| X | popuppers64 | a64sddd.exe | "Popuppers adware |
| N | PowerDVD | PowerDVD.exe | "Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled |
| N | PP3100b | flatbed.exe | "Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan |
| U | PPHIDPAD | pphidpad.exe | "PenPower Chinese handwriting recognition software"
|
| U | Praize Messenger | itLoad.exe | "Praize IM Christian chat instant messenger"
|
| X | Prcgd | Prcgd.exe | "Added by the AUTORUN-BCJ WORM!"
|
| X | PreInstall Windows | [path] repcale.exe [path] beird.exe | "Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
|
| Y | Preload | Preload.exe | Millenium Multi-Function Keyboard driver
|
| ? | PreloadApp | hphprld.exe | "HP PhotoSmart printers related. What does it do and is it required?"
|
| U | Primax 3D Mouse | 3dmoused.exe | Enables the scroll button on the Primax 3-D Scroll mouse
|
| N | Print Master Event Reminder | PMremind.exe | "Event reminder for calendar dates |
| U | PrivacyKeyboard | PrivacyKeyboard.exe | "PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices |
| N | ProdikeysAutorun | Prodload.exe | "Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured |
| X | ProtocolEventTsk | csrwjd.exe | "Added by the STINX-N TROJAN!"
|
| X | PSGuard | PSGuard.exe | "Variant of the SmitFraud alias FAKEALE-C TROJAN!"
|
| X | PSGuard spyware remover | PSGuard.exe | "Variant of the SmitFraud alias FAKEALE-C TROJAN!"
|
| U | PsMFCard | PsMFCard.exe | "Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue |
| Y | PsPCCard | PsPCCard.EXE | Background Power Saving task found on Toshiba laptops and which handles turning Power Saving ON and OFF on any inserted PC Card (PCMCIA card). Only ever disable if you do not use any power saving or hibernation settings (ie: they are all OFF)
|
| U | PsSound | PsSound.exe | "On a Toshiba laptop. Operates your sound in one of 4 modes |
| Y | QH Live Update Scheduler | UPSCHD.EXE | "Quick Heal Anti-Virus"
|
| U | QUICKCARE | sprtcmd.exe /P QUICKCARE | "Qwest Broadband QuickCare (provided by SupportSoft |
| U | QuickCare2.2 | sprtcmd.exe /P QuickCare2.2 | "Qwest Broadband QuickCare (provided by SupportSoft |
| N | QuickFinder Scheduler | QFSched.exe | Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
|
| N | QuikShield | qkshield.exe | "QuikShield popup blocker - reportedly stealth installed |
| U | razer | razerhid.exe | "Razer gaming mouse/keyboard driver - required if you use the additional features and programmed keys/macros"
|
| U | RCScheduleCheck | RCSCHED.EXE | "Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
|
| X | Real player updater | realupd.exe | "Added by the PARLAY TROJAN!"
|
| X | RealDownload Express | npnzdad.exe | Advertising spyware
|
| X | Realplayer Codec Support | realsched.exe | "Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
|
| N | Realsched | realsched.exe | "Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player |
| U | RealSPEED | RealSPEED.Exe | "RealSPEED - tweaking utility to speed-up your internet connection"
|
| X | realtpsk | realsched.exe | "Chinese originated adware - detected by Panda as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name and this file is located in %System%"
|
| X | RealUpdater | realupd.exe | "Added by the PARLAY or MITGLIEDER.I TROJANS!"
|
| Y | Recguard | recguard.exe | "On HP computers |
| U | Reclusa | razerhid.exe | "Microsoft Reclusa (by Razer) gaming keyboard driver - required if you use the additional features and programmed keys/macros"
|
| X | reg1.reg | vuamgard.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| U | regdefend | regdefend.exe | """RegDefend is a configurable |
| X | RegSrv64D | RegSrv64D.exE | "Added by the WINKO.AO WORM!"
|
| X | Reload | reload.exe | "Added by the LAZAR TROJAN!"
|
| X | Remndr | CsRemnd.exe | CasinoOnline foistware
|
| X | Removed.exe | Removed.exe | GatorCheat - adware downloader
|
| X | Rg2catbd | Rg2catbd.exe | Added by a variant of the BANLOAD family of TROJANS!
