Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
Xpathex.exe"Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field"
XMSPF.EXE"Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
Xgbpm.exe"Added by the DLOADR.ZZD WORM! Note - has a blank entry under the Startup Item/Name field"
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
Mass""TelechipsUpatch.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
""[Ephemeral 2.4] by TreeHuggerX[path to worm]
""[Ephemeral 2.5] by TreeHuggerX[path to worm]
""[Ephemeral 2.x] by TreeHuggerX[path to worm]
X$sys$cmp$sys$xp.exe"Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
?%cmpmixtitle%%cmpmixstr%"Possibly related to C-Media Mixer Control panel?"
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
X%Temp%%Temp%delwdef2008.bat"WinDefender 2008 rogue privacy program - not recommended
X'AdwarePro''AdwarePro'.exe"AdWarePro rogue security software - not recommended"
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(*)Runwin32API.exe"Homepage hijacker
X(Default)NOTEPAD.exe"Added by the RUSTY WORM! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)syspol.exe"Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)"rundll32.exe [path to DLL file]Do98Work"
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.Progwinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X.protectedN/A"Smitfraud variant"
U0pit.exe"PrivateEye surveillance software. Uninstall this software unless you put it there yourself"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
Y00PCTFWFirewallGUI.exe"System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
N12Voip12Voip.exe"12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
?17779Proj2002N/A"??"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
U1Win32CfgKeyloggerpro.exe"Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!"
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
X2k6 updatzcrss3.exe"Added by the RBOT-CPD WORM!"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X360antiarp[path to trojan]"Added by the PASTA.AIB TROJAN!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
Y3capplnk3capplnk.exeUS Robotics Modem driver
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
X456655explorer.exe"Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X4wd!!!Natal!.pif"Added by the OPASERV.AI WORM!"
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X55278grepclient1.exe"Added by the LINEAGE-S TROJAN!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X7.61125E+16angpd.exe"ANG AntiVirus 09 rogue security software - not recommended
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
UA4ProxyA4Proxy.exe"Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites"
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
XAaepopar.exe"PurityScan/Clickspring adware"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAappadprot.exe"AdBlaster adware"
Xaaprotect[path to trojan]"Added by the BANCBAN-MJ TROJAN!"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAccessoriesPlusclockplus.exe"Clock Plus
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
UAcer eAP Launch ToolEAPLAU~1.EXE"Empowering Technology Launcher
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UAcer ePower ManagementePowerTray.exe"Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks. Also appears as the Packard Bell PowerSave power management utility included on some of their notebook models - as Packard Bell is now owned by Acer"
UAcer ePower ManagementePowerTrayLauncher.exeLauncher for the Acer® PowerSmart Manager power management utility included on some models in the Aspire range of notebooks
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
Nacpartagpart11.exeProgram for finding trucks on-line
XAcrobat Readacroup32.exe"Added by the VANBOT-BQ TROJAN!"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
XAcroreadGoogleUpdate.exe"Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp%"
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
UAd-Protectad-protect.exe"Ad-Protect spyware and spam monitoring tool"
NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
?addproxyaddproxy.exeRelated to Adobe Photoshop
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
Yadi CleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
Yadi DSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
Xadlhidppsncc32.exe"Added by the SLAPER.AI TROJAN!"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
XAdobe Filter Platformafilterplatform.exe"Added by the RBOT-OP WORM!"
XAdobe Flash PlayerAdobeFP.exe"Added by the AUTORUN-BBP WORM!"
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProupdt.exe"Added by the IRCBOT-VQ WORM!"
XAdobeReaderProrruxdkf.exe"Added by the RBOT.ADF BACKDOOR!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProlxlfsprrj.exe"Added by the RBOT.BDZ BACKDOOR!"
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderProsubset.exe"Added by the RBOT.OCU WORM!"
XAdobeReaderProwinini.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProrvdjlefr.exe"Added by the RBOT-CQZ WORM!"
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
XAdobeReaderProlssas.exe"Added by the RBOT-CLB WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProchkdisk.exe"Added by the RBOT-BDV WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
XAdobe_RLXccwap.exe"Added by the BCKDR-RCL TROJAN!"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
Xadpadp.exe"Spyware installed by Net2Phone
XAdPopupdcf5678.exe"Added by the AGENT-FZ TROJAN!"
Xadprotadprot.exe"AdBlaster adware"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
XAdvapiAdvapi.exe"Added by the NETDEVIL.12 WORM!"
XAdware PunisherAdwarePunisher.exe"Adware Punisher rogue spyware remover - not recommended
XAdware Punisher MonitorAdwarePunisher_monitor.exe"Adware Punisher rogue spyware remover - not recommended
XAdware SpyAdwareSpy.exe"AdwareSpy rogue adware remover - not recommended
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdwareProtectorAdwareProtector.exe"Part of rogue security tools
XAdwareSpyAdwareSpy4.exe"AdwareSpy rogue adware remover - not recommended
XAdware_ProNETAdware_Pro.exe"Adware Pro rogue security software - not recommended
XAdwarz Spy RemoverADWARZ.EXE"Added by the SPYBOT-EV WORM!"
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
UAEZBProcaptezbp.exe"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
Xagentppl.exe"Added by the DREF-U VIRUS!"
XAgent Explorer[random filename]Unidentified adware
?AgenteRemupd.exe"Part of an older version of Panda Antivirus. Is this an update reminder (guess because of the name)
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
Xagpagp32.exe"Added by the GAOBOT.SY WORM!"
Uahfpahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
Uahfprogahfp.exe"Advanced Hide Folders - ""is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others"". Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP"
XAhorreMemoriaSysRep.exe"AhorreMemoria rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XAHU[path to worm]"Added by the ANACON-B WORM!"
UAi Gear HelpGearHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi NapAiNap.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
?AidemHotKeyKEYAPP.EXE"Keyboard related"
Uaiepkaiepk2.exe"Another IE Popup Killer - pop-up stopper"
XAim Pluginaimplugin.exe"Added by the GUAP-F WORM!"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UAIMProaimpro.exe"AIM Pro - secure instant messaging
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
?Alcom PCL CaptureFMW_PCAP.EXE"??"
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
NAlienAutopsyTest_BS.exe"Alienware computer technical support software"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UallSnapallSnap.exe"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UALPassALPass.exe"ALPass password manager"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XAlphaAntalpha.exe"Alpha Antivirus rogue security software - not recommended
XAlphaAVAlphaAV.exe"Alpha Antivirus rogue security software - not recommended
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XALTER DATA[path] repcale.exe [path] beird.exe"Added by the IRCFLOOD.CD TROJAN! Both files are located in %System%\ccdew"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
UAMD PowerNow!GemBack.exe"
Yamd_dc_optamd_dc_opt.exe"
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
UAMO_Taskplaner.exeAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
NAnapod Manageranamgr.exe"Anapod Explorer from Red Chair Software ""is the most advanced Windows iPod® software available
YANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiKeepAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiKeep.exeAntiKeep.exe"AntiKeep rogue security software - not recommended
XAntiMalware_ProNETAntiMalware_Pro.exe"AntiMalware Pro rogue security software - not recommended
UAntiPopUpAntiPopUp.exe"AntiPopUp for IE - pop-up stopper"
XAntiSpionagepgs.exe"AntiSpionage
XAntiSpionagePropgs.exe"AntiSpionagePro
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiSpy2008AntiSpy2008.exe"Antispy 2008 rogue spyware remover - not recommended
XAntiSpyBossasb32.exe"AntiSpyBoss rogue security software - not recommended
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
XAntiSpyKitAntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.2AntiSpyKit 5.2.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.3AntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyMonAntiSpyMon.exe"Antispyware Protector rogue security software - not recommended"
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntispySpiderantispyspider.exe"AntiSpySpider rogue spyware remover - not recommended
XAntispyStormAntispyStorm.exe"AntispyStorm rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware ProAntiSpyware Pro.exe"AntiSpyware Pro 2009 rogue spyware remover - not recommended
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot rogue spyware remover - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntispywareDAntispywareD.exe"AntiSpywareDeluxe rogue security software - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiSpywareSuitepgs.exe"AntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare family"
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiSpyZoneAntiSpyZone.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.5AntiSpyZone 4.5.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.6AntiSpyZone 4.6.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.9AntiSpyZone 4.9.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.1AntiSpyZone 5.1.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.4AntiSpyZone 5.4.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiVer2008pgs.exe"AntiVer2008
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
Yaolavp.exe"AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory"
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UAOL Companioncompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
Xaolupdater.exeaolupdater.exe"Added by a variant of the IRCBOT TROJAN!"
YAPC UPS StatusDisplay.exe"APC PowerChute® Personal Edition status icon"
XAPcDefenderAPcDefender.exe"APcDefender rogue security software - not recommended
XAPCProtect.exeAPCProtect.exe"APCProtect rogue security software - not recommended
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
XAPD123APD123.exe"PacerD Media/Pacimedia.com adware"
Xaphexaphex.exe"Added by the IRCBOT-OH TROJAN!"
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XAPI32api32.exe"Added by the IRCBOT-B TROJAN!"
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
XAPIMonapimonx.exeAdded by the TIBSER.A downloader TROJAN!
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
UAPLAPL.exe"Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup
Xapmanager.exeapmanager.exe"AP Manager ransomware download manager - not recommended
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UApointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XApp.EXEName[path to worm]"Added by the BODIRU WORM!"
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
Xappis.exeappis.exe"Added by the AGENT-BC TROJAN!"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
NApplication LauncherApplication Launcher.exe"System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UAppPlusAppPlus.exe"AppPlus - ""menu bar or tray launcher that docks to your desktop
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
YApwheelApwheel.exeWheel support for an Alps mouse
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xaqadcup.exeaqadcup.exe"Added by the AGENT.BG WORM!"
XAqujyjax[path to file]"Added by the RANCK-CQ TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
XArman[path to worm]"Added by the IRCBOT-TG WORM!"
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINbelgium_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINuk_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
YAshampoo FireWallFireWall.exe"Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
YAshampoo FireWall PROFireWall.exe"Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
Xashcapservirsess.exe"SpySure spyware"
XashDip.exeashDip.exe"Added by the DROPR-CZ TROJAN!"
YashDispashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
XashDsp.exeashDsp.exe"Added by a variant of the SDBOT WORM!"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?AspireServiceAspireService.exe"Found on Acer laptops
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XASpyCASpyC.exe"AntiSpyCheck rogue spyware remover - not recommended
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
NASWDPASWDP.exe"MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
Xatf.exepgs.exe"Part of the PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
UATI 2D ComponentAti2mdxx.exe"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the ""U"" recommendation"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XAti Control Panelatiphexx.EXE"Added by the RBOT-BR WORM!"
XATI Cpanelatiphexx.exe"Added by the AGOBOT-NV WORM!"
UATI Desktop ComponentATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
XATI DisplayATIDisplay.exe"Added by the BDOOR-AFH BACKDOOR!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
NATI GART Set-up UtilityAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
UATI Launchpadlaunchpd.exe"Convenient way to start all your Multimedia Center applications (DVD
XATI Rage3d ProAtiRage4dPro.exe"Added by the AGOBOT-OG WORM!"
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XAtiCpanelatiphexx.exe"Added by the AGOBOT.IL WORM!"
Xaticpaxx.exeaticpaxx.exe"Added by the RBOT-XP WORM!"
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename
NAtiKeyatiptkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Control Panel → Display
XAtiPanelatip.exe"Added by the TACTSLAY.U TROJAN!"
Xatipatxxatipatxx.exe"Added by the SMALL-ED TROJAN!"
NATIPOLABati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
NATIPOLLati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
UAtiPTAAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UATIPTAATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
UAtiPTAAtiptaab.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UAtiPTAAAAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UAtiPTAAAATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
UatiptaxxAti2ptxx.exe"Control panel for the ATI series of video cards allowing access to such features as display resolution
UATIPTAXXATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
Xatiptextatiptext.exe"Added by the COSIAM-A TROJAN!"
UAtiQiPclAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
XatiupdateATIUPDATE5.EXE"Added by the DEBESKI.A TROJAN!"
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
XATIUpdateratiupdxx.exe"Added by the RBOT-ABX WORM!"
XAtiupdplatiupdpl.exe"Added by the SMALL.AOS TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
XATM Controladpn.exe"Added by the MMS.A WORM!"
XAtomic-x27CAtomicpartC.exe"Added by the KATOMIK-A WORM!"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAtxBrwIexplor.exe"""Pop Marketing"" adware"
YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
XAucompatAucompat.exe"Added by the GEMA TROJAN!"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
NAudioCommander ApplicationAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto updatSysDebug.exe"Added by the FORBOT-BA WORM!"
XAuto UpdateAUP.exeAdded by an unididentified WORM or TROJAN!
XAuto Updatedma.exe"Added by the RBOT-AVO WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
Xautoloadspooll.exe"Added by the SILLYFDC WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
Xautoloadspool.exe"Added by the AGENT-GSG TROJAN!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAutopdateAutopdate.exe"Added by the RBOT-AGL WORM!"
NAUTOPROPREGPROP.EXE WMPADDIN.DLL"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
Xautorepairdexs.exe"Added by a variant of the SDBOT WORM!"
UAutoroute SMTPAutoSmtp.exe"Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
NAutoSpellautospel.exe"AutoSpell - spell checker (version 6.*)"
NAutoSpell 5ASWATC32.EXE"AutoSpell - spell checker"
Nautoupdautoupd.exeRaxco Software auto update utility
Xautoupdautoupd.exe"Added by an unidentified VIRUS
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoUpdateraupdate.exe"Tinybar variant"
XAutoUpdaterAutoUpdate.exe"PeopleonPage foistware"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
Xautoupdatev2autoupdatev2.exe"Detected by Kaspersky as the AGENT.FQ TROJAN!"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
Yavast!ashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
Yavpavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavpavp.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
XAVP-SEavp-32.exe"Added by the AGOBOT.FS WORM!"
Xavpaavpo.exe"Added by the LEGMIR-ARK TROJAN!"
Yavpccavpcc.exe"Kaspersky Labs anti-virus"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
XAvpMAvpM.exe"Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in %Windir%\pchealth\UploadLB\Config"
Xavpmsavpms.exe"Added by the ONLINEGAMES.CPV TROJAN!"
XAvpravpr.exe"Added by the MYDOOM.AF WORM!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
XAVSeguropgs.exe"AVSeguro
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
Xavtapiavtapi.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
XAVupdate32 UpdateAVupdate32.exe"Added by the RBOT.CNI TROJAN!"
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
YAVWUpd32AVWUPD32.EXE"AntiVir® PersonalEdition Classic - updater"
Uawpliteawplite.exe"AllWallpapers Lite desktop wallpaper changer"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
XAXPDefenderAXPDefender.exe"Advanced XP Defender rogue security software - not recommended
XAXPFixerAXPFixer.exe"AdvancedXPFixer rogue security software - not recommended
XA_M_P_NETAntiMalwarePro.exe"AntiMalware Pro rogue security software - not recommended
?a_vpdvpd.exe"Located in an IBMTOOLS\VPD sub-directory. What does it do and is it required?"
NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
Xb3dUpdateZupdate.exe"Associated with B3d Projector foistware - see here"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
UBack2zipBack2zip.exe"Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
NBackpack UDFbpudfmon.exe"Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk"
Xbackup[path to worm]"Added by the AGOBOT-H WORM!"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackup Servicebackup.svcUnidentified adware
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackup4all OTB AgentB4AOTB.exe"""Backup4all is an award-winning data backup software for Windows. This backup utility was designed to protect your valuable data from partial or total loss by automating backup tasks
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
?BackupNotifybackupnotify.exe"HP Digital Imaging related. What does it do and is it required?"
UBACPI10bacpi10a.exe"Known as ""PowerKey"" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray"
XBand-Aid[path to file]"Added by the RANKY.O TROJAN!"
NBandwidth Meter ProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBandwidth Monitor ProBandwidth Monitor Pro.exe"Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP"
NBandwidthMeterProBandwidthMeterPro.exe"System Tray access to Bandwidth Meter Pro - ""an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"""
UBanpopup by PratikBanpopup.exeBanpopup - popup killer
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
XBastioneAntiviruspgs.exe"BastioneAntivirus
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
UBatLogEx"rundll32.exe [path] BatLogEx.DLLStartBattLog"
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
UBayMgrDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices
UBayswapbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
XBCPCbcpc.exe"BroadcastPC adware variant"
Xbcpc_cbcpc_c.exe"BroadcastPC adware variant"
NBCWipeTMbcwipetm.exe"BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
XBeegees Updatebeegees.exe"Added by the SDBOT-ADK WORM!"
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
NBelkin PCMCIA WLAN Monitormonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
XBestPopUpKillerBestPopupKiller.exe"Popup killer by Swanksoft - not recommended
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
XBeSys[path to file]"BeSys adware"
XBF4Pbf4p.exe"Added by the IRCBOT.GEN WORM!"
Xbfxtray[path to trojan]"Added by the AGENT-GEB TROJAN!"
NBHOCopBHOCop.exe"PC Magazine's
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
?BigDogPathVM_STI.EXE"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
UBigPond ToolbarbpumTray.exe"Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
NBigPondCablebpcable.exeTelstra Bigpond Cable login software - can be started manually
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
Xbin32hpuppstub.exe"PrecisionPop adware"
UBionix Wallpaper 5Bionix Wallpaper 5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionix Wallpaper 5beta.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBioniX Wallper.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
UBioniXWallpaperBionixWallpaper5.exe"BioniX Wallpaper Changer - ""the most advanced wallpaper changer/wallpaper manager software in the world"""
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
?BIOVCIPBIOVCIP.exe"??"
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
NBitWare Print Monitorbwprnmon.exe"FaxServe network fax software"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
NBlackBerryAutoUpdateRIMAutoUpdate.exe"Automatic updates for BlackBerry smartphones
NBlackICE PC Protectionblackice.exe"Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
NBlazeChangerFBZPaper.exe"Ember graphic file viewer
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockKeeperBlockKeeper.exe"BlockKeeper rogue security software - not recommended
XBlockProtector.exeBlockProtector.exe"BlockProtector rogue security software - not recommended
UBLOG"rundll32.exe [path] BatLogEx.DLLStartBattLog"
NBLSTAPPblstapp.exePuts access to Creative's BlasterControl in the System Tray
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBMNstrpmon.exe"Part of CleanPCTool
NBMupdateBMupdate.exe"Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xbootpd.exebootpd.exe"Added by the AGENT-DT TROJAN!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
Xboot_reg[path to file]"Added by the BANCBAN-CA TROJAN!"
