDDiskProtect | MDDiskProtect.exe | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | MDDiskProtect.exe | MDDiskProtect.exe | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| X | mdetect | [path to trojan] | "Added by the SPABOT TROJAN!"
|
| U | Mediafour MacDrive | MDDiskProtect.exe | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| X | MediaPath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | Meeting Connection | comsutil.exe | "Added by the PPDOOR-E TROJAN!"
|
| X | Meeting Connection | wowdache.exe | "Added by the PPDOOR-D TROJAN!"
|
| X | Meeting Connection | hgakdl32.exe | "Looks like a variant of the PPDOOR-E TROJAN!"
|
| Y | mgavctrl | mgavrtcl.exe | Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
|
| U | MGSysCtrl | MGSysCtrl | Part of the System Control Manager for MSI notebooks - displays animations for hot key commands (such as turning the wirelss card on/off)
|
| X | Microsoft (R) Windows Protected Content Restoration Service | services.exe | "Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
|
| U | Microsoft ActiveSync | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| X | Microsoft ActiveX Debugger NT | [path to trojan] | "Added by the BANCOS-DO TROJAN!"
|
| X | Microsoft boot system cfg32 | actboost.exe | "Added by the BROPIA.R WORM!"
|
| X | Microsoft Connection Manager Monitor | cmmon.pif | "Added by the RBOT-AKV WORM!"
|
| U | Microsoft CTF Loader | ctfmon.exe | "Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or |
| X | Microsoft DirectX | Spoolserv.exe | "Added by the DINFOR WORM!"
|
| X | Microsoft DirectX | rasmngr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft DirectX | PDSched.exe | "Added by the SDBOT.CN WORM!"
|
| X | Microsoft DirectX | wuamgrd.exe | "Added by the SDBOT.MY WORM!"
|
| X | Microsoft DirectX | time123.exe | "Added by the SDBOT.MD WORM!"
|
| X | Microsoft Directx | directxat.exe | "Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
|
| X | Microsoft DirectX | wupdate.exe | "Added by the RBOT-L WORM!"
|
| X | Microsoft Directx click | directxclick.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directx clicks | directxclickers.exe | "Added by the RBOT-GHT WORM!"
|
| X | Microsoft Directx push | directxpushup.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directxsp | directxbt.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directxspnew | directxnew.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Internet Antivirus Protection | antivirus.exe | "Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
|
| X | Microsoft Macro Protection SubSsy | msacroprots386.exe | "Added by the RBOT-KE WORM!"
|
| X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | "Added by the RBOT.KN WORM!"
|
| X | Microsoft Messenger Management Controls | msmgmctl.exe | "Added by the RBOT-APA WORM!"
|
| X | Microsoft Problem Doctor | windr128.exe | "Added by the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr32.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr64.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Redirect | [path to file] | "Added by the BANKER-FW TROJAN!"
|
| X | Microsoft Redirect | systen.exe | "Added by the BANCOS-FO TROJAN!"
|
| X | Microsoft Security Management | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Server Applacations | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft standard protector | winsocks5.exe | Added by the SMALL.CF TROJAN!
|
| X | Microsoft standard protector | [path to trojan] | "Added by the STOX-C TROJAN!"
|
| X | Microsoft task tray monitor | ctray.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft TCP/IP Connection Monitor | svchost32.exe | "Added by the RBOT.KS WORM!"
|
| U | Microsoft Webserver | svctrl.exe | Personal web server program which enables you to create and host a web server from your computer. Not required for most people
|
| X | Microsoft Windows Control | mswctl32.exe | "Added by the RBOT.JP WORM!"
|
| X | Microsoft Word | BootSector.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works
|
| X | Microsoft« ActiveX Debugger NT | setdebugnt.exe | "Added by the BANCOS-CZ TROJAN!"
|
| N | MightyFAX Controller | MFNTCTL.EXE | "Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software""
|
| N | Mirabilis ICQ | NDetect.exe | "If connected to the internet |
| ? | misiCTRL | misiCTRL.exe | "Miro video driver related. Is it required?"
|
| N | Mobile Connectivity Suite | Application Launcher.exe | "System Tray access to the HTC Sync mobile phone management utility for models including the Hero |
| N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs
|
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel
|
| N | MP3 CD Extractor | CD-Extractor.exe | """MP3 CD Extractor is an audio CD to MP3 ripper which can extract Digital Audio tracks from Audio CDs into files on the hard disk"""
|
| X | MP3Collection | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | mrsvctr | mrsvctr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS Agent Protection | ag1.exe | "Added by the IRCBOT.AZ BACKDOOR!"
|
| X | MS Auto-IPSec Protection | MSASP32.exe | "Added by the RBOT-AER WORM!"
|
| X | MS Decryption Software | active.exe | "MediaTickets adware variant"
|
| X | MS DirectX Sound Drivers | msdrvdx.exe | "Added by the RBOT.BCX WORM!"
|
| X | MS DVD DirectX Dll Drivers | mdxdl.exe | "Added by the SDBOT-XI WORM!"
|
| X | MS DVD DirectX Sound Drivers | msdrvdx.exe | "Added by the SDBOT-XJ WORM!"
|
| X | MS System Call Function | msscf32.exe | "Added by the RBOT-GBZ WORM!"
|
| X | ms window update | ******.exe [* = random character] | "Added by a variant of the RBOT WORM!"
|
| X | MS Windows Local Directory | MSWLD32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS-Connect | arr.exe | "Adult content dialler - see here"
|
| X | MS-Connect | cdm.exe | "Adult content dialler - see here"
|
| X | MS-Connect | game.exe | "Adult content dialler - see here"
|
| X | MS-Connect | msite18.exe | "Adult content dialler - see here"
|
| X | MS-Connect | web.exe | "Adult content dialler - see here"
|
| X | msconfigurator | ctfsdk.exe | "Added by the DELF-ALS TROJAN!"
|
| X | msctfg32 | msctfg32.exe | "Added by the RBOT-TJ WORM!"
|
| X | msctrl.exe | msctrl.exe | "Microsoft Security Adviser rogue security software - not recommended"
|
| X | Msctrl32 | Msctrl32.scr | "Added by the REDIST WORM!"
|
| X | msdev control | msdevctrl.exe | "Added by the SPYBOT.N BACKDOOR!"
|
| X | msdirect.exe | msdirect.exe | "Added by the CERTIF-L TROJAN!"
|
| X | msdrvctrl | msdrvctrl.exe | "Added by the VIDCACH-A TROJAN!"
