Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UACTIVBOARDABoard.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exe"ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue spyware remover - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntiVirGear 3.7AntiVirGear 3.7.exe"AntiVirGear rogue security software - not recommended
XAntiVirGear 3.8AntiVirGear 3.8.exe"AntiVirGear rogue security software - not recommended
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiVituSBase.exe"Added by the BAS.A WORM!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
XAVAntivir.exe"Antivir rogue security software - not recommended
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
YAvxliveavxlive.exe"Bullguard or BitDefender antivirus"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
XBastioneAntiviruspgs.exe"BastioneAntivirus
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XCerbDivXx.exe"Added by the KEYLOG-LV TROJAN!"
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
NCitiVANCitiVAN.exe"Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again"
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
UComm Drivercommh32.exe"G Data ""PC Spion"". PC monitoring and surveilling software
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative DetectorCTDetect.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
UCreativeMixerCTMIX32.EXE"Creative soundcard System Tray access to
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
XCTDrive"rundll32.exe drvmod.dllstartup"
UDAZEL Delivery AgentDcDaemon.exe"Control and send documents
NDDCActiveMenuDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XDevice Security Driverdevicesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
XDirectX Video Driverdxterm5.exe"Added by the WILAB-A TROJAN!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
?Divamon.exeDivamon.exe"Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
Xdivxdivxenc.exe"Added by the SPBOT.B TROJAN!"
XDivxcodll.exe"Added by the GRAVEBOT-A TROJAN!"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
XDivx4 codecdevldr32.exe"Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
XDivXCodecNEWMAIL.exe"Added by the DELF-RQ BACKDOOR!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
XDriveCleaner FreeUDC.exe"DriveCleaner rogue security software - not recommended
XDriveDefenderGDC.exe"DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
UDriveLEDOODLed.exe"O&O DriveLED - hard disk monitoring and crash prevention"
XDrivergbot.exe"Added by the JUNTADOR.K TROJAN!"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
NDriverMaxdevices.exe"DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
NDriveSelectdriveselect.exe"DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDyFuCA Active Alertactalert.exe"Adult content dialler - see here"
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
Xeth0 driverexec.exe"Added by the SPYBOT-Z WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
?Excite Private Messenger Pipex8impipe.exe"??"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XExtra AntivirusExtraAV.exe"Extra Antivirus rogue security software - not recommended
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
NGameDriveGDTask.exe"GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
NGDriveGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
XGeneral AntivirusGenAvir.exe"General Antivirus rogue security software - not recommended
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHIVHIV.exe"Added by the HIVA TROJAN!"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
XHot 8.0 Livehot.exe"Added by the BANKER.EIE TROJAN!"
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
XIBM Keyboard Driverikeybdrv.exe"Added by the SDBOT.IC TROJAN!"
UIDriveE StartupIDrvieEStartup.exe"IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
XIEDriverIEDriver.exe"IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze"
XIEDriverxplore.exe"IeDriver adware variant"
XIEDriverTD.exe"IeDriver adware variant"
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
XInet Deliveryinetdl.exe"Inet Delivery adware"
XInet Deliveryinetdl_2.exe"Inet Delivery adware"
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
UIntel Active Monitorimontray.exe"System tray monitoring of fans
XIntel Drivercsrs.exe"Added by a variant of the SDBOT WORM!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XInternet AntivirusIAvir.exe"Internet Antivirus rogue security software - not recommended
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
Yiolo AntiVirusioloAV.exe"iolo AntiVirus"
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
XiPOD USB DriverIPODUSB.EXE"Added by a variant of the RBOT WORM!"
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
NiRiS AntiVirus Active MonitorWIMMUN32.exe"Iris Antivirus - discontinued
UiRiver AutoDBMLService.exe"Associated with the iRiver Music Manager"
NiRiver UpdaterUpdater.exe"Updates for the iRiver Music Manager - used with their digital music players"
Xiviv.exe"Part of the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
XivHosttaskManager.exe"Added by a variant of the SPYBOT WORM! See here"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
NIVPServiceMgrivpsvmgr.exe"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as
Xivy.exeivy.exe"Added by the AGENT-ENZ TROJAN!"
Xiyelejivyujixit.exe"Added by the SDBOT.BJK WORM!"
Ujv16PT - Privacy ProtectorTask.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer
XKasper AntivirusKASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
XKaspersky AntivirusKasperskyAV.exe"Added by a variant of the RBOT WORM!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
XLAN Driverlandriver32.exe"Added by the RBOT.BT WORM!"
XLaunch Norton AntiVirus 2000jorgf.exe"Added by the RBOT-AUI WORM!"
Xldriverldriver.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
NLifeDrive ManagerLifeDriveMgr.exe"Keeps the Palm LifeDrive Manager utility in the systray. Shortcut available via Start -> Programs"
ULifeDrive? ManagerLifeDriveMgrTray.exe"System Tray utility for the Palm LifeDrive Mobile Manager"
XLinksys Modem Driverslinksys.exeAdded by the IRCBOT.VD WORM!
NLive MenuDllcmd32.exe"eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here"
XLive Messangerlivemsgr.exe"Added by the RBOT.BXX WORM!"
XLive Messangerwllmsngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive PC CareLP[random characters].exe"Live PC Care rogue security software - not recommended
?live rdrloadloud.exe"??"
XLive Security SuiteLiveSS.exe"Live Security Suite rogue security software - not recommended
XLive update monitorsrvany32.exe"Added by the AGOBOT.AFM WORM!"
Xlive update monitorumxlu32.exe"Added by the AGOBOT.ADK WORM!"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLive-Helplmns.exe"Added by the RBOT-GHE WORM!"
XLive-Messenger.exeLive-Messenger.exe"Added by the SILLYP2P WORM!"
XLiveAntispyLiveAntispy.exe"LiveAntispy rogue security software - not recommended
Xlivekeywebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
Xlivekeyswebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
NLiveMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
NLiveNoteLivenote.exeAsus graphics card driver live update feature
XLiveProtectLiveProtect.exe"System Live Protect rogue security software - not recommended
XLiveSexCamsLiveSexCams.exePremium rate adult content dialler
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
NLiveUpdateCopyer.exe"Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XLivreDibane.bat"Added by the BANEDI VIRUS!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XM S DVD DirectX Dll Driversmsxdl.exe"Added by the SDBOT-BJN WORM!"
UMacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMacDrive applicationMacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XMacromedia DriveIexplor32.exe"Added by a variant of the RBOT WORM!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
XMcAfee AntivirusMcAfeeAV.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus 32MCAFEEAV32.EXE"Added by the SPYBOT-EH WORM!"
XMcafee Antivirus Monitoring System326VSStatmn326.exe"Added by a variant of the SDBOT WORM!"
XMcafee Antivirus Monitoring System32mnVSStatmn32.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus ProtectionmcafeeAV.exe"Added by a variant of the RBOT WORM!"
XMcaffe AntivirusMcafeescn.exe"Added by a variant of the SPYBOT WORM!"
UMediafour MacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMediafour MacDriveMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
UMediafourGettingStartedWithMacDrive6MacDrive.exe"MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
UMicrosoft ActiveSyncWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Driverfaet.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Norton Antivirusnorton.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Sound Driversound32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updatelivemessenger.com"Added by the ADLOAD-LN TROJAN!"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft Video Drivervideodrv.exe"Added by the SDBOT-AGP WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft64antiv.exe"Added by the SOBER WORM!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftKsDrivers.bat"Added by the SHUTDOWN-F TROJAN!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicrosoft« ActiveX Debugger NTsetdebugnt.exe"Added by the BANCOS-CZ TROJAN!"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Drivermsdriver.exe"Added by the SDBOT-XD WORM!"
XMicrsoft Driverwindrive32.exe"Added by the SLINBOT.TT BACKDOOR!"
NMobile Connectivity SuiteApplication Launcher.exe"System Tray access to the HTC Sync mobile phone management utility for models including the Hero
XModem Driverz Updatesmdmdrv.exe"Added by a variant of the SDBOT WORM!"
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
XMONPluginSrIvcsn3monap23.exe"Added by a variant of the RBOT WORM!"
NMotive SmartBridgempbtn.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeMotiveSB.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
UMotiveMonitormotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used by the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufacturer. For most users it's not required
NMotiveSBMotiveSB.exe"System tray icon for the Virtual Assistant from AT&T Broadband
Xmousedrive.exeinstantmsgrs.exe"Added by the FORBOT-ER WORM!"
XMPL32 driverMPL32.exe"Added by the LOONY-M TROJAN!"
YmpLockDriveLockDrive.exe"LockDrive from i8 Technologies makes selected folders and drives read only and can be used to prevent users downloading or copying data to portable drives and memory sticks - i.e.
XMS Decryption Softwareactive.exe"MediaTickets adware variant"
XMS DirectX Sound Driversmsdrvdx.exe"Added by the RBOT.BCX WORM!"
XMS DVD DirectX Dll Driversmdxdl.exe"Added by the SDBOT-XI WORM!"
XMS DVD DirectX Sound Driversmsdrvdx.exe"Added by the SDBOT-XJ WORM!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs Sound Driversmsdrv.exe"Added by the SDBOT-WR WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMSDriverundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMSNFixdriver.exe"Added by the SILLYFDC.BBY WORM!"
XMsn 8.0 Livemsn.exe"Added by the BANKER.EIE TROJAN!"
XMSN Live Clientmsnlvclient.exe"Added by the IRCBOT.AWF BACKDOOR!"
XMSN Live Messangermsnlivegs.exe"Added by the RBOT-FSG WORM!"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
XMSN Messengerlive.messenger.com"Added by the DELF.AOI BACKDOOR!"
XMSN Messenger Live Loginmsnmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMstask32driverMstask32.exe"Added by the LOONY-D TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XNano Antivirusnanoav.exe"Nano Antivirus rogue security software - not recommended
XNAV Live Update[path to worm]"Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec"
XNegativespain.exe"Added by the BANKER-EXJ TROJAN!"
NNero DriveSpeedDRIVESPEED.EXE"Ahead Nero DriveSpeed - set the CD reading speed of a CD/DVD drive on-the-fly to reduce the noise on high-speed drives"
UNet Activity Diagramnad.exe"Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs"
XNetropa Internet ReceiverNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
NNetStat LiveNsl.exe"AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data"
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNod32 Free antivirusnod32krn.exe"Added by the RBOT-AAO WORM! Note - not the popular free NOD32 antivirus software
XNod3d2 Free antivirusN0D32KRN.EXE"Added by the RBOT-ABQ WORM!"
XnodriverAUEKXRZ.EXE"Added by a variant of the SPYBOT WORM!"
XnodriverSVCHOST.EXE"Added by the SPYBOT-Z BACKDOOR! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
XNortE Antivirusnorte.exe"Added by the RBOT.BQQ WORM!"
XNortE Antivirusnorten.exe"Added by the RBOT-AFF WORM!"
XNorton Antiviral Scannernavscnr.exe"Added by the DELBOT-K WORM!"
XNorton Antivirusnortonav.exe"Added by the RBOT-AYE TROJAN! Note - this is not the real Norton AV!"
XNorton Antivirus 2004SYMANTECAV2.EXE"Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV!"
XNorton Antivirus 7.0a[path to file]"Added by the PERDA-B or RANCK-CT TROJANS!"
XNorton Antivirus AVFVProtect.exe"Added by the NETSKY.P WORM! Note - this is not the popular AV software!"
XNorton AntiVirus SysNAVsys32.exe"Added by a variant of the WOOTBOT WORM!"
XNorton Antivirus Updaternortonav.exe"Added by the DELBOT-T WORM! Note - this is not the real Norton AV!"
XNorton Drive Protectionmsdt32.exe"Added by the FORBOT-GB WORM! Note - this not a valid Norton program!"
XNorton Live Update Servercpsdv.exe"Added by the AGOBOT.EW TROJAN!"
XNorton Live UpdaterCavapsvc.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterSochost.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterAvapsvc.exe"Added by the AGOBOT-BG BACKDOOR!"
