| X | DASDS VSAVdjs | dsabdw.exe | "Added by the SDBOT-RE WORM!"
|
| X | daskaskfsak6 | dsfids6.exe | "Added by the ONLINEG-J TROJAN!"
|
| X | daskgfkkcx15 | dasdsaads15.exe | "Added by the ONLINEG-Q TROJAN!"
|
| X | dasxdads | fsdqd.exe | "Added by the GAOBOT.BIQ WORM!"
|
| U | DellSupport | DSAgnt.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | DeskAd Service | DeskAdServ.exe | "DeskAd.Service adware"
|
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | Disk Check | chkdsk32.exe | "Added by the IM TROJAN!"
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| X | djdsdvqwa | vjdhdg.exe | "Added by the SDBOT-EF BACKDOOR!"
|
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| N | DrgToDsc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| X | Drmupgds | Drmupgds.exe | "Maxfiles adware"
|
| X | DropSpam Lifestyle | dslifestyle.exe | "Dropspam adware"
|
| X | ds | ds.exe | "Added by the SPYMON TROJAN!"
|
| U | DS Clock | dsclock.exe | "Digital desktop clock including synchronization with atomic servers - see here"
|
| X | dS35DLL | ffqca.exe | "Added by the SDBOT-KV WORM!"
|
| X | dsa | dsa.exe | Homepage hijacker - redirecting to downseek.com
|
| X | DSAcass | [path to file] | "Added by the RANKY.M TROJAN!"
|
| X | dsadlsa14 | dsakfsak14.exe | "Added by the ONLINEG-P TROJAN!"
|
| X | DSB | DSB.exe | "EnergyPlugin adware"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | dsd | zz.exe | "Added by the RBOT-FOX WORM!"
|
| N | DSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| X | dsfghjgj | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | dsgb | lcsass.exe | "Added by the AGENT.TGZ BACKDOOR!"
|
| X | Dsi | dp-******.exe | Added by an unidentified adware where ****** are random characters
|
| X | Dsi | dp-him.exe | "Added by the MULTIDR-AH TROJAN!"
|
| X | Dskcompat | Dskcompat.exe | "Added by the GEMA TROJAN!"
|
| U | DSKEY | DsKey.exe | "Part of PC PhoneHome - ""secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection"". Security software from Brigadoon Security Group for tracking down lost/stolen computers"
|
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| Y | DSLagentexe | DSLagent.exe | "Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
|
| Y | dslmon | dslmon.exe | Sagem DSL modem related. Apparently needed to detect the modem
|
| U | DSLSTATEXE | dslstat.exe | System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
|
| X | DsmSer | dsm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | svosm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | sysup.exe | "Added by the SERFLOG.B WORM!"
|
| Y | DSndUp | DSndUp.exe | "Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | DSS | dssagent.exe | "Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| X | DSService | dmrss.exe | "Added by the AGOBOT-XX WORM!"
|
| ? | DSSSGENS | dssagens.exe | "??"
|
| X | dstiosys | plsitctl.exe | "Added by the MAILBOT-BX TROJAN!"
|
| X | DSystemDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| N | DVDSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| ? | ESSNDSYS | ESSNDSYS.EXE | "Related to an ESS based soundacard. Is it required?"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | ffeqfqs | dqddss.exe | "Added by the SDBOT-SG WORM!"
|
| X | fjdslssdfd | mat2.exe | "Added by the SLAPEW.C TROJAN!"
|
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| X | fsdsft | [path to backdoor] | "Added by the RANKY.S BACKDOOR!"
|
| X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
|
| ? | GrdSys32 | GrdSys32.exe | "X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
|
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GsAds | gms2.exe | "PacerD_Media/Pacimedia.com adware"
|
| N | Hard Disk Sentinel | HDSentinel.exe | "Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find |
| X | HELPER | Netherlands.exe | "AsdPlug premium rate adult content dialer variant"
|
| U | hidserv | hidserv.exe | "This is the Human Interface Device Server for Win98SE/2000/Me/XP |
| X | HOT FIX | windsys2.exe | "Added by the AGOBOT.AOI BACKDOOR!"
|
| U | HotKeysCmds | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | HotKeysCmds | [path to worm] | "Added by the PAHATIA-A WORM!"
