10658 Y !1_pgaccount pgaccount.exe "DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly" Y !1_ProcessGuard_Startup procguard.exe "DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks." U !NoLoad winrecon.exe "WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it" U $EnterNet Enternet.exe Connection manager for the EnterNet ISP. You can also use RASPPOE X $WindowsRegKey%update IEXPLORE.EXE "W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually!" X (L4r1$$4) (4nt1) (V1ruz) SP00Lsv32.pif ASSIRAL.B WORM! X *JanisRuckenbrodII janis.com POPS VIRUS! X *Microsoft Update ctxma.exe W32.HLLW.STMU TROJAN! X *Microsoft Update cxma.exe W32.HLLW.STMU TROJAN! X *microsoft update cxma.exe W32.HLLW.STMU TROJAN X *Microsoft Update wstcl.exe W32.HLLW.STMU TROJAN! X *Microsoft Update wucxt.exe W32.HLLW.STMU TROJAN! X *Microsoft Update wuytc.exe W32.HLLW.STMU TROJAN! X *MS Setup ?? "Virtumondo adware, also known as the VUNDO TROJAN!" X *Security Center secctr.exe SDBOT.BRO WORM! Y *StateMgr statemgr.exe Windows ME default for System Restore. Do NOT disable! X *windows update waurclt.exe variant of the WIN32.RBOT WORM! X *windows update wkmst.exe SDBOT.AVD WORM! X *windows update wsctl.exe SPYBOT.PR WORM! X *windows update wscxt.exe RBOT.AOS WORM! X *windows update wuaucrlt.exe SPYBOT.HUR WORM! X *windows update wurauclt.exe W32/RBOT-SY WORM! X *WinLogon ?? VUNDO TROJAN! X *winstats winstats.exe Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder. X *wuauclt.exe wmsvc.exe W32/RBOT-UG WORM! X ",main drive Loader" wininfo.exe Suspected malware as it appears in 3 different registry locations - see here X .mscdr lassa.exe WEBUS.C TROJAN! X .mscdr lsvchost.exe WEBUS.D TROJAN! X .mscdsr lsvchost.exe Troj/Bdoor-CR Trojan! X .mscsbl svhost.exe BACKDOOR-CMQ TROJAN! X .msfupdate msveup.exe W32.ALLOCUP.A WORM! X .mssecure mssecure.exe DDOS_BOXED.X TROJAN! X .mssecure mssecure.exe Troj/Borobot-B Trojan! X .norton rchost.exe variant of the BOXED-A TROJAN! X .Prog services.exe NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process X .Prog winlogon.exe NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process X .svchost CSRSS.EXE "WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X .TEXTCONV csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X .WMAudio csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process"" which provides text window support, shutdown, and hard-error handling" X .WMAudio lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" N /l:eng ?? "Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup" X ;Rundll ?? PWSLEGMIR.E VIRUS! X ?? ?? Troj/StartPa-GL Trojan! Found in the WINDOWS or Winnt directory. X ?? ?? Troj/Mosuck-H TROJAN! X ?? _autorun.exe W32/Antinny-L WORM! X ?? _cfg.exe W32/Antinny-L WORM! X ?? _config.exe W32/Antinny-L WORM! X ?? _ctcp.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? _env.exe W32/Antinny-L WORM! X ?? _loader.exe W32/Antinny-L WORM! X ?? _login.exe W32/Antinny-L WORM! X ?? _setup.exe W32/Antinny-L WORM! X ?? _start.exe W32/Antinny-L WORM! X ?? 10010.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? 321102.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? 321102.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? 34763.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ABCXYZ.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? abrek.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? acctres8.exe Adsrv.com/IeDriver adware variant X ?? ActionScr.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? actxprxy.exe Adsrv.com/IeDriver adware variant X ?? admparse.exe Adsrv.com/IeDriver adware variant X ?? advpack1.exe Adsrv.com/IeDriver adware variant X ?? AliceSD.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? AppMasterCenter.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? asferror.exe Adsrv.com/IeDriver adware variant X ?? atitvo32.exe Adsrv.com/IeDriver adware variant X ?? atl_helper.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ATLIEHELPER.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? audiosrv.exe Adsrv.com/IeDriver adware variant X ?? autodisc.exe Adsrv.com/IeDriver adware variant X ?? avicap32.exe Adsrv.com/IeDriver adware variant X ?? avifile5.exe Adsrv.com/IeDriver adware variant X ?? avpmondll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? awinrar.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? backd.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? backorif.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? barint.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? batmeter.exe Adsrv.com/IeDriver adware variant X ?? bhoserv.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? bidispl2.exe Adsrv.com/IeDriver adware variant X ?? bingo9.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? bling.exe W32/RBOT-NI WORM! X ?? bnui.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Bogobot.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? bootvid2.exe Adsrv.com/IeDriver adware variant X ?? bootvid4.exe Adsrv.com/IeDriver adware variant X ?? borlandg.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? BoundRec.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? br0ken.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Brong32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? browser8.exe Adsrv.com/IeDriver adware variant X ?? cabview1.exe Adsrv.com/IeDriver adware variant X ?? catsrvps.exe Adsrv.com/IeDriver adware variant X ?? cdmodem4.exe Adsrv.com/IeDriver adware variant X ?? charmapnt.exe Troj/Bancos-DR TROJAN! X ?? chkdsk.exe "PurityScan/Clickspring adware - unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2000/NT always be located in the Winnt\System32 or Windows\System32 folder, and ought moreover NOT to figure among the startups!" X ?? clamav.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" N ?? cmmpu.exe MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) X ?? cmon14.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? cmon14.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? cmpbk321.exe Adsrv.com/IeDriver adware variant X ?? cnftips.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? control64.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? corrida.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? CToolBar.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? CXTPLS_LOADER.EXE AproposMedia adware X ?? d?dplay.exe PurityScan/Clickspring adware X ?? d?xplore.exe PurityScan/Clickspring adware X ?? DCC_send.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? defect08.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? dePloy.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Dest068.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? dexplore.exe PurityScan/Clickspring adware X ?? dialer423.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? die.exe SUMTAX VIRUS! X ?? diskcheck.exe BACKDOOR.SINGU.B TROJAN! X ?? diskserv.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" N ?? dlbabmgr.exe Dell AIO Printer A940 related. Not Required at Startup X ?? driver32.exe variant of the W32/SDBOT WORM! X ?? driver64.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? DrWatson32.exe Dremn TROJAN! X ?? dstart2.exe Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.alw X ?? DTOURS.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? dvdplay.exe PurityScan/Clickspring adware X ?? ERTYDF.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ExchangeMaster.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? EXE32EXE.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? exe81.exe "MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on." X ?? exe82.exe "MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on." X ?? expoler.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? FLKPT.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? forces_elite.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ftbar.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" N ?? fts.exe 012 Israeli ISP dialer - can be loaded manually N ?? FWPortal.exe 012 Israeli ISP dialer - can be loaded manually X ?? gabber.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? hyandex.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? iehelper.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? iesetupdll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? init32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? InpriseMon.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? install2.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? j?vaw.exe PurityScan/Clickspring adware X ?? JAguAr.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? jopplerg.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Kargo.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? keybdll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? KeywordFinder.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? killall.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? l?ass.exe PurityScan/Clickspring adware X ?? l?gonui.exe PurityScan/Clickspring adware X ?? LOPTCON.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? lsass.scr Troj/Bancban-CW Trojan! X ?? m?config.exe PurityScan/Clickspring adware X ?? m?dtc.exe PurityScan/Clickspring adware X ?? m?iexec.exe PurityScan/Clickspring adware X ?? media64.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? mediaplayer32.exe variant of the WIN32.RBOT WORM! X ?? MNTP.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? MON76234.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? moniter.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? mozilla-text.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? msag.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? msdos32.exe variant of the WIN32.AGENT.AH downloader TROJAN! X ?? ms-its.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? MsNetHelper.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? MSTCPDLL.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? n?lookup.exe PurityScan/Clickspring adware X ?? n?pdb.exe PurityScan/Clickspring adware X ?? n?tdde.exe PurityScan/Clickspring adware X ?? n?tepad.exe PurityScan/Clickspring adware X ?? new32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? newbreed.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? nmdllw.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? NopeZ.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? NsCplTray.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? NSYSCPLSTR.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? NukeSpan.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? openstre.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? panel_its.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ParisM.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? PasswdMon.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? pathex.exe TROJ/MKMOOSE-A WORM! X ?? ping.exe PurityScan/Clickspring adware - NOTE - do not confuse with the Microsoft utility of the same name as described here X ?? pizda.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? powerdll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? PrcIdle.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? prcmon.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Preliminary.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? prgsys0984.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? progmen.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? qtsks.exe WEBDOR.Y TROJAN X ?? qwe.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? r?gedit.exe PurityScan/Clickspring adware X ?? r?gsvr32.exe PurityScan/Clickspring adware X ?? r?ndll.exe PurityScan/Clickspring adware X ?? r?ndll32.exe PurityScan adware variant X ?? roses.exe W32/Rbot-AFT Worm! X ?? RtlFindVal.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? runload32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? SAPSTR.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? sbin.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? scanregw.exe PurityScan/Clickspring adware X ?? scanSYS.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? se?vices.exe PurityScan adware variant X ?? seli.exe "MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on." X ?? Serviceprocess.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? SetupExeDll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Shaitan1678.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? sitebar.exe unidentified TROJAN! X ?? slamm.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? sound64.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? spoolsv.exe PurityScan/Clickspring adware X ?? SpyElim.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? srbho.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ssweeper.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? StartCpl.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? startman.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? StatusCheck.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? stuffmon.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? svchost.scr Troj/Bancban-CX and Troj/Bancban-DA TROJANS! X ?? svchost.scr Troj/Bancban-CY Trojan! X ?? svchost.scr BANKER-CC TROJAN! X ?? svchostss.exe variant of the WIN32.RBOT WORM! X ?? sysconf16.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? SysEntry.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? sysmon12.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? syspanel.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? SysSupport.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? System.exe Troj/Nethief-N Trojan! X ?? SYSTRAV.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? t?skmgr.exe PurityScan/Clickspring adware X ?? TemplateDongle.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? teqq32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Testimonials.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? TForm1.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? tmservice.exe variant of the WIN32.RBOT WORM! X ?? TorontoMail.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Trayz.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? TRPT.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? trycrt.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? ttg.exe SUMTAX VIRUS! X ?? typeconf.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? Uint32.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? uio.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? UserSp1.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? utsgmon.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? vxdman.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? w?aclt.exe PurityScan/Clickspring adware X ?? w?auboot.exe PurityScan/Clickspring adware X ?? w?auclt.exe PurityScan/Clickspring adware X ?? w?crtupd.exe PurityScan/Clickspring adware X ?? w?nlogon.exe PurityScan adware variant X ?? w?nspool.exe PurityScan/Clickspring adware. X ?? w?nword.exe PurityScan adware variant X ?? w?wexec.exe PurityScan/Clickspring adware X ?? WhatsNewBot.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? win32API.exe "Homepage hijacker, see here (* = any digit)" X ?? win32snd.exe W32/RBOT-DQ WORM! X ?? WinInitDll.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? winSOCKS.exe "Homepage hijacker, see here (* = any digit)" X ?? wormexe.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? WTFCTF.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? wuauboot.exe "PurityScan/Clickspring adware = NOTE: Do NOT confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!" X ?? wucrtupd.exe PurityScan/Clickspring adware - do NOT confuse with the Windows Critical Update Notification application as described here X ?? x1.exe Troj/Dadobra-A TROJAN! X ?? x2.exe Troj/Dadobra-A TROJAN! X ?? x3.exe Troj/Dadobra-A TROJAN! X ?? x4.exe Troj/Dadobra-A TROJAN! X ?? x5.exe Troj/Dadobra-A TROJAN! X ?? x6.exe Troj/Dadobra-A TROJAN! X ?? x7.exe Troj/Dadobra-A TROJAN! X ?? XTermInit.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? xwiz.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? xxtoolbar.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? zantu.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?? zxc.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X ?ekio Startups ?? W32/AGOBOT-OV WORM! X @ ?? SEEKER.K VIRUS! N @Hoc Toolbar AtHoc.exe One-click activated browsing toolbar used by various web-sites. See here for more info N @loha reminder.exe Registration reminder for @loha@home E-mail utility X @tour_ww ?? Adult content dialler X [Ephemeral 2.x] by TreeHugger ?? "LEMOOR.A WORM! where ""x"" represents 3 or 4" N [System Mechanic Professional Update [Incinerator.dll] ?? "System_Mechanic's ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again." X \TOOLS.exe tools.exe Lycos SideSearch/Fastfind.org adware X ^`d}qZxu ~`d}qzxu3zYF GAOBOT.GEN!POLY WORM! U _AntiSpyware MssCli.exe McAfee AntiSpyware X _Cat1 nmmst.exe TROJ_SMALL.SD TROJAN! X _Cat2 nmstt.exe TROJ/SMALL-DT downloader TROJAN! X _Cat3 msmsgrxp.exe variant of the TROJ/SMALL-DT downloader TROJAN X _Cat4 msmsgr2.exe TROJ/SMALL-EB TROJAN! X _Hazafibb ?? ZAFI.B WORM! infection X _ntrdlhost _Ntrdlhost.exe TROJ/DLOADER-JV TROJAN! X _ntrRescueService _ntrrs.exe TROJ/DLOADER-JV TROJAN! X _pnd_Panda Antivirus ?? Malware! - detected by ESET's Nod32 antivirus as Win32/TrojanDropper.Agent.NAK X _svchost.con svchost.com W32.ERKEZ.C WORM! X _System_Run _svchost_.exe Troj/Lineage-Z TROJAN! X _SystemBoot services.exe "TROJ/SOBER-Q TROJAN!! - NOTE - this file is placed in a ""%Windir%\Help\Help"" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X _SystemDriver csrss.exe "ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!" X _tdiserv_ _tdicli_.exe W32/Tdibd-A WORM! X _tdiserv_ _tdicli_.exe W32.TDISERV.A WORM! U _winadm winadm.exe "Parents Friend - ""Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC""" X _WinMain winexec.exe Malware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ts X _WinStart services.exe "W32.SOBER.O WORM! - Note - this file is placed in a ""%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X _winsystem.sys smss.exe W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! X _x-Finder _x-Finder.exe Disconnects and redials an ISP modem to an adult content site U {0228e555-4f9c-4e35-a3ec-b109a192b4c2} gnotify.exe Google Gmail_notifier . Alerts you when you have new Gmail messages. X {12EE7A5E-0674-42f9-A76B-000000004D00} ?? BrowserAid/Startium parasite X {2CF0B992-5EEB-4143-99C0-5297EF71F444} ?? BrowserAid/Startium parasite X {2CF0B992-5EEB-4143-99C2-5297EF71F44B} ?? BrowserAid/Startium parasite X 000hpdllhos hpdllhost.exe LZIO.com adware downloader U 000StTHK 000StTHK.exe "Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)" X 0050726-007-i32-1 0050726-007-i32-1.exe Troj/Bancban-EC TROJAN! U 00THotkey 00THotKey.exe "For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev." U 0190 Warner WARN0190.EXE Anti-dialer program (Germany) U 0900 Warner WARN0900.EXE Anti-dialer program (Germany) X 0utlook Express ?? W32/RBOT-CC WORM! X ˝Windows Update svchosts.exe FRUTCA TROJAN! X 1111swapmgr.exe 1111swapmgr.exe BDOOR-IC TROJAN! U 12Ghosts Popup-Killer 12popup.exe 12Ghosts Popup-Killer X 180adsolution 180adsolution.exe 180Solutions/N-Case adware variant X 180ax 180ax.exe 180Solutions/N-Case adware variant X 180ClientStubInstall ?? 180Solutions adware related X 180ClientStubInstall ?? 180Solutions adware related X 180ClientStubInstall ?? 180Solutions adware related N 1A:MacVisionTrayMonitor TrayMonitor.exe Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) Y 1A:Stardock MCP mcpserver.exe "Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications" Y 1A:Stardock TrayMonitor TrayServer.exe For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX X 1on1 1on1.exe Adult content dialler U 1Srv32 SpyAgent4.exe "SpyTech SpyAgent monitoring software. ""Spy software that allows you to monitor EVERYTHING users do on your PC.""" U 1Win32Cfg Keyloggerpro.exe KeyloggerPro - monitoring software U 1Win32Cfg SpyBuddy.exe SpyBuddy monitoring software X 1WinCfg32 WebMailSpy.exe WebMailSpy SPYWARE! X 2020Downloader mssvr.exe 2020Search Toolbar related. Reported to be auto-installed Y 2kadiras 2kadiras.exe Allied_Telesyn AT series router/modem related - apparently required X 2thousandbuck ?? RANKY.L TROJAN! U 2wSysTray 2portalmon.exe 2Wire Homeportal user interface X 32-bit Thunking service thunk32.exe W32.Derdero.A WORM! X 357AA41A-B7A8-4632-A27D-5B980B25CF43 ?? SMALL-AQ TROJAN! X 357AA41A-B7A8-4632-A27D-5B980B25CF43 services.exe "FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" Y 3c1807pd ?? 3Com WinModem driver. See here for more WinModem information Y 3capplnk 3capplnk.exe US Robotics Modem driver N 3cdminic 3CDMINIC.EXE 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards Y 3CM Link 3cmcnkw.exe Required for a US Robotics WinModem as it provides the link to Windows - won't work without it. Y 3Cmlink 3CmlinkW.exe For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information N 3ComDMIAgent 3CDMINIC.EXE 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards N 3D Text 3D Text.scr JERMY.A VIRUS! U 3Deep Control Panel 3DeepCTL.EXE "From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games" X 3Dfx Acc GFXACC.EXE GIBE VIRUS! N 3dfx Task Manager 3dfxMan.exe System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs Y 3dfx Tools 3dfxCmn.dll Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards Y 3dfxv2ps.dll 3dfxv2ps.dll Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards U 3DLabsHelperDemon 3dldemon.exe "Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive."" In most cases it can be safely disabled" Y 3DMouse.EXE 3DMouse.EXE Dritek System Inc. 3D Mouse driver U 3qdctl.exe 3qdctl.exe "Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ" Y 3ware 3DM 3dm.exe Monitors status of the disk array on 3ware IDE RAID controllers X 4wd!!! Natal!.pif OPASERV.AI VIRUS! X 5-1-61-96 members-area.exe Adult content dialler X 5-2-46-112 5-2-46-112.exe Adult content pop-up dialler. Removal instructions here X 5p4m ?? Troj/Litebot-C TROJAN! X 98D0CE0C16B1 ?? BrowserAid/Startium parasite related Y 9xadiras 9xadiras.exe Allied_Telesyn AT series router/modem related - apparently required X 9xHtProtect AVprotect9x.exe W32.NETSKY.M WORM! X a a.exe Commercials file that registers itself in the system registry and redirects IE to a certain commercial website X A New Windows Updater w32NTupdt.exe W32.Mytob.BM WORM! U A1000 Settings Utility cpqa1000.exe "Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features" U A4Proxy A4Proxy.exe Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites X A70F6A1D-0195-42a2-934C-D8AC0F7C08EB ?? BrowserAid/Startium parasite related N AAATraySaver TraySaver.exe "System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray" U AAK aak.exe "Advanced Anti-Keylogger - ""Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere""" X Aaou amee.exe PurityScan/Clickspring adware X Aapp adprot AdBlaster adware N ABBYY Community Agent CAGENT.EXE Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the?5.0 version of the software X ABC keylogger.exe Monitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by SpyCop in their FAQ N ABITEQ abiteq.exe "Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds." U Absolute Shield dseraser.exe Absolute Shield/Evidence Eliminator - iternet history eraser U Absolute StartUp monitor ASMon.exe Absolute Startup - startup monitor from F-Group Software X ABsr absr.exe AUTOUPDER VIRUS! X absr mwsvm.exe SeekSeek search hijacker related - as seen here X abtu lopsearch.exe Loads the executable for LOP adware - mp3serch.exe is the final version whilst lopsearch.exe is the beta version X abtu mp3serch.exe Loads the executable for Lop.com. mp3serch.exe is the final version whilst lopsearch.exe is the beta version U AbyssWebServer abyssws.exe Abyss web server Y AcBtnMgr_Xxx AcBtnMgr_Xxx.exe "Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation" U acc acc.exe "Advanced Call Center - ""full-featured yet easy-to-use answering machine software for your voice modem""" X ACCDEFRAGINFO ?? W32/Darby-O WORM! U Accelerate accelerate.exe Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection N Access Ramp Monitor armon32.exe "Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again" X Access WebControl ?? TROJ/PPDOOR-M TROJAN! U AccessManager AccessMgr.exe "Part of SmartPipes SecureSite software - ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management""" X AccessMedia P2P Loader amp2pl.exe "My AccessMedia toolbar related, stealth installed!" U AccessoriesPlus clockplus.exe """Clock Plus"", part of Accessories_Plus allows you to select from dozens of alternatives for the Windows clock." N AccessRamp Monitor01 ARMon32a.exe "From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service.""" N AccessRampLAN01 ARUpld32.exe "Version of the above for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003" U AcctMgr AcctMgr.exe "Norton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities?all from the safety of your own PC" N AccuWeather.com˝ Desktop ?? Desktop weather from AccuWeather.com X accwizz.exe accwizz.exe W32.Ruland.A WORM! X accwizzz.exe accwizzz.exe W32.Ruland.A WORM! Y Acecad.Wtxpload Wtxpload.exe Acecad driver for an AceCad USB Graphics Tablet N AceGain LiveUpdate LiveUpdate.exe "AceGain_LiveUpdate . ""AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences.""" U AcerGoto AcerGoto.exe "Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer." U AcerNotebookManager almxptray.exe System Tray access on some Acer Notebooks to give faster access to system settings U AcerPowerkey Powerkey.exe PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn F3 X Aceu ?? PurityScan/Clickspring adware U AClntUsr AClntUsr.exe Altiris AClient Service Windows Tray Icon N Acme.PCHButton pchbutton.exe Used by HP Instant Support Y ACMonitor_Xxx ACMonitor_Xxx.exe "Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation" X acocash fastdown.exe Adult content dialler X acocash fastfown.exe Adult content dialler U Acombo3dmouse Acombo3d.exe Mouse driver - required if you use non-standard Windows driver features X Aconti aconti.exe Adult content dialler U acoustic acoustic.exe Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained N acpart agpart11.exe Program for finding trucks on-line U Acrobat Assistant ACROTRAY.EXE "Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation" U Acronis Scheduler2 Service schedhlp.exe "Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images" N Acronis True Image Monitor TrueImageMonitor.exe Part of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage N Acronis TrueImage Monitor TrueImageMonitor.exe Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage N AcronisTrueImage Monitor TrueImageMonitor.exe Part of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage N Action Manager 32 am32.exe Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs N Activation Activation.exe Part of Microsoft Money U Activboard MMKeybd.exe "Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys" X Active Bit Station abs.exe W32.MYTOB.BZ WORM! U Active Email Monitor aem25.exe "Active_Email_Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email." U Active shield Activeshield.exe "Active_Shield is ""an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses[""" X ActiveDesktop systray32.exe DABOOM VIRUS! X ACTIVEDS ACTIVEDS.EXE OPASERV.T VIRUS! N ActiveEyes ActiveEyes.exe ActiveEyes from TFI Technology U ActiveMenu ActiveMenu.exe Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case U ActivePlus activeplus.exe Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) Y ActiveShield MCVSSHLD.EXE McAfee VirusScan On-line. See also McAgentExe entry. U ActiveSpeed AS.exe Ascentive ActiveSpeed Internet Optimizer X ActiveX Streamer msgfix.exe SDBOT.NQ WORM! X ActiveXUpdate svcss.exe variant of the DEDLER.C TROJAN! U Activity actik.exe ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself! N ActivSurf ?? Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates U ActMaker ActMak25.exe "The ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer." U ACU ACU.exe Atheros wireless Client Utility For HP Compaq U ACU_QSB ACU.exe Atheros wireless Client Utility For HP Compaq U Ad Blocker blocker.exe "Ad Blocker - blocks popups, and also removes banners, image ads and flash ads" U Ad Blocker Pro Ad Blocker Pro.exe """Ad Away"" popup and banner remover" U Ad Muncher AdMunch.exe "Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications" U AD2KClient AD2KClient.exe Executable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip˝ disk. Required if you wish the applications to launch on insertion of a disk N Adaptec DirectCD Directcd.exe DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later N AdaptecDirectCD Directcd.exe DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later X AdAware wini.exe W32/RBOT-XN WORM! N Ad-aware Ad-aware.exe "Ad-aware from Lavasoft. Checks your PC for ""Spyware"" which reports back your internet activities to ""base"". Available via Start -> Programs" X Ad-Aware Ad-Aware.exe W32/Rbot-ADJ Worm! N Adaware Bootup ad-aware.exe "Ad-aware from Lavasoft. Checks your PC for ""Spyware"" which reports back your internet activities to ""base"". Available via Start -> Programs" X Adaware lptt01 or Adaware ml097e adaware.exe "Variant of the RapidBlaster parasite (in a ""Adaware"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware" X Add**.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X Add**32.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log." U AdDelete AdDelete.exe Banner advertisment blocker X AdDestroyer AdDestroyer.exe "Like VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code" N ADGJdet ADGJDet.exe Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection Y Adiras Adiras.exe ADSL USB modem related X ADM Library Loader admlib32.exe variant of the SDBOT WORM! X Admanager Controller AdManCtl.exe WindUpdates ADW_WINAD.M adware X Admilli Service AdmilliServ.exe WindUpdates AdmilliServ adware X AdminSoft sysfile.vbs VBS/STARGRUB-A WORM! U Ad-Muncher ADMUNCH.EXE "Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications" X Adobe Adobe.exe unidentified VIRUS! X adobe gam.exe unidentified WORM or TROJAN! X Adobe sysbat32.exe TROJ_LOWZONES.T TROJAN! X Adobe sysconfig.exe unidentified WORM or TROJAN! X Adobe zteam.exe unidentified TROJAN! X Adobe Acrobat Distiller Application acrotray.exe W32.RANDEX.DFJ WORM! X Adobe Acrobat Reader CFG ?? variant of the WIN32.RBOT WORM! U Adobe Gamma Loader Adobe Gamma Loader.exe "Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine" X Adobe Photoshop 7.0 AdobePhotoshop.exe variant of the W32/SDBOT WORM! - NOTE: Do NOT confuse with the Adobe photo editing software of the same name! N Adobe Reader Speed Lauch reader_sl.exe Speeds up the lauch of Adobe (Acrobat) Reader 7 N Adobe Reader Speed Lauch READER~1.EXE Speeds up the lauch of Adobe (Acrobat) Reader 7 N Adobe Reader Speed Launch reader_sl.exe "Speeds up the time it takes to load the Adobe_Reader application. Your choice, but not required for Adobe Reader to function properly" X AdobeA adobes.exe FLOOD.BA VIRUS! X AdobeFonts fonts.hta Browser hijacker - redirecting to Hugesearch.net N AdobeVersionCue VersionCueTray.exe """An exclusive feature of the Adobe(r) Creative Suite, Version_ Cue(tm) helps you find files fast, track multiple versions of your files, and share your files for creative collaboration""" X Adope File Manager lsasv.exe unidentified WORM or TROJAN! X adp adp.exe "Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc" X adprot adprot.exe AdBlaster adware variant N ADQuickAccess Adtray.exe After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95 X AdRoarUpdate ARUpdate.exe AdRoar adware updater X AdRotator.Application csrss.exe "AdRotator adware variant - Note - do NOT be confuse with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt\System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X AdRotator.Application services.exe "FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" U ADService ADService.exe Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip˝ disk. Required if you wish the applications to launch on insertion of a disk U AdsGone Adsgone.exe AdsGone - pop-up stopper N ADSL Diagnostic Tools mapiicon.exe System tray access to ADSL modem diagnostic tools. Available via Start -> Programs Y AdslTaskBar ?? "ISP software, initializes DSL modem" Y ADSS ADSS.exe ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied X adstartup Adstartup.exe Adlogix adware X adstartup automove.exe Adlogix adware variant X AdStatus Service AdStatServ.exe WindUpdates AdStatus_Service adware U AdSubtract adsub.exe "AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs" X Adtools Service AdTools.exe Windupdates Adware X Adult_Chat Adult_Chat.exe Adult content dialler X Adult_Chat1 Adult_Chat1.exe Adult content dialler X AdultX AdultX.exe Adult content dialler and hijacker X AdUpdater sysupudt.exe Unidentified adware downloader/updater U ADUserMon ADUserMon.exe Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip˝ disk. Required if you wish the applications to launch on insertion of a disk X Advanced Internet Protocol cerf.exe W32.SpyBot worm variant X Advanced Protection System advpsys.exe variant of the WIN32.RBOT WORM! X Advanced Tool Checks advchks.exe variant of the WIN32.RBOT WORM! N Advanced Tools Check or ADVCHK ADVCHK.EXE Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget U Advanced Uninstaller PRO Installation Monitor monitor.exe Innovative Solutions The user can choose whether or not to monitor installs. X Advapi Advapi.exe NETDEVIL.12 (NetDevil 1.2) VIRUS! U Advertising Killer Akiller.exe AKiller - pop-up stopper X advmon32 advmon32.exe Crypter.C trojan variant infection U Adware Agent adware agent.exe Adware Agent popup blocker N Adware Spy AdwareSpy.exe "Adware remover - not recommended, see Rogue/Suspect_list" X AdwareAlert AdwareAlert.Exe """Spyware remover"" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites" U Ad-watch Ad-watch.exe Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system N AELaunch AELaunch.exe Audio Applications Launcher for the Philips Acoustic Edge soundcard X AERVICESN AERVICESN.exe W32/RANDON-AO WORM! N AeXAgentLogon AeXAgentActivate.exe Altiris Agent transmits information about your machine for the purpose of asset management and deployment U AEZBProc aptezbp.exe "IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions" U AFAFilter windefault.exe AFAFilter - internet filter software N Agent Agent.exe "Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs" X Agent Browser ?? PPdoor.M-bdr backdoor TROJAN! X Agent Explorer ?? Unidentified adware X agentsvr agentsvr.exe "Malware, detected by Kaspersky antivirus as AdWare.Monker.a - NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder." U AgfaCLnk AgfaCLnk.exe For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive X agp agp32.exe W32.Gaobot.SY worm Y AGRSMMSG AGRSMMSG.exe IBM AMR modem driver N AGSatellite AGSatellite.exe Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs X AGSeyApp AGSeyApp.exe GoldenEye SPYWARE! N ahfpor and ahfprog ahfp.exe "Advanced Hide Folders - ""is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either""" U AHNSD AhnSD.exe AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis N AHQInit ahqinit.exe Part of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required X Ahst iebs.exe PurityScan/Clickspring adware X Aica tuaa.exe PurityScan/Clickspring adware X Aida eetu.exe PurityScan/Clickspring adware X Aida ttuh.exe PurityScan/Clickspring adware U aiepk aiepk2.exe Another IE Popup Killer - pop-up stopper N AIM aim.exe "AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs" X AIM Instant Message Cookies ?? W32/RBOT-AFV WORM! X Aim Quick Start Aim.exe W32/Forbot-BB worm infection X AIM reminder AIM reminder.exe BUDDY VIRUS! X AIM95 Startup aim95.exe AGOBOT.AEE WORM! X aimaol lptt01 or aimaol ml097e aimaol.exe "Variant of the RapidBlaster parasite (in a ""Aimaol"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" U aimb.exe aimb.exe "IMSufSentinel is a Spyware program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it." N AimingClick AimingClick.exe AimingClick from AimingTech. Web searching tool. Available via Start -> Programs N AIMster ?? Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs N AIMWDInstall AIMWDInstall.exe "WildTangent on-line games installer as part of AOL Instant Messenger. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case" Y Aiptek Graphics Tablet (USB) atwtusb.exe USB interface for Aiptek Graphics Tablet (USB) X aircity aircity.exe "Related to ""Prutect"" malware from e2Give" X AKEYNAME WinServ.exe EVILBOT.C TROJAN! U AKiller akiller.exe BuyPin Advertising Killer - popup killer U ala.exe ala.exe Access_Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer. U Alarm Manager Alarm.app.exe Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop N Album Fast Start ABMTSR.EXE "Scanner software, not required for scanner to work" X Alchem Alchem.exe Transponder parasite updater/installer X alcmtr ALCMTR.EXE "Realtek AC97 Audio - Event Monitor. ""Sypware"" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers" U Alcohol or Alcohol Autorun Alcohol.exe Alcohol 120% - CD/DVD emulation/writing/copying software N AlcWzrd ALCWZRD.EXE "RealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one." X AlcxMonitor Alcxmntr.exe "Realtek AC97 Audio - Event Monitor. ""Sypware"" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers" X aldefr ere service tay0x.exe W32/RBOT-XS WORM! X Alevir Alevir.exe OPASERV.A VIRUS! X Alevir Alevir.exe OPASERV.F or OPASERV.G VIRUSES! X AlevirOld ?? OPASERV.G VIRUS! N Alexa Alexa.exe? "Alexa Toolbar""is a downloadable toolbar that helps you navigate the Internet as you surf, by instantly providing you with related information about the site you're viewing"". Available via Start -> Programs" X ALG.EXE iexplorer .exe W32/DEMOTRY-B WORM! X ALG32 ALG32.EXE StartPage.K TROJAN! X ALGU ALGU.EXE TROJ/CWS-I TROJAN! N Alias SketchBook Snapshot ALIASS~2.EXE Screen-capture utility for Alias Sketchbook N AlienAutopsy Test_BS.exe Alienware computer technical support software Y ALiSndMgr ALiSndMg.exe ALi AC97 Sound driver X alkasr ?? BALKART VIRUS U All Aboard Status stswin.exe All Aboard! Internet Connection Sharing status icon X All Sea screen saver TaskTray.exe """Free screensaver"", installs lots of foistware. See here. Get rid of it" X All Sea web link FWLink.exe """Free screensaver"", installs lots of foistware. See here. Get rid of it" N AllerCalc AllerCalc.exe AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually. U AllSeeingEye ase.exe "All-Seeing_Eye security software - ""monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions.""" U allSnap allSnap.exe """allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop""" X Alogrithm Link Queue alq.exe variant of the W32/SDBOT WORM! U Alogserv Alogserv.exe "From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up" U ALPass ALPass.exe ALPass password manager Y Alps Electric USB Server Monserv.exe Alps Electric USB Server - required according to this article U AlpsPoint Apoint.exe Touchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work N Altnet points manager.exe Altnet TopSearch adware N Altnet Points Manager points manager.exe Altnet TopSearch adware X AltnetPointsManager points manager.exe Altnet TopSearch adware U AltoMB_service AltoMBsrv.exe Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management U ALUAlert ALUNotify.exe Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis N Aluria Security Center SecurityCenter.exe "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here" U Aluria's Pop-Up Stopper eps.exe Aluria Pop-Stopper N Aluria's Spyware Eliminator ASE.exe "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here" U AlwaysOnTopMaker AlwaysOnTopMaker.exe "Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop" X AmazingTens AmazingTens.exe Premium rate adult content dialer N AME_CSA "rundll32 amecsa.cpl, RUN_DLL" Loads ADSL modem Control Panel applet N America Online *.* Tray Icon aoltray.exe Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs U AModemLockDown ModemLockDown.exe start "ModemLockDown allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc" Y Amon AMON.EXE Monitoring part of Eset's NOD32 virus-scanner Y Amonitor amon.exe Tiny Personal Firewall U AMP WinOFF winoff.exe "WinOFF is "" a utility designed to shut down Windows computers automatically, in a fully configurable way.""" U AMSN amsn.exe aMSN P2P client - can be started manually X anbv32 nabv32.exe TITOG.C VIRUS! Y ANIWZCS2Service WZCSLDR2.exe ALPHA_Networks wireless driver N Announcements Annclist.exe MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it N Anntext Anntext.exe Caere Pagekeeper text annotation server U ANONYMIZER_SPYWAREKILLER AnonAntiSpyware.exe Anonymizer Spyware Killer; see here U ANONYMIZER_SPYWAREKILLER SpyWareKiller.exe Anonymizer Spyware Killer; see here U Another Internet Explorer Popup Killer aiepk.exe Another IE Popup Killer - pop-up stopper X ansjava ?? W32/Randon-AN Worm! X Anskya PYSKY.NET.exe TROJ/DLOADER-MW TROJAN! X Answer Problem dSAFsqs.exe W32/SDBOT-SC WORM! X Anti Isass.exe WIN32.BROPIA.K WORM! X Anti Spam Service spamsvc.exe W32/Mytob-BK Worm! U Anti Trojan Elite TJEnder.exe Anti_Trojan_Elite trojan remover U antidialer.co.uk Dialer_Watcher.exe Dialer_Watcher is an application that allows you to detect Dialers on your computer. U Anti-keylogger check antikey.exe Anti-keylogger - protects against keylogger programs monitoring your keystrokes U AntiPopUp AntiPopUp.exe AntiPopUp for IE - pop-up stopper U Anti-Trojan-Watch ATWatch.exe Anti-Trojan Watch - trojan detector Y AntiVir XP AVwin.exe AntiVir antivirus X Antivirus av.exe SINKIN VIRUS! Resets IE start page to realphx.com X Antivirus iexpl0res.exe unidentified WORM or TROJAN! X AntiVirus kaspery.exe variant of the WIN32.RBOT WORM! X Antivirus maja.exe W32.NETSKY.H WORM! X Antivirus Installer ?? Troj/Badgent-A Trojan! X Anti-Virus Product Sync ?? W32.Kedebe.D WORM! X Anti-Virus Update Scheduler ?? "variant of the HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more..." X Anti-Virus Update Scheduler winsp3.exe Malware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system. X Anti-Virus Update Scheduler V1.39.12R ?? "HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more..." X antivirus32 antivirus.exe W32.Spybot.KAI WORM! X AntivirusGold AntivirusGold.exe Malware masquerading as an antivirus - also installs the Winnook TROJAN! X antiware ?? Troj/Dloader-HW TROJAN! U AntiWindowsMessenger AntiMsMsg.exe Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory. Y AnVir AnVir.exe AnVir Task Manager - protects computer against viruses and manages running processes and startup files U anvshell anvshell.exe System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar N AnyDVD AnyDVD.exe "AnyDVD is a driver, which descrambles DVD-Movies automatically in the background. This DVD appears unprotected and region code free for all applications and the Windows operating system as well" N AO Tray or AOTray AOTray.Exe System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel X AOL 9.0 Optimized AOLClient.exe Backdoor.Spyboter.A TROJAN! X AOL 9.0 Optimized AOLClient.exe Backdoor.Spyboter.gen TROJAN! U AOL Broadband Check-Up matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in ""add/remove programs"" some help menus in help and support will not be available. You decide" N AOL Companion companion.exe "Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use." X Aol Configuration Loader aimsng.exe W32/SDBOT-XE WORM! X AOL Instant Messanger aim.exe W32/Sdbot-YT Worm! X AOL Instant Messengar aol.exe W32/AGOBOT-FN WORM! X Aol Instant Messenger aolmsg.exe W32.Kelvir.AL WORM! X AOL Instant Messenger 7.213 aim9283.exe W32/Sdbot-ZF Worm! X Aol Instant Messenger Fix aolfix.exe W32/Sdbot-ABJ WORM! X AOL Messenger ?? Unidentified worm or trojan X AOL Messenger aolmsngr.exe W32/SDBOT-JF WORM! U AOL Spyware Protection AOLSP Scheduler.exe AOL's spyware protection program U AOL TopSpeedMonitor aoltsmon.exe AOL's TopSpeed web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up. U AolAcsDaemon1 Acsd.exe AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually Y AolAcsDaemon1 AOLACSD.EXE "AOLacsd.exe is a part of the AOL Internet Software and relates to the connection driver, essential to Internet connection. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems" X AolCon config.com TAPLAK VIRUS! N AOLDialer AOLDial.exe AOL ISP software dialer; can be activated through a desktop shortcut N AolFix AolFix.exe "Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL? to run correctly. Not seen much any more and should only run once" X Aornum aornum.exe Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware Y APC UPS Status Display.exe APC PowerChute Personal Edition status icon U APC_SERVICE mainserv.exe "PowerChute˝ Personal Edition - ""safe system shutdown software with sophisticated power management functions""" Y apc_tray apc_tray.exe Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure X Api**.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X Api**32.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X API32 api32.exe IRCBOT-B TROJAN! X APIMon apimonx.exe TIBSER.A downloader TROJAN! X APIMon msreg.exe TROJ_DROPPER.Z TROJAN! X APIMon winapix.exe variant of the TIBSER.A downloader TROJAN! X apisvc.exe apisvc.exe variant of the Lamebot TROJAN! U APL APL.exe "Sage_Software's_ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application." U Apoint Apoint.exe Touchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work X App.EXEName ?? BODIRU VIRUS! X App32dll msnavc32.exe VX2 adware related U Appcon vAppCon.exe "Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the ""Auto-start when OS starts"" option. Required for a connection to be established" X appconn appconn.exe CARGAO trojan U AppExtender AppExtCB.exe Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received X appis.exe appis.exe AGENT-BC TROJAN! Y Application mdmsetsp.exe Aztech Labs modem driver U Application Explorer Naldesk.exe "Novell Zenworks Application Explorer Executable; ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components.""" X Application Layer Gateway Service algs.exe W32.LINKBOT.M WORM! U AppPlus AppPlus.exe "AppPlus - ""menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)""" Y Apvxd or Apvxdwin APVXDWIN.EXE Part of Panda Anti-Virus. Required to enable permanent virus protection Y Apwheel Apwheel.exe Wheel support for an Alps mouse? X apyginapygin simenu.exe SDBOT.BTR WORM! X AQ3HelperStartUp AQ3HEL~1.EXE "ScreenScenes ""Aquatica Water Worlds"" screensaver. Comes with GAIN spyware" X aqadcup aqadcup.exe Backdoor.Agent.bg worm X Aqujyjax ?? TROJ/RANCK-CQ TROJAN! X Aqujyjax aqujyjax.exe W32/SDBOT-YC WORM! X Archive archive.exe Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Centim.a X ARCHIVE CONTROL fixupdattr.exe W32.MYTOB.GU WORM! N ARCSolo Recovery ?? Backup software by Computer Associates - no longer supported N ares ares.exe "Ares is ""a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download""" N areslite AresLite.exe "Ares Lite Edition is ""a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download""" X Aritima aritima.exe ARITIMA VIRUS! U Artera arteraui.exe "Artera Turbo Internet Accelerator - ""surf faster, boost download speed"". Only required if you find it helps improve your performance" X ASDPLUGIN 100171be.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN 100176br.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN adult1.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN Austria.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN belgium_nm.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN canada.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN czech.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN dbaccess.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN dsldbaccess.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN dslgeaccess.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN Finland.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN france.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN fullgames.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN geaccess.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN mexico.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN netherlands.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN temp532.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN turkey.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN uk_nm.exe AsdPlug premium rate adult content dialer variant X ASDPLUGIN Xadult1.exe AsdPlug premium rate adult content dialer variant X asdx xwinrpc32.exe AGOBOT.VO WORM! N ASE Scheduler ASE Scheduler.exe "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here" U Ashampoo PopUpBlocker PopUpKiller.exe "Ashampoo popup blocker, part of Privacy Protector Plus; see here" Y ashAvast ashAvast.exe Part of Avast antivirus X ASHLT Ashlt.exe Ashlt adware Y ashMaiSv ashmaisv.exe Part of Avast! anti-virus software U AsioReg ?? ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality U ASK ?? StealthKeylog surveillance software. Uninstall this software unless you put it there yourself. X asl Aslru.exe TROJ/BANCOS-CU TROJAN! U Asmw Soft Popups Burner popups burner.exe "Popup blocker, part of Asmw Soft PC_Optimizer" X ASP.NET State Service csrss.exe "TROJ/DLOADER-QI TROJAN! NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" N asp4tray asp4tray.exe System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel Y AspireTimeMachine acertmb.exe "System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry" U a-squared a2guard.exe "a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the a 'Background Guard' real time protection feature" X assistse ASSISTSE.EXE CnsMin (Chinese_Keywords) related X AST AST WIN32.VB.AH TROJAN! X AST AST.exe AutoStarter parasite X AStart AStart WIN32.VB.AH TROJAN! U ASTART astart.exe ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings N asTray Astray.exe Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer N Astro Astro.exe Checks for updates to Quicken on a system reboot N ASUS Live Update ALU.exe ASUS Live Update utility - reportedly not required N ASUS Probe AsusProb.exe ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area U ASUS SmartDoctor VGAProbe.exe ASUS video card fan/thermal monitor U ASUS TweakEnable astart.exe Restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings N ASUSKey V38SHELL.EXE System tray Icon for quickly changing video modes U asustweakenable ATweak.exe Asus Tweaking Utility - for fine tuning the settings of your ASUS display card N ASWDP ASWDP.exe MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market X ASWnk aswnk.exe Adult content dialler X atapidrv atapidrv.exe W32/AGOBOT-SL WORM! U Athan Athan.exe Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world. N ATI CATALYST CLI.exe "System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLE.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop" N ATI CATALYST System Tray CLI.exe SystemTray "System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop" X Ati Control Panel atiphexx.exe SDBOT.CC worm infection N ATI DeviceDetect ATIDtct.EXE This utility was meant for future use of the ATI TV WONDER? USB 2.0 video driver and can be disabled. N ATI GART Set-up Utility Atigart.exe "Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed" U ATI Launchpad launchpd.exe "Convenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu" X ATI Rage3d Pro AtiRage4dPro.exe W32/AGOBOT-OG WORM! Y ATI Remote Control ATIRW.exe Driver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it Y ATI Remote Control ATIX10.exe Driver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it N ATI Scheduler Atisched.exe Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see N ATI Task Application Atitkad.exe System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display N ATI Task Application (Atikey) Atitask.exe System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display X ATI Technology Startup techstart.exe W32/Rbot-AEU Worm! X ATI VIDEO REGKEY ati2vid.exe SDBOT.UR WORM! N Ati2mdxx Ati2mdxx.exe For ATI video cards. System Tray access to display mode changing N ATICCC CLI.exe "System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLE.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop" U ATICCC cli.exe runtime "ATI's CATALYST(tm) CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. If not you can start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime" X AtiCpanel atiphexx.exe AGOBOT.IL worm infection X aticpaxx.exe aticpaxx.exe W32/RBOT-XP WORM! U AtiCwd AtiCwd.exe This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card U AtiCwd32 AtiCwd32.exe This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card X AtiDisplayDrv atidrvxx.exe W32/RBOT-VZ WORM! N AtiKey Atikey32.exe System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display N AtiKey atiptkad.exe System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display N Atikey Atitask.exe System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display U ATIModeChange Ati2mdxx.exe System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager X atipatxx atipatxx.exe TROJ/SMALL-ED TROJAN! U ATIPOLAB ati2evae.exe ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks U ATIPOLAB or ATIPOLL ati2evxx.exe "ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces? on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources" U AtiPTA ?? "Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings" U AtiPTAAA ?? "Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings" U atiptaxx ?? "Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings" X atiptext atiptext.exe COSIAM-A TROJAN! U AtiQiPcl AtiQiPcl.exe Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's U ATISmart ati2s9ag.exe "ATI's ""SMARTGART"", which is included with the ""Catalyst"" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings" X atisrc2 windfind.exe "Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return" X ATITech Active.exe Troj/Roamer-A TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N atitray or AtiTrayTools atitray.exe ATI Tray Tool - allows quick access to ATI graphics card settings X atiupdate ?? DEBESKI.A VIRUS! X atiupdate msshed32.exe DELF.EP downloader TROJAN! X ATIUpdater atiupdxx.exe W32/RBOT-ABX WORM! X Atiupdpl atiupdpl.exe TROJ_SMALL.AOS TROJAN! X ativopen ativopen.exe Premium rate adult material dialer U ATIX10 atix10.exe ATI Remote Wonder - PC wireless remote control X ATM Control adpn.exe MMS.A VIRUS! N ATnotes atnotes.exe Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs U Atomic.exe Atomic.exe Atomic_Clock_Sync synchronizes your computer's time with the NIST time server. N Atomica atomica.exe Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key U AtomicTime ATOMICTIME.EXE AtomicTime - utility that synchronizes your PC clock to an atomic clock U Atrack atrack.exe "New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert" U Atray Atray.exe Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons U ATSpooler AppsTraka.exe AppsTraka surveillance software. Uninstall this software unless you put it there yourself. U ATTBroadbandUpdate SAUpdate.exe Big Brother from Quest Software. System and network monitor U ATTRedUpdate AutoUpdate.exe Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates X AttuneClientEngine attune_ce.exe """Attune is a revolutionary service that provides you with targeted Intelligram messages to help you avoid common computer problems. Attune may also let you know when you need a specific product, service, or upgrade to optimise the use of your computer"". Not required - treated as adware" X AttuneContentUpdater attune_cu.exe Related to the above. All needed for the program to do its job properly X AttuneDiscovery attune_di.exe Related to the above. All needed for the program to do its job properly X AttuneSystray attune_st.exe Related to the above. All needed for the program to do its job properly N aTuner atuner.exe aTuner - tweak tool for GeForce based graphics cards U AT-Watch ATWatch.exe Anti-Trojan Watch - trojan detector Y atwtusb atwtusb.exe USB interface for Aiptek Graphics Tablet (USB) X AtxBrw Iexplor.exe """Pop Marketing"" adware" U AU Agent AUagent.exe Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon X au.exe au.exe Added as the result of the BEAGLE.B WORM! Y AUCBPNP aucbnpn.exe Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot X Aucompat Aucompat.exe GEMA TROJAN! X Audcntr audcntr.exe WIN32.GEMA TROJAN! X AUDIO SOUND.exe Dial/Ployb-A TROJAN! X Audiocntl audiocntl.exe Crypter.C trojan variant infection N AudioDeck ADeck.exe ADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items. X Audiodrv audiodrv.exe CRYPTER-C TROJAN! N AudioHQ Ahqtb.exe For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs X audioinf audioinf.exe Crypter.C trojan variant infection X AUNPS2 "RUNDLL32 AUNPS2.DLL,_Run@16" AlwaysUpdatedNews.com parasite related - More_information X aupd symcsvc.exe ABWIZ.D TROJAN! X aupd sysvcs.exe ABWIZ.C TROJAN! Y Aureal A3D Interactive Audio sa3dsrv.exe For Aureal based 3D soundcards. A3D sound features won't work with this disabled Y Aureal A3D Interactive Audio Init A3dInit.exe For Aureal based 3D soundcards. A3D sound features won't work with this disabled X ausvc ausvc.exe AUTOUPDER VIRUS! X Auth Starter Ident startauth.exe W32/RBOT-WP WORM! U AuthConsoleStart AuthStart.exe "Security Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private." X authz authz.exe unidentified virus X Auto CD-ROM Startup cdaccess.exe SPYBOT.BLA WORM! X auto repair system qualityx.exe "Unidentified worm, probably a W32.SpyBot variant" N Auto T Bar or autotbar autotbar.exe If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled X Auto updat crcss.exe SDBOT.AAG WORM! X Auto updat crsrs.exe W32/FORBOT-BP WORM! X Auto updat crsrs.exe W32/FORBOT-BP WORM! X Auto updat SysDebug.exe W32/Forbot-BA worm infection X Auto Updat WindowsSys32.exe variant of the W32/FORBOT WORM! X "Auto updat, various other names" crsrs.exe W32/Forbot-AK worm infection X Auto Update AUP.exe unididentified WORM or TROJAN! X Auto Update svchost.exe "TROJ/DUMARDL-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Auto Updates svchost.exe Troj/Cheuko-A TROJAN! X Auto WinUpdate taskmrg.exe W32/Rbot-AFA Worm! U Autobar autobar.exe "Connect buttons on the keyboard for internet direct access, etc. on HP computers" U AutoCAD Startup Accelerator acstart16.exe Preloads some libraries that are used by AutoCAD in order to make the software load faster Y autoclk autoclk.exe Sagem Modem driver. Installed and required on systems running Windows 98 or ME N AutoEA Ahqrun.exe For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ X AUTOEXE AUTOEXE.exe W32/SEMAPI-A WORM X Autoloaderaproposclient Apropos_Client_Loader.exe AproposMedia adware X Autoloaderaproposclient cxtpls_loader.exe AproposMedia adware X AutoLoaderEnvoloAutoUpdater auto_update_loader.exe Envolo/AproposMedia adware updater N AutoMate Task Service automate.exe Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs X Automatic Defrag Manager defrag.exe W32/Rbot-AKE WORM! X Automatic Microsoft Windows Updater suchost.exe W32/RBOT-EQ WORM! X Automatic Windows Updater Update.exe GAOBOT.AO WORM! N Automatically launches the United Devices Age UD.EXE The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs X Autopdate Autopdate.exe W32/Rbot-AGL WORM! N AUTOPROP "REGPROP.EXE, WMPADDIN.DLL" "Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension" X AUTOPROTECTU navapq32.exe unidentified WORM or TROJAN! X autorepair dexs.exe variant of the W32/SDBOT WORM! U AutoSizer AUTOSIZER.EXE AutoSizer - utility that automatically maximizes windows when they're opened N AutoSpell 5 ASWATC32.EXE AutoSpell - spell checker N AutoTKit AUTOTKIT.EXE On HP PC\'s. Unclear what purpose it serves - but there\'s a known issue with Internet Explorer Toolbar settings not being saved with it enabled N autoupd autoupd.exe "Raxco Software Auto Update utility.""Used to keep your software up-to-date""" X autoupd autoupd.exe VIRUS! - found in a folder of the same name X autoupdate ?? variant of the QOOLOGIC TROJAN! X autoupdate ?? variant of the QOOLOGIC TROJAN! X autoupdate "WINUP2DATE.DLL,SHStart" Unidentified adware - detected by Panda antivirus as Trj/Clicker.CY X Autoupdate Service kaka.exe TROJ/SYMPE-B TROJAN! X AutoUpdater aupdate.exe "Aupdate, Tinybar variant. Spyware" X AutoUpdater AutoUpdate.exe PeopleonPage foistware X AutoVirusProtection ciscv.exe variant of the WIN32.RBOT WORM! X aux.exe aux.exe BACKDOOR.ZINS TROJAN! X auxAudioDevice aux32.exe W32/Zusha-C WORM! N AUXXTRAY au30setp.exe System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel X AV ?? MIDFIN WORM! X AV UpDate Update.exe theTROJ/FUROOT-A TROJAN! Y avast! ashDisp.exe Part of Avast! anti-virus software Y Avast! ashserv.exe Avast! anti-virus software Y avast! Web Scanner Ashwebsv.exe Avast! antivirus Y Avast32 Astart32.exe Part of Avast! anti-virus software X avc avmon.exe unidentified TROJAN! U AvconsoleEXE Avconsol.exe From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it X AveoAttune atmdlusr.exe Related to AttuneClientEngine above X AvG svchost323.exe W32/RBOT-ZA WORM! X AVG Grisoft Updater updater.exe W32/AGOBOT-OT WORM! Y AVG_CC or avgcc32 avgcc32.exe "AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates" Y AVG_EMC AVGEMC.exe AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses Y AVG_RegCleaner AVGREGCL.exe AVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems Y AVG7_AMSVR Avgamsvr.exe AVG antivirus related Y AVG7_CC AVGCC.exe "AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates" Y AVG7_EMC AVGEMC.exe AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses Y AVG7_Run avgw.exe Part of AVG Anti-Virus 7.0 Y avgamsvr.exe Avgamsvr.exe AVG antivirus related Y AVGCtrl AVGCTRL.EXE Background task of the AntiVir antivirus program which scans files transparently in the background Y AVGCtrl AVGNT.EXE Background task of the AntiVir antivirus program which scans files transparently in the background Y avgmsvr.exe avgmsvr.exe Required for AVG Anti-Virus 7.0 to function Y Avgserv9.exe Avgserv9.exe Background monitoring program for AVG anti-virus Y AVGuard AVGNT.EXE Background task of the AntiVir antivirus program which scans files transparently in the background Y AVGuard AVGUARD.EXE Background task of the AntiVir antivirus program which scans files transparently in the background X avidrv drvsc.exe Detected as the Trojan-Downloader.Win32.Agent.ph TROJAN! by Kaspersky Anti-Virus. Note: No URL available at this time. X Avimgt Avimgt.exe GEMA TROJAN! X Avimgt32 Avimgt32.exe GEMA TROJAN! Y avinit AVINIT9X.EXE Command antivirus related Y AVK Mail Checker AVKPop.exe eXtendia AVK AntiVirus email checker Y AVKBar AVKBar.exe GData AntiVirusKit Anti-virus Y AvMaiSrv Avmaisrv.exe Avast32 anti-virus - E-mail scanner X avnort formatsys.exe W32.Serflog.A WORM! X avnort msmbw.exe W32.Serflog.A WORM! X avnort serbw.exe W32.Serflog.A WORM! X AVP ?? Troj/Mutbo-A TROJAN! Y avpcc avpcc.exe Kaspersky Labs anti-virus Y avpm avpm.exe Kaspersky antivirus X Avpr avpr.exe W32.Mydoom.AF WORM! X Avril Lavigne - Muse ?? AVRIL-A VIRUS! Y AVSCHED32 AVSched32.exe AntiVir anti-virus from H BDEV Y AVSchedScan SCHSC9X.EXE Command antivirus related X AvSer dsm.exe W32.Serflog.B WORM X AvSer msmpatch.exe W32.Serflog.B WORM! X AvSer svosm.exe W32.Serflog.B WORM! X AvSer sysup.exe W32.Serflog.B WORM! X avserve.exe avserve.exe SASSER VIRUS! X avserve2.exe avserve2.exe SASSER.B or SASSER.C VIRUSES! X avserve3.exe avserve3.exe SASSER.G worm N Avtray Avtray.exe Command Antivirus tray icon U AVWUpd32 AVWUPD32.EXE "AntiVir updater. Useful, but can be run manually" Y avx communicator xcommsur.exe Anti-virus part of BitDefender virus scanner/firewall Y Avxlive avxlive.exe Bullguard or BitDefender antivirus Y avxlni avxinit.exe Anti-virus part of BitDefender virus scanner/firewall U AWatch Awatch.exe "Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products." N awhost32 awhost32.exe "Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended" Y a-winpoet-service winpppoverethernet.exe "WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking" U AWMON Ad-Monitor.exe F-Secure_Anti-Spyware U AWMON Ad-Watch.exe Part of Lavasoft Ad-aware SE Plus and Pro - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system U awxDTools ?? "AwxDTools related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools. (i.e.: *.cue, *.iso, *.ccd ...)" X AxFilter "Rundll32 AXFILTER.DLL, Rundll32" CnsMin (Chinese_Keywords) related Y azmodem azexe.exe Aztech_Labs modem driver N B.Reader remin.exe Birthday Reminder 5.0 - as the name implies X b3d BDEsecureinstall.exe "B3d Projector - installed along with the KaZaA file sharing utility. Causes a program called ""ZUPDATE.EXE"" to periodically try to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents" X b3dUpdate Zupdate.exe Same as above but not installed via KaZaA U b9 B9.exe "FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. ""Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run""" X b99 msmm.exe ClientMan parasite variant X babeie "rundll32 cnbabe.dll, dllstartup" CommonName Toolbar spyware. To uninstall see here N Babylon Client Babylon.exe "Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on""" N Babylon Translator Babylon.exe """Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on""" X Back Updates Uninstall.log.vbs VBS.YPSAN.D WORM! X Backdoor.NuAgent agent.exe AGENT-DP TROJAN! X Background Intelligent Transfer Service rundll32.exe "TROJ/VB-ZD TROJAN! - Note: this file is located in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file!" U BackgroundSwitcher bgswitch.exe "Background Switcher Powertoy. Included with the last beta version of the XP Powertoys. Whenever a user right clicked his desktop and chose properties he could see a new tab which allowed him to enable a ""Desktop Slide Show."" This would automatically change the Windows Desktop at an interval specified by the user. Available here" N Backpack UDF bpudfmon.exe Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk X Backup Service backup.svc Unidentified adware U BackupExecScheduler besch.exe "Veritas ""Back Up My PC"" software" N BackWeb backweb.exe Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs N Backwork Backwork.exe Backwork trojan detector U BACPI10 bacpi10a.exe "Known as ""PowerKey"" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray" N BacsTray BacsTray.exe Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems X BADDATE BADDATE.EXE unidentified VIRUS! X BagleAV csrss.exe "W32.NETSKY.AB WORM! