Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
U$EnterNetEnternet.exe"Connection manager for the EnterNet ISP. You can also use RASPPOE"
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
?.NET configsysmon32.exe"??"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
?00notify33NetBrowser.exe"Part of Best Network Security
?1CmailSNETMAIL.EXE"??"
X4.68474E+12netdll32.exe"Added by the SDBOT-DEV WORM!"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdware_ProNETAdware_Pro.exe"Adware Pro rogue security software - not recommended
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAntiMalware_ProNETAntiMalware_Pro.exe"AntiMalware Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
XA_M_P_NETAntiMalwarePro.exe"AntiMalware Pro rogue security software - not recommended
UBeatNik Internet ClockBeatNik.exe"BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
XBullsEye Networkbargains.exe"BargainBuddy adware"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
XChckupNetverchk.exe"Covert Sys Exec malware variant"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
Ncnetkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
UCP4HPOTOneTouch.EXE"Supports the additional multimedia keys on HP/Compaq laptops which give single button press access to standard functions such as Mail
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
XCRP386 Networkingcrp386.exe"Added by the IRCBOT.N TROJAN!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XDialNetmxt32.exeAdult content dialler
XDialUp Network ApplicationRnaap.exe"Added by a variant of the SDBOT WORM!"
?disc detectorqnetquestnotifty.exe"??"
Udistributed.net clientDNETC.EXE"Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
?DJSNetCNDJSNetCN.exe"""Symantec Licensing Detect Internet Connection""
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
Xdrvnetwdrvnetw.exe"Added by the BROGGER-B TROJAN!"
NEasyNetworkMcENUI.exe"McAfee's EasyNetwork user interface - ""enables secure file sharing
UEicon NetworksLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
NEthernettcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEthernet Linkingethernet.exe"Added by a variant of the IRCBOT TROJAN!"
?Extranet AutoDialAutoExt.exeNortel Networks Contivity Extranet Switching Software
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
XFLooDNeTFLooDeR.exe"Added by the ENDOOL TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
XGLF Network Lan MonitorNPFMNTOR.exe"Added by the RBOT-AGY WORM!"
UGnetmousgnetmous.exe"Genius mouse driver - required if you use non-standard Windows driver features"
UGNETMOUSEgnetmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
UGuruNetGuruNet.exe"GuruNet lets you click on any word on your screen to get the relevant information you want"
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHomeland NetworkHomelandNetwork.exeHomeland Network Notifier - pops ads
UHornetMonitorMntrHrnt.exe"Hornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network"
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
?HP Network Registry Agenthpnra.exe"??"
UHughesNet Toolsmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
XICQICQNET.vbs"Added by the GORMLEZ-A WORM!"
XICQ Netwinlogon.exe"Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XICQNetwinlogon.exe"Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIEFeaturesInternetfeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
UIJNetworkScanUtilityCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
XINETinetsync.exe"Meplex adware"
XInet DataBaseInetdbs.exe"Added by the QEDS WORM!"
XInet Deliveryinetdl.exe"Inet Delivery adware"
XInet Deliveryinetdl_2.exe"Inet Delivery adware"
XInetapiNetapi.exe"Added by the NETDEVIL.14 TROJAN!"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
Uinetcntrlinetcntrl.exeBsafe Online - internet filter
?InetConfinetconf.exe"??"
UInetdINETD32.EXE"Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
Uinetinfo.exeinetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
Xinetinfomon managerinetinfomon.exe"Added by the DONBOMB.A TROJAN!"
Xinetmgrinetmgr.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XInternetInternet.exe"Added by the PWS-CS TROJAN!"
XInternetrecruit.exe"Added by the RBOT-AJG WORM!"
Xinternet[trojan filename].exe"Added by the MIFENG-D TROJAN!"
XInternetwinlogom.exe"Added by a variant of the SDBOT WORM!"
XInternetnteusodp.exe"Added by the RBOT-GFJ WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
Xinternetlsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XInternetalm7tas.exe"Added by a variant of the RBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet AntivirusIAvir.exe"Internet Antivirus rogue security software - not recommended
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
UInternet Call DirectorICD.EXE"TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
UInternet Call ManagerICM.EXE"Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Connection Wizardstisvsq.exe"EasySearch adware"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Content PublisherICP.EXE"Added by the RBOT-UD WORM!"