XNorton Protect Activiescsrss.exe"Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XNorton Service Driverwsul.exe"Added by the RBOT-ABI WORM!"
XNortonAntivirusLSASS.exe"Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp"
XNortonAVnorton_antivirus.exe"Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program"
XnortonsantivirusccEvtMngr.exe"Added by the HZDOOR-A TROJAN!"
Xnsdrivernssys32.exe"NetShagg adware"
YNVIDIA ActiveArmorntrayfw.exe"System Tray access to the the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets"
XnVidia Application Driversnvidiav32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XnVidia Display Drivernvsvc64.exe"Added by the IRCBOT-YK WORM! Note - this is not related to any nVidia based graphics card"
XnVidia Display Drivers (x86)nvsys86.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XNVIDIA DriverMSPMSPSU.EXE"Added by the WOOTBOT.Y WORM!"
XnVidia DriversnVidiaDrvers.exe"Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card"
XNVidia Drivers[path to trojan]"Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
XnVidia System Driversnvsys32.exe"Added by an unidentified WORM or TROJAN! See here"
XNVIDIA Video driversvideo_32D.exe"Added by the AGOBOT.KV WORM!"
XNVIDIA Video driversvideo_32sD.exe"Added by the RBOT-BB WORM!"
XOlive SystemSzchost.exe"Added by the MERCURYCAS.A TROJAN!"
XOmega AntiVirOM83b.exe"Omega AntiVir rogue security software - not recommended
?online cdromActive acid.exe"??"
XOpen Service Driversopiater.exe"Added by a variant of the RBOT WORM!"
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
UOpenwares LiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
UOStivityInvAgtostivity.exe"OStivity - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network
XPaladin Antiviruspav.exe"Paladin Antivirus rogue security software - not recommended
XPC Drive ToolGDC.exe"PC Drive Tool rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XPC Live GuardPC[random characters].exe"PC Live Guard rogue security software - not recommended
YPC Tools AntiVirus ClientPCTAV.exe"System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses
UPC Tools Privacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
XPCAntiVirusPropgs.exe"PCAntiVirusPro rogue security software - not recommended
XPCPrivacyCleanerpcpc.exe"PCPrivacyCleaner rogue privacy tool - not recommended"
XPCPrivacyDefender FreewareUPSPDAP.exe"PCPrivacyDefender rogue privacy program - not recommended
XPCPrivacyToolGDC.exe"PCPrivacyTool rogue privacy tool - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XPersonal AntivirusPerAvir.exe"Personal Antivirus rogue security software - not recommended
UPervasive.SQL Workgroup EngineW3dbsmgr.exeDatabase Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
XPex Sound DriverToday's Results.vbs"Added by the TRODE-A WORM!"
Xpex Sound driver 2Today's Results.vbs"Added by the TRODE-A WORM!"
?PhilipsLimeLimeAlive.exe"Associated with some Philips portable media players such as the GoGear. What does it do and is it required?"
YPinnacleDriverCheckPSDrvCheck.exe"Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
NPivotSoftwarewpctrl.exe"PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
XPnP Driverplayboy.exe"Added by the FORBOT-FR WORM!"
NPoivYPoivY.exe"PoivY - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XPower-Antivirus-2009Power-Antivirus-2009.exe"Power Antivirus 2009 rogue security software - not recommended
NPowerArchiver TrayPASTARTER.EXE"System Tray access to PowerArchiver from ConeXware
XPrint Driver Helper Servicecrsrr.exe"Added by the AGENT-BC TROJAN!"
XPrinting Drivermsprint.exe"Added by the RBOT.JH WORM!"
NPrivacy Eraser ProPrivacyEraser.exe"Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities"
XPrivacy GuarantorPrivacyGuarantor.exe"Privacy Guarantor rogue privacy program - not recommended
YPrivacy GuardianPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
UPrivacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
XPrivacy ProtectorPrivacy Protector.exe"PrivacyProtector rogue privacy tool - not recommended
XPrivacy WatcherPrivacy Watcher.exe"Privacy Watcher rogue privacy program - not recommended
XPrivacyConductorGDC.exe"PrivacyConductor rogue privacy tool - not recommended
YPrivacyGuardianIndexPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
UPrivacyKeyboardPrivacyKeyboard.exe"PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices
XPrivacyProtector FreeUPRP.exe"PrivacyProtector rogue privacy tool - not recommended
XPrivacyScannerpscan.exe"Privacy Champion
XPrivacyWarriorGDC.exe"PrivacyWarrior rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NPrivateDiskpdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
XPrivateNet[various filenames]Premium rate adult content dialler
UPrivoxyprivoxy.exe"Privoxy - web proxy with advanced filtering capabilities for protecting privacy
XProAntiVirusProAntiVirus.exe"Added by the RBOT-FTP WORM!"
UProgressive TouchSynTPEnh.exe"Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads
UProgressive TouchSynTPLpr.exe"Synaptics TouchPad driver helper - included with drivers for Synaptics based TouchPads
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
XProtectionDeDriverGDC.exe"ProtectionDeDriver rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XProtejaseuDriveSysRep.exe"ProtejaseuDrive rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
UPurgativePURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
YQCDriverInstallerLqdsw.exe"Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart
YQH Live Update SchedulerUPSCHD.EXE"Quick Heal Anti-Virus"
XQuick Officeactivate.exe"Added by the RANSOMLOCK.D TROJAN! Note - this infection hooks the keyboard to prevent anything except numbers from being typed and displays a Russian message requesting a valid license key"
NQuickBooks Delivery AgentQBDAGENT.EXEAs far QAGENT but for QuickBooks. Can also have the version number in the name
URAMDriveRDTask.exe"Virtual Hard Drive Pro from Farstone - ""takes a portion of your system memory and creates a RAM disk drive
XRapid AntivirusRapid Antivirus.exe"Rapid Antivirus rogue security software - not recommended
XRCAutoLiveUpdateMaxLURC.exe"Max Registry Cleaner rogue registry cleaner - not recommended
XRcf Driverrcf.exe"Added by the RANDEX.BLD WORM!"
