| X | starter | iexplore.exe | "Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| U | StartFoxie | StartFoxie.exe | "Foxie Suite from Softonic International. ""This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements"""
|
| X | startkey | update.exe | "Added by the BIFROSE-DG TROJAN!"
|
| X | StartKey | pligde.exe | "Added by the BIFROSE.E TROJAN!"
|
| X | startkey | royale.exe | "Added by a variant of the SDBOT WORM!"
|
| X | StartKey | msnmsie.exe | "Added by the BIFROSE.M BACKDOOR!"
|
| X | StartMenu | browse.exe | "Added by the DROWSY-C TROJAN!"
|
| X | startpage | startpage.exe | Browser hijacker - redirecting to pages2start.com
|
| X | StartReplySystem | loadnewmessage.exe | "Added by the HIDAGENT-B WORM!"
|
| U | StayAlive | StayAlive.Exe | "Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
|
| N | StickyNote | StickyNote.exe | Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
|
| U | StreamZap Remote | zremote.exe | "StreamZap PC Remote - control Windows Media Player |
| X | strmsoums | msnmegrse.exe | "Added by the SDBOT-ZK TROJAN!"
|
| X | StubPath | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | STV | winscrne.exe | "Added by a variant of the SDBOT WORM!"
|
| U | Suitcase Startup | Suitcase.exe | "Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system"
|
| X | Sun Java Console for Windows NT & XP | jconsole.exe | "Added by the VANEBOT-C WORM!"
|
| X | Sun Java Updater v5 | javajre.exe | "Added by the AUTORUN-XI WORM!"
|
| X | SunJava Updater v7 | javale.exe | "Added by the ACKANTTA.B WORM!"
|
| X | supdate | supdate.exe | "Added by the MALWARE.D TROJAN!"
|
| Y | SUPERAntiSpyware | SUPERAntiSpyware.exe | "SUPERAntiSpyware - spyware |
| X | svshostdriver | msnmessengerupdate.exe | "Added by the SDBOT-BI BACKDOOR!"
|
| X | Swf32 | AVupdate.exe | "Added by the MERKUR.E WORM!"
|
| X | Sygaete Personal Firewall | SyGate.exe | "Added by the RBOT-GLX WORM!"
|
| X | Sygate Personal Firewall | Sygate.exe | "Added by the RBOT-PN WORM!"
|
| X | Sygate Personal Firewall | Mcafeeupdate.exe | "Added by the RBOT.YN WORM!"
|
| X | Sygate Personal Firewall | service.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Port Blocker | volume.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Port Blocker | winupdate.exe | "Added by a variant of the RBOT WORM!"
|
| U | SymmTime | GeTTime.exe | "SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC) |
| U | SymmTime | SymmTime.exe | "Older version of SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC) |
| U | SymmTime Application | GeTTime.exe | "SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC) |
| ? | SynSetup | SynTP.tmp RunOnce.exe | "Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
|
| X | Sys-Stat | wuapdxe.exe | "Added by the SDBOT.HK WORM!"
|
| X | Sysctrls | winupdate.exe | Added by an unidentified WORM or TROJAN!
|
| X | SysDefence.exe | SysDefence.exe | "SysDefence rogue security software - not recommended |
| X | SysLive | SysLive.exe | "Added by the EXPICHU WORM!"
|
| X | sysme | sysme.exe | "Added by the PSW_STEALER_C TROJAN!"
|
| X | sysmem | mmsete.exe | "Added by the NOPIR.C WORM!"
|
| X | SysMon | wowexece.exe | "Added by the MULAN-A TROJAN!"
|
| X | sysnate | sysnate.exe | "Added by the MEDIAS TROJAN!"
|
| X | syspare | syspare.exe | "Added by the BIFROSE-AN TROJAN!"
|
| X | Syss | ehuupdate.exe | "EHU adware"
|
| U | SysSense | SysSense.exe | """SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray"". Google AdSense account required"
|
| X | SysService | SysService.exe | "Added by the BDFORM-A BACKDOOR!"
|
| X | system | lsasse.exe | "Added by the RBOT-YL WORM!"
|
| X | SYSTEM | SystemFile.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | system | ssclie.exe | "Added by the AGENT.LW BACKDOOR!"
|
| X | system | Microsoft Office.exe | "Added by the BANCBAN-LH TROJAN!"
|
| X | System | IEXPL0RE.EXE | "Added by the VB.KS WORM! Note the number ""0"" in the filename"
|
| X | System Cache | SysCache.exe | "Added by an unidentified VIRUS |
| X | System Configuration | iexplore.exe | "Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | system handler | srvhandle.exe | "Added by the REDPLUT VIRUS!"
|
| X | System Information Manager | Navcpe.exe | "Added by the SDBOT-QB WORM!"
|
| X | System Information Manager | iexplore.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | System Monitoring | cute.exe | "Added by the RAHIWI.A WORM!"
