Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X1lsass.scr"Added by the BANCOS.V TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
U1455 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX1455 multifunction printer
U2335dn Scan2PCScan2pc.exeScan to PC application for the scanning function of the Dell 2335 multifunction laser printer
U3170 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX3170 multifunction laser printer
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X3D Text3D Text.scr"Added by the JERMY.A WORM!"
U4x26 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers
U4x28 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers
U6200 Scan2PCScan2pc.exeScan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
?ab EazySchedulerezsched.exe"??"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad
XAdwareKiller_schedulesschedules.exe"EAdwareKiller rogue spyware remover - not recommended
YAirPlusCFGAirPlusCFG.exe"Driver and configuration utility for a number of wireless routers and adapters from D-Link"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
XAll Sea screen saverTaskTray.exe"Free screensaver
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntivirusschermpgs.exe"Antivirusscherm
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XASC-AntiSpywareWinCleaner.exe"WinCleaner 2009 rogue security software - not recommended
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
Xasc32asc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XasccacAasacsqgl.exe"Added by the MULTIDRP.AA TROJAN!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAuto Scroll LoaderASCRLL.EXE"Added by the SPYBOT-T WORM!"
XAuto Updaterasclt.exe"Added by the SLINBOT.CJ BACKDOOR!"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
XAutoloaderaproposclientApropos_Client_Loader.exe"AproposMedia adware"
XAutoloaderaproposclientcxtpls_loader.exe"AproposMedia adware"
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
UAwaySchAwaySch.EXE"Part of the IBM ThinkVantage Productivity Center. ""The Away Manager application allows you preselect and run routine tasks to maintain your system's performance"""
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
NB'sCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
UBackup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
UBackupExecSchedulerbesch.exe"Veritas ""Back Up My PC"" software"
NbascstrayBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
UBattery Scopebatmgr.exeMonitors battery levels on a notebook/laptop PC
XBatzBackBatzBack.scr"Added by the BACKZAT WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
UBelkin F5D8073 N Wireless ExpressCard Adapter UtilityBelkinwcui.exe"Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter"
XBeschermingsToolSysRep.exe"BeschermingsTool
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
XBlockScannerBlockScanner.exe"BlockScanner rogue security software - not recommended. A member of the WiniGuard family"
Xbobycsrs.scr"Added by the BANCBAN-PC TROJAN!"
Xbobynetburn.scr"Added by the BANCBAN-OX TROJAN!"
Xboby.Isass.scr"Added by the BANCBAN-OH TROJAN!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XBrowserUpdateSched[random filename]"ZenoSearch adware"
NBsCLiPBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
XBymer.ScannerWininit.exe"Added by the BYMER WORM!"
XBymer.ScannerMsinit.exe"Added by the BYMER WORM!"
UCalendarscopecs.exe"Calendarscope calendar software"
?CardScan AutoSyncCSyncCfg.exe"Related to the CardScan business card reader range of products. May be related to synchronization with E-mail software and mobile devices (see here)?"
XCAS Clientcasclient.exe"CasinoClient adware"
XCashToolbarMSCStat.exe"Added by the DOWNLOADER-MY TROJAN!"
XCFDStartWinMuschi.exe"WINMUSCHI dialler"
XCGI Firewall ScriptCGIAGENT.EXE"Added by the BROPIA-U WORM!"
XCheckdiskmscas.exe"Added by the VAGON-A TROJAN!"
XCheckScan32regload16.exe"Added by the AEBOT.K WORM!"
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
XCisco Systems[path to worm]"Added by the AUTORUN.UHR WORM!"
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
XClient for Microsoft Networksmsclient32.exe"Added by the SDBOT-BXQ WORM!"
XClientMan1mscman.exe"ClientMan parasite variant"
NClik Status Monitortoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
XClrSchLoader[path to file]"ClearSearch adware"
Xcmrstcmrst.scr"Added by the DLOADER-FP TROJAN!"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
NCompaq Computer Corp SCCenter ModuleSCCENTER.EXEFor Compaq PC's. Part of Backweb
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
NCompaqSystraycpqpscp.exeCompaq System Tray icon
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration Loadersyscfg32.exe"Added by the SDBOT.B BACKDOOR!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfigurations Ascltasclt.exe"Added by the SDBOT-MX WORM!"
XConfLoadersysconf16.exe"Added by the SDBOT-FB TROJAN!"
NCONNECTAuto UpdateCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
NCONNECTSchedulerCONNECTScheduler.exe"Automatic update scheduler for the Sony CONNECT Player originally supplied with their range of USB or hard disk based MP3 players and used in conjunction with the CONNECT Music store download service - now replaced by SonicStage CP"
Xconscorrconscorr.exe"VX2.Transponder parasite updater/installer related"
XCore System Hardwaresyscorehd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XCPCmscl0ckCPCmsclock.ExE"Added by the IRCFLOOD.BF TROJAN!"
?CQSCP2PSCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XcronosMARCO!.SCR"Added by the OPASERV.G WORM!"
XCStsc.exe"Cyber Security rogue security software - not recommended
Ucsccsc.exeCommand line compiler for Microsoft C# it gets installed with the .NET SDK
Xcscriptscscripts.exe"Added by the BDOOR-AAP BACKDOOR!"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
Xcsrsccsrsc.exe"Added by an unidentified VIRUS
YCSScheduleCheckSCHWIZEX.EXE"Part of ConfigSafe - lets you identify changes to the registry
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
?CTSchedCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
?Cwcdschk.exeCwcdschk.exe"IBM Thinkpad related?"
YD-Link AirPlus XtremeGAirPlusCFG.exe"D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
YD-Link D-Link Wireless 108G DWA-120AirPlusCFG.exeD-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
YD-Link D-Link Wireless 108G DWA-520AirPlusCFG.exeD-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
YD-Link RangeBooster G WDA-2320AirPlusCFG.exe"D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
YD-Link RangeBooster G WUA-2340AirPlusCFG.exe"D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
Xdarkimgst.scr"Added by the BANCOS.U TROJAN!"
Xdarkimgrt.scr"Added by the BANCBAN-FH TROJAN!"
Xdarkcsrs.scr"Added by the BANCBAN-GT or BANCBAN-GU TROJANS!"
UDell DataSafe SchedulerDataSafeOnlineScheduler.exe"Scheduler for Dell DataSafe™ Online which ""helps protect your music
NDellSCdellsc.exeDell Solution Center - web-based troubleshooting tools and educational offerings
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
?Description of Shortcuts*.exe"* seems to be a sequence of alphanumerics that can be different
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
NDisc DetectorCtNotify.exe"For Creative sound cards. Detects when you insert a CD
?disc detectorqnetquestnotifty.exe"??"
?discovegdiscoveg.exe"??"
?DISCoverDISCover.exe"Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
UDiscUpdateManagerDiscUpdMgr.exe"Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
NDiscUpdateManagerDiscUpdateMgr.exe"DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple
UDiscWizardMonitor.exeDiscWizardMonitor.exe"Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
XDistributed Link Trackingascvt.exe"Added by the AGOBOT-GH BACKDOOR!"
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
NDMASchedulerDMAScheduler.exe"Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
XDNSCacheBoostdnsping.exe"Added by the DNSBUST-A TROJAN!"
Xdnscleanerdnscleaner.exe"CoolWebSearch parasite variant"
NDrag-to-DiscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
XDRam prosessorplscd.exe"Added by the RBOT.CYA WORM!"
NDrgToDscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
YDrwebschedulerDrwebscd.exe"DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications
UDS Clockdsclock.exe"Digital desktop clock including synchronization with atomic servers - see here"
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
XDVAScvssdfaAsSDdwd.exe"Added by the LIOTEN.IP TROJAN!"
?EDFcsndiscfcsn.exe"Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
XehSchedehSched.exe"Added by the SDBOT-DHF WORM!"
UELBERTRicoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
UELBERT_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
UElectron MicroscopeEMIII.exe"Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home
YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
XERScwERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
UeScan UpdaterTrayicos.exe"MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
XEScorcherescorcher.exe"Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
XExeName32Warm.scr"Added by the SCOLD WORM!"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExploreUpdSched[random filename]"ZenoSearch adware"
XEYORENotepad.scr"Added by the GIMLET-A WORM!"
?fgl23DoubleScreenHooksf23happ.exe"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
UFRISK FP-SchedulerF-Sched.exe"Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
NFSCBossFSCBoss.exeFree Store Club shop online software
NFSScrCtlFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
UFtpqueueFtpsched.exe"Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
NGadwin PrintScreenPrintScreen.exe"Gadwin PrintScreen - utility to capture
Xgamepatcher.scr"Added by the PSW-ED TROJAN!"
XgcasServrealsched.exe"Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XGeneric Host ProcessSCHOST.EXE"Added by the RBOT-NC WORM!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
Xgescwgescw.exe"Part of BeschermingsTool
XGlobalSCAPE[random filename]"Added by the RBOT-AYM WORM!"
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
UGroupWise PDA Connect - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
?GscbcGscbc.exe"??"
Xgtydfiisca.exe"Added by the CLAGGER-BB TROJAN!"
Xgtydfiscca.exe"Added by the DWNLDR-GTK TROJAN!"
UH/PC Connection AgentWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
Xhdlpscom[8 random letters].exe"Added by the RBOT-FUL WORM!"
Xhelphelp.scr"Added by the BANCOS-BBU TROJAN!"
XHelpereschlp.exe"Added by the BLASTER.T WORM!"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
UHijackThis startup scanHijackThis.exe"""HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware
NHome Theater SchSvrSchSvr.exe"WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
UHotKeysCmdshkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
XHotKeysCmds[path to worm]"Added by the PAHATIA-A WORM!"
