| U | Sidebar | Sidebar.exe | "Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
|
| N | SIDEBAR | dsidebar.exe | """Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"""
|
| N | Simple Star PhotoShow Media Manager | mssysmgr.exe | "Simple Star PhotoShow photo editing and organizing software |
| N | SiS KHooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
|
| U | siscolor | color.exe | Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
|
| N | SleepManager | SleepMgr.exe | "This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY |
| U | Slibe.com | Sliber.EXE | "Sliber - freeware screen capturing & online sharing tool"
|
| U | SlickRun | sr.exe | """SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords) |
| N | slimp3 | SliMP3 Server.exe | "Slimp3 Server - ""presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards |
| N | SM56 Helper Win32 Utility | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray
|
| N | Sm56acl | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray
|
| N | Smart Card Service | ScardSvr.exe | "For Smart Card readers. Known to cause problems |
| X | Smartfixer | SmartFixer.exe | "SmartFixer rogue system error and cleaning utility - not recommended"
|
| ? | SmartLauncher | SmartLauncher.exe | "Related to SmartLauncher from Northstar Systems Corp. What does it do and is it required?"
|
| X | smartprotector | smartprotector.exe | "Smart Protector rogue security software - not recommended |
| U | SmartRAM | MemCleaner.exe | "Memory Cleaner - monitors your system in the background and frees up memory when ever need to increase the performance of your computer. Part of IOBit Advanced Windows Care Personal/Professional"
|
| X | SmcSVR | SmcSVR.exe | "Added by the LEGMIR.JU TROJAN!"
|
| X | smgr | smgr.exe | Added by an unidentified WORM or TROJAN!
|
| N | Smserial | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray
|
| N | SMSI Loader | SMLoader.exe | "Smith Micro HotFax - fax software"
|
| X | smsys | Explorer.exe | "Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
|
| U | SMSystemAnalyzer | SMSystemAnalyzer.exe | "Part of the Iolo System Mechanic optimization tool"
|
| N | SMToolbar | SMToolbar.exe | StartMake.com toolbar
|
| X | SM_IAN | ian_monitor.exe | "AdvancedCleaner rogue security software - not recommended |
| X | SN Messenger | msnmsgr.exe | "Added by the RBOT-AVP WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| U | Snapfish Media Detector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| U | SnapfishMediaDetector | SnapfishMediaDetector.exe | "Snapfish Media Detector - ""Upload your photos to Snapfish |
| ? | snbr | snbr.exe | "??"
|
| X | sncntr | sncntr.exe | "Added by the DLUCA-I TROJAN!"
|
| X | Sndsaver | Sndsaver.exe | "Added by the GEMA TROJAN!"
|
| ? | SO5 Integrator Pass One | sointgr.exe | "StarOffice 5. See here for more details"
|
| ? | SO5 Integrator Pass Two | sointgr.exe | "StarOffice 5. See here for more details"
|
| X | SoftBarrier | SoftBarrier.exe | "SoftBarrier rogue security software - not recommended |
| X | SoftSoldier | SoftSoldier.exe | "SoftSoldier rogue security software - not recommended |
| N | Sony Ericsson PC Suite | Application Launcher.exe | "System Tray access to Sony Ericsson PC Suite which ""connects your phone to your computer and expands the capabilities of your phone"". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone"
|
| U | SonyPowerCfg | SPMgr.exe | Related to Sony VAIO Power Management Module installed on laptops and provides additional configuration options for these devices
|
| ? | SoSyncMonitor | SoSyncMonitor.exe | "SuperOffice related. What does it do and is it required?"
|
| X | Sound Loader | sndloader.exe | "Added by the AGOBOT-BV WORM!"
|
| U | SP2 Connection Patcher | SP2ConnPatcher.exe | Changes limit of concurrent TCP connections of Windows Service Pack 2
|
| X | sp2ctr | sp2ctr.exe | "Added by the DLUCA-M TROJAN!"
|
| U | Spam Monitor | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| U | spamihilator | spamihilator.exe | "Spamihilator - spam filter"
|
| U | SpamMonitor | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| U | SpamMonitor Application | SpamMonitor.Exe | "System Tray access to Spam Monitor from PC Tools - which ""is an easy-to-use spam filter that detects and isolates unsolicited junk mail sent to your mailbox. Designed for computer users |
| ? | SPC610NC_Monitor | Monitor.exe | "Related to the Philips SPC610NC webcam. What does it do and is it required?"
|
| N | SpeedBitVideoAccelerator | VideoAccelerator.exe | """SpeedBit Video Accelerator makes videos from YouTube and over 150 sites stream faster and play smoother by reducing buffering problems and video interruptions or hiccups"""
|
| U | SpeedMeter | SpeedMeter.exe | Application measuring upload and download speed
|
| X | SpeedRunner | SpeedRunner.exe | Identified as a variant of the TrojanDownloader.Matcash malware
|
| N | Spinner Plus | spinner.exe | ""Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed |
| X | spoolsv manager | SpoolMgr.exe | "Added by the ASSIRAL WORM!"
|
| X | spoolsvr | SPOOLSVR.EXE | "Added by the RAYROB.A TROJAN!"
|
| U | Spy Blocker | spyblocker.exe | "SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important |
| U | Spy Protector | SpyProtector.exe | "Included in the full version of Security Task Manager |
| U | SpyBlocker | spyblocker.exe | "SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important |
| Y | Spybot - Search & Destroy | TeaTimer.exe | "Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options |
| Y | SpybotSD TeaTimer | TeaTimer.exe | "Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options |
| X | SpyBurner | SpyBurner.exe | "SpyBurner rogue spyware remover - not recommended |
| X | SpyDevastator | SpyDevastator.exe | "SpyDevastator rogue security software - not recommended |
| X | SpyFighterMonitor | SpyFighter.exe | "SpyFighter spyware remover - not recommended |
| X | SpyGuarder | spyguarder.exe | "SpyGuarder rogue security software - not recommended |
| X | SpyHealer | SpyHealer.exe | "SpyHeal rogue spyware remover - not recommended"
|
| X | SpyHunter | SpyHunter.exe | "Enigma SpyHunter - not recommended |
| X | Spyinator | Spyinator.exe | "Spyinator rogue spyware remover - not recommended"
|
| U | Spykiller | Spykiller.exe | "Spyware remover - older versions are not recommended |
| X | SpyKiller.exe | SpyKiller.exe | "Super Spyware Killer rogue spyware remover - not recommended"
|
| X | SpyNuker | Spynuker.exe | "A ""spyware removal program"" by TrekBlue |
| X | SpyOnThis Monitor | SpyOnThisMonitor.exe | "SpyOnThis rogue spyware remover - not recommended"
|
| U | spyprodetector | spydetector.exe | Spyware Process Detector spyware remover
|
| U | spyshelter | antikeylogger.exe | "SpyShelter - anti-keylogger protects against keylogger programs monitoring your keystrokes"
|
| X | SpyShredder | SpyShredder.exe | "SpyShredder rogue spyware remover |
| X | spysoldier | spysoldier.exe | "SpySoldier rogue spyware remover - not recommended |
| X | SpySpotter | SpySpotter.exe | "SpySpotter rogue spyware remover - not recommended |
| X | SpySpotter System Defender | Defender.exe | "SpySpotter rogue spyware remover - not recommended |
| U | SpyStopper | spystopper.exe | "SpyStopper - blocks intrusive spyware |
| U | SpySweeper | SpySweeper.exe | "Spy Sweeper - detects and removes spyware"
|
| X | SpyTrooper | SpyTrooper.exe | "SpyTrooper rogue spyware remover - not recommended |
| Y | Spyware Doctor | spydoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| Y | Spyware Doctor | swdoctor.exe | "Older version of Spyware Doctor antispyware from PC Tools"
|
| U | Spyware Nuker Installer | SpywareNukerInstaller.exe | "Spyware remover by TrekBlue. Previously not recommended but the latest version was delisted here"
|
| N | Spyware Scanner | AseScanner.exe | "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU |
| X | Spyware Slayer | SpywareSlayer.Exe | "Spyware Slayer spyware remover - not recommended |
| X | Spyware Stormer | SpywareStormer.Exe | "Spyware Stormer spyware remover - not recommended |
| X | Spyware Striker Pro | SpywareStriker.exe | "Ascentive Spyware Striker Pro rogue spyware remover - not recommended |
| X | Spyware Sweeper | SpywareSweeper.exe | "SpywareSweeper rogue spyware remover - not recommended"
|
| U | Spyware Vanisher | FreeScanner.exe | "Spyware Vanisher - spyware remover. Previously not recommended |
| U | Spyware Vanisher | SpywareVanisher.exe | "Spyware Vanisher - spyware remover. Previously not recommended |
| X | spywareisolator | spywareisolator.exe | "SpywareIsolator rogue spyware remover - not recommended |
| X | SpywareLocker | SpywareLocker.exe | "SpywareLocker rogue security software - not recommended |
| X | SpywareRemover | SpywareRemover.exe | "SpywareRemover spyware remover - not recommended |
| X | SpywareRemover2009 | SR.exe | "SpywareRemover 2009 rogue spyware remover - not recommended |
| X | spywarescanner | spywarescanner.exe | "Spyware Scanner 2008 rogue security software - not recommended |
| X | SpywareSweeper | SpywareSweeper.exe | "SpywareSweeper rogue spyware remover - not recommended"
|
| X | SQInstaller | SQInstaller.exe | "Xupiter SQWire toolbar related. Use Spybot S&D |
| X | SQL | server.exe | "Added by the PUNYA-B WORM!"