|
| ? | ROUTD | ROUTD.exe | "??"
|
| X | run= | RAVMOND.exe | "Added by the LOVGATE-F WORM!"
|
| Y | run= | wswpd.exe | "Used with some models of Panasonic |
| X | rundl332 | math.exe ...pluged.exe | "Added by the DOOMJUICE WORM!"
|
| X | RUNLOAD | l0ad.exe | "PurityScan/Clickspring adware"
|
| X | RUNLOUD | loud.exe | "PurityScan/Clickspring adware"
|
| X | RunSearvices | tread.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
|
| X | Run_cd | Run_cd.exe | "Added by the GHOST.23 TROJAN!"
|
| X | rxres32 | ati2vid.exe | "Added by the RBOT-FL WORM!"
|
| X | Safeguard.exe | Safeguard.exe | "Super Spyware Killer rogue spyware remover - not recommended"
|
| X | Saggwwgg | CVAvwwd.exe | "Added by the LIOTEN.HT WORM!"
|
| U | SaiMfd | SaiMfd.exe | "Saitek MFD File System Driver - associated with the Saitek SST (Saitek Smart Technolgy) configuration software for their game controllers. Create a shortcut and run manually when required"
|
| U | Salmosa | razerhid.exe | "Razer Salmosa gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| U | SATARaid | SATARaid.exe | RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
|
| X | Savasddwq | ffasd.exe | "Added by the SDBOT-SI WORM!"
|
| N | ScrapPad | Scrappad.exe | "ScrapPad allows you to quickly and easily record notes |
| U | SDAutoLiveupdate | LiveUpdateSD.exe | "Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| X | sdchosts32 | vbdd.exe | Added by the RANKY.AG TROJAN!
|
| X | Security iGuard | Security iGuard.exe | "Security iGuard spyware remover - not recommended |
| X | Service Manager | dxsound.exe | "Added by the PROXY-GRIC TROJAN!"
|
| X | Services | winread.exe | "Added by an unidentified VIRUS |
| X | Servicing | hostd.exe | "Added by the SDBOT.BUI WORM!"
|
| X | SESync | sed.exe | "DownloadWare adware"
|
| N | setup | hphprld.exe ....setup.exe | HP DeskJet Setup - printers function normally without it
|
| N | Share-to-Web Namespace Daemon | hpgs2wnd.exe | "Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
|
| X | ShareSearcher | wsusupd.exe | "Added by the ENCLAG-A TROJAN!"
|
| X | shccde | winssled.exe | "Added by the BUZUS.CQMU TROJAN!"
|
| X | Shell Tray Window | ShellTraywnd.exe | "Added by the STULTDOR-A TROJAN!"
|
| X | Shield Security | shield.exe | "Added by the RIZO.A TROJAN!"
|
| X | Showbehind | SHOWBEHIND.EXE | "Advertisement display which can be stopped here"
|
| U | ShowWnd | ShowWnd.exe | "Found on Gateway computers (and maybe others) - see here. ""Showwnd is included with the Chicony keyboard software and is used by the software to stop the keyboard driver's taskbar entry from reappearing. It is not necessary to remove the keyboard software |
| U | SightSpeed | SightSpeed.exe | "SightSpeed Video Chat - ""lets you connect with all your friends and family easily. Make video calls |
| U | SiSRaid | SRaid.exe | "Related to the SIS Raid system from Silicon Integrated Systems"
|
| U | SiSSWLED | sisswled.exe | System Tray utility for SiS 900 network cards
|
| X | sload | sload.exe | "Win SynchroAd adware |
| U | Smart Keyboard | Smartkbd.exe | Netropa Smart Keyboard driver
|
| ? | SmWizard | SmWizard.exe | "SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
|
| N | snp2std | vsnp2std.exe | Digital camera related
|
| ? | snpstd | vsnpstd.exe | "Sonix PC Camera Monitor MFC Application. What does it do and is it required?"
