Arcade File Downloads Support Forum
Email

Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown




Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.exe"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.dll"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Y!AVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
ME""MS Java Applets for Windows NTXjavaapplets.exe
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
XP & ME"MS Java for Windows NTXxpjavams.exe
Version"NVIDIA Compatible Windows Vista Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Compatible Windows7 Display driverU"RUNDLL32.EXE NvCpl.dll
Version"NVIDIA Driver Helper ServiceU"RUNDLL32.EXE nvsvc.dll
Version"NVIDIA nView Control PanelNnwiz.exe
please"This is a virusXbigbadvirus.exe
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$drv$sys$drv.exe"Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
U$Volumouse$volumouse.exe"Volumouse from Nirsoft. ""Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"""
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X*Intelli Mouse Pro Version 2.0B*ncsjapi32.exe"Added by the BUZUS-O WORM!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
?00DSKSVR00desksaver.exe saskda"Part of Advanced Desktop Shield
U00DSKSVR01desksaver.exe tray"System Tray access to Advanced Desktop Shield
X0_AVD32xzboot.exe"Added by the AGENT-IWI TROJAN!"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons
N12Voip12Voip.exe"12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
N1:00hpdrv.exeHP utility for monitoring when and how many recoveries have been done
U1A:MacVisionTrayMonitorTrayMonitor.exe"Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar
Y1A:Stardock MCPmcpserver.exe"Master Control Program for Stardock apps
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
X2020Downloadermssvr.exe"2020Search Toolbar"
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X32.exenvscv32.exe"Added by the AGENT-LOL TROJAN!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
XaMsSvrdll.vbs"Added by the MUTAFROG!INF WORM!"
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion
?a2dservicea2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
Xa9z1eizA1eatulabov.exe"Added by the AGENT-GWD TROJAN!"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
UACTIVBOARDABoard.exe"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email
XActive Securityasecurity.exe"Active Security rogue security software - not recommended
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exe"ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProsvxhost.exe"Added by a variant of the RBOT WORM - see here"
XAdobeReaderProrvdjlefr.exe"Added by the RBOT-CQZ WORM!"
XAdobeReaderPromsnservex.exe"Added by the RBOT.AKM BACKDOOR!"
XAdobeReaderPromsnsrcdv.exe"Added by the INJECT-H WORM!"
XAdobeReaderProservice.exe"Added by the RBOT-BCA WORM!"
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe® Creative Suite
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
Xadstartupautomove.exe"Adlogix adware variant"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
XAdtools ServiceAdTools.exe"Windupdates Adware"
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
XAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
XAdvanced Spyware Remover ProAsr.exe"Advanced Spyware Remover rogue spyware remover - not recommended
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner rogue security software - not recommended
Xadvanceddefenderadvanceddefender.exe"Advanced Defender rogue security software - not recommended
XAdvancedPrivacyGuardapg.exe"AdvancedPrivacyGuard rogue privacy program - not recommended
XAdvancedPrivacySuiteAPS.exe"AdvancedPrivacySuite rogue privacy program - not recommended
XAdVantageAdVantage.exe"MediaAdVantage adware"
XAdVantage SetupAdVantageSetup.exe"MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the ""DAEMON Tools sponsor ad module"" option during install) and possibly others"
Xadvap32[path to trojan]"Added by the MUTANT.AT TROJAN!"
XAdvapiAdvapi.exe"Added by the NETDEVIL.12 WORM!"
NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
Xadvmon32advmon32.exe"Added by a variant of the CRYPTER.C TROJAN!"
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 rogue security software - not recommended
XAdwarz Spy RemoverADWARZ.EXE"Added by the SPYBOT-EV WORM!"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
?AidemHotKeyDVMAIN.EXE"Keyboard related"
?Air2Dataa2dservice.exe"Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required?"
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
NAlcohol Soft Development Teamaxcmd.exe"Part of Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAlevirAlevir.exe"Added by the OPASERV-A WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
Xalgv.exealgv.exe"Added by the AUTORUN-BEA WORM!"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
XAll Sea screen saverTaskTray.exe"Free screensaver
UAlogservAlogserv.exe"From McAfee VirusScan for logging scanning activities. In some cases
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XAlphaAVAlphaAV.exe"Alpha Antivirus rogue security software - not recommended
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UALServALServ.exeUtility that enables a user to control the volume and surround sound and select Pro Logic/Stereo on 2 satellite speakers and subwoofer of old Altec Lansing speaker systems. The right-side speaker has 4 controls on top providing same functionality
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xamircivilsvchost.exe…"Added by the AMIRECIVEL WORM!"
Xamvaamvo.exe"Added by the SILLYFDC-BR WORM!"
Xanbv32nabv32.exe"Added by the TITOG.C WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended
XAntiVer2008pgs.exe"AntiVer2008
XAntiVermeansAntiVermeans.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsAntiVermins.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.0AntiVermins 3.0.exe"Antivermins rogue security software - not recommended
XAntiVermins 3.3AntiVermins 3.3.exe"Antivermins rogue security software - not recommended
XAntiVerminserAntiVerminser.exe"Variant of the Antivermins rogue security software - not recommended
XAntiVerminsProAntiVerminspro.exe"Antivermins rogue security software - not recommended
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
XAntiVirsmss.exe"Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue spyware remover - not recommended
XAntiviralGoldenAntiviralGolden.exe"AntiviralGolden rogue security software - not recommended
XAntiVirGear 3.7AntiVirGear 3.7.exe"AntiVirGear rogue security software - not recommended
XAntiVirGear 3.8AntiVirGear 3.8.exe"AntiVirGear rogue security software - not recommended
XAntiVirProtectAntiVirProtect.exe"AntiVirProtect rogue security software - not recommended
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusAntvrs.exe"AntiVirus 2008 rogue security software - not recommended
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended
XAntivirusaav.exe"Advanced Antivirus rogue security software - not recommended
XANTIVIRUSAVS.exe"Antivirus Sentry rogue security software - not recommended
XANTIVIRUSmicroAV.exe"Micro Antivirus 2009 rogue security software - not recommended
XAntivirusMSA.exe"MS Antivirus rogue security software - not recommended
XANTIVIRUSUltraAV.exe"Ultra Antivirus 2009 rogue security software - not recommended
XAntivirusxpa.exe"Xpert Antivirus Enterprise rogue security software - not recommended
XAntivirusSPP.exe"Spyware Preventer rogue security software - not recommended
XAntivirussav.exe"System Antivirus 2008 rogue security software - not recommended
XAntivirusuav.exe"Ultimate Antivirus 2008 rogue security software - not recommended
XAntiviruswav.exe"Windows Antivirus 2008 rogue security software - not recommended
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Agent Proaap.exe"Antivirus Agent Pro rogue security software - not recommended
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus Pro 2010AntivirusPro_2010.exe"Antivirus Pro 2010 rogue security software - not recommended
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus Updatesavupdchk.exe"Added by the AGOBOT-IP WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden rogue security software - not recommended"
XAntivirus.exeAntivirus.exe"Antivirus rogue security software - not recommended
XAntivirus2008yantvrs.exe"AntiVirus 2008 rogue security software - not recommended
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusBESTInstaller.exe"Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here"
XAntivirusBESTabest.exe"AntivirusBEST rogue security software - not recommended
XAntivirusDocAntivirusDoc.exe"AntivirusDoc rogue security software - not recommended
XAntivirusFiablepgs.exe"AntivirusFiable
XAntivirusForAllpgs.exe"AntivirusForAll rogue security software - not recommended
XAntivirusGoldAntivirusGold.exe"AntivirusGold rogue security software - not recommended
XAntivirusGold 5.1AntivirusGold 5.1.exe"AntivirusGold rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAntivirusOrdipgs.exe"AntivirusOrdi
XAntivirusPCPakkepgs.exe"AntivirusPCPakke
XAntivirusPCSuitepgs.exe"AntivirusPCSuite rogue security software - not recommended
XAntiviruspertuttipgs.exe"Antiviruspertutti rogue security software - not recommended. A member of the AVSystemCare family"
XAntiVirusProAntiVirusPro.exe"Anti Virus Pro rogue security software - not recommended"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirus Pro rogue security software - not recommended"
?AntiVirusProtectionqumk.exe"??"
XAntivirusProtectionantivirusprotection.exe"Antivirus Protection rogue security software - not recommended
XAntivirusschermpgs.exe"Antivirusscherm
XAntivirusXP.exeAntivirusXP.exe"Antivirus XP Pro rogue security software - not recommended
XAntiVirus_ProNETAntiVirus_Pro.exe"AntiVirusPro rogue security software - not recommended
XAntiVituSBase.exe"Added by the BAS.A WORM!"
UAnVirAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Security SuiteAnVir.exe"AnVir Security Suite - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task ManagerAnVir.exe"AnVir Task Manager - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager FreeAnVir.exe"AnVir Task Manager Free - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
UAnVir Task Manager ProAnVir.exe"AnVir Task Manager Pro - ""is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work"". Monitors and manages startup programs
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
XAnvTrgrAnvTrgr.exe"AntivirusTrigger rogue security software - not recommended
UAnyDVDAnyDVD.exe"AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the ""U"" recommendation"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
Yaolavp.exe"AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory"
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
XAOLSPYWAREREMOVER32AOLSPYWARECLEANER32.EXE"Added by the SPYBOT-HJ WORM!"
Xaoueisysrtmvs.exe"Chivio dialer"
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM!"
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Added by the IRCBOT.BJJ BACKDOOR!"
XApplication Layer Servicesavrsvc.exe"Added by the IRCBOT.BJM BACKDOOR!"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplication Managerapnsvc.exe"Added by the SMALLTRO.FN TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NArcSoft Connection ServiceACDaemon.exe"Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovax ShieldArovaxShield.exe"Part of Arovax Shield from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
YArovaxShieldArovaxShield.exe"Part of Arovax Shield from Arovax
XASC-AntiSpywareWinAntivirus.exe"Win Antivirus Vista/XP rogue security software - not recommended
YAshampoo AntiVirus ServiceGuardGui.exe"System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
YashAvastashAvast.exe"Part of Avast antivirus"
Xashcapservirsess.exe"SpySure spyware"
YashMaiSvashmaisv.exe"E-mail scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
?AspireServiceAspireService.exe"Found on Acer laptops
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
?AsusACPIServerAsAcpiSvr.exe"Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required?"
NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
Xasussvcasussvc.exe"Added by the AGENT-FPB TROJAN!"
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
UATI Technologies Inc. HydraVision Desktop ManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UATI Technologies Inc. HydraVision ViewportHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename
NATIPOLABati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
NATIPOLLati2evxx.exe"Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAudio Device Managerwinfp.exe"Added by the IRCBOT-XS WORM!"
XAudio Device ManagerWinNT.exe"Added by the IRCBOT.USP BACKDOOR!"
XAudio Device ManagerWNDXP.exe"Added by the IRCBOT.AJL BACKDOOR!"
XAudio Device Managersfhgj.exe"Added by the IRCBOT-ZA BACKDOOR!"
NAudioCommanderVistaAudioCommander.exe"System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation
XAudiodrvaudiodrv.exe"Added by the CRYPTER-C TROJAN!"
UAudioDrvEmulatorDLLML.exe AudDrvEm.dll"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
XAudoi Device Loadersmssv.exe"Added by the AGOBOT-ZY WORM!"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAuto Startsndvol32.exe"Added by the SLINBOT.AX BACKDOOR!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Root%\Application Data\WINDOWS"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XautoMewscript.exe solution.vbs"Added by the VBS.SASAN WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""solution.vbs"" file is found in %Windir%"
XautoMewscript.exe samok.vbs"Added by the SAMOK-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""samok.vbs"" file is located in %Windir%"
XAutoProtectAutoProtect.vbs"Added by the KILLBAT-C WORM!"
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
XAutoupdate Service[path to trojan]"Added by the AGENT-CB TROJAN!"
XAutoUpdate32services.exe"Added by WINSPY.88! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\debug64"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
Xautoupdatev2autoupdatev2.exe"Detected by Kaspersky as the AGENT.FQ TROJAN!"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Xauto__antiav__keyantiav_exe.exe"Added by the BAGLEDI-AA TROJAN!"
XauxAudioDeviceaux32.exe"Added by the AIZU WORM!"
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAVAntivir.exe"Antivir rogue security software - not recommended
Xavexpressav.exe"Express Antivirus 2009 rogue security software - not recommended
XAV AntiSpywareava.exe"AV AntiSpyware rogue security software - not recommended
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
XAV7antivirus7.exe"Antivirus7 rogue security software - not recommended
NAvaFindAvaFind.exe"AvaFind file search utility"
Xavagent3974chnb8895.exe"AntiVirus ransomware security software - not recommended
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
YAvast!ashServ.exe"Main part of avast! Antivirus - including the resident protection
Yavast!ashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner
Yavast! Web ScannerAshwebsv.exe"Web scanning part of avast! Antivirus. Starts via a registry ""Run"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
YAvast32Astart32.exe"Part of Avast! anti-virus software"
Xavcavmon.exeAdded by an unidentified TROJAN!
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
YAVG Anti-Spywareavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
YAVG Anti-Virus systemavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG Anti-Virus Systemavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG Anti-Virus Systemavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG AntiVirus Scanneravgscnx.exe"Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry"
XAVG AntiVirus Updateravgwusv.exe"Added by the SILLYFDC.BAX WORM! Note - this is not a legitimare AVG entry"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
YAVG IDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
UAVG Internet Securityavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVG7_AMSVRAVGAMSVR.EXE"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
YAVG7_CCavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
YAVG7_EMCavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YAVG7_Runavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
UAVG8_TRAYavgtray.exe"System Tray access to and notifications for the 8.* series of internet security products from AVG Technologies - including Internet Security
UAVG9_TRAYavgtray.exe"System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security
Yavgamsvr.exeAvgamsvr.exe"This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher"
Yavgasavgas.exe"System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware"
Yavgccavgcc.exe"System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled
Yavgcc32avgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVGCtrlAVGCtrl.exe"Part of AntiVir® PersonalEdition Classic antivirus"
Yavgemcavgemc.exe"E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry
YavgfwsrvAVGFWSRV.EXE"Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks
YAVGIDSAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
YAVGIDSUIAVGIDSUI.exe"System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. ""Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
YAVGntAVGnt.exe"AntiVir® PersonalEdition Classic antivirus. System Tray icon and control program"
YAvgserv9.exeAvgserv9.exe"Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
Uavgtrayavgtray.exe"System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security
YAVGuardAVGuard.exe"AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
YAVG_CCavgcc32.exe"System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests
YAVG_EMCAVGEMC.exe"AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
YAVG_RegCleanerAVGREGCL.exe"Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XAvimgtAvimgt.exe"Added by the GEMA TROJAN!"
XAvimgt32Avimgt32.exe"Added by the GEMA TROJAN!"
YavinitAVINIT9X.EXE"Command Antivirus related"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
XAvirTrAvirTr.exe"AntivirusTrigger rogue security software - not recommended
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
YAVKBarAVKBar.exe"GData AntiVirusKit Anti-virus"
YAVKTrayAVKTray.exe"System Tray access to the antivirus part of G Data range of internet security products"
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
?AvMenuAVMenu.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required?"
YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
Yavpavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Xavpavp.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
XAVP-SEavp-32.exe"Added by the AGOBOT.FS WORM!"
Xavpaavpo.exe"Added by the LEGMIR-ARK TROJAN!"
Yavpccavpcc.exe"Kaspersky Labs anti-virus"
XavplAntivirus.exe"AntiVirus Plasma rogue security software - not recommended
XAvpMAvpM.exe"Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in %Windir%\pchealth\UploadLB\Config"
Xavpmsavpms.exe"Added by the ONLINEGAMES.CPV TROJAN!"
XAvpravpr.exe"Added by the MYDOOM.AF WORM!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
Xavrlabsavrlabs.exe"VirusResponse Lab 2009 rogue security software - not recommended"
Xavscanavscan.exe"Added by the SILLYFDC.BCR WORM! The file is in the users %Temp% directory"
XAVScanwinav.exeUnidentfied rogue security software
XAvScanavscan.exe"Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\<rogue name>"
XavscanUsbconeted.exe"Added by the PROVIS-A TROJAN!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAVSchedulerAVSCHSVC.EXE"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVSeguropgs.exe"AVSeguro
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
Xavserve2.exeavserve2.exe"Added by the SASSER.B or SASSER.C WORMS!"
Xavserve3.exeavserve3.exe"Added by the SASSER.G WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music
XAVSTRTnavpsrvc.exe"Added by the FORBOT-EF WORM!"
XAVSystemCarepgs.exe"AVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
Xavtapiavtapi.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
NAvtrayAvtray.exe"Command Antivirus tray icon"
XAVTrayAVTray.exe"Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended
XAVupdate32 UpdateAVupdate32.exe"Added by the RBOT.CNI TROJAN!"
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
YAVWUpd32AVWUPD32.EXE"AntiVir® PersonalEdition Classic - updater"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
YAvxliveavxlive.exe"Bullguard or BitDefender antivirus"
Yavxlniavxinit.exe"Anti-virus part of BitDefender virus scanner/firewall"
?Avxnews??"??"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
?a_vpdvpd.exe"Located in an IBMTOOLS\VPD sub-directory. What does it do and is it required?"
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
XBackup Servicebackup.svcUnidentified adware
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBaRloNdDiLhepservices.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
XBastioneAntiviruspgs.exe"BastioneAntivirus
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
XBcvsrv32msbvd32.exe"Added by the AGOBOT-SR WORM!"
XBcvsrv32system2.exe"Added by the AGOBOT-PU BACKDOOR!"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
?BELORVBIBELORVBI.exe"??"
XBestsellerAntiviruspgs.exe"BestsellerAntivirus rogue security software - not recommended
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
?BigDogPathVM_STI.EXE"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
XbingdianBingdian.vbs"Added by the BINGD WORM!"
?BIOVCIPBIOVCIP.exe"??"
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootCleansmartdrv.exe"Added by the LURKA-A VIRUS!"
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is located in %System%"
XbootsecNAVSSE.exe"Added by the FORBOT-CY WORM!"
Xboot_regsvchot.exe"Added by the BANCBAN-BQ TROJAN!"
XBortMedViruspgs.exe"BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
XBPCV2BPCV2.exe"BroadcastPC adware"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
XBrave-SentryBraveSentry.exe"BraveSentry rogue security software - not recommended
XBraveSentryBraveSentry.exe"BraveSentry rogue security software - not recommended
Xbraviaxbraviax.exe"Added by the FAKEALER.LE TROJAN!"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBTVbtv.exe"BroadcastPC adware"
XBtvCbtvclean.exe"BroadcastPC adware"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
Ubugwatcher servicebugwatcher.exe"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
UButton Serverbttnserv.exe"Found on a Compaq PC
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
?BZEnvironmentVariableCollectorBZEnvironmentVariableCollector.exe"Part of BlazentAgent from Blazent who provide ""outsourcing governance automation for IT Outsourcing (ITO) relationships"". What does it do and is it required?"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
YCaAvTrayCAVTray.exe"eTrust™ EZ Antivirus system tray application from Computer Associates"
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit
UCamera DetectorDEVDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
Xcaseyvideocaseyvideo.exeMalware causing adult content popups
Xcaseyvideo[*] [* = digit]caseyvideo[*].exe [* = digit]Malware causing adult content popups
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
YCAVRIDCAVRID.exe"eTrust™ EZ Antivirus Real Time Infection Report from Computer Associates"
YCAVSCAVS.exe"Cheyenne (now eTrust) antivirus"
XCAZNOVASCAZNOVAS.exe"Added by the CAZNO TROJAN!"
Xcbvcsurretnd.exe"Added by the FRETHOG-C WORM!"
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
YCcEvtMgrccEvtMgr.exe"Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
XccEvtMrg.execcEvtMrg.exe"Added by the RBOT.GZ WORM!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003
YccRegVfyccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
Xccsvit.execcsvit.exe"Added by the STARTPA-HP TROJAN!"
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
NCDANTSRVCDANTSRV.exe"C-Dilla License Management software. Used for any program that uses C-dilla Protection
Xcddrv32cddrv32.exe"Added by a variant of the CRYPTER.C TROJAN!"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
UCDVAgentCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
XCerbDivXx.exe"Added by the KEYLOG-LV TROJAN!"
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
XCEventMgrCell.exe"Added by the BIFROSE-AK TROJAN!"
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
UCGServercgserver.exe"Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs"
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Xche32che.ocx.vbs"Added by the ADENU-B VIRUS!"
YCheckVCRIOMagic.exe"Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)"
XChinagnqvasdd.exe"Added by the SDBOT-SE WORM!"
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
Xchkdrviemon.exe"Detected by Symantec as the ADCLICKER TROJAN!"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
?ChronitelInitTVCHTVINIT.EXE"??"
XCi ServsSysTuwin.exe"Added by the AGENT-NIQ TROJAN!"
XCi Svrcisvr.exe"Added by the IRCBOT.AWN BACKDOOR!"
NCIJxP2PSERVERCIJxP2PS.EXE"Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
NCitiVANCitiVAN.exe"Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again"
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
XCleanUp AntivirusCU[random characters].exe"Cleanup Antivirus rogue security software - not recommended
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
UCleverKeysCK.exe"CleverKeys - ""is free software that provides instant access to definitions at Dictionary.com
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClip Service Managerclipmg.exe"Added by the DELF.DXJ TROJAN!"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClipbook ServiceClipsrv.exe"Supports Windows XP ClipBook Viewer
NClipsrvClipsrv.exe"Supports Windows XP ClipBook Viewer
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
?CLMLServer for HP TouchSmartCLMLSvc.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
NCmFlywaveNameCmFlywav.exe"Driver for Linksys Wireless-G Music Bridge"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
YCnwiDeviceAgentcnwida.exe"Part of the Canon imagePROGRAF W8400 printer management software"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM Servicemskwda.com"Added by the AGENT-JIX TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
UComm Drivercommh32.exe"G Data ""PC Spion"". PC monitoring and surveilling software
Xcommandjavaw.exe"Added by the AGOBOT-LG WORM!"
YCommon ClientccRegVfy.exe"Part of earlier versions of Norton AntiVirus - ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XCommonServicewinup.exe"Added by the DLOADR-BJJ TROJAN!"
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
XConducteurPriveGDC.exe"ConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfig Loadersvchost2.exe"Added by the AGOBOT.XE WORM!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfiguration Driverscghost.exe"Added by the SDBOT-DLA WORM!"
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loadercvcd.exe"Added by the AGOBOT-DH BACKDOOR!"
XConfiguration Loadermservs.exe"Added by the SDBOT-NM WORM!"
XConfiguration Loaderscvh0st.exe"Added by the AGOBOT-AX WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfiguration UpdateUPDT32V2.EXE"Added by the SPYBOT-AA BACKDOOR!"
XCONFIGUREvantivir62.exe"Added by the AGOBOT-ZD BACKDOOR!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XContent Servicewinserv[LETTER].exe"PurityScan adware"
XContentServicewinservn.exe"PurityScan adware - see here"
XContraviroContraviro.exe"Contraviro rogue security software - not recommended
XContraVirusContraVirusPro.exe"ContraVirus rogue security software - not recommended
XContraVirusContraVirus.exe"ContraVirus rogue security software - not recommended
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
XControlPanel"svcc.exe internat.dllLoadKeyboardProfile"
XControlPanel"private.exe internat.dllLoadMouseCarpetProfile"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
Xcpntmgcnavpmc.exe"Added by the SIMCSS TROJAN!"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XCPQHotKeyshotkeysvc.exe"Added by the RBOT-XA WORM!"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
UCpu Level Up helpCpuLevelUpHelp.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
?CQSCP2PSERVERCQSCP2PS.EXE"""Compaq printer utility which is required in the startup menu in order to make the printer work correctly"". Is it actually required?"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative DetectorCTDetect.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
NCreativeDiscNotifierCTNOTIFY.EXE"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM
UCreativeMixerCTMIX32.EXE"Creative soundcard System Tray access to
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
Xcserv32cserv32.exe"Added by the STRATION.EC WORM!"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
XCTDrive"rundll32.exe drvmod.dllstartup"
NCTDVDDetCTDVDDet.exe"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player
XCTF Device Loaderctfmond.exe"Added by the AGOBOT-FO WORM!"
XCTFMONwscript.exe /E:vbs winjpg.jpg"Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""winjpg.jpg"" file is located in %System%"
XCTFMONwscript.exe /E:vbs regedit.sys"Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""regedit.sys"" file is located in %System%"
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
XCTHELPERsvhost.exe"Added by the SDBOT-RZ WORM!"
?CTPDPSRVCTPDPSRV.EXE"Compaq A3000 printer driver (in the %System%\spool\DRIVERS\W32\X86 folder). Is it required?"
UCtrlVolCtrlVol.exe"Volume control key on Acer
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTsysVolCTSYSVOL.exeCreative sound card volume controls
?cttdpsrvcttdpsrv.exe"??"
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
XcvhnykzxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Xcvmonitor.execvmonitor.exe"Added by the SDBOT.BV WORM!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
Ncwbckvercwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
Ncwbsvstrcwbsvstr.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop
UCyber-Defender 2003uwcdsvr.exe"
NCyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyber-shot Viewer Media Check ToolSPUVOL~1.EXE"Part of the Sony Picture Utility software supplied with Sony Cyber-shot digital cameras. Automatically invokes an import process if the camera is connected and has media on it"
NCyberlink PowerCinema 3.0PCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
XDarkDevil.Grasiele.BRGrasiele.VBS"Added by the LEMBRA WORM!"
XDASDS VSAVdjsdsabdw.exe"Added by the SDBOT-RE WORM!"
XDataSystem.dat.vbs"Added by the BISCUIT.A WORM!"
XData Filevdehost.exe"Added by the SDBOT-DOS TROJAN!"
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word
UDAZEL Delivery AgentDcDaemon.exe"Control and send documents
Ndbservdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
Xdc2k5SVIQ.EXE"Added by the COIDUNG-A WORM!"
UDCfssvcdcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
Udcfssvedcfssvc.exe"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup
XDCOM Server[path to trojan]"Added by the AGENT-CCQ BACKDOOR!"
NDDCActiveMenuDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefaultmtask.vbe"Added by the ALLEM WORM!"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
?desk-top-servicedesk-top-service.exe"??"
XDeskAd ServiceDeskAdServ.exe"DeskAd.Service adware"
Udesksaverdesksaver.exe"Part of Advanced Desktop Shield
UDeskSaverDeskSaver.exe"DeskSaver from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". The Pro version also includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
UDeskSaver ProDeskSaver.exe"DeskSaver Pro from Headway Creative - utility that allows you ""to backup and to restore the icons position easily on the Windows desktop"". Includes a ""Taskbar Economizer"" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaver"
Udesksaver.exedesksaver.exe"Part of Advanced Desktop Shield
Xdesktopdesktop.ini.vbs"IE-Title malware"
UDesktop Maestro Vista TrayRMTray.exe"Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevelopment Environmentdevenv.exe"Added by the DELBOT-AH WORM!"
UDEventAgenteventagt.exeDEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UDevice DetectorDevDetect.exe"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
NDevice Detector 2DevDtct2.exe"Installed by various Olympus products
XDevice Hardwaredevicehnd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice IO Systemdeviceio.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managementwnsystem.exe"Added by the AGOBOT-LH WORM!"
XDevice Managerwfxmgr.exe"Added by the RBOT.AJU WORM!"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Driverdevicesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UDeviceDiscoveryhpotdd01.exe"Detection of new imaging
XDevicePathProyecto1.exe"Added by the GRUEL WORM!"
XDevicePathRoot.exe"Added by the GRUEL WORM!"
UDevicesolesvr.exe"Salfeld Child Control - parental control software"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Udevldr16devldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Udevldr16.exedevldr16.exe"Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
?Devlogdevlog.exe"Apparently mainboard/chipset related
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
?DiamondviewDiamondview.exe"Manulife Financial Insurance program. Is it required at startup?"
UDigiSrvDigiSrv.exe"Related to camera software from DigitalDreams"
NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
XDirector Videobtnmgern.exe"Added by the MYTOB-KL WORM!"
UDIRECTVDSLDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
XDirectX Driverstdhost.exe"Added by the SDBOT.GVJ BACKDOOR!"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Added by the RBOT.UXL WORM!"
XDirectX Video Driverdxterm5.exe"Added by the WILAB-A TROJAN!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
?discovegdiscoveg.exe"??"