UReceiverPcfaxRcv.exe"Incorporated on multifunction digital copiers (such as the
XRegRunmActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XRequired Service Driversmicront.exe"Added by the RBOT-ABD WORM!"
URightFAX Print-to-Fax DriverFaxCtrl.exe"Part of RightFAX from Captaris - ""the proven market leader in fax server and document delivery software"""
URivaTunerRivaTuner.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTuner ApplicationRivaTuner.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTuner.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTunerWrapper.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerWrapper ApplicationRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
XRoam04ActiveX.exe"Added by the ROAMER-A TROJAN!"
XRPC Driversrpcall.exe"Added by the SDBOT.FLY WORM!"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
XSafeHardDriveSysRep.exe"SafeHardDrive rogue system error and cleaning utility - not recommended
USDAutoLiveupdateLiveUpdateSD.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
Xsecdrive.exesecdrive.exe"Added by a variant of the SPYBOT WORM! See here"
XSecure AntiVirus Proav.exe"Secure AntiVirus Pro rogue security software - not recommended
XSecurity AntivirusSA[random characters].exe"Security Antivirus rogue security software - not recommended
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
USensivaSensiva.exe"Symbol Commander makes the use of your PC
XService Driversmsnpg.exe"Added by the RBOT.BMD WORM!"
XService DriversPC.EXE"Added by the SDBOT-WK WORM!"
XService DriversCompt.exe"Added by the RBOT-ZJ WORM!"
XService Driversabl.exe"Added by the SDBOT-YX WORM!"
XService DriversMSNMEssenger.exe"Added by a variant of the RBOT WORM!"
XService Host Driversvchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XServicesActivecssrs.exe"Added by the AGOBOT-GB BACKDOOR!"
XShellExplorer.exe sound_drive16.exe"Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""sound_drive16.exe"" file is located in %System%"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
XSichererAntiviruspgs.exe"SichererAntivirus
XSmart Antivirus-2009.exeSmart Antivirus-2009.exe"Smart Antivirus 2009 rogue security software - not recommended
XSmss.exe driverwinupd32.exe"Added by the SDBOT.MI BACKDOOR!"
USoftK56 Modem Drivercarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XSolelunaAntiViruspgs.exe"SolelunaAntiVirus rogue security software - not recommended. A member of the AVSystemCare family"
XSoundMax Audio DriversSndMAX.exe"Added by a variant of the SDBOT WORM!"
Xstartkeyantivir.exe"Added by the BIFROSE-TO TROJAN!"
UStayAliveStayAlive.Exe"Part of RealSPEED - tweaking utility to speed-up your internet connection. Stay connected even after a period of inactivity on the net"
UStayAlivesa.exe"StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen
XStreams Drivers[trojan filename]"Added by the RESTARTER.E TROJAN!"
Xsvshostdriversvshost.exe"Added by the SDBOT-HN TROJAN!"
Xsvshostdrivermsnmessengerupdate.exe"Added by the SDBOT-BI BACKDOOR!"
XSymantec Antivirus professionaldfrgfrat.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalautoformat.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionaldyndns.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalf0dns.exe"Added by the FORBOT-GT WORM!"
XSymantec Antivirus professionalflushdns.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalfor.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalregedit.exe"Added by a variant of the FORBOT WORM! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
XSymantec Antivirus professionalSymantex.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalwindows .exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalWinhp32.exe"Added by a variant of the FORBOT WORM!"
XSymantec Antivirus professionalwinudp.exe"Added by a variant of the WOOTBOT WORM! See here"
XSymantec Antivirus professionalxplrer.exe"Added by a variant of the FORBOT WORM!"
USymantec NetDriver MonitorSNDMon.exe"Part of Symantec's LiveUpate (eg
USymantec NetDriver WarningSNDWarn.exePart of Symantec Live Update - displays the warning when you need to update the firewall database
USymKeepAliveCKA.exe"Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive"
USynaptics Pointing Device DriverSynTPEnh.exe"Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads
XSysAntivirus 2009sysav.exe"SysAntivirus 2009 rogue security software - not recommended
Xsysftray2bolivar19.exe"Added by the KOOBFACE.I WORM!"
XSysLiveSysLive.exe"Added by the EXPICHU WORM!"
XSysResWWE DIVAS.exe"Added by the ELIPTER.D WORM!"
XSystemantivirus.vbe"Added by the AUTORUN-AYI WORM!"
XSystem 64 Driver for Gamessys64dvr.exe"Added by the SDBOT TROJAN!"
XSystem driverMessenger.exe"Added by the WOOTBOT.GI WORM!"
XSystem Driverswingmt.exe"Added by the SDBOT-MG WORM!"
XSystem Driverscpsq32.exe"Added by the SDBOT.AXH WORM!"
XSystem Driverssysdrv32.exe"Added by the AGOBOT-ZX WORM!"
XSystem File Driversnvsysvc32.exe"Added by the AGOBOT.WJ WORM!"
XSystem Servlcelive.exe"Added by the IRCBOT-GX WORM!"
XSystem32-Drivercsrs32.exe"Added by the SDBOT-CP BACKDOOR!"
XSystemDrivemaxpaynow1.exe"Added by the TIBS.BKU TROJAN!"
XSystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
XSystemDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystemDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XSystems Backupswindrives.exe"Added by the AGOBOT-RB WORM!"
XSystems Servicedrivex.exe"Added by a variant of the RBOT WORM!"
Xsystems usb driverWindows2.exe"Added by a variant of the RBOT WORM!"
XSystray driversystray.exe"Added by the MUTEBOT TROJAN! Note - this is not the legitimate systray.exe process"
XTaskmon driverwinampa.exe"Added by the LOONY-I TROJAN! Note - this is NOT associated with the popular Winamp media player. The valid file for the Winamp Agent resides in a ""Winamp"" subdirectory of %ProgramFiles% whereas this file is located in %System%"
Ytcactivetca.exe"Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage"
UThe Easy Bee's HiveATCEgSvr.exe"The Easy Bee is a software that allows you to record Internet navigation sequences
YThinkVantage Active Protection SystemTpShocks.exe"Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T
NTivoliLCFEP.EXE"Tivoli 'TME' System Tray icon - ""'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"""
?TivoNotifyTiVoNotify.exe"Part of Tivo Desktop. What does it do and is it required?"
