Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
XMSPF.EXE"Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Note the filename has a ""0"" rather than an upper case ""o"""
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X%Temp%%Temp%delwdef2008.bat"WinDefender 2008 rogue privacy program - not recommended
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)NOTEPAD.exe"Added by the RUSTY WORM! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)twunk_32.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(Default)Systrsy.exe"Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)syspol.exe"Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)winlog.exe"Added by the RBOT-CVY WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(Default)5640.exe"Added by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Mcafee.exe"Added by the AGENT.AY TROJAN! Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)fada.exe"Added by the VB.HEI TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run
X(Default)Default.exe"Added by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\RunOnce & HKCU\RunOnce in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)KEYBOARD.exe"Added by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)xtreme.exe"Added by the DROPR-CZ TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLMRun in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
?.NET configsysmon32.exe"??"
?00notify33NetBrowser.exe"Part of Best Network Security
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
?39ELTFH25Z8SKFEzg1q5.exe"Seems to be associated with software by Resplendence SP ?"
X3Dfx AccGFXACC.EXE"Added by the GIBE WORM!"
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
X4wd!!!Natal!.pif"Added by the OPASERV.AI WORM!"
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
X7f8ez****.exe 9idf"Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
?AAACLEANAAACLEAN.INF"??"
Xaacmeyfaacmeyf.exe"Added by the AF.20 TROJAN!"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
Xabcdefghabcdefgh.exe"EPJ TROJAN!"
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
XAceu[random filename]"PurityScan adware"
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XAdKillerAD Defender.exe"Part of the Advanced Spyware Remover rogue spyware remover - not recommended
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
XAdobe Filter Platformafilterplatform.exe"Added by the RBOT-OP WORM!"
XAdobe Flash PlayerAdobeFP.exe"Added by the AUTORUN-BBP WORM!"
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdobeReaderProrruxdkf.exe"Added by the RBOT.ADF BACKDOOR!"
XAdobeReaderProlxlfsprrj.exe"Added by the RBOT.BDZ BACKDOOR!"
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderProrvdjlefr.exe"Added by the RBOT-CQZ WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XAdPopupdcf5678.exe"Added by the AGENT-FZ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
UAESTFltrAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
Xafskfask8fsfjasj8.exe"Added by the ONLINEG-L TROJAN!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
Uahfpahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
Uahfprogahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
YAirGCFGAirGCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirNCFGAirNCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
NAlbum Fast StartABMTSR.EXE"Scanner software
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?Alcom PCL CaptureFMW_PCAP.EXE"??"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
UAlfaClock ClassicAlfaClock.exe"AlfaClock Free Edition from AlfaSoft Research Labs - ""enhances your taskbar clock (tray clock) with fully customizable clock display
UAlfaClock2AlfaClock2.exe"AlfaClock2 from AlfaSoft Research Labs -""enhances your tray clock functionality. Of course
?ALFY AccelleratorAlfyAC~1.exe"??"
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
XAll Sea web linkFWLink.exe"Free screensaver
Xalt CTRL Shiftet3rd.exe"Added by the SDBOT-RH BACKDOOR!"
UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
YAntiFreezeAntiFreeze.exe"AntiFreeze from Resplendence Software Projects - ""offers a last recourse when you find your computer in a hung state"". If your system has hung and AntiFreeze is running
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
NAOL Fast StartAOL.exe"Fast Start loads the AOL integrated email
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAolConconfig.com"Added by the TAPLAK WORM!"
NAolFixAolFix.exe"Run on Gateway Astra computers
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
XAqujyjax[path to file]"Added by the RANCK-CQ TROJAN!"
Xara-key[random filename]"Added by the ANTINNY WORM!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
XArmorDefenderArmorDefender.exe"ArmorDefender rogue security software - not recommended
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
YAshampoo FireWallFireWall.exe"Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
YAshampoo FireWall PROFireWall.exe"Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xatf.exepgs.exe"Part of the PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
Xaudioinfaudioinf.exe"Added by a variant of the CRYPTER.C TROJAN!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
Xautoloadcftmon.exe"Added by the SOCKS-E WORM!"
XAutomatic Defrag Managerdefrag.exe"Added by the RBOT-AKE WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
NAvaFindAvaFind.exe"AvaFind file search utility"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
?AxFilter"Rundll32 AXFILTER.DLL Rundll32"
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
NBackpack UDFbpudfmon.exe"Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
?BackupNotifybackupnotify.exe"HP Digital Imaging related. What does it do and is it required?"
XBand-Aid[path to file]"Added by the RANKY.O TROJAN!"
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
Xbdfgergggasw.exe"Added by the SDBOT-RT WORM!"
UBearFlixBearFlix.exe"BearFlix is optimized for the fast download of video files"
UBeFasterbefaster3.exe"BeFaster internet connection optimization tool"
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
XBeSys[path to file]"BeSys adware"
XBF4Pbf4p.exe"Added by the IRCBOT.GEN WORM!"
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
UBGInfoBginfo.exe"BGinfo automatically displays relevant information about a Windows computer on the desktop's background
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
NbigfixBIGFIX.EXE"BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
YBitDefender 12bdwizreg.exe"Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
UBitDefender for Yahoo! Messengeryahmon.exe"Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
Nbjcfdcdf.exe"BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
XBLFblf.exe"Added by the DELBOT-M WORM!"
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
UBlue Frogbluefrog.exe"Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive"
XBluetooth Configbtwindin32.exe"Added by the SDBOT-DFN WORM!"
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
NBMMLREFBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
NBMMLREF.EXEBMMLREF.EXE"Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the ""N"" status"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBnexe[random filename]"Added by the KITRO.D (or ARGEN.A) WORM!"
XBoot Configbootconfig.exe"Added by the FLOOD-EV TROJAN!"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
XBrasilBRASIL.PIF"Added by the OPASERV.E WORM!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBT00003*abcdefg23.exe"Added by the VB-VT TROJAN where * = 5
YBTUSRBDGFBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
YBufferZoneCLIENTGUI.EXE"BufferZone from Trustware - ""is the only security software that creates a separate environment allowing you unlimited freedom to enjoy all Internet activities without the fear of external threats"""
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
UBuzof.exebuzof.exe"Buzof from Basta Computing "enables you to automatically answer
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
UBySoft FreeRAMFreeRAM.exe"""Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status
XByteDefenderByteDefender.exe"ByteDefender rogue security software - not recommended
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
UCafeStationCafeStation.exe"""CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations
Ycafwccafw.exe"CA Personal Firewall - part of the CA Internet Security Suite"
XcAgOu[filename].hta"Added by the KAKWORM WORM!"
YCAISafeisafe.exe"Part of Computer Associates eTrust EZ Antivirus"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
NCallControlftctrl32.exe"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed
UCamera Assistant Softwaretraybar.exeCamera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
Ycapfasemcapfasem.exe"CA Personal Firewall - part of the CA Internet Security Suite"
NCapfaxcapfax.exe"PhoneTools fax software"
Ucapfupgradecapfupgrade.exe"CA Personal Firewall - part of the CA Internet Security Suite"
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
Xcartao[path to file]"Added by the DLOADER-QD TROJAN!"
Xcartaoconflicted.exe"Added by the DADOBRA-DV TROJAN!"
XCashFiestaCashfiesta.exe"CASHFIESTA.A pay-per-surf adware"
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
UcbInterfacecbInterface.exe"System Tray access to Cobian Backup versions 8 thru 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XccExecutebootcfg1.exe"Added by the NEMSI-B VIRUS!"
YccRegVfyccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
Xcdoosoftolhrwef.exe"Added by the AUTORUN-AAG WORM!"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
NCFDCFD.exe"BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
NcfFncEnabler.execfFncEnabler.exe"Toshiba ""Config Free"" wireless network manager on their range of laptops"
Xcfgboostcfgboot.exeAdded by an unidentified WORM or TROJAN!
Ycfgintprcfgintpr.exe"Configuration Interpreter - part of Tiny Personal Firewall V4"
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xcfgmgr52"RunDLL32.EXE cfgmgr52.dllDllRun"
Ncfgwizcfgwiz.exe"Introduced with Norton Anti-Virus 2002
UCFi ShellToys Utility ManagerCFiShlMan.exe"Manager for CFi ShellToys from Cool Focus International Ltd - which ""puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders
?cFosDNTcFosDNT.exe"cFos DSL Modem driver related. What does it do and is it required?"
?cFosInst_Checkcfosinst.exe"cFos DSL Modem driver related. What does it do and is it required?"
UcFosSpeedcFosSpeed.exe"cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly"
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
XCftmon32afd.exe"Added by the AUTORUN-AUB WORM! The ""afd.exe"" file is located in %Windir%"
XCftmon32afd.exe"Added by the SCAR.AYWK TROJAN! The ""afd.exe"" file is located in %AppData%"
Xcfycfy.exe"Surfenhance.com SearchForIt adware variant"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
YCharter High-Speed Security Suitefspex.exe"Charter High-Speed Security Suite - security software in collaboration with F-Secure"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UChikkaDefaultChikkaLauncher.exe"Chikka PC text messanger and IM client"
XCHK NTchkntf.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
XCiodiagDECCONF.EXE"Added by the STRAT.EL TROJAN!"
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
Xclfmonclfmon.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
Xclfmon.execlfmon.exe"Added by the AGENT-BJ TROJAN!"
XCli Confgcliconfig.exe"Added by a variant of the SPYBOT WORM! See here"
UClickoffClickoff.exe"Clickoff automatically dismisses annoying dialog boxes"
XCLICONFGCLICONFG.EXE"Added by the OPASERV.T WORM!"
XClient Agent[path to file]"Added by the PPDOOR-J TROJAN!"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
UCLMFrontPanelclmpanel.exe"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
UCloneCDElbyCDFLElbyCheck.exe"From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
XClrSchLoader[path to file]"ClearSearch adware"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
Xcmd32configs.exe"Hijacker
XCMFibulaCMFibula.exe"CASClient adware"
NCmFlywaveNameCmFlywav.exe"Driver for Linksys Wireless-G Music Bridge"
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
Xcmrsfcmrsf.exe"Added by the DELF-HU TROJAN!"
XCn323cnfrm33.exe"Added by the MIMAIL.G WORM!"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
XCnfrm32cnfrm.exe"Added by the MIMAIL.D WORM!"
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
NColorificHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
Ucom.codeode.cactusspamfiltercactusspamfilter.exe"Cactus Spam - free easy-to-use spam blocker"
XCOMCFGcomcfg.exe"Added by the TOADCOM.A TROJAN!"
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XCommon Filestwain.exe"Added by the AGENT.BEA TROJAN!"
UComodo FirewallCPF.exe"Comodo Firewall"
YCOMODO Firewall Procfp.exe"Comodo Firewall Pro"
YCOMODO Memory Firewallcmf.exe"""Comodo Memory Firewall is a buffer overflow detection and prevention tool which provides the ultimate defence against one of the most serious and common attack types on the Internet - the buffer overflow attack"""
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
XConfgbootconfig.exe"Added by the VB-ERB WORM!"
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigwinconfig.exe"Added by the GIP.113.B1 TROJAN!"
XConfigCONFIG.EXE"Added by the PSWGIP.B TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig Loader[worm filename]"Added by the AGOBOT-AE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loaderwincrt32.exe"Added by the AGOBOT-AW WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
XConfig33.exeConfig33.exe"Added by the SDBOT.T TROJAN!"
XConfiggLoadercart322.exe"Added by the GAOBOT.DJ WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration DefaultWuxat.exe"Added by the SPYBOT-CA WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadercmd32.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderwincrt32.exe"Added by the GAOBOT.BF WORM!"
XConfiguration Loaderwindex.exe"Added by the GAOBOT.BZ WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderWinreg.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loaderconfgldr.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xconfiguration loaderwinicfg32.exe"Added by the GAOBOT.RQ WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderloadcfg32.exe"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderwincffg.exe"Added by the AGOBOT.A3 WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loaderdezi.exe"Added by the SDBOT-OB WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loaderextrac.exe"Added by the SDBOT-AFP WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderconfigldr.exe"Added by the AGOBOT-PP TROJAN!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loaderntdm.exe"Added by the AGOBOT.RV WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loaderwin32exec.exe"Added by the SDBOT-LA WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration LoaderFILENAME.EXE"Added by the AGOBOT-DQ WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderwinfix.exe"Added by the SDBOT-MA WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader 2confuldr.exe"Added by the AGOBOT-FC WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loadingconfigldr.exe"Added by the AGOBOT-EC WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration ManagerCNFGLD32.EXE"Added by the SDBOT TROJAN!"
XConfiguration ManagerCnfgldr.exe"Added by the SDBOT TROJAN!"
XConfiguration Managercfg32.exe"BookedSpace parasite. Note - the ""cfg32.exe"" file is located in %Windir%"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
NConfiguration UtilityCONFIG.EXEControls linksys wireless connection. Available from the Desktop
UConfiguration Utilitywlanutil.exe"NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)"
XConfiguration WizardCfgwiz32.exe"Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe)"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
UConfigUtilityConfigUtility.exe"Wireless management utility for the HWC54G Hi-Speed Wireless-G CardBus Card from Hawking Technologies
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
XContent connector[random filename].exe"Added by the DIALER-Y TROJAN! Note - uses a random filename and random folders. Usually the folder containing the file is a Temp folder"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
NControllerWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
?Coupon Offers??"??"
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
NCPQDFWAGCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
YCPQSTUTFIXstutfix.exe"For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
Xcsoftoksoftok.exe"Added by the QQPASS.G TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
Xctf.exectf.exeAdded by a variant of the BIFROSE TROJAN!
Xctflog managerctflog.exe"Added by the DONBOMB.A TROJAN!"
XCTFM0N.exeCTFM0N.exe"Added by the STARTPAGE.P TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
Xctfmomctfnom.exe"Added by the BCKDR-QTA BACKDOOR!"
Uctfmonctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
Xctfmoncftmon.exe"Added by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfmonmIRC.dll"Added by the DELBOT-E TROJAN!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
UCTFMonctfmon.exe"Family KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a ""CTF"" sub-folder"
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XCTFMONwin.exe"Added by the VBS.RUNAUTO.G WORM!"
XCtfmonwmisys.exe"Added by the IRCBOT-ADS WORM!"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
XCtfmon.exectfmon32.exe"CoolWebSearch Ctfmon32 parasite variant"
Xctfmon.exectfmon.exe"Added by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
Uctfmon.exectfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
Xctfmon.exectfmon.exe eminem.exe"Added by the BHARAT.A WORM!"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XCTFMON32CTFMON32.EXE"CoolWebSearch Ctfmon32 parasite variant - also detected as the CWS-E TROJAN!"
Xctfmon32[random filename].exe"Added by the RBOT-GSN WORM!"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
Xctfmonactfmona.exe"Added by the DLOADR-BME TROJAN!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
Xctfmunctfmun.exe"Added by the AGENT.ACEZ TROJAN!"
Xctfnnonctfmon.exe"Added by the TURKOJAN.IL BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
XctfnomrundIl32.exe"Added by the LEGMIR-AW TROJAN!"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
XCTMON.EXEcfmon.exe"Added by the CLCKR-AN TROJAN!"
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
NCTxfiHlpCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
NCTXFIREGCTxfiReg.exeCreative Labs sound card driver related. It appears that it isn't required and maybe registration related
XCtykd[path to file]"SMALL.SN spyware"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcximddlldfrmmd.exe"Added by the BUZUS.CQMU TROJAN!"
UCyber-Defender 2003uwcdsvr.exe"
Xcyberfree.exe****.dat [* = random char]Unidentified adware
XCyberWolfCyberWolf.exe"Added by the KICKIN.A (or CYDOG.C) WORM!"
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
YD-Link Air UtilityAirCFG.exeD-Link Air PCI wireless driver and configuration utility
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link DWA-125AirGCFG.exe"D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link D-Link Xtreme N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
Xd9fw5i91pd9fw5i91p.exe"Added by the AGENT-GIW BACKDOOR!"
NDACONFIGEXEdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
Xdagofault.exe"Added by the PUNYA-A WORM!"
XDaily Weather Forecastweather.exe"Added by the DLOADER-IP TROJAN!"
XDanton*[random filename]"Added by the DANTON TROJAN! where * = random number"
Xdaskaskfsak6dsfids6.exe"Added by the ONLINEG-J TROJAN!"
Xdaskgfkkcx15dasdsaads15.exe"Added by the ONLINEG-Q TROJAN!"
Xdasxdadsfsdqd.exe"Added by the GAOBOT.BIQ WORM!"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
NData LifeGuardBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital's series of hard drives
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
NDataCachingFlashKsk.exe"SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon"
UDCfssvcdcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
Udcfssvedcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Xdebuggerhelp.pif"Added by the DELF-DRA WORM!"
Xdeejayforboo.exe"Added by the FORBOT-AY WORM!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefaultmtask.vbe"Added by the ALLEM WORM!"
Xdefaultshell32.exe"Added by the BINGHE TROJAN!"
XDefault_default.pif"Added by the RUBBLE-C WORM!"
Udefaultmskbw.exe"PC Surveillance PRO surveillance software. Uninstall this software unless you put it there yourself"
UDefault ManagerDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDefaultConfigurationdefaultconfh.exe"Added by the AGOBOT-JC WORM!"
XDefault_Page_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefault_Search_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefendAPcDefendAPc.exe"DefendAPc rogue security software - not recommended
Xdefenderdefender25.exe"DollarRevenue adware"
Xdefenderdfndref_7.exe"DollarRevenue adware"
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
?deferguidefergui.exe"Related to IBM Standard Software Installer. What does it do and is it required?"
UDefMgrDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
Xdefragm_checkdefragment.exe"CoolWebSearch parasite variant"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
UDefragTaskBardefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
UdefragTaskBar.exedefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
Udefwatchdefwatch.exeDetects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
UDeleteHistoryFreedhf.exe"Delete History Free - ""Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"""
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
XDepassxXfsa.exe"Added by the SDBOT-SK WORM!"
UDepFrezfrzstate.exe"Deep Freeze from Faronics Coporation. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
NDeskflagDeskflag.exe"DeskFlag - animated USA flag on the desktop"
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDevice Managerwfxmgr.exe"Added by the RBOT.AJU WORM!"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
XDfqwSfSffsqsd.exe"Added by the SDBOT-SH WORM!"
XDI2[path to file]"BroadcastPC adware"
UDigisoft AntiDialerAntiDialer.exe"Digisoft AntiDialer"
XDiomacdfdafbfd.exe"Added by the MULDROP.F TROJAN!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
NDisc DetectorCtNotify.exe"For Creative sound cards. Detects when you insert a CD
?disc detectorqnetquestnotifty.exe"??"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
Xdiskinfdiskinf.exe"Added by the CRYPTER.A TROJAN!"
UDisplayFusionDisplayFusion.exe"DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much
XDist-FBGeneveGDC.exe"NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
Ydlatfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
?DLForcerExeDLForcerEXE.exe"??"
NDLF_00000B00Vcdlf.exe"Known to cause problems with "Out of memory" errors (see here). Otherwise
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDllExecutable[path to file]"Added by the VB-SP WORM!"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDokterFixSysRep.exe"DokterFix
XDot1XCfgDot1XCfg.exe"Added by the AGOBOT.EA TROJAN!"
Xdown[trojan filename]"Added by the SMALL-QJ TROJAN!"
