Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xne.exe"Added by the IRCBOT-ZL TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
U$Volumouse$volumouse.exe"Volumouse from Nirsoft. ""Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"""
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Mcafee.exe"Added by the AGENT.AY TROJAN! Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)xtreme.exe"Added by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLMRun in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X3-habibiehabibie.exe"Added by the BRONTOK-CR WORM!"
Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3D Mouse driver
Xajesse.exe"Added by the MELO-A WORM!"
NA NoteA Note.exe"""A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"""
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
XAaouamee.exe"PurityScan adware"
UAAWAd-Aware.exe"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
?Ad Online Guideadonlineguide.exe"??"
UAd-AwareAd-Aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAd-AwareAd-Aware.exe"Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
UAdDeleteAdDelete.exeBanner advertisment blocker
XAdobeAdobe.exe"Added by an unidentified VIRUS
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
UAdsGoneAdsgone.exe"AdsGone - pop-up stopper"
Uadsnweadsnwe.exe"EmailSpyMonitor E-mail surveillance software. Uninstall this software unless you put it there yourself"
Xadstartupautomove.exe"Adlogix adware variant"
XAdVantageAdVantage.exe"MediaAdVantage adware"
XAdwareDeleteadwaredelete.exe"AdwareDelete rogue adware remover - not recommended
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
?AHNUEAHNUE.exe"??"
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
UAllSeeingEyease.exe"All-Seeing_Eye security software - ""monitors everything that takes place on your computer
XALTER DATA[path] repcale.exe [path] beird.exe"Added by the IRCFLOOD.CD TROJAN! Both files are located in %System%\ccdew"
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
YAntiFreezeAntiFreeze.exe"AntiFreeze from Resplendence Software Projects - ""offers a last recourse when you find your computer in a hung state"". If your system has hung and AntiFreeze is running
XAntiMalwareAntiMalware.exe"AntiMalware rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpyZoneAntiSpyZone.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiVituSBase.exe"Added by the BAS.A WORM!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
NaresliteAresLite.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
Uarmy logoreadmename.exe"Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements"
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
?AspireServiceAspireService.exe"Found on Acer laptops
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
UATIMACEMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) component
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
UAtomicTimeATOMICTIME.EXE"AtomicTime - utility that synchronizes your PC clock to an atomic clock"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
XAUTOEXEAUTOEXE.exe"Added by the SEMAPI-A WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
XAutopdateAutopdate.exe"Added by the RBOT-AGL WORM!"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
Xauto__antiav__keyantiav_exe.exe"Added by the BAGLEDI-AA TROJAN!"
Xauto__hloader__keyhloader_exe.exe"Added by the BAGLE.AB TROJAN!"
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
YAvxliveavxlive.exe"Bullguard or BitDefender antivirus"
Uawpliteawplite.exe"AllWallpapers Lite desktop wallpaper changer"
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
Yazmodemazexe.exe"Aztech Labs modem driver"
Xb3dUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XBADDATEBADDATE.EXE"Added by an unidentified VIRUS
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
NBearSharebearshare.exe"BearShare file sharing client. Versions known to include spyware - see here"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
NBlackIce Utilityblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
NBMupdateBMupdate.exe"Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBregbcre.exe"BroadcastPC adware variant"
XBregbptre.exe"BroadcastPC adware variant"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Xbrowserbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
YBubbleBubble.exe"Part of Windows SteadyState
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
XBunxbeagle.exe"Added by the LEBREAT-E WORM!"
YCAISafeisafe.exe"Part of Computer Associates eTrust EZ Antivirus"
Ucapfupgradecapfupgrade.exe"CA Personal Firewall - part of the CA Internet Security Suite"
Xcapturecapture.exe"Added by the THEEF-B TROJAN!"
NCaptureBatCapture.exe"!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XccAppexample.exe"TwoSeven spyware"
XccUpdateccUpdate.exe"Added by the AGOBOT.YS WORM!"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
?ChangeLineschngline.exe"??"
XCheatleGigaByte.exe"Added by the SHODI.B VIRUS!"
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
XchiCkiechiCkie.exe"Added by the CHIKO WORM!"
XChokeChoke.exe -blahhh"Added by the CHOKE WORM!"
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
NClickMeClickMe.exe"ClickM ""JOKE"" program"
NClipMate7ClipMate.exe"Clip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard"
UClockWiseCLOCKWISE.EXE"ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates
UClUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XCMEcme.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?CmUCRRunCmUCReye.exe"Related to Medion Display Information. What does it do and is it required?"
XCNBABECNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UComproRemoteComproRemote.exe"VideoMate TV tuner and capture card - remote control driver"
?Concurreconcurre.exe"??"
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
Xconime.execonime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
?Contactecontacte.exe"Some kind of driver?"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
UCookieWallcookie.exe"CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return"
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
Xcosinecosine.exe"Added by the RBOT-SW WORM!"
Xcplbrowse.exe"Added by the TACTSLAY.C TROJAN!"
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XCtModuleCtModule.exe"Added by the CLICKER-EG TROJAN!"
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Ucwupdatecwupdate.exe"ContentProtect from ContentWatch - internet filter"
UCyber Trioshowmode.exe"From G-Tek Technologies. Allows you to set the PC in one of three modes
Xcyberfree.exe****.dat [* = random char]Unidentified adware
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
Xd3dupdate.exebbeagle.exe"Added by the BEAGLE.A WORM!"
NDAEMON Tools LiteDTlite.exe"Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
UDancerDncLE.exe"Part of Microsoft Plus! Digital Media Edition - see here"
XDATABASE MySql[path] repcale.exe [path] beird.exe"Added by the RANDON-AL WORM! Both files are often located in %System%\qsws"
XDAupdateDAupdate.exeNavEnhance adware
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
UDepFrezfrzstate.exe"Deep Freeze from Faronics Coporation. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
?desk-top-servicedesk-top-service.exe"??"
XDeskMateAutoUpdateDeskMateAutoUpdate.exe"DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related"
UDeskSlideDeskSlide.exe"""DeskSlide is utility for automating wallpaper changes on your desktop"""
UDeskSpacedeskspace.exe"DeskSpace desktop management utility from Otaku Software Pty Ltd - which ""gives you more space for your windows and icons. You can eliminate desktop clutter by arranging your windows and icons across up to six desktops
UDesktop iCalendarDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar LiteDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar Lite.exeDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDhcpCepPYJJKIME.exe"Added by the AGENT-BXQ TROJAN!"
XDieselRecalculate.exe"Added by the LAZAR TROJAN!"
YDigital Patrol Update 5update.exe"Digital Patrol - ""a powerful anti trojan scanner
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDiskstartCode.exeAdult content dialler
UdisplayThe_Eye.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
YDkServiceDkService.exe"From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled
XDKTimedktime.exe"Added by the LUNII TROJAN!"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?DLForcerExeDLForcerEXE.exe"??"
XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
Xdllcache.exedllcache.exe"Added by the VISPAT.A WORM!"
Xdluxdedluxde.exeAll-In-One-Telcom (adult content dialler) variant
Xdmimedmime.exe"Malware installed by different rogue security software including SpyKillerPro"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNSEDNSE.exe"Part of rogue security tools
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
UDown2HomeDown2Home.exe"Down2Home - ""monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"""
XDownloadWare EngineDwe.exe"DownloadWare adware"
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
XDropSpam Lifestyledslifestyle.exe"Dropspam adware"
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
NDTliteDTlite.exe"Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDxupdate.exeDxupdate.exe"Added by the MAFEG WORM!"
XDyFuCAoptimize.exe"Adult content dialler - see here"
UDynSiteDynSite.exe"DynSite - dynamic DNS client
?DZKillMeDZSAVEME.EXE"??"
NEA CoreCore.exe"Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
UEasyTuneIIIEasyTune.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
?ecpeECPE.EXE"??"
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
UEmouseEmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
Uemozeemoze.exe"emoze pcConnector - ""Push your personal & business emails
Xemuleemule.exe"Added by the RBOT-ALZ WORM! Note - do not confuse with the legitimate eMule peer-to-peer (P2P) file-sharing program which is normally located in %ProgramFiles%\eMule. This one is located in %System%"
NeMuleemule.exe"eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project
NeMuleAutoStartemule.exe"eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
XEQAdviceEQAdvice.exe"NewAds1 adware"
XEQArticleEQArticle.exe"EQArticle adware"
NESPN BottomLinebline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop
XEsutitydeosutityde.exe"Added by the SDBOT.BQD WORM!"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
NEvidence Eliminatoree.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
Xewrgetujgeurge.exe"Added by the AUTOINF-AK WORM!"
?Excite Private Messenger Pipex8impipe.exe"??"
Xexe lptt01exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xexe ml097eexe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
NEye Tide Launcheroneeyetideone.exeNascar wallpaper
YezPS_PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
XFCEngineFCEngine.exe"CASClient adware"
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
Xfilenamefilename.exe"Added by the VB.FSY TROJAN!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
UFilterGatefiltergate.exe"Filtergate internet filtering software - filters sounds
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
UFlashMuteFlashMute.exe"""FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively
UFLMOFFICE4DMOUSEmoffice.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
XFreeAttentioneqsefeqe.exeAdded by an unidentified WORM or TROJAN!
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
XGame HouseGameHouse.exe"Added by the DELF-DRA WORM!"
NGameTrackerGTLite.exe"GameTracker - ""Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"""
XgaSrvegaSrve.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
NGet Smilegetsmile.exePuts smilie faces in your E-mail. Run manually when required
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
XGigaByteCheatle.exe"Added by the SHODI.B VIRUS!"
YGmouseGmouse.exeAmouse mouse driver - required if you use non-standard Windows driver features
UGNETMOUSEgnetmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
Xgooglegoogle.exe"Added by the RBOT-AMW WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
NGoogle UpdateGoogleUpdate.exe"Update manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %AppData%\Google\Update"
XGoogle UpdateGoogleUpdate.exe"Added by the BUZUS.DBFM TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %System%"
Xgouday.exereadme.exe"Added by the BEAGLE.C WORM!"