|
| X | System Restore Data | [path] repcale.exe [path] beird.exe | "Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
|
| X | System Service | MSREXE.EXE | "Added by the AML TROJAN!"
|
| X | System Service | msnxpexe.exe | "Added by the RBOT-AUA WORM!"
|
| X | System Servlce | live.exe | "Added by the IRCBOT-GX WORM!"
|
| X | System time updator | CSysTime.exe | "Added by the RANDEX.S WORM!"
|
| X | System Update2 | update.exe | "Added by the AUTOTROJ-C TROJAN!"
|
| X | System Updates | unve.exe | "Added by the RBOT-AWG TROJAN!"
|
| X | system32 | QQGame.exe | "Added by the QQPASS-AC TROJAN!"
|
| U | SystemAgent | Sage.exe | """Microsoft Plus! System Agent automatically tunes your system |
| X | SystemExplorer | explore.exe | "Homepage hijacker - file located in the ""Services"" folder in Common Files"
|
| X | SystemFile | SystemFile.exe | "Added by the DULLDOOR-A TROJAN!"
|
| U | SystemSafe | Syssafe.exe | "System Safety Monitor - system monitoring tool with additional application firewalling"
|
| X | SystemService | qservice.exe | Premium rate adult content dialler
|
| X | SysTime | systime.exe | "CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN!"
|
| X | systr2 | SERVICE.exe | "Added by the VB-DQY WORM!"
|
| X | Systray | [filename.exe] | "Winfavorites adware"
|
| X | systree | systree.exe | "Added by the BANCOS.L TROJAN!"
|
| X | SYS_CLEAN | Service.exe | "Added by the FLOPCOPY WORM!"
|
| U | T3Console | T3Console.exe | "Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data"
|
| X | Taba | stte.exe | "PurityScan adware"
|
| Y | Taskbar Shuffle | taskbarshuffle.exe | """Taskbar Shuffle is a simple |
| Y | taskbarshuffle | taskbarshuffle.exe | """Taskbar Shuffle is a simple |
| X | Taskman | sysdate.exe | "Added by the SILLYFDC.BCQ WORM!"
|
| X | taskmngr | [path] msnve.exe [path] task.exe | "Added by the FLOOD-EK TROJAN!"
|
| X | taskmone | taskmone.exe | "Added by the SINGU-S TROJAN!"
|
| Y | TBLFUNC | tblmouse.exe | "Aiptek HyperPen graphics tablet driver"
|
| X | Telephony Provider | Iexplore.exe | "Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Teth | drle.exe | "PurityScan adware"
|
| N | TGPro Office | IdxOffice.exe | "With IdiomaX Office Translator ""you can translate documents directly from your favorite text editor (Microsoft Word |
| X | Tiger | Shine.exe | "Added by the HAPPYLOW (or NISHE-A) VIRUS!"
|
| N | Timed Backups Manager Startup | BACKTIME.EXE | "Backup Plus - backup software"
|
| N | TimeOnline | TIMEONLINE.EXE | Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
|
| X | timessquare | timessquare.exe | "Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
|
| X | TimeSyncApp | TimeSynchronize.exe | "DealHelper adware"
|
| U | Timezone | TimeZone.exe | "Microsoft Daylight Saving Time Update Utility - see here"
|
| X | Tinue | Tinue.exe | "Added by the SILLYFDC.BCO WORM!"
|
| U | Titlebar Date | Titlebar Date.exe | "Titlebar Date by Titlebar Software - displays the day of the week and date and time in the active window's tile bar. For example |
| U | Titlebar Time | Titlebar Time.exe | "Titlebar Time by Titlebar Software - displays the day of the week |
| U | TitleTime | TiTime.exe | """TitleTime adds the current date and/or time to the Caption of the currently active application window. Additional options are a second clock (with a different time) |
| N | TK8 EasyNote | EasyNote.exe | "TK8 EasyNote - desktop post-it notes"
|
| X | TkNetDriver Monitor | lexbce.exe | "Added by the SDBOT-ADF WORM!"
|
| X | tmax | pupdate.exe | Adware pop-up generator
|
| U | TMEEJME.EXE | TMEEJME.EXE | Toshiba TME (Toshiba Mobile Extension) Control
|
| X | TmNetDriver Monitor | exbce.exe | "Added by the SDBOT-ABR WORM!"
|
| U | TMOUSE | tmouse.exe | "Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL + ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL + SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects |
| X | tmp_up | sample.exe | QuickBar adware
|
| X | Tok-Cirrhatus | IDTemplate.exe | "Added by the RONTOKBRO.A WORM!"