UInternet Disk CleanerCLEARH~1.EXE"""Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
UInternet Download Acceleratorida.exe"Internet Download Accelerator download manager"
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Exploreriexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet ExplorerIExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorerhttp.exe"Added as part of a new potential CWS infection
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet ExplorerIEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
XInternet Explorertwain.exe"Added by the AGENT.BEA TROJAN!"
XInternet Explorer Agentiexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
UInternet History EraserHERASER.exe"Internet History Eraser - deletes your browsing tracks"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Mail and Newsmsqdevl.exe"EasySearch adware"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Optimizeroptimize.exe"Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInternet Security 2010IS2010.exe"Internet Security 2010 rogue security software - not recommended
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet SendMore log.exeUnidentfied adware
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
YInternet Sharing Serveriss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
XInternet Suspentionstory.exe"Added by the WOOTBOT.HV WORM!"
NInternet SweeperSweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
UInternet TimerITIMER.exe"Shareware dial-up connection call cost calculator from Ratsoft"
XInternet Washer Proiw.exe"Internet Washer manages temporary browser files
XInternet.exeInternet.exe"Added by the MAGICCALL VIRUS!"
Xinternet.exeyinyin3345.vbs"Added by the YINI MACRO!"
XInternet2 Optimizerwkfix.exe"Added by a variant of the RBOT WORM!"
NInternetCallsInternetCalls.exe"InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetExplorer32iexplore32.exe"Added by the RBOT-GRA WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
XInternetShieldInternetShield.exe"InternetShield rogue security software - not recommended
UInternetSpyInternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
XInternetWasherProiw.exe"Internet Washer manages temporary browser files
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInternet_Explorer.exeInternet_Explorer.exe"Added by the BANKER-END TROJAN!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
XIntranetintranet.exe"Added by the CHIMOZ.AC TROJAN!"
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
XIpNetworkipnetwork.exeMaxifiles adware
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
XISSinet.exe"Meplex adware"
NIusagenetdet.exe"Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up"
UJv16pt Network Residentjv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
XKinofilmoff.NetReklamer.exe"Added by the AGENT-NGX TROJAN!"
XL0adersfaxneti.exe"Added by a variant of the SDBOT TROJAN!"
Xlnternet ExplorerAMSNDMGR.EXE"Added by the KWBOT.R WORM! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Xload32netda.exe"Added by the NIBU.E TROJAN!"
Xload=inetinfo.exe"Added by the PROXY-GG TROJAN!"
XLocal Area NetworkOpenGL.exe"Added by a variant of the RBOT WORM!"
XLocal Internet ConnectionLIC.exe"Added by the SDBOT-YA WORM!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XMachineTestCMagesta.exe"Added by the SDBOT-NE WORM!"
UMaxtorOneTouchOneTouch.exe"Maxtor OneTouch Hard Drives/OneTouch Family hard disk backup software"
UMBNetmbnet.exeMBNet (Portugal) Credit Card Processing software
Xmcafee Software Intrenetmcafee.exe"Added by the RBOT-ATR WORM! Note - this is not a valid McAfee program"
XMedia PlayerSysnet.exe"BANKER.MW spyware"
XMessenger Protocolnetsender.exe"Added by the SDBOT-ACC WORM!"
XMicrcoft UpdatInternet.exe"Added by the RBOT-ANA WORM!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoftinternetdat.exe"Added by the RBOT.ETY BACKDOOR!"
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllernlc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft .NET Confinguratormsnconf.exe"Added by an unidentified VIRUS
UMicrosoft Broadband NetworkingMSBNTray.exeMicrosoft Broadband Networking Tray Application
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
XMicrosoft Informationsecurenet.exe"Added by the SDBOT.AJM WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internetwindows32.exe"Added by the SDBOT-F WORM!"
XMicrosoft Internetwincfg16.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Internet Acceleration Utilityiau.exe"EasySearch adware"
XMicrosoft Internet Acceleration Utility[path to file]"Added by the AGENT-CX TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Internet Dumping Protocolinetdump.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Internet Firewallfirewall.exe"Added by the IRCBOT.MD BACKDOOR! Located in %System%"
XMicrosoft Internet Firewall ManagerGMT16.exe"Added by the RANDEX.AT WORM!"
XMicrosoft Internet Firewall Updateupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft Internet Syncinginetsync.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicrosoft Netviewgesfm32.exe"Added by the RANDEX.C WORM!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Networkmsnet.exe"Added by the MOCKBOT.A WORM!"
XMicrosoft NetworkNetworksystem.exe"Added by the SDBOT-AAI WORM!"