XBortMedViruspgs.exe"BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Ubpcpost.exebpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XBPCV2BPCV2.exe"BroadcastPC adware"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
UBPKbpk.exe"Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
XBrasilBRASIL.PIF"Added by the OPASERV.E WORM!"
XBregbptre.exe"BroadcastPC adware variant"
XBridge"rundll32.exe [path] Bridge.dllLoad"
UBrmfRmPABrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-SpizaetusnorBtok.exe"Added by the RONTOKBRO.B WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
XBron-Spizaetuseksplorasi.exe"Added by the RONTOKBRO.J WORM!"
XBron-SpizaetusElnorB.exe"Added by the RONTOKBRO.D WORM!"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
XBron-SpizaetusRakyatKelaparan.exe"Added by the BRONTOK-J or BRONTOK-L WORMS!"
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
XBrowser Paladblck.exe"BrowserAid/BrowserPal foistware"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
Xbrwdiag[path to worm]"Added by the STRATIO-BN WORM!"
XBS Mediaplayerbsplyr.exe"Added by the RBOT-OU WORM!"
NBS Playerbsplayer.exe"BSplayer - A video player used to play avi
NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Nbsplayerbsplayer.exe"BSplayer - a video player used to play avi
XBT[path to trojan]"Added by the LITEBOT-B TROJAN!"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XBT00003*hiklmnop27.exe"Added by the VB-VT TROJAN where * = 2
Ubtbb_wcm_McciTrayAppMcciTrayApp.exe"System tray access to Motive's Broadband 2.0 configuration and repair utility"
UBTModemProtectionBTModemProtection.exe"BT Privacy Online modem protection software
UBTopenworldDialBTYahoo.exeBT Yahoo! internet connection manager
NBudgetSipBudgetSip.exe"BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
XBugsDestroyerSysRep.exe"BugsDestroyer rogue system error and cleaning utility - not recommended
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullguardoptInbulldownload.exe"Part of Bullguard antivirus"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
Nbwprnmon.exebwprnmon.exe"FaxServe network fax software"
Xbxproxybxproxy.exe"Added by the BXPROXY TROJAN!"
Xbxproxy[random].dll"SoftStop rogue security software - not recommended"
XC7[path to worm]"Added by the MEDIAKILL.A WORM!"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
XCacheLoader[path to trojan]"Added by the DLOADER-NZ TROJAN!"
UCacheSentry ProCacheSentry Pro.exe"""CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
UCaddais BackupOnDemandBODMon.exe"Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
UCalendarscopecs.exe"Calendarscope calendar software"
YCallBumpingcbpopw.exe"Related to the Gazel 128 PCI ISDN adapter. Required if you use it"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
?CameraApplicationLauncherCameraApplicationLaunchpadLauncher.exe"Supports the integrated webcam on IBM/Lenovo Thinkpad notebooks. What does it do and is it required?"
NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
?CamMonitorhpqcmon.exe"From HP and related to digital imaging"
UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
UCanonMyPrinterBJMyPrt.exePrinter software for Canon Bubblejet printers
?CAP3ONCAP3ONN.EXE"Canon driver
Ycapfasemcapfasem.exe"CA Personal Firewall - part of the CA Internet Security Suite"
NCapfaxcapfax.exe"PhoneTools fax software"
Ucapfupgradecapfupgrade.exe"CA Personal Firewall - part of the CA Internet Security Suite"
UCAPingCAPing.exeCitibank Citianywhere software
YCaponCapon.exeCanon printer driver
YCaponCaponn.exeCanon printer driver
XCaptcha7rundll captcha.dll"Added by the TINY.WRE TROJAN!"
XCaptionMgr32crssr.exe"Added by the ZAR.A WORM!"
Xcapturecapture.exe"Added by the THEEF-B TROJAN!"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
UCaptureAssistantCaptureAssistant.exe"Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text
NCaptureBatCapture.exe"!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways
NCarbonite BackupCarboniteUI.exe"""Carbonite's online backup service starts automatically and works quietly and continuously in the background protecting your data"""
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
Xcartao[path to file]"Added by the DLOADER-QD TROJAN!"
YccAppccApp.exe"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
XccApp[random filename]"Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus"
XccAppWMADZ.EXE"Added by the RBOT-LJ WORM!"
XccApp.EXE"Added by the RBOT-LJ WORM!"
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccAppexample.exe"TwoSeven spyware"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccApproutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XccAppsN/A"Added by the KANGAROO-A TROJAN!"
XccAppsccApps.exe"Added by the KANGAROO-B WORM!"
XccctpHistoryJMTi.exe"Added by the GANBATE.A WORM!"
XccDHCP32ccDHCP32.exe"Added by the AGOBOT-HJ WORM!"
XccHelpccHelp.hta"Searchq adware"
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XccpAppslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UccProxyCCPROXY.EXE"Part of Norton Internet Security
XccPrxy.execcPrxy.exe"Added by the SHIPUP-H WORM!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccUpdateccUpdate.exe"Added by the AGOBOT.YS WORM!"
UccUpdMgrccUpdMgr.exe"In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself!"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
XCdcompatCdcompat.exe"Added by the GEMA TROJAN!"
NCDInterceptorcdi.exeCD indexer for measuring the speed of CD players
Xcdmmslpoklpllsm.exe"Added by the TEDIJINI-A TROJAN!"
XCdnCtrcdnup.exe"CNNIC Update pest"
XCDSpeed.exeCDSpeed.exe"Added by the IRCBOT.AEX BACKDOOR!"
UCeEPOWERcepmtray.exe"Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed
XCekirge[path to worm]"Added by the KERGEZ.A WORM!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
?CEPAwsot.exe"??"
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
Ycfgintprcfgintpr.exe"Configuration Interpreter - part of Tiny Personal Firewall V4"
UcFosSpeedcFosSpeed.exe"cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly"
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YCharter High-Speed Security Suitefspex.exe"Charter High-Speed Security Suite - security software in collaboration with F-Secure"
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Xchcp.exechcp.exe"Added by the SDBOT.BMH BACKDOOR!"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
YCheckMsgPlus"MsgPlusH.dll VerifyInstallation"
XCheckWinPerfperfinfo.exe"Added by a variant of the IRCBOT TROJAN!"
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
Xchoperunlli32.exe"Added by the QQPASS-U TROJAN!"
NChristmas Music PlayerTTEST6.EXE"Christmas Music Player brings the music of the Christmas Holiday to your desktop"
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
XCinnabd Prompt32CmdPrompt32.pif"Added by the ASSIRAL-B WORM!"
XCirebonPunyaXXrocks.exe"Added by the BHARAT.A WORM!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
UClauerUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
?CleanRegPathCleanReg.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
UCleanTempCLEANT~1.EXE"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
UCleanTempCleanTemp.exe"CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory"
NCleanupONICTASK.EXE"Internet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet"
YCleanUpmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
YCleanUpCleanUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
?CleanupProgramcleanup.exe"Sony Vaio related - what does it do and is it required? Located in a C:\Sonysys folder"
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
UClient Access API Daemoncwbappcd.exe"IBM iSeries Client Access
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
XClient Agentipxwping.exe"Added by the PPDOOR-N TROJAN!"
XClient Agentphotes.exe"Added by the PPDOOR-P TROJAN!"
XClient Agent[path to file]"Added by the PPDOOR-J TROJAN!"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClient Updatewup.exe"Added by the OPANKI.O WORM!"
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xclipboard.execlipboard.exeAdded by an unidentified WORM or TROJAN!
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
Uclipdiaryclipdiary.exe"Clipdiary from Softvoile - ""Free Clipboard Manager for keeping the clipboard history"""
NClipMate5xClipMt5x.exe"Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
NClipmate6CLIPMT60.EXE"Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
NClipMate7ClipMate.exe"Clip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard"
NClipomaticClipomatic.exe"Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
NClipTrakClipTrak.exe"
NClipTrakkerClipTrakker.exe"Cliptrakker - clipboard extender"
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
UCLMFrontPanelclmpanel.exe"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
XClrSchLoader[path to file]"ClearSearch adware"
XCLSIDmsgplus.exeAdult content dialler
XCLSIDplugin.exeAdult content dialler
XCLSIDmsgplus.exePremium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
Xcls_pack.execls_pack.exe"Added by the Malware Defense rogue security software. Also detected as the FAKEAV-AQB TROJAN!"
UClUpdateClUpdate.exe"Automatic updates for the software supporting the Clau-ACCV and Clauer-idCAT digital certificate USB keys"
XCMAPPcmappclient.exe"CasClient adware - also detected as the CMAPP TROJAN!"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
XCmeUPDCMEupd.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
UCobian BackupcbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian BackupCobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10Cobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 10 InterfacecbInterface.exe"System Tray access to Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 6CobBU.exe"Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7CobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 ApplicationCobBU.exe"Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 7 Interfacecobui.exe"System Tray access to Cobian Backup 7 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 8Cobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 8 interfacecbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup 9Cobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitacbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup AmanitaCobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Black MooncbInterface.exe"System Tray access to Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
UCobian Backup Black MoonCobian.exe"Cobian Backup 8 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup BoletusCobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup Interface 6cobui.exe"System Tray access to Cobian Backup 6 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
?COEMsgDisplayCOEMsgDisplay.exe"Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?"
Xcof.updit[random filename]"Added by a variant of the SDBOT WORM!"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
NCOM-IPCOMIP.EXECOM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
Ucom.codeode.cactusspamfiltercactusspamfilter.exe"Cactus Spam - free easy-to-use spam blocker"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
Xcombop.execombop.exe"Added by the BOWFEED-A TROJAN!"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
XCommand Prompt32CmdPrompt32.pif"Added by the ASSIRAL.B WORM!"
YCommon ClientccApp.exe"Part of earlier versions of Norton AntiVirus - Auto-protect and E-mail check will not function without this"
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
UComodo FirewallCPF.exe"Comodo Firewall"
YCOMODO Firewall Procfp.exe"Comodo Firewall Pro"
UComodo Launch Pad TrayCLPTray.exe"System Tray access to LaunchPad as bundled with Comodo's freebie offerings such as Comodo Anti-Virus. Some allege that LaunchPad is impossible-to-uninstall adware
UCompanion Modulecompanion.exe"The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. ""Use the Companion to quickly get to your favourite features
XCompanionWizardcompwiz.exe"Part of WinAntiVirusPro 2007 rogue security software (and possibly others) - not recommended
UCompaq AlerterCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
NCompaq DMIcpqdmi.exeCompaq version of the Desktop Management Interface
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
UCompaq Knowledge Centersilent.exe & matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
UCompaq PK Daemoncpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use them
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
?CompaqHW Comp Managercpqhcm.exe"Running on a Compaq laptop - any ideas?"
NCompaqPrinTrayprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
NCompaqSystraycpqpscp.exeCompaq System Tray icon
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XCompliant[worm filename]"Added by the RBOT-LB WORM!"
XComPlus Applicationstwain.exe"Added by the AGENT.AQO TROJAN!"
UComproRemoteComproRemote.exe"VideoMate TV tuner and capture card - remote control driver"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
UCompuSpyCompuSpy.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
Xcon[path to trojan]"Added by the BRAVE-A TROJAN!"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfiguration Loadedwupdated.exe"Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration LoaderWinHelper.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwump.exe"Added by the AGOBOT-BU BACKDOOR!"
XConfiguration Loaderupdate.exe"Added by the SDBOT-OS WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
XConfiguration32 Loader32winamp32.exe"Added by the SDBOT-BIC WORM!"
XConnect2Partyconnect2party.exeAdult content dialler
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTAUTrayAppCONNECTAUTrayApp.exe"System Tray access to change update settings for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
UConnection KeeperConKeepM.exe"""Connection Keeper is an invaluable time-saving tool for dial-up users. This free program simulates Internet browsing (at a random interval) to prevent your connection from appearing idle
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"cmd32.exe internat.dllLoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"[path to executable] internat.dllLoadKeyboardProfile"
XControlPanel"popcorn.exe internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlPanel"twink64.exe internat.dllLoadKeyboardProfile"
UCookie Cop 2CookieCop.exe"
UCookie PalCPBRWTCH.EXE"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
UCookiePatrolCookiePatrol.exe"CookiePatrol - cookie interceptor stopping spyware cookies that used to be part of PestPatrol before CA's aquisition"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NCoolwallpapercwm_tray.exe"Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers"
Xcoolwebprogramclrssn.exe"CoolWebSearch Smartsearch parasite variant"
NCopernic Desktop SearchDesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
UCopperheadrazerhid.exe"Razer Copperhead gaming mouse driver - required if you use the additional features and programmed keys/macros"
UCopy handlerCopy Handler.exe"Copy Handler lets you copy between hard disks
NCopyrightmwcpyrt.exeDisplays copyright information on IBM ThinkPads
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
NCorel Photo DownloaderMediaDetect.exe"Related to Corel Photo Album"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
UCostAwareniIPCApp.exe"NetInternals CostAware - download quota measuring tool"
NCountry Selectpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
NCountrySelectionpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
?Coupon Offers??"??"
Xcouponicacouponica.exe"Adware - see here"
?CPCopyProtectionNotifier.exe"Related to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition"
UCP32NOTCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
UCP4HPOTOneTouch.EXE"Supports the additional multimedia keys on HP/Compaq laptops which give single button press access to standard functions such as Mail
NCP888M1CP888M1.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
Xcpanelwinlogin32.exe"Added by the RBOT-FOY WORM!"
UCPATR10CPATR10.EXE"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba
UCPBrWtchCPBrWtch.exe"Kookaburra Software's Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
YCPD_EXECPD.EXEFirewall bundled with McAfee VirusScan 6.*
Xcpldeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xcplmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xcpls_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xcplbrowse.exe"Added by the TACTSLAY.C TROJAN!"
NCplBTQ00CplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
UCPLDFL10CPLDFL10.EXEPart of the EzButton feature on some Toshiba (and maybe others) laptops which support additional buttons
Xcpntmgcwincomp.exe"Added by the WINTRIM.A TROJAN!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Xcpntmgcnavpmc.exe"Added by the SIMCSS TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
?CPortPatchcppatch.exe"CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?"
Xcppc[path to trojan]"Added by the VB-NV BACKDOOR!"
YCPQAcDcCPQAcDc.exeCompaq PowerCon power management software for laptops
UCPQAlertCPQAlert.exe"Compaq's Insight Manager Agent - a tool that allows for ""fault
NCPQBootPerfDBCPQBootPerfDB.EXESee the entry for Compaq Message Server
YCPQCalibCPQCalib.exeCompaq PowerCon power management software for laptops
NCPQDFWAGCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
UCPQEASYACCcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UCPQEASYACCStartEAK.exe"Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Ucpqeauicpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Ucpqekkcpqek.exe"For Compaq PC's. Easy Access button support for the keyboard"
XCPQHotKeyshotkeysvc.exe"Added by the RBOT-XA WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
NCPQINKAGENTcpqinkag.exe"That is the Compaq Ink Agent for some inkjet printers
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
NCpqsetCpqset.exeDefault settings software in Hewlett Packard notebook
YCPQSTUTFIXstutfix.exe"For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton"
UCPQTEAMcpqteam.exeThis program is bundled with HP servers. When loaded a system tray icon will be available that launches the HP Network Configuration Tool
XcprcprAdroar.com adware downloader
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCPU Idlecpuidlexp.exe"Added by the AGOBOT-BW WORM!"
UCpu Level Up helpCpuLevelUpHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
XCPU Managercpumgr.exe"Added by the PANDEM.B WORM!"
UCPU Power MonitorCpuPowerMonitor.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme). Associated with the ""Energy Saving"" feature of AI Gear - which ""is a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features."" Part of AI Suite"
XCPU Temp Controlwuitgurd.exe"Added by the RBOT-AHV WORM!"
XCPU Watcher"rundll32.exe cpu.dllload"
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
UCPUcoolCpucool.exeProgram to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
NCPUMonCPUMon.exe"""CPUMon continuously displays the updated system statistics in a floating window as well as in system tray area"""
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
Xcpythidep.exe"Added by the MIRJACK-A TROJAN!"
Xcqlygworld_cup_.bat"Added by the WCUP.A WORM!"
?CQSCP2PSCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
XCritical Update Checkbattlenet.exe"Added by the DELF-LB TROJAN!"
NCriticalUpdateWucrtupd.exe"MS Windows Critical Update Notification. If you want to keep Windows up-to-date
XCriticalUpdatewucrtupd.exe"Added by the NOALA.B WORM! Note - this file is located in the Windows or Winnt folder
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XCRP386 Networkingcrp386.exe"Added by the IRCBOT.N TROJAN!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
XCrustydmcpl.exe"Added by the RUSTY WORM!"
Xcryptdlgcryptdlg.exeAdded by an unidentified TROJAN!
NCryptLoadRouterClient.exe"CryptLoad download manager"
Ucryptoexpertcexpert.exe"CryptoExpert from SecureAction Research. Advanced on the fly encryption system"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NcsaRemspqmdmui.exeCompaq modem country selection
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XCsimPlayerCsimPlayer.exe"Added by the KOOBFACE-AD WORM!"
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
UCTAPR2CTAPR2.exe"Console Launcher for the Creative Sound Blaster X-Fi series"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XctfmonWinUP.exe"Added by the BANKER-VV TROJAN!"
XCTFMON.CPLCTFM0N.CMD"Detected by Symantec as the SILLYFDC WORM! See here"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
Xcthelpcthelp.exe"Added by the SDBOT TROJAN!"
UCTHELPERCTHELPER.EXE"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers
XCTHelpercthelper.exe"Added by the RBOT-XB WORM! Note - do not confuse with the Creative application of the same name described here"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
NCTPerformanceUtilityCTPowUti.exe"Related to Creative PowerSysTrayApp. This program is a non-essential process
Xctpmonctpmon.exe"Registry Cleaner rogue - not recommended
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
?cttdpsrvcttdpsrv.exe"??"
XCTUpdatectupdclt.exe"Added by the RBOT-ABG WORM!"
NCTxfiHlpCTXFIHLP.EXEAdded by the installation of a Creative Labs X-Fi sound card. This particular process provides the help functionality for your card
XCtykd[path to file]"SMALL.SN spyware"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
NCursorXPCursorXP.exe"CursorXP from Stardock - tool for creating mouse cursors"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
Ncwbinhlpcwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ucwcptraycwcptray.exe"Related to ContentWatch Parental Control internet filter"
Ucwupdatecwupdate.exe"ContentProtect from ContentWatch - internet filter"
NCXMonHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
NCyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
UCyberPatrolNewcphq.exe"""CyberPatrol is one of the most powerful and popular client-based
XCydoorUpdateCD_Load.exe"Adware. Check here for information about Cy-Door and here for a program that can remove it"
NCyphTrayCyphTray.exe"Cypherus - encryption software"
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus G Wireless UtilityAirPlus.exe"D-Link AirPlus G wireless configuration and monitoring utility"
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
Xd3dupdate.exebbeagle.exe"Added by the BEAGLE.A WORM!"