UHP Health Check ScheduleHPHC_Scheduler.exeHP Health Check Scheduler from Hewlett-Packard
?HP IDSchedulerHPIDSCHD.exe"HP Instant Delivery Scheduler"
NHP JetDiscoveryHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
NHP Precision Scanhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
UHP ScanPatchHPScanFix.exe"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used
NHP ScanPicturehpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
UHP SchedIndexerhppschedindexer.exe"Installed by HP multi-function printer driver software
NHP software updateHPWuSchd2.exeHP software updates. If a shortcut doesn't exist create your own and run it manually
NHP software updateHPWuSchd.exe"HP software updates. If a shortcut doesn't exist
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
Nhpfschedhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
?hpScannerFirstBootscannerfb.exe"HP scanner related"
Xhpsysconf1[random filename]"Added by a variant of the VIVIA.A TROJAN!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
Xicrosoft Visualplscx.exe"Added by the RBOT-AYO WORM!"
XIE-Securityiescan.exe"IE-Security rogue spyware remover - not recommended
XIE-Securitywdscan.exe"IE-Security rogue spyware remover - not recommended
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
UIJNetworkScanUtilityCNMNSUT.EXENetwork utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
UImScInstImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UImScInst.exeImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
?insCOA5insCOA5.exe"??"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XIntranetschost.exe"Added by the RBOT.SV BACKDOOR!"
UInventory ScanLDISCN32.EXE"LANDesk® Management Suite software component"
NIomega Backup Schedulerdtiom98.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
UIRIS_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
UIRIS_XRX_S2PScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
XIsassRenascimentoIssas.exe"Added by the BANKER.GAX TROJAN!"
Xiscchiscch.exe"Added by the LCPRANK-A WORM!"
Nisschissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NISUSSchedulerissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NiSysCleaneriSysCleaner.exe"iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user"
NJava(TM) Platform SE 6jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
NJava(TM) Platform SE 6 U*jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now. U* represents the update version
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
Xjava-pluginjavasctp.exe"Added by the VB.AMX TROJAN!"
XJavascriptjscript.exe"Added by the DELBOT-AD WORM!"
XJavaScript Debugging ServiceJsDbgMan.exe"Added by the DERDERO.E WORM!"
XJavaScriptMsxrsMsxrs.exe"Added by the VB.BL WORM!"
XJavaUpdateSchedjusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
YJetAdmin Discovery IndicatorHPJETDSC.EXE"HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
Njuschedjusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
Xjusched[path to trojan]"Added by the BANKER-BWR TROJAN!"
Xjuschedjusched.exe"Added by the BANKER-BOV TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
XKvsc3Kvsc3.exe"Added by the PWS-ANM TROJAN!"
ULANDeskInventoryClientLDIScn32.exe"LANDesk® Management Suite software component"
ULaplink PDASync 3.1 - ScheduleSyncScheduleSync.exe"Laplink PDASync for ScheduleSync - PDA synchronisation utility"
ULapLink schedulerLlsched.exeUtility that automatically performs file transfers as unattended background operations
ULidPolicypwrschem.exeA utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery
NLifeScape Media DetectorPicasaMediaDetector.exe"Media detector for Picasa's automatic photo organizer"
NLightscribeLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribe Control PanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
NLightScribeControlPanelLightScribeControlPanel.exe"System Tray access to the LightScribe Control Panel for CD/DVD writers based upon HP's LightScribe laser-etching process - which allows you to burn a label straight onto specially coated blank disks. Part of the main LightScribe System Software (LSS)"
Xloadctftpscr32.exe"Added by the AGENT-FPN TROJAN!"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
?load=WINOSCFG.EXE"Could it be something to do with configuring Windows on a new PC from an OEM supplier?"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
ULogan_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4500 Series multifunction printer
XLogin Screen Saverlogin.scr"Added by the RBOT-AVN WORM!"
YLogoffSCTUINotify.exe"Part of Windows SteadyState
XLTM2winscan.exe"Added by the LITMUS-B TROJAN!"
YLXBSCATS"rundll32 [path] LXBStime.dll _RunDLLEntry@16"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
UMagicDiscMagicDisc.exe"MagicISO - ""very helpful utility designed for creating and managing virtual CD drives and CD/DVD discs"""
YMailScan DispatcherLaunch.exe"MicroWorld MailScan Dispatcher splits each e-mail message into various components such as the header
XMalware ScannerMalScr.exe"Malware Scanner rogue security software - not recommended
UMaple_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung CLX-216x Series multifunction printers
XMascro soft SDK updates2SDKrepair2.exe"Added by the SDBOT.BXM WORM!"
UMatrix Screen Lockermatrix.exe"Matrix Screen Locker is a system tray application that allows for quick and secure PC lock when you wish. The screen does a ""matrix style"" scrolling characters effect when the lock is running"
XMatrixScreen[filename]"Added by the MATRIXSCREEN TROJAN!"
XMatrixScreenSavermss.exeUnidentified malware
UMaxBackSchedulemaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
XMcafee Anti ScanNortonScn.exe"Added by a variant of the RBOT WORM!"
XMcAfee Online virus Scanneravp.exe"Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XMcAfee Online Virus Scannernzm.exe"Added by the IRCBOT.XV WORM!"
YMcAfee VirusScanmcmnhdlr.exe"Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically
YMcAfee VirusScanmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
YMcAfee VirusScanoasclnt.exe"On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access
XMcafee VirusScan Managermvcsvm.exe"Added by the SILLYFDC.BBV TROJAN!"
XMcAfeeScanPlusMcAfeeScanPlus.exe"Added by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder"
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
YMcAfeeWebscanXWebScanX.exe"From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs
XMcaffe AntivirusMcafeescn.exe"Added by a variant of the SPYBOT WORM!"
XMCX Updtescorti.exe"Added by the RBOT-ARP WORM!"
XMedia Software UPdatersscs.exe"Added by the RBOT-ABE WORM!"
Xmediapluscash.exemediapluscash.exe"MediaGateway adware"
XMemScannerMemScanner.exe"Part of Enigma SpyHunter - not recommended
YMessengerSCANMSG.EXE"AntiVirus Quick Heal - virus protection"
UMessengerDiscoveryMessengerDiscovery.exe"MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features. Now superseded by MessengerDiscovery Live - with support added for Windows Live"
UMFP1815_S2PScan2pc.exeScan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
UMGSysCtrlMGSysCtrlPart of the System Control Manager for MSI notebooks - displays animations for hot key commands (such as turning the wirelss card on/off)
XMi7sft sdcescorti.exe"Added by the RBOT.ELC WORM!"
XMicosoft Startupsyscall.exe"Added by the SDBOT-JI WORM!"
XMicro CRC Protocolscrc32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoftrtvcscan.exe"Added by the RBOT-GGU WORM!"
XMicrosoftschost.exe"Added by the RBOT.FEH BACKDOOR!"
UMicrosoft ActiveSyncWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XMicrosoft Clientmsclient.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Conf Ldrsysconf.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft Configmsconf.exe"Added by the RBOT.PV WORM!"
XMicrosoft ConfigMSCONF.EXE"Added by the RBOT-LG WORM!"
XMicrosoft Config 32msconfigx32.exeReported as the MSCONFIGX32 TROJAN! Possible Rbot variant
XMicrosoft Config 32bitmscnfg32.exe"Added by the RBOT-Z WORM!"
XMicrosoft Config Loadermsconfig32.exe"Added by the AGOBOT.XX WORM!"
XMicrosoft Config Loadermsconf32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Configuewemsconfiguwe.exe"Added by the SDBOT-BPK WORM!"
XMicrosoft Configurationmsconfig32.exe"Added by the SDBOT.MQ WORM!"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Digital Clockmsclock.exe"Added by the NACKBOT-D WORM!"
XMicrosoft DirectXPDSched.exe"Added by the SDBOT.CN WORM!"
XMicrosoft Disk Scannerscansdisk.exe"Added by the WOOTBOT.DT WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft machinearcpack.scr.exe"Added by the RBOT.ADF BACKDOOR!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft MediaScopewinmes.exe"Added by the RBOT-XU WORM!"
XMicrosoft Office Studioscvhvst.exe"Added by the RANDEX.CST WORM!"
XMicrosoft RDLLsysconf32.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosoft Restorescrgrd.exe"Added by the SPYBOT.BR WORM!"
XMicrosoft Scanregmicrosoftscanreg.exe"Added by the FRANRIV.A WORM!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft Synchronization Managernetscape.exe"Added by the RANDEX.AE WORM!"
XMicrosoft Synchronization Managerscreen.exe"Added by the SDBOT-ACO WORM!"
NMicrosoft System Configuration Utilitymsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updateascdl.exe"Added by the GAOBOT.SY WORM!"
XMicrosoft Updatemsconfg.exe"Added by the RBOT.H WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Update 32mscnfg.exe"Added by the RBOT-ALM WORM!"
XMicrosoft Update 64 BITschvost.exe"Added by the RBOT.CAU WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Update Managerscvideo.exe"Added by the SDBOT-CVP TROJAN!"
XMicrosoft Updatermsconsole.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Updaterssysconfigs.exe"Added by the RBOT-DF TROJAN!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicrosoft Visual Studioplscdksxg.exe"Added by the RBOT-AWV WORM!"
XMicrosoft Windows Client Firewallmsclt.exe"Added by the VANEBOT-F WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updatescrhost.exe"Added by the RBOT-AOW WORM!"
XMicrosoft Winsockmswinsck.exe"Added by the RBOT-ANK WORM!"
YMicrosoftAntiSpywareCleanergcASCleaner.exe"Microsoft Antipsyware - now superseded by Microsoft's Windows Defender"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
XMicrosofts MediaScopewinmep.exe"Added by the RBOT-WB WORM!"
XMicrosofts MediaScopewinmedplay.exe"Added by a variant of the RBOT WORM!"