|
| X | SoftStronghold | SoftStronghold.exe | "SoftStronghold rogue security software - not recommended |
| X | Special Firewall Service | avguard.exe | "Added by the NETSKY.G WORM! Note - do not confuse with AntiVir® antivirus which uses the same filename. This one is located in %Windir%"
|
| U | sprtcmd | sprtcmd.exe | "Self-help support tool for a number of high-speed internet providers and computer suppliers such as Comcast |
| U | Spybot-S&D | SpybotSD.exe | "Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck |
| U | SpybotSD | SpybotSD.exe | "Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck |
| U | SpybotSnD | SpybotSD.exe | "Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck |
| X | SpyHazard | SpyHazard.exe | "SpyHazard rogue spyware remover - not recommended |
| X | SpyLocked | SpyLocked.exe | "Spylocked rogue spyware remover - not recommended |
| X | SpyRid | Spy-Rid.exe | "Spy-Rid rogue spyware remover - not recommended"
|
| U | SpyWare Shield | Shield.exe | "Acronis Privacy Expert Spyware Shield prevents spyware and other suspicious programs from being installed on PCs"
|
| X | spywareguard | spywareguard.exe | "Spyware Guard 2008 rogue spyware remover - not recommended |
| X | Spywareguard lptt01 | Spywareguard.exe | "RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Spywareguard ml097e | Spywareguard.exe | "RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | SpywareLocked | SpywareLocked.exe | "Spylocked rogue spyware remover - not recommended |
| X | SpywareQuaked | SpywareQuaked.exe | "SpywareQuake 2.4 rogue spyware remover - not recommended |
| Y | SpywareTerminator | SpywareTerminatorShield.exe | "Spyware Terminator's real-time protection. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| X | sqlpdro | providd.exe | "Added by the AGENT-LXF TROJAN!"
|
| N | SsAAD | SsAAD.exe | "Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable"
|
| N | SsAAD.exe | SsAAD.exe | "Starts Sony's SonicStage CP digital music manager automatically when an ATRAC audio device is connected - such as a Walkman MP3 player or a PlayStation® Portable"
|
| Y | Ssd | Std.exe | "Stealthdisk - file and folder hiding/locking utility"
|
| X | Start aThx Roll | f0mered.exe | "Added by the RBOT.AAV WORM!"
|
| X | Startup Configuration | wztoid.exe | "Added by the RBOT-ASD WORM!"
|
| N | Status Monitor | BrMfcWnd.exe | Brother scanner status monitor - can be started manually
|
| U | Sticky Pad | StickyPad.exe | "Sticky Pad from Green Eclipse. Place sticky notes on your desktop"
|
| X | suck | l0ad.exe | "PurityScan adware"
|
| N | SunJavaUpdateSched | jusched.exe | "Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
|
| X | SunJavaUpdateSched10 | jushed.exe | "Added by the ACKANTTA.F WORM!"
|
| X | SunJavaUpdateSched132 | jschd.exe | "Added by the AUTORUN-AQY WORM!"
|
| X | SunJavaUpdateSched16 | jvshed.exe | "Added by the ACKANTTA.G WORM!"
|
| U | Support.com Scheduler and Command Dispatcher | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| X | Svced | Svced.exe | "Added by the DELF.F TROJAN!"
|
| X | Svshost Update Service | svcbind.exe | "Added by the MYTOB.LH WORM!"
|
| U | SWd | winwd.exe | "PC Security from Tropical Software - ""is the ultimate in computer security |
| N | sXe Injected | sXe Injected.exe | "sXe Injected anti-cheat system client/server for Half-Life server based games that prevents cheat programs being loaded"
|
| X | sysdxvid | sysdxvid.exe | "Added by the DLUCA-S TROJAN!"
|
| X | sysguard | sysguard.exe | "Added by the FAKEAV-KI TROJAN!"
|
| X | sysmod | sysmod.exe | "Added by the SPYBOT-DU WORM!"
|
| X | SysR | sysmd.exe | "Ulubione adult content dialer"
|
| X | SYSTEM | d.exe | "Added by the MYTOB.LP WORM!"
|
| X | System | winupd.exe | "Added by a variant of the SDBOT WORM!"
|
| X | System Document Application | nmod.exe | "Added by the SDBOT-ABB WORM!"