Xd9fw5i91pd9fw5i91p.exe"Added by the AGENT-GIW BACKDOOR!"
Xdabrun"rundll32.exe dabapi.dllRundll32"
YDadAppdadapp.exe""DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required
NDAEMON Tools ProDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTProAgent.exe"System Tray access to an older version of DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDaily Plannerdayplan.exe"Daily Planner - discontinued
NDapDAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XData Protectiondatprot.exe"Data Protection rogue security software - not recommended
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
XData789Regedit.exe ....data789.tmpHomepage hijacker
XDATABASE MySql[path] repcale.exe [path] beird.exe"Added by the RANDON-AL WORM! Both files are often located in %System%\qsws"
UDataKeeperDataKeeper.exe"PowerQuest DataKeeper (now owned by Symantec) backup software"
XDAupdateDAupdate.exeNavEnhance adware
XDbgHlp32DbgHlp32.exe"Added by the WINKO.AO WORM!"
XDC6dc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDC6_checkdc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
Xddeprocddeproc.exe"Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
UddhelperW815DM.EXE"Enuff Parental Control Software by Akrontech"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft
XDealHelperBrwsrdhbrwsr.exe"DealHelper adware"
XDealHelperDowndownload.exe"DealHelper adware"
XDealHelperUpdateDHUpdt.exe"DealHelper adware"
XDebuggerexplorer32dbg.exe"Added by the CWS-M TROJAN!"
XDebuggeriexplore_dbg.exe"Added by the CWS-M TROJAN!"
Xdebuggerhelp.pif"Added by the DELF-DRA WORM!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefault_default.pif"Added by the RUBBLE-C WORM!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDefault_Page_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefault_Search_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefendAPcDefendAPc.exe"DefendAPc rogue security software - not recommended
Xdefender[path to trojan]"Added by the VB-BAQ TROJAN!"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
UDell PanelMgrSSMMgr.exe"Monitors ink levels
UDell Photo AIO Printer 922dlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 942dlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 962dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor
YDellAutomatedPCTuneUpPTAgnt.exe"PC TuneUp from Dell - ""silently monitors your system
UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
UDellSupportCentersprtcmd.exe /P DellSupportCenter"Dell Support Center (provided by SupportSoft
Xdelsaapdelsaap.exe"NCase adware"
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
UDeltaIITaskbarAppDeltaIITray.exe"System Tray access to the Delta Control Panel for the M-Audio Delta series of PCI audio cards"
?DelTmpDelTemp.exe"Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?"
XDELXP Protocoldelxp.exe"Added by a variant of the SDBOT WORM!"
XDepassxXfsa.exe"Added by the SDBOT-SK WORM!"
UDepFrezfrzstate.exe"Deep Freeze from Faronics Coporation. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
?desk-top-servicedesk-top-service.exe"??"
XDeskMateAutoUpdateDeskMateAutoUpdate.exe"DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related"
UDeskSaver ProDeskSaver.exe"DeskSaver Pro from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". Includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
UDeskSpacedeskspace.exe"DeskSpace desktop management utility from Otaku Software Pty Ltd - which ""gives you more space for your windows and icons. You can eliminate desktop clutter by arranging your windows and icons across up to six desktops
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
Xdesktopdesktop.exe"Added by the SDBOT.MD WORM!"
XDesktopDesktop.com"Added by the VB-DRN WORM!"
Xdesktopdesktop.ini.vbs"IE-Title malware"
NDesktop ArchitectDATRAY.EXE"Desktop theme manager available
YDesktop ArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktop CalendarDesktop Calendar.exe"Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
UDesktop iCalendarCalendar.exe"Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather
UDesktop iCalendarDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendarDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop iCalendar LiteDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar Lite.exeDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar.exeDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop Maestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktop Maestro Vista TrayRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
XDesktop Searchdesktop.exe"iSearch adware"
XDesktop Security 2010Desktop Security 2010.exe"Desktop Security 2010 rogue security software - not recommended
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
NDesktop WeatherTHE WEATHER CHANNEL.exe"Desktop Weather by The Weather Channel - provides current temperature
NDesktop Weather 3THE WEATHER CHANNEL.exe"Desktop Weather 3 by The Weather Channel - provides current temperature
NDesktop Weather 3THEWEA~1.EXE"Desktop Weather 3 by The Weather Channel - provides current temperature
YDesktopArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktopIconToyDesktopIconToy.exe"""Desktop Icon Toy is an easy to use desktop icon enhancement tool
UDesktopMaestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktopMaestroRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
Ndesktopmgrdesktopmgr.exe"Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
UDesktopXDESKTOPX.EXE"A program that replaces the regular Desktop and Taskbar
Ndeskupdeskup.exeAdds Iomega Zip drive icons to the desktop
Udesp2kdesp2k.exe"Part of the Turbo Analyzer tool from LightComm Brazil Telecom that analyzes and corrects ADSL configurations"
UDetectorAppDetectorApp.exe"Related to Roxio MyDVD (was Sonic) DVD authoring software"
XDevelopment Environmentdevenv.exe"Added by the DELBOT-AH WORM!"
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
XDevicePathProyecto1.exe"Added by the GRUEL WORM!"
XDevicePathRoot.exe"Added by the GRUEL WORM!"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Xdfgfdgrergd[path to trojan]"Added by the RANKY.CK TROJAN!"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
Ydhcpagntdhcpagnt.exeIntel DSL modem driver - leave enabled or you'll have to re-install the drivers
XDhcpCepPYJJKIME.exe"Added by the AGENT-BXQ TROJAN!"
XDI2[path to file]"BroadcastPC adware"
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
NDialog HelperPDDLGHLP.EXE"Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs"
XDialUp Network ApplicationRnaap.exe"Added by a variant of the SDBOT WORM!"
XDiam prlaeroqedrhg.exe"Added by the SDBOT-DEU WORM!"
NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
YDigital Patrol Update 5update.exe"Digital Patrol - ""a powerful anti trojan scanner
XDigital Protectiondigprot.exe"Digital Protection rogue security software - not recommended
UDirect UpdateDUControl.exe"DirectUpdate dynamic DNS updater"
XDirect X Opengldxopengl.exe"Added by a variant of the RBOT-CJ WORM!"
YDirectory Opus Desktop Dblclkdopusrt.exe"Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor
XDirectXddhelp32.exe"Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
XdirectxSqlexploit.exe"Added by the SDBOT.D TROJAN!"
XdirectxPipeCmd.exe"Added by the SDBOT.D TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
XDisk KeeperSECURITY.EXE"Daosearch adware"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
XDiskRetterSysRep.exe"DiskRetter
UDiskSuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
XDispatcherdispatcher.exe"Added by the DLOADR-AS TROJAN!"
Xdispenterdispenter.exe"Added by the AGENT-MKK TROJAN!"
UdisplayThe_Eye.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
XDisplaybackup.exe"Added by the BRONTOK-CR WORM!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
NDisplay Settingshptasks.exe"Allows for the adjustment of the display for LCD screen
UDisplayFusionDisplayFusion.exe"DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much
NDisplayTrayIconTrayIcon.exe"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution
UDisspydisspy.exe"Disspy spyware detection and removal software"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
Xdjtopr1150.exedjtopr1150.exe"WebRebates adware"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
NDLHelperEXEWATCH.exeDownload helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
XDLHelperEXE.exeN/ADownloader for Microgaming/Casino software - stealth installed
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
XDllExecutable[path to file]"Added by the VB-SP WORM!"
Xdllhelpdllhelp.exe"Added by the STARTPAGE.DQ hijacker"
Xdllhelpdllhlp.exe"Added by the Downloader-HI TROJAN!"
Xdllhostxp.exedllhostxp.exeBrowser hijacker and adware downloader
XDLLUPDATE32dllupdate32.exe"Added by the AGOBOT.IA WORM!"
UDLPSPDLPSP.EXEDell laser printer status monitor
Xdlsp2mxdlsp2mx.exe"Added by the MPB-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""dlsp2mx"""
XDluxjpDluxjp.exe"Added by the DLUCA.D TROJAN!"
XDm Hrlpns.exe"Added by the IRCBOT.WORM.61673 WORM!"
NDMISLAPPDMISLAPP.exe"DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDNHelper32DNHlp32.exeAdded by an unidentified WORM or TROJAN!
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
NDocuMagix InitPWATCH.EXE"PaperMaster is an application for the PC designed to automate the process of organizing
XDoggy StyleMsPMSPSd.exe"Added by the SDBOT-AAP WORM!"
XDokterFixSysRep.exe"DokterFix
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
UDon't Panicdontpanicdemodp.exe"30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
UDon't Panic Pop-Up Stopperdpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
UDon't Panic!DP.EXE"Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
UDopusdopus.exe"Directory Opus - a file manager from GPSoft"
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
UDoubleDesktopdd.exe"""DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"""
Xdownhlp32.exe"Added by the DLOADER.BG TROJAN!"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownload PlusDownloadPlus.exe"DownloadPlus adware"
NDownloadAcceleratorDAP.EXE"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YDpAgentdpagent.exe"Part of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for example"
NDPAgntDPAgnt.exe"digitalPersona fingerprint scanner"
YDPASDPASNT.exe"DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
YDpcnavdpcnav.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
NDPConfigDPConfig.exe"Compuware DevPartner Studio Configuration Utility
Xdpcproxydpcproxy.exe"Added by the GOLDENP-A TROJAN!"
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
YDpcstartdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpidpi.exe"Delfin Media Viewer or ""Promulgate"" adware"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
Udpps2dpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
Xdpsdps.exe"SmartestSearch parasite - poses as a foistware
Ndptrackerdptracker.exe"CamTrack webcam software that enhances the way people video chat"
UDpUtilTEDTray.exe"Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device"
XdpzProtectn.vbe"Added by the RUNAUTO.H WORM!"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
NDrag'n'Drop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
?DragDropDragDrop.exe"??"
NDragnDrop_AutolaunchAutolaunch.exe"Iomega HotBurn - CD-RW burning software"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosessorplscd.exe"Added by the RBOT.CYA WORM!"
XDRam prosessorHWAPI.exe"Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRam rar procwinupdaterar.exe"Added by a variant of the IRCBOT TROJAN!"
XDRam rare procupdaterarwin.exe"Added by the RBOT-GQW WORM!"
XDRan posessorDAP.exe"Added by a variant of the SDBOT WORM!"
XDrAntispyDrAntispy.exe"DrAntiSpy rogue security software - not recommended"
?dregfixph_finder.exe"??"
Xdrin[path to trojan]"Added by the SMALL.DPB TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
XDRM Upgradedrmupgd.exe"Added by the IRCBOT.AWU BACKDOOR!"
XDrmupgdsDrmupgds.exe"Maxfiles adware"
XDropSpam Lifestyledslifestyle.exe"Dropspam adware"
XDrProtectionDrProtection.exe"DrProtection rogue security software - not recommended"
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDsidp-******.exeAdded by an unidentified adware where ****** are random characters
XDsidp-him.exe"Added by the MULTIDR-AH TROJAN!"
XDskcompatDskcompat.exe"Added by the GEMA TROJAN!"
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
NDSL Monitorspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
YDSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
Xdstiosysplsitctl.exe"Added by the MAILBOT-BX TROJAN!"
UDT 11Mbps WLAN PC Card StationDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT 11Mbps WLAN USB StationDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT HPWDTHtml.exe"HP My Display from HP. Rebranded version of Display Tune from Portrait Displays
UDualCoreCenterStartUpDualCoreCenter.exe"Unified control center for overclocking both the graphics card and the CPU
XDumpDump.exe"Added by the ZIMUSE WORM!"
Xdumprepspoolc.exe"Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
Xdumprepdump-k.exe"Added by the BUZUS-U WORM!"
Xdumprepdump.exe"Added by the CODOX-A WORM!"
Ndumprep 0 -kdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Ndumprep 0 -udumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
XDVD Upgradedvdupgd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XDvdcompatDvdcompat.exe"Added by the GEMA TROJAN!"
NDVDUpgradeDVDUpgrd.exe"Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
YDvp95Dvp95.exe"Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine"
Ydvpapi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
YDvpInitExeDvpinit.exe"Command Antivirus related"
YdvprptDvprpt.exe"Command Antivirus related"
NDW4DesktopWeather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW6DesktopWeather.exe"Desktop Weather 6 by The Weather Channel - provides current temperature
NDwlClientsupport.exeDownload manager for Dell support alerts
Xdwqblwppx.exe[random].exe"Okcashbackmall adware"
Xdwqblwpvl.exe[random].exe"Okcashbackmall adware"
UDWQueuedReportingdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
XDx8compatDx8compat.exe"Added by the GEMA TROJAN!"
NDXM6Patch_981116p_981116.exe"Win32 cabinet self extractor. More info here"
XDxupdate.exeDxupdate.exe"Added by the MAFEG WORM!"
XDyFuCAoptimize.exe"Adult content dialler - see here"
XDynamic DHCPdydhcp.exe"Added by the RINBOT.B TROJAN!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
XDynHttp Dns Binarydynizari.exe"Added by a variant of the RBOT WORM!"
XE-nrgyPlusE-nrgyPlus.exe"Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
NE6TaskPanelTaskPanl.exe"Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
UEanthologyAppEANTHO~1.EXE"eAcceleration Stop-Sign security software related. Previously not recommended
UEanthologyAppeanthology.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertsys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertEANTHO~1.EXE"eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted
Ueanth_system_patchersys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
NEapcisetupsbsetup.exeRockwell RipTide soundcard application software. Sound works without it
NEAPCISETUPwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
YEarthlink Protection Control Centerelnk_pcc.exe"EarthLink Protection Control Center - ""powerful
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
XEasySpywareCleanerEasySpywareCleaner.exe"EasySpywareCleaner rogue spyware remover - not recommended
UEasySync ProXCPCMenu.exe"""IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAutoDetect.exe"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
?ecpeECPE.EXE"??"
Xeditpadeditpad.exe"Added by the CONSPER-B TROJAN!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UEFI Job Monitor"[path] efjm.dllrun"
UEfpap.exeEfpap.exe"Easy File & Folder Protector. Deny access to certain files and folders
Xegikugunapolecy.exe"Added by the SDBOT.AOE WORM!"
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
UELBERTRicoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
UELBERT_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
UElectron MicroscopeEMIII.exe"Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
Xelitemediaelitemediapop.exe"Added by the LOWZONE-BB TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware"
XEliteProtectorEliteProtector.exe"EliteProtector rogue spyware remover - not recommended
XELNKProxysmproxy.exe"Surfmonkey adware"
YElsaCapiCtlRcapi.exe"Assumed to stand for Remote Common Application Programming Interface (RCAPI)
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
YEmail Protectionemlproxy.exe"AntiVirus Quick Heal - E-mail protection"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
Xempine121307.exe"Delfin Media Viewer adware related"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
?Empowering Technology LaunchereAPLauncher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
?EmpoweringTechnologyFramework.Launcher.exe"Part of Acer Empowering Technology. What does it do and is it required?"
?encapsulated command toolwintr.com"??"
UEncompass_ENCMONTRENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
XEnergyPlugInEnergyPlugin.exe"EnergyPlugin adware variant"
XEnh Win Updtenhupdt.exe"Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
NEnigmaPopupStopEnigmaPopupStop.exe"Part of Enigma SpyHunter - not recommended
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UEnterprise HarmonyrsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
UEnterra Icon KeeperIcnKeepr.exe"Icon Keeper - ""tool to save and restore icon positions on the desktop"""
YEnvyHFCPLEnMixCPL.exe"VIA Envy24 PCI Audio Controller driver"
UEOUAppEOUWiz.exeIntel ProSET Wireless related - provides additional configuration options for these devices
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPM-DMepm-dm.exe"Device Manager - part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UePowerManagementePM.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UePower_DMCePower_DMC.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles
UEPoXUSDMUSDM.EXE"EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
UePrompterePrompter.exe"ePrompter - E-mail notification software"
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Status Monitor 3E_[various].EXE"Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C45 SeriesE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C66 SeriesE_S4I0S2.EXE"Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status
UEPSON Stylus C67 SeriesE_FATIAAL.EXE"Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C87 SeriesE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3100E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status
UEPSON Stylus CX3200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5400E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo 2200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status
UEPSON Stylus Photo 825E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
UEpsonPhotoStarterEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this
XEptrnopdb.exeAdded by an unidentified WORM or TROJAN!
?EquipmenEquipmen.exe"??"
Xeraseplgeraseplg.exe"Added by the GENOME.AQUV TROJAN!"
XErrCleanSysRep.exe"ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XErreurChasseurSysRep.exe"ErreurChasseur
XErrorProtector Freeertmain.exe"ErrorProtector rogue system error and cleaning utility - not recommended"
XErrorRepairToolErrorRepairTool.exe"ErrorRepairTool rogue system error and cleaning utility - not recommended"
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
Xertyuoprttrwq.exe"Added by the AUTORUN-APA WORM!"
UERUNT AutoBackupAUTOBACK.EXE"ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots
YeSafe ProtectESPWatch.exe"eSafe from Aladdin - internet security for gateway and E-mail servers"
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
NESFTPesftp.exe"ESftp - FTP client for transfering files between a local PC and another remote computer"
UeSnipsClientGW.exe"eSnips Client Gateway from eSnips"
XEspecialDeneca.bat"Added by the DELUZ VIRUS!"
XEsphortu.exe"PurityScan adware"
NESPN BottomLinebline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop
?essapmessapm.exe"ESS Solo soundcard driver. Is it required?"
Yesspkesspk.exeESS Technology modem speaker driver file. Required to get on-line with this modem
UEssSpkPhoneessspk.exe"ESS Technologies Call waiting
?eSupIniteSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
Xethernetairftp.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
YeTrust EZ Firewallefpeadm.exe"eTrust EZ Firewall"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Reminderpmremind.exe"Event reminder for calendar dates
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEVGAPrecisionEVGAPrecision.exe"EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible
UEvtMgr6Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
NeWare StartupiWareStart.exe"eWare iWare task bar. Not required"
Yewido anti-spywareewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
Xewupdaterewupdater.exe"EasyWebSearch adware updater"
Xexample[random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
NExcite PlatformExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
?Excite Private Messenger Pipex8impipe.exe"??"