XMicrosoft Network Daemon for Win32Netd32.exe"Added by the SDBOT.R TROJAN!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Network Neighbourhoodnetworknbh.exe"Added by the RBOT.DMN WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Networking Agent For SP2msnac32.exe"Added by the SPYBOT.PEN WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
XMicrosoft UpdateBotnet.exe"Added by the RBOT.AFL WORM!"
XMicrosoft Update 32network.exe"Added by the RBOT-ARZ WORM!"
XMicrosoft Update 32neta.exe"Added by the RBOT-AMI WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft xpsp2Networksystem.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftNetwork Daemon for Win32NETD32.EXE"Added by the RANDEX.F WORM!"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
XMilitary Net KillerMNK.exe"Added by the MILLNET-A WORM!"
NMirabilis ICQICQNet.exe"If connected to the internet
XMMicrosoft Security Managementinetforn.exe"Added by the RBOT.AFZ WORM!"
Umobile PhoneToolsmPhonetools.exe"Motorola Phone Tools"
UModemOnHoldnetWaiting.exe"NetWaiting/Modem-on-Hold - allows you to place your Internet connection on hold while you take a voice call (if Call Waiting is supported by your phone company). See here for more information"
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
XMovieNetworksMovieNetworks.exeMovieNetworks will connect you by a domestic premium rate telephone number 900-xxx-xxxx - so you get xxx rated pictures and junk and high internet costs. Remove the %ProgramFiles%\MovieNetworks directory
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
NMozilla Quick LaunchNetscp6.exeNetscape 6 and Mozilla browsers
XMPNetmpn.exe"Added by the DELBOT-W WORM!"
XMS Internet Executor 32MSIXEC32.exe"Added by the RBOT-AEQ WORM!"
XMS Internet ExploreMSIEx.exe"Added by a variant of the RBOT WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Network Controlmswin.exe"Added by the DUMBA TROJAN!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
XMSDRVNetFilter.exe"Added by the INTERRUPDATE TROJAN!"
XMsinetMsinet.exe"Added by the RBOT-AOA WORM!"
XMSNnetstats.exe"Added by the IRCBOT.UXP WORM!"
NMSN Internet Accesstrayclnt.exeQuick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards
XMSNETmsnet.exe"Added by the BOA WORM!"
XMSVersionINTERNETFEATURES.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMS_NETD_WIN32netd32.EXE"Added by the RANDEX.F WORM!"
UmyNetWatchmannwclient.exe"Sends your firewall alerts to a website
UN2PTrayNet2fone.exe"An Internet telephony application. Needed only if you have an account at Net2Phone
XNAVNet***.tmp [* = random digit]Unidentified adware
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNetWINREG.EXE"Added by the ASSASIN.D TROJAN!"
Xnetnet.net"Added by the MDROP-CIF TROJAN!"
UNet AcceleratorNetAccelerator.exe"Rizal NetAccelerator - ""Optimizing Dial-Up
UNet Activity Diagramnad.exe"Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs"
XNET Bios Statsntbstats.exe"Added by the SDBOT-ZX WORM!"
XNet Command Senternvscvse.exe"Added by the IRCBOT!DF6280E5 VIRUS!"
XNet CoNNAntispy.exe"Added by the AGOBOT.ALK WORM!"
XNET DEMONndemon.exe"Added by the AGOBOT-LA WORM!"
UNet iDiid.exe"""With the Net_iD program
XNET protection systemnetst.exe"Added by the RIZO.A TROJAN!"
XNet**.exe [* = random char]Net**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XNet**32.exe [* = random char]Net**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
NNet-It LauncherNILaunch.exe"Net-It - web publishing software"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
UNet4SwitchNet4Switch.exe"ASUS Net4Switch utility as provided on their range of notebooks - which ""helps users to quickly configure the notebook PC's network settings and easily switch between different network environments. A wizard guides users to create and edit configuration settings as well as diagnose problems in the settings for timely connection"""
Xnet64svhoster.exe"Added by the AGENT.JVF TROJAN!"
UNetAcceleratorNetAccel.exe"NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster
XNetAdm7NETADM7.EXE"Added by the BANCOS.F TROJAN!"
XNetapiNetapi.exe"Added by the NETDEVIL.14 TROJAN!"
Xnetapi32netapi32.exeAdded by an unidentified TROJAN!
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
NNetAppelNetAppel.exe"NetAppel - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UNetAssistantmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XNetbeansnetbeans.exe"Added by the DELBOT-R WORM!"