XMicrosoftValuesyscnfg.exe"Added by an unidentified VIRUS
UMicrosoft® Windows® Operating SystemWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
UMicrotek Scanner FinderScannerFinder.exeMonitors whether a scanner is present. Provided with Microtek scanners
XMircosoft Sockets SP2mssck.exe"Added by the MYTOB.ET WORM!"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XModularConfigsyscnfg.exe"Added by an unidentified VIRUS
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
NMozilla Quick LaunchNetscp6.exeNetscape 6 and Mozilla browsers
UMPSExemscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
Xmqadscp3mqadscp3.exe"Added by the STRATION.CX WORM!"
UMRU-Blaster Schedulerscheduler.exe"Scheduler for MRU-Blaster - ""a program made to do one large task - detect and clean MRU (most recently used) lists on your computer"""
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMs configsumsconfigsu.exe"Added by a variant of the SDBOT WORM!"
XMS Configuration Utilitymsconfig32.exe"Added by the WOOTBOT.DY WORM!"
XMS Microsoft Socket DeamonMSSCKD32.exe"Added by a variant of the RBOT WORM!"
XMS Screen Saverscrsave.scr"Added by the RBOT-AGT WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMS System Call Functionmsscf32.exe"Added by the RBOT-GBZ WORM!"
XMs System ConfigMscfg.exe"Added by the SDBOT-CCR WORM!"
XMS Updatesmscache.exeSpyware web downloader
XMS Windows Updatescguard.exe"Added by the RBOT-YZ WORM!"
XMS-patchmsconfig32.exe"Added by the RBOT-AUF WORM!"
YMSASCuiMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
Xmsavsc.exemsavsc.exe"Added by the AGENT.ANQ TROJAN!"
Xmsbsc[path to trojan]"Added by the BANKER-DF TROJAN!"
Xmscmsc.exe"MaCatte Antivirus 2009 rogue security software - not recommended
Xmsccrtmsccrt.exe"Added by the PWS-ALA TROJAN!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
Xmschkdf.exemschkdf.exe"Added by a variant of the SDBOT WORM!"
XMSChoExEsuge.exe"Added by a variant of the RBOT WORM!"
?mscimcinfo.exe"McAfee Internet Security related. What does it do and is it required?"
Xmsclacmsclac.exe"Added by the SDBOT-JM WORM!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmscmanmscman.exe"ClientMan parasite variant"
Xmscmsmscms.exe"Added by the AGENT-MS TROJAN!"
Umscnmscn.exePart of the SafeChildNet internet filtering program - required if you use it
XMscntmscnt.exe"Added by the DLUCA-C TROJAN!"
XMscolourmscolour.exe"Added by the GEMA TROJAN!"
XMSCommXmscommx.exe"Added by a variant of the RBOT WORM!"
XMsconf32Msconf32.exe"Added by the AGOBOT-NR WORM!"
XMSCONFG32.EXEMSCONFG32.EXE"Added by the OPTIX.04.C TROJAN!"
NMSConfigmsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
XMSConfigMSCONFIG32.EXE"Added by the SPYBOT.B WORM!"
Xmsconfigmsconfig.exe"CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsconfigmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xmsconfigwins.exe"Added by the RBOT.PF WORM!"
XMSConfigMSCONFIG35.EXE"Added by a variant of the SPYBOT WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
Xmsconfigwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfigmsconfig.com"Added by the IRCBOT-SM WORM!"
Xmsconfigmsconfig.bat"Added by the PAHATIA.B WORM!"
XMSConfiglssas.exe"Added by the AUTORUN.CEY WORM!"
XMSConfigxwpwqf.exe"Added by the AGENT-NEW TROJAN!"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMSConfig Managermsupdate.exe"CoolWebSearch parasite variant"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig.msconf.exe"Added by the BUZUS-AY WORM!"
Xmsconfig.exeproxy.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig.exeuline.exeAdded by a variant of the AGENT.AH downloader TROJAN!
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfig45MSConfig45.exe"Added by the SDBOT.OJ TROJAN!"
XMSConfigrjdbgmrg.exe"Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
NMSConfigRemindermsconfig.exeEntry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
XMsConfigsMsConfigs.exe"Added by the ALCAN.A WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmsconfiguratorctfsdk.exe"Added by the DELF-ALS TROJAN!"
XMSControl28crsss.exe"Added by the SPYBOT.AJX WORM!"
XMSControl31winnsyst.exe"Added by the RBOT.CFY WORM!"
XMSControl3d1isasse.exe"Added by the RBOT.CGU WORM!"
XMSCOREsyscnfg.exe"Added by an unidentified VIRUS
?MSCRMStartupMicrosoft.Crm.Application.Hoster.exe"Related to Microsoft Dynamics CRM integrated solutions for Financial
XMscsgsMSCSGS.EXE"Added by the ZEZER WORM!"
XMscsgs32MSCSGS32.EXE"Added by the ZEZER WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
Xmsctfg32msctfg32.exe"Added by the RBOT-TJ WORM!"
Xmsctrl.exemsctrl.exe"Microsoft Security Adviser rogue security software - not recommended"
XMsctrl32Msctrl32.scr"Added by the REDIST WORM!"
XMSCVTMSCVT.exe"Added by the SLIDESHOW WORM!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMSDLLsyscnfg.exe"Added by an unidentified VIRUS
Xmsmmsm.scr"Added by the BANKER-EHJ TROJAN!"
Xmsmcmscpbo.exe"ClientMan parasite variant"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSNmsscomd.exe"Added by a variant of the SPYBOT WORM! See here"
XMSN Managermscmgr.exeUnidentified malware - causes multiple browser windows to open
XMSN Updatemscon.exe"Added by the RBOT-QA WORM!"
Xmsnmsg.exemscmd32.exeAdded by a variant of the AGENT.AH TROJAN!
Xmsnsched2msnsched2.exe"Added by the SPYBOT.NNT WORM!"
Xmsnscr.exemsnscr.exe"Added by the CERTIF-P TROJAN!"
XmsnToolbaarmsnmsgesc.exe"Added by the RBOT.BMF WORM!"
UMSPY2002ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
UMSRegScanSGP.exe"SpyGator surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSSDemo.exe"SupremeSpy surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanETNKL.exe"ComKeylogger surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanKSPDemo.exe"KeyStalker PRO surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanDDSSDemo.exe"SystemSleuth surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESP+.exe"ESP surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanESPDemo.exe"Eye Spy Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanSBPDemo.exe"SpyBoss Pro surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYEKPND.exe"EyeCandy Computer Monitor surveillance software. Uninstall this software unless you put it there yourself"
UMSRegScanYKPND.exe"YKPMD surveillance software. Uninstall this software unless you put it there yourself"
Xmsscan.exemsscan.exe"Microsoft Security Adviser rogue security software - not recommended"
UMSSCDLMSSCDLL.exe"SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
Xmssoulmsmscc2.exe"Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
Xmssoulmsmscc.exe"Added by the BANCOS.HKT TROJAN!"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
Xmstsdsc.exemstsdsc.exe"Added by the CIMUZ-CD TROJAN!"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
Xmsvsc32msdev.exe"Added by the RBOT-GJ WORM!"
XMSWindows SysClmscl32.exe"Added by the RBOT.AHI WORM!"
UMVRescuemvrescueRelated to Multivision Computers back up/restore program. Multivision Computers ceased operating in 2004
Umwavscanmwavscan.com"MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system
XMy Web Search Bar Search Scope Monitorm3SrchMn.exe"MyWebSearch parasite"
XMyDailyHoroscopeMYDAIL~1.EXE"MyDailyHoroscope foistware"
XMyDailyHoroscopeMyDailyHoroscope.exe"MyDailyHoroscope foistware"
XMySLScanmsvc32.exe"Added by the FORBOT-EH WORM!"
XNatalNatal.scr"Added by the OPASERV.AE WORM!"
XNAV Scan ServiceNAVSCAN32.EXE"Added by the SDBOT.VG WORM!"
XNavAgent32SCardSvr32.Exe"Added by the MOFEI.B WORM!"
UNaviscopenaviscope.exe"Naviscope is a multipurpose browser enhancement that can speed up Web searches
XNavScan[filename]"Added by the OBSORB TROJAN!"
XNAVSCAN32.EXENAVSCAN32.exe"Added by the SDBOT-DO WORM!"
XNAVSCANNER32NAVSCANNER32.EXE"Added by the RBOT.QC WORM!"
UNBKeyScanNBKeyScan.exe"This tool comes with a special version of Nero BackItUp for some external harddisks. Controls two buttons on the drive - one button power off the drive and the other directly calls Nero BackItUp to make a quick backup"
XNet Command Senternvscvse.exe"Added by the IRCBOT!DF6280E5 VIRUS!"
UNetscapeInstallService.exeRelated to Netscape installation
NNetscape MessengerNETSCAPE.EXE"In Netscape 6 (I know for sure with 6.2.1
NNetscp6Netscp6.exeNetscape 6
UNetScreen-RemoteSafeCfg.exe"NetScreen Remote VPN client software"
XNeuerSchildpgs.exe"NeuerSchild
XNI.USYPSysProtectScannerInstall.exe"Installer for the SysProtect rogue security software
XNI.UWFX5WinFixer2005ScannerInstall.exe"WinFixer 2005 web installer - ""foistware""
YNOD32POP3Pop3scan.exe"POP3 E-mail part of Eset's NOD32 virus-scanner"
XNorton Antiviral Scannernavscnr.exe"Added by the DELBOT-K WORM!"
UNorton Program Schedulernsched32.exe"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95
UNorton Program SchedulerNPSsvc.exe"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95
?Norton Program Scheduler Event Checkernpscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker"
XNorton Systemcsrs.scr"Added by the BANLOA-AFM TROJAN!"
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
UNovastorSchedulerdSCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
?NPS Event Checkernpscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker"
XNSCheckNSCHECK.EXE"MarketScore parasite - ActiveX control used to download premium-rate dialers"
Xnscntrlnscntrl.exe"Added by the DLOAD-DC TROJAN!"
Xnssysconf[random filename]"Added by the VIVIA.A TROJAN!"