Xexe lptt01exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
?exmonhpimoniter.exe"Some kind of hp digital camera maybe or a photo smart connection probe?"
Xexp1orer.exeexp1orer.exe"Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename
XExpatch[random filename]"Added by the PWSLMIR-G TROJAN!"
Xexpcrt[random filename]"Added by a variant of the SLAPER TROJAN!"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
XexplerUpdadv.exe"Added by the QQPASS-N TROJAN!"
XExplkwexpup.exeKeywords hijacker
Xexplord.exeexplord.exe"Added by the DLOADR-AYW TROJAN!"
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreExplorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
Xexploreff.exeexploreff.exe"Added by the FINFANSE TROJAN!"
Xexplorep.exeexplorep.exe"Added by the LINEAG-I TROJAN!"
Uexplorerexplorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorershellexpl.exe"Added by the SHELDOR TROJAN!"
Xexplorerexpl32.exe"Added by the RATSOU TROJAN!"
XExplorer[path to worm]"Added by the AUTEX WORM!"
XExplorershellexp.exe"Added by the AGENT-ZY TROJAN!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XEXPLORERsys.exe"Added by the SILLYFDC-A TROJAN!"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
Xexplorerexplorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
XEXPLOREREXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
Xexplorerexplorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
XExplorer Loaderexplr32.exe"Added by the AGOBOT.N WORM!"
XExplorer Loaderexplorerl.exe"Added by the SDBOT-ADI WORM!"
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XExplorer32Expl32.exe"Added by the HACKTACK.B TROJAN!"
XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
XExplorerTaskexplorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
UExpress ClickYesClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt
XExternal DependenciesExternal.exe"Added by the MYTOB.EC WORM!"
?ExxtremeHelperDemonexxdemon.exe"Creative Exxtreme graphics card related?"
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
UEZEJMNAPEzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NezHelperezHelper.exe"Part of the ezPeer+ ezHelper music sharing program."
NEzPrintezprint.exe"Lexmark Fast Pics - helps users of their printers to enhance
YezPS_PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezPS_PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UEZSMART Appezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
YF-StopWF-StopW.exe"F-Prot anti-virus background scanner by F-Risk Software"
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
UFabrik Ultimate Backup Statusfabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink
XFaltCheckallps.exe"Added by the AGENT.RAP TROJAN!"
?fapmonfapmon.exe"Fair Access Policy monitor for DirecPC/DirecWay internet access"
NFastTrack AcceleratorSPEED UP.EXE"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop
UFatPipeDHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
UFatpipe Dialerfpdialer.exeDailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSearchSearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFCHelpFCHelp.exe"Added by either FCHelp adware or a variant of it"
XfddddHOMEdxxatp.exe"Added by the RANKY.AA TROJAN!"
XFdr Command Modulesp2.exe"Added by the SDBOT.WP WORM!"
UFD_SAPFD.exeReported to be the autopassword program from the Sony Microvault thumb drive
XFeCPYfecpy.exe"FlashEnhancer adware"
UFellowes ProxyR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
UFerrariWallPaperFerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
XFestplattenReinigerGDC.exe"FestplattenReiniger
Xff[path to worm]"Added by the RBOT-XL WORM!"
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XfGQEGqHOMEgwwgtp.exe"Added by the RANKY.J TROJAN!"
XFHPageshdochp.exe"Added by the WINHOUND TROJAN!"
XFhzepgyiHELLRAIDER.EXE"Added by the MINDCTRL.A BACKDOOR!"
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Protection Monitorfilemon.exe"Added by a variant of the RBOT WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFileFreedom_Pluginwtm.exe"FileFreedom peer-to-peer sharing program"
Nfilehippo.comUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
NFileHippo.com Update CheckerUpdateChecker.exe"Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
XFilterProgramGDC.exe"FilterProgram rogue privacy tool - not recommended
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
XFindHack[path to worm]"Added by the KELVIR-BA WORM!"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
?FireBox Control PanelFireBox.exe"Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
XFirefox Plugin Managerfirefoxpgm.exeAdded by the MSNPHOTO.E WORM!
UFirefox PreloaderFirefoxPreloader.exe"Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
YFirePodFIREPOD.EXE"Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFirewall PolicyMidiDef32.exe"Added by the PIEBOT-A TROJAN!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
UFirewallStartupFirewallstartup.exe"Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean
XFirst Home Pagehttp://find.naupoint.com"Naupoint browser hijacker"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFlaCPYflacpy.exe"FlashEnhancer adware"
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Player2[path to worm]"Added by the IRCBOT.PD WORM!"
NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
XFlash_Player_Installying.exe"Constructor VC2000 malware"
XFlenCPYflencpy.exe"FlashEnhancer adware"
UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
XFlnCPYflncpy.exe"FlashEnhancer adware"
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
Xflpsflps.vbs"Added by the BYRON WORM!"
Xflpycntlflpycntl.exe"Added by the CRYPTER.C TROJAN!"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
XFlyswatDesktopflydesk.exeAdvertising spyware
XFolderRaper[path to worm]"Added by the VB.GOZ WORM!"
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YFoolProoffpwinldr.exe"FoolProof Security PC security software from SmartStuff"
YFoolProofSweep??"Part of FoolProof Security PC security software from SmartStuff"
UFoul PXFoulPX.exe"Foul PX
YFP Loaderloadfp.exe"FoolProof Security - PC security software from SmartStuff"
Nfpassistfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
?FPWGMWZDFPWGMWZD.exe"??"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
NFrapsFRAPS.EXE"Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting
UFree Ram Optimizerfro.exe"Free Ram Optimizer monitors your memory
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
UFreeMem ProFMEMPRO.EXE"FreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
NFreePDF Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFreePDF_Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
UFreeRAM XPFreeRAM XP Pro *.exe"FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UFreeRAM XPFreeRAM XP Pro.exe"FreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
UFresh Desktopfreshdesktop.exe"Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XFriendlyTypeNamewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
UFRISK FP-SchedulerF-Sched.exe"Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
UFRITZ!webProtectFwebProt.exeFirewall included in FRITZ! ISP DSL software
NFromine WinPopupwinpopup.exeInstant Messenger program
?FSDPSRVFSDPSRV.exe"??"
Xfsdsft[path to backdoor]"Added by the RANKY.S BACKDOOR!"
Ufspfsp.exe"Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents"
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
XFtkCPYftkcpy.exe"FlashEnhancer adware"
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
XFTPGraberFTPGraber.exe"Added by the DLOADER-DT TROJAN!"
NFTPManagerFTPDM.exe"""Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another
UFtpqueueFtpsched.exe"Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
?FtpServer.exeFtpServer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
NFullAudioWMPImporter.exeUsed to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
Xga6pcwga6pcw.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
UGainwardTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Xgamepatcher.scr"Added by the PSW-ED TROJAN!"
NGame DeviceJOYUPDRV.EXEGenius game controller profile activator
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTB"Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
NGameSpotkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
UGazelDisplaygsyno.exe"BT Digital Access USB - Gazel ISDN installation System Tray icon"
YGBMPro7AgentGBMAgent.exe"Genie Backup Manager Pro 7 - backup software"
YGBSpaceManSpaceMan.exe"GreenBorder - secure your browsing activities on the internet"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
XGDAX[path to backdoor]"Added by the RANKY.K TROJAN!"
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XGetPack18GetPack18.exe"Internet Speed Monitor adware related - see example here"
XGetPack19GetPack19.exe"Internet Speed Monitor adware related - see example here"
XGetPack20GetPack20.exe"Internet Speed Monitor adware related - see example here"
XGetPack21GetPack21.exe"Internet Speed Monitor adware related - see example here"
XGetPack22GetPack22.exe"Internet Speed Monitor adware related"
XGetPack23GetPack23.exe"Internet Speed Monitor adware related"
XGetPack24GetPack24.exe"Internet Speed Monitor adware related - see example here"
XGetPack25GetPack25.exe"Internet Speed Monitor adware related"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
XGLF Network Lan MonitorNPFMNTOR.exe"Added by the RBOT-AGY WORM!"
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
XGoldenAntiSpypgs.exe"GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
UGoogle DesktopGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
UGoogle Desktop SearchGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
NGoogle Earth ViewerGOOGLEMAPS.EXE"Google Earth ""combines satellite imagery
UGoogle IME AutoupdaterGooglePinyinDaemon.exe"Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
NGoogle UpdateGoogleUpdate.exe"Update manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %AppData%\Google\Update"
XGoogle UpdateGoogleUpdate.exe"Added by the BUZUS.DBFM TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %System%"
NGoogle UpdaterGOOGLE~1.EXE"Downloads and installs updates for Google applications (Google Earth
NGoogle UpdaterGoogleUpdater.exe"Downloads and installs updates for Google applications (Google Earth
UGoogleDesktopGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
XGoogleUpdater3GoogleMapper.exe"Added by the ROUTROBOT WORM!"
Xgotnewupdate000.exegotnewupdate000.exe"Added by the FAKEAV-BGA TROJAN!"
UGoToMyPCg2svc.exe"ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
Xgovurarope"Rundll32.exe retasevo.dlls"
XGP Updatergpupdater.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XGPLv3[random name].dll"Vundo adware"
Xgpmcewindow.exe"Added by the VB.CK WORM!"
?gramdate2Stop.exe"??"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XGraphic Loaderntvdm32.exe"Added by a variant of the RBOT WORM!"
XGraphic Updateopenglx.exe"Added by the IRCBOT.AMU WORM!"
XGraphics_default.pif"Added by the AUTOSKY WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
UGravis Appawareloaderdbserver.exe"Looks like it's associated with Gravis game controllers and the Keyset Manager
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
UGroupWise PDA Connect - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - GrpWseAgnt.exe"GroupWise PDA Connect PDA synchronisation utility - from Novell"
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
NGrpConvgrpconv.exe"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
Xgshpzzgshp.vbsHomepage hi-jacker
?GsiFinal"rundll32 gspndll.dllpostInstall final"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XGStartupGMT.exe"Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
UGTVEpgGTVEpg.exe"Part of Got All Media - control your TV tuner and other utilities from your PC"
XGuard ProVH339.exe"Guard Pro rogue security software - not recommended
YGuardGui ApplicationGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
XGuardPcs.exeGuardPcs.exe"GuardPcs rogue security software - not recommended
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
Xgwizarpl.exe"Detected by F-Prot as W32/Downloader-Sml-based"
UGWMDMpiGWMDMpi.exe"Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information"
UH/PC Connection AgentWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XHackMuFptHackMuFpt.exe"Added by the SCLOG-AG TROJAN!"
Xhagentavp.exe"Added by the ""Herman Agent"" remote access TROJAN!"
UHaMFrontPanelhampanel.exe"Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget
UHandy Backup 3.9hbagent.exe"Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
XHanUpdatehanz.exe"Added by the RBOT-GLJ WORM!"
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
XHardware Profilehxdef.exe"Added by the LOVGATE.AB WORM!"
XHardware Profilehxdef.exe..."Added by the LOVGATE.Z WORM!"
XHataDuzelticisiSysRep.exe"HataDuzelticisi
XHATAPE[path to trojan]"Added by the BANKER-QF TROJAN!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
UHDAudDeckHDAudioCPL.exe"Vista control panel for VIA Vinyl HD Audio Codecs from VIA Technologies
?HDhelptbhdhelp.exe"Associated with Philips Edge series soundcards. Is it required?"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
?Helphelpext.exe"??"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XHelpWizardnil.exe"Added by the BANCOS-BCZ TROJAN!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
Xhelpctl.exehelpctl.exe"Added by the GASLIDE TROJAN!"
XHelpereschlp.exe"Added by the BLASTER.T WORM!"
XHELPERgreece_nm.exe"AsdPlug premium rate adult content dialer variant"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHELPERnew_zealand.exe"AsdPlug premium rate adult content dialer variant"
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
XHELPERcanada.exe"AsdPlug premium rate adult content dialer variant"
XHELPERfrance.exe"AsdPlug premium rate adult content dialer variant"
XHELPERtemp532.exe"AsdPlug premium rate adult content dialer variant"
Xhelper.dllrundll32.exe [path] helper.dll"CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XHelpExp.exeHelpExp.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
Xhelpohelpo.exe"Added by the BANLOA-BU TROJAN!"
Xhelpwhelpw.exeAdware downloader
YHEProtectHSockPE.exe"Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
XHewlett Packard Managerhpmanager.exe"Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
NHewlett Packard RecorderRemind32.exeHP multifunction registration
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Uhfxphfxp.exe"Hide Folders XP - hide your folders so only you can view them"
XhgkytwekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xhgqhp.exehgqhp.exe"Added by the FLUSH.F TROJAN!"
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
Xhhtnsnrnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
XHidup_SusahPembantu.exe"Added by the SILLYFDC.BDM WORM!"
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
YHighPoint ATA RAID Management Softwareraidman.exe"HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
UHijackThis startup scanHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
Xhimem.exe[path to worm]"Added by the STRATION-FW WORM!"
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
UHitwarePKLiteHITWAR~1.EXE"Hitware Popup Killer Lite"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHLcleanuphlsetup2.exe"LinkReplacer/FFinder adware"
XHLL Data Parameterhllcxpa.exe"Added by the RBOT.AFG WORM!"
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHML PowerSourcehmlsvc32.exe"Added by the SDBOT-XL WORM!"
XHMV PowerSourcehmusvc32.exe"Added by the SDBOT-YW WORM!"
?HomeCentre WakeUpLGWAKEUP.EXE"Associated with the no longer supported Xerox HomeCentre printer/scanner"
Xhomepage.monitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
UHondaHelperHondaHelper.exe"Part of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod® in you car"
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
Xhosthelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XHost Processmame.exe"Added by the RBOT-APO WORM!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?Hot Party 22hotpart22.exe"??"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
UHotkeyAppHotkeyApp.exe"Programmable keys on Acer
XHotKeysCmds[path to worm]"Added by the PAHATIA-A WORM!"
XHotPixhotpix.exeAdult content dialler
Xhotplughotplug.exe"Added by the SILLYDL TROJAN!"
UHotplughot_plug.exe"Related to the SiS_Hot_Plug_Application. Enables automated driver loading for hotpluggable devices. If this service is stopped
XHPmon.exe"Added by the SILLYFDC WORM!"
?hp 1000 firmwarefwdl.exe"HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?"
UHP AutoIndexerhppautoindexer.exe"Installed by HP multi-function printer driver software
NHP CD Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
NHP CD-DVDhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
NHP CD-Writerhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
Xhp centerBACKWEB-*****.exe"See here - ""messaging service that automatically sends you support information
Nhp center UIShadowBar.exe"User Interface for HP Center - see here"
NHP Component Managerhpcmpmgr.exe"Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
XHP DeskjetHP_DeskJet_500.exe"Added by the FORBOT-DA WORM!"
XHP Desktopccappms.exe"Added by the SDBOT-TG WORM!"
UHP Digital Imaging Monitorhpqtra08.exe"System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera
UHP Display Settingshpdisply.exe"Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
UHP Gaming Keyboardrazerhid.exeHP VoodooDNA Gaming Keyboard (powered by Razer) driver - required if you use the additional features and programmed keys/macros
UHP Health Check ScheduleHPHC_Scheduler.exeHP Health Check Scheduler from Hewlett-Packard
?HP IDSchedulerHPIDSCHD.exe"HP Instant Delivery Scheduler"
NHP Image Zone Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
NHP Info Express??"On HP PCs
UHP Instant Supportmatcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
NHP JetDiscoveryHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
NHP JetSpeed AutostartAUTOSTART.EXEAutostart executable for the old multiplayer game HP Jetspeed
UHP Laser Jet Directorhppdirector.exe"System Tray icon that opens various functions such as copy
?HP Network Registry Agenthpnra.exe"??"
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
NHP Parallel Port Testhppt.exeAssociated with a HP ScanJet scanner
XHP Photo ManagerHPPhotoManager.exe"Added by the SDBOT.AXU WORM!"
NHP Photosmart Premier Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
?HP Port Resolverhpbpro.exe"??"
NHP Precision Scanhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
NHP Presentation ReadyPresRdy.exeHP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
UHP RecordNow??"From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."""
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
UHP SchedIndexerhppschedindexer.exe"Installed by HP multi-function printer driver software
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
?hp Silent ServiceHpSrvUI.exe"HP related"
NHP Simple TraxHpcron.exeSupplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
NHP software updateHPWuSchd.exe"HP software updates. If a shortcut doesn't exist
NHP Statushpstatus.exeHP Printer Status and Alerts
?HP Status Serverhpboid.exe"Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?"
UHP TV NowHpTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
NHP Updates??"On HP PCs
?HP Visualize InitHpVisIni.exe"HP Visualize software related. What does it do and is it required?"
NHP-Aio FlightRemind32.exeHP multifunction registration
UHPADVISORHPAdvisor.exeHP Total Care Advisor - a suite of help and hardware check programs to help you check the health of your PCs
Nhpaiodevicehpodev07.exe"Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
NHPAIO_PrintFolderMgrhpoopm07.exe"Directly from HP: "This process has one purpose - detects if the device moves to a different port
UHPBootOpHPBootOp.exe"""HP Boot Optimizer intelligently and dynamically launches software during startup
Xhpcmdcmd.exe"Added by the ADCLICK-DS TROJAN!"
Nhpcmpmgrhpcmpmgr.exe"Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
UHPDAgentHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
Xhpdeskjethpdeskjet.exe"Added by the GENOME.AQUV TROJAN!"
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb11.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb12.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb13.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Nhpfschedhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Nhpgs2wndhpgs2wnd.exe"Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
UHpha1monHpha1mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHpha2monHpha2mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.1 to 3.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHpha3monHpha3mon.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.3.138 to 3.4.13 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon03hphmon03.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. Known to cause 100% CPU load in some cases. Only needed if you use this feature
UHPHmon04hphmon04.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 4.0 to 4.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
Uhphmon05hphmon05.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 5.0 to 5.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon06hphmon06.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 6.0 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
XHphomehphome.jsHomepage hijacker
NHPHUPD04hphupd04.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD05hphupd05.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD06hphupd06.exeHP software update checker and wizard launcher. Available via the Start menu
NHPHUPD07hphupd07.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD08hphupd08.exeHP software update checker and wizard launcher. Available via Start -> Programs
?hpjsiroutehpjsira.exe"Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2""
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
YHpLampHPLAMP.EXEHP Scanner Utility that controls your scanners light bulb. Needed if it's switched on
Uhplampchplampc.exeHP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
UHPLogiFinderhp_finder.exeHP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
UHpMmKbdHpMmKbd.exeHP's multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
UHPMVTrayHPMVTray.exe"HP Media Vault Networked Storage Device - System Tray management utility"
XHPNThpdll.exe"Malware downloader - detected by Kaspersky as the VB.KU TROJAN!"
