Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
X ools.exetools.exe"FastFind adware variant"
Xsystem32.exe"Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field"
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
XMSPF.EXE"Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xajsha5.exe"Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field"
Xregedit.exe /s appboost.reg"Added by the APPIX.D WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""appboost.reg"" is located in %Windir%"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Consume"Consumer Input Rewarded with MyPointsU"ConsumerInputRewardedwithMyPoints
Inc.""Machine WorksXaecces.exe
Inc.""Microsoft AssociatesXiexplorer.exe
Inc.""Microsoft NetMeeting AssociatesXNetMeeting.exe
Inc.""Miramar SystemsUatmsg.exe
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Mass""TelechipsUpatch.exe
please"This is a virusXbigbadvirus.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
X$sys$cmp$sys$xp.exe"Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$drv$sys$drv.exe"Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
U$Volumouse$volumouse.exe"Volumouse from Nirsoft. ""Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"""
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
?%cmpmixtitle%%cmpmixstr%"Possibly related to C-Media Mixer Control panel?"
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-end
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
N%FP%Friendly fts.exefts.exeFriendly ISP software front-end
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
X(*)API MachinewinSOCKS.exe"Homepage hijacker
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware
X(Default)Systrsy.exe"Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)syspol.exe"Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msarti.com"Added by the SILLYFDC.CJ WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\..\Policies\Explorer\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)msnupdate.exe"Added by the RBOT-GWT BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run & HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Bandookmsdll.exe"Added by an unidentified TROJAN - see here"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
Y*Restorerstrui.exePart of Windows System Restore and added as a RunOnce registry entry. Leave alone
X*Security Centersecctr.exe"Added by the SDBOT.BRO WORM!"
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*windows updatewuaruclt.exe"Added by the RBOT-TF WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
?.NET configsysmon32.exe"??"
X.NET.msnmgnr.exe"Added by the DELF.AYF WORM!"
X.nortonrchost.exe"Added by the BOXED-H TROJAN!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
N/sN/A"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
U000StTHK000StTHK.exe"Toshiba Hot key functionality for the function keys (Fn-Esc
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
U00ERSRRRNKYeraser.exe"Part of Evidence Exterminator
?00notify33NetBrowser.exe"Part of Best Network Security
?00saskdanewlock.exe saskda"Part of Access Manager
U00THotkeysystem32THotkey.exe"For Toshiba Satellite notebook series to use the front buttons
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
N1&1 EasyLoginEasyLogin.exe"1&1 EasyLogin - quick access to webhost 1&1's Control Panel
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups
U12Ghosts Clip12clip.exe"12Ghosts Clip - ""Screen shots made easy"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads
U12Ghosts Popup-Killer12popup.exe"12Ghosts Popup-Killer"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts SetColor12color.exe"12Ghosts SetColor - ""Change your desktop icon text colors
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
U12Ghosts Synchronize12sync.exe"12Ghosts Synchronize - ""Sync PC clock with an atomic clock over the Internet"""
U12Ghosts Tower12tower.exe"12Ghosts Tower - ""Quickly access and manage all Ghosts (included in all packages)"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
X180adsolution180adsolution.exe"180solutions adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X180sa180sa.exe"180Search adware"
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
?1CmailSNETMAIL.EXE"??"
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
U1Win32CfgSpyBuddy.exe"SpyBuddy from ExploreAnywhere
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2-suhartosuharto.exe"Added by the BRONTOK-CR WORM!"
X2020Downloadermssvr.exe"2020Search Toolbar"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X27csrss32.exe"Added by the SLSORVE-D TROJAN!"
X27msm32.exe"Added by the SLSORVE-E TROJAN!"
X2k6 updatzcrss3.exe"Added by the RBOT-CPD WORM!"
X2Searchmain.exe"2Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
X3.8853E+11AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
?39ELTFH25Z8SKFEzg1q5.exe"Seems to be associated with software by Resplendence SP ?"
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exe"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore)
Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3D Mouse driver
X3d_sound3d_sound.exe"Added by the RIADOS-A TROJAN!"
X3P_UDEC_IAIAInstall.exe"Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
X4-gusdurgusdur.exe"Added by the BRONTOK-CR WORM!"
U4oDKHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
X5-1-61-96members-area.exeAdult content dialler
X6-susilo bsby.exe"Added by the BRONTOK-CR WORM!"
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
X666Ska.exe"Added by the PIPES TROJAN!"
X678lsas32.exe"Added by the SLSORVE-B TROJAN!"
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
X7X29C2X78Ysyss_.exe"Added by the AGENT-GMS TROJAN!"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g MIMO Wireless UtilityRaUI.exe"Wireless configuration utility for Railink 802.11g MIMO based products"
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
Y9xadiras9xadiras.exe"Allied Telesyn AT series router/modem related - apparently required"
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Controller (and maybe othe.html" title="Access Controller (and maybe othe">Access Controller (and maybe othe
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
Access Lock (and maybe others) -.html" title="Access Lock (and maybe others) -">Access Lock (and maybe others) -
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
X@sysload.exe"Added by the DELF-EL TROJAN!"
X@regedit -s win.dll"Added by the SEEKER.K TROJAN! Note that regedit is the the legitimate Windows Registry Editor and shouldn't be deleted. The ""win.dll"" file is located in %Windir%"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
X@wincms.exe"Added by the RBOT.CBR WORM!"
X@winsys32.exe"Added by the DELF.CP BACKDOOR! Note that the entry under the Startup Item/Name field my be blank"
Xajesse.exe"Added by the MELO-A WORM!"
XaMsSvrdll.vbs"Added by the MUTAFROG!INF WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
Ya-squareda2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Ya-squareda2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-squared Anti-Dialera2adguard.exe"System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which provides ""provides a complete defense against Dialers"""
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
UA1000 Settings Utilitycpqa1000.exe"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAASSKK2LSASS.EXE"Added by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%"
?ab EazySchedulerezsched.exe"??"
Xabassabass.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
UAbsolute Shielddseraser.exe"Absolute Shield Evidence Eliminator - internet history eraser"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XABsrabsr.exe"Added by the AUTOUPDER TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
UAbyssusrazerhid.exe"Razer Abyssus gaming mouse driver - required if you use the additional features and programmed keys/macros"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
YAccelerometerStAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
YAccelerometerSysTrayAppletAccelerometerSt.exeHP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed
UAccess ConnectionsACTray.exe"System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - ""allowing users to seamlessly switch between wired and wireless environments
XAccess Control Appwinsto.exe"Added by the AGENT.DGO TROJAN!"
NAccess IBM Message Centeribmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
NAccess Ramp Monitorarmon32.exe"Monitors your progress on the internet; hang-ups
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management
XAccessMedia P2P Loaderamp2pl.exe"My AccessMedia toolbar related
UAccessoriesPlusclockplus.exe"Clock Plus
NAccessRamp Monitor01ARMon32a.exe"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup
NAccessRampLAN01ARUpld32.exe"Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file
Yaccrdsubaccrdsub.exe"ActivIdentity ActivClient - security software from ActivIdentity Corporation which ""enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login"""
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize
?Ace bowsAce bows.exe"??"
UAcer Assist Launcherlauncher.exe"Acer Assist - program that provides information about new updates or notices from Acer"
?Acer Empowering Technology MonitorSysMonitor.exe"Part of Acer Empowering Technology. What does it do and is it required?"
UAcer ePresentation HPDePresentation.exe"Part of Acer Empowering Technology. Allows you to manage both internal and external displays"
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
Uacousticacoustic.exe"Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained"
UAcrobat AssistantAcroTray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 7.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
UAcrobat Assistant 8.0Acrotray.exe"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exe"ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
UACU_QSBACU.exe"Atheros wireless Client Utility"
UAd Arrestadarrest.exe"Ad Arrest IE popup killer from GameFools"
XAddClassAddClass.exe"CoolWebSearch Addclass parasite variant"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
XAdDestroyerAdDestroyer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XAdditional GuardWI[random characters].exe"Additional Guard rogue security software - not recommended
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
Yadi DSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XaDiradirss.exe"Added by the SPAMSRV-E TROJAN!"
YAdirasAdiras.exeADSL USB modem related
Xadlhidppsncc32.exe"Added by the SLAPER.AI TROJAN!"
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process
XAdministrator di DagoDago.exe"Added by the PUNYA-B WORM!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
XAdobesysbat32.exe"Added by the LOWZONES.T TROJAN!"
NAdobe AcrobatReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
XAdobe Flash PlayerAdobeFP.exe"Added by the AUTORUN-BBP WORM!"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdobeAadobes.exe"Added by the FLOOD.BA TROJAN!"
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
XAdobeReaderProwinslog.exe"Added by a variant of the RBOT WORM!"
XAdobeReaderProlxlfsprrj.exe"Added by the RBOT.BDZ BACKDOOR!"
XAdobeReaderProcbdzfrsl.exe"Added by the RBOT.AZQ BACKDOOR!"
XAdobeReaderProsubset.exe"Added by the RBOT.OCU WORM!"
XAdobeReaderProspoolss.exe"Added by the SDBOT-AKZ WORM!"
XAdobeReaderProlssas.exe"Added by the RBOT-CLB WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProchkdisk.exe"Added by the RBOT-BDV WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
Xadodemasteradodemaster.exe"Downloader of Korean origin
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover
XAdsAlertAdsAlert.exe"AdsAlert rogue security software - not recommended"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
UAdsGoneAdsgone.exe"AdsGone - pop-up stopper"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
YADSMTrayADSMTray.exeASUS Data Security Manager provides password protected data encryption on ASUS notebooks
Uadsnweadsnwe.exe"EmailSpyMonitor E-mail surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwkadsnwk.exe"Keylogger Spy Monitor keystroke logger/monitoring program - remove unless you installed it yourself!"
Uadsnwsadsnws.exe"ScreenSpyMonitor surveillance software. Uninstall this software unless you put it there yourself"
Uadsnwyadsnwy.exe"Yahoo! Messenger Spy Monitor - ""spyware program that records Yahoo! Instant Messenger information on the computer and saves it to a log file"". Uninstall this software unless you put it there yourself"
UaDSProcMngraDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
YADSSADSS.exe"ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied"
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
UAdSubtractadsub.exe"AdSubtract blocks ads
XAdtools ServiceAdTools.exe"Windupdates Adware"
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
UADUserMonADUserMon.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
XAdware PunisherAdwarePunisher.exe"Adware Punisher rogue spyware remover - not recommended
XAdware Punisher MonitorAdwarePunisher_monitor.exe"Adware Punisher rogue spyware remover - not recommended
XAdware SpyAdwareSpy.exe"AdwareSpy rogue adware remover - not recommended
XAdwareKiller_schedulesschedules.exe"EAdwareKiller rogue spyware remover - not recommended
XAdwareSpyAdwareSpy4.exe"AdwareSpy rogue adware remover - not recommended
XAdwarz Spy RemoverADWARZ.EXE"Added by the SPYBOT-EV WORM!"
UAEFltrs ApplicationAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
?Aeiwlsta.exeAeiwlsta.exe"IBM High Rate Wireless LAN Adapter driver. Is it required?"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
UAESTFltrAESTFltr.exe"Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
?AeXSWDUsrAeXSWDUsr.exe"Altiris Express NS Client Manager software. Is it required?"
Xafmsmsgsafmsmsgs.exe"Added by the DLOADR-CUX TROJAN!"
Xafskfask8fsfjasj8.exe"Added by the ONLINEG-L TROJAN!"
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution
XAgentalsys.exe"Added by the DREF-V VIRUS!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
UAgere SoftModem Messaging AppletAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
UAGRSMMSGAGRSMMSG.exeInstalled with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem
NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
YAHNSDAhnSD.exe"AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis"
XAhorreMemoriaSysRep.exe"AhorreMemoria rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xahostahost.exe"Added by a variant of the SDBOT WORM!"
XAhstiebs.exe"PurityScan adware"
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
XAim Quick StartAim.exe"Added by the FORBOT-BB WORM! Note - this is not the popular AOL Instant Messenger utility"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
Uakeysakeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
NAlbum Fast StartABMTSR.EXE"Scanner software
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
UAlfaClock ClassicAlfaClock.exe"AlfaClock Free Edition from AlfaSoft Research Labs - ""enhances your taskbar clock (tray clock) with fully customizable clock display
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
NAlienAutopsyTest_BS.exe"Alienware computer technical support software"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
Xalkasr?????.exe"Added by the BALKART TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAll Sea screen saverTaskTray.exe"Free screensaver
XAll Sea web linkFWLink.exe"Free screensaver
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UAllSeeingEyease.exe"All-Seeing_Eye security software - ""monitors everything that takes place on your computer
UallSnapallSnap.exe"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
UALLTEL DSL Check-up Centermatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XALMcsrss32.exe"Added by the ANACON-D VIRUS!"
UAlogservAlogserv.exe"From McAfee VirusScan for logging scanning activities. In some cases
UALPassALPass.exe"ALPass password manager"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
UALServALServ.exeUtility that enables a user to control the volume and surround sound and select Pro Logic/Stereo on 2 satellite speakers and subwoofer of old Altec Lansing speaker systems. The right-side speaker has 4 controls on top providing same functionality
Xalt CTRL Shiftet3rd.exe"Added by the SDBOT-RH BACKDOOR!"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UALTOOLSAccessL.exe"ALTools family of PC utilities"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
UAlwaysReady Power Message APPARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
XAmazingTensAmazingTens.exePremium rate adult content dialler
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
UAmIcoSinglunAmIcoSinglun.exe"Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
UAMO_Taskplaner.exeAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMO_TA~1AMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAMSGAmsg.exe"Part of the IBM ThinkVantage Productivity Center. ""The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"""
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
NAMSNamsn.exe"aMSN Messenger is a multiplatform MSN messenger clone"
Xamsnamsn.exe"Added by the BANKER-BNZ TROJAN!"
XAndware DefenceZsoft32.exe"Added by the GAOBOT.OO WORM!"
Xangeleyesmsdll.exe"Added by the VB.PI TROJAN!"
Xanimalssanimalss.exe"Added by the AGOBOT-VE WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
YANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
XAntiMalwareSuiteAMS.exe"AntiMalwareSuite rogue security software - not recommended
XAntiSpionagepgs.exe"AntiSpionage
XAntiSpionagePropgs.exe"AntiSpionagePro
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiSpy2008AntiSpy2008.exe"Antispy 2008 rogue spyware remover - not recommended
XAntiSpyBossasb32.exe"AntiSpyBoss rogue security software - not recommended
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1AntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended
XAntiSpyControlpgs.exe"AntiSpyControl rogue security software - not recommended
XAntiSpyGoldenAntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGolden 5.1AntiSpyGolden 5.1.exe"AntiSpyGolden rogue spyware remover - not recommended"
XAntiSpyGuardAntiSpyGuard.exe"AntiSpyGuard rogue security software - not recommended
XAntiSpyKitAntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.2AntiSpyKit 5.2.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyKit 5.3AntiSpyKit 5.3.exe"AntiSpyKit rogue spyware remover - not recommended
XAntiSpyMonAntiSpyMon.exe"Antispyware Protector rogue security software - not recommended"
Xantispysoldierantispysoldier.exe"AntiSpyware Soldier rogue spyware remover - not recommended
XAntispySpiderantispyspider.exe"AntiSpySpider rogue spyware remover - not recommended
XAntispyStormAntispyStorm.exe"AntispyStorm rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware ProAntiSpyware Pro.exe"AntiSpyware Pro 2009 rogue spyware remover - not recommended
XAntispyware PRO XPasproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XAntispyware-2008.exeAntispyware-2008.exe"AntiSpyware 2008 rogue security software - not recommended
YAntiSpyWare2GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot rogue spyware remover - not recommended
XAntiSpywareControlpgs.exe"AntiSpywareControl rogue security software - not recommended
XAntispywareDAntispywareD.exe"AntiSpywareDeluxe rogue security software - not recommended
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue security software - not recommended
XAntiSpywareGuardasg.exe"AntiSpywareGuard rogue spyware remover - not recommended
XAntiSpywareMasterasm.exe"AntiSpywareMaster rogue security software - not recommended
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield rogue security software - not recommended
XAntiSpywareSuitepgs.exe"AntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare family"
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiSpyZoneAntiSpyZone.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.5AntiSpyZone 4.5.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.6AntiSpyZone 4.6.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 4.9AntiSpyZone 4.9.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.1AntiSpyZone 5.1.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiSpyZone 5.4AntiSpyZone 5.4.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiVituSBase.exe"Added by the BAS.A WORM!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
XAntiWorm2008pgs.exe"AntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare family"
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task ManagerAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
UAny To-Do Listanytodo.exe"Any To-Do List ""the ultimate software solution to keep yourself organized and reminded"""
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
NAOL Fast StartAOL.exe"Fast Start loads the AOL integrated email
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]"Added by an unidentified VIRUS
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed ""web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit
YAolAcsDaemon1Acsd.exe"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAolAcsDaemon1AOLACSD.EXE"AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
XAOLStartAOLStart.exe"Added by the KRAIMER.12 TROJAN!"
Xaoueisysrtmvs.exe"Chivio dialer"
YAPC UPS StatusDisplay.exe"APC PowerChute® Personal Edition status icon"
XAPcSafeAPcSafe.exe"APcSafe rogue security software - not recommended
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XApPache SystemApPache.exe"Added by the RBOT-YP BACKDOOR!"
Xappis.exeappis.exe"Added by the AGENT-BC TROJAN!"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplicationcsrss.exe"Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
XApplication In SystemSnxmsh.exe"Added by the AGENT-LNV TROJAN!"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UAppPlusAppPlus.exe"AppPlus - ""menu bar or tray launcher that docks to your desktop
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xarcaderockstararcaderockstar32.exe"Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean
NArcSoft ConnectACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArctosarazerhid.exe"Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros"
Naresares.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
NaresliteAresLite.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images
Xargq32csrss_32.exe"Added by the RBOT-CPM WORM!"
Xaromisaromis.exe"Added by the NUWAR.JQ WORM!"
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovax ShieldArovaxShield.exe"Part of Arovax Shield from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovaxShieldArovaxShield.exe"Part of Arovax Shield from Arovax
UARPWRMSGARPWRMSG.EXE"""Away Mode"" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
Xasamasam.exe"Added by the FAKEAV-BGU TROJAN!"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasc32asc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
XASDdASDd.exe"AntiSpywareDeluxe rogue security software - not recommended
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINbelgium_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINuk_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
YAshampoo AntiSpyWare 2AntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiSpyWare 2 GuardAntiSpyWare2Guard.exe"Part of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
UAshampoo Core Tunerct.exe"Ashampoo® Core Tuner from Ashampoo GmbH & Co. KG - a utility which helps you to get the most out of a multi-processor (or dual core) computer. ""For instant results you just need to select Auto-Optimize to optimize all the programs you are running or Boost to give more power to a single program"". This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access"
YAshampoo FireWallFireWall.exe"Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG"
YAshampoo FireWall PROFireWall.exe"Ashampoo® Firewall PRO from Ashampoo GmbH & Co. KG"
UAshampoo HDD Control GuardHDDControlGuard.exe"Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
UAshampoo Magical DefragaDefragCtrl.exe"System Tray access to the main user interface for Ashampoo® Magical Defrag from Ashampoo GmbH & Co. KG - which ""runs in the background as a service
UAshampoo Magical Optimizer TaskplanerAMO_TA~1.EXE"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
UAshampoo Magical Optimizer TaskplanerAMO_Taskplaner.exe"Part of Ashampoo® Magical Optimizer from Ashampoo GmbH & Co. KG - which removes stagnant and unnecessary hard drive files
Nashampoo Magical UnInstallMagicalUnInstall.exe"Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker
Nashampoo UnInstaller WatcherUIWatcher.exe"Part of the Ashampoo® UnInstaller series from Ashampoo GmbH & Co. KG - including UnInstaller Platinum 2
YashAvastashAvast.exe"Part of Avast antivirus"
Xashcapservirsess.exe"SpySure spyware"
XashDip.exeashDip.exe"Added by the DROPR-CZ TROJAN!"
YashDispashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
XashDsp.exeashDsp.exe"Added by a variant of the SDBOT WORM!"
XASHLTAshlt.exe"Ashlt adware"
YashMaiSvashmaisv.exe"E-mail scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAsiaeasm.exe"PurityScan adware"
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XaslAslru.exe"Added by the BANCOS-CU TROJAN!"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?AspireServiceAspireService.exe"Found on Acer laptops
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
XASpyCASpyC.exe"AntiSpyCheck rogue spyware remover - not recommended
Xasr64_ldm.exeasr64_ldm.exe"Added by the Dr. Guard rogue security software - not recommended
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
XAss and tittiesCMD32.EXE"Added by the SDBOT-GG BACKDOOR!"
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
XASTAST"Added by the VB.AH TROJAN!"
XASTAST.exe"AutoStarter parasite"
UASTARTastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
XAStartAStart"Added by the VB.AH TROJAN!"
NasTrayAstray.exe"Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer"
NAstroAstro.exeChecks for updates to Quicken on a system reboot
XAstrumAstrum.exe"Astrum Antivirus Pro rogue security software - not recommended
Xasusasus.exe"Added by the RBOT-OC WORM!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
UASUS TweakEnableastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
UAsusEPCMonitorAsEPCMon.exe"Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and ""on screen display"""
NASUSGamerOSDGamerOSD.exe"GamerOSD by ASUSTek - for ""real-time overclocking
NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
Xasussvcasussvc.exe"Added by the AGENT-FPB TROJAN!"
UAsusTrayAsTray.exe"Part of the ACPI driver for the Asus Eee PC range. Watches the sensors of the motherboard such as power and temperature"
UasustweakenableATweak.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
NASUSWebStorageASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NAsusWSDashBoardASUSWSDashBoard.exe"System Tray access to ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts"
NASWDPASWDP.exe"MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
XASWnkaswnk.exeAdult content dialler
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
Xatf.exepgs.exe"Part of the PCSecureSystem rogue security software - not recommended. A member of the AVSystemCare family"
Xatf_reinstallatf.exe"Part of the AVSystemCare rogue security software - not recommended. See here"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines
NATI CATALYST System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ Control Center. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
UATI Desktop ComponentATIPTAXX.EXE"Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution
XATI DisplayATIDisplay.exe"Added by the BDOOR-AFH BACKDOOR!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
NATI GART Set-up UtilityAtigart.exe"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
NATICCCCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
NAtikeyAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
UAtiTrayToolsatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
UATKOSD2ATKOSD2.exe"On-screen display utility bundled with laptops from ASUS. If this utility is not installed then you will not be able to properly use other AsusTek utilities such as Splendid and Power Gear"
NATnotesatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
UAtomSyncatomsync.exe"AtomSync - ""this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN"""
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneSystrayattune_st.exe"Aveo Attune automated helpdesk software - adware/spyware"
Yatwtusbatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
XAUDIOSOUND.exe"Added by the PLOYB-A TROJAN!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
XaugmsgAUGMSG.EXE"Added by the SPYBOT-CO WORM!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
UAuslogics BoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to ""Start programs faster. Speed up computer start time. Increase Internet speed
UAuslogics BoostSpeed 4boostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
XAuth Starter Identstartauth.exe"Added by the RBOT-WP WORM!"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3700 Series on XE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4800 Series on XE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX5500 Series on XE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UAuto EPSON Stylus CX7800 Series on XE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 1400 Series on XE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R280 Series on XE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R340 Series on XE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX680 Series on XE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
XAuto Startdosin.exe"Added by the SDBOT-GO BACKDOOR!"
XAuto Startsndvol32.exe"Added by the SLINBOT.AX BACKDOOR!"
XAuto Startwindos.exe"Added by the SLINBOT.BO BACKDOOR!"
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto updatSysDebug.exe"Added by the FORBOT-BA WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
NAutoCADacstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart16.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
NAutoCAD Startup Acceleratoracstart17.exe"Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
Xautoloadspooll.exe"Added by the SILLYFDC WORM!"
Xautoloadwindowsupdate.exe"Added by the POLYCRYP.DY TROJAN!"
Xautoloadspool.exe"Added by the AGENT-GSG TROJAN!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutomated Windows Updateswauclt.exe"Added by the GAOBOT.AJD WORM!"
XAutomatic Microsoft Windows Updatersuchost.exe"Added by the RBOT-EQ WORM!"
XAutomatic Updatesalgs.exe"Added by the IRCBOT-AAM TROJAN!"
XAutomatic Windows UpdaterUpdate.exe"Added by the GAOBOT.AO WORM!"
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
Xautorepairdexs.exe"Added by a variant of the SDBOT WORM!"
UAutoroute SMTPAutoSmtp.exe"Autoroute SMTP - ""automatic switching between SMTP servers depending on what network you are currently working in."" You need to have two Internet service providers"
Xautorunsxs.exe"Added by the SMALLVBS-A WORM!"
XAutoRunallrs.exe"Added by the MUDROP.LJ TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
UAutoSizerAUTOSIZER.EXE"AutoSizer - utility that automatically maximizes windows when they're opened"
NAutoSpellautospel.exe"AutoSpell - spell checker (version 6.*)"
NAutoSpell 5ASWATC32.EXE"AutoSpell - spell checker"
UAutoSysautosys.exe"Winguardian surveillance software. Uninstall this software unless you put it there yourself"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
XAutoUpdatesmss.exe"Added by WINSPY.88! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
YAvast!ashServ.exe"Main part of avast! Antivirus - including the resident protection
Yavast!ashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAvast32Astart32.exe"Part of Avast! anti-virus software"
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
YAVG IDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_AMSVRAVGAMSVR.EXE"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgamsvr.exeAvgamsvr.exe"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgasavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
YAVGIDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
YAVGIDSUIAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
YAvgserv9.exeAvgserv9.exe"Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
XAVP-SEavp-32.exe"Added by the AGOBOT.FS WORM!"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
Xavpmsavpms.exe"Added by the ONLINEGAMES.CPV TROJAN!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
Xavrlabsavrlabs.exe"VirusResponse Lab 2009 rogue security software - not recommended"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVSeguropgs.exe"AVSeguro
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
Xavserve2.exeavserve2.exe"Added by the SASSER.B or SASSER.C WORMS!"
Xavserve3.exeavserve3.exe"Added by the SASSER.G WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
?Avxnews??"??"
UAwaySchAwaySch.EXE"Part of the IBM ThinkVantage Productivity Center. ""The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"""
Nawhost32awhost32.exe"Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file
XAwoasmmo.exe"PurityScan adware"
?AWUSGSTAAWUSGSTA.exe"Reportedly related to a USB Wifi Adapter - is it required at startup?"
UawxDTools"awxDTools.dll awxRegisterDll"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System TrayIconTrayIcon.exe"System Tray access to AXIS Print System from AXIS Communications - ""adds printer discovery
UAzMixerSelAzMixerSel.exe"Related to Realtek_Azalia Mixer Selector"
NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
Xb3dBDEsecureinstall.exe"B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the ""System"" directory. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
Xb99msmm.exe"ClientMan parasite variant"
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
NBabylon TranslatorBabylon.exe"""Babylon-Pro is a powerful information tool that instantly provides relevant information
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBackgroundSwitcherbgswitch.exe"Originally included with Microsoft's XP PowerToys (but now withdrawn - see here
UBackgroundSwitcherBackgroundSwitcher.exe"John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting"
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XBackup Onesmbguard.exe"Added by the SDBOT-MI WORM!"
XBackup Servicebackup.svcUnidentified adware
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
NBacsTrayBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBakraIEHost.EXE"Added by the MULTIDR-AH TROJAN!"
XbalSYSMONMS.EXE"Added by the FAKEALERT TROJAN!"
Xbargainsbargains.exe"BargainBuddy adware"
Xbargainsbargainbuddy.exe"BargainBuddy adware"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
?Bart Stationstation.sbrt"Related to PeoplePC ISP. May be a dialler for dial-up accounts?"
UBart StationPPCOLink.exeDialer for PeoplePC ISP
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
XBastioneAntiviruspgs.exe"BastioneAntivirus
XBatsecure2.bat"Added by the ZCREW.C TROJAN!"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
Ybatterymiserbatterymiser.exe"Battery Miser power management utility for LG Notebooks"
YBatteryMiser 5BatteryMiser5.exe"Battery Miser 5 power management utility for LG Notebooks"
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
UBAUSBBAUSB.exe"Boston Acoustics Audio
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBayswapbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
UBayswap2TbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
NBBC AlertsBBC_Alerts.exe"BBC Alerts - ""You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"""
UBBC News alertsskinkers.exe"BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens"
NbbSysTraybbSysTray.exe"Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"""
YBCMDMMSGbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
YBCMSMMSGBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
UBCSSyncBCSSync.exe"Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
Xbdfgergggasw.exe"Added by the SDBOT-RT WORM!"
YBDNewsAgentbdnagent.exe"BitDefender antivirus - updater"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
UBDRegionbrs.exe"Part of Cyberlink's PowerDVD version 8 - removes the Blu-ray region on a DVD"
YBDSwitchAgentbdswitch.exe"Bitdefender 8 antivirus and firewall"
NBearSharebearshare.exe"BearShare file sharing client. Versions known to include spyware - see here"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
XBedreigingsMonitoorpgs.exe"BedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare family"
XBeegees Updatebeegees.exe"Added by the SDBOT-ADK WORM!"
UBeFasterbefaster3.exe"BeFaster internet connection optimization tool"
Xbegins0.exe"Added by the MYTOB-HE WORM!"
Ubeidsystemtraybeidsystemtray.exe"Related to Belgium Identity Card card reader"
UBelgacomsprtcmd.exe /P Belgacom"Self-help support tool for Belgacom broadband users (provided by SupportSoft
UBelkin F5D8013 N Wireless Notebook Card UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card"
UBelkin F5D8053 N Wireless USB Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
UBelkin Wireless G Notebook Card Client UtilityBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook Card
UBelkin Wireless USB UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UBelkin Wireless UtilityBelkinwcui.exe"Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card"
UBellSouthAlertManager.exeBellSouthAlertManager.exe"Related to BellSouth Alert Manager"
?Belsta.exeBelsta.exe"Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?"
XBeschermingsToolSysRep.exe"BeschermingsTool
UBestCrypt Auto OpenBestCrypt.exe"BestCrypt from Jetico
XBestPopUpKillerBestPopupKiller.exe"Popup killer by Swanksoft - not recommended
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives
XBeSys[path to file]"BeSys adware"
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
YBGNewsAgentbgnewsag.exe"BullGuard antivirus updater"
Nbgsmsndbgsmsnd.exePrinter driver to generate PDF files from any program
UBI1HelperStartUpBI1HEL~1.EXE"ScreenScenes ""Beach Islands"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
?BigDogPathVM_STI.EXE"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
XBigfileSearchBigfileSearch.exe"BigfileSearch adware. File located in %Program Files%\BigfileSearch"
Xbigorisbigoris.exe"Added by the DORF-AZ TROJAN!"
YBigPondWirelessBroadbandCMBigPond_CM.exe"Related to BigPond_Wireless_Broadband Service by Telstra"
XBillGatesLoh.exeBillGatesLoh.exe"Added by the AGENT-FZO TROJAN!"
Xbin32hpuppstub.exe"PrecisionPop adware"
NBing Barmswinext.exe"Bing Bar - the latest incarnation of the MSN Toolbar from version 5.* onwards. This entry loads the toolbar into memory at start-up before you open your internet browser. Not required - it will load with the browser and remains in memory after the browser is closed"
XbingdianBingdian.vbs"Added by the BINGD WORM!"
?Bingo Charmcharms.exe"Some kind of screen icon kind of like desk flag
UBiomenumenusw.exe"Related to Sony VAIO - passwords
XBiosBios32.exe"Added by an unidentified VIRUS
Xbiosbios.exe"Added by the BANCBAN-PW TROJAN!"
XBIOS XP Loader[random filename]"Added by the RBOT-IC WORM!"
XBIOS1BIOS1.EXE"Added by the OPASERV.T WORM!"
?BisonHKBisonHK.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
YBisonInst0402BR040286.exe"Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye"
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender Antiphishing HelperIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
UBitDefender for MSN Messengermsnmon.exe"Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website"
UBitDefender for Yahoo! Messengeryahmon.exe"Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
UBitDefender_P2P_StartupBitDefender_P2P_Startup.exe"Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website"
NBJ Printer Status MonitorCjstsr.exeCanon BJ printer status monitor
NBJ Status Monitor 5xxCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
Ubladsblads.exe"A Tweak-XP component
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
XBLMessagingIntegrationblengine.exe"BuddyLinks adware"
UBlockAdsblads.exe"A Tweak-XP component
XBlockDefenseBlockDefense.exe"BlockDefense rogue security software - not recommended
XBlocker System611 MonitoringPopUpBlocker611.exe"Added by the RBOT.BLJ WORM!"
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
Ublsloaderblsloader.exe"BellSouth ISP Internet Tools"
Xblssblss.exe"Added by the BLARUL TROJAN!"
NBLSTAPPblstapp.exePuts access to Creative's BlasterControl in the System Tray
NBlubsterBlubster.exe"Related to Blubster Music sharing service"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBlueSoleilBLUESO~1.EXE"BlueSoleil Bluetooth wireless manager from IVT Corporation"
UBlueSpace NEBlueSpaceNE.exe"""BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter"". Shortcut available via Start -> Programs"
UBluetooth Connection AssistantLBTWiz.exe"Bluetooth connection manager for Logitech based bluetooth wireless products"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
Ublueyonder Instant Support Toolmatcli.exe"Blueyonder Instant Support Tool. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NBMail InstallationFTP_back.exe"Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not"
XBMNstrpmon.exe"Part of CleanPCTool
UBMO MasterCard WalletEWALLET.EXE"The wallet conveniently stores billing
UBO1HelperStartUpBO1HEL~1.EXE"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UBO1HelperStartUpBo1helper.exe"ScreenScenes ""Butterfly Oasis"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XBoarddata[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
YBOCleanautostartBoclean.exe"NSClean's BOClean anti-trojan software"
UBoingo Wireless UtilityIcon###XXX#X#.exe"Starts the Boingo Wireless utility
Xboler.exesyser.exe"Added by the RBOT-AYS WORM!"
UbombshelBOMB32.EXEPart of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
XBONZI Task SwitcherTaskswitch.exe"Added by the SPYBOT.DTR WORM!"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
NBookMarkSinksyncit.exeBookmark synchronization utility
NBookMarkSyncsyncit.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
NBookMarkSync2Itsync2it.exe"Sync2IT BookMarkSync - ""real-time automatic synchronization service that allows you to access your bookmarks
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
UBoostSpeedboostspeed.exe"System Tray access to Auslogics BoostSpeed 4 system optimization utility - which ""Start programs faster. Speed up computer start time. Increase Internet speed
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
?Boots Insert DetectInsDetect.exe"Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
YBootSkin Startup JobsBootSkin.exe"Stardock BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens"
UBootStatusBOOTST~1.EXE"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBortMedViruspgs.exe"BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBossIdeawinlogin.exe"Added by the LINEAGE-I TROJAN!"
?BostonBoston.exe"Part of the Boston Acoustics USB speaker systems. What does it do and is it required?"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
Ubpcpost.exebpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
XBrasilBrasil.exe"Added by the OPASERV.E WORM!"
XBrasilBRASIL.PIF"Added by the OPASERV.E WORM!"
XBrasilOld[worm filename]"Added by the OPASERV.P WORM!"
Xbrastkbrastk.exe"Added by the DORF-BV TROJAN!"
XBrave-SentryBraveSentry.exe"BraveSentry rogue security software - not recommended
XBraveSentryBraveSentry.exe"BraveSentry rogue security software - not recommended
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
YBrindys BriTrayBRITRAY.EXE"Main process for the following applications: GEDEX
UBroadcom Wireless Manager UIbcmntray.exe"Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems"
NBroadcom Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBron-SpizaetusnorBtok.exe"Added by the RONTOKBRO.B WORM!"
XBron-Spizaetus[path to file]"Added by the BRONTOK-F WORM!"
XBron-Spizaetusbronstab.exe"Added by the RONTOKBRO.C WORM!"
XBron-Spizaetuseksplorasi.exe"Added by the RONTOKBRO.J WORM!"
XBron-SpizaetusElnorB.exe"Added by the RONTOKBRO.D WORM!"
XBron-Spizaetussempalong.exe"Added by the BRONTOK-E WORM!"
XBron-SpizaetusRakyatKelaparan.exe"Added by the BRONTOK-J or BRONTOK-L WORMS!"
XBron-Spizaetus-5118REPMkomodo-6321422.exe"Added by the BRONTOK-R WORM!"
XBron-Spizaetus-cfgmktoqbbm-qotkmgfc.exe"Added by the BRONTOK-M WORM!"
XBron-Spizaetus-cfgmmnrubbm-urnmmgfc.exe"Added by the BRONTOK-N WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
Xbrowsermsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowsers_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowserdeamon.exe"Added by the TACTSLAY.C TROJAN!"
Xbrowser aidbrowseraid.exe"BrowserAid/BrowserPal foistware"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
YBrowser Hijack Blasterbhblaster.exe"Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard"
UBrowser LauncherCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
XBrowser Paladblck.exe"BrowserAid/BrowserPal foistware"
UBrowser SentinelBrowserSentinel.exe"Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NBrowserWebCheckloadwc.exeChecks to make sure that IE is still your default browser
XBS Mediaplayerbsplyr.exe"Added by the RBOT-OU WORM!"
NBS Playerbsplayer.exe"BSplayer - A video player used to play avi
NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
?BsMntBsMnt.exe"Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Nbsplayerbsplayer.exe"BSplayer - a video player used to play avi
XBsRteMemoteXZZ.exe"Added by the AUTORUN-AJU WORM!"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBsx3"RunDLL32.EXE bs3.dllDllRun"
UBT Broadband Basic Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBT Broadband Desktop Helpmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
UBtcMaestroKMaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
?btinstbtinst.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
?BTSETBOOTKEYBTSetBootKey.exe"Related to a USB Bluetooth adaptor. What does it do and is it required?"