XNetbios Helpernbthlp.exe"Added by the BANKER.Y TROJAN!"
XNetBiosSrvcHPSrvPrt.exe"Added by the SDBOT-COL WORM!"
XNetBioy Clientnetbioy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
?NetBrowserNetBrowser.exe"Part of Best Network Security
?NetBrowser.exeNetBrowser.exe"Part of Best Network Security
Xnetcsvc.exe"Added by the VESLORUKI.DWK TROJAN!"
Xnetconfignetconfig.exe"Added by the NETWARE TROJAN!"
UNetCruiser DialerNCDialer.exe"NetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected
Xnetdaemonnetdaemon /v"Malware designed to ""kill"" a number of antispyware applications (SpyBot
Xnetdll32netdll32.exe"Added by the CRYPTER.A TROJAN!"
Xnetdllexnetdllex.Exe"Added by the CRYPTER.A TROJAN!"
XNetDyVisualGuard.exe"Added by the NETSKY.N or NETSKY.W WORMS!"
XNETFP32.EXENETFP32.EXEAdded by the AGENT.CD TROJAN!
?netfxupdatenetfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
UNETGEAR WG111T Smart Wizardwlan111t.exe"Configuration utility for the Netgear WG111T multi-rate Wireless USB 2.0 Adapter that ""provides wireless access to your desktop or notebook PC through the computer's USB port"""
UNetGuardNetGuard.exeFBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor
Xnethost.exe[path to file]"Added by the PERDA-J TROJAN!"
UNetlimiterNetlimiter.exe"Netlimiter - ""An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."""
NNetline Usernetchk.exe"Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game
XNetLinknetlink32.exe"Added by the GAOBOT.WO WORM!"
XNetLogonuserint.exe"Added by the SDBOT-BC WORM!"
UNetManageImportnmcpdata.exe"NetManage business software related"
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
UNetMeterNetMeter.exe"""Net Meter is a small
XNetMeterNielsenOnline.exe"NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited
UNetMeterHooNetMeter.exe"""Net Meter is a powerful and easy-to-use bandwidth meter. It monitors traffic of all network connections and displays real-time graphical and numerical data transfer rates. Net Meter can display details of multiple network connections at the same time. It records all network traffic and includes extensive logging (daily
XNetMonnetmon.exe"Added by the MIMAIL.M WORM!"
Xnetmondllcache.exe"Added by the BCKDR-RAA TROJAN!"
XNetmonwNetmonw.exe"Added by the BDOOR-FX BACKDOOR!"
Unetmsgnetmsg.exe"Net_Message is a small tool to send messages across the network
UNetOnHoldFTNOHMgr.EXE"""FaxTalk NetOnHold 1.5 works with the Modem-On-Hold capabilities found in V.92 modems to provide the ability to place an Internet connection ""on hold"" and receive incoming calls or place outgoing calls"""
UNetPanelStarter.exe"Gemius surveillance software. Uninstall this software unless you put it there yourself"
UNetPatrolwinclient.exe"NetPatrol network monitoring software"
Xnetpc32.exenetpc32.exe"Malware
NNetPerSecNetPerSec.exe"
NNetPumperNetPumperIEProxy.exe"NetPumper download manager - bundles Cydoor and SaveNow adware
XNetReachnrcheck.exe"Added by an unidentified VIRUS
XNetropa Internet ReceiverNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
UNetRunNetRun.exe"NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected
UNetscapeInstallService.exeRelated to Netscape installation
NNetscape MessengerNETSCAPE.EXE"In Netscape 6 (I know for sure with 6.2.1
NNetscp6Netscp6.exeNetscape 6
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNetServicentsvc.exe"Added by the QQPASS-DU TROJAN!"
Xnetservicesrecall.exe"Added by the WOOTBOT.D WORM!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
UNetShow Powerpoint HelperNSPPTHLP.EXE"If disabled
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
NNetStat LiveNsl.exe"AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data"
XNetSurfageAssureGDC.exe"NetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
Xnetsv32netsv32.exe"Added by the SDBOT-PX WORM!"
Xnetsv32sv.exe"Added by the DELF.CCD TROJAN!"
YNettGain2000WgwMngr.exe"Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution
YNettGain2000 VerifierNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speed
UNetTimeNETTIME.EXE"From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols
XNettordinateurGDC.exe"Nettordinateur rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XNettoyeurDePCGDC.exe"NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UNetTurbonetturbo.exe"NetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled"
XNetunit32wunit32.exeAdded by an unidentified WORM or TROJAN!