Nhpodbliahpodblia.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Nhpoddt01.exeN/A"Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software
Uhpoddt01.exehpotdd01.exe"Detection of new imaging
Nhpodlb08hpodlb08.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Yhpppthpppt.exeRelated to the drivers for HP ScanJet scanners
YhppptaHPPPTA.exeHP parallel port driver for certain hardware
XHpPrinterhpserver.exe"Added by the CMJSPY-W TROJAN!"
NHPPROPTYHPPROPTY.EXE"HP LaserJet Toolbox"
UHPPWRSAVHPPWRSAV.EXE"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com
?hpqcmonhpqcmon.exe"From HP and related to digital imaging"
?hpqSRMonhpqSRMon.exe"Related to HP Digital Imaging products. What does it do and is it required?"
UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
?hpScannerFirstBootscannerfb.exe"HP scanner related"
XhpSdwxmarkGaddw.exe"Added by the SDBOT-RB WORM!"
Nhpsjbmgrhpsjbmgr.exe"HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup
NHPStarthpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Uhpsysdrvhpsysdrv.exe"This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP
Xhptoolshptools.exe"Added by a variant of the SDBOT WORM!"
Xhptoolsmicrosoft.exe"Added by a variant of the SDBOT WORM!"
NHPUProvenTactics.exe"Proven Internet Marketing software"
UhpWirelessAssistantHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsbolhpztsbol.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
NHP_dladlatray.exe"On HP PCs
XHP_runnerfront.exe"Added by the SILLYFDC WORM!"
Xhriiexpl0re.exe"Added by the DLOADER.MAQ TROJAN! Note the number ""0"" in the filename"
UHtinpdor.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
XHTML Help Systemhhs.pif"Added by the RBOT-ATB WORM!"
XHTML32 Help Systemhhs32.pif"Added by the RBOT-ATE WORM!"
UHTpatchhtpatch.exeHTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
XHtProtectAVprotect.exe"Added by the NETSKY.L WORM!"
XHTTP Tunneling Servermstunnel.exe"Added by the RBOT.EDL WORM!"
Xhttp://www.lienvandekelder.beLienVandeKelder.exe"Added by the MYTOB-AZ WORM!"
Xhttp://www.lienvandekelder.beLien Van de Kelder.exe"Added by the MYTOB-AP WORM and variants!"
Xhttp://www.lienvandekelder.beLien Vande Kelder.exe"Added by the MYTOB-AQ WORM!"
Xhttp://www.lienvandekelder.beLien vd Kelder.exe"Added by the MYTOB-M WORM!"
Xhttp://www.lienvandekelder.beLien.exe"Added by the MYTOB-CZ WORM!"
Xhttp://www.lienvandekelder.beLientjeuh.exe"Added by the MYTOB-P WORM!"
Xhttp://www.lienvandekelder.beLienVdK.exe"Added by the MYTOB-U WORM!"
Xhttp://www.lienvandekelder.beVan de Kelder Lien.exe"Added by the MYTOB-BF WORM!"
Xhttp://www.lienvandekelder.beWe Love Lien Van de Kelder.exe"Added by the MYTOB-CV WORM!"
Xhttp://www.lienvandekelder.comLien Van de Kelder.exe"Added by the MYTOB-EQ WORM!"
Xhttp://www.lienvandekelder.com/LienVandeKelder.exe"Added by the MYTOB-EO WORM!"
Xhttpdc_pan.exeAdded by a variant of the DELF-A TROJAN!
Xhttpddeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpdmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpds_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpdbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpddeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xhttps-sslhttps.exe"Added by the MOEGA.D WORM!"
XhuigeziSP00LSV.EXE"Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
XHwpsystem_wc.exe"Eziin adware"
UHWSetupHWSetup.exe hwSetUP"""Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS
Xhxadsec[path to trojan]"Added by the ADCLICK-AP TROJAN!"
UHydarVisionDesktopManagerdesk95.exe"ATI's HydraVision desktop management software
UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionDesktopManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UHydraVisionViewportviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionViewPortHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
XHyper Startinstantmsgrs.exe"Added by the RBOT-NH WORM!"
Yiamappiamapp.exe"AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago
?Iapiap.exe"Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about
XIASHLPRIASHLPR.EXE"Added by the OPASERV.T WORM!"
Xibin[path to trojan]"Added by the PERDA-C TROJAN!"
YIBM Password Managerpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
UIBM ThinkPad EasyEject Support ApplicationEzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NIBM ThinkPad EasyEject Tray UtilityEZEJTRAY.EXE"System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NIBM ThinkPad Tray UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
UIBM ThinkPad UtilityNPDTray.exeSystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
UIBM TrackPoint Accessibility Featurestp4ex.exe"Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound""
UIbmpmsvcibmpmsvc.exe"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn
?IBMPRCibmprc.exeIBM application - what does it do and is it required?
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
?IBMUltraBayHotSwapSoundIBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
YIBM_PWMGRpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
UIBWin Background processIBackground.exe"IBackup for Windows"
Xicccomp[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
YICFmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XICQ Center[path to worm]"Added by the RANDIN WORM!"
XICQ Hacking ProICQpro.exe"Added by a variant of the NETSPY TROJAN!"
NICQ Plusvplus.exe"ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
XIcqBetawebcamupdate.exeAdded by an unidentified TROJAN!
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Visualplscx.exe"Added by the RBOT-AYO WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
NIC_KEY_3spvic.exe"Instant Chess related"
UiDesktopidesktop.exe"Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
UIDriveE StartupIDrvieEStartup.exe"IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
XIDTemplatesIDTemplate.exe"Added by the BRONTOK-H WORM!"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIE Java Updateiejava.exe"Added by the AGENT-HD TROJAN!"
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XIE6porn.pif"Added by the RBOT-ATF WORM!"
XIEACCESStemp532.exe"AsdPlug premium rate adult content dialer variant"
XIEAgent update checkiewatch.exe"Added by the BOMKA TROJAN!"
XIECheckxpssl.exe"Added by the TIRBOT-E WORM!"
XIECheckmssvp.exe"Added by the TIRBOT-G WORM!"
XIEDriverxplore.exe"IeDriver adware variant"
XIEexplorer AUpdateIEexplore32.exe"Added by the RBOT-GRE WORM!"
XIehelpersyslaunch.exeOutwar adware downloader
XIELoader32iexplore32.exe"Added by the SPEX or SPEX.B WORMS!"
XIESetIExplorer.dll"Added by the PWS-BLUEDIT TROJAN!"
Xiesetupi.exeiesetupi.exe"Added by a variant of the RBOT WORM!"
Xiestartiexp1orer.exe"Added by the NEMOG.C TROJAN!"
XieupdateMCP****.exe [**** = random char]"Added by the ASOXY TROJAN!"
Xieupdatemcpdll32.exeAdware downloader trojan
Xieupdate[random filename]"Added by the AGENT-C BACKDOOR!"
Xieupdatesieupdates.exe"Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
XIEXPL0RERIEXPL0RER.EXE"Added by the AGOBOT-QL WORM!
Xiexploiexplor.exe"Added by the SIDEA TROJAN!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
XIexploitIexploit.html"Added by the INKER.B WORM!"
Xiexplor.exeiexplor.exe"Added by an unidentified WORM or TROJAN! See here"
XIexploreiexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIEXPLOREiexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIExploreIEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
XIEXPLOREIEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XiExplore Iniie4uini.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIEXPLORE.EXEgoot.exe"Added by the BIFROSE-C TROJAN!"
XIExplorerIexplor32.exe"Added by the BDOOR-BY BACKDOOR!"
XIExplorerIExplorer.EXE"Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
XIexplorerexplorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIexplorer.exeIexplorer.exe"Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
XiExpresseriexpresser.exe"Added by the SLENFBOT.AP WORM!"
Xifpipf.exe"Added by the CLAGGER-AG TROJAN!"
Xifperx[random filename]"Added by a variant of the SLAPER TROJAN!"
Xifperxxmliwvug.exe"Added by the SLAPER.U TROJAN!"
UIFSplash.exeIFSplash.exeI-FORCE driver for force feedback steering wheel
UIFXSPMGTifxspmgt.exe"Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer
Uigfxpersigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
?IglpbvIglpbv.exe"??"
XIGuardPc.exeIGuardPc.exe"IGuardPc rogue security software - not recommended
?iHP-100iHPDetect.exe"Drive Letter Searcher
XIinliptl.exe"PurityScan adware"
NiIWiperSystemwiper.exe"System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
YIJ75P2PSERVERIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
UIKLrundll32.exe [path] IKL.dll"IKL surveillance software. Uninstall this software unless you put it there yourself"
XiLLeGaLMplayer.exe"Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
XiLLeGaL.exeMplayer.exe"Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
XilortgdgkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XImage"rundll32 [path] [trojan filename]Install"
XImage Remote Playerssysvn.exe"Added by a variant of the IRCBOT BACKDOOR!"
XImagePathtaskbarmngr.exe"Added by the SDBOT-XB WORM!"
XIMAPIload.exe"Added by the DOWNDEL-A TROJAN!"
NiMarkup ClientiUtil.exe"Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
NImesh Auto Update??"Update check for the Imesh file sharing system. Turn the update off under ""options"""
Ximgit[path to file]"Added by the BANKER-EM TROJAN!"
UIMJPMIGIMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XIMJPMIG6.1HelpCat.exe"Added by the BESVERIT WORM!"
UIMJPMIG8.1IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XIMJPMIG8.2msime82.exe"Added by the VB-CYG WORM!"
XIMJPMIG8.2msime80.exe"Added by the VB-CYJ TROJAN!"
UIMOLIMOLApp.exe"IncrediMail for Office Outlook Add-On"
UImonitorPlguni.exe"Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection
Ximonitor[path to trojan]"Added by the IMONI-A TROJAN!"
XimPlayokimPlayok.exe"Added by the CUTWAIL TROJAN!"
XIMprocessIM-svr.EXE"IMNames adware"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
XIMwireimwireup.exe"SafeSurfing adware variant"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
XInetapiNetapi.exe"Added by the NETDEVIL.14 TROJAN!"
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XInfeStopInfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
XINFO DATAapc.exe"Added by the RANDON.B WORM!"
UInfoPenMSNInfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
?Infoplay.exeInfoplay.exe"Written by New Media Properties
XInformation Updateiu.exe"Detected by Kaspersky as the CENTIM.CH TROJAN!"
XInit[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XInitial Pageinstall.exeEasySearch browser hijack installer
YInoRPCInoRpc.exe"Associated with eTrust Antivirus/InoculateIT"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
NInstant Update Centerreminder.exe"Event reminder for calendar dates
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInstantPleasureXXXinstantpleasurexxx.exeAdult content dialler
NInstantTrayPCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
Xintdctrridctup20.exe"SafeSurfing adware variant"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
UIntel PDSpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
UIntel Product Number UtilityIntelProcNumUtility.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
NIntel PROSet Tray Iconpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
XIntel system toolhookdump.exe"Added by the SPYRE-H TROJAN!"
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
UIntelAPMClientamclient.exe"LANDesk® Management Suite software component"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
UIntelliPointpoint32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
UIntelliPointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
UIntellitypetype32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
XIntelprcAas3lovu.exe"Added by the SILLYFDC-CG WORM!"
UIntelProcNumUtilitycpunumber.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
XInterceptedSystem[path to worm]"Added by the ANACON-B WORM!"
XInternetnteusodp.exe"Added by the RBOT-GFJ WORM!"
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
XInternet Connection Wizard[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Content PublisherICP.EXE"Added by the RBOT-UD WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Exploreriexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet ExplorerIExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorerhttp.exe"Added as part of a new potential CWS infection
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet ExplorerIEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
XInternet Explorertwain.exe"Added by the AGENT.BEA TROJAN!"
XInternet Explorer Agentiexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Optimizeroptimize.exe"Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
XInternet Protocol Configuration Loaderipcl32.exe"Added by the SDBOT TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet Suspentionstory.exe"Added by the WOOTBOT.HV WORM!"
NInternet SweeperSweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
XInternet Washer Proiw.exe"Internet Washer manages temporary browser files
XInternet2 Optimizerwkfix.exe"Added by a variant of the RBOT WORM!"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetExplorer32iexplore32.exe"Added by the RBOT-GRA WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
UInternetSpyInternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
XInternetWasherProiw.exe"Internet Washer manages temporary browser files
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInternet_Explorer.exeInternet_Explorer.exe"Added by the BANKER-END TROJAN!"
NInterTrust Quick Startit_cpq~1.exe"InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
NInterVoipInterVoip.exe"InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
NIntroducing Media ManagerSPLASHA.EXE"MS Media Manager tour. Not required"
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
XIoadqmMedia Player.exe"Added by the HAWAWI WORM!"
Yiolo Personal FirewallioloFW.exe"iolo Personal Firewall"
UIomega Automatic Backupibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
UIomega Automatic Backup 1.0.1ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
NIomega Backup Schedulerdtiom98.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
UIomega ImIconXPimiconxp.exe"Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system
NIomega Startup OptionsIMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
XIPIP.EXE"Added by the AGOBOT-QO WORM!"
UIP Changer 2.0IPChanger.exe"IP Changer 2.0 from Plustech Inc - network configuration management tool"
XIP Packet Redirect Serviceipredirect.exe"Added by the FORBOT.SM WORM!"
XIP Stackipstack.exe"Added by the AGOBOT.CW WORM!"
XIP**.exe [* = random char]IP**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XIP**32.exe [* = random char]IP**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
NiPalmmon.exe"Installed with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded"
XIPC Connectionipcconn.exe"Added by the RBOT-AEG WORM!"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
Xipcfg.exeipcfg.exe"Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
XIpCtrlipcon32.exe"Added by an unidentified VIRUS
XIPFWipwf.exe"Added by the DLOADER-YF TROJAN!"
?IPHSendIPHSend.exe"AOL related. What does it do and is it required?"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
YIPinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XIPLog Securityiplogsec.exe"Added by the IRCBOT.GP BACKDOOR!"
?iPlusAgent2iAgent2.exe"Related to iriver portable media products. What does it do and is it required?"
Xipmon.exeipmon.exe"Added by the RECERV or R3C.B TROJANS!"
XIpNetworkipnetwork.exeMaxifiles adware
XIpnukerIpnuker.vbs"Added by the INKER.B WORM!"
NIPO3IP Operator 2005.exe"
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
XiPOD USB DriverIPODUSB.EXE"Added by a variant of the RBOT WORM!"
XiPod USB ServiceiPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
NiPodderiPodder.exe"iPodder (now known as Juice) - a free utility that ""allows you to select and download audio files from anywhere on the Internet to your desktop"". This entry is present if you choose the option to add it to the startup group during installation"
UiPodManageriPodManager.exe"Apple iPod® management software for the iPod® player - updates
?iPodWatcheriPodWatcher.exe"Associated with Apple's iPod® player. Detects when the iPod® is connected?"
Uipointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
NIPPDetectIPP4Detect.exe"Part of Presto! Mr.Photo - ""an ideal program for creating
Xipregipreg.exe"Added by the ZAGABAN-H TROJAN!"
?iPrint LPT Redirectornipplpte.exe"Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
NiPrint Trayiprntctl.exe"Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
UiProtectYouip.exe"iProtectYou - internet filtering/parental control and network monitoring software"
XipruniPY.exe"iProtectYou spyware"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XiPSec7ipsec7.exe"Added by the AGENT.AHVR TROJAN!"
UipsecdialerIPSECD~1.EXE"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
Uipsecdialeripsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
YIPSecMonIPSecMon.exe"Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
XIPTable ConfigurationWinipcfgs.exe"Added by a variant of the RBOT WORM!"
Niptrayiptray.exe"System Tray access to Intel Desktop Utilities - ""provides you with the means to monitor system temperatures
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
NIPWIPW.exe"Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time
Nipwusbipw.exe"Related to Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to ""make and receive free Internet calls on your regular phone"" whilst ""at the same time
Xipwfipwf.exe"Added by the SCHOEBERL TROJAN!"
XIpWinsipwins.exe"IPWins adware"
Xipxwshelipxwshel.exe"Added by the WAREZOV.DG WORM!"
Xipyjywoniz.exe"Added by the SDBOT.BQD WORM!"
UIRIS_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
UIRIS_XRX_S2PScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
NiRiver UpdaterUpdater.exe"Updates for the iRiver Music Manager - used with their digital music players"
?IRPMonitoritcnmon.exe"??"
XIrwftp[path to trojan]"Added by the BANCOS-AP TROJAN!"
Xirwftpiexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xirwftpftpmon.exe"Added by the BANCBAN-BO TROJAN!"
Xir_ftpir_ftp.exe"Added by the IRFTP TROJAN!"
Xir_ftpirwftp.exe"Added by the BANCOS.H TROJAN!"
XiSecurity applet"rundll32.exe iSecurity.cplSecurityMonitor"
UISHelphelp.exe"ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it"
YISLP2STAISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers
XISMPack5ISMPack5.exe"Internet Speed Monitor C adware related - see example here"
XISMPack6ISMPack6.exe"Internet Speed Monitor C adware related - see example here"
XISMPack7ISMPack7.exe"Internet Speed Monitor C adware"
XISMPack8ISMPack8.exe"Internet Speed Monitor C adware related - see example here"
YISP.COM High Speedslipgui.exe"User interface for Slipstream - internet acceleration through compression/decompression techniques
XISPSERVICEpsycho.exe"Added by the IRCFLOOD-O TROJAN!"
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
UiSpyNOWispynow.exe"iSpyNOW - remote monitoring and surveillance software"
NIsReminderISPopup.exe"Related to GuardWare iShield - this is the registration reminder for the trial version
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
YISTraypctsTray.exe"System Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools"
NISUSPMISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NISUSPM StartupISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NItsDeductiblePopUpItsDeductible.exe"ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
YiTunes HelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
XiTunes MusiciTunesHelper32.exe"Added by the SDBOT.CHK WORM!"
YiTunesHelperiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
Uitypeitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
NIVPServiceMgrivpsvmgr.exe"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as
UIW_Drop_Iconiwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
Xixploreixplore.exe"Added by the SDBOT-CY TROJAN!"
Xixploresixplores.exe"Added by the SDBOT-CE WORM!"
Xixproxy[path to trojan]"Added by the XORPIX-A TROJAN!"