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
YGroove Virtual OfficeGroove.exe"""Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
UHarehare.exe"Hare - improve and optimize performance of desktop/laptop PCs"
UHDDlifeHDDlife.exe"HDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
YHEProtectHSockPE.exe"Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XhgkytwekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
UHideOEHideOE.exe"HideOE - allows you to 'hide' Outlook Express or minimize it to the System Tray"
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
XHost Processmame.exe"Added by the RBOT-APO WORM!"
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
UHotIDEhotide.exeHotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
Xhotwetlovehotwetlove.exeAdult content dialler. Will not uninstall - components have to be manually deleted
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
Xhriiexpl0re.exe"Added by the DLOADER.MAQ TROJAN! Note the number ""0"" in the filename"
XHservicemsservice.exe"Added by the AUTORUN-KL WORM!"
Xhsimsexgame.exeUnidentified malware
Xhttpdbrowse.exe"Added by the TACTSLAY.C TROJAN!"
XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
NICH Syntheusexe.exe"Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
NIcon AnimationHDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
NICQ LiteICQLite.exe"ICQ Lite - compact version of the popular messaging program"
XICQ Lite MessengerICQLITE.EXE"Added by an unidentified VIRUS
XIcqBetawebcamupdate.exeAdded by an unidentified TROJAN!
XIDEide.exe"Added by the ASSASIN.F TROJAN!"
XIDTemplatesIDTemplate.exe"Added by the BRONTOK-H WORM!"
XIECacheIECache.exe"Detected by Bitdefender as the DELF.OFC TROJAN! See here"
XIEDriverxplore.exe"IeDriver adware variant"
XIEService.exeIEService.exe"FastFind adware variant"
XIexploreiexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIEXPLOREiexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIExploreIEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
XIEXPLOREIEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIEXPLORE.EXEgoot.exe"Added by the BIFROSE-C TROJAN!"
YIKE Service 95IKEService.exe"Associated with PGP. The PGP Tray can be disabled
XilortgdgkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
XIMEconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntelliflag_be.exeIntelliflag_be.exe"Intelliflag spyware"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Optimizeroptimize.exe"Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
XiPod USB ServiceiPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
?iPrint LPT Redirectornipplpte.exe"Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
YIREIKEIreIKE.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
UiRiver AutoDBMLService.exe"Associated with the iRiver Music Manager"
XISMModuleISMModule.exe"Internet Speed Monitor C adware related - see example here"
NItsDeductiblePopUpItsDeductible.exe"ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
XITUNESitune.exe"Added by the RBOT-ZU WORM!"
Uitypeitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
Xixploreixplore.exe"Added by the SDBOT-CY TROJAN!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJava Updatehostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
XJavaCoreJavaCore.exe"Added by the MATCASH TROJAN!"
UJMB36X IDE SetupJMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupxInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
?jotlmillenzje.exe"??"
NJuiceJuice.exe"Juice - a free utility that ""allows you to select and download audio files from anywhere on the Internet to your desktop"". This entry is present if you choose the option to add it to the startup group during installation"
Xjusodlsevere.exe"Added by the QQPASS.48436 TROJAN!"
UKatMouseKatMouse.exe"KatMouse - utility to enhance the functionality of mice with a scroll wheel
Nkazaalitekazaalite.exe"Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original
XKeenvalueKeenvalue.exe"KeenVal adware"
XkERekERe.exe"Added by the BRONTOK-BT WORM!"
XKernelUpdate.exe"Added by the DELF-FN TROJAN!"
XKernelFaultCheckmsime.exe"Added by the TINY-P TROJAN!"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XKernel_checkwmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
?Key2serve.exe"??"
Ukeystrokekeystroke.exe"QuickLaunch surveillance software. Uninstall this software unless you put it there yourself"
XKIT3hpprintqueue.exe"Added by the ADCLICK-DS TROJAN!"
UKodak EasyShare softwareEasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
XKvmSecure.exeKvmSecure.exe"KvmSecure rogue security software - not recommended
Ulaimaimlite.exe"""AIM Lite is a reference application for testing some new client technology developed here at AOL®
?LanguageShortcutLanguage.exe"Part of Cyberlink's PowerDVD prior to version 8. Language settings?"
XLaptop AccessSage.exe"Added by the SDBOT-NB WORM!"
Xlasselasse.exe"Added by the NTOS TROJAN!"
ULaunch LGDCoreLGDCore.exePart of the GamePanel Software for the Logitech G-Series of gaming keyboards. This is the keyboard driver and if it's disabled you will lose access to special features and programmed keys
XLavasoft Ad-AwareAd-Aware.exe"Added by the RBOT-SO WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
ULCD SmartieLCDSmartie.exe"""LCD Smartie is software for Windows that you can use to show lots of different types of information on your LCD/VFD."" Typically used by the PC modding community to display statistics such as CPU temp
Xlexplorelexplore.exe"Added by the BROPIA WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
NLG Intelligent Updateautoupdate.exe"Automatic update utility for LG Notebooks"
ULGDCoreLGDCore.exePart of the GamePanel Software for the Logitech G-Series of gaming keyboards. This is the keyboard driver and if it's disabled you will lose access to special features and programmed keys
ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
XLimewireLimeWire.exe"Added by the RBOT-AGH WORM!"
NLimeWire On StartupLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
NLimeWire x.xLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xlivekeywebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
Xlivekeyswebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
NLiveNoteLivenote.exeAsus graphics card driver live update feature
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XLoadMyGame.exe"Added by the LAMEYEAR-A WORM!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
ULocalProxyproxy4free.exe"""ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored
XLogitech CameraSoundcane.exe"Added by the SDBOT.MUC WORM!"
XLogitech DesktopApPache.exe"Added by the RBOT-YP WORM!"
NLogitech QuickCamManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
NLogitechSoftwareUpdateManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
ULogServiceLogService.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XLOVELOVE.EXE"Added by the VB-ZQ TROJAN!"
XLsasSSygate.exe"Added by the SDBOT.BCA WORM!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
XLTM2bible.exe"Added by the LITMUS.203 TROJAN!"
UMacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMacDrive applicationMacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
NMacNameMacName.exe"Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks"
UMacroPhonemacrophone.exe"MacroPhone is a network based telephony application that ""allows you to handle server based voice mail and fax functions for all users in your company"" and ""offers many related functions
UMacroPhone Clientmacrophone.exe"MacroPhone is a network based telephony application that ""allows you to handle server based voice mail and fax functions for all users in your company"" and ""offers many related functions
NMagitimeMagitime.exe"Magitime - connection tracking utility which monitors online time
XMalware Defensemdefense.exe"Malware Defense rogue security software - not recommended
XMalware-WipeMalware-Wipe.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWipeMalwareWipe.exe"MalwareWipe rogue security software - not recommended
UManageDesk LiteManageDesk Lite.exe"ManageDesk Lite from Managebytes Desktop management software. Each desktop is a separate working space for you to use"
NManifestEngineManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
Xmanrotcemanrotce.exeAdded by unidentified malware
NMatrox PowerDesk SEMatrox.PowerDesk SE.exe"Matrox PowerDesk SE - multi-display desktop management controls"
UMaxBackSchedulemaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
UMBProbembrpobe.exe"MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs"
YMcAfee SecurityCenterMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
Xmcafee Software Intrenetmcafee.exe"Added by the RBOT-ATR WORM! Note - this is not a valid McAfee program"
YMcUpdateMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMCUpdateExeMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMcVsRtemcvsrte.exe"Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
Nmdac_runoncerunonce.exeAssociated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe".
XMDNSservice.exe"Mirar adware variant"
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
UMediafour MacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMediafourGettingStartedWithMacDrive6MacDrive.exe"MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediaLifeServiceMediaLifeService.exe"Related to MediaPlay Cordless Mouse from Logitech"
XMediaPlayeSMediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
XMeeting Connectionwowdache.exe"Added by the PPDOOR-D TROJAN!"
XMemory Checkmemore.exe"Added by the KILLAV.C TROJAN!"
XMessangerbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Ymgavrtclexemgavrte.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
XMicrcoft Updatspoolsae.exe"Added by the RBOT-AIB WORM!"
XMicrooft Timingpupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftsqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Verifierfile.exe"Added by the RBOT-AED WORM!"
XMicrosoft DLL Verifierchkfile.exe"Added by the RBOT-AOC WORM!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Featuresmsie.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
UMicrosoft IntelliType Proitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft Memory Flow Cycleflowcycle.exe"Added by the IRCBOT.WAD BACKDOOR!"
XMicrosoft Neser Experiencenese.exe"Added by the RBOT-YH WORM!"
NMicrosoft OfficeMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
UMicrosoft Office GrooveGROOVE.EXE"System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
NMicrosoft Office Shortcut BarMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft OpeionsIEXwe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Profile Managerprofile.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Registrycsrse.exe"Added by the RBOT-PC WORM!"
XMicrosoft Safe Mode Managersafemode.exe"Added by the IRCBOT.HM BACKDOOR!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosoft Security Monitor Processofice.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Serviceservice.exe"Added by the IRCBOT-XX BACKDOOR!"
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Execution Managerexecute.exe"Added by a variant of the IRCBOT TROJAN! See here"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization Managerfirewire.exe"Added by the SDBOT-AFC WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft Updatewudmate.exe"Added by the RBOT.AP WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updatemcupdate.exe"Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
XMicrosoft UpdateSygate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updateupdate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updateenule.exe"Added by the IRCBOT.DU BACKDOOR!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMicrosoft Update Emulatorkern-mxe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinentce.exe"Added by the RBOT-FA WORM!"
XMicrosoft Update MachineLANWAKE.EXE"Added by the RBOT-QZ WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicrosoft Updattingmiroupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft upnp Updatemsie.exe"Added by the RBOT-LQ WORM!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoft Web Devicewdevice.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft Word ProfissionalJava Plug In close.exe"Added by the BANKER-EL TROJAN!"