|
| N | TomTomHOME.exe | TomTomHOME.exe | "TomTom HOME - free management program for your PC to look after their GPS navigation products"
|
| U | Toshiba Key State | KEYSTATE.EXE | "Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g. |
| U | TouchFreeze | TouchFreeze.exe | "TouchFreeze is simple utility for Windows that automatically disables the touchpad on notebooks while you are typing text - so that you can avoid accidentally changing the position of the cursor in your document or clicking on an option"
|
| U | tpopservice | tpopservice.exe | DirecWay two-way satellite internet service enhanced POP proxy server for email
|
| U | Tracks Eraser | te.exe | "Tracks Eraser from Acesoft - "Erases all tracks of your internet activity""
|
| U | Tracks Eraser Pro | te.exe | "Tracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity""
|
| N | Tray Date | Tray Date.exe | "Tray Date by Titlebar Software - displays a simple icon in the System Tray (that can't be configured) which shows the current date. The originator's website is no longer available but you can still download it here. Whilst it only uses around 10MB of memory |
| U | traydate.exe | TRAYDATE.EXE | TrayDate - displays the date as well as the time in the System Tray
|
| X | truetype | truetype.exe | "Added by the COSIAM-I TROJAN!"
|
| ? | TSService | NSSERVICE.EXE | "??"
|
| N | tunebite | tunebite.exe | """Tunebite lets you make unprotected copies of copy-protected music files by recording them while they are being played"". Can be launched from it's Start Menu shortcut"
|
| U | TurboExplorer | TE.exe | "Web accelerator - ""TurboExplorer 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing"
|
| N | TurboNote | tbnote.exe | Post-It's on your desktop. Available via Start -> Programs
|
| U | TvrRemote | Remote.exe | "Remote Control driver for LifeView internal and external TV products"
|
| U | TvrSchedule | Schedule.exe | "Scheduler for Mercury Ez View TV Tuner Card"
|
| U | Tweak-Me | TWEAK-ME.exe | "3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support) |
| X | TXMouie | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | Update | Zupdate.exe | "Associated with B3d Projector foistware - see here"
|
| X | Update | Update.exe | "QuickButton adware"
|
| X | Update | WinUpdate.exe | "Added by the SDBOT-CV BACKDOOR!"
|
| Y | Update Service | Update.exe | "Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
|
| X | Update Windows | EXPLORE.EXE | "Added by a variant of the SDBOT WORM!"
|
| X | Update Windows | EXPLORE.EXE | "Added by a variant of the SDBOT WORM!"
|
| X | Update.exe | ravseuper.exe | "Added by the QQPASS-P TROJAN!"
|
| X | updatereal | realupdate.exe | Chinese originated adware
|
| X | Updates | msupdate.exe | "CoolWebSearch parasite variant"
|
| X | UpdateService | wservice.exe | "Added by the DREF-K WORM!"
|
| X | updatewin | update.exe | "Added by a variant of the SDBOT WORM!"
|
| X | UPNPService | WinSVCservice.exe | "Added by the AGOBOT.UN WORM!"
|
| U | Upromise | Upromise.exe | "Upromise college savings program"
|
| X | UpToDate | uptodate.exe | "BrowserAid/BrowserPal foistware"
|
| X | uptolate | nucle.exe | Added by a variant of the BIFROSE TROJAN!
|
| X | USB Drivers1 | msupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | USB Hardware Monitoring | USBhardware.exe | "Added by the RBOT-NN WORM!"
|
| U | USBPhoneforSkype | USBPhoneforSkype.exe | "USBPhoneForSkype uses Skype to dial out from a generic USB phone"
|
| X | User Sharing | usrshare.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | User Sharing Wizard | usnshare.exe | "Added by the SLENFBOT.DF WORM!"
|
| X | USERINTERFACE REPORT3R | M0USE.exe | "Added by the MYTOB.HS WORM!"
|
| U | UStorag | ustorage.exe | "U-Storage is application software running under Microsoft Windows |
| N | Ustorage | Ustorage.exe | "Maintenance tool (enable security functions) for a USB drive from Pretec"
|
| Y | Vade Retro Outlook Express | Vaderetro_oe.exe | "Vade Retro anti-spam software for Outlook Express from GOTO software products"
|
| X | VCatch Premium | VCatchpre.exe | "VCatch antivirus. Considered spyware itself - see here"
|
| X | vcbbjf | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | verse | verse.exe | "Added by the STAP-C WORM!"
|
| X | Version | manage.exe | "JRAUN adware variant"
|
| X | VGATune | VGATune.exe | "Added by the RBOT-AWM WORM!"
|
| X | Video Services | explore.exe | "Added by the GAOBOT.GL WORM!"
|
| U | ViGlance | ViGlance.exe | "ViGlance (Windows 7 SuperBar for XP) adds a Windows 7 style SuperBar for Windows XP users and can be loaded at boot time or started manually"
|
| X | vipantispyware | vipantispyware.exe | "VipAntiSpyware rogue spyware remover - not recommended"
|
| X | VirusRescue | VirusRescue.exe | "VirusRescue rogue security software - not recommended"
|
| U | ViSplore | ViSplore.exe | "ViSplore (Glass Browser for XP) adds a Vista style file browser for Windows XP users"
|
| X | VistaDrive | VistaDrive.exe | "VistaDrive malware"
|
| X | VistaUpgrade | vistaupgrade.exe | "Added by the STRATION-AX WORM!"