|
| X | ssgrate.exe | sysdoor.exe | "Added by the MITGLIEDER.N TROJAN!"
|
| X | ssgrate.exe | winerdir.exe | "Added by the MITGLIEDER.O TROJAN!"
|
| U | SSMMgr | SSMMgr.exe | "Monitors ink levels |
| X | start | isfmntr.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| X | start | sbmntr.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| X | Start Upping | taksmgr.exe | "Added by the RBOT-QK WORM!"
|
| X | startkey | svcmgr.exe | "Added by the HIPPER-B TROJAN!"
|
| X | startkey | RunWinRaR.exe | Added by a variant of the BIFROSE-LV TROJAN!
|
| X | startkey | explorer.exe | "Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | startkey | server.exe | "Added by the BIFROSE-DB TROJAN!"
|
| X | startkey | antivir.exe | "Added by the BIFROSE-TO TROJAN!"
|
| U | Startup Manager Scanner | StartupMonitor.exe | "Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans |
| Y | Startup Scan | Sensor.EXE | "AntiVirus Quick Heal - scheduling agent"
|
| U | StartupMonitor | StartupMonitor.exe | "Mike Lin's StartupMonitor |
| X | StatBar | STATBAR.exe | "StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory |
| X | stcloader | stcloader.exe | "SecondThought adware"
|
| X | stealth.injector.exe | stealth.injector.exe | "Added by the THEALS.A WORM!"
|
| ? | STPMGR | STPMGR.EXE | "Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs"
|
| N | Streamload Uploader | StreamMgr.exe | "Uploader for MediaMax (was Streamload) - ""gives you a private and secure place to upload |
| X | SunJavaSched | ccEvtMngr.exe | "Added by the SDBOT-YP WORM!"
|
| X | SunJavaUpdaterv13 | javaupdater.exe | "Added by the ROUTROBOT WORM!"
|
| Y | SunProtectionServer | SunProtectionServer.exe | "CounterSpy antispyware software"
|
| Y | SunServer | SunServer.exe | "CounterSpy antispyware software"
|
| X | super | super.exe | "Added by the AGOBOT-QT WORM!"
|
| U | Supercleaner | Supercleaner.exe | "Supercleaner - all in one disk cleaner for your computer"
|
| X | Supervisor.exe | Supervisor.exe | "Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome"
|
| X | Surfer lptt01 | surfer.exe | "RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Surfer ml097e | surfer.exe | "RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| N | suScheduler | UCLauncher.exe | "Scheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks"
|
| X | Sustem | explorer.exe | "Added by an unidentified VIRUS |
| X | SustemUpdate | explorer.exe | "Added by an unidentified VIRUS |
| X | SVA Player | SVAplayer.exe | "SVAPlayer parasite"
|
| X | SVCHOST | taskgmr.exe | "Added by the MYTOB.F or MYTOB.H WORMS!"
|
| X | svchost | [path to explorer.exe] | "Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
|
| X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN!
|
| X | Svconr | Svconr.exe | "WaveRevenue-lBann adware"
|
| X | Svhost Service Server | svhostser.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | svshost | messenger.exe | "Added by the LOONY-G TROJAN!"
|
| X | SWCaller | SWcaller.exe | "Swporta homepage hijacker"
|
| U | swg | GoogleToolbarNotifier.exe | "Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
|
| X | SwiftCleaner | SwiftCleanerScanner.exe | "SwiftCleaner rogue cleaning utility - not recommended |
| U | Switcher | Switcher.exe | """On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN |
| N | SxgTkBar | sxgtkbar.exe | Yamaha SXG soundcard utility - gives quick and easy access via the system tray bar to diagnostics and configuration
|
| X | Sygate Personal Firewall | syserror.exe | "Added by the RBOT.UC WORM!"
|
| X | Symantec Antivirus professional | for.exe | "Added by a variant of the FORBOT WORM!"
|
| X | Symantec Antivirus professional | xplrer.exe | "Added by a variant of the FORBOT WORM!"
|
| X | SyncManager | msorunner.exe | "Added by a variant of the TACTSLAY TROJAN!"
|
| U | SynTPLpr | SynTPLpr.exe | "Synaptics TouchPad driver helper - included with drivers for Synaptics based TouchPads |
| X | SYS1 | explorar.exe | "Added by the SILLYFDC.BDJ WORM!"
|
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
|
| X | SysCleaner | SysCleaner.exe | "SysCleaner rogue cleaning utility - not recommended |
| X | SysCom | msnmsgr.exe | "Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%MSN Messenger or %ProgramFiles%Windows LiveMessenger. This one is located in %Windir%\system"
|
| X | sysconfig | iexplorer.exe | "Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | sysfiler | sysfiler.exe | "Added by the RETSAM TROJAN!"
|
| X | SysManager | Manager.EXE | "Added by the DAGGER.140 TROJAN!"
|
| X | sysMett1 | explorer.exe | "Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
|
| X | sysmngr32 | sys64mnger.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sysmon | SystemMonitor.exe | "Added by the NUJAMA-A WORM!"
|
| X | sysPersonalFirewall | msnmssgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | sysPersonalFirewall | tskm0nitor.exe | "Added by the SDBOT.APC WORM!"
|
| X | SysProtector | SysProtector.exe | "SysProtector rogue security software - not recommended |
| X | SysRes | TASKMANAGER.exe | "Added by the ELIPTER.A or ELIPTER.B WORMS!"
|
| X | system | Explorer.exe | "Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | System | YPager.exe | "Added by the JUNTADOR.K TROJAN! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger"
|
| X | System | cber.exe | Added by an unidentified TROJAN!
|
| X | system | messenger.exe | Added by an unidentified WORM or TROJAN!
|
| X | SYSTEM | windmupdr.exe | "Added by a variant of the RBOT WORM!"
|
| X | system | svcr.exe | "Added by the SPYONE TROJAN!"
|
| X | System | Xsfr.exe | "Added by the CULLER-D WORM!"
|
| X | System 64 Driver for Games | sys64dvr.exe | "Added by the SDBOT TROJAN!"
|
| X | System CGI Manager | syscgmgr.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | system check | updater.exe | Unidentified adware downloader
|
| X | System Download Manager | SysMgr.exe | "Added by the RBOT.CIG WORM!"
|
| X | System driver | Messenger.exe | "Added by the WOOTBOT.GI WORM!"
|
| U | System Files Updater | System Files Updater.exe | "System Files Updater from Flyakiteosx ""will transform the look of an ordinary Windows XP system to resemble the look of Mac OS X"""
|
| X | System Manager | sysmgr.exe | "Added by the IRCBOT.AGW BACKDOOR!"
|
| X | System Manager | sysmngr.exe | "Added by the IRCBOT.BAQ BACKDOOR!"
|
| U | System Mechanic Popup Blocker | PopupBlocker.exe | "Popup blocker part of Iolo System Mechanic utility suite"
|
| U | System Mechanic Popup Stopper | Popupstopper.exe | "Popup stopper part of Iolo System Mechanic utility suite"
|
| X | System Process | CSRSR.exe | "Added by the AGOBOT-SQ WORM!"
|
| X | System Registry Manager | sysrgmgr.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | System Service | exp0lrer.exe | "Added by a variant of the RBOT WORM!"
|
| X | System Service | teskmangr.exe | "Added by the RBOT-AUV WORM!"
|
| X | SYSTEM service helper | svchelper.exe | "Added by the MONKBD-A WORM!"
|
| X | System Services Monitor | server.exe | "Bifrost malware"
|
| X | System Update | wupdmgr.exe | "Added by the SOROMO-A TROJAN!"
|
| X | System Update Application | msbuffer.exe | "Added by the SDBOT.AFF WORM!"
|
| X | System Update2 | explorer.exe | "Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | System Update2 | wupdmgr.exe | "Added by the AUTOTROJ-C TROJAN!"
|
| X | System51616 | msnmsgesser.exe | "Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
|
| X | SystemArmor | SystemArmor.exe | "SystemArmor rogue security software - not recommended |
| X | SystemB | MessengerStopper.exe | "MessStopper adware"
|
| X | SystemBooster2009 | sbr_updater.exe | "SystemBooster2009 rogue system suite - not recommended |
| X | Systemboot | msnsngr.exe | "Added by a variant of the RBOT WORM!"