XMicrosoft's System ModuleSysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
XMicrosoftCorpupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftCorpwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftNAPCupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftNAPCwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftUpdateMicrosoftUpdate.exe"Added by the BANKER-EHC TROJAN!"
XMicrosoft©iexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
NMiniNoteMININOTE.EXE"Mini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software"
NMiniphoneglophone.exe"VoiceGlo Glophone - ""an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer"" using the VoIP (Voice over Internet Protocol). No longer available"
NMMReminderServiceMMReminderService.exe"Mind Manager from Mindjet - ""easy way to organize ideas and information"". Registration reminder"
UMobile Phone SuiteMobilePhoneSuite.exeLogitech Mobile Phone Suite
NModemUtilitymdmsetpe.exeSystem Tray configuration icon for Aztech modems
UMotorola Desktop SuiteDesktopSuite.exe"Related to Motorola Desktop Suite - PC software managing Motorola mobiles such as the A1000"
Xmousemouse.exe"Added by the RBOT-AHJ WORM!"
Xmousedrive.exeinstantmsgrs.exe"Added by the FORBOT-ER WORM!"
XMouseDrvupdate.exe"Added by the ZOTOB.N WORM!"
XMovieMlmovie.exe"Added by the BEAGLE.DS WORM!"
XMovieplaceMovieplace.exe"MoviePlace malware"
YmpLockDriveLockDrive.exe"LockDrive from i8 Technologies makes selected folders and drives read only and can be used to prevent users downloading or copying data to portable drives and memory sticks - i.e.
XMPREXEMPREXE.EXE"Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file"
YMPREXE.exemprexe.exe"WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus"
XMS Decryption Softwareactive.exe"MediaTickets adware variant"
XMS Explorermexplore.exe"Added by the YAHA.AE WORM!"
Xms ownagewinPE.exe"Added by the RBOT-AJL WORM!"
XMS servicemsservice.exe"Added by the RBOT-ZG WORM!"
XMS SyS Restoresysrestore.exe"Added by the RBOT.XM WORM!"
XMS Timetimezone.exe"Added by the AGOBOT.ADY WORM!"
XMS Unix Binarymsnupdate.exe"Added by the RBOT-AAM WORM!"
XMS Unix Binaryoutlookexpressupdate.exe"Added by the RBOT-YU WORM!"
XMS Unix BinaryWin32Update.exe"Added by the RBOT-BAS WORM!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS Unix Binarytrmupdate.exe"Added by the RBOT-ACC WORM!"
XMS UPDATERupdate.exe"Added by the RBOT-VC WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS-Connectgame.exe"Adult content dialler - see here"
XMSChoExEsuge.exe"Added by a variant of the RBOT WORM!"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
XMSDNnese.exeAdded by the SDBOT.AHY WORM!
Xmsidlemsidle.exe"Added by the OPASERV-O WORM!"
XMSInfoAVBgle.exe"Added by the NETSKY.O WORM!"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMNTJBEMSMNTJBE.EXE"Added by the BANCOS-EF TROJAN!"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMSNmsservice.exe"Added by the IRCBOT-ABZ TROJAN!"
XMSN BETAservice.exe"Added by the RBOT.AUU WORM!"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Live Loginmsnmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMsn Messenger Updatemsnupdate.exe"Added by a variant of the RBOT WORM!"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMSN Softwaremsnsoftware.exe"Added by the IRCBOT.AWD BACKDOOR!"
XMSN Updatingmsnupdate.exe"Added by the QHOST.AEI TROJAN!"
UMSN Video EnhancedMSNVE.exe"""MSN Video Enhanced can play videos that have dramatically improved video quality and sound. It can play the latest high-quality videos at the best possible quality."" No longer appears to exist"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
Xmsnupdtkolie.exe"Added by a variant of the RBOT WORM!"
Xmsofficemsoffice.exe"Added by the LIKASIMAL WORM!"
XMSOfficeCfgqservice.exePremium rate adult content dialer
Xmsreg.exemsrege.exe"Added by the ZINX TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
Xmssysintcomime.exe"Added by the NETSNAKE-I TROJAN!"
Xmsupdatemsupdate.exe"Added by the RBOT-MZ WORM!"
XMSUpdatecriticalUpdate.exe"Affilred adware"
Xmsupdateupdate.exe"Added by a variant of the SDBOT WORM!"
XMSupdate.exeN/A"CoolWebSearch parasite variant - resets home page to an adult content site"
Xmsvcc25salvage.exe"Added by a variant of the SDBOT WORM!"
Xmswavemswave.exe"Added by the CRYPTER.A TROJAN!"
XMSWinupdatewinupdate.exe"Added by the DLOADR-AAW TROJAN!"
XMsys32morfitwebentrance.exe"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage"
XMultimedia extensionsmservice.exe"EasySearch adware"
Nmumservicemumservice.exe"Software updater for Motorola products"
Xmxjxde.exemxjxde.exe"Added by the ORCU.B TROJAN!"
XMy Web Search Community Toolsm3IMPipe.exe"MyWebSearch parasite"
XMyappservice.exeHomepage hijacker
XMyDailyHoroscopeMyDailyHoroscope.exe"MyDailyHoroscope foistware"
XMyFastAccessmyfastupdate.exeMy-Fast-Access toolbar updater
UMyIE.exeMyIE.exe"MyIE2/Maxthon browser related"
XmyMh2iexpl0re.exe"Added by the AGENT.HWE TROJAN! Note the number ""0"" in the filename"
XMyPcSecureMyPcSecure.exe"MyPcSecure rogue security software - not recommended
UN2PTrayNet2fone.exe"An Internet telephony application. Needed only if you have an account at Net2Phone
XNAMEDPIPE SYSTEMnamedpipe.exe"Added by the MYTOB-FH TROJAN!"
Xnapv.exewupdate.exe"Added by the AGOBOT-JX BACKDOOR!"
UNaviscopenaviscope.exe"Naviscope is a multipurpose browser enhancement that can speed up Web searches
XNAV_UpdateNAV_Update.exeUnidentified WORM or TROJAN!
UNB ProbeNBProbe.exe"Monitors the status of notebooks from ASUS - including CPU (speed
XNBT System alias[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM!"
XNet Command Senternvscvse.exe"Added by the IRCBOT!DF6280E5 VIRUS!"
?netfxupdatenetfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
XNetMeterNielsenOnline.exe"NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited
Xnetmondllcache.exe"Added by the BCKDR-RAA TROJAN!"
UNetscapeInstallService.exeRelated to Netscape installation
NNetscape MessengerNETSCAPE.EXE"In Netscape 6 (I know for sure with 6.2.1
UNetTimeNETTIME.EXE"From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols
XNiroFile UpdatedNiroFile.exe"Added by a variant of the IRCBOT TROJAN!"
UNNADFREEAdFree.exe"Ad-Free by Net Nanny - ""is customizable software for blocking unwanted Internet advertising in your home
XNoAdwareNoAdware.exe"NoAdware - spyware remover. This version is not recommended - see here"
NNokia Ovi SuiteNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
NNokiaOviSuiteNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
NNokiaOviSuite.exeNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
XNortE Antivirusnorte.exe"Added by the RBOT.BQQ WORM!"
XNorton Auto-Protectffbaqe.exe"Added by the SLINBOT.RF BACKDOOR! Note - this is not a valid Norton product"
XNorton UpdateccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton UpdatecUpdate.exe"Added by the AGOBOT.APP WORM!"
XNorton UpdaterNortonUpdate.exeAdded by an unidentified WORM or TROJAN!
XNorton UpdaterccUpdate.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
Xnsense.exe"Added by the AGOBOT-ML WORM!"
UNsengineNsengine.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here"
XNSupdateNSupdate.exe"Added by the Dial/Laet-B premium rate dialer!"
Xnternet Exploreriexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XNTmessageSystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
UnTunenTune.exe"Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures
UNuvaTimeNuvaTime.exe"NuvaTime - reminder for women using NuvaRing"
UNVIDIA nTunenTune.exe"Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures
UNVIDIA® NVRAIDnvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
Xnvjxuenvjxue.exe"Added by the EYEVEG-J WORM!"
UNVRaidServicenvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
Nocrawareocraware.exe"Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications
XOfficeOffice.exe"Added by the KRAIMER.12 TROJAN!"
XOfficeWord MonitorsOfflce.exe"Added by the IRCBOT.JZ TROJAN!"
XOKGOwinutade.exe"Added by the BANKER-EHZ TROJAN!"
NOnlineTimeonlinetime.exe"OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs"
XOpen Siteopnste.exe"OpenSite adware"
XOpen Siteopensite.exe"OpenSite adware"
XOpen2Enterrunme.exeAdult content dialler
UOpenwares LiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XOPTIMIZERiexplore.exe"Added by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOPTIMIZERiexplore.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
UOPTMOUSEMOUSEoptmouse.exe"Related to a Samsung optical mouse"
XOrbitUpdateupdate.exe"Xupiter OrbitExplorer toolbar related. Drive-by foistware. Use Spybot S&D
XOuterinfoUpdateOuterinfoUpdate.exe"Clickspring.Outerinfo adware"
XOutLooksInSane.exe"Added by the SWOOP TROJAN!"
Xoutpostupdateoutpostupdate.exe"Added by the COSIAM-C TROJAN!"
Xovyriwitelace.exe"Added by the SDBOT.BVS WORM!"
NPadTouchPadExe.exeToshiba Touch and Launch - offers easy movement and freedom of programs navigation with TouchPad
XPalNetawarepnetaware.exePalTalk adware - as included in Morpheus
NPaltalkNetaware.exePALNETAW~1.EXEVoice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start → Programs. Delete the shortcut in Start → Programs → StartUp as well otherwise it will be reinstated
XPandaAVEnginePandaAVEngine.exe"Added by the NETSKY.R WORM!"
?Pathlide.exe"??"
Xpathnamepathname.exe"Added by the IRCCONTACT TROJAN!"