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X Bakra IEHost.EXE IEDriver adware variant X Band-Aid ?? BACKDOOR.RANKY.O TROJAN! U Banpopup by Pratik Banpopup.exe Banpopup - popup killer X Bar Ding lolt Analiz.exe RBOT-RP WORM! X bargains bargains.exe Bargain Buddy - advertising spyware installed with Net2Phone & LimeWire amongst others. Some further information here X bargains barginbuddy.exe Bargain Buddy - advertising spyware installed with Net2Phone & LimeWire amongst others. Some further information here N bascstray BascsTray.exe Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems X Bat secure2.bat ZCREW.C VIRUS! N Batchreg1 ?? "Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here" U BatInfEx rundll32.exe Displays battery status information on an IBM Thinkpad U Battery Scope batmgr.exe Monitors battery levels on a notebook/laptop PC U BatteryBar batterybar.exe "BatteryBar - displays battery usage, and the current percentage of battery power left" X BatzBack BatzBack.scr BACKZAT VIRUS! U BAUSB BAUSB.exe "Boston Acoustics Audio, USB driver" X bawindo bawindo.exe BEAGLE.AR WORM! X bawindo bawindo.exe W32.BEAGLE.AU WORM! U BayMgr DockApp.exe Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices? U Bayswap bayswap.exe Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices U Bayswap2 TbUpdate.exe Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices U BBC News alerts skinkers.exe BBC News Desktop Alerts service; see here - The BBC News desktop alert and breaking news e-mail services let you find out about all the latest news as it happens. N bbSysTray bbSysTray.exe "Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions""" U bbui bbui.exe AOL DSL status monitor displaying a red/green icon indicating if you have a connection U bca bca.exe "BeClean Agent - registry, history, temp files, etc cleaner" U BCDetect bcdetect.exe Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see Y BCMDMMSG bcmdmmsg.exe BCM voicemodem driver. Required for dial-up if you have one of these modems U BCMHal ?? "BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings" Y BCMSMMSG BCMSMMSG.exe BCM voicemodem driver. Required for dial-up if you have one of these modems X bcnswSX ?? Ranck-AJ trojan infection N BCNT bcnt.exe AWS Weatherbug related. What does it do? X BCPC bcpc.exe BroadcastPC adware variant X bcpc_c bcpc_c.exe BroadcastPC adware variant U BCTweak bctweak.exe "BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings" X Bcvsrv32 bcvsrv32.exe W32/AGOBOT-TD WORM! N BCWipeTM bcwipetm.exe "BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed" X BD dc.exe Troj/Rasdoor-A TROJAN! Y BDMCon Bdmcon.exe Either BitDefender or BullGuard antivirus Y BDNewsAgent bdnagent.exe BitDefender antivirus - updater Y BDOESRV bdoesrv.exe Bitdefender 8 antivirus and firewall Y BDSwitchAgent bdswitch.exe Bitdefender 8 antivirus and firewall N BearShare bearshare.exe BearShare file sharing client. Versions known to include spyware - see here U BeFaster befaster3.exe BeFaster internet connection optimization tool N Belkin PCMCIA WLAN Monitor monitorbk.exe Belkin USB Network Adapter Management utility - can be started manually U BelNotify "NPBelv32.dll,RunDll32_BelNotify" "BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service." X Belt Belt.exe Transponder parasite updater/installer X Benadril Alert Tool benadrilalert.exe Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril N BestPopUpKiller BestPopupKiller.exe "Popup killer by Swanksoft - not recommended, see Rouge/Suspect_list" X BeSys ?? BeSys ADWARE! Y bg bullguard.exe Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster U BGInfo Bginfo.exe "BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more." Y BGNewsAgent bgnewsag.exe BullGuard antivirus updater N bgsmsnd bgsmsnd.exe Printer driver to generate PDF files from any program N BHOCop BHOCop.exe ZDNet's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware U BHODemon 2.0 BHODemon.exe "BHODemon ""protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!"" If you prefer forgoing resident protection, the application can also be run on demand." U BI1HelperStartUp BI1HEL~1.EXE Beach_Islands Screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... X BIE ?? BDplugin parasite N bigfix BIGFIX.EXE "BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet˝ Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog" U BigPond Toolbar bpumTray.exe "Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier""" N BigPondCable bpcable.exe Telstra Bigpond Cable login software. Can be started manually. N Billminder Billmind.exe Can be setup in Quicken to remind user of due payments. Available via Start -> Programs X bin32hpu ppstub.exe PrecisionPop adware X bingdian Bingdian.vbs BINGD VIRUS! X Bios Bios32.exe unidentified VIURS! X BIOS XP Loader ?? "W32/RBOT-IC, ~http://www.sophos.com/virusinfo/analyses/w32rbotic.html WORM!" X BIOS1 BIOS1.EXE OPASERV.T VIRUS! N BitComet BitComet.exe BitComet P2P client - can be launched from Start Menu > Programs X BitDefender Antivirus BITDEFENDERX.EXE variant of the W32.SPYBOT WORM! Y BitDefender Communicator xcommsvr.exe BitDefender antivirus U BitDefender for MSN Messenger msnmon.exe Bitdefender anti-virus for MSN Messenger. Unless you have MSN Messenger running all the time start it manually U BitDefender for Yahoo! Messenger yahmon.exe BitDefender Antivirus for Yahoo! Messenger - free AV add-on for Yahoo! Messenger Y BitDefender Live! Init bdinit.exe BitDefender antivirus Y BitDefender Scan Server bdss.exe BitDefender antivirus Y BitDefender Virus Shield vsserv.exe BitDefender antivirus U BitDefender_P2P_Startup BitDefender_P2P_Startup.exe Bitdefender anti-virus for file transfers via internet messaging clients such as ICQ and MSN Messenger. Unless you have these running all the time start it manually Y bitdefenderlive avxlive.exe Main program of BitDefender virus scanner/firewall N BitWare Print Monitor bwprnmon.exe FaxServe network fax software N BJ Printer Status Monitor Cjstsr.exe Canon BJ printer status monitor N BJ Status Monitor 5xx CJSTRxx.EXE "Canon printer status monitor - where ""xx"" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers" N bjcfd CFD.exe BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs N BlackICE PC Protection or BlackIce Utility blackice.exe "Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - \'(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.\' See also LoadBlackD" X Blah service CCAPPS32.EXE RBOT.TV WORM! X blah service FaLeH.exe W32/Rbot-AES Worm! X blah service internet.exe variant of the WIN32.RBOT WORM! X blah service microsoft.exe variant of the WIN32.RBOT WORM! X blah service msnmsgrr.exe RBOT.PZ WORM! X blah service smnp.exe RBOT.IZ WORM! X blah service tazkmgr.exe RBOT.UA WORM! X blah service winsysengine.exe W32/Rbot-KI worm infection X blah service winupdate.exe GAOBOT.BIA WORM! X blahh service msengine.exe variant of the WIN32.RBOT WORM! X blahx service msnjompa.exe SDBOT.AML WORM! N BlazeChanger FBZPaper.exe "Ember graphic file viewer, manager, and touch-up system" N bldbubg bldbubg.exe Part of Dell Alerts which provides customers with an update on latest updates for his/her system X Bles bles.exe TROJ/BLESH-A TROJAN! U blinkx blinkx.exe "Blinkx_Desktop ""Smart Folders"" software" X BLMessagingIntegration blengine.exe BuddyLinks adware U BlockAds blads.exe "A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks" X BlockChecker Block-checker.exe BlockChecker adware X Blocker System611 Monitoring PopUpBlocker611.exe RBOT.BLJ WORM! N BlockTracker BlockTracker.exe If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file U blsloader blsloader.exe BellSouth ISP Internet_Tools X blss blss.exe Backdoor.Blarul TROJAN! N BLSTAPP blstapp.exe Puts access to Creative's BlasterControl in the System Tray X bluestart rraut.exe VB.GY.2 downloader TROJAN! U BlueToothAuthentication Agent ?? "Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, ""Rundll irprops.cpl missing entry Bluetooth authentication agent"", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup." U BluetoothAuthenticationAgent ?? "Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate." U Blueyonder Instant Support Tool matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide" N BMail Installation FTP_back.exe Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not X BMan BMan1.exe Abcsearch.com/DealHelper adware variant U BMMGAG "Rundll32 PWRMONIT.DLL, StartPwrMonitor" Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window U BMMLREF BMMLREF.EXE Battery Manager for IBM ThinkPad laptops U BMO MasterCard Wallet EWALLET.EXE "The wallet conveniently stores billing, shipping and payment information on your PC" N BMupdate BMupdate.exe "Related to BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install" X BMZ bmz.exe nCase adware X Bndt32 Bndt32.exe LACON VIRUS! X Bnexe ?? KITRO.D (or ARGEN.A) VIRUS! U BO1HelperStartUp BO1HEL~1.EXE ScreenScenes Butterfly_Oasis screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... U BO1HelperStartUp Bo1helper.exe ScreenScenes Butterfly_Oasis screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... X Boarddata ?? variant of the RANDON.AN WORM! Y BOC412 BOC412.exe Version 4.12 of NSClean's BOClean anti-trojan software Y BOCleanautostart Boclean.exe NSClean's BOClean anti-trojan software U bombshel BOMB32.EXE Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems X Bonzi Buddy ?? Spyware - read here for information and here for removal instructions X boo boo.exe Adware downloader - detected by Kaspersky antivirus as Trojan.Win32.Favadd.o X BookedSpace ?? "Adware, related to the Remanent parasite" N BookmarkCentral BMLauncher.exe "Bookmark Express - ""offers a more flexible way to manage Web site bookmarks, regardless of which browser you use""" U Boost XP Service bxservice.exe Boost XP from Systweak - WinXP tweaking utility? X boot boot.exe Troj/Puppet-A Trojan! X Boot Manager bootmng.exe variant of the W32.SPYBOT WORM! X Boot Manager Njgal.exe KILO VIRUS! X boot_reg ?? TROJ/BANCBAN-CA TROJAN! X BootCfg Install.log.vbs VBS.YPSAN.D WORM! X BootCTRL bootctrl.exe unidentified WORM or TROJAN! X BootLoader BootLoader.exe.vbs WATERWORKS VIRUS! X bootpd.exe bootpd.exe Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.vk X bootpd.exe bootpd.exe Troj/Agent-DT Trojan! X BootsCfg ?? VBS.SPILTRON WORM! X BootsCfg ?? VBS.SPILTRON WORM! X BootsCfg ?? VBS.YPSAN.E WORM! X BootsCfg Date.POP.vbs VBS.KUULLIO WORM! U BootStatus BOOTST~1.EXE "Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day.? Once you exit it, it has no more effect on resources" U BootWarn BootWarn.exe "From here : ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from ?Start \ Programs \ Norton AntiVirus?. If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab ş it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages.""" N Bose Wave/PC Monitor wavepcmonitor.exe System Tray access for this system (more info on the system here). Available via Start -> Programs X BossIdea winlogin.exe TROJ/LINEAGE-I TROJAN! X Bot Loader svchostt.exe W32.GAOBOT.ALV WORM! X Bouncer RunStartup bouncer.exe "VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs" X Bouncer RunStartup LiveUpdate.exe "VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs" U bpcpost.exe bpcpost.exe MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it X BPCv2 BPCv2.exe BroadcastPC adware X BPCv2_re bpc2_re_inst.exe BroadcastPC adware variant U BPK bpk.exe "Blazing Tools Perfect Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove" U BPK nvsr32.exe "Blazing Tools Perfect Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove" N BPServer G6FTPSrv.exe BulletProof FTP Server X BPT bpt.exe BroadcastPC adware U BQTray.exe BQTray.exe "System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually" X Brasil Brasil.exe OPASERV.E VIRUS! X Brasil BRASIL.PIF OPASERV.E VIRUS! X BrasilOld ?? OPASERV.P VIRUS! X Brct trdb.exe Reported as Win32.PurityScan.y TROJAN! by Kaspersky Anti-Virus. Class: Trojan-Downloader. Note: Lowers Internet Explorer security settings and downloads unwanted files. U Break_Reminder BREAK REMINDER.exe Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here X Breg bcre.exe BroadcastPC adware variant X Breg bptre.exe BroadcastPC adware variant X Breg breg.exe BroadcastPC adware variant X Bridge ?? Flingstone.com browser hijacker Y Brindys BriTray BRITRAY.EXE "Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired" U BrmfRmPA BrmfRmPA.exe Brother resource manager - needed for a Brother MFC printer/copier/scanner and PC to properly communicate N Broadband Wizard bbwiz.exe Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs N BrowseProxy FindService.exe "Actual Names - ""It is now possible to enter a particular word or keyword phrase that is associated with your business, and immediately be directed to YOUR WEBSITE! The Actual Names technology can do this for you""" X browser msgaol.exe WIN32.TACTSLAY.C TROJAN! X browser s_menu.exe WIN32.TACTSLAY.C TROJAN! X browser aid browseraid.exe BrowserAid/BrowserPal foistware Y Browser Hijack Blaster bhblaster.exe Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings U Browser Launcher Commandr.exe "Logitech internet keyboard ""Commander"" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys" X Browser Pal adblck.exe BrowserAid/BrowserPal foistware U Browser Sentinel BrowserSentinel.exe "Browser Sentinel. Notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page. See here" N BrowserWebCheck loadwc.exe Checks to make sure that IE is still your default browser N BS Player bsplayer.exe "BSplayer - A video player used to play avi, mpg, wmv and other multimedia files." N BsCLiP BSCLIP.exe CD recording utility that comes with a lot of CDR/CDRW drives and isn't required N B'sCLiP BSCLIP.exe CD recording utility that comes with a lot of CDR/CDRW drives and isn't required X Bsoft lppt01 Bsoft.exe "New variant of the RapidBlaster parasite (in a ""BelmontSoft"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Bsx3 ?? BookedSpace parasite variant X BT ?? Troj/Litebot-B TROJAN! U BT Broadband Help matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide" U BTModemProtection BTModemProtection.lnk "BT Privacy Online modem protection software, see here" U BtStart btstart.exe Broadcorp (formerly WIDCOMM) Bluetooth Connectivity Software U bttray bttray.exe "System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device" Y BTUSRBDG BtUsrBdg.exe Used with a Mitsumi_USB_Bluetooth adaptor (and maybe others) Y BTUSRBDGF BtUsrBdg.exe Used with a Mitsumi USB Bluetooth adaptor X BTV btv.exe BroadcastPC adware N Buddyizer Buddyizer.exe Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network U bugwatcher service bugwatcher.exe "Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures" N BuildBU bldbubg.exe Part of Dell Alerts which provides customers with an update on latest updates for his/her system X BuildLab winlogon.exe NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process X BuildLabs csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X BuildLabs lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" U Bulldog Service upsd.exe Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link Y BullGuard mgui.exe Part of Bullguard antivirus U BullGuard Update avxlive.exe Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions Y BullGuard XComm XCOMMSVR.EXE Part of Bullguard antivirus Y BullGuardInit AVXINIT.EXE Part of Bullguard antivirus Y BullguardoptIn bulldownload.exe Part of Bullguard antivirus X BullsEye bargains.exe eXact Advertising BargainBuddy/Bullseye adware X BullsEye Network bargains.exe eXact Advertising BargainBuddy/Bullseye adware X Bunx beagle.exe W32/Lebreat-E WORM! N BurnQuick Queue BQTray.exe "System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually" U Button Server bttnserv.exe "Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required" N ButtonKey ButtonKey.exe CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut N Buzme Bmui.exe "Buzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem" U BuzMe RCUI.exe Display Client for the BuzMe Internet Call Waiting Service. U Buzof.exe buzof.exe "Buzof from Basta Computing ""enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes""" X bxsx5 ?? BookedSpace parasite variant X bxxs5 ?? BookedSpace parasite X Bymer.Scanner Msinit.exe BYMER WORM! X Bymer.Scanner Wininit.exe BYMER WORM! X c c:\archiv~1\win.com CUYDOC VIRUS! X C:\WINDOWS\IEXPLOR.EXE IEXPLOR.EXE """Pop Marketing"" adware" X C:\WINDOWS\VCMnet11.exe VCMnet11.exe """Windows AFA Internet Enhancement"" - a browser hijacker, redirecting to adsourcecorp.com - see here" X C:\WINDOWS\WinTask.exe WinTask.exe """Pop Marketing"" adware" U C2K CYB2K.EXE CYBERsitter 2000 or 2001 -? anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser U c32cs2 c32cs2.exe Cyber_Sentinel Internet filtering software X C7 ?? W32.MEDIAKILL.A WORM! U CA-AMAgent amagent.exe "Unicenter_Asset_Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting." Y CaAvTray CAVTray.exe eTrust? EZ_Antivirus system tray application from Computer Associates X Cabchk Cabchk.exe GEMA TROJAN! X Cabchk32 Cabchk32.exe GEMA TROJAN! X CABCInstall CABCInstall.exe CABC content delivery software U CacheBoost trayicon.exe "CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost""" X CacheLoader ?? Troj/Dloader-NZ TROJAN! N Cacheman Cacheman.exe Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up Y CacheMgr CacheMgr.exe Sophos Antivirus Remote Update N CACStarter cacstart.exe Cash A Check - check writing software U Caddais BackupOnDemand BODMon.exe "Caddais BackupOnDemand - ""runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location""" U Cadenza CdzSvc.exe Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices U CADS cads.exe Cyber Sentinel internet filtering software N CAgent CAgent.exe Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents X cAgOu ?? KAKWORM VIRUS! N CahootWebcard CahootWebcard.exe """The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details"". Run manually when needed" Y CAISafe isafe.exe Part of Computer Associates eTrust EZAntivirus N Cal Reminder Shortcut calrem.exe Produces a pop-up reminder of events scheduled using the MS Office Calendar X Calc Microsoft Windows wincalc.exe unidentied WORM or TROJAN! N Calendar 200X Reminder calendar.exe "Calendar200X - shows holidays, reminders of various anniversaries,tasks etc" U Calendarscope cs.exe Calendarscope calendar software X calk calk.exe TROJ/STARTPA-FH TROJAN! U CallCenter Main Application V3calmcp.exe """V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications."" Main application" U CallCenter Printer Interface V3faxecp.exe """V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications."" Fax printer" N CallControl ftctrl32.exe "FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows" N CamCheck CamCheck.exe NuCam camera software related U Cameno Cameno.exe Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above N Camera Detector ?? ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically. N Camera Detector ?? ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically. N Camera Detector Camdetect.exe ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically. N Camio Viewer x IXApplet.exe "Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. ""x"" in the name is the version" N Canada Canada.exe Known to be a dialler - but is it maliscous or clean? N Canary canary-std.exe "Canary monitoring program. Keylogger, monitors all computer activity" X candy command32.exe W32/Rbot-LV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X candynet Taskmsg.exe W32/Rbot-NA WORM! N Canon Printer Monitor BJCxxx Cjstlst.exe Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs N Capfax capfax.exe PhoneTools fax software Y Capon Capon.exe Canon printer driver Y Capon Caponn.exe Canon printer driver X CaptionMgr32 crssr.exe W32.ZAR.A WORM! N Capture Express 2000 capexp.exe Capture Express - screen capture utility N Card Monitor REGCNT09.exe For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs X Care20 Care20.exe TopMoxie adware U Care2GTU Care2GTU.exe "Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it keep it" X CARPserver CARPserver.exe TROJ/BANKER-AN TROJAN! U CARPservice carpserv.exe "Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example" X cartao ?? TROJ/DLOADER-QD TROJAN! X cartao conflicted.exe TROJ/DADOBRA-DV TROJAN! X cartao killing.exe TROJ/DLOADER-QN TROJAN! X CAS Client casclient.exe CasinoClient adware U CasAgnt CasAgnt.exe Program by Extended Systems which allows you to sync your Casio PDA with your PC X Casdvqwa bmqnzkg.exe RANDEX.BE VIRUS! X caseyvideo CaseyVideo.exe malware causing p0rn popups X CashBack cashback.exe eXact Advertising BargainBuddy/CashBack adware X CashFiesta Cashfiesta.exe CASHFIESTA.A pay-per-surf adware N Cashsurfers Cashbar Navigator Cashbar.Exe "Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals""" X CashToolbar CD_Load.exe """CashToolbar"" Downloader-MY TROJAN!" X CashToolbar svchost.exe """CashToolbar"" Downloader-MY TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" X Cassandra cassandra.exe Melkosoft_Cassandra adware - also detected as a variant of the WIN32.KREPPER TROJAN! X Cassandra and or Control handler ?? Troj/Krepper-AI Trojan! X CasStub casstub.exe Troj/Cass-A TROJAN! Y CAVRID CAVRID.exe eTrust? EZ_Antivirus Real Time Infection Report from Computer Associates Y CAVS CAVS.exe "Cheyenne, ( now eTrust ) antivirus" X CAZNOVAS CAZNOVAS.exe CAZNO VIRUS! X CBACK.EXE CBACK.EXE Troj/Penta-A TROJAN! U CBWAttn CBWAttn.exe "Required for Bitware to answer incoming faxes, can cause sleep mode problems" U CBWHost CBWHost.exe "Required for Bitware to answer incoming faxes, can cause sleep mode problems" X CC2KUI comet.exe Comet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See here for more information and for the uninstall procedure X ccApp ?? OBSORB VIRUS! Note the random filename compared to the valid Norton AntiVirus entry above X ccApp ?? W32/RBOT-LJ WORM! Y ccApp ccApp.exe Part of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this X ccApp gcasServ.exe variant of the WIN32.RBOT WORM! - do NOT confuse with the Microsoft AntiSpyware executable of the same name as described here X ccApp WMADZ.EXE W32/RBOT-LJ WORM! X ccAppr expIorer.exe WIN32.TACTSLAY.A TROJAN! X ccAppr outIook.exe WIN32.TACTSLAY.A TROJAN! X ccAppr svcrhost.exe WIN32.TACTSLAY.A TROJAN! X ccAppr svcshost.exe WIN32.TACTSLAY.A TROJAN! X ccApps services.exe NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process X ccApps winlogon.exe NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process U CCD Manager DDS.EXE Project Labs Century CD manager for their CD/DVD storage device N Ccdecode ?? Part of the closed caption decdoder/MS VBI codec. Should only run once Y CCDoctorLogonTesting ccdoctor.exe "Checks your system to make sure it's configured properly for running Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product" Y ccenter CCenter.exe RAV AntiVirus Y CcEvtMgr ccEvtMgr.exe "Part of Norton AntiVirus 2003.Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this" X ccEvtMrg.exe ccEvtMrg.exe RBOT.GZ WORM! X ccExecute bootcfg1.exe W32/NEMSI-B VIRUS! X ccHelp ccHelp.hta """Searchq"" adware" X ccpApps csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X ccpApps lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" U ccProxy CCPROXY.EXE "Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage." Y CcPxySvc CCPXYSVC.exe "Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall" X ccreg explorer.exe ZCREW VIRUS! Note - this is not the valid explorer.exe Y CcRegVfy ccRegVfy.exe "Part of Norton AntiVirus 2003. ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack""" X ccRegVfY expIorer.exe WIN32.TACTSLAY.A TROJAN! X ccRegVfY outIook.exe WIN32.TACTSLAY.A TROJAN! X ccRegVfY svcrhost.exe WIN32.TACTSLAY.A TROJAN! X ccRegVfY svcshost.exe WIN32.TACTSLAY.A TROJAN! Y ccSetMgr ccSetMgr.exe Part of Norton AntiVirus 2004. What does it do? X ccUpdate ccUpdate.exe AGOBOT.YS WORM! U ccWasher aolwasher.exe "Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL" U CCWC7a ac.exe "Cache, Cookie & Windows Cleaner Ver. 7, Auto clean. Created by moleculesoft" U CCWC7I idxl.exe "Cache, Cookie & Windows Cleaner 7 created by moleculesoft.com" U CCWC7s stealth.exe "Cache, Cookie & Windows Cleaner 7, stealth mode. Created by moleculesoft" N CD Storage Master cdstorager.exe "CD_Storage_Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection." X cd1 cd1.exe Premium rate adult content dialer N CDANTSRV CDANTSRV.exe "C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually" X Cdcompat Cdcompat.exe GEMA TROJAN! X cddrv32 cddrv32.exe Crypter.C trojan variant infection N CDInterceptor cdi.exe CD indexer for measuring the speed of CD players X Cdrom Controller cdromcntrl.exe TROJ/BATTRY-A TROJAN! N CDTray CDTray.exe "On HP PCs, this is the small CD icon next to the time" U CeEPOWER cepmtray.exe "Toshiba\'s Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times" X Cekirge ?? KERGEZ.A VIRUS! X center ?? W32.BOFRA.A WORM! X CentralProcessor taskimgr.exe BANCOS.J VIRUS! X cesmain.dll "cmail.dll, Rundll32" CnsMin (Chinese_Keywords) related X CEventMgr Cell.exe Troj/Bifrose-AK TROJAN! N CFD CFD.exe BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs X CFDStart WinMuschi.exe WINMUSCHI dialler X cfgboost cfgboot.exe unidentified WORM or TROJAN! Y cfgintpr cfgintpr.exe Configuration Interpreter - part of Tiny Personal Firewall V4 X cfgmgr51 ?? BookedSpace adware variant X cfgmgr52 ?? BookedSpace adware variant N cfgwiz cfgwiz.exe "Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it" U cFosSpeed cFosSpeed.exe cFos_Software Internet acceleration program related. Note: May be necessary for the software to work properly. X cftmon32 taskmgr#.exe SOWSAT.C and SOWSAT.J VIRUSES! where # is a number greater than or equal to zero X cfy cfy.exe Surfenhance.com SearchForIt adware variant U CGServer cgserver.exe Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs X Cgtask Services cgtask.exe LALA.B VIRUS! X Cgywin cgywin32.exe W32/Rbot-AEI Worm! U ChamClock ChamClock.exe Chameleon Clock - system tray clock replacement U ChangeICON SPMSMON.EXE Card reader related program. Note: May cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem. X change-me-now msgfix1.exe SDBOT.ZD WORM! N Chatango Chatango.exe "Chatango ""allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!."" The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately." N Chcenter chcenter.exe "IMSI HiJaak - ""the easiest way to convert, capture, and manage all your graphic files""" X che32 che.ocx.vbs WM97/Adenu-B VIRUS! X Cheatle GigaByte.exe SHODI.B VIRUS! N Check for One Touch Update wiseupdt.exe Checks for updates for Visioneer OneTouch scanners N Check for TWS Updates WiseUpdt.exe Interactive Brokers - check for update to their standalone Java-based trading platform U Check Messenger cmesseng.exe Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account N CheckCustomWorksUpdate CheckCWupdate.exe "Update checker, part of CustomWorks - ""customize any embroidery designs to design your own unique creations""" U CheckIt ToolBox.exe "CheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify" U CheckIt 86 CheckIt86.exe CheckIt_86 popup blocker Y CheckMsgPlus ?? "MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info." X checkrun ?? EliteBar adware X CheckScan32 regload16.exe AEBOT.K WORM! U CherryKeyMan KeyMan.exe Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys X china11msn CHINA11MSN.EXE W32.ENVID.O WORM! U ChineseStar cstar.exe Chinese language support software U CHIPDRIVEPinManager sokscmpn.exe ChipDrive Smartcard software U CHIPDRIVESmartcardManager SCMgr.exe ChipDrive Smartcard software N CHKADMIN CHKADMIN.EXE "Compaq Network Management System. When running, it places an icon in the system tray titled ""Intelligent Manageability""" N chkhbci chkhbci.exe Smart Card reader software for Omnikey readers X Choke Choke.exe-blahh CHOKE VIRUS! X chope runlli32.exe Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X chostsv chostsv.exe BANPAES.C VIRUS! U CHotKey mhotkey.exe "Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features" U CHotKey MK9805.EXE "Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features" U CHotKey zHotkey.exe "Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features" N Christmas Music Player TTEST6.EXE """Christmas Music Playerbrings the music of the Christmas Holiday to your desktop""" X CiaBackdoor msldr.com VIRUS! X cihost.exe cihost.exe LINST VIRUS! N CIJxP2PSERVER CIJxP2PS.EXE "Compaq printer utility which is required in order to make the printer work correctly - ""x"" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7" U Cisco Systems VPN Client ipsecdialer.exe The Cisco VPN_Client Lets local users gain Administrator privileges on the operating system U Cisco Systems VPN Client vpngui.exe Sets up IPSec communications for Cisco's VPN_Client N CISrvr Program CISRVR.EXE Related to internet setup on Compaq PC's X Cissi Cissi.exe CISSI.A VIRUS! U CitiUCS CitiUCS.exe Citibank Virtual_Account_Numbers N CitiVAN CitiVAN.exe Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again X CJET CJet.exe Adware.FFToolBar adware toolbar. Y Cjstcom Cjstcom.exe Canon printer BJ status language monitor Y ClamWin ClamTray.exe ClamWin antivirus X Classes int1.exe """Switch"" adult content dialler" X Classes intl.exe """Switch"" adult content dialler" X Classes MSTAR2.EXE """Switch"" adult content dialer" X Classes mstart.exe """Switch"" adult content dialer" X Classes run_21.exe """Switch"" adult content dialler" X Classes srv.exe """Switch"" adult content dialler" X Classes srv2.exe """Switch"" adult content dialler" U CLBOOT32 CLBOOT32.EXE "PC-Duo_Remote_Control from Vector. ""System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!"". For tech support users to provide remote assistance" U CLCLSet CLCL.exe CLCL clipboard caching utility X clean_service clean_service.cmd W32.Refaz WORM! U CleanSweep Smart Sweep- Internet Sweep Csinsm32.exe Automatic logging of installs from Norton CleanSweep - available via Start -> Programs N CleanSweep Useage Watch CSUSEM32.EXE Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time U CleanTemp CLEANT~1.EXEBCleanTemp.exe CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory Y CleanUp mcappins.exe Used by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled. N Cleanup ONICTASK.EXE Internet Cleanup from Aladdin Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet X clfmon.exe clfmon.exe TROJ/AGENT-BJ TROJAN! N Click Radio Tuner clickr~1.exe ClickRadio - subscription service playing radio music via the internet N Click Tray Calendar ClickT~1.EXE "ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc" N ClickMe ClickMe.exe "ClickM ""JOKE"" program" U Clickoff Clickoff.exe Clickoff automatically dismisses annoying dialog boxes X ClickTheButton csrss.exe """ClickTheButton"" Downloader-MY TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!" X ClickTheButton CTB.exe """ClickTheButton"" Downloader-MY TROJAN!" X ClickTheButton MSCStat.exe """ClickTheButton"" Downloader-MY TROJAN!" X CLICONFG CLICONFG.EXE OPASERV.T VIRUS! U Client Access API Daemon cwbappcd.exe "IBM iSeries Client Access, see here" N Client Access Check Version cwbckver.exe "Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to.?Not required - and can be turned off in the Client Access properties. It's a waste of resources" N Client Access Help Update cwbinhlp.exe "Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries" N Client Access Service CwbSvStr.Exe "Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources" U Client Access Taskbar cwbuitsk.exe "IBM iSeries Client Access taskbar, see here" X Client Agent ?? Troj/PPdoor-J TROJAN! X Client Agent ipxwping.exe Troj/PPdoor-N TROJAN! X Client for Microsoft Networks msclient32.exe W32/Sdbot-BXQ Worm! X Client Server Runtime Process csrs.exe W32.LINKBOT.M WORM! X Client Server Runtime Process csrsss.exe W32/SDBOT-LD WORM! X Client Update wup.exe variant of the W32/OPANKI-A WORM! X ClientMan1 mscman.exe "Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,? ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!""" N Clik Status Monitor toolsclickstat.exe Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed N Clipbook Service Clipsrv.exe "Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks" N ClipMate5x ClipMt5x.exe Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs N Clipmate6 CLIPMT60.EXE Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs N Clipomatic Clipomatic.exe "Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data" X ClipSrv clipserv.exe W32/SDBOT-AAV WORM! N Clipsrv Clipsrv.exe "Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks" U ClipTrak ClipTrak.exe ClipTrak clipboard extender N ClipTrakker ClipTrakker.exe Cliptrakker - clipboard extender U CLMFrontPanel clmpanel.exe "System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost" X clock ?? "LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe" X Clock_Manager amsngr.exe TROJ/SDBOT-XM TROJAN! X ClockSync Sync.exe "ClockSynck - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available" U ClockWise CLOCKWISE.EXE "ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync" U CloneCD or CloneCDTray CloneCDTray.exe "System tray for CloneCD - the only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions" U CloneCDElbyCDFL ElbyCheck.exe From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it X ClrSchLoader Loader.exe Lycos/IGetNet.ClearSearch parasite X CLSID com.exe Adult content dialler X CLSID dll.exe Adult content dialler X CLSID msgplus.exe "Premium rate adult content dialer - NOTE: this is NOT the MSN Messenger 'MessengerPlus' extension, as described here" X CLSID plugin.exe Adult content dialler X CLSID sed.exe Adult content dialler U cma cma.exe "DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center""" X CMAPP cmappclient.exe CasClient adware - also detected as Trojan.Cmapp N Cmaudio "Rundll32 cmicnfg.cpl, CMICtrlWnd" System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel X Cmd cmd32.exe P2P.TANKED VIRUS! X cmd32 configs.exe "Hijacker, also detected as the QURL-2 TROJAN!" X cmdcon cmdcon.exe CRYPTER.A TROJAN! X CmdPrompt32.pif CmdPrompt32.pif W32.Assiral.B WORM! X CME cme.exe Part of Gator advertising spyware - see here for removal instructions U C-Media Echo Control EchoCtrl.exe C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer N C-Media Mixer Mixer.exe C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs X CmeSYS CMEsys.exe Part of Gator advertising spyware - see here for removal instructions X CmeUPD CMEupd.exe Part of Gator advertising spyware - see here for removal instructions X Cmmon32Sys cmmon32.exe WIN32.SMALL.CL TROJAN! U CmPCIaudio "RunDll32 CMICNFG3.CPL,CMICtrlWnd" Registers the Control Panel applet for a C-Media PCI sound card U CMPDPSRV CMPDPSRV.EXE "Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). ""Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more."" Installed with some Compaq and Lexmark printers" X Cmpnt Devices2.exe Troj/Tompai-D TROJAN! X Cmpnt mainsv.exe Troj/Tompai-C TROJAN! X cmrss ?? Troj/Dloader-QQ TROJAN! X cmrss cmrss.exe DELF.DU and Troj/Dloader-NK TROJANS! X cmrss crmss.exe DLOADER-EK TROJAN! X cmrst cmrst.exe PWSteal.Bancos.S TROJAN! X cmrst cmrst.scr Troj/Dloader-FP TROJAN! X CMS_Update ms_update.exe eBoard adware variant U CMSETTINGS ctmn.exe Part of NetNanny Chat_Monitor X cmsound vcpdll.exe TCXMEDI-D downloader TROJAN! X cmsound vcsystem.exe TCXMEDI-D downloader TROJAN! X cmss system.exe variant of the WIN32.RBOT WORM! X cmssapp iexplore_.exe Troj/Bancban-CQ Trojan! X cmssSystemProcess csms.exe AGENT-Y TROJAN! X cmssSystemProcess csmss.exe TROJ/AGENT-CO TROJAN! X cmssSystemProcess mcsmss.exe REPSAMO TROJAN! X cmt101 cmt101.exe Crypter.C trojan variant infection X cmx32 cmx32.exe W32.GEMA.D TROJAN! X Cn323 cnfrm33.exe W32.MIMAIL.G WORM! X CNBABE CNBABE.EXE Appears to be spyware KAZAA (and maybe others) that displays pop-up ads whilst you\'re browsing N cnet kontiki.exe Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops X Cnfrm32 cnfrm.exe W32.MIMAIL.D WORM! X CnsMax Internat.exe POINTEX VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir% X CnsMin ?? CnsMin (Chinese_Keywords) related Y CnxAdslL CnxAdslL.exe "DLink, Zoom, or Conexant modem driver" N CnxDslTaskBar CnxDslTb.exe Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems U Codename Dashboard dashboard.exe "Codename: Dashboard - ""an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time""" X Coldlife -icmp Systray.exe IRC/FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process U coloreal coloreal.exe "Makes colours sharper and brighter, but will only work with coloreal capable monitors" N Colorific Control Panel Hgcctl95.exe From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor X COM Service mscom32.com BEASTY.H VIRUS! X COM Service msdrce.com BEASTY.I trojan X COM Service msjclh.com PLUX VIRUS! X COM Service msynvr.com BEASTY.G VIRUS! X COM+ Event System DRWTSN16.EXE variant of the LOVGATE WORM! X COM+ EventSystem Services ECSERVER.EXE variant of the W32/SDBOT WORM! X Com+ Sys csrs.exe W32/FORBOT-BT WORM! X COM+ System Applications lsas.exe AGOBOT.SE WORM! X COM++ System exploier.exe variant of the LOVGATE WORM! X COM++ System suchost.exe variant of the LOVGATE WORM! X COM++ System svchost.exe variant of the LOVGATE WORM! U ComAgent ComAgent.exe "ComAgent, MDaemon's instant messaging client" X combo.exe combo.exe Troj/Chimo-C TROJAN! X combop.exe combop.exe "Troj/Bckdr-CSJ TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. When run, this file together with its little friend combo.exe send spam from your machine." X combop.exe combop.exe Troj/Bowfeed-A TROJAN! X Comcast Network ribiva.exe IRC_TROJAN variant! X ComcastSUPPORT tgkill.exe "Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an ""enhanced"" support and self-repairing tool. This is ""beta"" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs" X COMCFG comcfg.exe TOADCOM.A VIRUS! X comctl32 comctl32.exe Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am U COMDRV32 svdhost.exe "Orvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/" N COM-IP COMIP.EXE COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212) U Comm Driver commh32.exe "G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!" X COMMAND command.exe QQPASS.E VIRUS! X Command Gotit.exe TITOG VIRUS! X command javaw.exe W32/Agobot-LG WORM! X Command system.exe GATECRASH.A or GATECRASH.B VIRUSES! X command32 command32.exe Troj/LineaDl-A TROJAN! N CommCtr commctr.exe """Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!"". Available via Start -> Programs" U Compaq Alerter CPQAlert.exe "Compaq's Insight Manager Agent - a tool that allows for ""fault, performance, and configuration management"". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information" N Compaq Computer Corp SCCenter Module SCCENTER.EXE For Compaq PC's. Part of Backweb N Compaq DMI cpqdmi.exe Compaq version of the Desktop Management Interface X Compaq Drivers F1rewalls.exe W32/SDBOT-WD WORM! N Compaq Internet Setup inetwizard.exe For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list X Compaq Jes Drivers winjes.exe W32/SDBOT-XR WORM! U Compaq Knowledge Center matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support"". You decide" U Compaq Knowledge Center silent.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support"". You decide" N Compaq Message Server COMPAQ-RBA.EXE "Applies to CPQBootPerfDB below as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the ""Compaq Advisor/Compaq Message Screener"" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the ""advanced"" tab. Not required and can cause problems" U Compaq PK Daemon cpqkl.exe For Compaq laptops for programming user configurable keys. Not required unless you use them X Compaq Print Fax cpqa1000.exe W32/SDBOT-WL WORM! X Compaq Service Drivers amsn.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers compq.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers compqs.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers msnsvc.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers msnt.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers navapqwa.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers NtKernelSystem.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers systeminfos.exe W32/SDBOT-XC WORM! X Compaq Service Drivers wincmd.exe RBOT.ATV WORM! X Compaq Service Drivers wind32.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers winmsn.exe variant of the W32/SDBOT WORM! X Compaq Service Drivers 32 compq32.exe variant of the W32/SDBOT WORM! X Compaq Service Drivrs copq.exe variant of the WIN32.RBOT WORM! X Compaq Sound Drivers For WINDOWS sounddr.exe W32/SDBOT-XG WORM! N Compaq Video CD Watcher ?? For Compaq PC's. MPEG viewer X Compaq32 Service Drivers ms32.exe SDBOT.BWH WORM! X Compaq32 Service Drivers msconfig32.exe W32/SDBOT-ADC WORM! X Compaq32 Service Drivers msnt32.exe variant of the WIN32.RBOT WORM! N CompaqHW Comp Manager cpqhcm.exe "Compaq_Intelligent_Managability agent; ""a solution that simplifies inventory management by automating the collection of hardware asset data for Compaq servers running in a NetWare environment""." N CompaqPrinTray printray.exe Puts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop X Compaqs Service Drivers compqs.exe variant of the W32/SDBOT WORM! N CompaqSystray cpqpscp.exe Compaq System Tray icon X Compatibility Service Process regsvs.exe GAOBOT.YN WORM! X Compd Service Drivrs codq.exe variant of the W32/SDBOT WORM! X Computing Technologie Firewall lsauth.exe W32/SDBOT-WX WORM! N COMSMDEXE comsmd.exe 3Com tray icon X ComTry Web Searcher wstray.exe Comtry MP3 Downloader related - spyware X comxt comxt.exe Comxt trojan infection X Config service.exe ISRAZ.B VIRUS! X Config Loadation iEEexplore.exe SDBOT.H WORM! X Config Loadatiorin I3Explorer.exe SDBOT.H WORM! X Config Loader scvhost.exe GAOBOT.AE or GAOBOT.AO WORMS! X Config Loader svchosl.exe GAOBOT.P WORM! X Config Loader svhost.exe variant of the AGOBOT/GAOBOT WORM! X Config Loader sysldr32.exe GAOBOT WORM! X Config Loader for Microsoft Windows mwincfg32.exe AGOBOT.BD WORM! X Config Loader2 explores.exe GAOBOT.BT WORM! X Config Loadr winsys32.exe AGOBOT-HN WORM! X Config33.exe Config33.exe SDBOT.T backdoor TROJAN! X ConfiggLoader cart322.exe GAOBOT.DJ WORM! U ConfigSafe AUTOCHK.EXE "ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice" U ConfigSafe CFGSAFE.EXE "ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice" N ConfigServices Config.exe Part of initial setup on a Compaq PC X Configuration ?? W32/SDBOT-ML WORM! X configuration apphost.exe W32/SDBOT-VP WORM! X Configuration ntsys32.exe W32/SDBOT-LN WORM! X Configuration Default Wuxat.exe W32/SPYBOT-CA WORM! X Configuration File Winset32.exe BackDoor.Flux.101 TROJAN! X Configuration Loaded lssas.exe variant of the W32/SDBOT WORM! X Configuration Loaded wupdated.exe MOEGA or MOEGA.AG or MOEGA.AP VIRUSES! X Configuration Loader aim95.exe LOADCFG or SDBOT TROJANS X Configuration Loader botss.exe W32/SDBOT-XS WORM! X Configuration Loader ccSort.exe AGOBOT.SR WORM! X Configuration Loader cmd32.exe "LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files" X Configuration Loader confgldr.exe POLYBOT VIRUS! X Configuration Loader crcss.exe AGOBOT.ADG WORM! X Configuration Loader dezi.exe W32/SDBOT-OB WORM! X Configuration Loader dosrun32.exe GAOBOT.AO WORM! X Configuration Loader IEXPL0RE.EXE "LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files" X Configuration Loader ldasp.exe AGOBOT.BH WORM! X Configuration Loader lexplore.exe W32/RBOT-AGX WORM! X Configuration Loader microsoft.exe GAOBOT.JB WORM! X Configuration Loader mouse.exe variant of the AGOBOT/GAOBOT WORM! X Configuration Loader msg.exe SDBOT.BT WORM! X Configuration Loader msgcfgsrv.exe variant of the AGOBOT/GAOBOT WORM! X Configuration Loader msgfix.exe W32/SDBOT-QG and W32/Sdbot-BTE WORMS! X Configuration Loader msnss.exe GAOBOT.AUS worm X Configuration Loader MSTasks.exe "LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files" X Configuration Loader scvhost.exe W32/AGOBOT-AAE and Backdoor.Sdbot.AR WORMS! X Configuration Loader seru32.exe W32/SDBOT-VR WORM! X Configuration Loader Service.exe GAOBOT.AO WORM! X Configuration Loader service5.exe GAOBOT.AF WORM! X Configuration Loader Servicess.exe GAOBOT.AO WORM! X Configuration Loader smsai.exe W32/SDBOT-YE WORM! X Configuration Loader smss32.exe AGOBOT.MB WORM! X Configuration Loader svchost.exe W32/ParaDrop-A WORM! X Configuration Loader svchost2.exe AGOBOT.JR WORM! X Configuration Loader svhst.exe GAOBOT.YC WORM! X Configuration Loader svupdate.exe W32.RANDEX.DXP WORM! X Configuration Loader sw32.exe AGOBOT.BQ WORM! X Configuration Loader sycfg34.exe GAOBOT.AN WORM! X Configuration Loader syscfg32.exe SDBOT.B WORM! X Configuration Loader sysinfo.exe GAOBOT.FQ WORM! X Configuration Loader System.exe GAOBOT.AO WORM! X Configuration Loader systemry.exe variant of the AGOBOT/GAOBOT WORM! X Configuration Loader wincffg.exe AGOBOT.A3 WORM! X Configuration Loader wincrt32.exe GAOBOT.BF WORM! X Configuration Loader windex.exe GAOBOT.BM WORM! X Configuration Loader windex.exe GAOBOT.BZ WORM! X Configuration Loader WinHelper.exe variant of the AGOBOT/GAOBOT WORM! X configuration loader winicfg32.exe GAOBOT.GEN!POLY WORM! X Configuration Loader Winreg.exe GAOBOT.AO WORM! X Configuration Loader Service devl32.exe W32/SDBOT-XY WORM! X Configuration Loader Service Winsys32.exe W32/RBOT-YV WORM! X Configuration Loader Service winsys32.exe W32/RBOT-YV WORM! X Configuration Loader10 ip7.exe W32/AGOBOT-ANZ WORM! X Configuration Loading configldr.exe AGOBOT-EC WORM! X Configuration Loading svchos1.exe GAOBOT.DK WORM! X Configuration Loading Service wscel.exe W32/SDBOT-WJ WORM! X Configuration Manager CNFGLD32.EXE SDBOT WORM! X Configuration Manager Cnfgldr.exe SDBOT WORM! X Configuration Service suchost.exe TREB VIRUS! X Configuration Services mswords.exe W32/SDBOT-YM WORM! N Configuration Utility CONFIG.EXE Controls linksys wireless connection. Available from the Desktop U Configuration Utility wlanutil.exe NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) N Configuration Wizard Cfgwiz32.exe "variation of the HACKTACK VIRUS! Not to be confused with the valid MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe) in C:\Windows\System" X Configuration32 Loader32 winamp32.exe W32/Sdbot-BIC WORM! X ConfLoader sysconf16.exe TROJ/SDBOT-FB TROJAN! N Conmgr conmgr.exe Starts Winfax pro at startup U ConMgr.exe conmgr.exe Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut? X Connect2Party connect2party.exe Adult content dialler N Connection Manager CManager.exe SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service X Connectivity Tool ?? Troj/Litebot-E TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Connector sms.EXE Dial/ExDial-B Dialer! Note: Dial/ExDial-B is a premium rate porn dialer. X Connector SYS.EXE Dialer.Nunci premium dialer. X Cons consol32.exe "Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed" X conscorr conscorr.exe Transponder parasite updater/installer X Console de Gerenciamento Microsoft csrss.exe Troj/Bancban-ET TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X ContentDownload ?? MatrixDialer related X ContentService winservn.exe Homepage hijacker X ContinueInstall bpsinstall.exe BrowserAid parasite X Control ?? CoolWebSearch parasite related X Control handler ?? CoolWebSearch parasite variant X Control handler ahjinst.exe CoolWebSearch parasite variant N control panel smctrlw.exe System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card X Control Panel System.exe DANI VIRUS! X Controladores ?? Troj/Telefo-A Trojan! N ControlCenter2.0 brctrcen.exe Brother scanner 'Control Center' application; can be started manually N ControlCentreTray XWCTray.exe "System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc" X Controlled Resource System Service crss.exe "variant of the AGOBOT.GEN WORM! **Note - this is NOT the legitimate crss.exe process, which should NOT figure in Msconfig/Startup!" N Controller WFXCTL32.EXE From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs X ControlPanel ?? Awmcash.biz foistware X ControlPanel "internat.dll,LoadKeyboardProfile" Troj/Bizves-A TROJAN! X ControlPanel "popcorn.exe internat.dll,LoadKeyboardProfile" Troj/Bizves-B Trojan! X ControlPanel "popcorn320.exe rundll.dll,LoadMouseProfile" variant of the TROJ/DLOADER-RA TROJAN! X ControlPanel "popcorn64.exe rundll.dll,LoadMouseProfile" Troj/Dloader-OI TROJAN! X ControlPanel "popcorn72.exe rundll.dll,LoadMouseProfile" TROJ/DLOADER-RA TROJAN! X ControlPanel "rundll32 internat.dll, LoadKeyboardProfile, [path] twink64.exe internat.dll,LoadKeyboardProfile" CoolWebSearch parasite related X ControlPanel svcc.exe WorldSearch adware X ControlPanel "systemctrl.exe internet.dll,LoadNetworkProfile" "Browser hijacker, also detected as TROJ/STARTPA-FX" U Cookie Cop 2 CookieCop.exe "Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return" U Cookie Pal CPBRWTCH.EXE "Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return" U CookieJar Cookiejar.exe "Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return" U CookiePatrol CookiePatrol.exe CookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies U CookieWall cookie.exe "CookieWall from Analog X. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return" U Cool Desk cdesk.exe "Cool Desk is a virtual desktops manager. ""Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them"". Not required but may be of use to you" X CoolDownloads ?? MatrixDialer related X CoolMP3 ?? MatrixDialer related U CoolSwitch taskswitch.exe ALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen N Coolwallpaper cwm_tray.exe Cool_Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers X coolwebprogram clrssn.exe CoolWebSearch parasite related U Copernic Desktop Search CopernicDesktopSearch.exe "Copernic Desktop_Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures.""" U CopernicPerUserTaskMgr CopernicPerUserTaskMgr.exe Automatic tasking feature of Copernic Pro multi-search engine tool U Copy handler Copy Handler.exe "Copy_Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes." N Copyright mwcpyrt.exe Displays copyright information on IBM ThinkPads N Corel Colleagues & Contacts Reminders cffrem.exe "Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office" N Corel Desktop Application Director dadx.exe The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs N Corel Family & Friends reminders CFFREM.EXE "Corel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic" N Corel Registration or Corel Registration Remi Remind32.exe If you don\'t want to register Corel products and be reminded about it every 2 weeks disable it N Corel Reminder NAVBROWSER.EXE If you don't want to register Corel products and be reminded about it every 2 weeks disable it N CorelCENTRAL 10 I_26dadCC.exe CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs X CorelDraw Toolbox CorelDraw.exe W32/SDBOT-VZ WORM! N CorelMedia FoldersIndexer8 MFindexer.exe MFINDE~1.EXE "Part of CorelDraw bundles for indexing media files - similar to ""fast find"" in MS Office" X CoreSrv coresrv.exe Some IRC trojans/worms use this - see here for more information N CorrectConnect CConnect.exe Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available X cosine cosine.exe W32/RBOT-SW WORM! U CostAware niIPCApp.exe NetInternals CostAware - download quota measuring tool N CountrySelection or Country Select pctptt.exe "Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you\'ve set the modem up to the chosen country it\'s not required" X couponica couponica.exe Adware - see here U CP32NOT CP32BTN.EXE "For the programmable ""one-touch"" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons" U CP4HPOT OneTouch.EXE One Touch keyboard driver. Required if you use the additional keys U CPATR10 CPATR10.EXE "Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast" U CPBrWtch CPBrWtch.exe "Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return" Y CPD_EXE CPD.EXE Firewall bundled with McAfee VirusScan 6.* X cpl deamon.exe WIN32.TACTSLAY.C TROJAN! X cpl msgaol.exe WIN32.TACTSLAY.C TROJAN! X cpl s_menu.exe WIN32.TACTSLAY.C TROJAN! N CplBTQ00 CplBTQ00.EXE Related to the EZbutton quick launcher N CPLDBL10 CPLDBL10.exe Related to the EZbutton quick launcher X cpntmgc navpmc.exe MagicControl downloader trojan variant X cpntmgc simcss.exe MagicControl downloader trojan variant X cpntmgc wincomp.exe Remote-control trojan from Electronic Group - see here X cpntmgc winmgts.exe Remote-control trojan from Electronic Group - see here Y CPQAcDc CPQAcDc.exe Compaq PowerCon power management software for laptops U CPQAlert CPQAlert.exe "Compaq's Insight Manager Agent - a tool that allows for ""fault, performance, and configuration management"". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information" N CPQBootPerfDB CPQBootPerfDB.EXE See the entry for Compaq Message Server Y CPQCalib CPQCalib.exe Compaq PowerCon power management software for laptops N CPQDFWAG CpqDfwAg.exe For Compaq PC's. Runs Compaq diagnostics on every boot U CPQEASYACC cpqeadm.exe For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys U CPQEASYACC StartEAK.exe For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys U cpqeaui cpqeaui.exe For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys U cpqek kcpqek.exe For Compaq PC's. Easy Access button support for the keyboard X CPQHotkeys hotkeysvc.exe W32.Kelvir.A or W32.Kelvir.B WORM! U CPQInet Runtime Service CpqInet.exe For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers N CPQINKAGENT cpqinkag.exe "That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)" U cpqns cpqnpcss.exe Related to Compaq.Net - not required if you don't use that N Cpqset Cpqset.exe Default settings software in Hewlett Packard notebook Y CPQSTUTFIX stutfix.exe For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton X cpr cpr Adroar.com adware downloader X CPU Manager cpumgr.exe PANDEM.B VIRUS! X CPU Temp Control wuitgurd.exe W32/RBOT-AHV WORM! X CPU Watcher ?? TROJ/DLOADER-LO TROJAN! X CPU Windows Status cpustats.exe variant of the WIN32.RBOT WORM! U CPUcool Cpucool.exe "Program to keep the processor cool when idle in ""overclocked"" systems. Also available via Start -> Settings -> Control Panel" X Cpusave Cpusave.exe GEMA TROJAN! X Cpusave32 Cpusave32.exe GEMA TROJAN! X cpyt hidep.exe Troj/Mirjack-A Trojan! X cqlyg world_cup_.bat WCUP VIRUS! U cracked_windows1 cracked_windows1.exe Cracked Windows popup killer N CrazyTalk Serve ?? "CrazyTalk from Reallusion - ""the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions."" Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS" X CRC Value Verifier crsss.exe SPYBOT.UK WORM! X CRC Value Verifier crsss32.exe variant of the WIN32.RBOT WORM! X CRC Value Verifier Crsss64.exe W32/Rbot-NY WORM! X CRC Value Verifier svchost32.exe W32/RBOT-OA WORM! X Crc32stats Dependencies Crc32stats.exe W32.MYTOB.GT WORM! U Creata Mail JMSrvr.exe "Creata_Mail . Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express." X Create A Monster createAMonster.exe Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related N CreateCD Createcd.exe Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs N CreateCD50 Createcd50.exe Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs N Creative AGP Wizard agpwiz.exe Part of Creative's BlasterControl N Creative Launcher CTLauncher.exe For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs N Creative MediaSource Go CTCMSGo.exe """Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats""" N Creative PCI Audio Configuration Utility starter.exe System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer N Creative Service for CDROM Access Ctsvccda.exe Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs N Creative WebCam Tray Camtray.exe Creative WebCam tray control; can be started manually. X Creative.exe Creative.exe PROLIN VIRUS! N CreativeDiscNotifier CTNOTIFY.EXE "For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel" U CreativeMixer CTMIX32.EXE "Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the ""speaker"" icon. Not required unless you adjust any settings otherwise available via the standard icon" X Critical Update Check battlenet.exe Troj/Delf-LB TROJAN! N CriticalUpdate Wucrtupd.exe "MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site" X Crnsava scrnsave.pif W32/Sdbot-ZV WORM! X cronos MARCO!.SCR OPASERV.G VIRUS! U CrossMenu CrossMenu Toshiba CrossMenu Utility - allows the user to create their own menus X crs crs.exe W32/Agobot-TJ WORM! Note: This worm\trojan file is found in the Root folder. Example: ( C:\ ) X Crusty dmcpl.exe Added as the result of the RUSTY VIRUS! X cryptdlg cryptdlg.exe unidentified TROJAN! X Cryptographic Service ?? Win32.Korgo.AB worm N csaRem spqmdmui.exe Compaq modem country selection Y CSAV_CheckViruses vchk.exe Part of Command AntiVirus X CSCRS Value cscrs.exe W32/RBOT-AAA WORM! X CSCRS Value Check MsPMSPSd.exe variant of the W32/SDBOT WORM! U CSINJECT.EXE CSINJECT.EXE "Part of Quarterdeck/Norton CleanSweep. For a full description see here. An excerpt - ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes.""" X csm Win Updates csm.exe W32/ZOTOB.B WORM! X csoftok softok.exe TROJAN.PWS.QQPASS.G TROJAN! X csrsc csrsc.exe unidentified VIRUS! U csrss csrss.exe "Spyware.BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. - NOTE - this file is placed in the Program Files\Supremtec folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X CSRSS CSRSS.EXE "Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling" X Csrss csrss.exe "W32.Chod WORM! Note - This will be installed in a random folder and is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X Csrss csrss.exe "W32.CHOD.B WORM! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!" X CSRSS Loader csrsss.exe AGOBOT.TX WORM! X csrssLevel4 csrss.exe "Unidentified malware - NOTE - this file is placed in a C:\Windows\System\Level4 folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X CSRSSU CSRSSU.exe CoolWebSearch parasite related - hijacking to Slawsearch.com. Also see here X CSRSSW CSRSSW.EXE TROJ/CWS-F TROJAN! X CSRSWIN ?? WINSHELL.50 VIRUS! X CSRSX ?? WINSHELL.50.B VIRUS! U CSS Server CSSServer.exe ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself. U CSS_Central CSS_1631.EXE "CSS Communication Agent (95 Host) from Command Software Systems""CSS Central? provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console.""" Y CSScheduleCheck SCHWIZEX.EXE "Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot" X cssrs cssrs.exe Troj/Bancban-DW TROJAN! X csss Csss.exe BALICK VIRUS! X CSV10P70 CSv10P070.exe ClearSearch adware related X CSV7P26 CSV7P26.exe ClearSearch adware related X CSV7P70 CSV7P070.exe ClearSearch adware related X CSV7P91 CSV7P91.exe ClearSearch adware related U csvdea csvdea.exe SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself. Y ct ct.exe ct.exe is a file is for the HP Learning Adventure software?and if you use this software it is required to run it X CT Control Settings CTSVCCD.EXE W32/RBOT-YS WORM! N CTAVTray CTAvTray.exe For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ U CTCMonitor CTCMonitor.exe "Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required" N CTDVDDet CTDetect.exe "Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again" N CTDVDDet CTDVDDet.exe "Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again" X ctflog manager ctflog.exe DONBOMB.A TROJAN! X CTFM0N.exe CTFM0N.exe STARTPAGE.P TROJAN! X ctfmon cftmon.exe TROJ/DELIVE-A TROJAN! X ctfmon ctfmon.exe Troj/SDBot-06 Trojan! X ctfmon ctfmon.exe Adware responsible for tenmonkey.com popups - file located in the Winnt or Windows folder - NOTE: do not confuse with the MS Office file of the same name as described here X ctfmon mIRC.dll Troj/Delbot-E Trojan! X ctfmon taskmgr32#.exe SOWSAT.B VIRUS! where # is a number from 0 to 9 X ctfmon WinConst.exe Troj/Assasin-G Trojan! U ctfmon.exe ctfmon.exe "CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don\'t need these features. For more info on ctfmon see here;en-us;282599 . CTFMON can be disabled from Control Panel, Text & Speech Services. NOTE: The file will always be located in the System32 folder. If it is located elsewhere, it will likely be a worm or trojan!" X ctfmon.exe ctfmon.exe PWSteal.Raidys TROJAN! X Ctfmon.exe ctfmon32.exe CoolWebSearch parasite related X CTFMON32 CTFMON32.EXE CoolWebSearch parasite related - also detected as the TROJ/CWS-E TROJAN! X CTFMONSS CTFMONSS.EXE TROJ/CWS-F TROJAN! X ctfnom rundIl32.exe Troj/LegMir-AW TROJAN! Note: This is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling). This trojan file (rundIl32.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X ctfnom.exe OSRSS.exe Troj/Dloader-UQ TROJAN! Note: This trojan file (OSRSS.exe) is found in the Windows or Winnt folder. X ctfnom.exe SVOHOST.exe Troj/Digidor-A or Troj/StartPa-HA TROJAN! X cthelp cthelp.exe SDBOT TROJAN! N CTHELPER CTHELPER.EXE "CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a ""leave alone"" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it" X CTHelper cthelper.exe W32/RBOT-XB WORM! - NOTE - do NOT confuse with the Creative application of the same name described here X CTime ?? CoolWebSearch parasite related X CTin10 CTin10.exe BANCOS.E VIRUS! N CTRegRun CTRegRun.exe For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative U CtrlVol CtrlVol.exe Acer's on screen volume control using the Fn key N CTStartup CTEaxSpl.exe Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard U CTsysVol CTSYSVOL.exe Creative sound card volume controls X CTUpdate ctupdclt.exe W32/RBOT-ABG WORM! X Ctykd ?? TSPY_SMALL.SN spyware Y cuagentExe Cuagent.exe Command Antivirus related X cuo cuo.exe BUGBEAR VIRUS! X Current Security Config csecure.exe W32/Rbot-AMO WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N cursor Screendragon_VS_Taskbar.exe ScreenDragon video player N CursorXP CursorXP.exe CursorXP from Stardock - tool for creating mouse cursors U CurtainsSysSvc AuthSL.exe "Security Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private." U Customizer2000 logon.exe "Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes""" N CuteMX CuteMX.EXE File sharing utility X cvmonitor.exe cvmonitor.exe WORM_SDBOT.BV Y CVPND cvpnd.exe Sub-system used by?Cisco VPN client?for making a connection to a remote IPSec server U CW cw4.exe "Chat_Watch ""is a monitoring and logging software for online chat and instant messaging programs""" U CWatch cw.exe ChatWatch - chat monitoring tool N cwbckver cwbckver.exe "Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to.?Not required - and can be turned off in the Client Access properties. It's a waste of resources" N cwbinhlp cwbinhlp.exe "Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries" N cwbsvstr cwbsvstr.exe "Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources" U cwupdate cwupdate.exe "ContentProtect, from ContentWatch - http://www.contentwatch.com/products/contentprotect.phpinternet filter" N CXMon Hpi_Monitor.exe "Autodetects when a HP camera is attached to the computer and launches the ""HP Photoimaging Software"". Available via Start -> Programs" N Cyber cyberchk.exe "Part of Belkins ""Multimedia Cleaning Kit"" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after ""x"" amount of time has passed" U Cyber Trio showmode.exe "From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs" U Cyber-Defender 2003 uwcdsvr.exe Cyber Defender 2003 X cyberfree.exe ?? Unidentified adware U CyberLat Ram Cleaner CLRamCleaner.exe "CyberLat RAM Cleaner is a program that Frees, Optimizes and Defrags your system\'s wasted memory (RAM). Some users swear by programs such as this but I suggest you read this article and make up your own mind" N CyberMedia Agent CMAGENT.EXE "Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled" X CyberWolf CyberWolf.exe KICKIN.A (or CYDOG.C) VIRUS! X CyDoor or CydoorUpdate CD_Load.exe Adware. Check here for information about Cy-Door and here for a program that can remove it N CyphTray CyphTray.exe Cypherus - encryption software N D066UUtility D066UUTY.EXE TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software X D3**.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X D3**32.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X d3dupdate.exe bbeagle.exe BEAGLE.A WORM! U D4 D4.exe Dimension 4 - network time synchronization software N DACONFIGEXE daconfig.exe 3Com NIC Diagnostics. Available via Start -> Programs Y DadApp dadapp.exe """DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked"" - direct from Dell" X Daemon daemon.exe c daemon2.exe W32.Selotima.A WORM! N Daemon DAEMON32.EXE Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs U Daemon or DAEMON Tools-1033 Daemon.exe "Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive" N Daily Planner dayplan.exe "Daily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them" X Daily Weather Forecast weather.exe DLOADER-IP TROJAN! U Dancer DncLE.exe Part of Microsoft Plus! Digital Media Edition - see here X Danton ?? DANTON VIRUS! N Dap DAP.exe Download Accelerator Plus from SpeedBit - download manager/accelerator X dark imgrt.scr Troj/Bancban-DU WORM! X dark imgst.scr PWSTEAL.BANCOS.U TROJAN! X DarkDevil.Grasiele.BR Grasiele.VBS LEMBRA VIRUS! X DarKNesS LsasS LsasS23.exe unidentified WORM or TROJAN! X dasxdads fsdqd.exe GAOBOT.BIQ WORM! X data msngs.exe W32/RBOT-ADQ WORM! X Data System.dat.vbs BISCUIT.A VIRUS! N Data LifeGuard BACKWE~1.EXE Data LifeGuard diagnostic tools for Western Digital\'s series of hard drives N Data LifeGuard LifeLine Lite installer DLGLI.EXE Backweb installer - see here X Data Restore Service prq8.exe W32.Kelvir.AI WORM! X Data789 ?? Homepage hijacker X DATABASE MySql ?? variant of the RANDON.AN WORM! N DataCaching FlashKsk.exe "SmartMedia Card management from the installation of a SanDisk reader for a camera\'s SmartMedia card and also adds the ""Unplug and Eject Hardware"" System Tray icon" U DataLayer DataLayer.exe "Nokia PC Suite 5 - ""A collection of powerful tools that you can use to manage your phone features and data."" Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on" U DataViz Inc Messenger DvzIncMsgr.exe "Installed with DataViz ""Documents to Go"" software" N DataViz Messenger DvzMsgr.exe "DataViz Documents to Go - ""allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts""" X Datcheck datcheck.exe KEYPANIC VIRUS! X Date Manager datemanager.exe DateManager - calendar program. Contains Gain adware X DateMakerIntl DateMakerIntl.exe Premium rate dialler also referred to as the PORNSPA.F VIRUS! X Daudi daudi.exe "Malware, as yet unidentified" X DAupdate DAupdate.exe NavEnhance adware U DayToday DAYTODAY.EXE DayToday from RoboMagic Software Corp. Displays the date on the taskbar U DAZEL Delivery Agent DcDaemon.exe "Control and send documents, etc, to any destination - see here" N dbserv dbserv.exe Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled N DBTMON dbtmon.exe Dell button monitor for 9XX series printer most commonly associated with 922. Can safely be turned off does not hamper printer operations. Can be accessed from the start menu X DCE Manager dcemgr.exe TUMAG.A TROJAN! U DCfssvc or dcfssve dcfssvc.exe "Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can\'t load pictures from your camera/dock - Kodak\'s dock is an example" X Dcom System Patch Microsoft.exe RANDEX.MS WORM! U DDCActiveMenu DDCActiveMenu.exe Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case X DDCM or DDCMan DDCMan.exe Digital Distribution Channel from Wild Tangent - adware X ddeproc ddeproc.exe Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here X DDialler DDialler.exe Adult content dialler X de32gen de32gen.exe CRYPTER.C trojan variant infection N DeadAIM ?? DeadAIM - feature enhancing product for AOL\'s Instant Messenger program X DealHelperBrwsr dhbrwsr.exe DealHelper adware X DealHelperDown download.exe DealHelper adware X DealHelperUpdate DHUpdt.exe DealHelper adware X Debug DebugW32.exe GUBED VIRUS! X DebugMonitor debugmonitor.exe W32.Mydoom.BG WORM! U DeeEnEs DeeEnEs.exe DeeEnEs - automatically updates a dynamic IP address when it changes. X deejay forboo.exe Added as result of a Forbot-AY worm infection X Default explore.vbs VBS.Allem WORM! X Default mtask.vbe VBS.Allem WORM! X default shell32.exe Backdoor.Binghe TROJAN! X Default System Research vhchost.exe TARNO.I VIRUS! X Default web browser IexpIore.exe "OBLIVION.B VIRUS! Note - don not confuse ""IexpIore.exe"" with ""iexplore.exe"" (Internet Explorer), the first has a captial ""i"" in place of lower case ""L""" X Default_Page_URL http://find.naupoint.com Naupoint browser hijacker X Default_Search_URL http://find.naupoint.com Naupoint browser hijacker X defragm_check defragment.exe CoolWebSearch parasite related U defwatch defwatch.exe Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis U Delay or Delayrun delayrun.exe On HP PCs this program is used to help prevent conflicts or timing issues on fast computers X Delete Me worm.exe Added as the result of the DOOMHUNTER VIRUS! N Dell Alert DAMon.exe """Dell Alert"" utility, that's supposed to make interaction with Support easier" N Dell QuickSet quickset.exe ell taskbar icon allowing you to quickly change settings U DELLMMKB or DellTouch DELLMMKB.EXE Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys N DellSC dellsc.exe Dell Solution Center - web-based troubleshooting tools and educational offerings U DellSupport DSAgnt.exe Dell Support Agent offers additional support and update features for your Dell computer or laptop. U DellTouch MMKeybd.exe Dell multimedia keyboard manager. Required if you use the additional keys X delmsbb delmsbb.exe nCase adware X delsaap delsaap.exe nCase adware X delsubmit ?? CoolWebSearch parasite related N DeltTray deltray.exe "System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel" X Deneca Virus salvado W97M.DELUZ VIRUS! U DepFrez frzstate.exe "Deep Freeze from Hyper Technologies. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example" X Desire desires.exe Adult content dialler X DeskAd Service DeskAdServ.exe DeskAd.Service adware N DeskColor DESKCOLOR.EXE Provides transparent icon text backgrounds and coloured icon text N Deskflag Deskflag.exe DeskFlag - animated USA flag on the desktop N DeskMateAutoUpdate DeskMateAutoUpdate.exe DeskMates: Virtual scantily clad girls enhance your desktop - according to PestPatrol BargainBuddy adware related X DeskMateAutoUpdate DeskMateAutoUpdate.exe DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related U Desksite CMA cma.exe "DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center""" X Desktop ?? BOOKMARKER VIRUS! X desktop desktop.exe SDBOT.MD WORM! X desktop desktop.exe W32.Kobot.L WORM! N Desktop Architect DATRAY.EXE "Desktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc" N Desktop Plant AZARE10S.PLT "Vritual plant from here - this version is an Azalea, there are others so the filename may be different" X Desktop Search desktop.exe "iSearch ""Desktop Search"" hijacker" N Desktop Weather THE WEATHER CHANNEL.exe "Desktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc" N Desktop Weather 3 THE WEATHER CHANNEL.exe or THEWEA~1.EXE "Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc" N desktopmgr desktopmgr.exe "Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the ""Blackberry""" X DesktopUpdate ?? MatrixDialer related U DesktopX DESKTOPX.EXE "A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking" N deskup deskup.exe Adds Iomega Zip drive icons to the desktop X destroyb11 destroyb11.exe Troj/Delf-KO TROJAN! U detect idetect.exe "iNTERNET Turbo from Clasys Ltd. ""It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds"". If you find it helps your connectivity leave it enabled" N Detector detector.exe "USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software" U DEventAgent eventagt.exe DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this X Device Configuration Loader msdvc32.exe variant of the GAOBOT/AGOBOT WORM! U Device Detector DevDetect.exe Watches for external digital imaging products being connected from ACD Systems N Device Detector 2 DevDtct2.exe "Installed by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a ""high"" priority level which can negatively impact system resources" U DeviceDiscovery hpotdd01.exe "Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products" X DevicePath ?? GRUEL VIRUS! U Devices olesvr.exe Salfeld Child Control 2003 - parental control software U devldr16.exe devldr16.exe "Associated with some Creative Labs sound cards.? Provides audio support for DOS applications.? Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices" X dgtstart dgtstart.exe DigitalNames.g adware N dguard dguard.exe eAcceleration Stop-Sign related; not recommended; see note X DHCP Server regsvr.exe W32/RBOT-PR WORM! Y dhcpagnt dhcpagnt.exe Intel DSL modem driver - leave enabled or you'll have to re-install the drivers N diagent diagent.exe System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs X Diagnostic diagnostic.exe Troj/Alpha-C TROJAN! X Dial22 or Dial33 dlm.exe Adult content dialler X Dialer ?? Unidentfied malware U Dialer Control dc.exe Dialer-Control . Detects and protects from premium rate p0rn dialers U Dialer Detect dd.exe "DialerDetect detects stealth installed premium rate dialers, and sounds the alarm when such a connection is being installed without you knowing it." U Dialgo SDK PhoneAnswer.exe "Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis""" X DialNet mxt32.exe Adult content dialler N Dialog Box Assistant OSDEx.exe Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders N Dialog Helper PDDLGHLP.EXE Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs X DialUp Network Application Rnaap.exe variant of the W32/SDBOT WORM! X DIECOX csrss.exe BackDoor-ATM.gen trojan variant X Diesel Recalculate.exe /reloadenterpice Lazar TROJAN! U DietK DietK.exe "DietK - add-on for Kazaa Media Desktop; ""removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results.""" X DigiD DigitalSound.exe Adware downloader N DigiGuide CLIENT.EXEclient01.exe TV guide and reminder N Digital Dashboard CPQMLDET.exe For Compaq PC's. Loads Digital Dashboard options N Digital Dashboard devgulp.exe For Compaq PC's. Loads Digital Dashboard options N Digital Line Detect DLG.exe Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems N Digital River eBot downlo~1.exe "Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here" X DigitalNames DigitalNamesStart.exe DigitalNames spyware variant N DigitalWizard ISWizard.exe "InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content" N DigitalWizard Monitor dwMon.exe "InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content" N DIGStream digstream.exe DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically U Dimension Dimension.exe "Dimension, a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol." U Dimension4 d4.exe "Atomic clock synchronisation freeware - starts-up, adjusts the system clock, then shuts down" X Dino3 dino3.exe Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result X Dinst dinst.exe GrandStreet parasite variant - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Intexp.d X Dir1 caKe CAKE VIRUS! X Direct settings sdchost.exe TROJ/DAEMONI-I TROJAN! U Direct Update DUControl.exe DirectUpdate dynamic DNS updater X Direct X Direct3D dxd3d.exe variant of the W32/SDBOT WORM! X Direct X Opengl dxopengl.exe variant of the W32/RBOT-CJ WORM! X direct3d.exe direct3d.exe TROJ/CERTIF-F TROJAN! N DirectCD DirectCD.exe DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later X directs.exe directs.exe BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS! U DIRECTVDSL Directvdsl.exe Starts DirectTV DSL modem at boot up. Can also be started manually X directx ?? SDBOT.D WORM! X DirectX ddhelp32.exe BIONET.318 VIRUS! Note - not the DirectX helper which is ddhelp.exe X DirectX DirectX.exe BLAXE or LOGPOLE VIRUSES! X DirectX directx32.exe AGOBOT.CG WORM! X DirectX 32 directx32.exe variant of the AGOBOT/GAOBOT WORM! X DirectX for Microsoft Windows dtxservice.exe PROGENT TROJAN! X DirectX for Microsoft Windows Fservice.exe PRORAT TROJAN! X DirectX for Microsoft Windows Sservice.exe PRORAT TROJAN! X DirectX For Microsoft˝ Windows fservice.exe Troj/Prorat-P TROJAN! X DirectX shell driver ?? Troj/MarktMan-B TROJAN! X DirectX Video Driver dxterm5.exe W32/WILAB-A TROJAN! X DirectX64 DirectXset.exe BROWNEY.A VIRUS! X DirectX9 Diag dx9diag.exe W32/RBOT-ALT WORM! U Dirkey Dirkey.exe Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl Alt 1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl 1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders? N Disc Detector CtNotify.exe "For Creative sound cards. Detects when you insert a CD, DVD, etc" N DiscoverDeskshop Deskshop.exe "Discover Deskshop - single use ""virtual"" credit card" X Disk Keeper keep.exe Mslware - recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.ve X Disk Keeper SECURITY.EXE WEBSEARCH TROJAN - a variant of Daoser-A X Disk Manager diskver.exe RBOT.AQT WORM! X Disk Master ?? DISTER VIRUS! - a spam relayer U Disk_Monitor Disk_Monitor.exe "Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader" X DiskCheck msdarkend.exe unidentified WORM or TROJAN! N DiskeeperSystray DkIcon.exe DisKeeper defragmentation software - can be started manually. X diskinf diskinf.exe CRYPTER.A trojan infection N Disknag disknag.exe Dell program that reminds you to make your? backup diskettes X Diskstart cat.exe MS-Connect dialler X Diskstart Code.exehit.exeSnt.exe Adult content dialler U display The_Eye.exe ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself. X Display Drivers cssrs.exe AGOBOT.FX WORM! N Display Settings hptasks.exe "Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers." N DisplayTrayIcon TrayIcon.exe "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display" U Disspy disspy.exe Disspy spyware detection and removal software N Distiller Assistant 3.01 DISTASST.EXE From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs X Distributed File System blade.exe W32.MYFIP.AC WORM! X Distributed File System Dfsvc.exe MYFIP.A or MYFIP.K WORMS! X Distributed File System kernel32dll.exe W32.MYFIP-C or W32.MYFIP.K or W32.Myfip.T WORMS! X Distributed File System win.exe W32.MYFIP.AB WORM! U distributed.net client DNETC.EXE Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses Y Dit dit.exe """Drive Icon and Label Utility"" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found" N DiTask.exe DiTask.exe "Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs" X divx divxenc.exe Added to the Spbot.B TROJAN! X DivX MediaPlayer 7.0 Dr.DivX.exe ALADINZ.G VIRUS! X DivX Player DivXPlayer.exe variant of the WIN32.RBOT WORM! X DivX Updater DivX.Exe NALDEM or MASTAK VIRUSES! X Divx4 codec devldr32.exe unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file N DJREGFIX ?? "DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers" Y DkService DkService.exe From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. Used to schedule defragmenting on a regular basis and not required if you do so manually. X DKTime dktime.exe Downloader.Lunii trojan infection X Dkware lptt01 or Dkware ml097e dkware.exe "Variant of the RapidBlaster parasite (in a ""DonkeySoft"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" Y dla tfswctrl.exe "Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones""" N DlaTray Dlatray.exe "System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones""" X dlder dlder.exe "Advertising spyware. Considered to be one oft the worst - even creating a fake ""explorer.exe"" file. Can be installed via versions of ""Grokster"", ""Lime Wire"" and ""KaZaA"" amongst other file-sharing utilities (see here). Reported in the past as a virus" X DlDir1 caKe CAKE VIRUS! N DLF_00000B00 Vcdlf.exe "Known to cause problems with ""Out of memory"" errors (see here). Otherwise, it's purpose is unknown" N DLG DLGCHBW.exe Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates N DLHelperEXE WATCH.exe Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished X DLHelperEXE.exe ?? Downloader for Microgaming/Casino software - stealth installed X dlhost dlhost.exe Troj/ExpHook-A TROJAN! Y D-Link Air USB Utility AirCFG.exe D-Link wireless PCI adapter related Y D-Link Air Utility AirCFG.exe D-Link wireless PCI adapter related N D-Link AirPlus DWL-650+ Utility WLANMON.exe D-Link Air Plus Wireless PC modem connection monitor Y D-Link AirPlus G AirGCFG.exe D-Link Airplus Wireless Router driver X Dlite dllmanager.exe WOOTBOT.DN WORM! X Dll Boot Loader on Startup (do not remove this) ?? unidentified TROJAN! X DLL Manager dllmngr32.exe variant of the WIN32.RBOT WORM! X DLL Service Manager ?? RPCBOT.F VIRUS! X DLL32 dllmem32.exe KWBOT.E VIRUS! X DllCacherv2 dllcachev2.exe BACKDOOR.LATEDA TROJAN! X dlldmt dlldmt.exe CRYPTER.C trojan variant infection X DllExecutable ?? W32/VB-SP WORM! X dllhelp dllhelp.exe W32/Startpage.DQ hijacker infection X dllhelp dllhlp.exe Downloader-HI TROJAN! X dllhostxp.exe dllhostxp.exe browser hijacker and adware downloader X DllLoader lssas.exe TROJ/BDOOR-JE WORM! X Dlload killer.exe Troj/KillAV-FK TROJAN! X dllreg dllreg.exe CRYPTER.A trojan infection X DLLService32 dllsvc32.exe AGOBOT.VX WORM! X dluca dluca.exe Adult content dialler - see here X dluca dluca.exe DLUCA.C VIRUS! X dluxde dluxde.exe All-In-One-Telcom (adult content dialler) variant X Dluxjp cnfrm.exe DLUCA.D VIRUS! X DM mgr dm_mgr.exe JITTAR VIRUS! X DM_server dmserver.exe Comet Cursor adware X dm_service ?? MITGLIEDER.P TROJAN! N DMILDR dmildr.exe "Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs?" N DMISL DMISL.EXE DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information N DMISLAPP DMISLAPP.exe DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information X Dmsvc32 Dmsvc32.exe AGOBOT.ABU WORM! X dmtdll dmtdll.exe Crypter.C trojan variant infection U DMXLauncher DMXLauncher.exe "Part of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files." X Dnar Dnar.exe "Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here" Y DNE Binding Watchdog "rundll dnes.dll, DnDneCheckBindings" Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work Y DNE DUN Watchdog "rundll dnes.dll, DnDneCheckDUN13" Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work X DNS mc-110-12-0000079.exe TrojanDownloader.Agent.rv TROJAN! X DNS mc-58-12-0000080.exe """Shorty"" adware component, also detected as the AGENT.FD TROJAN!" X DNS mc-58-12-0000093.exe Nail/Aurora related malware X DNS mc-58-12-0000120.exe """Shorty"" adware component, also detected as the AGENT.FD TROJAN!" X DNS mc-58-12-0000140.exe """Shorty"" adware component, also detected as the AGENT.FD TROJAN!" X Dns Resolver dnsrslve.exe W32/RBOT-WS WORM! X DNS Service dnsresolver.exe W32/RBOT-PQ WORM! X DNSCacheBoost dnsping.exe TROJ/DNSBUST-A TROJAN! X dnscleaner dnscleaner.exe CoolWebSearch parasite related X DocTor Doctor.exe DOTOR VIRUS! N DocuMagix Init PWATCH.EXE "PaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed" X Doggy Style MsPMSPSd.exe W32/Sdbot-AAP WORM! X DOGStart GSDOGST.EXE unidentified VIRUS! A possibility is a trojan known as PENIS X doit.exe doit.exe W32/FORBOT-EK WORM! U Don't Panic dontpanicdemodp.exe "30-day trial version of Don't Panic privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite.""" U Don't Panic Pop-Up Stopper dpps2.exe Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group X dos dos64.exe adware downloader trojan X Dos Prompt Loader cygwin.exe W32/SDBOT-VV WORM! X Dot.net Networking Snss32.exe variant of the IRC_TROJAN ! N DoUWantIt duwi.exe DoUWantIt - online shopping assistant. Start it manually X down hlp32.exe TROJ_DLOADER.BG TROJAN! N Download Accelerator Plus 5.0 DAP.exe "Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is ""adware"" based" X Download Plus DownloadPlus.exe DownloadPlus parasite - opens pop-up adverts N Download Wonder DownloadWonder.exe "Download Wonder from Forty Software. Download manager for resuming downloads, amongst other features" N DownloadAccelerator DAP.EXE "Download_Accelerator_Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based" X DownloadLegalMusic ?? MatrixDialer related X DownloadWare dw.exe "DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent" X DownloadWare Engine Dwe.exe "DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent" X Downxz Downxz.bat W32.Mydoom.W WORM! N DPAgnt DPAgnt.exe digitalPersona fingerprint scanner Y Dpcnav dpcnav.exe DirecWay from DirectTV satellite based high-speed internet access N DPConfig DPConfig.exe "Compuware DevPartner Studio Configuration Utility, a tool for software developers - system tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when needed." X dpcproxy dpcproxy.exe Troj/GoldenP-A trojan infection Y DPCProxyLoadOnStartup dpcstart.exe DirecWay from DirectTV satellite based high-speed internet access U Dpcstart dpcstart.exe "Startup program for Direcway 2-way satellite internet service. Loads DirecWay\'s Navigator, tray icon, etc" Y Dpcstart dpcstart.exe DirecWay from DirectTV satellite based high-speed internet access. Proxy software X dpi dpi.exe "Delfin_Media_Viewer or ""Promulgate"" adware" U dpps2 dpps2.exe Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group X dps dps.exe "SmartestSearch parasite -poses as a foistware, bogus adware/spyware remover called ""scumware-remover""" X DR_S DR_S.exe AdShooter adware N DragnDrop_Autolaunch Autolaunch.exe Iomega_HotBurn - CD-RW burning software N Drag'n'Drop_Autolaunch Autolaunch.exe Iomega HotBurn - CD-RW burning software X DrefIW SysDref.exe W32/Dref-D WORM! X DrefIW SysDrefIWv2.exe W32/DREF-C WORM! N DrgToDsc DrgToDsc.exe "Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly" N DriveLED OODLed.exe O&O DriveLED - displays your HDD LED on your monitor. Start manually X Driver gbot.exe JUNTADOR.K VIRUS! X Driver32 Scam32.exe SIRCAM VIRUS! X DriverCheck svchost.exe "TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X DriverDB svcmdx32.exe BACKDOOR.BERPI TROJAN! X DriverLoad svchost.exe "TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" N DriveSelect driveselect.exe DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs U dRMON SmartAgent SmartAgt.exe Part of the network monitoring program group for 3Com NIC cards. See here for more info X drmu W95Mm.exe Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread X drocher d.exe Premium rate adult content dialer X Drvddll_exe drvddll.exe BEAGLE.X WORM! U drvlsnr drvlsnr.exe Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly X drvr32h drvr32h.exe unidentified VIRUS! X drvrmanager drvrquery32.exe BOOHOO VIRUS! X drvsys.exe drvsys.exe BEAGLE.W WORM! X drvupd ?? "Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack" X DrWatson drwatson_.exe TROJ/LOHAV-S TROJAN! X DrWatson drwatson_32.exe TROJ/LOHAV-S TROJAN! X DrWeb Antivirus DRWEBAV.EXE unidentified WORM or TROJAN! Y Drwebscheduler Drwebscd.exe "Dr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem" U DS Clock dsclock.exe Digital desktop clock including synchronization with atomic servers - see here X dsa dsa.exe Homepage hijacker - redirecting to downseek.com X DSAcass ?? RANKY.M backdoor TROJAN! X DSB DSB.exe EnergyPlugin adware N DSentry DSentry.exe "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts" X Dsi ?? unidentified adware where ****** are random characters X Dskcompat Dskcompat.exe GEMA TROJAN! N DSL Monitor spdstrm.exe Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray U DSLagentexe DSLagent.exe Enables the Media Center software on a Media Center PC to be lauched via the button on the remote. Required if you prefer not to double-click the desktop icon first Y dslmon dslmon.exe Sagem DSL modem related. Apparently needed to detect the modem. U DSLSTATEXE dslstat.exe System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example) X DsmSer dsm.exe W32.Serflog.B WORM X DsmSer msmpatch.exe W32.Serflog.B WORM X DsmSer svosm.exe W32.Serflog.B WORM X DsmSer sysup.exe W32.Serflog.B WORM X DSS ?? Troj/DSSDoor-C TROJAN! X DSS dssagent.exe DSSAgent by Br?derbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info X DSService dmrss.exe W32/AGOBOT-XX WORM! N DU Meter DUMETER.EXE Hagel Technologies internet bandwidth monitor X duck duck.exe W32/Agobot-AVG Worm! N dumprep 0 -kordumprep 0 -u dumprep 0 -kdumprep 0 -u "Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out" X DUN_SERVICES3 dun3.exe Trojan.Sokiron TROJAN! X Duweculey yujixit.exe SDBOT.BRP WORM! U DVD43 DVD43.exe DVD43 is a small tool that overrides CSS copy-protection found on DVD movies. N dvd43 DVD43_Tray.exe "DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies.""" X dvd98 windvd98.exe CULT.P VIRUS! U DVDBitSet DVDBitSet.exe DVD RW Drive/Disc Compatibility Setting. Installed with HP DVD RW drives to enhance compatibility with existing readers. You can also set a DVD RW default drive write mode which is always used X Dvdcompat Dvdcompat.exe GEMA TROJAN! U DVDLauncher DVDLauncher.exe A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use N DVDSentry DSentry.exe "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts" Y Dvp95 Dvp95.exe Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine Y dvpapi9x DVPAPI9X.exe Command AntiVirus for Windows 95/98/Me Y DvpInitExe Dvpinit.exe Command Antivirus related Y dvprpt Dvprpt.exe Command Antivirus real time protection X dvraudio dvraudio.exe Crypter.C trojan variant infection X dvsfss fbsfsdrs.exe W32/Sdbot-QA worm infection U DVSync dvsync.exe DVSync is the program that allows you to synchronize your daVinci?s PDA's data with your Personal Information Manager on the PC X Dvx wsxsvc.exe "Delfin_Media_Viewer or ""Promulgate"" adware variant" X dw dw.exe "DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent" U DW4 Weather.exe Desktop_Weather U DWHeartbeatMonitor DWHeartbeatMonitor.exe DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference N DwlClient support.exe Download manager for Dell support alerts Y dwStart FireWall.exe The_Shield Firewall X Dx sys#.exe DEXTER.A VIRUS! where # is a random number X Dx8compat Dx8compat.exe GEMA TROJAN! X dxdiags.exe dxdiags.exe Troj/Certif-G TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X dxdll32 ntxdll.exe W32.Gaobot.CPX WORM! N DXDllRegExe dxdllreg.exe "Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it" X DxLoad DX3DRndr.exe GIBE.B VIRUS! N DXM6Patch_981116 p_981116.exe Win32 cabinet self extractor. More info here X dxmsrv dxmsrv.exe unidentified WORM or TROJAN! X Dxsty Dxsty.exe GEMA TROJAN! X Dxupdate.exe Dxupdate.exe MAFEG VIRUS! X DyFuCA optimize.exe Adult content dialler - see here X DyFuCA Active Alert actalert.exe Adult content dialler - see here X Dynamic Dns Binary CMD16.EXE W32/RBOT-XM WORM! X Dynamic Dns Binary dynitora.exe W32/RBOT-WT WORM! X Dynamic Dns Binary WinHelpcfn.exe variant of the WIN32.RBOT WORM! X Dynamic Dns Binary winxp34.exe variant of the WIN32.RBOT WORM! X Dynamic Link Library loader Loader32.exe BACKDOOR.KOL TROJAN! U DynDNS Updater DynDNS.exe "Dynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org." N DynDNS-Updater Traytool ddutray.exe DynDNS updater tray icon; allows easy configuration of the Dynamic DNSSM service.; can be run manually X DynHttp Dns Binary dynizari.exe variant of the WIN32.RBOT WORM! U DynSite DynSite.exe "DynSite is a dynamic DNS client, also called an automatic IP updater." U Dynu Basic Client dynubas.exe Dynu online dynamic IP update client. Useful when using a dial up modem. U E_S10IC2 E_S10IC2.exe "Epson Stylus printer monitor - for checking ink levels, etc." U E_S23 E_SICN03.exe "Epson printer status monitor - for checking ink levels, etc." U E_SOEIC1 E_SOEIC1.exe "Epson Stylus printer monitor - for checking ink levels, etc." N E6TaskPanel TaskPanl.exe "Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space" U eabconfg.cpl EabServr.exe Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys X Eac Download download.exe Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here X Eac_Cnry canary.exe CANARY VIRUS! U EACLEAN eaclean.exe For Compaq PC's. Easy Access button support for the keyboard N eanth_critical_update_alert sys_alert.exe eAcceleration Stop-Sign related; not recommended; see note N eanth_system_patcher sys_alert.exe eAcceleration Stop-Sign related; not recommended; see note N eanthology_install.exe eanthology_install.exe eAcceleration Stop-Sign related; not recommended - see note N EanthologyApp EANTHO~1.EXE eAcceleration Stop-Sign related; not recommended; see note N EanthologyApp eanthology.exe eAcceleration Stop-Sign related; not recommended; see note N Eapcisetup sbsetup.exe Rockwell RipTide soundcard application software. Sound works without it N EAPCISETUP wizard.exe Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation N EarthLink ToolBar 5.0 etoolbar.exe "EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time" N Easy Start Button esb.exe Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys X EasyAV EasyAV.exe W32.NETSKY.S or W32.NETSKY.T WORM! X EasyDates EasyDates.exe Premium rate adult content dialer X EasyDates_nl EasyDates_nl.exe Adult content dialler U EasyKey or Easy Key easykey.exe For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used U EasyKeyboardLogger epl.exe EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! U EasyMessage em2.exe "Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here" U Easy-PrintToolBox BJPSMAIN.EXE A utility to launch the applications that are bundled with a Canon bubblejet printer X EasySearchBar ESBUpdate.exe EasySearchBar adware downloader X easyServ Server.exe EASYSERV VIRUS! U EasySync Pro XCPCMenu.exe EasySync Pro is a Lotus program for synchronizing a PDA with Lotus Notes U EasyTuneIII EasyTune.exe Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available U EasyTuneIV ET4Tray.exe Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available X easywww ?? EasyWWW adware X EbatesMoeMoneyMaker ?? Ebates adware X EbatesMoeMoneyMaker0 EbatesMoeMoneyMaker0.exe Ebates adware X eBay Toolbar EBAYTBAR.EXE "eBay Toolbar - reportes as spyware as it ""phones home""" U eBayToolbar eBayTBDaemon.exe eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites. U eBoard or eMachines eBoard Eboard.exe eMachines multimedia keyboard manager. Required if you use the extra keys N eBot DownloadWizard.exe "eBot from Digital River - ""helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'."" Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs" X E-Card ecard.exe YODI VIRUS! U E-color IconMgr.Exe Sets the colour of your monitor when running games that recognise E-Color so that you get \'what the game designer intended\' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program U eCopy Desktop Printer Service mrmlnc32.exe "eCopy Suite software connects your Canon imageRUNNER or document scanner to your company?s e-mail and other networked enterprise applications for easy, instantaneous distribution and management of scanned documents." N edexter edexter.exe eDexter supplements Internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser. X editpad editpad.exe CoolWebSearch parasite related X editpad editpad.exe Consper-B trojan infection N EDLoader DTLoader.exe Effective Desktop from MiniStars Software - desktop management software no longer being supported U EDRestore ?? "Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP""" X educational writer ?? W32/Rbot-LZ worm infection U Edwizard Edwizard.exe "SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks""" U eFax DllCmd J2GDllCmd.exe eFax_Messenger fax software U eFax Tray Menu J2GTray.exe eFax_Messenger fax software tray menu N eFax.com Tray Menu HotTray.exe eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here X efaxs lptt01 or efaxs ml097e efaxs.exe "Variant of the RapidBlaster parasite (in an ""efaxs"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" U EFI Job Monitor "efjm.dll,run" Ricoh Imagio Printer/Scanner driver status monitor U Efpap.exe Efpap.exe "Easy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching" U ehTray ehtray.exe Windows XP Media_Center_Edition 2005. Enables the user to access Windows Messenger from within Media Center X ei10.exe ei10.exe AGOBOT-NK WORM! U Eicon NetworksLAN_DAEMON or Eicon TechnologyL watch.exe Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually X eixfi china.bat WCUP VIRUS! X ekor.exe igamatu BACKDOOR.SDBOT.AQ TROJAN! U Elbycheck ElbyCheck.exe From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it U Electron Microscope EMIII.exe "Electron Microscope, or EM , is a program used to track Stanford?s distributed computing program client called Folding at Home, FAH It will monitor up to 50 clients and give you the details about each client?s progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues." X Element Element.txt ELEM TROJAN! X element furth ?? variant of the RANDON.AN WORM! N elm Elmenv.exe "ViaTech eLicense for securing, distributing and selling music online" X ELNKProxy smproxy.exe Surfmonkey adware U ELSA WINman Suite Winmsuit.exe "Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU" Y ElsaCapiCtl Rcapi.exe "Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem" U ELSAChipGuard elsavect.exe "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking" U ELSBLaunch ELSBLaunch.exe EarthLink SpamBlocker U EM_EXEC EM_EXEC.EXE "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled" N EMA.exe EMA.EXE Time management system which helps you to manage your time and appointments N eMailEncryption velozsys.exe eAcceleration Stop-Sign related; not recommended; see note X eMakeSV EMAKESV.EXE Switch premium rate adult content dialer variant X emoc0re emo.exe W32/AGOBOT-AGE WORM! X empin e121307.exe "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X empin e121307.Stub.exe "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X emsw.exe emsw.exe "Believed to be spyware - made by a company called Alset. Also known as ""HelpExpress"". Will install itself if you have previously had Attune by Aveo installed as they're by the same company. Uninstall via Add/Remove programs" X emule emule.exe W32/Rbot-ALZ WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N eMusicClient Systray eMusicClient.exe eMusic MP3 download software N EN4060C Taskbar en4060ct.exe Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray X enBrowser ?? WINBO adware component N Encarta Dictionary Quickshelf QSHLFED.EXE Provides quick access to Encarta's Dictionary features? N ENCMONITOR monitor.exe The Encompass Monitor. This program is the Connect Direct Program.? It is more trouble than it is worth and few use it N Encoder Agent WMENCAGT.EXE "MS Windows Media Encoder, which?already has a shortcut in?the Start Menu if installed" U Encompass_ENCMONTR ENCMONTR.EXE Optional simple browser from Yahoo (Encompass) U Energizer FileSaver Energizer FileSaver.exe Energizer FileSaver - UPS back-up utility for Energizer UPS products X EnergyPlugIn EnergyPlugin.exe EnergyPlugin adware variant U enginecs2 enginecs2.exe Cyber_Sentinel Internet filtering software Y EngUtil EngUtil.exe "Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking" X Enh Win Updt enhupdt.exe Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h X enhance32 enhance32.exe CRYPTER.A trojan infection N EnigmaPopupStop EnigmaPopupStop.exe "Part of Enigma SpyHunter - not recommended, see note" U EnsoniqMixer starter.exe "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility" X Enumerate Service wsys.exe MANIFEST VIRUS! Y EnvyHFCPL EnMixCPL.exe VIA Envy24 PCI Audio Controller driver U eonemng eOneMng.exe "eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC" N EPoXUSDM USDM.EXE "EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc" N ePrint 4.0 Service EPRINT4.EXE "A component of the LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more! - Can be started manually." U ePrompter ePrompter.exe ePrompter - E-mail notification software N EPS e_srcv02.exe "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check" N EPS e_srcv03.exe "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check" N EPSON Background Monitor STMS.EXE Supposed to keep an Epson printer ready for quick printing.? Users report little difference whether it is on or not U EPSON CardMonitor EPSON CardMonitor1.0.exe Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint N EPSON Status Monitor 3 Environment Check e_srcv02.exe "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check" N EPSON Status Monitor 3 Environment Check e_srcv03.exe "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check" U EPSON Stylus C44 Series E_S10IC2.EXE "Epson Stylus C44 Series printer monitor - for checking ink levels, etc." U EPSON Stylus C46 Series E_S4I0T1.EXE "Epson Stylus C46 Series printer monitor - for checking ink levels, etc." U Epson Stylus C62 Series E-S0BIC1.EXE Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required U Epson Stylus C82 Series e_s0hic1.EXE Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required U EPSON Stylus Photo R300 Series E_S4I2F1.EXE Epson Status Monitor - gets installed with many Epson printers and gives you a progress of your print jobs as they are printing. U EpsonPhotoStarter EPSON_PhotoStarter.exe Only needed if you want to make full use of the capabilities of an Epson printer that included this? U Eraser eraser.exe -hide Eraser allows for complete removal of data from your hard drive U eRecoveryService check.exe "Acer Notebook related - Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity." N EReg reg32.exe "EReg is a software registration tool incorporated on products such as those by Br?derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it" X erghgjhgdr windlhhl.exe W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM! N Eror Nuker ErrorNuker.exe ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required. X eros.exe eros.exe Adult content dailler X ErrorGuard ErrorGuard.exe Spyware remover of dubious repute - see here X erthegdr windll2.exe W32.Beagle.CG WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X erthgdr svc.exe W32.Beagle.BK WORM! X erthgdr svc.exe W32.BEAGLE.BN or W32.Beagle.BP WORM! X erthgdr windll.exe BAGLE.BD WORM! X erthgdr2 svc23.exe BAGLE.CG WORM! U ERUNT AutoBackup AUTOBACK.EXE "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored if desired." Y eSafe Protect ESPWatch.exe eSafe from Aladdin - internet security for gateway and E-mail servers U ESB esb.exe Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys Y eScan Monitor AVKWCTL9X.EXE eScan antivirus U eScan Scheduler avkserv.exe eScan antivirus scheduler U eScan Updater Trayicos.exe eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads X EScorcher escorcher.exe Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead N ESFTP esftp.exe ESftp - FTP client for transfering files between a local PC and another remote computer X Esoh Esoh123.exe AGOBOT.FF WORM! X Especial Deneca.bat W97M.DELUZ VIRUS! N ESPN BottomLine bline.exe "ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down.""" Y Essdc essdc.exe Related to an ESS Solo soundcard. Seems as though it's required Y ESSOLO ESSOLO.exe Sound card driver that re-instates itself every time it's removed Y esspk esspk.exe ESS Technology modem speaker driver file. Required to get on-line with this modem U EssSpkPhone essspk.exe "ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets" X ETB Tester etbtest.exe W32/RBOT-ABR WORM! X etbrun ?? EliteBar adware variant X ethernet airftp.exe variant of the W32/SDBOT WORM! X ethernet msftp.exe SDBOT.BXJ WORM! X ethernet msnger.exe variant of the W32/SDBOT WORM! N Ethernet tcaudiag.exe 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs X Ethernet Drivers ethernet.exe W32.GAOBOT.CEZ WORM! X Ethernet Drivers smrrs.exe W32/RBOT-AAK WORM! X Etraffic JavaRun.exe Marketing software from TopMoxie Y eTrust EZ Firewall efpeadm.exe eTrust EZ Firewall U eTrust PestPatrol Active Protection PPActiveDetection.exe "PestPatrol real-time protection feature. ""Stops spyware before it infects your system""" Y eTrustCIPE ezdsmain.exe eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior X eTunnel winfw.exe unidentified TROJAN! U EuroGlot EuroGlot.exe "Euroglot - ""multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian""" N Event Planner Reminders PLNRnote.exe Sierra Event Planner tray icon N Event Reminder pmremind.exe A calendar/alarm program that installs with Br?derbund Printmaster U EVENTLISTENER EvLstnr.exe Used with a Nikon digital camera to recognize when the camera is plugged in N eventmgr eventmgr.exe Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs U Evidence Cleaner ecleaner.exe Evidence_Cleaner cleans up tracks left by your PC and Internet activities N Evidence Eliminator ee.exe Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis X Evil Evil.exe W32.Mytob.JM WORM! Note: This worm file may be found in the Windows or Winnt folder. N evntsvc evntsc.exe "Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it" U EVOLOSTA EVOLOSTA.EXE "Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it" X EvtHtm evthtm.exe Premium rate adult material dialer U EW Message Server msg32.exe Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices N eWare Startup iWareStart.exe eWare iWare task bar. Not required X ewupdater ewupdater.exe EasyWebSearch adware updater N Excite Platform Exlaunch.exe Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer N ExciteAssistantEXE ASSISTANT.EXE "With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open" X exe lptt01 or exe ml097e exe.exe "Variant of the RapidBlaster parasite (in an ""Exe"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X execfg4 execfg4.exe ELECTRON VIRUS! X ExeName32 Warm.scr SCOLD VIRUS! U Exif Launcher Exiflaquickdcr.exe USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly U Exif Launcher QuickDCF.exe USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly U ExitKiller Ekiller.exe Exit Killer - automatically closes pop-up windows in your browser X exp.exe exp.exe variant of the SMALL.ABD downloader TROJAN! X EXPL0RE.EXE EXPL0RE.EXE Troj/Popno-A TROJAN! Note: Notice that (EXPL0RE.EXE) is spelled using the number 0 instead of the letter O. This trojan is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X expler Updadv.exe Troj/QQPass-N TROJAN! X Explkw expup.exe Keywords hijacker X explore explore.exe W32.Hawawi WORM! X Explore explore.exe Adult content dialler X Explore Explorer.exe "IRC.FLOOD.G VIRUS! Note - this is not the valid Windows ""explorer.exe""" X explore manager explore.exe DONBOMB.A TROJAN! X explore.exe Explore.exe GRAYBIRD.G VIRUS! X Explorer ?? AUTEX VIRUS! X Explorer config_.com W32/Floppy-D WORM! X Explorer drv.exe Troj/Small-FD TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X EXPLORER EXPL0RER.EXE Troj/BeastDo-Y TROJAN! X explorer expl32.exe RATSOU VIRUS! U explorer explorer.exe Starts Windows Explorer. Unless this has been manually added to startups or another program it could be a WORM! such as PE_BISTRO or DVLDR or MYDOOM.B or Troj/Torpig-A . Note that it is also not the explorer.exe task/service you'll see when via CTRL ALT DEL X explorer explorer.exe "PWS.ZAYA TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is installed in a C:\Windows\System\Service folder. Moreover, the valid explorer.exe will only figure among the startups if you intentionally placed it there!" X Explorer shellexp.exe variant of the Backdoor.Sheldor TROJAN! X Explorer shellexpl.exe GPIX and SHELDOR VIRUSES! X EXPLORER sys.exe TROJ/SILLYFDC-A TROJAN! X explorer wscript.exe Sneaky way to start any VBS script. Many viruses use VBS files X Explorer Loader explr32.exe AGOBOT.N WORM! X Explorer lptt01 or Explorer ml097e explorer.exe "Variant of the RapidBlaster parasite (in an ""explorer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Explorer which has the same executable name" X EXPLORER MICROSOFT SYSTEM explore.exe variant of the WIN32.RBOT WORM! X Explorer Updater IEXPLORE.exe W32/Sdbot-WO worm infection X Explorer32 efsdfgxg.exe TROJ/CLICKER-Y TROJAN! X Explorer32 Expl32.exe HACKTACK VIRUS! X Explorer32 explorer6s4.exe Downloader.Win32.Small.biq TROJAN! X exporet winset.exe TROJ/QQPASS-I TROJAN! U Exshow95 EXSHOW95.exe Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices X External Dependencies External.exe W32.Mytob.EC WORM! U ExtraDNS ExtraDNS.exe ExtraDNS - DNS configuration tool N Eye Tide Launcher oneeyetideone.exe Nascar wallpaper Y EZ Firewall ca.exe eTrust EZ_Armor Internet Security N ezagent ezagent.exe EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs N EzButton EzButton.EXE EZbutton is a quick launcher for the Media player app that comes with certain laptops. Typically installed in a C:\Program Files\EzButton folder N EZDesk EZDESK.EXE Utility that remembers icon locations for each user and resolution. Available here N EzEjMnAp EzEjMnAp.exe "For IBM Thinkpad Notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually"". Available via Start -> Programs" X eZmmod mmod.exe eZula TopText adware Y ezShieldProtector for PxorezPS_Px ezSP_Px.exe Engine that allows PrimoDVD from Veritas (was Prassi) and Drag\'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings Y ezShieldProtector for PxorezPS_Px ezSP_PxEngine.exe Engine that allows PrimoDVD from Veritas (was Prassi) and Drag\'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings U EZSMART App ezsmart.exe EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported X ezula eZmmod.exe eZula TopText adware X eZulaMain eZulaMain.exe eZula TopText adware X eZuluMain eZuluMain.exe "Comes with ""KaZaA"" installation. Advertising Spyware. Not required but KaZaA won't work" X eZWO wo.exe eZula TopText adware X f~a ra32.exe BackDoor-CAY TROJAN! U f1Tray.exe F1TRAY.EXE System Tray icon for FusionOne?s MightyPhone software. MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer. X f607 f607.exe URAT.B VIRUS! X f73cdc8ee94e btsendto.exe Associated with mysearchnow.com/searchbar.html U FamilyKeyLogger cisvc.exe """Family Keylogger - is your best choice, if you want to know what other users on your machine are typing"". Note! - this is not the cisvc.exe service." X Fantasia injector wincfg.exe AGOBOT.US WORM! X farmmext farmmext.exe Transponder parasite updater/installer X Fash Fash.exe Ibis toolbar adware related N Fast fast.exe Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys N FAST Defrag FAST2.EXE FastDefrag defragmenting software X Fast Search svcnv.exe "Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf" X Fast start Ntut.exe unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i X Fast start svcnt.exe unidentified adware - recognized by Kaspersky antivirus as a variant of the Win32.Favadd TROJAN! U FastCache fc.exe FastCache from AnalogX - speeds up browsing by resolving DNS requests locally X FastStart ntnut32.exe StartPage.L TROJAN! X FastStart svcnut.exe Browser hijacker - a variant of the STARTPAGE.L TROJAN! X FastStart svcnut32.exe Browser hijacker - a variant of the STARTPAGE.L TROJAN! N FastTrack Accelerator SPEED UP.EXE "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus" N FastUser fast.exe Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys U FatPipe DHCP Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users U Fatpipe Dialer fpdialer.exe Dialler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users U FaxCenterServer fm3032.exe "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others." U FBDirect FBDirect.exe "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs" X fc runfc.exe CAMPURF VIRUS! U FD_SAP FD.exe Reported to be the autopassword program from the Sony Microvault thumb drive. X Fdr Command Module sp2.exe SDBOT.WP WORM! X feelalright mirc.exe W32/IRCFlood-M WORM! U FEELitDeviceManager feelitdm.exe Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals) X fegoze SVCH0ST.EXE "GRAYBIRD.D VIRUS! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." U Fellowes Proxy R3proxy.exe Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice X Fen Startups fensvc32.exe W32.RANDEX.CCF WORM! U FerrariWallPaper FerrariWP.exe Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com X ffis ffisearch.exe "iSearch ""Desktop Search"" hijacker" U FG1_00 frntgate.exe FrontGate MX - e-mail spam blocker X fGQEGqHOME gwwgtp.exe BACKDOOR.RANKY.J TROJAN! U Fhtisxk fhtisxk.exe "XtraKeys - keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove via Spybot S&D (for example)" U FieldForms Sync SyncService.exe "Resco FieldForms . A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well." X FiendlyType csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X FILE abcdefg.exe W32.Kelvir.DD Worm! X file laoder configuration rnd32.exe RBOT.BQJ WORM! X File System taskmqrs.exe variant of the WIN32.TOXBOT/CODBOT WORM! X File System Service wmiprvsc.exe AGOBOT-HZ TROJAN! X File0_0 MD1.exe Troj/Dloader-OR Trojan! X File1 Dia Claro.htm Troj/Dloader-OR Trojan! N FileFreedom_Plugin wtm.exe FileFreedom peer-to-peer sharing program X FileManager32 ?? NOTUP.A VIRUS! X FileSoft ?? SST.B VIRUS! U FilterGate filtergate.exe "Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items" U Filterguard Filtrgrd.exe "An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ?short-cut? to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by ?right-clicking? on the icon" X Find find.exe W32.OPANKI WORM! X Find Fast Findfast.exe Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier Y Find Virus Launch Program fvlaunch.exe Part of Dr. Solomon's Antivirus N FinePrint Dispatcher vx FPDISPxA.EXE "FinePrint - virtual printer for use with any printer. Search for ""dispatcher"" here for more information. If removed, it will re-install when program is run - hence the Y recommendation" N FineReader7NewsReaderPro AbbyyNewsReader.exe ABBYY FineReader OCR software X FireFox Service Drivers ssmss.exe variant of the W32/SDBOT WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item. X Firewall Firewall.bat VBS.Ypsan.G WORM! X Firewall SP2 UPDATE.exe W32.ELITPER.E WORM! X Firewall wmlaunch .exe W32.ELIPTER.A or W32.ELIPTER.B or W32.ELIPTER.D WORM! Y Firewall Client Connectivity Monitor ISATRAY.EXE MS Internet Security and Acceleration Server - see here X Firewall Sp2 system sys32Conf.exe W32/Rbot-ABT WORM! X Firewall Updater msnupdateit.exe W32/RBOT-AAQ WORM! X firewall_anti firewall_anti.exe Trojan.Fantibag.A or Troj/Netdeny-B TROJAN! U FirewallStartup Firewallstartup.exe Innovative Solutions The user can choose whether or not to monitor installs when loaded. X FirewallSvr FirewallSvr.exe W32.NETSKY.X or W32.NETSKY.Y WORM! X FireWire Driver samx.exe BACKDOOR.SDBOT.AE WORM! X FireWire Service nvscv32.exe variant of the W32/SDBOT WORM! X FireWire Services nvcsv32.exe variant of the W32.SPYBOT WORM! X First Home Page http://find.naupoint.com Naupoint browser hijacker X FIX = WinFIX1.0.vbs VBS/Gormlez-A Worm! Y Fix-it mxtask.exe "Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required" Y Fix-it AV memcheck.exe Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources X Fixnice vcvw.exe SDBOT TROJAN! U FjMenu FjMenu.exe "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable." N fkSysMon fksysmon.exe "fkWrae SysMon - system monitor - ""displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more""" X FlaCPY flacpy.exe FlashEnhancer adware variant U FlashEnc FlashEnc.exe Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission. which is a pain. No need for it if you do not want these features X Flashget Download Manager Flashget.exe W32/RBOT-AGZ WORM! N FlashPath Status or FlashPath Monitor SDSTAT.EXE FLSHSTAT.EXE System Tray icon that you can\'t get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs X FlenCPY flencpy.exe FlashEnhancer Adware variant U Flexicd Flexicd.exe CD player - part of the Win95 Power Toys U FLMK08KB MMKEYBD.EXE Multimedia keyboard manager. Required if you use the additional keys U FLMOFFICE4DMOUSE moffice.exe Mouse properties for Logytech Typhoon Office Mouse X FlnCPY flncpy.exe FlashEnhancer adware variant X FLooDNeT FLooDeR.exe FLOODNET VIRUS! X Floppy Master ?? Troj/Zonit-F TROJAN! X flps flps.vbs BYRON VIRUS! X flpycntl flpycntl.exe CRYPTER.C trojan infection Y FltProcess msinet.exe Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done X FlyswatDesktop flydesk.exe Advertising spyware U FmctrlTray Fmctrl.EXE Genius SM-Live Control Panel. Enhances?audio output?through Genius sound cards (makes a big difference and?worth the 3MB Ram used) X fmnwebassist fmnwebassist.exe Adware popup generator U FMStart Fmstart.exe "GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop" X fmsz fmsz.exe FMSZ trojan X fnmwebassist fnmwebassist.exe WinPL adware X Folder Service wssdtu.exe MANIFEST VIRUS! U Folder View folderview.exe Folder_View enhances the Windows file Explorer by making all folders you need available in a single click. N Folding@home WINFAH.EXE "Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs" N FoneSyncSystemTray FoneSyncSystemTray.exe System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required X FontFix fontfix.exe unidentified VIRUS! X FontsLoader ldfnt32.hta Unidentified malware X FONTVIEW FONTVIEW.EXE OPASERV.T VIRUS! X foobin lptt01 or foobin ml097e adaware.exe "Variant of the RapidBlaster parasite (in a ""foo1"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" Y FoolProof fpwinldr.exe FoolProof Security PC security software from SmartStuff Y FoolProofSweep ?? Part of FoolProof Security PC security software from SmartStuff N Forbes ForbesAlerts.exe Forbes Business News Alerts - displays business news headlines in a little window on the screen X ForceShow ?? AdultLinks/QAbar parasite related N Forget Me Not AGRemind.exe Calendar reminder part of American Greetings˝ CreataCard˝ U Fortis Secure Layer Config cseinst.exe Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information. N FotoStation Easy AutoLaunch FotoStation Easy AutoLaunch.exe Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either U Foul PX FoulPX.exe "Foul PX, Optusnet usage stat checker" U FourthDay FourthDay.exe "The Fourth Day - ""astronomical clock and almanac for your system tray""" X foxdh foxdhend.exe PWSteal.Menghuan TROJAN! Y foxie firewall firewall.exe "Foxie Security Firewall - Part of Foxie Security, Privacy and Productivity Suite" Y foxie update update.exe "Foxie Secure Update - Part of Foxie Security, Privacy and Productivity Suite" X foxwudy9912 service.exe TROJ/BANCOS-BT TROJAN! Y FP Loader loadfp.exe FoolProof Security - PC security software from SmartStuff N Fpx mnmsrvc.exe Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations X France svchost.exe variant of W32.MIMAIL.C WORM! **Note this is not the valid svchost.exe as described for Win2K or WinXP N Fraps fraps.exe Fraps Real-Time Video Capture software U Free Download Manager fdm.exe """Free Download Manager"" See here" U Free Ram Optimizer fro.exe "Free_Ram_Optimizer monitors your memory, and frees up ram if it falls below a certain minimum." Y Freedom Freedom.exe "Zero Knowledge Freedom - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more" U FreeMem Pro FMEMPRO.EXE Some users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind U FreeMemVn2 FreeMem.exe Some users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind X FreeMP3download ?? MatrixDialer related U FreeRAM XP FREERAM XP PRO 1.40.EXE FreeRAM_XP is a freeware application to free and defragment your computer?s RAM U FreeRAM XP FreeRAM XP Pro x.exe "Some users swear by memory management utilities such as FreeRAM XP Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind. ""x"" indicates the version number" U freesurfer fs20.exe EMS Free Surfer mk II - pop-up stopper U Fresh Desktop freshdesktop.exe Fresh_Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals. X FriendlyType lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" X FriendlyTypeName Services.exe NEVEG.A or NEVEG.B WORM! - Note - this is not the valid Windows Service Controller services.exe process X FriendlyTypeName winlogon.exe "NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!" N FriendlyWebQuick-Launch SELFCERT.EXE selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well U FRISK FP-Scheduler F-Sched.exe Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis U FRITZ!webProtect FwebProt.exe Firewall included in FRITZ! ISP DSL software N Fromine WinPopup winpopup.exe Instant Messenger program X Frsk frsk.exe Unidentified adware downloader trojan Y FRW_EXE FRW.EXE ConSeal Signal9 firewall - now McAfee Personal firewall Y frxmxins frxmxins.exe ATI 3D Studio MAX/VIZ driver X FS Agent fagent.exe TROJ/VOLVER-B TROJAN! Y fsaa fsaa.exe F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers N FSCBoss FSCBoss.exe Free_Store_Club shop online software U F-Secure Management Agent FSMA32.EXE F-Secure Antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products Y F-Secure Manager FSM32.EXE F-Secure Antivirus - carry out scheduled virus scans automatically Y F-Secure Startup Wizard FSSW.EXE F-Secure antivirus Y F-Secure TNB TNBUtil.exe F-Secure antivirus U fsp fsp.exe Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents Y fspr FolderShield.exe Folder Shield - hide personal files and folders N FSScrCtl FSScrCtl.exe "Screen saver control applet used by the ""Stardust Screen Saver Toolkit"" and ""SolidWorks Screen Saver""" U fsserv fserv.exe Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time Y F-StopW F-StopW.exe F-Prot anti-virus background scanner by F-Risk Software X FSW FSW.exe FreeScratchAndWin parasite U FSWebServer fsws.exe Easy_File_Sharing_Web_Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services. X FtkCPY ftkcpy.exe FlashEnhancer adware variant U FTMSFLT(USB) FTMSFLTU.EXE Fujitsu\'s Touch Panel Message Notifier X FTP FOR WINDOWS ftpwin32.exe variant of the WIN32.RBOT WORM! X FTPGraber FTPGraber.exe DLOADER-DT TROJAN! N FTPManager FTPDM.ex "Robust_FTP is a Windows-based file transfer client application that transfers files between a user?s local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (With upload transfer resume and download transfer resume) - can be started manually." U Ftpqueue Ftpsched.exe Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers U Fujitsu Menu FjMnuIco.exe "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable." X fukerservice fukerz.exe Win32.Rbot worm variant X FUKLBAR bar.