XJava appletjavaup.exe"Added by the SDBOT-ACF WORM!"
XJava Applicationvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XJava Auto Updateujm.exe"Added by the SDBOT-ADH WORM!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XJava updatejavaqs.exe"Added by the SWARLEY.A WORM!"
XJava Updatekeeper.exe"Added by the AGENT-DIS TROJAN!"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJava Updatehostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
NJava(TM) Platform SE 6jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
NJava(TM) Platform SE 6 U*jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now. U* represents the update version
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
Xjava-pluginjavasctp.exe"Added by the VB.AMX TROJAN!"
XJavascriptjscript.exe"Added by the DELBOT-AD WORM!"
XJavaScript Debugging ServiceJsDbgMan.exe"Added by the DERDERO.E WORM!"
XJavaScriptMsxrsMsxrs.exe"Added by the VB.BL WORM!"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
XJavaUpdateSchedjusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
?Jessops Insert DetectInsDetect.exe"Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
YJetAdmin Discovery IndicatorHPJETDSC.EXE"HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry
YJMB36X ConfigureJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupJMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
UJMB36X IDE SetupxInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
Xjon315[path to trojan]"Added by the MAILBOT-BI TROJAN!"
Xjpgdiag[path to worm]"Added by the STRATION-AN WORM!"
Xjpupdjpupd.exe"Added by the DIALER.CM TROJAN!"
XJufualtwinxp2.exe"Added by the SDBOT-AAB WORM!"
XJuPojupos.exe"Added by the SDBOT-CAG WORM!"
Xjusched[path to trojan]"Added by the BANKER-BWR TROJAN!"
UJussDropUtilityJussDrop.exe"Related to DropShots Inc. A subscription based service for family to connect
NJustVoipJustVoip.exe"JustVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
Ujv16PT - Privacy ProtectorTask.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer
UJv16pt Network Residentjv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
Xjzvfvsqpcjzvfvsqpc.exe"Added by the AGENT-GWP BACKDOOR!"
XK2ps_full.taskK2ps_full.exe"Added by the JUNTADOR.K TROJAN!"
NK6CPU.EXEK6CPU.EXEAuthenticates CPU as K6 in system properties
UKalibumpKalibump.exe"Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy"
UKaren's Once-A-Day IIPTOAD.exe"""Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!"" Scheduler that lets you specify progams
UKASPOESpamTest.exe"Kaspersky Anti-Spam"
XKasper AntivirusKASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
YKaspersky Anti-HackerKAVPF.exe"Kaspersky Anti-Hacker personal firewall - no longer available"
YKaspersky Anti-Virus MonitorAvpM.exe"Kaspersky Anti-Virus Lite - no longer available"
XKaspersky AntivirusKasperskyAV.exe"Added by a variant of the RBOT WORM!"
XKaspersky Email Securityjavaupd.exe"Added by the SWARLEY.A WORM!"
Xkaspersky32kasperskyLabs32.exe"Added by the RBOT-GOT WORM!"
XKasperskyAvkaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus"
XKasperskyAVEngKasperskyaveng.exe"Added by the NETSKY.V WORM!"
Ykavavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YKAVPersonal50Kav.exe"Kaspersky Anti-Virus Personal 5.0"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
YKavPFWKavPFW.exe"KingSoft Personal Firewall"
NKAZAA[path] kpp.exe [path] kazaalite.kpp"System Tray access to later versions of the Kazaa Lite P2P file sharing utility - namely the K++ and Resurrection variants. Kazaa Lite is the unauthorized modification of the original Kazaa Media Desktop - with the malware removed"
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XKazaa lptt01kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
YKB926239"rundll32.exe apphelp.dll ShimFlushCache"
XKeepCopKeepCop.exe"KeepCop rogue security software - not recommended
XKeepCop.exeKeepCop.exe"KeepCop rogue security software - not recommended
UKerio VPN Clientkvpnclient.exe"Kerio VPN Client"
XKernelUpdate.exe"Added by the DELF-FN TROJAN!"
UKernel and Hardware Abstraction LayerKHALMNPR.EXE"Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
XKernel Faultsftphost.exe"Added by the RBOT.BHU WORM!"
Xkernel32dllguardpc.exe"Added by the FORBOT-CU WORM!"
Xkernel32sys.dllIEXPLORER.exe"Added by the RBOT-MK WORM!"
XKernel32_sysdampersysdamp.exe"Added by an unidentified WORM or TROJAN! See here"
Xkernel44.dll"taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
Nkernelfaultcheckdumprep 0 -k"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
Nkernelfaultcheckdumprep 0 -u"Used in connection with memory dumps - you can disable these by - right clicking on My Computer
XKernelFaultCheckptool32.exe"Added by the LEGMIR-BN TROJAN!"
XKernellAppscsrss.exe"Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""System"" subfolder"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XKernellAppssvshosti.exe"Added by the BANCBAN-V TROJAN!"
XKernellApps32smss.exe"Added by the BANCBAN-AN TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
XKernelRuntime[path to worm]"Added by the MYTOB-JO WORM!"
XKernel_checkwmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
Xkeysysxp.exe"Added by the BEAGLE.AB WORM!"
Xkeysys_xp.exe"Added by the BEAGLE.AC WORM!"
Xkeywinxp.exe"Added by the BEAGLE.AG WORM!"
Xkeyboard[path to trojan]"Added by the DLOADR-AOZ TROJAN!"
NKeyboard CustomizerTpKmapAp.exe"Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also
YKeyboard Preload CheckPreload.exeMillenium Multi-Function Keyboard driver
Ukeymapkeymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
Xkeymgrldr"rundll32 setupapi InstallHinfSection... keymgr3.inf"
UKeyPatrolKeyPatrol.exe"KeyPatrol - key logger detector using both behavioral and pattern-matching algorithms that used to be part of PestPatrol before CA's aquisition"
Ukeyplusplusstartk.exe"Key++ Invisible Spy Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
UKeyspan Digital Media RemoteKDMRdmn.exe"Remote control driver for Keyspan Digital Media Remote devices"
XKgjgrnnypbw.exe"Added by the QuickLinks/Forethought adware"
UKHALMNPRKHALMNPR.EXE"Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
UKill PopupKillPopup.exe"KillPopup - pop-up stopper"
Xkisspingy.exe"Added by a variant of the IRCBOT BACKDOOR! The file is located in a random subfolder of %ProgramFiles%"
XKIT3hpprintqueue.exe"Added by the ADCLICK-DS TROJAN!"
UKLogKeyspy.exe"KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!"
Xklop[path to file]"Added by the AGENT-WQ TROJAN!"
Xklop[random].tmp"Found with Trojan.Win32.StartPage.aw. Possibly a variant of the AGENT-WQ TROJAN!"
Uklprun32dll.exe"PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online"
Uklpexplorer.exe"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself!"
XKnowledgeBase GUIwppewafaj.exe"Added by the RBOT-GRZ WORM!"
UKN_PanelAppPanelApp.exe"KnowledgePanel online survey software"
NKodak Batch Transferpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
NKodak Picture Easy *.* Batch TransferPezDownload.exe"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
NKodak Picture Transfer Softwarepts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
NKodak Software Updaterbackweb*****.exe"Software updater for Kodak Easyshare digital cameras"
NKODAK Software UpdaterKodak Software Updater.exe"Software updater for Kodak Easyshare digital cameras"
YKPDrv4XPKPDrv4XP.exeMediaKey USB Keypad Driver
YKPFW32.EXEKPFW32.EXE"KingSoft Personal Firewall"
YKPFWSvc.EXEKPFWSvc.EXE"KingSoft Personal Firewall"
UKryptel Component StartKicker.exe"Kryptel encryption software"
YKTPWarektp.exeRelated to KTP Ware TSR Enhancements from ELANTECH
XKYM Control Settingsphqghum.exe"Added by the RBOT.BQD WORM!"
Xl44sys**iexplore"Added by the VBS.LIDO WORM - where ** is a number between 65 and 76"
XL4r1$$aL4r1$$a.pif"Added by the ASSIRAL-C WORM!"
ULaCie BackupLaCieBackup.exe"LaCie '1-Click' backup software for their range of mobile hard drives"
Xlameshit[path to trojan]"Added by the LOWZONE-H TROJAN!"
XLANdhcp.exe"Added by the RBOT-GYI WORM!"
Xlanbruplanbrup.exe"SafeSurfing adware"
NLancement rapide d'Adobe Readerreader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly. French version"
ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
XLanGuard[path to trojan]"Added by the DLOADER-VO TROJAN!"
ULANMessage ProLANMES~1.exe"LANMessage Pro - ""a powerful tool for communicating with other people on your office/home network"""
ULanSpeed2LanSpeed2.exeMonitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
?LanzarL2007[path] setup.exe"??"
ULaplink PDASync 3.0 - LtNts4NtsAgnt.exe"Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
ULaplink PDASync 3.1 - PocketPCAUTODE~1.EXE"Laplink PDASync for Windows Mobile Pocket PC - PDA synchronisation utility"
ULaplink PDASync 3.1 - ScheduleSyncScheduleSync.exe"Laplink PDASync for ScheduleSync - PDA synchronisation utility"
ULapLink schedulerLlsched.exeUtility that automatically performs file transfers as unattended background operations
XLaptop AccessSage.exe"Added by the SDBOT-NB WORM!"
XLaserJetspoolvs.exe"Added by the DLOADER.PFR TROJAN! This is not the file of the same name from older versions of MS Office - see the link for the location"
XLAsIAf32RePEAtLD.exe"Added by the REPEATLD WORM!"
ULaunAppLaunApp.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
NLaunch ApplicationLaunchApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
ULaunch PC Probe IIProbe2.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
NLaunch YahooPOPs! at Windows startupYAHOOPOPS.EXE"YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs"
ULaunchApLaunchAp.exe"Programmable keys on Acer
YLaunchAppAlaunch"Part of Acer eRecovery - ""a powerful utility that does away with the need for recovery disks provided by the manufacturer
NLaunchApplicationLaunchApplication.exe"System Tray access to Nokia PC Suite - which ""is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one."" This allows you (amongst other options) to backup your devices contents to your PC
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
YLCDPlayerLCDPlyer.exe"Related to SuperAdBlocker"
Nlcfeplcfep.exe"Tivoli 'TME' System Tray icon - ""'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"""
NLDMLogitechDesktopMessenger.exe"Installed with the software for Logitech products. Automatically checks for software upgrades and new products
UledpointerCNYHKey.exeChicony Electronics Multimedia Keyboard Hotkey Driver
ULENOVO.TPFNF6RTPFNF6R.exeSupports the Fn+F6 hotkey combination on IBM/Lenovo Thinkpad notebooks which mutes the microphone
XLetsRock[path to trojan]"Added by the RANKY.Y BACKDOOR!"
XLetum[path to worm]"Added by the LETUM.A WORM!"
XLexmark Printlexmark.exe"Added by a variant of the SPYBOT WORM! See here"
NLexmarkPrinTrayprintray.exeLexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
Xlexplorelexplore.exe"Added by the BROPIA WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Nlexppslexpps.exe"For Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC
NLG Intelligent Updateautoupdate.exe"Automatic update utility for LG Notebooks"
ULGODDFUfwupdate.exeAuto firmware update program for LG Electronics CD-ROM/DVD writer
ULgWDskTpLgWDskTp.exe"Logitech Wireless Desktop mouse and keyboard software. There is an icon for this program on the taskbar next to the clock"
Xli-speed****dlres.exeAdult web-dialler - **** is random
XLibreSystemSysRep.exe"LibreSystem
ULidPolicypwrschem.exeA utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery
XLife FireWall Update1FireWall-Update1.exe"Added by the RBOT-ARS WORM!"
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
?LifeCamLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
?LifeExpLifeExp.exe"Related to Microsoft's LifeCam series of webcams. What does it do and is it required?"
NLifeScape Media DetectorPicasaMediaDetector.exe"Media detector for Picasa's automatic photo organizer"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLimeWire On StartupLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
Xlimewirepro.exelimewirepro.exe"Added by the IRCBOT-WA WORM!"
XLimpetexplorer16.exe"Added by the RBOT-AJD WORM!"
NLine Speed Meter V3.0LineSpeedMeter.exe"LineSpeedMeter - detect the download and upload speed of your internet connection"
XLitebot[path to trojan]"Added by the LITEBOT-A TROJAN!"
XLive PC CareLP[random characters].exe"Live PC Care rogue security software - not recommended
XLive update monitorsrvany32.exe"Added by the AGOBOT.AFM WORM!"
Xlive update monitorumxlu32.exe"Added by the AGOBOT.ADK WORM!"
XLive-Helplmns.exe"Added by the RBOT-GHE WORM!"
XLiveAntispyLiveAntispy.exe"LiveAntispy rogue security software - not recommended
XLiveProtectLiveProtect.exe"System Live Protect rogue security software - not recommended
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
NLiveUpdateCopyer.exe"Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
Xlk3h1[path to file]"Added by the MOSUCK-G TROJAN!"
?LLMODCL2"rundll.exe setupx.dll InstallHinfSection ..LLMODCL2.INF"
ULManagerQtZpAcer.exeAcer Launch Manager - on Acer laptops it supports the dedicated multimedia buttons and allows users to configure their function. If the optional WLAN module and Bluetooth radio are installed the associated buttons can set their operating state
ULManagerHotkeyApp.exe"Programmable keys on Acer
ULManagerCPLBCL53.EXESystem Tray icon found on Acer Travelmate laptops that allow you control access to the Internet and email buttons and other computer configurations
XlMAPllMAPl.exe"Added by the AGOBOT-RE WORM!"
?lmpdpsrvlmpdpsrv.exe"Related to a Lexmark printer/scanner. Printer sharing server? Is it required?"
Xlnternet ExplorerAMSNDMGR.EXE"Added by the KWBOT.R WORM! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Xload[path to worm]"Added by the KELVIR.AI WORM!"
Xloadexplorer.exe"Added by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xloadctftpscr32.exe"Added by the AGENT-FPN TROJAN!"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
Uload=esspk.exe"Speakerphone capability through a soundcard for an ESS modem"
Nload=HPWHRC.EXELoads the Status Window software for the HP Laserjet printers
?load=WPSLOAD.EXE"Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk"
Yload=wpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 and LBP-460 parallel port laser printers (and maybe others)
Xload=Spoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xload=dapdll.exe"Added by the ATAK.E WORM!"
XLoadab1explorer.exe"Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XLoadDBackUpBcTool.exe"Added by the GIBE WORM!"
Xloaddr[path to trojan]"Added by the AGENT-DIY TROJAN!"
YLoadDvpApi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
XloaderWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XLoadersHeIp.exe"Added by the SDBOT-ADB WORM!"
XLoadingAgentZipLoader32.exe"Added by the OBLIVION TROJAN! This executable is one of the most common but there are more"
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMect1explorer.exe"Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XLoadPFWwmimgr.exe"Added by the QEDS-B WORM!"
XLoadPowerProfileASDAPI.EXE"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLoadPowerProfileRundll.exe powerprof.dll"Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
XLoadPowerProfilerundl.exe"Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
XLoadPowerProfileRundll32.exe"Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xloads.exesuploads.exe"Added by the AGENT-BZ TROJAN!"
XLoadServiceRest In Peace"Added by the KANGAROO-A WORM!"
XLoadSIPS"rundll32.exe SIPSPI32.dll SIPSPI32"
XLocal Area NetworkOpenGL.exe"Added by a variant of the RBOT WORM!"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XLocal Pagehttp://find.naupoint.com"Naupoint browser hijacker"
ULocalProxyproxy4free.exe"""ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored
ULock My PClockpc.exe"Lock My PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen
ULogan_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printer
NLogiciel de transfert d'images KODAKpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
Xlogin[path to trojan]"Added by the HOTWORD-A TROJAN!"
XLogin Service[path to file]"Added by the MIGMAF TROJAN!"
XLoginPassportLgnpsp32.exe"Added by the REDIST.C WORM!"
YLogitechCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
NLogitech . Product RegistrationeReg.exe"Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice
XLogitech DesktopApPache.exe"Added by the RBOT-YP WORM!"
XLogitech DesktopIPCONN.EXE"Added by the SDBOT-WE WORM!"
XLogitech Desktop Controllerwrcam.exe"Added by a variant of the RBOT WORM!"
NLogitech Desktop Messengersetup-8876480.exe"Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products
NLogitech Desktop Messengerldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
NLogitech Desktop MessengerLogitechDesktopMessenger.exe"Installed with the software for Logitech products. Automatically checks for software upgrades and new products
NLogitech Desktop Messenger Agentldmconf.exe"Installed with older versions of the software for Logitech products. Configures the options for Logitech Desktop Messenger to activate notifications about software upgrades and/or new products
ULogitech Hardware Abstraction LayerKHALMNPR.EXE"Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
ULogitech SetPointKEM.exeKeyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
ULogitech SetPointKHALMNPR.EXE"Part of Logitech's SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
ULogitech SetPointSetpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
NLogitech Wakeuplgwakeup.exeLoads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
YLogitechCommunicationsManagerCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
NLogitechDesktopMessengerLogitechDesktopMessenger.exe"Installed with the software for Logitech products. Automatically checks for software upgrades and new products
ULogitechGalleryRepairISStart.exe"Installed with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
NLogitechSoftwareUpdateManifestEngine.exe"Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
ULogitechVideoRepairISStart.exe"Installed with Logitech's QuickSmart and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present
ULogitechVideo[inspector]InstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
XLogo[path to trojan]"Added by the DLOADER-RH TROJAN!"
XLogonrepclient1CSRSS.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
YLook 'n' Stoplooknstop.exe"Look 'n' Stop personal firewall"
XLookup_Syslookupsys.exeP04n trojan
XLosMejoresMP3"rundll32.exe MSA64CHK.dllDllMostrar"
NLotus Organizer EasyClipeasyclip.exe""The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address
XLotusHlpLotusHlp.exe"Added by the WINKO.AO WORM!"
NLowRateVoipLowRateVoip.exe"LowRateVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XLowRiskFileTypessysguard.exe"Added by the FAKEAV-UY TROJAN!"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
ULPMailCheckerLPMLCHK.exe"Part of Lenovo's ThinkVantage® Productivity Center on their ThinkPad notebooks or ThinkCentre desktops. Checks for incoming e-mail and blinks the ThinkVantage button LED"
ULPManagerLPMGR.exe"Part of Lenovo's (was IBM) ThinkVantage Productivity Center - ""guides you to a host of information and tools to help you set up
XLprLpr123.exe"Added by the REMPSTEAL password stealer TROJAN!"