|
| ? | HP IDScheduler | HPIDSCHD.exe | "HP Instant Delivery Scheduler"
|
| N | HP JetDiscovery | HPJETDSC.EXE | HP JetAdmin software which monitors printing jobs on a network environment
|
| X | HP Service Drivers | hdsys.exe | "Added by the SDBOT-ZE WORM!"
|
| X | hxadsec | [path to trojan] | "Added by the ADCLICK-AP TROJAN!"
|
| X | IE-Security | wdscan.exe | "IE-Security rogue spyware remover - not recommended |
| X | Intec Service Drivers | msmsgredss.exe | "Added by the SDBOT-AGL WORM!"
|
| U | Intel PDS | pds.exe | Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
|
| X | InterceptedSystem | [path to worm] | "Added by the ANACON-B WORM!"
|
| X | InternetGetConnectedState | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetGetConnectedStateEx | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | iPod USB Service | iPODService.exe | "Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service |
| X | ItalU | italfds.exe | "Added by a TROJAN - see here"
|
| Y | JetAdmin Discovery Indicator | HPJETDSC.EXE | "HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry |
| Y | JMB36X Configure | JMRaidSetup.exe | "JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
|
| U | KBD | KbdStub.EXE | Key Watcher from HP - watches for Multimedia Keys on HP keyboards
|
| U | LCD Smartie | LCDSmartie.exe | """LCD Smartie is software for Windows that you can use to show lots of different types of information on your LCD/VFD."" Typically used by the PC modding community to display statistics such as CPU temp |
| U | LgWDskTp | LgWDskTp.exe | "Logitech Wireless Desktop mouse and keyboard software. There is an icon for this program on the taskbar next to the clock"
|
| X | loads.exe | loads.exe | "MediaMotor adware"
|
| X | loads.exe | medload.exe | "Medload adware"
|
| X | loads.exe | suploads.exe | "Added by the AGENT-BZ TROJAN!"
|
| X | LoadService | Rest In Peace | "Added by the KANGAROO-A WORM!"
|
| X | LoadService | "Maaf | tempatmu bukan di sin" |
| X | LoadService | Virus | "Added by the CAGER.A WORM!"
|
| X | LoadSIPS | "rundll32.exe SIPSPI32.dll | SIPSPI32" |
| U | MagicDsk | MAGICDSK.EXE | Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
|
| X | MainDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MalwaresWipeds | MalwareWipeds.exe | "MalwareWipe rogue security software variant - not recommended |
| X | MalwareWipeds | MalwareWipeds.exe | "MalwareWipe rogue security software variant - not recommended |
| N | Mass storage check registry | "rundll32.exe MSDServ.dll | check registry" |
| X | mds.exe | mds.exe | "Added by the MADS-A TROJAN!"
|
| U | MDSA Sentinel X | smss.exe | "SentinelX surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the smss.exe process which is always located in %System%. This one is located in %ProgramFiles%\MDSA Software"
|
| X | MediaLoads | dw.exe | "Medialoads adware"
|
| X | MediaLoads Installer | dw.exe | "Medialoads adware"
|
| X | MicroedSoft Toolbar | Smoked.exe | "Added by the RBOT-ALN WORM!"
|
| X | Microsoft ADservice | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Agent | mdss32.exe | "Added by the KEYLOG-AG TROJAN!"
|
| X | Microsoft DirectX | PDSched.exe | "Added by the SDBOT.CN WORM!"
|
| X | Microsoft Helpdesk Side | mshelpdsk.exe | "Added by the SPYBOT.ANJJ WORM!"
|
| X | Microsoft Inet Xp.. | teekids.exe | "Added by the BLASTER.C WORM!"
|
| X | Microsoft Intrenet Explorer | Soundsyst.exe | "Added by the RBOT-AQU WORM!"
|
| X | Microsoft Sounds | soundman.exe | "Added by the RBOT-GCI WORM!"
|
| X | MicroSoft ssadsadas3s1 | eXtream.exe | "Added by the SPYBOT.ZK TROJAN!"
|
| X | MicroSoft ssadssjdhasjadas3s1 | kdjfsdklfjsl.exe | "Added by the SDBOT.AEX WORM!"