UBtStartbtstart.exe"Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software"
YBTUSRBDGBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
YBTUSRBDGFBtUsrBdg.exe"Used with a Mitsumi USB Bluetooth adaptor (and maybe others)"
NBudgetSipBudgetSip.exe"BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
XBugsDestroyerSysRep.exe"BugsDestroyer rogue system error and cleaning utility - not recommended
Ubugwatcher servicebugwatcher.exe"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XBuildLabscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XBuildLabslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
XBullsEyebargains.exe"BargainBuddy adware"
XBullsEye Networkbargains.exe"BargainBuddy adware"
?BullsEye TrackerBeTrack.exeBullseye - intelligent research assistant
Xbuohxqtfswbgcjydr.exe"Added by the AGENT-NRC TROJAN!"
Xburitosburitos.exeIdentified as a variant of the Downloader.FraudLoad.C malware
UButton Serverbttnserv.exe"Found on a Compaq PC
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
XBwddwss[path to trojan]"Added by the RANKY.BD TROJAN!"
Xbxsx5"RunDLL32.EXE bsx5.dllDllRun"
Xbxxs5"RunDLL32.EXE bxxs5.dlldllrun"
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
UBySoft FreeRAMFreeRAM.exe"""Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status
Uc32cs2c32cs2.exe"Cyber Sentinel - internet filtering software"
UC:Program Filesdfjdkjfdkjfldjfdfjdkjfdkjfldjfwinlogin.exeCritProc.exe"KeyProwler keystroke logger/monitoring program - remove unless you installed it yourself!"
UC:Program FilesNetMeterNetMeter.exeNetMeter.exe"""Net Meter is a small
XC:WINDOWSasam.exeasam.exe"Added by the PEACOMM.E TROJAN!"
XC:WINDOWSIEXPLOR.EXEIEXPLOR.EXE"""Pop Marketing"" adware"
XC:WINDOWSsystem32SetupCmd.exeSetupCmd.exe"Detected by Kaspersky as the AGENT.AAW TROJAN!"
XC:WINDOWSWinTask.exeWinTask.exe"""Pop Marketing"" adware"
XCABCInstallCABCInstall.exe"Ignite Technologies (was CABC) content delivery software"
XCable Modem AdapterWindowsSec.exe"Added by the WOOTBOT.A WORM!"
UCacheBoosttrayicon.exe"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers
UCacheSentry ProCacheSentry Pro.exe"""CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache"""
NCACStartercacstart.exeCash A Check - check writing software
UCaddais BackupOnDemandBODMon.exe"Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
UCADScads.exe"Cyber Sentinel - internet filtering software"
UCafeStationCafeStation.exe"""CafeSuite is the solution for your internet cafe. Our software provides you with ameans to control the workstations
Xcaidiysetupdiynetsetupuni.exe"DIYNet adware"
YCAISafeisafe.exe"Part of Computer Associates eTrust EZ Antivirus"
UCaISSDTcaissdt.exe"Computer Associates Dashboard Tray applet"
NCal Reminder Shortcutcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
XCalc Microsoft Windowswincalc.exeAdded by an unidentified WORM or TROJAN!
UCalendarscopecs.exe"Calendarscope calendar software"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
UCamera Assistant Softwaretraybar.exeCamera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam
UCameraAssistantCameraAssistant.exe"Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom
UCanarycanary-std.exe"Canary keystroke logger/monitoring program - remove unless you installed it yourself!"
XcandynetTaskmsg.exe"Added by the RBOT-NA WORM!"
UCanon MultiPASS Status Monitormonitr32.exeCannon Multi-Pass status monitor - your choice
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCanon Printer Monitor BJCxxxCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
UCanonSolutionMenuCNSLMAIN.exe"
Ycapfasemcapfasem.exe"CA Personal Firewall - part of the CA Internet Security Suite"
XCaptionMgr32crssr.exe"Added by the ZAR.A WORM!"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
UCaptureAssistantCaptureAssistant.exe"Capture Assistant ""is a convenient and easy-to-use text and graphics capture tool"". It allows you to capture text
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCAS Clientcasclient.exe"CasinoClient adware"
XCas2Stubcas2stub.exe"CasinoClient adware"
UCasAgntCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
Xcaseyvideocaseyvideo.exeMalware causing adult content popups
Xcaseyvideo[*] [* = digit]caseyvideo[*].exe [* = digit]Malware causing adult content popups
XCashBackcashback.exe"Part of eXact Advertising Software
XCashFiestaCashfiesta.exe"CASHFIESTA.A pay-per-surf adware"
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XCasino Royalejamesbond.exe"Added by the RBOT-FZO WORM!"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
XCassandracassandra.exe"SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN!"
XCasStubcasstub.exe"Added by the CASS-A TROJAN!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
YCAVSCAVS.exe"Cheyenne (now eTrust) antivirus"
XCAZNOVASCAZNOVAS.exe"Added by the CAZNO TROJAN!"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
UCBWHostCBWHost.exe"Required for Bitware to answer incoming faxes
?CBWUserCBWDial.exe"Associated with Bitware that integrates fax
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XccAppswinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XccAppsN/A"Added by the KANGAROO-A TROJAN!"
XccAppsccApps.exe"Added by the KANGAROO-B WORM!"
XccctpHistoryJMTi.exe"Added by the GANBATE.A WORM!"
UCCD ManagerDDS.EXE"Project Labs Century CD manager for their CD/DVD storage device"
NCcdecode"rundll32.exe streamci StreamingDeviceSetup"
YCCDoctorLogonTestingccdoctor.exe"Checks your system to make sure it's configured properly for running IBM Rational ClearCase
XccpAppscsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
XccpAppslsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
Xccrssmsdtc.exe"Added by the STAP-C WORM!"
YccSetMgrccSetMgr.exe"Part of Norton AntiVirus 2004. What does it do?"
XccStartccStart.exe"Added by the AGOBOT-IR WORM!"
XccStartccInfo.exe"Added by the AGOBOT-GQ BACKDOOR!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
Xccsvit.execcsvit.exe"Added by the STARTPA-HP TROJAN!"
UccWasheraolwasher.exe"Webroot Cache & Cookie Washer - cleaning browser tracks
UCCWC7sstealth.exe"Moleculesoft Cache
NCD Storage Mastercdstorager.exe"CD Storage Master - a program designed to catalog CD information
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
UCDLoadersb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
Xcdmmslpoklpllsm.exe"Added by the TEDIJINI-A TROJAN!"
Xcdoosoftherss.exe"Added by the SILLYFDC.BCT WORM!"
Xcdoosoftolhrwef.exe"Added by the AUTORUN-AAG WORM!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
Xcdscds.exe"Added by the SPYMON TROJAN!"
XCDSpeed.exeCDSpeed.exe"Added by the IRCBOT.AEX BACKDOOR!"
XCentralProcessortaskimgr.exe"Added by the BANCOS.J TROJAN!"
?CEPAwsot.exe"??"
UCertificateRegistrationSafeSignCertReg.exeSafeSign Certificate Registration Utility for Microsoft Crypto applications
YCertStoreInitCertStoreInit"Aladdin eToken authentication and password management"
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
Xcfgboostcfgboot.exeAdded by an unidentified WORM or TROJAN!
UCFi ShellToys Utility ManagerCFiShlMan.exe"Manager for CFi ShellToys from Cool Focus International Ltd - which ""puts all the tools you need right where you need them - just a click away on your context menu. Right-click one or more files or folders
?cFosDNTcFosDNT.exe"cFos DSL Modem driver related. What does it do and is it required?"
?cFosInst_Checkcfosinst.exe"cFos DSL Modem driver related. What does it do and is it required?"
UcFosSpeedcFosSpeed.exe"cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly"
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
Xcftmonsfcmonit.exeAdded by a variant of the AGENT.ERG TROJAN!
XcftmonWindowsUpdate.exe"Added by the AGENT.AQK BACKDOOR!"
Xcftmon32taskmgr*.exe [* = number]"Added by the SOWSAT.C and SOWSAT.J WORMS!"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
UCGServercgserver.exe"Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs"
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
Xchange-me-nowmsgfix1.exe"Added by the SDBOT.ZD WORM!"
UChangeICONSPMSMON.EXECard reader related program. Note - may cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem
?ChangeLineschngline.exe"??"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
YCharter High-Speed Security Suitefspex.exe"Charter High-Speed Security Suite - security software in collaboration with F-Secure"
UChatStatChatStat.exe"ChatStat from ChatStat Technologies
Xche32che.ocx.vbs"Added by the ADENU-B VIRUS!"
Ucheatmonitorstart.exe"CheatMonitor surveillance software. Uninstall this software unless you put it there yourself"
NCheck for One Touch Updatewiseupdt.exeChecks for updates for Visioneer OneTouch scanners
NCheck for TWS UpdatesWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
UCheck Messengercmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account. Qchex appear to be no longer in buisness
NCheckCustomWorksUpdateCheckCWupdate.exe"Update checker
XCheckdiskmscas.exe"Added by the VAGON-A TROJAN!"
XCheckFaultKernelmswdm.exe"Added by the SMALL-CSK TROJAN!"
YCheckMsgPlus"MsgPlusH.dll VerifyInstallation"
Xcheckrunelitelsj32.exe"Added by the MULTIDR-ER TROJAN!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
UChicoSyswebtmr.exe"Child Control parental control software"
Xchina11msnCHINA11MSN.EXE"Added by the ENVID.O WORM!"
XChinagnqvasdd.exe"Added by the SDBOT-SE WORM!"
UChineseStarcstar.exeChinese language support software
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
XCHK Diskerchkdsker.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XChkDiskchk_disk.exeAdded by an unidentified WORM or TROJAN!
Xchkdskautoexec.bat"Added by the ANPES WORM!"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
NChristmas Music PlayerTTEST6.EXE"Christmas Music Player brings the music of the Christmas Holiday to your desktop"
?ChromeMarkkeysh.exe"Related to this. Don't know what keysh.exe does though and if it's required"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
XCi Svrcisvr.exe"Added by the IRCBOT.AWN BACKDOOR!"
XCiaBackdoormsldr.comAdded by a VIRUS!
Xcihost.execihost.exe"Added by the LINST TROJAN!"
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
XCirebonPunyaXXrocks.exe"Added by the BHARAT.A WORM!"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
XCissiCissi.exe"Added by the CISSI.A WORM!"
UCitiUCSCitiUCS.exe"Citibank Virtual Account Numbers - ""With this free service for Citi cardmembers
YCjstcomCjstcom.exeCanon printer BJ status language monitor
XClassesint1.exe"""Switch"" premium rate adult content dialler variant"
XClassesintl.exe"""Switch"" premium rate adult content dialler variant"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XClassesMSTAR2.EXE"""Switch"" premium rate adult content dialler variant"
XClassesmstart.exe"""Switch"" premium rate adult content dialler variant"
UCLCLSetCLCL.exeCLCL clipboard caching utility
NClean Access AgentCCAAgent.exe"Cisco Clean Access Agent from Cisco Systems
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
?CleanEasyImgcleanall.exe"??"
XCleanPCToolSysRep.exe"CleanPCTool rogue system error and cleaning utility - not recommended
UCleanSweep Smart Sweep- Internet SweepCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
NCleanSweep Useage WatchCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
Xcleansweep.execleansweep.exe"Added by the AGENT-NEU TROJAN!"
NCleanupONICTASK.EXE"Internet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet"
YCleanUpmcappins.exeUsed by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
XCleanupToolSysRep.exe"CleanupTool rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
UCleverKeysCK.exe"CleverKeys - ""is free software that provides instant access to definitions at Dictionary.com
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClickSight Launchercs.exe"Launcher for the ClickSight® marketing tool from ClickStream Technologies - which ""is a patented data-collection technology that helps independent software vendors understand the current and future usage of their product"""
XClickTheButtoncsrss.exe"ClickTheButton adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
UClient Access API Daemoncwbappcd.exe"IBM iSeries Client Access
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Client Access Express Welcomecwbwlwiz.exe"Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access Help Updatecwbinhlp.exe"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
UClient Access Taskbarcwbuitsk.exe"IBM iSeries Client Access taskbar
XClient Agentphotes.exe"Added by the PPDOOR-P TROJAN!"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
NClient Security Solutioncssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClientMan1mscman.exe"ClientMan parasite variant"
NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
NCLISTARTCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
Xclkhost[path to trojan]"Added by the WIXUD-B TROJAN!"
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
XClock Manageramsngr.exe"Added by the SDBOT-XM TROJAN!"
XClockSyncSync.exe"ClockSync - synchronizes your system clock with an internet time server. It's by WhenU
UClockWiseCLOCKWISE.EXE"ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
XClrSchLoader[path to file]"ClearSearch adware"
XCLSIDcom.exeAdult content dialler
XCLSIDdll.exeAdult content dialler
XCLSIDmsgplus.exeAdult content dialler
XCLSIDplugin.exeAdult content dialler
XCLSIDsed.exeAdult content dialler
XCLSIDmsgplus.exePremium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
XCLSRSSLSACS.EXE"Added by the SILLYFDC-X WORM!"
Xcls_pack.execls_pack.exe"Added by the Malware Defense rogue security software. Also detected as the FAKEAV-AQB TROJAN!"
?CM-SmWizardSmWizard.exe"SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?"
Xcmd32configs.exe"Hijacker
Xcmdbcscmdbcs.exe"Added by the LINEAG-GKW TROJAN!"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
XCmdShell.exeCmdShell.exe"Added by the BCKDR-QHY BACKDOOR!"
XCmeSYSCMEsys.exe"Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
UCMGShieldUICMGShieldUI.exe"UI for CMG (CREDANT Mobile Guardian) Shield from Credant Technologies. ""The CMG Shield resides on devices and external media to enforce security policies even if the device is disconnected from the network."" Used to protect sensitive corporate on laptops
XCmmon32Syscmmon32.exeAdded by the SMALL.CL TROJAN!
Xcmonitorstartupmon.exe"SystemDoctor rogue security software - not recommended
Xcmonitorpasmon.exe"SystemDoctor rogue security software - not recommended
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmrsfcmrsf.exe"Added by the DELF-HU TROJAN!"
Xcmrsscmrss.exe"Added by the DELF.DU TROJAN!"
Xcmrsscrmss.exe"Added by the DLOADER-EK TROJAN!"
Xcmrss[path to trojan]"Added by the DLOADER-QQ TROJAN!"
Xcmrstcmrst.exe"Added by the BANCOS.S TROJAN!"
Xcmrstcmrst.scr"Added by the DLOADER-FP TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
XCMSallycallmesally.exe"Added by the CASAL.A TROJAN!"
UCMSETTINGSctmn.exe"Part of NetNanny
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsssystem.exe"Added by a variant of the RBOT WORM!"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcmssSystemProcesscsmss.exe"Added by the AGENT-CO TROJAN!"
XcmssSystemProcessmcsmss.exe"Added by the PROXYSER-F TROJAN!"
XcmssSystemProcesscsms.exe"Added by the AGENT-Y TROJAN!"
XCMSystemCMSystem.exe"CASClient adware"
XCnsMaxInternat.exe"Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
YCnxAdslLCnxAdslL.exe"DLink
NCnxDslTaskBarCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
UCobian Backup BoletusCobian.exe"Cobian Backup 10 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (XP/Vista/7). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCodename Dashboarddashboard.exe"Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework
?COEMsgDisplayCOEMsgDisplay.exe"Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XColdlife -icmpSystray.exe"Added by the FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process"
NCollaborationHostp2phost.exe"Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCom+ Syscsrs.exe"Added by the FORBOT-BT WORM!"
XCOM+ System Applicationlsas.exe"Added by the AGOBOT-MO WORM!"
XCOM+ System Applicationslsas.exe"Added by the AGOBOT.SE WORM!"
XCOM++ Systemexploier.exe"Added by the LOVGATE.Z WORM!"
XCOM++ Systemsuchost.exe"Added by the LOVGATE-F WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
Ucom.codeode.cactusspamfiltercactusspamfilter.exe"Cactus Spam - free easy-to-use spam blocker"
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
XComcastSUPPORTtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
XCommandsystem.exe"Added by the GATECRASH.A or GATECRASH.B TROJANS!"
UCommand WorkStation 4cws 4.exe"EFI's Command WorkStation makes ""managing demanding workflows easier by centralizing job management. The software automatically identifies the Fiery servers on the network and offers customization options for displaying information"" - for high-end print environments"
XCommon Filestwain.exe"Added by the AGENT.BEA TROJAN!"
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
YCommunications_HelperCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
YCommunications_Helper.exeCommunications_Helper.exe"Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
NCompaq ConnectionsCOMPAQ~1.EXE"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
NCompaq ConnectionsCompaq Connections.exe"See here - ""messaging service that automatically sends you support information
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
NCompaq Internet Setupinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
UCompaq Knowledge Centersilent.exe & matcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
NCompaqSystraycpqpscp.exeCompaq System Tray icon
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
XComPlus Applicationstwain.exe"Added by the AGENT.AQO TROJAN!"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
UCompuSpyCompuSpy.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
UCompuSpy KeyLoggercswin2008.exe"CompuSpy surveillance software. Uninstall this software unless you put it there yourself"
XComputing Technologie Firewalllsauth.exe"Added by the SDBOT-WX WORM!"
NCOMSMDEXEcomsmd.exe3Com tray icon
XComStartTrojan Guarder.exe"TrojanGuarder rogue security software - not recommended"
XComTry Web Searcherwstray.exeComtry MP3 Downloader related - spyware
XConfidentSurfGDC.exe"ConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfidentUserSRP.exeConfidentUser rogue system error and cleaning utility - not recommended
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfigTaskUpdate.exe"Added by the MDROP-BRO TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loadersysldr32.exe"Added by the GAOBOT WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
XConfig LoaderSYSMGR.EXE"Added by the AGOBOT.C WORM!"
XConfig Loader for Microsoft Windowsmwincfg32.exe"Added by the AGOBOT.BD WORM!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfig Loadrwinsys32.exe"Added by the AGOBOT-HN WORM!"
UConfigSafeCFGSAFE.EXE"ConfigSafe - lets you identify changes to the registry
UConfigSafeAUTOCHK.EXE"ConfigSafe - lets you identify changes to the registry
NConfigServicesConfig.exePart of initial setup on a Compaq PC
Xconfigsetupconfigsetup32.exe"Added by the AGOBOT-AFP WORM!"
Xconfigurationapphost.exe"Added by the SDBOT-VP WORM!"
XConfigurationntsys32.exe"Added by the SDBOT-LN WORM!"
XConfigurationmsgfixs.exe"Added by the SDBOT-NN WORM!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration FileWinset32.exeAdded by the FLUX.101 TROJAN!
XConfiguration Loadedlssas.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration Loaderlfass.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersycfg34.exe"Added by the GAOBOT.AN WORM!"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersw32.exe"Added by the AGOBOT.BQ WORM!"
XConfiguration LoaderSystem.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersysinfo.exe"Added by the GAOBOT.FQ WORM!"
XConfiguration Loadermicrosoft.exe"Added by the GAOBOT.JB WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgfix.exe"Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS!"