|
| X | SystemData | MBlocker.exe | "Messenger Blocker rogue security software - not recommended"
|
| X | SystemDefender | SystemDefender.exe | "SystemDefender rogue spyware remover - not recommended |
| X | SystemFighter | SystemFighter.exe | "SystemFighter rogue security software - not recommended |
| ? | SystemGuardAlerter | SystemGuardAlerter.exe | "Part of the Iolo System Mechanic maintenance software. What does it do?"
|
| X | SystemGuardCenter | SystemGuardCenter.exe | "System Guard Center rogue security suite - not recommended |
| X | Systems | sescmgr.exe | "Added by the DWNLDR-GAH TROJAN!"
|
| U | SystemService | nsserver.exe | "NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | SystemTuner | SystemTuner.exe | "System Tuner rogue system suite - not recommended |
| X | SystemWarrior | SystemWarrior.exe | "SystemWarrior rogue security software - not recommended |
| U | SystemWizard Sniffer | Sniffer.exe | "SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC"
|
| X | systr | SYSERVER.exe | "Added by the VB-DQY WORM!"
|
| X | Systray | w32explorer.exe | "Added by the RBOT-AJY WORM!"
|
| X | sys_Runtt1 | explorer.exe | "Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
|
| X | Syzmy3 | exp1orer.exe | "Added by the LINEAG-AIO TROJAN! Note the number ""1"" in the filename"
|
| X | SyztMy | expiorer.exe | "Added by the LINEAG-AIN TROJAN!"
|
| N | T-DSL SpeedMgr | speedmgr.exe | T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically
|
| ? | TAcelMgr | TAcelMgr.exe | "TOSHIBA Acceleration Utilities related. What does it do and is it required?"
|
| X | TAKSMGN | taskmr.exe | "Added by the RBOT-AHS WORM!"
|
| N | TalkingReminder | TALKINGREMINDER.EXE | "Talking Reminder from Software River Solutions - talking calendar reminder"
|
| U | TallyGenicom PanelMgr | SSMMgr.exe | "Monitors ink levels |
| ? | TangoManager | TangoManager.exe | "Tango Broadband access software. Is it required?"
|
| X | Task | tasker.exe | "Added by the MYDOOM.R WORM!"
|
| X | Task Bar | TASKBAR.EXE | "Added by the FRETHEM.J WORM!"
|
| ? | Task BarSvr | TaskBarSvr.exe | "Part of the Starband satellite always on internet service. Not included on the current system. What does it do and is it needed?"
|
| X | Task Manager | taskmngr.exe | "Added by the RBOT.Y WORM!"
|
| X | Task manager | taskemngr.exe | "Added by the RBOT-AGA WORM!"
|
| X | Task manager | taskmngr.exe | "Added by the RBOT-AYZ WORM!"
|
| X | Task Manager | tskmngr.exe | "Added by the RBOT-GOU WORM!"
|
| X | Task manager | taskmangr.exe | "Added by the SPYBOT-CH WORM!"
|
| N | Taskbar | Taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
|
| X | taskdir | taskdir.exe | "Added by the LAGER.AQ TROJAN!"
|
| X | taskmanager | taskmanager.exe | "Added by the AGOBOT-TF WORM!"
|
| X | taskmanger | taskmanger.exe | "Added by a variant of the RBOT WORM!"
|
| X | Taskmgr | Taskmgr.exe | "System1060 homepage hi-jacker. Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1060"" sub-folder"
|
| X | taskmgr | taskmgr.exe | "Added by the STARTPAGE.G hijacker. Note - this is NOT the Windows Task Manager file!"
|
| X | taskmgr | explorer.exe | "Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | taskmgr | taskmanager.exe | "Added by the BCKDR-QHT BACKDOOR!"
|
| X | TaskMgr | keymayker.exe | "Added by the LDPINCH-EP TROJAN!"
|
| N | taskmgr.exe | taskmgr.exe | "Windows Task Manager in Windows XP. If run from the Startup folder |
| X | taskmgr.exe | paint.exe | Added by a variant of the AGENT.AH TROJAN!
|
| X | taskmgr.exe | mirc.exe | Added by a variant of the AGENT.AH TROJAN!
|
| X | taskmgr.exe | paintms.exe | Added by a variant of the AGENT.AH TROJAN!
|
| X | taskmngr lptt01 | taskmngr.exe | "RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | taskmngr ml097e | taskmngr.exe | "RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | taskngr | taskngr.exe | "Added by the BANCOS-AWX TROJAN!"
|
| U | tbbMeter | tbbmeter.exe | "tbbMeter - bandwidth meter developed by thinkbroadband.com ""to help you monitor your Internet usage. It allows you to see how much your computer is sending to and receiving from the Internet in real time. It also shows you how your Internet usage varies at different times of the day"""
|
| U | tcomantidialerrun | T-Com Antidialer.exe | "T-Com Antidialer from T-Com internet provider. It's a small antidialer utility which monitors whether you're trying to dial a new connection. It basically asks you do you want to dial the shown number or not. Protects agains dialer malware"
|
| X | TCPServer | TCPServer.exe | "Added by a variant of the SDBOT WORM!"
|
| X | tcupdater | tcupdater.exe | Topconverting.com/180Search adware updater
|
| Y | TeaTimer | TeaTimer.exe | "Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options |
| U | tgcmd | hcenter.exe | "Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | The Easy Bee's Hive | ATCEgSvr.exe | "The Easy Bee is a software that allows you to record Internet navigation sequences |
| X | The Spy Guard Monitor | spyguard_monitor.exe | "The SpyGuard rogue spyware remover - not recommended |
| X | TheLastDefender | LastDefender.exe | "The Last Defender rogue security software - not recommended |
| U | Thoosje Vista Sidebar | Thoosje Vista Sidebar.exe | "Thoosje's Vista Sidebar - sidebar and skins for microsoft Windows XP and Vista"
|
| U | ThrustTSR | TMTMTSR.exe | "Thrustmaster Thrustmapper - ""t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"""
|
| X | Time Manager | TimeManager.exe | "Added by the MYTOB-BV WORM!"
|
| U | Timemanager.exe | Timemanager.exe | "Time Manager will let you track billable and non-billable time by customer |
| X | TIMER | TIMER.EXE | "Added by the TIMESE.AG WORM!"
|
| U | TimounterMonitor | TimounterMonitor.exe | "Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
|
| N | Tiny Watcher Logon Time | Watcher.exe | "Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items"
|
| U | TivoServer | TiVoServer.exe | "Tivo Server - installed with the TiVo Home Media Option. It streams audio files to your television/home theater from your PC"
|
| U | TivoTransfer | TivoTransfer.exe | "Tivo Transfer Service. TiVo Desktop is an easy-to-use application that lets you publish and share digital music |
| U | tlntsvr | tlntsvr.exe | "Microsoft program associated with Telnet"
|
| ? | Tmmkb | Tmmkysvr.exe | "Toshiba multi-media keyboard software - possibly including creating keyboard shortcuts?"
|
| N | TMMonitor | tmmonitor.exe | "System Tray access and sync monitor for TotalMedia from Arcsoft - ""an all-in-one multimedia application that allows you to access and work with digital photos |
| U | TMTMTSR | TMTMTSR.exe | "Thrustmaster Thrustmapper - ""t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"""
|
| U | Toggler | toggler.exe | """Toggler allows you to gain control over your Caps Lock |
| X | Tok-Cirrhatus-1959sarc | sv711224030r.exe | "Added by the BRONTOK-R WORM!"
|
| N | toolbar_eula_launcher | EULALauncher.exe | "Related to Google Desktop"
|
| N | Tor | tor.exe | "Tor anonymous internet communication system. Shortcut available via Start -> Programs"
|
| N | ToshibaPinger | pinger.exe | "Pinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any |
| X | Total PC Defender | Total PC Defender.exe | "Total PC Defender rogue security software - not recommended |
| X | Total Protect 2009 | pcpc_starter.exe | "Total Protect 2009 rogue security software - not recommended |
| U | TotalMedia Backup Monitor | uBBMonitor.exe | "ArcSoft's TotalMedia Backup - ""Backing up your precious photos |
| U | TPHKMGR | TPHKMGR.exe | "Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue ""ThinkVantage"" or ""Access IBM"" help key |
| U | TPHKMGR.exe | TPHKMGR.exe | "Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue ""ThinkVantage"" or ""Access IBM"" help key |
| U | TPHOTKEY | TPHKMGR.exe | "Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue ""ThinkVantage"" or ""Access IBM"" help key |
| U | TPP Auto Loader | Tppaldr.exe | "Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD |
| ? | TPwrMgr | TPwrMgr.exe | "Found on a Toshiba laptop. Related to power management?"