|
| ? | VMConsole.exe | VMConsole.exe | "Sony VAIO Media Console - installed on the VAIO Media Integrated Server PCs. What does it do and is it required?"
|
| U | VOBID | InstantDrive.exe | "Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
|
| U | voip phone | voip phone.exe | "Related to Acer Bluetooth VoIP phone - as optionally supplied with some of their notebooks such as the TravelMate 8200"
|
| N | Voipwise | Voipwise.exe | "Voipwise - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| N | Washerie.exe | washerie.exe | "Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer |
| X | WDNS SYSTEM | nibie.exe | "Added by the MYTOB-BY WORM!"
|
| U | WDSmartWare | WDSmartWare.exe | "Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range"
|
| U | Weather Pulse | weatherpulse.exe | "Weather Pulse from Tropic Designs. ""Display popular Satellite images and video from around the globe |
| N | WeatherEye | WeatherEye.exe | "WeatherEye - desktop weather from TheWeatherNetwork"
|
| N | Weatherscope | Weatherscope.exe | "WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | webalize | webalize.exe | "Searchcentrix hijacker"
|
| N | WebDrive | webdrive.exe | "System Tray access to WebDrive from South River Technologies |
| N | WebDriveTray | webdrive.exe | "System Tray access to WebDrive from South River Technologies |
| U | websaverlive | websaverlive.exe | "WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle"
|
| N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up
|
| U | WG111v2 Smart Wizard Wireless Setting | RtlWake.exe | "Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
|
| U | WhatPulse | WhatPulse.exe | "WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes"
|
| X | WhenUSave | Save.exe | "WhenU.Save adware"
|
| X | WhenUSearchWHSE | whse.exe | "WhenU.Save adware"
|
| X | widelink | widelinke.exe | "WideLink adware. File located in %Program Files%\widelink"
|
| X | Will I Ever | anqbse.exe | "Added by the SDBOT-TK WORM!"
|
| X | Win Security | winsecure.exe | "Added by the SLENFBOT.RD WORM!"
|
| X | win update | wapdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Win Update | SysUpdate.exe | "Added by the AGOBOT-TN WORM!"
|
| X | Win Update | oleupdate.exe | "Added by the AGENT-UY TROJAN!"
|
| X | win update | wupdate.exe | "Added by the RBOT-P BACKDOOR!"
|
| X | Win32 | Game.exe.vbs | "Added by the SCAFENE WORM!"
|
| X | Win32 Kernel Update | win32update.exe | "Added by the PROXY-BS TROJAN!"
|
| X | Win32 System Kernel | winservice.exe | "Added by the SDBOT.KIN WORM!"
|
| X | Win32 USB2 Driver | winupdate.exe | "Added by the AGOBOT.YE WORM!"
|
| X | Win32 USB2.0 Driver | service.exe | "Added by the SDBOT-QF WORM!"
|
| X | win32update | win32update.exe | "Added by the GENOME.AQUV TROJAN!"
|
| X | WinAble | winable.exe | "Added by the MATCASH.BG TROJAN!"
|
| X | winactive | WINACTIVE.EXE | "WinActive variant of the LOP.com hijacker"
|
| X | winbin32 | win32exe.exe | "Added by the RBOT-ZL WORM!"
|
| U | WINCINEMAMGR | WinRemote.exe | "InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
|
| X | Winde | winde.exe | "Added by the DLUCA TROJAN!"
|
| X | WinDLL (mysnlive.exe) | "rundll32.exe mysnlive.exe | start" |
| X | WinDLL (redyLive.exe) | "rundll32.exe redyLive.exe | start" |
| X | WinDLL (service.exe) | service.exe | "Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
|
| X | Windo Servic Agen | alirexe.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Window | explore.exe | "Added by the GAOBOT.ADW WORM!"
|
| X | window2 | ieupdate.exe | "Added by the FORBOT-BM WORM!"
|
| X | Windowfdgfds DLL fgfdg Verifier | winsecure.exe | "Added by a variant of the RBOT WORM!"
|
| X | windows | iexplore.exe | "Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Windows 32 Update | Windows-Update.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows ASN Service | rge.exe | "Added by the RBOT-AOK WORM!"
|
| X | Windows Auto Updater | WINDOWSUPDATE.EXE | "Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
|
| X | Windows Configuration System | IExplore.exe | "Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Windows Configuration Utility | winxupdate.exe | "Added by the AGOBOT.LW WORM!"
|
| X | WINDOWS DENEME | deneme.exe | "Added by the MYTOB-CR WORM!"
|
| X | Windows DLL Loader | wdevice.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Driver | windrive.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows drivers update | windowsupdate.exe | "Added by the RBOT-ACE WORM!"
|
| X | Windows Dynamic Library Cache | dllcache.exe | "Added by the INJECT-HT TROJAN!"
|
| X | Windows Executer | svchostie.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Windows File System Frame | ntframe.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Firewall Updater | windowsupdate.exe | "Added by the SPYBOT.AVEO WORM!"