UTivoServerTiVoServer.exe"Tivo Server - installed with the TiVo Home Media Option. It streams audio files to your television/home theater from your PC"
UTivoTransferTivoTransfer.exe"Tivo Transfer Service. TiVo Desktop is an easy-to-use application that lets you publish and share digital music
XTkNetDriver Monitorlexbce.exe"Added by the SDBOT-ADF WORM!"
XTmNetDriver Monitorexbce.exe"Added by the SDBOT-ABR WORM!"
XTRE AntiVirustreav.exe"TRE AntiVirus rogue security software - not recommended
YTrend Micro AntiVirus 2007tavui.exe"Part of Trend Micro AntiVirus 2007"
YTrendMicro AntivirusAveagent.exeVirus scanner
XTrustedAntiviruspgs.exe"TrustedAntivirus rogue security software - not recommended. A member of the AVSystemCare family"
Xtyack drivetyack.pif"Added by the RBOT-AMT WORM!"
XUnigrayUnigray Antivirus.exe"Unigray Antivirus rogue security software - not recommended"
XUniversal Plug & Play devicesWinUPPD.exeAdded by an unidentified WORM/TROJAN!
XUniversal USB Servicesvchost32.exe"Added by the KELVIR.R WORM!"
Xupdate driverSNDVOL32.EXE"Added by the SPYBOT-CU BACKDOOR!"
XUSB 2.0 DriverupdateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 DriverupdateXP.exe"Added by the AGOBOT-QP WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XUSB 2.0 DriverUpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
XUSB 2.1 Driverwinupdate1.exe"Added by a variant of the RBOT WORM!"
XUsB drivermsjavx86.exe"Added by the AGOBOT-PQ WORM!"
XUSB Driver4UpdateXP*.exe [* = random digit]"Added by a variant of the SDBOT WORM!"
XUSB Drivers1msupdate.exe"Added by a variant of the RBOT WORM!"
XUSB Driverz2msnplus1.exe"Added by the SDBOT-XQ WORM!"
XUSBDrivesmsfirewalI.exe"Added by the RBOT-ABP WORM!"
XUSD Driverccrss.exe"Added by the SDBOT.BFH WORM!"
UVDrive2WebLifeDisk.exe"EarthLink WebLife Disk - ""Consumers can quickly save files from their desktop into WebLife Disk
XVgaDriverRsrVga32.exe"Added by the KEYLOG-AH TROJAN!"
XVideo Card Driver (do not remove)tsasi.exe"Added by the SPYBOT-EF WORM!"
XVideo Driversvchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XVideo DriverMsregdrv32.exe"Added by the SPIGOT BACKDOOR!"
XVideo Multimedia Driverndrives32.exe"Added by the RBOT-DK WORM!"
XVideo ProcessNivopsvc.exe"Added by the AGOBOT-GT WORM!"
XVideoDriver[filename]"Added by the GSPOT20.A TROJAN!"
XVideoDrivervideodrv.exe"Added by the MIMAIL.A WORM!"
XVideoDrivergspotbot.exe"Added by the SPIGOT.C TROJAN!"
XVideoDriverHookvmdriver.exe"Added by the BCKDR-PSS BACKDOOR!"
XVidiaDrivers[path to trojan]"Added by the RANKY.U TROJAN!"
XVIEW POINT DRIVERSphqghum.exe"Added by the RBOT.BRX WORM!"
XVIEW POINT DRIVERS FOR WIN32phqghu.exe"Added by a variant of the RBOT WORM!"
UViivMonitorViivMonitor.exe"Related to Intel Media Share Software. ""Stream or download media files from your Intel® Core®2 Processor with Viiv® technology-based PC"""
NVirtualCloneDriveVCDDaemon.exe"Virtual Clone Drive
NVirtualDriveVDTask.exe"VirtualDrive from Farstone - virtual CD/DVD drive emulator. Available via Start → Programs"
XVistaDriveVistaDrive.exe"VistaDrive malware"
XVividGalutVividGalut.exeAdult content related web downloader
XVMount drivevmount.exe"Added by the RIZO.A TROJAN!"
UVOBIDInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XVxD Driver Initializationntsvxd.exe"Added by the SDBOT-LW WORM!"
NWaveTop Receiver 1N/A"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
NWaveTop Receiver 2N/A"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
UWD Drive ManagerWDBtnMgrUI.exe"System Tray access to the WD Drive Manager management software for selected external drives in the My Book and My Passport range. Hovering over the icon displays health status (temperature
XWEB DRIVERS FOR WIN32phqgh.exe"Added by a variant of the RBOT WORM!"
NWebDrivewebdrive.exe"System Tray access to WebDrive from South River Technologies
NWebDriveTraywebdrive.exe"System Tray access to WebDrive from South River Technologies
Uwebsaverlivewebsaverlive.exe"WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle"
UWildTangent Web Driver updaterwcmdmgrl.exe"Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
XWin Antivir 2008Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended
XWin Antivirus 2008Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended
XWin Drivers SSLhpws.exe"Added by the IRCBOT.67098 WORM!"
XWin Drivers SSLTASKMAN4.exe"Added by a variant of the RBOT WORM!"
XWin Drivers SSL32hpwsnnsbc.exe"Added by the SPYBOT.MAR WORM!"
XWin USB 2.0 USB DriverHPPrint.exe"Added by the SPYBOT.DNB WORM!"
XWin32 Driversvchosts.exe"Added by the FORBOT-FD WORM!"
XWin32 Driversysmls.exe"Added by the MYTOB.JH WORM!"
XWin32 Driverswinlogons.exe"Added by the FORBOT-FG WORM!"
XWin32 DRK Driverwdrk32.exe"Added by the WOOTBOT.CY WORM!"
XWin32 Firewall Driverwinfw.exe"Added by a variant of the RBOT WORM!"