|
| X | tracesweeper | tracesweeper.exe | "Trace Sweeper rogue privacy tool - not recommended"
|
| U | Track4WinMonitor | STMonitor.exe | "Track4Win Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
| ? | Tracker | Tracker.exe | "Possibly associated with My Deluxe Invoices program"
|
| U | Tray Folder | Tray Folder.exe | "Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here"
|
| U | TrayFolder | Tray Folder.exe | "Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here"
|
| N | TrayServer | TrayServer.exe | For monitoring tray icons
|
| N | tray_helper | tray_helper.exe | "Tray Helper is an Email checker with additional tools |
| X | Trojan Guarder Gold Version | Trojan Guarder.exe | "TrojanGuarder rogue security software - not recommended"
|
| U | True Internet Color Icon | internetcolor.exe | "Part of 3Deep® from E-Color (now superseded by 3DxWizzard™) - ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"""
|
| N | TrueImageMonitor.exe | TrueImageMonitor.exe | "Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
|
| X | Trust Cleaner | TrustCleaner.exe | "Smitfraud variant"
|
| X | TrustDoctor | TrustDoctor.exe | "TrustDoctor rogue security software - not recommended |
| X | TrustFighter | TrustFighter.exe | "TrustFighter rogue security software - not recommended |
| X | TrustSoldier | TrustSoldier.exe | "TrustSoldier rogue security software - not recommended |
| X | TrustWarrior | TrustWarrior.exe | "TrustWarrior rogue security software - not recommended |
| N | TSMsger | TSMsger.exe | "Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
|
| ? | Tukati | TukatiRedistributor.exe | "Tukati Digital Content Distribution. Is it required?"
|
| U | TuneUp MemOptimizer | memoptimizer.exe | "Part of ""TuneUp Utilities"" |
| U | TurboMemoryCharger | turbomemorycharger.exe | "Turbo Memory Charger - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| ? | Tweak Manager | WinManager.Exe | "WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?"
|
| U | twister | twister.exe | "Twister ""AntiTrojanVirus"""
|
| ? | TypeRegChecker | TypeRegChecker.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| U | typeteller | typeteller.exe | "TypeTeller keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | UberIcon | UberIcon Manager.exe | "Uber Icon by Punk Labs. Creates a more customizable atmosphere on your desktop by extending Windows to perform new effects when you launch your icons and folders"
|
| X | UCmd | fallfour.exe | "Added by the SDBOT-AZA WORM!"
|
| N | Uidler | Uidler.exe | Uniloc Titlewave Browser used with some shareware
|
| N | UIWatcher | UIWatcher.exe | "Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2 |
| ? | Ulead AutoDetector | Monitor.exe | "Related to Ulead Systems Inc. programs. What does it do and is it required?"
|
| ? | Ulead AutoDetector v2 | monitor.exe | "Related to Ulead Systems Inc.. What does it do and is it required?"
|
| U | Ulead Memory Card Detector | Monitor.exe | "Ulead Memory Card Detector - ""Automatically starts datadownload when your card is inserted into a memory card reader"""
|
| X | Ultimate Cleaner | UltimateCleaner.exe | "Ultimate Cleaner rogue security software - not recommended |
| X | Ultimate Defender | UltimateDefender.exe | "Ultimate Defender rogue security software - not recommended |
| X | Ultimate Fixer | UltimateFixer.exe | "UltimateFixer rogue system error and cleaning utility - not recommended"
|
| X | Undefined | winter.exe | "Added by the KILLAV.LW TROJAN!"
|
| N | Uniblue Registry Booster | RegistryBooster.exe | "RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean |
| N | Uniblue RegistryBooster 2 | RegistryBooster.exe | "RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean |
| N | Uniblue RegistryBooster 2009 | RegistryBooster.exe | "RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean |
| U | Uniblue SpyEraser | spyeraser.exe | "SpyEraser from Uniblue. Spyware detection program"
|
| U | UniblueSpeedUpMyPC | Launcher.exe | "SpeedUpMyPC 2009 from Uniblue - which ""lets you monitor and control all your PC resources with easy |
| X | Update | CDUpdater.exe | """Carpe Diem"" adult premium rate dialler related"
|
| N | Update Manager | UpdateManager.exe | "Searches for updates for the Rogers Yahoo! Browser - can be run manually"
|
| X | update mon sys | updaterar.exe | "Added by a variant of the RBOT WORM!"
|
| X | Update.exe | ravseuper.exe | "Added by the QQPASS-P TROJAN!"
|
| N | UpdateChecker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| X | UpdateManager | updmanager.exe | "Added by the ANYHOMB.F TROJAN!"
|
| X | UpdateMgr | updmgr.exe | "SouthBeachTel premium rate adult content dialer"
|
| N | updateMgr | AdobeUpdateManager.exe | Automatic updates for the Adobe Reader file viewer
|
| N | updatemgr.exe | updatemgr.exe | "Once a month |
| X | updater | wupdater.exe | "KeenVal adware"
|
| ? | updater | updater.exe | "??"
|
| N | UPDATE~1 | updatemgr.exe | "Once a month |
| X | Updmgr | updmgr.exe | "KeenVal adware"
|
| X | updmgr | rvupdmgr.exe | "KeenVal adware"
|
| X | updtr.exe | updtr.exe | "Added by the AGENT-MXG TROJAN!"
|
| X | USAR | USAR.exe | "Ultimate Spyware Adware Remover - not recommended |
| X | USB Device Server! | usbserver.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | USBConfigration2 | wmmndir.exe | "Added by the AGOBOT-SV WORM!"
|
| U | USBDetector | USBDetector.exe | USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
|
| X | User Messenger Manager | usnmsgr.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Userinit | cologsver.exe | "Added by the DROPPER.DJO TROJAN!"
|
| X | Usrr | rncr.exe | "PurityScan adware"
|
| ? | v | WMPVer.EXE | "Dritek System Inc. 3D Mouse related. Is it required?"
|
| X | VBouncer | VirtualBouncer.exe | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
| X | VbouncerDL | VBouncerInner.exe | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
| X | VBundleOuterDL | BundleOuter.EXE | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
| N | VCDPlayer | VCDPlayer.exe | "Virtual CD drive emulator. Available via Start -> Programs"
|
| U | VCDTower | VCDTower.exe | "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive |
| N | Vegas Palms - Launcher | Launcher.exe | "Vegas Palms on-line cassino"
|
| ? | Verizon Custom Uninstall Tracking | InstallHelper.exe | "Verizon related installation tracker. What does it do and is it required?"
|
| X | Video Lan Player | VideoLanPlayer.exe | "Added by the RBOT-MY WORM!"
|
| X | Video Manager | videomgr.exe | "Added by the PANDEM.C WORM!"
|
| X | VideoDriverHook | vmdriver.exe | "Added by the BCKDR-PSS BACKDOOR!"
|
| N | VidSvr | vidsvr.exe | MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
|
| U | Viewbar | Viewbar.exe | "Agloco Viewbar is a small toolbar that rests on the bottom of your screen or browser window while you surf the Internet. The Viewbar software is what enables AGLOCO to collect the money you are earning while browsing the Internet"". Get paid for browsing but you must consent to them collecting your personal information"
|
| N | ViewMgr | ViewMgr.exe | "Viewpoint Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL |
| U | ViivMonitor | ViivMonitor.exe | "Related to Intel Media Share Software. ""Stream or download media files from your Intel® Core®2 Processor with Viiv® technology-based PC"""
|
| X | Virtual Bouncer | VirtualBouncer.exe | "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove |
| U | VirtualExpander | VirtualExpander.exe | "Micro Vault Virtual Expander from Sony for their range of USB memory sticks. This software will compress your data to virtually store about 3 times as much data"
|
| U | VirtuaReminder | VirtuaReminder.exe | "VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments |
| X | Virus Remover Profesional | virusremover.exe | "Virus Remover Profesional rogue security software - not recommended |
| X | VirusBurster | VirusBurster.exe | "VirusBursters rogue security software - not recommended |
| X | virusbye | virusbyeUpdater.exe | "VirusBye rogue security software - not recommended"
|
| X | VirusIsolator.exe | VirusIsolator.exe | "VirusIsolator rogue security software - not recommended |
| U | VirusKeeper | VirusKeeper.exe | "VirusKeeper uses a powerful real-time threat detection engine"
|
| X | VirusLocker | VirusLocker.exe | "VirusLocker rogue security software - not recommended |
| X | VirusRanger | VirusRanger.exe | "VirusRanger rogue security software - not recommended"
|
| X | Virus_Scanner | Virus_Cleaner.exe | "Added by the PANOL WORM!"
|
| X | VisualStudio | msorunner.exe | "Added by a variant of the TACTSLAY TROJAN!"
|
| X | VITAL BOOT PROCESS | taskmngr.exe | "Added by a variant of the RBOT WORM!"
|
| X | VITAL BOOT PROCESS | taskmnsgr.exe | "Added by the Rbot-VY WORM!"