Xnetupdate32netupdate32.exe"Added by the RBOT-GQZ WORM!"
Xnetviewnetview.exe"Added by the BIFROSE.L BACKDOOR!"
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
XNETVISIONPasse-partoutPasse-partout.exe"Added by the DIALCAR-M DIALER!"
Xnetwsvw.exe"Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware"
XNetWatch32netwatch.exe"Added by the MIMAIL.C WORM!"
NNetword Agentnwant33.exeAn interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs
XNetWorkcsrs.exe"Added by the AGOBOT.JJ WORM!"
XNetworknetwin.exe"Added by the SILLYFDC-CG WORM!"
XNetwork Accesswinssh.exe"Added by a variant of the SDBOT WORM!"
XNetwork AdministrationNAS.exe"Added by the ANTILAM.20.Q TROJAN!"
XNetwork Administration Servicersvc32.exe"Added by the RBOT.ABH WORM!"
UNetwork Associates Error Reporting ServiceTBMon.exeNetwork Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
XNetwork Connectionsinternat.exe"Added by the VB-ZD TROJAN!"
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
UNetWork Device SwitchNetDevSW.exeToshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
XNetwork Host Controller[path to trojan]"Added by the WHISPER TROJAN!"
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNetwork Host Service[random]32.exe"Added by the RBOT-BAB WORM!"
XNetwork manegersvchost.exe"Added by the AGENT.BX BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetwork Protocol Servicewuamgrd.exe"Added by the RBOT.EA WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Provisioning ServiceWinNPS.exeAdded by an unidentified WORM/TROJAN!
XNetwork Securitysecsvc.exe"Added by the RBOT-ALX WORM!"
XNetwork SecurityNSecurity.exe"Added by the IRCBOT.AAV WORM!"
XNetwork Security Guard**********.exe [* = random char]"CoolWebSearch parasite variant"
XNetwork Security Guard[path to trojan]"Added by the COLEM-A TROJAN!"
XNetwork Security XPnvsvc86.exe"Added by the RBOT-GUI WORM!"
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNetwork ServiceMccTrayApp.exeAdded by an unidentified WORM or TROJAN!
XNETWORK SERVICESVÑHOST.exe"Added by the DELF-EW BACKDOOR!"
XNetwork Service Managernetsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
XNETWORK.EXENETWORK.EXE"Added by the DELF-GM TROJAN!"
XNetworkAssociates Incinternet.exe"Added by the LOVGATE.AB WORM!"
XNetworkClientNetworkClient.exe"Added by the LEMUR WORM!"
XNetworkKeynetkey.exe"Added by the IRCBOT-AJ TROJAN!"
XNetworks ConfiguratorNetConfs.exe"Added by the RBOT-OX WORM!"
XNetworks ControlerNetsis.exe"Added by the RBOT-NG WORM!"
NNetworkSetupdlink.exe"D-Link System Tray icon"
Xnetxsvx.exe"Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware"
Xnetzipsvzip.exe"Added by the DELF.ZWL TROJAN!"
XNetzip Smart Downloadernpnzdad.exeAdvertising spyware
NNetZIPFoldersnzfprop.exe"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL NewDotNetStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL NewDotNetStartup"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"Installer for the WinAntiSpyware 2005 rogue spyware remover - not recommended
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"Installer for the WinAntiSpyware 2006 rogue spyware remover - not recommended
XNI.UWFX5UWFX5NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0614UWFX5LP_0001_0614NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0715UWFX5LP_0001_0715NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0802UWFX5LP_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5LP_0001_0803UWFX5LP_0001_0803NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX5TUWFX5TNetInstaller.exe"Added by the DOWNLDR-BO TROJAN!"
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer 2006 web installer - ""foistware""
XNielsen NetRatingsinsight.exe"NetRatings Premeter spyware"
UNliaClientNetpia.exe"Netpia NLIA System - ""In the existing Internet address system
Xnorten Software Intrenetnorten.pif"Added by the RBOT-AWA WORM!"
Xnstatnetstat.exeAdult content dialler
Xnternet Exploreriexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Yntl NetguardRPS.exe"ntl Netguard - anti-virus a package of services
XNvCplScannetstat32.exe"Added by the SDBOT.BRL WORM!"