XWin32 Firewall Driverswinfirewall.exe"Added by the WOOTBOT.GX WORM!"
XWin32 FireWire DriverCTHELPER32.EXE"Added by the WOOTBOT TROJAN!"
XWin32 FRT Drivermsfr32.exe"Added by the WOOTBOT.EJ WORM!"
XWin32 LSA Driverlsa.exe"Added by the FORBOT-FJ WORM!"
XWin32 NDIS Driverxpndis.exe"Added by a variant of the RBOT WORM!"
XWin32 NDIS DriverNdistcp.exe"Added by the WOOTBOT.EU WORM!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32 NVIDIA DriverMSPMSPSU.EXE"Added by a variant of the WOOTBOT.Y WORM!"
XWin32 SSL Driverwinssv.exe"Added by the FORBOT-BH WORM!"
XWin32 Svchosts Driversvchosts.exe"Added by the FORBOT-FO WORM!"
XWin32 USB Driverwinxpinit.exe"Added by the SDBOT.AA TROJAN!"
XWin32 USB Drivermvsecn.exe"Added by the FORBOT-BK WORM!"
XWin32 Usb Driversvhosint32.exe"Added by the FORBOT-BE or FORBOT-J WORMS!"
XWin32 Usb Driverusb32.exe"Added by the SDBOT-OV WORM!"
XWin32 Usb DriverAvpG.exe"Added by the FORBOT-BX WORM!"
XWin32 USB Driverrundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWin32 USB2 Driverwin32usb.exe"Added by the SPYBOT.DHV WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Driversvchosting.exe"Added by the FORBOT-J or SDBOT.HU WORM!"
XWin32 USB2 Driversys32.exe"Added by the WOOTBOT.X WORM!"
XWin32 USB2 Driversys32snd.exe"Added by the FORBOT-AN WORM!"
XWin32 USB2 Driverwind32.exe"Added by the FORBOT-AH WORM!"
XWin32 USB2 Driverwinupdate.exe"Added by the AGOBOT.YE WORM!"
XWin32 USB2 Driverupdatemgr.exe"Added by a variant of the FORBOT WORM!"
XWin32 USB2 Driverwinsnd32.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Drivermsn.exe"Added by the FORBOT-EX WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWin32 USB2 Driveralgg.exe"Added by the TIBS.BF WORM!"
XWin32 USB2 Driverusb2.exe"Added by the FORBOT-Y WORM!"
XWin32 USB2 Driverwinusb32.exe"Added by the FORBOT-M WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
XWin32 USB3 Driverwin32tool.exe"Added by a variant of the RBOT WORM!"
XWin32 Wmls Driverwinitr32.exe"Added by the WOOTBOT.B WORM!"
XwinactiveWINACTIVE.EXE"WinActive variant of the LOP.com hijacker"
XWinActiveJWinActiveJ.exeAdded by the ROTARRAN VIRUS!
XWinAntivirusAVSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XWinAntiVirus Pro 2007WinAv.exe"WinAntiVirus Pro 2007 rogue security software - not recommended
XWinAntiVirusPro2006WinAV.exe"WinAntiVirus Pro 2006 rogue security software - not recommended
XWind River Systemsvxworks.exe"Added by the ACKANTTA WORM! Note that this is not related to the VxWorks platform from Wind River"
XWinDLL (mysnlive.exe)"rundll32.exe mysnlive.exestart"
XWinDLL (redyLive.exe)"rundll32.exe redyLive.exestart"
XWindow Msn Live Messangermsnmsgsls.exe"Added by the RBOT.BJD BACKDOOR!"
XWindows Activate Systemsyssv.exe"Added by a variant of the SPYBOT WORM!"
XWindows Anti-Virus Built 32AntiVirus32.exe"Added by the SDBOT-BG WORM!"
XWindows Domain Name Driverswindns.exe"Added by the FORBOT-EP WORM!"
XWindows DotFix livemsdotfix.exe"Added by the IRCBOT.XGK BACKDOOR!"
XWindows Drive CompatibilitySystem32Driver32.exe"Added by the SUPOVA.Z WORM!"
XWindows Driverwinxpdriver.exe"Added by the WOOTBOT.EE WORM!"
XWindows Driverwindrive.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driver Adaptersvchost.exe"Added by the ANTINNY-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Driver Servicesmsdrvs32.exe"Added by the WOOTBOT.L WORM!"
XWindows Driver Supwindvrhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows driver updatedmsvc32.exe"Added by the SDBOT-GP BACKDOOR!"
XWindows driver updateIpconfig32.exe"Added by the SDBOT-JV WORM!"
XWindows Driver!windriver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Driversssms.exe"Added by the RBOT-AT WORM!"
XWindows drivers updatewindowsupdate.exe"Added by the RBOT-ACE WORM!"
XWindows HP Drivershpdmws.exe"Added by the SDBOT.AQU WORM!"
XWindows IPv6 Driverswipv6.exe"Added by the SDBOT-VJ WORM!"
XWindows Livemsgnms.exe"Added by the XPACK.AV TROJAN!"
XWindows LiveWindowsLive.exe"Added by the REALBOT-A WORM!"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
XWindows Live Clientmsnclient.exe"Added by a variant of the IRCBOT TROJAN! See here"
UWindows Live Family Safety Filterfsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XWindows Live Managerwinlivemgr.exe"Added by the SHEUR.EB TROJAN!"
XWindows Live Messagesmsgnlive.exe"Added by the AGENT.AYH WORM!"
XWindows Live Messengermsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XWindows live Messengermsn.com"Added by the IRCBOT-AAV WORM!"
XWindows Live Messengermsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NWindows Live Messengermsnmsgr.exe"Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
XWindows Live Messenger[random].exe"Added by the RBOT-GVL WORM!"
XWindows Live Messengermsnd.exe"Added by the BCKDR-QQQ BACKDOOR!"
XWindows Live Messenger 8.12ctfmon.exe"Added by the LIPARK-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %UserProfile%"
XWindows Live Messenger Addonwllivemsngr.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Live Messenger Servicermsmgslive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger Servicesmsgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Messenger!livemsngr.exe"Added by the IRCBOT.AWE BACKDOOR!"