|
| X | Vital Load Process | Spoolsvr.exe | "Added by the RBOT.AIF WORM!"
|
| X | vmsnGraber | VMSNGRABER.EXE | "Added by the ENVID.B WORM!"
|
| X | VMware Tools | Xplorer.exe | "Added by the AUTOIT.K TROJAN!"
|
| X | vnmispoisn downloader | vnmispoisn downloader.exe | SearchBarCash adware variant
|
| N | VoipBuster | VoipBuster.exe | "VoipBuster - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| N | VoipRaider | VoipRaider.exe | "VoipRaider - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| ? | voowsmcr | huhdir.exe | "??"
|
| N | VsEcomrEXE | VSECOMR.EXE | From McAfee VirusScan up to version 4.x. This executable is responsible for the periodic "update" prompts
|
| Y | VSOCheckTask | mcmnhdlr.exe | "Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically |
| X | vst | vstkmgr.exe | "Added by the AGOBOT.SK WORM!"
|
| U | VTTimer | VTTimer.exe | Driver file for the on-board VIA/S3G KM400/KN400 graphics which enables TV in/out communication
|
| N | vTunerStartUp | vTuner.exe | "vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet""
|
| U | VZAccess Manager | VZAccess Manager.exe | Verizon Access manager for enterprises
|
| U | VZRemoteCommander | AvRmtCtr.exe | Related to Sony's VAIO Zone Remote Commander
|
| X | W32PluginsDownloaderXMLHTTPSelfClearing7520 | wiper.exe | "Added by the PROXYSER-M TROJAN!"
|
| U | wallchgr.exe wstart | Wallchgr.exe | "WallChanger - wallpaper changer from Blue Tree Software"
|
| X | WallPaper | taskimgr.exe | "Added by the BANKER-GX TROJAN!"
|
| U | WallpaperChanger | Wallpaper.exe | "A wallpaper changer and manager utility. There is the Freeware version and the Pro version. The freeware version is completely free. The Pro version is 30-day trialware |
| N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client
|
| U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
|
| U | WashAndGo - Cleanup of old Backupfiles | checker.exe | "WashAndGo - temp file cleaner"
|
| U | Washer | washer.exe | "Window Washer from Webroot Software. Useful utility that deletes safe to remove files |
| U | WatcherHelper | WaHelper.exe | "Sierra Wireless Watcher™ - wireless configuration utility"
|
| X | waumgr | waumgr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| Y | WaveFramer | WaveFramer.exe | "Part of SafeSpace (from Artificial Dynamics) which ""protects computers from Internet malware infection without the need for signature updates or regular maintenance"""
|
| Y | WavXMgr | WavXDocMgr.exe | "Part of Wave Systems Corp. Embassy Trust Suite. ""Document Manager uses the hardware security provided by the TPM to provide strong protection for data. Files encrypted by Document Manager cannot be located or viewed by others"""
|
| X | Wbcmgr | wbcmgr.exe | "Added by the SLENFBOT.AW WORM!"
|
| X | WCESMngr | WCEMNGR.EXE | "Added by the AGOBOT-QX WORM!"
|
| N | wcmdmgr.exe | wcmdmgr.exe | "Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
|
| X | WCPT | wintsvtr.exe | "PurityScan adware"
|
| U | WD Backup Monitor | uBBMonitor.exe | "WD Backup - customized version of ArcSoft's TotalMedia Backup for Western Digital external drives (see here)"
|
| U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click
|
| N | WEATHER | WEATHER.EXE | "Weatherbug provides current outdoor temperature in the System Tray |
| N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
|
| U | Webshots | Launcher.exe | "Webshots - software that displays photos as your screensaver and wallpaper |
| U | WebWasher | wwasher.exe | "Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs"
|
| U | wfips | iphider.exe | "ICQ (messaging/chat program) anti-bomb software. ""WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed."" For more information about ICQ bombs see here"
|
| U | WGWLocalManager | WGWLocalManager.exe | "Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution |
| Y | WgwMngr | WgwMngr.exe | "Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution |
| X | wiascr | wiascr.exe | "Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" |
| X | Wifi Booter | wifibooter.exe | "Added by the IRCBOT.ATH BACKDOOR!"
|
| X | Wifi Loader! | wifiloader.exe | "Added by the IRCBOT.XES BACKDOOR!"
|
| X | Win Patch | ntldr.exe | "Added by the SDBOT-GS WORM!"
|
| X | Win Server Updt | winserver.exe | "Added by a variant of the IMISERV TROJAN!"
|
| X | Win TaskLoader | msgmr.exe | "Added by the MYTOB.L WORM!"
|
| X | Win Update | msnmger.exe | "Added by the RBOT-GDP WORM!"
|
| X | Win Updater | WINUPDATER.EXE | "Added by the RBOT.IP WORM!"
|
| X | Win32 Configuration | mplayer.exe | "Added by the FORBOT-BZ WORM!"
|
| X | Win32 Device Loader | Win32ldr.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | win32 internet server | winserver.exe | "Added by the DERMON-D TROJAN!"
|
| X | Win32 NT Adv Services | taskmngr.exe | "Added by the RBOT-ADE WORM!"
|
| X | win32 security updates downloader | tskmngr.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Win32 Services | wuamngr.exe | "Added by the SDBOT-N WORM!"
|
| X | win32 system server | winserver.exe | "Added by the DERMON-A TROJAN!"
|
| X | Win32 USB2 Driver | updatemgr.exe | "Added by a variant of the FORBOT WORM!"
|
| X | WIN32DS | clienttimer.exe | "Eziin adware"
|
| X | Win32Host Process | webemir.exe | "Added by the TURGEN -A TROJAN!"
|
| X | WIN32io | clienttimer.exe | "Eziin adware"
|
| X | win32serv | devicer.exe | "Added by the CHECKOUT WORM!"
|
| U | Winacsr | Winacsr.exe | "AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | WinBar | WinBar.exe | ""WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls""
|
| X | WinButler | WinButler.exe | Identified as a variant of the Trojan-Dropper.Agent.DKN malware
|
| N | WinCinemaMgr | WinCinemaMgr.exe | "WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| U | WinColorReminder | WinColorReminder.exe | "The Microsoft Color Control Panel Applet for Windows XP ""helps you manage Windows color settings in one place."" Part of the Pro Imaging Powertoys"
|
| X | Wind Optimizer | WindOptimizer.exe | "Wind Optimizer rogue system optimization tool - not recommended |
| X | Wind0ws Sharing | ssprotecter.exe | "Added by the RBOT-AHW WORM!"
|
| X | windefender | windefender.exe | "Added by the AGENT.BYH TROJAN!"
|
| X | Windeows NetStart Service2 | tesakrmger.exe | "Added by the RBOT-AMY WORM!"
|
| X | WinDLL (smaprnter.exe) | "rundll32.exe smaprnter.exe | start" |
| X | WinDLL (tepmlayer.exe) | "rundll32.exe tepmlayer.exe | start" |
| X | WinDLL (Wseclayer.exe) | "rundll32.exe Wseclayer.exe | start" |
| X | Windowfdgfds DasdLL Verifier | winupdatr.exe | "Added by the AGOBOT.HZ WORM!"
|
| X | Windows | explorer.exe | "Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | WINDOWS | ymssgr.exe | "Added by the BCKDR-PS BACKDOOR! Note - deactivates the Microsoft\Internet Connection Firewall (ICF)"
|
| X | Windows | taskmngr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows | Cfreer.exe | "Added by the CULLER-C WORM!"
|
| X | Windows | Zser.exe | "Added by the CULLER-D WORM!"
|
| U | Windows & Internet Cleaner Pro | WICleaner.exe | "Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
|
| X | Windows Auto Update | winupdater.exe | "Added by the SDBOT.TF WORM!"
|
| X | Windows Automatic Update | wuamgrder.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Automatic Updates | dvldr.exe | "Added by the RBOT.MF WORM!"
|
| X | Windows Automation | msdspr.exe | "Added by the SOLAME.A WORM!"
|
| X | Windows Backup Configuration | IEXPLORER.exe | "Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Windows Booter! | winbooter.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Bootup | task-mngr.exe | "Added by the RBOT-AWP WORM!"
|
| X | Windows Config | ZANBOR.EXE | "Added by the SPYBOT-MH WORM!"
|
| X | Windows Controls Center | winudmr.exe | "Added by the LAMER.AA BACKDOOR!"
|
| X | Windows Download Manager | windlmngr.exe | Added by an unidentified TROJAN!
|
| X | Windows Driver | winxpdriver.exe | "Added by the WOOTBOT.EE WORM!"
|
| X | Windows Driver! | windriver.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Enterprise Defender | WindowsEDefender.exe | "Windows Enterprise Defender rogue security software - not recommended |
| X | Windows Explorer | EEXPLORER.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Explorer | explorer.exe | "Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windows Explorer | Windows Explorer.EXE | "Added by the VB-EBA WORM!"