XPayTimepaytime.exe"Added by the STARTPA-YR TROJAN!"
UPC Pitstop Optimize SchedulerPCPOptimize.exe"Scheduler for the Optimize system optimization utility from PC Pitstop"
NPC SuitePCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
NPC Suite TrayPCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
XPC-AntispywarePC-Antispyware.exe"PC-AntiSpyware rogue spyware remover - not recommended"
Ypccguide.exepccguide.exe"Part of Trend Micro web-security products - Internet Security 2005-2007
NPCDRealtimerealtime.exe"Apparently the monitoring device for PC Doctor Online. It provides a ""free"" examination on system files (i.e. registry)
XPcEXPLODEspecialfile.exe"Added by the RBOT.RH WORM!"
UPcEyepceye.exe"PCEye 2000 - parental control utility"
XPCHEasySearchSTUpdate.exePCH EasySearch bar
UPCLEPCIppe.exe"Pinnacle Systems PCI Performance Enhancer. "This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards.""
NPCMServicePCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
UPCPitStopEraserPCPitStopErase.exe"""PC PitStop Erase is both a free privacy scanner and paid tracks cleaner"""
UPCPOptimizePCPOptimize.exe"Scheduler for the Optimize system optimization utility from PC Pitstop"
XPcsSecurePcsSecure.exe"PcsSecure rogue security software - not recommended
NPCSuitePCSuite.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
UPCTVOICEpctvoice.exe"The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it
UPDEnginePDEngine.exe"PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot"
Npdservicepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
NPDService.exepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
?PDVD8LanguageShortcutLanguage.exe"Part of Cyberlink's PowerDVD version 8. Language settings?"
?PeeramidPService.exe"In a ""Koptimizer"" folder in Program Files. What does it do and is it required?"
UPent@VALUE 3.2Pent@VALUE.exePent@VALUE Digital Satellite Internet PC Receiver
XPest-CapturePestCapture.exe"PestCapture rogue security software - not recommended
XPestCapturePestCapture.exe"PestCapture rogue security software - not recommended
UPGPSERVICEpgpservice.exe"PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice
?PhilipsLimeLimeAlive.exe"Associated with some Philips portable media players such as the GoGear. What does it do and is it required?"
UPhilipsRemotePhilipsRemote.exe"Remote control support for MusicMatch Jukebox on Philips audio players such as the AZ2555 Sound Machine - see
UPhraseExpressphrase.exe"""PhraseExpress organizes your frequently used text phrases and allows pasting them into any application"""
UPicture Package VCD MakerResidence.exe"Sony Picture Package software for their range of Digital Handycam video cameras. Used to connect the camcorder via USB and allows the user to burn the content directly to a CD"
XPIPE SYSTEMpipe.exe"Added by the MYTOB-FF WORM!"
NPlayMoviePMVService.exe"Part of Acer Arcade Deluxe lets you browse pictures
NPLNRNotePLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
XPluto! Pagersrvhandle.exe"Added by the REDPLUT VIRUS!"
UPMTpersonalmoneytree.exe"According to the web site Personal Money Tree is an automatic cash rebate program. Note: Not recommended"
XPofatchnstrue.exe"Added by the RANDEX.Z WORM!"
XPoliceAVxppolice.exe"XP Police Antivirus rogue security software - not recommended
XPollonpollone.exe"Added by the SPYBOT.FW WORM!"
UPopUpStopperFreeEditionPSFREE.EXE"Panicware's Pop-Up Stopper - free limited features version"
XPornfolioioande.exe"Added by the SDBOT.ATW WORM!"
NPost-itR Software Notes LitePsn2Lite.exe"Post-it® Software Notes - Lite from 3M - now replaced by the more advanced Post-it® Digital Notes"
YPowerChutePwrchute.exe""During a power outage
XPowerChutePwrchute.exe"Added by the LAZAR-A TROJAN! Note - this is located in %ProgramFiles%\APC_Power"
UPowerForPhonePowerForPhone.exe"""ASUS Power 4 Phone is a telephone terminal emulation utility which can use hotkeys to handle a phone call from Skype or Modem in your notebook system."" For more information you can find a user's manual here"
UPower_GearBatteryLife.exePower management for all Asus notebook. Useful but not critical
UPPCRunoncePPCRunOnce.exe"Related to PeoplePC ISP software - may display advertising
UPPK Setup(Server)SEServe.exe"Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button
Nppmateppmate.exe"PPMate - free tool for streaming online TV via P2P (peer-to-peer)"
XPPPOEOEwinlite.exe"Added by the RBOT-AAN WORM!"
NPrecision Time Clock CheckerPrecisionTime.exePrecision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
XPrecisionTimePrecisionTime.exe"PrecisionTime - clock synchronizing software containg spyware by Claria/GAIN. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XPreInstall Windows[path] repcale.exe [path] beird.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\detr"
YPrevxOnePXConsole.exe"Prevx intrusion prevention software"
NPrint Screen Deluxepsdeluxe.exe"Utility allows "Print Scrn" or "Print Screen" key to capture
XPrinterSpool[path] RESTORE.EXE [path] SPOOL.EXE"Added by the ALADINZ.K TROJAN!"
NPrintScreenUNWISE.EXE"Gadwin PrintScreen - utility to capture
NPrivateDiskpdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
XProc993wqxfne.exe"Added by the IXBOT-D WORM!"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
XPromoRegalt.exe.exeAdded by a variant of the AGENT.DOM TROJAN!
XProvan Securitypsecure.exe"Added by the RBOT.BRV WORM!"
XPruotaee.exe"PurityScan adware"
UPSFreePSFree.exe"Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
NPsnLitePsnLite.exe"Post-it® Software Notes - Lite. ""You can use this digital version of the famous canary yellow note to remind you to do something
UPubellePubelle.exe"Pubelle - French popup blocker by Guillaume Ryder"
UPurge with Current OptionsPURGEIE.EXE"PurgeIE from Assistance & Resources for Computing
XPVModulepvmodule.exe"Adperform.com/Adoptim.com adware - located in %ProgramFiles%\PrintView and detected by Avira AntiVir antivirus as the AGENT.ALB TROJAN! NOTE - the 'real' PrintView installs in C:\CBR folder"
UPwrsavePwrsave.exeToshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
XPYJJIMEPYJJIME.exe"Added by the AGENT-BXQ TROJAN!"
?qBrowseqbrowse.exe"??"
UQPServiceQPService.exe"HP QuickPlay - ""brings your favorite music and movies to life with the touch of a button"""
Xqservicesqservice.exe"Added by the PROGENT-A TROJAN!"
XQuantifier Securityqsecue.exe"Added by the SPYBOT.UOL WORM!"
YQuick Heal On-Line ProtectionCateye.exe"Quick Heal - virus scanner"
XQuick Officeactivate.exe"Added by the RANSOMLOCK.D TROJAN! Note - this infection hooks the keyboard to prevent anything except numbers from being typed and displays a Russian message requesting a valid license key"
NQuickbooks Update Agentqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
NQuicknotequicknote.exe"JC&MB Quicknote Virtual Scrapbook"
XQuickTimeUpdateQuickUpdate.exe"Added by the BIFROSE-CW TROJAN!"
Xqweqwe.exe"Added by the LINEAGE-F TROJAN!"
XRA ServerSlave.exeAdded by the RA TROJAN!
URamIdleramidle.exe"RAM Idle LE - ""A smart memory management program that will keep your computer running better
URAMpageRAMpage.exe"Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon
XRandex virus built for IRBMeirbme.exe"Added by the RANDEX.RH WORM!"
XRaptorDefenceRaptorDefence.exe"RaptorDefence rogue security software - not recommended
Xrate.exei11r54n4.exe"Added by the BEAGLE-I WORM!"
Xrate.exei1ru74n4.exe"Added by the BEAGLE.E WORM and variants!"
XRavAvRavMonE.exe"Added by the RJUMPF-F WORM!"
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
Xravshelliexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
Xravtaskiexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
XRavUptetsagetlke.exe"Added by the QQPASS-AK TROJAN!"
XrCrondservice.exe"""Switch"" premium rate adult content dialler variant"
URE.exeRE.exe"RegistryEasy registry cleaner - regarded by Symantec as a potentially unwanted application
?RealTimeUpdateRealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
NRecSheRecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
URefereereferee.exe"MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run"
Xregeditautoexe.exe"Added by a variant of the RBOT WORM!"
XRegFreezeregfreeze.exe"RegFreeze rogue spyware remover - not recommended
XRegister ManagerRegistryManage.exe"Added by the SDBOT.AYH WORM!"
XRegistry Value Nameservice.exe"Added by the RBOT-AHT WORM!"
XRegistryMonitorsysfade.exe"Added by the SYSFADE TROJAN!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
?RegServerregserve.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
NRegShaveregshave.exe"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers
Xreg_keyloader_name.exe"Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!"
URemindMeRemindMe.exe"Remind-Me - calendar software"
URemoteRemote.exe"Remote Control driver for LifeView internal and external TV products"
XRESpyWare.exeRESpyWare.exe"RESpyWare rogue security software - not recommended
XRestorerestore.exe"Antispyware Shield Pro rogue security software - not recommended
Xretimeretime.exe"Added by the GIPMA TROJAN!"
?RMremoteRmRemote.exe"Remote control driver for REALmagic Xcard. Is it required?"
Xrn4ddirote.exe"Added by the MAROON.A TROJAN!"
URocket.TimeRocketTime.exe"Rocket.Time - time synchronization software from Rocket Software"
Xromaherematrixhere.exe"SuperSpider hijacker - a CoolWebSearch parasite variant"
Xrune.exe"Added by the IMONI-E TROJAN!"
Xrun=msoffice.exe"Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file
URunAlertAService.exe"PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/2K"
Xrundll***die.exe [path] mdll.exe"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] secure.bat"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] secure.exe"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] ttg.exe"Added by the SUMTAX TROJAN! where *** is 134
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
XRUNGogoToolsLaunchAdware.exe"GoGoTools adware"
URunOnceRUNONCE.EXEPart of MS Data Access Components - only required if you use these
XRunoncerunouce.exe"Added by the CHIR-B WORM!"