NDownload Accelerator Manager Free Editiondam.exe"Download Accelerator Manager Free Edition from Tensons Corp"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDrefIWSysDrefIWv2.exe"Added by the DREF-C WORM!"
XDrefIWSysDref.exe"Added by the DREF-D WORM!"
?dregfixph_finder.exe"??"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
XDriveCleaner FreeUDC.exe"DriveCleaner rogue security software - not recommended
XDriveDefenderGDC.exe"DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDropSpam Lifestyledslifestyle.exe"Dropspam adware"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
XdS35DLLffqca.exe"Added by the SDBOT-KV WORM!"
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
Xdsadlsa14dsakfsak14.exe"Added by the ONLINEG-P TROJAN!"
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDVAScvssdfaAsSDdwd.exe"Added by the LIOTEN.IP TROJAN!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
UdvHighMemcfgmng32.exe"Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
NdwStartFireWall.exe"The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
XDyFuCAoptimize.exe"Adult content dialler - see here"
XDyFuCA Active Alertactalert.exe"Adult content dialler - see here"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
YEAFRCliStartEAFRCliStart.exe"Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
?EDFcsndiscfcsn.exe"Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
Xeducational writer[random filename]"Added by the RBOT-LZ WORM!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
UeFax 4.1J2GDllCmd.exe"DLL Command Utility for version 4.1 of eFax Messenger from j2 Global Communications
UeFax 4.1J2GTray.exe"System Tray access to version 4.1 of eFax Messenger from j2 Global Communications
UeFax 4.2J2GDllCmd.exe"DLL Command Utility for version 4.2 of eFax Messenger from j2 Global Communications
UeFax 4.2J2GTray.exe"System Tray access to version 4.2 of eFax Messenger from j2 Global Communications
UeFax 4.3J2GDllCmd.exe"DLL Command Utility for version 4.3 of eFax Messenger from j2 Global Communications
UeFax 4.3J2GTray.exe"System Tray access to version 4.3 of eFax Messenger from j2 Global Communications
UeFax 4.4J2GDllCmd.exe"DLL Command Utility for version 4.4 of eFax Messenger from j2 Global Communications
UeFax 4.4J2GTray.exe"System Tray access to version 4.4 of eFax Messenger from j2 Global Communications
UeFax DllCmdJ2GDllCmd.exe"DLL Command Utility for eFax Messenger from j2 Global Communications
UeFax DllCmd 3.5J2GDllCmd.exe"DLL Command Utility for version 3.5 of eFax Messenger from j2 Global Communications
UeFax DllCmd 4.0J2GDllCmd.exe"DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications
NeFax Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
UeFax Tray MenuJ2GTray.exe"System Tray access to eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.3J2GTray.exe"System Tray access to version 3.3 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 3.5J2GTray.exe"System Tray access to version 3.5 of eFax Messenger from j2 Global Communications
UeFax Tray Menu 4.0J2GTray.exe"System Tray access to version 4.0 of eFax Messenger from j2 Global Communications
NeFax.com Tray MenuHotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xefaxs ml097eefaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UEFI Hot Foldershffw.exe"""EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select
UEFI Job Monitor"[path] efjm.dllrun"
UEfpap.exeEfpap.exe"Easy File & Folder Protector. Deny access to certain files and folders
Xeixfichina.bat"Added by the WCUP.A WORM!"
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
?EmpoweringTechnologyFramework.Launcher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
XenBrowser[name of file]"WINBO adware"
NEncarta Dictionary QuickshelfQSHLFED.EXE"Provides quick access to Encarta's Dictionary features?"
?ENCSurfsurfboard.exe"??"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
YEnvyHFCPLEnMixCPL.exe"VIA Envy24 PCI Audio Controller driver"
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C67 SeriesE_FATIAAL.EXE"Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status
UEPSON Stylus C87 SeriesE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
Xerfgddfkwind2ll2.exe"Added by the BEAGLE.CQ WORM!"
XError Safeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XError Safe Freeuers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorFixErrorFix.exe"ErorrFix rogue system error and cleaning utility - not recommended
XErrorProtector Freeertmain.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
XErrorSafeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeFreeUERS.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
YeSafe ProtectESPWatch.exe"eSafe from Aladdin - internet security for gateway and E-mail servers"
NESFTPesftp.exe"ESftp - FTP client for transfering files between a local PC and another remote computer"
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
XEtrafficJavaRun.exe"TopMoxie adware"
YeTrust EZ Firewallefpeadm.exe"eTrust EZ Firewall"
XeTunnelwinfw.exeAdded by an unidentified TROJAN!
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
NExcite PlatformExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
Xexecfg4execfg4.exe"Added by the ELECTRON WORM!"
?Executedelfolders.exe"??"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
UExif LauncherExiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
UExif LauncherQuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
Xexploreff.exeexploreff.exe"Added by the FINFANSE TROJAN!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
XExploreUpdSched[random filename]"ZenoSearch adware"
NExtraFilmHemmaAgentAgent.exe"ExtraFilm Photo Assistant"
YEZ Firewallca.exe"eTrust EZ Armor Internet Security"
UEZ-DUB FinderEZ-DUB.exe"Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
YezShieldProtector for PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UE_S4I2F1E_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
Xfftkclean.exe"FlashEnhancer adware"
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
YF-Secure TNBTNBUtil.exe"F-Secure antivirus"
YF-StopWF-StopW.exe"F-Prot anti-virus background scanner by F-Risk Software"
Uf1Tray.exeF1TRAY.EXE"System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
?f23mxinsf23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
Xf2install.exef2install.exe"Added by the IEFEAT-I TROJAN!"
UF5D7050v3Belkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UF5D8001Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
UF5D8011Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
UF5D8055v1Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
UF5D8071Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
UF5D9010Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
UF5D9050Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
Xf607f607.exe"Added by the URAT.B TROJAN!"
Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
UFabrik Ultimate Backup Statusfabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink
XFaltCheckallps.exe"Added by the AGENT.RAP TROJAN!"
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
?fapmonfapmon.exe"Fair Access Policy monitor for DirecPC/DirecWay internet access"
Xfarkrishfarkrish.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
Xfarmmextfarmmext.exe"VX2.Transponder parasite updater/installer related"
XFashFash.exeUnidentified adware
Xfaslkakj11kjgagklj11.exe"Added by the LEGMIE-ARE TROJAN!"
Nfastfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
XfastA-fast.exe"A-fast Antivirus rogue security software - not recommended
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
NFAST DefragFAST2.EXE"FastDefrag defragmenting software"
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
XFast Searchsvcnv.exe"Homepage
XFast startNtut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
UFastCachefc.exe"FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
Xfastsmellfastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
NFastTrack AcceleratorSPEED UP.EXE"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
UFastTVSyncFastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps
NFastUserfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
NFastUsrfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
XfaTfaT.exe"Added by the BANKER-DFP TROJAN!"
Xfat.exefat.exe"Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended
XFat32 Microsoftfat32.exe"Added by the RBOT-EL WORM!"
UFatPipeDHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
UFatpipe Dialerfpdialer.exeDailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
Ufatrecovfatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
UFBDirectFBDirect.exe"Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan
?FBIFBISM.exe"Compaq related but what does it do?"
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSearchSearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSSAie3sh.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
Xfcrunfc.exe"Added by the CAMPURF WORM!"
XFCEngineFCEngine.exe"CASClient adware"
XFCHelpFCHelp.exe"Added by either FCHelp adware or a variant of it"
XFCManFCMan.exe"FCHelp adware"
XFdaemon securityfsecur.exe"Added by the SDBOT.KXO WORM!"
XFDD SYSTEMFdd.exe"Added by the MYTOB-FO WORM!"
XfddddHOMEdxxatp.exe"Added by the RANKY.AA TROJAN!"
XFdr Command Modulesp2.exe"Added by the SDBOT.WP WORM!"
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UFD_SAPFD.exeReported to be the autopassword program from the Sony Microvault thumb drive
XFeCPYfecpy.exe"FlashEnhancer adware"
Ufeedreader.exefeedreader.exe"""Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"""
Xfeelalrightmirc.exe"Added by the IRCFLOOD-M WORM!"
UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
UFellowes ProxyR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
UFerrariWallPaperFerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
XFestplattenReinigerGDC.exe"FestplattenReiniger
Xff[path to worm]"Added by the RBOT-XL WORM!"
Xffsvhost32.exe"Added by the LINEAG-AFF TROJAN!"
Xffeqfqsdqddss.exe"Added by the SDBOT-SG WORM!"
XffeqOMEvcvsav.exe"Added by the RANKY.AB TROJAN!"
Xffisffisearch.exe"iSearch adware"
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XfGQEGqHOMEgwwgtp.exe"Added by the RANKY.J TROJAN!"
XFHPageshdochp.exe"Added by the WINHOUND TROJAN!"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
UFhtisxkfhtisxk.exeXtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
XFhzepgyiHELLRAIDER.EXE"Added by the MINDCTRL.A BACKDOOR!"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XFILEabcdefg.exe"Added by the KELVIR.DD WORM!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
Xfile laoder configurationrnd32.exe"Added by the RBOT.BQJ WORM!"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XFile Systemtaskmqrs.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XFile Systemtaskmqr.exe"Added by the RBOT.BWQ WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFile-Sharing Wizardshwizard.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFile0_0MD1.exe"Added by the DLOADER-OR TROJAN!"
XFile1Dia Claro.htm"Added by the DLOADER-OR TROJAN!"
XFileFreedom_Pluginwtm.exe"FileFreedom peer-to-peer sharing program"
Nfilehippo.comUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
NFileHippo.com Update CheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilenfilen.exe"Added by the VBNAM-A WORM!"
Xfilenamefilename.exe"Added by the VB.FSY TROJAN!"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
UFilterGatefiltergate.exe"Filtergate internet filtering software - filters sounds
UFilterguardFiltrgrd.exe"An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian
XFilterProgramGDC.exe"FilterProgram rogue privacy tool - not recommended
XFindfind.exe"Added by the OPANKI WORM!"
NFind FastFindfast.exeFrom older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
Xfindfastfindfast.exe"Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
Xfindfast.exefindfast.exeIdentified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
XFindHack[path to worm]"Added by the KELVIR-BA WORM!"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFireFoxfirefox.exe"Added by the RBOT-ATP WORM! Note - this is not the popular FireFox web browser and is located in %System%"
XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
UFirefox PreloaderFirefoxPreloader.exe"Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
Xfirefox.exefirefox.exe"Added by the BANKER-EBO TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
YFirePodFIREPOD.EXE"Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFirevall Administratingrndll.exe"Added by the PUSHBOT-B WORM!"
Xfirewalfirewal.exe"Added by the BANCBAN-QY TROJAN!"
XFirewallwmlaunch .exe"Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
XFirewallwmlaunch .exe"Added by the ELIPTER.D WORM!"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
XFirewallFirewall.bat"Added by the YPSAN.G WORM!"
Xfirewallfw_304.exe"Added by the BDOOR-JQ BACKDOOR!"
XFirewallctfmon.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
Xfirewallfirewall.exe"Added by the SURO-A TROJAN!"
Xfirewall 2008logoneui.exe"Added by the SILLYFDC WORM!"
XFirewall Administratinginfocard.exe"Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFirewall configReadMe.exe"Added by the SILLYFDC.BBT WORM!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall PolicyMidiDef32.exe"Added by the PIEBOT-A TROJAN!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
XFirewall.exeFirewall.exe"Added by the AGENT.AGL BACKDOOR! Located in %System%"
YFireWall.exeFireWall.exe"Ashampoo® Firewall PRO and Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG. Located in an Ashampoo related sub-directory of %ProgramFiles%"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
YFirewallGUIFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
UFirewallStartupFirewallstartup.exe"Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean
XFirewallSvrFirewallSvr.exe"Added by the NETSKY.X or NETSKY.Y WORMS!"
Xfirewall_antifirewall_anti.exe"Added by the NETDENY-B TROJAN!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFirst Home Pagehttp://find.naupoint.com"Naupoint browser hijacker"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
XFix ToolFix-Tool.exe"Fix Tool rogue system error and cleaning utility - not recommended"
YFix-itmxtask.exe"Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard
YFix-it AVmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
XFixnicevcvw.exe"Added by the SDBOT TROJAN!"
Xfjdslssdfdmat2.exe"Added by the SLAPEW.C TROJAN!"
UFjMenuFjMenu.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
NfkSysMonfksysmon.exe"fkWrae SysMon - system monitor - ""displays the current memory consumption
XFlaCPYflacpy.exe"FlashEnhancer adware"
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media%%%%%.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media%%%.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFlash Media^ ^^^ %% % ^% ^%%^ %^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^^^^^.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media^^^^^^.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media% ^% ^^^ %^% %% ^ ^ %%% ^% %^ % %^^.exe"Added by a variant of the IRCBOT BACKDOOR! Note the space at the beginning of the filename"
XFlash Media^%%^%%%^% %^ ^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%^^%^^% %^^^^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^%^^^%% ^ ^ %^^^^^ %^ ^%^^ ^%^^^^^ %^ ^^^%^%%.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%^% ^ %^%% ^ % ^%%^^ %^^%^%^ ^%% %^.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%%%%%%^^ ^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Mediaskxs��'�'%''msn'�%'fix''.exe"Added by the AGENT.ZOY TROJAN!"
XFlash Media^ %%^%^%.exe"Added by the FLUSH.A TROJAN! Note the space at the beginning of the filename"
XFlash Media%% % ^^ % %% ^%^^ ^^^ % ^%% ^ ^.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note the space at the beginning of the filename"
XFlash Media^ ^ % ^ % % ^ ^ ^%% ^% %%^^.exe"Added by the IRCBOT.BAW BACKDOOR!"
XFlash Player2[path to worm]"Added by the IRCBOT.PD WORM!"
?FLASH32#NAME?"??"
XFlash32FLASH32.COM"Added by the STARTER-F TROJAN!"
UFlashEncFlashEnc.exe"Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission
NFlashgetFlashGet.exe"FlashGet download manager"
XFlashget Download ManagerFlashget.exe"Added by the RBOT-AGZ WORM!"
XFlashGuardFlashGuard.exe"Added by the AUTOIT.AL WORM!"
UFlashMuteFlashMute.exe"""FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively
NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
XFlashy BotFlashy.exe"Added by the GLUPZY.A WORM!"
XFlash_Player_Installying.exe"Constructor VC2000 malware"
XFlenCPYflencpy.exe"FlashEnhancer adware"
UFlexicdFlexicd.exe"CD player - part of the Win95 Power Toys"
UFlingRunfling.exe"Fling - free FTP software from NCH Software"
UFLMBROWSERMOUSEmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMK08KBMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keys
UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMLABTECMOUSEmouse32A.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMMEDIONMOUSEmouse32a.exeMouse utility for a Medion branded Fellowes mouse
UFLMOFFICE4DMOUSEmoffice.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMOFFICE4DMOUSEmouse32a.exeMouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMTRUSTMOUSEmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
XFlnCPYflncpy.exe"FlashEnhancer adware"
XFLooDNeTFLooDeR.exe"Added by the ENDOOL TROJAN!"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
?Flow Go TVflogotv.exe"??"
Xflpsflps.vbs"Added by the BYRON WORM!"
Xflpycntlflpycntl.exe"Added by the CRYPTER.C TROJAN!"
?FLSVCIFLSVCI.exe"??"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
XFlyswatDesktopflydesk.exeAdvertising spyware
UFmctrlTrayFmctrl.EXEGenius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
Xfmnwebassistfmnwebassist.exeAdware popup generator
UFMStartFmstart.exe"GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks
XFMSZfmsz.exe"Added by the FMSZ TROJAN!"
Xfnmwebassistfnmwebassist.exe"WinPL adware"
?FocusFocus.exe"ISDN configuration wizard?"
Xfofficenm.exe"Added by the DELF-CB TROJAN!"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolder Viewfolderview.exe"Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
XFolderRaper[path to worm]"Added by the VB.GOZ WORM!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
NFolding@homeWINFAH.EXE"Folding@Home is a distributed computing project which studies protein folding
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
XFontboot.exe"Added by the AGENT-LZW TROJAN!"
XFont Viewerfontviewer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFontFixfontfix.exe"Added by an unidentified VIRUS
NfontnavFontNav.exe"Font Navigator from Bitstream Inc. - a font management utility"
XFontsLoaderldfnt32.htaUnidentified malware
XFONTVIEWFONTVIEW.EXE"Added by the OPASERV.T WORM!"
UFooBar 1.0FooBar.exe"FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoolfool.exe"Added by the SILLYFDC.BCV WORM!"
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
YFoolProofSweep??"Part of FoolProof Security PC security software from SmartStuff"
NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
XForceShow"rundll32.exe QaBar.dllForceShowBar"
NForget Me NotAGRemind.exe"Calendar reminder part of Broderbund's American Greetings® CreataCard®"
UforteManagerdthtml.exe"forteManager from LG. Rebranded version of Display Tune from Portrait Displays
YFortiClientFortiClient.exe"Fortinet security systems are the new generation of real time network protection systems"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
Xfotosfotos.exe"Added by the BANKER-FP TROJAN!"
NFotoStation Easy AutoLaunchFotoStation Easy AutoLaunch.exeInstalled with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
UFoul PXFoulPX.exe"Foul PX
UFourthDayFourthDay.exe"The Fourth Day - ""astronomical clock and almanac for your system tray"""
XFoWilCofowilco.exe"Added by the WOOTBOT.CR WORM!"
Xfoxdhfoxdhend.exe"Added by the MENGHUAN TROJAN!"
Xfoxdhfoxdh.exe"Added by the GWGHOST-Q TROJAN!"
Xfoxrxjhfoxrxjh.exe"Added by the GWGHOST-T TROJAN!"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
YFP Loaderloadfp.exe"FoolProof Security - PC security software from SmartStuff"
Nfpassistfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
?FPWGMWZDFPWGMWZD.exe"??"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
XFrameWork 2.5FrameWork.exe"Added by the RBOT-FMW WORM! Note - can terminate AV related processes"
XFramework module libraryinfocard.exe"Added by the BUZUS.AYX TROJAN!"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NFrapsFRAPS.EXE"Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting
NFree Download Managerfdm.exe"""Free Download Manager"" - see here"
?Free Downloads Monitorfdcmon.exe"??"
NFree DVD DirectFreeDVDDirect.exe"Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
UFree Key Loggerfreekeylogger.exe"Free Key Logger keystroke logger/monitoring program - remove unless you installed it yourself!"
UFree Ram Optimizerfro.exe"Free Ram Optimizer monitors your memory
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
XFreeAttentioneqsefeqe.exeAdded by an unidentified WORM or TROJAN!
NFreebie NotesFreebieNotes.exe"Freebie Notes by Power Soft - create electronic notes (stickers)"
NFreeCallFreeCall.exe"FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
YFreedomFreedom.exe"Freedom Internet Security & Privacy - anti-virus
UFreeMem ProFMEMPRO.EXE"FreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeMemVn2FreeMem.exe"FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
NFreePDF Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFreePDF_Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
UFreeRAM XPFreeRAM XP Pro *.exe"FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeRAM XPFreeRAM XP Pro.exe"FreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
Xfreestylelockx.exe"Added by the RBOT-ATH WORM!"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
Xfreexstylelockbar.exe"Added by the LOXBOT.D WORM!"
Xfreexstylelockbr.exe"Added by the LOXBOT.C WORM!"