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" X fvek fvek.exe Troj/Drivol-A TROJAN! Y fwenc.exe fwenc.exe "Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers""" X Fwr Command Module fwr.exe W32/Sdbot-PP worm infection N fwrastrc fwrastrc.exe Dial-up software for Friendly Technologies/1NationOnLine free ISP N fwservice fwservice eAcceleration Stop-Sign related; not recommended; see note X FX ieloader.exe WIN32.SMALL.RR downloader TROJAN! U fxredir fxredir.exe Canon MultiPASS fax redirector X g.exe g.exe Backdoor.Graybird.Q TROJAN! Note: This trojan file is found in the Windows or Winnt folder. X G_Server.exe G_Server.exe TROJ/FEUTEL-C and Troj/Feutel-J TROJANS! X G00123 ?? BUGBROS VIRUS! X G0mez = G0mez.vbs VBS/Gormlez-A Worm! X G3 GSMedia3.exe Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux N Gadu-Gadu gg.exe Polish language Instant Messaging client N Gadwin PrintScreen PrintScreen.exe "Gadwin PrintScreen - utility to capture, print or save the current window" X GAELICUM.EXE GAELICUM.EXE Troj/Penta-A TROJAN! X gah95on6 gah95on6.exe ShopAtHome/SAHagent adware U gaim gaim.exe "Gaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks." U Gainward TBPanel.exe Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel X game shit.exe Netclap Gold backdoor TROJAN! N Game Device JOYUPDRV.EXE Genius game controller profile activator X Games Acceleration ?? Troj/SmutSrch-A Trojan! X Games Acceleration svshost.exe EasySearch adware X Games toolbar ?? "Topconverting.com/180Search ""Games Toolbar"" adware" N GameSpot kontiki.exe Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops U gameutil.exe gameutil.exe Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot U GammaHotKeys setgamma.exe Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop X gaSrv gaSrv.exe "Adware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ" X gaSrve gaSrve.exe "Adware downloader, identified by Panda antivirus as Trj/Downloader.ALQ" X Gate Personal Firewall Systpl.exe RBOT.ADC WORM X Gate Personal Firewall Systpl.exe RBOT.ADC WORM X Gator gator.exe Spyware - see here for removal instructions X Gator eWallet gator.exe Gator eWallet - also see here U GazelDisplay gsyno.exe BT Digital Access USB - Gazel ISDN installation System Tray icon U GBTray or GoBack GBTray.exe "System Tray icon access to Roxio\'s (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users" X gcasDtServ gcasDtServ.exe "unidentified WORM or TROJAN. - Note - there IS in fact also a Microsoft Antispyware process bearing the same name, but it will not figure among the startup items!" U gcasServ gcasServ.exe "Microsoft, formerly Giant AntiSpyware" X gcasServ realsched.exe variant of the WIN32.TACTSLAY.A TROJAN! - NOTE - do NOT confuse with the Real Player executable as described here N GCS GrabClipSave.exe GrabClipSave screen capture tool X GDAX ?? BACKDOOR.RANKY.K TROJAN! X gdien32 gdien32.exe Troj/Singu-P Trojan! U GDMgr.exe gdmgr.exe GuardMon is a commercial spyware program designed to monitor all forms of user activity on a computer N GDrive GDriver.exe Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager N Gearbox confsvr.exe NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here N GEARsec gearsec.exe Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player X GEDZAC GEDZAC.exe GEMEL VIRUS! N GemStRmW GemStRmW.exe "For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually" U Gene USB Monitor USBMonit.exe Monitors USB ports for insertion of Sandisk USB flashdrives. X general lptt01 or general ml097e general.exe "Variant of the RapidBlaster parasite (in a ""General"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Generic host proccess for windows SVCHOSTS.EXE W32/SPYBOT-GQ WORM! X Generic Host Process SCHOST.EXE W32/RBOT-NC WORM! X Generic Host Process svchost.exe Troj/Dloader-NX Trojan! X Generic Host Process for Win32 Services bazzi.exe W32.AHKER.E WORM! X Generic Host Process for Win32 Services intspvc.exe DINFOR.D VIRUS! X Generic Host Process for Win32 Services ntspcv.exe SDBOT.S WORM! X Generic Host Process for Win32 Services winsvc.exe W32/Sdbot-O worm infection X Generic Host Process for Win32 Services winsvc32.exe W32/SDBOT-P WORM! X Generic Host Process326a System Backup scvhost326a.exe variant of the W32/SDBOT WORM! X Generic Host Service lshost.exe RBOT.LU worm infection X Generic Service Process nvsvc.exe AGOBOT.BY WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here X Generic Service Process regsvc32.exe GAOBOT.UJ or GAOBOT.UL WORMS! X Generic Service Process regsvc32.exe W32.GAOBOT.UJ WORM! X Generic Service Process serv1ces.exe W32/Agobot-JK WORM! X Generic Services Process regsvc32.exe W32.Gaobot.SY worm Y Genie USB Monitor USBmonitor.exe Port monitor for an external USB hard drive. Required to enable access to the drive X Geography TX 1.0 NT CompuSpeed.vbs VBS/NEWLEY-A WORM! X Gestionnaire de disques universel sysoobe.exe Troj/Toader-A TROJAN! Note: This trojan file is found in the System\oobe (95/98/Me) or System32\oobe (Nt/2000/XP) folder. N Get Smile getsmile.exe Puts smilie faces in your E-mail. Run manually when required N GetRight Tray Icon GETRIGHT.EXE GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs X GetTheMusic ?? MatrixDialer related N GhostStartService GhostStartService.exe Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard N GhostStartTrayApp GhostStartTrayApp.exe System Tray access to Norton Ghost - added from the 2003 version X gigabit.exe gigabit.exe BEAGLE.U WORM! X GigaByte Cheatle.exe SHODI.B VIRUS! Y Gilat SOM Enumerator dllhost.exe For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system Y GilatFTC ftc.exe For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system X GinaDll ntgina.dll ANIG.A worm infection U Glass2k Glass2k.exe """Glass2k is a small little program that allows Win2K/XP users to make any window transparent""" X GLF Network Lan Monitor NPFMNTOR.exe W32/RBOT-AGY WORM! Y Glide Glidew32.exe Cirque touchpad driver X GLSetIT32 isass.exe variant of the OPTIX PRO series of VIRUSES! X GLSetIT32 msiexec16.exe OPTIX PRO series of VIRUSES! X GLSetT32 smsiexec.exe TROJ/OPTIX-D TROJAN! X glv glv.exe DLOADER-NG TROJAN! X GMedia2 GSM2.exe Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux X GMedia2 GSMedia3.exe Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux Y Gmouse Gmouse.exe Amouse mouse driver - required if you use non-standard Windows driver features U Gnetmous gnetmous.exe Genius NetScroll mouse driver - required if you use non-standard Windows driver features X GNP Generic Host Process svchost.exe "Troj/Zapchas-R NOTE - This file is placed in the C:\Winnt\System or C:\Windows\System folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Go!Zilla gozilla.exe Download manager for resuming downloads and choosing multiple download locations. Advertising spyware X Go!Zilla Monster Downloads Go.exe Download manager for resuming downloads and choosing multiple download locations. Advertising spyware U GoBack GBMenu.exe "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users" U GoBack Polling Service GBPoll.exe "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users" U GoBack Tray Icon GBTray.exe System Tray icon access to GoBack (above) X GOG GOG.exe PHILIS.B VIRUS! X goidr goidr.exe Goidr adware U Goldensoft_MndlSvr MndlSvr.exe "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking" X Golum services.exe "GOLUM.A TROJAN! - Note - this services.exe file is placed in a Winnt\System32\Golum or Windows\System32\Golum subdirectory, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X golumm services.exe "CoolWebSearch parasite variant. Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X google google.exe W32/Rbot-AMW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. U Google Desktop Search GoogleDesktop.exe "Google_Desktop_Search - ""a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks.""" N Google Earth Viewer GOOGLEMAPS.EXE "Google_Earth ""combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips.""" X google toolbar ggtb32.exe W32/AGOBOT-RR WORM! Y googleadbgone googleadbgone.exe Googleadbgone - advertising / popup blocking program N GoogleDCClient GoogleDCC.exe "Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click ""Stop Computing""" U googletalk googletalk.exe "Google_Talk ""enables you to call or send instant messages to your friends for freeşanytime, anywhere in the world"". Can be launched manually." U GoToMyPC g2svc.exe ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser X GotSmiley GotSmiley.exe "Gator GotSmiley - adware based, also see here" X gouday.exe readme.exe BEAGLE.C WORM! N GRA gra.exe "Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag?and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility" X Graphic Driver smss32.exe variant of the WIN32.RBOT WORM! X Graphic Loader ntvdm32.exe variant of the WIN32.RBOT WORM! U Gravis Appawareloader dbserver.exe "Looks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them" U Gravis Xperience Driver Support Grxp4exe.exe Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used N Greetings Workshop GWREMIND.EXE You really want to be reminded about somebody's birthday at the expense of resources? X gremier ?? GPREMIER VIRUS! X Gremlin intrenat.exe DOOMJUICE VIRUS! N Grokster Grokster.exe Groster Peer-To-Peer File Sharing program Y GrpConv grpconv.exe "Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article," X GsAds gms2.exe PacerD_Media/Pacimedia.com adware component X gshp zzgshp.vbs Homepage hi-jacker N Gsiconexe Gsicon.exe ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities N GSOrganizer GSOrganizer.exe GoldenSection Organizer - personal information manager X gssomatic gssomatic.exe Searchcentrix hijacker X GStartup GMT.exe Gator spyware component - see here X gsv gsv.exe ROBAL 1.0 backdoor TROJAN! N Gtwatch gtwatch.exe Associated with a Mustec scanner and not required N Guardian CMGrdian.exe "McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic" X guarnset guarnset.exe Adlogix adware U GuruNet GuruNet.exe GuruNet lets you click on any word on your screen to get the relevant information you want. X GustavVED ?? OPASERV.H VIRUS! X gvagfxj ?? "Unidentified adware, spyware or virus" Y gw port controller PORTCT95.EXE "From a visitor - ""I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work"". From the file properties, the file is known as ""Smart Thru Fax Drive Spy"" and is supplied by Samsung" N GWInkMonitor GWInkMonitor.exe "Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!" N GWMDMMSG GWMDMMSG.exe "Used with internal modems on Gateway and vprMatrix PCs. This is the ""GTW modem messaging applet"" and is not required for the modem to work correctly" U GWMDMpi GWMDMpi.exe Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information U gwum gwum.exe "Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system ""tweakers""" U H/PC Connection Agent WCESCOMM.EXE Active sync for use with Windows CE based palm PC X h4te Service Drivers h4te.exe variant of the WIN32.RBOT WORM! X hachimitsu-lemon hachimitsu-lemon.exe HACHILEM TROJAN! X hagent avp.exe """Herman Agent"" remote access TROJAN!" U HalifaxHowardCluster skinkers.exe Howard_the_Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages U HaMFrontPanel hampanel.exe "Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless" U Handy Backup 3.9 hbagent.exe Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers U Hardware Doctor Hwdoctor.exe "Winbond Hardware Doctor - as included on some motherboard using Winbond\'s hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you\'re concerned about your system temperature - typically for ""overclocked"" systems" X Hardware Monitor Service mshms.exe Troj/Wollf-A TROJAN! X Hardware Profile hxdef.exe variant of the LOVGATE WORM! U Hardware Sensors Monitor hmonitor.exe "Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for ""overclocked"" systems" U Hare hare.exe Hare - improve and optimize performance of desktop/laptop PCs U HawkEye HAWK_95.EXE "Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs" U HawkEye IV Control Panel HAWK_32.EXE "Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs" X Hbinst Hbinst.exe Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here N HC Reminder hc.exe "For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed" N HCDetect HCDetect.exe "MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem" U hcenter tgcmd.exe "See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation" X hclean32.exe hclean32.exe "TROJAN downloader/installer! - assumed to be associated with Wareout, malware masquerading as a spyware and dialer remover, see here" U Hcontrol hcontrol.exe Hotkeys on an ASUS Notebook. Only required if you use the additional keys X HDAudio Driver 1.0 ?? Troj/Teadoor-D TROJAN! X HDAudio Driver 2.0 ?? Troj/Teadoor-E TROJAN! U HDDHealth hddhealth.exe "HDD_Health is a ""full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure.""" U HDDlife HDDlife.exe HDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks. N HDtray HDtray.exe Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel X he3bbcff ?? LZIO.com adware downloader X he3e3fc4 ?? LZIO.com adware downloader X HELLBOT TEST 1hellbot.exe W32.MYDOOM.BO WORM! X hellodolly shost.exe YODO VIRUS! X helloworld nb32ext2.exe W32/MYDOOM.BV WORM! X helloworld nb32ext3.exe MYTOB.JT WORM! X Help Temp Files netreg.exe W32/FORBOT-EM WORM! X helpctl.exe helpctl.exe GASLIDE VIRUS! X HELPER canada.exe AsdPlug premium rate adult content dialer variant X Helper eschlp.exe BLASTER.T VIRUS! X HELPER france.exe AsdPlug premium rate adult content dialer variant X HELPER greece_nm.exe AsdPlug premium rate adult content dialer variant X HELPER Netherlands.exe AsdPlug premium rate adult content dialer variant X HELPER new_zealand.exe AsdPlug premium rate adult content dialer variant X HELPER sweden.exe AsdPlug premium rate adult content dialer variant X HELPER temp532.exe AsdPlug premium rate adult content dialer variant X helper.dll ?? CnsMin (Chinese_Keywords) related X HelpExp.exe HelpExp.exe Attune HelpExpress. Disable - see here X helpmanager spoler.exe RANDEX.J VIRUS! X helpw helpw.exe adware downloader X hErcUnes softhost.exe W32.GARROCH WORM! U Hermes Messenger DGDRHE~1.EXE A LAN messenger alternative to WinPopUp - Digital Dreams Software N Hewlett Packard Recorder Remind32.exe HP multifunction registration U Hf Hf.exe Hide Folders - hide your folders so only you can view them X HF Security hfsecure.exe W32/AGOBOT-TI WORM! U hffsrv hffsrv.exe "Hide_Files_&_Folders is a password-protected security utility working at the Windows kernel level allowing you to password-protect files and folders, or to hide them securely from viewing and searching." U hfxp hfxp.exe Hide Folders XP - hide your folders so only you can view them X hgqhp.exe hgqhp.exe FLUSH.F TROJAN! N HGTXPEI FirstReboot.exe Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel U Hibernation hib32.exe "Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly" X Hid.exe hid.exe RATSOU.B VIRUS! X hiden hiden.exe AGENT-IW TROJAN! U HideOE HideOE.exe HideOE - allows you to 'hide' Outlook Express or minimize it to the sytem tray. X HideRun.exe Hiderun.exe BOOHOO VIRUS! X HideRun.exe pro.gif BOOHOO VIRUS! X HideRun.exe svhost.exe BOOHOO VIRUS! U hidserv hidserv.exe "This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and?PS/2 keyboards" N High Definition Audio Property Page Shortcut HDAudPropShortcut.exe "Realtek audio card related; probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required." U HijackThis startup scan HijackThis.exe "HijackThis lists the contents of key areas of the Registry and hard drive--areas that are used by both legitimate programmers and hijackers. The program is continually updated to detect and remove new hijacks. It does not target specific programs and URLs, only the methods used by hijackers to force you onto their sites. As a result, false positives are imminent, and unless you're sure about what you're doing, you always should consult with knowledgable folks before deleting anything. Required if you'd like Hijack This to run a scan at startup, and show the results when new items are found (if so, check the appropriate box in the ""Config"" section"")" N HistoryKill histkill.exe "HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs" U HitwarePKLite HITWAR~1.EXE Hitware Popup Killer Lite X HIV HIV.exe HIVA VIRUS! U hk hk.exe KeyLoggerExp keystroke logger/monitoring program - remove unless you installed it yourself! U hkcmd hkcmd.exe "Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel" X HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curre windowsupdate.exe W32/Forbot-BJ WORM! X HKEYok runlli32.exe Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. U HKSERV.EXE HKserv.exe Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS U hkss hkss.exe Compaq HotKey Support - multimedia keyboard support X hlhtxo.exe hlhtxo.exe QLOWZONES-27 TROJAN! X hlinstaller1 hlinstaller1.exe Identified by Kasperksy_Labs as Trojan.Win32.SecondThought.aa X HLL Data Parameter hllcxpa.exe RBOT.AFG WORM! X HMI PowerSystem hmisvc32.exe W32.RANDEX.CZZ WORM! X HML PowerSource hmlsvc32.exe W32/SDBOT-XL WORM! U Hmonitor Hmonitor.exe Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status X HMV PowerSource hmusvc32.exe W32/Sdbot-YW Worm! X HOI Services holsvc32.exe W32/AGOBOT-SF WORM! N Holiday Lights Holiday Lights.exe Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs X Hollaback slvhosts.exe SDBOT.BMO WORM! N Home Theater SchSvr SchSvr.exe "WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs" U HomeAlarm HomeAlarm.exe Chameleon Clock - system tray clock replacement X Homeland Network HomelandNetwork.exe "Homeland_Network Notifier - Pops ads, see their privacy_policy" U Hook99startup hk2re.exe """Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent""" U HookSys HookSys.exe "SurfinGuard Pro - protects against all malicious code delivered through executables, scripting files, ActiveX and Java" Y HorngTech4D bally4d.exe HorngTech 4D mouse driver X Host ?? POPDIS VIRUS! X hostdll.exe hostdll.exe BANKER-BO TROJAN! X Hostren.exe Hostren.exe "PWS.BANKER.F, a variant of the BANKER-BO TROJAN!" X hostserv hostserv.exe RBOT.BPZ WORM! X hostserv wiz98.exe variant of the W32/SDBOT WORM! X HostSVC syse HostSVC.exe W32/RBOT-ANZ WORM! U Hot Corners Hotc.exe "Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen""" U Hot Key Kbd 2690 Daemon SK9910DM.exe Multimedia keyboard manager - required if you use any special keys U Hot Key Keybd 9910 Daemon SK9910DM.exe Multimedia keyboard manager - required if you use any special keys X Hot_Kiss Hot_Kiss.exe Adult content dialler X Hot_Tarts Hot_Tarts.exe adult material dialer X Hot_Tarts_** Hot_Tarts_** Premium rate adult content dialer (where * is a random char) X Hotbar Hbinst.exe Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here X Hotbar HbOEAddOn.exe Hotbar adware X Hotfix Updat svdhost32.exe GAOBOT.ZW WORM! U HotIDE hotide.exe HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks U HotkeyApp HotkeyApp.exe Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 U HotKeysCmds hkcmd.exe "Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties" X HotPix hotpix.exe Adult content dialler X hotplug hotplug.exe Trojan.Downloader.Agent.AM X HotSurprise HotSurprise.exe Premium rate adult content dialer N HotSync Manager hotsync.exe Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing.? Available via Start -> Programs X hotwetlove hotwetlove.exe Adult content dialler. Will not uninstall - components have to be manually deleted U HoverDesk HoverDesk.exe HoverDesk - desktop replacement software U HP AutoIndexer hppautoindexer.exe "Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup" N HP CD-DVD or HP CD Writer hpcdtray.exe System Tray access to a HP CD-Writer\'s functions. Available via Start -> Programs X hp center BACKWEB-137903.exe "Based upon HP's own description from here - ""With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music"" I have classified this as adware.?The number may change - if yours is different let me know" X hp center UI ShadowBar.exe User Interface for HP Center N HP Component Manager hpcmpmgr.exe "Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can\'t shutdown the computer because hpcmpmgr.exe can\'t be ended""" X HP Deskjet HP_DeskJet_500.exe W32/FORBOT-DA WORM! U HP Digital Imaging Monitor hpqtra08.exe "System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos from a camera, for example" U HP Display Settings hpdisply.exe "Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message" N HP Image Zone Fast Start hpqthb08.exe "Improves the startup time of HP Image Zone. If you disable it, HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time" N HP Info Express ?? "On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb" U HP Instant Support matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide" N HP Internet Center SURFBRD.EXE Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them N HP JetDiscovery HPJETDSC.EXE HP JetAdmin software which monitors printing jobs on a network environment N HP JetSpeed Autostart AUTOSTART.EXE Autostart executable for the old multiplayer game HP Jetspeed U HP Laser Jet Director hppdirector.exe "System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc" N HP Network Registry Agent hpnra.exe "Hewlett-Packard Network Registry Agent background task installed by the drivers for many of HP?s printers since 2002. See here under ""hpnra.exe""" N HP Parallel Port Test hppt.exe Associated with a HP ScanJet scanner X HP Photo Manager HPPhotoManager.exe SDBOT.AXU WORM! N HP Precision Scan hpmdlbwx.exe HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required N HP Presentation Ready PresRdy.exe "HP Omnibook related:? ""Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device""" U hp psc 2000 Series hpobnz08.exe System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start U HP RecordNow ?? "From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used.""" U HP ScanPatch HPScanFix.exe "Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting" N HP ScanPicture hpsplmwa.exe HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required U HP SchedIndexer hppschedindexer.exe "Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup" X HP Service Drivers hdsys.exe W32/Sdbot-ZE Worm! N HP Simple Trax Hpcron.exe Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon N HP software update HPWuSchd.exe "HP software updates. If a shortcut doesn't exist, create your own and run it manually" N HP software update HPWuSchd2.exe "HP software updates. If a shortcut doesn't exist, create your own and run it manually" N HP Status hpstatus.exe HP Printer Status and Alerts U HP TV Now HpTvNow.exe Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) - user's choice! N HP Updates ?? "On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb" N HP_dla dlatray.exe "On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD" N HP-Aio Flight Remind32.exe HP multifunction registration N HPAIO_PrintFolderMgr hpoopm07.exe "Directly from HP: ""This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port."" For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to ""hpodir07.exe"" works just fine if you need to use the scanner" N hpaiodevice hpodev07.exe "Direct from HP - ""Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when ""portable"" is chosen during installation)"". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to ""hpodir07.exe"" works just fine if you need to use the scanner" N HPAiODevice(hp psc 900 series) -1 hpobrt07.exe "Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry" U HPDJ Taskbar Utility ?? (1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info N hpfsched hpfsched.exe HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature U HPGamesActiveMenu ActiveMenu.exe Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case N hpgs2wnd hpgs2wnd.exe """HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites.""Available via Start -> Programs" U Hpha1mon Hpha1mon.exe Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature. U HPHAxMON HPHAxMON.EXE "Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. ""x"" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards" U HPHmon** ?? Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn\'t inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don\'t use the reader U HPHmon04 hphmon04.exe Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature U HPHmon06 hphmon06.exe "Related to the Hewlett Packard software HP Photosmart printer, it provides easy access to flash card reading functions. This program is not essential to the running of the system. Your choice." X Hphome hphome.js Homepage hijacker N HPHUPD** hphupd**.exe HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs N hphupd04 hphupd04.exe HP Photosmart software update checker and wizard launcher. Available via Start -> Programs N HPHUPD06 hphupd06.exe Belongs to the HP Photosmart application and is responsible for keeping this software upto date. This program is not essential to the running of the system X HPl Services hmlsvc32.exe W32/AGOBOT-SI or W32/Agobot-SM or W32/Agobot-SN and W32/Agobot-ATK WORMS! Y HpLamp HPLAMP.EXE HP Scanner Utility that controls your scanner?s light bulb. Needed if it's switched on. Also refer here for troubleshooting U hplampc hplampc.exe HP Scanner Lamp Utility. Fixes an issue with the scanner lamp not going off. U HPLaptopGamesActiveMenu ActiveMenu.exe Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case U HPLogiFinder hp_finder.exe HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used U HpMmKbd HpMmKbd.exe HP?s multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard N hpodblia hpodblia.exe HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually N hpodlb08 hpodlb08.exe HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually Y hpotdd01.exe hpotdd01.exe "hpotdd01.exe is installed alongside HP Multimedia products and is responsible for digital imaging. ""This program is a non-essential process, but should not be terminated unless suspected to be causing problems.""" Y hpppta HPPPTA.exe HP parallel port driver for certain hardware X HpPrinter hpserver.exe Troj/CmjSpy-W Trojan! N HPPROPTY HPPROPTY.EXE HP LaserJet Toolbox U HPPWRSAV HPPWRSAV.EXE "Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the?instructions and you will find an updated lamp control patch" U HPSCANMonitor hpsjvxd.exe HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner N hpsjbmgr hpsjbmgr.exe "HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment" N HPStart hpstart.wsf This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot X hpsysconf1 ?? VIVIA.A trojan variant U hpsysdrv hpsysdrv.exe "This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working" N HPU ProvenTactics.exe Proven Internet Marketing software N HPZTS04 hpzts04.exe Hewlett Packard printer toolbox shortcut that resides in the system tray X HQI Services hqisvc32.exe W32/AGOBOT-RO WORM! X HQI Services hqlsvc32.exe W32/AGOBOT-RP WORM! U HR Hr.exe HiddenRecorder periodically takes screenshots of the computer. If you didn't install this yourself remove it. Y HREF.OCX ?? HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller X hsim isearch.exe Unidentified Malware X hsim sexgame.exe Unidentified Malware X hsim toolbar.exe Unidentified Malware U HSLAB Logger logger.exe HSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it. U Hti npdor.exe Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required U HTpatch htpatch.exe HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6% X HtProtect AVprotect.exe W32.NETSKY.L WORM! X http://www.lienvandekelder.be Lien Van de Kelder.exe W32/Mytob-CP or W32/Mytob-CO or W32.Mytob.GK WORMS! X http://www.lienvandekelder.be Lien Vande Kelder.exe W32/Mytob-AQ Worm! X http://www.lienvandekelder.be Lien vd Kelder.exe W32/Mytob-M Worm! X http://www.lienvandekelder.be Lien.exe W32/Mytob-CZ Worm! X http://www.lienvandekelder.be Lientjeuh.exe W32/Mytob-P Worm! X http://www.lienvandekelder.be LienVandeKelder.exe W32/MYTOB-AZ WORM! X http://www.lienvandekelder.be LienVdK.exe W32/MYTOB-U WORM! X http://www.lienvandekelder.be Van de Kelder Lien.exe W32/Mytob-BF Worm! X http://www.lienvandekelder.be We Love Lien Van de Kelder.exe W32/Mytob-CV Worm! X httpd c_pan.exe infection by a Troj/Delf-A trojan variant! X httpd deamon.exe WIN32.TACTSLAY.C TROJAN! X httpd msgaol.exe WIN32.TACTSLAY.C TROJAN! X httpd s_menu.exe WIN32.TACTSLAY.C TROJAN! X https-ssl https.exe MOEGA.D VIRUS! X huigezi HgzServer.exe GRAYBIRD.C VIRUS! X Hvid Hvid.exe GEMA TROJAN! X HWINFO** HWINFO** PUROL VIRUS! where * is a random character Y HWinst ?? For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out X Hwp system_wc.exe Eziin adware X hxadsec ?? Troj/AdClick-AP TROJAN! X HXDL.EXE HXDL.EXE "Believed to be spyware - made by a company called Alset. Also known as ""HelpExpress"". Will install itself if you have previously had Attune by Aveo installed as they\'re by the same company. Uninstall via Add/Remove programs" U HydarVisionDesktopManager desk95.exe "ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this_one . HydraVision can be uninstalled through Add/Remove Programs." U HydarVisionViewport viewport.exe ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup U HydraVisionDesktopManager desk98.exe ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup U HydraVisionViewport viewport.exe ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup X Hyper Start instantmsgrs.exe W32/RBOT-NH WORM! X I am not Ranky. I am eTunnel! disney.exe unidentified WORM or TROJAN! X I am not Ranky. I am eTunnel! msyervice.exe unidentified WORM or TROJAN! X I am not Ranky. I am eTunnel! winsys.exe unidentified WORM or TROJAN! X I/O Controllers svcnet.exe TROJ/TIBIK-B TROJAN! X I386 I386.exe MYPOWER VIRUS! U i8kfangui i8kfangui.exe Graphical interface for fan speed control U IAAnotif iaanotif.exe "IAA Event Monitor User Notification Tool - part of Intel˝ Application Accelerator - ""a performance software package for desktop PCs using select Intel˝ chipsets"" that ""replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs."" If you use the RAID version it\'s required to notify you if a RAID 1 disk has failed" Y iamapp iamapp.exe "AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well" X Iamnacho On Irc.MusIrc.com Is a Homosexual! XBox64.exe RANDEX.Y VIRUS! U ias ias.exe InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself! X IASHLPR IASHLPR.EXE OPASERV.T VIRUS! X ibin ?? Troj/Perda-C Trojan! X ibm ibm.exe Troj/LegMir-AH Trojan! N ibmmessages ibmmessages.exe "Allows IBM to push messages onto users' computers. Quote: ""The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport""" U Ibmpmsvc ibmpmsvc.exe "Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes" U IBMUltraBayHotSwapCPLLoader IBMBAY2N.EXE Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops U IBWin Background process IBackground.exe IBackup for Windows U IBWin Monitor IBMonitor.exe IBackup for Windows N IC_KEY_3 spvic.exe Instant Chess related X icasServ icasServ.exe "Browser hijacker, redirecting to Searchforfree.info, also detected as TROJ/ICASERV-A" X ICcontrol iccontrol.exe ICcontrol premium rate adult content dialer X icdd7ee6 ?? LZIO.com adware downloader X icddefff ?? LZIO.com adware downloader N ICH Synth eusexe.exe "Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with ""SoundMAX integrated Digital Audio"" (Analog Devices Inc.) devices" X icifati yujixit.exe SDBOT.ZZH WORM! U iClean iClean.exe "IEClean - ""advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy""" N iCn NAG.EXE "iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist" N ICO ICO.EXE Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games N Icon Animation HDE.EXE Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons N Icon Hearit 95 hearit95.exe Audio desktop customization utility from Moon Valley Software. Resource hog N Icon Hearit 98 hearit98.exe Audio desktop customization utility from Moon Valley Software. Resource hog X Icon lptt01 or Icon ml097e icon.exe "Variant of the RapidBlaster parasite (in an ""Icon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" Y ICONCLNT iconclnt.exe APC PowerChute Tray Icon. Associated with the UPS listing U ICONDESK ICONDESK.EXE Small utility which will allow you the option of hiding or showing your desktop icons N Iconfig.exe Iconfig.exe "Icon for LS-120 ""Superdisk""" X iConfigLoader DIIhost.exe GAOBOT.AO WORM! N Iconoid Iconoid.exe Iconoid is a desktop icon manager N Iconsaver Iconsaver.exe IconSaver is a desktop icon manager X ICQ = ICQNET.vbs VBS/Gormlez-A Worm! X ICQ Center consoles.exe RANDIN VIRUS! X ICQ Chat Service icqjdhs.exe variant of the WIN32.RBOT WORM! X ICQ Hacking Pro ICQpro.exe version of the NETSPY VIRUS! N ICQ Lite ICQLite.exe ICQ Lite - compact version of the popular messaging program X ICQ Lite Messenger ?? "Unidentified worm or trojan. Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory." X ICQ Messenger 2002 ICQ2002.exe W32/Sdbot-AB WORM! X ICQ Net winlogon.exe W32.NETSKY.C or W32.NETSKY.D or W32.NETSKY.E or W32.NETSKY.K WORM! **Note - this is NOT the legitimate Windows winlogon.exe process X ICQ Net winlogon.exe "Win32.Netsky.D WORM! - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!" N ICQ Plus vplus.exe ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs X IcqBeta webcamupdate.exe unidentified TROJAN! X ICQNet winlogon.exe "W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" U ICSDCLT ?? Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines N ICServer Icserver.exe Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations Y ICSMGR ICSMGR.EXE Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you?re sharing the internet on various computers N ID Commander IDCom.exe Caller ID utility for identifying incoming telephone numbers X ID8525 ID8525.exe ID8525 VIRUS and homepage hijacker! X ID8525 id85255.exe ID8525 VIRUS and homepage hijacker! X IDE ide.exe ASSASIN.F VIRUS! X IDE Loader IDElibr32.exe "XILON VIRUS!. Related to the game ""Diablo II""" X idecntl idecntl.exe Crypter.C trojan variant infection U iDesktop idesktop.exe Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse N IDMan IDMan.exe "Internet Download Manager - download files faster, schedule and resume" N IDW Logging Tool idwlog.exe Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems X IE configure explorer.exe Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the Windows or Winnt folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. U IE Doctor IEDoctor.exe "IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options""" X IE Menu Extension toolbar ?? "Topconverting.com/180Search ""IEMenuExtension"" toolbar" U IE New Window Maximizer iemaximizer.exe "IE New Window Maximizer, see here - automatically maximize new Internet Explorer and Outlook Express windows." X IE Runtime wini.exe W32.Picrate.B WORM! X IE Runtime wini.exe W32/RBOT-ABK and W32/Rbot-ADM WORMS! X IE Runtimes winis.exe W32/Rbot-ADZ Trojan! X IE**.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X IE**32.exe (* = random char) ?? "CoolWebSearch/HomeSearch adware component - for examples, see this log" X IE6 ssmss.exe W32.Gaobot.DXO WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item. X IE6 wkstmg.exe variant of the W32/SDBOT WORM! X IEACCESS surfya.exe IEAccess premium rate adult content dialer variant X IEACCESS temp532.exe AsdPlug premium rate adult content dialer variant X IECheck MSDTCs.exe W32/TIRBOT-D WORM! X IECheck mssvp.exe W32/Tirbot-G Worm! X IECheck xpssl.exe W32/TIRBOT-E WORM! N iecheck.exe iecheck.exe Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 U IECleanAux Ieboot6.exe "IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup" X iedll iedll.exe "Homepage hijacker, redirecting to coolwwwsearch.com" X IEDriver IEDriver.exe Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze X IEDriver TD.exe IEDriver adware variant X IEDriver xplore.exe IEDriver adware variant X IEengine IEeng.exe TROJ_STARTPAG.AI hijacker X ieexec.exe ieexec.exe TROJ/MULTIDR-DY TROJAN! X IEFeatures ?? POPMON.A VIRUS! - also known as PopMonster adware X IefxTray IefxTray.exe RILER-H TROJAN! X ieharv.exe ieharv.exe Troj/Banker-HH TROJAN! X Iehelper syslaunch.exe Outwar adware downloader X iel2cde8 ?? LZIO.com adware downloader X ielcaabe ?? LZIO.com adware downloader X IELoader32 iexplore32.exe W32.Spex or W32.Spex.B WORM! X Iesar Iesar.exe Browser hijacker - redirecting to an adult web page X Iesearch.exe Iesearch.exe LookNSearch adware X IEService.exe IEService.exe FastFind parasite variant X iestart iexp1orer.exe NEMOG.C VIRUS! N ietsr ietsr.exe "IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc" X ieupdate MCP****.exe ASOXY VIRUS! where **** are random characters X ieupdate mcpdll32.exe Adware downloader trojan X IEXPL0RER IEXPL0RER.EXE W32/AGOBOT-QL WORM! X iexpl0res iexpl0res.exe "RBOT.AEX WORM! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot" X Iexploit Iexploit.html VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder. X Iexplore iexplore.exe BOXER VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder X IEXPLORE iexplore.exe "APHEXDOOR VIRUS! Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) wheras the valid ""iexplore.exe"" (IE) resides in C:\Program Files" X Iexplore Services iexplore.exe unidentified VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder X IExplorer Iexplor32.exe TROJ/BDOOR-BY TROJAN! X IExplorer IExplorer.EXE BANCOS-CH and Troj/Bancos-CW TROJANS! X iexplorer lptt01 or iexplorer ml097e iexplorer.exe "Variant of the RapidBlaster parasite (in an ""iexplorer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)" X Iexplorer.exe Iexplorer.exe TROJ/BANCBAN-EN TROJAN! X IExplorer32 Java Scripting IExplore32b.exe RBOT.ABO WORM! X IExplorer32c Java Scripting IExplore32cb.exe RBOT.ABN WORM! X IExplorer6 Java Scripting IExplore326.exe variant of the W32/SDBOT WORM! X IExplorer7 Java Scripting IExplore327.exe variant of the W32/SDBOT WORM! U IFSplash.exe IFSplash.exe I-FORCE driver for force feedback steering wheel X igamatu atecaca.exe IRCBOT.R WORM! N igfxtray igfxtray.exe "Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel" X igsex2x igsex2x.exe NewDial premium rate adult content dialler X iilc IILC.EXE Homepage hijacker X Iinl iptl.exe PurityScan/Clickspring adware X iisvers iisvers.exe unidentified TROJAN or adware N iIWiper Systemwiper.exe System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis Y IJ75P2PSERVER IJ75P2PS.EXE Printer utility which is required in order to make the printer work correctly Y IKE Service 95 IKEService.exe "Associated with PGP. The PGP Tray can bedisabled, but without IKESERVICE you won\'t be able to de- or encrypt anything" U iKeyWorks IKEYMAIN.EXE A4Tech wireless keyboard driver and utility X iLLeGaL or iLLeGaL.exe Mplayer.exe HOLAR.C (or GALIL@MM) VIRUS! Note - this should not be comfused with Windows Media Player which has the same filename U iLyric iLyric.exe iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button N iM Start Center iM_Tray.exe Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner X Image ?? CoolWebSearch parasite related Y Image & Restore IMAGE32.exe "Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run" N Image Transfer SonyTray.exe Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually. U Imagefox imagefox.exe "ImageFox 2.0 is an ""add-on"" graphics previewer for most Windows Open/Save As dialog boxes" X Imagemgt32 Imagemgt32.exe GEMA TROJAN! X ImagePath taskbarmngr.exe W32/SDBOT-XB WORM! X IMClass Svhosl.exe unidentified WORM od TROJAN! N imekrig imekrig.exe "Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)" N IMEKRMIG6.1 IMEKRMIG.EXE "Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)" N Imesh ?? Imesh is a file sharing system N Imesh Auto Update ?? "Update check for the Imesh, http://www.imesh.com file sharing system. Turn the update off under ""options""" U ImgIcon ImgIcon.exe "Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running" X imgit ?? BANKER-EM TROJAN! N ImgStart ImgStart.exe Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs N imjpmig or Imjpmig8.1 IMJPMIG.EXE "Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)" U IMOL IMOLApp.exe IncrediMail for Office Outlook_Add-On N Imonitor Plguni.exe McAfee QuickClean 3.0 - removes internet clutter and unwanted programs U IMONTRAY imontray.exe "System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you ""overclock"" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards" U IMStart IMStart.exe InterMute security software related X IMwire imwireup.exe SafeSurfing parasite variant Y InCD incd.exe "Ahead_InCD packet writing software. Similar to DirectCD. - For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. - For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows." N IncMail IncMail.exe """IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality""" N InControl Desktop Manager DMHKEY.EXE For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs N Incredimail IncMail.exe """IncrediMail"" is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality""" N Incredimail incredimail.exe """IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality""" X Index Service dllhost32.exe AGOBOT.CH WORM! U Index Washer WashIdx.exe "Windows_Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG" X Indexindicator Indexindicator.exe /check Lazar TROJAN! N IndexSearch IndexSearch.exe Associated with PaperPort scanner software from ScanSoft X ine svchosts.exe WIN32.RBOT.BNL WORM! X Inet DataBase Inetdbs.exe W32.QEDS WORM! X Inet Delivery inetdl.exe Inet_Delivery adware X Inet Delivery inetdl_2.exe Inet_Delivery adware X Inetapi Netapi.exe NETDEVIL.14 (NetDevil 1.4) VIRUS! U inetcntrl inetcntrl.exe Bsafe Online - internet filter U Inetd INETD32.EXE "Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation" U inetinfo.exe inetinfo.exe "Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code ( more)" X inetinfomon manager inetinfomon.exe DONBOMB.A TROJAN! X inetmgr inetmgr.exe Actual Names (AdvSearch) Internet Keywords parasite X InetMSN msnet.exe variant of the SDBOT WORM! X InetServices wsock32.exe Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN! U Info Select is.exe Info Select from Micro Logic - personal information manager X Info32x Info32x.exe GEMA TROJAN! U InfoPenMSN InfoPenIM.exe InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand U Infra-red Monitor IRMON.EXE System Tray access to infra-red devices. Not required unless you use infra-red devices X infus infus.exe Adult content dialler U Infuzer Infuzer.exe "Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities""" X infwin infwin.exe Msview parasite variant X Init32 Init32.exe W32.WINEX.A TROJAN! X Initial Page install.exe """EasySearch"" browser hijack installer" Y Initialize8x8 8x8_init.exe Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay X injob injobs.exe Trojan.Binjo TROJAN! N Ink Monitor InkMonitor.exe Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line N InkWatch InkWatch.exe Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line Y InoRPC InoRpc.exe Associated with eTrust Antivirus/InoculateIT Y InoRT InoRT9x.exe Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here U InoTask InoTask.exe Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here X InstaFinderK InstaFinderK_inst.exe InstaFinder adware N InstallAurealDemos InstallAurealDemos.js Used to initialize the Aureal A3D demos InstallShield wizard U InstallBuddy Ibtna.exe "InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync" X Installed shell32.dll Office.exe... variant of the LOVGATE WORM! X Installer dial.exe Malware - detected by Kaspersky antivirus as trojan-dropper.win32.agent.mm X Installs SP2 ?? variant of the RANDON.AN WORM! X Instance 001 ?? W32/Alasrou-A WORM! X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Access ?? Electronic_Group/InstantAccess premium rate adult content dialer variant X Instant Buzz Daemon IBDaemon.exe Instant_Buzz adware N Instant Update Center reminder.exe "From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG.? PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner" U Instant Wireless Configuration Utility WPC11Cfg.exe Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration U Instant Wireless Configuration Utility WUSB11cfg.exe Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration N InstantAccess INSTAN~1.EXE From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs U InstantDrive InstantDrive.exe Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer?s hard drive. Part of InstantCD/DVD burning software X InstantPleasure instantpleasure.exe Adult content dialler X InstantPleasureXXX instantpleasurexxx.exe Adult content dialler N InstantTray PCLETray.exe Pinnacle_InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually.. X instit instit.bat OPASERV.H VIRUS! X instit INSTIT.BAT OPASERV.K VIRUS! X intdctrr idctup20.exe SafeSurfing parasite variant U Intel Active Monitor imontray.exe "System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you ""overclock"" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards" U Intel File Transfer xfr.exe Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients U Intel PDS pds.exe Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled U Intel Product Number Utility IntelProcNumUtility.exe Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here N Intel PROSet Tray Icon promon.exe System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features X Intel system tool hookdump.exe Topantispyware adware - also detected as the SPYRE-H TROJAN! X Intel system tool winnook.exe Troj/Spyre-C Trojan! A.K.A WIN32.TOPANTISPYWARE.L X Intel system works iis.exe RBOT.QGA WORM! N Intel˝ Common User Interface igfxtray.exe "Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel" X intel32.exe intel32.exe SmitFraud alias FakeAle or SPYJACK-B TROJAN! X InteliSys smss.exe "Advertisingvision adware - file is located in C:\Windows or C:\Winnt, and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file which would normally NOT figure in Msconfig/Startup!" X intell32.exe intell32.exe SmitFraud alias Desktophijack.C TROJAN! U IntelliPoint point32.exe Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features U Intellitype type32.exe "For MS programmable keyboards. If you disable Intellitype in Startup, any ""Hot Keys"" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them" U IntelMem IntelMem.exe "Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line" U IntelProcNumUtility cpunumber.exe Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here Y IntelWireless ifrmewrk.exe Associated with the Intel PRO/Set Wireless software. Y InterCheck Monitor Icmon.exe Part of Sophos ant-virus sofware X Interdll Interdll.exe DELF family of VIRUSES! X Internal ?? SMOTHER & TRANSLAT VIRUSES! X Internal ?? FORTNIGHT.D VIRUS! X InternalSystray Kazza.exe "OPTIXPRO.12.C VIRUS! Note - unlike the valid KaZaA executable, this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP)" X internat internat.exe TROJ/LYDRA-F TROJAN! X internat internat.exe Troj/Lydra-B Trojan! X Internat msgsrv32.exe TROJ/NYRUBOT-A WORM! X Internat systray.exe "IRC.ALADINZ.P TROJAN! ** Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file" X Internat Conf bootconf.exe "Homepage hijacker, redirecting to coolwwwsearch.com; see for example here" N internat.exe internat.exe Language selection icon in system tray X Internat.exe internat.exe "NETSNAKE VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a ""?"" icon wheras this version resides in %windir% and has a ZIP icon" X Internat32 internat32.exe Octa-B trojan infection X internct WinSocks5.exe GRAYBIRD.F VIRUS! X Internet Internet.exe Troj/PWS-CS TROJAN! X Internet recruit.exe W32/Rbot-AJG WORM! X internet smss.exe Troj/Mifeng-K TROJAN! U Internet Answering Machine IAM.exe From Callwave It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access U Internet Answering Machine IAMNET~1.EXE From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access X Internet Config svchosts.exe SDBOT WORM! X Internet Connection Wizard ?? Troj/SmutSrch-A Trojan! X Internet Connection Wizard stisvsq.exe EasySearch adware X Internet Content Publisher ICP.EXE W32/RBOT-UD WORM! U Internet Download Accelerator ida.exe Internet_Download_Accelerator download manager X Internet Exploere Services urlmon32.dll.exe EVIAN.C VIRUS! X Internet Explorer http.exe "Added as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed." X Internet Explorer IEXPLORE.EXE Rbot-EY worm infection X Internet Explorer iexplorer.exe "LORSIS VIRUS! Note - the valid Internet Explorer would not normally run at startup unless added manually by the user and would not run from the registry ""RunServices"" key as this does" X Internet Explorer IExplorer.exe Troj/Nethief-O Trojan! X Internet Explorer Security iexplore.pif W32/Rbot-ALQ WORM! X Internet Explorer Updater iexplorer.exe REUR.B VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe) X Internet Explorer Updater lexbac.exe DOWNLOAD VIRUS! U Internet History Eraser HERASER.exe Internet History Eraser - deletes your browsing tracks X Internet Loader1 MSInstall61.exe KWBOT.B VIRUS! X Internet Mail and News ?? Troj/SmutSrch-A Trojan! X Internet Mail and News msqdevl.exe EasySearch adware X Internet Optimizer optimize.exe Internet_Optimizer parasite X Internet Protocol Configuration Loader ipcl32.exe SDBOT TROJAN! X Internet Send More log.exe Unidentfied adware X Internet Service intersvc.exe W32/SPYBOT-DE WORM! X internet service ssvhost.exe variant of the WIN32.RBOT WORM! X internet service syscfg32.exe W32/RBOT-QS WORM! X Internet Services internet.exe W32.MYTOB.BT WORM! X Internet Services interserv.exe RBOT.BNT WORM! X Internet Services systemdev.exe W32/Sdbot-PW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X INTERNET SERVISES winz32.exe KWBOT.Z VIRUS! Y Internet Sharing Server iss_srvr.exe Intel AnyPoint internet sharing software X Internet Suspention story.exe WOOTBOT.HV WORM! N Internet Sweeper Sweeper.exe Internet Sweeper - removes unnecessart left over files after browsing the internet U Internet Timer ITIMER.exe Shareware dial-up connection call cost calculator from Ratsoft X Internet.exe Internet.exe MAGICCALL VIRUS! X internet.exe yinyin3345.vbs XM97/YINI-A macro VIRUS! X INTERNET_SERVISES winz32.exe SDBOT.Q WORM! X Internet2 Optimizer wkfix.exe variant of the WIN32.RBOT WORM! X InternetWasherPro or Internet Washer Pro iw.exe "Internet Washer manages temporary browser files, cookies, etc - a \'trial\' Internet Washer Pro seems to have been widely stealth-installed around March 2003" U InternodeUsage mum.exe Australian ISP's free monthly download meter X Internt Internt.exe PEEPER or CARUFAX.A VIRUSES! X Intersoft Msngr intersoftmsngr.exe W32/AGOBOT-NW WORM! N InterTrust Quick Start it_cpq~1.exe InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business X InterU WINDRV.EXE IRCINTER.A VIRUS! N Intervideo WinCinema Manager WinCinemaMgr.exe WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs N Intervideo WinScheduler WinScheduler.exeSchSvr.exe "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs" U InterWARN interwarn.exe "InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs" X Intespention IEXPLORE.exe W32/Forbot-FL WORM! Note: This is not the legitimate Windows Process IExplore.exe (Which is found in the Internet Explorer folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item unless you put it there. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Intmgr Intmgr.exe GEMA TROJAN! X Intrenat Intrenat.exe LEMIR.E VIRUS! N Introducing Media Manager SPLASHA.EXE MS Media Manager tour. Not required N Introduction-Registration ?? "For Compaq PC's. Should only run first time, PC Introduction & Compaq registration" X IntruderAlert ia99.exe Intruder Alert '99 from Bonzi - spyware X Ioadqm Media Player.exe HAWAWI VIRUS! U iolo Task Agent Task_Agent.exe iOlo System Mechanic Task Agent. Scheduled maintenance N iolo Utility Bar SMUtilityBar.exe "Iolo ""System Mechanic"" Utility_Bar - can be launched manually." U Iomega Automatic Backup or Iomega Automatic B ibackup.exe Iomega Automatic Backup - automatic backups for use with Iomega portable HDD? N Iomega Backup Scheduler dtiom98.exe Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs U Iomega Disk Icons or Iomega Drive Icons IMGICON.EXE "Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running" U Iomega ImIconXP imiconxp.exe "Iomega REV_System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks." N Iomega Startup Options IMGSTART.EXE Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs N Iomega Watch IOWATCH.EXE Used by Iomega drives. Available via Start -> Programs N IomegaWare COMMANDER.EXE Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs U Iomon98.exe Iomon98.exe PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang X IP Stack ipstack.exe AGOBOT.CW WORM! N iPalm mon.exe Installed with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded X IPC Connection ipcconn.exe W32/Rbot-AEG Worm! X IPC Spool Manager winspec.exe W32/SDBOT-BLU WORM! X IPC Spool Manager wnmgre.exe W32/SDBOT-ZC WORM! X ipcfg.exe ipcfg.exe Adware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan X IPConfig svcxnv32.exe HACARMY.E TROJAN! X IPConfig svcxnw32.exe variant of the HACARMY.E TROJAN! X IpCtrl ipcon32.exe unidentified WORM or TROJAN! X IPInSightLAN 01 ipclient.exe "Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly ""phones home"" and wastes resource - hence the ""X"" status" N IPInSightMonitor 01 ipmon32.exe Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information Y IPinst ?? For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out X ipmon.exe ipmon.exe RECERV or R3C.B VIRUSES! X Ipnuker Ipnuker.vbs VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder. X iPOD USB Driver IPODUSB.EXE variant of the WIN32.RBOT WORM! X iPod USB Service iPODService.exe "variant of the WIN32.RBOT WORM! - Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program Files\iPod\bin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup!" U iPodManager iPodManager.exe "Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods" X IPOT Service Drivers compaq.exe variant of the FUROOTKIT TROJAN! X IPOT USB Service DRIVER hpsebc087.exe W32/SDBOT-WA WORM! X IPOT USB Service DRV32 hpsebc08.exe W32/SDBOT-WH WORM! N iPrint Tray iprntctl.exe Novell˝ iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net. U iProtectYou ip.exe iProtectYou - internet filtering/parental control and network monitoring software X iprun iPY.exe -h iProtectYou SPYWARE! U ipsecdialer IPSECD~1.EXE -run_only_if_connected -auto_initiation The Cisco VPN_Client lets local users gain Administrator privileges on the operating system U ipsecdialer ipsecdialer.exe The Cisco VPN_Client lets local users gain Administrator privileges on the operating system Y IPSecMon IPSecMon.exe Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet X IPTable Configuration Winipcfgs.exe variant of the WIN32.RBOT WORM! X IPv6 Helper Driver csass.exe AGOBOT.TC WORM! X IPv6 STUN Service netstun.exe variant of the W32/SDBOT WORM! X ipwf ipwf.exe Trojan.Schoeberl TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X ir_ftp ir_ftp.exe IRFTP VIRUS! X ir_ftp irwftp.exe BANCOS.H VIRUS! X irc session sessionmgr.exe W32/SDBOT-ACE WORM! Y IREIKE IreIKE.exe Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet N iRis Active Monitor winmon32.exe "Iris Antivirus - discontinued, replace with good alternative" N iRiS AntiVirus Active Monitor WIMMUN32.exe "Iris Antivirus - discontinued, replace with good alternative" U iRiver AutoDB MLService.exe Associated with the iRiver Music Manager N iRiver Updater Updater.exe Updates for the iRiver Music Manager - used with their digital music players U IrMon IRMON.EXE System Tray access to infra-red devices. Not required unless you use infra-red devices X Irwftp ?? BANCOS.CR trojan infection X irwftp ftpmon.exe TROJ/BANCBAN-BO TROJAN! X irwftp iexplorer.exe TROJ/BANKER-AN TROJAN! U IrXfer IrXfer.exe Microsoft Infrared Transfer application N IS CfgWiz cfgwiz.exe Norton Internet Security configuration wizard X Isass Isass.exe BACKDOOR.FUTRO TROJAN! N isdbdc isdbdc.exe For Compaq PC's. May install properties in dial-up networking when you register with an ISP U isDeleteMe isDel.bat Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product. N ISDN Monitor Linksts.exe "Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon" U ISDNwatch IWatch.exe "FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks""" U ISHelp help.exe ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it. N ISLP2STA ISLP2STA.EXE Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though Y islp2sta islp2sta.exe A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers. U iSpyNOW ispynow.exe iSpyNOW - remote monitoring and surveillance software X Israfel Israfel.vbs GAGGLE.D VIRUS! X issEnc32Svr issEnc32.exe variant of the WIN32.RBOT WORM! U ISStart ISStart.exe "LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation" Y ISSVC ISSVC.exe Part of Norton Internet Security Suite X IST Service istsvc.exe ISTBar foistware X ist service uninstall HIDES.EXE ISTBar parasite related X ist service uninstall mstasks2.exe ISTBar parasite related X ist service uninstall wow.exe ISTBar parasite related X istinstall_zazzer.exe istinstall_zazzer.exe Unidentified adware downloader/installer N ISUSPM Startup ISUSPM.exe InstallShield Update Service related; Automatically searches for and performs any updates to the software. Not required. N ISUSScheduler issch.exe InstallShield Update Service Scheduler; automatically searches for and performs any updates to the software so you?re always working with the most current version. Not required. X isystem isystem.exe Troj/Chorus-A TROJAN! Searchforfree Browser hijacker. U Itk Itk.exe "In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it" U iTouch iTouch.exe "iTouch loads the iTouch configuration program for Logitech keyboards. It?s needed if your keyboard has shortcut buttons and if you use them. It?s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock" N ItsDeductiblePopUp ItsDeductible.exe ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip X Itunes dials.exe Detected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus. Note: A Url is not available at this time. X ITUNES itune.exe W32/RBOT-ZU WORM! X ITUNES itunes.exe W32/OSCABOT-L WORM! Y iTunesHelper iTunesHelper.exe Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation N Iusage netdet.exe Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up N IVPServiceMgr ivpsvmgr.exe "Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba?s equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates. Not required." U IW ControlCenter iwctrl.exe "Pinnacle_Systems InstantWrite - enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM." U iwctrl iwctrl.exe "Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis" X I-Worm.GiGu uGiG.eXe GINK VIRUS! X ixplore ixplore.exe "unidentified WORM or TROJAN! - NOTE: although this file is placed in the Internet Explorer folder in Program Files, it is most certainly malware, and not to be confused with the legitimate IE executable, which is spelled iExplore.exe!" X iyelejiv yujixit.exe SDBOT.BJK WORM! N j2 Tray Menu HotTray.exe eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here X JA Cfg Util v2 jacfg2.exe W32/RBOT-AL WORM! U Jammer jammer.exe "Jammer by Agnitum - ""Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web""" X Jammer2nd JAMMER2ND.EXE W32.NETSKY.Z WORM! X Jammer2nd Jammer2nd.exe W32.Netsky.Z WORM! X Java applet javaup.exe W32/Sdbot-ACF WORM! X Java Runtimes iexplore.exe KILLAV.B VIRUS! Note - this is not the valid IE (iexplore.exe) file as it's located in C:\Winnt\Java\Java rather than C:\Program Files\Internet Explorer X Java Virtual Machine javaw.exe variant of the WIN32.RBOT WORM! X JavaScript Debugging Service JsDbgMan.exe W32.Derdero.E WORM! X JavaUpdate0.07 ?? BACKDOOR.JUPDATE TROJAN! X JavaUpdateSched jusched32.exe Troj/Bckdr-CKB TROJAN! X JavaVM java.exe "W32.MYDOOM.M or W32.MYDOOM.N or W32.MYDOOM.BB WORM! **Note - This is not the valid Windows ""java.exe"" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt" X jawa32 jawa32.exe Backdoor.Agent.bg trojan X Jawa322 jawa32.exe variant of the Backdoor.Agent.bg trojan N JB Jiffybar.exe """Get Paid As You surf"" application" N Jet Detection ADGJDet.exe Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection Y JetAdmin Discovery Indicator HPJETDSC.EXE "HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator" X jete yujixit.exe SDBOT.BRT WORM! X jijbl ezlwy.bat REDDW VIRUS! U JobHisInit JobHisInit.exe Used by Ricoh network printers to enable network printing from the client U Job-oversigt taskmon.exe "Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)" U JogServ2 or Jog Serve JogServ2.exe """Jog Dial"" on a Sony Vaio laptop.? The dial can select various functions such as control audio. Needed if you use its features" X Jreg Jreg2b.exe BroadcastPC adware variant X Jufualt winxp2.exe W32/SDBOT-AAB WORM! N jusched jusched.exe Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel X jushed32.exe jushed32.exe CoolWebSearch parasite related X jutsu jutsu.exe W32/RBOT-LS WORM! U jv16 PT TempFileTool TempTool.exe jv16 PowerTools' temporary file remover U jv16PT - Privacy Protector Task.jvb jv16 PowerTools 2005 - Privacy_Protector allows you to protect your privacy by clearing the unwanted history items and cookies from you computer every time you startup your computer. U Jv16pt Network Resident jv16pt_network.exe jv16 PowerTools' network resident program. Only needed if you are using the program's network features X jvdnlssn fljzsshc.exe Flingstone.com adware - and its Golden Palace Casino program X JVM0.12 ?? TEADOOR-A TROJAN! X JVM0.14 ?? TROJ/TEADOOR-B TROJAN! X jxef1104 jxef1104.exe W32/XIPI-A WORM! X K2ps_full.task K2ps_full.exe JUNTADOR.K VIRUS! N K6CPU.EXE K6CPU.EXE Authenticates CPU as K6 in system properties X Kadoc ?? Staprew TROJAN! X Kadoc ?? Staprew TROJAN! X kak kak.hta KAKWORM VIRUS! U Kalibump Kalibump.exe Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy X kalvsys ?? EliteBar/SearchMiracle adware N Kana Reminder Reminder.exe Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time U Karen's Once-A-Day II PTOAD.exe "Karen's_Once-A-Day_II is a scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time Windows starts each day, or the first time a particular user logs on each day." U KASP OESpamTest.exe Kaspersky_Anti-Spam X Kasper Antivirus KASPERANTIVIRUS.EXE SPYBOTER.GEN TROJAN! X Kasper Antivirus KASPERANTIVIRUS.EXE variant of the W32.SPYBOT WORM! Y Kaspersky Anti-Hacker KAVPF.exe Kaspersky Anti-Hacker firewall X Kaspersky Antivirus KasperskyAV.exe variant of the WIN32.RBOT WORM! X KasperskyAv kaspersky.exe W32.MIMAIL.T WORM! **Note - This has nothing to do with Kaspersky AntiVirus X KasperskyAVEng Kasperskyaveng.exe W32.NETSKY.V WORM! Y kav50 kav.exe Part of Kaspersky Anti-Virus program X KAVFOX win1ogoin.exe Troj/GWGhost-M TROJAN! X KAVPersonal svchost.exe "Troj/Lineage-V TROJAN! Note:This is NOT the legitimate Windows svchost.exe process, which should NOT figure in Startup!" Y KAVPersonal50 Kav.exe Kaspersky Anti-Virus Personal 5.0 Y KavPFW KavPFW.exe KingSoft Personal Firewall X KavRuns Windll.exe TRYNOMA VIRUS! Y KavStart KAVStart.exe KingSoft Personal Firewall X KavSvc ?? QOOLOGIC TROJAN! X kavsvc ?? "QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe)" Y kavsvc kavsvc.exe Kaspersky antivirus X KAVutil ?? WINTOO.B VIRUS! N KAZAA kazaa.exe "KAZAA is a file-sharing program which unfortunately being ad-based includes ""Cy-door"" adware. Check here for information about ""Cy-door"" and here for a program that can remove it" X Kazaa Download Accelerator Updater ?? SafeguardProtect/Veevo X Kazaa Download Accelerator Updater (required) ?? SafeguardProtect/Veevo X Kazaa lptt01 or Kazaa ml097e kazaa.exe "Variant of the RapidBlaster parasite (in a ""kazaa"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name" X KAZAACuf ?? KITRO.D (or ARGEN.A) VIRUS! N kazaalite kazaalite.exe "Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms" N KaZooM KaZooM.Exe "KaZoom from Blue Haven Media - ""add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches""" Y KB891711 KB891711.exe "Installed by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup." U KBD KBD.EXE Multimedia keyboard manager. Required if you use the multimedia keys U KBD MediaCenter MEDIACTR.EXE Multimedia keyboard manager. Required if you use the multimedia keys X kbddrv32 kbddrv32.exe CRYPTER.A trojan infection X kbddrvinf kbddrvinf.exe CRYPTER.A trojan infection N KCeasy KCeasy.exe KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella. U KClient kstatus.exe KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet. N kdx KHost.exe "KonTiki Secure Delivery Plug In related. ""The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers""" U KE9801 DriBat32.exe KE-9801 multimedia keyboard - required if you use the multimedia keys X Keenvalue Keenvalue.exe eUniverse/KeenValue adware U KEMailKb KEMailKb.EXE Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down U Kerio VPN Client kvpnclient.exe Kerio VPN Client X kern64dll ?? PWSteal.Tarno.J trojan infection. X Kernal Fault Check ntosrkl.exe variant of the W32/SDBOT WORM! X kernctl32 "rundll32 kctl32.dll,initialize" Trojan.Proxy.Agent.AT infection X Kernel bboy.exe MUMU.B VIRUS! X KERNEL 32 SKERNEL32.com W32/SEMAPI-A WORM X Kernel Faults ftphost.exe RBOT.BHU WORM! X Kernel Loader ntkrnl.exe CERVIVEC.A VIRUS! X Kernel Services service32.exe TROJ/PRX-B TROJAN! X kernel system daemon ACTIVAT0R.exe RANDEX.AW VIRUS! X Kernel_check wmiprvse.exe W32/SONEBOT-B WORM! X kernel12.exe kernel12.exe unidentified WORM or TROJAN! X kernel32 kern32.exe BADTRANS.A VIRUS! X kernel32 kernel.dli NETDEVIL.B VIRUS! X Kernel32 Kernel.dll REDLOF.M VIRUS! X kernel32 kernel32.dlI NETDEVIL.15 VIRUS! X Kernel32 Kernel32.exe "number of VIRUSES - such as BABYLONIA, KERNEL and HOOKER" X Kernel32 Kernel32.win GAGGLE.D VIRUS! X Kernel32 kernel32s.exe W32/SDBOT-PU TROJAN! X Kernel32 krnl32.exe EPON VIRUS! X kernel32dll guardpc.exe W32/FORBOT-CU WORM! X KernelCheck ?? unidentified TROJAN! N KernelFaultCheck dumprep 0 -k "Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out" N kernelfaultcheck dumprep 0 -u "Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out" X KernelFaultChk sms.exe "DEADHAT VIRUS! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u""" X Kernell systems.exe TARNO.C VIRUS! X Kernell32 Kernell.dll DESTINY VIRUS! X KernellApps csrss.exe BANCBAN-AC TROJAN! X KernellApps lexplore.exe Troj/Bancban-BS TROJAN! X KernellApps svshosti.exe Bancban-V trojan infection X Kernelw Kernelw32.exe INDOR.E VIRUS! X key sys_xp.exe BEAGLE.AC WORM! X key sysxp.exe BEAGLE.AB WORM! X key winxp.exe BEAGLE.AG WORM! X Key Logger csrss.exe W32.Buchon.A worm. X Key1 Rlid.exe LIXY VIRUS! Y KeyAccess keyacc32.exe "KeyServer KeyAccess client software - ""when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure""" X Keybdcntl keybdcntl.exe Crypter.C trojan variant infection U Keyboard Manager MMKeybd.exe Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as MULTIMEDIA KEYBOARD Y Keyboard Preload Check Preload.exe Millenium Multi-Function Keyboard driver X keyboard_enum keyboard_enum.exe TROJ/BDOOR-GP TROJAN! U KeyMaestro kmaestro.exe Multimedia keyboard manager. Required if you use the multimedia keys U keymap keymap.exe System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game X keymgrldr "rundll32 setupapi, InstallHinfSection... keymgr3.inf" CoolWebSearch parasite related U KeyPatrol KeyPatrol.exe "KeyPatrol - detects Key Loggers (""keyboard loggers"" or ""keyloggers"") using both behavioral and pattern-matching algorithms" U keystroke keystroke QuickLaunch is a spyware program that logs keystrokes and captures screenshots. If you didn't install this yourself remove it. N KeyText KeyText.exe Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs U KeyWallet KWallet.exe """KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually""" X kfienq masbl.bat KIFER VIRUS! X kgjdi27 kgjdie27.exe Sdbot.AP WORM! N khooker khooker.exe SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required U KICKMON.EXE KICKMON.EXE "KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required" U Kill Popup KillPopup.exe KillPopup Pop-up stopper N Kinberlink Kinberlink.exe Kinberlink network messaging. Available via Start -> Programs U KK Loader loadkk.exe "KeyKey XP Professional from KeyKey.com. ""Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user.""" U KLog Keyspy.exe Hacktool.KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself! U klp explorer.exe "ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in a C:\WINDOWS\System\PAL\CSS folder (Win 98/ME) or in the C:\Winnt\System\PAL\CSS or C:\Windows\System\PAL\CSS subfolder (Windows 2000 and Win XP)" U klp run32dll.exe PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online U KM9801U MMHotKey.exe Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen U kmw_run.exe kmw_run.exe Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features U kmw_show.exe kmw_show.exe Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features N Kodak Batch Transfer pezdow1.exe "Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC" U Kodak EasyShare software EasyShare.exe Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually. N Kodak Picture Easy *.* Batch Transfer PezDownload.exe "Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version" N Kodak Picture Transfer Software pts.exe Looks for Kodak camera connection and media insertion. Available via Start -> Programs N Kodak Software Updater ?? Software updater for Kodak Easyshare digital cameras Y KodakCCS KodakCCS.exe Kodak DC File System Driver U Komunikator tlen.exe Tlen - a Polish language Instant Messaging client N Konni Symbol Autostart KonniSymbol.exe Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5 N kontiki kontiki.exe Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops Y KPDrv4XP KPDrv4XP.exe MediaKey USB Keypad Driver U KREC32 krec32.exe StarrCommander Pro Keystroke logging software X Krnlcheck csrss.exe "BACKDOOR.BOTNACHALA TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!" U Krnlmod Krnlmod.exe "Keylogger - see here. Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't, treat it as ""X"" and uninstall or remove via Spybot S&D (for example)" X Ksrv32 Ksrv32.exe W32/Agobot-PI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. U ktchnsnk ktchnsnk.exe HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted X KV2005 word.EXE TROJ/VB-IW TROJAN! X kv3000 lover.vbe ZSYANG.B VIRUS! X kvern16.dll ?? DailyWinner adware X kw3eef76 ?? LZIO.com adware downloader N kX Mixer kxmixer.exe Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards. X KYK Control Settings KYSVCXD.EXE variant of the WIN32.RBOT WORM! X KYM Control Settings phqghum.exe RBOT.BQD WORM! X L4r1$$a L4r1$$a.pif W32/ASSIRAL-C WORM! X laltin L90112201.Stub.exe "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X LAN Driver landriver32.exe RBOT.BT WORM! X lanbrup lanbrup.exe SafeSurfing adware U LanguageMonitor Oplmsb01.exe OKI Printer language support monitor X LanGuard languard.exe Adware downloader - also detected as the TROJ/SECONDT-C TROJAN! U LanSpeed2 LanSpeed2.exe Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card) U laokey.exe LaoKey.exe Lao Script for Windows (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications. U LapLink scheduler Llsched.exe Utility that automatically performs file transfers as unattended background operations X lar ?? ROXY.C VIRUS! X Lar Llass.exe INOR-A VIRUS! X LARISSA ANTI VIRUS LARISSA_ANTI_VIRUS.exe Klassir TROJAN! X LAsIAf32 RePEAtLD.exe REPEATLD VIRUS! Y LASTinst ?? For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out U LaunApp LaunApp.exe Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 U Launch Ai Booster OverClk.exe The ASUS Ai_Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup. N Launch YahooPOPs! at Windows startup YAHOOPOPS.EXE YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs U LaunchAp LaunchAp.exe Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 U LaunchApp Alaunch.exe Acer Launch tool utility on laptops U Launchboard lnchbrd.exe """LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions""" X Launcher launcher.exe Spyware component related to DownloadWare and found in Program FilesKFH N Launcher relaunch.exe Audio Applications Launcher for the Philips Rythmiic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs X Lavasoft Ad-Aware Ad-Aware.exe "W32/RBOT-SO WORM! - NOTE: this is NOT the popular spyware remover, as described here" U Lavasoft Adwatch Ad-watch.exe Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system Y laxmsp32.exe laxmsp32.exe Lexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work? X Laz Kernn.exe TROJ/BANCOS-LN WORM! U LCDC LCDC.exe LCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins Y LCDPlayer LCDPlyer.exe Related to SuperAdBlocker N lcfep lcfep.exe "Tivoli ±TME? System Tray icon - ""\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally""" U LClock lclock.exe LClock is a program that makes the Windows' clock look like a Windows Longhorn Clock. X lcvga lcvga.exe Hostol-A TROJAN! X ld ld.exe CoolWebSearch parasite variant N LDM ?? "Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech. Also listed under Logitech Desktop Messenger" X ldriver ldriver.exe Troj/Chorus-A TROJAN! Searchforfree Browser hijacker. U LED TRAY LEDTRAY.EXE Installs a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work U ledpointer CNYHKey.exe Chicony Electronics Multimedia Keyboard Hotkey Driver N LeechGet LeechGet.exe LeechGet download manager X LetsSearch LetsSearch.exe BrowserAid/BrowserPal foistware variant U Lexmark **** Series lxbkbmgr.exe "Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut" U Lexmark **** Series lxbmbmgr.exe "Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut" U Lexmark **** series lxbtbmgr.exe "Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut" Y Lexmark 2200 Series Button Manager lxbvbmgr.exe Lexmark printer button manager. Required for correct operation Y Lexmark 3100 Series lxbrbmgr.exe Lexmark printer button manager. Required for correct operation. U Lexmark X5100 Series lxbabmgr.exe System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut Y Lexmark X6100 Series lxbfbmgr.exe Lexmark X6100 printer button manager - required for correct operation U Lexmark X74-X75 lxbabmgr.exe System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut Y Lexmark Xxx Button Monitor ACMonitor_Xxx.exe "Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation" N LexmarkPrinTray printray.exe Lexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray X lexplore lexplore.exe "W32.BROPIA WORM! - NOTE: this process is spelled ""LEXPLORE.exe"" (with an ""L""), not Iexplore.exe like the familar Internet Explorer executable!" N lexpps lexpps.exe "For Lexmark printers. From Lexmark: ""This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all"". It is known that firewalls can however alert you to ""lexpps.exe"" requesting server privileges" U LexStart lexstart.exe Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance X Lfh Lfh.exe TROJ/ZAURGA-A TROJAN! U Lfsndmng lfsndmng.exe "LightningFAX Enterprise Fax Server - ""puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents""" N lhttseng ?? Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine X li01f948 ?? LZIO.com adware downloader N LicCrtl runservice.exe "Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program" U LicCtrl ?? "Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program" U LidPolicy pwrschem.exe A utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery. N LifeScape Media Detector PicasaMediaDetector.exe Media detector for Picasa's automatic photo organizer X lify yujixit.exe variant of the W32/SDBOT WORM! U Lightning Download Lightning.exe "Lightning_Download download manager. Can be launched manually, but will need to start up if you want it to ""catch clicks"" off Internet Explorer" X Limewire LimeWire.exe W32/Rbot-AGH WORM! N LimeWire x.x LimeWire.exe LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware X Limpet explorer16.exe W32/Rbot-AJD WORM! X li-multi**** li-multi****.exe Adult web-dialler - **** is random N Line Speed Meter V3.0 LineSpeedMeter.exe LineSpeedMeter - detect the download and upload speed of your internet connection N Linksts linksts.exe "Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon" X Linksts linksts.exe "Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon" X Linux Linux.vbs LOVELETTER.AS VIRUS! U LiquidView lviewj.exe """Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display\'s native resolution. The software lets you increase the size of items that are hard to read on your monitor""" X Lisa Lisa.exe DIAL/SCOM-D premium rate adult content dialer. X li-speed**** dlres.exe Adult web-dialler - **** is random X List checker 32 BIT list32.exe W32/Rbot-AHO WORM! X Litebot ?? Troj/Litebot-A TROJAN! N LIU LIU.exe "Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway" N LIU Rubicon.exe "Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway" N Live Menu Dllcmd32.exe eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here N LiveMonitor LMonitor.exe MSI Live Update2 - auto-detects and suggests the latest BIOS/Driver/Utilities information N LiveNote Livenote.exe Asus graphics card driver live update feature X LiveSexCams LiveSexCams.exe Premium rate adult content dialer U LiveUpdate LiveUpdate.exe Web-update utility as used by various types of software - see http://liveupdate.openwares.org/ X li-vita**** li-vita****.exe Adult web-dialler - **** is random X Livre Dibane.bat W97M.BANEDI VIRUS! X llsass llsass.exe "TROJ/PROXY-GG TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." N LM Status LMSTATUS.EXE Xerox WorkCenter XE - language monitor status application U LManager HotkeyApp.exe Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio U LManager QtZgAcer.EXE Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio U LManager QtZpAcer.exe Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio X lMAPl lMAPl.exe W32/AGOBOT-RE WORM! U LMgrOSD OSDCtrl.exe "OSD (on-screen-display) utility - Part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language - User's choice!" N LMonitor LMonitor.exe Lmonitor utility comes with MSI\'s LiveUpdate Version 3 - periodically checks for updated drivers and utilities X lmrt lmrt.exe Unidentified adware N LMSTATUS LMSTATUS.EXE Xerox WorkCenter XE - language monitor status application X lmu LMU.exe "Downloader trojan, recognized by Kaspersky antivirus as Backdoor.Win32.Agent.bg" X lnternet Explorer AMSNDMGR.EXE "KWBOT.R VIRUS! Note that the ""l"" is a lower case ""L"" and not an upper case ""I""" X load ?? W32.Kelvir.AI WORM! X load _Kerne1.exe Troj/Lineage-AN TROJAN! X load Internat.exe PWSteal.Wowcraft TROJAN! X Load mdm.exe Backdoor.Binghe TROJAN! X load msgsr32.exe W32/SDBOT-QR WORM! X Load MyGame.exe W32/LameYear-A Worm! X load rundll32.exe PWSteal.Wowcraft TROJAN! X load svchsot.exe Troj/GWGhost-O TROJAN! Note: (svchsot.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X load svhost32.exe PWSteal.Wowcraft TROJAN! U LOAD WB LOADWB.EXE "Part of Stardock's WindowBlinds custom desktop program. ""WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much?more"". If you use it - keep it if not then uninstall it" Y load= 01comm32.exe "Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those." X load= a1g.exe ATAK.B WORM! N load= adw30.exe After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95 Y load= AICLIENT.EXE Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system U load= asistat.exe Status monitor for an NEC SuperScript printer Y load= Bfrecv.exe Bitware modem driver X load= dapdll.exe W32.ATAK.E WORM! U load= esspk.exe Speakerphone capability through a soundcard for an ESS modem X load= hint.exe W32.ATAK WORM! Y load= hotkey.exe Solo 5300 display driver for Win2K on some Gateway laptops N load= HPWHRC.EXE Loads the Status Window software for the HP Laserjet printers X load= inetinfo.exe TROJ/PROXY-GG TROJAN! X load= msater.exe RETSAM VIRUS! X load= shambl3r.exe REMABL VIRUS! X load= Spoolsv.exe "CIADOOR.B VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file" X load= svhost32.exe TROJ/LINEAGE-AB TROJAN! N load= vi_grm.exe Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings Y load= wpshrc.exe Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others) X load32 1111a.exe W32.Dumaru.AH WORM! X load32 l32x.exe W32.DUMARU.Z W32.DUMARU.Y or DUMARU.AD WORM! X load32 load32.exe W32.DUMARU WORM! X load32 load32.exe NIBU or W32.Bambo TROJAN! X LOAD32 Lorena.exe W32.Mapson.C WORM! X load32 netda.exe NIBU.E TROJAN! X load32 swchost.exe TURTA.A WORM! X load32 swchost.exe NIBU.I TROJAN! and the W32/Dumaru-AK WORM! X load32 winldra.exe BACKDOOR.NIBU.J or DUMARU-BI and Troj/Dumaru-N TROJANS! Note: Also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this KeyLogger. For more information Click_Here X Loadab1 explorer.exe Troj/Lineage-AJ TROJAN! Y LoadBlackD blackd.exe "This is the ""intrusion detection system"" of the BlackICE PC Protection (was Defender) firewall which loads independently of the ""user interface"" (BlackICE Utility)" X LoadDBackUp BcTool.exe GIBE VIRUS! X loaddll loaddll.exe Winvest SPYWARE! X loader loader.exe "Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe" X loader WMPLAYER.EXE Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn\'t load at startup X loader32 ?? Domcom TROJAN! X loader32 Loader32.exe unidentified TROJAN! X loadfax loadfax.exe Troj/Winflux-C TROJAN! X LoadFonts "LoadFonts.vbs, Tahoma.vbs" Homepage hijacker that changes your homepage to an adult content site X LoadGolfCourses LoadGolfCourses.exe PlayMiniGolf.com foistware - stealth installed! X Load-Guard LGuarg.exe.vbs VBS.YENO.C WORM! X LoadHTML ?? Mshtmpre adware X LoadingAgent msload32.exe OBLIVION TROJAN! X LoadingAgent ZipLoader32.exe OBLIVION TROJAN! X LoadManager msload.exe OPASERV.T VIRUS! X loadMecq0 explorer.exe MUMUBOU.C TROJAN! ** Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually X loadMecq3 rundll32.exe Troj/LegMir-AS TROJAN! X loadMect1 explorer.exe "TROJ/LINEAGE-L TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Program Files folder! Note: The LINEAGE-AD variant will drop the ct1dll.dll file in the system folder." X loadMefs rundll32.exe "TROJ/LEGMIR-JA TROJAN! - NOTE: this file is found in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!" X loadMefs rundll32.exe "Troj/LegMir-JB TROJAN! Note: This is not the legitimate Windows Process rundll32.exe, Which is found in the Windows folder(98\ME) or the System32 folder(NT\2000\XP). This trojan file is found in the Windows\inf or Winnt\inf folder." X loadMefs smss32.exe TROJ/FLOOD-EL TROJAN! N LoadMSvcmm msvcmm32.exe Auto-update for Movielink - internet movie rental System Tray access X LoadOrderVerification ?? "TRON VIRUS! * is a random file name, possibly Pthymvfr.exe" U Loadout Manager nost_LM.exe Manager for the Belkin Nostromo n50 SpeedPad game controller - see here X LoadPFW wmimgr.exe W32/Qeds-B Worm! U LoadPowerProfile ?? "Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings" X LoadPowerProfile ASDAPI.EXE CABRO VIRUS! Not to be confused with the valid entry below X LoadPowerProfile rundl.exe TOFAZZOL VIRUS! Note - do not confuse with the valid LoadPowerProfile entry above! X LoadPowerProfile Rundll.exe powerprof.dll "LOXOSCAM TROJAN! **Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe""" X LoadPowerProfile Rundll32.exe "MIROOT VIRUS! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line" X LoadPowerScheme ?? Ulubione adult content dialer U LoadQM loadqm.exe "Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the ""users choice"" recommendation. If you have problems leave it, otherwise I recommend you disable it" X loads.exe loads.exe MediaMotor/Popuppers adware downloader X loads.exe medload.exe MediaMotor/Popuppers adware downloader X loads.exe suploads.exe MediaMotor/Popuppers adware downloader X LoadService "Maaf, tempatmu bukan di sin" Troj/Kagen-A TROJAN! X LoadService Rest In Peace W32/KANGAROO-A WORM! X LoadService Virus CAGER.A WORM! X LoadSIPS ?? 123Mania adware X loadwin winset.exe TROJ/QQPASS-I TROJAN! X loadwin winsys.exe TROJ/QQPASS-J TROJAN! X LoadWindowsFile ?? DELF.B VIRUS! where is the infected file X Local Area Network OpenGL.exe variant of the WIN32.RBOT WORM! X Local Internet Connection LIC.exe W32/SDBOT-YA WORM! X LOCAL INTERNET WEB DRIVERS FOR WIN32 phqghume.exe variant of the WIN32.RBOT WORM! X Local Page http://find.naupoint.com Naupoint browser hijacker X Local runole service srvc32.exe TROJ/SMALL-DP TROJAN! X Local Security Authority Service Isass.exe W32.LINKBOT.M WORM! X Local Security Authority Service lssas.exe W32/POEBOT-J WORM! X Local Service Intenat.exe Troj/Nuclear-J TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Local-Settings-of-[User Name] ?? W32.Gavgent.A WORM! U Lock My PC lockpc.exe "Lock_My_PC . A tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse." U Logi_Mwx Logi_MwX.exe "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled" U Logi_Mwx Logi_MwX.Exe "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled" U Login winlog.exe Salfeld Child Control 2003 - parental control software X Login Screen Saver login.scr variant of the WIN32.RBOT WORM! X Login Service ?? MIGMAF VIRUS! X LoginPassport Lgnpsp32.exe REDIST.C VIRUS! X Logitech Logitech.exe RBOT.BJH WORM! X Logitech Camera Soundcane.exe SDBOT.MUC WORM! X Logitech Desktop ApPache.exe W32/RBOT-YP WORM! X Logitech Desktop IPCONN.EXE W32/SDBOT-WE WORM! X Logitech Desktop Controller wrcam.exe variant of the WIN32.RBOT WORM! N Logitech Desktop Messenger ?? "Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech" U Logitech SetPoint KEM.exe Keyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys U Logitech Utility Logi_MwX.exe "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled" U Logitech Utility Logi_MwX.Exe "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled" N Logitech Wakeup lgwakeup.exe Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images X Logitech Wireless logitechwls.exe W32/Mytob-BS Worm! U LogitechGalleryRepair ISStart.exe "LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation" N LogitechImageStudioTray LogiTray.exe Logitech Image Studio - installed with Logitech QuickCams X Logitechs Logitechs.exe SDBOT.BWE WORM! U LogitechVideoRepair ISStart.exe "LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation" N LogitechVideoTray LogiTray.exe Logitech Image Studio - installed with Logitech QuickCams N LogiTray LogiTray.exe Logitech Image Studio - installed with Logitech QuickCams U LogMeIn GUI LogMeInSystray.exe "RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone." U LogMeIn GUI ragui.exe "RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone." X Logo ?? Troj/Dloader-RH TROJAN! U Logon Loader LogonLoader.exe Logon_Loader - customize Boot & Login Screens U Logon Loader Random LogonLoader.exe Logon_Loader - customize Boot & Login Screens X Logon.exe logon.exe BKDR_ZINS.A TROJAN! X logon.exe logon.exe Zins.B TROJAN! U LogonStudio logonstudio.exe "WinCustomize LogonStudio - ""Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users""" X LogService lsass.exe "Troj/Bdoor-IU TROJAN! Note:This is NOT the legitimate Windows lsass.exe process, which should NOT figure in Startup!" X LogService wincalc.exe BACKDOOR.PAPROXY TROJAN! U LogWatch logwat95.exe Licensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see here. Not required if you already have a newer version or the patch has been applied X longos WIWT.EXE BANKER-CD TROJAN! Y Look 'n' Stop looknstop.exe Look 'n' Stop personal firewall U LookNMeet Agent.exe LooknMeet dating service X Lookup_Sys lookupsys.exe P04n trojan N Lotus Organizer EasyClip easyclip.exe """The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page."" Available via Start -> Programs" N Lotus QuickStart smartctr.exe "Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs" U Lotus SuiteStart suitest.exe "Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as ""Lotus SuiteStart 97 Edition"". All individual components available via Start -> Programs" X LowVersionSupport ?? LASTRAS VIRUS! where is the name of the file dropped by the virus X Lpr Lpr123.exe REMPSTEAL password stealer TROJAN! U LPS Lps.exe "Local Port Scanner - ""With LPS you're able to check your computer for open or listening ports""" U LPtask lptask.exe "Program Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted" X LRBZ Utility 32 lrbz32.exe W32/AGOBOT-JQ WORM! N LS120 Superdisk ?? "Supposed to accelerate transfer rate on LS-120, contributes to system lockups" X LSA lsa.exe W32/SDBOT-YV WORM! X LSA wfdmgr.exe W32.Mytob.C WORM! X LSA Service LSASS.exe "W32.Ahker.G WORM! **Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!" X LSA Shell (Export Version) LSASS.exe "several variants of the AHKER WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X lsass ?? ALADINZ.F VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! X lsass ?? EliteBar adware variant X Lsass kavmm.exe "unidentified WORM or TROJAN! - NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here . Contrary to this impostor, the legitimate file will always be located in the Kaspersky Lab folder in Program Files." X lsass lsasrv.exe W32.Mydoom.AU WORM! X lsass lsasrv.exe SAVAGE.A WORM! X lsass lsasrv.exe W32.Mydoom.AS WORM! X lsass lsass.exe RATSU.B VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! X lsass start.bat ZCREW VIRUS! X Lsass woekd.exe unidentified WORM or TROJAN! X LSASS 32 ISASS32.pif W32/ASSIRAL-C WORM! X LSASS Authority lshosts32.exe SDBOT-UY TROJAN! X LSASS Authority lsvhosts.exe SDBOT.BCE WORM! X LSASS Daemon LSASSd.exe variant of the AGOBOT/GAOBOT WORM! X lsass service lsass2.exe variant of the GAOBOT/AGOBOT WORM! X lsass2k Update lsass2k.exe variant of the WIN32.RBOT WORM! X LSASS32 Isass32.exe W32.KELVIR.M WORM! X lsass32 lsass32.exe Troj/Lydra-B Trojan! X lsass64BiT.exe lsass64BiT.exe W32/FORBOT-CK WORM! X lsassig lsassig.exe Troj/Bancos-EC TROJAN! Note: This trojan file is found in the System\drivers (95/98/Me) or System32\drivers (Nt/2000/XP) folder. X lsasss lsasss.exe Troj/Geekmy-A TROJAN! Note: lsasss.exe (notice the extra s) is not the legitimate Windows Process. (lsass.exe) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X lsasss.exe lsasss.exe Sasser.E worm N lsburnwatcher lsburnwatcher.exe Used for automatically updating HP programs X lsess lsess.exe W32.SINNAKA.A WORM! X lsmss.exe lsmss.exe TROJ/PROXY-GG TROJAN! N LSPFix LSPmonitor.exe "eAcceleration Stop-Sign related - not recommended, see note" N LSPmonitor LSPmonitor.exe "eAcceleration Stop-Sign related - not recommended, see note" X lssass lssas.exe AGOBOT.RL WORM! X LSvr LSvr.exe PowerStrip foistware Y LT DAEMON ltdaemon.exe Acts as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used X LTDMgr LTDMgr.exe PowerStrip foistware X LTM2 bible.exe LITMUS VIRUS Variant! X LTM2 MPGSRV32.EXE LITMUS VIRUS variant! X LTM2 MSGSRV32.EXE LITMUS VIRUS variant! (Note: MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:\Windows\System) X LTM2 MSGSRV320.EXE LITMUS VIRUS Variant! X LTM2 winscan.exe TROJ/LITMUS-B TROJAN! X LTM2 winupdate.exe LITMUS VIRUS Variant! U LtMoh Ltmoh.exe Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet Y LTMSG ltmsg.exe "One of the ""popular"" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information" N LTSMMSG LTSMMSG.exe "Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too" X LTSMSG Shell32.exe PWSteal.Lemir.B TROJAN! Y LTWinModem1 ltmsg.exe "One of the ""popular"" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information" X ltwob formatsys.exe W32.Serflog.A WORM! X ltwob msmbw.exe W32.Serflog.A WORM! X ltwob serbw.exe W32.Serflog.A WORM! U LUGuard LUGuard.exe "PC-Duo Remote_Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN, WAN or internet." Y Lusetup LUSetup.exe "Symantec, LiveUpdate_installer , required to install a new version of the application - will only run once, and the entry is automatically deleted after a reboot." U LVComs lvcoms.exe Lvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera U LVCOMSX LVCOMSX.EXE "It provides extra functionality for Logitech multimedia webcam devices. It is non-essential to the running of the system, but should not be terminated unless suspected to be causing problems." U LWBMOUSE "lwbwheel.exe, MOUSE32A.EXE" Mouse driver - required if you use non-standard Windows driver features N Lwinst Run Profiler lwtest.exe Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs Y lxbrbmgr lxbrbmgr.exe Lexmark printer button manager. Required for correct operation. N LXSUPMON LXSUPMON.EXE Lexmark Printer. The printer should work fine without it X LzioMediaUpdater LzioMediaUpdater.exe LZIO.com adware downloader X M_S DVD DirectX Dll Drivers msxdl.exe W32/SDBOT-BJN WORM! X M1cr0s0ft S3rcurity systemconfig.exe RBOT.BKB WORM! X M1cr0s0ft Upd4t4zS update32.exe W32/RBOT-MI WORM! X m32info m32info.exe CRYPTER.A trojan infection N M3Tray m3tray.exe Movielink - internet movie rental System Tray access X m4n70s Personal Firewall m4n70s.exe variant of the W32.SPYBOT WORM! X Macfee Security Patch Mpfsheild.exe W32/RBOT-NP WORM! U Machine Debug Manager mdm.exe "Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to ""hang"" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable" X Machine Debug Manager msdn.exe variant of the WIN32.RBOT WORM! X Machine Update Soft wusas.exe unidfentified WORM! N MacLic MacLic.exe Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks N MacName MacName.exe Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks X Macromedia Dreamweaver XM macdwXM.exe W32/AGOBOT-RI WORM! X Macromedia Drive Iexplor32.exe variant of the WIN32.RBOT WORM! X Macromedia Flash Update scvhost.exe variant of the WIN32.RBOT WORM! Y MAD.EXE MAD.EXE MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up? N MadExe LaunchRA.exe Dell Resolution Assistant U MAFWTaskbarApp MAFWTray.exe Drivers for the M-Audio Firewire Audiophile - Interface U MagicDsk MAGICDSK.EXE Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons U MagicLinker3 MagicLnk.exe ThaiSoftware Thai Dictionary N Magitime Magitime.exe "Magitime - connection tracking utility which monitors online time, expense, data transfer" X Mail_Check Mail_Check.exe PANOIL.C VIRUS! U MailBell mailbell.exe MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) U Mailbox Verifier mboxvrfy.exe Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) N MailCleaner MAILCLEANER.EXE "MailCleaner ""protect your computer from viruses sent to your machine via the popular e-Mail reader Incredimail. In addition the program will check all incoming files downloaded by Internet Explorer, Netscape Navigator, ICQ and iMesh"" - not recommended as it bundles Gator/Gain/Claria adware" X mailman.exe mailman.exe CERTIF-E TROJAN! Y MailScan Dispatcher Launch.exe "MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned" U MAIN main.exe SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan X main16 main16.exe CRYPTER.A trojan infection X main32 main32.exe CRYPTER.A trojan infection X MainStart svcmfte32.exe Troj/Stinx-A Trojan! X mainviewex mainviewex.exe W32.GEMA.D TROJAN! X Major Microsoft Windows Driver Boot loader bpool.exe W32.MYTOB.AJ WORM! N Mania Win Restore RESWIN.EXE Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs X Mantis ?? MANTIBE VIRUS! where is the filename X MapiDrv mpisvc.exe MIPSIV VIRUS! X mapisvc32 mapisvc32.exe KX VIRUS and also recognised by Symantec as FPAI adware X Martini pinmart.exe variant of the W32/SDBOT WORM! X Mascro soft SDK updates2 SDKrepair2.exe SDBOT.BXM WORM! X Mascro soft SDK updates2 SDKrepair2.exe variant of the W32/SDBOT.W WORM! N masqform.exe masqform.exe "PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms" N Mass storage check registry ?? Used with a USB based smartmedia card reader U Master Volume Spy MASTERVOLUMESPY.EXE "Volume control for the Gateway Destination ""DestiVu"" media interface" U Matador mantispm.exe MailFrontier_Desktop (Matador) email spam blocker software U Matador mlfbuddy.exe MailFrontier - anti-spam application X MatrixScreen ?? MATRIXSCREEN TROJAN! X MatrixScreenSaver mss.exe "Malware, see here" N Matrox Color Control hgcctl95.exe For Matrox video cards. Quick access to changing colors N Matrox Control Center mgactrl.exe For Matrox video cards. Quick access to settings N Matrox Diagnostic mgadiag.exe For Matrox video cards. Quick access to diagnostics N Matrox Powerdesk PDesk.exe For Matrox video cards. Quick access to tweak your card to your liking N Matrox QuickDesk mgaqdesk.exe For Matrox video cards. Quick access to tweak your card to your liking X MaxAlerts max.exe Bonzi MaxALERT - spyware Y MaxtorCombo ComboButton.exe Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) U MaxtorOneTouch OneTouch.exe Maxtor OneTouch Hard Drives/OneTouch Family hard disk backup software U MaxtorReg AUTOREG.EXE Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of Y MayaPan MayaPan.Exe Audiotrak Maya soundcard driver U MBM 4 MBM4.exe Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs U MBM 5 MBM5.exe Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs U MBNet mbnet.exe MBNet (Portugal) Credit Card Processing software U MBProbe mbrpobe.exe MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs X MC wintrims.exe WINTRIM VIRUS! Y mc or SMC Service or SmcServices smc.exe spfsmc.exe Sygate Firewall X Mcafee Anti Scan NortonScn.exe Win32.Rbot worm variant X McAfee Antivirus McAfeeAV.exe variant of the WIN32.RBOT WORM! X Mcafee Antivirus Monitoring System326 VSStatmn326.exe variant of the W32/SDBOT WORM! X Mcafee Antivirus Monitoring System32mn VSStatmn32.exe variant of the WIN32.RBOT WORM! X McAfee Antivirus Protection mcafeeAV.exe variant of the WIN32.RBOT WORM! X Mcafee Auto Protect mcafeshield.exe W32/RBOT-UH WORM! Y McAfee Firewall CPD.EXE Firewall bundled with McAfee VirusScan 6.*.?Can also be listed as CPD_EXE N McAfee Guardian CMGRDIAN.EXE "McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic" N McAfee QuickClean Imonitor Plguni.exe McAfee_QuickClean_3.0 - removes internet clutter and unwanted programs X McAfee Windows Protection mcafee32.exe variant of the W32.SPYBOT WORM! N McAfee Winguage ?? "Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious"". Resource hog. Available via Start -> Programs" U McAfee.InstantUpdate.Monitor RuLaunch.exe "Instant Updater for McAfee\'s VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis" X McAfeeScanPlus McAfeeScanPlus.exe Backdoor.Mepcod TROJAN! Note: This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder. Y McAfeeUpdaterUI UpdaterUI.exe Associated with McAfee Enterprise 7.0.0. - background process Y McAfeeVirusScanService Avsynmgr.exe "From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application" Y McAfeeWebscanX WebScanX.exe "From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc" X Mcaffe Antivirus Mcafeescn.exe W32.SpyBot worm variant U McAgentExe mcagent.exe "From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed" Y Mcappins.exe mcappins.exe Used by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled. N MChanger MChanger.exe "Media Changer - utility that allows you to change wallpapers, sounds, themes, etc" X MCM3 mcm3.exe ShopAtHome/SAHagent adware variant X Mcrosoftr Update Mcrosoftr.exe variant of the WIN32.RBOT WORM! X MCUpdateExe mcagent.exe TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here U McUpdateExe mcupdate.exe From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions Y mcupdmgr.exe MCUPDMGR.EXE McAfee antivirus SecurityCenter Update Manager Y McVsRte mcvsrte.exe Part of McAfee's SecurityCenter. Must remain checked but one? user reports Windows glitches with no response from McAfee as to why Y mcvsshld mcvsshld.exe McAfee VirusScan On-line. See also McAgentExe entry. X MD IE Plugin md.exe Marketdart spyware X MD IE Plugin winy.exe Adware N mdac_runonce runonce.exe "Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete ""runonce.exe"".?" N MDDiskProtect.exe MDDiskProtect.exe "MediaFour MacDrive for Windows - easily open, edit and save files from Mac-formatted disks, format Mac disks and burn Mac CDs and DVDs!" X mdetect ?? SPABOT VIRUS! X Mdm Mdm.vbs WHITEHO or TRAPPY VIRUSES! U MDM7 mdm.exe "Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to ""hang"" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable" X Mdmdll mdmdll.exe WIN32.CRYPTER downloader TROJAN! X Mdmdll32 mdmdll32.exe Crypter.C trojan variant infection X MDN MDN.exe RBOT.AOA WORM! X MDN MDNS.exe W32.Spybot.JPB WORM! X MDN MDNZ.exe RBOT.AQD WORM! X mds.exe mds.exe TROJ/MADS-A TROJAN! X mdwmdmsp mdwmdmsp.exe Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am N MECA Meca.exe Meca instant messenging client X MedGS MEDGS1.exe PacerD_Media/Pacimedia.com adware component X Media Access MediaAccK.exe Windupdates MEDIAPAS.A adware X Media Gateway MediaGateway.exe 180Solutions Windupdates adware variant - also see here X Media Load msn32.exe Unidentified backdoor trojan U Media Manager Indexer AIRSVCU.EXE "Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here" X Media Pass MediaPass.exe WindUpdates MediaPass adware X Media Pass MediaPassK.exe MediaPass adware X Media Player media.exe FLDMEDIA-A VIRUS! X Media Player Sysdll.exe TROJ/BANKER-BR TROJAN! X Media Player Sysnet.exe BANKER.MW WORM! X Media Player wmplayer.exe W32/Agobot-BM WORM! X Media Player Update xpsp1mfh.exe variant of the WIN32.RBOT WORM! X Media Plug x.1.2 msdm.exe MULDROP.352 VIRUS! X Media Service msn64.exe SPYBOT.EV worm infection X Media service msnmsgxr.exe WORM_SDBOT.TF X Media service notpad.exe variant of the AGOBOT/GAOBOT WORM! X Media service SYSTEM64.EXE RBOT.QV worm infection X Media Software UPdater sscs.exe W32/RBOT-ABE WORM! X Media X Services MSNGRx.exe RBOT.AUL WORM! X media_driver media_driver.exe "TUPEG VIRUS! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X media_manager mediaman.exe "Mini-Player,? IMESH related foistware, see here" X media_stub stub.exe "Mini-Player,? IMESH related foistware, see here" X MEDIA32 ?? Troj/PurScan-Z Trojan! N MediaFace Integration Sethook.exe "Fellowes Neato? cd label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar""" U Mediafour Mac Volume Notifications Macvntfy.exe Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod U Mediafour XPlay Tray Notification Icon Xptryicn.exe Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod U MediaKey MediaKey.exe Multimedia keyboard manager. Required if you use the multimedia keys X MediaLoads or MediaLoads Installer dw.exe Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information N MediaMonitor Mediam~1.exe Installed by Smartdisk MVP CD burning software. Software will work fine without it X mediamotor.exe mmups.exe MediaMotor/Popuppers adware X MediaPath ?? GRUEL VIRUS! X mediapluscash.exe mediapluscash.exe MediaMotor/Popuppers adware component N MediaRing Talk mrtalk.exe "Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs" X MediaXPServicePack mxpsp.exe variant of the WIN32.RBOT WORM! X Media-XP-Service-Pack3 msnzx.exe W32/Sdbot-ACW WORM! X Meeting Connection comsutil.exe PPDOOR-E TROJAN! X Meeting Connection wowdache.exe TROJ/PPDOOR-D TROJAN! X Members area ?? Premium rate adult content dialer X MemConfig SetupIE.com TAPLAK VIRUS! U MemMonster memmnstr.exe MemMonster is a memory manager which enables your computer to work more efficiently. U MemoKit MK.EXE Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind X memory outlookrem.exe W32.Nopir.C Worm! X Memory Check memore.exe KILLAV.C VIRUS! U Memory Stick Monitor MSstat.exe Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive N Memory Stick Monitor MSTAT.exe "Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer" X Memory Watcher MemoryWatcher.exe MemoryWatcher spyware U Memory+ tfimemsr.exe Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind X MemoryMeter MemoryMeter.exe Autoinstalling spyware by Total Velocity X MEMreaload MEMreaload.exe /checkmouse /updateration Lazar TROJAN! N MemScanner MemScanner.exe SpyHunter - spyware remover of somewhat dubious repute; see note U MemTurbo memturbo.exe MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind N MenuSnap MenuSnap.exe "MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing ""Sort by Name"" if availabe" X Message Queuing msmqs.exe FREEFORS VIRUS! U Message_Blocker messageblock.exe "Message Blocker - ""prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message""" N MessagerStarter Freeserve StartMessager.exe Freeserve Messenger X Messanger deamon.exe WIN32.TACTSLAY.C TROJAN! X Messanger msgaol.exe WIN32.TACTSLAY.C TROJAN! X Messanger s_menu.exe WIN32.TACTSLAY.C TROJAN! X Messanger trillian.exe variant of the AGOBOT/GAOBOT WORM! X Messenger messenger.exe KUTEX VIRUS! X Messenger ntsubsys.exe SDBOT.BGE WORM! X Messenger Wmsngr.exe variant of the WIN32.RBOT WORM! X Messenger Block msngrblock.exe PATOO VIRUS! X Messenger Protocol netsender.exe W32/Sdbot-ACC WORM! X Messenger Service msmsgs.exe W32/SDBOT-ZB WORM! X Messenger Service nvhost.exe MYTOB.IF WORM! X Messenger Service Updater svshost.exe MYTOB.GC WORM! X Messenger start-up Msgran.exe GRAMOS VIRUS! X Messenger6 command.pif W32.INZAE.B WORM! U MessengerDiscovery MessengerDiscovery.exe "MessengerDiscovery is a MSN Messenger add-on, adding over 70 new features." N MessengerPlus MsgPlus.exe "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!" N MessengerPlus2 MsgPlus.exe "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!" N MessengerPlus3 MsgPlus.exe "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!" X messnger ?? DELODER VIRUS! where is the worm name X messnger Dvldr32.exe DELODER.A VIRUS! X MeTaLRoCk (irc.musirc.com) has sex with printers metalrock-is-gay.exe RANDEX.Q WORM! X MeuPrograma accwizz.exe W32.Ruland.A WORM! X mfin32 mfin32.exe MyFreeInternetUpdate - adware downloader N MGA Quickdesk MGAQDESK.EXE For Matrox video cards. Quick access to tweak your card to your liking N MGA_CD_Install mgasetup.exe Matrox Millennium video driver. Not required once drivers installed Y mgavctrl or mgavrtclexe mgavrtcl.exe mgavrte.exe McAfee\'s Virus Scan Online X mgmtapi mgmtapi.exe Unidentified malware X MHDOGStart mhdogst.EXE unidentified VIRUS! A possibility is a trojan known as PENIS N MHINIT MHINIT.EXE Part of the Cybermedia Clean Sweep package X Micr Update soundblaster.exe WORM_SDBOT.NP X Micr0s0ft Upd4t4z svchost32.exe variant of the WIN32.RBOT WORM! X Micrcoft Exploerer spoolsal.exe W32/Rbot-AKK WORM! X Micrcoft Updat Internet.exe W32/Rbot-ANA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Micrcoft Updat spoolsae.exe W32/Rbot-AIB WORM! X Micrcoft Updat spoolsaex.exe W32/Rbot-AJM WORM! X Micro Process appconf.exe unidentified WORM or TROJAN! X Micro Update dailin.exe W32/RBOT-ER WORM! U Microangelo Desktop Muamgr.exe "Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs" N microAttuneDownload atmdlusr.exe USR (US Robotics) modem auto updater. May be a sub-set of Attune X MicroCQ0 explorer.exe Troj/Lineage-AK Note: This trojan file (explorer.exe) is found in the Program Files folder and is not the legitimate Windows file (explorer.exe) that is found in the Windows folder. U MicroDialler atdialler1.exe Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered X MicroedSoft Toolbar Smoked.exe W32/RBOT-ALN WORM! X Microfinder lptt01 or Microfinder ml097e mcf.exe "Variant of the RapidBlaster parasite (in a ""mcf"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Microft Exploerer spoolsac.exe W32/Rbot-AMD WORM! Note: This is not the legitimate Windows Process spoolsv.exe. (Notice the difference in the spelling) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X MicroLoad ?? DARBY VIRUS! X Micromedia Flash Update wdfmrg.exe variant of the W32/SDBOT WORM! X Microoft Timing pupdate.exe variant of the WIN32.RBOT WORM! X microsft windows updates mwupdate32.exe variant of the WIN32.TOXBOT/CODBOT WORM! X Microsof Windows Host svhost32.exe RBOT.ADY WORM! X Microsof Winlog Host wilogon32.exe RBOT.XC WORM! X Microsofot x386 System Monitor system32.exe WORM_WOOTBOT.M X microsoft microsoft.hta HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! X microsoft svchost.exe ASTEF or RESPAN VIRUSES! Note - this is not the valid svchost.exe as described here X Microsoft win32.exe BACKDOOR.DARKMOON TROJAN! X Microsoft (C) HTML Application host ?? W32/Rbot-YB WORM! X Microsoft .NET Confingurator msnconf.exe unidentified VIRUS! X Microsoft 16Bit Update wuapdate16.exe WORM_RBOT.CZ X Microsoft 64 Bit Runtime Updater wupdt64.exe variant of the WIN32.RBOT WORM! X Microsoft ActiveX Debugger NT ?? Troj/Bancos-DO TROJAN! X Microsoft ADservice ?? variant of the WIN32.RBOT WORM! X Microsoft ADservice adservice.exe variant of the WIN32.RBOT WORM! X Microsoft Agent mdss32.exe KEYLOG-AG TROJAN! X Microsoft ALG32 Protocol alg32.exe variant of the W32.SPYBOT WORM! N Microsoft Announcement Listener Annclist.exe MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it X Microsoft Ansti Update msie.exe W32/Rbot-LE worm infection X Microsoft AntiSpyware Bazzi.exe AHKER.J WORM! X Microsoft AOL Instant Messenger MSAOL32.exe W32/RBOT-AAI WORM! X Microsoft AOL32 Protocol aol32.exe variant of the W32.SPYBOT WORM! X Microsoft Application Center mappc.exe variant of the WIN32.RBOT WORM! X Microsoft Application Manager msapl32.exe TROJ/BROPIA-AE TROJAN! X "Microsoft Associates, Inc." iexplorer.exe variant of the LOVGATE WORM! X Microsoft AUT Update MSlti16.exe RBOT.EB WORM! X Microsoft AUT Update MSlti32.exe W32/Rbot-X worm X Microsoft Authority Service lsass.exe W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder. X Microsoft auto update winupdate.exe BMBOT VIRUS! X Microsoft Automatic Update Serivce msautou.exe W32/Rbot-AOB WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Automatic Updater Explorer.exe W32/RBOT-SG WORM! X Microsoft AutoUpdater svhost.exe RBOT.QG worm infection X Microsoft Bool Value MV2.exe variant of the WIN32.RBOT WORM! X Microsoft boot system cfg32 actboost.exe W32.Bropia.R WORM! X Microsoft Cab Manager exec.exe Affilred.B adware X Microsoft checker MsPMSPTv.exe variant of the W32/SDBOT WORM! - do not confuse with the Microsoft's Digital Rights Management file described here X Microsoft Client mshost.exe W32/Rbot-AND WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Client/Server Runtime Server Subsystem csrs.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Client/Server Runtime Server Subsystem csrssa.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Command Line wincmd.exe variant of the WIN32.RBOT WORM! X Microsoft Conf Ldr sysconf.exe variant of the SDBOT WORM! X Microsoft Config msconf.exe RBOT.PV WORM! X Microsoft Config MSCONF.EXE RBOT-LG WORM! X Microsoft Config 32bit mscnfg32.exe W32/RBOT-Z WORM! X Microsoft Config File config.exe Win32.KillFiles.gr TROJAN! - This is malware that will attempt to delete all system dlls! X Microsoft Configuration Utility msconf.exe W32/RBOT-AFX WORM! X Microsoft Connection Manager Monitor cmmon.pif W32/Rbot-AKV WORM! X Microsoft Control Center crtl.exe W32/RBOT-VX WORM! X Microsoft Core Support MSxUP32.exe W32/Rbot-ANR WORM! X Microsoft Corporation ?? "various VIRUSES such as VISAGES, BABYBEAR and TOFACED" X Microsoft CronD Service MSCRON.EXE Unidentified AIM-based worm/trojan X Microsoft Crs Fix Serv wincrs.exe SDBOT.BWF WORM! X Microsoft CSRSS32 Protocol csrss32.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft CSRSS386 Protocol csrss386.exe variant of the W32.SPYBOT WORM! X Microsoft Cvrt mscvrt32.exe "unidentified VIRUS!. Named almost, but not exactly like the legitimate msvcrt or msvcrt20.dll" X Microsoft Data Helper cihost.exe "Malware, possibly a Linst trojan variant" X Microsoft Data Machine csdata32.exe variant of the WIN32.RBOT WORM! X Microsoft Database Handler mssql32.exe RANDEX.AX VIRUS! X Microsoft Datalog Application msdata.exe variant of the W32/SDBOT WORM! X Microsoft DDE Control wupades.exe variant of the W32/SDBOT WORM! X Microsoft DDEs Control Erun.pif W32/Rbot-AMU WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Debug Service dbgbgr.exe variant of the WIN32.RBOT WORM! X Microsoft Decryption Technology Msfenoe.exe W32/SPYBOT-DG WORM! X Microsoft Desktop Manager msdesk32.exe variant of the WIN32.RBOT WORM! X Microsoft Dev iexplorer32.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Development Debugger msdev.exe variant of the WIN32.RBOT WORM! X Microsoft Device Manager msdevmgr32.exe LATEDA.B TROJAN! X Microsoft Diagnostic ?? ACEBOT VIRUS! The .exe will be random and must be deleted after the virus has been removed. Not to be confused with the DOS based MSD.EXE X Microsoft Diagnostic msdiag32.exe W32/RBOT-UC WORM! X Microsoft Digital Clock msclock.exe W32/Nackbot-D worm infection X Microsoft DirectX PDSched.exe SDBOT.CN WORM! X Microsoft DirectX rasmngr.exe Win32.Rbot worm variant X Microsoft DirectX Spoolserv.exe DINFOR VIRUS! X Microsoft DirectX time123.exe SDBOT.MD WORM! X Microsoft DirectX wuamgrd.exe SDBOT.MY WORM! X Microsoft DLL Extensions SystemDll.exe W32/Rbot-ADV or W32/Rbot-AJR WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Dll Management windll.exe W32/RBOT-MT WORM! X Microsoft Dll Printer Manager dllpt.exe SDBOT.BIH WORM! X Microsoft DLL Verifier chkfile.exe W32/Rbot-AOC WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft DLL Verifier file.exe W32/Rbot-AED Worm! X Microsoft DLLSet32 dllset32.exe RBOT.OZ WORM! X Microsoft DNS Query msdns.exe variant of the W32/WOOTBOT WORM! X Microsoft Document krisp.exe W32/SDBOT-RQ WORM! X Microsoft Driver faet.exe variant of the WIN32.RBOT WORM! X Microsoft Driver Manager mswindrv.exe W32/FORBOT-EZ WORM! X Microsoft driver update Mshome.exe SDBOT.BL WORM! X Microsoft Drivers WSconf.exe variant of the W32/SDBOT WORM! X Microsoft ErgoPack wserb32.exe W32/RBOT-RI WORM! X Microsoft EV32 Service MSev32.exe variant of the WIN32.RBOT WORM! X Microsoft Excel msexcel.exe W32/RBOT-TQ WORM! X Microsoft Excell wuamngr32.exe W32/RBOT-QH WORM! X Microsoft Executing microsoft.exe AGOBOT.UV WORM! X Microsoft Explorer explorer.pif W32/Sdbot-ACX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Explorer explorer.scr W32/Rbot-ADH Worm! X Microsoft Explorer svapache.exe W32/RBOT-VR WORM! X Microsoft Explorer2 bitchbot.exe SDBOT.EV WORM! X Microsoft Explorer2 nome.exe RANDEX.AA WORM! X Microsoft Explorer2 system.exe BKDR_IRCBOT.BS TROJAN! X Microsoft EXPLOREXP Protocol explorexp.exe variant of the W32.SPYBOT WORM! X Microsoft Features ms32cfg.exe WORM_RBOT.HO X Microsoft Features msie.exe variant of the WIN32.RBOT WORM! X Microsoft File Demand Manager wmgrdf.exe variant of the WIN32.RBOT WORM! X Microsoft Find Fast Findfast.exe Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier X Microsoft Firewall firewallsp2.exe W32/Rbot-MC worm infection Y MICROSOFT FIREWALL CLIENT ISATRAY.EXE MS Internet Security and Acceleration Server - see here X Microsoft Games gamemanager.exe SPYBOT.AHQ WORM! X Microsoft Gina V Encryption MSGINAV.EXE Unidentified worm or trojan N Microsoft Greetings Reminder MHPRMINF.EXE You really want to be reminded about somebody's birthday at the expense of resources? U Microsoft Greetings Reminders MHPRMIND.EXE Microsoft Home Publishing greetings reminder N Microsoft Greetings Workshop Reminder Gwremind.exe You really want to be reminded about somebody's birthday at the expense of resources? X Microsoft Help svh0st.exe variant of the W32.SPYBOT WORM! X Microsoft Help SVC msnmngr.exe W32/Sdbot-PQ worm infection X Microsoft Help System mshelp32.exe CoolWebSearch parasite variant X Microsoft Host Protocol svhost.exe variant of the WIN32.RBOT WORM! X Microsoft Host Service mswinexect.exe RBOT.ZU WORM! X Microsoft Hosting Service WINHOSTING.EXE RBOT.AEV WORM! X Microsoft Hosts Service Isass.exe variant of the WIN32.RBOT WORM! X Microsoft IDCN mshe1p.exe unidentified TROJAN! X Microsoft IE Iexplore.exe W32/Forbot-AG worm infection X Microsoft IE Execute shell IEExec.exe ALADINZ.N VIRUS! X MicroSoft IE Sasser ISASS.EXE SDBOT.MX WORM! X Microsoft IIS ?? W32/Francette-S Worm! X Microsoft IIS syshost.exe FRANCETTE VIRUS! X Microsoft Inc. iexplorer.exe variant of the LOVGATE WORM! X Microsoft Incroporate mfs.exe W32/RBOT-ANF WORM! X Microsoft Inet Xp.. teekids.exe BLASTER.C VIRUS! X Microsoft Instant Messenger msngmsngr32.exe Win32.Spyboter.gen TROJAN! X Microsoft Int Service MsIntSrv.exe variant of the WIN32.RBOT WORM! U Microsoft Intellitype Pro speedkey.exe Additional keyboard shortcuts on MS programmable keyboard X Microsoft Internal AntiVirus Systems dIlhost.exe W32/Rbot-AEV Worm! X Microsoft Internet expl0rer.exe W32.SpyBot worm variant X Microsoft Internet msnm.exe W32/Sdbot worm variant X Microsoft Internet wincfg16.exe variant of the W32/SDBOT WORM! X Microsoft Internet windows32.exe W32/SdBot-F worm infection X Microsoft Internet Acceleration Utility ?? Troj/SmutSrch-A Trojan! X Microsoft Internet Acceleration Utility ?? TROJ/AGENT-CX TROJAN! X Microsoft Internet Acceleration Utility iau.exe EasySearch adware X Microsoft Internet Exp iiexplorer.exe W32/Rbot-KX worm infection X Microsoft Internet Explorer crsys32.exe RBOT.UZ WORM! X Microsoft Internet Explorer iexplore.exe "W32/POEBOT-J or W32/Mytob-CW WORM! - NOTE - This file is installed in the Windows\System32 or Winnt\System32 folders and is NOT to be confused with the Internet Explorer executable, which will always be located in the Internet Explorer folder in Program Files!" X Microsoft Internet Explorer iexplorer.exe W32/SDBOT-XN WORM! X Microsoft Internet Explorer mccagent.exe TROJ/DLOADER-UD TROJAN! X Microsoft Internet Explorer movies.exe Troj/Bancos-DZ TROJAN! X Microsoft Internet Explorer msngrt.exe W32/SdBot-GU worm infection X Microsoft Internet Explorer smiissm.exe TROJ/DLOADER-JQ TROJAN! X Microsoft Internet Explorer svchosts.exe Bancban-U trojan infection X Microsoft Internet Explorer svzhost.exe variant of the WIN32.RBOT WORM! X Microsoft Internet Firewall Manager GMT16.exe RANDEX.AT VIRUS! X Microsoft Internet Services Smss32.exe WORM_RBOT.MS X "Microsoft Internet, varying file names" dmsvc32.exe W32/Sdbot-AZ worm infection X Microsoft Intrenet Explorer Soundsyst.exe variant of the WIN32.RBOT WORM! X Microsoft IPC svshost.exe unidentified VIRUS! X Microsoft IPC system.exe NULLBOT VIRUS! X Microsoft IT Update ?? variant of the Win32.Rbot WORM! X Microsoft IT Update IEserv.exe variant of the Win32.Rbot WORM! X Microsoft IT Update msupdate.exe variant of the Win32.Rbot WORM! X Microsoft IT Update svchsst.exe W32/RBOT-DH WORM! X Microsoft IT Update win43.exe SPYBOT.BI WORM! X Microsoft IT Update winn43.exe variant of the Win32.Rbot WORM! X Microsoft IT Update winsyst32.exe W32/RBOT-FC WORM! X Microsoft Java Virtual Machine javavm.exe variant of the WIN32.RBOT WORM! X Microsoft Java Virtual Machine MsConfiG.exe W32/FORBOT-DV WORM! X Microsoft Java Virtual Machine msjvm.exe variant of the W32/SDBOT WORM! X Microsoft Java Virtual Machine msvmjava.exe RBOT.ER WORM! X Microsoft Java Virtual Machine winscr32.exe variant of the W32/WOOTBOT WORM! X Microsoft Java Windows Update ?? W32/RBOT-DZ WORM! X Microsoft JavaVM msjarun.exe W32/Rbot-JW worm X Microsoft Kernel Windows_kernel32.exe W32.NETSKY.AE WORM! X Microsoft LAN32 Protocol lanXp.exe W32/RBOT-SS WORM! X Microsoft Legacy Device trass.exe W32/Rbot-AIX WORM! X Microsoft Lmhosting Service lmhosts.exe W32/RBOT-RC WORM! X Microsoft Locals 332 ?? W32/Rbot-KU worm infection X Microsoft Login winlogin.exe W32/Rbot-AJP WORM! X Microsoft LSA layer MSLSA32.exe W32/Rbot-AKZ WORM! X Microsoft LSASS386 Protocol scvhost32.exe variant of the W32.SPYBOT WORM! X Microsoft LV ?? TROJ/BDOOR-BDL TROJAN! X Microsoft Machine winjava.