|
| X | Windows Fixes Systems | elite.exe | "Added by the MYTOB.EG WORM!"
|
| X | Windows his Layer | pilotGame.exe | "Added by the RBOT.GLX WORM!"
|
| X | Windows Host Service | svchoste.exe | "Added by the KELVIR.BF WORM!"
|
| X | Windows Image | wintimage.exe | "Detected by Avast as the SDBOT-GEN44 WORM!"
|
| X | Windows Live | WindowsLive.exe | "Added by the REALBOT-A WORM!"
|
| X | Windows Live Care.exe | WindowsLiveCare.exe | "Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
|
| X | Windows Live Messages | msgnlive.exe | "Added by the AGENT.AYH WORM!"
|
| X | Windows Live Messenger | msnlive.exe | "Added by the RBOT.BMV BACKDOOR!"
|
| X | windows Live Messenger | iexplore.exe | "Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows Live Messenger Servicer | msmgslive.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Live Messenger Services | msgrlive.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Live Messenger! | msgrlive.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Live Service | msnlive.exe | "Added by the SLENFBOT.DI WORM!"
|
| X | Windows Loader | SysUpdate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Logon Procedure | Svchoste.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Logon Service | winlogoservice.exe | "Added by the SPYBOT.ANOO WORM!"
|
| X | Windows Management Informant | wmmiexe.exe | "Added by the IRCBOT-V BACKDOOR!"
|
| X | WINDOWS MANAGEMENT SYSTEM | wm1exe.exe | "Added by the RBOT-VT WORM!"
|
| X | Windows Media Player | mpwe.exe | "Added by the RBOT-TT WORM!"
|
| X | Windows Media Updater | crease.exe | "Added by the RBOT-ATI WORM!"
|
| X | Windows Media Upgrade | NeUpgrade.exe | "Added by the RBOT.BMF TROJAN!"
|
| X | Windows Memory Sharing | memshare.exe | "Added by the IRCBRUTE.AG TROJAN!"
|
| X | Windows Messenger Live Startup | windowsmsnlive.exe | "Added by the DELF.DAX TROJAN!"
|
| X | Windows Mouse Services | winmouse.exe | "Added by the IRCBOT.AGA BACKDOOR!"
|
| X | Windows MS Update 32 | jebote.exe | "Added by the FORBOT-GK WORM!"
|
| X | Windows MSN Live Messanger | wmsnlive.exe | "Added by the RBOT.BMV BACKDOOR!"
|
| X | Windows MSN Live Messenger | winmessengerlive.exe | "Added by the IRCBOT.EAD BACKDOOR!"
|
| X | Windows Net Cfg | service.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Network Controller | winmms32.exe.exe | "Added by the FORBOT-ED WORM!"
|
| X | Windows Process | win_update.exe | "Added by the LASTWORD WORM!"
|
| X | Windows Protectot | boxide.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Windows Reg Services | ffservice.exe | "Added by the DLOADER-PL or DLOADER-XM TROJANS!"
|
| X | Windows Reg Services | dservice.exe | "Added by the PRORAT-D TROJAN!"
|
| X | Windows Reg Services | fservice.exe | "Added by the PRORAT-D TROJAN!"
|
| X | Windows Reg Services | ssservice.exe | "Added by the PRORAT-D TROJAN!"
|
| X | Windows Reg Services | lservice.exe | "Added by the PRORAT-O TROJAN!"
|
| X | Windows Reg Services | wservice.exe | "Added by the PRORAT-O TROJAN!"
|
| X | Windows Registry Scan | timeupdate.exe | "Added by the SPYBOT.JE WORM!"
|
| X | Windows Screensaver | Service.exe | "Added by the KELVIR.P WORM!"
|
| X | Windows Secure Update | WinSecure.exe | "Added by the RBOT-GDO WORM!"
|
| X | Windows Security | winscure.exe | "Added by the RBOT-BAF WORM!"
|
| X | Windows Security Center Notification Appls | sxe.exe | "Added by the RBOT-GKX WORM!"
|
| X | Windows Security Manager | winsecure.exe | "Affilred adware"
|
| X | Windows Security Module | module.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Security Tool | WinSecure.exe | "Added by the AGENT-GPY TROJAN!"
|
| X | Windows Service | private-zone.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Service | service.exe | "Added by the IRCBOT-ACV WORM!"
|
| X | Windows Service Pack Auto Update | del-me.exe | "Adware |
| X | Windows Services | service.exe | "Added by the RANDEX.R WORM!"
|
| X | Windows Services | scvhoste.exe | "Added by the SPYBOT.OBZ WORM!"
|
| X | Windows Services | iexplore.exe | "Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Windows Services | w32service.exe | "Added by the AUTORUN-FU WORM!"
|
| X | Windows Services | filename.exe | "Added by the SDBOT.FSK BACKDOOR!"
|
| X | Windows Services | wupdate.exe | "Added by the GAOBOT.ZT WORM!"