XLpr123Lpr123.exe"Added by the REMPSTEAL password stealer TROJAN!"
ULPSLps.exe"Local Port Scanner - ""With LPS you're able to check your computer for open or listening ports"""
ULPtasklptask.exe"Program Lock It And Protect Pro - lock and protect your folders from being opened
NLS120 Superdisk??"Supposed to accelerate transfer rate on LS-120
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xlsass[path to lsass.exe]"Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup!"
XLSASS 32ISASS32.pif"Added by the ASSIRAL-C WORM!"
Xlsass2k Updatelsass2k.exe"Added by a variant of the RBOT WORM!"
ULSPFixLSPmonitor.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Xlspinsigps.exe"Detected by Kaspersky as the VB.KC TROJAN!"
ULSPmonitorLSPmonitor.exe"eAcceleration Stop-Sign security software related. Previously not recommended
XLssas Monitoring StartupLSSAS.EXE"Added by the RBOT.XJ WORM!"
ULtcyCfgApplyLtcyCfg.exe"PCI Latency Tool - ""Utility to set PCI Latency and possibly prevent game stutter or improve FPS"" for older AGP/PCI graphics cards"
XLTM2MPGSRV32.EXE"Added by the LITMUS.201 TROJAN!"
XLTM2winupdate.exe"Added by the LITMUS.203 TROJAN!"
YLto ManagerDesktopLtoManager.exe"Related to Global Positioning System (GPS) found on HP iPAQ hw6500 unit and others"
Xluplup.exe"Added by the IRCBOT_GEN WORM!"
YLusetupLUSetup.exe"Symantec LiveUpdate installer - required to install a new version of the application. Will only run once
ULWBKEYBOARDKbdAp32A.exeKeyboard utility for a Labtec brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
Ylxamsp32lxamsp32.exeLexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work
YLXBSCATS"rundll32 [path] LXBStime.dll _RunDLLEntry@16"
YLXBTCATS"rundll32 [path] LXBTtime.dll _RunDLLEntry@16"
YLXBUCATS"rundll32 [path] LXBUtime.dll _RunDLLEntry@16"
YLXBXCATS"rundll32 [path] LXBXtime.dll _RunDLLEntry@16"
YLXBYCATS"rundll32 [path] LXBYtime.dll _RunDLLEntry@16"
YLXCCCATS"rundll32 [path] LXCCtime.dll _RunDLLEntry@16"
ULXCDCATS"rundll32 [path] LXCDtime.dll _RunDLLEntry@16"
YLXCECATS"rundll32 [path] LXCEtime.dll _RunDLLEntry@16"
YLXCFCATS"rundll32 [path] LXCFtime.dll _RunDLLEntry@16"
YLXCGCATS"rundll32 [path] LXCGtime.dll _RunDLLEntry@16"
YLXCJCATS"rundll32 [path] LXCJtime.dll _RunDLLEntry@16"
YLXCQCATS"rundll32 [path] LXCQtime.dll _RunDLLEntry@16"
YLXCRCATS"rundll32 [path] LXCRtime.dll _RunDLLEntry@16"
YLXCTCATS"rundll32 [path] LXCTtime.dll _RunDLLEntry@16"
YLXCYCATS"rundll32 [path] LXCYtime.dll _RunDLLEntry@16"
YLXDBCATS"rundll32 [path] LXDBtime.dll _RunDLLEntry@16"
YLXDCCATS"rundll32 [path] LXDCtime.dll _RunDLLEntry@16"
YLXDDCATS"rundll32 [path] LXDDtime.dll _RunDLLEntry@16"
YLXDICATS"rundll32 [path] LXDItime.dll _RunDLLEntry@16"
ULXDJCATS"rundll32 [path] LXDJtime.dll _RunDLLEntry@16"
NLXSUPMONLXSUPMON.EXE"Lexmark printer related. The printer should work fine without it but what does it do?"
ULyraHD2TrayAppLYRAHD2TrayApp.exeRelated to RCA Lyra MP3 Player
XLzioMediaUpdaterLzioMediaUpdater.exe"LZIO.com adware downloader"
?M Player Post Installerpostinstallm.exe"??"
UM-Audio MobilePre Control Panel LauncherMPTask.exe"Control Panel Launcher for MobilePre USB bus-powered preamp and audio interface from M-Audio"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exe"WhenU.Save adware"
UMacDrive applicationMacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XMacfee Security PatchMpfsheild.exe"Added by the RBOT-NP WORM!"
XMachine Update Softwusas.exeAdded by an unidfentified WORM!
Xmachine-debuggerWMIPRVSW.exe"Added by the AGOBOT.WW WORM!"
XMacromedia 8Flash Player.exe"Added by the JAMBU-A WORM!"
XMacromedia Critical Updaterrarww.exe"Added by a variant of the RBOT WORM!"
XMacromedia DriveIexplor32.exe"Added by a variant of the RBOT WORM!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
UMacroPhonemacrophone.exe"MacroPhone is a network based telephony application that ""allows you to handle server based voice mail and fax functions for all users in your company"" and ""offers many related functions
UMacroPhone Clientmacrophone.exe"MacroPhone is a network based telephony application that ""allows you to handle server based voice mail and fax functions for all users in your company"" and ""offers many related functions
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NMacrovision Update ServiceISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
UMAFWTaskbarAppMAFWTray.exeDrivers for the M-Audio Firewire Audiophile - Interface
XMagicantispyMagicantispy.exe"Magicantispy rogue spyware remover - not recommended
UMagicKeyboardPreMKBD.exe"Related to Samsung laptops. Provides ability to program keys to perform specific functions"
XMailBlocker[path to trojan]"Added by the AGENT-LRJ TROJAN!"
YMailScan DispatcherLaunch.exe"MicroWorld MailScan Dispatcher splits each e-mail message into various components such as the header
?Main Executable (HP)HP05T0R5.exe"HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
UMalware SweeperMalSwep.exe"Malware Sweeper - ""Protects the user from malicious malware and monitors the sanity of the running programs"""
XMalware-WipeMalware-Wipe.exe"MalwareWipe rogue security software variant - not recommended
XMalware-WipedMalware-Wiped.exe"MalwareWipe rogue security software variant - not recommended
YMalwarebytes' RogueRemover PRORogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
XMalwareProMFCMalwarePro.exe"MalwarePro rogue security software - not recommended
XMalwareStopperMalwareStopper.exe"Malware Stopper rogue security software - not recommended"
XMalwaresWipedsMalwareWipeds.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWipeMalwareWipe.exe"MalwareWipe rogue security software - not recommended
XMalwareWipedMalwareWiped.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 5.5MalwareWiped 5.5.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 5.6MalwareWiped 5.6.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 5.7MalwareWiped 5.7.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 5.8MalwareWiped 5.8.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 6.1MalwareWiped 6.1.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 6.2MalwareWiped 6.2.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 6.3MalwareWiped 6.3.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 6.4MalwareWiped 6.4.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiped 6.9MalwareWiped 6.9.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWipedsMalwareWipeds.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWipeProMalwareWipePro.exe"MalwareWipe rogue security software variant - not recommended
XMalwareWiperMalwareWiper.exe"MalwareWipe rogue security software variant - not recommended
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
XMapEDCMapEDC.exe"Added by the WaveRevenue-McBoo TROJAN!"
XMapiDrvmpisvc.exe"Added by the MIPSIV TROJAN!"
Xmapisvc32mapisvc32.exe"Added by the KX VIRUS and also recognised by Symantec as FPAI adware"
XMapiyashaMapiyasha.exe"Added by the SILLYFDC-DM WORM!"
UMaple_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-216x Series multifunction printers
XMartinipinmart.exe"Added by a variant of the SDBOT WORM!"
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
XMaster Card Updaate 32Mastercard32.exe"Added by a variant of the RBOT WORM!"
UMaster Volume SpyMASTERVOLUMESPY.EXE"Volume control for the Gateway Destination ""DestiVu"" media interface"
XMasterBoot Switchpopupkill.exe"Added by a variant of the RBOT WORM!"
UMatadormantispm.exe"MailFrontier Desktop (Matador) email spam blocker software"
NMatrox PowerdeskPDesk.exe"""Matrox PowerDesk software provides extra multi-display desktop management controls"""
NMatrox PowerDesk 8matrox.powerdesk.exe"""Matrox PowerDesk software provides extra multi-display desktop management controls"""
NMatrox PowerDesk SEMatrox.PowerDesk SE.exe"Matrox PowerDesk SE - multi-display desktop management controls"
XMAV_checkmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
Xmav_startupmonmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
XMaxAntiSpyMaxAntiSpy.exe"MaxAntispy Russian rogue spyware remover - not recommended"
YMayaPanMayaPan.Exe"Audiotrak Maya soundcard driver"
Xmb2np[random filename]Added by the IRCBOT.TJ WORM!
UMBProbembrpobe.exe"MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs"
XMcAfee Antivirus ProtectionmcafeeAV.exe"Added by a variant of the RBOT WORM!"
YMcAfee Application Installermcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XMcafee Auto Protectmcafeshield.exe"Added by the RBOT-UH WORM!"
UMcAfee BackupMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Backup and RestoreMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Data BackupLogOnHook.exe"Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
UMcAfee Data BackupMcAfeeDataBackup.exe"McAfee Data Backup (now Online Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
YMcAfee Desktop Firewall TrayFireTray.exe"McAfee Desktop Firewall"
YMcAfee Family Protectionmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
YMcAfee FirewallCPD.EXEFirewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
YMcAfee Managed Desktop AgentMYAGTSVC.EXE"Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
UMcAfee Online BackupMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
UMcAfee Online Backup StatusMOBKstat.exe"System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
XMcAfee Online virus Scanneravp.exe"Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
UMcAfee QuickClean ImonitorPlguni.exe"Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection
YMcAfee SecurityCenterMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
UMcAfee SpamKillerMskAgent.exe"McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
XMcAfee Windows Protectionmcafee32.exe"Added by a variant of the SPYBOT WORM!"
UMcAfee.InstantUpdate.MonitorRuLaunch.exe"Instant Updater for McAfee's VirusScan
UMcAfeeDataBackupMcAfeeDataBackup.exe"McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
XMCAFEEIPSsetup.exe"Added by the WHITEWELL TROJAN!"
XMcAfeeScanPlusMcAfeeScanPlus.exe"Added by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder"
YMcAfeeUpdaterUIUpdaterUI.exeMcAfee common updater user interface
YMcAfeeUpdaterUIUdaterUI.exeUpdater user interface for McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
Ymcappinsmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
Xmceipww[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
NMCPLaunchMCPLaunch.exe"Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops
XMcrosoftr UpdateMcrosoftr.exe"Added by a variant of the RBOT WORM!"
YMcUpdateMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
YMCUpdateExeMcUpdate.exeAutomatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
XMCX Updatewisp.exe"Added by the RBOT-AQH WORM!"
XMCX Updtescorti.exe"Added by the RBOT-ARP WORM!"
XMD IE Pluginmd.exe"Marketdart spyware"
XMD IE Pluginwiny.exeAdware
UMDDiskProtectMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMDDiskProtect.exeMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
Xmdetect[path to trojan]"Added by the SPABOT TROJAN!"
Xmdwmdmspmdwmdmsp.exe"Adware - detected by Kaspersky as the AGENT.AM TROJAN!"
XMedia Adapterbitblt.exe"Added by the HANSAH-A WORM!"
UMedia Card Companion MonitorMCC Monitor.exe"Monitor for Media Card Companion from ArcSoft. ""Automates the tedious processes associated with downloading and sharing files from digital cameras
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
XMedia PassMediaPassK.exe"WindUpdates MediaPass adware"
XMedia PassMediaPass.exe"WindUpdates MediaPass adware"
XMedia Playermedia.exe"Added by the FLDMEDIA-A TROJAN!"
XMedia Playerwmplayer.exe"Added by a variant of the AGOBOT.BM WORM! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
XMedia PlayerSysdll.exe"Added by the BANKER-BR TROJAN!"
XMedia PlayerSysnet.exe"BANKER.MW spyware"
XMedia Player Updatexpsp1mfh.exe"Added by a variant of the RBOT WORM!"
XMedia Plug x.1.2msdm.exeAdded by the MULDROP.352 VIRUS!
XMedia servicenotpad.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMedia Software UPdatersscs.exe"Added by the RBOT-ABE WORM!"
XMedia Transfer Protocalsmsstc.exe"Added by a variant of the IRCBOT TROJAN!"
XMedia-XP-Service-Pack3msnzx.exe"Added by the SDBOT-ACW WORM!"
XMEDIA32[path to trojan]"Added by the PURSCAN-Z TROJAN!"
UMediafour MacDriveMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour XPlay Tray Notification IconXptryicn.exe"Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
UMediafour XPlay Tray Notification IconXptryicn.exe"Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod
Xmediamotor.exemmups.exe"Added by the AGENT-BY TROJAN!"
XMediaPathProyecto1.exe"Added by the GRUEL WORM!"
XMediaPathRoot.exe"Added by the GRUEL WORM!"
XMediaPipe P2P Loadermpp2pl.exe"MediaPipe peer-to-peer file swapping program also reported as a hijacker"
Xmediaplayer.exemediaplayer.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
Xmediaplayer.exemediaplayer.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
XMediaPlayeSMediaPlayer_update.exe"Added by the STARTER-K TROJAN!"
Xmediapluscash.exemediapluscash.exe"MediaGateway adware"
XMediaXPServicePackmxpsp.exe"Added by the SDBOT.CDT WORM!"
UMEDICsprtcmd.exe /P MEDIC"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
Umedicsp2sprtcmd.exe /P medicsp2"Self-help support tool for an unidentified high-speed internet provider (provided by SupportSoft
UMegaPanelHSTrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
XMegaVirusKitpgs.exe"MegaVirusKit rogue security software - not recommended. A member of the AVSystemCare family"
?meidntpavqgdpfrs.exe"??"
XMemConfigSetupIE.com"Added by the TAPLAK WORM!"
XMemory Managermemorymanager.pif"Added by the DELF-JJ TROJAN!"
UMemoryZipperPlusmemzip.exe"Memory Zipper Plus - ""optimizes the memory management of your system and boost-up its performance amazingly!"""
XMenaceSecurepgs.exe"MenaceSecure rogue security software - not recommended. A member of the AVSystemCare family"
NMenuSnapMenuSnap.exe"MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe"
NMessage Center PlusMCPLaunch.exe"Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops
XMessenger Explorerm41n.exe"Added by the SDBOT-SA BACKDOOR!"
XMessenger Protocolnetsender.exe"Added by the SDBOT-ACC WORM!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMessenger start-upMsgran.exe"Added by the GRAMOS WORM!"
XMessenger6command.pif"Added by the INZAE.B WORM!"
NMessengerPlusMsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
NMessengerPlus2MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
NMessengerPlus3MsgPlus.exe"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
XMeTaLRoCk (irc.musirc.com) has sex with printersmetalrock-is-gay.exe"Added by the RANDEX.Q WORM!"
XMeuProgramaaccwizz.exe"Added by the RULAND.A WORM!"
Xmfhsornwnduyregsvr32.exe gisyflngpshcvuakv.dll"Pro AntiSpyware 2009 rogue spyware remover - not recommended
Ymfpmfp.exe"McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content
UMFP PanelMgrSSMMgr.exe"Monitors ink levels
YMFP Server AgentMFPAgent.exe"Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
UMFP1815_S2PScan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
NMGA_CD_Installmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
Xmgmtapimgmtapi.exeUnidentified malware
XMicosoft Startupsyscall.exe"Added by the SDBOT-JI WORM!"
XMicosoft Startupsystall.exe"Added by the SDBOT-GM BACKDOOR!"
XMicr Updatesoundblaster.exe"Added by the SDBOT.NP WORM!"
XMicr Update Systemupwin.exe"Added by the SDBOT.YS WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicrcoft Exploererspoolsal.exe"Added by the RBOT-AKK WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
XMicrcoft Updatspoolsae.exe"Added by the RBOT-AIB WORM!"
XMicrcoft Updatspoolsaex.exe"Added by the RBOT-AJM WORM!"
XMicrcoft UpdatInternet.exe"Added by the RBOT-ANA WORM!"
XMicro CRC Protocolscrc32.exe"Added by a variant of the SDBOT WORM!"
XMicro Office[path to trojan]"Added by the BANCBAN-QC TROJAN!"
XMicro Processappconf.exeAdded by an unidentified WORM or TROJAN!
XMicro Updatedailin.exe"Added by the RBOT-ER WORM!"
NMicroangelo DesktopMuamgr.exe"Using MicroAngelo On Display
XMicroCQ0explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMicrofinder lptt01mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrofot Updatewinldx32.exe"Added by a variant of the RBOT WORM!"
XMicroft Exploererspoolsac.exe"Added by the RBOT-AMD WORM!"
XMicroft Update 32winssx.exe"Added by the RBOT-AQS WORM!"
XMicromedia Flash Updatewdfmrg.exe"Added by a variant of the SDBOT WORM!"
XMicromedia Flash Updatexptxt.exe"Added by the RBOT-GAB WORM!"
XMicrooft Timingpupdate.exe"Added by a variant of the RBOT WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMICROSFT MX UPDATE SUPPORTtaskmngrs.exe"Added by the RBOT-AUZ WORM!"
XMICROSFT MX UPDATE SUPPORTwinmx32.EXE"Added by the IRCBOT-FD WORM!"
XMICROSFT RAMA UPDATE SUPPORT[random filename]"Added by the RBOT-ASM or RBOT-AUW WORMS!"
XMICROSFT RAMA UPDATE SUPPORTMSN32.EXE"Added by the RBOT-AWJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTmtakthmyn.EXE"Added by the RBOT-AUJ WORM!"
XMICROSFT RAMA UPDATE SUPPORTMSGUPDAT32.EXE"Added by the RBOT-BBB WORM!"
XMicrosft Remote Procedure Daemonmsrpcd.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processcmh.exe"Added by the EGGDROP.V WORM!"
XMicrosft Security Monitor Processmssmppp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosft Security Monitor Processmssmpp.exe"Added by the SDBOT-DJW WORM!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosft Upgraed[random filename].exe"Added by a variant of the SDBOT WORM!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Added by the SMALL.HIT TROJAN!"
Xmicrosft windows updatesmwupdate32.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftlsass.ppf"Added by the RBOT-GAA WORM!"
XMicrosoftMSUPDATE.exeAdded by an unidentified WORM or TROJAN!
XMicrosoftupdater.exe"Added by the RBOT-GHP WORM!"