|
| X | Microsoft Update Emulator | wuaddsff.exe | "Added by the RBOT-GX WORM!"
|
| X | Microsoft Updater | wuamgrds.exe | "Added by the RBOT.A WORM!"
|
| X | Microsoft Updates Resources | WinFixIDs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updating | wuamguards.exe | "Added by the RBOT-BY WORM!"
|
| X | MicroSoft Visual SP | igxdfdfds.com | "Added by the SDBOT.GAV WORM!"
|
| X | Microsoft Windows 2000 | Winupdsdgm.exe | "Added by the GAOBOT.AO WORM!"
|
| X | Microsoft Windows DLL Services Configuration | winDSL.exe | "Added by the SDBOT-ZG WORM!"
|
| X | Microsoftkeysds | lass32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microst dds service | wsrss.exe | Added by an unidentified WORM or TROJAN!
|
| U | MilShieldSlave | ShieldWorker.exe | "Mil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities"
|
| X | MotherBoard Sounds | Sounds.exe | "Added by the RBOT-AAP WORM!"
|
| X | MP3freeDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | mppdds | mppdds.exe | "Added by the PWS-AKZ TROJAN!"
|
| X | mppds | mppds.exe | "LEGMIR.AQZ spyware"
|
| X | mqadscp3 | mqadscp3.exe | "Added by the STRATION.CX WORM!"
|
| X | MSN Update Service | msnupdsv.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| U | MSRegScan | DDSSDemo.exe | "SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
|
| X | mstds.exe | mstds.exe | "Added by the IPTABLES TROJAN!"
|
| X | mstsdsc.exe | mstsdsc.exe | "Added by the CIMUZ-CD TROJAN!"
|
| X | MSUpdSrv | msupdsrv.exe | "Browser hijacker |
| X | MyLife | CmdServ.exe | "Added by the HOLAR.A WORM!"
|
| X | NavAgent32 | SCardSvr32.Exe | "Added by the MOFEI.B WORM!"
|
| U | NDSTray | NDSTray.exe | "ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required |
| U | NDSTray.exe | NDSTray.exe | "ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required |
| X | NewDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | NiceDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | NoAds | NoAds.exe | Blocks advertisement banners in Internet Explorer
|
| X | Nord | nordsys.exe | "Added by the DREF-S WORM!"
|
| X | NT Printing Service | chkdsks.exe | "Added by the ARCHIVARIUS series of WORMS!"
|
| X | NT Printing Service | chkdskss.exe | "Added by the ARCHIVARIUS series of WORMS!"
|
| X | NT Printing Services | chkdsks.exe | "Added by the BUZUS-M TROJAN!"
|
| X | ntvdscm | ntvdscm.exe | "Added by the SCKEYLOG-I TROJAN!"
|
| U | NVIDIA® NVRAID | nvraidservice.exe | "Part of NVIDIA® MediaShield Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
|
| U | NVRaidService | nvraidservice.exe | "Part of NVIDIA® MediaShield Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
|
| U | ODSPConfig | ODSPConfig.exe | "DsktopSurveil surveillance software. Uninstall this software if you did not install it yourself"
|
| U | On screen display | TPOSDSVC.exe | "Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example |
| N | OptusNet Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | PC SpeedScan Pro | PCSpeedScan.exe | "Ascentive PC SpeedScan Pro registry optimizer - not recommended |
| U | PC Tools Disk Suite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| N | pdservice | pdservice.exe | "Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers |
| N | PDService.exe | pdservice.exe | "Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers |
| U | PDVDServ | PDVDServ.exe | "Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control |
| X | Personal Firwall | ptmedsrv.exe | "Added by the SDBOT.XY WORM!"
|
| X | Preview AdService | PrevAdServ.exe | Windupdates adware variant
|
| N | PrivateDisk | pdservice.exe | "Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers |
| X | PROCESS SESSION MANAGER | PIDSERV.EXE | "Added by the RBOT-Y WORM!"
|
| ? | Prodigy DSL | EnterNetDUN.Exe | "Prodigy EnterNet DUN PPPoE Client - is it required?"