|
| X | System Efficiency Monitor | mscommand.exe | "Added by the KWBOT.P WORM!"
|
| X | System Guard | mhguard.exe | "Added by the RBOT-AGU WORM!"
|
| U | System LifeGuard Scheduler | Slsched.exe | "System LifeGuard scheduler"
|
| U | System Mechanic Startup Guard | StartupGuard.exe | "System Mechanic Startup Guard protects the Window's startup locations from being modified by viruses |
| X | System Net Database | sysnd.exe | "Added by the RBOT-AAW WORM!"
|
| X | System Restore Data | [path] repcale.exe [path] beird.exe | "Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
|
| X | System Setup | rpcxcmod.exe | Added by an unidentified WORM or TROJAN!
|
| X | system tool | sysguard.exe | "Antivirus System Pro rogue security software - not recommended |
| X | system23 | notPad.exe | "Added by the ESTEEMS.D TROJAN!"
|
| X | systemguard | systemguard.exe | "System Guard 2009 rogue security software - not recommended |
| X | SystemMD | md.exe | Homepage hijacker
|
| X | Systems | itDDD.exe | "Added by the DLOADER-PP TROJAN!"
|
| X | SystemTasks | loaded.exe | Adult content dialler
|
| X | SystemTray | Windowsupd.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| N | SystemUpd | SystemUpd.exe | "Updater for Swapoo.com |
| X | SysUpd | Sysupd.exe | "VirtuMonde adware"
|
| N | Tad | tad.exe | From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute
|
| U | TalkTalk | sprtcmd.exe /P TalkTalk | "Self-help support tool for TalkTalk Broadband users (provided by SupportSoft |
| U | Tarantula | razerhid.exe | "Razer Tarantula gaming keyboard driver - required if you use the additional features and programmed keys/macros"
|
| X | Taskschd | TRAYWND.EXE | "Added by the LITMUS.002 TROJAN!"
|
| U | tgcmd | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | tgcmdprovidersbc | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| N | The Assistant | eSched.exe | "Related to WinTotal from a la mode inc. FormFiller for appraisers"
|
| X | The Spy Guard | spyguard.exe | "The SpyGuard rogue spyware remover - not recommended |
| X | TheDefend.exe | TheDefend.exe | "TheDefend rogue security software - not recommended |
| U | THGuard | TH_Guard.exe | "Resident memory scanning for TrojanHunter"
|
| U | THGuard | THGuard.exe | "Resident memory scanning for TrojanHunter"
|
| X | Timer | timed.exe | "Added by the BDOOR-LV BACKDOOR!"
|
| X | tipguard.exe | tipguard.exe | "Privacy Commander rogue privacy program - not recommended |
| N | TkBell.Exe | realsched.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| N | TkBellExe | realsched.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| N | TOSCDSPD | toscdspd.exe | "Related to Toshiba laptop CD/DVD drivers. This is a non-essential process. Disabling or enabling this is down to user preference"
|
| U | TotRecSched | TotRecSched.exe | "Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm"
|
| U | Touch Manager | WinLED.exe | Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
|
| U | TouchED | TouchED.exe | TouchPad On/Off Utility on a Toshiba laptop
|
| U | Transparent | TransparentD.exe | "Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop |
| U | Trashgrd | TRASHGRD.EXE | "Part of McAfee Nuts & Bolts. Protects all the files you delete |
| X | trend | trend.exe | "Added by the BANCOS-AZ TROJAN!"
|
| U | Trojancheck 6 Guard | tcguard.exe | "TrojanCheck anti-trojan software"
|
| U | TrueAssistant | TrueWizard.exe | """TrueSwitch makes changing your Internet Service Provider easy. We copy all your personal data to the new account |
| N | tsnp2std | tsnp2std.exe | Digital camera related
|
| X | TVMD | tvmd.exe | "Total Velocity - ""Secure commerce company that enables the 'checkout' process for our customers in order to safely and securely purchase our award winning software"". Autointsalling spyware"
|
| X | TVTMD | TVTMD.EXE | "Total Velocity variant - autoinstalling spyware"
|
| X | tymsetvc | osskhbd.exe | "Added by the MAILBOT-BW TROJAN!"