|
| U | MSKDetectorExe | MSKDetct.exe | "Part of McAfee Spamkiller"
|
| X | msmautoprotect | msmssgs.exe | "Added by the BIFROSE-AJ TROJAN!"
|
| X | MSN | ctfmoons.exe | "Added by the SPYBOT.HI WORM!"
|
| X | MSObject32 | MSObject32.js | "Added by the PUN TROJAN!"
|
| X | MSprotect.exe | MSprotect.exe | "Added by the DABYREV.A VIRUS!"
|
| X | MSVsmt | rpcxctx.exe | Added by an unidentified WORM or TROJAN!
|
| X | msxct | msxct.exe | "eXact Advertising (NaviSearch |
| U | Multi-function keyboard | GWHotkey.exe | "Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail |
| X | My Security Engine | MS[random characters].exe | "My Security Engine rogue security software - not recommended |
| X | My Security Wall | MS[random characters].exe | "My Security Wall rogue security software - not recommended |
| X | NAV Auto Protect | msfwe1.exe | "Added by a variant of the RBOT WORM!"
|
| X | NAV Auto Protect | navprotect.exe | "Added by the RBOT.BKW WORM! Note - this is not a valid Norton AntiVirus product from Symantec"
|
| X | NAV Auto Protect | dnsserv.exe | "Added by a variant of the SDBOT WORM!"
|
| X | NAV Auto Protect | mcafee32.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | NbkCtrl | NbkCtrl.exe | "Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
|
| N | NeroNETTrayIcon | NNServiceCtrl.exe | "System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
|
| U | Net Activity Diagram | nad.exe | "Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs"
|
| X | NET protection system | netst.exe | "Added by the RIZO.A TROJAN!"
|
| X | Network Connections | internat.exe | "Added by the VB-ZD TROJAN!"
|
| X | Network Service | MccTrayApp.exe | Added by an unidentified WORM or TROJAN!
|
| U | NGClient | ngctw32.exe | "Symantec Ghost Server software - needed for a ""a Ghost multicast"" (transfer images to multiple machines). Can be launched manually"
|
| X | NI.UGDCTH_0001_N122M1712 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.UGDCTR_0001_N108M0407 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.USYP | SysProtectScannerInstall.exe | "Installer for the SysProtect rogue security software |
| U | nmctxth | nmctxth.exe | "Related to Pure Networks comprehensive home and small business networking software that simplifies network configuration"
|
| Y | NMSSupport | IntelHCTAgent.exe | "Network monitor for Intel® Hub Connect Technology"
|
| N | Nokia Connection Monitor | NclConf.exe | "Monitors the infrared port |
| N | NokiaPCSyncTray | PCSync.exe | "System Tray access to Nokia PC Sync - which ""allows you to synchronise contacts |
| U | NOMAD Detector | ctnmrun.exe | Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
|
| X | Norton Antivirus AV | FVProtect.exe | "Added by the NETSKY.P WORM! Note - this is not the popular AV software!"
|
| X | Norton Auto Protect | nava.exe | Added by an unidentified WORM or TROJAN!
|
| X | Norton Auto Protect | crss32.exe | "Added by the SDBOT.ATF WORM!"
|
| Y | Norton Auto-Protect | navapw32.exe | Norton Anti-Virus's background scanning process
|
| X | Norton Auto-Protect | ccApp.exe | "Added by the AKHER.D WORM! Note - for the valid Norton AV entry the filename is ""navapexe"". This is also not the valid Norton AV file with the same filename"
|
| X | Norton Auto-Protect | SERVICES.exe | "Added by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also |
| X | Norton Auto-Protect | ffbaqe.exe | "Added by the SLINBOT.RF BACKDOOR! Note - this is not a valid Norton product"
|
| X | Norton AV Protection Startup | Ati2xxx.exe | "Added by a variant of the RBOT WORM!"
|
| N | Norton Disk Doctor | Ndd32.exe | "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up |
| X | Norton Drive Protection | msdt32.exe | "Added by the FORBOT-GB WORM! Note - this not a valid Norton program!"
|
| Y | Norton eMail Protect | POPROXY.EXE | "Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed |
| X | Norton GProtect | ngrfn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Norton Protect | npprotect.exe | "Added by the RBOT-WW WORM!"
|
| X | Norton protect | nvsvc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Norton Protect Activies | csrss.exe | "Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
|
| N | Norton System Doctor | Sysdoc32.exe | "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up |
| U | NovaBackup * Tray Control | NbkCtrl.exe | "Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
|
| U | NPROTECT | nprotect.exe | Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid
|
| X | ntddetect | ntddetect.exe | "Added by the AGENT-CU TROJAN!"
|
| X | ntuser | ctfmun.exe | "Added by the SILLYFDC WORM!"
|
| X | ntuser | ctfmon.exe | "Added by the AGENT-GSG TROJAN! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
|
| X | nvctrl.exe | nvctrl.exe | "Added by the ZLOB.G TROJAN!"
|
| Y | NVIDIA ActiveArmor | ntrayfw.exe | "System Tray access to the the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets"
|
| U | NVIDIA Media Center Library | "RunDLL32.exe NvMCTray.dll | NvTaskbarInit" |
| U | NVMCTRAY | "RunDLL32.exe NvMCTray.dll | NvTaskbarInit" |
| U | NvMediaCenter | "RunDLL32.exe NvMCTray.dll | NvTaskbarInit" |
| Y | NvRegisterMCTray | "RUNDLL32.EXE NVMCTRAY.DLL | NvMCRegisterApp NvCpl.dll" |
| Y | NvRegisterMCTrayNview | "RUNDLL32.EXE NVMCTRAY.DLL | NvMCRegisterApp nView.dll" |
| Y | Object Store Server | osserver.exe | "Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital |
| X | ObjectDock | Brico.cmd | "Added by the BOBANDY-A WORM!"
|
| U | Octoshape Streaming Services | OctoshapeClient.exe | "Octoshape Live Streaming - ""is a revolutionary technology that will reduce your bandwidth cost and improve the quality in sound and picture"""
|
| N | OfotoNow USB Detection | "Rundll32.exe OFUSBS.DLL | WatchForConnection OfotoNow" |
| N | Oil Change | OCTray32.exe | From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs
|
| ? | online cdrom | Active acid.exe | "??"