XConfiguration Loadermsnss.exe"Added by the GAOBOT.AUS WORM!"
XConfiguration LoaderMSTasks.exe"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loadersystemry.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration LoaderccSort.exe"Added by the AGOBOT.SR WORM!"
XConfiguration Loadersmss32.exe"Added by the AGOBOT.MB WORM!"
XConfiguration Loaderseru32.exe"Added by the SDBOT-VR WORM!"
XConfiguration Loaderbotss.exe"Added by the SDBOT-XS WORM!"
XConfiguration Loaderldasp.exe"Added by the AGOBOT.BH WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersmsai.exe"Added by the SDBOT-YE WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loadercrcss.exe"Added by the AGOBOT.ADG WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration Loadermouse.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadermsg.exe"Added by the SDBOT.BT WORM!"
XConfiguration Loaderahnhst.exe"Added by the AGOBOT.MX WORM!"
XConfiguration Loadermsnmsgr.exe"Added by the SDBOT-SO WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration LoaderWinSys32ys.exe"Added by the SDBOT.BCS WORM!"
XConfiguration Loaderasnclt32.exe"Added by the AGOBOT-EB BACKDOOR!"
XConfiguration Loadersoundconf.exe"Added by the AGOBOT-MH WORM!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loadermsgfixy.exe"Added by the SLINBOT.QW BACKDOOR!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
Xconmswfconrnbne.exe"Added by the SDBOT-DEX WORM!"
UConnect KasambaKasamba.exe"""Finding the expert help that you need is easy on Kasamba. With more than 30
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XConnectorSYS.EXE"Nunci premium rate dialer"
XConnectorsms.EXE"Added by the ExDial-B premium rate adult content dialer"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
XConsconsol32.exe"Hijacker - redirects to an adult content portal
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XConsole de Gerenciamento Microsoftcsrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XConsole de Gerenciamento Microsoftcsrss.exe"Added by the BANCBAN-ET TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Central de Segurança"" subfolder"
UConsumer InputConsumerInput.exe"Consumer Input Toolbar. Opt-in market research monitoring you browsing habits - see the FAQ"
XContent List Management Subsystemclmss.exe"Added by the SPYBOT-EL WORM!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XContentEraserGDC.exe"ContentEraser rogue privacy tool - not recommended
XContentServicewinservn.exe"PurityScan adware - see here"
UContentTransferWMDetector.exeContentTransferWMDetector.exe"Part of Sony's Content Transfer Software which ""provides an easy way to transfer music
XContinueInstallbpsinstall.exe"BrowserAid/BrowserPal foistware"
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
XControl handlerahjinst.exe"CoolWebSearch parasite variant"
Ncontrol panelsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
XControl PanelSystem.exe"Added by the DANI TROJAN!"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControladores[path to trojan]"Added by the TELEFO-A TROJAN!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
XControlPanel"host32.exe internat.dll LoadKeyboardProfile"
XControlPanel"systemctrl.exe internet.dll LoadNetworkProfile"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCool Deskcdesk.exe"Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UCoolSwitchtaskswitch.exeALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
Xcoolwebprogramclrssn.exe"CoolWebSearch Smartsearch parasite variant"
NCopernic Desktop SearchDesktopSearch.exe"Copernic Desktop Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
UCopernicPerUserTaskMgrCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
XCore Process Aplicationccapl.exe"Added by the QHOSTS.G TROJAN!"
XCore Process Aplication x16ccapl16.exe"Added by the SPYBOT.AFT WORM!"
XCore Process Aplication x32ccapl32.exe"Added by the SRAMLER.E TROJAN!"
XCore System Hardwaresyscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel Colleagues & Contacts Reminderscffrem.exe"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings
NCorel Desktop Application Directordadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
NCorel Family & Friends remindersCFFREM.EXE"Corel Family & Friends - all-in-one calender
NCorel RegistrationRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel Registration ReminderRemind32.exeIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
NCorelMedia FoldersIndexer8MFindexer.exePart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
NCorelMedia FoldersIndexer8MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
?CORESYScoresys.exe"??"
XCorporate Microsoft Updateuptask.exe"Added by the RBOT-GVB WORM!"
Xcosinecosine.exe"Added by the RBOT-SW WORM!"
UCostAwareniIPCApp.exe"NetInternals CostAware - download quota measuring tool"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
NCountry Selectpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
NCountrySelectionpctptt.exe"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell
?Coupon Offers??"??"
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
Xcplmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xcpls_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xcplbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xcpntmgcsimcss.exe"Added by the MAGICON.A TROJAN!"
Xcpntmgcwinmgts.exe"Added by the WINTRIM-B TROJAN!"
UCPQEASYACCcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UCPQEASYACCStartEAK.exe"Easy Access Button Support for Compaq PCs. Allows the use of programmable keys on multimedia keyboards. Required if you use the additional keys"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XCPQHotKeyshotkeysvc.exe"Added by the RBOT-XA WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
Ucpqnscpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
NCpqsetCpqset.exeDefault settings software in Hewlett Packard notebook
YCPQSTUTFIXstutfix.exe"For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton"
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCPU Windows Statuscpustats.exe"Added by a variant of the RBOT WORM!"
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
?CQSCP2PSCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
Ucracked_windows1cracked_windows1.exe"Cracked Windows popup killer"
Xcrash0001restorecrashwin32.bat"Added by the AGENT-ZC TROJAN!"
XCrashDump[path to trojan]"Added by the DROPPER.EAT TROJAN!"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
UCRBroadCastingCRBroadCasting.exe"CardReader2 from On Track Inovations Ltd. USB Card Reader"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
XCrc32stats DependenciesCrc32stats.exe"Added by the MYTOB.GT WORM!"
XCRCSScrcss.exe"Added by the IRCBOT-TH WORM!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
XCreate A MonstercreateAMonster.exe"Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related"
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrisysTec SentrySentry.exe"CrisysTec Sentry rogue privacy program - not recommended"
XCritical Error Safe32GetWaylayer32.exeAdded by the RBOT.IAL WORM!
Xcrmssrlt[random filename]"Added by a variant of the SLAPER TROJAN!"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
XCrossMenuCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
UCrossMenuCrossMenu.exeToshiba CrossMenu Utility - allows the user to create their own menus
Xcrscrs.exe"Added by the AGOBOT-TJ WORM!"
Xcrsmonsiomssls.exe"Added by the BACKDR-AU TROJAN!"
XCRSSCRSS.exe"Added by the AGOBOT-RM WORM!"
XCRSSlssas.exeAdded by an unidentified WORM or TROJAN!
Xcrssscrsss.exe"Added by the AUTORUN.FM WORM!"
XCRSSXP SysInfocrssxp.exe"Added by a variant of the SDBOT TROJAN!"
XCrustydmcpl.exe"Added by the RUSTY WORM!"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
?Crystal 3D Audio ControlCWD3DSND.EXE"Crystal 3D Audio sound driver. Is it required?"
XCStsc.exe"Cyber Security rogue security software - not recommended
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
NcsaRemspqmdmui.exeCompaq modem country selection
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XCseccs.exe"Cyber Security rogue security software - not recommended
Ncsecwizcsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
Xcserv32cserv32.exe"Added by the STRATION.EC WORM!"
XCsimPlayerCsimPlayer.exe"Added by the KOOBFACE-AD WORM!"
UCSINJECT.EXECSINJECT.EXE"Part of Quarterdeck/Norton CleanSweep. ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"""
Xcsm Win Updatescsm.exe"Added by the ZOTOB.B WORM!"
XCSNetManagerXpisass.exe"Added by the HIDER-O TROJAN!"
Xcsoftoksoftok.exe"Added by the QQPASS.G TROJAN!"
Xcsoscsos.exe"Added by the SDBOT-DFE WORM!"
Xcsrcscsrcs.exe"Added by the AGENT-HUA TROJAN!"
Xcsrscsrs.exe"Added by the GAOBOT.GEN!POLY WORM!"
Xcsrsccsrsc.exe"Added by an unidentified VIRUS
XCSRSSCSRSS.EXE"Search page hijacker
XCsrsscsrss.exe"Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrsscsrss.exe"Added by the KEYLOG-AQ KEYLOGGER! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xcsrsscsrss.exe"Added by the CHODE-J WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a random subfolder"
Xcsrssmsmsgs.exe"Added by the CHODE-J BACKDOOR! Note - this malware uses MSN Messenger (which is located in %Program Files%\Messenger) in the background to propogate itself"
Xcsrssnwiz.exe"Added by the CHODE-J WORM!"
Ucsrsscsrss.exe"BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Supremtec"
XCsrssCSRSS.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS"
Xcsrssssms.exeAdded by an unidentified malware
XCsrss Hostcsrhost.exe"Added by the IRCBOT.BIZ WORM!"
XCSRSS Loadercsrsss.exe"Added by the AGOBOT.TX WORM!"
Xcsrss.execsrss.exe"Added by the DALBUG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
XCSRSSUCSRSSU.exe"CoolWebSearch parasite variant - hijacking to Slawsearch.com. Also detected as the CWS-E TROJAN!"
XCSRSSWCSRSSW.EXE"Added by the CWS-F TROJAN!"
XCSRSWIN[trojan filename]"Added by the WINSHELL.50 TROJAN!"
XCSRSX[trojan filename]"Added by the WINSHELL.50.B TROJAN!"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
Ncssauthcssauth.exe"Part of Thinkvantage Client Security Solution for Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
Ncssauthecssauthe.exe"Part of Thinkvantage Client Security Solution for IBM/Lenovo ThinkPad notebooks and ThinkCentre desktops. Once configured via the associated setup screens this loads via winlogon.exe (and loads the password manager) and therefore disabling this entry has no effect"
YCSScheduleCheckSCHWIZEX.EXE"Part of ConfigSafe - lets you identify changes to the registry
Xcssrscssrs.exe"Added by the BANCBAN-DW TROJAN!"
Xcssrss.execssrss.exe"Malware installed by different rogue security software including SpyKillerPro"
XcsssCsss.exe"Added by the BALICK TROJAN!"
UCSS_CentralCSS_1631.EXE"CSS Communication Agent (95 Host) from Command Software Systems (now Authentium). ""CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console"""
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
Xctfmencssrs.exe"Added by the STARTP-DC TROJAN!"
Xctfmontaskmgr32*.exe [* = number]"Added by the SOWSAT.B WORM!"
XctfmonWinConst.exe"Added by the ASSASIN-G TROJAN!"
Xctfmonmsnmsgr.exe"Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XCtfmonwmisys.exe"Added by the IRCBOT-ADS WORM!"
Xctfmon.exemsupdate32.exe"Spy Sheriff/SpywareNO malware
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xctfmon32taskmgr32*.exe [* = digit]"Added by the SOWSAT.C WORM!"
XCTFMONSSCTFMONSS.EXE"Added by the CWS-F TROJAN!"
Xctfmoonmicrosoftconfigurator.exe"Added by the DELF-ALS TROJAN!"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
Xctfnom.exeOSRSS.exe"Added by the DLOADER-UQ TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
?CTSchedCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
NCTStartupCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
NCTSyncU.exeCTSyncU.exe"Creative Sync Manager - synchronizes music tracks on your computer with your player"
UCTsysVolCTSYSVOL.exeCreative sound card volume controls
?cttdpsrvcttdpsrv.exe"??"
XCueX44_stil_hereWINLOGON.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate winlogon.exe process
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XCurrent32msnpla.exe"Added by the SDBOT-DIS WORM!"
NCurseClientCurseClient.exe"CurseClient add-on manager for World of Warcraft and Warhammer Online games"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
UCursorGizmoCursorGizmo.exe"Cursor Gizmo - cursor management utility"
NCursorXPCursorXP.exe"CursorXP from Stardock - tool for creating mouse cursors"
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
Ncwbsvstrcwbsvstr.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Cwcdschk.exeCwcdschk.exe"IBM Thinkpad related?"
Xcwingllibatllsimm.exe"Added by a variant of the SDBOT WORM!"
Xcybansoscyban.exe"Added by the TATERF-V WORM!"
UCyber Trioshowmode.exe"From G-Tek Technologies. Allows you to set the PC in one of three modes
UCyber-Defender 2003uwcdsvr.exe"
NCyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
UCypressLinkMonCypressLinkMon.exe"Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store
XD SYSTEMdd.exe"Added by the MYTOB-FN WORM!"
YD-Link Air USB UtilityAirCFG.exeD-Link Air USB wireless driver and configuration utility
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
YD-Link AirPlus GAirGCFG.exeD-Link Airplus G wireless router driver and configuration utility
YD-Link AirPlus G Wireless UtilityAirPlus.exe"D-Link AirPlus G wireless configuration and monitoring utility"
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link RangeBooster N DWA-140AirNCFG.exe"D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-110AirGCFG.exeD-Link DWA-110 Wireless G USB adapter driver and configuration utility
YD-Link D-Link Wireless G DWA-510AirGCFG.exeD-Link DWA-510 Wireless G desktop adapter driver and configuration utility
YD-Link D-Link Wireless N Dual Band DWA-160AirNCFG.exe"D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
YD-Link D-Link Wireless N DWA-130AirNCFG.exe"D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
YD-Link Wireless G WDA-1320AirGCFG.exe"D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
YD-Link Wireless G WUA-1340AirGCFG.exe"D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
NDAEMON Toolsdaemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Litedaemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools LiteDTlite.exe"Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools ProDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTProAgent.exe"System Tray access to an older version of DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools Pro AgentDTAgent.exe"System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
NDAEMON Tools-1033daemon.exe"Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso
XDaily Weather Forecastweather.exe"Added by the DLOADER-IP TROJAN!"
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
Xdarkimgst.scr"Added by the BANCOS.U TROJAN!"
Xdarkimgrt.scr"Added by the BANCBAN-FH TROJAN!"
Xdarkcsrs.scr"Added by the BANCBAN-GT or BANCBAN-GU TROJANS!"
XDarkDevil.Grasiele.BRGrasiele.VBS"Added by the LEMBRA WORM!"
XDarKNesS LsasSLsasS23.exeAdded by an unidentified WORM or TROJAN!
XDASDS VSAVdjsdsabdw.exe"Added by the SDBOT-RE WORM!"
?DashBarStatedashIE"??"
?DashIEN/A"Could be related to "Dash Power Shopping" tool bar in IE?"
Xdaskaskfsak6dsfids6.exe"Added by the ONLINEG-J TROJAN!"
Xdaskgfkkcx15dasdsaads15.exe"Added by the ONLINEG-Q TROJAN!"
Xdasxdadsfsdqd.exe"Added by the GAOBOT.BIQ WORM!"
XDataSystem.dat.vbs"Added by the BISCUIT.A WORM!"
Xdatamsngs.exe"Added by the RBOT-ADQ WORM!"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
NData LifeGuard LifeLine Lite installerDLGLI.EXE"Backweb installer - see here"
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
XDATABASE MySql[path] repcale.exe [path] beird.exe"Added by the RANDON-AL WORM! Both files are often located in %System%\qsws"
NDataCachingFlashKsk.exe"SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word
Xdbar_starterstarter.exe"Deskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com"
UDBISQL9dbisqlg.exe"Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies"
Ndbservdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
Xdc2k5SVIQ.EXE"Added by the COIDUNG-A WORM!"
XDC6dc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XDC6_Checkuwasdc.exe"Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
XDC6_checkdc6_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
UDCfssvcdcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
Udcfssvedcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
XDcom System PatchMicrosoft.exe"Added by the RANDEX.MS WORM!"
Xdcsmdcsm.exe"Part of the PrivacyProtector and DriveCleaner rogue security tools"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XDealHelperBrwsrdhbrwsr.exe"DealHelper adware"
XDebugSMSS.exe"DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UDeeEnEsDeeEnEs.exe"DeeEnEs - automatically updates a dynamic IP address when it changes"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefaultmtask.vbe"Added by the ALLEM WORM!"
Xdefaultshell32.exe"Added by the BINGHE TROJAN!"
Udefaultmskbw.exe"PC Surveillance PRO surveillance software. Uninstall this software unless you put it there yourself"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDefault_Search_URLhttp://find.naupoint.com"Naupoint browser hijacker"
XDefensaAntiMalwarepgs.exe"DefensaAntiMalware
XDefense Centerdefcnt.exe"Defense Center rogue security software - not recommended
XDefenseNetSurfageGDC.exe"DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
UDefragTaskBardefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
UdefragTaskBar.exedefragTaskBar.exe"System Tray access to Ashampoo® Magical Defrag 2 from Ashampoo GmbH & Co. KG - which ""works is similar to a screensaver. Whenever the computer is idle the program cuts in automatically and starts cleaning up your hard disk"""
XDelayLoadmsprint.exe"Added by a variant of the Win32.Agent.ryo malware - see here"
NDelayShredShrCL.EXEMcAfee Shredder - not required at startup. You can run it manually via McAfee Security Center
?delcabdeltreew.exe C:cabs"??"
UDeleteHistoryFreedhf.exe"Delete History Free - ""Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"""
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
UDell PanelMgrSSMMgr.exe"Monitors ink levels
NDell QuickSetquickset.exeDell taskbar icon allowing you to quickly change settings
NDell Wireless Manager UIwltray.exeSystem tray access to wireless LAN card configuration options
NDellSCdellsc.exeDell Solution Center - web-based troubleshooting tools and educational offerings
UDellSupportDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
UDellSupportCentersprtcmd.exe /P DellSupportCenter"Dell Support Center (provided by SupportSoft
?DellTransferAgentTransferAgent.exe"Found on Dell computers. What does it do and is it required?"
Xdelmsbbdelmsbb.exe"180Search adware"
Xdelsaapdelsaap.exe"NCase adware"
?delstartdelstart.exe"Reportedly part of BT ISP software - what does it do and is it required in startup?"
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
UDeltaIITaskbarAppDeltaIITray.exe"System Tray access to the Delta Control Panel for the M-Audio Delta series of PCI audio cards"
XDeluxeCommunicationsDxc.exe"Deluxe Communications adware - successor to SurfSideKick"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
XDepassxXfsa.exe"Added by the SDBOT-SK WORM!"
UDepFrezfrzstate.exe"Deep Freeze from Faronics Coporation. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators
XderyheruxckeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
XDesiredesires.exeAdult content dialler
?desk-top-servicedesk-top-service.exe"??"
XDeskAd ServiceDeskAdServ.exe"DeskAd.Service adware"
NDeskColorDESKCOLOR.EXEProvides transparent icon text backgrounds and coloured icon text
NDeskflagDeskflag.exe"DeskFlag - animated USA flag on the desktop"
XDeskMateAutoUpdateDeskMateAutoUpdate.exe"DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related"
Udeskmechdeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
Udesksaverdesksaver.exe"Part of Advanced Desktop Shield
UDeskSaverDeskSaver.exe"DeskSaver from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". The Pro version also includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
UDeskSaver ProDeskSaver.exe"DeskSaver Pro from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". Includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
Udesksaver.exedesksaver.exe"Part of Advanced Desktop Shield
UDesksite CMAcma.exe"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
UDeskSlideDeskSlide.exe"""DeskSlide is utility for automating wallpaper changes on your desktop"""
UDeskSpacedeskspace.exe"DeskSpace desktop management utility from Otaku Software Pty Ltd - which ""gives you more space for your windows and icons. You can eliminate desktop clutter by arranging your windows and icons across up to six desktops
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
Xdesktopdesktop.exe"Added by the SDBOT.MD WORM!"
