| N | Pagoo | PAGOO.EXE | "Pagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem"
|
| X | PaRaY_VM | winlogon.exe | "Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
|
| U | Power2GoExpress | Power2GoExpress.exe | "Power2GoExpress - all media disc burning software"
|
| U | ProcessGovernor | processgovernor.exe | "Core engine for Process Lasso from Bitsum Technologies - ""a state-of-the-art |
| X | RealTimeProtector | winlogon.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
| X | Reg Service | winslogon.exe | "Added by the AGOBOT-SC WORM!"
|
| X | RegDone | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| U | RepliGo Assistant | RepliGoMon.exe | "Cerience RepliGo software - ""any document you have on your PC can be transferred to your mobile device"""
|
| X | ROOT_Machine | winlogon.exe | "Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inf"
|
| X | RPCserr32g | winlogon.exe | "Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | RPCserv32g | WINLOGON.EXE | "Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| U | Run Google Web Accelerator | GoogleWebAccWarden.exe | "Google Web Accelerator"
|
| X | RUNGogoTools | LaunchAdware.exe | "GoGoTools adware"
|
| X | RUNGogoTools | GoGoLaunch.exe | "GoGoTools adware"
|
| X | runwinlogon | winlogon.exe | "Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process |
| X | Services Logon | services.exe | "Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
|
| X | SkynetRevenge | winlogon.scr | "Added by the NETSKY.AA WORM!"
|
| X | SmansaApp | winlogon.exe | "Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | SonudMan | WNILOGON.exe | "Added by the QQROB-DC TROJAN! Note - this is not the legitimate winlogon.exe process |
| X | SpyEx | Winllogo.exe | "Added by the PRSKEY-A WORM!"
|
| U | Spyware Begone | SpywareBeGone.exe | "Spyware BeGone - spyware remover. Previously not recommended |
| U | Spyware Begone | freescan.exe | "Spyware BeGone - spyware remover. Previously not recommended |
| Y | Sr Agent | SrLogon.exe | "Related to Secure Resolutions - desktop virus protection"
|
| X | srv | winlogon.exe | "Added by the SILLYFDC.BCA WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%\Local Settings\Application Data"
|
| X | Startup | WinlogonStartup | Unidentified malware
|
| X | svchost | logon.exe | "Added by the SLEGON WORM!"
|
| U | swg | GoogleToolbarNotifier.exe | "Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
|
| X | SymantecFilterCheck | gmilogof.exe | "Added by the BANKER-EKC TROJAN!"
|
| X | syslogon | syslogon.exe | "Added by the SPYBOT-EP WORM!"
|
| X | SYSTEM | wiinlogon.exe | "Added by the RBOT-AVG WORM!"
|
| X | System Update2 | winlogon.exe | "Added by the AUTOTROJ-C TROJAN! Note - this is not the legitimate winlogon.exe process |
| ? | Tango | Setup.exe | "Tango Broadband access software. Is it required?"
|
| ? | TangoManager | TangoManager.exe | "Tango Broadband access software. Is it required?"
|
| X | Taskmgo | [path to file] | "Added by the BANCBAN-T TROJAN!"
|
| X | TEXTCONV | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| N | Tiny Watcher Logon Time | Watcher.exe | "Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items"
|
| U | TLogonPath | tb2logon.exe | "Timbuktu Pro - remote desktop access software"
|
| U | TMExLogon | TMESRV.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
|
| X | Torjan Program | WINLOGON.EXE | "Added by the WOWCRAFT.D TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Trojan Guarder Gold Version | Trojan Guarder.exe | "TrojanGuarder rogue security software - not recommended"
|
| ? | TSBxLogon | TMESBS2.EXE | "Found on a Toshiba laptop. May be related to TMESBS?"
|
| ? | ugon | aockstrs.exe | "??"
|
| X | Updade Windows | winlogom.exe | "Added by the TONAX-A TROJAN!"
|
| X | update run dos | logon.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Update Run MSword | LOGON.EXE | "Added by the RBOT.TY WORM!"