XNT Printing Servicespoolsc.exe"Added by the BUZUS-K WORM!"
YNTFSCLUPNTFSCLUP.EXE"Part of ConfigSafe- ""checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting"""
UNTI Backup NOW! SchedulerSchdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
Xntvdscmntvdscm.exe"Added by the SCKEYLOG-I TROJAN!"
XNvCplScanmsc32.exe"Added by the FORBOT-DD WORM!"
XNvCplScanwinasp.exe"Added by the FORBOT.BZ WORM!"
XNvCplScannvsc32.exe"Added by the BROPIA.N WORM!"
XNvCplScankav32.exe"Added by the FORBOT-EW WORM!"
XNvCplScannetstat32.exe"Added by the SDBOT.BRL WORM!"
XNvCplScandllmanager.exe"Added by the FORBOT.R WORM!"
XNVSystem32nvscv32.exe"Added by the AGOBOT-NO WORM!"
YOASClntoasclnt.exe"On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access
XODSYSCNTR.EXEHotVideo dialler
YOfficeScan95pccwin97.exe"Trend Micro antivirus OfficeScan"
YOfficeScanNT Monitorpccntmon.exe"Trend Micro OfficeScan Antivirus real-time scan monitor"
UOmniPassscureapp.exe"OmniPass from Softex Inc. - secure password management software"
UOn Screen DisplayOSD.EXE"By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume
UOn screen displayTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
NOneNote 2007 Screen Clipper and LauncherONENOTEM.EXE"System Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes
Xonly23SCVHOST.exe"Added by the BCKDR-PUQ BACKDOOR!"
XOpenApizszrscbm.exe"Added by the AGENT.RLH TROJAN!"
UOpSchedulerOpScheduler.exe"Part of Nuance (was Scansoft) OmniPage Pro document conversion software"
NOptusNet Desktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
UosCheckosCheck.exe"Part of Norton Antivirus. Initiates a quick scan (at startup) of the portions of the OS Symantec currently (as defined by the most recent updates downloaded onto the host computer) thinks are most susceptible to infection. This scan is not necessary for proper operation of Norton Antivirus"
UP3000x_S2PScanToPc.exeDell Laser MFP 1600N network application for scanning files to the PC
UPagis Schedule MonitorMonitor.exeScheduler for the Pagis scanning suite from Scansoft (now Nuance)
NPagis SchedulerMonitor.exeScheduler for the Pagis scanning suite from Scansoft (now Nuance)
UPanasonic Communications UtilityMfpscdl.exe"Port manager for Panasonic Panafax fax_machines"
UPanda Schedulerpavsched.exe"Scheduler for older versions of Panda Antivirus. Required if you have scans scheduled on a regular basis"
UPandaSchedulerpavsched.exe"Scheduler for older versions of Panda Antivirus. Required if you have scans scheduled on a regular basis"
Xpasscxd[random filename]"Added by a variant of the SLAPER TROJAN!"
UPBKSchedulerPBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"
UPC Pitstop Optimize SchedulerPCPOptimize.exe"Scheduler for the Optimize system optimization utility from PC Pitstop"
XPC Scoutpcscout.exe"PC Scout rogue security software - not recommended
NPC SpeedScan ProPCSpeedScan.exe"Ascentive PC SpeedScan Pro registry optimizer - not recommended
XPCCleanerSysCleaner.exe"PCCleaner rogue cleaning utility - not recommended
NPCHealthpchschd.exe"This is a ""scheduler"" and does not turn off PC Health. For more information refer here"
XPDASCANpdascan.exe"Added by the AGOBOT-QY WORM!"
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
XPersonal Security Center Monitorisc_ui.exe"Added by the FAKEALERT TROJAN!"
UPop-Up_ScannerPopupscn.exe"Panicware popup blocker"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
UPopUpStopperCompanionPSComp.exe"PopupStopper Companion popup blocker"
XPower Scanpowerscan.exe"Foistware by Integrated Search Technologies - the people behind ISTBar adware"
NPowerReg SchedulerPowerReg Scheduler.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerPowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg Scheduler V3PowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV2PowerReg SchedulerV2.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV3PowerReg SchedulerV3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
YPP2000 Real Time ScanPPVstop.exeProtector Plus anti-virus software - real time scanner
?PPSchedulerPPScheduler.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
XPrint Schedulerusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
NPrint Screen Deluxepsdeluxe.exe"Utility allows "Print Scrn" or "Print Screen" key to capture
XprinterSpyAssaultScanner.exe"SpyAssault spyware remover - not recommended
NPrintScreenUNWISE.EXE"Gadwin PrintScreen - utility to capture
NPrintscreen 95PRT95MIN.EXE"Printscreen 95 - utility to capture
XPrivacyScannerpscan.exe"Privacy Champion
XPrnShareWscript.exe prn_share.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""prn_share.vbs"" file is located in %System%"
XProteção de telassmaze.scr"Added by the BANCBAN-FB TROJAN!"
Xprotectprotect.scr"Added by the DLOADER-TQ TROJAN!"
Xprutsctprutsct.exe"Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications
XPSC mainsttool32.exe"Added by the OBFUSCATED.EV TROJAN!"
XPSCastorPSCastor.exe"Added by the PSCASTOR TROJAN!"
XPSCMainpscmain2.exe"Added by the OBFUSCATED.EV TROJAN!"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
YQH Live Update SchedulerUPSCHD.EXE"Quick Heal Anti-Virus"
XQQKAVscvhsot.exe"Added by the QQROB.ARQ WORM!"
YQuick Heal Startup ScanQHSTRT32.EXE"Quick Heal - virus scanner"
NQuicken Scheduled Updatesbagent.exeQuicken background downloading module
NQuickFinder SchedulerQFSCHD100.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
NQuickFinder SchedulerQFSched.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
NQuickFinder SchedulerQFSCHD110.EXE"Used in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
NQuickFinder SchedulerQFSCHD130.EXE"Used in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
UQwest 11n Wireless WPS ToolWpsCenter.exeWireless configuration utility for the Qwest 11N 150MB USB wireless adapter
UR2Plus_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4x20 Series multifunction printers
UR2Ricoh_S2PScan2pc.exeScan to PC application for the scanning function of the Ricoh MFP Type 103 multifunction printer
XRagesCameraRagesn.exe"Added by the SDBOT.AHJ WORM!"
XRasCon Remote Access Service Managerrasmngr.exe"Added by the SPYBOT.EM WORM!"
Xrasctrsrasctrs.exe"Hijacker
XRAX SYSTEMscrigz.exe"Added by the MYTOB.KR WORM!"
URCScheduleCheckRCSCHED.EXE"Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
Xreal scheduler.htaRealAudio.exe"Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player"
XRealplayer Codec Supportrealsched.exe"Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
NRealschedrealsched.exe"Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player
Xrealtpskrealsched.exe"Chinese originated adware - detected by Panda as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name and this file is located in %System%"
NRecSheRecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
URegClean Expert SchedulerRCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
URegClean Expert SchedulerRCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
XRegistrywscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
XRegistry Scannerregscanr.exe"Added by a variant of the OPTIX TROJAN!"
XRegscanregscanr.exe"Added by the OPTIX-SE TROJAN!"
XRegScanDLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
XRegScanRegscan.exe"Added by the TALEX TROJAN!"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XReg_WFTscanreg32.com"Added by the SENNASPY-F TROJAN!"
Nreminder-ScanSoft Product Registrationremind32.exeRegistration reminder for ScanSoft products such as PaperPort
XREMOVE MEasclt.exe"Added by the RANDEX-FC WORM!"
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
UResChanger2004ResChanger2004.exeEVGA graphic card utility providing easy access to display settings
URestart WSC Settingwscrestp.exe"WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes"
URetrieverSchedulerretrieverscheduler.exe"80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders
NRoxioDragToDiscDrgToDsc.exe"System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
XRPCMSschost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
Urscmptrscmpt.exe"Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status"
Yrtvscn95RTVSCN95.EXEReal-time virus scanner component of Norton Anti-Virus Corporate Edition
XRun MSupdt32wscript MSupdt32.vbs"Added by the CASER WORM!"
Nrun=hpfschedHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
Xrun=Celine.scr"Added by the CELINE-A TROJAN!"
XRunDLL34syscnfg.exe"Added by an unidentified VIRUS
Nscscrubxp.exe"ScrubXP - utility that deletes safe to remove files
Uscsc.exe"Watchdog 2.0 Software - monitoring program"
Uscrun.exe"All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes
XSC2scprot4.exe"Added by the AGENT.APP TROJAN!"
?sc23execsc23exec.exe"Possibly related to a digital camera"
YSC3300CCSC3300CC.exeSiPix digital camera Twain device driver
Xscains030109.Stub.exe"Delfin Media Viewer adware related"
XScamDiskSVOHOST.exe"Added by the LEWOR.D WORM!"
Xscanmscman.exe"ClientMan parasite variant"
?Scan DetectorPmxdetect.exe"Associated with PrimaScan scanners. Is it required?"
XScan Registerssms.exe"Added by the RBOT-AT WORM!"
?Scan Wizardbutton.exe"Associated with Scan Wizard as supplied with Microtek scanners - see also the Scanner Detector and Sdetect entries. What does it do and is it required?"
UScan2pcScan2pc.exe"Scan to PC application for the scanning function of multiple multifunction printers from Dell
XScanDiscsatan.exeAdded by the GREGSTAR TROJAN!
XScanDiskScanDisk.exe"Added by the GANDA.A WORM! Note - this is not the valid ""ScanDisk"" Win9x/Me standard disk error checker"
Xscands32.exescands32.exe"Added by a variant of the ADCLICKER TROJAN!"
XScandsk2scandsk2.exe"Added by the AGOBOT-PK WORM!"
Xscandskx.exescandskx.exe"Added by the DLOADR-ARM TROJAN!"
?ScanFile??"??"