XDesktopDesktop.com"Added by the VB-DRN WORM!"
Xdesktopdesktop.ini.vbs"IE-Title malware"
NDesktop ArchitectDATRAY.EXE"Desktop theme manager available
YDesktop ArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktop CalendarDesktop Calendar.exe"Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar
XDesktop Defender 2010Desktop Defender 2010.exe"Desktop Defender 2010 rogue security software - not recommended
UDesktop iCalendarCalendar.exe"Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather
UDesktop iCalendarDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendarDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop iCalendar LiteDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar Lite.exeDesktop iCalendar Lite.exe"Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events
UDesktop iCalendar.exeDesktop iCalendar.exe"Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar
UDesktop Maestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktop Maestro Vista TrayRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea
XDesktop Searchdesktop.exe"iSearch adware"
XDesktop Security 2010Desktop Security 2010.exe"Desktop Security 2010 rogue security software - not recommended
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
NDesktop WeatherTHE WEATHER CHANNEL.exe"Desktop Weather by The Weather Channel - provides current temperature
NDesktop Weather 3THE WEATHER CHANNEL.exe"Desktop Weather 3 by The Weather Channel - provides current temperature
NDesktop Weather 3THEWEA~1.EXE"Desktop Weather 3 by The Weather Channel - provides current temperature
YDesktopArmorDesktopArmor.exe"Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
UDesktopIconToyDesktopIconToy.exe"""Desktop Icon Toy is an easy to use desktop icon enhancement tool
UDesktopMaestrodeskmech.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
UDesktopMaestroRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
Ndesktopmgrdesktopmgr.exe"Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
UDesktopXDESKTOPX.EXE"A program that replaces the regular Desktop and Taskbar
Ndeskupdeskup.exeAdds Iomega Zip drive icons to the desktop
Udesp2kdesp2k.exe"Part of the Turbo Analyzer tool from LightComm Brazil Telecom that analyzes and corrects ADSL configurations"
Xdestroyb11destroyb11.exe"Added by the DELF-KO TROJAN!"
XDeus CleanerDCleaner.exe"Deus Cleaner rogue system cleaner utility - not recommended"
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XDevice IO Systemdeviceio.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Driverdevicesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
UDevicesolesvr.exe"Salfeld Child Control - parental control software"
XDfqwSfSffsqsd.exe"Added by the SDBOT-SH WORM!"
Xdgtstartdgtstart.exe"DigitalNames.g adware"
XDHCPsmss.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
XDiagnosticdiagnostic.exe"Added by the ALPHA-C TROJAN!"
XDiagnostic Agentdiagent.exe"Added by the AGOBOT-CW WORM!"
XDialer"rundll32.exe MSA32CHK.dllReg"
UDialgo SDKPhoneAnswer.exe"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID
NDialog Box AssistantOSDEx.exe"Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
XDIECOXcsrss.exe"Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XDieselRecalculate.exe"Added by the LAZAR TROJAN!"
XDigiDDigitalSound.exeAdware downloader
UDigisoft AntiDialerAntiDialer.exe"Digisoft AntiDialer"
UDigiSrvDigiSrv.exe"Related to camera software from DigitalDreams"
NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
XDigitalNamesDigitalNamesStart.exe"DigitalNames spyware variant"
NDigitalWizardISWizard.exe"InstallShield's DigitalWizard - free
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
NDIGStreamdigstream.exe"DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
UDimensionDimension.exe"Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames
UDimension4d4.exe"Dimension 4 - network time synchronization freeware - starts-up
XDinstdinst.exe"IMIServer/IEPlugin adware"
XDirect settingssdchost.exe"Added by the DAEMONI-I TROJAN!"
YDirectory Opus Desktop Dblclkdopusrt.exe"Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor
Xdirects.exedirects.exe"Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
UDIRECTVDSLDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
XdirectxSqlexploit.exe"Added by the SDBOT.D TROJAN!"
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
XDirectX64DirectXset.exe"Added by the BROWNEY.A WORM!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
?Disable EHCInousb20.exe"??"
XDisableKeybaord"Rundll32.exe KeyboardDisable"
XDisableMouse"Rundll32.exe MouseDisable"
NDisc DetectorCtNotify.exe"For Creative sound cards. Detects when you insert a CD
?disc detectorqnetquestnotifty.exe"??"
?discovegdiscoveg.exe"??"
?DISCoverDISCover.exe"Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
UDiscWizardMonitor.exeDiscWizardMonitor.exe"Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
XDisk Checkchkdsk32.exe"Added by the IM TROJAN!"
UDisk CleanerDiskCleaner.Exe"Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Keeper[path to trojan]"Added by the SMALL-VE TROJAN!"
XDisk KeeperSECURITY.EXE"Daosearch adware"
XDisk Managerdiskver.exe"Added by the RBOT.AQT WORM!"
XDisk Master[trojan name]"Added by the DISTER TROJAN! - a spam relayer"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDiskCheckmsdarkend.exeAdded by an unidentified WORM or TROJAN!
NDiskeeperSystrayDkIcon.exe"DisKeeper defragmentation software - can be started manually"
Xdiskinfdiskinf.exe"Added by the CRYPTER.A TROJAN!"
?DISKMON.EXEDISKMON.EXE"??"
NDisknagdisknag.exeDell program that reminds you to make your backup diskettes
XDiskRetterSysRep.exe"DiskRetter
XDiskstartCode.exeAdult content dialler
XDiskstartcat.exeMS-Connect dialler
XDiskstarthit.exeAdult content dialler
XDiskstartSnt.exeAdult content dialler
UDiskSuiteaDSProcMngr.exe"Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization
UDisk_MonitorDisk_Monitor.exe"Multi-media
Xdisnisadisnisa.exe"Added by the DORF-AE WORM!"
XDispatcherdispatcher.exe"Added by the DLOADR-AS TROJAN!"
Xdispenterdispenter.exe"Added by the AGENT-MKK TROJAN!"
UdisplayThe_Eye.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
XDisplaybackup.exe"Added by the BRONTOK-CR WORM!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
NDisplay Settingshptasks.exe"Allows for the adjustment of the display for LCD screen
UDisplayFusionDisplayFusion.exe"DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much
NDisplayTrayIconTrayIcon.exe"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution
UDisspydisspy.exe"Disspy spyware detection and removal software"
XDist-FBGeneveGDC.exe"NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed File Systemkernel32dll.exe"Added by the MYFIP-C or MYFIP.K WORMS!"
XDistributed File Systemblade.exe"Added by the MYFIP.AC WORM!"
XDistributed File Systemwin.exe"Added by the MYFIP.AB WORM!"
XDistributed Link Trackingascvt.exe"Added by the AGOBOT-GH BACKDOOR!"
Udistributed.net clientDNETC.EXE"Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
NDiTask.exeDiTask.exe"Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free
?Dixons Insert DetectInsDetect.exe"Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
Xdjdsdvqwavjdhdg.exe"Added by the SDBOT-EF BACKDOOR!"
NDJRegFixregedit /s c:hpdjregfix.reg"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
?DJSNetCNDJSNetCN.exe"""Symantec Licensing Detect Internet Connection""
YDkServiceDkService.exe"From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled
Ydlatfswctrl.exe"Drive letter access to a UDF packet writer for CD-RW - from HP
Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
Xdlhostdlhost.exe"Added by the EXPHOOK-A TROJAN!"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
UDLink System Traydlnetst.exe"Related to D-Link DGE-530T PCI card for servers and workstations"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDll Linksvchoist.exe"Added by the AUTOSKY WORM!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDLL32dllhost.dll"Added by the SUCLOVE.A WORM!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDLLHostdllhst.exe"Added by the DELBOT-AC WORM!"
XDllHostdllhost.exe"Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf"
Xdllhostxp.exedllhostxp.exeBrowser hijacker and adware downloader
XDllLoaderlssas.exe"Added by the BDOOR-JE BACKDOOR!"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
UDLPSPDLPSP.EXEDell laser printer status monitor
Xdlsp2mxdlsp2mx.exe"Added by the MPB-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""dlsp2mx"""
XDm Hrlpns.exe"Added by the IRCBOT.WORM.61673 WORM!"
NDMASchedulerDMAScheduler.exe"Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program
NDMISLDMISL.EXE"DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
NDMISLAPPDMISLAPP.exe"DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
XDmsvc32Dmsvc32.exe"Added by the AGOBOT.ABU WORM!"
Xdm[3 random letters].exedm[3 random letters].exe"Added by the RUINDEM TROJAN!"
XDM_serverdmserver.exe"Comet Cursor adware"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
Xdnamd140113.a.Stub.EXE"Added by the STUB_A TROJAN!"
YDNE Binding Watchdog"rundll dnes.dll DnDneCheckBindings"
YDNE DUN Watchdog"rundll dnes.dll DnDneCheckDUN13"
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNS[worm filename]"Added by the BCKDR-CQG BACKDOOR!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
?DNS2GoClientdns2goclient.exe"DNS2Go is a Domain Name System that will make your computer accessible anytime
NDNS7reminderEreg.exe Ereg.ini"Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
Xdnscleanerdnscleaner.exe"CoolWebSearch parasite variant"
XDNSEDNSE.exe"Part of rogue security tools
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
XDoggy StyleMsPMSPSd.exe"Added by the SDBOT-AAP WORM!"
XDOGStartGSDOGST.EXE"Added by an unidentified VIRUS
XDokterFixSysRep.exe"DokterFix
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
UDon't Panic Pop-Up Stopperdpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
XDontworrymysaym.exe"Added by the SDBOT-RC WORM!"
UDopusdopus.exe"Directory Opus - a file manager from GPSoft"
NDoroServerDoroServer.exe"Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
Xdosdos64.exeAdware downloader trojan
XDos Prompt Loadercygwin.exe"Added by the SDBOT-VV WORM!"
?Dosbat??"??"
UDoubleDesktopdd.exe"""DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"""
XDowmingzuDowmingzu.dll.vbs"Added by the SOLOW-E WORM!"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads
XDownload PlusDownloadPlus.exe"DownloadPlus adware"
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xdownsdowns.exe"Added by the BCKDR-MNR TROJAN!"
YDPASDPASNT.exe"DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
YDPASUpdateDPASAutoUpdate.exe"Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
YDPCProxyLoadOnStartupdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
YDpcstartdpcstart.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
Udpps2dpps2.exe"Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
Xdpsdps.exe"SmartestSearch parasite - poses as a foistware
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
NDrag-to-DiscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
XDRam Monitor 23tskman3.exe"Added by a variant of the RBOT WORM!"
XDRam prmaessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosesor[random filename]"Added by the SPYBOT.EE WORM!"
XDRam prosessor[random filename]"Added by the RBOT.CSG WORM!"
XDRam prosessorplscd.exe"Added by the RBOT.CYA WORM!"
XDRam prosessorHWAPI.exe"Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
XDRam prosessorWindowsUpdate.exe"Added by the RBOT-BBZ WORM!"
XDRam prosessormsupdate.exe"Added by the DELF-FAW TROJAN!"
XDRam prosessorwinupl.exe"Added by the RBOT-BCQ WORM!"
XDRan posessorDAP.exe"Added by a variant of the SDBOT WORM!"
XDrAntispyDrAntispy.exe"DrAntiSpy rogue security software - not recommended"
XDrCacheMSTDC.EXE"Added by the BDOOR-JM BACKDOOR!"
Xdreamsserver.exe"Added by a variant of the SDBOT WORM!"
XDrefIWSysDrefIWv2.exe"Added by the DREF-C WORM!"
XDrefIWSysDref.exe"Added by the DREF-D WORM!"
NDrgToDscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
NDriverMaxdevices.exe"DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
NDriveSelectdriveselect.exe"DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
UdRMON SmartAgentSmartAgt.exe"Part of the network monitoring program group for 3Com NIC cards. See here for more info"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
XDrmupgdsDrmupgds.exe"Maxfiles adware"
XDropSpam Lifestyledslifestyle.exe"Dropspam adware"
?DrvListnrDrvListnr.exe"Analog Devices SoundMAX soundcard related. What does it do and is it required?"
Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
Xdrvsys.exedrvsys.exe"Added by the BEAGLE.W WORM!"
Xdrvsyskithidr.exe"Added by the BAGLE.HR WORM!"
Xdrvsyskithldrrr.exe"Added by the BAGLE.QU TROJAN!"
Xdrv_st_keyhidn.exe"Added by the BEAGLE.FF WORM!"
XDrWatsondrwatson_.exe"Added by the LOHAV-S TROJAN!"
XDrWatsondrwatson_32.exe"Added by the LOHAV-S TROJAN!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
YDrwebschedulerDrwebscd.exe"DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications
XDR_SDR_S.exe"IstBar adware"
Xdsds.exe"Added by the SPYMON TROJAN!"
UDS Clockdsclock.exe"Digital desktop clock including synchronization with atomic servers - see here"
XdS35DLLffqca.exe"Added by the SDBOT-KV WORM!"
Xdsadsa.exeHomepage hijacker - redirecting to downseek.com
XDSAcass[path to file]"Added by the RANKY.M TROJAN!"
Xdsadlsa14dsakfsak14.exe"Added by the ONLINEG-P TROJAN!"
XDSBDSB.exe"EnergyPlugin adware"
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
Xdsdzz.exe"Added by the RBOT-FOX WORM!"
NDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
XdsfghjgjkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xdsgblcsass.exe"Added by the AGENT.TGZ BACKDOOR!"
XDsidp-******.exeAdded by an unidentified adware where ****** are random characters
XDsidp-him.exe"Added by the MULTIDR-AH TROJAN!"
XDskcompatDskcompat.exe"Added by the GEMA TROJAN!"
UDSKEYDsKey.exe"Part of PC PhoneHome - ""secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection"". Security software from Brigadoon Security Group for tracking down lost/stolen computers"
XDSKEY[path to trojan]"Added by the STARTER-G TROJAN!"
NDSL Monitorspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
YDSLagentexeDSLagent.exe"Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
Ydslmondslmon.exeSagem DSL modem related. Apparently needed to detect the modem
UDSLSTATEXEdslstat.exeSystem tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
XDsmSerdsm.exe"Added by the SERFLOG.B WORM!"
XDsmSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDsmSersysup.exe"Added by the SERFLOG.B WORM!"
YDSndUpDSndUp.exe"Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
XDsplObjectswindspl.exe"Added by the BEAGLE.DN WORM!"
XDSSdssagent.exe"Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
XDSS[path to trojan]"Added by the DSSDOOR-C TROJAN!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
?DSSSGENSdssagens.exe"??"
Xdstiosysplsitctl.exe"Added by the MAILBOT-BX TROJAN!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UDT 11Mbps WLAN PC Card StationDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT 11Mbps WLAN USB StationDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
UDT TaskDTHtml.exe"Display Tune from Portrait Displays
UDualCoreCenterStartUpDualCoreCenter.exe"Unified control center for overclocking both the graphics card and the CPU
?Duane Reade Insert DetectInsDetect.exe"Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
NDulux WeatherShield WeatherDeskweather.exe"Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
Xdumprepspoolc.exe"Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XDuwee wong CerbonCirebons.exe"Added by the BHARAT.A WORM!"
XDVAScvssdfaAsSDdwd.exe"Added by the LIOTEN.IP TROJAN!"
NDVD@ccessDVDAccess.exe"Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
UDVDBitSetDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
NDVDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
NDVDXGhostDVDGhost.EXE"DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
UDVSyncdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
XDvxwsxsvc.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
NDW4DesktopWeather.exe"Desktop Weather 4 by The Weather Channel - provides current temperature
NDW6DesktopWeather.exe"Desktop Weather 6 by The Weather Channel - provides current temperature
NDwlClientsupport.exeDownload manager for Dell support alerts
Xdwqblwrsq.exe[random].exe"Okcashbackmall adware"
NdwStartFireWall.exe"The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
XDW_Startrwwnw64d.exeIdentified as a variant of the AdWare.Win32.ZenoSearch.am malware
XDxsys*.exe [* = random number]"Added by the DEXTER.A WORM!"
Xdxdiag diagnosemsidxdia.exe"Added by a variant of the RBOT WORM!"
Xdxdiags.exedxdiags.exe"Added by the CERTIF-G TROJAN!"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
XDxstyDxsty.exe"Added by the GEMA TROJAN!"
XDynamic Dns Binarydynitora.exe"Added by the RBOT-WT WORM!"
XDynamic Dns BinaryCMD16.EXE"Added by the RBOT-XM WORM!"
XDynamic Dns Binarywinxp34.exe"Added by a variant of the RBOT WORM!"
XDynamic Dns BinaryWinHelpcfn.exe"Added by a variant of the RBOT WORM!"
UDynDNS UpdaterDynDNS.exe"Dynamic DNS IP address updater tool
NDynDNS-Updater Traytoolddutray.exe"DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
XDynHttp Dns Binarydynizari.exe"Added by a variant of the RBOT WORM!"
UDynSiteDynSite.exe"DynSite - dynamic DNS client
UDynu Basic Clientdynubas.exe"Dynu online dynamic IP update client. Useful when using a dial up modem"
?DZKillMeDZSAVEME.EXE"??"
NE-Color RegistrationSonnReg.exe"Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
XE-nrgyPlusE-nrgyPlus.exe"Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
Ue-Surveiller Stationestation.exe"ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
NE6TaskPanelTaskPanl.exe"Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
YEAFRCliStartEAFRCliStart.exe"Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
Ueanthology_install.exeeanthology_install.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_critical_update_alertsys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
Ueanth_system_patchersys_alert.exe"eAcceleration Stop-Sign security software related. Previously not recommended
NEapcisetupsbsetup.exeRockwell RipTide soundcard application software. Sound works without it
NEAPCISETUPwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
NEasy CD CreatorRoxAssist.exe"Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize
UEasy Keyeasykey.exeFor programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
NEasy Start Buttonesb.exeProvides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
UEasy-PrintToolBoxBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
XEasyAVEasyAV.exe"Added by the NETSKY.S or NETSKY.T WORMS!"
XEasyDatesEasyDates.exePremium rate adult content dialler
XEasyDates_gbEasyDates_gb.exe"""Edate-A"" premium rate adult content dialler"
XEasyDates_nlEasyDates_nl.exeAdult content dialler
UEasyKeyeasykey.exeFor programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
UEasyKeyboardLoggerEasyKeyboardLogger.exe"EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup
XEasyMessageem2.exe"180solutions adware"
NEasyNetworkMcENUI.exe"McAfee's EasyNetwork user interface - ""enables secure file sharing
XEasySearchBarESBUpdate.exeEasySearchBar adware downloader
XeasyServServer.exe"Added by the EASYSERV TROJAN!"