UNvPvrNetMonNvPvrNetMon.exe"Network monitor for the Personal Video Recorder function of the NVIDIA ForceWare Multimedia application - ""makes sure you don't miss your favorite show. If you won't be home to watch the show
NOne Touch MonitorOneTouchMonitor.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOne Touch MonitorONETOU~2.EXEFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOneTouch MonitorOneTouchMon.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOneTouchMonitorOneTouchMonitor.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOneTouchMonitor1tou~2.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOneTouchMonitorONETOU~2.EXEFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NONETOU~2OneTouchMonitor.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NONETOU~21tou~2.exeFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NONETOU~2ONETOU~2.EXEFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
NOnlineTimeonlinetime.exe"OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs"
XOptimum OnlineNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity
NOptusNet Desktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
UOptusNetUsageOptusNet Usage Meter.exe"Designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit
NOvernetOvernet.exe"Overnet peer-to-peer (P2P) file sharing program"
NP2P NETWORKINGP2P Networking.exePeer to Peer (P2P) sharing of files on the internet
NP2P NetworkingP2PPeer to Peer (P2P) sharing of files on the internet
Xp2p networkingp2pnetworking.exe"Added by the RBOT-ECP WORM!"
XP2P Networking2P2P Networking2.exeP2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately
NP2P Networking3P2P Networking3.exe"P2P Networking
Xp2pnetworkp2pnetwork.exe"Added by the ALCAN.A WORM!"
Xp2pnetworkingp2pnetworking.exe"Added by the RBOT-AFL WORM!"
Xp2snetiscomippwa.exe"Added by the SPAMTOO-AL TROJAN!"
XPalNetawarepnetaware.exePalTalk adware - as included in Morpheus
NPaltalkNetaware.exePALNETAW~1.EXEVoice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start → Programs. Delete the shortcut in Start → Programs → StartUp as well otherwise it will be reinstated
XPanda Software Intrenetpanda.pif"Added by the RBOT-ATZ WORM!"
XPcSecureNetPcSecureNet.exe"PcSecureNet rogue security software - not recommended
UPdaNet DesktopPdaNetPC.exe"PdaNet from June Fabrics Technology Inc. Use Windows Mobile Smartphone or PocketPC Phone as wireless modem for your PC"
NPicasaNetHello.exe"Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs
XPrivateNet[various filenames]Premium rate adult content dialler
?Prodigy DSLEnterNetDUN.Exe"Prodigy EnterNet DUN PPPoE Client - is it required?"
XProtectionNorton Internet Security.exe"Added by the ELITPER.E WORM!"
Xprunnet[path to trojan]"Added by the AGENT-HVB TROJAN!"
NPure Networks Port MagicPortAOL.exe"Pure Networks Port Magic
UQT4HPOTOneTouch.EXE"Supports the additional multimedia keys on HP/Compaq laptops which give single button press access to standard functions such as Mail
XRandom Interface Networkrst.exe"Added by the DELBOT-P WORM!"
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRaptelnetravspeger.exe"Added by the QQPASS-AA TROJAN!"
XRBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Serverglossary.exe"Added by the VANEBOT-J WORM!"
XReal Internet PlayerReaiplay.exe"Added by a variant of the SPYBOT WORM!"
Xrs32netrs32net.exe"Added by the AGENT-IFH TROJAN!"
XRSyncnetsync.exe"SafeSurfing adware"
Xruninetinfo.exe"Added by the BINGHE TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRundll32_8"rundll32.exe inetp60.dll DllRunServer"
XRuntt1Internet.exe"Added by the LINEAGE-Q TROJAN!"
USafetyNetipcTray.exe"Safety.Net from Netveda - ""offers Internet security
USafetyNet_NotifieripcLn.exe"Safety.Net from Netveda - ""offers Internet security
XSearchNet_UpServeUp.exe"SearchNet adware"
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
XServices Administratornetsvc.exe"Added by the DLOADER-NY TROJAN!"
XServices NetworkServices.exe"Added by the SWISYN-E WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XShell API32svcnet.exe"Added by the TIBICK.C WORM!"
Xskynetave.exeskynetave.exe"Added by the SASSER.D WORM!"
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
XSP2 Firewall/Internet Updatercrssrs.exe"Added by the RBOT.BJO WORM!"