?DISCoverDISCover.exe"Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Managerdiskver.exe"Added by the RBOT.AQT WORM!"
XDisk Panel Configurationdpcsvc.exe"Added by the IRCBOT.BSQ BACKDOOR!"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
XDist-FBGeneveGDC.exe"NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
XDistributed Link Trackingascvt.exe"Added by the AGOBOT-GH BACKDOOR!"
?Divamon.exeDivamon.exe"Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
Xdivxdivxenc.exe"Added by the SPBOT.B TROJAN!"
XDivxcodll.exe"Added by the GRAVEBOT-A TROJAN!"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
XDivx4 codecdevldr32.exe"Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
XDivXCodecNEWMAIL.exe"Added by the DELF-RQ BACKDOOR!"
Xdjdsdvqwavjdhdg.exe"Added by the SDBOT-EF BACKDOOR!"
YDkServiceDkService.exe"From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled
Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
NDLF_00000B00Vcdlf.exe"Known to cause problems with "Out of memory" errors (see here). Otherwise
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDll Linksvchoist.exe"Added by the AUTOSKY WORM!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDllCacherv2dllcachev2.exe"Added by the LATEDA TROJAN!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
XDmsvc32Dmsvc32.exe"Added by the AGOBOT.ABU WORM!"
XDM_serverdmserver.exe"Comet Cursor adware"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDNS Config servicewin32.exe"Added by the RBOT-TL WORM!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
XDnsCacheWscript.exe dns_cache.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
?DNXVCdnxvc.exe"??"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
NDoroServerDoroServer.exe"Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
XDowmingzuDowmingzu.dll.vbs"Added by the SOLOW-E WORM!"
YDpcnavdpcnav.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
XdpzProtectn.vbe"Added by the RUNAUTO.H WORM!"
XDR service[path to worm]"Added by the RBOT-CZT WORM!"
Xdreamsserver.exe"Added by a variant of the SDBOT WORM!"
XDrefIWSysDrefIWv2.exe"Added by the DREF-C WORM!"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended
XDriveCleaner FreeUDC.exe"DriveCleaner rogue security software - not recommended
XDriveDefenderGDC.exe"DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
UDriveLEDOODLed.exe"O&O DriveLED - hard disk monitoring and crash prevention"
XDrivergbot.exe"Added by the JUNTADOR.K TROJAN!"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
XDriverConfdvrconf.exe"Added by the AGOBOT-IY WORM!"
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\)
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
NDriverMaxdevices.exe"DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
XDrives swapAV1i.exe"Anti-Virus Number-1 rogue security software - not recommended
NDriveSelectdriveselect.exe"DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
XDriveSystemmaxpaynowti1.exe"Added by the TIBS.AZT TROJAN!"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
Xdrvddll.exedrvddll.exe"Added by the BEAGLE.AP WORM!"
XDrvddll_exedrvddll.exe"Added by the BEAGLE.X WORM!"
UDrvIconDrvIcon.exe"""Vista Drive Icon changes the drive icons shown in Windows ""My Computer""
?DrvListnrDrvListnr.exe"Analog Devices SoundMAX soundcard related. What does it do and is it required?"
Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
UDrvMon.exeDrvMon.exe"Alcor drive monitor software"
Xdrvnetwdrvnetw.exe"Added by the BROGGER-B TROJAN!"
Xdrvr32hdrvr32h.exe"Added by an unidentified VIRUS
Xdrvrmanagerdrvrquery32.exe"Added by the BOOHOO WORM!"
XDrvStartHPMedia.exe"Added by the BANCBAN-QE TROJAN!"
Xdrvsys.exedrvsys.exe"Added by the BEAGLE.W WORM!"
Xdrvsyskithidr.exe"Added by the BAGLE.HR WORM!"
Xdrvsyskithldrrr.exe"Added by the BAGLE.QU TROJAN!"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
Xdrv_st_keyhidn.exe"Added by the BEAGLE.FF WORM!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XDVAScvssdfaAsSDdwd.exe"Added by the LIOTEN.IP TROJAN!"
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
XDVD Upgradedvdupgd.exe"Added by a variant of the IRCBOT BACKDOOR!"
Ndvd43DVD43_Tray.exe"DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
UDVD43DVD43.exe"DVD43 is a small tool that overrides CSS copy-protection found on DVD movies"
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
NDVD@ccessDVDAccess.exe"Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
?DVDAgentDVDAgent.exe"Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
UDVDBitSetDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
?DVDCheckDVDCheck.exe"Related to an Intervideo program. What does it do and is it required in startup?"
XDvdcompatDvdcompat.exe"Added by the GEMA TROJAN!"
NDVDLauncherDVDLauncher.exe"Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
NDVDSentryDSentry.exe"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching
NDVDTrayDVDTray.exeHP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
NDVDUpgradeDVDUpgrd.exe"Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
NDVDXGhostDVDGhost.EXE"DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free
UdvHighMemcfgmng32.exe"Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
YDvp95Dvp95.exe"Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine"
Ydvpapi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
YDvpInitExeDvpinit.exe"Command Antivirus related"
YdvprptDvprpt.exe"Command Antivirus related"
Xdvraudiodvraudio.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
UDVSyncdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
XDvVideo32dvvid32.exe"Added by the TINY.FD TROJAN!"
XDvxwsxsvc.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
Xdwqblwpvl.exe[random].exe"Okcashbackmall adware"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
Xdxviddxvid.exe"Added by the DLUCA-Y TROJAN!"
XDyFuCA Active Alertactalert.exe"Adult content dialler - see here"
?DZKillMeDZSAVEME.EXE"??"
UD_V_Tdvt.exe"DICOM Validation Tool - ""DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"""
?D_V_Tdvt.exe"Installation could be a crack/hack to NOD32 - see here. Seen and removed in many logs. Investigate it further and if the file C:\d_v_t.reg is present then it should be fixed. Not to be confused with the DICOM entry here"
Ue-Surveiller Stationestation.exe"ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
XEasyAVEasyAV.exe"Added by the NETSKY.S or NETSKY.T WORMS!"
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup
XeasyServServer.exe"Added by the EASYSERV TROJAN!"
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneVGUI.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
Xebmmmebatesmmmv.exe"Ebates adware"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
NEEventManagerEEventManager.exe"Part of the Epson Creativity Suite supplied with their multi-function printer/scanners
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications
NEgisTecLiveUpdateEgisUpdate.exe"Software updater for biometric and data encryption products from EgisTec Inc"
NelmElmenv.exe"ViaTech eLicense for securing
UELSAChipGuardelsavect.exe"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed
YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
XeMakeSVEMAKESV.EXE"""Switch"" adult content dialer"
XeMakeSVEMAKE2B.EXE"""Switch"" adult content dialer"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
YEnvyHFCPLEnMixCPL.exe"VIA Envy24 PCI Audio Controller driver"
UEPGServiceToolEPGClient.exe"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
UEPGServiceToolEPGCLI~1.EXE"Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
UEPSON Status Monitor 3E_[various].EXE"Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXE"Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status
XEQAdviceEQAdvice.exe"NewAds1 adware"
YeRecoveryServicecheck.exe"Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
UeRecoveryServiceeRAgent.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer
Xerthgdrsvc.exe"Added by the BEAGLE.BN or BEAGLE.BP WORM!"
Xerthgdr2svc23.exe"Added by the BAGLE.CG WORM!"
UES Current Services[FILE NAME].exe"123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
Xeth0 driverexec.exe"Added by the SPYBOT-Z WORM!"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEtrafficJavaRun.exe"TopMoxie adware"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
?Event Logeventlog.exe"??"
NEvent Planner RemindersPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Planner Reminders Tray IconPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
NEvent Reminderpmremind.exe"Event reminder for calendar dates
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
Neventmgreventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Xeventwvreventwvr.exe"Added by the COSIAM_G TROJAN!"
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
UEVGAPrecisionEVGAPrecision.exe"EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible
UEvidence Cleanerecleaner.exe"Evidence Cleaner cleans up tracks left by your PC and Internet activities"
NEvidence Eliminatoree.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
XEvilEvil.exe"Added by the MYTOB.JM WORM!"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed
UEVOLOSTAEVOLOSTA.EXE"Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID
UEvoluent Mouse ManagerEvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
XEvtHtmevthtm.exe"Added by the DLUCA-EJ TROJAN!"
UEvtMgr6Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
?Excite Private Messenger Pipex8impipe.exe"??"
XExpertAntivirusExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
XexplerUpdadv.exe"Added by the QQPASS-N TROJAN!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExtra AntivirusExtraAV.exe"Extra Antivirus rogue security software - not recommended
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
UF5D7050v3Belkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
UF5D8055v1Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
XFast Searchsvcnv.exe"Homepage
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
UFastTVSyncFastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps
Ufatrecovfatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFenio Startupsfnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
Xffsvhost32.exe"Added by the LINEAG-AFF TROJAN!"
XffeqOMEvcvsav.exe"Added by the RANKY.AB TROJAN!"
Yffprsrvffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffprsrv.exeffprsrv.exe"File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled
Yffpsrvffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
Yffpsrv.exeffpsrv.exe"File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
XFiles Driversdphost.exe"Added by the SDBOT-DKZ WORM!"
XFiles Driversfdhost.exe"Added by the AGOBOT-AJC BACKDOOR!"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFire Wall serviceswnlmzsfhobi.exe"Added by the IRCBOT-QY WORM!"
XFire Well service[random].exe"Added by the RBOT-FJU WORM!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
XFiresWallservices[random].exe"Added by the RBOT-FJT WORM!"
XFirevall Administratingrndll.exe"Added by the PUSHBOT-B WORM!"
Xfirewallspoolsv.exe"Added by the DIZAN.F VIRUS!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
XFirewallSvrFirewallSvr.exe"Added by the NETSKY.X or NETSKY.Y WORMS!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
YFix-it AVmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
XFixnicevcvw.exe"Added by the SDBOT TROJAN!"
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
XFlash Driver[path to trojan]"Added by the AGENT.CWVT TROJAN!"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
?Flow Go TVflogotv.exe"??"
Xflpsflps.vbs"Added by the BYRON WORM!"
?FLSVCIFLSVCI.exe"??"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolder Viewfolderview.exe"Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
XFont Viewerfontviewer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NfontnavFontNav.exe"Font Navigator from Bitstream Inc. - a font management utility"
XFONTVIEWFONTVIEW.EXE"Added by the OPASERV.T WORM!"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NFree DVD DirectFreeDVDDirect.exe"Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
Xfree-save[path to risk]"Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
UFreeMemVn2FreeMem.exe"FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XFS6519FS6519.dll.vbs"Added by the SOLOW.B WORM!"
?FSDPSRVFSDPSRV.exe"??"
XFSHsvcnva.exeIdentified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
Ufsservfserv.exe"Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
Xfstsvc"rundll32.exe fstsvc.dllstart"
UFSWebServerfsws.exe"Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
?FtpServer.exeFtpServer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
XFUFUvirus.exe"Added by the VB-EJC TROJAN!"
XFuckerfucker.vbs"Added by the CATCHER-A WORM!"
Xfukerservicefukerz.exe"Added by a variant of the RBOT WORM!"
NFusionHdtvTrayFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
NFusionTrayAgentFusionHdtvTray.exe"FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
Xfvekfvek.exe"Added by the DRIVOL-A TROJAN!"
YFveNotifyfveNotify.exe"Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista
Ufwservicefwservice"eAcceleration Stop-Sign security software related. Previously not recommended
Xfzgsvhost32.exe"Added by the DLOADER.BDK TROJAN!"
XG0mezG0mez.vbs"Added by the GORMLEZ-A WORM!"
UG6FTP Server Tray MonitorG6FTPTray.exe"System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
?GACServiceGACService.exe"Related to a Gemplus product. What does it do and is it required?"
NGame DeviceJOYUPDRV.EXEGenius game controller profile activator
NGameDriveGDTask.exe"GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
XGames Accelerationsvshost.exe"EasySearch adware"
XGames Accelerationsvshost1.exe"Added by the DLOADR-AWD TROJAN!"
Xgammasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
XgaSrvgaSrv.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XgaSrvegaSrve.exe"Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
XgcasDtServgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
YgcasServgcasServ.exe"Giant Antipsyware - now superseded by Microsoft's Windows Defender"
XgcasServrealsched.exe"Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
NGCSGrabClipSave.exe"GrabClipSave screen capture tool"
NGDriveGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
NGearboxconfsvr.exe"NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
XGekio Startupsgnksvc32.exe"Added by the AGOBOT.AFJ WORM!"
XGeneral AntivirusGenAvir.exe"General Antivirus rogue security software - not recommended
XGeneric host proccess for windowsSVCHOSTS.EXE"Added by the SPYBOT-GQ WORM!"
XGeneric Host Processsvchost.exe"Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XGeneric Host Processcamacttiv.exe"Detected by AVG as the CIADOOR.13 TROJAN!"
XGeneric Host Process for Win Servicesmscvs.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Process for Win32 Servicesvlhost.exe"Added by the WOOTBOT.EX WORM!"
XGeneric Host Process for Win32 Servicerpchost.exe"Added by the IRCBOT.DCN WORM!"
XGeneric Host Process for Win32 Servicesntspcv.exe"Added by the SDBOT.S TROJAN!"
XGeneric Host Process for Win32 Servicesintspvc.exe"Added by the DINFOR.D WORM!"
XGeneric Host Process for Win32 Serviceswinsvc.exe"Added by the SDBOT-O WORM!"
XGeneric Host Process for Win32 Servicesbazzi.exe"Added by the AHKER.E WORM!"
XGeneric Host Process for Win32 Serviceswinsvc32.exe"Added by the SDBOT-P WORM!"
XGeneric Host Process for Win32 Serviceslspsvc.exe"Added by the MUMU.C WORM!"
XGeneric Host Process for Win32 ServicesSPSVC.EXE"Added by the SDBOT.DA WORM!"
XGeneric Host Process for Win32 Servicessvchost32.exe"Added by the AGOBOT.ALH WORM!"
XGeneric Host Process for Win32 Servicessvñhîst.exe"Added by the DLOADER.AK TROJAN!"
XGeneric Host Process for Win32 Serviceswinlogon.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XGeneric Host Process For Win32 Servicesmtsc32.exe"Added by the VB-CPL TROJAN!"
XGeneric Host Process for WinXP Servicesmshelp.exe"Added by the AGENT-GQP TROJAN!"
XGeneric Host Process2 System Backupscvhost2.exe"Added by the RBOT-BAH WORM!"
XGeneric Host Process326a System Backupscvhost326a.exe"Added by a variant of the SDBOT WORM!"
XGeneric Host Servicelshost.exe"Added by the RBOT.LU WORM!"
XGeneric Service Processregsvc32.exe"Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
XGeneric Service Processserv1ces.exe"Added by the AGOBOT-JK WORM!"
XGeneric Service Processnvsvc.exe"Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XGeneric Service Processsrvhost.exe"Added by the AGOBOT-FX WORM!"
XGeneric Service Processregsvr32.exe"Added by the AGOBOT-AGD WORM!"
XGeneric Service ProcessSRCHOST.EXE"Added by the AGOBOT-DG WORM!"
XGeneric Services Processregsvc32.exe"Added by the GAOBOT.SY WORM!"
XGenius Mose Driversvghost.exe"Added by a variant of the SPYBOT WORM! See here"
Xgenserv pathsdqdqg.exe"Added by the SDBOT-RF WORM!"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGerenciamento de arquivos do WindowsWinmod32.exe"Added by the DLOADER-WG TROJAN!"
XGestionnaire de disques universelsysoobe.exe"Added by the TOADER-A TROJAN!"
XGet-Torrent Servicewakeservice.exeGet-Torrent bittorrent client - Installs LOP adware
UGetting started with MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
XGhost AntivirusGhostAV.exe"Ghost Antivirus rogue security software - not recommended
NGhostStartServiceGhostStartService.exe"Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
Xglvglv.exe"Added by the DLOADER-NG TROJAN!"
XGmsvc32gmsvc32.exe"Added by the AGOBOT.ABN WORM!"
XGNP Generic Host Processsvchost.exe"Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
Xgocvir.exe"Added by the SILOV-A WORM!"
XGo And Startsvdll32.exe"Added by the RBOT.AI BACKDOOR!"
UGoBack Polling ServiceGBPoll.exe"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users
UGoldensoft_MndlSvrMndlSvr.exe"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive
XGolumservices.exe"Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process
Xgolummservices.exe"Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
Xgoodbadvir.exe"Added by the SILOV-B WORM!"
NGoogle Earth ViewerGOOGLEMAPS.EXE"Google Earth ""combines satellite imagery
XGoogle serviceGooglesetup.exe"Added by the IRCBOT-RJ WORM!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
UGoToMyPCg2svc.exe"ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
Xgovurarope"Rundll32.exe retasevo.dlls"
XGPLv3[random name].dll"Vundo adware"
XGraphic Driversmss32.exe"Added by a variant of the RBOT WORM!"
XGraphic Loaderntvdm32.exe"Added by a variant of the RBOT WORM!"
XGraphics adapter servicewindll.exe"Added by the ATNAS.A WORM!"
UGravis Appawareloaderdbserver.exe"Looks like it's associated with Gravis game controllers and the Keyset Manager
UGravis Xperience Driver SupportGrxp4exe.exe"Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
Xgremierwscript.exe gpremier.vbs"Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
Xgrgtgvgb.exe[random].exe"Added by the AGENT-EBF TROJAN!"
YGroove Virtual OfficeGroove.exe"""Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings
UGrooveMonitorGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
UGrooveMonitor UtilityGrooveMonitor.exe"Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
NGrpConvgrpconv.exe"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
Xgshpzzgshp.vbsHomepage hi-jacker
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
Xgsvgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
UGTVEpgGTVEpg.exe"Part of Got All Media - control your TV tuner and other utilities from your PC"
UGTVRecGTVRec.exe"Part of Got All Media - control your TV tuner and other utilities from your PC"
XGuard ProVH339.exe"Guard Pro rogue security software - not recommended
XGustavVED[filename].exe"Added by the OPASERV.H WORM!"
Xgvagfxjrundll32 ...gvagfxj.dll"Unidentified adware
XG_Server.exeG_Server.exe"Added by the FEUTEL-C TROJAN!"
XG_Server1.2.exeG_Server1.2.exe"Added by the GRAYBIRD-Z TROJAN!"
Xh4te Service Driversh4te.exe"Added by a variant of the RBOT WORM!"
Xhagentavp.exe"Added by the ""Herman Agent"" remote access TROJAN!"
XHard drive Controllerhdcontroller.exe"Added by the KIMAN.B WORM!"
XHardDriveGuardSysRep.exe"HardDriveGuard rogue system error and cleaning utility - not recommended
XHardware Monitor Servicemshms.exe"Added by the WOLLF-A TROJAN!"
UHawkEye IV Control PanelHAWK_32.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
NHD Audio Control PanelRtHDVCpl.exe"Realtek HD Audio Manager
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
XHDriveSweeperHDriveSweeper.exe"HDriveSweeper rogue privacy program - not recommended
XHekio StartupsHnksvc32.exe"Added by the AGOBOT-QE WORM!"
Xhellfiresvchost.exe"Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xhelloservhelloserv.exe"Added by the ZHELATI.BHA WORM!"
?HerculesCamServiceCamService.exe"Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
XhfdtubvnxkeepSafe.exe"Added by the KILLAV.KAX TROJAN!"
Yhffsrvhffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
Yhffsrv.exehffsrv.exe"Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
Uhidservhidserv.exe"This is the Human Interface Device Server for Win98SE/2000/Me/XP
XHijSrv32hijsrv.exe"Added by the BANKGERM-D TROJAN!"
XHIVHIV.exe"Added by the HIVA TROJAN!"
XHKCUserver.exe"Added by the AGENT-NLT TROJAN!"
XHKLMserver.exe"Added by the AGENT-NLT TROJAN!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
UhkservHKserv.exeKeyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
XHMI PowerSystemhmisvc32.exe"Added by the RANDEX.CZZ WORM!"
XHML PowerSourcehmlsvc32.exe"Added by the SDBOT-XL WORM!"
XHMV PowerSourcehmusvc32.exe"Added by the SDBOT-YW WORM!"
XHOI Servicesholsvc32.exe"Added by the AGOBOT-SF WORM!"
XHollabackslvhosts.exe"Added by the SDBOT.BMO WORM!"
XHome Antivirus 2010HomeAntivirus2010.exe"Home Antivirus 2010 rogue security software - not recommended
NHome Theater SchSvrSchSvr.exe"WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
XHomeAVhomeav.exe"Home Personal Antivirus rogue security software - not recommended
XHost Processsvchost.exe"Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
XHostname Manager Serverhost32srv.exe"Added by a variant of the RBOT WORM!"
Xhostservhostserv.exe"Added by the RBOT.BPZ WORM!"
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
XHostSrvsachostx.exe"Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
XHostSrvsachostx.exe"Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
XHostSrvsachostx.exe..."Added by the LOOKSKY.E WORM!"
XHostSVC syseHostSVC.exe"Added by the RBOT-ANZ WORM!"
XHot 8.0 Livehot.exe"Added by the BANKER.EIE TROJAN!"
XHOT FIXView.exe"Added by the WOOTBOT.BN WORM!"
XHot InsideHottest Story Ever.exe"Added by the BHARAT.A WORM!"
Xhotdlllvmmreg32.exe"BANKER.DX spyware"
XHotfix Updatsvdhost32.exe"Added by the GAOBOT.ZW WORM!"
Xhotwetlovehotwetlove.exeAdult content dialler. Will not uninstall - components have to be manually deleted
UHoverDeskHoverDesk.exe"HoverDesk - desktop replacement software"
NHP CD-DVDhpcdtray.exeSystem Tray access to a HP CD-Writer's functions. Available via Start -> Programs
NHP JetDiscoveryHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
?HP Port Resolverhpbpro.exe"??"
XHP Service Drivershdsys.exe"Added by the SDBOT-ZE WORM!"
?hp Silent ServiceHpSrvUI.exe"HP related"
?HP Status Serverhpboid.exe"Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?"
UHP TV NowHpTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
?HP Visualize InitHpVisIni.exe"HP Visualize software related. What does it do and is it required?"
UHPADVISORHPAdvisor.exeHP Total Care Advisor - a suite of help and hardware check programs to help you check the health of your PCs
Nhpaiodevicehpodev07.exe"Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
UHPGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
XHPl Serviceshmlsvc32.exe"Added by the AGOBOT-SI WORM and variants!"
UHPLaptopGamesActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UHPMVTrayHPMVTray.exe"HP Media Vault Networked Storage Device - System Tray management utility"
XHpPrinterhpserver.exe"Added by the CMJSPY-W TROJAN!"
UHPPWRSAVHPPWRSAV.EXE"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com
UHPSCANMonitorhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
Uhpsysdrvhpsysdrv.exe"This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP
NHPUProvenTactics.exe"Proven Internet Marketing software"
XHQI Serviceshqisvc32.exe"Added by the AGOBOT-RO WORM!"
XHQI Serviceshqlsvc32.exe"Added by the AGOBOT-RP WORM!"
UHREF.OCXregsvr32.exe ....HREF.OCX"HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
XHrn_qtvhrnsvc32.exe"Added by the SDBOT-AET WORM!"
XHservicemsservice.exe"Added by the AUTORUN-KL WORM!"
XHtProtectAVprotect.exe"Added by the NETSKY.L WORM!"
Xhtssv32.exehtssv32.exe"Added by a variant of the SDBOT TROJAN!"
XHTTP Tunneling Servermstunnel.exe"Added by the RBOT.EDL WORM!"
Xhttp://www.lienvandekelder.beLienVandeKelder.exe"Added by the MYTOB-AZ WORM!"
Xhttp://www.lienvandekelder.beLien Van de Kelder.exe"Added by the MYTOB-AP WORM and variants!"
Xhttp://www.lienvandekelder.beLien Vande Kelder.exe"Added by the MYTOB-AQ WORM!"
Xhttp://www.lienvandekelder.beLien vd Kelder.exe"Added by the MYTOB-M WORM!"
Xhttp://www.lienvandekelder.beLien.exe"Added by the MYTOB-CZ WORM!"
Xhttp://www.lienvandekelder.beLientjeuh.exe"Added by the MYTOB-P WORM!"
Xhttp://www.lienvandekelder.beLienVdK.exe"Added by the MYTOB-U WORM!"
Xhttp://www.lienvandekelder.beVan de Kelder Lien.exe"Added by the MYTOB-BF WORM!"
Xhttp://www.lienvandekelder.beWe Love Lien Van de Kelder.exe"Added by the MYTOB-CV WORM!"
Xhttp://www.lienvandekelder.comLien Van de Kelder.exe"Added by the MYTOB-EQ WORM!"
Xhttp://www.lienvandekelder.com/LienVandeKelder.exe"Added by the MYTOB-EO WORM!"
XhuigeziHgzServer.exe"Added by the GRAYBIRD.C TROJAN!"
XhuigeziSP00LSV.EXE"Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
XHvewsveqmgANACON.EXE"Added by the NACO.A WORM!"
XHvidHvid.exe"Added by the GEMA TROJAN!"
UHydarVisionDesktopManagerdesk95.exe"ATI's HydraVision desktop management software
UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionDesktopManagerHydraDM.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes
UHydraVisionViewportviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
UHydraVisionViewPortHydraMD.exe"Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates
XI am not Ranky. I am eTunnel!msyervice.exeAdded by an unidentified WORM or TROJAN!
XI just want to say I love Milko and I need a drinksvchost.exe"Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
XI/O Controllerssvcnet.exe"Added by the TIBIK-B TROJAN!"
?IaNvSrvIaNvSrv.exe"Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
XIBM Keyboard Driverikeybdrv.exe"Added by the SDBOT.IC TROJAN!"
UIbmpmsvcibmpmsvc.exe"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn
XicasServicasServ.exe"Browser hijacker
NIconsaverIconsaver.exe"IconSaver is a desktop icon manager"
XICQICQNET.vbs"Added by the GORMLEZ-A WORM!"
XICQ Chat Serviceicqjdhs.exe"Added by a variant of the RBOT WORM!"
Xicq litescvhost.exe"Added by the AGENT-DSF TROJAN!"
NICQ Plusvplus.exe"ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
Xicrosof Avps32 Controlav32.pif"Added by the RBOT-AVC WORM!"
Xicrosoft Visualplscx.exe"Added by the RBOT-AYO WORM!"
Xicrosoft Visual InterDevczvslmqb.exe"Added by the RBOT-AYP WORM!"
Xicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AER WORM!"
Xicrosoftf Avpx Controlavpx.exe"Added by the RBOT-AYN WORM!"
NICServerIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
XICU-SuckerService32.exe"Added by the ILLNOTIFIER.D TROJAN!"
NIC_KEY_3spvic.exe"Instant Chess related"
UIDriveE StartupIDrvieEStartup.exe"IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
XIE Java Updateiejava.exe"Added by the AGENT-HD TROJAN!"
XIECheckmssvp.exe"Added by the TIRBOT-G WORM!"
XIEDriverIEDriver.exe"IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze"
XIEDriverxplore.exe"IeDriver adware variant"
XIEDriverTD.exe"IeDriver adware variant"
Xieharv.exeieharv.exe"Added by the BANKER-HH TROJAN!"
UIEServerIEServer.exe"HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself"
XIEService.exeIEService.exe"FastFind adware variant"
XIEWinservwinserv.exe"Added by the BANKER-MY TROJAN!"
XIExploersvshosts.exe"Added by the IRCBOT.BT TROJAN!"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
Xifperxxmliwvug.exe"Added by the SLAPER.U TROJAN!"
Xigfxtrassvchots.exe"Added by the AUTORUN-AIW WORM!"
?IglpbvIglpbv.exe"??"
Xiisversiisvers.exeAdded by an unidentified TROJAN or adware
Xiiuyvyuuzcx.exe"Added by the AGENT-EOF TROJAN!"
YIJ75P2PSERVERIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
YIKE Service 95IKEService.exe"Associated with PGP. The PGP Tray can be disabled
XImage Remote Playerssysvn.exe"Added by a variant of the IRCBOT BACKDOOR!"
UImageDrive-{hex numbers}ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
XIMClassSvhosl.exeAdded by an unidentified WORM or TROJAN!
Ximcsslxmliwvug.exe"Added by the SLAPER.U TROJAN!"
XIMEvtMgr.exeIMEvtMgr.exe"Added by the KEYLOG-AR TROJAN!"