YScanInicioInicio.exe"Part of Panda Antivirus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active"
NScanner DetectorSDetect.exe"ScanSuite Scanner Detector - part of ScanWizard
YScanner File UtilityNsCatCom.exe"Kycocera Mita network copier/printer/scanner process to dump scanned documents onto a workstation"
?ScanPanelScanPanel.exe"Trust Easy Webscan scanner related - what does it do and is it required?"
XScanreg[filename]"Added by the QQPASS.E TROJAN!"
XScanRegistrynsrvnt.exe"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"
XScanRegistryscanregv.exe"Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe"
YScanRegistryScanregw.exeScans the Win98/Me system registry and makes back-ups at start-up - important should the registry become corrupt. Located in %windir%
XScanRegistryScanregw.exe"Added by the STATOR WORM! Note - this is not legitimate ScanRegistry entry - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %System%. Runs from the registry RunServices key as opposed to the Run key"
XScanRegistryN/A"Added by the DINOXI or DINOXI.B WORMS!"
XScanRegistryscanregw.exe"Added by the NYXEM-D WORM! Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines. This worm file is found in %System%"
XScanRegistryupdate.exe"Added by the DWNLDR-FZY TROJAN!"
NScanSoft OmniPage SE 4.0-reminderEreg.exe ereg.ini"Registration reminder for Ominpage SE version 4 from Scansoft (now Nuance)"
NScanSoft PaperPort 7 Registration ReminderNAVBrowser.EXE"Registration reminder for PaperPort 7 from Scansoft (now Nuance)"
NScanSoft PDF Professional 4-reminderEreg.exe Ereg.ini"Registration reminder for PDF Converter Professional version 4 from Scansoft (now Nuance)"
XScanSpywareScanner.exe"ScanSpyware rogue security software - not recommended
XScanSpyware v3.2Scanner.exe"ScanSpyware rogue security software - not recommended
XScanSpyware v3.5Scanner.exe"ScanSpyware rogue security software - not recommended
UScanSys32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XscAppscApp.exe"Added by the STANDO-E WORM!"
XscAppsuchost.exe"Added by the ACNATT.A WORM!"
XscAppwmiprvse.exe"Added by the SILLYFDC-AW WORM!"
NSCardSvrscardsvr.exeRelated to SmartCard readers and sometimes uses lots of system resources
XSCardSvrSCardSvr32.Exe"Added by the MOFEI.B WORM!"
USCDEmuApp.exeSCDEmuApp.exe"Related to PowerISO - CD/DVD image file processing tool"
USchdlr32Schdlr32.exe"Scheduled backups for the NTI Backup Now archiving utility. If a backup job has been scheduled
Xscheck45scheck45.exeRelated to unknown malware - hidden installer associated with it
Xschedlschedl.exe"Added by the VB-DVW WORM!"
Uschedmschedm.exe"Part of Antivir PersonalEdition Classic anti-virus"
XScheduIenrchk.exePremium rate adult content dialler
XScheduIrmsexploren.exe"Added by a variant of the SDBOT WORM!"
XScheduIrshch.exe"Added by a variant of the SDBOT WORM!"
XScheduIrsvchst.exe"Added by a variant of the SDBOT WORM!"
XScheduIrwinagent.exe"Added by a variant of the SDBOT WORM!"
UScheduleSchedule.exe"Scheduler for Mercury Ez View TV Tuner Card"
NScheduled MaintenanceScheduled_Maintenance.exe"Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs"
XSchedulerexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulerMSMSGS.EXE"Added by the HOSTBANK-A TROJAN! Note - this particular msmsgs.exe file is located in %System%\Config and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XScheduleroutIook.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulerwinagent.exe"Added by the TACTSLAY.B TROJAN!"
USchedulerScheduler daemon.exe"Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily
XSchedulermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XSchedulersdhch.exe"Added by the TACTSLAY.B TROJAN!"
XSchedulersvchst.exe"Added by the TACTSLAY.B TROJAN!"
XScheduler Servicewsass.exe"Added by the LIOTEN.KX WORM!"
XSchedulerMgrnavchk.exePremium rate adult content dialer
Uscheduler_monitorinit_scheduler.exe"Scheduler for ReaConverter advanced image converter"
Uscheduler_proxy Applicationscheduler_proxy.exe"Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates)
XScheduling AgentScheduler.exe"Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect"
XSchedulingAgantMMTASK.EXE"Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename"
USchedulingAgentmstask.exe"MS Scheduling Agent in Win98/Me/2K - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting
USchedulingAgentmstinit.exe"MS Scheduling Agent in WinNT - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting
XSchedulingAgentN/A"Added by the DINOXI or DINOXI.B WORMS!"
XSchedulingAgentmstask.exeAdded by unidentified MALWARE! Note - this is not the MS Scheduling Agent in Win98/Me/2K. This one also loads via the HKLM\RunServices registry key but is located in %System% on a WinXP machine - where a file of that name does not normally exist
XSchedulingAgentmstasks.exe"Added by the MSIC BACKDOOR!"
XSchijfBewakerSysRep.exe"SchijfBewaker
XSchijfControleurGDC.exe"SchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
USchmailiSchmaili.exe"Schmaili - insert animated smilies into your e-mail"
Xschost[path to trojan]"Added by the TJSERV.D TROJAN!"
NSchSvrSchSvr.exe"WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
YSCHWIZEXSCHWIZEX.EXE"Part of ConfigSafe - lets you identify changes to the registry
Xsck121helpsyss.exeAdded by a variant of the MAILBOT TROJAN!
Nsclaunchersclauncher.exe"SimpleCenter digital media player/manager that supports the iPod
Xsclicksclick.exe"Added by the FAKEALERT TROJAN!"
XScManagerscman.exe"Added by the FORBOT-CW WORM!"
Xscopedllscopedll.exe"Added by a variant of the CRYPTER.C TROJAN!"
NScotia OnLine Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
NScotia OnLine Security v*.* Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
XScrscr.scr"Added by the OPASERV.T WORM!"
NScrapPadScrappad.exe"ScrapPad allows you to quickly and easily record notes
Xscrbmk[path to trojan]"Added by the DLOADER-VP TROJAN!"
UScreen Calendarscrcal.exe"Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler"
UScreen Guardlaunch.exe"Part of Access Denied security and privacy software"
UScreen Guard Message Scansgms.exe"Part of Access Denied security and privacy software"
XScreen Saverscrnsaver.scr"Added by the RBOT-AGP WORM!"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
NScreenHunter 4.0 FreeScreenHunter.exe"""ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
NScreenPrint32ScreenPrint32.exe"ScreenPrint32 screen capture software - can be launched manually"
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
?screxescruser2k.exe"??"
?scriptscript.bat"Maybe associated with DOS on a Win9x machine"
YScriptBlockingSBServ.exe"Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information"
YScriptSentryScriptsentry.exe"Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly"
UScroll-In-Mouse V2.0SCROLL.EXE"Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
Xscrollerfpapli.exe"CoolWebSearch parasite variant"
Xscrssscrss.exe"Added by the HACDEF-R TROJAN!"
Xscrsvcscrsvc.exe"Added by the AGENT-DS TROJAN!"
XScrSvrScrSvr.exe"Added by the OPASERV WORM!"
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
YScsiScsi.exeSCSI Miniport driver
Xscssrr.exeServices.exe"Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xsctrlmgrsescmgr.exe"Added by a variant of the DWNLDR-GAH TROJAN!"
YSCTUINotifySCTUINotify.exe"Part of Windows SteadyState
Xscvhostsvzhost.exe"Added by a variant of the SPYBOT WORM!"
Uscvhostscvhost.exe"Wiretap surveillance software. Uninstall this software unless you put it there yourself"
Xscvhostscvhost.exe"Added by the AGOBOT-LI WORM!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xscvhost.exescvhost.exe"Added by the LOHAV-N TROJAN!"
XScvsrv32scvsrv32.exe"Added by the AGOBOT-PM BACKDOOR!"
XSdScans**stup_tmp.#32"Added by the SDSCAN.A TROJAN - where ** are random upper case letters"
XSearchAndDestroySchedulerSearchAndDestroy.exe"Search And Destroy rogue security software - see here and here"
XSearchEnhancementscbar.exe"SCBar foistware"
USecondChancesctray.exe"Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash"
USecurDiscNBHGui.exe"Part of the Nero multimedia suite backup function - ""Recover your data quickly and easily and create discs that are password protected. SecurDisc technology gives you peace of mind"""
NSecureClean4RegManagerscregmanager4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
NSecureClean4Traysctray4.exe"WhiteCanyon SecureClean 4 disk cleaner - clean hard drive data
NSecureCleanIECleanSCIEClean.exe"SecureClean - scans your system for hidden temporary files
XSecurity Mechaniclsascs.exe"Security Mechanic rogue security software - not recommended
XSecurity Patchscmss.exe"Added by the RBOT-ZW WORM!"
XSecurityScannerss2008.exe"Security Scanner 2008 rogue security software - not recommended
XServer Registryregscr32.exe"Added by the BIFROSE-ZB TROJAN!"
NService Connectionsccenter.exeFor Compaq PC's. Part of Backweb
XService Control Managerscm.exe"Added by the AGOBOT-GD BACKDOOR!"
XService Schedulerscheduler.exe"Added by the AGOBOT-PH WORM!"
XServicesscks32.exe"Added by a Proxy Trojan variant"
XServices HostScchost.exe"Added by the DONK WORM!"
USession Clientsescli.exe"SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
XShellsmsc.exe"Added by the BANCBAN-OY TROJAN!"
XShellNisca.exe"Added by the IBILL.Z TROJAN!"
XSichererSchutzpgs.exe"SichererSchutz
NSipDiscountSipDiscount.exe"SipDiscount - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
Usiscolorcolor.exeProbably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
Xsixer566sscc.exeAdded by an unidentified WORM or TROJAN!
YSkyBlaster SchedulerSSFSch.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
XSkynetRevengewinlogon.scr"Added by the NETSKY.AA WORM!"