|
| N | ProDsl | ProDsl.exe | Intel Pro/DSL 2100 modem connection manager. Available via Start -> Programs
|
| X | qaswww | jdsuml.exe | "Added by the BUZUS.CQMU TROJAN!"
|
| Y | QCDriverInstaller | Lqdsw.exe | "Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart |
| N | QD FastAndSafe | QDCSFS.exe | Automatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
|
| ? | Qdsafe | ?? | "??"
|
| U | Randsoft Harmony '98 | rsMenu.exe | "Randsoft Harmony '98 (superseded by Enterprise Harmony 99) for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | rCron | dservice.exe | """Switch"" premium rate adult content dialler variant"
|
| U | RemoteControl | PDVDServ.exe | "Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control |
| X | rollbk | dsm.exe | "Added by the SERFLOG.B WORM!"
|
| N | RoxioDragToDisc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| N | Sa3dsrv | Sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled
|
| X | sacmemds | smcntlwio.exe | "Added by the MAILBOT-BZ TROJAN!"
|
| X | Santa Bastards Bitch | SANTAS.BITCH.txt | "Added by the ATNAS.A WORM!"
|
| X | scands32.exe | scands32.exe | "Added by a variant of the ADCLICKER TROJAN!"
|
| X | Scandsk2 | scandsk2.exe | "Added by the AGOBOT-PK WORM!"
|
| X | scandskx.exe | scandskx.exe | "Added by the DLOADR-ARM TROJAN!"
|
| N | SCardSvr | scardsvr.exe | Related to SmartCard readers and sometimes uses lots of system resources
|
| X | SCardSvr | SCardSvr32.Exe | "Added by the MOFEI.B WORM!"
|
| X | SDKCprords | SDKc55rezzz.exe | "Added by the RBOT.VD WORM!"
|
| U | sds20 | svchost.exe | "InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
|
| X | SdScans** | stup_tmp.#32 | "Added by the SDSCAN.A TROJAN - where ** are random upper case letters"
|
| X | Serv-U | wssdsu.exe | "Added by the MANIFEST TROJAN!"
|
| Y | Sharing and Mapping Software | DShmap.exe | "Intel AnyPoint internet sharing software. Now discontinued"
|
| X | Shell | Explorer.exe kbdsys.exe | "Added by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""kbdsys.exe"" file is located in %AppData%\Microsoft\Keyboard"
|
| X | ShieldSafeness | ShieldSafeness.exe | "ShieldSafeness rogue security software - not recommended |
| N | SIDEBAR | dsidebar.exe | """Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"""
|
| X | Sistema de Comm | coxdsyrtl.exe | "Added by the AGENT-NDQ TROJAN!"
|
| X | SmallAndSecure | mssecure.exe | "Added by the RBOT.CU WORM!"
|
| N | Smart Card Service | ScardSvr.exe | "For Smart Card readers. Known to cause problems |
| X | Sndsaver | Sndsaver.exe | "Added by the GEMA TROJAN!"
|
| ? | sndsrvc | SNDSRVC.EXE | "Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required?"
|
| X | spa_start | Rundll32.exe spads.dll | "IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""spads.dll"" file is located in the Winnt or Windows folder"
|
| X | spa_start | Rundll32.exe sprt_ads.dll | "Superiorads adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""sprt_ads.dll"" file is located in %System%"
|
| N | Spdstart | Spdstart.exe | "Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications |
| U | SpeedswitchXP | SpeedswitchXP.exe | "SpeedswitchXP is a CPU frequency control for notebooks running Windows XP"
|
| Y | SpkrCnfg | DSndUp.exe | "Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
|
| U | Sprint DSL virtual assistant | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| X | Start Upping | windupds.exe | "Added by the SDBOT.AFH WORM!"
|
| X | StartupBin | iwnujdss.exe | "Added by the SDBOT-XZ WORM!"
|
| X | StartupOption | loadsysdisk.exe | "Added by the HIDAGENT-B WORM!"
|
| X | statloads | pgjd83sa.exe | "Added by the SDBOT-UM WORM!"
|
| Y | STDSB | STDSB.exe | "Scrollbar driver for notebooks. If taken out of the Startup |
| X | Sts | iwnujdss2.exe | "Added by the SDBOT-YI WORM!"