|
| U | UD Agent | UD.EXE | The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
|
| X | Uninstall**** | upd.exe | Adult content based screen saver where **** can be any number
|
| X | Universal Plug & Play devices | WinUPPD.exe | Added by an unidentified WORM/TROJAN!
|
| X | upd.exe | upd.exe | "Added by the DELF-AJW BACKDOOR!"
|
| X | Update | Sysupd.exe | Added by the SLACKBOT VIRUS!
|
| X | Update Explorer | iexploreupd.exe | "Added by a variant of the RBOT WORM!"
|
| X | UpdateComponent | CNF UPD.EXE | Added by the SPYBOT.GEN VIRUS!
|
| ? | UpdateFW | fwdload.exe | "Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?"
|
| X | Upgrade Service | winupd.exe | "Added by the TOFGER-U TROJAN!"
|
| Y | UPSentry 2000 | upsd.exe | Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
|
| Y | UPSlim | upsd.exe | Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
|
| X | upxdnd | upxdnd.exe | "Added by the JD-A TROJAN!"
|
| X | Usbd | usb_d.exe | "Added by the CIDRA-A TROJAN!"
|
| U | USBMMKBD | usbmmkbd.exe | USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version no longer pings a server when on-line wheras the older version did but did not transmit any user information
|
| X | VasddwDg | zxXZwd.exe | "Added by the SDBOT-SN WORM!"
|
| X | vcmicrec | msccsed.exe | "Added by the MAILBOT-CE TROJAN!"
|
| N | Verizon Control Pad | cpad.exe | "Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience"
|
| X | VGA Startup | vgacard.exe | "Added by a variant of the RBOT WORM!"
|
| N | vid | Vid.exe | """Logitech Vid is the fast |
| X | Video | explored.exe | "Added by the GAOBOT.RF WORM!"
|
| X | Virtual CD v6 | grplscd.exe | "Added by the RBOT-AXV WORM!"
|
| X | Virus Shield 2009 | VShield.exe | "Virus Shield 2009 rogue security software - not recommended |
| Y | VirusScan Online | mcvsshld.exe | "ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed |
| Y | VrProxyd | vrproxyd.exe | "Part of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal |
| N | vTPass | vtpassld.exe | "Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs |
| X | VxD Driver Initialization | ntsvxd.exe | "Added by the SDBOT-LW WORM!"
|
| N | war-ftpd.exe | WAR-FTPD.EXE | "War FTP Daemon from JGAA's Internet - FTP client"
|
| N | WARSVR | war-ftpd.exe | ""War FTP Daemon - the original free FTP server for windows"""
|
| X | WebSpyShield | WebSpyShield.exe | "WebSpyShield rogue security software - not recommended"
|
| X | Whvlxd | Whvlxd.exe | "Added by the ZAPCHAS-CS TROJAN!"
|
| X | Wifi Loader | wifiload.exe | "Added by the IRCBOT.XEL BACKDOOR!"
|
| N | Willow Road | WillowRoad.exe | Willow Road Screen Saver
|
| X | Win32 Console | cmd.exe | "Added by the ABI.C WORM! Note - this is not the legitimate cmd.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Win32 Debug Manager | microsoftupd.exe | "Added by the RBOT-GRJ WORM!"
|
| X | Win32 Ms Auto Updater | AutomsUPD.exe | "Added by a variant of the RBOT WORM!"
|
| X | Win32 USB2 Driver | sys32snd.exe | "Added by the FORBOT-AN WORM!"
|
| X | win32servv | load.exe | "iSearch adware"
|
| X | WIN3S2SNDS | winabsmod.exe | "Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX"" |
| X | win98 DNS | wingrd.exe | "Added by a variant of the RBOT WORM!"
|
| X | Winad Client | Winad.exe | WinAd adware by eXact Advertising
|
| X | WINAPLOGUPD | WINAPLOGUPD.EXE | "Added by the CAPSIDE-C WORM!"
|
| U | WinBackup Scheduler | Wbsched.exe | "LIUtilities WinBackup scheduler - backup software"
|
| X | Winbed | winbed.exe | Hijacker
|
| X | Wind Logd File | servicelogd.exe | "Added by a variant of the RBOT WORM!"