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
UFresh Desktopfreshdesktop.exe"Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
Nfreshclamfreshclam.exe"Auto update agent of the open source Clamwin virus scanner"
?frgukshdrkmck.exe"??"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
NFriendlyWebQuick-LaunchSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
UFRISK FP-SchedulerF-Sched.exe"Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
?FRITZ!DSL StartcenterStCenter.exe"FRITZ! ISP software ""StartCenter"" User interface that allows you to manage
UFRITZ!webProtectFwebProt.exeFirewall included in FRITZ! ISP DSL software
NFromine WinPopupwinpopup.exeInstant Messenger program
Xfroodytimoty.exeAdded by an unidentified malware
XFrskfrsk.exeUnidentified adware downloader trojan
Xfrunderc32xz.exeAdded by an unidentified TROJAN!
YFRW_EXEFRW.EXE"ConSeal Signal9 firewall - now McAfee Personal firewall"
Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
XFS Agentfagent.exe"Added by the VOLVER-B TROJAN!"
XFS6519FS6519.dll.vbs"Added by the SOLOW.B WORM!"
Yfsaafsaa.exe"F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers"
NFSCBossFSCBoss.exeFree Store Club shop online software
?FSDPSRVFSDPSRV.exe"??"
Xfsdsft[path to backdoor]"Added by the RANKY.S BACKDOOR!"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Ufspfsp.exe"Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents"
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
Ufsservfserv.exe"Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
Ufssuifsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
Ufssuifssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
Xfstsvc"rundll32.exe fstsvc.dllstart"
Ufsuifsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XFSWFSW.exe"FreeScratchAndWin parasite"
UFSWebServerfsws.exe"Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
Xftkftkclean.exe"FlashEnhancer adware"
XFtkCPYftkcpy.exe"FlashEnhancer adware"
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
UFTMSFLT(USB)FTMSFLTU.EXEFujitsu's Touch Panel Message Notifier
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
XFTPGraberFTPGraber.exe"Added by the DLOADER-DT TROJAN!"
NFTPManagerFTPDM.exe"""Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another
UFtpqueueFtpsched.exe"Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
?FtpServer.exeFtpServer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
Uftutil2"rundll32.exe ftutil2.dll SetWriteCacheMode"
XFUFUvirus.exe"Added by the VB-EJC TROJAN!"
XFuckD3w4FuckD3w4.exe"Added by the BRONTOK-DI WORM!"
XFuckerfucker.vbs"Added by the CATCHER-A WORM!"
UFujitsu Hotkey UtilityIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
UFujitsu MenuFjMnuIco.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
XFUKLBARbar.exe"PurityScan adware"
NFullAudioWMPImporter.exeUsed to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
XFunFun.exe"Added by the COIDUNG-A WORM!"
NFusionHdtvTrayFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
UFusionRCFusionRC.exe"Remote control manager for DVICO FusionHDTV"
UFusionRemoteFusionRc.exe"Remote control manager for DVICO FusionHDTV"
NFusionTrayAgentFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
Xfvekfvek.exe"Added by the DRIVOL-A TROJAN!"
YFveNotifyfveNotify.exe"Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista
XFW Managerfwcheck.exe"Added by the DELBOT-H WORM!"
XFWDMON.EXEfwdmon.exe"Added by the PROXY-S TROJAN!"
Yfwenc.exefwenc.exe"Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up
XFwr Command Modulefwr.exe"Added by the SDBOT-PP WORM!"
Nfwrastrcfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
Ufwservicefwservice"eAcceleration Stop-Sign security software related. Previously not recommended
XFXieloader.exeAdded by the SMALL.RR TROJAN!
XFxoekmmiyhart.exe"Added by the SDBOT-CZQ WORM!"
Ufxredirfxredir.exeCanon MultiPASS fax redirector
Xfzgsvhost32.exe"Added by the DLOADER.BDK TROJAN!"
Xf~ara32.exe"Added by the CAY TROJAN!"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG4G[random filename]Detected as Trojan-Downloader.Win32.VB.fki
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
Xgadkgak12fsafsakx12.exe"Added by the ONLINEG-N TROJAN!"
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
YGDFirewallTrayGDFirewallTray.exe"System Tray access to the firewall part of G Data range of internet security products"
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
YGetcaInfoMyCa.exe"Monitor for a Belkin USB Wireless adapter"
Xgf1.0.0.2ggf.exe"Added by the EDFON.A TROJAN!"
Xgfxtray"rundll32 ctccw32.dllfindwnd"
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
YGilatFTCftc.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
XGLF Network Lan MonitorNPFMNTOR.exe"Added by the RBOT-AGY WORM!"
XGlobalFlagACERACER.exe"Added by the VB.BL WORM!"
XGlobalFlagimglogimglog.exe"Added by the AGENT-GYK TROJAN!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
XGoogle Earth[random filename]"Added by the RBOT-AXK TROJAN!"
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
UGoogleToolbarNotifierGoogleToolbarNotifier.exe"Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
XGraphics_default.pif"Added by the AUTOSKY WORM!"
XGreatDefenderGreatDefender.exe"GreatDefender rogue security software - not recommended
XGreatDefender.exeGreatDefender.exe"GreatDefender rogue security software - not recommended
YGroove Virtual OfficeGroove.exe"""Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings
?GsiFinal"rundll32 gspndll.dllpostInstall final"
Xgtydfiisca.exe"Added by the CLAGGER-BB TROJAN!"
Xgtydfiscca.exe"Added by the DWNLDR-GTK TROJAN!"
Xgtydfggrrgg.exe"Added by the DLOADR-AZK TROJAN!"
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
Xgvagfxjrundll32 ...gvagfxj.dll"Unidentified adware
XHackMuFptHackMuFpt.exe"Added by the SCLOG-AG TROJAN!"
XHalflifehalflife2.exe"Added by the AGOBOT-OC BACKDOOR! Note - this file is not associated with Valve Corporation's Half-Life 2 game"
UHalifaxHowardClusterskinkers.exe"""Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
UHaMFrontPanelhampanel.exe"Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget
XHardware Profilehxdef.exe"Added by the LOVGATE.AB WORM!"
XHardware Profilehxdef.exe..."Added by the LOVGATE.Z WORM!"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
UHDDlifeHDDlife.exe"HDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks"
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
Xhe3bbcff"rundll32.exe he3bbcff.dllEnableRunDLL32"
Xhe3e3fc4"rundll32.exe he3e3fc4.dllEnableRunDLL32"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
Xhen[filename].exe"Added by the TARNO.G TROJAN!"
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
UHfHf.exe"Hide Folders - hide your folders so only you can view them"
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Yhffsrvhffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Yhffsrv.exehffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Uhfxphfxp.exe"Hide Folders XP - hide your folders so only you can view them"
XhgkytwekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
XHhjg5jfd93dftdfwinlogan.exe"Added by the ERTFOR.A TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
YHighPoint ATA RAID Management Softwareraidman.exe"HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
XHOT FIXGothic.exe"Added by the SDBOT.FIR WORM!"
XHOT FIXfilename.exe"Added by the SDBOT-DKM WORM!"
XHOT FIXE0chis.exe"Added by the HUPIGON.JTY TROJAN!"
XHOT FIXQOching.exe"Added by the WOOTBOT.VH WORM!"
XHOT FIXView.exe"Added by the WOOTBOT.BN WORM!"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
Xhotfixmsnnmaneger.exe"Added by the WOOTBOT.AF WORM!"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
UHOTFOON2hotfoon4.exe"Related to Hotfoon - a developer and provider of Internet Telephony technology based on LTP (Lightweight Telephony Protocol)"
?hp 1000 firmwarefwdl.exe"HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?"
NHP Image Zone Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
NHP Info Express??"On HP PCs
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
NHP Photosmart Premier Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
NHP software updateHPWuSchd.exe"HP software updates. If a shortcut doesn't exist
NHP-Aio FlightRemind32.exeHP multifunction registration
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAIO_PrintFolderMgrhpoopm07.exe"Directly from HP: "This process has one purpose - detects if the device moves to a different port
Nhpfschedhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
UHPLogiFinderhp_finder.exeHP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
?hpScannerFirstBootscannerfb.exe"HP scanner related"
NHPStarthpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Xhptoolsmicrosoft.exe"Added by a variant of the SDBOT WORM!"
XHP_runnerfront.exe"Added by the SILLYFDC WORM!"
UHREF.OCXregsvr32.exe ....HREF.OCX"HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
XHTML Help Systemhhs.pif"Added by the RBOT-ATB WORM!"
XHTML32 Help Systemhhs32.pif"Added by the RBOT-ATE WORM!"
XHWINFO*HWINFO*"Added by the PUROL WORM! where * is a random character"
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
Ui8kfanguii8kfangui.exeGraphical interface for fan speed control
UIAAnotifIaanotif.exe"Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes
NIBM Client Security Softwarecsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
UIBM TrackPoint Accessibility Featurestp4ex.exe"Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound""
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Xicddefff"rundll32.exe icddefff.dllEnableRunDLL32"
YICFmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
Xicifatiyujixit.exe"Added by the SDBOT.ZZH WORM!"
NIconfig.exeIconfig.exeIcon for LS-120 "Superdisk"
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Visualplscx.exe"Added by the RBOT-AYO WORM!"
Xicrosoft Visual InterDevczvslmqb.exe"Added by the RBOT-AYP WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIE6porn.pif"Added by the RBOT-ATF WORM!"
XIEACCESSsurfya.exe"
XIEFeaturesIEFeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XIEFeaturesInternetfeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XIefxTrayIefxTray.exe"Added by the RILER-H TROJAN!"
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
Xifpipf.exe"Added by the CLAGGER-AG TROJAN!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
Xifperxxmliwvug.exe"Added by the SLAPER.U TROJAN!"
UIFSplash.exeIFSplash.exeI-FORCE driver for force feedback steering wheel
UIFXSPMGTifxspmgt.exe"Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer
Uigfxhkcmdhkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
Uigfxpersigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
Xigfxtrassvchots.exe"Added by the AUTORUN-AIW WORM!"
UIgfxTrayigfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
XilortgdgkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
?ILO_Office_ManagerIntEdReg.exe /OFFMAN"Intense Educational Ltd - Language Office Software. Is it required?"
XImage"rundll32 [path] [trojan filename]Install"
NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
UImagefoximagefox.exe"ImageFox 2.0 (formerly available from ACDSee) is an ""add-on"" graphics previewer for most Windows Open/Save As dialog boxes"
Ximgit[path to file]"Added by the BANKER-EM TROJAN!"
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
?InetConfinetconf.exe"??"
Uinetinfo.exeinetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
Xinetinfomon managerinetinfomon.exe"Added by the DONBOMB.A TROJAN!"
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XInfeStopInfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
XINFO DATAapc.exe"Added by the RANDON.B WORM!"
UInfo Selectis.exe"Info Select from Micro Logic - personal information manager"
XInfo32xInfo32x.exe"Added by the GEMA TROJAN!"
XInfoData"rundll32.exe ********.dllrealset [* = random char]"
UInfoPenMSNInfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
?Infoplay.exeInfoplay.exe"Written by New Media Properties
XInformation Updateiu.exe"Detected by Kaspersky as the CENTIM.CH TROJAN!"
UInfra-red MonitorIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
Xinfusinfus.exeAdult content dialler
UInfuzerInfuzer.exe"Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them
Xinfwininfwin.exe"VX2.Transponder parasite updater/installer related"
XInstafinderinstafinder.exe"TopSearch.D adware"
XInstaFinderKInstaFinderK inst.exe"InstaFinder adware"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
UIntel(R) Common User Interfaceigfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfacehkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
XIntelliflag_be.exeIntelliflag_be.exe"Intelliflag spyware"
YIntelWirelessifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
XInternal[trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
XInternal Memory Filesysintmemory.exe"Added by the RBOT-GKT WORM!"
XInternat[trojan filename]"Added by the CMJSPY-Y TROJAN!"
XInternat Confbootconf.exe"Homepage hijacker
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
XInternet2 Optimizerwkfix.exe"Added by a variant of the RBOT WORM!"
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIntersoft Msngrintersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
Yiolo Personal FirewallioloFW.exe"iolo Personal Firewall"
Xioroxxo microsoft suxsystem32.exe"Added by a variant of the RBOT WORM!"
Xipcfg.exeipcfg.exe"Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
XIPFWipwf.exe"Added by the DLOADER-YF TROJAN!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
Xipwfipwf.exe"Added by the SCHOEBERL TROJAN!"
XIrwftp[path to trojan]"Added by the BANCOS-AP TROJAN!"
Xirwftpiexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xirwftpftpmon.exe"Added by the BANCBAN-BO TROJAN!"
UIrXferIrXfer.exeMicrosoft Infrared Transfer application
Xir_ftpir_ftp.exe"Added by the IRFTP TROJAN!"
Xir_ftpirwftp.exe"Added by the BANCOS.H TROJAN!"
NIS CfgWizcfgwiz.exeNorton Internet Security configuration wizard
XiSafeAViSafeAV.exe"iSafe AntiVirus rogue security software - not recommended
XIsrafelIsrafel.vbs"Added by the GAGGLE.D or GAGGLE.E WORMS!"
Xist service uninstall[random filename]"ISTBar adware related"
XItalUitalfds.exe"Added by a TROJAN - see here"
Xitunesffitunesff.exe"Added by the EB adult premium dialer"
XJA Cfg Util v2jacfg2.exe"Added by the RBOT-AL WORM!"
XJA Config 32Awesome32.exe"Added by a variant of the SDBOT WORM!"
XJava Applicationvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XJava SofteJava32.com"Added by the RBOT.ECN WORM!"
NJava(TM) Platform SE 6jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
NJava(TM) Platform SE 6 U*jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now. U* represents the update version
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
NJBJiffybar.exe"Get Paid As You surf" application
Xjcidls[random filename]"Added by a variant of the SLAPER TROJAN!"
XJfwehnrtghgfjrs.exe"Added by the SDBOT-IJ WORM!"
Xjkdfj94kgdftdfwinlogan.exe"Added by the ZLOB.BZ TROJAN!"
UJMB36X ConfigureJMRaidTool.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
YJMB36X ConfigureJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
XJufualtjava2.exe"Added by the SDBOT.AOE WORM!"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
Xjvdnlssnfljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjxef1104jxef1104.exe"Added by the XIPI-A WORM!"
Xjysyqm[random filename]"ZenoSearch adware"
Xjzvfvsqpcjzvfvsqpc.exe"Added by the AGENT-GWP BACKDOOR!"
XK2ps_full.taskK2ps_full.exe"Added by the JUNTADOR.K TROJAN!"
XKadoc[random filename].exe"Added by the STAPREW TROJAN!"
Xkamsoftckvo.exe"Added by the GAMANIA-BW TROJAN!"
YKaspersky Anti-HackerKAVPF.exe"Kaspersky Anti-Hacker personal firewall - no longer available"
XKAVFOXwin1ogoin.exe"Added by the GWGHOST-M TROJAN!"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
YKavPFWKavPFW.exe"KingSoft Personal Firewall"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKAVutil[worm filename]"Added by the WINTOO.B WORM!"
XKAZAACuf9"Added by the KITRO.D (or ARGEN.A) WORM!"
Xkbddrvinfkbddrvinf.exe"Added by the CRYPTER.A TROJAN!"
UKeNotifyKeNotify.exe"Toshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock
Xkern64dll[random filename]"Added by the TARNO.J TROJAN!"
XKernal Fault Checkntosrkl.exe"Added by a variant of the SDBOT WORM!"
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
XKernel Safe Modesmss.exe"Added by the 78CRACK-A TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xkernel44.dll"taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
XKernelConfigdestiny32.exe"Added by the AGOBOT.AMB WORM!"
Nkernelfaultcheckdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Nkernelfaultcheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XKernelFaultCheckptool32.exe"Added by the LEGMIR-BN TROJAN!"
XKernelFaultCheckmsime.exe"Added by the TINY-P TROJAN!"
XKernelFaultChecktell32.exe"Added by the LEGMIR-BF TROJAN!"
XKernelFaultCheckwinabc3.exe"Added by the NUBYS-A VIRUS!"
XKernelFaultCheckwinbin.exe"Added by the DLOADR-AAX TROJAN!"
XKernelFaultChksms.exe"Added by the DEADHAT WORM! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
Xkeyboardkybrdef_7.exe"DollarRevenue adware"
Xkfienqmasbl.bat"Added by the KIFER TROJAN!"
XKinofilmoff.NetReklamer.exe"Added by the AGENT-NGX TROJAN!"
XKL AntiFunLoveflcss.exe"Added by the FUNLOVE.4099 VIRUS!"
Xklop[path to file]"Added by the AGENT-WQ TROJAN!"
XKnowledgeBase GUIwppewafaj.exe"Added by the RBOT-GRZ WORM!"
NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
UKodak EasyShare softwareEasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
NKodak Picture Easy *.* Batch TransferPezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
NKodak Software Updaterbackweb*****.exe"Software updater for Kodak Easyshare digital cameras"
NKODAK Software UpdaterKodak Software Updater.exe"Software updater for Kodak Easyshare digital cameras"
YKPFW32.EXEKPFW32.EXE"KingSoft Personal Firewall"
YKPFWSvc.EXEKPFWSvc.EXE"KingSoft Personal Firewall"
Xkvasoftkva8wr.exe"Added by the ONLINEG.ICC WORM!"
Xkw3eef76"rundll32.exe kw3eef76.dllEnableRunDLL32"
UKX509kx509_kfwk5.exe"Kerberos Secure Authentication for Windows"
XL0adersfaxneti.exe"Added by a variant of the SDBOT TROJAN!"
Xl44sys**freecell"Added by the VBS.LIDO WORM - where ** is a number between 1 and 12"
XL4r1$$aL4r1$$a.pif"Added by the ASSIRAL-C WORM!"
Xlar[trojan filename]"Added by the ROXY.C TROJAN!"
XLAsIAf32RePEAtLD.exe"Added by the REPEATLD WORM!"
XLaunch Norton AntiVirus 2000jorgf.exe"Added by the RBOT-AUI WORM!"
XLavasoft Ad-AwareAd-Aware.exe"Added by the RBOT-SO WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
ULavasoft AdwatchAd-watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
Nlcfeplcfep.exe"Tivoli 'TME' System Tray icon - ""'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"""
?LCIDConfiglcidchng.exe"??"
ULENOVO.TPFNF6RTPFNF6R.exeSupports the Fn+F6 hotkey combination on IBM/Lenovo Thinkpad notebooks which mutes the microphone
NLenovoOobeOffersLenovoOobeOffers.exe"Displays product upgrades/offers from Lenovo on the first run of a new notebook/desktop. ""Oobe"" refers to the ""Out of box experience"""
ULexmark 5000 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 6500 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 7600 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 9300 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X6100 Serieslxbfbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
XLfhLfh.exe"Added by the ZAURGA-A TROJAN!"
ULfsndmnglfsndmng.exe"LightningFAX Enterprise Fax Server - ""puts faxing at the fingertips of networked enterprise users. It enables rapid
NLG MagnifierMagnifyingGlass.exe"Screen area magnifying utility for LG Notebooks"
XlgfxTraylgfxTray.exe"Added by the TAKEOBEL WORM! Note - the filename has a lower case ""L"" rather than an upper case ""i"" at the beginning and should not be confused with the valid Intel graphics file ""igfxtray.exe"""
ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
Nlhttseng"rundll32.exe ..lhttseng.inf RemoveCabinet"
Xli01f948"rundll32.exe li01f948.dllEnableRunDLL32"
ULicCtrl"rundll32.exe MMFS.DLL Service"
XLife FireWall Update1FireWall-Update1.exe"Added by the RBOT-ARS WORM!"