Xruntime.exeruntime.exeAdded by a variant of the Tibs malware
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
Xrxexplore.exe"Added by the ZHENGTU-A TROJAN!"
Xryan1918servidevice.exe"Added by the RBOT-GVR WORM!"
Xrydanmxe.exerydanmxe.exe"Added by the DLOADR-AZZ TROJAN!"
Xr_serverservice.exe"Added by the MULTIDR-CP TROJAN!"
?SA ServiceSAservice.exe"Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?"
XSafeSurfingUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
XSagate Security Firewallsagate.exe"Added by the GAOBOT.BOW WORM!"
XSAHBundlebundle.exe"ShopAtHomeSelect parasite"
Xsaiesaie.exe"180solutions adware"
NSalaatTimeSalaatTime.exe"""Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"""
Xsasserfixpackage.exe"Added by the DABBER.B WORM!"
USAUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
USAutoLaunchExeSAutoLaunchExe.exe"Sharp Zaurus PDA related
XSaveSave.exe"WhenU.Save adware"
XSaveDateSaveStartDate.ExeUnidentified adware
XSaveDefenseSaveDefense.exe"SaveDefense rogue security software - not recommended
USay The Time 5.0SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
USBAutoUpdatesbautoupdate.exe"SpywareBlaster auto-updater"
XScanRegistryupdate.exe"Added by the DWNLDR-FZY TROJAN!"
XscAppwmiprvse.exe"Added by the SILLYFDC-AW WORM!"
UScheduleSchedule.exe"Scheduler for Mercury Ez View TV Tuner Card"
NScheduled MaintenanceScheduled_Maintenance.exe"Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xsdfsdfsdfsp2update.exe"Added by a variant of the SPYBOT WORM!"
XSDK Core Componentsdkcore.exe"Added by the SDBOT-WC WORM!"
Xsdkupdate22SDK0mCORE.exe"Added by the FORBOT-DT WORM!"
XSearch-ExeSE.exe"Search-Exe hijacker"
Xsecdrive.exesecdrive.exe"Added by a variant of the SPYBOT WORM! See here"
Xsecures23mssecure.exe"Added by the AGOBOT-ABY WORM!"
XSecurityWindowsSecurityUpdate.exe"Added by a variant of the SDBOT WORM!"
XSecurity Service DBsecservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
Xseeveseeve.exe"Medload adware"
XSepate Security Firewallsepate.exe"Added by the RBOT.BLC BACKDOOR!"
NSEPCSuiteSEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XServiceservice.exe"Added by the ALADINZ.H TROJAN!"
XService Controllerservice.exe"Added by the PREVERT TROJAN!"
Xservice managerservice.exe"Added by the DONBOMB.A TROJAN!"
XService Monitormsnserve.exe"Added by the SPYBOT.YQW WORM!"
XService Processservice.exe"Added by the DCMBOT-C TROJAN!"
XService.exeService.exe"""servedby.advertising"" popup generator"
Xservicemngservice.exe"Added by the TAME-C WORM!"
XServicesback32.exe ...service.exe"Added by an unidentified VIRUS
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
Xservicessample.exe"Added by a variant of the RANKY TROJAN!"
XSERVlCESERVlCE.EXE"Added by the AGOBOT-UB WORM!"
NSETI@homeSETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
NseticlientSETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
XShellExplorer.exe iexplore.exe"Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
XShell32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShellapi32mcvsrte.exeAdded by an unidentified WORM! Note - do not confuse with the McAfee SecurityCenter file of the same name
XShellRun32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShineShine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
XShmgrate.exeibot4.exe"Added by the GASTER TROJAN!"
NShopSafeShopSafe.exe"Created by Orbiscom for MNBA (now Bank of America) - ShopSafe creates a temporary card number each time you make an online purchase"
UShortKeys Liteshklite.exe"ShortKeys Lite from Insight Software Solutions
UShutdownawareshutdownaware.exe"Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system"
XSingaporesingapore.exe"Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself"
UsiService.exesiService.exe"Spam Inspector - anti email spam software"
XSiteAdware.exeSiteAdware.exe"SiteAdware rogue security software - not recommended
Xskynetave.exeskynetave.exe"Added by the SASSER.D WORM!"
NSkypeSkype.exe"Skype is ""free calls
NSkypeMateSkypeMate.exe"SkypeMate acts as a bridge between networks of VoIP and PSTN"
XSkypeStartupSkype.exe"Added by the PYKSE-A WORM!"
Xslack12mfcee.exe"Added by a variant of the SDBOT WORM!"
XslideIexplore.exe"Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
Yslipcoreslipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques
YSlipStreamslipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques
Xsmsa_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsf_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsm_exe.exe"Added by the OLFEB.A TROJAN!"
Xsmsr_exe.exe"Added by the LUKUSPAM TROJAN!"
XSmallAndSecuremssecure.exe"Added by the RBOT.CU WORM!"
Usmodulsmodule.exe"UserMonitor from Neuber. Teachers can broadcast screen to other screens
Xsmrtdrvruntime.exe"Added by the AGOBOT.MT WORM!"
XSMSERIALWORKERSTARTERwinstrse.exe"Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended
Xsnapplesnapple.exe"Added by the FORBOT-EG WORM!"
NsofficeSOFFICE.EXEDisplays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
USoftickPPPPPPGate.exe"Softick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer"
XSoftwaresoftware.exe"Added by the CRABTON-B TROJAN!"
NSolidCapturesolidcapture.exe"SolidCapture - screen capture and image sharing toolkit"
USolidWorks Task Scheduler EngineswBOEngine.exe"Task scheduler for SolidWorks 3D CAD software"
NSony Ericsson PC SuiteSEPCSuite.exe"System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XSP2 data[path] repcale.exe [path] apc.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\winstat"
Xsp2updatesp2update.exe"SP2Update adware! Tracks URLs visited and search terms entered into Internet Explorer"
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
?sppbridgesppbridge.exe"Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? "
USpriteServiceSpriteService.exe"Sprite Backup is a backup application for Windows Mobile Pocket PC or Smartphone"
XSpruce - Auto UpdateSpruce.exe"Rabio ""Search Enhancer"" adware variant"
XSpyAxespyaxe.exe"SpyAxe rogue spyware remover - not recommended"
XSpyFighterUpdateAutoUpdate.exe"SpyFighter spyware remover - not recommended
Xspysnipespysnipe.exe"SpySnipe rogue security software - not recommended"
XSpywareSpyware.exe"BPS spyware remover - not recommended
USpyware BegoneSpywareBeGone.exe"Spyware BeGone - spyware remover. Previously not recommended
XSpyware QuakeSpywareQuake.exe"SpywareQuake 2.0 rogue spyware remover - not recommended
XSpyware removerRemove_spyware.exe"Unidentified
XSpywareCease.exeSpywareCease.exe"Spyware Cease rogue security software - not recommended"
XSpywareQuakeSpywareQuake.exe"SpywareQuake 2.0 rogue spyware remover - not recommended
XSpywareQuake.comSpyware-Quake.exe"SpywareQuake 2.0 rogue spyware remover - not recommended
XSpywareStrikeSpywareStrike.exe"SpywareStrike rogue spyware remover - not recommended
YSpywareTerminatorUpdateSpywareTerminatorUpdate.exe"Automatic updates for Spyware Terminator. Initially not recommended due to false positives but the later versions have since improved - see here"
XSpyWatchESpyWatchE.exe"SpyWatchE rogue security software - not recommended
Xssate.exeirun4.exe"Added by the BEAGLE.J WORM!"
Xssate.exewinsys.exe"Added by the BEAGLE.K WORM!"
NSSBkgdUpdateSSBkgdupdate.exe"Automatic updates for ScanSoft (now Nuance) products such as OmniPage and PaperPort. Can be disabled using the main program's options. Note - if you have a Soundblaster Audigy2 ZS soundcard installed on your computer and the volume of your sound system is turned on extremely high disabling this will solve the problem"
Xssgrate.exesystem.exe"Added by the MITGLIEDER.C TROJAN!"
Xssgrate.exeirun.exe"Added by the MITGLIEDER.D TROJAN!"
Xssgrate.exeirun4.exe"Added by the MITGLIEDER.F TROJAN!"
Xssgrate.exesysdoor.exe"Added by the MITGLIEDER.N TROJAN!"
Xssgrate.exewinerdir.exe"Added by the MITGLIEDER.O TROJAN!"
Xssgrate.exewinsystems.exe"Added by the BAGLEDL-J TROJAN!"
Xssgrate.exewintems.exe"Added by the MITGLIEDER.Q TROJAN!"
XSSUpdateSSUpdate.exe"MoneyTree parasite - ActiveX control used to download premium-rate dialers"
Xstaeck12mfcee.exeAdded by an unidentified WORM or TROJAN!
Xstaeck122mfceee.exeAdded by an unidentified WORM or TROJAN!
Xstandalone.exestandalone.exe"Added by the AGOBOT-ADS WORM!"
Xstart extractingspoolvse.exe"Added by the RBOT-XF WORM!"
Xstart extractingmcafee.exe"Added by the RBOT.FO BACKDOOR! Note - this is not a valid McAfee program and is located in %System%"
YStart RF Wireless Keyboardktrexe.exeYuanxun Electronics RF wireless keyboard driver
XStart Uppingsmssupdate.exe"Added by a variant of the RBOT WORM!"
UStartEaseStartEase.exe"
Xstarteriexplore.exe"Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
UStartFoxieStartFoxie.exe"Foxie Suite from Softonic International. ""This suite of free tools comes in the form of an Internet Explorer add-on and includes a mix of powerful security enhancements"""
Xstartkeyupdate.exe"Added by the BIFROSE-DG TROJAN!"
XStartKeypligde.exe"Added by the BIFROSE.E TROJAN!"