XMicrosoftExplorerr.exe"Added by the IRCBOT-WG TROJAN!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoftWinSecUp.exe"Added by the RBOT-GPL WORM!"
XMicrosoftwplayer.exe"Added by the IRCBOT-ABP TROJAN!"
XMicrosoftExplorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoftwinampaa.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftMicrosoftCorporation.exe"Added by the KILLFILES.AED TROJAN!"
XMicrosoft (C) HTML Application host[random filename]"Added by the RBOT-YB WORM!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows Network Latency Controller1.tmp"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows Protocol Deployment Manager[random].tmpAdded by an unidentified WORM or TROJAN!
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft 16Bit Updatewuapdate16.exe"Added by the RBOT.CZ WORM!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft Admin ProtocalMSADNIN.exe"Added by a variant of the RBOT WORM!"
XMicrosoft ALG32 Protocolalg32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft ALGXP Protocolalg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Ansti Updatemsie.exe"Added by the RBOT-LE WORM!"
XMicrosoft Anti-Spy[random filename]"Added by a variant of the SDBOT WORM!"
XMicrosoft AntiSpywareBazzi.exe"Added by the AHKER.J WORM!"
XMicrosoft AntiSpywareKT06.pif"Added by the IRCBOT.GEN WORM!"
XMicrosoft AOL32 Protocolaol32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Application Centermappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Application Managermsapl32.exe"Added by the BROPIA-AE TROJAN!"
XMicrosoft AUT UpdateMSlti32.exe"Added by the RBOT-X WORM!"
XMicrosoft AUT UpdateMSlti16.exe"Added by the RBOT.EB WORM!"
XMicrosoft auto updatewinupdate.exe"Added by the BMBOT TROJAN!"
XMicrosoft Auto UpdateWINHLP16.EXE"Added by the RBOT.GY WORM!"
XMicrosoft auto updatewuauclt.exe"Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Buffer Appmsbuffer.exe"Added by the SLINBOT.NQ BACKDOOR!"
XMicrosoft checkerMsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Connection Manager Monitorcmmon.pif"Added by the RBOT-AKV WORM!"
XMicrosoft Core SupportMSxUP32.exe"Added by the RBOT-ANR WORM!"
XMicrosoft Core Support[random filename]"Added by a variant of the RBOT TROJAN!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp SQL Certificatessqlcer.exe"Added by the ZYBOT-C WORM!"
XMicrosoft Corp SSL Certificateswindowz.exe"Added by the RBOT-GCZ WORM!"
XMicrosoft Corp TLS Certificatesmsauth.exe"Added by the RBOT-GAC WORM!"
XMicrosoft Corp Updateswupdates.exe"Added by the RBOT-AUU WORM!"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporaticn SQL Handlersqlhandler.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Corporation[random filename]"Added by various VIRUSES
XMicrosoft Corporationjview.exe"Added by the RBOT-AOD WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft Corporation SYM monitormssym.exe"Added by the RBOT-GDB WORM!"
XMicrosoft CP Web Managerwebcp.exe"Added by the IRCBOT.HP TROJAN!"
XMicrosoft CPU Over Heat ManagerCPU.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft CPXP Protocolcpxp.exe"Added by the RBOT.ATP WORM!"
XMicrosoft CSRSS32 Protocolcsrss32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft CSRSS386 Protocolcsrss386.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Data Helpercihost.exe"Malware
XMicrosoft Datalog Applicationmsdata.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDE Controlwupades.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Decryption TechnologyMsfenoe.exe"Added by the SPYBOT-DG WORM!"
XMicrosoft Desktop Managermsdesk32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Development Debuggermsdev.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Digital Cryptorsmdigits.exe"Added by the SDBOT.LM WORM!"
XMicrosoft DirectXSpoolserv.exe"Added by the DINFOR WORM!"
XMicrosoft DirectXPDSched.exe"Added by the SDBOT.CN WORM!"
XMicrosoft DirectXwupdate.exe"Added by the RBOT-L WORM!"
XMicrosoft Directx pushdirectxpushup.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspdirectxbt.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Directxspnewdirectxnew.exe"Added by a variant of the RBOT-GHT WORM!"
XMicrosoft Dllrunapidll.exe"Added by the RBOT-GRG WORM!"
XMicrosoft Dll Printer Managerdllpt.exe"Added by the SDBOT.BIH WORM!"
XMicrosoft Documentkrisp.exe"Added by the SDBOT-RQ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft ErgoPackwserb32.exe"Added by the RBOT-RI WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Explorerexplorer.pif"Added by the SDBOT-ACX WORM!"
XMicrosoft Explorerexplorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Explorer(64)explorer64.exe"Added by the SPYBOT-R WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Explorer2bitchbot.exe"Added by the SDBOT.EV WORM!"
XMicrosoft EXPLOREXP Protocolexplorexp.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Firewallfirewallsp2.exe"Added by the RBOT-MC WORM!"
XMicrosoft FixUppevblbvr.exe"Added by the RBOT.DWK WORM!"
XMicrosoft FixUpwnpzjpuw.exe"Added by a variant of the SDBOT WORM!"
Xmicrosoft frontpagetwain.exe"Added by the AGENT.AQO TROJAN!"
XMicrosoft Generic Update Managerwupdate.exe"Added by the RBOT-AWC TROJAN!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Gina V EncryptionMSGINAV.EXE"Added by an unidentified VIRUS
NMicrosoft Greetings ReminderMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
NMicrosoft Greetings RemindersMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
NMicrosoft Greetings Workshop ReminderGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
XMicrosoft HDCP for NTmsdhcp.exe"Added by a variant of the RBOT WORM!"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help Supportmshelp32.exe"Addded by the KELVIR-BF WORM!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Help Systemmshelp32.exe"CoolWebSearch parasite variant"
XMicrosoft Helpdesk Sidemshelpdsk.exe"Added by the SPYBOT.ANJJ WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Hyptertext Helpermshtha.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IDCNmshe1p.exeAdded by an unidentified TROJAN!
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft Inc.iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inc.iexplorer.exe..."Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Incroporatemfs.exe"Added by the RBOT-ANF WORM!"
XMicrosoft Inet Xp..teekids.exe"Added by the BLASTER.C WORM!"
UMicrosoft IntelliPointipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft IntelliPointpoint32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
UMicrosoft Intellitype Prospeedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
UMicrosoft IntelliType Proitype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
UMicrosoft IntelliType Protype32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internet Acceleration Utility[path to file]"Added by the AGENT-CX TROJAN!"
XMicrosoft Internet Acceleration Utility[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Internet Dumping Protocolinetdump.exe"Added by the IRCBOT.BLL BACKDOOR!"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Internet Firewall Updateupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft IPCsystem.exe"Added by the NULLBOT TROJAN!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft IT Updatewin64.exe"Added by the RBOT.GA WORM!"
XMicrosoft IT Update[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft IT UpdateIEserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatemsupdate.exe"Added by the RBOT-FE WORM!"
XMicrosoft IT Updatewinn43.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft IT Updatewin43.exe"Added by the RBOT-SA WORM!"
XMicrosoft IT Updatewindows.exe"Added by the RBOT-JM WORM!"
XMicrosoft IT Updatewinsyst32.exe"Added by the RBOT-FC WORM!"
XMicrosoft IT UpdateRhost32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft LAN32 ProtocollanXp.exe"Added by the RBOT-SS WORM!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft LV[path to file]"Added by the BDOOR-BDL BACKDOOR!"
XMicrosoft Machineupdata.exe"Added by the RBOT-DJ WORM!"
XMicrosoft Machinetemp.exe"Added by the RBOT-FSQ WORM!"
XMicrosoft Machinewinxp43.exe"Added by the RBOT-IA WORM!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft MachineUpdatesetempes.exe"Added by the RBOT.EWN BACKDOOR!"
XMicrosoft Macro Protection SubSsymsacroprots386.exe"Added by the RBOT-KE WORM!"
XMicrosoft Macro Protection Subsystemsmsmacroprotxz.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Macro Protection SubsystemsMsmacroprot32.exe"Added by the RBOT.KN WORM!"
XMicrosoft Management Console[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMicrosoft Map PCmappc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Mapped PCmappedpc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft mediawinmplayers.exe"Added by a variant of the SPYBOT WORM!"
UMicrosoft Media Center Tray AppletehTray.exe"Media Center Tray Applet - part of Windows Media Center on XP MCE
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Memory Dumping Protocolmemdump.exe"Added by the IRCBOT.BJK BACKDOOR!"
XMicrosoft Messenger XPMSMSN32.exe"Added by the RBOT-ZP WORM!"
XMicrosoft MicroP Protocolwdgmr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft MSGPLUS32 Protocolmsgplus32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft MSNGR32 Protocolmsngr32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Neser Experiencenese.exe"Added by the RBOT-YH WORM!"
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Networking Agent For SP2msnac32.exe"Added by the SPYBOT.PEN WORM!"
XMicrosoft Norotn Anti Virusmnhpot.exe"Added by the RBOT-GRO WORM!"
XMicrosoft NotePadnotepad.exe"Added by a variant of the RBOT WORM!"
XMicrosoft NT Updatewinexec32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officenxcxtpr.exe"Added by the RBOT-YG WORM!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
XMicrosoft Office Startwinupdates.exe"Added by the GAOBOT.BC WORM!"
NMicrosoft Office Startuposa.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft OfficeXPofficeXP.exe"Added by the KILLAV.MA WORM!"
XMicrosoft OpeionsIEXwe.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Patch Updatebootini.exe"Added by the RBOT-FMN WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft PCHealth32[path to file]"Added by the NICE-A TROJAN!"
XMicrosoft PCHealth32NDDENB.exe"Added by the PWSYAHOO-A TROJAN!"
XMicrosoft PCI Managermspci.exe"Added by the RBOT.BBG WORM!"
NMicrosoft People Near Mep2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XMicrosoft Personal Firewallsbakw.exe"Added by the RBOT-KS WORM!"
XMicrosoft Problem Doctorwindr128.exe"Added by the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr32.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Problem Doctorwindr64.exe"Added by a variant of the SMALLTRO.EF TROJAN!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Procedure CallMSPCALL.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Process Managerprocess32.exe"Added by the CHECKOUT WORM!"
XMicrosoft Profile Managerprofile.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft PSTCP32 Datapstcp32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Redirect[path to file]"Added by the BANKER-FW TROJAN!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft sdk tempsdktemp.exe"Added by the RBOT-ANP WORM!"
XMicrosoft SDKP3mswinsdq.exe"Added by the RBOT-ARY WORM!"
XMicrosoft Security Hot Fix Updatemshotfix.exe"Affilred adware"
XMicrosoft Security Managementwinamp.exe"Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
XMicrosoft Security Managementsp2fix.exe"Added by the RBOT.UB WORM!"
XMicrosoft Security Managerwinamp.exe"Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
XMicrosoft Security Monitor Processmssmp.exe"Added by the RBOT-FUB WORM!"
XMicrosoft Security Monitor Processmnsmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmsmp.exe"Added by the RBOT.GKQ WORM!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Security Monitor Processlsas.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processmsword.exe"Added by the VIRUT.P VIRUS!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processwindowsupdate.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Process[random filename]"Added by variants of the RBOT WORM! See here"
XMicrosoft Security Monitor Processcom.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processexel.exe"Added by the SDBOT.AFX BACKDOOR!"
XMicrosoft Security Monitor Processfirewall.exe"Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
XMicrosoft Security Monitor Processflash.exe"Added by the EGGDROP.EE BACKDOOR!"
XMicrosoft Security Monitor Processhel.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor ProcessHelpMe.exe"Added by the VB.BJO TROJAN!"
XMicrosoft Security Monitor Processkar.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Security Monitor Processlindicracker.exe"Added by the BIFROSE.GR BACKDOOR!"
XMicrosoft Security Monitor Processmail.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmmp.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssm32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Security Monitor Processmssmpi32.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Security Monitor Processnitty.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processofice.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processpoint.exe"Added by the IRCBOT.AVP BACKDOOR!"
XMicrosoft Security Monitor Processprinc.exe"Added by the HUPIGON.WTL TROJAN!"
XMicrosoft Security Monitor Processweb.exe"Added by the EGGDROP.V BACKDOOR!"
XMicrosoft Security Monitor Processwinsys32.exe"Added by the VIRUT.N VIRUS!"
XMicrosoft Security Monitor Processwinsyss32.exe"Added by the RBOT.AEU BACKDOOR!"
XMicrosoft Security Monitor Processword.exe"Added by the EGGDROP.DC BACKDOOR!"
XMicrosoft Security Panager[filename]"Added by the RBOT-ANL WORM!"
XMicrosoft Security Panagers[random filename]"Added by the RBOT-AIG WORM!"
XMicrosoft Security Panagerszzoboony.exe"Added by the RBOT-AOI WORM!"
XMicrosoft Security Pansasagersdgkztsqgn.exe"Added by the RBOT-BBJ WORM!"
XMicrosoft Security Processwininit.exe"Added by the RBOT-FKM WORM!"
XMicrosoft Security Updatesecurity32.exe"Added by the DELF-JJ TROJAN!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Server Applacationscli.exe"Added by the RBOT-GAQ WORM!"
XMicrosoft Server ApplicationSound.exe"Added by the RBOT-NE WORM!"
XMicrosoft Server Processsvhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Setup Initializazionlocalhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Sinsupodjiwjf.exe"Added by the RBOT-DN WORM!"
XMicrosoft Software Updatenmon.exe"Added by the RBOT.HZ WORM!"
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Special offerinfoebay.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft SSISVRI32 Protocolssisvri.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft standard protectorwinsocks5.exeAdded by the SMALL.CF TROJAN!
XMicrosoft standard protector[path to trojan]"Added by the STOX-C TROJAN!"
XMicrosoft startupwmpIayer.exeAdded by the IRCBOT.ACI TROJAN!
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
XMicrosoft Supportsys32ms.exe"Added by the RBOT-AHI WORM!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managerwinupdate.exe"Added by the SDBOT.ER WORM!"
XMicrosoft Synchronization Managerexplorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Synchronization Managermircup.exe"Added by the SDBOT.BQD WORM!"
XMicrosoft Systemmsupdtm.exe"Added by the SPYBOT.PKC WORM!"
XMicrosoft Systemwinamp1.exe"Added by the SDBOT-UF WORM!"
XMicrosoft System Backup[random filename]"Added by the RBOT-AGM WORM!"
XMicrosoft System CheckupCool.exe"Added by the DONK.B WORM!"
XMicrosoft System CheckupWnetlib.exe"Added by the DONK.C WORM!"
XMicrosoft System Checkupdbnetlib.exe"Added by the DONK.L WORM!"
XMicrosoft System CheckupKeymgr.exe"Added by the DONK.M WORM!"
XMicrosoft System Checkupinetman.exe"Added by the DONK.O WORM!"
XMicrosoft System Checkupntsysmgr.exe"Added by the DONK.S WORM!"
XMicrosoft System Checkupntsysman.exe"Added by the SDBOT-QW WORM!"
XMicrosoft System Checkuplibsysmgr.exe"Added by the SDBOT-CAF WORM!"
XMicrosoft System Checkupsysmgr.exe"Added by the SDBOT-OO TROJAN!"
XMicrosoft System Checkupnetapi32.exe"Added by the DONK-E WORM!"
XMicrosoft System Checkupwnetmgr.exe"Added by the DONK.Q WORM!"
XMicrosoft System Checkuplibsys32.exe"Added by the SDBOT-ACK WORM!"
XMicrosoft System Checkupnetlogin32.exe"Added by the SDBOT-GN BACKDOOR!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Updatesysupdate.exe"Added by the SDBOT.DG WORM!"
XMicrosoft System32 Updatecmsrg.exe"Added by the RBOT-GN WORM!"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft Task32 Protocoltaskmgr32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Taskmanager Updaterkeyboard.exe"Added by the RBOT-ALU WORM!"
XMicrosoft TCP Protocolwintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecoms Centerxpfilesys.exeAdded by the RBOT.BCJ TROJAN!
XMicrosoft Telecoms Centerwinupn.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Uwuamkopxp.exe"Added by the RBOT-AHC WORM!"
XMicrosoft UMA UpdateMSuma32.exe"Added by the RBOT.FS WORM!"
XMICROSOFT UNPACCKER SYSTEMunpak32.exe"Added by a variant of the RBOT WORM!"
XMICROSOFT UNPACK SYSTEMwinrarx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updat3mswkst32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoft.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemssmgrd.exe"Added by the SDBOT.JT WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updateascdl.exe"Added by the GAOBOT.SY WORM!"
XMicrosoft UpdateIsac.exe"Added by the RBOT-AU WORM!"
XMicrosoft Updateautomgr32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemediap.exe"Added by a variant of the RBOT WORM!"
XMicrosoft UpdateMicrosoftx.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft UpdateMslti32.exe"Added by the RBOT-LX WORM!"
XMicrosoft Updatemuamgrd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatenavmgrd.exe"Added by the SDBOT.DP TROJAN!"
XMicrosoft UpdateSmss32.exe"Added by the RBOT-CB WORM!"
XMicrosoft Updatesys32cfg.exe"Added by the RBOT.DR WORM!"
XMicrosoft UpdateVPC32.EXE"Added by the AGOBOT.XM WORM!"
XMicrosoft Updatewinsys32.exe"Added by the RBOT.BD WORM!"
XMicrosoft Updatewuamgrd.exe"Added by the RBOT-LK WORM!"
XMicrosoft Updatewuammgr32.exe"Added by the RBOT-AW WORM!"
XMicrosoft Updatewudmate.exe"Added by the RBOT.AP WORM!"
XMicrosoft Updatemsawindows.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatemsiwin84.exe"Added by the GAOBOT.AFJ WORM!"
XMicrosoft Updatewuamgrd32.exe"Added by the RBOT.ZB WORM!"
XMicrosoft UpdateNAV.exe"Added by the RBOT-IV WORM!"
XMicrosoft Updatesystemi32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Updatexpupdate.exe"Added by the RBOT-QE WORM!"
XMicrosoft Updatewebm.exe"Added by the SDBOT.WK WORM!"
XMicrosoft Updatewuagrd.exe"Added by the RBOT-FK WORM!"
XMicrosoft Updateaaupdt.exe"Added by the RBOT-RQ WORM!"
XMicrosoft Updatelsac.exe"Added by the GAOBOT.XW WORM!"
XMicrosoft UpdateMupdate.exe"Added by the RBOT-AG WORM!"
XMicrosoft Updateprowind32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatewauguard.exe"Added by the RBOT.AEE WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"