|
| N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required
|
| X | svhost1 | mdsn.exe | "Added by the VB-EPK TROJAN!"
|
| ? | SXGDSENU | sxgdsenu.exe | "Yamaha SXG soundcard driver"
|
| U | Sync Data | Hndsync.exe | "Pocket Real Estate - mobile synchronization manager"
|
| X | SyncMon | adslcomdos.exe | "Added by the CLUNKY-A TROJAN!"
|
| X | Sysmppcvppp | SysTdSvr.dll | "Generic2.PQG adware"
|
| X | system xp | acdsee demo.exe | "Added by the SALGA.A WORM!"
|
| X | System32 | winds32.exe | "Added by the DWNLDR-HFY TROJAN!"
|
| U | SystemTraySD | SDSystemTray.exe | "Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
|
| N | T-DSL SpeedMgr | speedmgr.exe | T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically
|
| X | Task Scheduler Engine | schedsvc32.exe | "Added by the RBOT-ASJ WORM!"
|
| U | TDS3 | TDS-3.exe | "DiamondCS TDS-3 antitrojan. Can be used to scan on demand |
| ? | TDspOff | Tdspoff.exe | "Found on a Toshiba laptop"
|
| N | TgAddServer | tgfix.exe | "Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast |
| U | TIxDSL | tidslmon.exe | Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs
|
| N | TOSCDSPD | toscdspd.exe | "Related to Toshiba laptop CD/DVD drivers. This is a non-essential process. Disabling or enabling this is down to user preference"
|
| U | TPHOTKEY | TPOSDSVC.exe | "Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example |
| U | TPOSDSVC | TPOSDSVC.exe | "Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example |
| U | TPOSDSVC.exe | TPOSDSVC.exe | "Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example |
| N | TwkSCardSrv | SCardS32.Exe | Used with Towitoko SmartCard Readers for card recognition
|
| X | Updater | adservernow.exe | "AdServerNow adware"
|
| X | UpdSys | [random filename] | Added by the BJ TROJAN!
|
| X | UtilitiesAndSoftware | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | VelocidadSimple | scrmain.exe | VelocidadSimple rogue optimization utility - not recommended
|
| N | VidSvr | vidsvr.exe | MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
|
| X | vXCXssdss | [path to trojan] | "Added by the RANCK-BO TROJAN!"
|
| X | wdskctl | wdskctl.exe | IEPlugin spyware
|
| U | WDSmartWare | WDSmartWare.exe | "Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range"
|
| X | wersds | doriot.exe | "Added by the JECT.C TROJAN!"
|
| X | wersds.exe | doriot.exe | "Added by the BAGLEDI-A TROJAN!"
|
| X | WIN32DS | clienttimer.exe | "Eziin adware"
|
| X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN!
|
| X | WIN3S2SNDS | winabsmod.exe | "Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX"" |
| X | WIN3S2SNDS | winiprtx.exe | "Added by the AGENT.DN TROJAN - known to BOClean as ""CWS/INDEX"" |
| U | WindowBlinds | wbload.exe | "WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins"
|
| X | Windowfdgfds DasdLL Verifier | winupdatr.exe | "Added by the AGOBOT.HZ WORM!"
|
| X | Windowfdgfds DasdLL Verifiew | [path to worm] | "Added by the RBOT-GGX WORM!"
|
| X | Windowfdgfds DLL fgfdg Verifier | Windowsdldfglcheckkk.exe | "Added by the RBOT.CSP WORM!"
|
| X | Windowfdgfds DLL fgfdg Verifier | winsecure.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows AdService | WinAdServ.exe | Windupdates adware variant
|
| X | Windows AdStatus | WinStat.exe | "Added by the BLESHARE!DR VIRUS!"
|
| X | Windows Audio Startup | nndsvc.exe | "Added by the IRCBOT-AAE TROJAN!"
|
| X | Windows Audio System | nndsvc.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Automation | msdspr.exe | "Added by the SOLAME.A WORM!"
|
| X | Windows Defender Adds | wda*.exe | "Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
|
| X | Windows Messenger Connect | wmdsvc.exe | "Added by the SLENFBOT.S WORM!"