|
| Y | Orange Connection Kit | atdialler1.exe | "Part of the Orange Connection Kit - changes the dial-up for Orange Any Time if access problems are encountered"
|
| U | OSSelectorReinstall | oss_reinstall.exe | "Related to Acronis Disk Director Suite"
|
| N | OurPictures | OurPictures.exe | "Related to RitzPix Online Photo Print services"
|
| X | PC Live Guard | PC[random characters].exe | "PC Live Guard rogue security software - not recommended |
| X | PC Protection Center | PcProtection.exe | "PC Protection Center 2008 rogue security software - not recommended |
| Y | PC Tools AntiVirus Client | PCTAV.exe | "System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses |
| Y | PcCtlCom | PCCTLCOM.EXE | "Part of Trend Micro web-security products - Internet Security 2005-2006 and Virus Buster 2005-2006"
|
| X | PCprotectar.exe | PCprotectar.exe | "PCprotectar rogue security software - not recommended. A member of the AntiAID family"
|
| X | PcsProtector | PcsProtector.exe | "PcsProtector rogue security software - not recommended |
| Y | PCTAV | PCTAV.exe | "System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses |
| Y | PCTAVApp | PCTAV.exe | "System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses |
| X | pctdf.exe | pctdf.exe | PCTotalDefender rogue spyware remover variant
|
| U | PcThrust | PcThrust.exe | "PCThrust from SwiftDog - ""increases computer performance by allocating higher portions of CPU power to active applications and games"""
|
| X | PCToolPro | SysRep.exe | "PCToolPro rogue system error and cleaning utility - not recommended |
| X | PCTotalDefender | pgs.exe | "PCTotalDefender rogue security software - not recommended. A member of the AVSystemCare family"
|
| X | pctp_check | startmon.exe | "Part of the PcTurboPro rogue system optimization tool - not recommended |
| U | pctspk | pctspk.exe | Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
|
| Y | pctsTray | pctsTray.exe | "System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
|
| Y | pctsTray.exe | pctsTray.exe | "System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
|
| X | PCTurboPro | pctp.exe | "PcTurboPro rogue system optimization tool - not recommended |
| U | PCTVOICE | pctvoice.exe | "The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it |
| U | PCTVRemote | remoterm.exe | Controls the remote control on some Pinnacle TV tuners
|
| U | pdfFactory Dispatcher v1 | fppdis1a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Dispatcher v2 | fppdis2a.exe | "FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Pro Dispatcher v1 | fppdis1.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| U | pdfFactory Pro Dispatcher v3 | fppdis3a.exe | "FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler |
| N | PDirect | PDirect.exe | IBM Presentation Director software
|
| U | pdp Server | ctpdpsrvr.exe | Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
|
| Y | PER Email Protection | pavmail.exe | "PER Antivirus"
|
| X | Perfect Defender 2009 | pdfndr.exe | "Perfect Defender 2009 rogue security software - not recommended |
| N | PerfectPrint | pfppop70.exe | Print engine used by Corel WordPerfect 7 and Presentations 7
|
| U | PerfectSuite | dthtml.exe | "PerfectSuite™ from ViewSonic. Rebranded version of Display Tune from Portrait Displays |
| X | Performs peer to peer connection | WinPTTP.exe | "Added by the RBOT-GMI WORM!"
|
| X | personalprotector | personalprotector.exe | "Personal Protector rogue security software - not recommended |
| X | PHIME2004C | CTFMDN.exe | "Added by the DLOADR-AMV TROJAN!"
|
| U | Phone Connection Monitor | audevicemgr.exe | "Connection monitor part of the Sony Ericsson PC Suite mobile phone management utility for some models |
| N | Picasa Media Detector | PicasaMediaDetector.exe | "Media detector for Picasa's automatic photo organizer"
|
| N | Picture Motion Browser Media Check Tool | SPUVolumeWatcher.exe | "Part of the Sony Picture Uility software supplied with Sony camera/camcorder products. Automatically invokes an import process if the camera/camcorder is connected and has media on it"
|
| U | Picture Package VCD Maker | Residence.exe | "Sony Picture Package software for their range of Digital Handycam video cameras. Used to connect the camcorder via USB and allows the user to burn the content directly to a CD"
|
| N | pictureBUZZTray | swtray.exe | "System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually"
|
| N | PivotSoftware | wpctrl.exe | "PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| X | pm32ctrl | pwr32crtl.exe | "Added by the CRYPTER.A TROJAN!"
|
| U | PopSubtract | PopSub.exe | "PopSubtract - pop-up killer"
|
| X | PopularScreensaversWallpaper | "rundll32 [path] F3SCRCTR.DLL | LES" |
| U | PowerPanel Personal Edition User Interaction | pppeuser.exe | "CyberPower PowerPanel Personal Edition UPS Monitoring & Control Software - ""is included with CyberPower's products. This exclusive software allows control and monitoring of your UPS to provide protection for your computer system |
| U | Powertweak | PTCTRL.EXE | ""Powertweak is designed to configure your system in the best way. A processor |
| N | PP****usb | FBDirect.exe | "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan |
| U | PractiSearch | PSearch.exe | "PractiSearch web search software"
|
| X | prdtect | prdtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prgtect | prgtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | Privacy Protector | Privacy Protector.exe | "PrivacyProtector rogue privacy tool - not recommended |
| X | PrivacyConductor | GDC.exe | "PrivacyConductor rogue privacy tool - not recommended |
| X | PrivacyProtector Free | UPRP.exe | "PrivacyProtector rogue privacy tool - not recommended |
| X | prjtect | prjtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prktect | prktect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prltect | prltect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prmtect | prmtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| U | ProjectWhois | ProjectWhois.exe | """Project Whois loads the domain names from all open Firefox and Internet Explorer windows into the one-click menu and gives easy access to the whois records from the System Tray"""
|
| N | projselector | projselector.exe | Roxio Project Selector - can be started manually
|
| U | Protect | SHVRTF.EXE | "PC Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash |
| X | protect | protect.scr | "Added by the DLOADER-TQ TROJAN!"
|
| X | ProtectDefender | ProtectDefender.exe | "ProtectDefender rogue security software - not recommended |
| X | Protected Storage | RUNDLL32.EXE MSSIGN30.DLL ondll_reg | "Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | protectinfo | protectinfo.exe | "ProtectInfo rogue security software - not recommended"
|
| X | ProtectingTool | SysRep.exe | "ProtectingTool rogue system error and cleaning utility - not recommended |
| X | Protection | [path] runtask.exe [path] protection.exe | Added by a variant of the AGENT.3.AU TROJAN!
|
| X | Protection | Protection.exe | "Added by the FEBELNECK-A WORM!"
|
| X | Protection | Firewall.exe | "Added by the ELIPTER.A or ELIPTER.B WORMS! Located in %ProgramFiles%\Internet Explorer"
|
| X | Protection | IExplore .exe | "Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
|
| X | Protection | Norton Internet Security.exe | "Added by the ELITPER.E WORM!"