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
?LifeCamLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
ULifeChatLifeChat.exe"Support software for Microsoft's ""LifeChat"" headsets - which are optimized for use with Windows Live Messenger"
NLifeDrive ManagerLifeDriveMgr.exe"Keeps the Palm LifeDrive Manager utility in the systray. Shortcut available via Start -> Programs"
ULifeDrive? ManagerLifeDriveMgrTray.exe"System Tray utility for the Palm LifeDrive Mobile Manager"
?LifeExpLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
NLifeScape Media DetectorPicasaMediaDetector.exe"Media detector for Picasa's automatic photo organizer"
Xlifyyujixit.exe"Added by a variant of the SDBOT WORM!"
?LightFrame 3LightFrameV3.exe"Support software for Philips range of LCD Monitors that support LightFrame™ - which ""reduces eye strain by surrounding your monitor frame with blue light that stimulates your visual senses for improved concentration and promotes an overall feeling of wellbeing"". What does it do and is it required?"
XLinkSafenessLinkSafeness.exe"LinkSafeness rogue security software - not recommended
Xlk3h1[path to file]"Added by the MOSUCK-G TROJAN!"
Xloadctftpscr32.exe"Added by the AGENT-FPN TROJAN!"
XloadSystemfile.dll.vbs"Added by an unidentified WORM or TROJAN! See here"
?load=cfgsys32.exe"??"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
Yload=Bfrecv.exeBitware modem driver
?Load=wtfeat.exe"Associated with the Wintab Digitizer"
Xload=inetinfo.exe"Added by the PROXY-GG TROJAN!"
Xloadfaxloadfax.exe"Added by the WINFLUX-C TROJAN!"
XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
ULoadFujitsuQuickTouchQuickTouch.exeMaps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions
XLoadGolfCoursesLoadGolfCourses.exePlayMiniGolf.com foistware - stealth installed!
XloadMefsrundll32.exe"Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process
XloadMefssmss32.exe"Added by the FLOOD-EL TROJAN!"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
XLoadPFWwmimgr.exe"Added by the QEDS-B WORM!"
XLoadPowerProfileASDAPI.EXE"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLoadPowerProfileRundll.exe powerprof.dll"Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
XLoadPowerProfilerundl.exe"Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
XLoadPowerProfileRundll32.exe"Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XLoadService"Maaf tempatmu bukan di sin"
XLoadWindowsFileKernel32.exe"Added by the DELF.B TROJAN!"
XLoadWindowsFilewinreg.exe"Added by the HUPIGON.A BACKDOOR!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XLocal Pagehttp://find.naupoint.com"Naupoint browser hijacker"
XLocal-Settings-of-[User Name][User Name].exe"Added by the GAVGENT.A WORM!"
ULocalProxyproxy4free.exe"""ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored
XLocator Service[filename]"Added by the AGOBOT-KY TROJAN!"
Xlofgyhlofgyh.exe"Added by the SDBOT-TP WORM!"
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
XLogin Service[path to file]"Added by the MIGMAF TROJAN!"
?Logitech Camera SoftwareElkCtrl.exeEntry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
NLogitech Desktop Messengerldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NLogitech Desktop Messenger Agentldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NLogitech Gaming SoftwareLWEMon.exePart of Logitech Gaming Software (formerly Wingman Software) for their range of game controllers. Starts the profiler (button configuration) and loads the last used profile at start-up - including System Tray access. Unless you're a hard-core gamer it's best to leave it disabled and load when needed
ULogitech Harmony Remote Software 7HARMON~1.EXE"Logitech
NLogitech QuickCamManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
NLogitechSoftwareUpdateManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
YLogoffSCTUINotify.exe"Part of Windows SteadyState
XLotsOfGames"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfJokes"rundll32.exe MSA64CHK.dllDllMostrar"
XLowRiskFileTypessysguard.exe"Added by the FAKEAV-UY TROJAN!"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
XLSAwfdmgr.exe"Added by the MYTOB.C WORM!"
XLSASS 32ISASS32.pif"Added by the ASSIRAL-C WORM!"
ULSPFixLSPmonitor.exe"eAcceleration Stop-Sign security software related. Previously not recommended
ULtcyCfgApplyLtcyCfg.exe"PCI Latency Tool - ""Utility to set PCI Latency and possibly prevent game stutter or improve FPS"" for older AGP/PCI graphics cards"
Xltwobformatsys.exe"Added by the SERFLOG.A WORM!"
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
YLXCFCATS"rundll32 [path] LXCFtime.dll _RunDLLEntry@16"
Ulxdfamonlxdfamon.exeLexmark 6500 Series printer device monitor
Ulxdfmon.exelxdfmon.exeLexmark 6500 Series printer device monitor
XM-soft OfficeM-soft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
Xm32infom32info.exe"Added by the CRYPTER.A TROJAN!"
XMacfee Security PatchMpfsheild.exe"Added by the RBOT-NP WORM!"
XMachine Update Softwusas.exeAdded by an unidfentified WORM!
Xmackfy.exemsms.exe"Added by the SDBOT-DID WORM!"
XMacromedia 8Flash Player.exe"Added by the JAMBU-A WORM!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
UMACVNTFYMACVNTFY.EXE"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMAFWTaskbarAppMAFWTray.exeDrivers for the M-Audio Firewire Audiophile - Interface
UMagicFormationMagicFormation.exe"MagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents
UMagicFormation.exeMagicFormation.exe"MagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents
UMailbox Verifiermboxvrfy.exe"Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)"
XMainStartsvcmfte32.exe"Added by the STINX-A TROJAN!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMalware Defensemdefense.exe"Malware Defense rogue security software - not recommended
Xmalwaredefmalwaredef.exe"Malware Defender 2009 rogue security software - not recommended
XMalwareProMFCMalwarePro.exe"MalwarePro rogue security software - not recommended
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
NManifestEngineManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
XMantis[filename]"Added by the MANTIBE VIRUS!"
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
Umasqform.exemasqform.exe"PureEdge Viewer - provides automation framework to manage and deploy XML forms-based processes for e-business and e-government systems. PureEdge was taken over by IBM (see here) and the product became Workplace Forms"
UMatadormlfbuddy.exe"MailFrontier - anti-spam application"
XMatrixScreen[filename]"Added by the MATRIXSCREEN TROJAN!"
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
XMbarInstall[random filename]"Mirar adware"
XMcAfeeMcAffeAv.exe"Added by the NETSKY.AL WORM!"
XmcafeeWin32.dll.vbs"Added by the CATCHER-B WORM!"
XMcafee Anti ScanNortonScn.exe"Added by a variant of the RBOT WORM!"
XMcAfee AntivirusMcAfeeAV.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus 32MCAFEEAV32.EXE"Added by the SPYBOT-EH WORM!"
XMcafee Antivirus Monitoring System326VSStatmn326.exe"Added by a variant of the SDBOT WORM!"
XMcafee Antivirus Monitoring System32mnVSStatmn32.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus ProtectionmcafeeAV.exe"Added by a variant of the RBOT WORM!"
YMcAfee Application Installermcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XMcafee Auto Protectmcafeshield.exe"Added by the RBOT-UH WORM!"
UMcAfee BackupMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Backup and RestoreMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Data BackupLogOnHook.exe"Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
UMcAfee Data BackupMcAfeeDataBackup.exe"McAfee Data Backup (now Online Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
YMcAfee Desktop Firewall TrayFireTray.exe"McAfee Desktop Firewall"
YMcAfee Family Protectionmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
YMcAfee FirewallCPD.EXEFirewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
UMcAfee GuardianCMGrdian.exe"McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security
YMcAfee Managed Desktop AgentMYAGTSVC.EXE"Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
UMcAfee Managed Services TrayStartMyagtTry.exeSystem tray notification for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
UMcAfee Online BackupMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Online Backup StatusMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
XMcAfee Online virus Scanneravp.exe"Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XMcAfee Online Virus Scannernzm.exe"Added by the IRCBOT.XV WORM!"
UMcAfee QuickClean ImonitorPlguni.exe"Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection
YMcAfee SecurityCentermcagent.exe"McAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection
YMcAfee SecurityCenterMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
Xmcafee Software Intrenetmcafee.exe"Added by the RBOT-ATR WORM! Note - this is not a valid McAfee program"
UMcAfee SpamKillerMskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
YMcAfee VirusScanmcmnhdlr.exe"Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically
YMcAfee VirusScanmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
YMcAfee VirusScanoasclnt.exe"On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access
XMcafee VirusScan Managermvcsvm.exe"Added by the SILLYFDC.BBV TROJAN!"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
NMcAfee Winguage??"Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications
UMcAfee.InstantUpdate.MonitorRuLaunch.exe"Instant Updater for McAfee's VirusScan
UMcAfeeDataBackupMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
YMcAfeeFireTrayFiretray.exe"McAfee Desktop Firewall"
XMCAFEEIPSsetup.exe"Added by the WHITEWELL TROJAN!"
XMcAfeeScanPlusMcAfeeScanPlus.exe"Added by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder"
YMcAfeeUpdaterUIUpdaterUI.exeMcAfee common updater user interface
YMcAfeeUpdaterUIUdaterUI.exeUpdater user interface for McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
YMcAfeeWebscanXWebScanX.exe"From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs
XMcaffe AntivirusMcafeescn.exe"Added by a variant of the SPYBOT WORM!"
XMCAFFE FLD LOADERMCAFFEFLD.EXE"Added by the RBOT-PY WORM!"
XMcaffeemcsheild.exe"Added by the RBOT-FDP WORM!"
XMcrosoftr UpdateMcrosoftr.exe"Added by a variant of the RBOT WORM!"
XMcsoftgfeqzvq.exe"Added by the SDBOT-NV WORM!"
XMedia Player Updatexpsp1mfh.exe"Added by a variant of the RBOT WORM!"
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
XMedia Software UPdatersscs.exe"Added by the RBOT-ABE WORM!"
XMedia Transfer Protocalsmsstc.exe"Added by a variant of the IRCBOT TROJAN!"
NMediaFace IntegrationSethook.exe"Fellowes Neato® cd label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
UMediafour Mac Volume NotificationsMACVNTFY.EXE"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour MacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMediafour MacDriveMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
UMediafour XPlay Tray Notification IconXptryicn.exe"Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
UMediafour XPlay Tray Notification IconXptryicn.exe"Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod
UMediafourGettingStartedWithMacDrive6MacDrive.exe"MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediaLifeServiceMediaLifeService.exe"Related to MediaPlay Cordless Mouse from Logitech"
?MedionVFDMdionLCM.exe"Related to Medion Display Information. What does it do and is it required?"
?meidntpavqgdpfrs.exe"??"
XMemConfigSetupIE.com"Added by the TAPLAK WORM!"
XMemory Managermemorymanager.pif"Added by the DELF-JJ TROJAN!"
XMemory Servicefreememory.exeAdded by the RBOT.GEN WORM!
UMemory+tfimemsr.exe"Memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XMenaceFighterGDC.exe"MenaceFighter rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NMessagerStarter FreeserveStartMessager.exeFreeserve Messenger
XMessenger6command.pif"Added by the INZAE.B WORM!"
Xmessnger[worm filename]"Added by the DELODER WORM!"
NMetacafeMetacafeAgent.exe"Metacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy Policy"
XMfc**.exe [* = random char]Mfc**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XMfc**32.exe [* = random char]Mfc**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
?mfgboot??"??"
Xmfhsornwnduyregsvr32.exe gisyflngpshcvuakv.dll"Pro AntiSpyware 2009 rogue spyware remover - not recommended
XmFilterMNeck.exe"Added by the CLICKER-AG TROJAN!"
Xmfin32mfin32.exeMyFreeInternetUpdate - adware downloader
Ymfpmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
UMFP PanelMgrSSMMgr.exe"Monitors ink levels
YMFP Server AgentMFPAgent.exe"Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
UMFP1815_S2PScan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
XMfqneqfebvdddwq.exe"Added by the RANDEX.AP WORM!"
XMgsgi servicewkzfn.exe"Added by the AGOBOT-AHL WORM!"
XMi7sft sdceb0yz.exe"Added by the RBOT.CWG WORM!"
XMi7sft sdceMNSQ.exe"Added by the RBOT.DMU WORM!"
XMi7sft sdcescorti.exe"Added by the RBOT.ELC WORM!"
XMickey Mouse Cereal[random filename].exe"Added by the RANKY.Q TROJAN!"
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicosoft Startupsyscall.exe"Added by the SDBOT-JI WORM!"
XMicosoft Startupsystall.exe"Added by the SDBOT-GM BACKDOOR!"
XMicr0s0ft Ms D0smsdx.exe"Added by the RBOT-AON WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicrcoft Exploererspoolsal.exe"Added by the RBOT-AKK WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
XMicrcoft Updatspoolsae.exe"Added by the RBOT-AIB WORM!"
XMicrcoft Updatspoolsaex.exe"Added by the RBOT-AJM WORM!"
XMicrcoft UpdatInternet.exe"Added by the RBOT-ANA WORM!"
XMicrcsoft Certificate Servicescflmon.exe"Added by the RBOT-FWV WORM!"
XMicro Office[path to trojan]"Added by the BANCBAN-QC TROJAN!"
XMicro Processappconf.exeAdded by an unidentified WORM or TROJAN!
XMicroedSoft ToolbarSmoked.exe"Added by the RBOT-ALN WORM!"
XMicrofinder lptt01mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrofinder ml097emcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicroLoad[random filename]"Added by the DARBY WORM!"
XMicromedia Flash Updatewdfmrg.exe"Added by a variant of the SDBOT WORM!"
XMicromedia Flash Updatexptxt.exe"Added by the RBOT-GAB WORM!"
XMicrooft Timingpupdate.exe"Added by a variant of the RBOT WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosft Conf 32msaconf.exe"Added by the RBOT.EYA WORM!"
XMicrosft Confige 32msaconfigurez.exe"Added by the RBOT.CLC WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMICROSFT MX UPDATE SUPPORTtaskmngrs.exe"Added by the RBOT-AUZ WORM!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMICROSFT RAMA UPDATE SUPPORTMSN32.EXE"Added by the RBOT-AWJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTmtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTMSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
XMicrosft Remote Procedure Daemonmsrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processcmh.exe"Added by the EGGDROP.V WORM!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosof Valuenmatt.exe"Added by a variant of the RBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
XMicrosof Winlog Hostwilogon32.exe"Added by the RBOT.XC WORM!"
XMicrosofot x386 System Monitorsystem32.exe"Added by the WOOTBOT.M WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
Xmicrosoftmicrosoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoftwin32.exe"Added by the DARKMOON TROJAN!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftwuauclt.exe"Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoftguard.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftwcsntfy.exe"Added by the AGOBOT-AHT WORM!"
XMicrosoftssmss.exe"Added by the RBOT-FZF WORM!"
XMicrosoftlsass.ppf"Added by the RBOT-GAA WORM!"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftmixers.exe"Added by the AGOBOT-AHU WORM!"
XMicrosoftmsmsger.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftradnom.exe"Added by the RBOT-GHO WORM!"
XMicrosoftrtvcscan.exe"Added by the RBOT-GGU WORM!"
XMicrosofttaskbar.exe"Added by a variant of the RBOT WORM!"
XMicrosoftupdater.exe"Added by the RBOT-GHP WORM!"
XMicrosoftwindl32.exe"Added by the SDBOT-DCZ WORM!"
XMicrosoftaim.exe"Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility"
XMicrosoftExplorerr.exe"Added by the IRCBOT-WG TROJAN!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoftmsngerf.exe"Added by the RBOT-GLW WORM!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoftrundll.exe"Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftwsim32.exe"Added by the RBOT-GTL WORM!"
XMicrosoftwplayer.exe"Added by the IRCBOT-ABP TROJAN!"
XMicrosoftmdms.exe"Added by the AGENT-GHY TROJAN!"
XMicrosoftExplorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoftinstall.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftinternetdat.exe"Added by the RBOT.ETY BACKDOOR!"
XMicrosoftntsvr.exe"Added by a variant of the RBOT WORM!"
XMicrosoftschost.exe"Added by the RBOT.FEH BACKDOOR!"
XMicrosoftsoundvol32.exe"Added by the RBOT.CIJ BACKDOOR!"
XMicrosoftsqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftwinline.exe"Added by the AGENT.KT TROJAN!"
XMicrosoftsystem32.exe"Added by the IRCBOT-ZZ WORM!"
XMicrosoftwinsys32.exe"Added by the RBOT-GSQ WORM!"
XMicrosoftwinnn.exe"Added by the RANDEX.GGP WORM!"
XMicrosoftsymtea.exe"Added by the SPYBOT.AMTE WORM!"
XMicrosoftMicrosoftCorporation.exe"Added by the KILLFILES.AED TROJAN!"
XMicrosoftfirefox.exe"Added by the RBOT-GVJ TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft .NET Confinguratormsnconf.exe"Added by an unidentified VIRUS
XMicrosoft 16Bit Updatewuapdate16.exe"Added by the RBOT.CZ WORM!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
UMicrosoft ActiveSyncWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Admin ProtocalMSADNIN.exe"Added by a variant of the RBOT WORM!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Agentmdss32.exe"Added by the KEYLOG-AG TROJAN!"
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft ALG32 Protocolalg32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft ALGXP Protocolalg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft allmmall.exeWopla.ac malware variant
NMicrosoft Announcement ListenerAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft AntiSpywareBazzi.exe"Added by the AHKER.J WORM!"
XMicrosoft AntiSpywareKT06.pif"Added by the IRCBOT.GEN WORM!"
XMicrosoft AOL Instant MessengerMSAOL32.exe"Added by the RBOT-AAI WORM!"
XMicrosoft AOL32 Protocolaol32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Application Centermappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Application Managermsapl32.exe"Added by the BROPIA-AE TROJAN!"
XMicrosoft AUT UpdateMSlti32.exe"Added by the RBOT-X WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft auto updatewuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Bool ValueMV2.exe"Added by a variant of the RBOT WORM!"
XMicrosoft boot system cfg32actboost.exe"Added by the BROPIA.R WORM!"
UMicrosoft Broadband NetworkingMSBNTray.exeMicrosoft Broadband Networking Tray Application
XMicrosoft Browser ServicesBrwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Browser ServicesBrwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Buffer Appmsbuffer.exe"Added by the SLINBOT.NQ BACKDOOR!"
XMicrosoft Cab Managerexec.exe"Affilred adware"
XMicrosoft Cab Managercab.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Calculatorcalc.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft checkerMsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Clientmshost.exe"Added by the RBOT-AND WORM!"
XMicrosoft Clientmsclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Command Csshost.exe"Added by the RBOT-CMK WORM!"
XMicrosoft Command Cwinhost32.exe"Added by the SDBOT-BBA WORM!"
XMicrosoft Command Linewincmd.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Conf Ldrsysconf.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft ConfgKeyswurmgrd32.exe"Added by the RBOT-ARX WORM!"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Fileconfig.exeAdded by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configs 32msgconfigrs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Configuration 35microsot1.exe"Added by an unidentified TROJAN!"
XMicrosoft Configuration Wizardtaskmrg.exe"Added by the SDBOT-MX TROJAN!"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Connection Manager Monitorcmmon.pif"Added by the RBOT-AKV WORM!"
XMicrosoft Control Centercrtl.exe"Added by the RBOT-VX WORM!"