XIMprocessIM-svr.EXE"IMNames adware"
UIMVUIMVUClient.exe"IMVU chat client that allows you to create ""your own avatars who chat in animated 3D scenes"""
Ximwinsrvcacpmonsrv.exe"Added by the SLAPER.E TROJAN!"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
XIncredible KeyloggerAdvKeylog.exe"IncredibleKeylogger spyware"
XIndex Servicedllhost32.exe"Added by the AGOBOT.CH WORM!"
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
Xinesvchosts.exe"Added by the RBOT.BNL WORM!"
XInet Deliveryinetdl.exe"Inet Delivery adware"
XInet Deliveryinetdl_2.exe"Inet Delivery adware"
XInetChkms[random value].exe"Added by the AGENT-IRL TROJAN!"
XInetServiceswsock32.exe"Added by the WOCK32-A TROJAN!"
XInfeStopInfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
XiNoticeiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
XInstallProvidernewsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Accessmwsrvacc.exe"InstantAccess premium rate adult content dialer"
XInstant Accesslinewsrv.exe"InstantAccess premium rate adult content dialer variant"
XInstant Messenger Serviceimservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
UInstantDriveInstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
XIntec Service Driversmsmsgrs.exe"Added by the SDBOT-ADN WORM!"
XIntec Service Drivers[path to worm]"Added by the RBOT-GLU WORM!"
XIntec Service Driverswing32.exe"Added by the RBOT.HAZ WORM!"
XIntec Service Driversmsmsgredss.exe"Added by the SDBOT-AGL WORM!"
XIntec Services Driverrswinrvc.exe"Added by a variant of the SDBOT WORM!"
XIntec Services Driversmsupdate22e.exe"Added by the RBOT-CGC WORM!"
UIntel Active Monitorimontray.exe"System tray monitoring of fans
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
XIntel Drivercsrs.exe"Added by a variant of the SDBOT WORM!"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
XIntel Service Driversmsconfig16.exe"Added by the MSCONFIG16 TROJAN!"
XIntel system toolsvehost.exe"Added by the AGENT-EBT TROJAN!"
XIntelli Mouse Pro Version 2.0Bncsjapi32.exe"Added by the BUZUS-O WORM!"
XIntelprcAas3lovu.exe"Added by the SILLYFDC-CG WORM!"
UIntelZeroConfigZCfgSvc.exe"Zero Config MFC Application
?Intense Registry ServiceIntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
XInternatmsgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
XInternet AntivirusIAvir.exe"Internet Antivirus rogue security software - not recommended
XInternet Antivirus ProIAPro.exe"Internet Antivirus Pro rogue security software - not recommended
XInternet Application DriverexpIorer.exe"Added by the IRCBOT-WK TROJAN!"
XInternet Configsvchosts.exe"Added by the SDBOT TROJAN!"
XInternet Connection Wizardstisvsq.exe"EasySearch adware"
XInternet Connection Wizardstisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet download manager serviceidman.exe"Added by the RBOT-BMS WORM!"
XInternet Exploere Servicesurlmon32.dll.exe"Added by the EVIAN.C WORM!"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Mail and Newsmsqdevl.exe"EasySearch adware"
XInternet Mail and Newsmsqdevl1.exe"Added by the DLOADR-AWD TROJAN!"
XInternet Security Servicemsq32.exe"Added by the RBOT-GFP WORM!"
XInternet Security Servicemsq23.exe"Added by the RBOT-GQL WORM!"
XInternet Security Servicemsql23.exe"Added by the RBOT-GML WORM!"
XInternet Security Servicemysqlwin32.exe"Added by the RBOT.UX TROJAN!"
XInternet Security Serviceexpllorer.exe"Added by the REFROSO.AFF TROJAN!"
XInternet Serverinetsrv.exe"Added by the STARTPA-EM TROJAN!"
XInternet Serviceintersvc.exe"Added by the SPYBOT-DE WORM!"
Xinternet servicesyscfg32.exe"Added by the RBOT-QS WORM!"
Xinternet servicessvhost.exe"Added by a variant of the RBOT WORM!"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XInternet Servicessystemdev.exe"Added by the SDBOT-PW WORM!"
XInternet Servicesinternet.exe"Added by the MYTOB.BT WORM!"
XInternet Servicesinterserv.exe"Added by the RBOT.BNT WORM!"
XInternet ServicesNetsvc.exe"Added by the MYTOB.MN WORM!"
XINTERNET SERVISESwinz32.exe"Added by the KWBOT.Z WORM!"
YInternet Sharing Serveriss_srvr.exe"Intel AnyPoint internet sharing software. Now discontinued"
Xinternet.exeyinyin3345.vbs"Added by the YINI MACRO!"
XINTERNET_SERVISESwinz32.exe"Added by the SDBOT.Q TROJAN!"
XInterUWINDRV.EXE"Added by the IRCINTER.A TROJAN!"
NIntervideo Win Cinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo Win Cinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWinCinemaMgr.exe"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinCinema ManagerWINCIN~1.EXE"WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
NIntervideo WinSchedulerWinScheduler.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NIntervideo WinSchedulerSchSvr.exe"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NInterVoipInterVoip.exe"InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
UInventory ScanLDISCN32.EXE"LANDesk® Management Suite software component"
Yiolo AntiVirusioloAV.exe"iolo AntiVirus"
UIomega Drive IconsIMGICON.EXE"Displays Iomega icons in Explorer/My Computer
XIP Packet Redirect Serviceipredirect.exe"Added by the FORBOT.SM WORM!"
XIPConfigsvcxnv32.exe"Added by the HACARMY.E TROJAN!"
XIPConfigsvcxnw32.exe"Added by a variant of the HACARMY.E TROJAN!"
XIpnukerIpnuker.vbs"Added by the INKER.B WORM!"
XiPOD USB DriverIPODUSB.EXE"Added by a variant of the RBOT WORM!"
XiPod USB ServiceiPODService.exe"Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service
XIPOT Service Driverscompaq.exe"Added by a variant of the FUROOTKIT TROJAN!"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
XIPv6 Helper Drivercsass.exe"Added by the AGOBOT.TC WORM!"
XIPv6 STUN Servicenetstun.exe"Added by a variant of the SDBOT WORM!"
UIr41_32.axregsvr32.exe Ir41_32.ax"Intel® Indeo® video 4.4 Decompression Filter related. The ""Ir41_32.ax"" file is located in %System%"
NiRis Active Monitorwinmon32.exe"Iris Antivirus - discontinued
NiRiS AntiVirus Active MonitorWIMMUN32.exe"Iris Antivirus - discontinued
UiRiver AutoDBMLService.exe"Associated with the iRiver Music Manager"
NiRiver UpdaterUpdater.exe"Updates for the iRiver Music Manager - used with their digital music players"
XiSafeAViSafeAV.exe"iSafe AntiVirus rogue security software - not recommended
XISPSERVICEpsycho.exe"Added by the IRCFLOOD-O TROJAN!"
XISPSERVICEwintmp.exe"Added by the IRCBOT.GP BACKDOOR!"
XIsrafelIsrafel.vbs"Added by the GAGGLE.D or GAGGLE.E WORMS!"
XissEnc32SvrissEnc32.exe"Added by a variant of the RBOT WORM!"
NISSI EZUpdate Serviceissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching
YISSVCISSVC.exePart of Norton Internet Security Suite
XIST Serviceistsvc.exe"ISTBar adware"
Xist service uninstall[random filename]"ISTBar adware related"
Xiviv.exe"Part of the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
XivHosttaskManager.exe"Added by a variant of the SPYBOT WORM! See here"
XivHost[6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
NIVPServiceMgrivpsvmgr.exe"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as
Xivy.exeivy.exe"Added by the AGENT-ENZ TROJAN!"
Xiyelejivyujixit.exe"Added by the SDBOT.BJK WORM!"
XJA Cfg Util v2jacfg2.exe"Added by the RBOT-AL WORM!"
Xjavaremote.cmd"Added by the BANKER-EHG TROJAN!"
Xjavasystem.exe"Added by a variant of the IRCBOT BACKDOOR!"
XJava (VM) v6.9jav.bat"Added by the AGENT-GZK TROJAN!"
XJava appletjavaup.exe"Added by the SDBOT-ACF WORM!"
XJava Applicationvssmf32.exe"Added by the SPIGOT BACKDOOR!"
XJava Auto Updateujm.exe"Added by the SDBOT-ADH WORM!"
XJava Runtime Environmentjbuild.exe"Added by the DELBOT-J WORM!"
XJava Runtime Valuerunjava.exe"Added by the RBOT-DDJ WORM!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XJava SofteJava32.com"Added by the RBOT.ECN WORM!"
XJava updatejavaqs.exe"Added by the SWARLEY.A WORM!"
XJava Updatekeeper.exe"Added by the AGENT-DIS TROJAN!"
XJava Updatesvchost.exe.exe"Added by the AGENT-LBS TROJAN!"
XJava Updatehostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
XJava Virtual Machinejavaw.exe"Added by a variant of the RBOT WORM!"
XJava VM v6.9.2jav.bat"Added by the DWNLDR-HLM TROJAN!"
XJava VM v6.91jav.bat"Added by the DWNLDR-HLL TROJAN!"
NJava(TM) Platform SE 6jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
NJava(TM) Platform SE 6 U*jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now. U* represents the update version
NJava(TM) Platform SE Auto Updater 2 0jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
XJava**.exe [* = random char]Java**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
XJava**32.exe [* = random char]Java**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
Xjava-pluginjavasctp.exe"Added by the VB.AMX TROJAN!"
XJava32 Configuration Loadermsnmesgr.exe"Added by a variant of the RBOT WORM!"
XJavaCoreJavaCore.exe"Added by the MATCASH TROJAN!"
XJavascriptjscript.exe"Added by the DELBOT-AD WORM!"
XJavaScript Debugging ServiceJsDbgMan.exe"Added by the DERDERO.E WORM!"
XJavaScriptMsxrsMsxrs.exe"Added by the VB.BL WORM!"
XJavaTraytraymgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
XJavaUpdateSchedjusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
XJavaVMjava.exe"Added by the MYDOOM.M WORM and variants! Note - not to be confused with the valid Windows ""java.exe"" which is located in %System% as this is located in %Windir%"
Xjavawsa.exejavawsa.exe"Added by the BANK-Y TROJAN!"
YJetAdmin Discovery IndicatorHPJETDSC.EXE"HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry
Xjiahussvchqs.exe"Added by the WOWPWS-AL TROJAN!"
Xjmudkve.dll"rundll32.exe jmudkve.dllmzrwkwf"
UJob-oversigttaskmon.exe"Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
UJog ServeJogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
UJogServ2JogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
Xjohkjhsrvd.exe"Added by a variant of the SLAPER TROJAN!"
Xjohn315srrvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj315srvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj3155srvcc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
Xjohnj3cdsrvdc.exe"Added by a variant of the SLAPER TROJAN!"
XJufualtsvhost.exe"Added by the SDBOT-ADJ WORM!"
XJufualtjava2.exe"Added by the SDBOT.AOE WORM!"
Xjusodlsevere.exe"Added by the QQPASS.48436 TROJAN!"
NJustVoipJustVoip.exe"JustVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
Ujv16 PT TempFileToolTempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
Ujv16PT - Privacy ProtectorTask.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer
UJv16pt Network Residentjv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
XJvcHostjvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
Xjvdnlssnfljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
XJVM0JVM0.exe"Added by the BANLOA-AX TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjvms.exejvms.exe"Added by the ORCU.B TROJAN!"
Xjzvfvsqpcjzvfvsqpc.exe"Added by the AGENT-GWP BACKDOOR!"
XkaaSVCHHS.exe"Added by the AGENT-JKP TROJAN!"
Xkalvsyskalv****.exe [* = random char]"EliteBar adware"
Xkalvsyskalv***32.exe [* = random char]"EliteBar adware"
Xkamsoftckvo.exe"Added by the GAMANIA-BW TROJAN!"
XKasper AntivirusKASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
YKaspersky Anti-HackerKAVPF.exe"Kaspersky Anti-Hacker personal firewall - no longer available"
YKaspersky Anti-Virus MonitorAvpM.exe"Kaspersky Anti-Virus Lite - no longer available"
XKaspersky AntivirusKasperskyAV.exe"Added by a variant of the RBOT WORM!"
XKaspersky Email Securityjavaupd.exe"Added by the SWARLEY.A WORM!"
XKasperskyAvkaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus"
XKasperskyAVEngKasperskyaveng.exe"Added by the NETSKY.V WORM!"
XKATKAT.vbs"Added by the SOAD-D WORM!"
Ykavavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
Xkavakavo.exe"Added by the LINEAG-GLG TROJAN!"
XKAVFOXwin1ogoin.exe"Added by the GWGHOST-M TROJAN!"
Xkavirkavir.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XKAVPersonalsvchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
YKAVPersonal50Kav.exe"Kaspersky Anti-Virus Personal 5.0"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
YKavPFWKavPFW.exe"KingSoft Personal Firewall"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
YKavStartKAVStart.exe"KingSoft Personal Firewall"
Ykavsvckavsvc.exe"Kaspersky antivirus"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
Xkavsvc[random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
XKAVutil[worm filename]"Added by the WINTOO.B WORM!"
XKazaa Download Accelerator Updater (required)regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
Xkbddrv32kbddrv32.exe"Added by the CRYPTER.A TROJAN!"
Xkbddrvinfkbddrvinf.exe"Added by the CRYPTER.A TROJAN!"
XKeenvalueKeenvalue.exe"KeenVal adware"
UKerio VPN Clientkvpnclient.exe"Kerio VPN Client"
XKernelservices.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XKernel Servicesservice32.exe"Added by the PRX-B TROJAN!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
Xkernel32kernel32.dll.vbs"Added by the WEKODE-A WORM!"
XKernel32svchosts.exeAdded by an unidentified WORM or TROJAN!
XKernel32svchost.exe"Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\drivers"
XKernellAppssvshosti.exe"Added by the BANCBAN-V TROJAN!"
XKernel_checkwmiprvse.exe"Added by the SONEBOT-B WORM! Note - this is not the legitimate wmiprvse.exe process which is always located in the %System%\wbem folder and should not normally figure in Msconfig/Startup!"
?Key2serve.exe"??"
Xkeyservkeyserv.exe"KeyThief spyware"
XKKM Servicekkm.exe"Added by the NANPY-I WORM!"
XKL AntiFunLoveflcss.exe"Added by the FUNLOVE.4099 VIRUS!"
YKPDrv4XPKPDrv4XP.exeMediaKey USB Keypad Driver
YKPFWSvc.EXEKPFWSvc.EXE"KingSoft Personal Firewall"
XKsrv32Ksrv32.exe"Added by the AGOBOT-PI WORM!"
XKV2005word.EXE"Added by the VB-IW TROJAN!"
Xkv3000lover.vbe"Added by the ZSYANG.B WORM!"
Xkvasoftkva8wr.exe"Added by the ONLINEG.ICC WORM!"
Xkvern16.dllregsvr32.exe kvern16.dll"DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The ""kvern16.dll"" file is found in %System%"
Xkviurskav.exe"Added by the SILLYFDC.BBJ WORM!"
XKvmSecure.exeKvmSecure.exe"KvmSecure rogue security software - not recommended
XKvsc3Kvsc3.exe"Added by the PWS-ANM TROJAN!"
XKV_HOSTcxjx.exe"Added by the LEGMIR-BB TROJAN!"
XKYK Control SettingsKYSVCXD.EXE"Added by a variant of the RBOT WORM!"
XLAN Driverlandriver32.exe"Added by the RBOT.BT WORM!"
ULANDeskInventoryClientLDIScn32.exe"LANDesk® Management Suite software component"
XLARISSA ANTI VIRUSLARISSA_ANTI_VIRUS.exe"Added by the KLASSIR TROJAN!"
XLaserJetspoolvs.exe"Added by the DLOADER.PFR TROJAN! This is not the file of the same name from older versions of MS Office - see the link for the location"
ULaunch Ai BoosterOverClk.exe"Included with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme)
?Launch LgDeviceAgentLgDevAgt.exe"Part of the GamePanel Software for the Logitech G-Series of gaming keyboards. What does it do and is it required?"
XLaunch Norton AntiVirus 2000jorgf.exe"Added by the RBOT-AUI WORM!"
XLavasoft Ad-AwareAd-Aware.exe"Added by the RBOT-SO WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
ULavasoft AdwatchAd-watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
XLayersecurity ServicemonitorLSSMON.EXE"Added by the BANKER.ZAQ TROJAN!"
Xlayersldmhostplsrvc.exe"Added by a variant of the SDBOT WORM!"
Xlcvgalcvga.exe"Added by the HOSTOL-A TROJAN!"
Xldriverldriver.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
ULELALinksys EasyLink Advisor.exe"System Tray access to Linksys EaasyLink Advisor - which ""is designed to set up your home network. LELA can locate computers
XLEMSRVlemsrv.exe"Added by the IRCBOT-TC TROJAN!"
ULENOVO.TPFNF6RTPFNF6R.exeSupports the Fn+F6 hotkey combination on IBM/Lenovo Thinkpad notebooks which mutes the microphone
NLenovoOobeOffersLenovoOobeOffers.exe"Displays product upgrades/offers from Lenovo on the first run of a new notebook/desktop. ""Oobe"" refers to the ""Out of box experience"""
ULexmark 2200 Serieslxbvbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 2200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan
ULexmark 5000 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 6500 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 7600 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 9300 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULG Direct Media Button ServiceLGDMEBTN.exe"Supports the Direct Media button on LG Notebooks that support it - such as the S1 PRO EXPRESS DUAL. Pressing this button launches the application for watching movies or listening to music"
?LgDevAgtLgDevAgt.exe"Part of the GamePanel Software for the Logitech G-Series of gaming keyboards. What does it do and is it required?"
Xli-rcash00001vldial.exe"Added by the Vl TROJAN!"
Xli-vita****li-vita****.exeAdult web-dialler - **** is random
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
XLife Personal FirewallFirewallingV10.exe"Added by the RBOT-BKF WORM!"
NLifeDrive ManagerLifeDriveMgr.exe"Keeps the Palm LifeDrive Manager utility in the systray. Shortcut available via Start -> Programs"
ULifeDrive? ManagerLifeDriveMgrTray.exe"System Tray utility for the Palm LifeDrive Mobile Manager"
?LightFrame 3LightFrameV3.exe"Support software for Philips range of LCD Monitors that support LightFrame™ - which ""reduces eye strain by surrounding your monitor frame with blue light that stimulates your visual senses for improved concentration and promotes an overall feeling of wellbeing"". What does it do and is it required?"
NLine Speed Meter V3.0LineSpeedMeter.exe"LineSpeedMeter - detect the download and upload speed of your internet connection"
ULingvo LauncherLvagent.exe"ABBYY Lingvo Electronic Dictionaries"
ULingvoTrainingTutor.exe"ABBYY Lingvo Electronic Dictionaries"
XLinksys Modem Driverslinksys.exeAdded by the IRCBOT.VD WORM!
XLinuxLinux.vbs"Added by the LOVELETTER.AS VIRUS!"
ULiquidViewlviewj.exe"""Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display's native resolution. The software lets you increase the size of items that are hard to read on your monitor"""
NLive MenuDllcmd32.exe"eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here"
XLive Messangerlivemsgr.exe"Added by the RBOT.BXX WORM!"
XLive Messangerwllmsngr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive PC CareLP[random characters].exe"Live PC Care rogue security software - not recommended
?live rdrloadloud.exe"??"
XLive Security SuiteLiveSS.exe"Live Security Suite rogue security software - not recommended
XLive update monitorsrvany32.exe"Added by the AGOBOT.AFM WORM!"
Xlive update monitorumxlu32.exe"Added by the AGOBOT.ADK WORM!"
XLive Windows Messenger Versionmsnmessage7.7.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XLive Windows Messenger Versionmsnmsngrlive.exe"Added by a variant of the IRCBOT BACKDOOR!"
XLive-Helplmns.exe"Added by the RBOT-GHE WORM!"
XLive-Messenger.exeLive-Messenger.exe"Added by the SILLYP2P WORM!"
XLiveAntispyLiveAntispy.exe"LiveAntispy rogue security software - not recommended
Xlivekeywebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
Xlivekeyswebgrade.exe"LiveKeys adware. File located in %Program Files%\livekey\livekeys"
NLiveMonitorLMonitor.exeMSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information
NLiveNoteLivenote.exeAsus graphics card driver live update feature
XLiveProtectLiveProtect.exe"System Live Protect rogue security software - not recommended
XLiveSexCamsLiveSexCams.exePremium rate adult content dialler
ULiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
XLiveUpdatesmss.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
NLiveUpdateCopyer.exe"Samsung PC Studio is a Windows-based PC program package that you can use easily to manage personal data and multimedia files by connecting a Samsung Electronics Mobile phone (GSM/GPRS/UMTS) to your PC. You can launch the update manually - see the instructions
XLiveUpdate32services.exe"Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
XLivreDibane.bat"Added by the BANEDI VIRUS!"
?lmpdpsrvlmpdpsrv.exe"Related to a Lexmark printer/scanner. Printer sharing server? Is it required?"
Xloadsvhost32.exe"Added by the WOWCRAFT TROJAN!"
Xloadsvchsot.exe"Added by the GWGHOST-O TROJAN!"
XloadSystemfile.dll.vbs"Added by an unidentified WORM or TROJAN! See here"
XLoad ServiceSvHost.exe"Added by the PESIN-D WORM!"
XLoad-GuardWscript.exe LGuarg.exe.vbs"Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
Nload=vi_grm.exeMonitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
Yload=Bfrecv.exeBitware modem driver
Xload=Spoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
Xload=svhost32.exe"Added by the LINEAGE-AB TROJAN!"
YLoadDvpApi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
XLoadFontsLoadFonts.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadFontsTahoma.vbsHomepage hijacker that changes your homepage to an adult content site
XLoadHTML"rundll32.exe regsvr32.exeMShtmpre"
NLoadMSvcmmmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XLoadOrderVerification[random filename]"Added by the TRON.A TROJAN!"
XLoadServiceRest In Peace"Added by the KANGAROO-A WORM!"
XLoadService"Maaf tempatmu bukan di sin"
XLoadServiceVirus"Added by the CAGER.A WORM!"
XLocal Authority Servicelsass.exe"Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLOCAL INTERNET WEB DRIVERS FOR WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
XLocal runole servicesrvc32.exe"Added by the SMALL-DP TROJAN!"
XLocal Security Authority Servcelssas.exe"Added by the POEBOT-T WORM!"
XLocal Security Authority Servicelssas.exe"Added by the POEBOT-J WORM!"
XLocal Security Authority ServiceIsass.exe"Added by the LINKBOT.M WORM!"
XLocal ServiceIntenat.exe"Added by the NUCLEAR-J TROJAN!"
XLocal Serviceservices.exe"Added by the P2PWORM-T WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Cursors"
XLocalSystemsvchost.exe"EHU adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XLocator Service[filename]"Added by the AGOBOT-KY TROJAN!"
XLogical Disk Detectionmrisvc.exe"Added by the IRCBOT.AOW BACKDOOR!"
XLogin Screen Saverlogin.scr"Added by the RBOT-AVN WORM!"
XLogin Service[path to file]"Added by the MIGMAF TROJAN!"
ULogitech ClickSmartLVCOMS.EXEEntry added when you install Logitech ClickSmart webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech ImageStudioLVCOMS.EXEEntry added when you install Logitech ImageStudio webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech QuickCamLVCOMS.EXEEntry added when you install older versions of Logitech QuickCam webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
ULogitech QuickCamLVComSX.exeEntry added when you install versions of the Logitech QuickCam webcam software - allows the full camera features (such as face tracking) to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
NLogitech VidVid.exe"""Logitech Vid™ is the fast
?LogitechCameraService(E)ElkCtrl.exeEntry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
YLogitechRegisterVideoApplicationsInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software
ULogitechVideoRepairISStart.exe"Installed with Logitech's QuickSmart and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present
ULogitechVideoTrayLogiTray.exe"System Tray access to My Logitech Pictures
ULogitechVideo[inspector]InstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications
XLogServicewincalc.exe"Added by the PAPROXY TROJAN!"
XLogServicelsass.exe"Added by the BDOOR-IU BACKDOOR! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XLogServicelsrss.exe"Added by the PAPROXY-D TROJAN!"
ULogServiceLogService.exe"SmartKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!"
XLOVELOVE.EXE"Added by the VB-ZQ TROJAN!"
XLoveHebeAvistaAA.exe"Added by the LOZAVITA TROJAN!"
NLowRateVoipLowRateVoip.exe"LowRateVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XLowVersionSupport[filename]"Added by the LASTRAS TROJAN!"
XLSA ServiceLSASS.exe"Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process
Xlsa Serviceslsa2srv.exe"Added by the TAME-C WORM!"
XLSA Shell (Export Version)LSASS.exe"Added by the AHKER.K WORM and variants. Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xlsasslsasrv.exe"Added by the MYDOOM.AG or MYDOOM.AS or MYDOOM.AU WORMS!"
XLsasskavmm.exe"Added by an unidentified WORM or TROJAN! NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here. Contrary to this impostor
XLSASS Authoritylsvhosts.exe"Added by the SDBOT.BCE WORM!"
Xlsass servicelsass2.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XLSvrLSvr.exe"PowerStrip foistware. Note - this is not the same as the video tweaking utility of the same name here"
XLTM2MSGSRV32.EXE"Added by the LITMUS.A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup! This one is located in %Windir%\Litmus"
XLTM2MPGSRV32.EXE"Added by the LITMUS.201 TROJAN!"
XLTM2MSGSRV320.EXE"Added by the LITMUS.C TROJAN!"
XLTM2MSGSSV32.EXE"Added by the FC.C TROJAN!"
XLTM2SVCHOST32.exe"Added by the LITMUS.203B TROJAN!"
XLTM2SVCHOSTÿ.exe"Added by the DROPPERFL.A TROJAN!"
XLTM2winvers16.exe"Added by the SMALL.ND TROJAN!"
Xltssvc"rundll32.exe ltssvc.dllstart"
ULVCOMSLVCOMS.EXE"Entry added when you install Logitech's ClickSmart
ULVCOMSXLVComSX.exeEntry added when you install versions of the Logitech QuickCam webcam software - allows the full camera features (such as face tracking) to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
Ulxdvamonlxdvamon.exeLexmark X5400 Series printer device monitor
Ulxdvmon.exelxdvmon.exeLexmark X5400 Series printer device monitor
XM S DVD DirectX Dll Driversmsxdl.exe"Added by the SDBOT-BJN WORM!"
XM3Development_WhenUSave_InstallerM3Development_WhenUSave_Installer.exe"WhenU.Save adware"
UMacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMacDrive applicationMacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
Xmachine-debuggerWMIPRVSW.exe"Added by the AGOBOT.WW WORM!"
Xmachine-debuggermdmsv.exe"Added by the AGOBOT-BR WORM!"
XMacromedia Dreamweaver XMmacdwXM.exe"Added by the AGOBOT-RI WORM!"
XMacromedia DriveIexplor32.exe"Added by a variant of the RBOT WORM!"
XMacromedia Flash Updatescvhost.exe"Added by a variant of the RBOT WORM!"
NMacrovision Update Serviceissch.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
NMacrovision Update ServiceISUSPM.exe"InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
UMACVNTFYMACVNTFY.EXE"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMailbox Verifiermboxvrfy.exe"Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)"
XMainStartsvcmfte32.exe"Added by the STINX-A TROJAN!"
Xmainviewexmainviewex.exe"Added by the GEMA.D TROJAN!"
Xmain_moduledrvmmx32.exe"Added by the DILA TROJAN!"
XMajor Microsoft Windows Driver Boot loaderbpool.exe"Added by the MYTOB.AJ WORM!"
YMalwarebytes' RogueRemover PRORogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
XMalwareRemovalMalwareRemoval.exe"Added by a fake version of Microsoft's Malicious Software Removal Tool - removal instructions here"
XMalwareRemovalBotMalwareRemovalBot.exe"MalwareRemovalBot rogue security software - not recommended
XManageProtocolCtrlcsmsv.exe"Added by the LOOKSKY.B TROJAN!"
XManagment Service[random filename]Added by the RBOT.BIS TROJAN!
XMapiDrvmpisvc.exe"Added by the MIPSIV TROJAN!"