|
| X | Windows Services Guide | svcguide.exe | "Added by the SLENFBOT.KQ WORM!"
|
| X | Windows smss service | service.exe | "Added by the AGENT-FPY TROJAN!"
|
| X | Windows Software | hbsppe.exe | "Added by the RBOT-GLL WORM!"
|
| X | Windows SP2 Update | Sp2update.exe | "Added by the WOOTBOT.BS WORM!"
|
| X | Windows Spoolsre Service | spoolsre.exe | "Added by the SDBOT-AAE WORM!"
|
| X | Windows spyware remover | Windows-spyware.exe | "Added by the SystemPoser TROJAN!"
|
| Y | Windows SteadyState - Bubble Messages | Bubble.exe | "Part of Windows SteadyState |
| X | Windows svchost | service.exe | "Added by the PUSHBOT.DU WORM!"
|
| X | WINDOWS SYSTEM | nibie.exe | "Added by the MYTOB-BY WORM!"
|
| X | WINDOWS SYSTEM | ninfoie.exe | "Added by the MYTOB-EP WORM!"
|
| X | WINDOWS SYSTEM | win.exe.exe | "Added by the MYTOB.FA WORM!"
|
| X | WINDOWS SYSTEM | servce.exe | "Added by the MYTOB-EI WORM!"
|
| X | WINDOWS SYSTEM | xpupdate.exe | "Added by the ZOTOB-G WORM!"
|
| X | WINDOWS SYSTEM | efefefe.exe | "Added by the MYTOB-KH WORM!"
|
| X | WINDOWS SYSTEM | wupdate.exe | "Added by the MYTOB-HT WORM!"
|
| X | WINDOWS SYSTEM By FEnR | windasz-updote.exe | "Added by the MYTOB.LR WORM!"
|
| X | WINDOWS SYSTEM CLEANER | iexplore.exe | "Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Windows Task Scheduler | asijdie.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Taskmanager | service.exe | "Added by the PUSHBOT.OR WORM!"
|
| X | Windows Time | tmservice.exe | "Added by a variant of the RBOT-YK WORM!"
|
| X | Windows Update | iexplorere.exe | "Added by the GAOBOT.AP WORM!"
|
| X | Windows Update | wudate.exe | "Added by the AGOBOT.ML WORM!"
|
| X | Windows Update | wupdate.exe | "Wengs adware"
|
| X | Windows Update | WindowsUpdate.exe | "Added by the BAYROB-A TROJAN!"
|
| X | Windows Update | Update.exe | "Added by the DELF-FN TROJAN!"
|
| X | Windows Update | winupdate.exe | "Added by the SDBOT-WS WORM!"
|
| X | Windows Update | mplupdate.exe | "Added by the MOEGA WORM!"
|
| X | Windows update | wudupdate.exe | "ISTBar adware related"
|
| X | Windows Update | msnsupdate.exe | "Added by the RBOT-AXS WORM!"
|
| X | Windows Update | win32update.exe | "Added by the SDBOT.FTK WORM!"
|
| X | Windows Update | McAfee.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
|
| X | Windows update | explore.exe | "Added by the GAOBOT.AL WORM!"
|
| X | Windows Update Automation | winuptdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | windows update configurator | explore.exe | "Added by the SDBOT.RY BACKDOOR!"
|
| X | Windows Update Controller | mwoffice.exe | "Added by the BATTRY-A TROJAN!"
|
| X | Windows update loader | xpupdate.exe | "Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
|
| X | Windows Update Manager | wupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Update Service 2004/2005 | systemupdate.exe | "Added by the RBOT-JE WORM!"
|
| X | Windows Update.exe | N/A | Homepage hijacker
|
| X | Windows Updated | spoolsae.exe | "Added by the RBOT-APM WORM!"
|
| X | Windows Updater | wupdate.exe | "Added by the WOOTBOT.AJ WORM!"
|
| X | Windows Updater Servc | xpuupdate.exe | "ContraVirus rogue security software - not recommended |
| X | Windows Updater Services | msnupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Updates Agent | winupdate.exe | "Added by the SPYBOT.HW WORM!"
|
| X | Windows USB 2.0 Driver | usbservice.exe | "Added by the RBOT-BLF WORM!"
|
| X | Windows USB Control Driver | iexplore.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows USB Monitor | servupdate.exe | "Added by the IRCBRUTE.AQ TROJAN!"
|
| X | Windows USB Printer | exe.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Vista Transformation | IEXPLORE.exe | "Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Windows Workstation Service | explore.exe | Added by unknown malware
|
| X | Windows XP Automatic Update | wXPupdate.exe | "Added by the RBOT-AFC WORM!"
|
| X | WindowsACEbar | acebarupdate.exe | "BarACE adware"
|
| X | WindowsCriticalUpdate | windows_critical_update.exe | "Added by the ASTEF or RESPAN WORMS!"