XMicrosoft Core SupportMSxUP32.exe"Added by the RBOT-ANR WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp SQL Certificatessqlcer.exe"Added by the ZYBOT-C WORM!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMicrosoft Corp TLS Certificatesmsauth.exe"Added by the RBOT-GAC WORM!"
XMicrosoft Corp Updateswupdates.exe"Added by the RBOT-AUU WORM!"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporaticn SQL Handlersqlhandler.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Corporationjview.exe"Added by the RBOT-AOD WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Corporation SYM monitormssym.exe"Added by the RBOT-GDB WORM!"
XMicrosoft CP Web Managerwebcp.exe"Added by the IRCBOT.HP TROJAN!"
XMicrosoft CPU Over Heat ManagerCPU.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft CPXP Protocolcpxp.exe"Added by the RBOT.ATP WORM!"
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft CRT Monitor Managercrtmon.exe"Added by the ROBOTON.A WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft CSRSS32 Protocolcsrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft CSRSS386 Protocolcsrss386.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft CTF Loaderctfmon.exe"Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft Data Machinecsdata32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Database Handlermssql32.exe"Added by the RANDEX.AX WORM!"
XMicrosoft Datalog Applicationmsdata.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDE Controlwupades.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Debug Manager Consolemdm32.exe"Added by the AGOBOT-AQ WORM!"
XMicrosoft Debug Servicedbgbgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
UMicrosoft Default ManagerDefMgr.exe"Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
XMicrosoft Desktop Managermsdesk32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Development Debuggermsdev.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Device Managermsdevmgr32.exe"Added by the LATEDA.B TROJAN!"
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft Diagnostic[random filename]"Added by the ACEBOT TROJAN!"
XMicrosoft Diagnosticmsdiag32.exe"Added by the RBOT-UC WORM!"
XMicrosoft Digital Clockmsclock.exe"Added by the NACKBOT-D WORM!"
XMicrosoft Digital Cryptorsmdigits.exe"Added by the SDBOT.LM WORM!"
XMicrosoft DirectXSpoolserv.exe"Added by the DINFOR WORM!"
XMicrosoft DirectXrasmngr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft DirectXPDSched.exe"Added by the SDBOT.CN WORM!"
XMicrosoft DirectXwuamgrd.exe"Added by the SDBOT.MY WORM!"
XMicrosoft DirectXtime123.exe"Added by the SDBOT.MD WORM!"
XMicrosoft Directxdirectxat.exe"Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft Directx clickdirectxclick.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directx clicksdirectxclickers.exe"Added by the RBOT-GHT WORM!"
XMicrosoft Directx pushdirectxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspdirectxbt.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspnewdirectxnew.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft DirktorWin[random filename]"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Disk Scannerscansdisk.exe"Added by the WOOTBOT.DT WORM!"
XMicrosoft DLLfumeta.exe"Added by the RBOT-AUG WORM!"
XMicrosoft Dllrunapidll.exe"Added by the RBOT-GRG WORM!"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL ExtensionsSystemDll.exe"Added by the RBOT-ADV WORM!"
XMicrosoft dll Host Servicewkssr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DLL Librarywinlib32.exe"Added by the ATNAS.A WORM!"
XMicrosoft Dll Managementwindll.exe"Added by the RBOT-MT WORM!"
XMicrosoft Dll Managermicrosoft32dll.exe"Added by the SHEUR.LH TROJAN!"
XMicrosoft DLL Managerdllmgr.exe"Added by the SDBOT-KJ WORM!"
XMicrosoft DLL Monitordllmon32.exe"Added by the AGENT.WP WORM!"
XMicrosoft DLL Monitordllmon64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Monitordllmonitor.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Dll Printer Managerdllpt.exe"Added by the SDBOT.BIH WORM!"
XMicrosoft DLL Serviceservicedll.exe"Added by the IRCBOT.OX BACKDOOR!"
XMicrosoft DLL Servicesvcdll.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft DLL Sourcedllsrc.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Verifierfile.exe"Added by the RBOT-AED WORM!"
XMicrosoft DLL Verifierchkfile.exe"Added by the RBOT-AOC WORM!"
XMicrosoft DLL Verifiercsrssv.exe"Added by the RBOT-ATK WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft DLL Verifierwns.exe"Added by the SPYBOT-LA WORM!"
XMicrosoft DLLSet32dllset32.exe"Added by the RBOT.OZ WORM!"
XMicrosoft DNS Host Resolutionhostres.exe"Added by the AGOBOT-MK BACKDOOR!"
XMicrosoft DNS Querymsdns.exe"Added by the AGENT-BS TROJAN!"
XMicrosoft DNSxmdnex.exe"Added by the DELBOT-AI WORM!"
XMicrosoft Documentkrisp.exe"Added by the SDBOT-RQ WORM!"
XMicrosoft Domain Controllermstc.exe"Added by the NUGACHE.A WORM!"
XMicrosoft Driverfaet.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft ErgoPackwserb32.exe"Added by the RBOT-RI WORM!"
XMicrosoft EV32 ServiceMSev32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Event EngineEvtEngn.exe"Added by the RBOT-XV WORM!"
XMicrosoft Excelmsexcel.exe"Added by the RBOT-TQ WORM!"
XMicrosoft Excelemsmsgs.exe"Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft Excellwuamngr32.exe"Added by the RBOT-QH WORM!"
XMicrosoft Executingmicrosoft.exe"Added by the AGOBOT.UV WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Explorerexplorer.pif"Added by the SDBOT-ACX WORM!"
XMicrosoft Explorerexplorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Explorer(64)explorer64.exe"Added by the SPYBOT-R WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Explorer2bitchbot.exe"Added by the SDBOT.EV WORM!"
XMicrosoft EXPLOREXP Protocolexplorexp.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Featuresms32cfg.exe"Added by the RBOT.HO WORM!"
XMicrosoft Featuresmsie.exe"Added by a variant of the RBOT WORM!"
XMicrosoft File Demand Managerwmgrdf.exe"Added by a variant of the RBOT WORM!"
NMicrosoft Find FastFindfast.exeFrom older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
XMicrosoft Firewallfirewallsp2.exe"Added by the RBOT-MC WORM!"
YMICROSOFT FIREWALL CLIENTISATRAY.EXE"MS Internet Security and Acceleration Server - see here"
XMicrosoft FixUppevblbvr.exe"Added by the RBOT.DWK WORM!"
XMicrosoft FixUpwnpzjpuw.exe"Added by a variant of the SDBOT WORM!"
Xmicrosoft frontpagetwain.exe"Added by the AGENT.AQO TROJAN!"
XMicrosoft Gamesgamemanager.exe"Added by the SPYBOT.AHQ WORM!"
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonmsnmsg.exe"Added by the IRCBOT-XH WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicroSoft Getway Dire[random filename]"Added by the IRCBRUTE.AM WORM!"
XMicroSoft Getway mqbol[12 random letters].exe"Added by the RBOT.GBA WORM!"
XMicrosoft Gina V EncryptionMSGINAV.EXE"Added by an unidentified VIRUS
NMicrosoft Greetings ReminderMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
NMicrosoft Greetings RemindersMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
NMicrosoft Greetings Workshop ReminderGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
XMicrosoft HDCP for NTmsdhcp.exe"Added by a variant of the RBOT WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help Supportmshelp32.exe"Addded by the KELVIR-BF WORM!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Helpdesk Sidemshelpdsk.exe"Added by the SPYBOT.ANJJ WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
Xmicrosoft hotmail monitormshotmon.exe"Added by the MYTOB-FL WORM!"
XMicrosoft hren1mmhren1.exeAdded by a variant of the AGENT.IWW TROJAN!
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft IE Execute shellIEExec.exe"Added by the ALADINZ.N TROJAN!"
XMicroSoft IE SasserISASS.EXE"Added by the SDBOT.MX WORM!"
XMicrosoft IISsyshost.exe"Added by the FRANCETTE WORM!"
XMicrosoft IIS[filename]"Added by the FRANCETTE-S WORM!"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft Inc.iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inc.iexplorer.exe..."Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Incroporatemfs.exe"Added by the RBOT-ANF WORM!"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
XMicrosoft Informationsecurenet.exe"Added by the SDBOT.AJM WORM!"
XMicrosoft Information Checkmicrosoft.exe"Added by the IRCBOT.AUH TROJAN!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Installshieldnundll32.exe"Added by the AGOBOT-AHZ WORM!"
XMicrosoft Instant Messengermsngmsngr32.exe"Added by the SPYBOTER.GEN TROJAN!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
UMicrosoft IntelliPointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft IntelliPointpoint32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft Intellitype Prospeedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
UMicrosoft IntelliType Proitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
UMicrosoft IntelliType Protype32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Internet Acceleration Utilityiau.exe"EasySearch adware"
XMicrosoft Internet Acceleration Utility[path to file]"Added by the AGENT-CX TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Internet Dumping Protocolinetdump.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Internet Firewallfirewall.exe"Added by the IRCBOT.MD BACKDOOR! Located in %System%"
XMicrosoft Internet Firewall ManagerGMT16.exe"Added by the RANDEX.AT WORM!"
XMicrosoft Internet Firewall Updateupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Internet Syncinginetsync.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft IPCsystem.exe"Added by the NULLBOT TROJAN!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft IT UpdateIEserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft IT UpdateRhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinemsjvm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual Machinejavavm.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft JavaVMmsjarun.exe"Added by the RBOT-JW WORM!"
XMicrosoft KernelWindows_kernel32.exe"Added by the NETSKY.AE WORM!"
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL BACKDOOR!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft LAN32 ProtocollanXp.exe"Added by the RBOT-SS WORM!"
XMicroSoft Legal ServiceSrb0ty.exe"Added by the SPYBOT.HW WORM!"
XMicroSoft Legal Syst3m32Syst3m32.exe"Added by the RBOT.UYL WORM!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Locals 332[random filename]"Added by the RBOT-KU WORM!"
XMicrosoft Locals466xagwxzy.exe"Added by the SPYBOT.EL WORM!"
UMicrosoft Location FinderLocationFinder.exe"Microsoft Location Finder ""is a client-side application that turns a regular WiFi enabled laptop
XMicrosoft Loginwinlogin.exe"Added by the RBOT-AJP WORM!"
XMicrosoft Loginswinlogins.exe"Added by the SPYBOT.BCZ WORM!"
XMicrosoft Logon User Interfacelogonnui.exe"Added by the RBOT-BCC WORM!"
XMicrosoft LSA layerMSLSA32.exe"Added by the RBOT-AKZ WORM!"
XMicrosoft Lsass CenterIsass.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Lsass Centertelecomes.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Lsass Managerlsass.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft LV[path to file]"Added by the BDOOR-BDL BACKDOOR!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft machineblah.exe"Added by a variant of the RBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Machineupdata.exe"Added by the RBOT-DJ WORM!"
XMicrosoft Machinetemp.exe"Added by the RBOT-FSQ WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft Managementlmas.exe"Added by the FORBOT-CZ WORM!"
XMicrosoft Management Consolelssas.exe"EasySearch adware"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Management Consolelssas1.exe"Added by the DLOADR-AWD TROJAN!"
XMicrosoft Managermsmanager.exe"Added by the MYTOB.LF WORM!"
XMicrosoft Map PCmappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Mapped PCmappedpc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft Media Center Tray AppletehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
XMicrosoft Media Managermedman.exe"Added by the RBOT.EUZ WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft media servicesIassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Memory Dumping Protocolmemdump.exe"Added by the IRCBOT.BJK BACKDOOR!"
XMicrosoft Memory Flow Cycleflowcycle.exe"Added by the IRCBOT.WAD BACKDOOR!"
XMicrosoft Memory Flow Cycleflowcycles.exe"Added by the WAREZOV.AAK WORM!"
XMicrosoft Message Machinemsmesg32.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Messenger Management Controlsmsmgmctl.exe"Added by the RBOT-APA WORM!"
XMicrosoft messenger sdmsngersd.exeAdded by an unidentified TROJAN!
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft MicroP Protocolwdgmr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Ming Serviceming.exe"Added by the RBOT-AWS WORM!"
XMicrosoft Movie MakerMmaker.exe"Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program"
XMicrosoft MSGPLUS32 Protocolmsgplus32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Messengermsnmnsgr.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Msn Messengermsmsgs.exe"Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft MSNGR32 Protocolmsngr32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft msnserumsnseru.exe"Added by the RBOT-APB WORM!"
XMicrosoft MsnSTmsnst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Neser Experiencenese.exe"Added by the RBOT-YH WORM!"
XMicrosoft Netviewgesfm32.exe"Added by the RANDEX.C WORM!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Networkmsnet.exe"Added by the MOCKBOT.A WORM!"
XMicrosoft NetworkNetworksystem.exe"Added by the SDBOT-AAI WORM!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Network Neighbourhoodnetworknbh.exe"Added by the RBOT.DMN WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Networking Agent For SP2msnac32.exe"Added by the SPYBOT.PEN WORM!"
XMicrosoft Nod32 Servicenood32.exe"Added by the RBOT.EJP WORM!"
XMicrosoft Norotn Anti Virusmnhpot.exe"Added by the RBOT-GRO WORM!"
XMicrosoft Norton Antivirusnorton.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft NotePadnotepad.exe"Added by a variant of the RBOT WORM!"
XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Nvidia Videonvidia.exe"Added by a variant of the SDBOT WORM!"
NMicrosoft Officeosa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft OfficeMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft OfficeMSMSGR.exe"Added by the GAOBOT.BB WORM!"
NMicrosoft OfficeOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Officelserv.exe"Added by the SDBOT.MH WORM!"
XMicrosoft OfficeMicrosoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Officemsoicons.exe"Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
XMicrosoft OfficeNxcao.exe"Added by the RBOT-ZE WORM!"
XMicrosoft Officenxcxtpr.exe"Added by the RBOT-YG WORM!"
XMicrosoft Officesvxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoffice32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsoff.exe"Added by the RAKER-C TROJAN!"
XMicrosoft Officemicrosoft.exe"Added by the BANKER-VF TROJAN!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
XMicrosoft Officemsmsgr.exe"Added by the GAOBOT.BB WORM!"
XMicrosoft Officemdm.exe"Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
UMicrosoft Office 2010BCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
NMicrosoft Office Fast CacheFastboot.exe"Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled"
UMicrosoft Office GrooveGROOVE.EXE"System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
XMicrosoft Office Monitoralg2k.exe"Added by the SDBOT-CZO WORM!"
XMicrosoft Office Monitoraql32.exe"Added by the RBOT-GCY TROJAN!"
NMicrosoft Office OneNoteONENOTEM.EXE"System Tray access to MS Office OneNote 2003 & 2007 - an electronic notebook that allows you to create free-form notes
NMicrosoft Office OneNote 2003 Quick LaunchONENOTEM.EXE"System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes
XMicrosoft Office quick launchOSA.exe"Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicrosoft Office Quick Launcheriau1.exe"Added by the DLOADR-AWD TROJAN!"
NMicrosoft Office Shortcut BarMsoffice.exeFeature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Office Studioscvhvst.exe"Added by the RANDEX.CST WORM!"
XMicrosoft OfficeXPofficeXP.exe"Added by the KILLAV.MA WORM!"
XMicrosoft Ofticemsmsgs.exe"Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMicroSoft OneCareFreeS3x.exe"Added by the SDBOT-DJT WORM!"
XMicrosoft OpeionsIEXwe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Patch Updatebootini.exe"Added by the RBOT-FMN WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft PCHealth32[path to file]"Added by the NICE-A TROJAN!"
XMicrosoft PCHealth32NDDENB.exe"Added by the PWSYAHOO-A TROJAN!"
XMicrosoft PCI Managermspci.exe"Added by the RBOT.BBG WORM!"
NMicrosoft People Near Mep2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosoft Personal Firewallsbakw.exe"Added by the RBOT-KS WORM!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Procedure CallMSPCALL.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Process Managerprocess32.exe"Added by the CHECKOUT WORM!"
XMicrosoft Profile Managerprofile.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft PSTCP32 Datapstcp32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft QMGRmsnqmgr.exe"Added by the IRCBOT-S TROJAN!"
XMicrosoft quick launchOSA.exe"Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
XMicrosoft RDLLsysconf32.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft Redirect[path to file]"Added by the BANKER-FW TROJAN!"
XMicrosoft Redirectsysten.exe"Added by the BANCOS-FO TROJAN!"
XMicrosoft Regestry Edit Managerregedit.exe"Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
XMicrosoft Regestry Managerregedit32.exe"Added by a variant of the IRCBOT.ARD WORM!"
XMicrosoft Regestry Managerregistry32.exe"Added by the IRCBOT.ARD WORM!"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicrosoft Registrycsrse.exe"Added by the RBOT-PC WORM!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Restorescrgrd.exe"Added by the SPYBOT.BR WORM!"
XMicrosoft Router Managerlinksys.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Router Managerrouter.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Rundllwindos.exe"Added by the SDBOT-WF WORM!"
XMicrosoft RuntimeCfgDll32.exe"Added by the RANDEX.BD WORM!"
XMicrosoft Safe Mode Managersafemode.exe"Added by the IRCBOT.HM BACKDOOR!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft sddcE Contoltaskmnegr.exe"Added by the RBOT-AUM WORM!"
XMicrosoft sddcE Contoltaskmn.exe"Added by the RBOT-BJZ WORM!"
XMicrosoft sdk tempsdktemp.exe"Added by the RBOT-ANP WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft security advisermssadv.exe"Microsoft Security Adviser rogue security software - not recommended"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Security Centerwcsntfy.exe"Added by the SDBOT.BYD WORM!"
XMicrosoft Security Controlersfxsecues.exe"Added by a variant of the SDBOT WORM!"
YMicrosoft Security Essentialsmsseces.exe"System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses
XMicrosoft Security GManagers[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Managementwinnt.exe"Added by the RBOT-MQ WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Managementwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XMicrosoft Security Managementwuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Security Managementbling.exe"Added by the RBOT.XL WORM!"
XMicrosoft Security Managementsp2fix.exe"Added by the RBOT.UB WORM!"
XMicrosoft Security Managerwinamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processlsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Monitor Processcom.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processexel.exe"Added by the SDBOT.AFX BACKDOOR!"
XMicrosoft Security Monitor Processfirewall.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
XMicrosoft Security Monitor Processflash.exe"Added by the EGGDROP.EE BACKDOOR!"
XMicrosoft Security Monitor Processhel.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosoft Security Monitor Processkar.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processlindicracker.exe"Added by the BIFROSE.GR BACKDOOR!"
XMicrosoft Security Monitor Processmail.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Security Monitor Processnitty.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processofice.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processpoint.exe"Added by the IRCBOT.AVP BACKDOOR!"
XMicrosoft Security Monitor Processprinc.exe"Added by the HUPIGON.WTL TROJAN!"
XMicrosoft Security Monitor Processweb.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processword.exe"Added by the EGGDROP.DC BACKDOOR!"
XMicrosoft Security Panager[filename]"Added by the RBOT-ANL WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft Security Panagerszzoboony.exe"Added by the RBOT-AOI WORM!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Security Systemmssecsys.exe"Added by the IRCBOT-WJ TROJAN!"
XMicrosoft Security Updatesecurity32.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Serverrserv.exe"Added by the AGOBOT.AVS WORM!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Server Applacationscli.exe"Added by the RBOT-GAQ WORM!"