|
| X | wind.exe | wind.exe | "Added by the MITGLIEDER.BD TROJAN!"
|
| X | Wind0ws | wordpad.exe | "Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the %ProgramFiles%\Accessories folder) which should not normally be seen in Msconfig or as a Startup item. This one is Located in %System%"
|
| X | WinDLL (dlfksdld.exe) | "rundll32.exe dlfksdld.exe | start" |
| X | WinDLL (wchshield.exe) | "rundll32.exe wchshield.exe | start" |
| U | WindowBlinds | wbload.exe | "WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
|
| U | WindowFX | wfxload.exe | "Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
|
| X | Windows applications server | SysShield.exe | "Added by the unregistered version of Personal Anti Malware rogue security software - not recommended |
| X | Windows Audio | snd.exe | "Added by the ACKANTTA.C WORM!"
|
| X | Windows Command | wincmd.exe | "Added by the RBOT.ANV WORM!"
|
| X | Windows ControlAd | WinCtlAd.exe | Windupdates adware variant
|
| X | Windows DNS Daemon | windnsd.exe | "Added by the WOOTBOT.AS WORM!"
|
| X | Windows firewall manager | msguard.exe | "Added by a variant of the RANDEX.GEL WORM!"
|
| X | Windows Guard | WAUMGRD.EXE | "Added by the RBOT-GY WORM!"
|
| X | Windows JavaScript Daemon | Winjsd.exe | "Added by the WOOTBOT.AF WORM!"
|
| X | Windows Keyboard Services | winkeyboard.exe | "Added by the IRCBOT.AFS WORM!"
|
| X | Windows Keyboard Services | winkeybrd.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Live Messenger | msnd.exe | "Added by the BCKDR-QQQ BACKDOOR!"
|
| X | Windows logging | winlogd.exe | "Added by the RBOT-ON WORM!"
|
| X | Windows Login | explored.exe | "Added by the GAOBOT.SY WORM!"
|
| X | Windows Management Instrumentation | mwd.exe | "Added by the GRAPS WORM!"
|
| X | Windows Media Player 3.6d | wmpa36d.exe | "Added by the RBOT-YA WORM!"
|
| X | Windows mod Verifier | Windows-mod.exe | "Added by the RBOT.DSU WORM!"
|
| X | Windows modez Verifier | Wwuamguard.exe | "Added by the RBOT.EZJ WORM!"
|
| X | Windows modez Verifier | wuamguard.exe | "Added by the RBOT.EZJ BACKDOOR!"
|
| X | Windows NetStart Service2 | winsN2SD.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Network Controller | Mqguard.exe | "Added by the FORBOT-CL WORM!"
|
| X | Windows Network Controller | WinxPupd.exe | "Added by the FORBOT-DK WORM!"
|
| X | Windows Performance Monitor | wmscupd.exe | "Added by the IRCBOT_GEN WORM!"
|
| X | Windows Relay Service | ipcbind.exe | "Added by the DELFINJECT.F TROJAN!"
|
| X | Windows Secure Update | load.exe | "Added by the FORBOT-GU WORM!"
|
| X | WINDOWS SECURITY | wingrd.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows ServeAd | WinServAd.exe | Windupdates adware variant
|
| X | Windows service | wuamgrd.exe | "Added by the RBOT-QW WORM!"
|
| X | Windows Service | dddd.exe | "Detected by Kaspersky as Dialer.Salc |
| X | Windows Service Agent | tjybssd.exe | "Added by the RBOT.XVD BACKDOOR!"
|
| X | Windows Service Agent 32 | mrthd.exe | "Added by the AGENT-GAQ TROJAN!"
|
| X | Windows Sound Manager | sound.exe | "Added by the AGOBOT-CD WORM!"
|
| X | Windows Subsys | winload.exe | "Added by the NETSPREE.C WORM!"
|
| X | Windows SyncroAd | SyncroAd.exe | Windupdates adware variant
|
| X | WINDOWS SYSTEM FILE | winload.exe | "Added by the MYTOB.DK WORM!"