XEasySpywareCleanerEasySpywareCleaner.exe"EasySpywareCleaner rogue spyware remover - not recommended
UEasySync ProXCPCMenu.exe"""IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - LtNts4NtsAgent.exe"Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasySync Pro - PocketPCAutoDetect.exe"Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
UEasyTuneIIIEasyTune.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneVGUI.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
Xeasywwweasywww2.exe"Added by an unidentified VIRUS
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
Xebmmmebatesmmmv.exe"Ebates adware"
UeDataSecurity LoadereDSloader.exe"Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons
?EDFcsndiscfcsn.exe"Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
UEDRestore??"Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
XEfata[random 5 characters].exe"Added by the FLUKAN-D WORM!"
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xefaxs ml097eefaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UEFI Hot Foldershffw.exe"""EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
XehSchedehSched.exe"Added by the SDBOT-DHF WORM!"
UEicon NetworksLAN_DAEMONwatch.exe"Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
XeKerberoseKerberos.exe"eKerberos rogue security software - not recommended"
UELBERTRicoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
UELBERT_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
UElectron MicroscopeEMIII.exe"Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home
Xelement furth[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
XELNKProxysmproxy.exe"Surfmonkey adware"
UELSA WINman SuiteWinmsuit.exe"Allows you to totally customize your ELSA graphics card settings
YElsaCapiCtlRcapi.exe"Assumed to stand for Remote Common Application Programming Interface (RCAPI)
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
UELSBLaunchELSBLaunch.exe"EarthLink SpamBlocker"
UeMachines eBoardEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
XeMakeSVEMAKESV.EXE"""Switch"" adult content dialer"
XeMakeSVEMAKE2B.EXE"""Switch"" adult content dialer"
UEMBASSY Trust Suite Secure UpdateAutoUpdate.exe"Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
XeMCryT Sh3ars Panagers[path to worm]"Added by the RBOT-AWI WORM!"
XeMessengeremsn.exe"Added by the RBOT.AHO BACKDOOR!"
UEmouseEmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
YEmsisoft Anti-Malwarea2guard.exe"System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses
Xemsw.exeemsw.exe"Attune HelpExpress - spyware. Disable and uninstall - see here"
NeMuleAutoStartemule.exe"eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project
NeMusicClient SystrayeMusicClient.exe"eMusic MP3 download software"
NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
XenBrowser[name of file]"WINBO adware"
?encapsulated command toolwintr.com"??"
NEncarta Dictionary QuickshelfQSHLFED.EXE"Provides quick access to Encarta's Dictionary features?"
UEncompass_ENCMONTRENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
?ENCSurfsurfboard.exe"??"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
Uenginecs2enginecs2.exe"Cyber Sentinel - internet filtering software"
NEnigmaPopupStopEnigmaPopupStop.exe"Part of Enigma SpyHunter - not recommended
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
?ENSMIX32.EXEENSMIX32.EXE"Sound card driver. Is it required?"
UEnsoniqMixerstarter.exe"Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
UEntbloess 2Entbloess2.exe"Related to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Exposé
UEnterprise HarmonyrsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XEnterprise SuiteWE[random characters].exe"Enterprise Suite rogue security software - not recommended
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPoXUSDMUSDM.EXE"EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
NEPSON Background MonitorSTMS.EXESupposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Status Monitor 3E_[various].EXE"Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C120 SeriesE_FATICCA.EXE"Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status
UEPSON Stylus C40 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status
UEPSON Stylus C41 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status
UEPSON Stylus C42 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S08IC1.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C43 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status
UEPSON Stylus C44 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UEPSON Stylus C45 SeriesE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status
UEPSON Stylus C46 SeriesE_S4I0T1.EXE"Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus C60 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status
UEPSON Stylus C61 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status
UEpson Stylus C62 SeriesE-S0BIC1.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C62 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status
UEPSON Stylus C63 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C64 SeriesE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status
UEPSON Stylus C66 SeriesE_S4I0S2.EXE"Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status
UEPSON Stylus C67 SeriesE_FATIAAL.EXE"Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status
UEpson Stylus C82 SeriesE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C82 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C84 SeriesE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status
UEPSON Stylus C87 SeriesE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3100E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status
UEPSON Stylus CX3200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3700 SeriesE_FATIACP.EXE"Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status
UEPSON Stylus CX3800 SeriesE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX4700 SeriesE_FATIADL.EXE"Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status
UEPSON Stylus CX4800 SeriesE_FATIADA.EXE"Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus CX5400E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UEPSON Stylus CX5500 SeriesE_FATICAP.EXE"Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXE"Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status
UEPSON Stylus CX7400 SeriesE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status
UEPSON Stylus CX8300 SeriesE_FATICEP.EXE"Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status
UEPSON Stylus CX8400 SeriesE_FATICEA.EXE"Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus D68 SeriesE_FATIAAE.EXE"Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status
UEPSON Stylus D78 SeriesE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status
UEPSON Stylus D88 SeriesE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status
UEPSON Stylus DX3800 SeriesE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXE"Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status
UEPSON Stylus DX4400 SeriesE_FATICAE.EXE"Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status
UEPSON Stylus DX4800 SeriesE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status
UEPSON Stylus DX7000F SeriesE_FATIBKE.EXE"Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status
UEPSON Stylus DX7400 SeriesE_FATICDE.EXE"Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status
UEPSON Stylus DX8400 SeriesE_FATICEE.EXE"Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status
UEPSON Stylus Photo 1400 SeriesE_FATIBUA.EXE"Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status
UEPSON Stylus Photo 2200E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status
UEPSON Stylus Photo 825E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXE"Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status
UEPSON Stylus Photo R280 SeriesE_FATICKA.EXE"Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status
UEPSON Stylus Photo R285 SeriesE_FATICKE.EXE"Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R340 SeriesE_FATIAJE.EXE"Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXE"Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX500E_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status
UEPSON Stylus Photo RX530 SeriesE_FATIAGP.EXE"Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status
UEPSON Stylus Photo RX600E_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXE"Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status
UEPSON Stylus Photo RX680 SeriesE_FATICJA.EXE"Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
UEPSON Stylus Pro 4000E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status
UEPSON Stylus Pro 7600E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status
UEPSON Stylus SX200 SeriesE_FATIEFE.EXE"Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status
UEPSON SX100 SeriesE_FATIEDE.EXE"Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status
UEPSON TX100 SeriesE_FATIEDP.EXE"Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status
UEPSON WorkForce 30 SeriesE_FATIEEA.EXE"Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status
UEPSON WorkForce 500 SeriesE_FATIEQA.EXE"Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status
UEPSON WorkForce 600 SeriesE_FATIEKA.EXE"Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status
UEpsonPhotoStarterEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this
Xeraseplgeraseplg.exe"Added by the GENOME.AQUV TROJAN!"
UErasereraser.exe"Eraser - ""an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns"". This entry starts the Scheduler with Windows and provides a System Tray icon for on-demand access. Located in %ProgramFiles%\Eraser"
Uerasereraser.exe"Part of Evidence Exterminator
Ueraser.exeeraser.exe"Part of Evidence Exterminator
YeRecoveryServicecheck.exe"Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceeRAgent.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
Xeros.exeeros.exeAdult content dailler
XErrCleanSysRep.exe"ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XErreurChasseurSysRep.exe"ErreurChasseur
XError Safeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XError Safe Freeuers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeers.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XErrorSafeFreeUERS.exe"ErrorSafe rogue system error and cleaning utility - not recommended"
XERSers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERScwERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
XERS_checkers_startupmon.exe"Part of the WinAntiVirus Pro 2006 rogue security software - not recommended
XERS_Checkuwasers.exe"Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
Xerthgdrsvc.exe"Added by the BEAGLE.BN or BEAGLE.BP WORM!"
Xerthgdr2svc23.exe"Added by the BAGLE.CG WORM!"
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
YeSafe ProtectESPWatch.exe"eSafe from Aladdin - internet security for gateway and E-mail servers"
UESBesb.exeEasy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
XEScorcherescorcher.exe"Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
NESFTPesftp.exe"ESftp - FTP client for transfering files between a local PC and another remote computer"
UeSnipsClientGW.exe"eSnips Client Gateway from eSnips"
XEsohEsoh123.exe"Added by the AGOBOT.FF WORM!"
XEspecialDeneca.bat"Added by the DELUZ VIRUS!"
XEsphortu.exe"PurityScan adware"
NESPN BottomLinebline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop
?ESS DaemonEssd.exe"Related to an ESS based soundacard. Is it required?"
?essapmessapm.exe"ESS Solo soundcard driver. Is it required?"
YEssdcessdc.exeRelated to an ESS Solo soundcard. Seems as though it's required
?ESSNDSYSESSNDSYS.EXE"Related to an ESS based soundacard. Is it required?"
YESSOLOESSOLO.exeSound card driver that re-instates itself every time it's removed
Yesspkesspk.exeESS Technology modem speaker driver file. Required to get on-line with this modem
UEssSpkPhoneessspk.exe"ESS Technologies Call waiting
?eSupIniteSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
XEsutitydeosutityde.exe"Added by the SDBOT.BQD WORM!"
XETB Testeretbtest.exe"Added by the RBOT-ABR WORM!"
Xethernetmsnger.exe"Added by a variant of the SDBOT WORM!"
Xethernetmsftp.exe"Added by the SDBOT.BXJ WORM!"
Xethernet adaptercsrmss.exe"Added by a variant of the RBOT WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
YeTrust EZ Firewallefpeadm.exe"eTrust EZ Firewall"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XeTrust Realtime Monitorrealmon.exe"Added by the LAZAR.B TROJAN!"
YeTrustCIPEezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
UEVGAPrecisionEVGAPrecision.exe"EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
UEVOLOSTAEVOLOSTA.EXE"Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID
UEvoluent Mouse ManagerEvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
UEvtMgr6Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
NeWare StartupiWareStart.exe"eWare iWare task bar. Not required"
Yewido anti-spywareewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
XEwthtasn.exe"PurityScan adware"
?Excite Private Messenger Pipex8impipe.exe"??"
NExciteAssistantEXEASSISTANT.EXE"With Excite Assistant
XExecUserExecUser.exe"Added by a variant of the RBOT WORM!"
?Executedelfolders.exe"??"
XExeName32Warm.scr"Added by the SCOLD WORM!"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
?exgiwslexgiwsl.exe"??"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorershellexpl.exe"Added by the SHELDOR TROJAN!"
XExplorershellexp.exe"Added by the AGENT-ZY TROJAN!"
XEXPLORERsys.exe"Added by the SILLYFDC-A TROJAN!"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorerTaskexplorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xexporetwinset.exe"Added by the QQPASS-I TROJAN!"
UExpress ClickYesClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt
UExshow95EXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
NExtender Resource MonitorRMSysTry.exe"Related to Windows Media Center from Microsoft"
XExternal DependenciesExternal.exe"Added by the MYTOB.EC WORM!"
XExtra AntivirusExtraAV.exe"Extra Antivirus rogue security software - not recommended
UExtraDNSExtraDNS.exe"ExtraDNS - DNS configuration tool"
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
NEZDeskEZDESK.EXE"Utility that remembers icon locations for each user and resolution. Available here"
YezPS_PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezPS_PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
YezShieldProtector for PxezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
UEZSMART Appezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
UE_S10IC2E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
UE_S23E_SICN03.exe"Epson printer status monitor - for checking ink levels
UE_S4I2F1E_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
UE_S4I2G1E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
UE_SOEIC1E_SOEIC1.exe"Epson Status Monitor 3 - for monitoring printer status
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
XF-Secure Gatekeeper[malware name].exe"Added by the NUWAR.AXQ WORM!"
UF-Secure Management AgentFSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
YF-Secure ManagerFSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
YF-Secure Startup WizardFSSW.EXE"F-Secure antivirus"
YF-Secure TNBTNBUtil.exe"F-Secure antivirus"
YF-StopWF-StopW.exe"F-Prot anti-virus background scanner by F-Risk Software"
?f23mxinsf23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
Xf2install.exef2install.exe"Added by the IEFEAT-I TROJAN!"
Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
UFabrik Ultimate Backup Statusfabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink
XFaltCheckallps.exe"Added by the AGENT.RAP TROJAN!"
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
XFantasia injectorwincfg.exe"Added by the AGOBOT.US WORM!"
Xfarkrishfarkrish.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XFashFash.exeUnidentified adware
Xfaslkakj11kjgagklj11.exe"Added by the LEGMIE-ARE TROJAN!"
Nfastfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
XfastA-fast.exe"A-fast Antivirus rogue security software - not recommended
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
NFAST DefragFAST2.EXE"FastDefrag defragmenting software"
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
XFast Searchsvcnv.exe"Homepage
XFast startNtut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
UFastCachefc.exe"FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
Xfastsmellfastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XFastStartntnut32.exe"Added by the STARTPAGE.L TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
NFastTrack AcceleratorSPEED UP.EXE"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
UFastTVSyncFastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps
NFastUserfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
NFastUsrfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
XFat32 Microsoftfat32.exe"Added by the RBOT-EL WORM!"
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
?FBIFBISM.exe"Compaq related but what does it do?"
XFBSearchFastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSearchSearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFBSSAie3sh.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
XFdaemon securityfsecur.exe"Added by the SDBOT.KXO WORM!"
XFDD SYSTEMFdd.exe"Added by the MYTOB-FO WORM!"
XFdr Command Modulesp2.exe"Added by the SDBOT.WP WORM!"
UFD_SAPFD.exeReported to be the autopassword program from the Sony Microvault thumb drive
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
UFellowes ProxyR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
XFestPlattenCleanerSysRep.exe"FestPlattenCleaner
XFestplattenReinigerGDC.exe"FestplattenReiniger
Xffsvhost32.exe"Added by the LINEAG-AFF TROJAN!"
Xffeqfqsdqddss.exe"Added by the SDBOT-SG WORM!"
XffeqOMEvcvsav.exe"Added by the RANKY.AB TROJAN!"
Xffisffisearch.exe"iSearch adware"
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XFHPageshdochp.exe"Added by the WINHOUND TROJAN!"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
UFhtisxkfhtisxk.exeXtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
XFiendlyTypecsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile Systemtaskmqrs.exe"Added by a variant of the TOXBOT/CODBOT WORM!"
XFile Systemtaskmqr.exe"Added by the RBOT.BWQ WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFile-Sharing Wizardshwizard.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
Xfilename processkerneldll.exe"Added by the AGOBOT-PO WORM!"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
NFind FastFindfast.exeFrom older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
Xfindfastfindfast.exe"Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
Xfindfast.exefindfast.exeIdentified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
NFineReader7NewsReaderProAbbyyNewsReader.exe"ABBYY FineReader OCR software - version 7"
UFingerPrintSoftwarefpapp.exeSupports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFirevall Administratingrndll.exe"Added by the PUSHBOT-B WORM!"
XFirewallSP2 UPDATE.exe"Added by the ELITPER.E WORM!"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
XFirewall Administratinginfocard.exe"Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
XFirewall auto setupwinlogon.exe"Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFirewall auto setup[path to trojan]"Added by the AGENT-GLY TROJAN!"
XFirewall Controlssys32.exe"Added by the SDBOT-DGI WORM!"
XFirewall Sp2 systemsys32Conf.exe"Added by the RBOT-ABT WORM!"
XFirewall Update System1WinedowsUpdater1.exe"Added by the RBOT-ARU WORM!"
XFirewall Updatermsnupdateit.exe"Added by the RBOT-AAQ WORM!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
UFirewallStartupFirewallstartup.exe"Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean
XFirewallSvrFirewallSvr.exe"Added by the NETSKY.X or NETSKY.Y WORMS!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFirst Home Pagehttp://find.naupoint.com"Naupoint browser hijacker"
?First Principle Groupfpg.exe"Related to the E-Players Card from First Principle Group"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
YFix-itmxtask.exe"Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard
Xfjdslssdfdmat2.exe"Added by the SLAPEW.C TROJAN!"
UFJTWAIN SetupFjtwSetup.exeFujitsu scanner utility
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
NfkSysMonfksysmon.exe"fkWrae SysMon - system monitor - ""displays the current memory consumption
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Media%%%%%.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media%%%.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media[path to trojan]"Added by the IRCBOT.AUR TROJAN!"
XFlash Media^ ^^^ %% % ^% ^%%^ %^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^^^^^.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Media^^^^^^.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XFlash Mediazrpk��'�'%''msn'�%'fix''.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media% ^% ^^^ %^% %% ^ ^ %%% ^% %^ % %^^.exe"Added by a variant of the IRCBOT BACKDOOR! Note the space at the beginning of the filename"
XFlash Media^%%^%%%^% %^ ^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%^^%^^% %^^^^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media^%^^^%% ^ ^ %^^^^^ %^ ^%^^ ^%^^^^^ %^ ^^^%^%%.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%^% ^ %^%% ^ % ^%%^^ %^^%^%^ ^%% %^.exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Media%%%%%%^^ ^ .exe"Added by a variant of the IRCBOT BACKDOOR!"
XFlash Mediaskxs��'�'%''msn'�%'fix''.exe"Added by the AGENT.ZOY TROJAN!"
XFlash Media^ %%^%^%.exe"Added by the FLUSH.A TROJAN! Note the space at the beginning of the filename"
XFlash Media%% % ^^ % %% ^%^^ ^^^ % ^%% ^ ^.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note the space at the beginning of the filename"
XFlash Media^ ^ % ^ % % ^ ^ ^%% ^% %%^^.exe"Added by the IRCBOT.BAW BACKDOOR!"
XFlash Player2[path to worm]"Added by the IRCBOT.PD WORM!"
?FLASH32#NAME?"??"
XFlash32FLASH32.COM"Added by the STARTER-F TROJAN!"
UFlashEncFlashEnc.exe"Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission
NFlashgetFlashGet.exe"FlashGet download manager"
XFlashget Download ManagerFlashget.exe"Added by the RBOT-AGZ WORM!"
XFlashGuardFlashGuard.exe"Added by the AUTOIT.AL WORM!"
UFlashMuteFlashMute.exe"""FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively
NFlashPath MonitorSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath MonitorFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusSDSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
NFlashPath StatusFLSHSTAT.EXESystem Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
XFlashy BotFlashy.exe"Added by the GLUPZY.A WORM!"
XFlash_Player_Installying.exe"Constructor VC2000 malware"
UFLMBROWSERMOUSEmouse32A.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMLABTECMOUSEmouse32A.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMMEDIONMOUSEmouse32a.exeMouse utility for a Medion branded Fellowes mouse
UFLMOFFICE4DMOUSEmoffice.exeMouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMOFFICE4DMOUSEmouse32a.exeMouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
UFLMTRUSTKBKbdAp32A.exeKeyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFLMTRUSTMOUSEmouse32a.exeMouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
XFloppy Master[path to trojan]"Added by the ZONIT-F TROJAN!"
Xflpsflps.vbs"Added by the BYRON WORM!"
?FLSVCIFLSVCI.exe"??"
YFltProcessmsinet.exe"Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
XFlyswatDesktopflydesk.exeAdvertising spyware
Xfmnwebassistfmnwebassist.exeAdware popup generator
UFMStartFmstart.exe"GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks
XFMSZfmsz.exe"Added by the FMSZ TROJAN!"