XMicrosoft Server ApplicationSound.exe"Added by the RBOT-NE WORM!"
Xmicrosoft server baselass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Processsvhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicerundll.exe"Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft Serviceservice.exe"Added by the IRCBOT-XX BACKDOOR!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft servicecssrs.exe"Added by the STARTP-DC TROJAN!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service 32sysddm32.exe"Added by the SDBOT.AKC WORM!"
XMicrosoft Service Access ManagerAccess.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Service Bootsboot.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Execution Managerexecute.exe"Added by a variant of the IRCBOT TROJAN! See here"
XMicrosoft Service firewall Managerfirewall.exe"Added by a variant of the SDBOT BACKDOOR! Located in %System%"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerservice32.exe"Added by the IRCBOT.WDW BACKDOOR!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicrosoft Serviceslsserv.exe"Added by an unidentified VIRUS
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Servicesservices.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicez Managerservicemgrz.exe"Added by the RBOT-ASN WORM!"
XMicrosoft Session Manager Subsystemsmss.exe"Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
NMicrosoft Sidewinder Game Controller SoftwareSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
XMicrosoft Sinsupodjiwjf.exe"Added by the RBOT-DN WORM!"
XMicrosoft Softwaresysinfo33.exe"Added by the RBOT.LS WORM!"
Xmicrosoft software****.exe [* = random char]Added by an unidentified WORM or TROJAN!
XMicrosoft softwarecdaccess.exe"Added by the RBOT.ABK WORM!"
XMicrosoft Software Updatenmon.exe"Added by the RBOT.HZ WORM!"
XMicrosoft Sound Driversound32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Sound Technologywinsound.exe"Added by the RBOT-AGG WORM!"
NMicrosoft Sound Volume Toolmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
XMicrosoft Soundssoundman.exe"Added by the RBOT-GCI WORM!"
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Special offerinfoebay.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicroSoft ssadsadas3s1eXtream.exe"Added by the SPYBOT.ZK TROJAN!"
XMicroSoft ssadssjdhasjadas3s1kdjfsdklfjsl.exe"Added by the SDBOT.AEX WORM!"
XMicroSoft ssas3s1SADASDA.exe"Added by the RBOT.URF WORM!"
XMicrosoft SSISVRI32 Protocolssisvri.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Standard Executions Librarywin32lib.exe"Added by the RBOT-AUK WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft standard protector[path to trojan]"Added by the STOX-C TROJAN!"
XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
NMicrosoft Sticky Notesstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
XMicrosoft Stuff you knowwinslogin.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Sum32sum32.exe"Added by the RBOT-YW WORM!"
XMicrosoft Supportsys32ms.exe"Added by the RBOT-AHI WORM!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft SVCmssvc.exe"Added by the BIFROSE-UQ TROJAN!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft Syn ManagerManager.exe"Added by the SDBOT.BEF WORM!"
XMicrosoft Synchronization Managerasgard.exe"Added by the SDBOT-AEA WORM!"
XMicrosoft Synchronization Managerbot.exe"Added by the SDBOT.IH WORM!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managerslhost.exe"Added by the SDBOT.YH WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization ManagerWinLoginnn.exe"Added by the SPYBOT.FO WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization ManagerxXx.exe"Added by the SDBOT-KZ WORM!"
XMicrosoft Synchronization Manager___synmgr.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Synchronization Manageral.exe"Added by the OPTXPRO.132 TROJAN!"
XMicrosoft Synchronization Managerwin.exe"Added by the SDBOT.AK WORM!"
XMicrosoft Synchronization Managerjava.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft Synchronization Managerwinlogon32.exe"Added by the SDBOT.AEU WORM!"
XMicrosoft Synchronization Managersvxhost.exe"Added by the SDBOT-ZU WORM!"
XMicrosoft Synchronization Managerwincfg32.exe"Added by the SDBOT.DO WORM!"
XMicrosoft Synchronization Managerscreen.exe"Added by the SDBOT-ACO WORM!"
XMicrosoft Synchronization Managerdevldr32.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
XMicrosoft Synchronization Managerexplorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Synchronization Managerfirewire.exe"Added by the SDBOT-AFC WORM!"
XMicrosoft Synchronization Managerwmedia.exe"Added by the SDBOT.BFC WORM!"
XMicrosoft Synchronization Managerwin932.exe"Added by the SDBOT.AH WORM!"
XMicrosoft Synchronization Managermircup.exe"Added by the SDBOT.BQD WORM!"
UMicrosoft Synchronization Managermobsync.exe"Microsoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline
XMicrosoft Synchronization Manageralien.exe"Added by the SDBOT-MV BACKDOOR!"
XMicrosoft Synchronization Managermicrosoft.exe"Added by the SDBOT-OM WORM!"
XMicrosoft Synchronization Manager 2svhostc.exe"Added by the SLINBOT.ST WORM!"
XMicroSoft sys32sysmsgr32.exe"Added by a variant of the SPYBOT WORM! See here"
XMicroSoft sys3s1h4ckn3t.exe"Added by the RBOT.QTY WORM!"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemmssys32.exe"Added by the PETTICK.A WORM!"
XMicrosoft Systemsys.exe"Added by the RBOT.AKI WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Administrationsystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System CheckupCool.exe"Added by the DONK.B WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System CheckupKeymgr.exe"Added by the DONK.M WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft System Monitormonsys.exe"Added by the IRCBOT-YV TROJAN!"
XMicrosoft System Monitorsystem.exe"Added by the IRCBOT.AUT BACKDOOR!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft System Restore ConfigurationCBRSS.EXE"Added by a variant of the SPYBOT WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Security AgentMSTSA.EXE"Added by the RBOT.CCM WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft system Valuesys57.exe"Added by a variant of the RBOT WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft Task Messenger Configtaskmgsr.exe"Added by the SDBOT-JK WORM!"
XMicrosoft task tray monitorctray.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Task32 Protocoltaskmgr32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Taskmanager Updaterkeyboard.exe"Added by the RBOT-ALU WORM!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecom Centertellecom.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Telecoma Centertellcoma.exe"Added by the RBOT-AWX WORM!"
XMicrosoft Telecoms Centertelcoms.exe"Added by the IRCBOT.GEN WORM!"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Time Managerdveldr.exe"Added by the RBOT-HQ WORM!"
XMicroSoft Toolbarkey.exe"Added by the RBOT-AEW WORM!"
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft Tray[random filename]"Added by the DELF.BZ TROJAN!"
XMicrosoft TTL Verifiermsttl.exe"Added by the RBOT-GAP WORM!"
XMicrosoft Uwuamkopxp.exe"Added by the RBOT-AHC WORM!"
XMicrosoft UMA UpdateMSuma32.exe"Added by the RBOT.FS WORM!"
XMICROSOFT UNPACCKER SYSTEMunpak32.exe"Added by a variant of the RBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updat3mswkst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoft.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updateascdl.exe"Added by the GAOBOT.SY WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updateautomgr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemediap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoftx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft UpdateMslti32.exe"Added by the RBOT-LX WORM!"
XMicrosoft Updatemuamgrd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatenavmgrd.exe"Added by the SDBOT.DP TROJAN!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft UpdateVPC32.EXE"Added by the AGOBOT.XM WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewuamgrd.exe"Added by the RBOT-LK WORM!"
XMicrosoft Updatewuammgr32.exe"Added by the RBOT-AW WORM!"
XMicrosoft Updatewudmate.exe"Added by the RBOT.AP WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatewuamgrd32.exe"Added by the RBOT.ZB WORM!"
XMicrosoft UpdateNAV.exe"Added by the RBOT-IV WORM!"
XMicrosoft Updatesystemi32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft Updatewebm.exe"Added by the SDBOT.WK WORM!"
XMicrosoft Updatewuagrd.exe"Added by the RBOT-FK WORM!"
XMicrosoft Updateaaupdt.exe"Added by the RBOT-RQ WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatewauguard.exe"Added by the RBOT.AEE WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewinsys.exe"Added by the RBOT-GV WORM!"
XMicrosoft Updatewserv32.exe"Added by the RBOT.AF WORM!"
XMicrosoft Updatewtm32.exe"Added by the RBOT-AQ WORM!"
XMicrosoft Updatewumgrd.exe"Added by the SDBOT-KY WORM!"
XMicrosoft Updatewuampd.exe"Added by the RBOT-UT WORM!"
XMicrosoft Updatemsupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft UpdateBotnet.exe"Added by the RBOT.AFL WORM!"
XMicrosoft Updatesghost.exe"Added by the SDBOT.AKV WORM!"
XMicrosoft Updateupdate_w.exe"Added by the RBOT-EW WORM!"
XMicrosoft Updatewindows24.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewingrd32.exe"Added by the RBOT-DW WORM!"
XMicrosoft Updatewssvr.exe"Added by the RBOT-OD WORM!"
XMicrosoft Updatewuamagr32.exe"Added by the SPYBOT.CG WORM!"
XMicrosoft UpdateWinUpdate32.exe"Added by the RBOT-TI WORM!"
XMicrosoft Updatewkfix.exe"Added by the RBOT-ABZ WORM!"
XMicrosoft UpdateKkk.exe"Added by the RBOT-AHL WORM!"
XMicrosoft Updatemcupdate.exe"Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
XMicrosoft UpdateMicr0s0ft.exe"Added by the AGOBOT.AAR WORM!"
XMicrosoft UpdateMsnmsngr.exe"Added by the RBOT.BQS WORM!"
XMicrosoft Updatemsupdate32.exe"Added by the SPYBOT.LZ WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesys.exe"Added by the RBOT-AJ WORM!"
XMicrosoft Updateup2dat5.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
XMicrosoft Updatewin-mang.exe"Added by the RBOT-AFK WORM!"
XMicrosoft Updatewinupdater.exe"Added by the RBOT.BIN WORM!"
XMicrosoft Updatewuamk0032.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamk032.exe"Added by the RBOT-AHD WORM!"
XMicrosoft Updatewuamk0p32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamkop.exe"Added by the RBOT-AFI WORM!"
XMicrosoft Updatewuamkop32.exe"Added by the RBOT.BGU WORM!"
XMicrosoft Updatewuampkd.exe"Added by the SDBOT.BBX WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft Updatewin32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updatewininit.exe"Added by the RBOT-AKR WORM!"
XMicrosoft Updatewuamgrd3.exe"Added by the RBOT-AMC WORM!"
XMicrosoft UpdateWudates.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatems.exe"Added by the SDBOT.CC WORM!"
XMicrosoft Updatewuagmsd.exe"Added by the RBOT-AX WORM!"
XMicrosoft Updatecmss.exe"Added by the RBOT-ATQ WORM!"
XMicrosoft Updatewuamgrb.exe"Added by the RBOT-AZE WORM!"
XMicrosoft UpdateWINDOC.EXE"Added by the SDBOT.PF WORM!"
XMicrosoft Updatephqghumea.exe"Added by the SDBOT.AFO WORM!"
XMicrosoft Updatesystem32.exe"Added by the RBOT.IS WORM!"
XMicrosoft Updatebling.exe"Added by the RBOT-AVK WORM!"
XMicrosoft UpdateSygate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Updateupdate.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft Updatedevmks32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft updatewinupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsupdate.exe"Added by the BOROBOT-I TROJAN!"
XMicrosoft Updatemixer.exe"Added by the RBOT-AIR WORM!"
XMicrosoft Updatetaskmgr32.exe"Added by the RBOT-CV WORM!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updatewangard.exe"Added by the RBOT-LH WORM!"
XMICROSOFT UPDATEWUAGTRD.EXE"Added by the RBOT-CJ WORM!"
XMicrosoft Updatespool.exe"Added by the AGENT-GJC TROJAN!"
XMicrosoft Updatebnmveqfts.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatedqbxhupdt"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Updateenule.exe"Added by the IRCBOT.DU BACKDOOR!"
XMicrosoft Updateexplorer.exe"Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Updateimchemaoa.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatelivemessenger.com"Added by the ADLOAD-LN TROJAN!"
XMicrosoft Updatemsnmsgl.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatennwyaupdt"Added by the RBOT.RHK BACKDOOR!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updaterundll32.dll"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Updatewuamgrdx.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updatewutr.exe"Added by the SPYBOT.AAR WORM!"
XMicrosoft UpdateSetPoints.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Updatesystem.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Updatemsgn.exe"Added by the RBOT.RQ BACKDOOR!"
XMicrosoft Updatewuamgrd16.exe"Added by the RBOT-BQ WORM!"
XMicrosoft Updatewindows32.exe"Added by the RBOT-BHQ WORM!"
XMicrosoft Updatewinsyst.exe"Added by the RBOT-DL WORM!"
XMicrosoft Update 23NtKernelSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 23spoolvs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32explore32.exe"Added by the SPYBOT.CYM WORM!"
XMicrosoft Update 32MSupdate32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Update 32wininit.exe"Added by the RBOT-ANY WORM!"
XMicrosoft Update 32wininit32.exe"Added by the RBOT-AKJ WORM!"
XMicrosoft Update 32[path to file]"Added by the RBOT-AJJ WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update 32servic.exe"Added by the RBOT-AXN WORM!"
XMicrosoft Update 32winitXP32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32mssetup32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32wiit.exe"Added by the RBOT-AMS WORM!"
XMicrosoft Update 32explorer.exe"Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update 32network.exe"Added by the RBOT-ARZ WORM!"
XMicrosoft Update 32om4r.exe"Added by the RBOT-AQP WORM!"
XMicrosoft Update 32winin.exe"Added by the RBOT-ARR WORM!"
XMicrosoft Update 32wuinit.exe"Added by the AGOBOT-UE WORM!"
XMicrosoft Update 32neta.exe"Added by the RBOT-AMI WORM!"
XMicrosoft Update 32spoolvs.exe"Added by the RBOT-BBQ WORM!"
XMicrosoft Update 32rundll32.exe"Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe
XMicrosoft Update 32taskMangr.exe"Added by the RBOT.AIE BACKDOOR!"
XMicrosoft Update 32winssx.exe"Added by the RBOT-ARW WORM!"
XMicrosoft Update 33init.exe"Added by the RBOT-ATT WORM!"
XMicrosoft Update 64 BITwininit32.exe"Added by the RBOT-AHE WORM!"
XMicrosoft Update 64 BITwinman32.exe"Added by the RBOT-AKI WORM!"
XMicrosoft Update 64 BITschvost.exe"Added by the RBOT.CAU WORM!"
XMicrosoft Update 64 BITwinl32xe.exe"Added by the RBOT-AQO WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMICROSOFT UPDATE CONFIGURATIONWIN32SNC.EXE"Added by the RBOT-AI WORM!"
XMicrosoft Update ControlMs64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Debuggerwincfg32.exe"Added by the SPYBOT.ZC WORM!"
XMicrosoft Update Deviceflolo.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update DLLrxxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Emulatorkern-mxe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Emulatorwuaddsff.exe"Added by the RBOT-GX WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Loader[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinerxhost.exe"Added by the RBOT.FC WORM!"
XMicrosoft Update Machineservicz.exe"Added by the RBOT-HU WORM!"
XMicrosoft Update MachineSP2.exe"Added by the SPYBOT.FP WORM!"
XMicrosoft Update Machinewinini.exe"Added by the RBOT-KV WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinememstat.exe"Added by the RBOT-OM WORM!"
XMicrosoft Update Machinentce.exe"Added by the RBOT-FA WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Update Machinewuawx.exe"Added by the RBOT-CE WORM!"
XMicrosoft Update Machinezonealarm.exe"Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
XMicrosoft Update Machinesystemll.exe"Added by the RBOT-JT WORM!"
XMicrosoft Update Machinewinupdt.exe"Added by the RBOT-FP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinewuamgd.exe"Added by the SDBOT.HQ WORM!"
XMicrosoft Update Machinewupdt32x.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Machine[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelinux.exe"Added by the RBOT-IM WORM!"
XMicrosoft Update Machinelmrss.exe"Added by the RBOT-DY WORM!"
XMicrosoft Update Machinewindowsu.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewininigo.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewinmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWinmsixp32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update MachineWinregs32.exe"Added by the RBOT.DN WORM!"
XMicrosoft Update Machinewinxpini.exe"Added by the RBOT-OB WORM!"
XMicrosoft Update Machinewuamgrd.exe"Added by the RBOT-HE WORM!"
XMicrosoft Update Machinewuagrd.exe"Added by the RBOT-GF WORM!"
XMicrosoft Update MachineLANWAKE.EXE"Added by the RBOT-QZ WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machinewinhost.exe"Added by the RBOT-GK WORM!"
XMicrosoft Update Machinewinss.exe"Added by the RBOT.JU WORM!"
XMicrosoft Update MachineWUAMGRDXS.EXE"Added by the RBOT-GL WORM!"
XMicrosoft Update Machinecrss32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinelsasse.exe"Added by the RBOT-DI WORM!"
XMicrosoft Update Machineqwerty.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinerxxhost.exe"Added by the RBOT.EP WORM!"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineSystemnt.exe"Added by the RBOT.DA WORM!"
XMicrosoft Update Machinesystemse.exe"Added by the RBOT-BD WORM!"
XMicrosoft Update Machinetaskmngrs.exe"Added by the RBOT-CR WORM!"
XMicrosoft Update Machinewindowsup.exe"Added by the RBOT-FV WORM!"
XMicrosoft Update Machinewuamgard.exe"Added by the SPYBOT.CS WORM!"
XMicrosoft Update Machinewupdate32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinesystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTMEMSER.EXE"Added by the RBOT-NQ WORM!"
XMicrosoft Update Machinewinnie.exe"Added by the RBOT-ACD WORM!"
XMicrosoft Update Machinewinortho.exe"Added by the RBOT-NW WORM!"
XMicrosoft Update Machinewins32.exe"Added by the RBOT.EZ WORM!"
XMicrosoft Update Machineserviz.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineTASKMAN4.EXE"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machinewftestb.exe"Added by the RBOT-AFZ WORM!"
XMicrosoft Update MachineWin32.exe"Added by the SDBOT.UV WORM!"
XMicrosoft Update Machinewindns.exe"Added by the RBOT.EF WORM!"
XMicrosoft Update MachineMSOICONS.EXE"Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machinentsystem.exe"Added by the RBOT.GF WORM!"
XMicrosoft Update Machinewinupdte.exe"Added by the RBOT-GKL WORM!"
XMicrosoft Update Machinejkfrnz.exe"Added by the RBOT-GOZ WORM!"
XMicrosoft Update Machinewlimyc.exe"Added by the RBOT-GQN WORM!"
XMicrosoft Update Machinexagwxzy.exe"Added by the RBOT.S WORM!"
XMicrosoft Update Machinejkydxg.exe"Added by the RBOT.AEA BACKDOOR!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Machinepaxrxo.exe"Added by the PUSHBOT.A WORM!"
XMicrosoft Update Machinepsmszw.exe"Added by the KOLABC.CC WORM!"
XMicrosoft Update Machinesyadpo.exe"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Update Machinesystemi.exe"Added by the BUZUS.JKU TROJAN!"
XMicrosoft Update Machinethvfyq.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machineubthec.exe"Added by the AGENT.AWZ TROJAN!"
XMicrosoft Update Machinewinmngr.exe"Added by the RBOT.GKQ BACKDOOR!"
XMicrosoft Update Machinegbhglj.exe"Added by the IRCBOT-ZJ TROJAN!"
XMicrosoft Update Machinewuamgdr.exe"Added by the RBOT-IO BACKDOOR!"