XSpooler SubSystem Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
UStart Network Scanner ToolsdFTP.exe"Part of
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
Xsvchost Netware Managersvchost.exe"Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XSwimSuitNetworkSwimSuitNetwork.exeAdvertising spyware
YSymantec NetBackup Desktop AgentDLOClientu.exe"Part of Symantec's NetBackup backup software"
USymantec NetDriver MonitorSNDMon.exe"Part of Symantec's LiveUpate (eg
USymantec NetDriver WarningSNDWarn.exePart of Symantec Live Update - displays the warning when you need to update the firewall database
XSymmetrical Networksymmec.exe"Added by the DELBOT-N WORM!"
XSysnetsnuninst.exeUnidentified adware
Xsysnetsysnet.exe"CasClient adware - also detected as the CMAPP TROJAN!"
XSysteminetinfo.exe"Added by the PARDROP-A TROJAN!"
Xsystemsysnet.exe"Added by the VETOR-J WORM!"
XSystem Netsys32.exe"Added by the FORBOT-FX WORM!"
XSystem Net Databasesysnd.exe"Added by the RBOT-AAW WORM!"
XSystem Networkingsysnet.exe"Added by the RBOT.API WORM!"
XSystem Restoresvcnet.exe"Added by the TIBICK WORM!"
XSystem Update2wininet.exe"Added by the AUTOTROJ-C TROJAN!"
Xsystem32NeT-BoT.exe"Added by the AGOBOT-LJ WORM!"
XSystem64inet.exe"Added by the DENGLE-A TROJAN!"
XSystemMap32Netisp32.vbs"Added by the REDIST.C WORM!"
XSystemNetworkNETSERV.EXEAdded by the NETCONTROL VIRUS!
XSystemNetworksysnet.exe"Added by a variant of the RBOT WORM!"
XTcp Application Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XTCP Internet ServicesTCPSVC32.EXE"Added by the SPYBOT.X TROJAN!"
XTelnetTelnet.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate telnet.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
XTelnet24[random filename]"Added by the RBOT-ARD WORM!"
NTesco.net"rundll32 [path] RyDial.dll QuickStart"
XThe Ethernetethernet.exe"Added by a variant of the SDBOT WORM!"
XThe Ethernetintranet.exe"Added by a variant of the SDBOT WORM!"
XThe Intranetintranet.exe"Added by a variant of the SDBOT WORM!"
XTkNetDriver Monitorlexbce.exe"Added by the SDBOT-ADF WORM!"
XTmNetDriver Monitorexbce.exe"Added by the SDBOT-ABR WORM!"
XTopic lnternetlnternet32.exe"Added by the RBOT-GLZ WORM!"
UTrue Internet Color Iconinternetcolor.exe"Part of 3Deep® from E-Color (now superseded by 3DxWizzard™) - ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"""
XTurboNet[path to trojan]"Added by the RENOS-EA TROJAN!"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities
XVCMnet11VCMnet11.exe"Windows AFA Internet Enhancement - a browser hijacker
XVideo Processnetsvcs.exe"Added by the AGOBOT.LH WORM!"
Xvmnetdhcpvmnetdhcp.exe"Added by the DWNLDR-GTC TROJAN!"
Xvtmesysnetcxcfm.exe"Added by a variant of the RBOT-GNA WORM!"
Xvtmesysnetlprto.exe"Added by the RBOT-GNA WORM!"
XW3KNetwork"rundll32.exe w3knet.dll dllinitrun"
UWarnetwarnet.exeWarnet - system cleanup software
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
XWin Net Wks32netwks32.exe"Added by the RBOT.AA WORM!"
Xwin32 internet serverwinserver.exe"Added by the DERMON-D TROJAN!"
XWin32 Network Drivercrss.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWin32.Trojan.Downloadernetstat2.exe"Added by the PAINTER TROJAN!"
XWindeows NetStart Service2tesakrmger.exe"Added by the RBOT-AMY WORM!"
Xwindllwindotnetsrv.exe"Added by the AUTORUN-ANO WORM!"
UWindows & Internet Cleaner ProWICleaner.exe"Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
XWindows .Net Managerlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcman.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managertcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows .Net Managerwebsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows connection managerInternet.exe"Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one
XWindows Internet Browser Servicesinternet.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet128.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Browser Servicesinternet64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
XWindows Internet Managersvchost.exe"Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Internet Protocolwinproc32.exe"CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Internet Servicewininet.exe"Added by the RBOT-AUX WORM!"
XWindows Local Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows Net Cfgservice.exe"Added by a variant of the RBOT WORM!"
XWindows NetDDewrmana32.exe"Added by the MYTOB.IM WORM!"