NSmart Card ServiceScardSvr.exe"For Smart Card readers. Known to cause problems
USmart Connect MonitorSCMon.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
USmart Connect SetupSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
NSmsDiscountSmsDiscount.exe"SmsDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
NSoftware Managerissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
USolidWorks Task Scheduler EngineswBOEngine.exe"Task scheduler for SolidWorks 3D CAD software"
USoloScheduleSolocfg.exe"Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis"
USoloSysCheckSyscheck.exe"Solo antivirus System Integrity Check - Monitors system registry
Xsomescit.exe"Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack""
XSonic RecordNow!smsc.exe"Added by a variant of the SDBOT WORM!"
XSpees1speedy.scr"Added by the OPASERV.Y WORM!"
XSPINXWscript.exe OXNEY.B.VBS"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""OXNEY.B.VBS"" file is located in %System%"
Xspoolsvscvhosts.exe"Added by the SMALL-AW TROJAN!"
XSpore.bScmhlpr.vbs"Added by the SORPE.B WORM!"
XSpy Protectorlsascs.exe"Spy Protector rogue security software - not recommended
USpyCop ScanCheckMAIN.EXE"SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan"
XSpyOnThisScannerSpyOnThis.exe"SpyOnThis rogue spyware remover - not recommended"
USpyware Begonefreescan.exe"Spyware BeGone - spyware remover. Previously not recommended
NSpyware ScannerAseScanner.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU
USpyware VanisherFreeScanner.exe"Spyware Vanisher - spyware remover. Previously not recommended
Xspywarescannerspywarescanner.exe"Spyware Scanner 2008 rogue security software - not recommended
NSQL Serverscm.exeSQL Server Service Control Manager. Available via Start -> Programs
XSQUpdatesCheckeruc.exe"Xupiter SQWire toolbar related. Use Spybot S&D
?srePostpone"rundll32.exe [path] srescan.dll DoSpecialAction"
USRS Audio SandboxSRSSSC.exe"SRS Audio Sandbox ""provide amazing audio immersion and maximum thump for a personalized audio experience!"""
USSC Service Utilityssc_serv.exe"SSC Service Utility is a printer utility for refilled Epson cartridges"
USSCFBTN.EXESSCFBTN.EXE"Samsung smarthru software
YsscRunSSCRun.exeAOL's firewall
YSSC_UserPromptUsrPrmpt.exe"Part of Symantec's AntiVirus suite and comes usually with a product update
UStart Network Scanner ToolsdFTP.exe"Part of
XStarterscvhosting.exe"Added by the SDBOT.RU WORM!"
Xstarterscvhostingg.exe"Added by the FORBOT-FB WORM!"
Xstartkeyscvhost.exe"Added by the BIFROSE-PM TROJAN!"
UStartup Manager ScannerStartupMonitor.exe"Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans
YStartup ScanSensor.EXE"AntiVirus Quick Heal - scheduling agent"
?StatusClientStatusClient.exePart of Hewlett Packard network printer drivers
?StatusClient 2.6StatusClient.exePart of Hewlett Packard network printer drivers
Xstrmsnmgrsmsnxmsgrsc.exe"Added by the SDBOT.JDR WORM!"
Xstrmsnmsgrsmsnmsgrsc.exe"Added by a variant of the RBOT WORM!"
XSTVwinscrne.exe"Added by a variant of the SDBOT WORM!"
XSunJavaSchedccEvtMngr.exe"Added by the SDBOT-YP WORM!"
XSunJavaSched Updateravamx.exe"Added by the RBOT-ABJ WORM!"
NSunJavaUpdateSchedjusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XSunJavaUpdateSchedscvhost.exe"Added by the SDBOT-AVX WORM!"
XSunJavaUpdateSchedjavamx.exe"Added by the SDBOT-WI WORM!"
XSunJavaUpdateSched10jushed.exe"Added by the ACKANTTA.F WORM!"
XSunJavaUpdateSched132jschd.exe"Added by the AUTORUN-AQY WORM!"
XSunJavaUpdateSched16jvshed.exe"Added by the ACKANTTA.G WORM!"
XSunJavaUpdatSchedspoolsv.exe"Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
USupport.com Scheduler and Command Dispatchertgcmd.exe"Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers
USurfChoiceSCMan.exe"SCMan is a utility that can control services on WinNT from the command line. This utility can create
NsuSchedulerUCLauncher.exe"Scheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks"
XSVCHOSTscvhost.exe"Added by the MYTOB.E or MYTOB.G WORMS!"
Xsvchostinetinfo.scr"Added by the ODELUD WORM!"
XSVCHost Protocol32scvhost32.exe"Added by a variant of the IRCBOT TROJAN!"
Xsvchostdll.scrsvchostdll.scr"Added by the BANCBAN-FM TROJAN!"
XSvchostsSCVHOST.EXE"Added by the AGOBOT-RQ BACKDOOR!"
Xsvchosts.scrsvchosts.scr"Added by the BANCBAN-DQ TROJAN and variants!"
Xsvcsharenvscv32.exe"Added by the FUJACKS-Z WORM!"
XSwiftCleanerSwiftCleanerScanner.exe"SwiftCleaner rogue cleaning utility - not recommended
USybaseCentral43scjview.exe"Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies"
XSymantec Autoscan[random filename]"Added by the RBOT-AJO WORM!"
XSymantecFilterCheckbsyys.scr"Added by the BANLOAD.DZC TROJAN!"
XSyntax Scriptsystacq.exe"Added by the SDBOT.AI WORM!"
XSyntax Scriptsaskatcw.exe"Added by the SDBOT-TE WORM!"
Xsyscfgsyscfg32.exe"Added by the KWBOT.S WORM!"
Xsyscfg34.exesyscfg34.exe"Added by the ELECTRON WORM!"
XSyscheckwin.htaBrowser hijacker
Xsyscheckiexplorer.exeAdded by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
USysCheck32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XSysCleanerSysCleaner.exe"SysCleaner rogue cleaning utility - not recommended
Xsysclxntldrt.exe"Added by the JLOK-A WORM!"
XsyscmSyscm.exe"Vanish adware"
XSysCommsnmsgr.exe"Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%MSN Messenger or %ProgramFiles%Windows LiveMessenger. This one is located in %Windir%\system"
?SysCompmssdnl.com"Unknown but suspect as *.com are not usually run at start up and the name isn't recognized"
Xsysconsyscon.exe"Added by the APRILCONE.A WORM!"
Xsyscon lptt01syscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsyscon ml097esyscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsysconfigiexplorer.exe"Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XSysConfigsyscfg35.exe"Added by the KAZMOR.C WORM!"
XSysConfigwincfg32.exe"Added by the SDBOT.ZD WORM!"
USysconfigStealth KeySpy.exe"StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!"
Xsysconfig32sysconfig32.exe"Added by the AGENT-MSP TROJAN!"
XSyscpySyscpy.exe"Firewall-bypassing
XSysCtlsysctl.exe"Added by the AOK TROJAN!"
XSysctrlsprocdll.exe"Added by the WEEDBOTZ.14 TROJAN!"
XSysctrlswinupdate.exeAdded by an unidentified WORM or TROJAN!
XSysctrlsmscntrl.exe"Added by the KOLABC.BB WORM!"
XSysctrlsSysctrls.exe"Added by the AGENT.AWZ TROJAN!"
XSysctrlswin32dll.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSysctrls32sevchost.exe"Added by the RBOT.ADF BACKDOOR!"
XSysCVMS.exeSysCVMS.exe"Added by the SMALL.CBA TROJAN!"
XSysScanbvt.exe"Added by the AUTOUPDER TROJAN!"
USystemsysctrl.exe"Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance
XSystemwsscntfy.exe"Added by a variant of the SDBOT WORM!"
Xsystemssclie.exe"Added by the AGENT.LW BACKDOOR!"
XSystem CacheSysCache.exe"Added by an unidentified VIRUS
XSystem CGI Managersyscgmgr.exe"Added by an unidentified WORM or TROJAN! See here"
XSystem Config Bootsyscgboot.exe"Added by the AGENT.VWU TROJAN!"
XSystem Configurationsyscfg32.exe"Added by the MYTOB.EA WORM!"
XSystem Core Memorysyscoremem.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSystem CSRSS Patchscrtkfg.exe"Added by the RBOT-ADA WORM!"
XSystem Efficiency Monitormscedit32.exe"Added by the SDBOT.P TROJAN!"
XSystem Efficiency Monitormscommand.exe"Added by the KWBOT.P WORM!"
XSystem Hostscvhost.exe"Added by a variant of the RBOT WORM!"
USystem LifeGuard SchedulerSlsched.exe"System LifeGuard scheduler"
XSystem Loadersyscfg.exe"Added by the AGOBOT-BS BACKDOOR!"
XSystem Management Servicesmsc.exe"Added by the RBOT-ANN WORM!"
XSystem MScvbmscvb32.exe"Added by the SOBIG.C WORM!"
XSystem Protectorlsascs.exe"System Protector rogue security software - not recommended
XSystem Scannersystem.exe"Added by the AGOBOT-DI BACKDOOR!"
XSystem Security Checkerssc.exe"Added by the IRCBOT-WI TROJAN!"
XSystem Supportsyscfg.exe"Added by the RBOT-AGQ WORM!"
XSystem Traymsccn32.exe"Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
XSystem Unixsyscfg32.exe"Added by the RBOT-ZD WORM!"
XSystem Updateswinsci.exe"Added by a variant of the RBOT WORM!"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystemCheckSysCheckBop32.exe"WINBO adware"
XSystemCheckerSyschk.exe"Added by the GALIL.F WORM!"
XSystemCleanerPROsysclpro.exe"SystemCleanerPro rogue security software - not recommended
XSystemOPsvscrtvc32.exe"Added by a variant of the SPYBOT WORM!"
XSystemsscchost.exe"Added by the DAEMOZ.A TROJAN!"