XWindows Live Messenger!msgrlive.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgswlivemsg.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Live Msgs!wlivemsgs.exe"Added by a variant of the IRCBOT TROJAN! See here"
YWindows Live OneCarewinssnotify.exe"System Tray access to and notifications from Windows Live OneCare - now superseded by Microsoft Security Essentials. ""OneCare helps keep your PC safe and secure while making your life easier. From virus scanning and file backups
XWindows Live Servicemsnlive.exe"Added by the SLENFBOT.DI WORM!"
XWindows Live Servicerusrserv.exe"Added by the SMALL.LU BACKDOOR!"
XWindows live Supportwlmsngr.exe"Added by the RBOT-BKL WORM!"
UWindows Live SyncWindowsLiveSync.exe"Windows Live Sync from Microsoft (formerly known as Windows Live FolderShare) - ""a free-to-use internet-based file synchronization application by Microsoft that is designed to allow files and folders between two or more computers be in sync with each other on Windows (Vista and later) and Mac OS X based computers"""
UWindows Live™ OneCare™ Family Safetyfssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
XWindows Media Drivermsnger.exe"Added by a variant of the RBOT WORM!"
XWindows Memory Driversmemretain.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Messenger Filesharewivsvc.exe"Added by the SILLYIM WORM!"
XWindows Messenger Live MSNwinlivemsnmessenger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Messenger Live Startupwindowslivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Messenger Live Startupwindowsmsnlive.exe"Added by the DELF.DAX TROJAN!"
XWindows Micro Driverswupdates32.exe"Added by the RBOT-AEH WORM!"
XWindows ms Driversmsnup32.exe"Added by the SDBOT-AAL WORM!"
XWindows Msn Live Messangermsnmsgsman.exe"Added by a variant of the SDBOT WORM!"
XWindows MSN Live Messangerwmsnlive.exe"Added by the RBOT.BMV BACKDOOR!"
XWindows MSN Live Messangerlivemsngs.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows MSN Live Messengerwinlivemsn.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows MSN Live Messengerwinmessengerlive.exe"Added by the IRCBOT.EAD BACKDOOR!"
XWindows MSX driverswinmsx.exe"Added by the RBOT-AYG TROJAN!"
XWindows Nivedia DriversysMGT.exe"Added by a variant of the RBOT WORM!"
XWindows Portable Device DriversMSKSVRVS.EXE"Added by a TROJAN - see here"
XWindows Printing DriverWinPrint.exe"Added by a variant of the RBOT WORM!"
XWindows Printing DriverWinSpooler.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Driverciadvs.exe"Added by the BUZUS-M TROJAN!"
XWindows Printing Driverciadvss.exe"Added by the ARCHIVARIUS series of WORMS!"
XWindows Printing Drivergpedits.exe"Added by the DCKEYG.A WORM!"
XWindows Server Driverssyssrv.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Server IP Verification Servicewsivs.exe"Added by an unidentified WORM or TROJAN! See here"
XWindows Serviceprivate-zone.exeAdded by an unidentified WORM or TROJAN!
XWindows Service Updatelivecal.exe"Added by the SDBOT-DEY WORM!"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows Sound DriverSndMon32.exe"Added by a variant of the SPYBOT WORM!"
XWindows sq Driverswinmsn32.exe"Added by the RBOT-ADI WORM!"
XWindows SSL Secondary DriversSSL32Dr.exe"Added by the SDBOT.ASQ WORM!"
XWindows Stand Sound DriversSounddrv.exe"Added by the SDBOT-XF WORM!"
XWindows Storm-Memory Driversmemorystorm.exe"Added by the SLENFBOT.CO WORM!"
XWindows System Driverssysretain.exe"Added by the SLENFBOT.BY WORM!"
XWindows System Serivcewinserv.exe"Added by the RBOT.ACA WORM!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows System32 Driverclsass32.exe"Added by the SDBOT-AGG WORM!"
XWindows UDP Control Centerwinlive32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Updatelivesrvs.exe"Added by a variant of the RBOT WORM!"
XWindows Update Driveupdrvs.exe"Added by a variant of the SDBOT WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows USB 2.0 Driverusb2ctrl.exe"Added by the RBOT-BIW WORM!"
XWindows USB 2.0 Driverusbservice.exe"Added by the RBOT-BLF WORM!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows USB Driver SupportWindowsusb.exe"Added by a variant of the SPYBOT WORM!"
XWindows User Mode Driver Managerwdfmrg.exe"Added by the SDBOT-ZN WORM!"
XWindows Video Driversvideons32.exe"Added by the GAOBOT.AZT WORM!"
XWindows Video DriversVIDEONS3.EXE"Added by the AGOBOT-KZ BACKDOOR!"
XWindows32 Serivceswinser32.exe"Added by the SPYBOT.AAF WORM!"
XWindowsHiverpcc.exe"Added by the DLENA-A TROJAN!"
XWindows_SerivceSERVICE.exe"Added by the WOOTBOT.AH WORM!"
XWinDriv32WinDriv32.exe"Added by the SMALL-BA TROJAN!"
XWinDriver Configurationwindrvconf.exe"Added by the AGOBOT-LX TROJAN!"
XWinDrivesWinDrives.EXE"Added by the SMALL.DIG WORM!"
XWinRunnersWinDrivers.exe"Added by the DULOAD.C WORM!"
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWinsecure AntivirusSecureantivirus.exe"Added by a variant of the SPYBOT WORM!"
XWinsock driverwinnt update.exe"Added by the SPYBOT-DM TROJAN!"
XWinsock driverwinnt64.exe"Added by the SPYBOT-DR WORM!"
XWinsock Drivernvscv32.exe"Added by the AGOBOT-FD WORM!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock driverwin.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWinsock drivertcpmngr.exe"Added by the SPYBOT-CK WORM!"
XWinsock driverwinupdate32.exe"Added by the SPYBOT-JZ TROJAN!"