|
| X | Windows�Updates | Update.exe | "Added by the RBOT.TRA BACKDOOR!"
|
| X | WindowsRegKey update | winupdate.exe | "Added by the RBOT-QJ WORM!"
|
| X | WindowsRegKey update | wdnupdate.exe | "Added by the SDBOT.QX WORM!"
|
| X | windowstime.exe | windowstime.exe | "Added by the DLOADR-AQV TROJAN!"
|
| X | WindowsUpdate | windows_update.exe | "Added by the LOFNI WORM!"
|
| X | windowsupdate | winupdate.exe | "Added by the WARPI WORM!"
|
| X | Windowsupdate | Windowsupdate.exe | "Added by the BANKER.ARK TROJAN!"
|
| X | windowsupdate | autoupdate.exe | "Added by the IRCBOT-P BACKDOOR!"
|
| X | WindowsUpdate renew | iexplore.exe | "Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | WindowsXP Update | windowsxpupdate.exe | "Added by the RBOT-PB WORM!"
|
| X | Windows_Serivce | SERVICE.exe | "Added by the WOOTBOT.AH WORM!"
|
| X | Windws Configuration Loader | LEXPLORE.exe | "Added by the SODABOT WORM!"
|
| X | WinGate initialize | WinGate.exe | "Added by the LOVGATE.F WORM!"
|
| X | Winhelp | TkBellExe.exe... | "Added by the LOVGATE.Z WORM!"
|
| X | Winhelp | TkBellExe.exe | "Added by the LOVGATE.E WORM!"
|
| X | WinLibUpdate | libupdate.exe | "Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
|
| X | WinLibUpdte | libupdte.exe | "Added by the BIONET.318 TROJAN!"
|
| X | winlogin | ReadMe.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | winlogin.exe | logfile.exe | Added by the AGENT.AH TROJAN!
|
| X | WinManage | wmanage.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | winmgmt | wmiprvse.exe | "Added by the AGENT-GHP TROJAN!"
|
| Y | winmodem | wmexe.exe | "Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
|
| X | winpipe | winpipe.exe | Browser hijacker redirecting to wow-access.com
|
| X | winpopup | winupie.exe | Adware by Tradeexit.com
|
| X | winprofile | iexpiore.exe | Added by a variant of the MONCHER WORM!
|
| X | WinProfile | iexpIore.exe | "Added by the CHUM-C TROJAN!"
|
| U | WINREMOTE | WinRemote.exe | "InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
|
| X | winrestore1 | winrestore.exe | "Added by the KILLFIL-Q TROJAN!"
|
| N | winroute | winroute.exe | "Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process |
| X | winsecure | winsecure.exe | "Browser hijacker |
| X | Winshell | remote.exe | "Added by the MYTOB.LJ WORM!"
|
| X | winskype | winskype.exe | "Added by the BROGGER-C TROJAN!"
|
| X | Winsock driver | winnt update.exe | "Added by the SPYBOT-DM TROJAN!"
|
| X | Winsock2 driver | SDJOIJE.EXE | "Added by the SPYBOT.DR TROJAN!"
|
| X | Winsock2 driver | winupdate.exe | "Added by the SPYBOT-BX WORM!"
|
| X | Winsock32driver | sp2XPupdate.exe | "Added by the HACKARMY.S TROJAN!"
|
| X | Winsock32driver | winXPupdate.exe | "Added by the HACKARMY.9728 TROJAN!"
|
| X | WinSrv | SHIZZLE.EXE | "Added by the HOBBIT.C WORM!"
|
| X | WinStar | IEXPL0RE.exe | "Added by the WOSRIST A TROJAN!"
|
| X | WINTASK | taskfile.exe | "Added by the MYTOB.EF WORM!"
|
| U | wintective | wintective.exe | "Wintective logs keystrokes |
| X | Wintime | Wintime.exe | "Added by the HARNIG TROJAN!"
|
| U | WinTime | wintime.exe | "WinTime - change desktop icons' color and font"
|
| X | winupdate | winupdate.exe | "Added by the ALCAN.B WORM!"
|
| X | winupdate.exe | winupdate.exe | "Added by the RADO TROJAN!"
|
| X | winupdate.reg | winupdate.exe | "Added by the SPYBOT.EAS WORM!"
|
| X | WinUpdateB | breatle.exe | "Added by the BRATLE.AWORM!"
|
| X | WinUpdater | update.exe | "Added by the STARTPAGE.C TROJAN!"
|
| X | WinZix Service | wakeservice.exe | "WinZix adware"
|
| X | wise | clockwise.exe | "Added by the LAZAR-A TROJAN!"
|
| U | WMIEXE.exe | wmiexe.exe | "NT component |
| X | wmiprevse | wmiprevse.exe | "Added by the BANKER-EPN TROJAN!"
|
| X | wmupdate | wmupdate.exe | "Added by the AGENT-GGJ TROJAN!"
|
| X | won update | WAPDATE.EXE | "Added by the RBOT.N WORM!"