Xmapisvc32mapisvc32.exe"Added by the KX VIRUS and also recognised by Symantec as FPAI adware"
Xmark the servicexxtra32.exe"Added by the SDBOT.APP WORM!"
Xmaskridermaskrider2001.vbs"Added by the SOLOW-G WORM!"
NMass storage check registry"rundll32.exe MSDServ.dll check registry"
XMastersvcghost.exe"Added by the IRCBOT.RB TROJAN!"
UMaster Volume SpyMASTERVOLUMESPY.EXE"Volume control for the Gateway Destination ""DestiVu"" media interface"
XMatrixScreenSavermss.exeUnidentified malware
XMAV_checkmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
Xmav_startupmonmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
UMaxBackSchedulemaxbackservice.exeBackup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
XMcAfeeMcAffeAv.exe"Added by the NETSKY.AL WORM!"
XmcafeeWin32.dll.vbs"Added by the CATCHER-B WORM!"
XMcAfee AntivirusMcAfeeAV.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus 32MCAFEEAV32.EXE"Added by the SPYBOT-EH WORM!"
XMcafee Antivirus Monitoring System326VSStatmn326.exe"Added by a variant of the SDBOT WORM!"
XMcafee Antivirus Monitoring System32mnVSStatmn32.exe"Added by a variant of the RBOT WORM!"
XMcAfee Antivirus ProtectionmcafeeAV.exe"Added by a variant of the RBOT WORM!"
YMcAfee Managed Desktop AgentMYAGTSVC.EXE"Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
UMcAfee Managed Services TrayStartMyagtTry.exeSystem tray notification for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
XMcAfee Online virus Scanneravp.exe"Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
XMcAfee Online Virus Scannernzm.exe"Added by the IRCBOT.XV WORM!"
YMcAfee VirusScanmcmnhdlr.exe"Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically
YMcAfee VirusScanmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
YMcAfee VirusScanoasclnt.exe"On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access
XMcafee VirusScan Managermvcsvm.exe"Added by the SILLYFDC.BBV TROJAN!"
YMcAfeeVirusScanServiceAvsynmgr.exe"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe)
XMcaffe AntivirusMcafeescn.exe"Added by a variant of the SPYBOT WORM!"
XMcsoftgfeqzvq.exe"Added by the SDBOT-NV WORM!"
YMcVsRtemcvsrte.exe"Part of older versions of McAfee's internet security products such as VirusScan and VirusScan Online. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
Ymcvsshldmcvsshld.exe"ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed
XMdmMdm.vbs"Added by the WHITEHO VIRUS or TRAPPY WORM!"
XMDNSservice.exe"Mirar adware variant"
UMedia Codec Update Serviceupdate.exe"Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
UMedia Manager IndexerAIRSVCU.EXE"Part of MS Visual InterDev
XMedia Servermsdts.exe"Added by a variant of the IRCBOT TROJAN!"
XMedia Servicemsn64.exe"Added by the SPYBOT.EV WORM!"
XMedia servicemsnmsgxr.exe"Added by the SDBOT.TF WORM!"
XMedia serviceSYSTEM64.EXE"Added by the RBOT.QV WORM!"
XMedia servicenotpad.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMedia Services[filename].exe"Added by the AGENT-BA BACKDOOR!"
XMedia X ServicesMSNGRx.exe"Added by the RBOT.AUL WORM!"
XMedia-XP-Service-Pack3msnzx.exe"Added by the SDBOT-ACW WORM!"
UMediafour Mac Volume NotificationsMACVNTFY.EXE"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour MacDriveMacDrive.exe"MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
UMediafour MacDriveMDDiskProtect.exe"Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediafour MacDriveMDGetStarted.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
UMediafourGettingStartedWithMacDrive6MacDrive.exe"MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7
UMediaLifeServiceMediaLifeService.exe"Related to MediaPlay Cordless Mouse from Logitech"
XMediaXPServicePackmxpsp.exe"Added by the SDBOT.CDT WORM!"
?MedionVFDMdionLCM.exe"Related to Medion Display Information. What does it do and is it required?"
XMegaVirusKitpgs.exe"MegaVirusKit rogue security software - not recommended. A member of the AVSystemCare family"
?meidntpavqgdpfrs.exe"??"
XMemory Allocation Serverciserv.exeAdded by an unidentified malware
XMemory Allocation Servicescisrv.exe"Added by the IRCBOT.FC BACKDOOR!"
XMemory relocation servicereloc32.exe"Added by the RELFEERWORM!"
XMemory Servicefreememory.exeAdded by the RBOT.GEN WORM!
NMessagerStarter FreeserveStartMessager.exeFreeserve Messenger
XMessenger Servicemsmsgs.exe"Added by the SDBOT-ZB WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XMessenger Servicenvhost.exe"Added by the JLOK-A WORM!"
XMessenger Service Updatersvshost.exe"Added by the MYTOB.GC WORM!"
XMessenger Sharing Controlmnwsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UMessengerDiscoveryMessengerDiscovery.exe"MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features. Now superseded by MessengerDiscovery Live - with support added for Windows Live"
XmessngerDvldr32.exe"Added by the DELODER.A WORM!"
Xmfhsornwnduyregsvr32.exe gisyflngpshcvuakv.dll"Pro AntiSpyware 2009 rogue spyware remover - not recommended
YMFP Server AgentMFPAgent.exe"Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
XMfqneqfebvdddwq.exe"Added by the RANDEX.AP WORM!"
Ymgavctrlmgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
Ymgavrtclexemgavrtcl.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
Ymgavrtclexemgavrte.exePart of older versions of McAfee's internet security products such as VirusScan and VirusScan Online
XMgsgi servicewkzfn.exe"Added by the AGOBOT-AHL WORM!"
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicosoft Data Core stuffsvshosts.exe"Added by the RBOT.FZA WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicrcoft Exploerersvchose.exe"Added by the RBOT-ASL WORM!"
XMicrcsoft Certificate Servicescflmon.exe"Added by the RBOT-FWV WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMICROSFT ANTIVIRUS UPDATE SUPPORTMSGUPDATED.EXE"Added by the RBOT-APZ WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMicrosft Updtessarvice.exe"Added by a variant of the SDBOT WORM!"
XMicrosof Valuenmatt.exe"Added by a variant of the RBOT WORM!"
XMicrosof Windows Hostsvhost32.exe"Added by the RBOT.ADY WORM!"
Xmicrosoftsvchost.exe"Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XMicrosoftsvchost.exe"Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoftmsvchost.exe"Added by the RBOT-GAW WORM!"
XMicrosoftrtvcscan.exe"Added by the RBOT-GGU WORM!"
XMicrosoftkasperskyLive32.exe"Added by the RBOT-GRT WORM!"
XMicrosoftnetsrv.exe"Added by the RBOT-GOS WORM!"
XMicrosoftntsvr.exe"Added by a variant of the RBOT WORM!"
XMicrosoftsoundvol32.exe"Added by the RBOT.CIJ BACKDOOR!"
XMicrosoftsqlservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftsvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft (R) Windows Configuration Backup Servicesvchost.exe"Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config""
XMicrosoft (R) Windows Network Latency Controllersp2vc.exe"Added by a generic password stealer TROJAN - see here"
XMicrosoft (R) Windows Network Security Management Servicensms.exe"Added by the RANKY.LC TROJAN!"
XMicrosoft (R) Windows Protected Content Restoration Serviceservices.exe"Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
XMicrosoft (R) Windows TCP/IP Socket Driver[path to trojan]"Added by the PROXY-DD TROJAN!"
XMicrosoft (R) Windows TCP/IP Socket Layerservices.exe"Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
XMicrosoft (R) Windows Update Servicewuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
UMicrosoft ActiveSyncWCESCOMM.EXE"Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier)
XMicrosoft ActiveX Debugger NT[path to trojan]"Added by the BANCOS-DO TROJAN!"
XMicrosoft ADservice[random filename]"Added by a variant of the RBOT WORM!"
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft Anti Virus Controllermsavc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Anti Virus Controllermsavc32.exe"Added by the SDBOT.EPW BACKDOOR!"
XMicrosoft Authority Servicelsass.exe"Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process
XMicrosoft Automatic Update Serivcemsautou.exe"Added by the RBOT-AOB WORM!"
XMicrosoft AutoUpdatersvhost.exe"Added by the RBOT.QG WORM!"
XMicrosoft Bool ValueMV2.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Browser ServicesBrwsr32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Browser ServicesBrwsr64.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft checkerMsPMSPTv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Client Pcspoolsrv.exe"Added by the RBOT-AQM WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Com Port Managersvdhost.exe"Added by the SDBOT-NI WORM!"
XMicrosoft Configoration Servicemsconfigs.exe"Added by the RBOT-ETT WORM!"
XMicrosoft Corpsvchost.exe"Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Corp. Host Servicessvchosl.exe"Added by the RBOT-FMZ WORM!"
XMicrosoft Corporationjview.exe"Added by the RBOT-AOD WORM!"
XMicrosoft Corporation Svchost Servicemssvc.exe"Added by a variant of the SDBOT WORM! See here"
XMicrosoft Corporation Svchost Servicemswsc.exeAdded by the AGENT.MAB TROJAN!
XMicrosoft CPU Over Heat ManagerCPU.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Critical Servicessvhhost.exe"Added by the AGOBOT-AJA WORM!"
XMicrosoft Crs Fix Servwincrs.exe"Added by the SDBOT.BWF WORM!"
XMicrosoft CSRSS Servicensmscrs.exe"Added by the RBOT-BPT WORM!"
XMicrosoft Cvrtmscvrt32.exe"Added by an unidentified VIRUS
XMicrosoft Debug Servicedbgbgr.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Development Debuggermsdev.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Development Servicesmsdevelop.exe"Added by the RBOT-FWS WORM!"
XMicrosoft Device Managermsdevmgr32.exe"Added by the LATEDA.B TROJAN!"
XMicrosoft Device Managermscmtl32.exe"Added by the AGENT.BMQ BACKDOOR!"
XMicrosoft Device Managersvcswin.exe"Added by the IRCBOT-YH TROJAN!"
XMicrosoft DirectXSpoolserv.exe"Added by the DINFOR WORM!"
XMicrosoft dll Host Servicewkssr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft DLL Host Servicedllmemhost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft DLL Host Servicesvcdllhst.exe"Added by the AGENT.EAK TROJAN!"
XMicrosoft dll Host Servicesvchost.exe"Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft DLL Serviceservicedll.exe"Added by the IRCBOT.OX BACKDOOR!"
XMicrosoft DLL Servicesvcdll.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft DLL Verifierfile.exe"Added by the RBOT-AED WORM!"
XMicrosoft DLL Verifierchkfile.exe"Added by the RBOT-AOC WORM!"
XMicrosoft DLL Verifiercsrssv.exe"Added by the RBOT-ATK WORM!"
XMicrosoft DLL Verifiermscon.exe"Added by the SDBOT.EAH WORM!"
XMicrosoft DLL Verifierwinavguard.exeAdded by the SDBOT.AAD WORM!
XMicrosoft DLL Verifierwns.exe"Added by the SPYBOT-LA WORM!"
XMicrosoft Driverfaet.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Driver Controlwindrv.exe"Added by the SDBOT.FW WORM!"
XMicrosoft Driver Managermswindrv.exe"Added by the FORBOT-EZ WORM!"
XMicrosoft Driver Setupmsddrv42.exe"Added by the PALEVO WORM!"
XMicrosoft Driver SetupJwrb.exe"Added by the AUTORUN-AOB WORM!"
XMicrosoft Driver Setupdllhost.exe"Added by the AUTORUN-AOZ WORM!"
XMicrosoft Driver Setupsysmngsr322.exe"Added by the BUZUS-AS TROJAN!"
XMicrosoft Driver Setupw7services.exe"Added by the AUTORUN-ARJ WORM!"
XMicrosoft Driver Setupmslsrv32.exe"Added by the SDBOT-DPF TROJAN!"
XMicrosoft Driver Setupccdrive32.exe"Added by the AGENT-LYL TROJAN!"
XMicrosoft Driver Setupcidrive32.exe"Added by the AGENT-NES TROJAN!"
XMicrosoft driver updateMshome.exeAdded by the SDBOT.BL WORM!
XMicrosoft DriversWSconf.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft EV32 ServiceMSev32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Event EngineEvtEngn.exe"Added by the RBOT-XV WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft FixUppevblbvr.exe"Added by the RBOT.DWK WORM!"
XMicrosoft Genetic Procresssvchost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Genuine Logonsvchost.exe"Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Gina V EncryptionMSGINAV.EXE"Added by an unidentified VIRUS
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Helpsvchosl.exe"Added by the AGENT-GPX TROJAN!"
XMicrosoft Help SVCmsnmngr.exe"Added by the SDBOT-PQ WORM!"
XMicrosoft Host Protocolsvhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Hosting ServiceWINHOSTING.EXE"Added by the RBOT.AEV WORM!"
XMicrosoft Hosts ServiceIsass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Initialization Serviceinitsvc.exe"Added by the IRCBOT.AXK BACKDOOR!"
XMicrosoft Initialization Servicesinitserv.exe"Added by the IRCBOT-ABO TROJAN!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft Int ServiceMsIntSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internal AntiVirus SystemsdIlhost.exe"Added by the RBOT-AEV WORM!"
XMicrosoft Internel Corporatnetvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internel Corporatsmbvhost.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Internet Antivirus Protectionantivirus.exe"Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet ServicesSmss32.exe"Added by the RBOT.MS WORM!"
XMicrosoft IPCsvshost.exe"Added by an unidentified VIRUS
XMicrosoft IT UpdateIEserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft IT Updatesvchsst.exe"Added by the RBOT-DH WORM!"
XMicrosoft Java Virtual MachineMsConfiG.exe"Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
XMicrosoft Java Virtual Machinemsjvm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Java Virtual Machinejavavm.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Java Virtual Machinemsjavarxp.exe"Added by the FORBOT-DL WORM!"
XMicrosoft Java Virtual Machinewinscr32.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Java Windows Update[filename]"Added by the RBOT-DZ WORM!"
XMicrosoft JavaVMmsjarun.exe"Added by the RBOT-JW WORM!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicrosoft Kinetik Svcmsftksvc.exe"Added by the AGENT.AGDO TROJAN!"
XMicroSoft Legal ServiceSrb0ty.exe"Added by the SPYBOT.HW WORM!"
XMicrosoft Lmhosting Servicelmhosts.exe"Added by the RBOT-RC WORM!"
XMicrosoft Lsass Servicewintcp32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft LSASS386 Protocolscvhost32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft LV[path to file]"Added by the BDOOR-BDL BACKDOOR!"
XMicrosoft Machinewinjava.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft machinescvhost.exe"Added by the RBOT.AEU TROJAN!"
XMicrosoft Manage Servicessychost.exe"Added by the SLENFBOT.AD WORM!"
XMicrosoft Manage Servicesschost.exe"Added by the SLENFBOT.B WORM!"
XMicrosoft media servicesIassd.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft media serviceswinmplayer.exe"Added by the RBOT.ZO WORM!"
XMicrosoft Messenger Servicemsmsg32.exe"Added by the RBOT.BOK WORM!"
XMicrosoft Ming Serviceming.exe"Added by the RBOT-AWS WORM!"
XMicrosoft Movie MakerMmaker.exe"Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program"
XMicrosoft MSN 7 Servicesmsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN 7 Servicesmsnmsger.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft MSN Servicesmsnsm.exe"Added by the RBOT.ARV BACKDOOR!"
XMicrosoft MSUPDATESpoolSvc.exe"Added by the SXTB-A TROJAN!"
XMicrosoft Netviewgesfm32.exe"Added by the RANDEX.C WORM!"
XMicrosoft Netviewmssvc32.exe"Added by an unidentified VIRUS
XMicrosoft Netview Component v5.1msnv32.exe"Added by the RANDEX.F WORM!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
XMicrosoft Network Services Controllermmsvc32.exe"Added by the NANPY-A WORM!"
XMicrosoft Nod32 Servicenood32.exe"Added by the RBOT.EJP WORM!"
XMicrosoft Norotn Anti Virusmnhpot.exe"Added by the RBOT-GRO WORM!"
XMicrosoft Norton Antivirusnorton.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft NT Driversntdrv.exeAdded by the SDBOT.AJN TROJAN!
XMicrosoft Nvidia Videonvidia.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Officelserv.exe"Added by the SDBOT.MH WORM!"
XMicrosoft Officesvxhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Officemsvcp.exe"Added by the AGENT-XK TROJAN!"
UMicrosoft Office GrooveGROOVE.EXE"System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively
XMicrosoft Office Studioscvhvst.exe"Added by the RANDEX.CST WORM!"
XMicrosoft Outlook Express Protocolsvchst.exe"Added by a variant of the RBOT WORM!"
XMicrosoft PC Health Remote Assistance File Open & Save controlssfrcdlg32.exe"Added by the RBOT-AVY WORM!"
XMicrosoft Proc Driver32msprc.exe"Added by a variant of the WOOTBOT WORM!"
XMicrosoft Registrosvchostt.exe"Added by the BANCOS-DH TROJAN!"
XMicroSoft Remote Secure ServiceMSRSS.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SCVHOST32 Protocolscvhost32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft SecureMessenger.NET Service"Added by the FORBOT-AM WORM!"
XMicrosoft Secure Messenger.NET Servicesecuritychk.exe"Added by the SDBOT.VT WORM!"
XMicrosoft SecuritywinService.exe"Added by a variant of the RBOT WORM!"
XMicrosoft security advisermssadv.exe"Microsoft Security Adviser rogue security software - not recommended"
XMicrosoft Security Centersavservices.exe"Added by the RBOT-ANU WORM!"
XMicrosoft Security Managementwinserv.exe"Added by the RBOT-MJ WORM!"
XMicrosoft Security Monitor Processservice.exe"Added by the DELF.BERW BACKDOOR!"
XMicrosoft Security Monitor Processsvcchost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Serverrserv.exe"Added by the AGOBOT.AVS WORM!"
XMicrosoft Server Applacationsmsnmsg.exe"Added by the AGOBOT.BBM WORM!"
XMicrosoft Server Applacationswuauct1.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Applacationslsasss.exe"Added by the RBOT-AQQ WORM!"
XMicrosoft Server ApplacationsQ8See.exe"Added by the SPYBOT.GEN3 TROJAN!"
XMicrosoft Server Applacationscli.exe"Added by the RBOT-GAQ WORM!"
XMicrosoft Server ApplicationSound.exe"Added by the RBOT-NE WORM!"
Xmicrosoft server baselass.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Server Processsvhst32.exe"Added by the BCKDR-QHR BACKDOOR!"
XMicrosoft Servicemicrohost.exe"Added by the RBOT-LC WORM!"
XMicrosoft Servicewinsvc.exe"Added by the SPYBOT-DB WORM!"
XMicrosoft Servicerundll.exe"Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft Serviceservice.exe"Added by the IRCBOT-XX BACKDOOR!"
XMicrosoft Servicewinspl.exe"Spyman spyware"
XMicrosoft servicecssrs.exe"Added by the STARTP-DC TROJAN!"
XMicrosoft Service 32mssvc32.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service 32sysddm32.exe"Added by the SDBOT.AKC WORM!"
XMicrosoft Service Access ManagerAccess.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Service Bootsboot.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Controllerservices.exe"Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process
XMicrosoft Service Disk Cycledisksave.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service DriversSystem.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service DriversVSADNIM.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Service Execution Managerexecute.exe"Added by a variant of the IRCBOT TROJAN! See here"
XMicrosoft Service firewall Managerfirewall.exe"Added by a variant of the SDBOT BACKDOOR! Located in %System%"
XMicrosoft Service Host Manager32svchost.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Host Processsvchost.exe"Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XMicrosoft Service Informationmsnservices.exe"Added by the RBOT.ID WORM!"
XMicrosoft Service Login Managerwinlogin.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Service Managerservice32.exe"Added by the IRCBOT.WDW BACKDOOR!"
XMicrosoft Service Managerwinsvc.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Service PackWindowsSP.exe"Added by the RBOT-RF WORM!"
XMicrosoft Service Pack2.1svchost2.exe"Added by the RBOT.ASN BACKDOOR!"
XMicrosoft Service ToolsMStools1.exe"Added by the RBOT-BHT WORM!"
XMicrosoft Serviceslsserv.exe"Added by an unidentified VIRUS
XMicrosoft Serviceslssrv.exe"Added by the RBOT.CW WORM!"
XMicrosoft Servicesservices.exe"Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Serviceslsrv.exe"Added by the RBOT-BK WORM!"
XMicrosoft Servicessvshost.exe"Added by the ALETS.B TROJAN!"
XMicrosoft Servicesbsc32.exe"Added by the BDOOR-AW BACKDOOR!"
XMicrosoft ServicesSmss32.exe"Added by the RBOT-AD WORM!"
XMicrosoft Servicessvssshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicesmodule.exe"Added by the LAVITS WORM!"
XMicrosoft Servicesmsmpserv.exe"Added by the IRCBOT.BKA BACKDOOR!"
XMicrosoft Services UnitdMSU32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Servicez Managerservicemgrz.exe"Added by the RBOT-ASN WORM!"
XMicrosoft Sound Driversound32.exe"Added by a variant of the SPYBOT WORM!"
NMicrosoft Sound Volume Toolmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
XMicrosoft SpA Servicemsapps.exe"Added by the RBOT-VI WORM!"
XMicrosoft SpA Servicewin32.exe"Added by the RBOT.ATS WORM!"
XMicrosoft SpA ServiceWinupd32.exe"Added by the RBOT.LT WORM!"
XMicrosoft SpAr Servicewinsbsd32.exe"Added by the RBOT-RN WORM!"
XMicrosoft Spool ** Servicespool**.exe"Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
XMicrosoft Spool Server for Win32spoolsrv.exe"Added by the RANDEX.H WORM!"
XMicrosoft Spool Svcspoolsvc32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Spooler ServicesSpoolsv.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft SSISVRI32 Protocolssisvri.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Startup Managersysservice.exe"Added by the AVALANEC TROJAN!"
Xmicrosoft supportsvchostt.exe"Added by the AGOBOT.AWN WORM!"
XMicrosoft SVCmssvc.exe"Added by the BIFROSE-UQ TROJAN!"
XMicrosoft Svchost local serviceswinoem.exe"Added by the RBOT-FPE WORM!"
XMicrosoft Svchost local servicesnzm23.exe"Added by the RBOT-GMC WORM!"
XMicrosoft Svchost local servicesmsnserver.exe"Added by the RBOT-GPM WORM!"
XMicrosoft Synchronization Managersvhost.exe"Added by the SDBOT-PY WORM!"
XMicrosoft Synchronization Managerjava.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Synchronization Managersvchosts.exe"Added by the SDBOT-LM WORM!"
XMicrosoft Synchronization Managersvxhost.exe"Added by the SDBOT-ZU WORM!"
XMicrosoft Synchronization Managerdevldr32.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
XMicrosoft Synchronization Manager 2svhostc.exe"Added by the SLINBOT.ST WORM!"
XMicrosoft System Debugservices32.exe"Added by the RBOT.AKH WORM!"
XMicrosoft System DLL Services Configurationwindir32.exe"Added by the SDBOT-ACY TROJAN!"
XMicrosoft System Filesvchots.exe"Added by the RBOT.BYU WORM!"
XMicrosoft System NTsvhost.exe"Added by the SDBOT.COU WORM!"
XMicrosoft System Saver[path to worm]"Added by the RBOT.BSK WORM!"
XMicrosoft System Servicednservice.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicetaskmgr1.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft System ServicewinIogon2.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Service Devicemssdh.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft System Servicesmsnmgsr.exe"Added by the KELVIR.K WORM!"
XMicrosoft System Servicesmsmsgr.exe"Added by the RBOT-ZH WORM!"
XMicrosoft system Valuesys57.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Task Manager Daemonspoolsrv.exe"Added by the SDBOT.FLL WORM!"
XMicrosoft TCP Servicescvhost.exe"Added by the AGOBOT-L WORM!"
XMicrosoft TCP/IP Connection Monitorsvchost32.exe"Added by the RBOT.KS WORM!"
XMicrosoft Telecoms Centersvcchost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Time Managerdveldr.exe"Added by the RBOT-HQ WORM!"
XMicrosoft Transfer File Servermtfs.exe"Added by the RBOT.AFE WORM!"
XMicrosoft TTL Verifiermsttl.exe"Added by the RBOT-GAP WORM!"
XMicrosoft Updatemvsc.exe"Added by the SPYBOT.DAZ WORM!"
XMicrosoft Updatenavmgrd.exe"Added by the SDBOT.DP TROJAN!"
XMicrosoft UpdateVPC32.EXE"Added by the AGOBOT.XM WORM!"
XMicrosoft UpdateNAV.exe"Added by the RBOT-IV WORM!"
XMicrosoft Updatesnlogsvc.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatesvhost.exe"Added by the RBOT-PI WORM!"
XMicrosoft Updatewinscv.exe"Added by the RBOT-BH WORM!"
XMicrosoft Updatewserv32.exe"Added by the RBOT.AF WORM!"
XMicrosoft Updatewssvr.exe"Added by the RBOT-OD WORM!"
XMicrosoft Updatescvhost.exe"Added by the RBOT-AEM WORM!"
XMicrosoft Updatesvghost.exe"Added by the RBOT.BUJ WORM!"
XMicrosoft Updatesvzhost.exe"Added by the RBOT.OX WORM!"
XMicrosoft UpdateWinDrv32.exe"Added by the RBOT.EGW WORM!"
XMicrosoft Updatedevmks32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatedrive.exe"Added by the BIFROSE-PN WORM!"
XMicrosoft Updatebnmveqfts.exe"Added by the BANLOAD.KWQ TROJAN!"
XMicrosoft Updatelivemessenger.com"Added by the ADLOAD-LN TROJAN!"
XMicrosoft Updatentservice.exe"Added by the AGENT-DIS TROJAN!"
XMicrosoft Updateservice.exe"Added by a variant of the RBOT WORM! See here"
XMicrosoft Update 23spoolvs.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update 32servic.exe"Added by the RBOT-AXN WORM!"
XMicrosoft Update 32spoolvs.exe"Added by the RBOT-BBQ WORM!"
XMicrosoft Update 64 BITschvost.exe"Added by the RBOT.CAU WORM!"
XMicrosoft Update Clinicsvsipconfig.exe"Added by the RBOT.BR WORM!"
XMicrosoft Update Deviceflolo.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Update Device Driverswuauclt.exe"Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update Eventsvnhost.exe"Added by the AGOBOT-GW BACKDOOR!"
XMicrosoft Update Machineservicz.exe"Added by the RBOT-HU WORM!"
XMicrosoft Update Machinexvshost.exe"Added by the RBOT.QP WORM!"
XMicrosoft Update Machinesvshost.exe"Added by the RBOT.AK WORM!"
XMicrosoft Update Machinescvhost.exe"Added by the RBOT-GS WORM!"
XMicrosoft Update Machineservicez.exe"Added by the SPYBOT.BI WORM!"
XMicrosoft Update Machinespoolserv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Machineserviz.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update MachineWINSVC32.EXE"Added by the RBOT.CU WORM!"
XMicrosoft Update Machineopmmve.exe"Added by the KOLABC.DES WORM!"
XMicrosoft Update Machinethvfyq.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managersvshost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Managerscvhost.exe"Added by the AGOBOT.AXJ WORM!"
XMicrosoft Update Managerscvideo.exe"Added by the SDBOT-CVP TROJAN!"
XMicrosoft Update Processwmipcvse.exe"Added by the AGOBOT-JF TROJAN!"
XMicrosoft Update Servermssrv.exe"Added by an unidentified VIRUS
XMicrosoft Update Servicecsrss32.exe"Added by the AGOBOT-HC WORM!"
XMicrosoft Update Servicemswin32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft update servicesystemm.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Update SERVICEphqghum.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Servicemsupdate.pif"Added by the RBOT-AQB WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Update Serviceswcsnfty.exe"Added by the RBOT-AGK WORM!"
XMicrosoft Update Serviceswsnfty.exe"Added by the RBOT-AFU WORM!"
XMicrosoft Update v2.6lxxex.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatersvhost.exe"Added by the AGENT.CDF TROJAN!"
XMicrosoft Updatervbcjlg.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Updater v2[path to worm]"Added by the AUTORUN-BCI WORM!"