|
| X | Windows TaskAd | Wintaskad.exe | Windupdates adware variant
|
| X | Windows UDP Control Center | ehSched.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows UDP Control Center | msnpd.exe | "Added by the SDBOT.EBA BACKDOOR!"
|
| X | Windows Update | Wuamgrd.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Update | winmguard.exe | "Added by the RBOT-EM WORM!"
|
| X | Windows Update | wuampd.exe | "Added by the RBOT.UM WORM!"
|
| X | Windows Update | Winload.exe | "Added by the DEDMIR-A WORM!"
|
| X | Windows Update | explored.exe | "Added by the GAOBOT.MF WORM!"
|
| X | Windows USB Printer | unqgod.exe | "Added by the RBOT.BKC BACKDOOR!"
|
| X | Windows Xp | nortonguard.exe | "Added by the MYTOB-DZ WORM!"
|
| X | WindowsAudio | systemupd.exe | "Added by the AGENT-TH WORM!"
|
| X | WindowsUpdate | Strad.exe | "Added by the CULLER-D WORM!"
|
| X | WindowsXP Module | DirectX3D.exe | "Malware |
| X | WinEssential | keyword.exe | "Jraun adware"
|
| X | WinGuard | winguard.exe | "Added by the AGOBOT-OQ WORM! The file is located in %System%"
|
| U | WinGuard | Winguard.exe | "Winguard Popup Remover - pop-up stopper. The file is located in %ProgramFiles%\Winguard Popup Remover"
|
| X | WinHelp | realsched.exe | "Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
|
| X | WinHound | WinHound.exe | "WinHound spyware remover - not recommended |
| X | WiniGuard | WiniGuard.exe | "WiniGuard rogue security software - not recommended. There are number of variants in this family sharing the same user interface - see here"
|
| X | wininetd | wininetd.exe | "Added by the WINET TROJAN!"
|
| X | WiniShield | WiniShield.exe | "WiniShield rogue security software - not recommended |
| U | WinLoad | Winload.exe | "PCTattletale is a surveillance software program that monitors user activity |
| X | winload | winload.exe | "Added by the AGENT-GNY TROJAN! Note - the file is located in %ProgramFiles%\Internet Explorer"
|
| X | WinLogonnd | winlogonnd.exe | "Added by the AGENT-NNQ TROJAN!"
|
| X | WinMed | winmed.exe | "Added by the AGENT.AIRF TROJAN!"
|
| X | winNT updatc | wupgrd.exe | "Added by a variant of the RBOT WORM!"
|
| X | WinProfile | Command.exe | "Added by the BUDDY.E TROJAN!"
|
| X | winpsd | winpsd.exe | "Added by the MYDOOM.Q WORM!"
|
| X | winrapid | winrapid.exe | "Added by a variant of the RBOT WORM!"
|
| X | WinReader | read.exe | "Added by the DELBOT-V WORM!"
|
| X | Winsock2 driver | WINSOUND.EXE | "Added by the SPYBOT-H WORM!"
|
| X | Winsock6 MIC driver | ieservicesupd.exe | "Added by the SPYBOT.AFZ WORM!"
|
| N | Wintime Wtxpload | Wxpload.exe Wintime | "Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet |
| X | Wintl | msdred.exe | Identified as a variant of the Trojan-Spy.Win32.Agent.cch malware
|
| X | winupated.exe | winupated.exe | "Added by a variant of the SDBOT WORM!"
|
| X | winupd | winupd.exe | "SearchNew adware"
|
| X | winupd.exe | winupd.exe | "Added by the BEAGLE.M or BEAGLE.N WORMS!"
|
| X | winupdate | jusched.exe | "Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
|
| X | WinUPPD.exe | [random filename] | Added by an unidentified WORM/TROJAN!
|
| X | winusb.dll | winguard.exe | "Added by the FORBOT-CN WORM!"
|
| X | winword | winword.exe | "Added by the TORPID-C TROJAN!"
|
| X | WINWORD.exe | WINWORD.exe | "Added by the DRIVUS TROJAN! Note - this is not the legitimate MS Word process of the same name |
| X | win_upd.exe | WINdirect.exe | "Added by the MITGLIEDER.M TROJAN!"