|
| U | Windows Mobile-based device management | wmdSync.exe | "Part of Windows Mobile Device Center in Vista. Microsoft Windows Mobile Device Center enables you to set up new partnerships |
| X | Windows Reg Services | dservice.exe | "Added by the PRORAT-D TROJAN!"
|
| X | Windows Security Update | ndsass.exe | "Added by the RBOT.ESM BACKDOOR!"
|
| X | Windows Service | dstart4.exe | Added by an unidentified TROJAN!
|
| X | Windows Service Agent | dsass.exe | "Added by the RBOT.MIRCO.BNG WORM!"
|
| X | Windows Service Agent | winupds32.exe | "Added by the RBOT-GQT WORM!"
|
| X | Windows Service Threads | svcthreading.exe | "Added by the SHEUR.AUM TROJAN!"
|
| X | Windows Service Threads | svcthreads.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | WINDOWS SYSTEM Dns | windsns.exe | "Added by the MYTOB.EY WORM!"
|
| X | Windows System Update Tools | upds.exe | "Added by the VANBOT.CX BACKDOOR!"
|
| X | Windows UDP Control | winudspm.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Updater | sdsys.exe | "Added by the FORBOT-JG WORM!"
|
| X | WindowsProtocolLog | lsadst.exe | "Added by the NANINF.C TROJAN!"
|
| X | Winds Sers Agts | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Winds Sersc Agts | rzrzncrtz.exe | "Added by the RBOT-GTV WORM!"
|
| U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
|
| ? | WinDSL_MTU | WinDSL_MTU.exe | "May be realted to Tiscali broadband |
| X | WinDSNX | Win****.exe [* = random char] | "Added by the DSNX TROJAN!"
|
| U | Windstream Broadband Check-up Center | matcli.exe | "Part of the Windstream Broadband service from AllTel. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| X | WinUpdate | updsys.exe | "Added by a variant of the RBOT WORM!"
|
| X | WinUpdsv | winupdsv.exe | "Added by the DROPO MACRO!"
|
| X | Woods Inc | wcmd.exe | "Added by the KILLFIL-O TROJAN!"
|
| X | Words | Words.exe | "Added by the AGENT.GIT TROJAN!"
|
| X | wpds.exe | doriot.exe | "Added by the SMALL-KY TROJAN!"
|
| X | wpds.exe | wwnrot.exe | "Added by the BAGLEDI-B TROJAN!"
|
| X | wqdfadads | sdqdad.exe | "Added by the MULDROP.F TROJAN!"
|
| X | ws_ds | sws32.exe | "Added by the DELF-GZ TROJAN!"
|
| X | wzxzxds | fdfddad.exe | "Added by the RANKY.AB TROJAN!"
|
| X | xcxdsaa7 | slcskxsdl7.exe | "Added by the ONLINEG-K TROJAN!"
|
| X | xzkadsfk10 | afslkfasl10.exe | "Added by the ONLINEG-R TROJAN!"
|
| N | YAMAHA DS-XG Launcher | dslaunch.exe | System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups
|
| U | ZeroAds | 0 | "ZeroAds - culls ads |
| U | ZeroAds | LAS0Ads.exe | "ZeroAds - culls ads |
| U | ZeroAds | Zeroads.exe | "ZeroAds - a popular Internet accelerator and anti-adware application"
|
| X | [random name] | ?hkdsk.exe | "PurityScan adware"
|
| X | [random name] | chkdsk.exe | "PurityScan adware. Note - the legitimate Windows chkdsk.exe will always be located in %System% and will NOT figure among the startups!"
|
| X | [various names] | dstart2.exe | "Adware - detected by Kaspersky as the SMALL.ALW TROJAN!"
|
| X | {**-**-**-**-**} | mrdsregp.exe | "Zenosearch adware |
| X | {1C-CC-C5-54-ZN} | dwdsregt.exe | "ZenoSearch adware"
|
| X | {2F-FF-F4-4C-ZN} | omdsregk.exe | "ZenoSearch adware"
|
| X | {8C-C4-4A-A4-ZN} | dwdsregt.exe | "ZenoSearch adware"
|
| X | {B7-7D-D0-08-ZN} | dwdsregt.exe | "Added by the AGENT-GBC TROJAN!"
|