Xstartkeyroyale.exe"Added by a variant of the SDBOT WORM!"
XStartKeymsnmsie.exe"Added by the BIFROSE.M BACKDOOR!"
XStartMenubrowse.exe"Added by the DROWSY-C TROJAN!"
Xstartpagestartpage.exeBrowser hijacker - redirecting to pages2start.com
XStartReplySystemloadnewmessage.exe"Added by the HIDAGENT-B WORM!"
UStayAliveStayAlive.Exe"Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
NStickyNoteStickyNote.exeUtility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
UStreamZap Remotezremote.exe"StreamZap PC Remote - control Windows Media Player
Xstrmsoumsmsnmegrse.exe"Added by the SDBOT-ZK TROJAN!"
XStubPathSservice.exe"Added by the PRORAT TROJAN!"
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
USuitcase StartupSuitcase.exe"Suitcase - system font manager start up utility. Used for dynamic managment of fonts on your system"
XSun Java Console for Windows NT & XPjconsole.exe"Added by the VANEBOT-C WORM!"
XSun Java Updater v5javajre.exe"Added by the AUTORUN-XI WORM!"
XSunJava Updater v7javale.exe"Added by the ACKANTTA.B WORM!"
Xsupdatesupdate.exe"Added by the MALWARE.D TROJAN!"
YSUPERAntiSpywareSUPERAntiSpyware.exe"SUPERAntiSpyware - spyware
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSwf32AVupdate.exe"Added by the MERKUR.E WORM!"
XSygaete Personal FirewallSyGate.exe"Added by the RBOT-GLX WORM!"
XSygate Personal FirewallSygate.exe"Added by the RBOT-PN WORM!"
XSygate Personal FirewallMcafeeupdate.exe"Added by the RBOT.YN WORM!"
XSygate Personal Firewallservice.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Port Blockervolume.exe"Added by a variant of the RBOT WORM!"
XSygate Personal Port Blockerwinupdate.exe"Added by a variant of the RBOT WORM!"
USymmTimeGeTTime.exe"SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
USymmTimeSymmTime.exe"Older version of SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
USymmTime ApplicationGeTTime.exe"SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
?SynSetupSynTP.tmp RunOnce.exe"Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
XSys-Statwuapdxe.exe"Added by the SDBOT.HK WORM!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSysDefence.exeSysDefence.exe"SysDefence rogue security software - not recommended
XSysLiveSysLive.exe"Added by the EXPICHU WORM!"
Xsysmesysme.exe"Added by the PSW_STEALER_C TROJAN!"
Xsysmemmmsete.exe"Added by the NOPIR.C WORM!"
XSysMonwowexece.exe"Added by the MULAN-A TROJAN!"
Xsysnatesysnate.exe"Added by the MEDIAS TROJAN!"
Xsysparesyspare.exe"Added by the BIFROSE-AN TROJAN!"
XSyssehuupdate.exe"EHU adware"
USysSenseSysSense.exe"""SysSense is your personal desktop Google AdSense monitor. It keeps your current Google AdSense information in the Windows system tray"". Google AdSense account required"
XSysServiceSysService.exe"Added by the BDFORM-A BACKDOOR!"
Xsystemlsasse.exe"Added by the RBOT-YL WORM!"
XSYSTEMSystemFile.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsystemssclie.exe"Added by the AGENT.LW BACKDOOR!"
XsystemMicrosoft Office.exe"Added by the BANCBAN-LH TROJAN!"
XSystemIEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
XSystem CacheSysCache.exe"Added by an unidentified VIRUS
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xsystem handlersrvhandle.exe"Added by the REDPLUT VIRUS!"
XSystem Information ManagerNavcpe.exe"Added by the SDBOT-QB WORM!"
XSystem Information Manageriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Monitoringcute.exe"Added by the RAHIWI.A WORM!"
XSystem Restore Data[path] repcale.exe [path] beird.exe"Added by the RANDON.AN WORM! Both files are located in %System%\frbyjed"
XSystem ServiceMSREXE.EXE"Added by the AML TROJAN!"
XSystem Servicemsnxpexe.exe"Added by the RBOT-AUA WORM!"
XSystem Servlcelive.exe"Added by the IRCBOT-GX WORM!"
XSystem time updatorCSysTime.exe"Added by the RANDEX.S WORM!"
XSystem Update2update.exe"Added by the AUTOTROJ-C TROJAN!"
XSystem Updatesunve.exe"Added by the RBOT-AWG TROJAN!"
Xsystem32QQGame.exe"Added by the QQPASS-AC TROJAN!"
USystemAgentSage.exe"""Microsoft Plus! System Agent automatically tunes your system
XSystemExplorerexplore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
XSystemFileSystemFile.exe"Added by the DULLDOOR-A TROJAN!"
USystemSafeSyssafe.exe"System Safety Monitor - system monitoring tool with additional application firewalling"
XSystemServiceqservice.exePremium rate adult content dialler
XSysTimesystime.exe"CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN!"
Xsystr2SERVICE.exe"Added by the VB-DQY WORM!"
XSystray[filename.exe]"Winfavorites adware"
Xsystreesystree.exe"Added by the BANCOS.L TROJAN!"
XSYS_CLEANService.exe"Added by the FLOPCOPY WORM!"
UT3ConsoleT3Console.exe"Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data"
XTabastte.exe"PurityScan adware"
YTaskbar Shuffletaskbarshuffle.exe"""Taskbar Shuffle is a simple
Ytaskbarshuffletaskbarshuffle.exe"""Taskbar Shuffle is a simple
XTaskmansysdate.exe"Added by the SILLYFDC.BCQ WORM!"
Xtaskmngr[path] msnve.exe [path] task.exe"Added by the FLOOD-EK TROJAN!"
Xtaskmonetaskmone.exe"Added by the SINGU-S TROJAN!"
YTBLFUNCtblmouse.exe"Aiptek HyperPen graphics tablet driver"
XTelephony ProviderIexplore.exe"Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XTethdrle.exe"PurityScan adware"
NTGPro OfficeIdxOffice.exe"With IdiomaX Office Translator ""you can translate documents directly from your favorite text editor (Microsoft Word
XTigerShine.exe"Added by the HAPPYLOW (or NISHE-A) VIRUS!"
NTimed Backups Manager StartupBACKTIME.EXE"Backup Plus - backup software"
NTimeOnlineTIMEONLINE.EXELightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
Xtimessquaretimessquare.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
XTimeSyncAppTimeSynchronize.exe"DealHelper adware"
UTimezoneTimeZone.exe"Microsoft Daylight Saving Time Update Utility - see here"
XTinueTinue.exe"Added by the SILLYFDC.BCO WORM!"
UTitlebar DateTitlebar Date.exe"Titlebar Date by Titlebar Software - displays the day of the week and date and time in the active window's tile bar. For example
UTitlebar TimeTitlebar Time.exe"Titlebar Time by Titlebar Software - displays the day of the week
UTitleTimeTiTime.exe"""TitleTime adds the current date and/or time to the Caption of the currently active application window. Additional options are a second clock (with a different time)
NTK8 EasyNoteEasyNote.exe"TK8 EasyNote - desktop post-it notes"
XTkNetDriver Monitorlexbce.exe"Added by the SDBOT-ADF WORM!"
Xtmaxpupdate.exeAdware pop-up generator
UTMEEJME.EXETMEEJME.EXEToshiba TME (Toshiba Mobile Extension) Control
XTmNetDriver Monitorexbce.exe"Added by the SDBOT-ABR WORM!"
UTMOUSEtmouse.exe"Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL + ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL + SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects
Xtmp_upsample.exeQuickBar adware
XTok-CirrhatusIDTemplate.exe"Added by the RONTOKBRO.A WORM!"
NTomTomHOME.exeTomTomHOME.exe"TomTom HOME - free management program for your PC to look after their GPS navigation products"
UToshiba Key StateKEYSTATE.EXE"Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g.
UTouchFreezeTouchFreeze.exe"TouchFreeze is simple utility for Windows that automatically disables the touchpad on notebooks while you are typing text - so that you can avoid accidentally changing the position of the cursor in your document or clicking on an option"
Utpopservicetpopservice.exeDirecWay two-way satellite internet service enhanced POP proxy server for email
UTracks Eraserte.exe"Tracks Eraser from Acesoft - "Erases all tracks of your internet activity""
UTracks Eraser Prote.exe"Tracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity""
NTray DateTray Date.exe"Tray Date by Titlebar Software - displays a simple icon in the System Tray (that can't be configured) which shows the current date. The originator's website is no longer available but you can still download it here. Whilst it only uses around 10MB of memory
Utraydate.exeTRAYDATE.EXETrayDate - displays the date as well as the time in the System Tray
Xtruetypetruetype.exe"Added by the COSIAM-I TROJAN!"
?TSServiceNSSERVICE.EXE"??"
Ntunebitetunebite.exe"""Tunebite lets you make unprotected copies of copy-protected music files by recording them while they are being played"". Can be launched from it's Start Menu shortcut"
UTurboExplorerTE.exe"Web accelerator - ""TurboExplorer 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing"
NTurboNotetbnote.exePost-It's on your desktop. Available via Start -> Programs
UTvrRemoteRemote.exe"Remote Control driver for LifeView internal and external TV products"
UTvrScheduleSchedule.exe"Scheduler for Mercury Ez View TV Tuner Card"
UTweak-MeTWEAK-ME.exe"3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support)
XTXMouiekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XUpdateUpdate.exe"QuickButton adware"
XUpdateWinUpdate.exe"Added by the SDBOT-CV BACKDOOR!"
YUpdate ServiceUpdate.exe"Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate.exeravseuper.exe"Added by the QQPASS-P TROJAN!"
Xupdaterealrealupdate.exeChinese originated adware
XUpdatesmsupdate.exe"CoolWebSearch parasite variant"
XUpdateServicewservice.exe"Added by the DREF-K WORM!"
Xupdatewinupdate.exe"Added by a variant of the SDBOT WORM!"