Xfnmwebassistfnmwebassist.exe"WinPL adware"
?FocusFocus.exe"ISDN configuration wizard?"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
NFoneSyncSystemTrayFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
XFontsLoaderldfnt32.htaUnidentified malware
YFoolProofSweep??"Part of FoolProof Security PC security software from SmartStuff"
NForbesForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
XForceShow"rundll32.exe QaBar.dllForceShowBar"
UFortis Secure Layer Configcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
Xfotosfotos.exe"Added by the BANKER-FP TROJAN!"
NFotoStation Easy AutoLaunchFotoStation Easy AutoLaunch.exeInstalled with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
Nfpassistfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
XFramework Windowsfrmwrk32.exe"Added by the FAKEAV-KS TROJAN!"
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NFrapsFRAPS.EXE"Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting
?Free Downloads Monitorfdcmon.exe"??"
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
XFreeAttentioneqsefeqe.exeAdded by an unidentified WORM or TROJAN!
NFreebie NotesFreebieNotes.exe"Freebie Notes by Power Soft - create electronic notes (stickers)"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
NFreePDF Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
NFreePDF_Assistantfpassist.exe"Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
Xfreestylelockx.exe"Added by the RBOT-ATH WORM!"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
Xfreexstylelockbar.exe"Added by the LOXBOT.D WORM!"
Xfreexstylelockbr.exe"Added by the LOXBOT.C WORM!"
Xfreinstpgs.exe"Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
UFresh Desktopfreshdesktop.exe"Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
Nfreshclamfreshclam.exe"Auto update agent of the open source Clamwin virus scanner"
?frgukshdrkmck.exe"??"
?FridaysInHellInstallerFridaysInHellInstaller.exe"??"
XFriendlyTypelsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
NFriendlyWebQuick-LaunchSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
UFRISK FP-SchedulerF-Sched.exe"Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
?FRITZ!DSL StartcenterStCenter.exe"FRITZ! ISP software ""StartCenter"" User interface that allows you to manage
XFrskfrsk.exeUnidentified adware downloader trojan
Yfrxmxinsfrxmxins.exeATI 3D Studio MAX/VIZ driver
XFS Agentfagent.exe"Added by the VOLVER-B TROJAN!"
XFS6519FS6519.dll.vbs"Added by the SOLOW.B WORM!"
Yfsaafsaa.exe"F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers"
NFSCBossFSCBoss.exeFree Store Club shop online software
?FSDPSRVFSDPSRV.exe"??"
Xfsdsft[path to backdoor]"Added by the RANKY.S BACKDOOR!"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Ufspfsp.exe"Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents"
YfsprFolderShield.exe"Folder Shield - hide personal files and folders"
NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
Ufsservfserv.exe"Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
Ufssuifsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
Ufssuifssui.exe"System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches
Xfstsvc"rundll32.exe fstsvc.dllstart"
Ufsuifsui.exe"System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety
XFSWFSW.exe"FreeScratchAndWin parasite"
UFSWebServerfsws.exe"Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
UFtLnSOP_setupFtLnSOP.exeFujitsu scanner utility
UFTMSFLT(USB)FTMSFLTU.EXEFujitsu's Touch Panel Message Notifier
XFTP FOR WINDOWSftpwin32.exe"Added by a variant of the RBOT WORM!"
UFtpqueueFtpsched.exe"Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
?FtpServer.exeFtpServer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
XFUFUvirus.exe"Added by the VB-EJC TROJAN!"
XFuckerfucker.vbs"Added by the CATCHER-A WORM!"
UFujitsu Hotkey UtilityIndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
UFujitsu MenuFjMnuIco.exe"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
NFusionHdtvTrayFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
UFusionRCFusionRC.exe"Remote control manager for DVICO FusionHDTV"
UFusionRemoteFusionRc.exe"Remote control manager for DVICO FusionHDTV"
NFusionTrayAgentFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
Nfwrastrcfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
Ufwservicefwservice"eAcceleration Stop-Sign security software related. Previously not recommended
Xfzgsvhost32.exe"Added by the DLOADER.BDK TROJAN!"
XG0mezG0mez.vbs"Added by the GORMLEZ-A WORM!"
XG3GSMedia3.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
Xgadkgak12fsafsakx12.exe"Added by the ONLINEG-N TROJAN!"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
Xgameshit.exeAdded by the Netclap Gold backdoor TROJAN!
Xgamepatcher.scr"Added by the PSW-ED TROJAN!"
XGame HouseGameHouse.exe"Added by the DELF-DRA WORM!"
NGameDriveGDTask.exe"GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
XGames Accelerationsvshost.exe"EasySearch adware"
XGames Acceleration[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTB"Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
NGameSpotkontiki.exe"Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
Xgammasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
UGammaHotKeyssetgamma.exe"Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop"
Xgangstagangsta.exe"Added by the RIMA.A BACKDOOR!"
UGARO Status Monitorcnwism.exePrint monitor for certain Canon printers
XgaSrvgaSrv.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XgaSrvegaSrve.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XGate Personal FirewallSystpl.exe"Added by the RBOT.ADC WORM"
NGateway Extended WarrantyGWCares.exeGateway Extended Warranty reminder
XGay_Sexy_**Gay_Sexy_**.exePremium rate adult content dialler (where * is a random char)
UGazelDisplaygsyno.exe"BT Digital Access USB - Gazel ISDN installation System Tray icon"
YGBSpaceManSpaceMan.exe"GreenBorder - secure your browsing activities on the internet"
XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
YgcasServgcasServ.exe"Giant Antipsyware - now superseded by Microsoft's Windows Defender"
XgcasServrealsched.exe"Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
Xgdagdgajsbbsbw.exe"Added by the SDBOT-QX WORM!"
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
NGEARsecgearsec.exeInstalled by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
NGemStRmWGemStRmW.exe"For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card
UGene USB MonitorUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
XGeneral AntivirusGenAvir.exe"General Antivirus rogue security software - not recommended
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Processlsassw.exe"Added by the AGOBOT-N WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGenericHostXPWinLoaderXP.exe"Added by the BDOOR-ACX BACKDOOR!"
YGenie USB MonitorUSBmonitor.exePort monitor for an external USB hard drive. Required to enable access to the drive
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
Xgerman.exewinsystems.exe"Added by the BAGLEDl-AE TROJAN!"
Xgerman.exewintems.exe"Added by the BAGLE-AS TROJAN!"
Xgescwgescw.exe"Part of BeschermingsTool
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
NGet Smilegetsmile.exePuts smilie faces in your E-mail. Run manually when required
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
XGhost Relay[random filename]"Added by the DNSCHANG.EK TROJAN!"
UGhostSecuritySuitegss.exe"Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
NGhostStartTrayAppGhostStartTrayApp.exe"System Tray access to Norton Ghost - added from the 2003 version"
YGhostSurfDelSatelliteDeleteSatellite.exe"Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning
UGiganews AcceleratorGiganewsAccelerator.exe"Giganews Accelerator from Giganews
YGilat SOM Enumeratordllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Xgimmygames[path to trojan]"Added by the DLOADR-LN TROJAN!"
Xgimmysmileysgimmysmileys.exe"GimmySmileys adware"
?GisdnLoggisdnlog.exe"BT Digital Access USB"
UGlass2kGlass2k.exe""Glass2k is a small little program that allows Win2K/XP users to make any window transparent""
XGlobal StartupWinDash.EXE"Detected by Kaspersky as the VB.Q WORM!"
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
XGlock Suite 1.1glock32.exe"Added by the TINY.GV TROJAN!"
XGLSetIT32msiexec16.exe"Added by the OPTIX PRO TROJAN!"
XGLSetIT32isass.exe"Added by a variant of the OPTIX PRO TROJAN!"
XGLSetT32smsiexec.exe"Added by the OPTIX-D TROJAN!"
XGMedia2GSM2.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
XGMedia2GSMedia3.exe"Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
YGmouseGmouse.exeAmouse mouse driver - required if you use non-standard Windows driver features
XGmsvc32gmsvc32.exe"Added by the AGOBOT.ABN WORM!"
UGnetmousgnetmous.exe"Genius mouse driver - required if you use non-standard Windows driver features"
UGNETMOUSEgnetmouse.exe"Genius mouse driver - required if you use non-standard Windows driver features"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XGo And Startsvdll32.exe"Added by the RBOT.AI BACKDOOR!"
XGo!Zilla Monster DownloadsGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
XGoldenAntiSpypgs.exe"GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
XGolumservices.exe"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process
Xgolummservices.exe"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
UGoogle DesktopGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
UGoogle Desktop SearchGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
NGoogle Earth ViewerGOOGLEMAPS.EXE"Google Earth ""combines satellite imagery
UGoogle Quick Search BoxGoogleQuickSearchBox.exe"Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
UGoogleDesktopGoogleDesktop.exe"Google Desktop - ""a desktop search application that provides full text search over your email
UGoogleQuickSearchBoxGoogleQuickSearchBox.exe"Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
UGoToMyPCg2svc.exe"ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
UGoTrustedGoTrusted Secure Tunnel.exe"""GoTrusted is the fast
XGotSmileyGotSmiley.exe"GotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xgovurarope"Rundll32.exe retasevo.dlls"
?gramdate2Stop.exe"??"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XGraphics_default.pif"Added by the AUTOSKY WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
UGravis Appawareloaderdbserver.exe"Looks like it's associated with Gravis game controllers and the Keyset Manager
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
?GrdSys32GrdSys32.exe"X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
XGreasyPalmUpdateGreasyPalmUpdate.exe"SearchFast adware"
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
NGreetings WorkshopGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
Xgrindersgrinders.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
NGroksterGrokster.exe"Grokster Peer-To-Peer File Sharing program"
UGroupWise PDA Connect - 3CmPlmAutoDet.exe"3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - GrpWseAgnt.exe"GroupWise PDA Connect PDA synchronisation utility - from Novell"
UGroupWise PDA Connect - PocketPCAUTODE~1.EXE"Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
XGsAdsgms2.exe"PacerD_Media/Pacimedia.com adware"
?GscbcGscbc.exe"??"
Xgshpzzgshp.vbsHomepage hi-jacker
NGsiconexeGsicon.exe"ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
?GsiFinal"rundll32 gspndll.dllpostInstall final"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
NGSOrganizerGSOrganizer.exe"GoldenSection Organizer (now WinOrganizer - personal information manager)"
Xgssomaticgssomatic.exe"Searchcentrix hijacker"
YgStartgStart.exegStart GPS software from Garmin
XGStartupGMT.exe"Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xgsvgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
Xgtydfiisca.exe"Added by the CLAGGER-BB TROJAN!"
Xgtydfiscca.exe"Added by the DWNLDR-GTK TROJAN!"
UGuardian PC Security ToolsPfft.exe"Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
XGuardPcs.exeGuardPcs.exe"GuardPcs rogue security software - not recommended
Xguarnsetguarnset.exe"Adlogix adware"
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
Xgwizntsystem.exe"Added by the NITWIZ.A TROJAN!"
NGWMDMMSGGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
XG_HostgHost.exe"Added by the AUTOIT-BP WORM!"
XG_Server.exeG_Server.exe"Added by the FEUTEL-C TROJAN!"
XG_Server1.2.exeG_Server1.2.exe"Added by the GRAYBIRD-Z TROJAN!"
UH/PC Connection AgentWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
Xhachimitsu-lemonhachimitsu-lemon.exe"Added by the HACHILEM TROJAN!"
UHalifaxHowardClusterskinkers.exe"""Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
NHard Disk SentinelHDSentinel.exe"Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
UHardware Sensors Monitorhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
XHardware Shell DetectionWinHSD.exe"Added by a variant of the RBOT WORM!"
UHarmony 98 - CasioOrgCasAgnt.exe"Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
XHataDuzelticisiSysRep.exe"HataDuzelticisi
UHawking Wireless UtilityHWU8DD.exe"Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies
XHbinstHbinst.exe"Hotbar adware"
UHControlUserHControlUser.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
Nhcsystrayhc_tray.exe"Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
NHDAShCutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
XHELLBOT TEST1hellbot.exe"Added by the MYDOOM.BO WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhellodollyshost.exe"Added by the YODO WORM!"
Xhelloservhelloserv.exe"Added by the ZHELATI.BHA WORM!"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XHelplshost.exeIdentified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
XHelp Temp Filesnetreg.exe"Added by the FORBOT-EM WORM!"
XHelp Temp Filesemp32.exe"Added by the FORBOT-EC WORM!"
UHelpCentersprtcmd.exe /P HelpCenter"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
UHelpCenter4.1sprtcmd.exe /P HelpCenter4.1"Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft
XHelpereschlp.exe"Added by the BLASTER.T WORM!"
XHELPERNetherlands.exe"AsdPlug premium rate adult content dialer variant"
XHELPERsweden.exe"AsdPlug premium rate adult content dialer variant"
Xhelpmanagerspoler.exe"Added by the RANDEX.J WORM!"
Xheomstoolheomstool.exe"Added by the HEOMS TROJAN!"
YHEProtectHSockPE.exe"Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
XhErcUnessofthost.exe"Added by the GARROCH WORM!"
UHermes MessengerDGDRHE~1.EXE"A LAN messenger alternative to WinPopUp - Digital Dreams Software"
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Yhffsrvhffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Yhffsrv.exehffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
XhgkytwekeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
NHGTXPEIFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
Xhhtnsnrnxntup.exe"Added by a variant of the ORCU.B TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHideStyleAnte Browse Trust.exe"IE toolbar taking you to Lop.com. If the exe is running
UHidetools Spy Monitorwmispe.exe"HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
Uhidservhidserv.exe"This is the Human Interface Device Server for Win98SE/2000/Me/XP
XHidup_SusahPembantu.exe"Added by the SILLYFDC.BDM WORM!"
Xhid_startgzmrotate.dll"AdRotator/IconAds adware"
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
NHigh Definition Audio Property Page ShortcutHDAShCut.exeHigh definition audio page shortcut for Realtek audio devices - not required
UHigh Definition Audio Property Page ShortcutCHDAudPropShortcut.exe"Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
YHighPoint ATA RAID Management Softwareraidman.exe"HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
UHijackThisHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
UHijackThis startup scanHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
XHijSrv32hijsrv.exe"Added by the BANKGERM-D TROJAN!"
XHistoriaLout.GDC.exe"HistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NHistoryKillhistkill.exe"HistoryKill removes your web surfing path by removing the URL drop-list history
UHitman Pro SurfRight Helpersrhelper.exe"Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
XHKCUserver.exe"Added by the AGENT-NLT TROJAN!"
XHKLMserver.exe"Added by the AGENT-NLT TROJAN!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
UhkservHKserv.exeKeyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
Uhksshkss.exeCompaq HotKey Support - multimedia keyboard support
XHLcleanuphlsetup2.exe"LinkReplacer/FFinder adware"
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHML PowerSourcehmlsvc32.exe"Added by the SDBOT-XL WORM!"
XHMV PowerSourcehmusvc32.exe"Added by the SDBOT-YW WORM!"
Xho2stdll.exeho2stdll.exe"Added by the BANKER-HO TROJAN!"
XHOI Servicesholsvc32.exe"Added by the AGOBOT-SF WORM!"
NHoliday LightsHoliday Lights.exe"Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
NHome Theater SchSvrSchSvr.exe"WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
Xhomepage.monitor.exeisamonitor.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
UHookSysHookSys.exe"SurfinGuard Pro from Finjan - internet protection software
XHostN/A"Added by the POPDIS or STARTPAGE.F TROJANS!"
Xhosthelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XHost Processmame.exe"Added by the RBOT-APO WORM!"
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHost Process for Windows Taskstaskhost.exe"Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhostdll.exehostdll.exe"Added by the BANKER-BO TROJAN!"
UHostManagerAOLHostManager.exe"Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
XHostname Manager Serverhost32srv.exe"Added by a variant of the RBOT WORM!"
XHostren.exeHostren.exe"Added by PWS.BANKER.F
Xhostservhostserv.exe"Added by the RBOT.BPZ WORM!"
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
UHostsFileMgrwinHostsEdit.exe"AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
UHostsManhm.exe"""HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
UHot CornersHotc.exe"Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
XHOT FIXE0chis.exe"Added by the HUPIGON.JTY TROJAN!"
XHOT FIXwindsys2.exe"Added by the AGOBOT.AOI BACKDOOR!"
XHot InsideHottest Story Ever.exe"Added by the BHARAT.A WORM!"
UHot Key Kbd 2690 DaemonSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XHotbarHbinst.exe"Hotbar adware"
XHotbarSAHotbarSA.exe"Hotbar adware"
Xhotefixmsnmanegers.exe"Added by the IRCBRUTE.AS TROJAN!"
Xhotfixmsnnmaneger.exe"Added by the WOOTBOT.AF WORM!"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
UHotKeysCmdshkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
XHotKeysCmds[path to worm]"Added by the PAHATIA-A WORM!"
NHotSync Managerhotsync.exeInstalled when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
XHot_KissHot_Kiss.exeAdult content dialler
XHot_TartsHot_Tarts.exeAdult content dialler
XHot_Tarts_**Hot_Tarts_**.exePremium rate adult content dialer (where * is a random char)
XHot_Tarts_AuHot_Tarts_Au.exePremium rate adult content dialler
XHot_Tarts_mcHot_Tarts_mc.exe"HotTarts adult content dialer"
UHoverDeskHoverDesk.exe"HoverDesk - desktop replacement software"
Nhp center UIShadowBar.exe"User Interface for HP Center - see here"
XHP DeskjetHP_DeskJet_500.exe"Added by the FORBOT-DA WORM!"
XHP Desktopccappms.exe"Added by the SDBOT-TG WORM!"
UHP Display Settingshpdisply.exe"Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
UHP Health Check ScheduleHPHC_Scheduler.exeHP Health Check Scheduler from Hewlett-Packard
?HP IDSchedulerHPIDSCHD.exe"HP Instant Delivery Scheduler"
NHP Image Zone Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
NHP Info Express??"On HP PCs
UHP Instant Supportmatcli.exe""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
NHP Internet CenterSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
NHP JetDiscoveryHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
NHP JetSpeed AutostartAUTOSTART.EXEAutostart executable for the old multiplayer game HP Jetspeed
UHP Laser Jet Directorhppdirector.exe"System Tray icon that opens various functions such as copy
?HP Network Registry Agenthpnra.exe"??"
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
NHP Parallel Port Testhppt.exeAssociated with a HP ScanJet scanner
NHP Photosmart Premier Fast Starthpqthb08.exe"Improves the startup time of HP Image Zone. If you disable it
?HP Port Resolverhpbpro.exe"??"
NHP Precision Scanhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
NHP Presentation ReadyPresRdy.exeHP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
UHP SchedIndexerhppschedindexer.exe"Installed by HP multi-function printer driver software
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
?hp Silent ServiceHpSrvUI.exe"HP related"
NHP Simple TraxHpcron.exeSupplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
NHP software updateHPWuSchd.exe"HP software updates. If a shortcut doesn't exist
NHP Statushpstatus.exeHP Printer Status and Alerts
?HP Status Serverhpboid.exe"Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?"
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
NHP Updates??"On HP PCs
?HP Visualize InitHpVisIni.exe"HP Visualize software related. What does it do and is it required?"
UHPADVISORHPAdvisor.exeHP Total Care Advisor - a suite of help and hardware check programs to help you check the health of your PCs
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
Xhpdeskjethpdeskjet.exe"Added by the GENOME.AQUV TROJAN!"