|
| N | wkfud | wkfud.exe | A marketing program for MS Works
|
| N | WkUFind | WkUFind.exe | "MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet |
| X | WLiveCD.exe | WLiveCD.exe | "Added by the VB-EQI TROJAN!"
|
| X | wmon | jusched.exe | "Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
|
| X | WMSDOS-ServicePack2 | cmd.exe /c C:WMSDOS.sys | "Detected by Bitdefender as the DELF.OFC TROJAN! See here. Note that cmd.exe is a legitimate Microsoft file normally located in %System% and shouldn't be deleted"
|
| X | WNAD | WNAD.EXE | "Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system |
| X | Woods Inc | wcmd.exe | "Added by the KILLFIL-O TROJAN!"
|
| N | WorksFUD | wkfud.exe | A marketing program for MS Works
|
| U | Worm Detector | wd.exe | "Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam"
|
| X | wqdfadads | sdqdad.exe | "Added by the MULDROP.F TROJAN!"
|
| X | WSAConfiguration | win32upd.exe | "Added by a variant of the RBOT WORM!"
|
| Y | wswpd | wswpd.exe | "Used with some models of Panasonic |
| U | WTIndicator | SchedInd.exe | "WinTask - software that automates a variety of routine tasks quickly and simply"
|
| X | wupd32 | wupd.exe | "Added by the STRATION.EL WORM!"
|
| X | wzxzxds | fdfddad.exe | "Added by the RANKY.AB TROJAN!"
|
| N | X-Grabber | sswizard.exe | "ScreenShot Wizard"
|
| ? | XeroxEndeavorBackgroundTask | xGKOHbgnd.exe | "Associated with a Xerox multifunction and/or scanner. What does it do and is it required?"
|
| X | xload32 | netdd.exe | "Added by the NETSPY TROJAN!"
|
| X | XPGuard | XP-Guard.exe | "XP-Guard rogue security software - not recommended |
| X | XPShield | XP-Shield.exe | "XP-Shield rogue security software - not recommended |
| N | Yahoo! Friend | YahooFriend.exe | "Yahoo!_Friend - plug-in for Yahoo! Messenger that add lots of emoticons and windows effects"
|
| X | ynavmrcd.exe | ynavmrcd.exe | "Added by the DLOADR-AVC TROJAN!"
|
| U | Zboard | Zboard.exe | "Ideazon Zboard gaming software"
|
| X | zggjmyd | zggjmyd.exe | "Added by the AFCORE.O BACKDOOR!"
|
| Y | ZPLED | ZPKBDLED.exe | Driver for the Advent ADE-AD2 Wireless Keyboard
|
| U | zSPGuard | Spguard.exe | ""StartPage Guard (SPG) protects your PC from cyberscam |
| X | [random name] | w?crtupd.exe | "PurityScan adware"
|
| X | [random name] | n?tepad.exe | "PurityScan adware"
|
| X | [random name] | w?nword.exe | "PurityScan adware"
|
| X | [random name] | wucrtupd.exe | "PurityScan adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) process"
|
| X | [random name] | notepad.exe | "PurityScan adware. Note - this is not Windows Notepad which has the same executable name"
|
| X | [random] | [random]tssd.exe | "Antivirus Suite and AntiSpyware Soft rogue security software - not recommended |
| X | [random] | [random]sysguard.exe | "Antivirus Soft |
| X | [various names] | win32snd.exe | "Added by the RBOT-DQ WORM!"
|
| X | [various names] | AliceSD.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | backd.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | DCC_send.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | newbreed.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _ | mzqdd.exe | "Added by the AGENT.BZB TROJAN!"
|
| X | {**-**-**-**-**} | rwwnw64d.exe | "Identified as a variant of the AdWare.Win32.ZenoSearch.am malware |
| X | {05CD0D77-4947-4a56-94FA-0DF0DC644D7B} | sysqyzwud.exe | "Added by the FAKEALERT-AM TROJAN!"
|
| X | {BAAA759D-56F0-428c-B8DA-827EA3B08C2C} | sysawechod.exe | "Added by the FAKEALERT-AH TROJAN!"
|