XMicrosoft Updateswkssvr.exe"Added by the RBOT.R WORM!"
XMicrosoft Updateswkssvrs.exe"Added by the RBOT-EB WORM!"
XMicrosoft Updatessvehost.exe"Added by the RBOT-GRW WORM!"
XMicrosoft Updatessvshost.exe"Added by the AGOBOT-AIW WORM!"
XMicrosoft Updatessvdhost.exe"Added by the RBOT-GVH WORM!"
XMicrosoft Updatesservice.exe"Added by the POISON.HPT BACKDOOR!"
XMicrosoft Updatingnavguard.exe"Added by the RBOT.HW WORM!"
XMicrosoft Updating Clientwebsvc.exe"Added by the RBOT.AQ WORM!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoft UpToDate Driver (32-bits)[random filename].exe"Added by the SPYBOT.LXJ WORM!"
XMicrosoft USB Windows2 Driverusbautotuner.exe"Added by the SILLYFDC.BCL WORM!"
XMicrosoft USB2 Drivercrmss.exe"Added by the RBOT-VK WORM!"
XMicrosoft usnsvc Serviceusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XMicrosoft Valuesigfkishc.exe"Added by the RBOT-GLO WORM!"
XMicrosoft VertupdateMSvert32.exe"Added by the MYTOB-CY WORM!"
XMicrosoft Video Capture ControlsMSsrvs32.exe"Added by the SDBOT-AAK WORM!"
XMicrosoft Video Controlstskmsgr.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Video Drivervideodrv.exe"Added by the SDBOT-AGP WORM!"
XMicrosoft Viewer Monitor Managerviewmon.exe"Added by the XPAK.A TROJAN!"
XMicrosoft Virtual Service Managervservice32.exe"Added by the MSNWORM.T WORM!"
XMicrosoft Virual Machinesms.exe"Added by the RBOT-SP WORM!"
XMicrosoft Vista Upgrade Validation Servicecfmon.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Visual Applicationvpcrtf.exe"Added by the IRCBOT-XJ TROJAN!"
XMicrosoft Visual Debugermdm.exe"Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
XMicrosoft Visual SourceSafeservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XMicrosoft Visual SourceSafewinlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
XMicroSoft Visual SPigxdfdfds.com"Added by the SDBOT.GAV WORM!"
XMicroSoft Visual SP2igfxsrvc32.exe"Added by the SDBOT.GAV WORM!"
XMicrosoft Visual Studioplscdksxg.exe"Added by the RBOT-AWV WORM!"
XMicrosoft Visual Studio VSAvarpc32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Web Devicewdevice.exe"Added by a variant of the SDBOT WORM!"
UMicrosoft Webserversvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
XMicrosoft Win Corp TLS Verificationmswintls.exe"Added by the RBOT-GCT WORM!"
XMicrosoft WindowsKernel.vbs"Added by the EDIBARA-A VIRUS!"
XMicrosoft Windowspwjbvphi.exe"Added by the RBOT-GQK WORM!"
XMicrosoft Windows DLL Servicesmwindll.exe"Added by the SDBOT-VX WORM!"
XMicrosoft Windows DLL Services Configurationnewdll.exe"Added by the SDBOT-ZR WORM!"
XMicrosoft Windows DLL Services Configurationnewdll2.exe"Added by the SDBOT-ABD WORM!"
XMicrosoft Windows DLL Services Configurationpoker.exe"Added by the SDBOT-ZY WORM!"
XMicrosoft Windows DLL Services Configurationpoker3.exe"Added by the SDBOT-AAH WORM!"
XMicrosoft Windows DLL Services Configurationproxy.exe"Added by the SDBOT-ZL WORM!"
XMicrosoft Windows DLL Services Configurationwindir32.exe"Added by the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindir32a.exe"Added by a variant of the SDBOT.BHF WORM!"
XMicrosoft Windows DLL Services Configurationwindll32.exe"Added by the SDBOT.BHD WORM!"
XMicrosoft Windows DLL Services ConfigurationwinDSL.exe"Added by the SDBOT-ZG WORM!"
XMicrosoft Windows DLL Services Configurationdllmanager32.exe"Added by the SDBOT-BTU WORM!"
XMicrosoft Windows Driverswindrv.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows DVRwindvr.exe"Added by the RBOT-AXD WORM!"
XMicrosoft Windows Kernel Serviceswinkrnl386.exe"Added by the ZEBROXY TROJAN!"
XMicrosoft Windows Keyboard servicekeyboard.exe"Added by the RBOT-CRF WORM!"
UMicrosoft Windows Media Player Network Sharing Service Configuration ApplicationWMPNSCFG.exe"Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music
XMicrosoft Windows Registry Servicewregistry.exe"Added by the AGOBOT.AKG WORM!"
XMicrosoft Windows Secure ServerrpcxWindows.exe"Added by the RBOT-LL WORM!"
XMicrosoft Windows Securityspvsper.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Securitywscndrives.exe"Added by the RBOT-AJK WORM!"
XMicrosoft Windows Servicewinsys.exe"Added by the RBOT-ADP WORM!"
XMicrosoft Windows Service Packwinspkn.exe"Added by the RBOT-AYD WORM!"
XMicrosoft Windows Servicesmsw32.exe"Added by the RBOT-FWQ WORM!"
XMicrosoft Windows ServicesSersices.exe"Added by the SDBOT-NO WORM!"
XMicrosoft Windows Services Edtssvvcchhoosst.exe"Added by the RBOT-FYF TROJAN!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Socketx32 Serviceswinsockx32.exe"Added by the RBOT-FWT WORM!"
XMicrosoft Windows Soundsvghost.exe"Added by a variant of the SPYBOT WORM! See here"
XMicrosoft Windows Soundsvshost.exe"Added by the RBOT.RNE BACKDOOR!"
XMicrosoft Windows Soundsvuhost.exe"Added by the KOLAB.XC WORM!"
XMicrosoft Windows Sound Driverssounddrivers.exe"Added by the SLENFBOT.ABU WORM!"
XMicrosoft Windows Storage Machine Servicewinms.exe"Added by the RBOT-AHK WORM!"
XMicrosoft Windows SVCHOSTSVCHOST.exe"Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XMicrosoft Windows System Service Managerwinsvc.exe"Added by the SPYBOT.LR WORM!"
XMicrosoft Windows Updatascvhost.exe"Added by the RBOT.CEM BACKDOOR!"
XMicrosoft Windows Updatesvchos.exe"Added by the SDBOT.AC WORM!"
XMicrosoft Windows Updatesvcshost.exe"Added by the FORBOT-CF WORM!"
XMicrosoft Windows Updatesvmhost.exe"Added by the FORBOT-CH WORM!"
XMicrosoft Windows Updatesvshost.exe"Added by the WOOTBOT.CJ WORM!"
XMicrosoft Windows Updatescvvhost.exe"Added by the FORBOT-DH WORM!"
XMicrosoft Windows Updatesvzhost.exe"Added by the FORBOT-EV WORM!"
XMicrosoft Windows Updatesccvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Updateservcs.exe"Added by the SDBOT.AL BACKDOOR!"
XMicrosoft Windows Update Clientservices.exe"Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMicrosoft Windows Update Servicewupdmgr32.exe"Added by the DOS.AUTOCAT TROJAN!"
XMicrosoft Windows Update Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMicrosoft Windows Update x86[various filenames]"Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe
XMicrosoft Windows UpdaterTMNTSrv.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windows Updaterspoolvs.exe"Added by the RBOT.ACQ WORM!"
XMicrosoft Windows Updatersuvhost.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows W32 Servicesmssw32.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Windows WKS Servicegt.exe"Added by the SDBOT.IR BACKDOOR!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft Windows Workstationdevcode.exe"Added by the RBOT-AWL WORM!"
XMicrosoft Windows XP Configuration Loaderm32svco.exe"Added by the SDBOT.WORM!.48548 WORM!"
XMicrosoft Winedows WinServiPodFix.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Winsock Servicemsusvc.exe"Added by the RBOT-ANS WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
XMicrosoft Word ProfissionalJava Plug In close.exe"Added by the BANKER-EL TROJAN!"
XMicrosoft World Servicewinworld.exeAdded by an unidentified IRC worm with backdoor capability!
XMicrosoft XML Servicemsxmlx.exe"Added by the RBOT.KS WORM!"
XMicrosoft--Updatessxvhost.exe"Added by the RBOT-FH WORM!"
XMicrosoft-Updatessvxhost.exe"Added by the RBOT-CT WORM!"
XMicrosoft64antiv.exe"Added by the SOBER WORM!"
XMicrosoftCorpjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftDriverService32drsys32.exe"Added by the IRCBOT.AKX BACKDOOR!"
XMicrosoftKsDrivers.bat"Added by the SHUTDOWN-F TROJAN!"
XMicrosoftMessengermsnserv.exe"Added by the DARKER.M WORM!"
XMicrosoftNAPCjavaw.exe"Added by the BUZUS.BULO TROJAN!"
XMicrosoftOEMsmvss.exe"Added by the DEDLER-G TROJAN!"
XMicrosoftPersonalFirewallspoolsrv.exe"Added by the WOOTBOT.DO BACKDOOR!"
XMicrosoftROMDriverServicecdrss.exe"Added by the IRCBOT.BLF BACKDOOR!"
XMicrosofts Help Servicesmsnmngr.exe"Added by the SDBOT-PJ WORM!"
XMicrosofts Servicelcsrv16.exe"Added by a variant of the RBOT WORM!"
XMicrosoftServiceManagermstask32.exe"Added by the YAHA.P WORM!"
XMicrosoftServiceManagerWintsk32.exe"Added by the YAHA.U WORM!"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftServiceManagermsupdat.exe"Added by the YAHA.AA WORM!"
XMicrosoftUpdatesvhest.exe"Added by the RBOT-ES WORM!"
XMicrosoftValuesyscnfg.exe"Added by an unidentified VIRUS
XMicrosoftvirussysoverload.exe"Added by the FORBOT-AL WORM!"
XMicrosoftWindows[various filenames]"MagicSearch - a CoolWebSearch parasite variant"
XMicrosoftXP Service Pack 2servicepack2.exe"Added by the RBOT.EMC WORM!"
XMicrosoft« ActiveX Debugger NTsetdebugnt.exe"Added by the BANCOS-CZ TROJAN!"
UMicrosoft® Windows Mobile® Device Centerwmdc.exe"Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista
XMicrosongsvchosts11.exe"Added by the SDBOT-EV WORM!"
XMicrost dds servicewsrss.exeAdded by an unidentified WORM or TROJAN!
Xmicrosystemsnddrv.exe"Added by the VB.AXG TROJAN!"
XMicroszoft Update Mach1nezssvchst.exe"Added by the RBOT-ED WORM!"
XMicrsoft Driverwindrive.exe"Added by the SDBOT.AF TROJAN!"
XMicrsoft Drivermsdriver.exe"Added by the SDBOT-XD WORM!"
XMicrsoft Driverwindrive32.exe"Added by the SLINBOT.TT BACKDOOR!"
?MigrationVendorSetupCaller"rundll32.exe migrate.dll CallVendorSetupDlls"
UMilShieldSlaveShieldWorker.exe"Mil Shield from Mil Incorporated. It protects your privacy by removing all tracks from your online or offline computer activities"
NMiniMavisMiniMavis.exeMavis Beacon typing tutor
XMiniServer.exeMiniServer.exe"Added by the LITTLEW-E TROJAN!"
XMircosoft DNS Servicesvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMircosoft Windows Developer Enviromentdevenv.exeAdded by an unidentified WORM or TROJAN!
XMircosoft Windows Developer Enviromentdevenv.exe"Added by the RBOT.AUJ BACKDOOR!"
XMircrosoft Svchost32svchost32.exe"Added by the RBOT-AZW WORM!"
NmiroVIDEO Tray Toolmisitray.exe"Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed
Xmmemdrvmmemdrv.exe"SecondSight spyware. Note - SecondSight is spyware that captures keystrokes and screen shots
XMmgsvcmmgsvc.exeMmgsvc spyware
NMMReminderServiceMMReminderService.exe"Mind Manager from Mindjet - ""easy way to organize ideas and information"". Registration reminder"
?mmsysrecover.exe"??"
XMMtask Servicemmtask.exe"Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename"
Umm_servermm_server.exe"Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator"
Xmnsvcmnsvc.exe"Added by the AUTOUPDER TROJAN!"
Xmnsvcspmnsvcsp.exe"Added by an unidentified VIRUS
NMobile Connectivity SuiteApplication Launcher.exe"System Tray access to the HTC Sync mobile phone management utility for models including the Hero
XModemlocatesvc.exe"Added by a variant of the SPYBOT WORM!"
XModem Driverz Updatesmdmdrv.exe"Added by a variant of the SDBOT WORM!"
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
UMonitor Apache ServersApacheMonitor.exePart of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
XMonitor calibrationAV1i.exe"Anti-Virus-1 rogue security software - not recommended
XMonitoring Servicesvchost.exe"Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\tasks"
XMONPluginSrIvcsn3monap23.exe"Added by a variant of the RBOT WORM!"
XMonTestvccxzq.exe"Added by the SDBOT-EA WORM!"
NMotive SmartBridgempbtn.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeMotiveSB.exe"System tray icon for the Virtual Assistant from AT&T Broadband
NMotive SmartBridgeBTHelpNotifier.exe"System tray icon for help from BT Broadband
UMotiveMonitormotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used by the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufacturer. For most users it's not required
NMotiveSBMotiveSB.exe"System tray icon for the Virtual Assistant from AT&T Broadband
Xmousedrive.exeinstantmsgrs.exe"Added by the FORBOT-ER WORM!"
XMouseDrv[path to worm]"Added by the ZOLOAD-B WORM!"
XMouseDrvupdate.exe"Added by the ZOTOB.N WORM!"
XMoussaEvil[path to file]"Added by the MUSANUB-A WORM!"
XMoveSearchSearch.exe"PigSearch adware"
XMoveSearchzsearch.exe"PigSearch adware"
NMovielink Manager Uninstallmsvcmm32.exe"Auto-update for Movielink - internet movie rental System Tray access"
XMovieMlmovie.exe"Added by the BEAGLE.DS WORM!"
Xmoviemkmoviemk.exe"Added by the DWNLDR-GTB TROJAN!"
XMovieNetworksMovieNetworks.exeMovieNetworks will connect you by a domestic premium rate telephone number 900-xxx-xxxx - so you get xxx rated pictures and junk and high internet costs. Remove the %ProgramFiles%\MovieNetworks directory
XMovieplaceMovieplace.exe"MoviePlace malware"
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
XMP Servicesmpsvc.exe"Added by the WOOTBOT.EQ WORM!"
XMP Tclockvvmptclock.exe"Added by the NACKBOT-A WORM!"
XMP Tclockvvmptclock.exe"Added by the NACKBOT-A WORM!"
XMP Tclockvvmptclockvv.exe"Added by the RANDEX.CJ WORM!"
XMPL32 driverMPL32.exe"Added by the LOONY-M TROJAN!"
YmpLockDriveLockDrive.exe"LockDrive from i8 Technologies makes selected folders and drives read only and can be used to prevent users downloading or copying data to portable drives and memory sticks - i.e.
XMPtask Servicesmptask.exe"Added by the LALA or AOT TROJANS!"
Xmptsgsvc.exemptsgsvc.exe"Hacker Tool - detected by DiamondCS TDS-3 anti-trojan as ""HackTool.Win32.Hidd.j"""
XMQT Svcmqtsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xmrsvctrmrsvctr.exe"Added by a variant of the SDBOT WORM!"
Xmssvhost32.exe"Added by the LEGMIR-AQO TROJAN!"
XMS Config Loadersvchos1.exe"Added by the AGOBOT.R WORM!"
XMS Config Loadersvcrhost.exe"Added by a variant of the RBOT WORM!"
XMS Config ServiceMsloader32.exe"Added by the RBOT-KJ WORM!"
XMS Config v12mscfg12.exe"Added by the AGOBOT.YP WORM!"
XMS Config v13lrbz32.exe"Added by the GAOBOT.AOL WORM!"
XMS Config v13mscfg13.exe"Added by the AGOBOT.YQ WORM!"
XMS Decryption Softwareactive.exe"MediaTickets adware variant"
XMS DirectX Sound Driversmsdrvdx.exe"Added by the RBOT.BCX WORM!"
XMS Domain Name Server DeamonMSDNSD32.exe"Added by the RBOT-CMZ WORM!"
XMS DVD DirectX Dll Driversmdxdl.exe"Added by the SDBOT-XI WORM!"
XMS DVD DirectX Sound Driversmsdrvdx.exe"Added by the SDBOT-XJ WORM!"
XMS Host Managerivhost.exe"Added by the RBOT-BJN WORM!"
XMS Java Applets for Windows NT & XPjavaapplet.exe"Added by the RBOT.BHG WORM!"
XMs Java for Windows NTMS32.exe"Added by the VANEBOT-H WORM!"
XMs Java for Windows NTmsi32java.exe"Added by the VANEBOT-I WORM!"
XMs Java for Windows NTmsjava.exe"Added by the VANEBOT-E WORM!"
XMs Java for Windows NTmsi32info.exe"Added by the RBOT.AFX WORM!"
XMS Java for Windows XP & NTjavanet.exe"Added by the VANEBOT-A WORM!"
XMS Java Service Wrapper Windows NT & XPwrapper.exe"Added by the VANEBOT-D WORM!"
XMs Java Update For Windows NT/XPmsijavaupdt32.exe"Added by the RANDEX.AF WORM!"
XMS Java virtual machinejavavm.exe"Added by the RBOT.ABG WORM!"
XMS Registry ServiceMSRMS32.exe"Added by the RBOT-AKP WORM!"
XMS Screen Saverscrsave.scr"Added by the RBOT-AGT WORM!"
XMS Security Authority Servicelsass.exe"Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process
XMS Security Hotfixservice5.exe"Added by the GAOBOT.AG WORM!"
XMS servicemsservice.exe"Added by the RBOT-ZG WORM!"
XMS Service Driverswinscv.exe"Added by the SDBOT-COG WORM!"
XMs Sound Driversmsdrv.exe"Added by the SDBOT-WR WORM!"
Xms spool servicemsspooler.exe"Added by a variant of the RBOT WORM!"
XMS UniXnavupdate64.exe"Added by the RBOT.CRZ BACKDOOR!"
XMs Update WinServices NT/XPwinservnt32.exe"Added by the VANEBOT-G WORM!"
XMs Valud LoaderSvhots.exe"Added by the AGOBOT-SP WORM!"
XMS Win32 Network Serviceswindriver.exe"Added by the AGOBOT.ADH WORM!"
XMS Windows AOL DriverMSAOLdrv.exe"Added by the RBOT-ASP WORM!"
XMS Windows TASK ServiceMSWTASK32.exe"Added by a variant of the RBOT WORM!"
XMS-DOS Boot ServiceBoot32.pif"Added by the RBOT-AMF WORM!"
XMS-DOS Security Servicems-dos.pif"Added by the RBOT-AMR WORM!"
XMS-DOS ServiceMS-DOS.pif"Added by the RBOT-AII WORM!"
XMS-DOS Windows ServiceMS-DOS.PIF"Added by the RBOT-AJW WORM!"
XMS32DLLachi.dll.vbs"Added by the ACHI-A TROJAN!"
XMS32DLLBha.dll.vbs"Added by the BUTSUR-A WORM!"
XMS32DLLMS32DLL.dll.vbs"Added by the ZODGILA WORM!"
XMsAudio"MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
Xmsavsc.exemsavsc.exe"Added by the AGENT.ANQ TROJAN!"
Xmscleanmsvchost.exe"Added by the OPANKI-Q WORM!"
Xmsconfigscvhost.exe"Added by the AGENT-DSF TROJAN!"
XMsconfigicpldrvx.exe"Added by the BANLOAD.BFT TROJAN!"
Xmsconfig serviceMSupdate32.exe"Added by a variant of the SPYBOT WORM!"
Xmsconfig38mssvcc.exe"Added by the RBOT-BJV WORM!"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
Xmscsvc.exemscsvc.exe"Added by the BANCOS.T TROJAN!"
XMSCVTMSCVT.exe"Added by the SLIDESHOW WORM!"
XMSDatablavadasq.exe"Added by the LIOTEN.IK WORM!"
Xmsdevmsdev.exe"Added by the FORBOT-CR WORM!"
Xmsdevmsconfig.exe"Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
Xmsdev controlmsdevctrl.exe"Added by the SPYBOT.N BACKDOOR!"
XMSDOS Security Servicemsdos.pif"Added by the RBOT-AMP WORM!"
XMSDOS ServiceMSDOS.PIF"Added by the RBOT-AIY WORM!"
XMSDOS Windows ServiceMSDOS.PIF"Added by the RBOT-AKF WORM!"
XMSDosdrvmsdosdrv.exe"Added by the BACROS WORM!"
XMSDriverundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDRVNetFilter.exe"Added by the INTERRUPDATE TROJAN!"
Xmsdrvctrlmsdrvctrl.exe"Added by the VIDCACH-A TROJAN!"
Xmservseres.exe"Added by the AGENT-LIL WORM!"
Xmservices.exemservices.exe"Added by the SDBOT.WJ WORM!"
Xmsetsvchost.exe"Added by the BIZEX-F TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""mset"" sub-directory"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
XMSFWAVTSMFTPDev.exe"Added by the RBOT-ACF WORM!"
Xmsgserv_Syss.exe"Added by the FANTA TROJAN!"
XMsgsrv16Msgsrv16.exe"Added by the DELF family of TROJANS!"
YMSGSRV32.exemsgsrv32.exe"Windows 32-bit VxD Message Server. For more information on its function and why it's needed
XMsgsvc32[worm filename]"Added by the NAUTICAL-A WORM!"
XMsgSvcMgr32cmdzxdll.exe"Added by the RBOT-AEK WORM!"
Xmsgsvr32msgsvr32.exe"Added by the DEADHAT.B WORM! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
XMSInfoAVBgle.exe"Added by the NETSKY.O WORM!"
XMSInstallsmvss.exe"Added by the DEDLER-G TROJAN!"
Xmsjava servicexpcd.exe"Added by the SDBOT.VM WORM!"
XMSKernel32MSKernel32.vbs"Added by the LOVELETTER (I LOVE YOU) VIRUS!"
Xmskridermaskrider.dll.vbs"Added by the SOLOW-F WORM!"
UMSKServerExeMSKSrvr.exe"Part of McAfee Spamkiller"
Xmsliveupdatemsliveupdate.exe"Added by the AGOBOT.ALT WORM!"
XMSMcAfeeeAvsynmgr32e.exe"Added by the FRAMAR TROJAN!"
XMSMcAfeehAvsynmgr32h.exe"Added by the FRANGO TROJAN!"
XMSMcAfeeSAvsynmgr32S.exe"Added by the VOLAC or VOLAC.DR TROJANS!"
XMsMoviesMsMovies.exe"Added by the ALCRA-E WORM!"
?MsmqIntCertregsvr32 /s mqrt.dll"Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?"
XMsMsgSrvmsmsgsrv.exe"Added by the CQO TROJAN!"
XMSMsgSvcMSMSGSVC.exe"Browser hijacker
Xmsnmsnsvc.exe"Added by a variant of the SDBOT WORM!"
XMSNscvhost.exe"Added by the IRCBOT-ZW WORM!"
XMSNwkssvr.exe"Added by the PUSHBOT.S WORM!"
XMSNFixdriver.exe"Added by the SILLYFDC.BBY WORM!"
XMSNwkssvrs.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSNwksvr.exe"Added by the IRCBOT-XU WORM!"
XMSNwmev.exe"Added by a variant of the SPYBOT WORM! See here"
XMSNservices51651.exe"Added by the IRCBOT-AAL TROJAN!"
XMSNmsservice.exe"Added by the IRCBOT-ABZ TROJAN!"
XMSNsvchost.exe"Added by the PUSHBOT.FA WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMsn 8.0 Livemsn.exe"Added by the BANKER.EIE TROJAN!"
XMSN BETAservice.exe"Added by the RBOT.AUU WORM!"
XMSN Live Clientmsnlvclient.exe"Added by the IRCBOT.AWF BACKDOOR!"
XMSN Live Messangermsnlivegs.exe"Added by the RBOT-FSG WORM!"
XMSN Managercvss.exe"Added by a variant of the SPYBOT WORM!"
XMSN Managermsnmgrsv.exe"Added by the IRCBOT.BAZ BACKDOOR!"
XMSN Message Servicemsnmsg.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Messanger Livewinntmsn.exe"Added by the RBOT-FSO WORM!"
XMSN Messengerlive.messenger.com"Added by the DELF.AOI BACKDOOR!"
XMSN Messenger Live Loginmsnmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Messenger Live Windowsmessengerlive.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN messenger servicemssgs.exeAdded by an unidentified TROJAN!
XMsn Messenger Servicemsnmsg.exe"Added by the SDBOT.BMU WORM!"
XMSN Messenger Service Startermsnmgsr.exe"Added by the RBOT-AOS WORM!"
XMSN Messenger Service Startupmsnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Messenger Servicesmsnmgr.exe"Added by the RBOT.ADF TROJAN!"
XMSN Messenger Servicesmsnmgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMsn Messenger updatemsnservice.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMsn Messsengerregsvr.exe"Added by the AGENT-GXM TROJAN!"
NMSN Quick ViewMsndc.exeQuick way to connect to MSN internet service
XMSN Servmsmsnserv.exe"Added by the IRCBOT.AVF BACKDOOR!"
XMsn Servmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servermsmsnserver.exe"Added by the IRCBOT.AUS BACKDOOR!"
XMSN servicemsnmgr16.exe"Added by a variant of the RBOT WORM!"
XMSN Serviceamsnmsgrs.exe"Added by a variant of the SDBOT WORM!"
XMsn Servicematrixcam.exe"Added by the MYTOB.JH WORM!"
XMsn Serviceraloded.exe"Added by the MYTOB-DY WORM!"
XMSN servicemsnmsgr16.exe"Added by the RBOT-RZ WORM!"
XMSN serviceNTDKRN.EXE"Added by the RBOT.UJ WORM!"
XMSN Servicemsnsvc.exe"Added by the SLENFBOT.EG WORM!"
XMSN Service Updateswinproc.exe"Added by the KELVIR-BB WORM!"
XMSN Service Utilitiesnkn.exe"Added by the KELVIR-BC WORM!"
XMSN Service!msnservice.exe"Added by a variant of the RBOT WORM! See here"
XMSN Servicermsnsrv.exe"Added by a variant of the IRCBOT TROJAN!"
XMSN Servicermsnservicer.exe"Added by the SLENFBOT.PQ WORM!"
XMSN Servicesmsnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN Servicesmsnservice.exe"Added by the IMPARD-A TROJAN!"
XMsn Update Serviceuserx.exe"Added by the MYTOB.JF WORM!"
XMSN Update Servicemsnupdsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN UPDATERSvirtualmemory.exe"Added by the RBOT-JK WORM!"
XMSN User Servermsnserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Server!msnservices.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicemsnsvc.exe"Added by the SLENFBOT.NS WORM!"
XMSN User Service!msnserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Servicesmsnuserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMSN User Svcmsnusnsvc.exe"Added by the IRCBOT.AVV BACKDOOR!"
UMSN Video EnhancedMSNVE.exe"""MSN Video Enhanced can play videos that have dramatically improved video quality and sound. It can play the latest high-quality videos at the best possible quality."" No longer appears to exist"
XMSN32 X ServiceMSN32x.EXEAdded by an unidentified WORM!
XMSN6.1 Auto-Updaterv6msn.exe"Added by the AUTORUN-MM WORM!"
Xmsnager32svchostt.exe"Added by the WOMANIZ.E TROJAN!"
XMSNavWHMSWkwrH.exe"Added by the ANAV-A WORM!"
Xmsndrvsysmsndrvsys.exe"Added by the BROGGER-D TROJAN!"
XMsnExplorerSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
NMSNIAMSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG
XMsnMessengerSvcmsnmsgr.exe"Added by a variant of the RBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
XMSNPluginSrIvcsn3vasap23.exe"Added by a variant of the RBOT WORM!"
XMSNPluginSrvcsp6.exe"Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
XMSNPluginSrvcssagate.exe"Added by the SDBOT.AKJ WORM!"
XMSNServiceMSNService.exe"Added by the CARPET.C WORM!"