XMicrosoft Update ManagerWINRLS.EXE"Added by the RBOT-AF WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Update Managerscvideo.exe"Added by the SDBOT-CVP TROJAN!"
XMicrosoft Update MecheneUpdatez.exe"Added by the RBOT-GI WORM!"
XMicrosoft Update Modulerundll24.exe"Added by the RBOT-PS WORM!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Security Patchmssecurityupdatepatch.exeAdded by the AGENT.EF TROJAN!
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Update Timewuam.exe"Added by the RBOT-M WORM!"
XMicrosoft Update USB2wuammgrd32.exe"Added by the RBOT-ADT WORM!"
XMicrosoft Update v2.6lxxex.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Win32awinupdate32a.exe"Added by the RBOT-LO WORM!"
XMicrosoft Update Win32xwinupdate32x.exe"Added by the RBOT-AJN WORM!"
XMicrosoft Update32wuamgrd32.exe"Added by the RBOT-PU WORM!"
XMicrosoft Updaterwinsys32.exe"Added by the RBOT.RL WORM!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatervbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updaterwuamgrds.exe"Added by the RBOT.A WORM!"
XMicrosoft Updaterwinupdate.exe"Added by the AGENT-KIR TROJAN!"
XMicrosoft Updater ResourcesWinFixd32.exe"Added by the SPYBOT.CA WORM!"
XMicrosoft Updater v2[path to worm]"Added by the AUTORUN-BCI WORM!"
XMicrosoft UPDATER32lsass.exe"Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
XMicrosoft UPDATER32LSASS32.EXE"Added by the RANDEX.AR WORM!"
XMicrosoft Updaterstskmgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Updaters ProsWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
XMicrosoft Updatessystemc32.exe"Added by the RBOT-GR WORM!"
XMicrosoft Updateswkssvr.exe"Added by the RBOT.R WORM!"
XMicrosoft Updateswkssvrs.exe"Added by the RBOT-EB WORM!"
XMicrosoft Updateswuamgrd.exe"Added by the RBOT-CO WORM!"
XMicrosoft Updateswtemp32.exe"Added by the RBOT-AHQ WORM!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updates[worm filename]"Added by the AGOBOT-AIZ WORM!"
XMicrosoft Updateswgcptsud.exe"Added by the RBOT-GTF WORM!"
XMicrosoft Updateswinit.exe"Added by the SDBOT-CSB WORM!"
XMicrosoft Updates 2 USBwgafixer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updates 5 USBsp3fixer.exe"Added by the RBOT-ADS WORM!"
XMicrosoft UpdateS Machinewgrd.exe"Added by the RBOT-FI WORM!"
XMicrosoft Updates ResourcesWinFixIDs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatingnavguard.exe"Added by the RBOT.HW WORM!"
XMicrosoft Updatingsyswr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatingwuamguards.exe"Added by the RBOT-BY WORM!"
XMicrosoft Updating Clientwebsvc.exe"Added by the RBOT.AQ WORM!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicrosoft Updattingmiroupdate.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updote[random filename]"Added by the RBOT-ARC WORM!"
XMicrosoft UpMachinedoezs.exe"Added by the RBOT.BCT WORM!"
XMicrosoft upnp Updatemsie.exe"Added by the RBOT-LQ WORM!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft Urlmonurlmon.exe"Added by the AGENT-GOO TROJAN!"
XMicrosoft USA Plugusaplug.exe"Added by the RBOT-DVC WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
NMicrosoft Utility StartupOSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Valuesigfkishc.exe"Added by the RBOT-GLO WORM!"
XMicrosoft VertupdateMSvert32.exe"Added by the MYTOB-CY WORM!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Video Drivervideodrv.exe"Added by the SDBOT-AGP WORM!"
XMicrosoft Viewer Monitor Managerviewmon.exe"Added by the XPAK.A TROJAN!"
XMicrosoft Virtual Service Managervservice32.exe"Added by the MSNWORM.T WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Vista Upgrade Validation Servicecfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Visual Applicationvpcrtf.exe"Added by the IRCBOT-XJ TROJAN!"
XMicrosoft Visual Debugermdm.exe"Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicroSoft Visual SPigxdfdfds.com"Added by the SDBOT.GAV WORM!"
XMicroSoft Visual SP2igfxsrvc32.exe"Added by the SDBOT.GAV WORM!"
XMicrosoft Visual Studioplscdksxg.exe"Added by the RBOT-AWV WORM!"
XMicrosoft Visual Studio VSAvarpc32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Web CP Managerwebcp32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Web Devicewdevice.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft web updatewebmsn.exe"Added by the RBOT-EMQ WORM!"
UMicrosoft Webserversvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft Win UpdateWinUP.exe"Added by the RBOT-BPR WORM!"
XMicrosoft WIN32 DOSMSdos32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft WIN32 SecurityMSsec32.exe"Added by the RBOT-DOQ TROJAN!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicroSoft Window Updaterwinsupdater.exe"Added by the RBOT-ZZ WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windowsatup"Added by a variant of the RBOT WORM!"
XMicrosoft WindowsMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
XMicrosoft Windowsexplorar.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows[path to file]"Added by the BDOOR-LI BACKDOOR!"
XMicrosoft Windowsbootini.exe"Added by the VANEBOT-K WORM!"
XMicrosoft WindowsKernel.exe"Added by the EDIBARA-A VIRUS!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windowspwjbvphi.exe"Added by the RBOT-GQK WORM!"
XMicrosoft Windowswindets.com"Added by the FLOOD-EQ TROJAN!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows 128bit Subsystemsystem12.exe"Added by the RANCK-CZ TROJAN!"
XMicrosoft Windows 16Bitmswinn16.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows 32 Updatewin32update.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows 32Bitmswinn32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows 64 Bitmswin32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Adapter 5.1.3214[worm filename].exe"Added by the STRAT.GEN-3 WORM!"
XMicrosoft Windows Autowxcknautowxckn.exe"Added by the RBOT.DYZ BACKDOOR!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
XMicrosoft Windows Communicator for NT/XPwincomm.exe"Added by the RBOT.ATH WORM!"
XMicrosoft Windows Config 32win32conf.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Controlmswctl32.exe"Added by the RBOT.JP WORM!"
XMicrosoft Windows CSRSScsrss.exe"Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NMicrosoft Windows Desktop Search System TrayWindowsSearch.exeSystem Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
NMicrosoft Windows Desktop Search Tool Tray AdminWindowsSearch.exe"System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*)
XMicrosoft Windows DHCP___r.exe"Added by the MASLAN.A or MASLAN.C WORMS!"
XMicrosoft Windows DLL 32-BITmsncheck32.exe"Added by the SDBOT-XX WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows DLLHandlerbitpaint.exe"Added by the SDBOT.AHG WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows ExpressMicrosoft Update"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Expresswebsploit.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Expresswindowslogonb.exe"Added by the SDBOT.ABOO WORM!"
XMicrosoft Windows Files Loadercgy32win.exe"Added by the RBOT-AXR WORM!"
XMicrosoft Windows Game Updatermsgame32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows GUIWindowz.exe"Added by the RANDEX.AEV WORM!"
XMicrosoft Windows GUImsmonk32.exe"Added by the SDBOT-PE WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
XMicrosoft Windows Loaderwloader.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Windows Logon Processwinlogon.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Media Playermediaplayer.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Media Playerwimp.exe"Added by the RBOT-FN WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
NMicrosoft Windows Search System TrayWindowsSearch.exe"System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securewindocs.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Secure Updaterpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Windows Securetywurguar.exe"Added by the RBOT-KY WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Session Manager Subsystemsmss.exe"Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UMicrosoft Windows SidebarSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows Systemsrwhost.exe"Added by the RBOT-AWU WORM!"
XMicrosoft Windows Systemsyshost.exe"Added by the RBOT-ASW WORM!"
XMicrosoft Windows SystemSystem.exe"Added by the VB.KV WORM!"
XMicrosoft Windows System Kernelkernel32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Task Managementmstasks.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Task MangerMstosk.exe"Added by the SDBOT-WW WORM!"
XMicrosoft Windows Tasks Managementtaskmng.exe"Added by the RBOT-FXK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatawindows.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updata[5 random letters].exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoft Windows Updatemsoffice2.exe"Added by the RBOT-GB WORM!"
XMicrosoft Windows Updatespools.exe"Added by the SDBOT.TD WORM!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatemsnmessenger.exe"Added by the SDBOT.AJ WORM!"
XMicrosoft Windows Updatemsnwun.exe"Added by the SDBOT-RM WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updateswwhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows UpdateMSNMSGR.EXE"Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Windows Updatemnswinsx.exe"Added by the RBOT-AWH WORM!"
XMICROSOFT Windows updatepdate.exe"Added by the RBOT.BZT WORM!"
XMicrosoft Windows Updatesrshost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Windows Updatewindowsupdate.exe"Added by the AGOBOT.ON WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Updatesyssinfos.exe"Added by the RBOT-FWR WORM!"
XMicrosoft Windows Update Applicationwuap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Clientcsrss.exe"Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Logonwin-logon.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows Update XP64********.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Update XP64updatexp64.exe"Added by the SDBOT-AIM WORM!"
XMicrosoft Windows Update XP64Lcuninst.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Update XP64mzhxlixm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinupdgm.exe"Added by the GAOBOT.BI WORM!"
XMicrosoft Windows UpdaterWINIUPDATES.EXE"Added by the RBOT-KK WORM!"
XMicrosoft Windows UpdaterWINUPDATE.EXE"Added by the RBOT-LI WORM!"
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterwin32upd.exe"Added by the RBOT-EC WORM!"
XMicrosoft Windows Updatermsnupdateit.exe"Added by the AGOBOT-RL WORM!"
XMicrosoft Windows Updaterwindates.exe"Added by the SDBOT.TE WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updaterwinfix.exe"Added by the RBOT-CM WORM!"
XMicrosoft Windows updaterDlog32zx.exe"Added by the MYDOOM.W WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows Updateswsap32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updating Systemmsresource.exe"Added by the RBOT-EAM WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WinSaSS Managementwinsass.exe"Added by the RBOT-APW WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Winedows startupWinKey.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Winedows UpdateingNinKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WINGS32 ProtocolWinSGR32.exe"Added by the RBOT-APU WORM!"
XMicrosoft WinRaRwinrar.exe"Added by the RBOT-AEC WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft Winsock Wrapperws2_32s.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Winsock32 Systemwinsock32.exe"Added by the SPYBOT.AKKC WORM!"
XMicrosoft WinSound[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft winsupdaterWINSUPDATER.EXE"Added by the SPYBOTER.FB BACKDOOR!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft WinUpdatesyslx32.exe"Added by an unidentified VIRUS
XMicrosoft WinUpdatesyswin32.exe"Added by the RBOT-HO WORM!"
XMicrosoft WinUpdatespfix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinamp61.exe"Added by a variant of the RBOT WORM!"
XMicrosoft WinUpdateWinupd32.exe"Added by the RBOT.MQ WORM!"
XMicrosoft WinUpdateWinNTinit32.exe"Added by the RBOT.VS WORM!"
XMicrosoft WinUpdatemsupdte.exe"Added by an unidentified TROJAN! See examples here & here"
XMicrosoft WinUpdatesserm32.exe"Added by the RBOT.GE WORM!"
XMicrosoft WMmswm32.exe"Added by the BCKDR-AM BACKDOOR!"
XMicrosoft WordBootSector.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
XMicrosoft Word ProfissionalJava Plug In close.exe"Added by the BANKER-EL TROJAN!"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
XMicrosoft Word Profissionalcsrss.exe"Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
NMicrosoft Works Calendar Reminderswkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
NMicrosoft Works PortfolioWksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file. Can be prevented from starting from a setting within Portfolio
NMicrosoft Works Update Detectionwkdetect.exeChecks for updates to MS Works
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft WPCEmail[path to trojan]"Added by the SNIFFER-N TROJAN!"
XMicrosoft WWW[path to trojan]"Added by the AGENT-DRI TROJAN!"
XMicrosoft WxdateSyswu32.exe"Added by the SPYBOT.HZ WORM!"
XMicrosoft X Updatewuamkoppnp.exe"Added by the RBOT-ANI WORM!"
Xmicrosoft xdaemon 2.0xdaemon.exe"Added by the DELF.D TROJAN!"
XMicrosoft XML Servicemsxmlx.exe"Added by the RBOT.KS WORM!"
XMicrosoft Xp Systems loaderwinsystem32xp.exe"Added by the KELVIR.W WORM!"
XMicrosoft Xp Systems loaderswin32xpsys.exe"Added by the SPYBOT.NYT WORM!"
XMicrosoft XPSP Protocolxp386.exe"Added by a variant of the RBOT WORM!"
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft xpsp2xpsp2.exe"Added by the SDBOT-YQ WORM!"
XMicrosoft's System ModuleSysmodule.exe"Added by the BDOOR-FJ BACKDOOR!"
XMicrosoft(R) System Managersysmgr.exe"Added by the AGENT.QTR TROJAN!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-software****.exe [* = random char]"Added by a variant of the RBOT WORM!"
XMicrosoft-Updatewngard.exe"Added by the RBOT-JV WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
XMicrosoft.exe[random].exe"Added by a variant of the IRCBOT TROJAN!"
Xmicrosoft.exemicrosoft.exe"Added by the GOLDUN-GB TROJAN!"
XMicrosoft32win32sys.exeAdded by an unidentified WORM or TROJAN!
Xmicrosoft420microsoft420.exe"Added by the MENACE.B WORM!"
XMicrosoft64antiv.exe"Added by the SOBER WORM!"
YMicrosoftAntiSpywareCleanergcASCleaner.exe"Microsoft Antipsyware - now superseded by Microsoft's Windows Defender"
XMicrosoftCorpflashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftCorpjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftCorpmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftCorpregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrosoftCorpsecurebind.exe"Added by the INJECT TROJAN!"
XMicrosoftCorpsysdiag64.exe"Added by a the AUTOINF-AB WORM!"
XMicrosoftCorptraymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftCorpupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftCorpwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftf DDEs ContDLLrune.pif"Added by the RBOT-AGF WORM!"
XMicrosoftf DDEs ContrDLrunm.pif"Added by the RBOT-AFQ WORM!"
XMicrosoftf DDEs Controllxes.exe"Added by the RBOT.BOF WORM!"
XMicrosoftf DDEs Controlwees.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlsoff.pif"Added by the RBOT-AKH WORM!"
XMicrosoftf DDEs Controlwhy-.exe"Added by the RBOT-AMV WORM!"
XMicrosoftf DDEs Controlmsnn.exe"Added by the RBOT-AXT WORM!"
XMicrosoftf DDEs ControlFEnR.exe"Added by the RBOT-AIM WORM!"
XMicrosoftf DDEs Controlw33s.exe"Added by a variant of the RBOT WORM!"
XMicrosoftf DDEs Controlwaes.exe"Added by a variant of the RBOT WORM!"
XMicrosoftkeysdsystemproc.exe"Added by the FORBOT-BI WORM!"
XMicrosoftkeysdsystemwin32s.exe"Added by the WOOTBOT.CO WORM!"
XMicrosoftkeysdslass32.exe"Added by a variant of the RBOT WORM!"
XMicrosoftKsDrivers.bat"Added by the SHUTDOWN-F TROJAN!"
Xmicrosoftm eegs cuntrolloor.pif"Added by a variant of the RBOT WORM!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
XMicrosoftmsn32.exemicrosoftmsn32.exe"Added by the CERTIF-C TROJAN!"
XMicrosoftMultimediaTaskMmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
XMicrosoftNAPCflashsplayer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftNAPCjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftNAPCmsnrmgs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftNAPCregtray.exe"Added by the POISON.AHNW BACKDOOR!"
XMicrosoftNAPCsecurebind.exe"Added by the INJECT TROJAN!"
XMicrosoftNAPCsysdiag64.exe"Added by a the AUTOINF-AB WORM!"
XMicrosoftNAPCtraymgr.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoftNAPCupdate.exe"Added by the AUTORUN-ASG WORM!"
XMicrosoftNAPCwupdate.exe"Added by the AGENT-LAY TROJAN!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMicrosoftOEMsmvss.exe"Added by the DEDLER-G TROJAN!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts mediawinmplayd.exeAdded by an undidentified WORM or TROJAN!
XMicrosofts mediawingtp.exe"Added by the RBOT-VO WORM!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Security Manager****.exe [**** = random char]"Added by the RBOT-WH TROJAN!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosofts Updateslsasss.exe"Added by the RBOT-AEX WORM!"
XMicrosofts Updatezcmsssr.exe"Added by an unidentified VIRUS
XMicrosofts Updatezexploirez.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrosoftShellShellcomm.exe"Added by the BANCBAN-QG TROJAN!"
XMicrosoftSourceSafecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSourceSafelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoftSysSPOOLSYS.exe"Added by the TARNO.N TROJAN!"
XMicrosoftUpdatesyshelper.exe"Added by the WOOTBOT.AC WORM!"
XMicrosoftUpdateWinUp32.exe"Added by an unidentified VIRUS
XMicrosoftUpdateMicrosoftUpdate.exe"Added by the BANKER-EHC TROJAN!"
XMicrosoftUpdatewindll.exe"Added by the RBOT-IH WORM!"
XMicrosoftUpdateRBuilder.exe"Added by the DLOADR-BMV TROJAN!"
XMicrosoftUpdatesvhest.exe"Added by the RBOT-ES WORM!"
XMicrosoftUpdatedownnew.exe"Added by the TANTO-D TROJAN!"
XMicrosoftUpdates[path to trojan]"Added by the DELF-LO TROJAN!"
XMicrosoftUpdatessyshelped.exe"Added by the FORBOT-AZ WORM!"
XMicrosoftValuesyscnfg.exe"Added by an unidentified VIRUS
XMicrosoftvirussysoverload.exe"Added by the FORBOT-AL WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosoftWindowsa@26m.exe"Added by the KILLPAR-B TROJAN!"
XMicrosoftXP Service Pack 2servicepack2.exe"Added by the RBOT.EMC WORM!"
XMicrosoftz turn Controlaexl.exe"Added by the SDBOT.BCO WORM!"
XMicrosoftz turn Controlread.pif"Added by the RBOT-AFS WORM!"
XMicrosoft©iexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrosoft© PID LexPIDLex.exe"Added by the NIOVADOOR TROJAN!"
XMicrosoft© System MapperSysMap.exe"Added by the MAPSY TROJAN!"
XMicrosoft« ActiveX Debugger NTsetdebugnt.exe"Added by the BANCOS-CZ TROJAN!"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
UMicrosoft® Windows® Operating SystemSidebar.exe"Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
NMicrosoft® Windows® Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft® Windows® Operating Systemp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
UMicrosoft® Windows® Operating SystemehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
NMicrosoft® Windows® Operating Systemstikynot.exe"Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
NMicrosoft® Works 7.0wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
NMicrosoft® Works 8wkcalrem.exeIf you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
XMicrosot NT Support[random filename].exe"Added by the RBOT-CTI WORM!"
XMicrosotufed Update 32windinit.exe"Added by the RBOT-CTJ WORM!"
XMicroszoft Update Mach1nezssvchst.exe"Added by the RBOT-ED WORM!"
UMicrotek Scanner FinderScannerFinder.exeMonitors whether a scanner is present. Provided with Microtek scanners
XMicrozoft_OfizKdzEregli.exe"Added by the AMUS.A WORM!"