|
| X | Protection Center | cntprot.exe | "Protection Center rogue security software - not recommended |
| X | Protection System | psystem.exe | "Protection System rogue security software - not recommended |
| X | ProtectionComplete | pgs.exe | "ProtectionComplete rogue security software - not recommended. A member of the AVSystemCare family"
|
| X | ProtectionConue | pgs.exe | "ProtectionConue rogue security software - not recommended. A member of the AVSystemCare family"
|
| X | ProtectionDeDriver | GDC.exe | "ProtectionDeDriver rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | Protections | ProtEX32.exe | "Ultimate SecuritySuite rogue malware remover - not recommended |
| X | Protector GB | protectgb.exe | "Added by the BANKER.EIE TROJAN!"
|
| X | ProtectPcs.exe | ProtectPcs.exe | "ProtectPcs rogue security software - not recommended |
| X | ProtectSoldier | ProtectSoldier.exe | "ProtectSoldier rogue security software - not recommended |
| X | prqtect | prqtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prrtect | prrtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prstect | prstect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prtcct | prtcct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prttect | prttect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutcct | prutcct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutdct | prutdct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutgct | prutgct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | pruthct | pruthct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutict | prutict.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutlct | prutlct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutpct | prutpct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prutsct | prutsct.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prvtect | prvtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| X | prxtect | prxtect.exe | "Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications |
| N | PSIWin2.3 Connection Server | Psconsv.exe | Allows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
|
| X | Pwr32ctr | Pwr32ctr.exe | "Added by the GEMA TROJAN!"
|
| X | Pwr32ctrl | Pwr32ctrl.exe | "Added by the GEMA TROJAN!"
|
| U | PWSActivePrint_5 | ActivePrintSystem.exe | "ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
|
| U | QCTray | QCTray.exe | "System Tray access to IBM Access Connections - forerunner to the current ThinkVantage version. Connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments |
| U | QlbCtrl | QlbCtrl.exe | "HP Quick Launch Buttons control center on their laptops"
|
| Y | Quick Heal On-Line Protection | Cateye.exe | "Quick Heal - virus scanner"
|
| X | Quick Office | activate.exe | "Added by the RANSOMLOCK.D TROJAN! Note - this infection hooks the keyboard to prevent anything except numbers from being typed and displays a Russian message requesting a valid license key"
|
| ? | RAMConnectionChecker | RAMConnChecker.exe | "Part of Remote Access Manager (RAM) for Nortel Networks - which ""combines an intuitive |
| X | rasctrs | rasctrs.exe | "Hijacker |
| X | rbnynkctv | rbnynkctv.exe | "Added by the AGENT-GPA BACKDOOR!"
|
| X | Reactor3 | [random name]32.exe | "Added by the BOFRA.A WORM!"
|
| X | Reactor5 | [random name]32.exe | "Added by the BOFRA.D WORM!"
|
| X | Reactor6 | [random name]32.exe | "Added by the BOFRA.C WORM!"
|
| X | Reactor7 | [random name]32.exe | "Added by the BOFRA.B WORM!"
|
| X | Reactor8 | [random name]32.exe | "Added by the BOFRA.E WORM!"
|
| X | Reactor9 | [random name]32.exe | "Added by the BOFRA.E WORM!"
|
| N | Realtek HD Audio Sound Effect Manager | RTHDCPL.EXE | "Realtek HD Audio Control Panel |
| X | RealTimeProtector | winlogon.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
| X | redirect | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit
|
| X | Registry Protector | regprotect.exe | "Added by the ARIVER.A WORM!"
|
| X | RegistryDoctor2008 | registrydoctor.exe | "RegistryDoctor2008 rogue registry cleaner - not recommended |
| X | RegRun | mActiveX.exe | "Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
|
| X | REGRUNM | autoprotect.exe | Added by an unidentified WORM or TROJAN!
|
| U | REGSVR32 | regsvr32.exe ctasio.dll | "ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
|
| N | reminder-ScanSoft Product Registration | remind32.exe | Registration reminder for ScanSoft products such as PaperPort
|
| X | Remote System Protection | "rundll32.exe [random].dll | HUI_proc" |
| U | RemoteControl | rmctrl.exe | "Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control |
| U | RightFAX Print-to-Fax Driver | FaxCtrl.exe | "Part of RightFAX from Captaris - ""the proven market leader in fax server and document delivery software"""
|
| U | rmctrl | rmctrl.exe | "Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control |
| X | Roam04 | ActiveX.exe | "Added by the ROAMER-A TROJAN!"
|
| U | Run Nintendo Wi-Fi USB Connector Registration Tool | NintendoWFCReg.exe | "Related to Wi-Fi USB Connector from Nintendo"
|
| U | RunDLL32 | "RunDLL32.exe NvMCTray.dll | NvTaskbarInit" |
| X | Rundll32.exe | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | SafePCTool | SysRep.exe | "SafePCTool rogue system error and cleaning utility - not recommended |
| X | SafetyCenter | protector.exe | "Safety Center rogue security software - not recommended |
| U | SafetyNet | ipcTray.exe | "Safety.Net from Netveda - ""offers Internet security |
| U | Sametime Connect | Connect.exe | "IBM Lotus Sametime - instant messaging and Web conferencing software"
|
| U | SandboxieControl | SbieCtrl.exe | """SandBoxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer"""
|
| N | SBC Yahoo! Connection Manager | ConnectionManager.exe | Used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection
|
| U | SbUsb AudCtrl | "RunDll32 sbusbdll.dll | RCMonitor" |
| ? | Scan Detector | Pmxdetect.exe | "Associated with PrimaScan scanners. Is it required?"
|
| N | Scanner Detector | SDetect.exe | "ScanSuite Scanner Detector - part of ScanWizard |
| N | Screen Saver Control | FSScrCtl.exe | Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
|
| X | sctrlmgr | sescmgr.exe | "Added by a variant of the DWNLDR-GAH TROJAN!"
|
| Y | SCTUINotify | SCTUINotify.exe | "Part of Windows SteadyState |
| N | SDetect | SDetect.exe | "ScanSuite Scanner Detector - part of ScanWizard |
| X | SDK Codre Function22 | sdkimddprovment2.exe | "Added by the SDBOT-YJ WORM!"
|
| X | SDK Core Function | sdkimprovment.exe | "Added by the RBOT.BHL WORM!"
|
| X | SDK Core Function2 | sdkimprovment2.exe | "Added by the SPYBOT.OGX WORM!"