XMSOfficeservices.exe"Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
XMSOfficeCfgnavchk.exePremium rate adult content dialer
XMSOfficeCfgqservice.exePremium rate adult content dialer
XMSOfficeCfgssvr.exePremium rate adult content dialer
XMSPetServPET32.EXE"Added by the IRCBOT-VE WORM!"
XMSPluginSrvcp3.exe"Added by the RBOT-WV WORM!"
XMSRegSvcregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
XMss Servmsssrv.exe"Added by the SLENFBOT.AA WORM!"
XMss VCmssvc.exe"Added by the OPANKI.AB WORM!"
Xmssdbsrvmsupdtck.exeAdded by a variant of a password stealing TROJAN!
Xmsserrv32msserrv32.exe"Added by the STRATION.DW WORM!"
Xmsservmsserv.exe"Added by the BLACKLOG-A TROJAN!"
Xmsservlvsrev.exe"Added by the BROWMON-B TROJAN!"
Xmsserv32msserv32.exe"Added by the RBOT-ACK WORM!"
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMSServer"Rundll32.exe [random].dll#1"
XMsServermsfir80.exe"Added by the VB-CYJ TROJAN!"
Xmsservicemsserv.exe"Added by the HYD WORM!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
XMSSHVCMSSHVC.exe"Added by the NUFFY.A WORM!"
XMSStartOptimizerSCVHOST.EXE"Added by the DASMIN-E TROJAN!"
Xmssvc[path to trojan]"Added by the PSK TROJAN!"
XMSSVCsvcsys.exe"Added by the FATOOS-C TROJAN!"
YMSSVC.EXEMSSVC.EXE"StealthDisk - hides folders
Xmssvc32mssvc32.exe"Added by the AGOBOT-ME WORM!"
XMSSYSTEMsvcsys.exe"Added by the FATOOS-C TROJAN!"
XMStasksvchost.exe"Added by the LDPINCH-BV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XMstask32driverMstask32.exe"Added by the LOONY-D TROJAN!"
XMSTaskbar 32tbsvc32.exe"Added by the RBOT.BQZ WORM!"
XMSUpdatesvchosthlp.exe"Added by the BLASTER.T WORM!"
XMsupdatesvchosts.exe"Added by a variant of the TACTSLAY TROJAN!"
XMsupdatesvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XMsupdatesvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XMSUpdateDevKitaxfd.exe"Added by the SDBOT-ZD WORM!"
XMSUpdSrvmsupdsrv.exe"Browser hijacker
XMsVBdllsys32dll.exe"Added by the AIMDES.B or AIMDES.C WORMS!"
XMsVBdllMsVBdll.pif"Added by the AIMDES.A WORM!"
XMSVBVM60MSVBVBM60.pif"Added by the SCOLD-B WORM!"
Xmsvc32msvc32.exe"ClientMan parasite variant"
Xmsvc32msvc32.exe"Added by the AGOBOT-NT WORM!"
Xmsvcavmsvcav.exe"Added by the AGENT-ACR TROJAN!"
Xmsvccmsvchost.exe"Added by the XOMBE TROJAN!"
Xmsvcc25svcchost.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25salvage.exe"Added by a variant of the SDBOT WORM!"
Xmsvcc25svcchost.exe"Added by the SDBOT-CSE WORM!"
Xmsvccc66svcchosst.exe"Added by the RBOT-GLS WORM!"
Xmsvccc66dload.exe"Added by a variant of the RBOT WORM!"
Xmsvchostmsvchost.exe"Added by the IRCBOT-AV WORM!"
XMsvcServicemsvcs.exe"Added by the RBOT-RK WORM!"
Xmsvecuritymsvecurity.exe"Added by the DORF-BO WORM!"
XMSVersionINTERNETFEATURES.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
Xmsvhostaig.exe"Added by the AIMBOT-BC TROJAN!"
Xmsvload32msvload32.exe"Added by the RBOT-ACI WORM!"
Xmsvpsmsvps.exe"Added by the AGOBOT.ALI WORM!"
Xmsvsc32msdev.exe"Added by the RBOT-GJ WORM!"
XMSVsmtrpcxctx.exeAdded by an unidentified WORM or TROJAN!
Xmsvsrv32msvsrv32.exe"Added by the AGOBOT-KM WORM!"
Xmsvssmsvss.exe"Added by a variant of the RBOT WORM!"
XMSVSyncvideosync.exe"Added by a variant of the SPYBOT WORM!"
Xmsvupdatermsvupdater.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
XMSVXDMSVXD.EXE"Added by the DATOM.A WORM!"
Xmswavemswave.exe"Added by the CRYPTER.A TROJAN!"
XMswavedllmswavedll.exe"Added by the CRYPTER-C TROJAN!"
XMsWindows DRT Driverswsdrt32.exe"Added by the RBOT.ALT WORM!"
XMsWindows SSL Driversmssl32.exe"Added by the SPYBOT.API WORM!"
XMsWindows SysDatesysmsvc.exe"Added by the SPYBOT.FCD WORM!"
XMSWinSrvMSWinSrv.exe"Added by the MTRON TROJAN!"
XMSWinSrv32MSWinSrv32.exe"Added by the MTRON-B TROJAN!"
XMsWinVgrmsvgr.exe"Added by the MYTOB.LE WORM!"
Xmswkork Servicemsework.exe"Added by a variant of the RBOT WORM!"
Xmswsplvnmispoisn downloader.exeSearchBarCash adware variant
XMSysDrvmsdrv.exeAdded by the VB.WF TROJAN!
XMultimedia extensionsmservice.exe"EasySearch adware"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
Nmumservicemumservice.exe"Software updater for Motorola products"
NMusic01 ServerMusic01 Server.exe"J River Media Jukebox"
NMutexServiceExSys32Smm.exe"Webroot Sofware's discontinued ""Privacy Master"""
Xmv2crasos.exe"Added by the DROPPS-A TROJAN!"
UMVRescuemvrescueRelated to Multivision Computers back up/restore program. Multivision Computers ceased operating in 2004
NMVS SplashSplash.exeSplash screen for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses
Xmvsyswinaacsysiom.exe"Added by a variant of the SDBOT WORM!"
Umwavscanmwavscan.com"MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system
XMwsvmmwsvm.exe"SeekSeek search hijacker related - see here"
Xmxcllvec.exe"Eco Antivirus rogue security software - not recommended
UMxvgautilMxvgautil.EXE"Utility for a USB to VGA converter from MCT Corp"
XMy AppSMSSvc.exe"Added by the NEGASMS.A TROJAN!"
XMy SupervisorMSup1bf7.exe"My Supervisor rogue system suite - not recommended
XMyappservice.exeHomepage hijacker
XMyAVavpguard.exe"Added by the NETSKY.J WORM!"
YMyCIO Agent Servicemyagtsvc.exe"Part of the now obsolete McAfee VirusScan ASaP online anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
XMyLifeCmdServ.exe"Added by the HOLAR.A WORM!"
Umynswwntsrv.exe"Net Screen Watcher surveillance software. Uninstall this software unless you put it there yourself"
XMyPointsPointAlertwjview ...MyPointsPointAlertrun.exe"""With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles"". Dubious privacy policy"
XMySLScanmsvc32.exe"Added by the FORBOT-EH WORM!"
Xmysvcig38mysvcc.exe"Added by the RBOT-FOU WORM!"
Xmysvcig38recsl.exe"Added by a variant of the RBOT-FOU WORM!"
XMyVBAppSysNT.exe"ReferAd adware"
XMyVBAppinstall.exe"Detected as Generic Downloader.s by McAfee
XMyVBAppsetup.exe"Detected by Kaspersky as the VB.KB TROJAN! File location is in the root folder (i.e.
XMyVirt.exeMyVirt.exe"Added by the REMADM-C TROJAN!"
UMyVitalAgentVtlAgent.exe"MyVitalAgent from Lucent Technologies. Replacement for Net.Medic
YNaimagent_serviceEPOAgentnaimas32.exe"Networked version of McAfee VirusScan. Installs
XName Servermswins.exe"Added by a variant of the SDBOT WORM!"
Xnanosvchost.exe"Added by the NANO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNano Antivirusnanoav.exe"Nano Antivirus rogue security software - not recommended
Xnapv.exewupdate.exe"Added by the AGOBOT-JX BACKDOOR!"
XNarmonVirusAntismss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XNAVRuxDLL32.exe"Added by the MAPSON.D WORM!"
YNAV Agentnavapw32.exeNorton Anti-Virus's background scanning process
XnAv AGENTN/A"Added by the RIOSYS MACRO! Note the lower-case ""n"" and ""v"" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes"
XNAV Agentsystems.exe"Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name"
XNAV Agentwinsnav.vbs"Added by the ANPES WORM!"
XNAV Agentwmilib32.exe"Added by the VB-XU TROJAN!"
XNAV Auto Protnavprot1.exe"Added by the RBOT.ZAC WORM!"
XNAV Auto Protectmsfwe1.exe"Added by a variant of the RBOT WORM!"
XNAV Auto Protectnavprotect.exe"Added by the RBOT.BKW WORM! Note - this is not a valid Norton AntiVirus product from Symantec"
XNAV Auto Protectdnsserv.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Protectmcafee32.exe"Added by a variant of the SPYBOT WORM!"
XNAV Auto Update[random filename]"Added by the SPYBOT-E WORM!"
XNAV Auto Updateiamsad.exe"Added by the SPYBOT-CE BACKDOOR!"
XNAV Auto UpdateSadness.exe"Added by the SPYBOT-E WORM!"
XNAV Auto Updatescsrssp.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesnavwindows.exe"Added by a variant of the SDBOT WORM!"
XNAV Auto Updatesslserves.exe"Added by the RBOT.COI BACKDOOR!"
XNAV Auto Updatesnavupdaterx.exe"Added by a variant of the RBOT WORM!"
NNAV CfgWizcfgwiz.exe"Introduced with Norton Anti-Virus 2002
NNAV Configuration Wizardcfgwiz.exe"Introduced with Norton Anti-Virus 2002
UNAV DefAlertDefAlert.exeNorton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
XNAV Live Update[path to worm]"Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec"
XNAV Scan ServiceNAVSCAN32.EXE"Added by the SDBOT.VG WORM!"
XNavAgent32lasvr32.exe"Added by the FEMOT.D WORM!"
XNavAgent32SCardSvr32.Exe"Added by the MOFEI.B WORM!"
Xnavappnavapp.exe"NavExcel adware variant"
Ynavapw32navapw32.exeNorton Anti-Virus's background scanning process
XNAVChecknavchk.exePremium rate adult content dialer
XNAVCheckshman.exePremium rate adult content dialer
XNavegateiiexplorer.exe"Added by the BANCBAN-OP TROJAN!"
XNavegatewisterd.exe"Added by the BANKER-BOS TROJAN!"
UNaverPCGreenNPCGreenUpgrader.exe"Related to Naver_Anti-virus Realtime Monitor From NHNCorp"
UNaviscopenaviscope.exe"Naviscope is a multipurpose browser enhancement that can speed up Web searches
XNaviSearchnls.exe"NaviSearch
NNavLoadNAVBrowser.exeRegistration reminder for CorelDRAW 10
Xnavman_20sysnav32.exe"Hijacker
?NAVMD25UpdtNv28.exeAdded by Symantec for updating the MicroDefs for their AV products - is it required?
XNAVMon32NAVMon32.exE"Added by the WINKO.AO WORM!"
XNAVNet***.tmp [* = random digit]Unidentified adware
Xnavp.exenavp.exe"Added by the AGOBOT-OE WORM!"
XNavPassNavPass.exeFree system for gaining access to and downloading from adult content web-sites
XNavScan[filename]"Added by the OBSORB TROJAN!"
XNAVSCAN32.EXENAVSCAN32.exe"Added by the SDBOT-DO WORM!"
XNAVSCANNER32NAVSCANNER32.EXE"Added by the RBOT.QC WORM!"
XNAVtaskNAVtask.exe"Added by the REMBOT-A BACKDOOR!"
XNAVUpd"rundll32.exe navupd.dll Startup"
XNAVWatchNAVWatcher.exe"VX2.Transponder parasite updater/installer related"
XNAV_UpdateNAV_Update.exeUnidentified WORM or TROJAN!
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
YNCSW ServerNcsW.exe"LockLink access control management software. LockLink 7.0 lets users seamlessly manage both offline and online access control solutions available from IR Security & Safety"
XNDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XNDAvsvhost.exe"Added by the SERFLOG.C WORM!"
XNDIS Adapterservenxpp.exe"Added by the FORBOT-GP WORM!"
XNDIS AdapterServenxp.exe"Added by the SPYBOT.LY WORM!"
XNDIS Adaptersvchosttt.exe"Added by the WOOTBOT.AN WORM!"
XNDrvNDrv.exe"PurityScan adware"
XNegativespain.exe"Added by the BANKER-EXJ TROJAN!"
?neqprvfy.exeneqprvfy.exe"Appears to be related to the downloading of some application - possibly verifying updates?"
NNero DriveSpeedDRIVESPEED.EXE"Ahead Nero DriveSpeed - set the CD reading speed of a CD/DVD drive on-the-fly to reduce the noise on high-speed drives"
XNeroFileCheckmsjavam32.exe"Added by the AGOBOT.AKM WORM!"
NNeroNETTrayIconNNServiceCtrl.exe"System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network"
XNeroUpdate Checkmsjava.exe"Added by the AGOBOT.AMH WORM!"
XNeroUpdater6.8winjava.exe"Added by the AGOBOT.AMK WORM!"
UNet Activity Diagramnad.exe"Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs"
XNet Command Senternvscvse.exe"Added by the IRCBOT!DF6280E5 VIRUS!"
Xnet32svhost.exeAdded by a variant of the Trojan.Clicker family
Xnet64svhoster.exe"Added by the AGENT.JVF TROJAN!"
XNetAppwinserv.exe"Added by the SHADOWTHIEF TROJAN!"
XNetBiosSrvcHPSrvPrt.exe"Added by the SDBOT-COL WORM!"
Xnetcsvc.exe"Added by the VESLORUKI.DWK TROJAN!"
Xnetdaemonnetdaemon /v"Malware designed to ""kill"" a number of antispyware applications (SpyBot
XNetDyVisualGuard.exe"Added by the NETSKY.N or NETSKY.W WORMS!"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
XNetManagerServicentss.exe"Added by the BESTPICS.A TROJAN!"
XNetropa Internet ReceiverNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
UNetscapeInstallService.exeRelated to Netscape installation
XNetServicentsvc.exe"Added by the QQPASS-DU TROJAN!"
Xnetservicesrecall.exe"Added by the WOOTBOT.D WORM!"
Xnetservicessvchostn.exe"Added by the SDBOT.GI WORM!"
XNETServicescsxrs.exe"Added by a variant of the SDBOT WORM!"
XNetStartsvchost.exe"Added by the MKAR-A VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""NETSTART"" subfolder"
NNetStat LiveNsl.exe"AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data"
Xnetsv32netsv32.exe"Added by the SDBOT-PX WORM!"
Xnetsv32sv.exe"Added by the DELF.CCD TROJAN!"
YNettGain2000 VerifierNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speed
Xnetviewnetview.exe"Added by the BIFROSE.L BACKDOOR!"
XNETVISIONAdulti[random filename]"Trafficadvance dialer"
XNETVISIONPasse-partoutPasse-partout.exe"Added by the DIALCAR-M DIALER!"
Xnetwsvw.exe"Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware"
XNetwork Administration Servicersvc32.exe"Added by the RBOT.ABH WORM!"
UNetwork Associates Error Reporting ServiceTBMon.exeNetwork Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
Xnetwork device drivermsfirewall.exe"Added by the DELF-LB TROJAN!"
UNetWork Device SwitchNetDevSW.exeToshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
XNetwork Host Servicemsmnart32.exe"Added by the RBOT-CJV WORM!"
XNetwork Host Service[random]32.exe"Added by the RBOT-BAB WORM!"
XNetwork manegersvchost.exe"Added by the AGENT.BX BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XNetwork Protocol Servicewuamgrd.exe"Added by the RBOT.EA WORM!"
XNetwork protocol servicewintcp.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Provisioning ServiceWinNPS.exeAdded by an unidentified WORM/TROJAN!
XNetwork Securitysecsvc.exe"Added by the RBOT-ALX WORM!"
XNetwork Security XPnvsvc86.exe"Added by the RBOT-GUI WORM!"
XNetwork Servicesvchost.exe"Added by the STARTPA-CC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNetwork Servicesvhost.exe"Added by the HACDEF-K TROJAN!"
XNetwork ServiceMccTrayApp.exeAdded by an unidentified WORM or TROJAN!
XNETWORK SERVICESVÑHOST.exe"Added by the DELF-EW BACKDOOR!"
XNetwork Service Managernetsvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNetwork Servicesnetsvacs.exe"Added by the GAOBOT.AIS WORM!"
XNetwork Translation System Servicentss.exe"Added by the UNPDOOR TROJAN!"
Xnetxsvx.exe"Detected by Bitdefender as a variant of DROPPER.LDPINCH.Q malware"
Xnetzipsvzip.exe"Added by the DELF.ZWL TROJAN!"
XNew Anti VirusSystem.exe"Added by the BRONTOK-CH WORM!"
XNewmanplayavi.exe"Added by the LINEAGE-AT TROJAN!"
?News Serviceispnews.exe"F-Secure antivirus related. However
UNexusServerPNXSERVR.exe"Related to ProCoder 2.0 from Canopus. ""ProCoder 2.0 software combines speed and flexibility into a streamlined video conversion tool for professionals. Featuring
UNFM ServiceNPDOR9x.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
NNGServerngserver.exeSymantec/Norton Ghost Console service
XNI.UAVIFR_0001_N105M2404[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N108M0207[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M1202[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGESV_0001_N108M2006[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M0303[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M2811[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UGESV_0001_N122M3010[path to file]"Installer for the SysDepannage French rogue system error and cleaning utility - see here"
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNI.UWFX5V_0001_0802UWFX5V_0001_0802NetInstaller.exe"WinFixer 2005 web installer - ""foistware""
YnisservNISSERV.EXENorton Personal Firewall
UniSvcLocniSvcLoc.exe"Related to National Instruments Corp. LabView"
NNkvMon.exeNkvMon.exeNikon View 5 - for transferring pictures from Nikon digital cameras
NNkVwMon.exeNkVwMon.exeNikon View - for transferring pictures from Nikon digital cameras
?NMSSvcNMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cards
YNMSVCnmSvc.exe"Covenant Eyes - surveillance software that creates records of everything people do on a computer
?nMTaskBarServicenMtsk.exe"Taskbar control for ISDN NetMod modem. What does it do and is it required?"
UNNSvcnnsvc.exe"Net Nanny internet filter. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows 2K/XP/Vista"
XNod23 Servicenod23.exe"Added by the RBOT-GMK WORM!"
XNod29 Servicenodwr.exe"Added by a variant of the RBOT WORM!"
XNod32 Free antivirusnod32krn.exe"Added by the RBOT-AAO WORM! Note - not the popular free NOD32 antivirus software
XNod32 Servicenod64.exe"Added by the RBOT.ESJ WORM!"
XNod32 Servicealserv32.exe"Added by the RBOT.DHN WORM!"
XNod32 ServiceAutoUpdateWin32.exe"Added by the SDBOT-DJG WORM!"
XNod32 Servicenod6.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XNod3d2 Free antivirusN0D32KRN.EXE"Added by the RBOT-ABQ WORM!"
XnodriverAUEKXRZ.EXE"Added by a variant of the SPYBOT WORM!"
XnodriverSVCHOST.EXE"Added by the SPYBOT-Z BACKDOOR! Note - this is not the legitimate svchost.exe process which should normally figure in Msconfig/Startup!"
UNokia M PlatformNokiaMServer.exe"Part of the Nokia Music music manager
NNokia Ovi SuiteNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
UNokiaMServerNokiaMServer.exe"Part of the Nokia Music music manager
NNokiaOviSuiteNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
NNokiaOviSuite.exeNokiaOviSuite.exe"Nokia Ovi Suite for managing Nokia mobile devices - ""gives you an easy access to the contents of your Nokia device. Transfer files and information effortlessly between your device and your computer
XNortE Antivirusnorte.exe"Added by the RBOT.BQQ WORM!"
XNortE Antivirusnorten.exe"Added by the RBOT-AFF WORM!"
XNorton Antiviral Scannernavscnr.exe"Added by the DELBOT-K WORM!"
XNorton Antivirusnortonav.exe"Added by the RBOT-AYE TROJAN! Note - this is not the real Norton AV!"
XNorton Antivirus 2004SYMANTECAV2.EXE"Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV!"
XNorton Antivirus 7.0a[path to file]"Added by the PERDA-B or RANCK-CT TROJANS!"
XNorton Antivirus AVFVProtect.exe"Added by the NETSKY.P WORM! Note - this is not the popular AV software!"
XNorton AntiVirus SysNAVsys32.exe"Added by a variant of the WOOTBOT WORM!"
XNorton Antivirus Updaternortonav.exe"Added by the DELBOT-T WORM! Note - this is not the real Norton AV!"
XNorton Auto Protectnava.exeAdded by an unidentified WORM or TROJAN!
YNorton Auto-Protectnavapw32.exeNorton Anti-Virus's background scanning process
XNorton Auto-ProtectSERVICES.exe"Added by the AHKER.B WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%. Also
?Norton AV PreloadPremend.exe"Norton Antivirus related. What does it do and is it required"
XNorton AV Protection StartupAti2xxx.exe"Added by a variant of the RBOT WORM!"
XNorton Drive Protectionmsdt32.exe"Added by the FORBOT-GB WORM! Note - this not a valid Norton program!"
XNorton Live Update Servercpsdv.exe"Added by the AGOBOT.EW TROJAN!"
XNorton Live UpdaterCavapsvc.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterSochost.exe"Added by the GAOBOT.AO WORM!"
XNorton Live UpdaterAvapsvc.exe"Added by the AGOBOT-BG BACKDOOR!"
NNorton Navigator Loadernnloader.exe"An older Norton utility for file management under Windows 95. More information here"
UNorton Program SchedulerNPSsvc.exe"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95
?Norton Program Scheduler Event Checkernpscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker"
XNorton protectnvsvc.exe"Added by a variant of the RBOT WORM!"
XNorton Protect Activiescsrss.exe"Added by the BANKER-CZ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""D5133"" subfolder"
XNorton Service Driverwsul.exe"Added by the RBOT-ABI WORM!"
XNorton Service Processnavapvc.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XNorton Service Processnavapsvc.exe"Added by the AGOBOT-GV WORM! Note - this is not the valid Norton Anti-Virus service which has the same file and is located in %ProgramFiles%\Norton AntiVirus. This one is located in %System%"
XNorton SpySweeper AutoUpdatenavsw.exe"Added by the FORBOT-AS WORM!"
XNorton Updatewinsvc.exe"Added by the AGOBOT.ALP WORM!"
XNorton updatedNVSV32.EXE"Added by the SDBOT.ABH WORM!"
XNorton Updaternavupdtr.exe"Added by the SDBOT.AXV WORM!"
XNortonAntivirusLSASS.exe"Added by the PEXMOR WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Temp"
XNortonAVnorton_antivirus.exe"Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program"
XnortonavCCUPD32.EXEAdded by an unidentified WORM or TROJAN!
XNortons AV SYSTEMscvchost.exe"Added by a variant of the RBOT WORM!"
XNortons AVS Systemsarse.exe"Added by the RBOT.AWY WORM!"
XnortonsantivirusccEvtMngr.exe"Added by the HZDOOR-A TROJAN!"
XNortonVPlussvchost.exe"Added by the ROAMER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
NNoteBurnerVTBurnerGUI.exe"NoteBurner from NoteBurner Inc. - ""a versatile music converter that can be used as MP3 music converter
XNotification UtilityaltpayV2.exe"AltPay adware"
UNovaBackup * Tray ControlNbkCtrl.exe"Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number"
?NovaPortal Single User ServiceNPSU.exe"??"
UNovastorSchedulerdSCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
Xnovsvida.exenovsvida.exe"GlobalAccess dialer"
XNoWayViruspgs.exe"NoWayVirus rogue security software - not recommended
XNPF ValueNPFMONTR.exe"Added by the RBOT-AWD WORM!"
?NPS Event Checkernpscheck.exe"Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker"
Xnsdcmd servicesnsdcmdav.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xnsdcmd vid processnsdcmdwin.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
Xnsdrivernssys32.exe"NetShagg adware"
XNsvnsvsvc.exe"Delfin Promulgate adware"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
XNsvdrnsvdr.exeAdult content dialler
XNT LM Security Support ProviderWinNTLM.exe"Added by a variant of the SDBOT WORM!"
XNT Logging ServiceSyslog32.exe"Added by the DONK.B WORM and variants!"
XNT MICROSOFT SVCDntvsvcd.exe"Added by a variant of the RBOT WORM!"
XNT Printing Servicespoolsc.exe"Added by the BUZUS-K WORM!"
XNT Printing Servicechkdsks.exe"Added by the ARCHIVARIUS series of WORMS!"
XNT Printing Servicechkdskss.exe"Added by the ARCHIVARIUS series of WORMS!"
XNT Printing Serviceschkdsks.exe"Added by the BUZUS-M TROJAN!"
XNT ServiceNTOKSRNL.EXE"Added by the RBOT-AAG WORM!"
XNT Servicesntsvc.exe"Added by the AGOBOT.VJ WORM!"
XNT Virtual Machine[path to file]"Added by the SCAERBOT-A WORM!"
XNT-Virtual Device Managerntvdmn.exe"Added by the SDBOT-AAA WORM!"
XNtcheckmapserver.exe"Added by the TOMPAI-B WORM!"
Xntmsevtntmsevt.exe"Added by the STOPED-B TROJAN"
XNTP Server[path to trojan]"Added by the RANKY.F TROJAN!"
XNTSet32services.exe"Added by the WINSPY-C TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\dll32"
XNTSF MICROSOFT SYSTEMscvhost.exe"Added by a variant of the RBOT WORM!"
XNTsrv.exeNTsrv.exe"Added by a variant of the SERVU-O TROJAN!"
XNtsysvntsysv.exe"Added by the MIFENG-E TROJAN!"
Xntupdatednsvc.exe"Added by the SDBOT-TC WORM!"
Xntusersvchost.exe"Added by the POLYCRYP.DY TROJAN!"
UNTVDMNTVDM.EXE"Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT
Xntvdmdntvdmd.exe"Adware downloader - also detected as the DLOADER-YP TROJAN!"
Xntvdscmntvdscm.exe"Added by the SCKEYLOG-I TROJAN!"
YNuTCSetupEnvironncoeenv.exe"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows
UNuvaTimeNuvaTime.exe"NuvaTime - reminder for women using NuvaRing"
XNvagNTnvagNT.exe"Added by the AGOBOT-RV WORM!"
Xnvc Win32nvcvc.exe"Added by the RBOT-ADD WORM!"
XNvCCCplNvCCCpl.exe"Added by the NOGATA-A TROJAN!"
Xnvchostwinlogon.exe"Added by the KLONE-J TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvClipRsvsvchost.exe"Added by the DUMARU-K WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XNvClipRsvswchost.exe"Added by the DUMARU-AK WORM!"
?NVCLOCK"rundll32 nvclock.dll fnNvclock"
Xnvcoinvcoi.exe"Added by the DLOADER.TYO TROJAN!"
?NvColorInit"rundll32.exe NvQtwk.dll NvColorInit"
XNVCOMNVCOM.exe"Added by the AGOBOT-SB WORM!"
XNvCp1Do[path to trojan]"Added by the DWNLDR-GWE TROJAN! The most common filename seen is ""smss.exe"" - which is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
UNvCpl"RUNDLL32.EXE NvCpl.dllNvStartup"
XNvCplNvCpl.EXE"Added by the YANZ.B WORM!"
XNvCpl[random filename]"Added by the AGOBOT-APJ WORM!"
XNvCplwindowsp.exe"Added by a variant of the SDBOT WORM!"
XNvCplrundl32.exe"Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as ""rundll32.exe NvCpl.dll
XNvCpl28Deamonmdosft.exe"Added by the SPYBOT-AD WORM!"
XNvCPL32nvcpl32.exe"Added by the AGOBOT.DAA WORM!"
XNvCpl32Deamonnvcpl.exe"Added by the SPYBOT.S WORM!"