XSystemssescmgr.exe"Added by the DWNLDR-GAH TROJAN!"
Xsystemscrootsystembin.exe"Added by a variant of the RBOT WORM!"
XSystemWindowsscvhost.exe"Added by the SILLYFDC-CG WORM!"
Xsysygm32syscxd32.exe"Added by the IRCBOT-PC TROJAN!"
XTask Scheduler Engineschedsvc32.exe"Added by the RBOT-ASJ WORM!"
XTaskschdTRAYWND.EXE"Added by the LITMUS.002 TROJAN!"
UTaskSchedulerTaskSch.exe"ProSeries accounting software related"
XTerminal Servicesmstscc.exe"Added by the SDBOT-CZW WORM!"
UTEscKeyTEscKey.exeToshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
?Tesco Insert DetectInsDetect.exe"Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
NTesco.net"rundll32 [path] RyDial.dll QuickStart"
NThe AssistanteSched.exe"Related to WinTotal from a la mode inc. FormFiller for appraisers"
XTime Zone Synchronizationwscript zshell.js"Added by the NETDEX-A TROJAN!"
NTkBell.Exerealsched.exe"Application Scheduler installed along with RealOne Player. Once installed
NTkBellExerealsched.exe"Application Scheduler installed along with RealOne Player. Once installed
NTOSCDSPDtoscdspd.exe"Related to Toshiba laptop CD/DVD drivers. This is a non-essential process. Disabling or enabling this is down to user preference"
XTotalSecure2009scan.exe"Total Secure 2009 rogue security software - not recommended
UTotRecSchedTotRecSched.exe"Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm"
UTPKBDLEDTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
UTpscrexTpscrex.exe"Lenovo (IBM) ThinkPad hotkey related"
UTpScrLkTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
UTpScrLk.exeTpScrLk.exeIBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
NTranscode360Transcode360Tray.exe"Designed for WinXP Media Center Edition 2005 and the Xbox 360
YTrendMicro OfficeScan NTTMLISTEN.EXEVirus scanner
UTrojanScannerTrjscan.exe"Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed"
XTStsc.exe"Total Security rogue security software - not recommended
UTSClientMSIUninstallertscuinst.vbs"Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
Xttoolscvc.exe"Added by the BCKDR-OWM BACKDOOR!"
UTV SchedulerTVSCHL.EXE"ProLink PlayTVpro TV tuner software scheduler"
UTvrScheduleSchedule.exe"Scheduler for Mercury Ez View TV Tuner Card"
UTVT Scheduler Proxyscheduler_proxy.exe"Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates)
UTweak UI 1.33 deutsch"RUNDLL32.EXE TWEAKUI.CPL TweakMeUp"
NTwkSCardSrvSCardS32.ExeUsed with Towitoko SmartCard Readers for card recognition
XUERScwUERScw.exe"Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
Xugescwugescw.exe"Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
UUniScUnisc.exeMcAfee UnInstaller
Xupascwupascw.exe"PersonalAntiSpy rogue spyware remover - not recommended
XUpdate Checkerscvhost.exe"Added by the AGENT-DSF TROJAN!"
XUpdate InstallSchost.exe"Added by the GAOBOT.AO WORM!"
Xupdatesched[random filename]"ZenoSearch adware"
Xushlisscbltqu.exeObtained from an MP3 search list site. Also generates random processes on reboot
XUssiwnscpit.exe"PurityScan adware"
Xvcmicrecmsccsed.exe"Added by the MAILBOT-CE TROJAN!"
XVelocidadSimplescrmain.exeVelocidadSimple rogue optimization utility - not recommended
XVideo Processsysconf.exe"Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!"
XVideo Processormsconfsys88.exe"Added by the AGOBOT-QG WORM!"
XVirscannersmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UVirtual Access SchedulerVASCHD32.EXEThe scheduler for mail and usenet tool
XVirtual CD v6grplscd.exe"Added by the RBOT-AXV WORM!"
XVirus Scanvirscana.exe"Added by an unidentified VIRUS
XVirusCheckIIAVIRCHK.EXE"Added by the DASMIN TROJAN!"
XVirusRescueVirusRescue.exe"VirusRescue rogue security software - not recommended"
YVirusScan Onlinemcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
?VirusScanMSCVsStat.exe"Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe)
XVirusScannermnsys.exe"Added by the SDBOT-AFQ WORM!"
XVirusSchlachtpgs.exe"VirusSchlacht
XVirus_ScannerVirus_Cleaner.exe"Added by the PANOL WORM!"
NVistascanvistascan.exe"Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users
NVoipDiscountVoipDiscount.exe"VoipDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XVprocessscvtw32.exe"Added by the AGOBOT-FR BACKDOOR!"
YVrBootScanVRBScan.exe"Boot scan feature of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal
YVrScheduleVrres.exe"Part of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal
Xvscanjoke.vbs"Added by the ROOKIE-A TROJAN!"
Xvscannerspooll32.exe"Added by the OPTIXPRO.10 TROJAN!"
Xvschostvschosts.exe"Added by the VIPSY-A TROJAN!"
Xvschostvschost.exe"Added by the AGENT.QK BACKDOOR!"
XW32.ScranScran.exe"Added by the NARCS WORM!"
Xw32alanismope.scr"Added by the SINALA WORM!"
XW32Load[random filename].scr"Added by the CASPID WORM!"
XW32TcWTC32.scr"Added by the VOTE.D or VOTE.K WORMS!"
UWatson Subscriber for SENS Network Notificationsdwtrig20.exe"Used to launch Microsoft Error Reporting (DW20.exe) - if
UWCESCOMMWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
NWeatherscopeWeatherscope.exe"WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
NWebposition Gold 2wpsche~1.exe"Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
UWebScanDEFSCANGUI.EXE"eAcceleration Stop-Sign security software related. Previously not recommended
Uwebscanstopsignav.exe"eAcceleration Stop-Sign security software related. Previously not recommended
YWebScanXWebScanX.exe"From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs
Xwescmv[random filename]"Added by a variant of the SLAPER TROJAN!"
UWhitney2_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier
UWHITNEY2_XRX_S2PScan2pc.exeScan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer
UWhitneyXerox_S2PScan2pc.exeScan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer
UWHITNEY_S2PScan2pc.exeScan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers
Xwiascrwiascr.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
XWidnows Xp Web scanxpscan.exe"Added by a variant of the SDBOT WORM!"
XWin startupmscfg32.exe"Added by the SPYBOT-AE WORM!"
Xwin-xpnvsc32.exe"Added by the BROPIA.N WORM!"
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
XWin32 Cnfg32msconfgh.exe"Added by the MYTOB.NB WORM!"
XWin32 Securemsconfigsvc.exe"Added by a variant of the SDBOT WORM!"
XWin32 USB2 Driversmsc.exe"Added by the SDBOT.FO WORM!"
XWin32 USB2 Driversyscfg32.exe"Added by the FORBOT-R WORM!"
XWin32GScandisk.com"Added by the ESTRELLA TROJAN!"
XWinamp Agentcvscc.exe"Added by the AGOBOT-GK WORM!"
XWinAntiSpyware 2006 Scannerwas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended
UWinBackup SchedulerWbsched.exe"LIUtilities WinBackup scheduler - backup software"
Xwincfgsyscnfg.exe"Added by an unidentified VIRUS
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWindows 32 Rescuewin32resc.exe"Added by the FORBOT-EU WORM!"
XWindows Anti Virus Control Centeravrscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Anti Virus Control Centerwinavscan.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows cfgascv.exe"Added by the AGOBOT-SZ BACKDOOR!"
XWindows Confwindowsconf.exe"Added by a variant of the IRCBOT TROJAN! See here"
XWindows Configuration Loaderasclt.exe"Added by the SDBOT-OA WORM!"
XWindows Data Serverautodisc.exe"Added by the SPYBOT-CB WORM!"
XWindows Dcom2 Fixmscom32.exe"Added by the RBOT-QT WORM!"
YWindows DefenderMSASCui.exe"Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups
XWindows DLL LoaderSYSCFG16.EXE"Added by the DOMWIS-N WORM!"
XWindows Driver FoundationMTVSCMXT.EXE"Added by a variant of the RBOT WORM!"
XWindows Essensialsmvnesc.exe"Added by a variant of the IRCBOT TROJAN!"
XWindows Firewalllscvhost.exe"Added by the RBOT-EK WORM!"
XWindows Frameworkscvh0st.exe"Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
XWindows Helperwsctnfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Host Servicescvhosts.exe"Added by the SPYBOT.NLI WORM!"
XWindows HTML file readerSysconf32.exe"Added by the NOOMY.A WORM!"
XWindows Image Acquisition (WIASC)WIAcs.exe"Added by the RIZO.A TROJAN!"
XWindows Image Acquisition (WIASSC)WIAcss.exe"Added by the RIZO.A TROJAN!"
XWindows JavaScript DaemonWinjsd.exe"Added by the WOOTBOT.AF WORM!"
XWindows Loader Servicecivsc.exe"Added by a variant of the RBOT WORM!"
XWindows Messenger 4.14landisc.exe"Added by the SDBOT-KR WORM!"
XWindows MSConfig Startup Loggerwinlog.exe"Added by the RBOT.BCU WORM!"
XWindows Network ServiceMsconf32.exe"Added by a variant of the RBOT WORM!"
XWindows NT Logon Applicationwinlogon.scr"Added by the RBOT-ALP WORM!"
XWindows Performance Monitorwmscupd.exe"Added by the IRCBOT_GEN WORM!"
XWindows Pool Managerpoolsc.exe"Added by the OBOT.CH WORM!"
?Windows Print SpoolerSCVHOSTS.EXE"Suspicious due to the similarity to the valid ""svchost.exe"" file"
XWindows Registry Scanregscan32.exe"Added by the RBOT.KE WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Registry Scansvcdll.exe"Added by the RBOT-TP WORM!"