|
| U | Search Protection | SearchProtection.exe | """Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
|
| U | SearchProtection | SearchProtection.exe | """Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
|
| U | SecondChance | sctray.exe | "Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash"
|
| N | SecureClean4Tray | sctray4.exe | "WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data |
| X | Security Antivirus | SA[random characters].exe | "Security Antivirus rogue security software - not recommended |
| X | Security Guard | SG[random characters].exe | "Security Guard rogue security software - not recommended |
| X | Security Master AV | SM[random characters].exe | "Security Master AV rogue security software - not recommended |
| X | securw | Nctrup.exe | "Added by the NOPIR.A WORM!"
|
| X | Select server | slcsvr.exe | "Added by the DLOADER-WD TROJAN!"
|
| Y | serrdctl.exe | serrdctl.exe | "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
|
| N | Service Connection | sccenter.exe | For Compaq PC's. Part of Backweb
|
| N | Service Connection | bwtray.exe | For Compaq PC's. Part of Backweb
|
| X | serviceconnect | serviceconnect.exe | "Added by the AGOBOT.AIR WORM!"
|
| X | ServicesActive | cssrs.exe | "Added by the AGOBOT-GB BACKDOOR!"
|
| N | SharkEject | AEJCT32.exe | "Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded |
| X | Shedule Connection | arpo412.exe | "Added by the PPDOOR-R WORM!"
|
| ? | ShowIcon_Justrams_USB Product Driver v2.12r012 | shwicon.exe | "Related to Just Rams USB product driver. Is it required?"
|
| U | SideACT | SideACT.exe | "SideACT organizer software"
|
| U | Smart Connect Monitor | SCMon.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
|
| U | Smart Connect Setup | SCSetup.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
|
| U | Smart Protector Pro | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| N | Smart Start UP | PnPDetect.exe | "Part of Presto! Mr.Photo - ""an ideal program for creating |
| X | Smart Virus Eliminator | SM[random characters].exe | "Smart Virus Eliminator rogue security software - not recommended |
| X | smartprotector | smartprotector.exe | "Smart Protector rogue security software - not recommended |
| U | SmartProtector-Pro | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| X | Smiley District | plugin.exe | "Smiley District adware"
|
| U | Snapfish Media Detector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| U | SnapfishMediaDetector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| ? | SNCT511 | vsnct511.exe | "Unidentified ""Snapshot Viewer""- what does it do and is it required?"
|
| X | some | icthis.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| N | Sonic A3D Control | vrtxctrl.exe | Sound related options
|
| N | Sony Auto Update Tray Application | CONNECTAUTrayApp.exe | "System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
|
| X | soundtctrls | soundtctrls.exe | "Added by the AGOBOT-ZV WORM!"
|
| U | SP2 Connection Patcher | SP2ConnPatcher.exe | Changes limit of concurrent TCP connections of Windows Service Pack 2
|
| X | sp2ctr | sp2ctr.exe | "Added by the DLUCA-M TROJAN!"
|
| U | SpamSubtract | SpamSubtract.exe | "Intermute SpamSubtract - junk email detection and removal program"
|
| U | spamsubtract | SpamSub.exe | InterMute™ SpamSubtract - junk email detection and removal program. InterMute™ is now part of Trend Micro and their products are no longer supported
|
| N | Speed racer | CTSRReg.exe | Software for a Creative sound card
|
| U | SPSTEALT | SmartProtectorPro.exe | "Smart Protector Pro - internet privacy tool that erases tracks |
| U | SPSTEALT | SmartProtector-Pro.exe | "Smart Protector Pro internet eraser from SmartSoft - ""keeps out prying eyes and protects your private data on all Windows systems"""
|
| U | Spy Protector | SpyProtector.exe | "Included in the full version of Security Task Manager |
| X | Spy Protector | srcss.exe | "SpyProtector rogue security suite - not recommended |
| X | Spy Protector | lsascs.exe | "Spy Protector rogue security software - not recommended |
| U | spyprodetector | spydetector.exe | Spyware Process Detector spyware remover
|
| U | SpySubtract | SpySub.exe | "SpySubtract - multi spyware removal tool"
|
| Y | Spyware Doctor | spydoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| Y | Spyware Doctor | swdoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| U | Stardock ObjectDock | ObjectDock.exe | "Stardock ObjectDock is a program that enables users to organize their shortcuts |
| X | start extracting | spoolvse.exe | "Added by the RBOT-XF WORM!"
|
| X | start extracting | spoolvs.exe | "Added by the RBOT.BAN WORM!"
|
| X | start extracting | mcafee.exe | "Added by the RBOT.FO BACKDOOR! Note - this is not a valid McAfee program and is located in %System%"
|
| X | Startup Configuration | [six character filename] | "Added by the RBOT-ARV WORM!"
|
| N | Stay Connected! | StayCon.exe | "More than just a pinger |
| X | stealth.injector.exe | stealth.injector.exe | "Added by the THEALS.A WORM!"
|
| X | StorageProtector | SysRep.exe | "StorageProtector rogue system error and cleaning utility - not recommended |
| N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required
|
| Y | SunProtectionServer | SunProtectionServer.exe | "CounterSpy antispyware software"
|
| X | svchctrl | svchctrl.exe | "Added by the COBFINN TROJAN!"
|
| X | svchost connection monitor | svchost32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | svcshare | CTMONTv.exe | "Added by the FUJACKS-AJ WORM!"
|
| X | svctask | svctask.exe | "Added by the CHUCKYB-A TROJAN!"
|
| U | SX Virtual Link | Connect.exe | "SX Virtual Link from Silex Technology America |
| N | sXe Injected | sXe Injected.exe | "sXe Injected anti-cheat system client/server for Half-Life server based games that prevents cheat programs being loaded"
|
| X | SysCtl | sysctl.exe | "Added by the AOK TROJAN!"
|
| X | Sysctrls | procdll.exe | "Added by the WEEDBOTZ.14 TROJAN!"
|
| X | Sysctrls | winupdate.exe | Added by an unidentified WORM or TROJAN!
|
| X | Sysctrls | mscntrl.exe | "Added by the KOLABC.BB WORM!"
|
| X | Sysctrls | Sysctrls.exe | "Added by the AGENT.AWZ TROJAN!"
|
| X | Sysctrls | win32dll.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Sysctrls32 | sevchost.exe | "Added by the RBOT.ADF BACKDOOR!"
|
| X | SysProtect | System.exe | "Added by the NETSPY TROJAN!"