XWindows NetsWinNET.exe"Added by the RBOT-MO WORM!"
XWindows NetStart ServicewinsN2S.exe"Added by the RBOT-ZX WORM!"
XWindows NetStart Service2winsN2S.exe"Added by the RBOT-ABN WORM!"
XWindows NetStart Service2winsN2SD.exe"Added by a variant of the RBOT WORM!"
XWindows Netsystem LayerNetsystem.exe"Added by the RBOT.BEI WORM!"
XWindows Network ControllerMqguard.exe"Added by the FORBOT-CL WORM!"
XWindows Network ControllerWinxPupd.exe"Added by the FORBOT-DK WORM!"
XWindows Network Controllerwinmms32.exe"Added by the FORBOT-ED WORM!"
XWindows Network Controllerwingmt.exe"Added by a variant of the SDBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Network Controllerwinmms32.exe.exe"Added by the FORBOT-ED WORM!"
XWindows Network Firewallfirewall.exe"Added by the POEBOT-J WORM! Located in %System%"
XWindows Network Logonnpesvc.exe"Added by the AGENT.ERZ TROJAN!"
XWindows Network Servicewinvc32.exe"Added by the RBOT.RY WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows Network ServiceRealteks.exe"Added by the RBOT-GTG WORM!"
XWindows Network Serviceswinnetwork.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork128.exe"Added by the SLENFBOT.J WORM!"
XWindows Network Serviceswinnetwork32.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Serviceswinnetwork64.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Network Sessionnspsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networkingwinsys32.exe"Added by the GAOBOT.FL WORM!"
XWindows Networking Monitormdm.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networking Monitorinxmdmx.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Networking Monitoringmdm.exe"Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XWindows Networksnetcog.exe"Added by the MYTOB.FH WORM!"
XWindows Offical Netvvorksmywriter32.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Service Managernetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows ServicesNetworkDriver32.exe"Added by the RBOT-ACR WORM!"
XWindows ServicesNetworkDrivers.exe"Added by the SDBOT-YO WORM!"
XWindows System ConfigurationWinNeth.exe"Added by the RETHE-A WORM!"
XWindows System Configurationnether.exe"Added by the OPANKI-AB WORM!"
XWindows Telnet Serverwintel.exe"Added by the AGOBOT-MW WORM!"
XWindows Updateinetinf.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XWindows Update Filesdnetc.exe"Added by an unidentified VIRUS
XWindows Web Servicesnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XWindows32 Net Databasemsnd32.exe"Added by the RBOT-AAL WORM!"
XWindowsRegKey%updateethernet32m.exe"Added by the RBOT-EN WORM!"
XWinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
Xwininetwininet.exe"Added by the STUBBOT-C WORM!"
Xwininet.dllregperf.exe"Added by the ZLOB TROJAN and variants!"
Xwininet32wininet32.exe"Added by the RAZNEW-A TROJAN!"
Xwininetdwininetd.exe"Added by the WINET TROJAN!"
Xwinnetwinnet.exe"CommonName Toolbar spyware. To uninstall see here"
XWinNetDDE[random characters].exe"Added by the NETDEPIX.B TROJAN!"
YWinPoetWinPPPoverEthernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
XWins Service Driverwinet.exe"Added by the RBOT-APV WORM!"
XWinSigNetXP.exe"Added by the BANKER-FN TROJAN!"
Xwinsock2netsvr.exe"Added by the AGOBOT.LY WORM!"
?WOOKITGestMaj.exe GestionnaireInternet.exe"Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
Xxload32netdd.exe"Added by the NETSPY TROJAN!"
Xxloadnetxloadnet.exeAdded by the VB.NCK TROJAN!
UXnet2xnet2.exe"Green Dam Youth Escort content control software. Internet filtering software that the Chinese government requires to be installed on all new computers sold in China after July 1
XXpp2pnetworking.exe"Added by the SDBOT.XA WORM!"
UxPlanetControlxPlanetControl.exe"Tool that displays a globe with current day/night zones and clouds on users desktop."
XXpnetNetXp.exe"Added by the BANCBAN-AT TROJAN!"
XYahoo!ethernet.exe"Added by the PROSTI.AA BACKDOOR!"
Nzdnetkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
XZenet"rundll32 CNBabe.dll DllStartup"
X[random name]netdde.exe"PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
X[various names]MsNetHelper.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_WinINetservices.exe"Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{52-28-8E-E8-ZN}thinksnet.exe"Zeno Think-Adz adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.