|
| X | urudjeffni | winlogon.exe | "Added by the ROMARIO-A WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | user logon | [path to worm] | "Added by the PAHATIA-A WORM!"
|
| X | user logon | user logon.exe | "Added by the PAHATIA.A WORM!"
|
| X | userinit | winlogon.exe | "Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| U | VERBATIM STORE 'N' G | verbatim store 'n' go.exe | "Loads the driver for the Verbatim Store'n'Go PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium"
|
| N | Vongo Tray | Tray.exe | "System Tray access the now discontinued Vongo video-on-demand service"
|
| X | W1N32.DLL | WINLOGON .exe | "Added by the DROPPERFL.A TROJAN!"
|
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | "WashAndGo - temp file cleaner"
|
| X | wblogon | ubpr01.exe | "Added by the AGENT-HFI TROJAN!"
|
| X | wblogon | algg.exe | "Added by the AGENT.AGGI TROJAN!"
|
| ? | Webcam Go Sti Service Application | wbcgosvc.exe | "Control software for the portable Creative Webcam Go digital camera/PC web cam. What does it do and is it required?"
|
| N | Webposition Gold 2 | wpsche~1.exe | "Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
|
| X | Win32 Drivers | winlogons.exe | "Added by the FORBOT-FG WORM!"
|
| U | Winamp to Google Talk | winamptogoogletalk.exe | "Winamp to Google Talk |
| X | WinAuth | winlogon.exe | "Added by the STRTPAGE.BE TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Window UDP Control Servic | winlogon.exe | "Added by the RBOT-GXN WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows ARP Detectionc | winlogon.exe | "Added by the RBOT.EAB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Windows ARP Detectioncx | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Windows Log Agent | winlogon.exe | "Added by the KEYLOGGER.AVK TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
|
| X | Windows Logon | winlogin.exe | "Added by the SPYBOT-C TROJAN!"
|
| X | Windows Logon | winlogon.exe | "Added by the VB.HE VIRUS! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\system"
|
| X | Windows Logon Application | WinIogon.exe | "Added by the LINKBOT.M WORM!"
|
| X | Windows Logon Application | logon.exe | "Added by the POEBOT-J WORM!"
|
| X | Windows Logon Application | services.exe | "Added by the CIADOOR-L TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows Logon Application | win32help.exe | "Added by the DELBOT-X WORM!"
|
| X | Windows Logon Application | winlogon.exe | "Added by the POEBOT-KW WORM! Note - this is not the legitimate winlogon.exe process |
| X | Windows Logon Application | winamp.exe | "Added by the POEBOT-LR WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Windows Logon Applicationedc | winlogon.exe | "Added by the DWNLDR-HGR TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
|
| X | Windows Logon Applicatonedc | winlogon.exe | "Added by the VB-EBV TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
|
| X | Windows Logon Manager | logon.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Logon Procedure | Svchoste.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Logon Procedure | Svchosta.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | windows logon procedure | winlogonpc.exe | "Added by the WINLOGON TROJAN!"
|
| X | Windows Logon Service | winlogon.pif | "Added by the RBOT-AOU WORM!"
|
| X | Windows Logon Service | napi32.exe | "Added by the SPYBOT.ANDM WORM!"
|
| X | Windows Logon Service | winlogoservice.exe | "Added by the SPYBOT.ANOO WORM!"
|
| X | Windows mangement | winlogonn.exe | "Added by the RANDEX.FC WORM!"
|
| X | Windows Messanger Control Center | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows modez Verifier | WindowsLogon.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows modez Verifier | winlogom.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Network Logon | npesvc.exe | "Added by the AGENT.ERZ TROJAN!"
|
| X | Windows NT Logon Application | winlogon.scr | "Added by the RBOT-ALP WORM!"
|
| X | Windows Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | WINDOWS SYSTEM | winligon.exe | "Added by the MYTOB.EP WORM!"
|
| X | WINDOWS SYSTEM | gothica.exe | "Added by the MYTOB.HU WORM!"
|
| X | windows update | logonuit.exe | "Added by the LEGMIR-AO TROJAN!"