|
| X | SysProtect | syp.exe | "SysProtect rogue security software |
| X | SysProtect | USYP.exe | "SysProtect rogue security software |
| X | SysProtect Free | USYP.exe | "SysProtect rogue security software |
| X | SysProtector | SysProtector.exe | "SysProtector rogue security software - not recommended |
| U | System | sysctrl.exe | "Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance |
| X | System | BrO_AcT.exe | "Added by the SILLYFDC-AL WORM!"
|
| X | System Defender | WS[random characters].exe | "System Defender rogue security software - not recommended |
| X | System Doctor Free | systemdoc.exe | "SystemDoctor rogue security software - not recommended |
| X | System Protector | lsascs.exe | "System Protector rogue security software - not recommended |
| X | System Redirect | sysbho.exe | "Downloader trojan |
| X | System Services | connection.exe | Added by an unidentified WORM or TROJAN!
|
| X | SystemDoctor 2006 Free | sd2006.exe | "SystemDoctor rogue security software - not recommended |
| X | SystemDoctor Free | systemdoc.exe | "SystemDoctor rogue security software - not recommended |
| U | Task Catcher Real-Time Detector | tasktrap.exe | "Real-time monitor for Task Catcher from BillP Studios - which ""allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash"". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available"
|
| X | Task Help | wualcts.exe | "Added by a variant of the RBOT WORM!"
|
| N | TaskBar | CTLTask.exe | "Creative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects |
| N | Tasktray | CTLTray.exe | Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon. Also allows you to launch the Taskbar via right-click → Show Taskbar. The tasktray can be accessed via Start → Programs → Creative → Sound Blaster Audigy → Taskbar
|
| ? | TAudEffect | TAudEff.exe | "TOSHIBA Notebook related. What does it do and is it required?"
|
| N | tbctray | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
|
| Y | tcactive | tca.exe | "Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage"
|
| ? | TCtlIHook.exe | TCtrlIOHook.exe | "TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required?"
|
| ? | TCtrlIOHook | TCtrlIOHook.exe | "TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required?"
|
| ? | TCtryIOHook | TCtrlIOHook.exe | "TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required?"
|
| ? | Tesco Insert Detect | InsDetect.exe | "Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| Y | tfswctrl | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | tfswctrl.exe | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| U | ThinkPad EasyEject Utility | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | ThinkPad EasyEject Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| U | ThinkPad Presentation Director | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
|
| U | ThinkVantage Access Connections | ACTray.exe | "System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments |
| U | ThinkVantage Access Connections | ACWLIcon.exe | "Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments |
| Y | ThinkVantage Active Protection System | TpShocks.exe | "Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T |
| N | tkonnect | TKONNECT.EXE | "Dialer for the Tiscali internet service provider. Available as a desktop shortcut"
|
| U | TMERzCtl.EXE | TMERzCtl.EXE | Toshiba TME (Toshiba Mobile Extension) Control
|
| X | Total Protect 2009 | pcpc_starter.exe | "Total Protect 2009 rogue security software - not recommended |
| X | Total Virus Protection | TotalVirusProtection.exe | "Total Virus Protection rogue security software - not recommended |
| Y | TPSODDCtl | TPSODDCtl.exe | Power saving software on Toshiba laptops
|
| X | Transaction Tasker | stdhost.exe | "Added by the SDBOT.HNK BACKDOOR!"
|
| Y | Tray control for Malwarebytes' Anti-Malware | mbamtrayctrl.exe | "Malwarebytes' Anti-Malware - ""monitors every process and actually stops malicious processes before they even start. It uses our impressive technology that is in fact a completely novel way of heuristic scanning and it is our response to the increasingly complex malware threats"""
|
| N | TraySantaCruz | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
|
| U | TrojanShield Protector | Port.exe | "TrojanShield anti-hacker/anti-trojan software"
|
| Y | TrueVector | VSMON.EXE | Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
|
| X | TrustDoctor | TrustDoctor.exe | "TrustDoctor rogue security software - not recommended |
| U | TV878 Remote Control | C7XRCtl.exe | "Related to Kworld TV878 Tuner"
|
| X | tvctray | tvctray.exe | Added by the VB.QJ TROJAN!
|
| ? | Ulead AutoDetector | Monitor.exe | "Related to Ulead Systems Inc. programs. What does it do and is it required?"
|
| ? | Ulead AutoDetector v2 | monitor.exe | "Related to Ulead Systems Inc.. What does it do and is it required?"
|
| U | Ulead Memory Card Detector | Monitor.exe | "Ulead Memory Card Detector - ""Automatically starts datadownload when your card is inserted into a memory card reader"""
|
| X | UPCTPcw | UPCTPcw.exe | "Part of the PcTurboPro rogue system optimization tool - not recommended |
| U | USBDetector | USBDetector.exe | USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
|
| U | USBDetector | UDetect.exe | USB tray icon/detection for external Belkin (and maybe other makes) under Win98
|
| X | User Input Services | CTFMON32.EXE | "Added by the MANCSYN.AK TROJAN!"
|
| X | User Protection | usrprot.exe | "User Protection rogue security software - not recommended |
| U | USIUDF_Eject_Monitor | USISrv.exe | "Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present"
|
| X | VaCtrls | v7 | "Downloader |
| Y | VAGCtrl | VAGCTRL.EXE | "Vexira Antivirus - virus scanner from Central Command"
|
| U | VAIO Action Setup (Server) | VAServ.exe | "Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera |
| X | VB_run | comctl_32.exe | Dubious downloader from densmail.com
|
| U | Veo Velocity Connect | stim11.exe | Support software for the Veo Velocity Connect webcam
|
| X | Vhosts Protection | vhosts.exe | Added by an unidentified WORM or TROJAN!
|
| X | vidctrl | vidctrl.exe | "Delfin Promulgate adware variant"
|
| U | ViewpointPhotosDeviceConnect | FotomatDeviceConnect.exe | "Related to Viewpoint which is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything ""bad"". This will change from what we know in 2006 according to this article. You can remove it via Start -> Settings -> Control Panel -> Add/Remove Programs list..."
|
| X | virtual | winprotect.exe | "Added by the MUGLY.C WORM!"
|
| X | Virus Doctor | Vdoc[random].exe | "Virus Doctor rogue security software - not recommended |
| X | Virus Protect | vrsprtc.exe | "Added by the RBOT-APR WORM!"