XUPNPServiceWinSVCservice.exe"Added by the AGOBOT.UN WORM!"
UUpromiseUpromise.exe"Upromise college savings program"
XUpToDateuptodate.exe"BrowserAid/BrowserPal foistware"
Xuptolatenucle.exeAdded by a variant of the BIFROSE TROJAN!
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XUSB Hardware MonitoringUSBhardware.exe"Added by the RBOT-NN WORM!"
UUSBPhoneforSkypeUSBPhoneforSkype.exe"USBPhoneForSkype uses Skype to dial out from a generic USB phone"
XUser Sharingusrshare.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Wizardusnshare.exe"Added by the SLENFBOT.DF WORM!"
XUSERINTERFACE REPORT3RM0USE.exe"Added by the MYTOB.HS WORM!"
UUStoragustorage.exe"U-Storage is application software running under Microsoft Windows
NUstorageUstorage.exe"Maintenance tool (enable security functions) for a USB drive from Pretec"
YVade Retro Outlook ExpressVaderetro_oe.exe"Vade Retro anti-spam software for Outlook Express from GOTO software products"
XVCatch PremiumVCatchpre.exe"VCatch antivirus. Considered spyware itself - see here"
XvcbbjfkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xverseverse.exe"Added by the STAP-C WORM!"
XVersionmanage.exe"JRAUN adware variant"
XVGATuneVGATune.exe"Added by the RBOT-AWM WORM!"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
UViGlanceViGlance.exe"ViGlance (Windows 7 SuperBar for XP) adds a Windows 7 style SuperBar for Windows XP users and can be loaded at boot time or started manually"
Xvipantispywarevipantispyware.exe"VipAntiSpyware rogue spyware remover - not recommended"
XVirusRescueVirusRescue.exe"VirusRescue rogue security software - not recommended"
UViSploreViSplore.exe"ViSplore (Glass Browser for XP) adds a Vista style file browser for Windows XP users"
XVistaDriveVistaDrive.exe"VistaDrive malware"
XVistaUpgradevistaupgrade.exe"Added by the STRATION-AX WORM!"
?VMConsole.exeVMConsole.exe"Sony VAIO Media Console - installed on the VAIO Media Integrated Server PCs. What does it do and is it required?"
UVOBIDInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
Uvoip phonevoip phone.exe"Related to Acer Bluetooth VoIP phone - as optionally supplied with some of their notebooks such as the TravelMate 8200"
NVoipwiseVoipwise.exe"Voipwise - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NWasherie.exewasherie.exe"Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer
XWDNS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
UWDSmartWareWDSmartWare.exe"Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range"
UWeather Pulseweatherpulse.exe"Weather Pulse from Tropic Designs. ""Display popular Satellite images and video from around the globe
NWeatherEyeWeatherEye.exe"WeatherEye - desktop weather from TheWeatherNetwork"
NWeatherscopeWeatherscope.exe"WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xwebalizewebalize.exe"Searchcentrix hijacker"
NWebDrivewebdrive.exe"System Tray access to WebDrive from South River Technologies
NWebDriveTraywebdrive.exe"System Tray access to WebDrive from South River Technologies
Uwebsaverlivewebsaverlive.exe"WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle"
NWelcomeWelcome.exeLaunches the Welcome to Windows tutorial on boot up
UWG111v2 Smart Wizard Wireless SettingRtlWake.exe"Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
UWhatPulseWhatPulse.exe"WhatPulse collects statistics on how much you type on your computer and sends this information to a server. It is not a keylogger which monitors your keystrokes and what you type - it only counts the number of keystrokes"
XWhenUSaveSave.exe"WhenU.Save adware"
XWhenUSearchWHSEwhse.exe"WhenU.Save adware"
Xwidelinkwidelinke.exe"WideLink adware. File located in %Program Files%\widelink"
XWill I Everanqbse.exe"Added by the SDBOT-TK WORM!"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
Xwin updatewapdate.exe"Added by a variant of the RBOT WORM!"
XWin UpdateSysUpdate.exe"Added by the AGOBOT-TN WORM!"
XWin Updateoleupdate.exe"Added by the AGENT-UY TROJAN!"
Xwin updatewupdate.exe"Added by the RBOT-P BACKDOOR!"
XWin32Game.exe.vbs"Added by the SCAFENE WORM!"
XWin32 Kernel Updatewin32update.exe"Added by the PROXY-BS TROJAN!"
XWin32 System Kernelwinservice.exe"Added by the SDBOT.KIN WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
Xwin32updatewin32update.exe"Added by the GENOME.AQUV TROJAN!"
XWinAblewinable.exe"Added by the MATCASH.BG TROJAN!"
XwinactiveWINACTIVE.EXE"WinActive variant of the LOP.com hijacker"
Xwinbin32win32exe.exe"Added by the RBOT-ZL WORM!"
UWINCINEMAMGRWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
XWindewinde.exe"Added by the DLUCA TROJAN!"
XWinDLL (mysnlive.exe)"rundll32.exe mysnlive.exestart"
XWinDLL (redyLive.exe)"rundll32.exe redyLive.exestart"
XWinDLL (service.exe)service.exe"Added by the AGENT.BX WORM! The ""service.exe"" file is found in %System%"
XWindo Servic Agenalirexe.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
Xwindow2ieupdate.exe"Added by the FORBOT-BM WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows 32 UpdateWindows-Update.exe"Added by a variant of the RBOT WORM!"
XWindows ASN Servicerge.exe"Added by the RBOT-AOK WORM!"
XWindows Auto UpdaterWINDOWSUPDATE.EXE"Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration Utilitywinxupdate.exe"Added by the AGOBOT.LW WORM!"
XWINDOWS DENEMEdeneme.exe"Added by the MYTOB-CR WORM!"
XWindows DLL Loaderwdevice.exe"Added by a variant of the SDBOT WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows Dynamic Library Cachedllcache.exe"Added by the INJECT-HT TROJAN!"
XWindows Executersvchostie.exe"Added by the EGGDROP.V BACKDOOR!"
XWindows File System Framentframe.exeAdded by an unidentified WORM or TROJAN!
XWindows Firewall Updaterwindowsupdate.exe"Added by the SPYBOT.AVEO WORM!"
XWindows Fixes Systemselite.exe"Added by the MYTOB.EG WORM!"
XWindows his LayerpilotGame.exe"Added by the RBOT.GLX WORM!"
XWindows Host Servicesvchoste.exe"Added by the KELVIR.BF WORM!"
XWindows Imagewintimage.exe"Detected by Avast as the SDBOT-GEN44 WORM!"
XWindows LiveWindowsLive.exe"Added by the REALBOT-A WORM!"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows LoaderSysUpdate.exe"Added by a variant of the SDBOT WORM!"
XWindows Logon ProcedureSvchoste.exe"Added by a variant of the SPYBOT WORM!"
XWindows Logon Servicewinlogoservice.exe"Added by the SPYBOT.ANOO WORM!"
XWindows Management Informantwmmiexe.exe"Added by the IRCBOT-V BACKDOOR!"
XWINDOWS MANAGEMENT SYSTEMwm1exe.exe"Added by the RBOT-VT WORM!"
XWindows Media Playermpwe.exe"Added by the RBOT-TT WORM!"
XWindows Media Updatercrease.exe"Added by the RBOT-ATI WORM!"
XWindows Media UpgradeNeUpgrade.exe"Added by the RBOT.BMF TROJAN!"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Mouse Serviceswinmouse.exe"Added by the IRCBOT.AGA BACKDOOR!"
XWindows MS Update 32jebote.exe"Added by the FORBOT-GK WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messengerwinmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
XWindows Net Cfgservice.exe"Added by a variant of the RBOT WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Processwin_update.exe"Added by the LASTWORD WORM!"
XWindows Protectotboxide.exe"Added by a variant of the WOOTBOT WORM!"
XWindows Reg Servicesffservice.exe"Added by the DLOADER-PL or DLOADER-XM TROJANS!"
XWindows Reg Servicesdservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesfservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Servicesssservice.exe"Added by the PRORAT-D TROJAN!"
XWindows Reg Serviceslservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Reg Serviceswservice.exe"Added by the PRORAT-O TROJAN!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Center Notification Applssxe.exe"Added by the RBOT-GKX WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security Modulemodule.exe"Added by a variant of the RBOT WORM!"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Serviceservice.exe"Added by the IRCBOT-ACV WORM!"
XWindows Service Pack Auto Updatedel-me.exe"Adware
XWindows Servicesservice.exe"Added by the RANDEX.R WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Servicesw32service.exe"Added by the AUTORUN-FU WORM!"
XWindows Servicesfilename.exe"Added by the SDBOT.FSK BACKDOOR!"
XWindows Serviceswupdate.exe"Added by the GAOBOT.ZT WORM!"
XWindows Services Guidesvcguide.exe"Added by the SLENFBOT.KQ WORM!"
XWindows smss serviceservice.exe"Added by the AGENT-FPY TROJAN!"
XWindows Softwarehbsppe.exe"Added by the RBOT-GLL WORM!"
XWindows SP2 UpdateSp2update.exe"Added by the WOOTBOT.BS WORM!"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows spyware removerWindows-spyware.exe"Added by the SystemPoser TROJAN!"
YWindows SteadyState - Bubble MessagesBubble.exe"Part of Windows SteadyState
XWindows svchostservice.exe"Added by the PUSHBOT.DU WORM!"
XWINDOWS SYSTEMnibie.exe"Added by the MYTOB-BY WORM!"
XWINDOWS SYSTEMninfoie.exe"Added by the MYTOB-EP WORM!"
XWINDOWS SYSTEMwin.exe.exe"Added by the MYTOB.FA WORM!"
XWINDOWS SYSTEMservce.exe"Added by the MYTOB-EI WORM!"
XWINDOWS SYSTEMxpupdate.exe"Added by the ZOTOB-G WORM!"
XWINDOWS SYSTEMefefefe.exe"Added by the MYTOB-KH WORM!"