|
| X | Windows Explorer Key | explorer.exe | "Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windows Explorer.exe | Explorer.exe | "Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windows File XP Manager | wfdmgr.exe | "Added by the SDBOT.XD TROJAN!"
|
| X | Windows Fix | integator.exe | "Added by the SDBOT.ZAB WORM!"
|
| X | Windows Hijack Protection | comngr.exe | "Added by the AGENT-FYD TROJAN!"
|
| X | Windows Hijack Protection System | commngr.exe | "Added by a variant of the AGENT-FYD TROJAN!"
|
| X | Windows Host Booter | hostbooter.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | Windows Icons Manager | wicomgr.exe | "Added by the RBOT-AIF WORM!"
|
| X | Windows Kernel System Service | wkssvr.exe | "Added by a variant of the RANDEX.GEL WORM!"
|
| X | Windows Live Manager | winlivemgr.exe | "Added by the SHEUR.EB TROJAN!"
|
| X | Windows Live Messenger | msnmsgr.exe | "Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| N | Windows Live Messenger | msnmsgr.exe | "Windows Live Messenger (was MSN Messenger) utility - available via the Start menu. Disable by clicking on the ""Show menu"" icon and select Tools → Options → Sign In → deselect ""Automatically run Windows Live Messenger when I log on to Windows"". This is the Windows Defender/Vista MSConfig entry for version 14.*"
|
| X | Windows Live Messenger Addon | wllivemsngr.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Live Messenger! | livemsngr.exe | "Added by the IRCBOT.AWE BACKDOOR!"
|
| X | Windows live Support | wlmsngr.exe | "Added by the RBOT-BKL WORM!"
|
| X | Windows Local ISP | winthcr.exe | "Added by the SDBOT.ENZ BACKDOOR!"
|
| X | Windows Login | msnmsgr.exe | "Added by the AGOBOT-UC WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| X | Windows LoL Layer | gqwdcr.exe | "Added by the AGOBOT-AHS WORM!"
|
| X | Windows Media Driver | msnger.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Media Loader | wmloader.exe | "Added by a variant of the GAOBOT WORM!"
|
| X | Windows Media Player | wmediaplayer.exe | "Added by the AGOBOT-NQ WORM!"
|
| X | Windows Media Player | MediaPIayer.exe | "Added by the SDBOT-QO TROJAN! Note - the lower case ""l"" in ""MediapIayer"" is a capital ""i"""
|
| X | Windows Media Player | wmplayer.exe | "Added by the KELVIR.G WORM or variants! Note - this is not the valid Windows Media Player as the file is located in %System% rather than %ProgramFiles%\Windows Media Player"
|
| X | Windows Media Server! | wmserver.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Memory Sharing | memoryshr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Windows Memory Sharing | memshr.exe | "Added by the IRCBOT.MC BACKDOOR!"
|
| X | Windows Messenger Live MSN | winlivemsnmessenger.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows Messenger Service | winsmsgr.exe | "Added by the RBOT-VW WORM!"
|
| X | Windows modez Verifier | taskmngr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Monitor Services | winmonitor.exe | "Added by the RBOT-XX WORM!"
|
| X | Windows MS Update 32 | sucker.exe | "Added by the FORBOT-GJ WORM!"
|
| X | Windows Pc | winmgr.exe | "Added by the BIBOT-A WORM!"
|
| X | Windows Printing Driver | WinSpooler.exe | "Added by the ARCHIVARIUS series of WORMS!"
|
| X | Windows Rundll Center | msnsmgr.exe | "Added by the AGENT-LLB TROJAN!"
|
| X | Windows Scheduler | wmscheduler.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Scheduler! | scheduler.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Secure Fix | iPodFixer.exe | "Added by the WOOTBOT.BM BACKDOOR!"
|
| X | Windows Secure Update | winupser.exe | "Added by the RBOT-GCG WORM!"
|
| X | Windows Securety | wurger.exe | "Added by the AGOBOT-NC BACKDOOR!"
|
| X | Windows Server! | winsvr.exe | "Added by the IRCBOT.AYC BACKDOOR!"
|
| X | Windows Service | r.exe | "Added by a variant of the SMALL.VZ TROJAN!"
|
| X | Windows service | iexpl0rer.exe | "Added by the SDBOT.RO WORM!"
|
| X | Windows Service Agent | msnmagr.exe | "Added by a variant of the SLAPER TROJAN!"
|
| X | Windows Service Agent | msngear.exe | "Added by the RBOT.AHW BACKDOOR!"
|
| X | Windows Service Agent | msngerr.exe | "Added by the RBOT.EOZ WORM!"
|
| X | Windows Service Agent | msnmsgr.exe | "Added by the RBOT.ABIK BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| X | Windows Service Controller Agent | taksmgr.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Service Exec | ServiceLayer.exe | "Added by the SPYBOT-OI WORM! Note - do not confuse this with the Nokia service of the same name which resides in %ProgramFiles%\Common Files\PCSuite\Services or %Program Files%\PC Connectivity Solution. This one is located in %Windir%"
|
| X | Windows Service Manager | taskmgr.exe | "Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exeprocess which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""fonts\svc"" sub-folder"
|
| X | Windows Services | Explorer.exe | "Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windows Services B-Runner | svcbrunner.exe | "Added by the IRCBOT.BYV BACKDOOR!"
|
| X | Windows Services Joger | svcjoger.exe | "Added by the RBOT.CAT WORM!"
|
| X | Windows Servser | serviser.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Shell | taskgmr.exe | "Added by the MYTOB.BV WORM!"
|
| X | Windows Spooler | winsplr.exe | "Added by the SHEUR.ANX TROJAN!"
|
| X | Windows spoolservr Service | spoolservr.exe | "Added by the SDBOT-AAN WORM!"
|
| X | Windows SSL Secondary Drivers | SSL32Dr.exe | "Added by the SDBOT.ASQ WORM!"
|
| U | Windows Supervisor | winspvr.exe | "Windows Supervisor surveillance software. Uninstall this software unless you put it there yourself"
|
| X | WINDOWS SYSTEM | dcomuser.exe | "Added by the MYTOB.EO WORM!"
|
| X | WINDOWS SYSTEM | botzor.exe | "Added by the ZOTOB WORM!"
|
| X | WINDOWS SYSTEM | per.exe | "Added by the ZOTOB.C WORM!"
|
| X | WINDOWS SYSTEM | expI0rer.exe | "Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
|
| X | WINDOWS SYSTEM | Win32IMAPSVR.exe | "Added by the MYTOB-FQ or MYTOB-FU WORMS!"
|
| X | Windows System Configuration | nether.exe | "Added by the OPANKI-AB WORM!"
|
| X | Windows System Gateway | SPOOLER.EXE | "Added by a variant of the RBOT WORM!"
|
| X | Windows System Manager | winsysmgr.exe | "Added by the IRCBOT.BJG BACKDOOR!"
|
| X | WINDOWS SYSTEM MEMORY LOADER | memloader.exe | "Added by the MYTOB-IN WORM!"
|
| X | Windows System Restorer | SystemRestorer.exe | "Added by the DULOAD.C WORM!"
|
| X | Windows System32 | explorer.exe | "Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
|
| X | Windows SYSTEM32 | Realplayer.exe | "Added by the SPYBOT.ZH WORM!"
|
| X | Windows Systemnmg | stagmr.exe | "Added by the MYTOB.S WORM!"
|
| X | Windows SYStry | spoolsvr.exe | "Added by the SDBOT.GN BACKDOOR!"
|
| X | Windows Task Manager | taskgmr.exe | "Added by the MYTOB.BJ WORM!"
|
| X | Windows Task Manager | taskmngr.exe | "Added by the RBOT-ANM WORM!"
|
| X | Windows Task Manager Emulator | kennewr.exe | "Added by the SPYBOT-FA WORM!"
|
| X | Windows Task Mgr! | mstasker.exe | "Added by the IRCBOT.OE BACKDOOR!"
|
| X | Windows Taskmanager | iexplorer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Windows Taskmanager | taskngr.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows Taskmanager | tskmngr.exe | "Added by the IRCBOT.DHR BACKDOOR!"
|
| X | Windows Taskmanager | winpifviewer.exe | "Added by the PUSHBOT.BB WORM!"
|
| X | Windows Time | winmgr.exe | "Added by the RBOT-XC WORM!"
|
| X | Windows UDP Control Center | fxstaller.exe | "Added by the AGENT-IEE TROJAN!"
|
| X | Windows UDP Control Center | installer.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows UDP Control Center | winudpmsgr.exe | "Added by the SDBOT.GAV WORM!"
|
| X | Windows UDP Control Center | winupmgr.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows UDP Control Center | winudpmgr.exe | "Added by the DLOADR-HQL TROJAN!"