XWinsock2 driverSDJOIJE.EXE"Added by the SPYBOT.DR TROJAN!"
XWinsock2 driverMIRC32.exe"Added by the SPYBUZZ TROJAN!"
XWinsock2 driverkgzgjkpcw.exe"Added by the SDBOT.T TROJAN!"
XWinsock2 driverZONEALARM.EXE"Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program"
XWinsock2 driverwincfg.scr"Added by the SPYBOT-E TROJAN!"
XWinsock2 driverwinupdate.exe"Added by the SPYBOT-BX WORM!"
XWinsock2 driverSPOLSV.EXE"Added by the SPYBOT-CM WORM!"
XWinsock2 driver[random filename]"Added by members of the SPYBOT family of WORMS! Note - the random filename is located in %System%"
XWinsock2 driversysreq.exe"Added by the SPYBOT-CC WORM!"
XWinsock2 driverWUAUMQR.EXE"Added by the SPYBOT-DP WORM!"
XWinsock2 driverwincfg.exe"Added by the SPYBOT.CO WORM!"
XWinsock2 driversvchorsst.exe"Added by the SPYBOT-EE WORM!"
XWinsock2 driverSYSTEM32.EXE"Added by the SPYBOT-EG WORM!"
XWinsock2 driverdllcfg32.exe"Added by the SPYBOT.AG WORM!"
XWinsock2 driverCFTMON.EXE"Added by a variant of the IRCBOT BACKDOOR!"
XWinsock2 driverntsys32.exe"Added by the SPYBOT-DD WORM!"
XWinsock2 driverWINNT32.EXE"Added by the SPYBOT-CN WORM!"
XWinsock2 driverPAC.EXE"Added by the SPYBOT-ET WORM!"
XWinsock2 driverwinsock2.exe"Added by the SPYBOT-CT BACKDOOR!"
XWinsock2 drivermmtask5.exe"Added by the SPYBOT-CD WORM!"
XWinsock2 driverWWEUMQR.EXE"Added by the SPYBOT-BY WORM!"
XWinsock2 driverIEXPLORE .EXE"Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XWinsock2 driverWINSOUND.EXE"Added by the SPYBOT-H WORM!"
XWinsock32 driverTESTING.EXE"Added by the SPYBOT-B WORM!"
XWinsock32 driversystem32.exe"Added by the IRCBOT-VT TROJAN!"
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinsock32driversp2XPupdate.exe"Added by the HACKARMY.S TROJAN!"
XWinsock32driverwin32server.exe"Added by the BACKDOOR-AZV TROJAN!"
XWinsock32driverZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
XWinsock32driverZoneLockup.exe"Added by the HACARMY.D TROJAN!"
XWinsock32driverwin32server.exe"Added by the HACARMY.F TROJAN!"
XWinsock32driverwinXPupdate.exe"Added by the HACKARMY.9728 TROJAN!"
XWinsock32driversvchhost.exe"Added by the HACKARMY.I TROJAN!"
XWinsock6 MIC driverieservicesupd.exe"Added by the SPYBOT.AFZ WORM!"
Xwinsockdrivertskmg.exe"Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM!"
Xwinsockdriverwinsock2.2.exe"Added by a variant of the SPYBOT WORM!"
Xwinsockdriveriexplor.exe"Added by the BLATIC.A WORM!"
Xwinsockdriverwinsock3.exe"Added by the SPYBOT-DO WORM!"
Xwinsockdriverbot.exe"Added by the WARPIGS-D WORM!"
Xwinsockdriverwinsock4.1.exe"Added by a variant of the IRCBOT TROJAN! See here"
Xwinsockdriverwinsock2.exe"Added by the SPYBOT-AC WORM!"
XWinsocks2 drivermznmgr.exe"Added by a variant of the SDBOT WORM!"
Xwinsys32 Driverwinsys32.exe"Added by the LOONY-O TROJAN!"
XWinTask driverwintask.exe"Added by the DLOADER-NA TROJAN!"
Uwintectivewintective.exe"Wintective logs keystrokes
Xwinupdatefiv_[path to file]"Added by the COMBRA.C WORM!"
XWin_api_driversystem.exe"Added by the REVIRD TROJAN!"
XWIN_DRIVR32shchostv.exe"Added by a TROJAN - see here"
Xwin_drivr32zxhstn.exe"Added by the SMALL.CXO TROJAN!"
Xwistaantiviruswistaantivirus.exe"Wista Antivirus rogue security software - not recommended
XWlan Driveravscan.exe"Added by the WOOTBOT.DH WORM!"
XWLiveCD.exeWLiveCD.exe"Added by the VB-EQI TROJAN!"
XWnsck2 driverwlogf.exe"Added by the SPYBOT-AF WORM!"
XWstat32 driverWstat32.exe"Added by the LOONBOT TROJAN!"
XWupdate driver[various filenames]"Added by a variant of the SPYBOT WORM!"
XWupdate driverwupdadte.exe"Added by the SPYBOT-CQ WORM!"
XXP Antivirusxpantivirus.exe"XPAntivirus rogue security software - not recommended
XXP Antivirusxpa.exe"XP Antivirus rogue security software - not recommended"
XXPAntivirusXPAntivirus.exe"XPAntivirus rogue security software - not recommended
XXTN Service Driverswinxtn.exe"Added by the SDBOT-YK WORM!"
NYLive.exeYlive.exe"Yahoo! Assistant (formerly 3721 Internet Assistant) - not recommended"
XYourPrivacyGuardGDC.exe"YourPrivacyGuard rogue privacy tool - not recommended
XZi5AntiVirus Update.exe"Added by the ERKEZ.G WORM!"
NZinio DLMZinioDeliveryManager.exe"Related to Zinio used to read magazines in digital rather than paper format"
XZip Driver LoaderZipLoader32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XZip Driver Loadermsload32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
X[various names]driver32.exe"Added by a variant of the SDBOT WORM!"
X[various names]driver64.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_pnd_Panda Antivirus_pnd_*****.exe [* = random char/digit]Added by the AGENT.NAK TROJAN!
X_SystemDrivercsrss.exe"Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\addins\explorer"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.