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb11.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb12.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb13.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Nhpfschedhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Nhpgs2wndhpgs2wnd.exe"Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
XHphomehphome.jsHomepage hijacker
?hpjsiroutehpjsira.exe"Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2""
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
YHPLJ ConfigSetConfig.exeConnects system to networked HP printer.
XHpPrinterhpserver.exe"Added by the CMJSPY-W TROJAN!"
UHPPWRSAVHPPWRSAV.EXE"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com
?hpqSRMonhpqSRMon.exe"Related to HP Digital Imaging products. What does it do and is it required?"
UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
?hpScannerFirstBootscannerfb.exe"HP scanner related"
XhpSdwxmarkGaddw.exe"Added by the SDBOT-RB WORM!"
Nhpsjbmgrhpsjbmgr.exe"HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup
NHPStarthpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Uhpsysdrvhpsysdrv.exe"This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP
Xhptoolshptools.exe"Added by a variant of the SDBOT WORM!"
Xhptoolsmicrosoft.exe"Added by a variant of the SDBOT WORM!"
NHPUProvenTactics.exe"Proven Internet Marketing software"
UhpWirelessAssistantHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
UhpWirelessAssistantHPWAMain.exeWireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsbolhpztsbol.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
XHQI Serviceshqisvc32.exe"Added by the AGOBOT-RO WORM!"
XHQI Serviceshqlsvc32.exe"Added by the AGOBOT-RP WORM!"
UHREF.OCXregsvr32.exe ....HREF.OCX"HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
XHservicemsservice.exe"Added by the AUTORUN-KL WORM!"
Xhsimisearch.exeUnidentified malware
Xhsimsexgame.exeUnidentified malware
Xhsimtoolbar.exeUnidentified malware
UHSLAB Loggerlogger.exe"HSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it"
UHSONHSON.exeToshiba HotStart button support for instant-on entertainment on their laptops
UHSTranshstrans.exe"Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
?HsuGuiControlHsuGuiControl.exe"Part of the Starband Internet satellite client. What does it do and is it required?"
UhsysHSYS.EXE"Keylogger Express keystroke logger/monitoring program - remove unless you installed it yourself!"
XHTML Help Systemhhs.pif"Added by the RBOT-ATB WORM!"
XHTML32 Help Systemhhs32.pif"Added by the RBOT-ATE WORM!"
Xhtssv32.exehtssv32.exe"Added by a variant of the SDBOT TROJAN!"
XHTTP Tunneling Servermstunnel.exe"Added by the RBOT.EDL WORM!"
Xhttpdmsgaol.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpds_menu.exe"Added by the TACTSLAY.C TROJAN!"
Xhttpdbrowse.exe"Added by the TACTSLAY.C TROJAN!"
Xhttps-sslhttps.exe"Added by the MOEGA.D WORM!"
UHughesNet Toolsmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address
XhuigeziHgzServer.exe"Added by the GRAYBIRD.C TROJAN!"
XhuigeziSP00LSV.EXE"Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
XHvewsveqmgANACON.EXE"Added by the NACO.A WORM!"
YHWinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XHwpsystem_wc.exe"Eziin adware"
Xhwshws.exe"Added by the STARTPA-CT TROJAN!"
UHWSetupHWSetup.exe hwSetUP"""Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS
Xhxadsec[path to trojan]"Added by the ADCLICK-AP TROJAN!"
UHydarVisionDesktopManagerdesk95.exe"ATI's HydraVision desktop management software
UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionDesktopManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UHydraVisionViewportviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionViewPortHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XHyper Filesphfhost.exe"Added by the AGENT-JQO TROJAN!"
XHyper Startinstantmsgrs.exe"Added by the RBOT-NH WORM!"
XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
XI am not Ranky. I am eTunnel!winsys.exeAdded by an unidentified WORM or TROJAN!
XI am not Ranky. I am eTunnel!disney.exeAdded by an unidentified WORM or TROJAN!
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
?I81SHELLI81SHELL.exe"Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard"
XIamnacho On Irc.MusIrc.com Is a Homosexual!XBox64.exe"Added by the RANDEX.Y WORM!"
?IaNvSrvIaNvSrv.exe"Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
Uiasias.exe"InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XIASHLPRIASHLPR.EXE"Added by the OPASERV.T WORM!"
YIBM Client Securitycerttool.exe"Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk)
NIBM Client Security Softwarecsecwiz.exe"Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once
YIBM Password Managerpwmgr.exe"Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information
UIBM ThinkPad EasyEject Support ApplicationEzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
NIBM ThinkPad EasyEject Tray UtilityEZEJTRAY.EXE"System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
UIBM TrackPoint Accessibility Featurestp4ex.exe"Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound""
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Nibmmessagesibmmessages.exe"""The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
UIbmpmsvcibmpmsvc.exe"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn
UIBMUltraBayHotSwapCPLLoaderIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
?IBMUltraBayHotSwapSoundIBMBAYSN.EXE"Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
XIbsibs.exe"Added by the HIDEDIAL-B TROJAN!"
UIBWin Background processIBackground.exe"IBackup for Windows"
XicasServicasServ.exe"Browser hijacker
Xicccomp[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
NICH Syntheusexe.exe"Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
XICManagementmsic32.exe"Added by the MSIC BACKDOOR!"
UICONDESKICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
XiConfigLoaderDIIhost.exe"Added by the GAOBOT.AO WORM!"
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
XICQICQNET.vbs"Added by the GORMLEZ-A WORM!"
XICQ Chat Serviceicqjdhs.exe"Added by a variant of the RBOT WORM!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
XICQ Lite MessengerICQLITE.EXE"Added by an unidentified VIRUS
XICQ Messenger 2002ICQ2002.exe"Added by the SDBOT-ABL WORM!"
NICQ Plusvplus.exe"ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
XICQMsn[path to trojan]"Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Visualplscx.exe"Added by the RBOT-AYO WORM!"
Xicrosoft Visual InterDevczvslmqb.exe"Added by the RBOT-AYP WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
UICSDCLT"rundll32.exe Icsdclt.dll ICSClient"
NICServerIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
YICSMGRICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
XICU-SuckerService32.exe"Added by the ILLNOTIFIER.D TROJAN!"
NIC_KEY_3spvic.exe"Instant Chess related"
UiDesktopidesktop.exe"Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse"
Xidlesam[8 random letters].exe"Added by the ZHELATIN.EQ WORM!"
Xidmlssp[random filename]"Added by a variant of the SLAPER TROJAN!"
UIDriveE StartupIDrvieEStartup.exe"IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
XIDTemplatesIDTemplate.exe"Added by the BRONTOK-H WORM!"
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIE-Securityiescan.exe"IE-Security rogue spyware remover - not recommended
XIE-Securitywdscan.exe"IE-Security rogue spyware remover - not recommended
XIE6wkstmg.exe"Added by a variant of the SDBOT WORM!"
XIE6ssmss.exe"Added by the GAOBOT.DXO WORM!"
XIE6winsnt.exe"Added by the RBOT-GOV WORM!"
XIEACCESStemp532.exe"AsdPlug premium rate adult content dialer variant"
XIEACCESSsurfya.exe"
XIECheckMSDTCs.exe"Added by the TIRBOT-D WORM!"
XIECheckxpssl.exe"Added by the TIRBOT-E WORM!"
XIECheckmssvp.exe"Added by the TIRBOT-G WORM!"
XIEFeaturesIEFeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XIEFeaturesInternetfeatures.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XIehelpersyslaunch.exeOutwar adware downloader
XIesarIesar.exeBrowser hijacker - redirecting to an adult web page
XIesearch.exeIesearch.exe"LookNSearch adware"
UIEServerIEServer.exe"HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself"
XIEService.exeIEService.exe"FastFind adware variant"
XIESetIExplorer.dll"Added by the PWS-BLUEDIT TROJAN!"
Xiesetupi.exeiesetupi.exe"Added by a variant of the RBOT WORM!"
YIEShowIEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
Xiestartiexp1orer.exe"Added by the NEMOG.C TROJAN!"
Nietsrietsr.exe"IEClean by Kevin McAleavy - cookie manager
Xieupdatesieupdates.exe"Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
XiExpresseriexpresser.exe"Added by the SLENFBOT.AP WORM!"
UIFSplash.exeIFSplash.exeI-FORCE driver for force feedback steering wheel
UIFXSPMGTifxspmgt.exe"Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer
Uigfxpersigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
Xigfxtrassvchots.exe"Added by the AUTORUN-AIW WORM!"
Xigsex2xigsex2x.exe"NewDial premium rate adult content dialler"
XIISADMINSsystems.exe"Added by the AGOBOT.U WORM!"
Xiisversiisvers.exeAdded by an unidentified TROJAN or adware
NiIWiperSystemwiper.exe"System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
YIJ75P2PSERVERIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
UIJNetworkScanUtilityCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
YIKE Service 95IKEService.exe"Associated with PGP. The PGP Tray can be disabled
UiKeyWorksIKEYMAIN.EXE"A4Tech wireless keyboard driver and utility"
Xilassslsass.exe"Added by the INJECT-GZ TROJAN! Note - the legitimate lsass.exe process should not normally figure in Msconfig/Startup!"
NiLikeilikesidebar.exe"iLike Sidebar for iTunes and Windows Media Player"
XilortgdgkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
NiM Start CenteriM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
YImage & RestoreIMAGE32.exe"Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased
XImage Remote Playerssysvn.exe"Added by a variant of the IRCBOT BACKDOOR!"
NImage TransferSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
XImagePathtaskbarmngr.exe"Added by the SDBOT-XB WORM!"
XIMClassSvhosl.exeAdded by an unidentified WORM or TROJAN!
Ximcsslxmliwvug.exe"Added by the SLAPER.U TROJAN!"
NImesh??"Imesh is a file sharing system"
NImesh Auto Update??"Update check for the Imesh file sharing system. Turn the update off under ""options"""
NImgStartImgStart.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
NImgTaskImgtask.exe"Related to the WalletPix digital photo album. ""On some computers
XIMJPMIG8.2msime82.exe"Added by the VB-CYG WORM!"
XIMJPMIG8.2msime80.exe"Added by the VB-CYJ TROJAN!"
XImMsntimed.exe"Added by the WEBDOR.AK TROJAN!"
XIMprocessIM-svr.EXE"IMNames adware"
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UIMStartIMStart.exe"InterMute security software related"
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
NInControl Desktop ManagerDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
XIndex Servicedllhost32.exe"Added by the AGOBOT.CH WORM!"
UIndex WasherWashIdx.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
NIndexSearchIndexSearch.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XINETinetsync.exe"Meplex adware"
XInet DataBaseInetdbs.exe"Added by the QEDS WORM!"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
XInetMSNmsnet.exe"Added by a variant of the SDBOT TROJAN!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
Xinfamous.exewmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
XInfeStopInfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
Xinfosmss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
UInfo Selectis.exe"Info Select from Micro Logic - personal information manager"
UInfoPenMSNInfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
Xinfusinfus.exeAdult content dialler
XInitial Pageinstall.exeEasySearch browser hijack installer
Xinixsminix32.exe"Added by the AGENT.CKQX TROJAN!"
Xinjobinjobs.exe"Added by the BINJO TROJAN!"
XInomsnmoo.exe"Added by the RBOT-DPM WORM!"
UInoTaskInoTask.exe"Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
?insCOA5insCOA5.exe"??"
XInsiderInsider.exe"Added by the AGENT.KMC TROJAN!"
UInstaAlertInstaAlert.exe"""Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
XInstafinderinstafinder.exe"TopSearch.D adware"
XInstaFinderKInstaFinderK inst.exe"InstaFinder adware"
XInstallInstall.exe"Added by the BANCBAN-HG TROJAN!"
XInstall part IIupdates.exe"Added by the RELFEERWORM!"
?Install Pending Filessifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
xinstall32install32.exe"Added by the NUCLEAR.DG BACKDOOR!"
NInstallAurealDemosInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
UInstallBuddyIbtna.exe"InstallBuddy - automatically translates and installs your desktop documents
XInstallCleanerInstallCleaner.exe"Added by the ANYHOMB.F TROJAN!"
XInstalled shell32.dllOffice.exe..."Added by the LOVGATE.AO WORM!"
XInstalled shell32.dllOffice.exe"Added by the LOVGATE.E WORM!"
XInstallerdial.exe"Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
?InstallNAIProductSETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
XInstallProgram[path to trojan]"Added by the AGENT-HHU TROJAN!"
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstalls SP2[path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
XInstalls SP4[path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
UInstallstubinstallstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
XInstant Access"rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
XInstant Accessmwsrvacc.exe"InstantAccess premium rate adult content dialer"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XInstant Buzz DaemonIBDaemon.exe"Instant Buzz adware"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
Xinstant messengersinstantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
NInstant Update Centerreminder.exe"Event reminder for calendar dates
UInstant Wireless Configuration UtilityWUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
UInstant Wireless Configuration UtilityWPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
NInstantAccessINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInstantPleasureXXXinstantpleasurexxx.exeAdult content dialler
NInstantTrayPCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
Xinstitinstit.bat"Added by the OPASERV.H WORM!"
XinstitINSTIT.BAT"Added by the OPASERV.K WORM!"
?InstUtlR.exeInstUtlR.exe"??"
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
XIntel Drivercsrs.exe"Added by a variant of the SDBOT WORM!"
UIntel File Transferxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
UIntel PDSpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
XIntel Physical Routine 1.2Astnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
NIntel PROSet Tray Iconpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XIntel system toolhookdump.exe"Added by the SPYRE-H TROJAN!"
XIntel system toolwinnook.exe"Added by the SPYRE-C TROJAN!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
XIntel system worksiis.exe"Added by the RBOT.QGA WORM!"
UIntel(R) Common User Interfaceigfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfacehkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
UIntel(R) Common User Interfaceigfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
NIntelAudioStudioIntelAudioStudio.exe"""Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience"". Audio utility supplied with some Intel motherboards"
XInteliSyssmss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XIntelprcAas3lovu.exe"Added by the SILLYFDC-CG WORM!"
YIntelWirelessifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInterceptedSystem[path to worm]"Added by the ANACON-B WORM!"
XInternalregedit.exe /s c[month number]"Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir%
XInternal Memory Filesysintmemory.exe"Added by the RBOT-GKT WORM!"
XInternalSystrayKazza.exe"Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable
XInternatsystray.exe"Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
XInternatmsgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
XinternctWinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
Xinternetsmss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
XInternetnteusodp.exe"Added by the RBOT-GFJ WORM!"
Xinternetwinsas32.exe"Added by a variant of the SDBOT WORM!"
Xinternetlsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
XInternetalm7tas.exe"Added by a variant of the RBOT WORM!"
XInternetwins.exe"Added by the RBOT.AAYF WORM!"
UInternet Answering MachineIAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
UInternet Answering MachineIAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
XInternet AntivirusIAvir.exe"Internet Antivirus rogue security software - not recommended
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Connection Wizardstisvsq.exe"EasySearch adware"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Content PublisherICP.EXE"Added by the RBOT-UD WORM!"
UInternet Disk CleanerCLEARH~1.EXE"""Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Firewall Layertsqla.exe"Added by a variant of the SPYBOT WORM!"
UInternet History EraserHERASER.exe"Internet History Eraser - deletes your browsing tracks"
XInternet Loader1MSInstall61.exe"Added by the KWBOT.B WORM!"
XInternet Mail and Newsmsqdevl.exe"EasySearch adware"
XInternet Mail and News[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Security 2010IS2010.exe"Internet Security 2010 rogue security software - not recommended
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet SendMore log.exeUnidentfied adware
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
YInternet Sharing Serveriss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
XInternet Suspentionstory.exe"Added by the WOOTBOT.HV WORM!"
NInternet SweeperSweeper.exe"Internet Sweeper - removes unnecessart left over files after browsing the internet"
XInternet Washer Proiw.exe"Internet Washer manages temporary browser files
Xinternet.exeyinyin3345.vbs"Added by the YINI MACRO!"
NInternetCallsInternetCalls.exe"InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetGetConnectedStatewinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetGetConnectedStateExwinupdate.exe"Added by the SDBOT-JN WORM!"
XInternetShieldINTERN~1.EXE"InternetShield rogue security software - not recommended
XInternetShieldInternetShield.exe"InternetShield rogue security software - not recommended
UInternetSpyInternetSpy.exe"Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
XInternetWasherProiw.exe"Internet Washer manages temporary browser files
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
UInternodeUsagemum.exeAustralian ISP's free monthly download meter
XInters Configuration LoaderRCL0ADERS.exe"Added by the SDBOT-KX WORM!"
XIntersoft Msngrintersoftmsngr.exe"Added by the AGOBOT-NW WORM!"
NInterTrust Quick Startit_cpq~1.exe"InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XintranetSYS32CFG.EXE"Added by the SPYBOT-DW WORM!"
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
NIntroducing Media ManagerSPLASHA.EXE"MS Media Manager tour. Not required"
NIntroduction-Registration??"For Compaq PC's. Should only run first time
XIntSys1[path to trojan]"Added by the BANLOA-ASE TROJAN!"
YIntuit SyncManagerIntuitSyncManager.exe"Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync
UInventory ScanLDISCN32.EXE"LANDesk® Management Suite software component"
Yiolo AntiVirusioloAV.exe"iolo AntiVirus"
Yiolo Personal FirewallioloFW.exe"iolo Personal Firewall"
UIolo Task AgentTask_Agent.exe"Iolo System Mechanic Task Agent. Scheduled maintenance"
Niolo Utility BarSMUtilityBar.exe"Iolo System Mechanic Utility Bar - can be launched manually"
NIomega Backup Schedulerdtiom98.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
UIomega Disk IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
?Iomega QuickSyncQuicksync.exe"??"
NIomega Startup OptionsIMGSTART.EXE"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
Xioroxxo microsoft suxsystem32.exe"Added by a variant of the RBOT WORM!"
XIP Packet Redirect Serviceipredirect.exe"Added by the FORBOT.SM WORM!"
XIP Stackipstack.exe"Added by the AGOBOT.CW WORM!"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
XIPC Spool Managerwinspec.exe"Added by the SDBOT-BLU WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIPConfigipconfigs.exe"Added by the HACARMY.C BACKDOOR!"
?IPHSendIPHSend.exe"AOL related. What does it do and is it required?"
NIPInSightLAN 01IPClient.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
NIPInSightMonitor 01IPMon32.exe"IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth
YIPinstN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
XIPLog Securityiplogsec.exe"Added by the IRCBOT.GP BACKDOOR!"
?iPlusAgent2iAgent2.exe"Related to iriver portable media products. What does it do and is it required?"
XIpnukerIpnuker.vbs"Added by the INKER.B WORM!"
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
XiPOD USB DriverIPODUSB.EXE"Added by a variant of the RBOT WORM!"
XiPod USB ServiceiPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
XIPSEC Configurationwsupdate.exe"Added by the AGOBOT-IQ WORM!"
XiPSec7ipsec7.exe"Added by the AGENT.AHVR TROJAN!"
UipsecdialerIPSECD~1.EXE"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"