XNvCplDm2gr32.exe"""Switch"" premium rate adult content dialler variant"
XNvCplDntcpl.exe"""Switch"" premium rate adult content dialler variant"
UNvCplDaemon"RUNDLL32.EXE NvQTwkNvCplDaemon"
UNvCplDaemon"RUNDLL32.EXE NvCpl.dllNvStartup"
XNvCplDaemonmsmsgrs.exe"Added by the DLOADER-YI TROJAN!"
XNvCplDaemonXplorer.exe"Added by the ORBINA-A WORM!"
XNvCplDaemon32anvshell32.exe"Added by the VB-XU TROJAN!"
XNvCplDeamonnvdisp.exe"Added by the PEEPVIE-I TROJAN!"
XNvCplDmnNAVSVC.EXE"Added by an unidentified VIRUS
Xnvcpllnvcpll.exe"Added by the BANCBAN-PF TROJAN!"
XNvCplScanmsc32.exe"Added by the FORBOT-DD WORM!"
XNvCplScanwinasp.exe"Added by the FORBOT.BZ WORM!"
XNvCplScannvsc32.exe"Added by the BROPIA.N WORM!"
XNvCplScankav32.exe"Added by the FORBOT-EW WORM!"
XNvCplScannetstat32.exe"Added by the SDBOT.BRL WORM!"
XNvCplScandllmanager.exe"Added by the FORBOT.R WORM!"
XNvCpTDaemonwuauqmr.exe"Added by the CULT-B WORM!"
Xnvctrl.exenvctrl.exe"Added by the ZLOB.G TROJAN!"
Xnvd32 lptt01nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xnvd32 ml097envd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNVDispDrvNVDispDRV.EXE"Added by the WINKO.AO WORM!"
XNvGraphicsInterface[path to trojan]"Added by the BCKDR-QKI BACKDOOR!"
UNVHotkeyrundll32.exe nvHotkey.dll"Enables the use of ""hot keys"" for changing setting on Nvidia graphics"
XNvid[8 random charachters]Unidentified adware
XNvid32Nvid32.exe"Added by the GEMA TROJAN!"
XNvidex32Nvidex32.exe"Added by the GEMA TROJAN!"
YNVIDIA ActiveArmorntrayfw.exe"System Tray access to the the NVIDIA ActiveArmor hardware-optimized firewall built into some older nForce 3 and 4 series motherboard chipsets"
XnVidia Application Driversnvidiav32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XNvidia Control Daemonnksvc32.exeAdded by an unidentified WORM or TROJAN!
XNvidia Control Panelncsvc32.exe"Added by an unidentified VIRUS
XNVIDIA DisplayDisplayMonitor.exe"Added by the ABI.C WORM! Note - this is not a legitimate nVidia entry"
XnVidia Display Drivernvsvc64.exe"Added by the IRCBOT-YK WORM! Note - this is not related to any nVidia based graphics card"
XnVidia Display Drivers (x86)nvsys86.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XNVIDIA DriverMSPMSPSU.EXE"Added by the WOOTBOT.Y WORM!"
XnVidia DriversnVidiaDrvers.exe"Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card"
XNVidia Drivers[path to trojan]"Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
UNVIDIA Media Center Library"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
XNVIDIA Media Center Librarywinlogon.exe"Added by the AUTORUN-AZK WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NNVIDIA nForce APU1 UtilitiesNVATray.exe"nVidia's nForce Audio Processing Unit (APU)- ""provides 3D positional audio and DirectX 8.0 compatibility
UNVIDIA nTunenTune.exe"Older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures
UNVIDIA nTunenTuneCmd.exe"Now part of NVIDIA System Tools under the ""Peformance"" tag. NVIDIA nTune is utilty for monitoring and modifying the settings (such as temperatures
XNvidia Startup Managerksvc32.exe"Added by the AGENT-IWD TROJAN!"
XnVidia System Driversnvsys32.exe"Added by an unidentified WORM or TROJAN! See here"
UNVIDIA System MonitorNVMonitor.exe"NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures
UNVidia System UtilityNVSystemUtility.exe"NVidia System Utility - older version of the NVIDIA nTune utilty for monitoring and modifying the settings (such as temperatures
XNVIDIA Video driversvideo_32D.exe"Added by the AGOBOT.KV WORM!"
XNVIDIA Video driversvideo_32sD.exe"Added by the RBOT-BB WORM!"
XNvidia32nvidia32.exe"CoolWebSearch parasite variant - also detected as the HOSTS-B TROJAN!"
XNVidiaDrvnvfsvm.com"Added by the DELF-A BACKDOOR!"
XNviDiaGTlsass.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
NNvidiaQuickTweak"rundll32.exe NvQtwk.dll NvTaskbarInit"
UNVIDIA® NVRAIDnvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
Xnvidll32nvidll32.exe"Added by the RBOT-XK WORM!"
UNVIEW"rundll32.exe nview.dllnViewLoadHook"
Xnviload32nviload32.exe"Added by the SDBOT-VT WORM!"
NNvInitialize"rundll32.exe NvQtwk.dll NvXTInit"
Xnvirundllnvirundll.exe"Added by the SPYBOT.NPS WORM!"
Xnvjxuenvjxue.exe"Added by the EYEVEG-J WORM!"
YNVmaxNVmax.exeNVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
UNVMCTRAY"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
UNvMediaCenter"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
NNVMixerTrayNVMixerTray.exeSystem Tray access to audio controls from nVidia's motherboard ForceWare software
UNVMonitorNVMonitor.exe"NVIDIA System Monitor - part of NVIDIA System Tools. Utility for monitoring and logging system statistics (such as temperatures
XnvmsgdwnNVMSGDWN.EXE"Added by the GRABER-D TROJAN!"
XNvMsnWIsass.exe"Added by the BROPIA.K WORM!"
Xnvpatchnapatch.exe"Added by the SASSER-F WORM!"
UNvPvrNetMonNvPvrNetMon.exe"Network monitor for the Personal Video Recorder function of the NVIDIA ForceWare Multimedia application - ""makes sure you don't miss your favorite show. If you won't be home to watch the show
NNVQuickTweak"rundll32.exe NvQtwk.dll NvTaskbarInit"
UNVRaidServicenvraidservice.exe"Part of NVIDIA® MediaShield™ Storage - NVIDIA's management utility for creating and monitoring hard disk RAID arrays for the controllers integrated on their motherboards. Includes a Disk Alert System for troubleshooting with notifications via the System Tray. Not required if you don't have a RAID array or if you created the array at the BIOS level. Some users complain that it can report false errors"
YNvRegisterMCTray"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp NvCpl.dll"
YNvRegisterMCTrayNview"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp nView.dll"
?NVRotateSysTraynvsysrot.dll"Related to NVIDIA nView Control Panel. What does it do and is it required?"
NNVRTnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
?NVRTClkNVRTClk.exe"Related to a Gigabyte video card. What does it do
Xnvsv32.exenvsv32.exe"Added by the FORBOT-DI WORM!"
Xnvsv32.execstr.exe"Added by a variant of the SDBOT WORM!"
Xnvsv32.exeasr_fnt.exe"Added by the WOOTBOT.GE WORM!"
Xnvsv32.exenvsv33.exe"Added by the WOOTBOT.FP WORM!"
NNvSvcnvsvc.exe"NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active
Xnvsvcnvsvc.exe"Added by the BANKER-HQ TROJAN! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
XNVSVCnvsvc.exe"Added by the AGOBOT.ALX WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
UNvSvc"RUNDLL32.EXE nvsvc.dllnvsvcStart"
Unvsvc16nvsvc16.exe"MySuperSPy surveillance software. Uninstall this software unless you put it there yourself"
Xnvsvca32nvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
Xnvsvca32clfmon.exe"Added by the TACTSLAY.E TROJAN!"
XNVSystem32nvscv32.exe"Added by the AGOBOT-NO WORM!"
XNvt32complaint_7251.exe"Added by the ARTIEF.B TROJAN!"
XNvUpdaternwiz32.exe"Added by a variant of the RBOT WORM!"
Xnvviddrv32[random filename]"Added by the RBOT-HT BACKDOOR!"
XNvVideoCenterNvVid.exe"Added by the HAXDOOR-DO TROJAN!"
XNvXplDeamonxstyles.exeAdded by the SMALL.AJ VIRUS!
Xnxgsvc"rundll32.exe nxgsvc.dllstart"
XNxvstcssrs.exe"Added by the GAOBOT.CD WORM!"
XNxvstlsas.exe"Added by the GAOBOT.CD WORM!"
YObject Store Serverosserver.exe"Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital
?obsverobsver.exe"Part of LingoWare translating software - what does it do and is it required?"
UOctoshape Streaming ServicesOctoshapeClient.exe"Octoshape Live Streaming - ""is a revolutionary technology that will reduce your bandwidth cost and improve the quality in sound and picture"""
NOdebit Multimedia V2Odebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
NOdebit Multimedia V3Odebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
NOdebit Multimedia V3 - ServicesOdebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
Yoeprsrvoeprsrv.exe"Outlook Express Privacy - which ""lets you control access to Outlook Express and its email message database. When you enable protection
Yoeprsrv.exeoeprsrv.exe"Outlook Express Privacy - which ""lets you control access to Outlook Express and its email message database. When you enable protection
Yoepsrvoepsrv.exe"Outlook Express Protector from Ixis Research
Yoepsrv.exeoepsrv.exe"Outlook Express Protector from Ixis Research
Yoessrvoessrv.exe"Outlook Express Security - which is used ""to control access to Outlook Express and its databases. When it is active
Yoessrv.exeoessrv.exe"Outlook Express Security - which is used ""to control access to Outlook Express and its databases. When it is active
Xoe_drop_spamoesrv.exe"Dropspam adware"
XOffice Monitoradv32.exe"Added by the SDBOT-CWO WORM!"
XOffice Monitornvsvc86.exe"Added by the IRCBOT.BVO BACKDOOR!"
XOffice Monitor Word Exel Rsvch.exe"Added by the DWNLDR-GWW TROJAN!"
XOfficeAgentsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeAgentsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XOfficeGuardUIsvcss.exe"Added by the DEDLER-C TROJAN!"
XOfficeQuickAccessOfficeHost.vbs"Added by the PEXMOR WORM!"
XOLE Automation Serverole32aut.vbe"CoolWebSearch parasite variant"
XOLEDb Servicerunoledb32.exe"Added by a variant of the SPYRE.B TROJAN!"
Uolesvrolesvr.exe"Salfeld Child Control - parental control software"
XOlive SystemSzchost.exe"Added by the MERCURYCAS.A TROJAN!"
XOmega AntiVirOM83b.exe"Omega AntiVir rogue security software - not recommended
UOn screen displayTPOSDSVC.exe"Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example
UOnfolioStorageonfserv.exe"""Onfolio is the complete solution for collecting
?online cdromActive acid.exe"??"
XOnline Servicesvchost.exe"Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XOnline Servicestwain.exe"Added by the AGENT.BEA TROJAN!"
XOnluna Sarvicesachost.exe"Added by the TOFGER-AA TROJAN!"
XOnlune Sarvicesachost.exe"Added by the DAEMONI-J TROJAN!"
Xonly23SCVHOST.exe"Added by the BCKDR-PUQ BACKDOOR!"
XOnSrvrOnSrvr.exeOnWebMedia adware
XOpen Service Driversopiater.exe"Added by a variant of the RBOT WORM!"
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
Uopenvpn-guiopenvpn-gui.exe"""OpenVPN is a full-featured SSL VPN solution which can accomodate a wide range of configurations
UOpenwares LiveUpdateLiveUpdate.exe"Web-update utility as used by various types of software - see here"
XOpera addonsvhost.exe"Added by the AGENT-IBD WORM!"
XOperalaunchvmm.exe"Added by the AGENT-IBD WORM!"
NOperations Typhoon Rising RegistrationNOVG.EXE"Joint Operations registration reminder"
XOptional Web Drivers For WIN32phqghume.exe"Added by a variant of the RBOT WORM!"
NOptusNet Desktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
XOrbitViewview.exe"Xupiter OrbitExplorer toolbar related. Drive-by foistware. Use Spybot S&D
XOSSrlvknlg.exe"Marketscore.RelevantKnowledge adware"
UOStivityInvAgtostivity.exe"OStivity - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network
XOutlook Mail Servicesexpress.exe"Added by the RBOT.CJN WORM!"
XOutlook Mail Servicesoutlook.exe"Added by the RBOT-BKA TROJAN! Note that the valid Microsoft Outlook executeable is located in %ProgramFiles%\Microsoft Office\Office whereas this one is located in %System%"
?OVCJovcj.exe"??"
Xoverinstallpgs.exe"Part of VirtualPCGuard
NOvernetOvernet.exe"Overnet peer-to-peer (P2P) file sharing program"
Xovyriwitelace.exe"Added by the SDBOT.BVS WORM!"
UOWCWebCamDVwcdvtray.exe"WebCamDV from Orange Micro
Xoxbvpengwthtis.exe"Added by the SILLYFDC-AH WORM!"
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?Packard Bell EverSafe Tray ControlTrayControl.exe"Packard Bell EverSafe software. What does it do
XPaintingRoom evidence monitorpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
NPAL Evidence EliminatorCleaner.exe"PAL Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
XPaladin Antiviruspav.exe"Paladin Antivirus rogue security software - not recommended
UPanda Antispam Server ServicePasSrv.exe"AntiSpam part of an older version of Panda Internet Security"
YPanda Cleanerpavdr.exe"Panda internet security software related. Possibly the ActiveScan on-line scanner?"
YPanda Preventium+ ServicePREVSRV.EXE"Part of the 2004 & 2005 versions of Panda Antivirus and Internet Security"
UPanda Schedulerpavsched.exe"Scheduler for older versions of Panda Antivirus. Required if you have scans scheduled on a regular basis"
XPandaAVEnginePandaAVEngine.exe"Added by the NETSKY.R WORM!"
UPandaSchedulerpavsched.exe"Scheduler for older versions of Panda Antivirus. Required if you have scans scheduled on a regular basis"
NPaperportrunppdrv.exe"Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here"
XPaRaY_VMwinlogon.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XPatches ValueWinGamed.exe"Added by the SDBOT.BR WORM!"
?PathNvidiaTVpatchnvidiaTVout.exeRelated to a Gigabyte Nvidia based video card - typical file location is %ProgramFiles%\Gigabyte\Nvidia
XPAVpav.exe"Personal Antivirus rogue security software - not recommended. Located in %ProgramFiles%\PAV"
XPAV.EXE%Number%"Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number"
YPAV.EXEPAV.EXE"PER Antivirus"
YPAVFIRESPavFires.exe"Firewall included with older versions of Panda Antivirus and Internet Security"
YPAVFNSVRPavFnSvr.exe"Part of Panda Antivirus and Internet Security"
YPavkre9xpavkre9x.exe"Part of the 2005 & 2006 versions of Panda Antivirus and Internet Security"
YPavProcPavPrS9x.exe"Part of Panda Antivirus and Internet Security"
YPavProtPavProt.exe"Part of the 2004 & 2005 versions of Panda Antivirus and Internet Security"
YPavprot9Pavprot9.exe"Part of the 2005 versions of Panda Antivirus and Internet Security"
XPC Drive ToolGDC.exe"PC Drive Tool rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XPC Live GuardPC[random characters].exe"PC Live Guard rogue security software - not recommended
YPC Tools AntiVirus ClientPCTAV.exe"System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses
UPC Tools Privacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
XPCAntiVirusPropgs.exe"PCAntiVirusPro rogue security software - not recommended
?PCMCIA Resource Monitornvp2pmon.exe"NVIDIA nForce P2P Driver. What does it do and is it required?"
NPCMServicePCMService.exe"Part of Cyberlink's PowerCinema - which can be used to watch movies
XPCPrivacyCleanerpcpc.exe"PCPrivacyCleaner rogue privacy tool - not recommended"
XPCPrivacyDefender FreewareUPSPDAP.exe"PCPrivacyDefender rogue privacy program - not recommended
XPCPrivacyToolGDC.exe"PCPrivacyTool rogue privacy tool - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
XpcServerserver.exe"Ssppyy spyware"
XPCShieldregsvr32 sfg_****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPcsvpcsvc.exe"Delfin Media Viewer or ""Promulgate"" adware"
YPCTAVPCTAV.exe"System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses
YPCTAVAppPCTAV.exe"System Tray access to PC Tools AntiVirus from PC Tools - which ""provides world-leading protection against viruses
UPCTVOICEpctvoice.exe"The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it
UPCTVRemoteremoterm.exeControls the remote control on some Pinnacle TV tuners
XPCViruslesspgs.exe"PCVirusless
UPD0620 STISvcP0620Pin.dllCreative Technology Ltd installation plug-in related
XPDA Commanderstisvc32.exe"Added by the AGOBOT-TX WORM!"
?PDF Converter Registry ControllerRegistryController.exe"Part of PDF Converter Professional version 2 from Scansoft (now Nuance). what does it do and is it required?"
UpdfFactory Dispatcher v1fppdis1a.exe"FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Dispatcher v2fppdis2a.exe"FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Pro Dispatcher v1fppdis1.exe"FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
UpdfFactory Pro Dispatcher v3fppdis3a.exe"FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. ""pdfFactory products offer a unique approach to PDF creation that is simpler
NpdfSaver3pdfSaver3.exe"PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word
Updp Serverctpdpsrvr.exeIncluded and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
Npdservicepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
NPDService.exepdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
?PDVD8LanguageShortcutLanguage.exe"Part of Cyberlink's PowerDVD version 8. Language settings?"
UPDVDDXSrvPDVDDXSrv.exe"Remote Control background application for Cyberlink's PowerDVD DX - a Dell specific version of their standard PowerDVD product. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
UPDVDServPDVDServ.exe"Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
?PeeramidPService.exe"In a ""Koptimizer"" folder in Program Files. What does it do and is it required?"
UPent@VALUE 3.2Pent@VALUE.exePent@VALUE Digital Satellite Internet PC Receiver
YPER Email Protectionpavmail.exe"PER Antivirus"
Uperfmonperfmon.vbs"MindStorm AnalyzerPro from Secure Associates. ""A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"""
XPerfomance Monitordavcsync.exe"Added by the LAMUD-A WORM!"
XPerfomance Settingssvchost.exe"Added by the TOFGER-AP TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPersonal AntivirusPerAvir.exe"Personal Antivirus rogue security software - not recommended
XPersonal Computerscvhost.exe"Added by the RBOT-AJE WORM!"
XPersonal Firewall V9Firewall-UpdateV9.exe"Added by the RBOT-BJR WORM!"
XPersonal Firwallptmedsrv.exe"Added by the SDBOT.XY WORM!"
XPersonalAVpav.exe"PersonalAV rogue security software - not recommended. Detected as the FAKEAV.FT TROJAN by Trend. Located in %ProgramFiles%\PersonalAV"
UPervasive.SQL Workgroup EngineW3dbsmgr.exeDatabase Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
XPex Sound DriverToday's Results.vbs"Added by the TRODE-A WORM!"
Xpex Sound driver 2Today's Results.vbs"Added by the TRODE-A WORM!"
?PFW_PullSrvPULL.EXE"Personal Firewall related?"
YPGPSDKSVCpgpsdkserv.exe"PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings
UPGPSERVICEpgpservice.exe"PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice
XPGStub.exe[various filenames]Unidentified adware
Uphc700vphc700.exe"Related to the Philips SPC700NC web camera"
NPhilipsDMDeviceManager.exeDevice manager for Philips portable media players such as the GoGear
?PhilipsLimeLimeAlive.exe"Associated with some Philips portable media players such as the GoGear. What does it do and is it required?"
UPhone Connection Monitoraudevicemgr.exe"Connection monitor part of the Sony Ericsson PC Suite mobile phone management utility for some models
UPhoneFree version 6.2PHONEF??.EXE"An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here"
NPhoto Loader supervisoryPlauto.exe"Casio's Photo Loader software. Hook up your camera to the USB port
XPhotoshopsvchost.exe"Added by the CDOPEN-E TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%"
Xpicsvrpicsvr.exe"Delfin Promulgate adware"
NPicture Motion Browser Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony camera/camcorder products. Automatically invokes an import process if the camera/camcorder is connected and has media on it"
UPicture Package VCD MakerResidence.exe"Sony Picture Package software for their range of Digital Handycam video cameras. Used to connect the camcorder via USB and allows the user to burn the content directly to a CD"
Xpicviewpicview.exe"Added by the DWNLDR-FPH TROJAN!"
Xpicviewmsnmsgr.exe"Added by the BANLOA-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %Windir%"
UpiiserviceOEN/A"Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE"
YPinnacleDriverCheckPSDrvCheck.exe"Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
NPivotSoftwarewpctrl.exe"PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
XPixelsvrPixelsvr.exe"Added by the GEMA TROJAN!"
XPK Servicespksvc.exe"Added by the FORBOT-BW WORM!"
XPlasdll service[random filename]"Added by a variant of the SDBOT WORM!"
XPlayboyplayavi.exe"Added by the GAMANLOCK TROJAN!"
NPlayMoviePMVService.exe"Part of Acer Arcade Deluxe lets you browse pictures
NPluckSvrPluckUpdater.exe"Pluck Toolbar updater"
XPluto! Pagersrvhandle.exe"Added by the REDPLUT VIRUS!"
?PMCSPMC.Service.Main.exe"Related to MediaCenterService from Pinnacle Systems. What does it do and is it required?"
XPmediawinsrvc.exe"Internet marketing sofware from Permissioned Media Inc as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM!"
XPnP Driverplayboy.exe"Added by the FORBOT-FR WORM!"
Xpnpsvc_lock******.exe [* = random digit]Browser hijacker
Xpnpsvc_lockstartsvs.exeBrowser hijacker
XPNtask Servicespntask.exe"Added by the LALA.C TROJAN!"
Xpnvifjjusodl.exe"Added by the QQPASS.48436 TROJAN!"
NPoivYPoivY.exe"PoivY - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
XPoliceAVxppolice.exe"XP Police Antivirus rogue security software - not recommended
XPoliciesserver.exe"Added by the SPYRAT WORM!"
XPoliciesserver.exe"Added by the AGENT-NLT TROJAN!"
XPolicyRunspoolsv32.exe"Added by the BACKDOOR-DNV TROJAN!"
XPolicyRunsvchost.exe"Added by the SILLYFDC-AW WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xpool managerpopsvr.exe"Added by the AGENT-S BACKDOOR!"
Xpoolsvpoolsv.exeAdded by an unidentified WORM or TROJAN!
XPOPPopSrv***.exe"PeopleonPage foistware
Upop3 Serverconfig.cfg"Part of HTML2POP3 - ""Convert Webmail to POP3.Is also included a SMTP/POP3 tunneling system that allow send and receive email in a private network HTTP PROXY based. All connection are plugin based. Over 250 email server supported and tested"""
XPopeSvrPopeSvr.exe"Added by the LEGMIR-AJ TROJAN!"
Xpopsrv146popsrv146.exe"AproposMedia adware"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
XPopup and Advertisement Killersadkillers.exe"Added by the RBOT-DDH WORM!"
XPopup Blocker Updaterregsvr32 veev****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XPopup Defence Updaterregsvr32 pdfupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
UPopupVanishPopupVanish.exePop-up blocker
XPostdavatchnvdas.exe"Added by the RANDEX.T WORM!"
XPostpatchnvdes.exe"Added by the RANDEX.T WORM!"
XPower-Antivirus-2009Power-Antivirus-2009.exe"Power Antivirus 2009 rogue security software - not recommended
NPowerArchiver TrayPASTARTER.EXE"System Tray access to PowerArchiver from ConeXware
NPowerDVDPowerDVD.exe"Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled
XPowerManagersvchost.exe"Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
NPowerReg SchedulerPowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg Scheduler V3PowerReg Scheduler V3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV2PowerReg SchedulerV2.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
NPowerReg SchedulerV3PowerReg SchedulerV3.exe"PowerREGISTER from Leadertech. Registration reminder as used by Iomega
YPP2000 Real Time ScanPPVstop.exeProtector Plus anti-virus software - real time scanner
UPPK Setup(Server)SEServe.exe"Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button
UPPSVC[path to file]"PC Police surveillance software that logs keystrokes
XPreview AdServicePrevAdServ.exeWindupdates adware variant
XPrevXprevx.exe"Added by the IRCBOT-TF WORM! Note - this worm is located in the System (Win9x/Me) or System32 (XP/WinNT/2K) directory and is not the PrevX Home intrusion prevention software"
YPrevxHomeSAGUI.exe"PrevX Home intrusion prevention software"
YPrevxOnePXConsole.exe"Prevx intrusion prevention software"
YPrevxProSAGUI.exe"PrevX Home intrusion prevention software"
XPrint Driver Helper Servicecrsrr.exe"Added by the AGENT-BC TROJAN!"
NPrint Master Event ReminderPMremind.exe"Event reminder for calendar dates
XPrint Schedulerusnsvc.exe"Added by a variant of the KOBOT-C WORM!"
XPrint Servicesspolserv32.exe"Added by the RBOT.ZP WORM!"
XPrint SpoolerSpoolsv.exe"Added by the CIADOOR.B TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %Windir%"
XPrint Spoolerspoolsvc32.exe"Added by the SDBOT.BB TROJAN!"
XPrint Spoolerspoolsv32.exe"Added by the RBOT.SW WORM!"
XPrintervmmon32.exe"Added by the RBOT-CSB WORM!"
XPrinter Servicesspool.exe"Added by the RBOT-Y WORM!"
XPrinter spool Servicespool.exe"Added by the RBOT-ACP WORM!"
Xprinterdrvvdms.exe"Added by the OPTIXKIL.30 TROJAN!"
XPrinting Drivermsprint.exe"Added by the RBOT.JH WORM!"
XPrintSpoolSvSystem.exe"Added by the BDOOR-S BACKDOOR!"
UPRISMSVRPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
UPRISMSVR.EXEPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB Adapter
NPrivacy Eraser ProPrivacyEraser.exe"Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities"
XPrivacy GuarantorPrivacyGuarantor.exe"Privacy Guarantor rogue privacy program - not recommended
YPrivacy GuardianPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
UPrivacy Guardianpg.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Cache
XPrivacy ProtectorPrivacy Protector.exe"PrivacyProtector rogue privacy tool - not recommended
XPrivacy WatcherPrivacy Watcher.exe"Privacy Watcher rogue privacy program - not recommended
XPrivacyConductorGDC.exe"PrivacyConductor rogue privacy tool - not recommended
YPrivacyGuardianIndexPgIndex.exe"Part of Privacy Guardian from PC Tools - which ""is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer"". This startup entry runs only on the next reboot if the ""Index.dat"" option is selected for IE under ""Browsers"" when the users selects ""Clean Your Computer"". Index.dat files keep a track of pages
UPrivacyKeyboardPrivacyKeyboard.exe"PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices
XPrivacyProtector FreeUPRP.exe"PrivacyProtector rogue privacy tool - not recommended
XPrivacyScannerpscan.exe"Privacy Champion
XPrivacyWarriorGDC.exe"PrivacyWarrior rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
NPrivateDiskpdservice.exe"Part of SafeGuard PrivateDisk from Utimaco - which ""securely and transparently protects sensitive files on notebooks and desktop computers
XPrivateNet[various filenames]Premium rate adult content dialler
UPrivoxyprivoxy.exe"Privoxy - web proxy with advanced filtering capabilities for protecting privacy
XPrnShareWscript.exe prn_share.vbs"Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""prn_share.vbs"" file is located in %System%"
XProAntiVirusProAntiVirus.exe"Added by the RBOT-FTP WORM!"
XPROCESS SESSION MANAGERPIDSERV.EXE"Added by the RBOT-Y WORM!"
UProcessGovernorprocessgovernor.exe"Core engine for Process Lasso from Bitsum Technologies - ""a state-of-the-art
XProcessorsvchost.exe"Added by the AGENT-KIR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root directory (i.e. C:\ or D:\)"
UProcessSupervisorGUIProcessSupervisor.exe"Graphical user interface (GUI) for Process Lasso from Bitsum Technologies - ""a state-of-the-art
XProfileProfile.vbs"Added by the WHITEHO VIRUS or TRAPPY WORM!"
XProgram Access Service[10 random letters].exe"Added by the RBOT.GJJ WORM!"
UProgressive TouchSynTPEnh.exe"Synaptics TouchPad Enhancements - included with drivers for Synaptics based TouchPads
UProgressive TouchSynTPLpr.exe"Synaptics TouchPad driver helper - included with drivers for Synaptics based TouchPads
Xprompt drive[random filename]"Added by the SDBOT.AMF WORM!"