XWindows Registry Scanregscan23.exe"Added by a variant of the RBOT WORM!"
XWindows Registry Scanregscan.exe"Added by the RBOT-HA WORM!"
XWindows Registry Scanwinmedia.exe"Added by the SPYBOT.GK WORM!"
XWindows Rescue Systemwinsto.exe"Added by the SUURCH.CG TROJAN!"
XWindows SAomniscient.exe"BLAZEFIND adware"
XWindows Schedulerwmscheduler.exe"Added by a variant of the SDBOT WORM! See here"
XWindows Scheduler!scheduler.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows ScreensaverService.exe"Added by the KELVIR.P WORM!"
XWINDOWS SCREENSAVERssaver.scr"Added by the SDBOT-YZ WORM!"
XWindows Secure Connectionwinsc.exe"Added by the SDBOT.BTN WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Center Notification Appwscnfty.exe"Added by a variant of the RBOT WORM!"
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWindows Server Client Verification Servicewscvs.exe"Added by the AGENT.AWC TROJAN!"
XWindows Service Agentwmscc.exe"Added by the RBOT-GQP WORM!"
XWindows Service Hostscvhost.exe"Added by the SDBOT.N TROJAN!"
XWindows Service Hostschost.exe"Added by the GAOBOT.AO WORM!"
XWindows Servicesscmsg.exe"Added by a variant of the SDBOT WORM!"
XWindows Servicesscvhoste.exe"Added by the SPYBOT.OBZ WORM!"
XWindows Servicessmsc.exe"Added by a variant of the SDBOT WORM!"
Xwindows shellext.32mschost.exe"Added by the BLASTER.K WORM!"
XWindows SQL management 1.33scvhost.exe"Added by the SPYBOT-OB WORM!"
YWindows SteadyState - Session Timer Notify (UI)SCTUINotify.exe"Part of Windows SteadyState
XWINDOWS SYSTEMsmsc.exe"Added by the MYTOB-BR WORM!"
XWindows System ConfigurationSYSCFG16.EXE"Added by the WISDOOR-K TROJAN!"
XWindows System ConfigurationPasscfg16.exe"Added by the DOMWIS-E TROJAN!"
XWindows System Managersysconf.exe"Added by the MYTOB.AL WORM!"
XWindows System Managersmsc.exe"Added by a variant of the RBOT WORM!"
XWINDOWS SYSTEM mscdvvsmscdvvs.exe"Added by the MYTOB.MD WORM!"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindows System-Control Driverssyscontrl.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Task Schedulerasijdie.exeAdded by an unidentified WORM or TROJAN!
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
XWindows UDP Control CenterehSched.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerscvhost.exe"Added by the PUSHBOT.EH WORM!"
XWindows UDP Control Centerwinuscn32.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Centerwksvcsc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows UDP Control Serviceswksvcsc.exe"Added by the ANTIAV-C TROJAN!"
XWindows Updatescvhost.exe"Added by the SDBOT-XT WORM!"
XWindows Updatemsconfig32.exe"Added by a variant of the SPYBOT WORM! See here"
XWindows Updatescrigz.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Updatewinsc.exe"Added by the BUZUS.RYI TROJAN!"
XWindows Updatesmsscr.exe"Added by the BANKER-DK TROJAN!"
XWindows Update Processwmiprvsc.exe"Added by the SDBOT-CB WORM!"
XWindows Update Serviceregscv.exe"Added by the AGOBOT-AM BACKDOOR!"
XWindows Virus Scannerwinvsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindowsCRCwscrc.exe"Added by the SDBOT-VU WORM!"
XWindowsCriticalUpdatewindows_critical_update.exe"Added by the ASTEF or RESPAN WORMS!"
XWinds Sersc Agtsrzrzncrtz.exe"Added by the RBOT-GTV WORM!"
NWinDVR SchSvrSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
UWinFast ScheduleWfwiz.exeLeadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
UWinFastDTVDTVSchdl.exe"Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc"
XWinHelprealsched.exe"Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
XWinhlp32Wscript.exe Msexec32.vbs"Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
XWINLOGONwscript.exe WINLOGON.vbs"Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
XWinlogonscssrr.exe"Added by the AGENT-LXB TROJAN!"
?WinManagerschost.exe"??"
XWinmgr.exescvhost.exe"Added by the AGOBOT.AFG WORM!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
XWinScMngrwinsmc.exe"Added by the SDBOT-BPZ WORM!"
XWinsock Drivernvscv32.exe"Added by the AGOBOT-FD WORM!"
XWinsock Driverscvhost.exe"Added by the RBOT.AEU BACKDOOR!"
XWinsock2 driverwincfg.scr"Added by the SPYBOT-E TROJAN!"
XWinsock2.dllWINLODR.SCR"Added by an unidentified VIRUS
XWinsock32driverwin32server.scr"Added by the HACARMY TROJAN!"
XWinStartWscript.exe WinStart.vbs"Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
Xwinsyssyschost.exeAdded by an unidentified TROJAN!
UWinSysChecksb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
XWINTASK DLLjusched32.exe"Added by the MYTOB.AI WORM!"
NWinTOTAL Schedulerguru.exeWinTOTAL Real estate appraisal software related
Xwinupdatejusched.exe"Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
UWireless Connection Managerwirelesscm.exe"Wireless adapter configuration utility for D-Link's range"
XWlan Driveravscan.exe"Added by the WOOTBOT.DH WORM!"
XWMI Standard Event Consumer - Scriptingscrcons32.exe"Added by the RBOT-GRD WORM!"
XWMI Standard Event Consumer - Scriptingscrcs.exe"Added by a variant of the RBOT-GRD WORM!"
Xwmonjusched.exe"Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
UWMPNSCFGWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XWNSCwnsin**.exe [* = random char]"PurityScan adware"
XWnsck2 driverwlogf.exe"Added by the SPYBOT-AF WORM!"
XWNSIwnscp**.exe [* = random char]"PurityScan adware"
XWOOZautodisc.exe"Added by the AGENT-CPS TROJAN!"
UWorkstation Schedulerwm95.exe"Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled
XWPSVC Serviceswpnsc.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xwscmstdl.exe"MaCatte Antivirus 2009 rogue security software - not recommended
UWSchedulerWScheduler.exe"Windows Scheduler - "schedule unattended running of applications
Xwscmgrwscmgr.exe"Added by the AUTORUN-AA WORM!"
Xwscnftywscnfty.exe"Added by a variant of the RBOT WORM!"
Xwscntfyswsscntfy.exe"Added by the SDBOT-TN WORM!"
XWSConfigurationspoolsc.exe"Added by the AGOBOT-HY WORM!"
Xwscript.exevabian.vbs"Added by the VABI VIRUS!"
Xwscsvc.exewscsvc.exe"Added by a password stealing BANKER TROJAN!"
Xwscsvc32.exewscsvc32.exe"Antivirus rogue security software - not recommended
Xwsctf.exewsctf.exe"Added by the JAMPORK.E WORM!"
XWsdata serviceWSconf.exe"Added by the SDBOT.ZU WORM!"
XWSSVCsmsc.exe"Added by the AUTORUN-AGA WORM!"
UWTIndicatorSchedInd.exe"WinTask - software that automates a variety of routine tasks quickly and simply"
XWTSCwapisvcc.exe"PurityScan adware"
UX4ALLNLwdfsctl.exe"XS4All Webdisk - web space management utility for the Dutch ISP"
UXemiComputers SchedulerScheduler.exe"Smooth Program Scheduler from XemiComputers ""will start any program you want at a scheduled time"""
UXeroxScannerDaemonXrxFTPLt.exe"Xerox Scanner Daemon - driver for Xerox Scanner model fu621d"
?XeroxScanUtilityxrxzipui.exe"Associated with a Xerox multifunction and/or scanner. What does it do and is it required?"
UXSC SIP ClientX-Lite.exe"""CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download"". For VOIP and broadband users"
UXTNDConnect PC - ScheduleSyncSCHEDU~1.EXE"ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts
XYahoo MessenggerSCVHOST.exe"Added by the SOHANA-V WORM!"
XYahoo MessenggerSCVHSOT.exe"Added by the HAKAG-A WORM!"
XYahoo MessenggerSCVVHSOT.exe"Added by the SILLYFDC-AE WORM!"
XYahoo MessenggerSSCVIHOST.exe"Added by the SOHANA-W WORM!"
XYahoo MessenggerSSCVIIHOST.exe"Added by the SOHANA-Y WORM!"
XYahoo Messenggerscvhosts.exe"Added by the SOHANNA-AH WORM!"
XYahoo Messenggerscvshosts.exe"Added by the TRAX-A WORM!"
UYou've Got Pictures Screensaverygpsstra.exeAOL You've Got Pictures Screensaver
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
UZSSchedulerzsscheduler.dll"ZeroSpyware from FBM Software"
X[12 random characters]autodisc.exe"IeDriver adware variant"
X[32 random hex numbers]tsc.exe"Total Security rogue security software - not recommended
X[filename]svchost.scr"Added by the BANKER-CC TROJAN!"
X[original filename]svchost.scr"Added by the BANCBAN-CX TROJAN!"
X[original filename]xphost.scr"Added by the BANCBAN-HM TROJAN!"
X[random characters]rsbmsc.exe"Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
X[random name]scanregw.exe"PurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines"
X[random]lsass.scr"Added by the BANCBAN-CW TROJAN!"
X[random]svchost.scr"Added by the BANCBAN-CY TROJAN!"
X[various names]ActionScr.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]NsCplTray.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]NSYSCPLSTR.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]scanSYS.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]StatusCheck.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]sysconf16.exe"Wareout - malware masquerading as a spyware and dialer remover"
Y_AntiSpywareMssCli.exe"Part of McAfee AntiSpyware"
X_ntrRescueService_ntrrs.exe"Added by the DLOADER-JV TROJAN!"
U{1290A33C-85F5-4164-A1BE-7DD299D4986A}PBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.