XWINDOWS SYSTEMwupdate.exe"Added by the MYTOB-HT WORM!"
XWINDOWS SYSTEM By FEnRwindasz-updote.exe"Added by the MYTOB.LR WORM!"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Task Schedulerasijdie.exeAdded by an unidentified WORM or TROJAN!
XWindows Taskmanagerservice.exe"Added by the PUSHBOT.OR WORM!"
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
XWindows Updatewudate.exe"Added by the AGOBOT.ML WORM!"
XWindows Updatewupdate.exe"Wengs adware"
XWindows UpdateWindowsUpdate.exe"Added by the BAYROB-A TROJAN!"
XWindows UpdateUpdate.exe"Added by the DELF-FN TROJAN!"
XWindows Updatewinupdate.exe"Added by the SDBOT-WS WORM!"
XWindows Updatemplupdate.exe"Added by the MOEGA WORM!"
XWindows updatewudupdate.exe"ISTBar adware related"
XWindows Updatemsnsupdate.exe"Added by the RBOT-AXS WORM!"
XWindows Updatewin32update.exe"Added by the SDBOT.FTK WORM!"
XWindows UpdateMcAfee.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
XWindows Update Automationwinuptdate.exe"Added by a variant of the RBOT WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Update Controllermwoffice.exe"Added by the BATTRY-A TROJAN!"
XWindows update loaderxpupdate.exe"Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
XWindows Update Managerwupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows Update.exeN/AHomepage hijacker
XWindows Updatedspoolsae.exe"Added by the RBOT-APM WORM!"
XWindows Updaterwupdate.exe"Added by the WOOTBOT.AJ WORM!"
XWindows Updater Servcxpuupdate.exe"ContraVirus rogue security software - not recommended
XWindows Updater Servicesmsnupdate.exe"Added by a variant of the RBOT WORM!"
XWindows Updates Agentwinupdate.exe"Added by the SPYBOT.HW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB Monitorservupdate.exe"Added by the IRCBRUTE.AQ TROJAN!"
XWindows USB Printerexe.exe"Added by a variant of the RBOT WORM!"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindows XP Automatic UpdatewXPupdate.exe"Added by the RBOT-AFC WORM!"
XWindowsACEbaracebarupdate.exe"BarACE adware"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWindows�UpdatesUpdate.exe"Added by the RBOT.TRA BACKDOOR!"
XWindowsRegKey updatewinupdate.exe"Added by the RBOT-QJ WORM!"
XWindowsRegKey updatewdnupdate.exe"Added by the SDBOT.QX WORM!"
Xwindowstime.exewindowstime.exe"Added by the DLOADR-AQV TROJAN!"
XWindowsUpdatewindows_update.exe"Added by the LOFNI WORM!"
Xwindowsupdatewinupdate.exe"Added by the WARPI WORM!"
XWindowsupdateWindowsupdate.exe"Added by the BANKER.ARK TROJAN!"
Xwindowsupdateautoupdate.exe"Added by the IRCBOT-P BACKDOOR!"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowsXP Updatewindowsxpupdate.exe"Added by the RBOT-PB WORM!"
XWindows_SerivceSERVICE.exe"Added by the WOOTBOT.AH WORM!"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
XWinGate initializeWinGate.exe"Added by the LOVGATE.F WORM!"
XWinhelpTkBellExe.exe..."Added by the LOVGATE.Z WORM!"
XWinhelpTkBellExe.exe"Added by the LOVGATE.E WORM!"
XWinLibUpdatelibupdate.exe"Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
XWinLibUpdtelibupdte.exe"Added by the BIONET.318 TROJAN!"
XwinloginReadMe.exe"Added by the SILLYFDC.BBT WORM!"
Xwinlogin.exelogfile.exeAdded by the AGENT.AH TROJAN!
XWinManagewmanage.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xwinmgmtwmiprvse.exe"Added by the AGENT-GHP TROJAN!"
Ywinmodemwmexe.exe"Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
Xwinpipewinpipe.exeBrowser hijacker redirecting to wow-access.com
Xwinpopupwinupie.exeAdware by Tradeexit.com
Xwinprofileiexpiore.exeAdded by a variant of the MONCHER WORM!
XWinProfileiexpIore.exe"Added by the CHUM-C TROJAN!"
UWINREMOTEWinRemote.exe"InterVideo WinCinema Manager - needed for the use of WinDVD Remote Control"
Xwinrestore1winrestore.exe"Added by the KILLFIL-Q TROJAN!"
Nwinroutewinroute.exe"Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process
Xwinsecurewinsecure.exe"Browser hijacker
XWinshellremote.exe"Added by the MYTOB.LJ WORM!"
Xwinskypewinskype.exe"Added by the BROGGER-C TROJAN!"
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock2 driverSDJOIJE.EXE"Added by the SPYBOT.DR TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
XWinSrvSHIZZLE.EXE"Added by the HOBBIT.C WORM!"
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWINTASKtaskfile.exe"Added by the MYTOB.EF WORM!"
Uwintectivewintective.exe"Wintective logs keystrokes
XWintimeWintime.exe"Added by the HARNIG TROJAN!"
UWinTimewintime.exe"WinTime - change desktop icons' color and font"
Xwinupdatewinupdate.exe"Added by the ALCAN.B WORM!"
Xwinupdate.exewinupdate.exe"Added by the RADO TROJAN!"
Xwinupdate.regwinupdate.exe"Added by the SPYBOT.EAS WORM!"
XWinUpdateBbreatle.exe"Added by the BRATLE.AWORM!"
XWinUpdaterupdate.exe"Added by the STARTPAGE.C TROJAN!"
XWinZix Servicewakeservice.exe"WinZix adware"
Xwiseclockwise.exe"Added by the LAZAR-A TROJAN!"
UWMIEXE.exewmiexe.exe"NT component
Xwmiprevsewmiprevse.exe"Added by the BANKER-EPN TROJAN!"
Xwmupdatewmupdate.exe"Added by the AGENT-GGJ TROJAN!"
Xwon updateWAPDATE.EXE"Added by the RBOT.N WORM!"
UWorkPace 3.0workpace.exe"WorkPace - stress injury prevention software"
XWorkstation Ver 5.0vmware.exe"Added by the RBOT-AHB WORM!"
UWorldTime.exeWorldTime.exe"Part of AnyTime Organizer Deluxe from Individual Software Inc - ""Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop"""
YWPCycle.exeWpCycleWin.exe"Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end
?wristewriste.exe"??"
?wsbklitewsbklite.exe"Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?"
UWServiceWService.exe"Tablet client Driver for UC-Logic Pen/Graphics Tablet"
XWupdate driverwupdadte.exe"Added by the SPYBOT-CQ WORM!"
XWxp4Norton Update.exe"Added by the ERKEZ.D WORM!"
XxcfdhtyjkxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
UXE 8x LM Statuslmsxxe.exeXerox XE8 series laser printer status monitor
NXfireXfire.exeTerratec DMXFire 1024 soundcard control panel
XxInsIDExInsIDE.exe"Added by the ADLOAD.BH TROJAN! Note - this should not be confused with the valid IDE configuration utility from JMicron Technology which is normally located in %Windir%\RaidTool and uses the same filename. This one is located in %ProgramFiles%\xInsIDE"
UxInsIDExInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
XXP Antispyware 2009XP_AntiSpyware.exe"XP AntiSpyware 2009 rogue spyware remover - not recommended
Xxpiupdatexpiupdate.exe"Added by the RBOT-AAB WORM!"
Xxpprotectxpdeluxe.exe"XP Protector Deluxe rogue security software - not recommended
Xxpsp2installxpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
Xxpsp2Updatexpsp2Update.exe"Added by the AGENT-DPK BACKDOOR!"
XxSafexSafe.exe"Added by the SILLYFDC.BAY WORM!"
UXSC SIP ClientX-Lite.exe"""CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download"". For VOIP and broadband users"
XXTServiceUpdateXTServiceUpdate.exehahame.net adware downloader
Xxwarexware.exe"Malware downloader from xxsware.com
Xxwarecskware.exe"Malware downloader from xxsware.com
XYahoo Messenggerchrome.exe"Added by the AUTORUN-NG WORM!"
XYahoo Messenggergphone.exe"Added by the TIOTUA-W WORM!"
UYahoo! Widget EngineYahooWidgetEngine.exe"Yahoo! Widget Engine lets you run little files called Widgets that can do pretty much whatever you want them to"
Xyeahdude.exehallowelt.exe"Added by the GAOBOT.RS or GAOBOT.SA WORMS!"
NYLive.exeYlive.exe"Yahoo! Assistant (formerly 3721 Internet Assistant) - not recommended"
UZeroSpywareZeroSpyware.exeFBM Software ZeroSpyware 2004 spyware detector and remover
XZi5AntiVirus Update.exe"Added by the ERKEZ.G WORM!"
XZonealarmRemoveme.exe"Added by the FORBOT-BG WORM!"
XZonealarmiexplore.exe"Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XZPointwinmuse.exe"Added by the DLOADR-VJ TROJAN!"
Xzsmsgsiservice.exe"Added by the BANCOS-BU TROJAN!"
XZupdateZupdate.exe"Associated with B3d Projector foistware - see here"
X[12 random characters]admparse.exe"IeDriver adware variant"
X[random name]??xplore.exe"PurityScan adware"
X[random name]d?xplore.exe"PurityScan adware"
X[random name]n?tdde.exe"PurityScan adware"
X[random name]Servere.exe"Added by the LEGMIR-AQM TROJAN!"
X[random name]netdde.exe"PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[various names]EXE32EXE.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]forces_elite.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]openstre.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]PrcIdle.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]qwe.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]TemplateDongle.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]wormexe.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_explore manager_explore.exe"Added by the SPEXTA-C TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysxhtcwbse.exe"Added by the FAKEALERT-AM TROJAN!"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
X{C0FB7D08-056E-1033-0501-03020730002c}Update.exe"Added by the AGENT-EOG TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.