|
| X | Windows UDP Control Center | fxsteller.exe | "Added by the IRCBOT-J BACKDOOR!"
|
| X | Windows UDP Control Manager | winudpmgr.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | windows update | uddater.exe | "Added by the LEOX TROJAN!"
|
| X | windows update | msnsever.exe | "Added by the RBOT-AHN WORM!"
|
| X | Windows Update | taskmr.exe | "Added by the MYTOB-GZ WORM!"
|
| X | Windows Update | wupdmgr.exe | "Added by the BANCBAN-FC TROJAN and variants!"
|
| X | Windows Update | avkir.exe | "Added by the RBOT-GJP WORM!"
|
| X | Windows Update | taskngr.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Update | smsscr.exe | "Added by the BANKER-DK TROJAN!"
|
| X | Windows Update | tskmngr.exe | "Added by the AGENT.ALY BACKDOOR!"
|
| X | Windows Update Auto Update | wuaumgr.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Windows Update Check | syslodr.exe | "Added by the SMALL.LU TROJAN!"
|
| X | Windows Update Manager | wupdmngr.exe | "Added by the RANDEX.BTB WORM!"
|
| X | Windows Update Manager | WindowsUpdateManager.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Windows Updated | updatr.exe | "Added by the RBOT-AYB WORM!"
|
| X | Windows Updater Service Manager | winupdatr.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows USB 2.0 Driver | usbtskmgr.exe | "Added by the RBOT-BKG WORM!"
|
| X | Windows Workstation Start Service | mslanmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | WindowsKeyUpdate | master.exe | "Added by the JOSAM WORM!"
|
| X | Windowss Service Agent | mssngear.exe | "Added by the RBOT.KGU BACKDOOR!"
|
| X | WindowsSystem32 | asper.exe | "Added by the AGENT-EFP TROJAN!"
|
| X | WindowsSystem32 | msnmssgr.exe | "Added by the AGENT.ALY BACKDOOR!"
|
| X | WindowsSystem32 | msnmgaer.exe | "Added by the AGENT.ALY BACKDOOR!"
|
| X | Windowz Update V2.0 | Explorer.exe | "Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Windowz Update V2.0 | updater.exe | "Added by the YODO-C WORM!"
|
| U | WINDVDpatch | CTHELPER.EXE | "CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers |
| N | WinDVR SchSvr | SchSvr.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| X | WinFixer helper | wfxcwr.exe | "WinFixer web installer - ""foistware"" |
| X | WiniFighter | WiniFighter.exe | "WiniFighter rogue security software - not recommended |
| X | WinIFixer | WinIFixer.exe | "WinIFixer rogue security software - not recommended |
| U | WinIRXHelper | WinIRXHelper.exe | "MSI Media Center Deluxe software - see here"
|
| X | WinKernel | WinKer.exe | "Added by the MIRAB or SERVIDOR TROJANS!"
|
| X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related
|
| X | Winlogon | scssrr.exe | "Added by the AGENT-LXB TROJAN!"
|
| X | Winlogon Shell | Explorer.exe svchost.exe | "Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
|
| X | winlogon.exe | helper.exe | "Added by the FAKESPY-A TROJAN!"
|
| X | WINMGR | taskgmgr.exe | "Added by the MYTOB.AN WORM!"
|
| X | Winmgr.exe | scvhost.exe | "Added by the AGOBOT.AFG WORM!"
|
| X | winmngr.exe | [path to trojan] | "Added by the AGENT-ZB TROJAN!"
|
| X | WinMsg | winmsgr.exe | "Added by the DLOADR-AS TROJAN!"
|
| ? | Winnov Remote | WnvRsvr.Exe | "Winnov Video Capture Card related. What does it do and is it required?"
|
| X | winnt DNS ident | iexplorer.exe | "Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| N | Winpower | Winpower.exe | "Part of InstallAnywhere from Zero G Software |
| X | winprocessor Update | winprocessor.exe | "Added by the RBOT.IO WORM!"
|
| X | WinProt | server.exe | "Added by the CHUPACABRA TROJAN!"
|
| X | WinProtector | WinProtector.exe | "WinProtector rogue security software - not recommended |
| X | WinPWD Manager | wpwdmgr.exe | "Added by the RBOT-AUT WORM!"
|
| X | winrar | winrar.exe | "CoolWebSearch Therealsearch parasite variant. Note - this is not the file zipping utility also known as WinRAR!"
|
| X | WinReanimator | WinReanimator.exe | "WinReanimator rogue security software - not recommended |
| X | WINRUN | taskgmr.exe | "Added by the MYTOB-BX WORM!"
|
| X | WinSecured32 | ssmr.exe | "Added by a variant of the FORBOT WORM!"
|
| U | WinService32 | ssmgr.exe | "007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
|
| ? | Winshoe | wuadfdqr.exe | "Probably an unidentified VIRUS! Adds itself to 3 registry ""Run"" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed"
|
| X | Winsock driver | tcpmngr.exe | "Added by the SPYBOT-CK WORM!"
|
| X | winsock2 | netsvr.exe | "Added by the AGOBOT.LY WORM!"
|
| X | Winsock2 driver | WUAUMQR.EXE | "Added by the SPYBOT-DP WORM!"
|
| X | Winsock2 driver | WWEUMQR.EXE | "Added by the SPYBOT-BY WORM!"
|
| X | Winsock32driver | win32server.exe | "Added by the BACKDOOR-AZV TROJAN!"
|
| X | Winsock32driver | win32server.exe | "Added by the HACARMY.F TROJAN!"
|
| X | winsockdriver | iexplor.exe | "Added by the BLATIC.A WORM!"
|
| X | Winsocks2 driver | mznmgr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Winspool | spoolsvr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | WinSpyKiller | WinSpyKiller.exe | "WinSpyKiller rogue spyware remover - not recommended |
| X | WinStabilizer | WinStabilizer.exe | "Added by the AGOBOT-SW WORM!"
|
| X | winsupdater | winsupdater.exe | "Added by the ALCRA-F WORM!"
|
| X | winsupdatesysmngr64 | winsys64mnger.exe | "Added by the RBOT-BAG WORM!"
|
| X | Winsvr manager | DDEsvr.exe | "Added by the TIRBOT-C WORM!"
|
| X | WINTASK | taskgmr.exe | "Added by the MYTOB.I WORM and variants!"
|
| X | WINTASK | taskgamr.exe | "Added by the MYTOB.AU WORM!"
|
| X | WINTASK | iexplorer.exe | "Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | WINTASK | t4skmgr.exe | "Added by the MYTOB-AK WORM!"
|
| X | WINTASK | t4skgmr.exe | "Added by the MYTOB.CM WORM!"
|
| X | WINTASK32 | taskgmrr.exe | "Added by the MYTOB.FX WORM!"
|
| X | WINTASKMANAGER | taskgmr.exe | "Added by the MYTOB-AF WORM!"
|
| X | WINTASKS | taskgmr.exe | "Added by the MYTOB.BO WORM!"
|
| X | WinUPD32 | explorer.exe | "Added by an unidentified VIRUS |
| X | winupdateconn_ | Explorer.EXE | "Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | WinUsr | WinUsr.exe K1S2 | "Added by the CLUNK.A WORM!"
|
| U | WinUtilities Memory Optimizer | ToolMemoryOptimizer.exe | """WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!"" MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | WinVNC | iexplorer.exe | "Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | WinWorks | vstmgr.exe | "Added by the AGOBOT.ACJ WORM!"
|
| X | WinX Security Center | WinX Security Center.exe | "WinX Security Center rogue security software - not recommended |
| X | WinXDefender | WinXDefender.exe | "WinXDefender rogue spyware remover - not recommended |
| X | WinXProtector | WinXProtector.exe | "WinXProtector rogue security software - not recommended |
| X | WinXPService | taksmgr.exe | Identified as a variant of the IRC/Flood.tool malware
|
| X | WinXPService | taksmgr.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in %System%"
|
| X | WinXPService | taksmgr.exe | "Added by the KIRSUN.A BACKDOOR! The file is located in the root directory |
| N | Wireless Console | wcourier.exe | "ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
|
| N | Wireless Console 2 | wcourier.exe | "ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
|
| N | Wireless Console 3 | wcourier.exe | "ASUS Wireless Console - installed alongside ASUS wireless components and provides additional configuration options for these devices"
|
| U | Wireless Presenter | Wireless Presenter.exe | """Use your Nokia phone as a remote control for your PC with Nokia Wireless Presenter. Using Bluetooth wireless technology |
| X | Wireless Provider Server | wpsvr.exe | "Added by the FORBOT-AD WORM!"
|
| U | Wireless Switching Setting Utility | Switcher.exe | "On a Sony laptop with built in wireless it allows the user to select which wireless services they want to run (i.e. Wireless LAN |
| X | WIZZ | dazzler.exe | "Detected by Kaspersky as the DIALER.IS TROJAN!"