|
| X | Virus Protector | [random].exe | "Virus Protector rogue security software - not recommended |
| X | VirusProtect 3.8 | VirusProtect 3.8.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtect 3.9 | VirusProtect 3.9.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtectPro 3.3 | VirusProtectPro 3.3.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtectPro 3.4 | VirusProtectPro 3.4.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtectPro 3.5 | VirusProtectPro 3.5.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtectPro 3.6 | VirusProtectPro 3.6.exe | "VirusProtect Pro rogue security software - not recommended |
| X | VirusProtectPro 3.7 | VirusProtectPro 3.7.exe | "VirusProtect Pro rogue security software - not recommended |
| X | Volcano Security Suite | VS[random characters].exe | "Volcano Security Suite rogue security software - not recommended |
| U | VZRemoteCommander | AvRmtCtr.exe | Related to Sony's VAIO Zone Remote Commander
|
| U | w98Eject | w98Eject.exe | "Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to ""put away"" the ""disk"" before you unplug it from the USB port |
| X | wdskctl | wdskctl.exe | IEPlugin spyware
|
| X | wdwctrl | wdwctrl.exe | "Added by the DLUCA.E TROJAN!"
|
| N | WebCallDirect | WebCallDirect.exe | "WebCallDirect - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| N | wextract_cleanup0 | "advpack.dll | DelNodeRunDLL32 [path] [filename].TMP" |
| N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
|
| X | Wifi Connection | wificon.exe | "Added by the SLENFBOT.AC WORM!"
|
| X | Wifi Connection! | wificonnect.exe | "Added by the IRCBOT.XEL BACKDOOR!"
|
| X | win ctl app | wuctl.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Win Updator Services | ctfnom.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Win32 FireWire Driver | CTHELPER32.EXE | "Added by the WOOTBOT TROJAN!"
|
| X | winactive | WINACTIVE.EXE | "WinActive variant of the LOP.com hijacker"
|
| X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS!
|
| X | winctl | winctl.exe | "Added by the IRCBOT-YI TROJAN!"
|
| X | Wind0ws Sharing | ssprotecter.exe | "Added by the RBOT-AHW WORM!"
|
| X | WinDirectories | tdirs.exe | "Added by the VB-EPB VIRUS!"
|
| X | WinDLL (ctfmonm.exe) | "rundll32.exe ctfmonm.exe | start" |
| X | Windows (random character) | diskcheck.exe | "Added by the SINGU.B TROJAN!"
|
| X | Windows Action | csrs.exe | "Added by the SECCMU-A WORM!"
|
| X | Windows Activate System | syssv.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant
|
| X | Windows Additional Guard | WI[random characters].exe | "Windows Additional Guard rogue security software - not recommended |
| X | Windows ARP Detectionc | nvudlsp.exe | "Added by the AGENT.LMW BACKDOOR!"
|
| X | Windows ARP Detectionc | winlogon.exe | "Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Windows ARP Detectioncx | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Windows Config Connection | msicll.exe | "Added by the RBOT-EXQ WORM!"
|
| X | Windows connection manager | Internet.exe | "Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one |
| X | Windows ControlAd | WinCtlAd.exe | Windupdates adware variant
|
| X | Windows Enterprise Suite | WE[random characters].exe | "Windows Enterprise Suite rogue security software - not recommended |
| X | Windows Event Detection | wecsvc.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Event Section | sntsvc.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows File Protection | winprotect.exe | "Added by the AGOBOT.JB WORM!"
|
| X | Windows Firewall Updater | ctfcom.exe | "Added by the RBOT-GCB WORM!"
|
| X | Windows Helper | wsctnfy.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Hijack Protection | comngr.exe | "Added by the AGENT-FYD TROJAN!"
|
| X | Windows Hijack Protection System | commngr.exe | "Added by a variant of the AGENT-FYD TROJAN!"
|
| X | Windows Instruction Services | winstruct32.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Live Messenger 8.12 | ctfmon.exe | "Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
|
| X | Windows Logical Connection | wcnsvc.exe | "Added by the VIRUT.AO VIRUS!"
|
| N | Windows Media Connect 2 | WMCCFG.exe | "Windows Media Connect from Microsoft - stream digital media files on your computer to digital media receivers (DMRs) that are connected to your home network"
|
| X | Windows Messenger Connect | wmdsvc.exe | "Added by the SLENFBOT.S WORM!"
|
| X | Windows PC Defender | WP[random characters].exe | "Windows PC Defender rogue security software - not recommended |
| X | Windows Protected Storage | npssvc.exe | "Added by the IRCBOT.AUL BACKDOOR!"
|
| X | Windows Protection Suite | WI[random characters].exe | "Windows Protection Suite rogue security software - not recommended |
| X | Windows Protectot | boxide.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Windows Reversed Virus Protection | winrsvp.exe | "Added by the SLENFBOT.HX WORM!"
|
| X | Windows Secure Connection | winsc.exe | "Added by the SDBOT.BTN WORM!"
|
| X | Windows Security Suite | WI[random characters].exe | "Windows Security Suite rogue security software - not recommended |
| X | Windows Service Threads | svcthreading.exe | "Added by the SHEUR.AUM TROJAN!"
|
| X | Windows Service Threads | svcthreads.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Services M7 | ctfmon32.exe | "Added by the AGENT.WOH TROJAN!"
|
| X | Windows Services Tower | svctowers.exe | "Added by the IRCBOT.AGJ BACKDOOR!"
|
| X | Windows Services Tower | svctowing.exe | "Added by the SLENFBOT.LA WORM!"
|
| X | Windows SP4 | directCC.exe | "Added by the RBOT-ACX WORM!"
|
| Y | Windows SteadyState - Session Timer Notify (UI) | SCTUINotify.exe | "Part of Windows SteadyState |
| X | Windows svchost | ctfmon32.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | WINDOWS SYSTEM | ctech.exe | "Added by the MYTOB-KD WORM!"
|
| X | Windows System Defender | WS[random characters].exe | "Windows System Defender rogue security software - not recommended |
| X | Windows System Suite | WS[random characters].exe | "Windows System Suite rogue security software - not recommended |
| X | Windows Tracking Client | ctwsvc.exe | "Added by the AGENT-GMB TROJAN!"
|
| X | Windows Update AutoUpdate Client Product | wuauct.exe | "Added by the AGOBOT.ACL WORM!"
|
| X | Windows Update Firewall System | ctfmoom.exe | "Added by the RBOT-GAN WORM!"
|
| X | Windows Update Firewall System | ctfmom.exe | "Added by the SPYBOT.ANDM WORM!"
|
| X | Windows USB 2.0 Driver | usb2ctrl.exe | "Added by the RBOT-BIW WORM!"
|
| X | windowsupdate | RPC[RANDOM CHARACTERS].exe | "Added by the IRCBOT.B TROJAN!"
|
| X | WindowsUpdateDirect | dupadirect.exe | "Added by the DUPA-C TROJAN!"