UProtectSHVRTF.EXE"PC Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash
XProtectionDeDriverGDC.exe"ProtectionDeDriver rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
XProtejaseuDriveSysRep.exe"ProtejaseuDrive rogue system error and cleaning utility - not recommended. A member of the ErrClean family"
XProtocol Settingskav.exe"Added by a variant of the RBOT WORM!"
XProtocolDiskChksvcvlw32.exe"Added by the STINX-Y TROJAN!"
XProtocolEventTskcsrwjd.exe"Added by the STINX-N TROJAN!"
Xprovprov.exe"Added by a variant of the IRCBOT TROJAN!"
XProvan Securitypsecure.exe"Added by the RBOT.BRV WORM!"
XPrU Async Service[path to worm]"Added by the IRCBOT-UG WORM!"
Xprvtectprvtect.exe"Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications
YPSDrvCheckPSDrvCheck.exe"Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled"
XPServicesvcnow32.exe"Added by the SPYBOT-DJ TROJAN!"
XPSGuard spyware removerPSGuard.exe"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
YPSIMSVCPSIMSVC.exe"Part of Panda Antivirus and Internet Security"
NPSIWin2.3 Connection ServerPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
Xpsybnc server 3.1psybnc321.exe"Added by the RBOT.ENI BACKDOOR!"
XpsyBNC-2.1.4 Client ServerpsyBNC215.exe"Added by a variant of the RBOT WORM!"
XPTRGMYGK"rundll32.exe ptmg1v.dll DllRunMain"
UPUAC v2.0.7Puac.exe"""Peter's Ultimate Alarm Clock"""
UPurgativePURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
Xpushbotservice52.exe"Added by a variant of the PUSHBOT WORM! A family of worms that spread using MSN Messenger"
UPV92TRAYPV92Tray.exe"PCtel HSP V.92 modem configuration utility"
XPVModulepvmodule.exe"Adperform.com/Adoptim.com adware - located in %ProgramFiles%\PrintView and detected by Avira AntiVir antivirus as the AGENT.ALB TROJAN! NOTE - the 'real' PrintView installs in C:\CBR folder"
NPVRPVR.exe"Pocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card"
UPVUnInst1PVUnInst1.exe"Privacy View - privacy software that ensures that all your private computer files
NPWRISOVM.EXEPWRISOVM.EXE"PowerISO - a powerful CD/DVD image file processing tool"
UPwrsavePwrsave.exeToshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
UPWSActivePrint_5ActivePrintSystem.exe"ActivePrint from Pocket Watch LLC - ""Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware"""
NQ152404wsript.exe Q152404.VBSAppears to run Scandisk at bootup on NEC PCs
Xqappsrvc32.exeqappsrvc32.exe"Detected by Kaspersky as the WEBBER.M TROJAN!"
YQCDriverInstallerLqdsw.exe"Launches the camera driver setup wizard on the first reboot after installing Logitech's ClickSmart
XQffecdasvvzxx.exe"Added by the MULTIDRP.AA TROJAN!"
YQH Live Update SchedulerUPSCHD.EXE"Quick Heal Anti-Virus"
Xqkoszvd.dll"rundll32.exe qkoszvd.dlljwezubg"
UQPServiceQPService.exe"HP QuickPlay - ""brings your favorite music and movies to life with the touch of a button"""
XQQKAVscvhsot.exe"Added by the QQROB.ARQ WORM!"
XQQServerQQ.exe"Added by the DOWNLDR-AN TROJAN!"
Xqservicesqservice.exe"Added by the PROGENT-A TROJAN!"
XQTSvcmsocfg.exePremium rate adult content dialler
XQTSvcnavchk.exePremium rate adult content dialler
XQTSvcshman.exePremium rate adult content dialler
XQTSvcssvr.exePremium rate adult content dialler
UQtVprMtxQTVPRMTX.EXE"Multimedia keyboard driver from Dritek System Inc"
XQuick Officeactivate.exe"Added by the RANSOMLOCK.D TROJAN! Note - this infection hooks the keyboard to prevent anything except numbers from being typed and displays a Russian message requesting a valid license key"
NQuick View PlusQVP32.EXEQuick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs
UQuickBooks Database Server ManagerQBServerUtilityMgr.exe"Part of QuickBooks Pro/Premier from Intuit - ""QuickBooks Database Server Manager is a utility that allows you to configure the QuickBooks Server for multi-user access."" See here for further information"
NQuickBooks Delivery AgentQBDAGENT.EXEAs far QAGENT but for QuickBooks. Can also have the version number in the name
UQuickDVBTQuickDVB-T.exe"AVerTV_DVB-T connects Digital TV with your PC or Notebook and allows you to watch free-to-air digital terrestrial television channels with no subscription to pay"
UQuickTVQuickTV.exe"Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control"
Xqvqeqgebv.exe"Added by the AGOBOT-OJ WORM!"
XRA ServerSlave.exeAdded by the RA TROJAN!
URadioSvrRadioSvr.EXEUsed to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
URAID Event MonitorIaanotif.exe"Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes
URAMDriveRDTask.exe"Virtual Hard Drive Pro from Farstone - ""takes a portion of your system memory and creates a RAM disk drive
XRandex virus built for IRBMeirbme.exe"Added by the RANDEX.RH WORM!"
XRandom Interface Network Managerrinsv.exe"Added by the DELBOT-L WORM!"
XRapdataravsecs.exe"Added by the QQPASS-V TROJAN!"
XRapdatybsravseteyns.exe"Added by the PWS-ACP TROJAN!"
XRapid AntivirusRapid Antivirus.exe"Rapid Antivirus rogue security software - not recommended
XRaptelnetravspeger.exe"Added by the QQPASS-AA TROJAN!"
XRapteltravspegtl.exe"Added by the QQPASS-AB TROJAN!"
YRaptor Mobilevpnservices.exe"Symantec VPN Client used to connect to corporate networks. If unchecked
XRasCon Remote Access Service Managerrasmngr.exe"Added by the SPYBOT.EM WORM!"
YRAV8Trayravtray8.exe"RAV anti-virus related"
XRavAvRavMonE.exe"Added by the RJUMPF-F WORM!"
XRavAvAdobeR.exe"Added by the RJUMP.D WORM!"
XRAVEN_VLZS.EXERAVEN_VLZS.EXE"DownloadReceiver parasite - no longer in existence"
YRavMonRavMon.exe"RAV AntiVirus"
Xravshellexpl0rer.exe"Added by the DLOADER.MAR TROJAN!"
XRavshellexplore3.exe"Added by the PAKES.HZ TROJAN!"
XRavshellIEXPLORER.EXE"Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XRavshellrund1132.exe"Added by the AGENT.OKZ TROJAN!"
XRavshellsvch0st.exe"Added by the NSPM.PU TROJAN! Notice the digit ""0"" in the filename rather than the lower case ""O"""
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
Xravshelliexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
YRavStubravstub.exe"Rising antivirus"
Xravtaskrund1132.exe"Added by the DLOADER.IYT TROJAN!"
Xravtasksvch0st.exe"Added by the LINEAG-AIN TROJAN!"
YRavTaskRavTask.exe"Rising antivirus"
Xravtaskiexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
XRavTimeMstray.exe"Added by the WUKILL.A WORM!"
YRavTimerRavTimer.exe"RAV AntiVirus"
XRavTimerexplores.exe"Added by the HOMEY-A TROJAN!"
XRavTimeXP[worm filename]"Added by the WULLIK.B WORM!"
XRavTimeXPVirus"Added by the CAGER.A WORM!"
XRavTimXP[worm filename]"Added by the WULLIK.B WORM!"
XRavUptetsagetlke.exe"Added by the QQPASS-AK TROJAN!"
XRavUptktagetlktz.exe"Added by the QQPASS-AJ TROJAN!"
XRavUptperavsesur.exe"Added by the QQPASS-T TROJAN!"
?rav_temp.exerav_temp.exe"??"
Xrbnynkctvrbnynkctv.exe"Added by the AGENT-GPA BACKDOOR!"
XRBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Serverglossary.exe"Added by the VANEBOT-J WORM!"
XRCAutoLiveUpdateMaxLURC.exe"Max Registry Cleaner rogue registry cleaner - not recommended
XRcf Driverrcf.exe"Added by the RANDEX.BLD WORM!"
XrCrondservice.exe"""Switch"" premium rate adult content dialler variant"
XRDPlatinum v5RDPlatinumv5.exe"Registry Defender Platinum rogue registry cleaner - not recommended
Xrdvs[worm filename]"Added by the ULTIMAX.B WORM!"
XRealAV.exeRealAV.exe"Real Antivirus rogue security suite - not recommended
XRealplayer VideoRealPlay.exe"Added by a variant of the RBOT WORM!"
URealtek AC97 Audio - Event MonitorALCMTR.EXE"Realtek Azalia Audio - Event Monitor
URealtek Voice ManagerSkytel.exe"Realtek Voice Manager
UReceiverPcfaxRcv.exe"Incorporated on multifunction digital copiers (such as the
NRecoverN/AAdded during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
Xrecover.bmp.exeRundll.exe"Added by the ANAFTP-01 TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
NRecoverFromRebooRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebooRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
NRecoverFromRebootRecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
XRecoveru systemsvchast.exe"Added by a variant of the LINEAGE-AV TROJAN!"
XRecoveru systemssvchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
XReek 32 Serverreek32.exe"Added by the RANDEX.AL WORM!"
UReflex VisionReflexVision.exe"Reflex Vision from Increment Software. ""A background application for Windows XP that makes switching windows faster and easier"""
XReg Servicewinsy.exe"Added by a variant of the SPYBOT WORM!"
XReg Servicewinslogon.exe"Added by the AGOBOT-SC WORM!"
XReg Serviceipcfg.exe"Added by the AGOBOT-SO WORM!"
XReg ServiceREGSRV32.EXE"Added by the RBOT.ZW WORM!"
XReg ServiceWinnConfig.exe"Added by the AGOBOT-PF WORM!"
XReg ServiceNT32.exe"Added by the AGOBOT.G TROJAN!"
XReg ServicesWinboot32.exe"Added by the RBOT.PB WORM!"
Xreg1.regvuamgard.exe"Added by a variant of the IRCBOT TROJAN!"
Ureg2.0SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
XRegDoneservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
XREGEDITRegsrv32.com"Added by the SOUTHGHOST WORM!"
Xregeditsvchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
XRegexitUpdadv.exe"Added by the QQPASS-N TROJAN!"
Xreggsdgspoolserv.exe"Added by the SDBOT-MS WORM!"
Xreggsdgspoolsrv.exe"Added by the SDBOT-DI WORM!"
URegHelpsvchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
?Register SeqChkregsvr32.exe ..csseqchk.dll"??"
XRegistration Servicetoker.exe"Added by the SDBOT-BB WORM!"
XRegistration Servicemsvdm6.exe"Added by the SDBOT-HE TROJAN!"
XRegistrywscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
URegistry Mechanic Vista TrayRMTray.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
XRegistry Servregsvr.exe"Added by the WEBMONEY-G TROJAN!"
XRegistry Serverregsrv32.exe"Added by the RBOT-GM WORM!"
XRegistry Serverregserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRegistry ServiceREGSRV32.EXE"Added by a variant of the RBOT WORM!"
XRegistry Serviceresvs.exe"Added by the DELBOT-I WORM!"
XRegistry Serviceregsvc.exe"Added by the IRCBOT-ZM BACKDOOR!"
XRegistry ServicesRegistry.exe"Added by the CILE TROJAN!"
XRegistry Value Nameroses.exe"Added by the RBOT-AFT WORM!"
XRegistry Value Nameservice.exe"Added by the RBOT-AHT WORM!"
XRegistry Value Namewinapi32.exe"Added by a variant of the RBOT WORM!"
XRegistry Value Namesyswinxp.exe"Added by the RBOT.BTZWORM!"
XRegistry Value Nameenzxp.exe"Added by the RBOT-BAJ WORM!"
XRegistry Value Name StartMsPMSPSa.exe"Added by a variant of the SDBOT WORM!"
XRegkey for autostartwinservice.exe"Added by the RBOT-NU WORM!"
XRegRunmActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XRegScanDLLSRV32.EXE"Added by the AGOBOT.AEW WORM!"
?RegServerregserve.exe"Related to XGI Technology's Volari graphics cards - what does it do and is it required?"
Xregservices.exeregservices.exe"Added by an unidentified VIRUS
NRegShaveregshave.exe"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers
Xregsrvregsrv.exe"Added by the OPTIXPRO.11 TROJAN!"
Xregsrvscvhost.exe"Added by the AGOBOT.E WORM!"
XRegSrv64DRegSrv64D.exE"Added by the WINKO.AO WORM!"
Xregsrvcregsrvc.exe"Added by the STOPED-A TROJAN!"
XRegsvregsv.exeSearch hijacker - redirecting to scheo.com
XRegsvcregsv.exeAdded by an unidentified TROJAN!
Xregsvcsysd"Sys Detective+ spyware"
Xregsvc32regsvc32.exeHomepage hijacker that changes your homepage to an adult content site
Xregsvrregsvr.exe"Added by the WEBMONEY-G TROJAN!"
UREGSVR32regsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
XRegSvr32msmsgs.exe"Added by the ZLOB.B TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
XRegVerREGVER.EXE"Added by the LATINUS.16 TROJAN!"
XRegVfy32Regverif32.exe"Added by the SYGYP.A WORM!"
XRelevantKnowledgerlvknlg.exe"Marketscore.RelevantKnowledge adware"
Xreloadreload.vbs"Added by the LOVELETTER.AS VIRUS!"
Xreluvageilulupac.exe"Added by the SDBOT-UJ WORM!"
XRemote Access Adapterrvasvc.exe"Added by the IRCBOT.BIF BACKDOOR!"
XRemote Access Domainrswsvc.exe"Added by the IRCBOT.BFA TROJAN!"
XRemote Access Monitorrpgsvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRemote Access Service Managerrasmngr.exe"Added by the AGOBOT.KU WORM!"
XRemote Access SlaveSynchost.exe"Added by the RIPJAC TROJAN!"
XRemote Access Toolrwosvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NRemote ControllerTVRMVCR.EXE"ProLink PlayTVpro TV tuner software"
XRemote Event Systemresmsvc.exe"Added by the IRCBOT.YF BACKDOOR!"
XRemote Services Managermsrmsvc.exe"Added by the SLENFBOT.AJ WORM!"
XRemote Storage Accessrmasvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XRemote Terminal Taskrtsbsvc.exe"Added by the IRCBOT.AUZ BACKDOOR!"
URemoteControlPDVDServ.exe"Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
URemoteControl8PDVD8Serv.exe"Remote Control background application for Cyberlink's PowerDVD version 8. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
XREMOVE MEwindos.exe"Added by the SDBOT.EE WORM!"
XREMOVE MEtbbzxzxcxxcx.exe"Added by the SDBOT-TA WORM!"
XREMOVE MEasclt.exe"Added by the RANDEX-FC WORM!"
NRemovecplRemovecpl.exeRelated to a Belkin 54Mbps Wireless Utility Control Panel applet
XRemoved.exeRemoved.exeGatorCheat - adware downloader
URemoveIT Pro XTremoveit.exe"RemoveIT Pro from InCode Solutions - spyware
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
XRequired Service Driversmicront.exe"Added by the RBOT-ABD WORM!"
Xreseurcesvchost.exe"Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?Restart_VSViewsonic.exeCould be a left-over from the installation of a Viewsonic flat panel display
XRestore Operationsvchots.exe"Added by a variant of the RBOT WORM!"
YRestoreIT!VBPTASK.EXE"RestoreIT! from FarStone - ""automatically backs up all files on your computer to a protected partition on your hard drive"""
Xreszrv[8 random letters].exe"Added by a variant of the SDBOT WORM! See here"
URetrieverSchedulerretrieverscheduler.exe"80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders
URevoTaskbarAppRevoTask.exeControl Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available
NRFX_auto_upgraderundll32.exe npvpg005.dll"A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
URightFAX Print-to-Fax DriverFaxCtrl.exe"Part of RightFAX from Captaris - ""the proven market leader in fax server and document delivery software"""
XrIOphosIsrIOPHosIs.vBS"Added by the RIOSYS MACRO!"
URivaTunerRivaTuner.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTuner ApplicationRivaTuner.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTuner.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerStartupDaemonRivaTunerWrapper.exe"Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
URivaTunerWrapper ApplicationRivaTunerWrapper.exe"RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Vista and can appear twice - with registry key names of ""RivaTuner"" and ""RivaTunerStartupDaemon"" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the ""Launcher"" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
Urmoc3260.dll OCXregsvr32.exe rmoc3260.dll"A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The ""rmoc3260.dll"" file is found in %System%"
XRNBc Testwf32vbs.exe"Added by the RBOT-AGR WORM!"
XRNBc Testbvldv32.exe"Added by the RBOT-AJF WORM!"
XRNBz Testwf32vbc.exe"Added by the RBOT-AEY WORM!"
XRoam04ActiveX.exe"Added by the ROAMER-A TROJAN!"
YRogueMonitorRogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
YRogueRemoverPRORogueRemoverPRO.exe"Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
Xrollbksvosm.exe"Added by the SERFLOG.B WORM!"
XRPC DCOM Vulnerability Patchmsgfix.exe"Added by the RBOT.S WORM!"
XRPC Driversrpcall.exe"Added by the SDBOT.FLY WORM!"
XRPC Service[random filename]"Added by the BDOOR-AAD BACKDOOR!"
Xrpc Win32spoolscv.exe"Added by a variant of the RBOT WORM!"
XRPCser32gservices.exe"Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g1services.exe"Added by the PREX.D WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g3services.exe"Added by the PREXOT.D BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCser32g4services.exe"Added by the PREXOT.E BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32services.exe"Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gservices.exe"Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gCSRSS.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRPCserv32gMSDEFR.EXE"Added by the BOBAX.AD WORM!"
XRPCserv32gNB32EXT2.EXE"Added by the BOBAX.AD WORM!"
XRPCserv32gWINLOGON.EXE"Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
URPSPRpsserv32.exe"Red Pill Spy surveillance software. Uninstall this software unless you put it there yourself"
XRSPC Driver[random filename].exe"Added by the RBOT-SN WORM!"
XRSPC Driver D[random filename]"Added by a variant of the RBOT WORM!"
Xrsrvmon.exersrvmon.exe"Added by the AGENT.NY TROJAN!"
NRtHDVCplRtHDVCpl.exe"Realtek HD Audio Manager
Yrtvscn95RTVSCN95.EXEReal-time virus scanner component of Norton Anti-Virus Corporate Edition
Xrunservices.exe"Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066"
XRun MSupdt32wscript MSupdt32.vbs"Added by the CASER WORM!"
XRun Services as Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
Xrun windowsservic.bat"Added by the REBOOT-AP TROJAN!"
Xrun=svcinit.exe"CoolWebSearch parasite variant"
Xrun=RAVMOND.exe"Added by the LOVGATE-F WORM!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
URunAlertAService.exe"PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/2K"
YRunCAInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
XRundil32Updadv.exe"Added by the QQPASS-N TROJAN!"
URUNDLL32"RUNDLL32.EXE NvQTwkNvCplDaemon"
URunDLL32"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
Xrundll32rookie.vbs"Added by the ROOKIE-A TROJAN!"
Urundll32"rundll32.exe nview.dllnViewLoadHook"
Xrundll32svchs0t.exe"Added by the PWSTEAL-E TROJAN!"
XRundllSvrRundll.exe"Added by the HUAYU WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRunnersvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunProgServer.exe"Added by the OPTIX.04.A TROJAN!"
Xrunreperviewer.exe"Added by the REPER.A VIRUS!"
XRunSearvicestread.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XrunSubvalues[path to file]"Added by the DLOADER-QY TROJAN!"
Xrunsvcrunsvc.exe"Added by the SMALL-CF TROJAN!"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
XRVC6Playertskdbg.exe"Added by the ZAPCHAS-M TROJAN!"
XrvdeN/ARelated to li-speed****
XRVPbpc.exe"BroadcastPC adware"
Xrw servicealg32.exe"LOOPAD.A adware"
Xrxres32ati2vid.exe"Added by the RBOT-FL WORM!"
Xryan1918servidevice.exe"Added by the RBOT-GVR WORM!"
YR_serverr_server.exe"Radmin - remote admistrator server. Note - the file is located in %ProgramFiles%\Radmin"
Xr_serverservice.exe"Added by the MULTIDR-CP TROJAN!"
Xr_serverr_server.exe"Added by the HACDEF-DR TROJAN! Note - do not confuse with the valid Radmin file with the same name which is located in %ProgramFiles%\Radmin. This one is located in %System%"
XSsvhost.exe"Added by the AGOBOT-LN WORM!"
XS0undMansvch0st.exe"Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
?S24EvMonS24EvMon.exe"Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?"
XS3 Internal Chips3serv.exe"Added by the AGOBOT-DD WORM!"
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
?SA ServiceSAservice.exe"Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?"
NSa3dsrvSa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
USabre Serversabserv.exe"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
USabreserverSABSERV.EXE"Part of the Sabre computer reservations system/global distribution system (GDS) - used by airlines
XSafeGuard Popup Blocker Updaterregsvr32 sfgupd.dll"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Blocker Updater (required)regsvr32 sfg****.dll [* = ramdom char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 sfg****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeGuard Popup Updater (required)regsvr32 PDF****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
XSafeHardDriveSysRep.exe"SafeHardDrive rogue system error and cleaning utility - not recommended
XSafePcAvSafePcAv.exe"SafePcAv rogue security software - not recommended
USAGENTSERVICESagent.exe"TinySpyAgent commercial keystroke logger. Uninstall this software if you did not install it yourself"
XSaggwwggCVAvwwd.exe"Added by the LIOTEN.HT WORM!"
XSalestartmav_startupmon.exe"Part of the WinAntiVirus Pro 2007 rogue security software - not recommended
XSaMail[WORM FILE NAME].vbs"Added by the VBS.LIDO WORM!"
XSANS Servicesansv.exe"Added by the VANEBOT-AH WORM!"
YSAVAgentSAVAgent.exe"Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly
XSavasddwqffasd.exe"Added by the SDBOT-SI WORM!"
XSaveSave.exe"WhenU.Save adware"
XSavelssas.exe"Added by an unidentified TROJAN! See here"
XSaveArmorSaveArmor.exe"SaveArmor rogue security software - not recommended
XSaveDateSaveStartDate.ExeUnidentified adware
XSaveDefenderSaveDefender.exe"SaveDefender rogue security software - not recommended
XSaveDefenseSaveDefense.exe"SaveDefense rogue security software - not recommended
XSaveKeepSaveKeep.exe"SaveKeep rogue security software - not recommended
XSaveKeeperSaveKeeper.exe"SaveKeeper rogue security software - not recommended
XSavenowSaveNow.exe"WhenU.Save adware"
XSaveSoldierSaveSoldier.exe"SaveSoldier rogue security software - not recommended
XSavsvc"rundll32.exe savsvc.dllstart"
USBDrvDetSBDrv.exe"Detects the ""Easy Front-Panel Audio Connectivity Drive Internal Drive Bay"" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one"
Nsbdrvdetsbdrvdet.exeChecks to see if Creative sound card driver should be updated
XScamDiskSVOHOST.exe"Added by the LEWOR.D WORM!"
XScanRegistrynsrvnt.exe"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"
XScanRegistryscanregv.exe"Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe"
NScanSoft PaperPort 7 Registration ReminderNAVBrowser.EXE"Registration reminder for PaperPort 7 from Scansoft (now Nuance)"
XScanSpyware v3.2Scanner.exe"ScanSpyware rogue security software - not recommended
XScanSpyware v3.5Scanner.exe"ScanSpyware rogue security software - not recommended
XscAppwmiprvse.exe"Added by the SILLYFDC-AW WORM!"
NSCardSvrscardsvr.exeRelated to SmartCard readers and sometimes uses lots of system resources
XSCardSvrSCardSvr32.Exe"Added by the MOFEI.B WORM!"
XScheduIrsvchst.exe"Added by a variant of the SDBOT WORM!"
XSchedulersvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XSchedulersvchst.exe"Added by the TACTSLAY.B TROJAN!"
XScheduler Servicewsass.exe"Added by the LIOTEN.KX WORM!"
XSchedulerMgrnavchk.exePremium rate adult content dialer
NSchSvrSchSvr.exe"WinScheduler is installed with Home Theater or WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card
NScotia OnLine Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
NScotia OnLine Security v*.* Recoveryetdirrcv.exe"Scotia OnLine Security Software provided by Entrust for
XScreen Saverscrnsaver.scr"Added by the RBOT-AGP WORM!"
NScreen Saver ControlFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
YScriptBlockingSBServ.exe"Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information"
UScroll-In-Mouse V2.0SCROLL.EXE"Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
Xscrsvcscrsvc.exe"Added by the AGENT-DS TROJAN!"
XScrSvrScrSvr.exe"Added by the OPASERV WORM!"
XScrSvrOld[worm filename]"Added by the OPASERV WORM!"
Xscssrr.exeServices.exe"Added by the VB-EMX TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xscvhostsvzhost.exe"Added by a variant of the SPYBOT WORM!"
Uscvhostscvhost.exe"Wiretap surveillance software. Uninstall this software unless you put it there yourself"
Xscvhostscvhost.exe"Added by the AGOBOT-LI WORM!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
Xscvhost.exescvhost.exe"Added by the LOHAV-N TROJAN!"
XScvsrv32scvsrv32.exe"Added by the AGOBOT-PM BACKDOOR!"
USDAutoLiveupdateLiveUpdateSD.exe"Spyware Detector - spyware remover. Initially not recommended due to false positives but the later versions have since improved - see here"
XSDAvcsnss.exe"Added by the SERFLOG.C WORM!"
XSDAvsvhost.exe"Added by the SERFLOG.C WORM!"
Xsdchosts32vbdd.exeAdded by the RANKY.AG TROJAN!
XSDK Codre Function22sdkimddprovment2.exe"Added by the SDBOT-YJ WORM!"
XSDK Core Functionsdkimprovment.exe"Added by the RBOT.BHL WORM!"
XSDK Core Function2sdkimprovment2.exe"Added by the SPYBOT.OGX WORM!"
XSDR6V_Checkudcsdr.exe"Part of the DriveCleaner rogue security software - not recommended
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
XSearch.vbsHijacker
Xsearchbarvnmispoisn downloader.exeSearchBarCash adware variant
Xsearchnavsearchnav.exeSearchNav adware - IEFeatures/Popnav variant
XSearchNavVersionsearchnavversion.exeSearchNav adware - IEFeatures/Popnav variant
XSearchNet_UpServeUp.exe"SearchNet adware"
Xsecbootvtd 16.exe"Added by the HAXDOOR-AE TROJAN!"
Xsecdrive.exesecdrive.exe"Added by a variant of the SPYBOT WORM! See here"
Xsecserv.exesecserv.exe"Detected by Panda as an EasySearch adware variant. Note - EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer"
Xsecsvc32secsvcnt.exe"Added by the GLOBAL PATROL TROJAN!"
Xsecuresvshost.exe"Added by the RBOT-AFO WORM!"
XSecure AntiVirus Proav.exe"Secure AntiVirus Pro rogue security software - not recommended
XSecurePcAvSecurePcAv.exe"SecurePcAv rogue security software - not recommended
XSecureVeteranSecureVeteran.exe"SecureVeteran rogue security software - not recommended
XSecurity AntivirusSA[random characters].exe"Security Antivirus rogue security software - not recommended
XSecurity Antivirus Xp 1inetfor.exe"Added by the SDBOT.BAV WORM!"
XSecurity Master AVSM[random characters].exe"Security Master AV rogue security software - not recommended
XSecurity Server DBsecserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
Xsecurity servicesyss.exeAdded by an unidentified WORM or TROJAN!
XSecurity Servicesecsvc.exe"Added by the RBOT-GGF WORM!"
XSecurity Service DBsecservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XSecurity Service Processsvhost.exe"Added by the AGOBOT-LC WORM!"
XSecurity Update Servicewmiprvce.exe"Added by the AGOBOT.ZW WORM!"
XSecurity Update Service Processsvrhost23.exe"Added by the AGOBOT-GN WORM!"
Xseeveseeve.exe"Medload adware"
XSelect serverslcsvr.exe"Added by the DLOADER-WD TROJAN!"