|
| X | WksSVC | EXPLORER.exe | "Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| U | WLAN Manager | WLANManager.exe | Wireless management utility for the T-Com Speedport W 100 Card WLAN PCMCIA card
|
| N | WM VCR | WMVCR.exe | "WM Recorder allows you to record Windows Media(tm) streaming Video or Audio content. Can be accessed via Start Menu -> Programs"
|
| X | wmplayer.exe | wmplayer.exe | "Added by the BANCBAN-CZ TROJAN! Note - this is not the valid Windows Media Player as the file is located in %Windir% rather than %ProgramFiles%\Windows Media Player"
|
| X | word pair | bopotsvr.exe | "Added by the SHED-A TROJAN!"
|
| X | wow | bar.exe | "PurityScan adware"
|
| X | wow | Launcher.exe | "Added by the DELF-DOR TROJAN!"
|
| X | WPlayer | WPlayer.exe | Identified as a variant of the LDPinch.A malware
|
| ? | wr | WR.EXE | "??"
|
| ? | WR Command | wr.exe | "??"
|
| X | WRDialer | WrDialer.exe | WinPoet DSL dialler
|
| U | WScheduler | WScheduler.exe | "Windows Scheduler - "schedule unattended running of applications |
| X | wscmgr | wscmgr.exe | "Added by the AUTORUN-AA WORM!"
|
| X | wserver | wserver.exe | "Added by the NETSKY.AC or SASSER.G WORMS!"
|
| X | WTST | wapisvtr.exe | "PurityScan adware"
|
| X | wuviewer | wuviewer.exe | "Added by a Proxy Trojan variant"
|
| N | WXProcMgr Module | WXprocMgr.exe | "TVTonic from Wavexpress - ""enjoy 3 full-screen |
| X | wzhelper | wzhelper.exe | "Searchcentrix hijacker"
|
| U | X-Cleaner Deluxe | xcleaner.exe | "X-Cleaner Deluxe - privacy and anti-spy application"
|
| U | X1FileMonitor.exe | X1FileMonitor.exe | "Part of X1's Enterprise Desktop Search Resource Center. An enterprise desktop search engine"
|
| U | xbtl | bootldr.exe | "Active Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | XemiComputers Scheduler | Scheduler.exe | "Smooth Program Scheduler from XemiComputers ""will start any program you want at a scheduled time"""
|
| U | Xerox PanelMgr | SSMMgr.exe | "Monitors ink levels |
| Y | XFILTER | xfilter.exe | "Filseclab Personal Firewall Professional Edition"
|
| X | xftpGraber | Xftpgraber.exe | "Added by the ENVID.C WORM!"
|
| X | XP Protection Center | XPProtectionCenter.exe | "XP Protection Center rogue security software - not recommended |
| X | XP SecurityCenter | XPSecurityCenter.exe | "XPSecurityCenter rogue security software - not recommended |
| N | Xpadder | Xpadder.exe | """Xpadder simulates the keyboard and mouse using your gamepad"""
|
| U | XPCMonitor | XPCMonitor.exe | "XPC Monitor Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | XPdefender | XPdefender.exe | "XPdefender rogue spyware remover - not recommended |
| X | Xplorer | Xplorer.exe | "Added by the AUTOIT-BP WORM!"
|
| X | XpyBurner | XpyBurner.exe | "XpyBurner rogue spyware remover - not recommended |
| ? | XTCsgloader | XTCsgloader.exe | "Another Xupiter toolbar variant??"
|
| X | XupiterCfgLoader | XTCfgLoader.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | XupiterCfgLoader | BWCfgLoader.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | XupiterToolbarLoader | XupiterToolbarLoader.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| U | Y'z Toolbar | YzToolBar.exe | "Y'z Toolbar ""allows the user to change the toolbar icons in Explorer and Internet Explorer. The user can also create and add their own themes"""
|
| X | y1959sar | sv711224030r.exe | "Added by the BRONTOK-AK WORM and variants!"
|
| X | yahoo groups | upgrdmgr.exe | "Added by a variant of the RBOT WORM!"
|
| ? | Yahoo HP Reminder 1.1 | yr.exe | "??"
|
| X | Yahoo Instant Messengar | YahooMsgr.exe | "Added by the SDBOT.GEN TROJAN!"
|
| X | Yahoo Messenger | YPager.exe | "Added by the RBOT-QO BACKDOOR! Note - this is not the older version of Yahoo! Messenger which shares the same filename and is located on %ProgramFiles%\Yahoo!\Messenger. This one is found in %System%"
|
| X | Yahoo Messengger | regsvr.exe | "Added by the IMAUT.CN WORM!"
|
| X | Yahoo Updater | Messenger.exe | "Added by the FORBOT-FE WORM!"
|
| U | Yahoo! Mail | YMailAdvisor.exe | "Yahoo! Mail Advisor - informs you of any changes to your Yahoo! Mail settings (i.e. |
| N | Yahoo! Messenger | ypager.exe | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
| N | Yahoo! Pager | ypager.exe | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
| N | Yahoo! Pager | YahooMessenger.exe | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
| N | YahooMessenger | YahooMessenger.exe | "System Tray access to the Yahoo! Messenger instant messenger"
|
| U | YahooMonitor | YahooMonitor.exe | "Yahoo Messenger Monitor Sniffer surveillance software for the Yahoo! instant messenger. Uninstall this software unless you put it there yourself"
|
| X | yahoomsgr | Yahoomsngr.exe | "Added by the AGOBOT.AKZ WORM!"
|
| X | yahoo_toolbar lptt01 | yahoo_toolbar.exe | "RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | yahoo_toolbar ml097e | yahoo_toolbar.exe | "RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| ? | YAMAHA AC-XG Power Utility | yacpower.exe | "YAMAHA AC-XG Power Utility. What does it do and is it required?"
|
| U | YMailAdvisor | YMailAdvisor.exe | "Yahoo! Mail Advisor - informs you of any changes to your Yahoo! Mail settings (i.e. |
| N | ypager | ypager.exe | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
| N | Ypager.exe | ypager.exe | "System tray access to an older version of the Yahoo! Messenger instant messenger"
|
| U | Yumgo's Homepage Protector V1 | YumgoHomepageProtector.exe | "Yumgo's Homepage Protector"
|
| U | z-WrDialer | WrDialer.exe | WinPoet DSL dialer
|
| X | Zacker | Zacker.exe | "Added by the GEMEL WORM!"
|
| X | Zango SiteFinder | ZangoSiteFinder.exe | "ZangoSearch adware variant"
|
| U | zBrowser Launcher | Commandr.exe | "For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock |
| U | ZingSpooler | ZingSpooler.exe | Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums
|
| N | Zinio DLM | ZinioDeliveryManager.exe | "Related to Zinio used to read magazines in digital rather than paper format"
|
| X | Zolero Translator | ZoleroTranslator.exe | "Zolero Translator - added by Clickspring |
| N | Zune Launcher | ZuneLauncher.exe | "Automatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media |
| N | ZuneLauncher | ZuneLauncher.exe | "Automatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media |
| N | ZuneŽ | ZuneLauncher.exe | "Automatically launches the Zune software for Microsoft's Zune media players when they're connected to your PC. The software can be used to manage media |
| X | [12 random characters] | batmeter.exe | "IeDriver adware variant"
|
| X | [12 random characters] | asferror.exe | "IeDriver adware variant"
|
| X | [32 random hex numbers] | badware-protector.exe | "Badware Protector rogue security software - not recommended |
| X | [random name] | CXTPLS_LOADER.EXE | "AproposMedia adware"
|
| X | [random name] | ??plorer.exe | "PurityScan adware"
|
| X | [random name] | t?skmgr.exe | "PurityScan adware"
|
| X | [random name] | taskmngr.exe | "Added by the AGOBOT-CB WORM!"
|
| X | [random number] | explorer.exe | "Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
|
| X | [Randomly chosen existing folder name] | _loader.exe | "Added by the ANTINNY-L WORM!"
|
| X | [various names] | sitebar.exe | Added by an unidentified TROJAN!
|
| X | [various names] | ActionScr.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | AppMasterCenter.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | atl_helper.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | ATLIEHELPER.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | awinrar.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | CToolBar.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | ExchangeMaster.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | expoler.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | ftbar.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | gabber.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | iehelper.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | KeywordFinder.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | moniter.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | MsNetHelper.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | NSYSCPLSTR.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | SAPSTR.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | ssweeper.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | xxtoolbar.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | JAguAr.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _x-Finder | _x-Finder.exe | Disconnects and redials an ISP modem to an adult content site
|
| U | {1290A33C-85F5-4164-A1BE-7DD299D4986A} | PBKScheduler.exe | "Scheduler for CyberLink PowerBackup - archiving/backup utility"
|
| X | {DD651081-A909-45ad-BD71-2335B0ADE043} | sysabmpmfr.exe | "Added by the FAKEALERT-AH TROJAN!"
|