XMicrsft Updesexagwxz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrsoft CFG 32lrbzus32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrsoft DerSystemuqieelpb.exe"Added by the RBOT-GRI WORM!"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Drivermsdriver.exe"Added by the SDBOT-XD WORM!"
XMicrsoft Driverwindrive32.exe"Added by the SLINBOT.TT BACKDOOR!"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
XMicsoft-Published-Softwareexplrer.exe"Added by the RBOT-GFL WORM!"
XMicsorosft Security Centerwcnsfty.exe"Added by the RBOT-AHU WORM!"
NMightyFAX ControllerMFNTCTL.EXE"Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software""
UMindfulMindful.exe"Mindful from Felitec inc. ""Event reminder software with date and time tools in a simple to use system tray application"""
NMINIFERT.EXEMINIFERT.EXEPart of Backweb
Xminimo[path to file]"Added by the MOSUCK-X TROJAN!"
XMioft Wiws Seice ent[worm filename].exe"Added by the RBOT-GIJ WORM!"
XMiosf Updatewimsqaad.exe"Added by the SDBOT.AG TROJAN!"
XMirate Sp 2 Informationmiratesp2.exe"Added by the RBOT.QH WORM!"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMircosoft Sockets SP2mssck.exe"Added by the MYTOB.ET WORM!"
XMircosoft Updatewuampkd.exe"Added by a variant of the SDBOT WORM!"
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMircrosoft Svchost32svchost32.exe"Added by the RBOT-AZW WORM!"
XMircrosoft Technic HelpEditKey.exe"Added by the KOLABC.AS WORM!"
XMircrosoft Technic HelpRegKey.exe"Added by a variant of the SPYBOT WORM! See here"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
UMirrorFolderShellmrfshl.exe"MirrorFolder backup software"
XMirsoft sdcEtaskmegr.exe"Added by the RBOT-AWY WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMlcr0s0ftf DDEs C0ntr0iWAed.pif"Added by the RBOT-BJW WORM!"
XMlCROSOFT FEnRMlCROSOFT.EXE"Added by the GAOBOT.CII WORM! Note that both the name and command have a lower case ""L"""
UMMERefreshMMERefresh.exe"Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R"
XMMicrosoft Security Managementinetforn.exe"Added by the RBOT.AFZ WORM!"
Xmmsddlx[random filename]"Added by a variant of the SLAPER TROJAN!"
UMobipocket Reader Notificationsreadernotify.exe"Part of Mobipocket Reader - ""Store all your eBooks
XModeminfModeminf.exe"Added by a variant of the CRYPTER.C TROJAN!"
XModifiet Amateur HTPBwuaclt.exe"Added by the IRCBOT.AYS WORM!"
XModularConfigsyscnfg.exe"Added by an unidentified VIRUS
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
XMonAppli[random filename]"Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
XMonitor Test[random filename]"Added by the SDBOT-NC WORM!"
NMonstersoundtrayFreectrl.exeDiamond Multimedia sound card control panel
XMotherboard ConfigAti2xxx.exe"Added by the RBOT-AIK WORM!"
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
UMotorola Desktop Suite mRouter ConfigmRouterConfig.exe"Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
UMount Safe & SoundFbmount.exeFrom McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
UmouseElfMC.exe"Genius NetScroll mouse driver - required if you use non-standard Windows driver features"
UmouseElfmouseElf.exeSystem Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
UMousinfomousinfo.exeMS mouse information tool - for troubleshooting mouse problems
XMoussaEvil[path to file]"Added by the MUSANUB-A WORM!"
XMozila Firefoxfirebox.exe"Added by the RBOT-AIP WORM!"
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
XMozilla FirefoxF1REF0X.EXE"Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers ""1"" and ""0"" in place of upper case ""i"" and ""o"" respectively"
XMozilla Firefoxfirefox.exe"Added by the AUTOTUN.POM WORM! Note - this is not the popular FireFox web browser and is located in %System%"
XMP3files"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
YMPFExempf.exeMcAfee Personal Firewall
YMPFExeMpfTray.exeMcAfee Personal Firewall
YMPFTrayMpfTray.exeMcAfee Personal Firewall
UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
UmRouterConfigmRouterConfig.exe"Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth
XMr_CoolFace_GameEmma.exe"Added by the ROMARIO-A WORM!"
XMS Configmsdconfig.exe"Added by the RBOT-CZH WORM!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config LoaderMSWin32bck.exe"Added by the GAOBOT.AA WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Config Streammsasm.exe"Added by the AGOBOT-BA WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS ConfigurationMSFramer.exe"Added by the RANDEX.OL WORM!"
XMs Configurationmicrosoftsa32.exe"Added by the KELVIR.X WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMS Decryption Softwareactive.exe"MediaTickets adware variant"
XMS FIREWALLmsfrewall.exe"Added by the SDBOT-PU WORM!"
XMS FIREWALLmsfirewall.exe"Added by the SDBOT-QH WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Microsoft Socket DeamonMSSCKD32.exe"Added by a variant of the RBOT WORM!"
XMS OfficeOffice10.exe"Added by the VB.DT TROJAN!"
XMS Securitysystm.pif"Added by the RBOT-AQN WORM!"
XMS Security Hotfixservice5.exe"Added by the GAOBOT.AG WORM!"
XMs sock for Windows NTwinser.exe"Added by a variant of the SDBOT WORM!"
XMS Sound Config 16bitsndcfg16.exe"Added by the SDBOT.MB TROJAN!"
XMS Sys Securitymswin.pif"Added by the RBOT-APJ WORM!"
XMS System Call Functionmsscf32.exe"Added by the RBOT-GBZ WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMs System Configpcedit.exe"Added by a variant of the SDBOT WORM!"
XMS System Securitymswin32.pif"Added by the RBOT-AOX WORM!"
XMS Task Manager 32[trojan filename] .exe"Added by the RANKY.NF TROJAN!"
XMS Windows Security Updaterupdater.pif"Added by the RBOT-AKY WORM!"
XMS WINS Binaryign32.pif"Added by the RBOT-ASB WORM!"
XMS-DOS Boot ServiceBoot32.pif"Added by the RBOT-AMF WORM!"
XMS-DOS Security Servicems-dos.pif"Added by the RBOT-AMR WORM!"
XMS-DOS ServiceMS-DOS.pif"Added by the RBOT-AII WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
XMS-HTML[random filename]"Added by the LATINUS.15 TROJAN!"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
XMS32DLLffqca.exe"Added by the SDBOT-YD WORM!"
XMsAudio"MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
Xmschkdf.exemschkdf.exe"Added by a variant of the SDBOT WORM!"
?mscimcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
XMsconf32Msconf32.exe"Added by the AGOBOT-NR WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
XMSCOREsyscnfg.exe"Added by an unidentified VIRUS
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
Xmsctfg32msctfg32.exe"Added by the RBOT-TJ WORM!"
Xmsdefendermsdefender.exe"Identified as a variant of the PAKES.CMD TROJAN! See here for an example"
Xmsdefender.exemsdefender.exe"Added by the PAKES.ZL TROJAN!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMSDLLsyscnfg.exe"Added by an unidentified VIRUS
XMSDN for Windows NTmsdn.exe"Added by a variant of the RBOT WORM!"
XMSDN for Windows NT & WinXPmsdnxp.exe"Added by the IRCBOT-PE WORM!"
XMSDN for Windows with NT'smsdn-nt.exe"Added by the RBOT-EWD WORM!"
XMSDOS Security Servicemsdos.pif"Added by the RBOT-AMP WORM!"
XMSDOS ServiceMSDOS.PIF"Added by the RBOT-AIY WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMsdos32Msdos32.pif"Added by the RECORY WORM!"
XMSDRVNetFilter.exe"Added by the INTERRUPDATE TROJAN!"
XMsfindMsfind.exe"CoolWebSearch parasite variant"
XMSFind32msfind32.exe"Added by the CAYAM WORM!"
Xmsfindosa.exemsfindosa.exe"Added by the DOWNLOADER-BS TROJAN!"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
Xmsfw.exemsfw.exe"Microsoft Security Adviser rogue security software - not recommended"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
XMsg Fixagemsgfixed.exe"Added by the SDBOT.ZD WORM!"
XMsgApi[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMSI Configurationmsiconf.exe"Added by the AGENT.AKSZ TROJAN!"
Xmsiconf.exemsiconf.exeAdded by a variant of the FAKEALERT TROJAN!
XMSInfomsinfo.exe"Added by the ALADINZ.M TROJAN!"
XMSInfoAVBgle.exe"Added by the NETSKY.O WORM!"
Xmsjdqsfddwqt.exe"Added by the SDBOT-PO WORM!"
XMSKCES32[random filename]"Added by the CLONER TROJAN!"
XMSLARISSAMSLARISSA.pif"Added by the ASSIRAL.B WORM!"
XMSLogMicrosoftLog.exe"Added by a variant of the SDBOT WORM!"
Xmsmcmsgdmf.exe"ClientMan parasite variant"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMcAfeehAvsynmgr32h.exe"Added by the FRANGO TROJAN!"
XMSMcAfeeSAvsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
XMSMSGNERzzgf.exe"Added by the PWS-CCB TROJAN!"
XMSMSGNERfgozmox.exe"Added by the AGENT-EBJ BACKDOOR!"
XMSNctfmoons.exe"Added by the SPYBOT.HI WORM!"
XMSNFixdriver.exe"Added by the SILLYFDC.BBY WORM!"
XMSN Administration For Windowsmsnadp32.exe"Added by the BROPIA.W WORM!"
XMsn Bootmsnbootcfg.exe"Added by the IRCBOT.BFU BACKDOOR!"
XMSN CNF Managermsncnfmgr.exe"Added by the VUNDO TROJAN!"
XMsn Configmsngf.exe"Added by the RBOT-QG WORM!"
XMSN Configurationmsnconfig.exe"Added by a variant of the IRCBOT TROJAN!"
XMsn Configuration Loadermsngms.exe"Added by the KELVIR.T WORM!"
XMSN Configuration Loadermsmsncfg.exe"Added by the AGOBOT-KX BACKDOOR!"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN File Configurationmsnfilecfg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharingmsnusr.exe"Added by the SLENFBOT.AM WORM!"
XMSN File Sharing Wizardmsnsharewiz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN File Sharing!msnuser.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Funny Imagesimsngsr.exe"Added by the AGOBOT-TT WORM!"
XMsn Messengernkbf.exe"Added by the RBOT-GMQ WORM!"
XMSN Messenger BETA 7bbsdf.exe"Added by the RANKY.AA TROJAN! Note - this is not a valid MSN Messenger variant"
XMSN Softwaremsnsoftware.exe"Added by the IRCBOT.AWD BACKDOOR!"
XMSN Update Cfgmsnupdbt.exe"Added by an unidentified WORM or TROJAN! See here"
XMsn Update SUPPORT[random filename]"Added by the RBOT-BPS WORM!"
?MsnFixermsnfixjs.js"Located in the HPbinmsnfix directory of a HP PC"
XMSNMSGREswef.batIRC backdoor TROJAN or WORM!
Xmsnmsgy[path to file]"Added by the BANKER-EQ TROJAN!"
Xmsnntwinampf.exeAdded by the SMALL.DTS TROJAN!
XMsofficemsoffice.htaHijacker - redirecting to Searchdot.net
XMSOfficeservices.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
Xmsofficemsoffice.exe"Added by the LIKASIMAL WORM!"
XMSOffice32msjcf.exe"Added by the RAKER-A TROJAN!"
XMSOfficeCfgmsocfg.exePremium rate adult content dialer
XMSOfficeCfgnavchk.exePremium rate adult content dialer
XMSOfficeCfgqservice.exePremium rate adult content dialer
XMSOfficeCfgshman.exePremium rate adult content dialer
XMSOfficeCfgssvr.exePremium rate adult content dialer
Xmsoffwzmsoffwz.EXE"Added by the BANCBAN-HQ TROJAN!"
Xmsoft-updater23mssysstems.exe"Added by the RBOT-ATU WORM!"
Xmsoft-updater23slssystem.exe"Added by the RBOT-ASR WORM!"
XMSPQFileMSA****.TMP [* = random char]Homepage hijacker
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMsServermsfir80.exe"Added by the VB-CYJ TROJAN!"
XMSService_v1.0vfp02.exe"NewWeb adware"
Xmssfossfool.exe"Added by the RANDEX.EUS WORM!"
XMSSGisg[path to file]"Added by the RANKY.N TROJAN!"
Xmssonfigwinupdate.exe"Added by a variant of the SDBOT WORM!"
XMSSQL for Windows NT & XPmssqlsnt.exe"Added by a variant of the SDBOT WORM!"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMSUpdateDevKitaxfd.exe"Added by the SDBOT-ZD WORM!"
XMsVBdllMsVBdll.pif"Added by the AIMDES.A WORM!"
XMSVBVM60MSVBVBM60.pif"Added by the SCOLD-B WORM!"
XMSVersionINTERNETFEATURES.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMswincfgMswincfg32.exe"Added by the CYBRSPY.D TROJAN!"
Xmswspl[random filename]"Added by the SMALL.IQ TROJAN!"
XMsys32morfitwebentrance.exe"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage"
Xms_anti_spywaremwfirewall.exe"Added by the GAMQOWI TROJAN!"
Xms_anti_spywarebxpmwfirebpx.exe"Added by the SURILA-D TROJAN!"
Xms_anti_spywarebxpmwfibpx.exe"Added by the SURILA-J TROJAN!"
XMS_Update Checkwdfmgr.exe"Added by the AGOBOT-TB WORM!"
?Mufixmufix.exe"Part of INFOConnect
Xmule_st_keyflec006.exe"Added by the BAGLE.AV TROJAN!"
UMulti-function keyboardGWHotkey.exe"Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail
XMustafxmustafx.exeAdded by a variant of the VIRANTIX.B TROJAN!
XMy SupervisorMSup1bf7.exe"My Supervisor rogue system suite - not recommended
XMyapp[filename]"Added by the FATEE.B WORM!"
XMyFastAccessmyfastupdate.exeMy-Fast-Access toolbar updater
XMyLifeCmdServ.exe"Added by the HOLAR.A WORM!"
Xmysoftwinexplor.exe"Browser hijacker
NMySoftware NewsFlashNewsflsh.exe"Runs in your task bar and receives alerts and release information on MySoftware products from Avenquest"
UN2PTrayNet2fone.exe"An Internet telephony application. Needed only if you have an account at Net2Phone
XNAV Auto Protectmsfwe1.exe"Added by a variant of the RBOT WORM!"
XNAV Auto Protectmcafee32.exe"Added by a variant of the SPYBOT WORM!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
NNAV CfgWizcfgwiz.exe"Introduced with Norton Anti-Virus 2002
NNAV Configuration Wizardcfgwiz.exe"Introduced with Norton Anti-Virus 2002
UNAV DefAlertDefAlert.exeNorton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
XNavScan[filename]"Added by the OBSORB TROJAN!"
YNECMFKnecmfk.exeNEC wireless keyboard driver
?neqprvfy.exeneqprvfy.exe"Appears to be related to the downloading of some application - possibly verifying updates?"
XNeroFilNeroFil.EXE"Added by the RBOT.EAM TROJAN!"
XNeroFileCheckmsjavam32.exe"Added by the AGOBOT.AKM WORM!"
UNeroFilterCheckNeroCheck.exeAssociated with "Nero Burning Rom" CD writing software. Checks for driver issues
UNeroHomeFirstStartNMFirstStart.exe"Associated with Nero Scout
Xnetconfignetconfig.exe"Added by the NETWARE TROJAN!"
XNETFP32.EXENETFP32.EXEAdded by the AGENT.CD TROJAN!
?netfxupdatenetfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
Xnethost.exe[path to file]"Added by the PERDA-J TROJAN!"
UNetOnHoldFTNOHMgr.EXE"""FaxTalk NetOnHold 1.5 works with the Modem-On-Hold capabilities found in V.92 modems to provide the ability to place an Internet connection ""on hold"" and receive incoming calls or place outgoing calls"""
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNetSurfageAssureGDC.exe"NetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
YNettGain2000 VerifierNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speed
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
XNetworks ConfiguratorNetConfs.exe"Added by the RBOT-OX WORM!"
NNetZIPFoldersnzfprop.exe"
UNFM ServiceNPDOR9x.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
XNfonfomon.exe"Delfin Media Viewer adware related"
NnForce Tray Optionssstray.exenVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.GA6PU_0001_N108E1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6PU_0001_N120C2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GA6P_0001_N105E2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GA6P_0001_N111C1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115C0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N115E0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122C2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_0001_N122E0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.GA6P_2001_N108E1606[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.GDCDE_0001_N122C1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.GDC_0001_N111C1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GDC_0001_N122C1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GES_0001_N122C2610[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UAVIFR_0001_N105M2404[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UERSM_0001_N68M1602[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.UGA6P[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6PH_0001_N122M2910[path to file]"Installer for the AntiVirusAskeladd rogue security software - see here"
XNI.UGA6PK_0001_N122M1302[path to file]"Installer for the VirusForsvar Danish rogue security software - see here"
XNI.UGA6PL_0001_N108M2808[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PL_0001_N120M1302[path to file]"Installer for the VirusSchlacht Swedish rogue security software - see here"
XNI.UGA6PM_0001_N108M2108[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M1202[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PM_0001_N122M3010[path to file]"Installer for the AntivirusScherm Dutch rogue security software - see here"
XNI.UGA6PT_0001_N108M2208[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M1202[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PT_0001_N122M2910[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PU_0001_N108M1308[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M1202[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PU_0001_N120M2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PV_0001_N108M0207[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M1202[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6P_0001_N105M2704[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N111M1707[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N115M0110[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N119M1510[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N120M1710[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M0611[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2210[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0001_N122M2802[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_0007_N125M2002[path to file]"Installer for the BestsellerAntivirus rogue security software - see here"
XNI.UGA6P_1001_N122M0402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_1002_N122M1402[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4001_N122M2111[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_4444_N122M2811[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5001_N122M1902[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5555_N122M0312[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGDC1_0001_N119M0911[path to file]"Installer for the FilterProgram rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0307[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M0511[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCCZ_0001_N122M1712[path to file]"Installer for the SuspenzorPC Czech rogue privacy tool - see here"
XNI.UGDCDE_0001_N111M3007[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCDE_0001_N122M1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M0307[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCGR_0001_N122M1812[path to file]"Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
XNI.UGDCNL_0001_N111M3007[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M1912[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M3011[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDCPL_0001_N108M0207[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCPL_0001_N122M2012[path to file]"Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
XNI.UGDCRU_0001_N111M0208[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCRU_0001_N122M2012[path to file]"Installer for the SanitarDiska Romanian rogue privacy tool - see here"
XNI.UGDCTH_0001_N122M1712[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDCTR_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N108M0407[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0001_N111M1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M0502[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2603[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2610[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2802[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M2811[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0002_N108M1007[path to file]"Installer for the PC Drive Tool rogue privacy tool - see here"
XNI.UGDC_0003_N108M2407[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGESF_0001_N122M0201[path to file]"Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N105M0405[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M0303[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESL_0001_N122M2911[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UGESM_0001_N122M0303[path to file]"Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N108M2006[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M0303[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M2811[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M3010[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M0502[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"
XNI.UGES_0001_N122M2111[path to file]"Installer for the ErrClean rogue system error and cleaning utility - see here"