|
| X | WindowsXP Module | DirectX3D.exe | "Malware |
| X | Windows_Protect | winsystem.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows_Protect | winregal.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows_Protect | lsas.exe | "Added by the RBOT.ARO WORM!"
|
| X | Windows_Protect | wincontrol32.exe | "Added by the RBOT-ADK WORM!"
|
| X | Window_Protect | winsi32.exe | "Added by a variant of the RBOT WORM!"
|
| U | WINDVDpatch | CTHELPER.EXE | "CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers |
| N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card
|
| N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
|
| X | WinNetDDE | [random characters].exe | "Added by the NETDEPIX.B TROJAN!"
|
| X | WinPatch Protection | winpatch.exe | Added by an unidentified WORM or TROJAN!
|
| X | WinPCDoctor | SysRep.exe | "WinPCDoctor rogue system error and cleaning utility - not recommended |
| X | winprotect | win32.exe | "Added by the MUGLY.E WORM!"
|
| X | winprotect | winprotect.exe | "Added by the SDBOT-SB WORM!"
|
| X | winprotection | ccsrss.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | WinProtector | WinProtector.exe | "WinProtector rogue security software - not recommended |
| X | WinSpywareProtect | WinSpywareProtect.exe | "WinSpywareProtect rogue security software - not recommended |
| X | WinSpywareProtect (ver. 5.1) | WinSpywareProtect.exe | "WinSpywareProtect rogue security software - not recommended |
| U | wintective | wintective.exe | "Wintective logs keystrokes |
| U | WinUpdateProtection | csrss.exe | "EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
|
| X | WinXProtector | WinXProtector.exe | "WinXProtector rogue security software - not recommended |
| X | WinXPService | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""ctf"" sub-folder"
|
| X | win_upd.exe | WINdirect.exe | "Added by the MITGLIEDER.M TROJAN!"
|
| X | win_upd2.exe | WINdirect.exe | "Added by the BEAGLE.AO WORM!"
|
| X | Wireless Conections | WireConnect.exe | "Added by the SDBOT-VF WORM!"
|
| U | Wireless Connection Manager | wirelesscm.exe | "Wireless adapter configuration utility for D-Link's range"
|
| X | Wireless Connections | WIRECONNECT.EXE | "Added by the SDBOT-VM WORM!"
|
| N | WkDetect | WkDetect.exe | Checks for updates to MS Works
|
| N | WordPerfect Office 1215 | Registration.exe | "Corel WordPerfect Office 12 registration wizard"
|
| U | Worm Detector | wd.exe | "Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam"
|
| N | Wpctrl | wpctrlnt.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | Wpctrl | wpctrl95.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | wpctrl95 | wpctrlnt.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | wpctrl95 | wpctrl95.exe | "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens |
| N | WrCtrl | WrCtrl.exe | "Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work |
| X | wsctf.exe | wsctf.exe | "Added by the JAMPORK.E WORM!"
|
| U | X4ALLNL | wdfsctl.exe | "XS4All Webdisk - web space management utility for the Dutch ISP"
|
| X | XP Protection Center | XPProtectionCenter.exe | "XP Protection Center rogue security software - not recommended |
| X | xpprotect | xpdeluxe.exe | "XP Protector Deluxe rogue security software - not recommended |
| U | XTNDConnect PC | XCPCMenu.exe | "XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - 3CmPlm | Autodet.exe | "3Com Palm PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - CasioOrg | CasAgnt.exe | "Casio Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - ErPhn2 | ErTray.exe | "Sony Ericsson IrMC (Infrared Mobile Connectivity) phones and smartphones specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - LtNts4 | NtsAgnt.exe | "(IBM) Lotus Notes 4 specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - MyPalm | MPTray.exe | "Palm OS specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | XTNDConnect PC - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| U | xv_ctrl | v_ctrl.exe | 3dfx Underground Tools - "Gives direct hardware control to your video graphics adapter"
|
| U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures Screensaver
|
| X | Your Protection | urpprot.exe | "Your Protection rogue security software - not recommended |
| U | YSearchProtection | SearchProtection.exe | """Yahoo! Search Protection will alert you if an attempt is made to change your default browser search engine from Yahoo!"""
|
| U | Yumgo's Homepage Protector V1 | YumgoHomepageProtector.exe | "Yumgo's Homepage Protector"
|
| X | [12 random characters] | avifile5.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bootvid4.exe | "IeDriver adware variant"
|
| X | [12 random characters] | browser8.exe | "IeDriver adware variant"
|
| X | [12 random characters] | atitvo32.exe | "IeDriver adware variant"
|
| X | [12 random characters] | autodisc.exe | "IeDriver adware variant"
|
| X | [12 random characters] | cabview1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | advpack1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | batmeter.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bidispl2.exe | "IeDriver adware variant"
|
| X | [12 random characters] | asferror.exe | "IeDriver adware variant"
|
| X | [12 random characters] | catsrvps.exe | "IeDriver adware variant"
|
| X | [12 random characters] | admparse.exe | "IeDriver adware variant"
|
| X | [12 random characters] | audiosrv.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bootvid2.exe | "IeDriver adware variant"
|
| X | [12 random characters] | cmpbk321.exe | "IeDriver adware variant"
|
| X | [12 random characters] | ADPTIF67.exe | "IeDriver adware variant"
|
| X | [12 random characters] | asycfilt.exe | "IeDriver adware variant"
|
| X | [12 random characters] | ati2dvag.exe | "IeDriver adware variant"
|
| X | [12 random characters] | atl91036.exe | "IeDriver adware variant"
|
| X | [12 random characters] | blackbox.exe | "IeDriver adware variant"
|
| X | [12 random characters] | browser5.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bthserv1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | camocx28.exe | "IeDriver adware variant"
|
| X | [12 random characters] | CAMOCX74.exe | "IeDriver adware variant"
|
| X | [12 random characters] | capesnpn.exe | "IeDriver adware variant"
|
| X | [32 random hex numbers] | badware-protector.exe | "Badware Protector rogue security software - not recommended |
| X | [random characters] | securewinload32x.exe | "Added by the OPTIXP-N TROJAN!"
|
| X | [random characters] | rsbmsc.exe | "Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
|
| X | [random characters] | _default[random].pif | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | j[random].exe | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | sv[random].exe | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | yesbron.com | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | systs.exe | "Added by the AGENT-GDC TROJAN!"
|
| X | [random characters] | xvassdf.exe | "Added by the AUTORUN-BAD WORM!"
|
| X | [various names] | _ctcp.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | ActionScr.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | CToolBar.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | defect08.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | WTFCTF.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|