|
| U | WorkPace 3.0 | workpace.exe | "WorkPace - stress injury prevention software"
|
| X | Workstation Ver 5.0 | vmware.exe | "Added by the RBOT-AHB WORM!"
|
| U | WorldTime.exe | WorldTime.exe | "Part of AnyTime Organizer Deluxe from Individual Software Inc - ""Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop"""
|
| Y | WPCycle.exe | WpCycleWin.exe | "Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end |
| ? | wriste | wriste.exe | "??"
|
| ? | wsbklite | wsbklite.exe | "Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?"
|
| U | WService | WService.exe | "Tablet client Driver for UC-Logic Pen/Graphics Tablet"
|
| X | Wupdate driver | wupdadte.exe | "Added by the SPYBOT-CQ WORM!"
|
| X | Wxp4 | Norton Update.exe | "Added by the ERKEZ.D WORM!"
|
| X | xcfdhtyjkx | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| U | XE 8x LM Status | lmsxxe.exe | Xerox XE8 series laser printer status monitor
|
| N | Xfire | Xfire.exe | Terratec DMXFire 1024 soundcard control panel
|
| X | xInsIDE | xInsIDE.exe | "Added by the ADLOAD.BH TROJAN! Note - this should not be confused with the valid IDE configuration utility from JMicron Technology which is normally located in %Windir%\RaidTool and uses the same filename. This one is located in %ProgramFiles%\xInsIDE"
|
| U | xInsIDE | xInsIDE.exe | "JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
|
| X | XP Antispyware 2009 | XP_AntiSpyware.exe | "XP AntiSpyware 2009 rogue spyware remover - not recommended |
| X | xpiupdate | xpiupdate.exe | "Added by the RBOT-AAB WORM!"
|
| X | xpprotect | xpdeluxe.exe | "XP Protector Deluxe rogue security software - not recommended |
| X | xpsp2install | xpsp2Update.exe | "Added by the AGENT-DPK BACKDOOR!"
|
| X | xpsp2Update | xpsp2Update.exe | "Added by the AGENT-DPK BACKDOOR!"
|
| X | xSafe | xSafe.exe | "Added by the SILLYFDC.BAY WORM!"
|
| U | XSC SIP Client | X-Lite.exe | """CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download"". For VOIP and broadband users"
|
| X | XTServiceUpdate | XTServiceUpdate.exe | hahame.net adware downloader
|
| X | xware | xware.exe | "Malware downloader from xxsware.com |
| X | xware | cskware.exe | "Malware downloader from xxsware.com |
| X | Yahoo Messengger | chrome.exe | "Added by the AUTORUN-NG WORM!"
|
| X | Yahoo Messengger | gphone.exe | "Added by the TIOTUA-W WORM!"
|
| U | Yahoo! Widget Engine | YahooWidgetEngine.exe | "Yahoo! Widget Engine lets you run little files called Widgets that can do pretty much whatever you want them to"
|
| X | yeahdude.exe | hallowelt.exe | "Added by the GAOBOT.RS or GAOBOT.SA WORMS!"
|
| N | YLive.exe | Ylive.exe | "Yahoo! Assistant (formerly 3721 Internet Assistant) - not recommended"
|
| U | ZeroSpyware | ZeroSpyware.exe | FBM Software ZeroSpyware 2004 spyware detector and remover
|
| X | Zi5 | AntiVirus Update.exe | "Added by the ERKEZ.G WORM!"
|
| X | Zonealarm | Removeme.exe | "Added by the FORBOT-BG WORM!"
|
| X | Zonealarm | iexplore.exe | "Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | ZPoint | winmuse.exe | "Added by the DLOADR-VJ TROJAN!"
|
| X | zsmsgs | iservice.exe | "Added by the BANCOS-BU TROJAN!"
|
| X | Zupdate | Zupdate.exe | "Associated with B3d Projector foistware - see here"
|
| X | [12 random characters] | admparse.exe | "IeDriver adware variant"
|
| X | [random name] | ??xplore.exe | "PurityScan adware"
|
| X | [random name] | d?xplore.exe | "PurityScan adware"
|
| X | [random name] | n?tdde.exe | "PurityScan adware"
|
| X | [random name] | Servere.exe | "Added by the LEGMIR-AQM TROJAN!"
|
| X | [random name] | netdde.exe | "PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
|
| X | [various names] | EXE32EXE.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | forces_elite.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | openstre.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | PrcIdle.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | qwe.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | TemplateDongle.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | wormexe.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _explore manager | _explore.exe | "Added by the SPEXTA-C TROJAN!"
|
| X | {2C70168B-97CE-4f31-B85D-1FEC5002721D} | sysxhtcwbse.exe | "Added by the FAKEALERT-AM TROJAN!"
|
| U | {B179023B-6238-4499-8F26-CD73E9D90E0A} | MacDrive.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | {C0FB7D08-056E-1033-0501-03020730002c} | Update.exe | "Added by the AGENT-EOG TROJAN!"
|