|
| X | Windows Update | winlogonEvt.exe | "Added by the VB-DXM TROJAN!"
|
| X | Windows Update 32 | winlogons.exe | "Added by the FORBOT-FI WORM!"
|
| X | Windows Updater | svigost.exe | "Added by the RBOT-VS WORM!"
|
| X | Windows USB Printer | unqgod.exe | "Added by the RBOT.BKC BACKDOOR!"
|
| X | wingo | wingo.exe | "Added by the BEAGLE.AW or BEAGLE.AV WORMS!"
|
| X | wingo | [various filenames] | "Added by the BAGLE-AU WORM!"
|
| X | winIogom | winIogom.exe | "Added by the BANCBAN-ML TROJAN!"
|
| X | winlogoff | winlogoff.exe | "Added by the AGOBOT-TR WORM!"
|
| X | winlogon | winlogin.exe | "Added by the RANDEX.E WORM!"
|
| X | winlogon | winlogon.exe | "Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | winlogon | msreg32.exe | "Added by the SDBOT.EO WORM!"
|
| X | winlogon | winlogon32.exe | "Added by the MASLAN.C WORM!"
|
| X | winlogon | wpwlogon.exe | Added by an unidentified WORM or TROJAN!
|
| X | WINLOGON | wscript.exe WINLOGON.vbs | "Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
|
| X | Winlogon | Lsass.exe | "Added by the ALCOP-B WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | winlogon | nvchost.exe | Added by an unidentified WORM or TROJAN!
|
| X | Winlogon | WINLOGON.EXE | "Added by the PUNYA-B WORM! Note - this is not the legitimate winlogon.exe process |
| X | winlogon | system.exe | Added by a variant of the DELF.CNS TROJAN!
|
| X | winlogon | cleanmg.exe | "Added by the AGENT-ICR TROJAN!"
|
| X | Winlogon | scssrr.exe | "Added by the AGENT-LXB TROJAN!"
|
| X | winlogon service | urx.exe | "Added by the SPYBOT.EN WORM!"
|
| X | Winlogon Shell | Explorer.exe svchost.exe | "Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
|
| X | Winlogon.exe | N/A | "CoolWebSearch parasite variant - resets home page to an adult content site"
|
| X | winlogon.exe | helper.exe | "Added by the FAKESPY-A TROJAN!"
|
| X | winlogon.exe | msole32.exe | "Adware |
| X | winlogon32_ | [path to file] | "Added by the RULAND.A WORM!"
|
| X | WinLogonnd | winlogonnd.exe | "Added by the AGENT-NNQ TROJAN!"
|
| X | winlogon_user | ccIsass.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | WMAudio | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| X | wmplayer | vergon1885.exe | "Added by the BRONTOK-DG WORM!"
|
| X | WNILOGON | WNILOGON.exe | "Added by the LEWOR-M TROJAN!"
|
| X | Worms | logon.bat | "Added by the DELMP3-A WORM!"
|
| X | WSAConfiguration | winlogon32.exe | "Added by the AGOBOT-WC WORM!"
|
| X | xp_system | winlogon.exe | "Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate winlogon.exe |
| U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures Screensaver
|
| U | Yumgo's Homepage Protector V1 | YumgoHomepageProtector.exe | "Yumgo's Homepage Protector"
|
| X | zango | zango.exe | "180solutions adware"
|
| X | Zango SiteFinder | ZangoSiteFinder.exe | "ZangoSearch adware variant"
|
| X | Zango TvTimes | ZANGOT~1.EXE | "ZangoSearch adware"
|
| X | ZangoOE | OEAddOn.exe | "Zango Search Assistant adware"
|
| X | ZangoSA | ZangoSA.exe | "Zango Search Assistant adware"
|
| X | [random name] | l?gonui.exe | "PurityScan adware"
|
| X | [random name] | w?nlogon.exe | "PurityScan adware"
|
| X | [various names] | winlogon32.exe | Added by an unidentified WORM or TROJAN!
|
| X | [various names] | bingo9.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | Bogobot.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | Kargo.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|