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Macro Protection SubSsy msacroprots386.exe W32/Rbot-KE worm infection X Microsoft Macro Protection Subsystems Msmacroprot32.exe RBOT.KN WORM! X Microsoft Macro Protection Subsystems msmacroprotxz.exe W32.SpyBot worm variant X Microsoft Management lmas.exe W32/FORBOT-CZ WORM! X Microsoft Management Console ?? Troj/SmutSrch-A Trojan! X Microsoft Management Console lssas.exe EasySearch adware X Microsoft Map PC mappc.exe variant of the WIN32.RBOT WORM! X Microsoft Mapped PC mappedpc.exe variant of the WIN32.RBOT WORM! X Microsoft media winmplayers.exe variant of the W32.SPYBOT WORM! X Microsoft Media player 9 msmedia32.exe W32/RBOT-ADO WORM! X Microsoft media services Iassd.exe variant of the GAOBOT/AGOBOT WORM! X Microsoft media services winmplayer.exe RBOT.ZO worm infection X Microsoft MediaScope winmes.exe W32/RBOT-XU WORM! X Microsoft Message Machine msmesg32.exe SPYBOT.BI WORM! X Microsoft Messenger Service msmsg32.exe RBOT.BOK WORM! X Microsoft Messenger XP MSMSN32.exe W32/RBOT-ZP WORM! X Microsoft MicroP Protocol wdgmr32.exe variant of the WIN32.RBOT WORM! X Microsoft Movie Maker Mmaker.exe IRCBOT.C VIRUS! Note that this is not a valid Microsoft program X Microsoft MSGPLUS32 Protocol msgplus32.exe variant of the W32.SPYBOT WORM! X Microsoft MSNGR32 Protocol msngr32.exe variant of the W32.SPYBOT WORM! X Microsoft MsnST msnst32.exe variant of the WIN32.RBOT WORM! X Microsoft MSUPDATE SpoolSvc.exe SXTB-A VIRUS! X Microsoft Neser Experience nese.exe W32/RBOT-YH WORM! X "Microsoft NetMeeting Associates, Inc." NetMeeting.exe variant of the LOVGATE WORM! X Microsoft Netview gesfm32.exe RANDEX.C VIRUS! X Microsoft Netview mssvc32.exe unidentified VIRUS! X Microsoft Netview Component v5.1 msnv32.exe RANDEX.F VIRUS! X Microsoft Network msnet.exe MOCKBOT.A VIRUS! X Microsoft Network Networksystem.exe W32/SDBOT-AAI WORM! X Microsoft Network Daemon for Win32 Netd32.exe SDBOT.R WORM! X Microsoft Network Services Controller mmsvc32.exe W32/NANPY-A WORM! X Microsoft Networking Agent For SP2 msnac32.exe W32.SPYBOT.PEN WORM! X Microsoft NotePad notepad.exe variant of the WIN32.RBOT WORM! X Microsoft NT Update winexec32.exe variant of the WIN32.RBOT WORM! X Microsoft Office lserv.exe SDBOT.MH WORM! X Microsoft Office Microsoft Office.hta HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! X Microsoft Office MSMSGR.exe GAOBOT.BB WORM! N Microsoft Office Msoffice.exe "Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly." X Microsoft Office msoicons.exe W32/RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups! X Microsoft Office Nxcao.exe W32/RBOT-ZE WORM! X Microsoft Office nxcxtpr.exe W32/RBOT-YG WORM! N Microsoft Office OSA.EXE "Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show." X Microsoft Office svxhost.exe variant of the WIN32.RBOT WORM! N Microsoft Office Fast Cache Fastboot.exe Part of MS Office 95 (v7.0). According to this;en-us;Q132755 it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled U Microsoft Office OneNote 2003 Quick Launch ONENOTEM.EXE ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work. N Microsoft Office Shortcut Bar Msoffice.exe "Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly." X Microsoft Office Start winupdates.exe GAOBOT.BC WORM! N Microsoft Office Startup Osa9.exe "Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show." X Microsoft Office Studio scvhvst.exe W32.Randex.CST WORM! X Microsoft OfficeXP officeXP.exe KILLAV.MA WORM! X Microsoft Opeions IEXwe.exe variant of the WIN32.RBOT WORM! X Microsoft Outlook Express Protocol svchst.exe variant of the WIN32.RBOT WORM! X Microsoft PCHealth32 ?? TROJ/NICE-A TROJAN! X Microsoft PCI Manager mspci.exe variant of the W32/SDBOT WORM! X Microsoft Personal Firewalls bakw.exe W32/Rbot-KS worm infection X Microsoft Proc Driver32 msprc.exe variant of the W32/WOOTBOT WORM! X Microsoft Procedure Call MSPCALL.exe variant of the WIN32.RBOT WORM! X Microsoft PSTCP32 Data pstcp32.exe variant of the WIN32.RBOT WORM! X Microsoft QMGR msnqmgr.exe TROJ/IRCBOT-S TROJAN! X Microsoft RDLL sysconf32.exe variant of the SDBOT WORM! X Microsoft Registro svchostt.exe TROJ/BANCOS-DH TROJAN! X Microsoft Registry csrse.exe W32/RBOT-PC WORM! X MicroSoft Remote Secure Service MSRSS.exe variant of the WIN32.RBOT WORM! X Microsoft Restore scrgrd.exe SPYBOT.BR WORM! X Microsoft Rundll windos.exe W32/SDBOT-WF WORM! X Microsoft Runtime CfgDll32.exe RANDEX.BD VIRUS! X Microsoft Scanreg microsoftscanreg.exe FRANRIV.A VIRUS! X Microsoft SCVHOST32 Protocol scvhost32.exe variant of the WIN32.RBOT WORM! X Microsoft sdk temp sdktemp.exe W32/Rbot-ANP WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Secure Messenger.NET Service securitychk.exe WORM_SDBOT.VT X Microsoft Security winService.exe variant of the WIN32.RBOT WORM! X Microsoft Security Center savservices.exe W32/RBOT-ANU WORM! X Microsoft Security Controlers fxsecues.exe variant of the W32/SDBOT WORM! X Microsoft Security GManagers ?? variant of the W32/SDBOT WORM! X Microsoft Security Hot Fix Update mshotfix.exe Affilred adware X Microsoft Security Management msisrv32.exe W32/Rbot-ML worm infection X Microsoft Security Management winamp.exe variant of the WIN32.RBOT WORM! X Microsoft Security Management winnt.exe W32/RBOT-MQ WORM! X Microsoft Security Management winserv.exe W32/Rbot-MJ WORM! X Microsoft Security Management wuauct1.exe variant of the WIN32.RBOT WORM! X Microsoft Security Manager winamp.exe RBOT.TU WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) X Microsoft Security Panager ?? W32/RBOT-ANL WORM! X Microsoft Security Panagers ?? W32/RBOT-AIG WORM! X Microsoft Server Applacations msnmsg.exe variant of the WIN32.RBOT WORM! X Microsoft Server Applacations wuauct1.exe variant of the WIN32.RBOT WORM! X Microsoft Server Application Sound.exe W32/RBOT-NE WORM! X microsoft server base lass.exe variant of the WIN32.RBOT WORM! X Microsoft Service microhost.exe W32/Rbot-LC worm infection X Microsoft Service winsvc.exe W32/Spybot-DB worm infection X Microsoft Service Controller services.exe W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder. X Microsoft Service Drivers System.exe variant of the WIN32.RBOT WORM! X Microsoft Service Drivers VSADNIM.exe variant of the WIN32.RBOT WORM! X Microsoft Service Host Process svchost.exe "KRYNOS.B WORM! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" X Microsoft Service Pack WindowsSP.exe W32/RBOT-RF WORM! X Microsoft Service Pack2.1 svchost2.exe variant of the WIN32.RBOT WORM! X Microsoft Services bsc32.exe BDOOR-AW TROJAN! X Microsoft Services lsrv.exe W32/Rbot-BK worm X Microsoft Services lssrv.exe WORM_RBOT.CW X Microsoft Services services.exe ALETS VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process X Microsoft Services Smss32.exe W32/RBOT-AD WORM! X Microsoft Services svshost.exe BACKDOOR.ALETS.B TROJAN! X Microsoft Services svssshost.exe variant of the WIN32.RBOT WORM! X Microsoft Services Unitd MSU32.exe variant of the WIN32.RBOT WORM! X Microsoft Session Manager Subsystem smss.exe W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder. N Microsoft Sidewinder Game Controller Software SWTRAY.EXE MS SideWinder game controller system tray icon. Available via Start -> Programs X Microsoft Sinsup odjiwjf.exe W32/RBOT-DN WORM! X microsoft software ?? unidentified WORM or TROJAN! (where * stands for a random character) X Microsoft software cdaccess.exe RBOT.ABK WORM! X Microsoft Software sysinfo33.exe RBOT.LS worm infection X Microsoft Software Update nmon.exe RBOT.HZ worm infection X Microsoft Sound Driver sound32.exe W32.SpyBot worm variant X Microsoft Sound Technology winsound.exe W32/Rbot-AGG WORM! N Microsoft Sound Volume Tool mssvol.exe This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel X Microsoft SourceSafe csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X Microsoft SpA Service msapps.exe W32/RBOT-VI WORM! X Microsoft SpA Service win32.exe RBOT.ATS WORM! X Microsoft SpA Service Winupd32.exe RBOT.LT WORM! X Microsoft Special offer infoebay.exe variant of the WIN32.RBOT WORM! X Microsoft Spool Server for Win32 spoolsrv.exe RANDEX.H VIRUS! X Microsoft SSISVRI32 Protocol ssisvri.exe variant of the W32.SPYBOT WORM! X Microsoft standard protector winsocks5.exe variant of the TROJ/STOX-B TROJAN! X Microsoft Sum32 sum32.exe W32/RBOT-YW TROJAN! X Microsoft Sum32 sum32.exe W32/RBOT-YW WORM! X Microsoft Support sys32ms.exe W32/RBOT-AHI WORM! X Microsoft Synchronization Manager ___synmgr.exe W32.MASLAN.C WORM! X Microsoft Synchronization Manager al.exe OPTXPRO.132 TROJAN! X Microsoft Synchronization Manager asgard.exe SDBOT.PH worm infection X Microsoft Synchronization Manager bot.exe SDBOT.IH worm infection X Microsoft Synchronization Manager devldr32.exe variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs devldr32.exe file X Microsoft Synchronization Manager java.exe variant of the W32/SDBOT WORM! X Microsoft Synchronization Manager netscape.exe RANDEX.AE worm infection X Microsoft Synchronization Manager screen.exe W32/SDBOT-ACO WORM! X Microsoft Synchronization Manager slhost.exe SDBOT.YH worm infection X Microsoft Synchronization Manager svchosts.exe W32/SDBOT-LM WORM! X Microsoft Synchronization Manager svhost.exe W32/Sdbot-PY And W32/Sdbot-YR WORMS! X Microsoft Synchronization Manager svxhost.exe W32/Sdbot-ZU WORM! X Microsoft Synchronization Manager win.exe SDBOT.AK WORM! X Microsoft Synchronization Manager wincfg32.exe SDBOT.DO WORM! X Microsoft Synchronization Manager WinLoginnn.exe SPYBOT.FO worm infection X Microsoft Synchronization Manager winlogon32.exe SDBOT.AEU WORM! X Microsoft Synchronization Manager winupdate.exe SDBOT.ER worm infection X Microsoft Synchronization Manager xXx.exe W32/Sdbot-KZ worm infection X Microsoft System msupdtm.exe W32.Spybot.PKC Worm! X Microsoft System Backup ?? W32/Rbot-AGM WORM! X Microsoft System Checkup Cool.exe W32.HLLW.Donk.B WORM! X Microsoft System Checkup dbnetlib.exe W32.HLLW.Donk.L WORM! X Microsoft System Checkup inetman.exe W32.HLLW.Donk.O WORM! X Microsoft System Checkup Keymgr.exe W32.HLLW.Donk.M WORM! X Microsoft System Checkup libsys32.exe W32/SDBOT-ACK WORM! X Microsoft System Checkup libsysmgr.exe W32/SDBOT-CAF WORM! X Microsoft System Checkup netapi32.exe W32/DONK-E WORM! X Microsoft System Checkup ntsysman.exe W32/SDBOT-QW WORM! X Microsoft System Checkup ntsysmgr.exe W32.Donk.S WORM! X Microsoft System Checkup sysmgr.exe SDBOT-OO TROJAN! X Microsoft System Checkup Wnetlib.exe W32.HLLW.Donk.C WORM! X Microsoft System Checkup wnetmgr.exe W32.DONK.Q WORM! X Microsoft System Debug services32.exe RBOT.AKH WORM! X Microsoft System DLL Services Configuration windir32.exe W32/Sdbot-ACY Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft System NT svhost.exe IRC/SDBOT.COU WORM! X Microsoft System Restore Configuration CBRSS.EXE variant of the SPYBOT VIRUS! X Microsoft System Services msmsgr.exe W32/RBOT-ZH WORM! X Microsoft System Services msnmgsr.exe W32.KELVIR.K WORM! X Microsoft System Update sysupdate.exe SDBOT.DG WORM! X Microsoft Taskmanager Updater keyboard.exe W32/RBOT-ALU WORM! X Microsoft Telecom Center tellecom.exe variant of the WIN32.RBOT WORM! X Microsoft Telecoma Center tellcoma.exe variant of the WIN32.RBOT WORM! X Microsoft Time Manager dveldr.exe W32/Rbot-HQ worm X MicroSoft Toolbar key.exe W32/Rbot-AEW Worm! X Microsoft Transfer File Server mtfs.exe RBOT.AFE WORM! X Microsoft Tray ?? DELF.BZ VIRUS! X Microsoft U wuamkopxp.exe W32/RBOT-AHC WORM! X Microsoft UMA Update MSuma32.exe RBOT.FS WORM! X MICROSOFT UNPACCKER SYSTEM unpak32.exe variant of the WIN32.RBOT WORM! X MICROSOFT UNPACK SYSTEM winrarx.exe variant of the WIN32.RBOT WORM! X Microsoft Updat3 mswkst32.exe variant of the WIN32.RBOT WORM! X Microsoft Update aaupdt.exe W32/RBOT-RQ WORM! X Microsoft Update ascdl.exe W32.Gaobot.SY WORM! X Microsoft Update automgr32.exe variant of the Win32.Rbot WORM! X Microsoft Update Botnet.exe RBOT.AFL WORM! X Microsoft Update devmks32.exe variant of the WIN32.RBOT WORM! X Microsoft Update Isac.exe W32/Rbot-AU WORM! X Microsoft Update Kkk.exe W32/RBOT-AHL WORM! X Microsoft Update lsac.exe GAOBOT.XW WORM! X Microsoft Update mcupdate.exe "variant of the WIN32.RBOT WORM! - NOTE - this file is located in the Windows\System32 or Winnt\System32 folder, and must NOT be confused with the McAfee antivirus executable as described here" X Microsoft Update mediap.exe variant of the Win32.Rbot WORM! X Microsoft Update Micr0s0ft.exe AGOBOT.AAR WORM! X Microsoft Update Microsoft.exe GAOBOT.AFJ WORM! X Microsoft Update Microsoftx.exe variant of the Win32.Rbot WORM! X Microsoft Update mixer.exe W32/Rbot-AIR WORM! X Microsoft Update ms.exe BKDR_SDBOT.CC WORM! X Microsoft Update msawindows.exe GAOBOT.AFJ WORM! X Microsoft Update msconfg.exe Win32.Rbot.H WORM! X Microsoft Update msiwin84.exe GAOBOT.AFJ WORM! X Microsoft Update Mslti32.exe W32/Rbot-LX WORM! X Microsoft Update Msnmsngr.exe RBOT.BQS WORM! X Microsoft Update mssmgrd.exe SDBOT.JT WORM! X Microsoft Update msupdate.exe TROJ/BOROBOT-I TROJAN! X Microsoft Update msupdate32.exe SPYBOT.LZ WORM! X Microsoft Update muamgrd.exe variant of the AGOBOT.GEN WORM! X Microsoft Update mvsc.exe variant of the W32.Spybot.DAZ WORM! X Microsoft Update NAV.exe W32/RBOT-IV WORM! X Microsoft Update navmgrd.exe BKDR_SDBOT.DP TROJAN! U Microsoft Update phqghumea.exe Identified as unknown malware W32/Backdoor by Norman X Microsoft Update prowind32.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Update scvhost.exe W32/Rbot-AEM Worm! X Microsoft Update sghost.exe SDBOT.AKV WORM! X Microsoft Update Smss32.exe W32/Rbot-CB WORM! X Microsoft Update snlogsvc.exe variant of the WIN32.RBOT WORM! X Microsoft Update svghost.exe variant of the WIN32.RBOT WORM! X Microsoft Update svhost.exe W32/RBOT-PI WORM! X Microsoft Update svzhost.exe RBOT.OX WORM! X Microsoft Update sys.exe W32/RBOT-AJ WORM! X Microsoft Update sys32cfg.exe RBOT.DR WORM! X Microsoft Update systemi32.exe variant of the W32.SPYBOT WORM! X Microsoft Update up2dat5.exe variant of the W32/SDBOT WORM! X Microsoft Update update_w.exe W32/RBOT-EW WORM! X Microsoft Update VPC32.EXE AGOBOT.XM WORM! X Microsoft Update wauguard.exe RBOT.AEE WORM! X Microsoft Update webm.exe SDBOT.WK WORM! X Microsoft Update win32.exe variant of the W32/SDBOT WORM! X Microsoft Update winamp.exe variant of the WIN32.RBOT WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) X Microsoft Update windows24.exe variant of the WIN32.RBOT WORM! X Microsoft Update wingrd32.exe W32/RBOT-DW WORM! X Microsoft Update wingrd32.exe W32/RBOT-DW WORM! X Microsoft Update wininit.exe W32/Rbot-AKR WORM! X Microsoft Update win-mang.exe W32/Rbot-AFK Worm! X Microsoft Update winscv.exe W32/RBOT-BH WORM! X Microsoft Update winsys.exe W32/RBOT-GV WORM! X Microsoft Update winsys32.exe variant of the Win32.Rbot WORM! X Microsoft update winupdate.exe variant of the WIN32.RBOT WORM! X Microsoft Update WinUpdate32.exe W32/RBOT-TI WORM! X Microsoft Update winupdater.exe RBOT.BIN WORM! X Microsoft Update wkfix.exe W32/RBOT-ABZ WORM! X Microsoft Update wserv32.exe RBOT.AF WORM! X Microsoft Update wssvr.exe W32/RBOT-OD WORM! X Microsoft Update wtm32.exe W32/RBOT-AQ WORM! X Microsoft Update wuagmrd.exe variant of the WIN32.RBOT WORM! X Microsoft Update wuagmsd.exe W32/RBOT-AX WORM! X Microsoft Update wuagrd.exe W32/RBOT-FK WORM! X Microsoft Update wuamagr32.exe SPYBOT.CG WORM! X Microsoft Update wuamgrd.exe W32/RBOT-YI WORM! X Microsoft Update wuamgrd3.exe W32/Rbot-AMC WORM! X Microsoft Update wuamgrd32.exe RBOT.ZB WORM! X Microsoft Update wuamk0032.exe variant of the WIN32.RBOT WORM! X Microsoft Update wuamk032.exe W32/RBOT-AHD WORM! X Microsoft Update wuamk0p32.exe variant of the WIN32.RBOT WORM! X Microsoft Update wuamkop.exe W32/Rbot-AFI Worm! X Microsoft Update wuamkop32.exe RBOT.BGU WORM! X Microsoft Update wuammgr32.exe variant of the W32/Rbot-AW WORM! X Microsoft Update wuampd.exe W32/RBOT-UT WORM! X Microsoft Update wuampkd.exe SDBOT.BBX WORM! X Microsoft Update Wudates.exe variant of the WIN32.RBOT WORM! X Microsoft Update wudmate.exe RBOT.AP WORM! X Microsoft Update wumgrd.exe W32/SDBOT-KY WORM! X Microsoft Update xpupdate.exe W32/RBOT-QE WORM! X Microsoft Update 23 NtKernelSystem.exe variant of the WIN32.RBOT WORM! X Microsoft Update 23 spoolvs.exe variant of the WIN32.RBOT WORM! X Microsoft Update 32 ?? W32/Rbot-AJJ WORM! X Microsoft Update 32 explore32.exe W32.Spybot.CYM WORM! X Microsoft Update 32 mscnfg.exe W32/Rbot-ALM WORM! X Microsoft Update 32 mssetup32.exe variant of the WIN32.RBOT WORM! X Microsoft Update 32 MSupdate32.exe variant of the Win32.SpyBot WORM! X Microsoft Update 32 servic.exe variant of the WIN32.RBOT WORM! X Microsoft Update 32 wiit.exe W32/Rbot-AMS WORM! X Microsoft Update 32 wininit.exe W32/RBOT-ANY WORM! X Microsoft Update 32 wininit32.exe variant of the WIN32.RBOT WORM! X Microsoft Update 32 winitXP32.exe variant of the WIN32.RBOT WORM! X Microsoft Update 64 BIT schvost.exe RBOT.CAU WORM! X Microsoft Update 64 BIT wininit32.exe W32/RBOT-AHE WORM! X Microsoft Update 64 BIT winman32.exe W32/Rbot-AKI WORM! X MICROSOFT UPDATE CONFIGURATION WIN32SNC.exe W32/Rbot-AI WORM! X Microsoft Update Control Ms64.exe variant of the WIN32.RBOT WORM! X Microsoft Update Debugger wincfg32.exe SPYBOT.ZC WORM! X Microsoft Update DLL rxxhost.exe variant of the WIN32.RBOT WORM! X Microsoft Update Emulator kern-mxe.exe variant of the Win32.Rbot WORM! X Microsoft Update Loader ?? variant of the Win32.Rbot WORM! X Microsoft Update Loaders 2005 winusers.exe W32/RBOT-AIQ WORM! X Microsoft Update Loaders 2006 winusersystem32.exe variant of the AGOBOT/GAOBOT WORM! X Microsoft Update Machine ?? variant of the Win32.Rbot WORM! X Microsoft Update Machine crss32.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine expl0rer.exe variant of the SDBOT.OK WORM! X Microsoft Update Machine linux.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine lmrss.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine lsasse.exe W32/RBOT-DI WORM! X Microsoft Update Machine memstat.exe W32/RBOT-OM WORM! X Microsoft Update Machine MSOICONS.EXE variant of the WIN32.RBOT WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups! X Microsoft Update Machine ntce.exe W32/RBOT-FA WORM! X Microsoft Update Machine qwerty.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine rxhost.exe RBOT.FC WORM! X Microsoft Update Machine rxxhost.exe RBOT.EP WORM! X Microsoft Update Machine scvhost.exe W32/RBOT-GS WORM! X Microsoft Update Machine servicez.exe SPYBOT.BI WORM! X Microsoft Update Machine servicz.exe W32/Rbot-HU WORM! X Microsoft Update Machine serviz.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine SP2.exe SPYBOT.FP WORM! X Microsoft Update Machine spoolserv.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine svshost.exe RBOT.AK WORM! X Microsoft Update Machine system.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine system03.exe W32/RBOT-NM WORM! X Microsoft Update Machine systemll.exe W32/RBOT-JT WORM! X Microsoft Update Machine Systemnt.exe RBOT.DA WORM! X Microsoft Update Machine systemse.exe W32/RBOT-BD WORM! X Microsoft Update Machine TASKMAN4.EXE variant of the WIN32.RBOT WORM! X Microsoft Update Machine taskmngrs.exe W32/RBOT-CR WORM! X Microsoft Update Machine TMEMSER.EXE W32/RBOT-NQ WORM! X Microsoft Update Machine wftestb.exe W32/Rbot-AFZ Worm! X Microsoft Update Machine Win32.exe SDBOT.UV WORM! X Microsoft Update Machine windns.exe RBOT.EF WORM! X Microsoft Update Machine windowsu.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine windowsup.exe W32/RBOT-FV WORM! X Microsoft Update Machine winini.exe W32/Rbot-KV WORM! X Microsoft Update Machine wininigo.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine winmgr.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine Winmsixp32.exe RBOT.DN WORM! X Microsoft Update Machine winnie.exe W32/RBOT-ACD WORM! X Microsoft Update Machine winortho.exe W32/RBOT-NW WORM! X Microsoft Update Machine Winregs32.exe RBOT.DN WORM! X Microsoft Update Machine wins32.exe RBOT.EZ WORM! X Microsoft Update Machine winss.exe RBOT.JU WORM! X Microsoft Update Machine winupdt.exe W32/RBOT-FP WORM! X Microsoft Update Machine winxpini.exe variant of the Win32.Rbot WORM! X Microsoft Update Machine wuagrd.exe W32/RBOT-GF WORM! X Microsoft Update Machine wuamgard.exe SPYBOT.CS WORM! X Microsoft Update Machine wuamgd.exe SDBOT.HQ WORM! X Microsoft Update Machine wuamgrd.exe WindUpdates SyncroAd adware X Microsoft Update Machine wuawx.exe W32/RBOT-CE WORM! X Microsoft Update Machine wupdate32.exe variant of the WIN32.RBOT WORM! X Microsoft Update Machine wupdt32x.exe variant of the W32/SDBOT WORM! X Microsoft Update Machine xvshost.exe RBOT.QP WORM! X Microsoft Update Machine zonealarm.exe W32/RBOT-BZ WORM! - NOTE: this is not the valid Zone Labs firewall program! X Microsoft Update Manager svshost.exe variant of the WIN32.RBOT WORM! X Microsoft Update Manager WINRLS.EXE RBOT-AF WORM! X Microsoft Update Mechene Updatez.exe W32/RBOT-GI WORM! X Microsoft Update Process wmipcvse.exe TROJ/AGOBOT-JF TROJAN! X Microsoft Update Security Patch mssecurityupdatepatch.exe Win32.Agent.ef backdoor TROJAN! X Microsoft Update Server mssrv.exe "Worm or trojan, as yet unidentified" X Microsoft Update Service csrss32.exe W32/Agobot-HC WORM! X Microsoft Update Service mswin32.exe variant of the Win32.Spybot WORM! X Microsoft Update SERVICE phqghum.exe variant of the WIN32.RBOT WORM! X Microsoft update service systemm.exe variant of the W32/SDBOT WORM! X Microsoft Update Services wcsnfty.exe W32/RBOT-AGK WORM! X Microsoft Update Services wsnfty.exe W32/RBOT-AFU WORM! X Microsoft Update Time wuam.exe W32/Rbot-M WORM! X Microsoft Update USB2 wuammgrd32.exe W32/Rbot-ADT Worm! X Microsoft Update v2.6 lxxex.exe variant of the WIN32.RBOT WORM! X Microsoft Update Win32a winupdate32a.exe W32/Rbot-LO WORM! X Microsoft Update Win32x winupdate32x.exe W32/Rbot-AJN WORM! X Microsoft Updater Winsys32.exe variant of the WIN32.RBOT WORM! X Microsoft Updater wuamgrds.exe BKDR_RBOT.A! X Microsoft Updater Resources WinFixd32.exe SPYBOT.CA WORM! X Microsoft UPDATER32 lsass.exe RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup X Microsoft Updaters sysconfigs.exe W32/RBOT-DF TROJAN! X Microsoft Updaters tskmgr.exe variant of the WIN32.RBOT WORM! X Microsoft Updaters Pros WINDLL32XP.EXE SPYBOTTER.GEN VIRUS! X Microsoft Updates systemc32.exe W32/RBOT-GR WORM! X Microsoft Updates wkssvr.exe RBOT.R WORM! X Microsoft Updates wkssvrs.exe W32/RBOT-EB WORM! X Microsoft Updates wtemp32.exe W32/Rbot-AHQ WORM! X Microsoft Updates wuamgrd.exe W32/RBOT-CO WORM! X Microsoft Updates 2 USB wgafixer.exe variant of the WIN32.RBOT WORM! X Microsoft Updates 5 USB sp3fixer.exe W32/Rbot-ADS Worm! X Microsoft Updates Resources WinFixIDs.exe variant of the WIN32.RBOT WORM! X Microsoft Updating navguard.exe RBOT.HW WORM! X Microsoft Updating syswr.exe variant of the WIN32.RBOT WORM! X Microsoft Updating wuamguards.exe W32/RBOT-BY WORM! X Microsoft Updating Client websvc.exe RBOT.AQ WORM! X Microsoft Updating Machine sysc0de.exe RBOT.RB WORM! X Microsoft Updatting miroupdate.exe variant of the WIN32.RBOT WORM! X Microsoft UpMachine doezs.exe RBOT.BCT WORM! X Microsoft upnp Update msie.exe W32/Rbot-LQ worm infection X Microsoft uptime Service sycuptime.exe W32/RBOT-AHY WORM! X Microsoft uptime Service sysuptime.exe W32/RBOT-ACG WORM! X Microsoft UpToDate Driver (32-bits) ?? W32.SPYBOT.LXJ WORM! X Microsoft USB2 Driver crmss.exe W32/RBOT-VK WORM! X Microsoft Utility Startup OSA9.exe Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants X Microsoft Vertupdate MSvert32.exe W32/MYTOB-CY WORM! X Microsoft Video Capture Controls MSsrvs32.exe W32/SDBOT-AAK WORM! X Microsoft Video Controls tskmsgr.exe W32.SpyBot worm variant X Microsoft Virual Machine sms.exe W32/RBOT-SP WORM! X Microsoft Visual SourceSafe services.exe "W32.Neveg.B worm. Note - this is NOT the legitimate services.exe system file, which should NOT figure in Msconfig/Startup" X Microsoft Visual SourceSafe winlogon.exe W32.Neveg.B worm X Microsoft Visual Studio VSA varpc32.exe W32.SpyBot worm variant X Microsoft Web Device wdevice.exe variant of the W32/SDBOT WORM! U Microsoft Webserver svctrl.exe Personal web server program which enables you to create and host a web server from your computer. Not required for most people X MicroSoft Wind0ws Updater winsupdater.exe variant of the WIN32.RBOT WORM! X MicroSoft Window Updater winsupdater.exe W32/RBOT-ZZ WORM! X Microsoft Windows atup variant of the WIN32.RBOT WORM! X Microsoft Windows explorar.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Microsoft Windows.hta HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! X Microsoft Windows mstask0.exe SDBOT.FQ WORM! X Microsoft Windows 16Bit mswinn16.exe variant of the W32.SPYBOT WORM! X Microsoft Windows 2000 Winupdsdgm.exe GAOBOT.AO WORM! X Microsoft Windows 32Bit mswinn32.exe variant of the WIN32.RBOT WORM! X Microsoft Windows 64 Bit mswin32.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Control mswctl32.exe RBOT.JP WORM! X Microsoft Windows CSRSS csrss.exe "W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Microsoft Windows DHCP ___r.exe W32.Maslan.A or W32.Maslan.C WORMS! X Microsoft Windows DLL 32-BIT msncheck32.exe W32/SDBOT-XX WORM! X Microsoft Windows DLL Services mwindll.exe W32/SDBOT-VX WORM! X Microsoft Windows DLL Services Configuration dllmanager32.exe variant of the W32/SDBOT WORM! X Microsoft Windows DLL Services Configuration newdll.exe W32/Sdbot-ZR WORM! X Microsoft Windows DLL Services Configuration newdll2.exe W32/SDBOT-ABD WORM! X Microsoft Windows DLL Services Configuration poker.exe W32/SDBOT-ZY WORM! X Microsoft Windows DLL Services Configuration poker3.exe W32/SDBOT-AAH WORM! X Microsoft Windows DLL Services Configuration proxy.exe W32/Sdbot-ZL Worm! X Microsoft Windows DLL Services Configuration regscv.exe variant of the W32/SDBOT WORM! X Microsoft Windows DLL Services Configuration windir32.exe SDBOT.BHF WORM! X Microsoft Windows DLL Services Configuration windir32a.exe variant of the SDBOT.BHF WORM! X Microsoft Windows DLL Services Configuration windll32.exe SDBOT.BHD WORM! X Microsoft Windows DLL Services Configuration winDSL.exe W32/Sdbot-ZG Worm! X Microsoft Windows DLLHandler bitpaint.exe SDBOT.AHG WORM! X Microsoft Windows Explorer iexplorer.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Files Loader cgy32win.exe variant of the WIN32.RBOT WORM! X Microsoft Windows GUI msmonk32.exe W32/SDBOT-PE WORM! X Microsoft Windows GUI Windowz.exe RANDEX.AEV VIRUS! X Microsoft Windows Kernel Services winkrnl386.exe ZEBROXY VIRUS! X Microsoft Windows Loader wloader.exe variant of the GAOBOT/AGOBOT WORM! X Microsoft Windows Media Player mediaplayer.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Media Player wimp.exe W32/RBOT-FN WORM! X Microsoft Windows Registry Service wregistry.exe AGOBOT.AKG WORM! X Microsoft Windows Registry Updater wreg.exe W32/FORBOT-DN WORM! X Microsoft Windows Secure Server rpcxWindows.exe W32/Rbot-LL worm infection X Microsoft Windows Secure Update rpcxwinupdt.exe unidentified WORM or TROJAN! X Microsoft Windows Securety wurguar.exe W32/RBOT-KY WORM! X Microsoft Windows Security spvsper.exe variant of the W32/SDBOT WORM! X Microsoft Windows Security wscndrives.exe W32/Rbot-AJK WORM! X Microsoft Windows Service winsys.exe W32/Rbot-ADP Worm! X Microsoft Windows Services Controller wservices.exe WIN32.RBOT.FD WORM! X Microsoft Windows Storage Machine Service winms.exe W32/RBOT-AHK WORM! X Microsoft Windows System Service Manager winsvc.exe SPYBOT.LR WORM! X Microsoft Windows Task Manger Mstosk.exe W32/Sdbot-WW worm infection X Microsoft Windows Updata scvhost.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Update MSNMSGR.EXE W32/SDBOT-WM WORM! X Microsoft Windows Update msoffice2.exe W32/Rbot-GB worm infection X Microsoft Windows Update rundlls.exe HABRACK VIRUS! X Microsoft Windows Update scvvhost.exe W32/Forbot-FH WORM! X Microsoft Windows Update spools.exe WORM_SDBOT.TD X Microsoft Windows Update svchos.exe Backdoor.Sdbot.AC worm infection. X Microsoft Windows Update svcshost.exe W32/FORBOT-CF WORM! X Microsoft Windows Update svmhost.exe W32/FORBOT-CH WORM! X Microsoft Windows Update svshost.exe WOOTBOT.CJ WORM! X Microsoft Windows Update svzhost.exe W32/FORBOT-EV WORM! X Microsoft Windows Update swwhost.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Update Application wuap.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Update Logon win-logon.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Update Service wupdmgr32.exe DOS.AUTOCAT VIRUS! X Microsoft Windows Update XP64 ?? variant of the WIN32.RBOT WORM! X Microsoft Windows Updater msnupdateit.exe W32/AGOBOT-RL WORM! X Microsoft Windows Updater spoolvs.exe RBOT.ACQ WORM! X Microsoft Windows Updater suvhost.exe variant of the W32/SDBOT WORM! X Microsoft Windows Updater svchostz.exe DAEMONI-E VIRUS! X Microsoft Windows Updater TMNTSrv.exe variant of the WIN32.RBOT WORM! X Microsoft Windows Updater win32upd.exe W32/RBOT-EC WORM! X Microsoft Windows Updater windates.exe SDBOT.TE WORM! X Microsoft Windows Updater WINIUPDATES.EXE W32/Rbot-KK worm infection X Microsoft Windows Updater WINUPDATE.EXE W32/SDBOT-PU WORM! X Microsoft Windows Updater winupdgm.exe GAOBOT.BI WORM! X Microsoft Windows updaterD log32zx.exe W32.Mydoom.W WORM! X Microsoft Windows Updates explorer32.exe SDBOT.VQ WORM! X Microsoft Windows W32 Services mssw32.exe variant of the W32.SPYBOT WORM! X Microsoft Windows WKS Service gt.exe SDBOT.FV WORM! X Microsoft Windows XP Configuration Loader m32svco.exe W32/SDBOT.WORM.48548 X Microsoft WinRaR winrar.exe W32/Rbot-AEC Worm! X Microsoft Winsock mswinsck.exe W32/RBOT-ANK WORM! X Microsoft Winsock Service msusvc.exe W32/Rbot-ANS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoft Winsock Wrapper ws2_32s.exe variant of the W32.SPYBOT WORM! X Microsoft Winsocks 32 Controller MSWSCK32.exe variant of the WIN32.RBOT WORM! X Microsoft WinSound ?? variant of the WIN32.RBOT WORM! X Microsoft WinUpdate mntcgf032.exe W32/RBOT-PF WORM! X Microsoft WinUpdate spfix.exe variant of the WIN32.RBOT WORM! X Microsoft WinUpdate svh0st.exe SPYBOT.DL worm infection X Microsoft WinUpdate syslx32.exe Unidentified worm or trojan X Microsoft WinUpdate syswin32.exe W32/Rbot-HO WORM! X Microsoft WinUpdate Winamp61.exe variant of the WIN32.RBOT WORM! X Microsoft WinUpdate WinNTinit32.exe RBOT.VS WORM! X Microsoft WinUpdate Winupd32.exe RBOT.MQ WORM! X Microsoft WinUpdates serm32.exe RBOT.GE worm X Microsoft WM mswm32.exe TROJ/BCKDR-AM TROJAN! X Microsoft Word BootSector.exe variant of the AGOBOT alias GAOBOT WORM! X Microsoft Word Profissional csrss.exe Troj/Bancban-DB or Troj/Bancos-DP TROJAN! (Note:) May also be found in the \protect\ or \JavaVM\ folder. X Microsoft Word Profissional Java Plug In close.exe Troj/Banker-EL TROJAN! N Microsoft Works Calendar Reminders wkcalrem.exe Produces a pop-up reminder of events scheduled using the MS Works Calendar N Microsoft Works Portfolio WksSb.exe The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio N Microsoft Works Update Detection "wkdetect.exe, WkUFind.exe" Checks for updates to MS Works X Microsoft World Service winworld.exe unidentified IRC worm with backdoor capability! X Microsoft Wxdate Syswu32.exe SPYBOT.HZ WORM! X Microsoft X Update wuamkoppnp.exe W32/RBOT-ANI WORM! X microsoft xdaemon 2.0 xdaemon.exe DELF.D VIRUS! X Microsoft XML Service msxmlx.exe WORM_RBOT.KS X Microsoft Xp Systems loader winsystem32xp.exe W32.KELVIR.W WORM! X Microsoft Xp Systems loaders win32xpsys.exe W32.SPYBOT.NYT WORM! X Microsoft XPSP Protocol xp386.exe variant of the WIN32.RBOT WORM! X Microsoft xpsp2 Networksystem.exe variant of the W32/SDBOT WORM! X Microsoft xpsp2 xpsp2.exe W32/Sdbot-YQ Worm! X Microsoft? PID Lex PIDLex.exe NIOVADOOR VIRUS! X Microsoft? ActiveX Debugger NT setdebugnt.exe Troj/Bancos-CZ Trojan! X Microsoft˝ System Mapper SysMap.exe MAPSY VIRUS! X Microsoft32.exe Microsoft32.exe Unidentified worm or trojan X microsoft420 microsoft420.exe MENACE.B (or W32.SOFUNNY) VIRUS! X Microsoftf DDEs ContDLL rune.pif W32/Rbot-AGF WORM! X Microsoftf DDEs ContrDL runm.pif W32/Rbot-AFQ Worm! X Microsoftf DDEs Control Erun.pif variant of the WIN32.RBOT WORM! X Microsoftf DDEs Control FEnR.exe W32/RBOT-AIM WORM! X Microsoftf DDEs Control lxes.exe RBOT.BOF WORM! X Microsoftf DDEs Control soff.pif W32/Rbot-AKH WORM! X Microsoftf DDEs Control wees.exe variant of the the RBOT.BOF WORM! X Microsoftf DDEs Control why-.exe W32/Rbot-AMV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Microsoftkeysd systemproc.exe W32/FORBOT-BI WORM! X Microsoftkeysd systemwin32.exe variant of the WIN32.RBOT WORM! X Microsoftkeysd systemwin32s.exe WOOTBOT.CO WORM! X Microsoftkeysds lass32.exe variant of the WIN32.RBOT WORM! X MicrosoftKs Drivers.bat Troj/Shutdown-F TROJAN! X microsoftm eegs cuntrol loor.pif variant of the WIN32.RBOT WORM! X Microsoftmsn32.exe microsoftmsn32.exe TROJ/CERTIF-C TROJAN! X MicrosoftMultimediaTask Mmtask.exe Adware downloader - not the valid MusicMatch Jukebox which shares the same filename X MicrosoftNetwork Daemon for Win32 NETD32.EXE RANDEX.F VIRUS! X MicrosoftOEM smvss.exe TROJ/DEDLER-G TROJAN! X Microsofts media wingtp.exe W32/RBOT-VO WORM! X Microsofts media winmplayd.exe undidentified WORM or TROJAN! X Microsofts MediaScope winmedplay.exe variant of the WIN32.RBOT WORM! X Microsofts MediaScope winmep.exe W32/Rbot-WB WORM! X Microsofts Security Manager ?? RBOT-WH TROJAN! X Microsofts Service lcsrv16.exe variant of the WIN32.RBOT WORM! X Microsoft's System Module Sysmodule.exe TROJ/BDOOR-FJ TROJAN! X Microsofts Updates lsasss.exe W32/Rbot-AEX Worm! X Microsofts Updatez cmsssr.exe Unidentified worm or trojan X Microsofts Updatez exploirez.exe variant of the WIN32.RBOT WORM! X MicrosoftServiceManager EXPLORERE.EXE YAHA.AB VIRUS! X MicrosoftServiceManager mstask32.exe YAHA.P VIRUS! X MicrosoftServiceManager msupdat.exe YAHA.AA VIRUS! X MicrosoftServiceManager Wintsk32.exe YAHA.U VIRUS! X Microsoft-software ?? variant of the WIN32.RBOT WORM! X MicrosoftSourceSafe lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" X MicrosoftSys SPOOLSYS.exe PWSteal.Tarno.N TROJAN! X MicrosoftUpdate syshelper.exe WOOTBOT.AC WORM! X MicrosoftUpdate WinUp32.exe unidentified worm X Microsoft-Update wngard.exe W32/Rbot-JV worm infection X MicrosoftUpdates syshelped.exe W32/Forbot-AZ worm infection X Microsoft-Updates svxhost.exe W32/Rbot-CT WORM! X Microsoft--Updates sxvhost.exe W32/Rbot-FH worm infection X MicrosoftValue syscnfg.exe "Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside" X Microsoftvirus sysoverload.exe W32/FORBOT-AL WORM! X Microsoftz turn Control aexl.exe SDBOT.BCO WORM! X Microsoftz turn Control read.pif W32/Rbot-AFS Worm! X Microsong svchosts11.exe W32/SDBOT-EV WORM! X Microszoft Update Mach1nezs svchst.exe W32/RBOT-ED WORM! X Microzoft_Ofiz KdzEregli.exe AMUS.A VIRUS! X Micrsoft CFG 32 lrbzus32.exe variant of the AGOBOT/GAOBOT WORM! X Micrsoft Driver msdriver.exe W32/SDBOT-XD WORM! X Micrsoft Driver windrive.exe BACKDOOR.SDBOT.AF WORM! X Micsorosft Security Center wcnsfty.exe W32/RBOT-AHU WORM! N MightyFAX Controller MFNTCTL.EXE "Mighty FAX from RKS Software - ""installs a printer driver so that you can fax directly from Windows software""" N MimBoot mimboot.exe Starts Musicmatch_Jukebox at bootup - can be started manually. X Mincer Mincer.exe WM97/Minceme-A Worm! X MINIBUG MINIBUG.EXE Displays ads inside Weatherbug - see here N MINIFERT.EXE MINIFERT.EXE Part of Backweb U minilog MINILOG.EXE If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use N MiniMavis MiniMavis.exe Mavis Beacon typing tutor X minimo ?? TROJ/MOSUCK-X TROJAN! N MiniNote MININOTE.EXE "Mini NoteTab was the first in the family of ""NoteTab"" text and HTML editors from Fookes Software" X MiniPortRt miniport_mp.exe Malware - see here U MinMaxExtender Mmext.exe MinMaxExtender - window handling tool X Miosf Update wimsqaad.exe BACKDOOR.SDBOT.AG WORM! N Mirabilis ICQ icq.exe "If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs" N Mirabilis ICQ ICQNet.exe "If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs" N Mirabilis ICQ NDetect.exe "If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs" U "Miramar Systems, Inc." atmsg.exe Miramar PC/Mac networking software N Miranda IM miranda32.exe Miranda Instant Messaging client X Mirate Sp 2 Information miratesp2.exe RBOT.QH WORM! X Mircosoft Sockets SP2 mssck.exe MYTOB.ET WORM! X Mircosoft Update wuampkd.exe variant of the W32/SDBOT WORM! X Mircrosoft Svchost32 svchost32.exe W32/RBOT-AZW WORM! X Mircrosoft Windows Config DLL rundllc32b.exe W32/RBOT-ZY WORM! N miroVIDEO Tray Tool misitray.exe "Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card,?e.g. for the above actions" U MirrorFolderShell mrfshl.exe MirrorFolder backup software X Mismo win32x.exe W32/RBOT-JP WORM! N Mixer Mixer.exe C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs N Mixghost mixghost.exe "Management software for Altec Lansing speakers.? If a change is needed, the user can launch it from the Start menu" X ml00!.exe ml00!.exe "Malware, detected by Panda antivirus as Trj/Downloader.BWD" U ML1HelperStartUp ML1HEL~1.EXE Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... U ML1HelperStartUp ML1Helper.exe Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... X mload lxmstart.exe unidentified VIRUS! X MMB2 explorer.exe "unidentified WORM or TROJAN - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)" X MMC inisys.exe W32/Oscabot-I Worm! X mmcndmgr mmcndmgr.exe unidentified worm or trojan N MMCWINMGMT winmgmt.exe "Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here" X Mmessenger messenger.exe AGOBOT.GM WORM! X Mmgsvc mmgsvc.exe Spyware.Mmgsvc U MMhid mmhid.dll "This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP" N MMHotKey MMHotKey.exe Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen U MMKeybd MMKeybd.exe Multimedia keyboard manager. Required if you use the additional keys X mmod mmod.exe eZula TopText adware N mmpti m1mmpti.exe Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards X MMSystem ?? FUNNER.A worm infection X MMSystem RunDll32 W32/FUNNER-A WORM! N mmtask mmtask.exe Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator Y MMTASK mmtask.tsk "A check on the file\'s properties reveals ""Multimedia background task support module"". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc" X MMtask Service mmtask.exe BACKGAT.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename N MMTray mm_tray.exe MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator N MMTray MMTray.exe Part of Morgan Multimedia Codecs. Only required when the codecs are used N MMTray2K MMTray2K.exe Part of Morgan Multimedia Codecs. Only required when the codecs are used N MMTrayLSI MMTrayLSI.exe Part of Morgan Multimedia Codecs. Only required when the codecs are used X mmxp2passion.exe mmxp2passion.exe MediaMotor/Popuppers adware component X mmxrun msosa.exe "Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return" X mmxrun mswinindex.exe TwoSeven SPYWARE! X mnklins mnklins.exe Transponder parasite related X mnpol mnpol.exe DOWNLOADER.DLUCA.B TROJAN! U MNS MNS.exe "Mobile_Net_Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more." X mnsvc mnsvc.exe AUTOUPDER VIRUS! X mnsvcsp mnsvcsp.exe VIRUS! N mobsync mobsync.exe "MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages" X MOBSYNC32.EXE mobsync32.exe FINERO VIRUS! N MOD muamgr.exe "MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them" X Modem locatesvc.exe variant of the W32.SPYBOT WORM! X Modem Driverz Updates mdmdrv.exe variant of the W32/SDBOT WORM! U MODEMBTR MODEMBTR.EXE Modem Booster from inKline Global to improve ISP connections X Modeminf Modeminf.exe CRYPTER.C trojan variant infection U ModemOnHold MOH.EXE NetWaiting Modem-on-Hold Application N ModemUtility mdmsetpe.exe System Tray configuration icon for Aztech modems X ModularConfig syscnfg.exe "Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside" X Module Call initialize ?? variant of the LOVGATE WORM! X Modulo 00FE0F01 Host Internet syschost.exe TROJ/DELF-KW TROJAN! X MOJNPluginSrIvcs neomonap23.exe variant of the W32/SDBOT WORM! N Money Express moneyexpress.exe Part of MS Money. Available via Start -> Programs N MoneyAgent mnyexpr.exe Microsoft Money N MoneyAgent money express.exe Part of MS Money. Available via Start -> Programs N MoneyStartUp Money Startup.exe Microsoft Money N MoneyStartUp10.0 Activation.exe Part of MS Money 2002. Available via Start -> Programs X monitor monitor.exe "Browser hijacker, redirecting to NCM Search" U Monitor Apache Servers ApacheMonitor.exe Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs U Monitor_Helper monitor.exe MyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself! X Monitoring Service svchost.exe "CONE.C VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32" X Monitormgt Monitormgt.exe GEMA TROJAN! X MonitorSD SDMonitor.exe "Max Spyware Detector, bogus ""Spyware remover"" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""spywaredetector.net""" X MONPluginSrIvcs n3monap23.exe variant of the WIN32.RBOT WORM! N Monstersoundtray Freectrl.exe Diamond Multimedia sound card control panel X MonTest vccxzq.exe W32/SDBOT-EA WORM! U MoodBook mb.exe MoodBook is a free Windows utility that brings art to your desktop N moon phase moon.exe Moon Phase - tray icon that indicates the phases of the moon N Morpheus morpheus.exe "MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes ""I have seen no instance of any since using it""" X morphstb morphstb.exe Adware downloader - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Stubby.c X mosearch mosearch.exe Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here X Motherboard Config Ati2xxx.exe W32/RBOT-AIK WORM! X MotherBoard Sounds Sounds.exe W32/RBOT-AAP WORM! N Motive SmartBridge BTHelpNotifier.exe "System tray icon for the Virtual Assistant from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required" N Motive SmartBridge MotiveSB.exe "System tray icon for the Virtual Assistant from AT&T_Broadband , used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required" N Motive SmartBridge mpbtn.exe "System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required" U MotiveMonitor motmon.exe Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required N MotiveSB MotiveSB.exe The same as Motive SmartBridge below U MotMon motmon.exe Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required X motoin mm15201518.Stub.exe Delfin_Promulgate adware variant U Mount Safe & Sound Fbmount.exe From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start X mouse mouse.exe W32/Rbot-AHJ WORM! N Mouse 32A Mouse32A.exe Mouse driver to control mouse functions from Azona. Available via Start -> Programs N Mouse Suite 98 Daemon ICO.EXE Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games N Mouse Suite 98 Daemon pelmiced.exe Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games X mousebut mousebut.exe CRYPTER.A trojan infection X Mousecntl mousecntl.exe Crypter.C trojan variant infection N MouseCount MC.exe "MouseCount by Kittyfeet Software. ""Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year."" Not required" X MouseDrv ?? W32/Zoload-B WORM! X mousedrv mousedrv.exe CRYPTER.A trojan infection X MouseDrv update.exe ZOTOB.N WORM! U mouseElf gnetmous.exe Genius_NetScroll mouse driver - required if you use non-standard Windows driver features U mouseElf MC.exe System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features U mouseElf mouseElf.exe System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features U MouseImp MImpHost.exe "MouseImp Pro - ""A reliable assistant that turns your mouse into a simple, native but powerful controlling device""" U Mousinfo mousinfo.exe MS mouse information tool - for troubleshooting mouse problems N Movielink Manager Uninstall msvcmm32.exe Auto-update for Movielink - internet movie rental System Tray access X MovieNetworks MovieNetworks.exe MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:\Program Files\MovieNetworks directory X Movieplace Movieplace.exe MoviePlace malware X Mozila Firefox firebox.exe W32/RBOT-AIP WORM! X Mozilla Firefox F1REF0X.EXE variant of the W32/SDBOT WORM! N Mozilla Quick Launch Netscp6.exeMozilla.exe Netscape 6 and Mozilla browsers X MP Tcloaxs mptcloaxs.exe RANDEX.CT VIRUS! X Mp3 Loader Sysdata.EXE /S W32/Avette-A VIRUS! X MP3download ?? MatrixDialer related U MPEO Csinsm32.exe Automatic logging of installs from Norton CleanSweep - available via Start -> Programs X MPFExe mcagent.exe TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here Y MPFExe mpf.exe McAfee Personal Firewall Y MPFExe MpfTray.exe McAfee Personal Firewall X MPL32 driver MPL32.exe Loony-M trojan infection U MplSetup MplSetup.exe Used by Ricoh network printers to enable network printing from the client X MPM Manager MPM.exe DONBOMB.A TROJAN! U MPower MPower.exe "MPower from MindBeat. ""Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load"". Some users swear by programs such as this but I suggest you read this article and make up your own mind" X MPR MSG mprmsg32.exe W32.MYTOB.CF WORM! X MPREXE MPREXE.EXE OPASERV.T VIRUS! Note - this is not the legitimate Mprexe.exe system file Y MPREXE.exe mprexe.exe WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don\'t know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus X MprHTML MprHTML.exe variant of the VAGRNOCKER VIRUS! X mprocessor mprocessor.exe InstallDollars.com foistware U MPSExe mscifapp.exe "McAfee.com Privacy Service - ""combines personal identifiable information (PII) protection with online advertisement blocking and content filtering""" Y MpsOnn MpsOnn.exe Canon printer driver X MPtask Services mptask.exe LALA or DOWNLOADER-BN.B or AOT VIRUSES! N MPTBox MPTBOX.EXE Cannon Multi-Pass toolbox - a button bar X mptsgsvc.exe mptsgsvc.exe "Hacker_Tool - detected by TDS-3 antitrojan as ""HackTool.Win32.Hidd.j""" N MPXTray mpxptray.exe "Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc" X mqbkup mqbkup.exe OPASERV.K VIRUS! N mrtMngr mrtMngr.exe Maintenance Release Task Manager for Intuit?s QuickBooks or Quicken U MRUBlaster indexcleaner.exe MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder U MRU-Blaster Scheduler scheduler.exe MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer N MRU-Blaster Silent Clean mrublaster.exe MRU-Blaster - performs silent cleaning of MRU lists at boot X MS Auto-IPSec Protection MSASP32.exe W32/Rbot-AER Worm! X MS Autoloader 32 MSAuto32.exe SPYBOT.BD WORM! X Ms Builders Wupated.exe W32/AGOBOT-SS WORM! X MS Config Loader MSWin32bck.exe GAOBOT.AA WORM! X MS Config Loader svchos1.exe AGOBOT.R WORM! X MS Config Loader svcrhost.exe variant of the WIN32.RBOT WORM! X MS Config Service Msloader32.exe W32/Rbot-KJ WORM! X MS Config v13 lrbz32.exe W32.GAOBOT.AOL WORM! X Ms Configuration microsoftsa32.exe W32.KELVIR.X WORM! X MS Configuration MSFramer.exe RANDEX.OL VIRUS! X MS Decryption Software active.exe MediaTickets adware variant X MS DVD DirectX Dll Drivers mdxdl.exe W32/SDBOT-XI WORM! X MS DVD DirectX Sound Drivers msdrvdx.exe W32/SDBOT-XJ WORM! X MS Explorer mexplore.exe YAHA.AE VIRUS! X MS FIREWALL msfirewall.exe W32/SDBOT-QH WORM! X MS FIREWALL msfrewall.exe W32/SDBOT-PU WORM! X MS HTML msHtml.exe PESTDOOR.31 VIRUS! X MS HTML mslat.exe LATINUS.SVR VIRUS! X MS HTML Location Class MSHTML32.exe W32/RBOT-YD WORM! X MS Internet Executor 32 MSIXEC32.exe W32/Rbot-AEQ Worm! X MS lsass Startup lsass135.exe RBOT.WM WORM! X MS lsass6 Startup lsass1356.exe variant of the W32/SDBOT WORM! X MS Microsoft Socket Deamon MSSCKD32.exe variant of the WIN32.RBOT WORM! X MS MSN Menssenger 7.0 MSEXPORT.exe variant of the W32/SDBOT WORM! X MS MSN Menssenger 7.0 MSMSN7.exe W32/RBOT-ACA WORM! X MS Network Control mswin.exe DUMBA VIRUS! X ms ownage winPE.exe W32/Rbot-AJL WORM! X MS PLUS INC wpad.exe W32/MYTOB-AN WORM! X Ms Processe Manager msproc.exe RBOT.ATO WORM! X MS Real Player RealPlyr.exe RBOT.MR WORM! X MS Registry Service MSRMS32.exe W32/Rbot-AKP WORM! X MS Remote Procedure Call msrpc32.exe W32/RBOT-QL WORM! X MS Screen Saver scrsave.scr W32/Rbot-AGT WORM! X MS Security Authority Service lsass.exe W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X MS Security Hotfix service5.exe GAOBOT.AG WORM! X MS service msservice.exe W32/RBOT-ZG WORM! X MS Sound Config 16bit sndcfg16.exe SdBot.MB backdoor trojan X Ms Sound Drivers msdrv.exe W32/SDBOT-WR WORM! X Ms Spool32 MS SPOOL32.EXE ASASSIN VIRUS! X MS SyS Restore sysrestore.exe RBOT.XM WORM! X Ms task manager tskmgr.exe SDBOT.CCD WORM! X MS taskbar crssr.exe W32/Rbot-AGO WORM! X MS taskbar nts.exe W32/RBOT-AGB WORM! X MS taskbar taskbars.exe RBOT.BRW WORM! X MS Taskbars taskbars.exe W32/Sdbot-ACV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X MS taskmanager tskmgr.exe W32/Rbot-AKA WORM! X MS UniX navupdate64.exe variant of the WIN32.RBOT WORM! X MS Unix Binary msmq2inst.exe W32/RBOT-YF WORM! X MS Unix Binary msnq3insller.exe variant of the WIN32.RBOT WORM! X MS Unix Binary msnupdate.exe W32/RBOT-AAM WORM! X MS Unix Binary Norton2005Update.exe variant of the WIN32.RBOT WORM! X MS Unix Binary outlookexpressupdate.exe W32/RBOT-YU WORM! X MS Unix Binary trmupdate.exe W32/RBOT-ACC WORM! X MS Unix Binary win32ttb.exe SPYBOT.OQ WORM! X MS Unix Binary Win32Update.exe W32/RBOT-BAS WORM! X MS Unix Binary WinGuard.exe W32/RBOT-ACL WORM! X MS Update syshost.exe W32/Evaman-F worm infection X MS Updates aupd.exe Spyware web downloader X MS Updates mscache.exe Spyware web downloader X MS Updates syshosts.exe W32.Mydoom.Y WORM! X MS Updating Utility msupdater.exe W32/RBOT-XR WORM! X MS USB 2.0 Windows Support msusb32.exe variant of the WIN32.RBOT WORM! X Ms Valud Loader Svhots.exe W32/AGOBOT-SP WORM! X ms window update ?? variant of the WIN32.RBOT WORM! X MS windows Data list process MSDATLST.exe unidentified WORM or TROJAN! X MS Windows procces 32 msprocces.exe W32/Rbot-AEZ Worm! X MS Windows Process Class MSPRCSS32.exe W32/RBOT-YQ WORM! X MS Windows Security Updater updater.pif W32/RBOT-AKY WORM! X MS Windows Update scguard.exe W32/RBOT-YZ WORM! X MS_LARISSA MS_LARISSA.exe W32.Assiral WORM! X MS_NETD_WIN32 netd32.EXE RANDEX.F VIRUS! X MS_SETUP.EXE MS_SETUP.EXE CHARGE VIRUS! X MS_Update Check wdfmgr.exe W32/AGOBOT-TB WORM! X ms64.exe ms64.exe variant of the WIN32.RBOT WORM! X MS7531 ms7531.exe Homepage hijacker X MSACM msacm.exe W32/Opaserv-O worm infection X msadcheck msadcheck32.exe "Browser hijacker, redirecting to search-system.com" X MSAdmin jdbgmrg.exe DASMIN.A VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here X msadp32 msadp32.exe Octa-B trojan infection X MSAgent mshtm.exe "Browser hijacker, redirecting to buldog-search.com" U msaim msaolim.exe MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself! X MSBB msbb.exe nCase adware X Msbb.exe msbb.exe nCase adware X MsBootMgr.exe MsBootMgr.exe BACKDOOR.VERIFY TROJAN! X msbsc ?? Troj/Banker-DF Trojan! X MSChoExE suge.exe variant of the Win32.Rbot WORM! X mscman mscman.exe "Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!""" U mscn mscn.exe Part of the SafeChildNet internet filtering program - required if you use it X Mscnt mscnt.exe Troj/Dluca-C TROJAN! X Mscolour mscolour.exe WIN32.GEMA TROJAN! X MSCommX mscommx.exe Win32.Rbot worm variant X MSCONFG32.EXE MSCONFG32.EXE OPTIX.04.C VIRUS! X MSCONFG32.EXE MSCONFG32.EXE OPTIX.04.C VIRUS! X msconfig msconfig.exe CoolWebSearch parasite related. **Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting N MSConfig MSCONFIG32.EXE "Unidentified adware, spyware or virus" X MSConfig MSCONFIG35.EXE variant of the W32.SPYBOT WORM! X msconfig wins.exe RBOT.PF WORM! X Msconfig lptt01 or Msconfig ml097e msconfig.exe "Variant of the RapidBlaster parasite (in a ""msconfig"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name" X MSConfig Manager msupdate.exe "CoolWebSearch parasite related," N MSConfig or MSConfigReminder msconfig.exe "This is an entry that appears when you uncheck an item in the Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode" X msconfig service MSupdate32.exe W32.SpyBot worm variant X msconfig.exe proxy.exe variant of the WIN32.AGENT.AH downloader TROJAN! X msconfig.exe uline.exe variant of the WIN32.AGENT.AH downloader TROJAN! X MSConfig45 MSConfig45.exe SDBOT.OJ WORM! X MSConfigr jdbgmrg.exe DASMIN.C VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here X MsConfigs MsConfigs.exe ALCAN.A WORM! X MS-Connect arr.execdm.exegame.exemsite18.exeweb.exe Adult content dialler - see here X MSCORE syscnfg.exe "Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside" X Mscsgs MSCSGS.EXE ZEZER VIRUS! X Mscsgs32 MSCSGS32.EXE ZEZER VIRUS! X mscsvc.exe mscsvc.exe PWSTEAL.BANCOS.T and Troj/Banker-CK TROJANS! X Msctrl32 Msctrl32.scr REDIST VIRUS! X MSCVT MSCVT.exe SLIDESHOW VIRUS! X MSDcom MSDcom.exe variant of the W32/SDBOT WORM! X msdev msconfig.exe "AGOBOT.AAU WORM! - Note, this is NOT the legitimate Windows System Configuration Utility as described here" X msdev msdev.exe FORBOT-CR WORM! X MSDLL syscnfg.exe "Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside" X Msdmxm msdmxm.exe Troj/Dload-DC TROJAN! X MSDN nese.exe SDBOT.AHY WORM! X MSDN HELP msdn.exe AGOBOT.AIB WORM! X MS-DOS Boot Service Boot32.pif W32/Rbot-AMF WORM! X MS-DOS Boot Service boot32.pif variant of the WIN32.RBOT WORM! X MSDOS Security Service msdos.pif W32/Rbot-AMP WORM! X MS-DOS Security Service ms-dos.pif W32/Rbot-AMR WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X MSDOS Service MSDOS.PIF W32/RBOT-AIY WORM! X MS-DOS Service MS-DOS.pif W32/Rbot-AII WORM! X MSDOS Windows Service MSDOS.PIF W32/Rbot-AKF WORM! X MS-DOS Windows Service MS-DOS.PIF W32/Rbot-AJW WORM! X Msdos32 Msdos32.pif RECORY VIRUS! X msdos423 msdos423.exe MENACE.A (or W95.SOFUNNY.WORM@M) VIRUS! N MSDTC msdtc.exe MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server X Msemu32 Msemu32.exe Unidentified spyware/adware/hijacker X mservices.exe mservices.exe SDBOT.WJ WORM! X Msfind Msfind.exe CoolWebSearch parasite related. X MSFind32 msfind32.exe CAYAM VIRUS! X msfindosa.exe msfindosa.exe DOWNLOADER-BS VIRUS! X MSFTP Service Config r3grun.exe variant of the W32/SDBOT WORM! X MSFWAVTSM FTPDev.exe W32/RBOT-ACF WORM! X Msg Fixage msgfixed.exe SDBOT.ZD WORM! X MsgApi ?? Dedler-D trojan infection X msgb1 msgb1.exe Win32.Dluca.gen trojan infection N MsgCenterExe RealOneMessageCenter.exe RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way. X msgex32 msgex32.exe W32/APPFLET-A WORM! X Msgmgr ?? BABYBEAR VIRUS! X msgserv_ Syss.exe FANTA TROJAN! X Msgsrv16 Msgsrv16.exe DELF family of VIRUSES! Y MSGSRV32.exe msgsrv32.exe "Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background" X MsgSvcMgr32 cmdzxdll.exe W32/Rbot-AEK Worm! X msgsvr32 msgsvr32.exe "Added as the result of the DEADHAT.B VIRUS! Note - not to be confused with the valid ""msgsrv32.exe"" file which resides in the same directory (C:\Windows\System) on a Win9x/Me machine" U MSGTAG MSGTAG.exe MSGTAG is an application that tells you when your emails have been received and opened. X Msgtray sys16.exe unknown VIRUS! X Mshelp32 mshelp32.exe CoolWebSearch parasite variant X MSHT@ MSHT@.EXE MAGISTR.A VIRUS! X MS-HTML ?? LATINUS.15 VIRUS! X msident msident.exe Unidentified adware or trojan X msidle msidle.exe W32/Opaserv-O worm infection X MsIdle32.exe MsIdle32.exe BACKDOOR.VERIFY TROJAN! X MSIdll winmp.exe variant of the WIN32.RBOT WORM! X MSIE Parsers MSIE32ab.exe SDBOT.MV WORM! X msiew mseiw.exe LITTLOG TROJAN! X MSIEXEC MSIEXEC.EXE VBS/YOSENIO-A VIRUS! X MSIEXEC MSIEXEC32.exe AINESEY.A VIRUS! X MSIMN32 MSIMN32.EXE Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx X Msinet Msinet.exe W32/Rbot-AOA WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X MSInfo AVBgle.exe W32.NETSKY.O WORM! X MSInfo msinfo.exe ALADINZ.M VIRUS! X MSInstall smvss.exe TROJ/DEDLER-G TROJAN! X msjava service xpcd.exe SDBOT.VM worm infection U MSKAGENTEXE MskAgent.exe Part of McAfee Spamkiller X MSKCES32 ?? CLONER VIRUS! U MSKDetectorExe MSKDetct.exe Part of McAfee Spamkiller X MSkernel32 ?? TUXDER VIRUS! X MSKernel32 MSKernel32.vbs LOVELETTER (I LOVE YOU) VIRUS! U MSKExe spamkiller.exe McAfee SpamKiller X mskj mskj.exe Kaemon TROJAN! U MSKServerExe MSKSrvr.exe Part of McAfee Spamkiller X mslagent mslagent.exe Troj/Wintrim-F TROJAN! X MSLARISSA MSLARISSA.pif ASSIRAL.B WORM! X MSLog MicrosoftLog.exe variant of the W32/SDBOT WORM! X Mslogon lptt01 or Mslogon ml097e mslogon.exe "Variant of the RapidBlaster parasite (in a ""Mslogon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X MsManager msmgr32.exe YAHA.AF VIRUS! X msmanager32 msmngr32.exe RANDON-R (or WOMANIZ.A) VIRUS! X msmautoprotect msmssgs.exe TROJ/BIFROSE-AJ TROJAN! X msmc ?? ClientMan parasite variant X msmc mscpbo.exe ClientMan parasite variant X msmc msmc.exe ClientMan parasite variant X MSMcAfeee Avsynmgr32e.exe FRAMAR VIRUS! X MSMcAfeeh Avsynmgr32h.exe FRANGO VIRUS! X MSMcAfeeS Avsynmgr32S.exe VOLAC or VOLAC.DR VIRUSES! X MSMessnger msnupd.exe W32/Rbot-ADY Worm! X msMGR rtkmsg.exe W32/SDBOT-BPY WORM! X Msmgt msmgt.exe Total Velocity adware/hijacker X MSMNTJBE MSMNTJBE.EXE Troj/Bancos-EF TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X MSMNTMTS MSMNTMTS.EXE TROJ/BANKER-GZ TROJAN! X msmon msmon.exe variant of the Win32.GEMA.D TROJAN! U MSMSGS msmsgs.exe "Windows Messenger utility. If you don\'t use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck ""Run this program when Windows starts""" X MsMsgSrv msmsgsrv.exe BACKDOOR-CQO TROJAN! X MSMsgSvc MSMSGSVC.exe "Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!" X msmsngr msmsngr.exe W32/DOPBOT-B WORM! X MSN ctfmoons.exe SPYBOT.HI WORM! X MSN msn16.exe W32/SDBOT-VN WORM! X MSN msnmesengers.exe W32/Rbot-ME worm infection X MSN msnmesengers.exe RBOT-ME WORM! X msn msnmsg.exe W32/Rbot-GO worm X MSN msnmsgr.exe W32.Mytob or W32.Mytob.B WORM! **Note - this is not the valid MSN_Messenger utility X MSN msnmsgs.exe W32/Rbot-KL worm infection X MSN msnsgr.exe unidentified WORM or TROJAN! X msn msnsvc.exe variant of the W32/SDBOT WORM! X msn system32.exe KITRO.A VIRUS! X MSN 9.0 Plus ?? W32/Rbot-ALY WORM! X MSN Administration For Windows msnadp32.exe BROPIA.W WORM! X MSN ang cssrss.exe W32/FORBOT-CE WORM! X MSN BETA service.exe RBOT.AUU WORM! X Msn Config msngf.exe W32/RBOT-QG WORM! X Msn Configuration Loader msngms.exe W32.KELVIR.T WORM! N MSN Internet Access trayclnt.exe "Quick way to connect to MSN internet service - replaces ""MSN Quick View"" from V5.6 onwards" X MSN Manager cvss.exe W32.SpyBot worm variant X MSN Manager mscmgr.exe Unidentified malware - causes multiple browser windows to open X MSN Message Background loader msnmesg.exe variant of the WIN32.RBOT WORM! Note: File name may be different with some of the other variants. X MSN Messages msnmesg.exe W32/RBOT-ACN WORM! X MSN Messanger msnmsng.exe SDBOT.XN worm infection X Msn Messeng windns.exe variant of the WIN32.RBOT WORM! X MSN Messenger IExplorer.exe Troj/Banker-EU TROJAN! X MSN messenger messenger.exe "Unidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread" X MSN MESSENGER msmmsgr.exe W32.KELVIR.Q WORM! X MSN Messenger msmsgs.exe "TROJ/DLOADER-LN or ZLOB-C and Troj/ZlobDrop-C TROJANS! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!" X MSN Messenger msmsgs.exe Zhopa TROJAN! X MSN Messenger msnmsgr.exe AGOBOT.AOQ WORM! - Note - this is not the valid MSN Messenger utility as described here X Msn Messenger msnmsgs.exe "TROJ/LOONY-P TROJAN or the W32.MYTOB.AD WORM! - NOTE: not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!" X MSN Messenger msnmsngr.exe variant of the WIN32.RBOT WORM! X MSN Messenger Reosmsngr.exe variant of the W32.SPYBOT WORM! X MSN messenger service mssgs.exe "Unidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread" X Msn Messenger Update msnupdate.exe variant of the WIN32.RBOT WORM! X MSN Messenger User Controls msmsgr.exe W32.Kelvir.HI WORM! X Msn Messengers MSNMSGR.EXE RBOT.KX worm infection X MSN MMISSENGER mssmmspgr.exe W32.KELVIR.AJ WORM! X Msn Patch msndp.exe RBOT.AAI WORM! X Msn Patches msndr.exe variant of the W32/SDBOT WORM! X Msn Plus Updater msnplus.exe W32/RBOT-MU WORM! X Msn Processe Manager msni32.exe W32/Rbot-ADX Worm! N MSN Quick View Msndc.exe Quick way to connect to MSN internet service X MSN Registry loader msmnwin.exe W32.Kelvir.FK WORM! X MSN Service amsnmsgrs.exe variant of the W32/SDBOT WORM! X Msn Service matrixcam.exe MYTOB.JH WORM! X MSN service msnmgr16.exe variant of the WIN32.RBOT WORM! X MSN service NTDKRN.EXE RBOT.UJ WORM! X Msn Service raloded.exe W32/Mytob-DY WORM! X MSN Start msnmsgr7.exe W32/RBOT-PH WORM! X MSN Update msn32.exe RBOT.AHN WORM! X Msn Update Manager (Sp2) MSMSGS.EXE W32/AGOBOT-NL WORM! X Msn Update Service userx.exe W32.Mytob.JF WORM! X MSN Updater msnms.exe FORBOT-CG WORM! X Msn Updater msnplugins.exe W32/RBOT-HS WORM! X Msn Updater windatemanager.exe SDBOT.TS WORM! X MSN UPDATERS virtualmemory.exe Rbot-JK worm infection X MSN Updates spoolsv32.exe variant of the WIN32.RBOT WORM! X msn.exe son.exe Troj/StartPa-GS TROJAN! X MSN32 X Service MSN32x.EXE unidentified WORM! X MSN8m Startup msn8m.exe variant of the WIN32.RBOT WORM! X msnager32 svchostt.exe WOMANIZ.E TROJAN! N msnappau msnappau.exe "Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to ""update"" the toolbar" X Msnarrator msnarrator.exe NARAT.A VIRUS! - also identified as MPGCOM Toolbar adware X MSNavWH MSWkwrH.exe W32/ANAV-A WORM! X MSNET msnet.exe BOA VIRUS! X MsnExplorer MSEXPLOREN.EXE TROJ/BDOOR-EB TROJAN! X MsnExplorer SHCH.EXE TROJ/BDOOR-EB TROJAN! X MsnExplorer SVCHST.EXE TROJ/BDOOR-EB TROJAN! X MsnExplorer winagent.exe TROJ/BDOOR-EQ TROJAN! X MSNGrabber MSNgrabber.exe W32.ENVID.A WORM! X msngta32 msngta32.exe variant of the WIN32.RBOT WORM! N MSNIA MSNIASVC.EXE Added with MSN version 9. Resets certain internet settings upon bootup and can\'t be disabled via MSCONFIG X msnload32.exe msnload32.exe BANCOS.M TROJAN! X MSNMESENGER Main.exe PRORAT VIRUS! X msnmsg asgag.exe Adware trojan - probably CoolWebSearch parasite related. X msnmsg TBC.exe unidentified TROJAN! X msnmsg.exe mscmd32.exe variant of the WIN32.AGENT.AH TROJAN! X msnmsgq32 msnmsgq.exe WIN32.TACTSLAY.H TROJAN! N msnmsgr msnmsgr.exe "MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck ""Run this program when Windows starts""" X MsnMsgr MsnMsgrs.exe W32/NETSKY-AD WORM! X msnmsgr32-.exe msnmsgr-.exe W32.SpyBot worm variant X MSNMSGR5 MSNMSGR5.exe RBOT.PQ worm infection X MSNMSGRE swef.bat IRC worm or backdoor trojan! X MSNMSGRE swef.bat IRC worm or backdoor trojan! X MSNMSGRR swin.bat IRC backdoor trojan or worm! X MSNMSGRS swe.bat IRC worm or backdoor trojan! X MSNMSGRS swiss.bat IRC worm or backdoor trojan! X MSNMSGRS1 swed.bat IRC worm or backdoor trojan! X msnmsgsgs msnmsgsgs.exe """Catal"" alias Spy.Delitall.B backdoor TROJAN!" X msnmsgy ?? TROJ/BANKER-EQ TROJAN! X MSNPluginSrIvcs n3vasap23.exe variant of the WIN32.RBOT WORM! X MSNPluginSrvcs p6.exe SDBOT.AKJ or W32/Rbot-VJ WORM! X MSNPluginSrvcs sagate.exe SDBOT.AKJ WORM! N MSNProxy MSNProxy.exe MSNProxy - SOCKS4 proxy for MSN Messenger. Desktop shortcut available X msnsched2 msnsched2.exe W32.SPYBOT.NNT WORM! X MSNService MSNService.exe CARPET.C VIRUS! X msnsgs msnsgs.exe Troj/Cheuko-B TROJAN! X msnshed msnshed.exe W32/RBOT-YN WORM! X MSNSysRestore pc32.exe variant of the MASTAK VIRUS! X msnToolbaar msnmsgesc.exe RBOT.BMF WORM! X MSObject32 MSObject32.js PUN VIRUS! X Msoffice msoffice.hta Hijacker - redirecting to Searchdot.net X MSOffice services.exe "Browser hijacker. The file is placed in a newly created MSOffice folder in System32 - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X MSOfficeCfg msocfg.exe Premium rate adult material dialer X MSOfficeCfg navchk.exe Premium rate adult material dialer X MSOfficeCfg qservice.exe Premium rate adult material dialer X MSOfficeCfg shman.exe Premium rate adult material dialer X MSOfficeCfg ssvr.exe Premium rate adult material dialer X M-soft Office M-soft Office.hta HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! X MSOleath32 winss.exe KATHER TROJAN! X MSOOBD MSOOBD.EXE MAGISTR.A VIRUS! X mspaint.exe check32.exe WIN32.AGENT.AH TROJAN! X Mspatch69 ?? MPROX VIRUS! X Mspatch89 cnqmax.exe RANDEX.P VIRUS! X msping msping.exe Trojan.Floodblack Trojan! X MSPluginSrvc p3.exe W32/RBOT-WV WORM! X MSPLUS msplus32.exe W32/MYTOB-AM or W32/MYTOB-CL WORMS! X MSPQFile MSA****.TMP Homepage hijacker. See here for more information. **** can be anything X MSPRO32 ?? W32.Iberio WORM! X MSPRO32 pnp.exe ZOTOB.O WORM! X MSprotect.exe MSprotect.exe W32/Dabyrev-A WORM! U mspwr pupstman.exe """Transparent icon background"" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)?" U mspwr pupxpman.exe Related to Ashampoo's PowerUp_XP N MSPY2002 ImScInst.exe "Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word" X MSR msr.exe AGOBOT.RT WORM! X Msrc Msrc.exe KRYPTONIC GHOST VIRUS! X msreg.exe msrege.exe ZINX VIRUS! X msReg32 Loader msreg32.exe AGOBOT.IU WORM! X MSREGIT Msgp.exe KRYPGHOS (Kryptonic Ghost) VIRUS! U MSRegScan ETNKL.exe ComKeylogger surveillance software. Uninstall this software unless you put it there yourself. U MSRegScan SGP.exe "SpyGator is a spyware program that monitors Internet activity, logs keystrokes, and takes screenshots." X MSRegSvc regsvc32.exe Homepage hijacker that changes your homepage to an adult content site X msrepair msrepair.exe SDBOT.AFL WORM! X msresear ?? Troj/Weasyw-B TROJAN! X msresearch msresearch.exe TROJAN! - 180SearchAssistant adware related X msrundll msrund1l32.exe Backdoor.Binghe TROJAN! X MS-RunKey arr.exe MS-Connect dialler/hijacker X msrunocx32 msrunocx32.exe SKUS VIRUS! X Msrv32 Msrv32.exe AGOBOT-NB WORM! U MSSCDL MSSCDLL.exe SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself! X msserv lvsrev.exe TROJ/BROWMON-B TROJAN! X msserv msserv.exe TROJ/BLACKLOG-A TROJAN! X msserv32 msserv32.exe W32/RBOT-ACK WORM! X msservice msserv.exe HYD VIRUS! X mssfos sfool.exe W32.Randex.EUS WORM! X MSSGisg ?? RANKY.N TROJAN! X MSShow MSShow.exe Troj/QQRob-M TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X MSSHVC MSSHVC.exe NUFFY.A VIRUS! X mssoul msmscc2.exe "Win32.Dapizl.A banker WORM!: ( a ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)" X mssp3 mssp22.exe TROJ/IBANK-D TROJAN! X MSSQL Mssql.exe SDBOT WORM! X Msstart msstart.exe LIVUP.C VIRUS! X MSStartOptimizer Iexpres.exe POLDO.B VIRUS! X MSStartOptimizer WINUPD.EXE "Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return" X msstask msstask.exe MYPARTY VIRUS! X mssurfer lptt01 or mssurfer ml097e mssurfer.exe "Variant of the RapidBlaster parasite (in a ""surfer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware" X mssvc ?? PSK VIRUS! X MSSVC svcsys.exe FATOOS-C TROJAN! Y MSSVC.EXE MSSVC.EXE "Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection" X mssvc32 mssvc32.exe W32/Agobot-ME WORM! X mssys mssys.exe MYSS.B VIRUS! X mssysint comime.exe TROJ/NETSNAKE-I TROJAN! X mssysint Iexplore .exe PWSTEAL.ABCHLP and PSPIDER.310.B VIRUSES! Note - this is not the valid Internet Explorer (iexplore.exe) X mssyslanhelper msmsgri32.exe RANDEX.D VIRUS! X MsSystem msdos.exe Adult content downloader - see here X MsSystem mssys.exe VANTA.A VIRUS! X MSSYSTEM svcsys.exe FATOOS-C TROJAN! X Mstapi Mstapi.exe Keylogger trojan X Mstask mstask.exe "OPASERV.N VIRUS! Note - this is not the ""Scheduling Agent"" and the executable resides in C:\Windows or C:\WINNT" X mstask mstask.exe "Browser hijacker, redirecting to find-more.net" X MSTask run_dll.exe Yuupsearch adware X MStask svchost.exe "TROJ/LDPINCH-BV TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X MSTaskbar 32 tbsvc32.exe RBOT.BQZ WORM! X mstasks mstasks.exe PWSTEAL.OMERSTROKE TROJAN! X Mstng32 MSTng32.exe TANG VIRUS! X MSUpdate criticalUpdate.exe Affilred adware X Msupdate expIorer.exe WIN32.TACTSLAY.A TROJAN! X msupdate msupdate.exe W32/RBOT-MZ WORM! X Msupdate outIook.exe WIN32.TACTSLAY.A TROJAN! X MSUpdate svchosthlp.exe BLASTER.T VIRUS! X Msupdate svchosts.exe variant of the WIN32.TACTSLAY TROJAN! X Msupdate svcrhost.exe WIN32.TACTSLAY.A TROJAN! X Msupdate svcshost.exe WIN32.TACTSLAY.A TROJAN! X msupdate update.exe variant of the W32/SDBOT WORM! X MSUpdate wupd.exe ALADINZ.M VIRUS! X MSupdate.exe ?? CoolWebSearch parasite related. X MSUpdateDevKit axfd.exe W32/SDBOT-ZD WORM! X MsUpdater System udpsys32.exe RBOT.AAA WORM! X MSupdater.exe ?? CoolWebSearch parasite related. X msupdates msupdt.exe W32/Rbot-JO worm infection X MSUpdSrv msupdsrv.exe "Browser hijacker, redirecting to a porn site" X msurl msurl32.exe CRYPTER.A trojan infection X msuser32.exe msuser32.exe ANDROV VIRUS! X MsVBdll MsVBdll.pif W32.Aimdes.A WORM! X MsVBdll sys32dll.exe W32.Aimdes.B or W32.Aimdes.C WORM! X MSVBVM60 MSVBVBM60.pif SCOLD.C WORM! X MSVBVM60 msvbvm60.pif W32/SCOLD-B WORM! X msvc32 msvc32.exe ClientMan parasite variant X msvc32 msvc32.exe W32/AGOBOT-NT WORM! X msvcc msvchost.exe XOMBE VIRUS! X MSVersion ?? POPMON.A VIRUS! - also known as PopMonster adware X msvload32 msvload32.exe W32/RBOT-ACI WORM! X msvsc32 msdev.exe W32/RBOT-GJ WORM! X MSVsmt rpcxctx.exe unidentified WORM or TROJAN! X MSVSync videosync.exe W32.SpyBot worm variant X MSVXD MSVXD.EXE DATOM.A VIRUS! X msw msw.exe Abcsearch.com/DealHelper adware variant X mswave mswave.exe CRYPTER.A trojan infection X Mswavedll mswavedll.exe CRYPTER-C TROJAN! U MSwheel mswheel.exe Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features X MSWin mswin.exe BANKER-CU TROJAN! X Mswincfg Mswincfg32.exe BACKDOOR.CYBSPY TROJAN! X MsWindows SysDate sysmsvc.exe W32.Spybot.FCD WORM! X MSWindows Syspg mspg32.exe W32/Rbot-TB WORM! X MSWindowsUpdate Systern.exe W32/Rbot-AFD Worm! X Mswinpid32 mswinpid32.exe Win32.Lapos.A TROJAN! This is a a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim! X MSWinSrv MSWinSrv.exe MTRON TROJAN! X MSWinSrv32 MSWinSrv32.exe MTRON-B TROJAN! X mswkork Service msework.exe variant of the WIN32.RBOT WORM! X msword msword.exe W32/Rbot-ADR Worm! X mswork Service mswork.exe variant of the W32.SPYBOT WORM! X mswspl plugin1.exe TROJ_SMALL.IQ downloader TROJAN! X mswspl searchbarcash.exe SearchBarCash adware variant X mswspl vnmispoisn_downloader.exe SearchBarCash adware variant X mswspl wmplayer.exe TROJ_SMALL.IQ trojan downloader infection X msxct msxct.exe "eXact_Advertising (NaviSearch, BargainBuddy, CashBack) adware component" X Msy1 Startups msyj32.exe W32/AGOBOT-QQ WORM! X msys lptt01 msys.exe "New variant of the RapidBlaster parasite (in a ""Msyss"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Msys32 morfitwebentrance.exe "Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage?" X MSysDrv msdrv.exe Win32.VB.wf backdoor TROJAN! N MtdAcq MtdAcq.exe "Creative_MediaSource ""Sound Sniffer"", monitors the drive for new media files then automatically adds them to the media library." X Mtr2 mtr2.exe KRYPTONIC GHOST VIRUS! U MUAL mual.exe Millesky video mail updater and launcher U muamgr muamgr.exe "Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs" U MultiCAM Initializer MCamBoot.exe The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled U Multi-function keyboard GWHotkey.exe "Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)" X Multimedia Codecs mcc.exe TROJ/DLOADER-MB TROJAN! X Multimedia extensions ?? Troj/SmutSrch-A Trojan! X Multimedia extensions mservice.exe EasySearch adware U Multimedia KBD MMKeybd.exe Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as Keyboard Manager U MULTIMEDIA KEYBOARD MMKeybd.exe Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as Keyboard Manager U MultiRes MultiRes.exe MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP U MUPS MUPS.exe Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions Y murphy shield lmgui.exe Firewall part of BitDefender virus scanner/firewall N Music01 Server Music01 Server.exe J River Media Jukebox X MusIRC musirc4.71.exe RANDEX.Q WORM! X MusIRC (irc.music.com) client musirc4.71.exe RANDEX.Q WORM! N MutexServiceEx Sys32Smm.exe "Webroot Sofware's discontinued ""Privacy Master""" U MW1HelperStartUp Mw1helper.exe ScreenScenes MagicWaterfall screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30... U mwavscan mwavscan.com "MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive." N MWProEng MWProEng.exe Logitech Mouseware Pro software - only required when using special functions N MWSnap MWSnap.exe MWSnap - screen capture utility. Start manually when required X mwsoemon mwsoemon.exe """My Web Search"" malware" X Mwsvm mwsvm.exe SeekSeek search hijacker related - as seen here X MxHLp32 MxHLp32.exe variant of the VAGRNOCKER VIRUS! U MXO Auto Loader MXOaldr.exe Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions U MXOBG MXOALDR.EXE Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions U MxRunner MxRunner.exe EasyUninstall from Aladdin Systems (formerly by Ontrack) X My Agent msagent.exe NEGASMS.A VIRUS! X My App SMSSvc.exe NEGASMS.A VIRUS! X My Search Bar Eq S4BAREQ.EXE MySearch bar parasite X MyAccessMedia ?? "My AccessMedia toolbar related, stealth installed!" U MyAgtTry MyAgtTry.exe System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications X Myapp ?? FATEE.B VIRUS! X Myapp service.exe Homepage hijacker X MyAV avpguard.exe W32.NETSKY.J WORM! Y MyCIO Agent Service myagtsvc.exe McAfee VirusScan ASaP Agent service U myCIO.com ASaP MyAgtTry.exe System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications N myCIO.com Splash Splash.exe Splash screen for McAfee VirusScan ASaP on-line scanner X MyCometCursor MYCOME~1.EXE Comet Cursor adware X MyDailyHoroscope MYDAIL~1.EXE eConfidence MyDailyHoroscope foistware X MyDailyHoroscope MyDailyHoroscope.exe eConfidence MyDailyHoroscope foistware X MyFastAccess myfastupdate.exe My-Fast-Access toolbar updater U MyIE.exe MyIE.exe MyIE2/Maxthon browser related X MyLife CmdServ.exe HOLAR.A VIRUS! U myNetWatchman nwclient.exe "Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running" X MyPointsPointAlert ?? """With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles"". Dubious privacy policy" U myprint mileage mpm.exe Reports battery status on a portable printer X MySLScan msvc32.exe W32/FORBOT-EH WORM! X mysoft winexplor.exe "Browser hijacker, also detected as the TROJ/STARTPA-JR TROJAN!" U MytekSystrayExePath MyTekSystray.exe MyTek system tray - web site providing computer tech support in Australia X MyTotalSearch Email Plugin mtsoemon.exe MyTotalSearchBar adware X MyVBApp SysNT.exe ReferAd adware X MyVirt.exe MyVirt.exe REMADM-C TROJAN! U MyVitalAgent VtlAgent.exe "MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs" X MyWebSearch Email Plugin mwsoemon.exe MyWebSearch parasite U N2PTray Net2fone.exe "An Internet telephony application. Needed only if you have an account at Net2Phone, Inc" N NADaemon NADAEMON.EXE "Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after ""digital rights management"". One user reports disabling it has no detrimental affect - not required" N Naggerrunkey nagger.exe Packard Bell Free Internet Signup screen Y Naimagent_service EPOAgentnaimas32.exe "Networked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages" Y Naimagent_UI ?? Workstation background program for Network Associates? McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan X Name Iexplorer0.exe THREADSYS VIRUS! X NAP32 NAP32.exe Premium rate adult content dialer X Narrator ?? QOOLOGIC TROJAN! X Natal Natal.scr OPASERV.AE VIRUS! X NAV RuxDLL32.exe MAPSON.D VIRUS! X nAv AGENT ?? "RIOSYS VIRUS! Note the lower-case ""n"" and ""v"" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes" Y NAV Agent navapw32.exe Norton Anti-Virus's background scanning process X NAV Agent systems.exe TARNO.C VIRUS! Note - this is not the valid Norton Antivirus entry of the same name X NAV Agent winsnav.vbs W32.ANPES WORM! X NAV Agent wmilib32.exe Troj/VB-XU TROJAN! X NAV Auto Prot navprot1.exe RBOT.ZAC WORM! X NAV Auto Protect dnsserv.exe variant of the W32/SDBOT WORM! X NAV Auto Protect mcafee32.exe variant of the W32.SPYBOT WORM! X NAV Auto Protect msfwe1.exe variant of the WIN32.RBOT WORM! X NAV Auto Protect navprotect.exe variant of the WIN32.RBOT WORM! X NAV Auto Update Navautoupdate.exe SPYBOT VIRUS! X NAV Auto Updates csrssp.exe variant of the W32/SDBOT WORM! X NAV Auto Updates navupdaters.exe W32/RBOT-UN WORM! X NAV Auto Updates navupdaterx.exe variant of the WIN32.RBOT WORM! X NAV Auto Updates navwindows.exe variant of the W32/SDBOT WORM! X NAV Auto Updates slserver.exe variant of the W32/SDBOT WORM! X NAV Auto Updates slserves.exe variant of the W32/SDBOT WORM! N NAV CfgWiz or NAV Configuration Wizard cfgwiz.exe "Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it" U NAV DefAlert DefAlert.exe Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis X NAV Live Update ?? DEBORMS.C VIRUS! represents the path to the worm. Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec X NAV Scan Service NAVSCAN32.EXE SDBOT.VG worm infection X NAV_Update NAV_Update.exe Unidentified WORM or TROJAN! X NavAgent32 lasvr32.exe FEMOT.D VIRUS! X NavAgent32 SCardSvr32.Exe MOFEI.B VIRUS! X navapp navapp.exe NavExcel adware variant Y navapw32 navapw32.exe Norton Anti-Virus's background scanning process X NAVCheck navchk.exe Premium rate adult material dialer X NAVCheck shman.exe Adult material premium rate dialer U Naviscope naviscope.exe "Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more" X NaviSearch nls.exe eXact Advertising BargainBuddy/NaviSearch adware X navman_20 sysnav32.exe CoolWebSearch parasite related. X NAVNet ?? Unidentified adware X navp.exe navp.exe W32/AGOBOT-OE WORM! X NavPass NavPass.exe Free system for gaining access to and downloading from adult content web-sites N NavRegReminder NavLoad.ini "Corel, HP or ScanSoft registration reminder; not required" X NavScan ?? OBSORB VIRUS! X NAVSCAN32.EXE NAVSCAN32.exe W32/SDBOT-DO WORM! X NAVSCANNER32 NAVSCANNER32.EXE RBOT.QC WORM! X NAVUpd ?? NAVU VIRUS! X nawadll32 nawadll32.exe W32/Sdbot-ZI Worm! X nawdll32 nawdll32.exe W32/Sdbot-ZM Worm! N NB Common Dialog Enhancements COMDLGEX.EXE "Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs" N NB Start Menu STARTM.EXE Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B N NB Windows Patterns WINDBKGND.EXE "Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows" U NBJ NBJ.exe Ahead Nero BackItUp backup program. Only required for if you have scheduled back-ups U NbkCtrl NbkCtrl.exe Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here X NBT System alias ?? variant of the RANDON.AN WORM! X Ncao osoa.exe PurityScan/Clickspring adware X Ncao urpo.exe PurityScan/Clickspring adware N NCD ncd.exe Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path N NCS_SS Csinsm32.exe Same as CleanSweep Smart Sweep-Internet Sweep X NDAv csnss.exe W32.Serflog.C WORM! X NDAv svhost.exe W32.Serflog.C WORM! X NDIS Adapter lsass2.exe WOOTBOT.CW WORM! X NDIS Adapter ndis.exe SDBOT.VF worm infection X NDIS Adapter servenxpp.exe W32/FORBOT-GP WORM! X NDIS Adapter servenxpp.exe W32/Forbot-GP WORM! X NDIS Adapter windows.exe W32/FORBOT-BR WORM! X NDplDeamon nstask32.exe RANDEX.E WORM! X NDplDeamon winlogin.exe RANDEX.E WORM! U NDPS DPMW32.EXE Novell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature X NDrv NDrv.exe PurityScan/Clickspring adware U NDSTray NDSTray.exe "ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have." N Necbar Necbar.exe "Nec Assistant; Ark's Navigator, a graphical interface for NEC computers" Y NECMFK necmfk.exe NEC wireless keyboard driver U Necutray Necutray.exe "Driver for external USB storage devices (hard drives, flsh disks, etc)" X nero nrchk.exe Premium rate adult content dialer X Nero shch.exe variant of the TROJ/BDOOR-EB TROJAN! X Nero Updater.6.12 wmp9.exe W32/Agobot-AAG Worm! X Nero.ma ?? JONBARR.D VIRUS! where is 2 or 3 random digits X NeroAutoStartClient NeroASM.exe AGOBOT.VG WORM! U NeroCheck nerocheck.exe "Associated with ""Nero Burning Rom"" CD writing software. Checks for driver issues" X NeroCheck regedit.exe "DOOMJUICE.B VIRUS! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)" U NeroFilterCheck NeroCheck.exe "Associated with ""Nero Burning Rom"" CD writing software. Checks for driver issues" X NeroLoader NeroLoader.exe Troj/Bancban-EJ TROJAN! N NeroNETTrayIcon NNServiceCtrl.exe System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network X NeroUpdater6.8 winjava.exe AGOBOT.AMK WORM! X Net WINREG.EXE ASSASIN.D VIRUS! U Net Accelerator NetAccelerator.exe "Rizal NetAccelerator - ""Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???"". Only required if you find it helps improve your performance" U Net Activity Diagram nad.exe Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs X NET Bios Stats ntbstats.exe W32/Sdbot-ZX WORM! U NetAccelerator NetAccel.exe "NetAccelerator is a ""software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance" X NetAdm7 NETADM7.EXE BANCOS.F VIRUS! X Netapi Netapi.exe NETDEVIL.14 (NetDevil 1.4) VIRUS! X netapi32 netapi32.exe unidentified TROJAN! X NetApp winserv.exe SHADOWTHIEF VIRUS! X Netbios Helper nbthlp.exe PWS-BANKER.Y password stealing TROJAN! X netconfig netconfig.exe NETCONF VIRUS! U NetCruiser Dialer NCDialer.exe "NetCruiser Dialer from NetCruiser Software. ""An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections""" X netdaemon netdaemon /v "Malware designed to ""kill"" a number of antispyware applications: (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)" X netdll32 netdll32.exe CRYPTER.A trojan infection X netdllex netdllex.Exe CRYPTER.A trojan infection X NetDy VisualGuard.exe W32.NETSKY.N or W32.NETSKY.W WORM! X NETFP32.EXE NETFP32.EXE TrojanDownloader.Win32.Agent.cd U NetGuard NetGuard.exe FBM Software ZeroSpyware 2004 spyware detector and remover; real time monitor. N Net-It Launcher NILaunch.exe Net-It - web publishing software U Netlimiter Netlimiter.exe "Netlimiter - ""An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC.""" N Netline User netchk.exe "Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example" X NetLink netlink32.exe GAOBOT.WO WORM! X NetLogon userint.exe W32/SDBOT-BC WORM! U NetManageImport nmcpdata.exe NetManage business software related X NetManagerService ntss.exe BESTPICS.A VIRUS! X NetMeter NetMeter.exe NetRatings Premeter spyware X NetMon netmon.exe W32.MIMAIL.M WORM! X Netmonw Netmonw.exe TROJ/BDOOR-FX TROJAN! U netmsg netmsg.exe "Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well." U NetPatrol winclient.exe NetPatrol network monitoring software X netpc32.exe netpc32.exe "Malware, probably CoolWebSearch parasite related" N NetPerSec NetPerSec.exe NetPerSec - measures the real-time speed of your Internet connection X NetPumper NetPumperIEProxy.exe "NetPumper download manager - bundles Cydoor and SaveNow adware, see here" X NetReach nrcheck.exe unidentified VIRUS! X Netropa Internet Receiver Netropa.exe Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware U NetRun NetRun.exe "NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost" N Netscape Messenger NETSCAPE.EXE "In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed" N Netscp6 Netscp6.exe Netscape 6 U NetScreen-Remote SafeCfg.exe NetScreen_Remote VPN Client Software X NetService ntsvc.exe Troj/QQPass-DU TROJAN! X NetService ntsvc.exe Troj/QQPass-DU TROJAN! X NETServices csxrs.exe variant of the W32/SDBOT WORM! X netservices recall.exe variant of the W32/SDBOT WORM! X netservices svchostn.exe SDBOT.GI WORM! U NetShow Powerpoint Helper NSPPTHLP.EXE "If disabled, user created fonts can no longer be seen by other programs" N NetStat Live Nsl.exe AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data X netsv32 netsv32.exe W32/Sdbot-PX worm infection U NetTime NETTIME.EXE "From a visitor - ""This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP.""" U NetTurbo netturbo.exe "NetTurbo from SharewareOnline.com. ""Accelerate Your Internet Connections by up to 600%"". If you find it helps your connectivity leave it enabled" X Netunit32 wunit32.exe unidentified WORM or TROJAN! X NetWatch32 netwatch.exe W32.MIMAIL.C WORM! N Netword Agent nwant33.exe "An interesting browser utility that allows you to navigate by typing a single word or phrase (a ""NetWord"") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs" X NetWork csrs.exe AGOBOT.JJ WORM! X Network Access winssh.exe variant of the W32/SDBOT WORM! X Network Administration NAS.exe ANTILAM.20.Q VIRUS! X Network Administration Service rsvc32.exe RBOT.ABH WORM! U Network Associates Error Reporting Service TBMon.exe Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software X Network Connections internat.exe TROJ/VB-ZD TROJAN! X network device driver msfirewall.exe Troj/Delf-LB TROJAN! U NetWork Device Switch NetDevSW.exe Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary X Network Host Controller ?? WHISPER VIRUS! X Network protocol service wintcp.exe variant of the GAOBOT/AGOBOT WORM! X Network Protocol Service wuamgrd.exe WORM_RBOT.EA X Network Security secsvc.exe W32/Rbot-ALX WORM! X Network Security Guard ?? Troj/Colem-A TROJAN! X Network Security Guard ?? CoolWebSearch parasite related. X Network Service svchost.exe "Hijacker, also detected as Win32.Omal.C Trojan." X Network Service svhost.exe Troj/HacDef-K TROJAN! X Network Service Manager netsvc.exe variant of the GAOBOT/AGOBOT WORM! X NetworkAssociates Inc internet.exe variant of the LOVGATE WORM! X NetworkClient NetworkClient.exe LEMUR VIRUS! X Networks Configurator NetConfs.exe W32/RBOT-OX WORM! X Networks Controler Netsis.exe W32/RBOT-NG WORM! N NetworkSetup dlink.exe D-Link System Tray icon N NetZero_uoltray exec.exe regrun Netzero free ISP software - not required X Netzip Smart Downloader npnzdad.exe Advertising spyware N NetZIPFolders nzfprop.exe Netzip Classic zip file manager X NeuroMedia(IESpeaker) NeuroMedia.exe Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available N NeuroSpeech OESpeaker OEMonitor.exe Part of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not X New Csnm Manager csmn.exe SDBOT.BZS WORM! X New.net or NEWDOT~1 ?? NewDotNet foistware X New.net Startup ?? NewDotNet foistware N Newsalrt NEWSALRT.EXE MSNBC News system tray utility to alert you to new news X Newsgroup lptt01 or Newsgroup ml097e newsgroup.exe "Variant of the RapidBlaster parasite (in a ""newsgroup"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" N NewsUpd newsupd.exe For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here. X NewtonKnowsUpd ?? NewtonKnow hijacker U NFM Service NPDOR9x.exe Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required N nForce Tray Options sstray.exe "nVidia nForce Taskbar Utility - quick access to the nForce2 ""Sound Storm"" control panel and related utilitys" U NGClient ngctw32.exe "Symantec Ghost Server software - needed for a ""a Ghost multicast"" (transfer images to multiple machines). Can be launched manually" X ngpw36 ngpw36.exe AdBlaster adware variant N NGServer ngserver.exe Symantec/Norton Ghost Console service X NI.UWFX5 UWFX5NetInstaller.exe "WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here" X NI.UWFX5LP_0001_0802 UWFX5LP_0001_0802NetInstaller.exe "WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here" X NI.UWFX5LP_0001_0803 UWFX5LP_0001_0803NetInstaller.exe "WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here" X NI.UWFX5V_0001_0802 UWFX5V_0001_0802NetInstaller.exe "WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here" X NiceDownloads ?? MatrixDialer related N Nielsen NetRatings insight.exe "Nielsen NetRatings -? ""Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site?s audience and your customers"". Is it required?" X nikLaus nikLaus.exe NIKLAS VIRUS! N NInit NInit.exe Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required Y nisserv NISSERV.EXE Norton Personal Firewall Y Nisum NISUM.EXE Norton Personal Firewall U niSvcLoc niSvcLoc.exe Related to National Instruments Corp. LabView X NJG40 NJG40.EXE BANCOS.D VIRUS! N NkvMon.exe NkvMon.exe Nikon View 5 - for transferring pictures from Nikon digital cameras N NkVwMon.exe NkVwMon.exe Nikon View - for transferring pictures from Nikon digital cameras X NLS Keyboard keyboard.exe variant of the W32.SPYBOT WORM! Y NMSVC nmSvc.exe "Covenant Eyes -?surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it" X nnmgr nnmgr.exe Adware.FFToolBar adware toolbar. U NNSvc nnsvc.exe NetNanny internet filter X No Credit Card plugin-.exe Adult content pop-up dialler U NoAds NoAds.exe Blocks advertisement banners in Internet Explorer U NoAdware NoAdware "NoAdware Adware/Spyware remover - initially considerered a ""rogue"" program - see here . The latest version has since apparently mended its ways: see note" U NoAdware3 NoAdware3 "NoAdware Adware/Spyware remover - initially considerered a ""rogue"" program - see here . Has since apparently mended its ways: see note" X Nod32 Free antivirus nod32krn.exe W32/RBOT-AAO WORM! U Nod32CC nod32cc.exe Control Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button Y NOD32kernel Nod32krn.exe Nod32 Antivirus Version 2 Y nod32kui nod32kui.exe Nod32 Antivirus Version 2 Y NOD32POP3 Pop3scan.exe POP3 E-mail part of Eset's NOD32 virus-scanner X Nod3d2 Free antivirus N0D32KRN.EXE W32/RBOT-ABQ WORM! X nodriver AUEKXRZ.EXE variant of the SPYBOT VIRUS! X Noha aasd.exe PurityScan/Clickspring adware U No-IP DUC DUC20.exe Part of http://www.no-ip.com?provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available N Nokia Connection Monitor NclConf.exe "Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required" U Nokia Tray Application NclTray.exe "Nokia PC Suite 5 - ""A collection of powerful tools that you can use to manage your phone features and data."" Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on" U NOMAD Detector ctmnrun.exe Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected N NomdCheck nomdchek.exe Part of Intel's Native Audio U Norman ZANDA ZLH.EXE System Tray icon for Norman Antivirus X NortE Antivirus norte.exe RBOT.BQQ WORM! X NortE Antivirus norten.exe W32/Rbot-AFF Worm! X Norton Antivirus 7.0a ?? PERDA-B or RANCK-CT TROJAN Y Norton AntiVirus AutoProtect navapw32.exe Norton Anti-Virus's background scanning process. X Norton Antivirus AV FVProtect.exe W32.NETSKY.P WORM! **Note - this is not the popular AV software! X Norton AntiVirus Sys NAVsys32.exe variant of the W32/WOOTBOT WORM! X Norton Auto Protect crss32.exe SDBOT.ATF WORM! X Norton Auto Protect nava.exe unidentified WORM or TROJAN! X Norton Auto-Protect ccApp.exe "W32.Ahker.D WORM! **Note - for the valid Norton AV entry the filename is ""navapexe"". This is also not the valid Norton_AV_2003 file with the same filename" Y Norton Auto-Protect navapw32.exe "Norton Anti-Virus's background scanning process. Can be inconvenient because it scans files when Run/Opened or Downloaded/Created and you can scan files manually via right-click after downloading/copying. However, in light of some of the viruses around these days it's probably best to put up with the inconvenience" X Norton Auto-Protect SERVICES.exe W32.Ahker.B WORM! X Norton AV Protection Startup Ati2xxx.exe variant of the WIN32.RBOT WORM! N Norton Crashguard Monitor cgmenu.exe Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001 N Norton Disk Doctor Ndd32.exe "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well" Y Norton eMail Protect POPROXY.EXE "Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it" X Norton Firewall ?? Troj/Banker-ET TROJAN! N Norton Ghost 9.0 GhostTray.exe Norton_Ghost tray icon - the application can be launched manually X Norton Guard 32 ntguard32.exe variant of the WIN32.RBOT WORM! X Norton Live Update Server cpsdv.exe AGOBOT.EW WORM! X Norton Live Updater Cavapsvc.exe GAOBOT.AO WORM! X Norton Live Updater Sochost.exe GAOBOT.AO WORM! N Norton Navigator Loader nnloader.exe An older Norton utility for file management under Windows 95. More information here Y Norton Personal Firewall IntroWiz.exe Part of Norton Personal Firewall or Norton Internet Security X Norton Personal Firewall jah.exe variant of the W32/SDBOT WORM! X Norton Personal Firewall lah.exe variant of the WIN32.RBOT WORM! X Norton Personal Firewall npfw.exe W32/RBOT-UI WORM! X Norton Personal Firewall npfw32.exe W32/RBOT-UQ WORM! U Norton Program Scheduler NPSsvc.exe "Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans" U Norton Program Scheduler nsched32.exe "Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans" X Norton Protect npprotect.exe W32/RBOT-WW WORM! X Norton protect nvsvc.exe variant of the WIN32.RBOT WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here X Norton Protect Activies csrss.exe Troj/Banker-CZ TROJAN! X Norton Service Driver wsul.exe W32/RBOT-ABI WORM! X Norton Service Process navapvc.exe variant of the AGOBOT/GAOBOT WORM! X Norton SpySweeper AutoUpdate navsw.exe W32/Forbot-AS worm infection X Norton Swap Cleaner nortonswap.exe W32/Rbot-MH worm infection N Norton System Doctor Sysdoc32.exe "Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well" N Norton SystemWorks cfgwiz.exe Norton SDystem Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it X Norton Update ccUpdate.exe variant of the GAOBOT/AGOBOT WORM! X Norton Update winsvc.exe AGOBOT.ALP WORM! X Norton updated NVSV32.EXE SDBOT.ABH WORM! X Norton Updater ccUpdate.exe variant of the AGOBOT/GAOBOT WORM! X Norton Updater lsa.exe variant of the WIN32.RBOT WORM! X Norton Updater navupdtr.exe SDBOT.AXV WORM! X Norton Updater NortonUpdate.exe unidentified WORM or TROJAN! X Norton Updater winset.exe variant of the W32.SPYBOT WORM! X Norton Wizzard nwiz.exe GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name X norton32 norton32.exe Unidentified worm or trojan X NortonAntivirus LSASS.exe W32.Pexmor WORM! Note: This (LSASS.exe) is not the legitimate Windows Process and has nothing to do with NortonAntivirus. The legitimate Windows Process (Lsass.exe) is found in the System32 folder and should not be seen in Msconfig or as a Startup item. This worm file is found in the Windows\Temp or Winnt\Temp folder. X NortonAV norton_antivirus.exe BACKDOOR.NETJOE TROJAN! **Note: this is not the legitimate Symantec AV program X Nortons AV SYSTEM scvchost.exe variant of the WIN32.RBOT WORM! X nortonsantivirus ccEvtMngr.exe TROJ/HZDOOR-A TROJAN! X NortonVPlus svchost.exe Troj/Roamer-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. U Notebook Maximizer maximizer_startup.exe Toshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency X NOTEPAD NOTEPAD.exe "Added as the result of the RUSTY VIRUS! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! - This malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X Notepad lptt01 or Notepad ml097e notepad.exe "Variant of the RapidBlaster parasite (in a ""nvd32"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name" X notepad.exe msmsgs.exe TROJ/ZLOB-I and Troj/Zlob-H TROJANS! X notepad.exe msmsgs.exe "variant of the Troj/FAKESPY-B TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!" X notepad.exe upx.exe variant of the WIN32.AGENT.AH TROJAN! X notepad2.exe popuper.exe Troj/Puper-C and TROJ/PUPER-E TROJANS! X notes notepaad.exe RBOT.BME WORM! X Notn Eber.exe PurityScan/Clickspring adware X Notn wtta.exe PurityScan/Clickspring adware U NovaBackup * Tray Control NbkCtrl.exe Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html * represents the version number U Novast or Schedulerd SCHENGD.EXE NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it X NOYPI_KANG_ASTIG Exit to DosPrompt.pif W32.Filukin.A WORM! X NPF Value NPFMONTR.exe variant of the W32.SPYBOT WORM! U NPROTECT nprotect.exe Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here X NS ns.exe W32/AGOBOT-HS WORM! X NSCheck NSCHECK.EXE NetSetter/Marketscore foistware X nscntrl nscntrl.exe Troj/Dload-DC TROJAN! X nsdcmd services nsdcmdav.exe variant of the AGOBOT/GAOBOT WORM! X nsdcmd vid process nsdcmdwin.exe variant of the AGOBOT/GAOBOT WORM! X nsdlua nsdlua.exe All-In-One Telcom - adult content dialler X nsdriver nssys32.exe NetShagg adware X nse nse.exe AGOBOT-ML WORM! U Nsengine Nsengine.exe Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here U NSHelper aexnsinstallhelper.exe Altiris Express Notification Server Install helper - monitors integrity of the installation X nssysconf ?? VIVIA.A trojan variant X nstat netstat.exe adult material dialer X NsUpdate NsUpdate.exe Dial/Laet-B Dialer! Note: This is a premium rate dialer application and can run up very large phone bills. X Nsv nsvsvc.exe Delfin_Promulgate adware X nsvcin n20050308.exe "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X Nsvdr nsvdr.exe Adult content dialler U nsys nsys.exe NetSpy keystroke logger/monitoring program - remove unless you installed it yourself! X nsys32 nsys32.exe W32/Agobot-SU Worm! N NSystemMonitor Symmon.exe Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging N NT Kernel Patch ntkrnlpt.exe FaxServe network fax software X NT Logging Service Syslog32.exe W32/SDBOT-ACK WORM! X NT MICROSOFT SVCD ntvsvcd.exe variant of the WIN32.RBOT WORM! X NT security rundll32.com W32/Rbot-AJC WORM! X NT Service NTOKSRNL.EXE W32/RBOT-AAG WORM! X NT Services ntsvc.exe AGOBOT.VJ WORM! X NT Video API32 NTAPI32.exe W32/RBOT-FW WORM! X NT Virtual Machine ?? W32/SCAERBOT-A WORM! X Ntcheck mapserver.exe TROJ/TOMPAI-B WORM! X ntddetect ntddetect.exe TROJ/AGENT-CU or BDOOR-ZAU TROJANS! X NTdhcp NTdhcp.exe TROJ/QQROB-F TROJAN! X ntdll ntdll.exe BIONET.404 VIRUS! X NTDLM csrss.exe "HALE VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling as this resides in c:\winnt\system32\qossrv" X Ntech.patchs ?? LEMIR.G VIRUS! X ntechin n20050308.exe "Adware downloader, Delphin_Media_Viewer related, also detected as the DELMED.A TROJAN!" X NTFS16 ntfs16.exe W32/Rbot-LY worm infection Y NTFSCLUP NTFSCLUP.EXE "Part of ConfigSafe- ""checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99 % of the time it will only execute about a dozen instructions before exiting""" X ntfsmonitorpro ntfs64.exe W32/FORBOT-EB WORM! X NTFSS Microsoft System filees.exe RBOT.GAB WORM! X NTFSS MICROSOFT SYSTEM filess.exe RBOT.AXZ WORM! X ntldr ntldr.exe "Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: * Creates file C:\WINDOWS\SYSTEM\ntldr.exe. * Creates file C:\m.exe. * Creates file C:\WINDOWS\Search-For-You.url. * Creates file C:\n.bat. * Deletes file c:\q.exe. * Creates file C:\q.exe. * Creates file C:\r.bat" N ntlfreedom "RyDial.dll, QuickStart" NTL Freedom ISP software - reportedly not required X ntmsevt ntmsevt.exe TROJ/STOPED-B TROJAN. X NTP Server ?? RANKY.F VIRUS! Y nTrayFw ntrayfw.exe Software interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets N NTrtc ntrtc.exe Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here X NTSet32 services.exe Troj/WinSpy-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\dll32 or Winnt\dll32 folder. X NTSF MICROSOFT SYSTEM fufffy.exe W32/Rbot-AEL Worm! X NTSF Microsoft System fylez.exe variant of the WIN32.RBOT WORM! X NTSF Microsoft System ntsf.exe RBOT.ARQ WORM! X NTSF MICROSOFT SYSTEM ntssf.exe variant of the WIN32.RBOT WORM! X NTSF MICROSOFT SYSTEM scvhost.exe variant of the WIN32.RBOT WORM! X NTSF MICROSOFT SYSTEM winsis32.exe variant of the WIN32.RBOT WORM! X NTSF MICROSOFT SYSTEM wntsf.exe RBOT.ATC WORM! X ntsmod ntsmod.exe "adware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!" X NTsocket NoeWinnt.exe Ataka-E TROJAN! X NTsrv.exe NTsrv.exe variant of the SERVU-O TROJAN! U nTune nTune.exe nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards X ntupd32 ntupd32.exe See_Here X ntupdate dnsvc.exe W32/SDBOT-TC WORM! U NTVDM NTVDM.EXE "Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS\'s (Windows NT, 2K and XP). Required if hardware on a machine with these OS\'s needs 16-bit DOS drivers. You can find a bit more about NTVDM here" X ntvdmd ntvdmd.exe Adware downloader - also detected as the TROJ/DLOADER-YP TROJAN! X ntvdscm ntvdscm.exe Troj/ScKeyLog-I TROJAN! X NT-Virtual Device Manager ntvdmn.exe W32/SDBOT-AAA WORM! Y NuTCSetupEnviron ncoeenv.exe "Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone" X NvagNT nvagNT.exe W32/AGOBOT-RV WORM! X nvc Win32 nvcvc.exe W32/Rbot-ADD Worm! X NvClipRsv rsv32.exe Troj/Tofger-X trojan infection X NvClipRsv svchost.exe W32/Dumaru-AK WORM! X NvClipRsv swchost.exe W32/Dumaru-AK WORM! X NVCOM NVCOM.exe W32/AGOBOT-SB WORM! X NvCpl ?? W32/AGOBOT-APJ WORM! U NvCpl ?? Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card X NvCpl NvCpl.EXE W32.YANZ.B WORM! U NvCpl NvStartup Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card X NvCpl windowsp.exe variant of the W32/SDBOT WORM! X NvCplD m2gr32.exe """Switch"" premium rate adult content dialer" X NvCplD ntcpl.exe """Switch"" adult content dialer" U NvCplDaemon ?? Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card N NvCplDaemon ?? "System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the ""NVIDIA Driver Helper Service"" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)" U NvCplDaemon NvStartup Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card X NvCplDaemon32 anvshell32.exe Troj/VB-XU TROJAN! X NvCplDeamon nvdisp.exe Troj/PeepVie-I TROJAN! X NvCplDmn NAVSVC.EXE unidentified VIRUS! X NvCplScan kav32.exe W32/FORBOT-EW WORM! X NvCplScan msc32.exe W32/FORBOT-DD WORM! X NvCplScan nvsc32.exe W32.Kelvir.D WORM! X NvCplScan winasp.exe FORBOT.BZ WORM! X nvd32 lptt01 or nvd32 ml097e nvd32.exe "Variant of the RapidBlaster parasite (in a ""nvd32"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Nvid ?? Unidentified adware X Nvid32 Nvid32.exe GEMA TROJAN! X Nvidex32 Nvidex32.exe GEMA TROJAN! Y NVIDIA ActiveArmor ntrayfw.exe Software interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets X Nvidia Control Daemon nksvc32.exe W32/AGOBOT-OV WORM! X Nvidia Control Panel ncsvc32.exe "Worm, as yet unidentified" X NVIDIA Driver MSPMSPSU.EXE WORM_WOOTBOT.Y infection N NVIDIA nForce APU1 Utilities NVATray.exe "nVidia's nForce Audio Processing Unit (APU) ; provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time." U NVIDIA nTune nTune.exe nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards U NVidia System Utility NVSystemUtility.exe "The NVidia_System_Utility lets you adjust bus speeds, hardware voltages, memory controller timings, and fan speed as well as additional settings to increase performance aggressiveness and hardware voltages. Will also display a dynamic graph of CPU and system temperatures, hardware voltages, and memory bus speeds." X NVIDIA Video drivers video_32D.exe AGOBOT.KV WORM! X NVIDIA Video drivers video_32sD.exe W32/RBOT-BB WORM! X Nvidia32 nvidia32.exe CoolWebSearch parasite related. N NvidiaQuickTweak or NVQuickTweak ?? System Tray icon used to change display settings for nVidia based graphics cards. Unnecessary since you can easily configure these settings the way you want them in the Display Properties X nvidll32 nvidll32.exe W32/RBOT-XK WORM! U NVIEW ?? This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers X nviload32 nviload32.exe W32/SDBOT-VT WORM! X nviload32 nviload32.exe W32/SDBOT-VT WORM! N NvInitialize ?? Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled X nvirundll nvirundll.exe W32.SPYBOT.NPS WORM! X nvjxue nvjxue.exe W32/EYEVEG-J WORM! Y NVmax NVmax.exe NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card N NVMCTRAY ?? "System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties" N NvMediaCenter ?? "System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties" N NVMixerTray NVMixerTray.exe System Tray access to audio controls from nVidia's motherboard ForceWare software X nvmsgdwn NVMSGDWN.EXE Troj/Graber-D TROJAN! Note: This trojan file is found in the Windows or Winnt folder. X NvMsnW Isass.exe WIN32.BROPIA.K WORM! Y NVRaidService nvraidservice.exe nVidia NVRaid - hard disk striping/mirroring utility for increased performance and reliability. Required if you have a RAID setup N NVRT nvrt.exe NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports X nvsv32.exe asr_fnt.exe WOOTBOT.GE WORM! X nvsv32.exe cstr.exe variant of the W32/SDBOT WORM! X nvsv32.exe nvsv32.exe W32/FORBOT-DI WORM! X nvsv32.exe nvsv33.exe WOOTBOT.FP WORM! N NvSvc nvsvc.exe "NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that" X NVSVC nvsvc.exe AGOBOT.ALX WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file as described here X nvsvca32 nvsvca32.exe WIN32.TACTSLAY.E TROJAN! X NVSystem32 nvscv32.exe W32/Agobot-NO WORM! X NvUpdater nwiz32.exe variant of the WIN32.RBOT WORM! X NvXplDeamon xstyles.exe SMALL.AJ VIRUS! N nwiz nwiz.exe "Associated with the newer versions of nVidia graphics cards drivers.? Allows you to immensely improve desktop layouts by setting preferences and optimizations.? However, this isn't necessary for the operation of your system" X nwiz32 nwiz32.exe Troj/Sinbank-A TROJAN! Y Nwpopup Nwpopup.exe "Broadcast message handler part of Novell_Netware that displays server, printer and other messages." U nwrecmsg nwrecmsg.exe "Broadcast message handler part of Novell_Netware that displays server, printer and other messages - can cause crashes" U nwss Sp0.exe SpyOutside surveillance software. Uninstall this software unless you put it there yourself. Y NWTRAY nwtray.exe "Novell Netware. Displays the red ""N"" tray icon which can be disabled (by right-click on the icon) but is also needed by the client" Y oahstifr oahstifr.exe "Comes with HyperTextStudio. From the supplier - ""The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up.""" U OAKSTART OAKSTART.EXE Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. N OAKTASK OAKTASK.EXE "Taskbar utility for a ""control panel"" for a CD-RW" Y Object Store Server osserver.exe "Comes with HyperTextStudio. From the supplier - ""The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up.""" N OCAudioIni OCAudioIni.exe One-click Audio Converter - allows you to convert files of multiple audio formats right from Windows Explorer N ocraware ocraware.exe "Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs" X ocx32 ocx32.exe ASTEF or RESPAN VIRUSES! X OCXUPDT32 ocxupdt32.exe W32/AGOBOT-IF WORM! X OD SYSCNTR.EXE HotVideo dialler U ODBC BackUp fdxxl.exe "G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!" X oddworldz.exe oddworldz.exe Troj/Multidr-EG TROJAN! X od-matrxx od-matrxx.exe Adult dialler - xx can be any number N Odometer Odometer.EXE Mouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available U ODSPConfig ODSPConfig.exe DsktopSurveil surveillance software - get rid of it unless you installed it yourself! X od-stndxx od-stndxx.exe Adult dialler - xx can be any number X od-teenxx od-teenxx.exe Adult dialler - xx can be any number X Oeloader Oeloader.exe "Xupiter OrbitExplorer toolbar related, drive-by foistware" X OEM Tools 32 tres32.exe RBOT.QB worm infection X OEM32 Tools sres32.exe W32.SpyBot worm variant N OEMCLEANUP or OEMRESET oemreset.exe Resets OEM installation settings at bootup. Not required unless you\'re new to PC\'s U OEMRUNONCE oemrun.exe Windows Millennium file - used by setup when installing the OEM 'express' version of the operating system. Uncheck after setup has finished. U oeplugin bxOEPlugin.exe noHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple text. U OESpamTest OESpamTest.ExE Kaspersky_Anti-Spam N OEXCheck EA2Check.exe "Express Assist from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others" X Offer Companion or Offers offers.exe Advertising spyware X Office Startup Exploer.exe GAOBOT.BV WORM! **Note - This is not a valid MS Office entry X Office Startup exploer.exe AGOBOT.BV WORM! N Office Startup "Osa.exe, Osa9.exe" "Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show." X OfficeAgent expIorer.exe WIN32.TACTSLAY.A TROJAN! X OfficeAgent outIook.exe WIN32.TACTSLAY.A TROJAN! X OfficeAgent svcrhost.exe WIN32.TACTSLAY.A TROJAN! X OfficeAgent svcshost.exe WIN32.TACTSLAY.A TROJAN! X OfficeDeamon msorunner.exe variant of the WIN32.TACTSLAY TROJAN! Y OfficeGuard RegChecker ogrc.exe Kaspersky Labs anti-virus X OfficeGuardUI svcss.exe DEDLER-C TROJAN! X OfficeQuickAccess OfficeHost.vbs W32.Pexmor WORM! Note: This worm file is found in the Windows\Temp or Winnt\Temp folder. X Offices msnmgd32.exe W32/FORBOT-DV WORM! Y OfficeScan95 pccwin97.exe Trend Micro antivirus OfficeScan Y OfficeScanNT Monitor pccntmon.exe Trend Micro OfficeScan Antivirus real-time scan monitor X OFFICEXP OFFICEXP.exe WOOTBOT.HE WORM! N OfotoNow USB Detection ?? Autodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs Y ogrc ogrc.exe Kaspersky Labs anti-virus N Oil Change OCTray32.exe From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs X OLE ?? STAWIN or TARNO.D VIRUSES! X oleaccrc oleaccrc.exe Adware downloader - recognized by Kaspersky antivirus as TrojanDownloader.Win32.Agent.am X OLEDb Service runoledb32.exe variant of the SPYRE.B TROJAN! X Olehelp Olehelp.exe CoolWebSearch parasite related. X olehelp olehelp.exe BOOKMARKER.D or BOOKMARKER.G hijacker/viruses X OleLoader ole32.exe BACKDOOR.WIN32.DELF.BR TROJAN! U olesvr olesvr.exe Salfeld Child_Control_2003 - parental control software X Olive System Szchost.exe MERCURYCAS.A VIRUS! X Olympic IE4321.exe Adult content premium rate dialer - also detected as Trojan.Win32.Small.CZ X Omf4 OMF4.EXE FREEMEGA VIRUS! N OmgStartup omgstartup.exe Sony program called OpenMG Jukebox - player and music organizer U OmniHTTPd ohttpd.exe OmniHTTPd web server from Omnicron N OmniPage Opware32.exe "Part of OmniPage Pro from Scansoft (was Caere) - ""the fastest, easiest way to turn paper documents into digital files you can edit."" Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs" U OmniPass scureapp.exe OmniPass from Softex Inc. - secure password management software U On Screen Display OSD.EXE "By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a ""hot key"" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don\'t adjust things regularly - can also freeze" N One Touch Monitor 1tou~2.exe For Visioneer OneTouch scanners. System tray access to the control panel for the scanner N OneTouch Monitor OneTouchMon.exe """Finds"" the Visioneer scanner to see if it's on then loads it in the tray for quick access which delays the initial boot to desktop process. According to the Windows_Startup_Online_Repository , with the icon in the tray, if you restart or leave desktop, on your return, it again looks for the scanner and again bogs down your system. A desktop icon or star t > programs will provide access without the constant delays. Advise not to load this one in the tray." N OneTouchMonitor OneTouchMonitor.exe For Visioneer OneTouch scanners. System tray access to the control panel for the scanner X Onflow onflow.exe Onflow is a internet company that offers an online advertising program. Not required - uninstall X Online Service svchost.exe "HOSTIDEL.B or TARNO.B VIRUSES! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32" X Online Service svchost.exe HOSTIDEL.C VIRUS!. This is not the valid svchost.exe as described here X online_party online_party.exe Adult content dialler U OnlinePCfix SmoothSurfer SS.exe "Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists" N OnlineTime onlinetime.exe OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs X Onluna Sarvice sachost.exe TROJ/TOFGER-AA TROJAN! X Onlune Sarvice sachost.exe TROJ/DAEMONI-J TROJAN! X OnSrvr OnSrvr.exe OnWebMedia adware X oo4 ?? BookedSpace parasite variant N OP12 Reminder Ereg.exe Registration reminder for OmniPage Pro 12 from ScanSoft X Open Service Drivers opiater.exe variant of the WIN32.RBOT WORM! X Open Site opensite.exe OpenSite adware X Open Site opnste.exe OpenSite adware X Open2Enter runme.exe Adult Content Dialler X Open2Enter runme2.exe Adult Content Dialler X Open32 Open32.exe Horseserver.net browser hijacker X OpenGL Drivers 0penGLD.exe W32/YIMP-A WORM! X OpenMstart mcmgr32.exe """Switch"" adult content dialer" X OpenMstart mmgr32.exe """Switch"" adult content dialer" X OpenMstart Snt.exe """Switch"" adult content dialer" U OpenOffice.org *.*.* quickstart.exe "OpenOffice.org office suite quick start (where ""*.*.*"" is the version number)" N OpenOffice.org x QUICKS~1.EXE "Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). ""x"" represents the version number" U Openwares LiveUpdate LiveUpdate.exe Web-update utility as used by various types of software - see here N Operator ?? "Media Pilot operator, in Win.ini. Locks port open" U Operator xtmop.exe Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported N OpiStat OPISTAT.EXE OpiStat is a European Research Institute whose goal is to understand consumer needs and opinions better X OPQFile ?? Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit X opr opr.exe MediaMotor/Popuppers adware component X opsql update check opsql.exe W32/RBOT-ACJ WORM! X OPTIMIZER iexplore.exe "EVIVINC VIRUS! Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files" X Optimum Online Netsurf.exe OptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity. X Optional Web Drivers For WIN32 phqghume.exe variant of the WIN32.RBOT WORM! U Optus Cable Data Monitor datamonitor.exe "Allows Optus customers to monitor their actual data usage against Optus' ""data allowance limits""." U OptusNetUsage OptusNet Usage Meter.exe "This product is designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be." N Opware12 Opware12.exe OmniPage Pro 12 from ScanSoft N Opware14 Opware14.exe "ScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs" N OpwareSE2 OpwareSE2.exe "ScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs" X OrbitUpdate update.exe "Xupiter OrbitExplorer toolbar, drive-by foistware" X OrbitView view.exe "Xupiter OrbitExplorer toolbar, drive-by foistware" N OrderReminder OrderReminder.exe The HP Order Reminder utility is installed with the HP LaserJet printer software and allows you to set specific times for reminders to check the current level of toner in the print cartridge - it also contains an Order Now link to a Web page that helps you order supplies online from a reseller of your choice. X OrgyCam OrgyCam.exe Adult content dialler U OrigRage128Tweaker RAGE128TWEAK.EXE Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com U ORiNOCO Cmluc.exe Client Manager software for an ORiNOCO wireless LAN card X OSA winword.exe Trojan.Kangenie TROJAN! X Osa32 NTOSA32.exe ANIG VIRUS! X OSS ossproxy.exe NetSetter/Marketscore foistware X OSS rk.exe "RelevantKnowledge, NetSetter/Marketscore foistware variant" X OSSProxy OSSPROXY.EXE NetSetter/MarketScore foistware U OStivityInvAgt ostivity.exe "OStivity - ""a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system""" X Osus acao.exe PurityScan/Clickspring adware X Osus rrup.exe "PurityScan/Clickspring -Adware - The executable is located in the user's ""Application Data"" folder or the Program Files\htwu folder." X otcx otcxxh.exe CAROOL VIRUS! X outlook outlook.exe W32/SDBOT-RU WORM! X Outlook Express Config ?? variant of the WIN32.RBOT WORM! X Outlook Express Protocol look.exe W32/RBOT-ACS WORM! X OutLooks InSane.exe SWOOP TROJAN! Y Outpost Firewall outpost.exe Outpost personal firewall X outpostupdate outpostupdate.exe Troj/Cosiam-C TROJAN! X Outwar syslaunch.exe Outwar adware downloader N Overnet Overnet.exe Overnet peer-to-peer (P2P) file sharing program X ovyriwi telace.exe SDBOT.BVS WORM! U OWCCardbusTray ocbtray.exe Icon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface U OWCWebCamDV wcdvtray.exe "WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam" X OWMngr OWMngr.exe OnWebMedia/SearchSeekFind advertising foistware U OxigenClientAdmin Oxigen.exe Open University Oxigen screensaver admin client. Downloads the latest information from the net to display in the screen saver. X oz2 oz2.exe W32.Mydoom.W WORM! N p_981116 p_981116.exe Win32 cabinet self extractor. More info here X P2P Networking P2P P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately. X P2P NETWORKING P2P Networking.exe P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately. X P2P NETWORKING p2pautostart.exe P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately. X P2P Networking2 P2P Networking2.exe P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately. N P2P Networking3 P2P Networking3.exe "P2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required; see here" X p2pnetwork p2pnetwork.exe ALCAN.A WORM! X p2pnetworking p2pnetworking.exe W32/Rbot-AFL Worm! X P3p4chk P3p4chk.exe GEMA TROJAN! X p4mx4 p4mx4.exe CRYPTER.A trojan infection X PaciSoft pacis.exe PacerD_Media/Pacimedia.com adware installer N PadTouch PadExe.exe "Toshiba Touch and Launch, offers easy movement and freedom of programs navigation with TouchPad." U Pagekeeper Jobs or Pagekeeper Lite pkjobs.exe "PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc" X PAgent PAgent.exe "Scans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See here for more info" N Pagis Scheduler Monitor.exe Scheduler for the Pagis scanning suite from Scansoft.? N Pagoo PAGOO.EXE Pagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem X paint.exe shnlog.exe TROJ/PUPER-A And Troj/Puper-D TROJANS! X PaintingRoom evidence monitor paintingroom.exe Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you... X PaintingRoom smile monitor paintingroom.exe Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you... N Palm.exe Palm.exe Palm Desktop Software for use with Palm handheld devices. Available via Start -> Programs X PalNetaware pnetaware.exe PalTalk N PaltalkNetaware.exe PALNETAW~1.EXE Voice chat program. This program stores all buddy list info?apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated U pamela.exe pamela.exe Pamela is a plug-in or add-on that adds features to Skype peer to peer voice service. Note: Located in the Program files\Pamela folder. U Panda Antispam Server Service PasSrv.exe "AntiSpam software, part of Panda Platinum_Internet_Security" Y Panda Cleaner pavdr.exe Panda Antivirus related - possibly Panda ActiveScan X PandaAVEngine PandaAVEngine.exe W32.NETSKY.R WORM! U PandaScheduler pavsched.exe Panda Antivirus scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it X Pantera pantera.exe SDBOT.AYN WORM! N Paperport runppdrv.exe Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here N PaperPort PTD pptd40nt.exe """PaperPort"" software associated with scanners" N PaperQuote System Tray Icon PQTRAY.EXE "PaperQuote is a ""wallpaper"" changer with daily quotes that are either for inspiration or motivation" X Parallel Tasking ptask.exe TROJ/SMALL-CJ TROJAN! U PartSeal PartSeal.exe System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere U Password Door Loader PDMonitor.exe Password Door - password protection software N PasteLister plister.exe PasteLister - clipboard extender. Start manually when required X Patch patch.exe W32/NetBus TROJAN! X Patches Value WinGamed.exe SDBOT.BR worm infection X pathname pathname.exe BACKDOOR.IRCCONTACT TROJAN! X PAV.EXE ?? KITRO.D (or ARGEN.A) VIRUS!. %Number% can be any number Y PAV.EXE PAV.EXE PER Antivirus Y PAVFIRES PavFires.exe Panda Antivirus Y PAVFNSVR PavFnSvr.exe Panda Titanium Antivirus Y PavProc PavPrS9x.exe Panda Titanium Antivirus Y PavProt PavProt.exe Panda Titanium Antivirus X PayTime paytime.exe Troj/StartPa-YR Trojan! U pbagent pbagent.exe Probot keystroke logger/monitoring program - remove unless you installed it yourself! U PC Alert III alert.exe "MSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock" U PC Booster pcbooster.exe "PC Booster from inKline Global - ""easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition""" U PC Dynamics SdwMon32 sdwmon32.exe "SafeHouse ""Personal Privacy"" protects and hides your private and personal photos, videos, files and folders by making them ""invisible"" and encrypted." U pcAnywhere Agent pcamgt.exe Part of pcAnywhere 9.0 or later. This process listens for incoming PC Anywhere connections if your PC is configured as a PC Anywhere host. Y PCBODYGUARD or PCBG PCBODYGUARD.EXE "PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc" Y PCCClient.exe PCCClient.exe PC-Cillin 2002 antivirus software Y pccguide.exe pccguide.exe PC-Cillin 2002 antivirus software Y PCCIOMON.EXE PCCIOMON.EXE PC-Cillin 2000 antivirus software. This is the actual virus-scanner Y PCClient.exe PCClient.exe Trend Micro PC-cillin Internet Security X PC-Config32 corona.exe CORONEX.A VIRUS! Y PccPfw PccPfw.exe Trend Micro PC-Cillin personal firewall Y PcCtlCom Pcctlcom.exe Trend Micro PC-cillin Internet Security N PCDRealtime realtime.exe "Apparently the monitoring device for PC Doctor Online. It provides a ""free"" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to ""order"" the fee-based fixes from its web site." U PC-Duo System Snapshot CLBOOT32.EXE "PC-Duo_Remote_Control from Vector. ""System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!"". For tech support users to provide remote assistance" X PcEXPLODE specialfile.exe RBOT.RH worm infection N PCHbutton PCHbutton.exe Used by HP Instant Support N PCHealth pchschd.exe "This is a ""scheduler"" and does not turn off PC Health. For more information refer here" X PCHEasySearch STUpdate.exe PCH EasySearch bar U PCLEPCI ppe.exe "Pinnacle Systems PCI Performance Enhancer. ""This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards.""" X PCprot crcss.exe unidentified WORM! U PCRecSA PCRecSA.exe "Part of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a ""clean"" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to" X pcServer server.exe """Ssppyy"" spyware" X PCShield ?? "SafeguardProtect/Veevo malware, where * is a random char or digit" N PCStart Pcm25.exe Runs as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big N PCSuiteTrayApplication LaunchApplication.exe "System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu." N PCSuiteTrayApplication TrayApplication.exe "System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu." X Pcsv pcsvc.exe "Delfin_Media_Viewer or ""Promulgate"" adware" N PcSync PcSync.exe "If a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs" X PcSync PCsync.exe W32/RBOT-XJ WORM! - NOTE: do NOT confuse with the Nokia application described here U pctspk pctspk.exe Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions U PCTVOICE pctspk.exe Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions U PCTVOICE pctvoice.exe "The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It?s better to leave it" U PCWatch pcwatch.exe Spyware.PCWatch surveillance software. Uninstall this software if you did not install it yourself. X PDASCAN pdascan.exe W32/AGOBOT-QY WORM! U PDEngine PDEngine.exe PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot N pdexplo PDEXPLO.EXE PowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs N pdfFactory Pro Dispatcher v1 fppdis1.exe """With pdfFactory you can create PDF documents from any program printing to the virtual PDF printer"". Available via a desktop shortcut or Start -> Programs" U pdfMachine dispatcher mapisnd.exe pdfMachine Windows print driver N pdfSaver3 pdfSaver3.exe "PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc." N PDirect PDirect.exe IBM Presentation Director software U pdp Server ctpdpsrvr.exe Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network U PDVDServ PDVDServ.exe "Remote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one" N Pe2ckfnt SE chkfont.exe "Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu" N PeerGuardian PeerGuardian_1.99b_pr14.exe "PeerGuardian ""is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections.""" U PeerGuardian pg2.exe "PeerGuardian is an IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists, a list editor, automatic blocklist updates, and blocking all of IPv4 (TCP, UDP, ICMP, etc)." U Pent@VALUE 3.2 Pent@VALUE.exe Pent@VALUE Digital Satellite Internet PC Receiver X PeqBL100 PEQBL100.exe W32.PEQ WORM! Y PER Email Protection pavmail.exe PER Antivirus N PerfectPrint pfppop70.exe Print engine used by Corel WordPerfect 7 and Presentations 7 X Perfomance Monitor davcsync.exe W32/Lamud-A Worm! X Perfomance Settings svchost.exe "TROJ/TOFGER-AP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X PerformCl perfcl.exe adware downloader and installer Y PersFw PersFw.exe Kerio or Tiny Personal Firewall N Persistence igfxpers.exe Associated with the Common User Interface module for Intel graphics cards X Personal Computer scvhost.exe W32/Rbot-AJE WORM! Note: This trojan file scvhost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. X Personal Firwall ptmedsrv.exe SDBOT.XY WORM! U Pervasive.SQL Workgroup Engine W3dbsmgr.exe Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup U PestPatrol Control Center PPControl.exe PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol U PestPatrolCL PestPatrolCL.exe "PestPatrol's command line scanner, combines with the Windows Task scheduler and is required in cases where schedules for regular scanning are set" U Petit Larousse 2001 HIPL2000Popup.exe Popup dictionary tool X PgMonitr PgMonitr.exe Delfin_Promulgate adware variant Y PGPSDKSVC pgpsdkserv.exe "PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality" U PGPSERVICE pgpservice.exe "PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a ""fall-back"" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference" N PGPtray pgptray.exe PGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs X pgtaff pgtaff.exe AdRotator adware variant N Phime2002a or PHIME2002ASync TINTSETP.EXE "Part of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word" U PhoneFree version 6.2 PHONEF??.EXE An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here N Photo Express Calendar Checker SE CALCHECK.EXE "If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly" N Photo Loader supervisory Plauto.exe "Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures" N PhotoShow Deluxe Media Manager mssysmgr.exe "Simple Star PhotoShow_Deluxe photo editing and organizing software; makes it easy to send and share digital photos.. Bundled with software from Nero, ComCast, SnapFish, MacroMedia and others." N PhotoWise QuickLink quicklnk.exe "Agfa PhotoWise - ""PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more.""" N Picasa Media Detector PicasaMediaDetector.exe Media detector for Picasa's automatic photo organizer N PicasaNet Hello.exe "Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs." N Pickatag pickatag.exe "Pick-a-tag - ""Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages""" N PICPRTR PICPRTR.EXE Program for viewing and measuring a variety of 3D CAD data formats X picsvr picsvr.exe Delfin_Promulgate adware N pictureBUZZTray swtray.exe System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually U PiDunHK PIDUNHK.EXE "Part of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens" U piiserviceOE ?? Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE X pilif pilif.exe W32.Fili worm infection N Pinger pinger.exe "Pinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification" X PingTimeout Institution pingchek.exe W32/SDBOT-VY WORM! Y PinnacleDriverCheck PSDrvCheck.exe Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled N Piolet piolet.exe Piolet - peer-to-peer file sharing client N Piracy SysUtil.exe """Software Piracy Alert"" feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: ""The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users.""" N PivotSoftware wpctrl.exe "PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties" X Pixel32 Pixel32.exe GEMA TROJAN! X Pixelpwr32 Pixelpwr32.exe GEMA TROJAN! X Pixelsvr Pixelsvr.exe GEMA TROJAN! U pjWebCam pjWebCam.exe Webcam automation software that saves regular photos from webcam and can also act as HTTP server X PK Guard pkguard32.exe W32.Guapim WORM! X PK Services pksvc.exe W32/FORBOT-BW WORM! U PktAnything PocketCompanion.exe "PocketAnything lets you save anything on your computer to your mobile, with one click." U Planl?gningsagent mstask.exe "Windows Task Scheduler (on Danish language versions of Windows) - displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on." U PlaxoUpdate InstallStub.exe "Installstub.exe is is Plaxo's core executable program, which is used to check for new or updated information from the Plaxo Network. This program also interacts with Outlook." U PLEAPCPUCPL pleapu.exe CPU Control Panel for the Powerleap CPU upgrade N Plguni Plguni.exe McAfee QuickClean 3.0 - removes internet clutter and unwanted programs U plmg.exe plmg.exe Paragon Last Minute Bidder - auction assistant software X Plob kernel.com OPTIXPRO.12 VIRUS! X Plook plook.exe Affiliatetarget.com adware U Pluck Tray PluckTray.exe RSS (XML TAGS) reader program N PluckSvr PluckUpdater.exe Pluck Toolbar updater X Plug And Play msnmsg.exe W32/RBOT-ID WORM! U PLXSTART PLXSTART.EXE "Sets the spindown timeout and access speeds at startup and displays the ""Plextor Manager 2000"" splash screen for Plextor CD-RW." N PLXTASK PLXTASK.EXE "Taskbar utility for a ""control panel"" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)" X pm32ctrl pwr32crtl.exe CRYPTER.A trojan infection X pm32info pm32info.exe CRYPTER.A trojan infection X pmc 764.exe Adult content dialler X PMedia winsrvc.exe Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B VIRUS! X pmr pmr.exe Powerstrip foistware variant U PMT personalmoneytree.exe According to the web site Personal_Money_Tree is an automatic cash rebate program. Note: Not recommended. N PMTSHOOT pmtshoot.exe MS tool for troubleshooting power management problems U PMXInit pmxinit.exe Restores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma? N PNAgent PNAgent.exe "PhatNoise Music Manager - manages WMA, MP3, WAV, etc music files" X PNP wuaaclt.exe W32/Lilbre-A WORM! X PnP Driver playboy.exe "W32/Forbot-FR WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. Added Note: This malware can collect system information, add or delete shares and users, kill processes, download and execute files, send email, remotely control a connected web cam, sniff network traffic or launch a denial-of-service attack!" X PNP FIX ?? W32/Rbot-AKQ WORM! U Pnpchk Pnpchk.exe Aztech Labs Sound 3 PnP driver X pnpsvc_lock ?? browser hijacker X pnpsvc_lock startsvs.exe browser hijacker U PNSetup PNSetup.exe PopNot - pop-up killer X PNtask Services pntask.exe LALA.C VIRUS! U Pocket Sheet Sync PSXLTRAY.EXE Casio Pocket Sheet synchronization software X Poet Poet.exe DOEP.A VIRUS! X Pofatch nstrue.exe RANDEX.Z VIRUS! U point32 point32.exe Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features U POINTER point32.exe Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features N Points Manager points manager.exe Altnet TopSearch adware X Pollon pollone.exe SPYBOT.FW WORM! X POP PopSrv***.exe "PeopleonPage foistware, bundled with Grokster where *** are random digits" Y pop3trap.exe pop3trap.exe PC-Cillin 2000 antivirus software -> E-mail scanner X PopeSvr PopeSvr.exe Troj/LegMir-AJ TROJAN! X PopMark WinTask.exe """Pop Marketing"" adware" U PopNot PopNot.exe PopNot - pop-up killer U PopOops PopOops.exe PopOops - pop-up killer U Popopen popopen.exe PopOpen makes your windows spring open with animation effects Y Poproxy POPROXY.EXE "Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it" X popsrv146 popsrv146.exe "PeopleOnPage online dating browser enhancement - also adware and privacy issues, see here. For removal instructions see here" U PopSubtract PopSub.exe PopSubtract - pop-up killer U Popup Ad Filter PopFilter.exe Popup Ad Filter - pop-up killer X Popup Blocker System PopUpBlocker.exe variant of the WIN32.RBOT WORM! X Popup Blocker System326a Monitoring PopUpBlocker6a.exe RBOT.AUH WORM! X Popup Blocker System8 Monitoring PopUpBlocker8.exe variant of the WIN32.RBOT WORM! X Popup Blocker Updater ?? SafeguardProtect/Veevo X Popup Defence Updater ?? SafeguardProtect/Veevo hijacker X Popup Defence Updater (required) ?? SafeguardProtect/Veevo hijacker U Popup Defender PD.exe Popup Defender - pop-up killer U Pop-Up Smasher PopupSmasher.exe Pop-Up Smasher - pop-up killer U Pop-Up Stopper dpps2.exe Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group U Popup Terminator GLADManager.exe Popup Terminator - pop-up killer U Pop-Up_Blocker Popup.exe "A Tweak-XP component, blocks advertisement pop-up windows in Internet Explorer. Can be enabled/disabled via Tweak-XP -> Internet Tweaks" U Pop-Up_Scanner Popupscn.exe Panicware popup blocker U PopupEliminator Popup Eliminator.exe Popup Eliminator - pop-up killer U PopUpKiller PopUpKiller.exe PopUpKiller - pop-up killer X popuppers newpop63.exe Popuppers adware variant X popuppers64 a64sddd.exe "Popuppers adware, also detected as the TROJ/LOWZONE-AA TROJAN!" X popuppers65 a64sddd.exe Popuppers adware variant X popuppers65 a65d.exe Popuppers adware variant U PopUpStopperCompanion PSComp.exe PopupStopper_Companion popup blocker U PopUpStopperFreeEdition PSFREE.EXE Pnaicware's Pop-Up Stopper - free limited features version U PopUpStopperProfessional PopUpStopperProfessional.exe Panicware's Pop-Up Stopper - paid for version U PopupVanish PopupVanish.exe Pop-up blocker U PopUpWasher PopUpWasher.exe PopUpWasher pop-up killer U PopUpWatch PopUpWatch.exe "Part of BPS Trace Remover - made by the folks who ""developed"" BPS Spyware Remover which reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!" N Post-It(r) Software Psnotes.exe "Pop-up ""yellow"" notes on screen. Available via Start -> Programs" U POW! pow.exe Pop-up killer X Power Scan powerscan.exe """Foistware"" by Integrated Search Technologies - the people behind the ISTbar parasite" U Power_Gear BatteryLife.exe Power management for all Asus notebook. Useful but not critical. N PowerBar Powerbar.exe "Part of CyberLink's PowerDVD software; not sure what exactly it does, but not required in startup" Y PowerChute Pwrchute.exe """During a power outage, if you're not available to save your files & close down Windows....PowerChute will do that for you. PowerChute will save your application files, close your applications and shut down your computer just like you would...otherwise, the APC UPS (Uninterruptible Power Supply) unit would go to battery until it wore down, then your computer would shutoff""" U PowerDOCSAPIHost papihost.exe "Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment""" N PowerDVD PowerDVD.exe "Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled, PowerDVD will open automatically when a DVD movie is inserted. Launch manually" U PowerKey PowerKey.exe Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 X PowerManagement Rundlll.exe SURDUX VIRUS! X PowerManager Svchost.exe JEEFO VIRUS! Note - this is not the valid svchost.exe as described here Y PowerPanel POWPANEL.EXE Power management utility on notebooks/laptops - automatically switches modes when running on battery X PowerPrifile "rundl132 kenel.dll, PowerProfileEnable" INMOTA VIRUS! U PowerPro powerpro.exe "Part of the power professional program that loads the floating menu bar. Can be accessed from Start -> Programs, but I'd leave it alone if you use this program" X PowerProf PowerProf.exe WIN32.LOREX.B TROJAN! X PowerProfile mfcp30.exe RINDAS-A TROJAN! N PowerQuest Startup Utility PQINIT.EXE "From a visitor - ""This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems""" N PowerReg Scheduler PowerReg Scheduler.exe "PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others" N PowerReg SchedulerV2 PowerReg SchedulerV2.exe "PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others" N PowerReg SchedulerV3 PowerReg SchedulerV3.exe "PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others" N PowerStrip powerstrip.exe PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings N PowerStrip pstrip.exe PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings U PowerTools Tray Icon pttray.exe PowerTools - add-on for AOL U Powertweak PT2.EXE """Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured."" This item is added to startup if \'Use predefined settings\' is enabled in the programs options" U Powertweak PTCTRL.EXE """Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured."" This item is added to startup if \'Configure system at logon\' is enabled in the programs options" N PP****usb FBDirect.exe "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs" U PP2000 Instaupdate PPInupdt.exe Protector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually Y PP2000 Real Time Scan PPVstop.exe Protector Plus anti-virus software - real time scanner Y PP2000 Taskbar Control PPTbc.exe Protector Plus anti-virus software - system tray access N PP3100b flatbed.exe "Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop" U ppass Antispy.exe "AntiSpy firewall - ""program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide""" U PPControl PPControl.exe PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol U PPHIDPAD pphidpad.exe PenPower Chinese handwriting recognition software U PPK Setup(Server) SEServe.exe "Programmable Power Key on Sony Vaio laptops. ""Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended""" U PPMemCheck ppmemcheck.exe "PPMemCheck - ""extends PestPatrol's power so that the most dangerous Pests -- those that are about to execute -- are found, terminated, and cleaned from a user's system""" X PPPOEO pingppac.exe W32.Spybot WORM! X PPPOEOE WINLITE.EXE W32/RBOT-AAN WORM! N PProTray pprotray.exe Part of the power professional program. Loads the System Tray control U PPSVC ?? "PC_Police is spyware that logs keystrokes, files looked at, applications used, and chats on either MSN, Yahoo, ICQ or AOL. This information can then be transmitted to a remote user. If you didn't install this yourself remove it." N pptd40nt pptd40nt.exe """PaperPort"" software associated with scanners" U PPUpdate ppupdater.exe "PPUpdater - ""is the update program that ships with PestPatrol. It is able to update licensed and evaluation versions, and presents a visual display of what it is doing"". Run manually unless you think you'll forget to check for updates on a regular basis" N PPWWebCap PPWebCap.exe """PaperPort"" software associated with scanners" X pqhelper pqhelper.exe Searchcentrix hijacker U PractiSearch PSearch.exe PractiSearch web search software U Praize Messenger itLoad.exe Praize IM Christian chat instant messenger U Prayer PTW.EXE Islamic Adhan program (call fpr daily prayers) X prdtect prdtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prmtect.exe and so forth!" N Precision Time Clock Checker PrecisionTime.exe Precision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time X PrecisionTime PrecisionTime.exe PrecisionTime - clock synchronizing software containing adware by Claria/GAIN X precpop2 starter.exe PrecisionPop adware X Prein ?? Unidentified adware Y Preload Preload.exe Millenium Multi-Function Keyboard driver X Premeter nrpr.exe "NetRatings software by Opistat . ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!" X Premeter prmt.exe "NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!" X Preview AdService PrevAdServ.exe Windupdates Adware Variant Y PrevxHome SAGUI.exe PrevX_Home intrusion prevention software Y PrevxPro SAGUI.exe Prevx_Home intrusion prevention software X prgtect prgtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X Pribi.exe Pribi.exe FastFind adware variant N Price Patrol neo.exe Price Patrol by Half.com - internet shopping companion for finding the best on-line prices U Primax 3D Mouse 3dmoused.exe Enables the scroll button on the Primax 3-D Scroll mouse X Print Driver Helper Service crsrr.exe AGENT-BC TROJAN! N Print Master Event Reminder PMremind.exe "Print Master Gold - calander feature that pops up reminders, such as birthdays" N Print Screen Deluxe psdeluxe.exe "Utility allows ""Print Scrn"" or ""Print Screen"" key to capture, print or save the current window" X Print Services spolserv32.exe RBOT.ZP WORM! X print sharing ?? ZCREW.B VIRUS! Note - this is not the valid Windows Explorer (explorer.exe) X print sharing start.bat ZCREW VIRUS! X Print Spooler spool.exe TROJ/BDOOR-IS TROJAN! X Print Spooler spools.exe W32/Rbot-LD worm infection X Print Spooler Spoolsv.exe "CIADOOR.B VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file" X Print Spooler spoolsv32.exe RBOT.SW WORM! X Print Spooler spoolsvc32.exe SDBOT.BB WORM! X Printer dipset.exe variant of the Proxy-FBSR TROJAN! X Printer private.exe Win32.Rbot worm variant X Printer Spyassault.exe "Bogus ""Spyware remover"" - see this list of non-Recommended anti parasite software" U printer SpyAssaultScanner.exe "Bogus ""Spyware remover"" - see this list of non-Recommended anti parasite software" X printer sysprinter.exe TROJ_SMALL.ZY TROJAN! X Printer Monitor webprinter.exe TROJ/IRCBOT-Z TROJAN! X Printer Spool updater.exe variant of the WIN32.RBOT WORM! X Printer spool Service spool.exe W32/RBOT-ACP WORM! X printer spooler commonaccess.exe Troj/Delf-LB TROJAN! X Printer Spooler Subsystem spoolss.exe "variant of the WIN32.RBOT WORM! - Note - this is NOT the legitimate Windows spoolss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X PrinterSpool ?? ALADINZ.K VIRUS! X Printing Driver msprint.exe RBOT.JH WORM! N Printkey2000 printkey2000.exe Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required X PrintMngr system.exe unidentified TROJAN! N printnow printnow.exe "PrintNow - a utility that primarily allows ""Print Srceen"" or ""Alt Print Screen"" screenshots to be sent directly to a printer" N PrinTray Printray.exe Lexmark/Compaq printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. See also LexmarkPrintray and CompaqPrinTray N PrintScreen UNWISE.EXE "Gadwin PrintScreen - utility to capture, print or save the current window" N Printscreen 95 PRT95MIN.EXE "Printscreen 95 - utility to capture, print or save the current window" X PrintSpoolSv System.exe Troj/Bdoor-S worm infection U PRISMSTA.EXE PRISMSTA.EXE Creates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example Y privacy cleaner cleaner.exe "Foxie Privacy Cleaner - Part of Foxie Security, Privacy and Productivity Suite" N Privacy Eraser Pro PrivacyEraser.exe Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities U PrivacyKeyboard PrivacyKeyboard.exe "PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices, both known and unknown, currently in use or presently being developed worldwide.""" X PrivacyScanner pscan.exe """Privacy Champion"", a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to porn websites, and then offers to ""clean"" them.. Produces loads of False Positives as goad to purchase." X PrivateNet ?? Premium rate adult content dialer U Privoxy privoxy.exe "Privoxy - web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk" X PrizeSurfer prizesurfer.exe """PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware" X prjtect prjtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prktect prktect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prltect prltect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prmt prmt.exe "NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!" X prmtect prmtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!" U PrnSys Executable PrnSys.exe "Print screen utility bundled with some HP printer software; not required, but your choice if you like that feature." U Pro PCL Status Monitor PENGSS.EXE Xerox printer/fax/copier status monitor (PCL = printer control language) X process.exe process.exe PWSTEAL.BANCOS.P TROJAN! U ProcessGovernor processgovernor.exe "Process Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions." U ProcessSupervisorGUI ProcessSupervisor.exe "Process Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions." X procmon procmon.exe BIONET.40A VIRUS! N ProdikeysAutorun Prodload.exe "Creative Prodikeys software. ""an interactive music entertainment device which not only functions as a full-featured, ergonomic ?QWERTY? keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop.""" N ProDsl ProDsl.exe Intel Pro/DSL 2100 modem connection manager. Available via Start -> Programs X Profile Profile.vbs WHITEHO or TRAPPY VIRUSES! U ProfileAMP Profile8 "WinAmp media player add-on; ""will replace %s with the current Winamp song and %m with current memory stats every song change. Change the color of your links, have a count down to a certain date. Works for all versions of Winamp.""" X profiler liteout.exe TROJ/ZAPCHAS-G WORM! X profiler prof.exe TROJ/ZAPCHAS-G WORM! N Profiler Profiler.exe "Enables the ""Profiler"" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs" X Prog csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X Prog lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" X Program File Progmon.exe PEEPER VIRUS! X Program in Windows iexplore.exe variant of the LOVGATE WORM! U Program Neighborhood Agent pnagent.exe Citrix_Program_Neighborhood_Agent N projselector projselector.exe Roxio Project Selector; can be started manually N Promon.exe promon.exe System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features X PromulGate PgMonitr.exe Delfin_Promulgate adware variant N PRONoMgr.exe PRONoMgr.exe System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features U PRONoMgrWired PRONoMgr.exe Intel?s Pro 100 Ethernet card manager U Propel Accelerator PropelAC.exe Propel Internet Accelerator U ProPort Startup ProPort.exe "Proport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolving" X ProSiteFinder prositefinder.exe Adware by 180Solutions X Prote??o de tela ssmaze.scr BANCBAN-FB TROJAN! X protect protect.scr Troj/Dloader-TQ TROJAN! U Protect SHVRTF.EXE "PC_Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry." X Protected Storage ?? variant of the LOVGATE WORM! X Protection ?? variant of the Downloader.Agent.3.AU TROJAN! X Protection Firewall.exe W32.Elitper.A WORM! X Protection Iexplore .exe W32.Elitper.D WORM! X Protection Norton Internet Security.exe W32.ELITPER.E WORM! X Protection Protection.exe W32/FEBELNECK-A WORM! X Provan Security psecure.exe RBOT.BRV WORM! N PROXOMITRON PROXOM~1.EXE HTML proxy N Proxomitron Proxomitron.exe HTML Proxy U ProxyWay proxyway.exe ProxyWay anonymous proxy surfing software U PRPCMonitor PRPCUI.exe "Intel˝ SpeedStep? interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40%" X prqtect prqtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prrtect prrtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prstect prstect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prtcct prtcct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prttect prttect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prutcct prutcct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D." X prutdct prutdct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutgct prutgct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X pruthct pruthct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutict prutict.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutlct prutlct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutpct prutpct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutqct prutqct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prutsct prutsct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X pruttct pruttct.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!" X prvtect prvtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X prxtect prxtect.exe """Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!" X ps1 ps1.exe PacerD_Media/Pacimedia.com adware component U PS2 ps2.exe "Multimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lost." X psaload32 psaload32.exe W32/Rbot-ADL Worm! X PSD Tools Channel ChannelUp.exe BuddyLinks adware Y PSDrvCheck PSDrvCheck.exe Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled X PService svcnow32.exe TROJ/SPYBOT-DJ TROJAN! U PSFree PSFree.exe Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group X PSGuard PSGuard.exe Bogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN! X PSGuard spyware remover PSGuard.exe Bogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN! X pshower pshwr.exe SafeSurfing adware variant Y PSIMSVC PSIMSVC.exe Panda Titanium Antivirus N PSIWin2.3 Connection Server Psconsv.exe Allows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs U pskl keyspy.exe KeyboardLogger logs keystrokes and records the windows in which they were entered. If you didn't install it yourself remove it. U PsMFCard PsMFCard.exe "Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in use" Y PSNotify psnotify.exe "Pharos SignUp Vx - ""PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries""" X PSof1 PSof1.exe PacerD_Media/Pacimedia.com adware installer X PSoft1 psoft1.exe PacerD_Media/Pacimedia.com adware installer U PspContr pspcontr.exe Driver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver U PsSound PsSound.exe "On a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delay" U pst memaker2.exe SpymodePCSpy surveillance software. Uninstall this software unless you put it there yourself. X ptech ptech.exe "Related to ""Prutect"" malware from e2Give" N ptfb ptfb.exe "Push the Freakin' Button - ""When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future""" X PtiuPbmd ?? Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required? U PTRUN32 ptr32w.exe Spyware.ParentTools surveillance software. Remove unless you installed it yourself! U ptrun32 ptrun32.exe Parent Tools for AIM N Ptsnoop Ptsnoop.exe These descriptions I've come across - all valid as far as I can see :- U pttrun pttrun.exe "Transmeta Crusoe processor related. Reduces application launch times and makes the computer ""more responsive""" N PtUDFApp PtUDFApp.exe "Sony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start -> Programs. Note that you must add a /T switch to the command line to get it to load to the taskbar" X Public Microsoft ODBC ?? MASLAN.D WORM! N Pure Networks Port Magic PortAOL.exe "Pure Networks Port Magic, as available in the latest version of the AOL˝ 9.0 Optimized SE software; automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and video. See here" U Purgative PURGATIVE100.EXE AIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack X Purgatory Purga.exe W32/Purgory-B WORM! N Push Client pull.exe Client software from Interwise that MS use for their webcasts N Push The Freakin' Button ptfb.exe "Push the Freakin' Button - ""When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future""" N PUSH6599 PUSH6599.EXE Scan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software X PutA!! PutA!!.exe OPASERV.L VIRUS! X PutAS! PutA!!.com OPASERV.Z VIRUS! X putil ?? Troj/LdPinch-AA trojan infection X putil ?? LDPINCH VIRUS! U PV92TRAY PV92Tray.exe PCtel HSP V.92 modem Configuration Utility N PVR PVR.exe Pocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card U PVUnInst1 PVUnInst1.exe "Privacy_View is privacy software that ensures that all your private computer files, photos, documents, and websites remain secure from prying eyes." N pwindicator pwic.exe ParaWin XP - International Language Software for Windows XP/NT/2000 X Pwr32ctr Pwr32ctr.exe GEMA TROJAN! X Pwr32ctrl Pwr32ctrl.exe GEMA TROJAN! X Pwr32mgt Pwr32mgt.exe GEMA TROJAN! Y Pwrmonit Rundll32 PwrMonit.dll IBM's proprietary 'battery maximiser' and power monitoring software for laptops X Pwroff Pwroff.exe GEMA TROJAN! U Pwrsave Pwrsave.exe Toshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power U PwrupTweakMe PUPXPTWK.EXE """Ashampoo PowerUp XP is a convenient tool for fine-tuning your Windows˝ NT4, 2000 and XP configuration to suit your precise needs and wishes. It gives you direct access to many frequently-required settings and parameters, enabling you to make your operating system behave the way you want.""?Boot-up options won't work if disabled?" U PWS Tray PwsTray.exe "Microsoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start -> Programs" N Q152404 ?? Appears to run Scandisk at bootup on NEC PCs X q36i36O lms2cenu.exe SECONDTHOUGHT VIRUS! N QAGENT qagent.exe "Quicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the Internet" X qappsrvc32.exe qappsrvc32.exe Proxy_Trojan variant - identified by Kaspersky antivirus as Trojan-Proxy.Win32.Webber.m N QBCD autorun autorun.exe Quick Books CD X qbkupdbs mqbkup.exe OPASERV.K VIRUS! X qbotd ?? BOTTEN VIRUS! X QBRSR QuickBrowser.exe QuickBrowser/Top-banners.com adware U Qchex Tray Icon Qchex.exe Related to G7_Productivity_Systems Check Software. U QCTRAY Qctray.exe "System Tray icon providing access to the ""IBM Access Connections"" wizard on ThinkPad laptops and also allows to change the network environment. Not the same as QCWLIcon, which is pertinent only to the Wireless LAN" U QCWLICON Qcwlicon.exe "Used by IBM Thinkpad laptops with built-in wireless card (802.11). System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off" N QD FastAndSafe QDCSFS.exe Automatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually U QDM or QDMStart QdmStart.exe "QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI\'s series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc" X qgqqft ?? Ranky.T TROJAN! Y QH Live Update Scheduler UPSCHD.EXE Quick_Heal Anti-Virus Y QH Office 2K Check O2KCHECK.EXE Quick_Heal Anti-Virus MS Office documents virus checker N QNPlus QNPlus.exe Quick Notes Plus by Conceptworld - sticky notes tool U Qoeloader Qoeloader.exe Qurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs X QQ sendmess.exe SEMES VIRUS! X QQServer QQ.exe Troj/DownLdr-AN TROJAN! X qservices qservice.exe Troj/Progent-A TROJAN! X qservices qservice.exe Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder. N QSort2000 QSORT.EXE "Utility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose ""Sort by Name""" U QT4HPOT OneTouch.exe Hewlett Packard One Touch keyboard driver. Required if you use the additional keys U QTaskStartup qtask.exe "Feature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts feature" X QTime nrchk.exe Premium rate adult content dialer N QTSTUB.EXE Qtstub.exe Part of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders X QTSvc msocfg.exe Adult material premium rate dialer X QTSvc navcke.exe Adult material premium rate dialer X QTSvc shman.exe Adult material premium rate dialer X QTSvc ssvr.exe Adult material premium rate dialer N qttask Qttask.exe "System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards" X Quantifier Security qsecue.exe W32.Spybot.UOL WORM! U Quick Controls Astrotoolbar.exe Gateway Astro Screen and Sound Controls tray icon U Quick Heal Messenger QHM32.EXE "Quick_Heal Anti-Virus Messenger - Keeps you informed about the latest threats, hoaxes etc." Y Quick Heal On-Line Protection Cateye.exe Quick Heal - virus scanner Y Quick Heal Startup Scan QHSTRT32.EXE Quick Heal - virus scanner N Quick Shelf xx qushelfxx.exe "Places an icon in the system tray for launching MS Bookshelf. Available via Start -> Programs""xx"" represents the version number - ie, 98, 99" Y Quick Startup Fquick32.exe For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone X Quick Time file manager quicktimeprom.exe SDBOT TROJAN! N Quick View Plus QVP32.EXE Quick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs N QuickBooks Delivery Agent QBDAGENT.EXE As far QAGENT but for QuickBooks. Can also have the version number in the name N Quickbooks Update Agent qbupdate.exe Associated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not U QuickCamPro QuickCamPro.exe "System Tray for Picture Capture utility that can run unattended. Pictures every 30 seconds for example, auto FTP Upload, etc" X quicken quicken.exe CoolWebSearch parasite related. X quicken Waol.exe CoolWebSearch parasite related. X quicken Winrar.exe CoolWebSearch parasite related. N Quicken Scheduled Updates bagent.exe Quicken background downloading module N Quicken Startup QWDLLS.EXE Quicken option to load DLLs at startup N QuickenSEMessage Qsemsg.exe Quicken option N QuickFinder Scheduler QFSCHD100.exe Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products) N QuickFinder Scheduler QFSched.exe Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products) Y QuickLaunchEr QuickLaunchEr.Exe QuickLaunchEr - allows you to quickly launch programs from an icon in the system tray N Quicklink III QL.EXE "HP fax program and only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start -> Programs" N Quicknote quicknote.exe JC&MB Quicknote Virtual Scrapbook U QuickPassword agquickp.exe Smart card-based authentication and digital signature client software N QuickRes QUICKRES.EXE Utility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel -> Display. Not required unless you have to change resolutions on a regular basis N quickset quickset.exe Dell taskbar icon allowing you to quickly change settings X Quicktime qttasks.exe TROJ/ADCLICK-AK TROJAN! X Quicktime shch.exe variant of the TROJ/BDOOR-EB TROJAN! X Quicktime Mediaplayer winmplyer32.exe W32/RBOT-PM WORM! X Quicktime Mediaplayr wnmplyr.exe variant of the WIN32.RBOT WORM! X Quicktime Pro 3.0 winuodps.exe GAOBOT.BH WORM! X Quicktime Runtime Qtimer.exe W32.SpyBot worm variant X Quicktime Task ?? NetVision dialer N QuickTime Task Qttask.exe "System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards" X QuickTime Task qttasks.exe CoolWebSearch parasite related. N QuickTime Update Completion x quicktimeupdatehelper.exe "Different numbers caused by number of launches. So if 3 updates are made separately, 3 would appear (in theory)" X QuicktimeMngr QUICKTIMEMNGR.EXE WOOTBOT.AW worm infection X Quicktlme ru.exe Adult content dialler U QuickTV QuickTV.exe Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control X Quickzip Ls.exe MsConnect browser hijacker and dialler X QuickZip lu.exe MsConnect browser hijacker and dialler N QuikShield qkshield.exe "QuikShield popup blocker - reportedly stealth installed, see here" N QuikSync QUIKSYNC.EXE Used by Iomega drives. Available via Start -> Programs X qwe qwe.exe TROJ/LINEAGE-F TROJAN! U QWS3270 Sessions sessions.exe QWS3270 Secure terminal emulation software Y r_server r_server.exe Radmin - remote admistrator server X r_server service.exe TROJ/MULTIDR-CP TROJAN! X RA Server Slave.exe RA VIRUS! X RabbitWannaHome rabbit.exe W32.MIMAIL.S WORM! Y Rabo Session Monitor RaboSessionMon.exe Related to RaboBank electronic banking software N RadarSync RadarSync.exe "Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically" U RadBoot RadBoot.exe RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings U RadioSvr RadioSvr.EXE Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network U Rainlendar Rainlendar.exe Rainlendar is a customizable calendar that displays the current month. U RAM Idle Professional RAM_XP.exe "RAM_Idle - a memory management program which manages the free RAM that is available to Windows, thus preventing your computer from running progressively slower over time." U RAMASST RAMASST.exe "Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP\'s CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs" X RamBooster2 rb.exe AKAK VIRUS! U RAMDef ramdef.exe Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind U RAMDrive RDTask.exe Virtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarStone U RamIdle ramidle.exe "RAM Idle - ""A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by? freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows."" Some users swear by programs such as this but I suggest you read this article and make up your own mind" U RAMpage RAMpage.exe "Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source" X Randex virus built for IRBMe irbme.exe W32.Randex.RH worm infection X random 10-character filename Winupdates.exe W32/Rbot-MM worm infection X RandomWin32 mgnwin32.exe W32/SDBOT-DV WORM! X rant rant.exe W32/RBOT-ZB WORM! Y RapApp RAPAPP.EXE "Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch" X Rapdata ravsecs.exe Troj/QQPass-V TROJAN! X Rapdatae rabseuser.exe TROJ/QQPASS-S TROJAN! U Rapid Restore rrpcsb.exe "XPoint ""Rapid Restore PC""; a ""Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user.""" X RapidBlaster rb32.exe Homepage hijacker (adult content) - see this newsgroup thread Y Raptor Mobile vpnservices.exe "Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking" X RasCon Remote Access Service Manager rasmngr.exe WORM_SPYBOT.EM X rasctrs rasctrs.exe "Hijacker, also detected as the ADWAHECK TROJAN!" X Rase boln.exe PurityScan/Clickspring adware X RasMan.exe RasMan.exe Troj/Feutel-H Trojan! X rate.exe ?? Unidentified adware X rate.exe i11r54n4.exe BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS! Y RAV8Tray ravtray8.exe RAV anti-virus related X RAVEN_VLZS.EXE RAVEN_VLZS.EXE Another eAcceleration program - spyware. Read their privacy statement here Y RavMon RavMon.exe RAV AntiVirus X RavTime Mstray.exe WUKILL.A VIRUS! Y RavTimer RavTimer.exe RAV AntiVirus X RavTimeXP ?? WULLIK.B VIRUS! X RavTimeXP Virus CAGER.A WORM! X RavTimXP ?? WULLIK.B VIRUS! X RavUptpe ravsesur.exe TROJ/QQPASS-T TROJAN! N Ray Process Killer Prkill.exe "Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click ""Ok"" to terminate it. Use CTRL ALT DEL instead" Y razertra razertra.exe razer diamondback mouse driver X rb32 lptt01 or rb32 ml097e rb32.exe "Variant of the RapidBlaster parasite (in a ""RapidBlaster"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X rbenh ml***e rbenh.exe "Variant of the RapidBlaster parasite (in a ""RBEnhance"" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Rcf Driver rcf.exe RANDEX.BLD VIRUS! X rCron dservice.exe """Switch"" premium rate adult content dialer" X rCron rcron.exe """Switch"" adult content dialer" U RCScheduleCheck RCSCHED.EXE "Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running""" X RCSync RCSync.exe "PrizeSurfer related. ""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware" U RDClient RDCLIENT.EXE Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection X RDLL RunDll16.exe SDBOT.F WORM! X rdvs ?? ULTIMAX VIRUS! is the worm filename created X Reactor3 ?? W32.BOFRA.A WORM! X Reactor5 ?? W32.BOFRA.D WORM! X Reactor6 ?? W32.BOFRA.C WORM! X Reactor6 ?? W32.Mydoom.AK WORM! X Reactor7 ?? W32.BOFRA.B WORM! X Reactor8 ?? W32.BOFRA.E WORM! X Reactor9 ?? W32.BOFRA.E WORM! X readdb40 ?? LZIO.com adware downloader X Real Internet Player Reaiplay.exe variant of the W32.SPYBOT WORM! X Real player updater realupd.exe PARLAY VIRUS! X real scheduler real scheduler.hta CEEGAR TROJAN! U Real Spy Monitor Winrsm.exe Realspy keystroke logger/monitoring program - remove unless you installed it yourself! X Real Statics Agent ccreal.exe variant of the WIN32.RBOT WORM! X RealAudio RealAudio.exe CEEGAR TROJAN! N RealDownload RealPlay.exe Download manager. Available via Start -> Programs X RealDownload Express npnzdad.exe Advertising spyware N Reality Fusion GameCam SE RFTRay.exe System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs N RealJukeboxSystray tsystray.exe System Tray icon for RealJukebox X realone_nt2003 moniker.exe SNONE.A VIRUS! X RealP1ayer ?? "RPLAY.A TROJAN! **Note that the name has a number ""1"" in place of the second lower case ""L""" N realplay realplay.exe System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences X realplay lptt01 or realplay ml097e realplay.exe "Variant of the RapidBlaster parasite (in a ""RealPlay"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name" X Realplayer Codec Support realsched.exe W32/AGOBOT-AAD WORM - NOTE - do NOT confuse with the Real Player executable as described here X Realplayer One realplay.exe W32/RBOT-NK WORM! N RealPlayer2 MsgCenterExe RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way. X RealPlayerUpdater realupd32.exe TROJ/LOHAV-T TROJAN! N Realsched realsched.exe "Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry" X Real-Tens Real-Tens.exe DownloadWare based advetising spyware U Realtime Audio Engine mmrtkrnl.exe Associated with ALCATech BPM_Studio Y Realtime Monitor realmon.exe Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates N RealTray RealPlay.exe System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences X RealUpdater realupd.exe PARLAY or MITGLIEDER.I VIRUSES! X RebateNation0 RebateNation0.exe WebRebates adware variant N Reboot Reboot.exe MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards Y Recguard recguard.exe "On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense" N Reclip reclip.exe Reclip Popup Clipboard manager X Recommended Hotfix - {0421701D-CF13-4E70-ADF0 RH.DLL SmartPops adware N Recover ?? Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete N RecShe RecSche.exe Recording scheduler for WatchTV Capture Card (TV Tuner card) X Recycle Bin Handler recycler.exe TROJ/SHUCKBOT-A TROJAN! X Recycle Bin Handler 2005 system.exe TROJ/BDOOR-HO TROJAN! X RecycleSTR msreg32.exe W32/RBOT-TC WORM! N Red Flag redflag.exe PMS prediction program with modes for guys and girls - no longer available X Red Swoosh EDN Client RSEDNClient.exe Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network X redirect redirect*.exe Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit N Redline Taskbar taskbar.exe Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards X REEGRUN ?? SECDROP.AI TROJAN X Reek 32 Server reek32.exe RANDEX.AL WORM! U Referee referee.exe MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run N Refresh Refresh.exe (Iomega) Refresh - loads the Iomega desktop icons at startup X Reg Reg.hta Homepage hi-jacker. Removal instructions here X Reg Service ipcfg.exe W32/Agobot-SO Worm! X Reg Service REGSRV32.EXE RBOT.ZW WORM! X Reg Service WinnConfig.exe W32/Agobot-PF Worm! X Reg Service winslogon.exe W32/AGOBOT-SC or W32/Agobot-SY WORM! X Reg Service winsy.exe variant of the W32.SpyBot WORM! X Reg Services Winboot32.exe WORM_RBOT.PB X reg_key FUKULAMER.exe BEAGLE.AH WORM! X reg_key loader_name.exe BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS! X reg_run Systen.exe TROJ/BANCOS-BS TROJAN! X Reg_WFT Regsysw.com WILSEF VIRUS! X Reg_WFT scanreg32.com Troj/SennaSpy-F Trojan! X reg1.reg vuamgard.exe variant of the BACKDOOR.IRC.BOT TROJAN! U reg2.0 SVCH0ST.EXE "eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X Reg32 Reg32.exe Hijacker - redirecting to only-virgins.com X reg32 reg32.exe NOUPDATE.B VIRUS! X Reg32 reg33.exe CoolWebSearch parasite related. X regcheck ?? SERVPAM TROJAN! X Regcheck ~CAB001.EXE CYBERSPY VIRUS! X RegCleaner SYSio32.exe unidentified virus VIRUS!. Note - do not confuse this with the popular RegCleaner registry cleaner freeware X RegCompres Regcpm32.exe POLDO.B VIRUS! X RegCompres REGCPM32.EXE "Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return" X Regcxdinaf REGCXDINAF.EXE TROJ/BANCOS-BW TROJAN! X Regcxn Regcxn.exe COIBOA-D TROJAN! U regdefend regdefend.exe "RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage." X RegDone services.exe NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process X RegDone winlogon.exe NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup! X RegDone Ex csrss.exe "WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X RegDoneEx lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" X regedit autoexe.exe variant of the WIN32.RBOT WORM! X regedit regedit.exe "BRID.A VIRUS! Note - resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). The valid ""regedit.exe"" resides in C:\Windows (Win9x/Me/XP) or C:\Winnt (WinNT/2K)" X REGEDIT Regsrv32.com SOUTHGHOST VIRUS! X regedit svchost.exe ccRegVfy Trojan.Rona Trojan! X Regexit runlli32.exe Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Regexit Updadv.exe Troj/QQPass-N TROJAN! U RegFreeze regfreeze.exe RegFreeze anti-spyware software X reggsdg spoolserv.exe W32/SDBOT-MS WORM! U RegHelp svchosts.exe "SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world.""" U REGIST~1 REGIST~1.EXE "Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation" X Register Manager RegistryManage.exe SDBOT.AYH WORM! N Register MediaRing Talk register.exe If you don't want to register MediaRing and be reminded about it every bootup disable it U RegisterDropHandler REGIST~1.EXE "Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation?" X Registration Service toker.exe W32/SDBOT-BB WORM! N Registration-Studio 8 RegTool.exe Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems U Registry ?? "Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it." X Registry wscript.exe VBSWG VIRUS! X Registry Checker Regrun.exe SDBOT TROJAN! X Registry Checkup winreg.exe unidentified WORM or TROJAN! X Registry Checkup System326a Monitor Winregs326a.exe variant of the W32/SDBOT WORM! X Registry Integrity Checker regintmon.exe variant of the AGOBOT/GAOBOT WORM! X Registry Integritycheck WCPDT.EXE W32/AGOBOT-RF WORM! X Registry Loader regloadr.exe GAOBOT.AO WORM! X Registry Loader winhlpp32.exe GAOBOT.AO WORM! X Registry oidet win32.exe RBOT.BMT WORM! X Registry Scanner regscanr.exe OPTIX LITE FIREWALL BYPASS VIRUS! X Registry Server regsrv32.exe W32/Rbot-GM WORM! X Registry Service REGSRV32.EXE variant of the WIN32.RBOT WORM! X Registry Services Registry.exe DOWNLOADER.CILE VIRUS! X Registry System16 Checkup Monitor SystemReg16.exe variant of the WIN32.RBOT WORM! X Registry System166 Checkup Monitor SystemReg166.exe variant of the WIN32.RBOT WORM! X Registry Value Name service.exe W32/RBOT-AHT WORM! X Registry Value Name winapi32.exe variant of the WIN32.RBOT WORM! X Registry Value Name Start MsPMSPSa.exe variant of the W32/SDBOT WORM! X RegistryCheck ?? Ulubione adult content dialer X RegistryChk winbackup.exe MERTIAN VIRUS! U RegistryMechanic RegMech.exe "Registry Mechanic for Windows - ""you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages""" X RegistryMonitor registry.pif Affilred adware X Regkey for autostart winservice.exe W32/RBOT-NU WORM! Y RegProt Regprot.exe RegistryProt from Diamond Computer Systems - protects the system registry against changes X Regptmens REGPTMENS.EXE Troj/Bancos-ED TROJAN! X REGRUN ?? Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! X REGRUN dialer.exe Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! X RegRun mActiveX.exe Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! X REGRUN regeditt.exe Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! X REGRUN sory.exe Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! X REGRUN winfix22490.exe Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! U RegRun WinBait winbait.exe Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.. Y Regrun2 WatchDog.exe "Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc?" X REGRUNM autoprotect.exe unidentified WORM or TROJAN! X Regrx rundll32.exe "TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!" X RegScan DLLSRV32.EXE AGOBOT.AEW WORM! X RegScan Regscan.exe BACKDOOR.TALEX TROJAN! X Regscan regscanr.exe TROJ/OPTIX-SE TROJAN! X regservices.exe regservices.exe W32/Rbot-MN worm infection N RegShave regshave.exe "Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly" X regsrv regsrv.exe OPTIXPRO.11 VIRUS! X regsrv scvhost.exe AGOBOT.E WORM! X regsrvc regsrvc.exe TROJ/STOPED-A TROJAN! X Regsv regsv.exe Search hijacker - redirecting to scheo.com X Regsvc regsv.exe unidentified TROJAN! U regsvc systune AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed. X regsvc32 regsvc32.exe Homepage hijacker that changes your homepage to an adult content site X regsvr regsvr.exe WEBMONEY-G TROJAN! U REGSVR32 ?? ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality X RegSvr32 msmsgs.exe Trojan.Zlob.B or Troj/Zlob-M TROJAN! X regsync regsync.exe SafeSurfing adware U RegTweak RegTwk.exe "Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface" X RegVer REGVER.EXE LATINUS.16 VIRUS! X RegWrite csrss.exe "SOKACAPS VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling" U Regx10EXE atix10.exe ATI Remote Wonder - PC wireless remote control U ReleaseRAM RRAM.exe """Release RAM allows your computer to run faster and uses your computer's RAM more efficiently"". Some users swear by programs such as this but I suggest you read this article and make up your own mind" X Reload reload.exe /reloadenterpice Lazar TROJAN! X reload reload.vbs LOVELETTER.AS VIRUS! N RemHelp Remhelp.exe BT Voyager ADSL Modem Help related N Remind_XP Remind_XP.exe "Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package" N Reminder Remind_XP.exe "Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package" N Reminder reminder.exe From MS Money. Reminds you of your bills N Reminder-cpqXXXXX remind32.exe Compaq printer Registration N Reminder-hpcXXXXX remind32.exe HP CD-Writer Registration N Reminder-ranXXXXX remind32.exe Registration reminder widget for Rand Mcnally maps N reminder-ScanSoft Product Registration remind32.exe Registration reminder for ScanSoft products such as PaperPort U RemindMe RemindMe.exe Remind-Me - calendar software X Remndr CsRemnd.exe CasinoOnline foistware U Remote Access rnaapp.exe "Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed" X Remote Access Slave Synchost.exe RIPJAC VIRUS! N Remote Control Rc.exe Hinet Hi-Five ISP software N Remote Controller TVRMVCR.EXE ProLink PlayTVpro TV tuner software U Remote Desktop Computing marspc.exe Marspc Remote Desktop Computing U Remote Management Agent zenrc32.exe "Part of Novell's ZENworks - ""Complete End-to-End Directory-enabled Network Management"". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation" U remote master remote master.exe Required if you want your ASUS Remote control to work at all. Available via Start -> Programs X Remote Procedure Call winrpc.exe W32/Rbot-KM worm infection X Remote Procedure Call winsysrpc.exe W32/Sdbot-PS worm infection X Remote Procedure Call For Windows 32bit rpc.exe W32/Rbot-MD worm infection X Remote Procedure Call Locator ?? variant of the LOVGATE WORM! X Remote Procedure Calls mswinc.exe W32/RBOT-IT WORM! X Remote Procedure Calls mswinrpc.exe RBOT.KJ worm infection X Remote Procedure Calls win.exe W32/SDBOT-QI WORM! Y Remote Update Monitor imonitor.exe Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer. N Remote_Agent RemoteAgent.exe "Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs" Y RemoteAgent RAUAgent.exe "Trend Micro's Office Scan Client, see here ; ""Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates""." U RemoteCenter RcMan.exe "Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats" U RemoteControl PDVDServ.exe "Remote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one" U RemoteControl rmctrl.exe "Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one" X REMOVE ME windos.exe SDBOT.EE WORM! N Removecpl Removecpl.exe Related to a Belkin 54Mbps Wireless Utility Control Panel applet X Removed.exe Removed.exe GatorCheat - adware downloader U RepliGo Assistant RepliGoMon.exe "Cerience RepliGo software - ""any document you have on your PC can be transferred to your mobile device""" U ReproPRD PrdUsb.exe "Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work" X requester requester.*.exe "variant of the Win32.Muquest.A trojan - NOTE: the asterisk stands for a digit, examples: requester.5.exe, requester.10.exe" X Required Service Drivers micront.exe W32/RBOT-ABD WORM! X resagnt restun.exe Adware downloader - detected by Panda antivirus as Trj/Downloader.ALQ X reseurce ?? Troj/Lineage-AI TROJAN! N Resolution Assistant matcli.exe "Dell Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide" N Resource Meter rsrcmtr.exe Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes U Restart WSC Setting wscrestp.exe WinStart Commander - part of Ultra_WinCleaner_Utility_Suite . Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes. Y RestoreIT! VBPTASK.EXE "RestoreIT! from FarStone ""allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure.""" X restory restory.exe RETSAM VIRUS! U Resume Copy copyfstq.exe Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function U ResumeFixClocks resumefix.exe Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards X retime retime.exe GIPMA VIRUS! U RetrieverScheduler retrieverscheduler.exe "80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information"". Real-time scheduler - shortcut available" U RevoTaskbarApp RevoTask.exe Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it; but changes to speaker setup and sound modification (Bass/Treble etc) will not be available. N RexSyMon rexsymon.exe Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC X RF EC.exe Troj/Lineage-U TROJAN! U rfagent rfagent.exe "Registry_First_Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders" X RFTray RFTRay.exe Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs Y rfw Rfw.exe RAV AntiVirus N RFX_auto_upgrade ?? A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade U RH rh32.exe EuroFonts - adds Euro symbols to pre-Euro computers X Rhino ?? W32.BOFRA.A WORM! U RhinoBlocker RhinoBlocker.exe RhinoBlocker - pop-up stopper N RHSI SHS SHS.exe "Rogers Hi-Speed Internet software. ""Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash""" X richup richup.exe SafeSurfing parasite variant U Ring Central Fax rcenterrll.exe Only needed if you want a PC to answer faxes automatically X rIOphosIs rIOPHosIs.vBS RIOSYS VIRUS! U RivaTuner or RivaTunerStartupDaemon RivaTuner.exe RivaTuner for tweaking nVidia graphics cards. Required if you make any changes U rmctrl rmctrl.exe "Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one" N rmmon mprmmon.exe Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card X rn4d dirote.exe BKDR_MAROON.A TROJAN! X RNBc Test bvldv32.exe W32/Rbot-AJF WORM! X RNBc Test wf32vbs.exe W32/Rbot-AGR WORM! U RNBOStart sentstrt.exe Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools X RNBz Test wf32vbc.exe W32/Rbot-AEY Worm! X RNDc Test wf32b.exe variant of the W32/SDBOT WORM! X rngmf ?? RANKY.C VIRUS! X Rnudll32 tadxtr.exe TROJ/QQPASS-O TROJAN! X Roam04 ActiveX.exe Troj/Roamer-A TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder. N RoboForm RoboTaskBarIcon.exe "Roboform - password manager and web form filler. Will work without this startup entry, as the ""active"" component is an integrated Internet Explorer browser plugin" N RoboFormWatcher RoboFormWatcher.exe AI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs U Rocket.Time RocketTime.exe Time synchronization software from Rocket Software X rollbk dsm.exe W32.Serflog.B WORM X rollbk msmpatch.exe W32.Serflog.B WORM X rollbk svosm.exe W32.Serflog.B WORM X rollbk sysup.exe W32.Serflog.B WORM X romahere matrixhere.exe SuperSpider hijacker - a CoolWebSearch parasite variant X romahere2 ?? SuperSpider hijacker - a CoolWebSearch parasite variant X romahere3 ?? SuperSpider hijacker - a CoolWebSearch parasite variant X Root_Machine ?? Troj/Bancban-DI TROJAN! X ROOT_Machine winlogon.exe Troj/Banker-FI TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\inf or Winnt\inf folder. N RoxAssist RoxAssist.exe "Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message ""Engine initialized successfully with full recorder support"". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use ""Add Remove Programs"" in ""Control Panel"".) .Can be run manually" N RoxioAudioCentral RxMon.exe "Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. ""Includes a player, media manager, ripper, tag and sound editor - integrated in a single application"". Not required for Roxio to work properly." N RoxioDragToDisc DrgToDsc.exe "Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly" Y RoxioEngineUtility EngUtil.exe "Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking" U RP32 rp32.exe ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems. X RPC MSschost.exe variant of the GAOBOT/AGOBOT WORM! X RPC Patcher ?? BOLGI VIRUS! X rpc Win32 shost32.exe W32/RBOT-ABL WORM! X rpc Win32 spoolscv.exe variant of the WIN32.RBOT WORM! X rpcda Win32 rpcda.exe W32/Rbot-AE Worm! X RPCserv32 services.exe "W32.MYDOOM.AL WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X RPCserv32g CSRSS.EXE "BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X RPCserv32g MSDEFR.EXE BOBAX.AD WORM! X RPCserv32g NB32EXT2.EXE BOBAX.AD WORM! X RPCserv32g services.exe "MYDOOM.BH WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X RPCserv32g services.exe "W32.BOBAX.AA WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X RPCserv32g services.exe "W32/MYDOOM.BV WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X RPCserv32g SMSS.EXE "BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X RPCserv32g WINLOGON.EXE "BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" Y RPCSS.exe rpcss.exe "Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here" X RpcxWindows Extensions rpcxwinex.exe RBOT.ACP WORM! X rreg rreg.exe Unidentified adware X RRMedic rrmedic.exe Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection U rscmpt rscmpt.exe Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status U rsMenu rsMenu.exe Synchronizes a Casio PDA with MS Outlook X RSPC Driver ?? W32/RBOT-SN WORM! X RSPC Driver D ?? variant of the WIN32.RBOT WORM! X RSS "rundll32 RSSToolbar.dll, DllRunMain" """Related Sites"" toolbar - SearchAndClick hijacker variant" U RssReader RssReader.exe RssReader - a free RSS reader able to display any RSS and Atom news feed (XML) X RSync netsync.exe SafeSurfing adware X rtcdll rtcdll.exe Unidentified adware N RtlMon.exe RtlMon.exe Monitor for RealTek network card Y RTMonitor RTMonitor.exe "Cheyenne, ( now eTrust ) antivirus" X rtos rtos.exe IRC trojan Y rtvscn95 RTVSCN95.EXE Real-time virus scanner component of Norton Anti-Virus Corporate Edition X Ruby13 Ruby13.exe MEXER.E worm X Ruby14 Ruby14.exe W32/FIGHTRUB-A WORM! X ruin system32.exe TROJ/DELF-JM TROJAN! U RuLaunch RuLaunch.exe "Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis" X run Autoexec.com HOLCAS.A WORM! X run dec25.exe W32.ATAK.F WORM! X run inetinfo.exe Backdoor.Binghe TROJAN! X Run Msn Messenger msnmgr.exe AGOBOT.HA WORM! X Run MSupdt32 wscript MSupdt32.vbs CASER VIRUS! U Run POPFile in background perl.exewperl.exe POPFile - E-mail spam blocker X Run Services as Application localsvc.exe Troj/Dloader-NY Trojan! X Run Services as Application netsvc.exe Troj/Dloader-NY Trojan! X Run Services as Application spoolsvc.exe Troj/Dloader-NY Trojan! X Run Services as Application svcadmin.exe Troj/Dloader-NY Trojan! X Run Services as Application svcman.exe Troj/Dloader-NY Trojan! X Run Services as Application svcrun.exe Troj/Dloader-NY Trojan! X Run Services as Application tcpsvc.exe Troj/Dloader-NY Trojan! X Run Services as Application websvc.exe Troj/Dloader-NY Trojan! U Run StartupMonitor StartupMonitor.exe "Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu" X Run TaskMrg csrss.exe TROJ/LDPINCH-W TROJAN! X run windows servic.bat REBOOT-AP TROJAN! X Run XP Service Pack xpservicepack.exe Sdbot.AQA worm infection X Run[0] syscnfg.exe "Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside" X Run_cd Run_cd.exe GHOST.23 VIRUS! Y run= asistat.exe "Used with some models of Panasonic, Epson and NEC printers - required for printer to work." X run= Autoexec.com HOLCAS.A WORM! X run= Celine.scr TROJ/CELINE-A TROJAN! X run= clean_service.cmd W32.Refaz WORM! X run= cyxid98.exe Unidentified malware X run= dllreg.exe TROJ/DUMARU-L TROJAN! X run= DRDOOM.EXE W32/SEMAPI-A WORM N run= fmedia.exe FMedia FaxWorks related - can be run manually X run= fntldr.exe CoolWebSearch parasite related. N run= hpfsched HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature X run= htmlsync.exe Searchforfree.info browser hijacker X run= iexpIore.exe OBLIVION-B TROJAN! X run= info32.exe CoolWebSearch parasite variant. N run= lxdboxcp.exe Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS X run= mdm.exe TROJ/PROXY-GG TROJAN! X run= mouse_configurator.win VBS.GAGGLE.E WORM! X run= msoffice.exe "ADWARELOADER TROJAN! - NOTE: Do NOT confuse with the (legitimate) Microsoft Office file, which would typically be located in the Program Files\Microsoft Office\Office folder!" X run= msreg32.exe BACKDOOR-FORCEDENTRY TROJAN! X run= Msvxd.exe W32.DATOM WORM! X run= msxmidi.exe CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw N run= pcfix2k.exe pcfix2k splash screen X run= ptlseq.cpl PhoenixNet BIOS adware. See here U run= ramsys.exe Advanced Startup Manager from Rays Lab X run= RAVMOND.exe variant of the LOVGATE WORM! X run= real.exe variant of the LOVGATE WORM! X run= RegistryReminder.exe APSTROJAN.OB TROJAN! X run= services.exe "Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!" X run= services.exe "TROJ/KREPPER-N TROJAN! - NOTE - this file is placed in a inet10066 folder in Winnt or Windows , and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" Y run= smsrun16.exe "Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs" X run= svcinit.exe CoolWebSearch parasite related. X run= svhost.exe ADMINCASH.B TROJAN! X run= winlogon.exe CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process! X run= wmplayer.exe CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable! Y run= wswpd.exe "Used with some models of Panasonic, Epson and NEC printers - required for printer to work." X Run05 rundll_32.exe Troj/Bancos-DT TROJAN! X Run32dll ocxdll.exe Unidentified mIRC VIRUS! X run32dll task32.exe Unidentified mIRC VIRUS! X run32dll WINClock.exe Unidentified mIRC VIRUS! U RunAlert AService.exe "MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system" N runAP runAP.exe Not required but what is it? X Runapp32 Runapp32.exe NEODURK VIRUS! Y RunCA InvokeSvc3.exe Wireless-G USB Wireless Network Adapter related - would appear to be required X rund1132 rund1132.exe W32/DOPBOT-A WORM! X Rund1132.exe Rund1132.exe Troj/StartPa-HS TROJAN! X Rund1l32 Winfi1e32.exe MERTIAN VIRUS! X Rundil32 runlli32.exe Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Rundil32 Updadv.exe Troj/QQPass-N TROJAN! X rundl332 math.exe ...pluged.exe DOOMJUICE VIRUS! X rundli32 rundli32.exe LADE VIRUS! X Rundli32 runlli32.exe Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Rundll ?? MYTOB.IG WORM! X RunDLL ?? Flingstone.com browser hijacker X Rundll Rundll~.exe W32/DELF-KT TROJAN! X Rundll16 Rundll16.exe any number of VIRUSES! X rundll32 ?? AUTEX VIRUS! U rundll32 ?? Associated with a Bluetooth adapter. If disabled the error dialogue box disappears N RunDLL32 ?? "System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties" N RUNDLL32 ?? "System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the ""NVIDIA Driver Helper Service"" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)" U rundll32 ?? Loads default settings for Leadtek Winfast graphics cards X rundll32 csrss.exe "GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!" X RUNDLL32 rundl32.exe W32/Demotry-A Worm! X Rundll32 Rundll32.exe "DVLDR VIRUS! Note - this is not the valid ""Rundll32.exe"" as it\'s in the Windows\Fonts directory" X rundll32 rundll32.exe "SANKER VIRUS! Note that the valid ""rundll32.exe"" resides in C:\Windows\System32 wheras this version resides in C:\Windows" X Rundll32 Windows.exe QQPASS.E VIRUS! X RunDLL32 winupdate.exe Unidentified VIRUS! - possibly a BMBOT variant N Rundll32 cmicnfg "Rundll32 cmicnfg.cpl, CMICtrlWnd" System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel X Rundll32.exe ?? W32/Xelif-A worm infection X Rundll32_7 ?? "BrowserAid ""Featured Results"" hijacker variant" X Rundll32_8 ?? BrowserAid adware X Rundll32_8 ?? BrowserAid parasite variant X rundll64 ?? AUTEX VIRUS! X RundllSvr Rundll.exe W32.HUAYU WORM! X Rundllsystem32 Rundllsystem32.exe NETDEVIL.B VIRUS! X Rundnm Rundnm.exe TROJ/DELF-HA TROJAN! X RUNGogoTools GoGoLaunch.exe www.gogotools.com adware X RUNGogoTools LaunchAdware.exe GoGoTools adware X RUNHYPER hyperx.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" X runing win.exe Troj/Delf-LC TROJAN! X RUNLOAD l0ad.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" X RUNLOUD loud.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" U RunOnce RUNONCE.EXE Part of MS Data Access Components - only required if you use these X RunProg Server.exe OPTIX.04.A VIRUS! X RunProg wini.exe OPTIX.04.D VIRUS! X runreper viewer.exe W32.REPER.A WORM! X runs run.exe W32/Rbot-BWF WORM! X RunServices runsvc32.exe AGOBOT.QJ WORM! X runSubvalues ?? TROJ/DLOADER-QY TROJAN! U RunSysd32 RunSysd32.exe DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within X Runtt1 Internat.exe Troj/Lineage-R Trojan! X Runtt1 Internet.exe Troj/Lineage-Q Trojan! X RunWin ?? TROJ/BANKER-ES TROJAN! X runwin32 runwin32.exe Troj/ESearch-A trojan X RunWindowsUpdate uptodate.exe BrowserAid/BrowserPal foistware U Rupsw32 Rupsw32.exe "MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems." X RVC6Player tskdbg.exe TROJ/ZAPCHAS-M TROJAN! X rvde ?? Related to li-speed**** X RVP bpc.exe BroadcastPC adware N RxMon rxmon9x.exe Dell Resolution Assistant X S0undMan svch0st.exe "variant of the LOVGATE WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X S3 Internal Chip s3serv.exe W32/AGOBOT-DD WORM! N S3apphk S3apphk.exe A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems. N S3TRAY S3Tray.exe S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display U S4F S4F.exe S4F internet filtering software X s4helper s4helper.exe Searchcentrix hijacker N Sa3dsrv Sa3dsrv.exe 3D sound extension for Windows X saap saap.exe 180Solutions/N-Case adware variant N Sabreserver SABSERV.EXE Airline reservation software from Sabre. Available via Start -> Programs X sac sac.exe 180Solutions/N-Case adware variant X SACC sacc.exe SurfAccuracy adware N SAClient RegCon.exe "AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you\'re immediately notified by e-mail, pager, or text messaging" X Safe ?? Troj/Banker-DT TROJAN! X Safe SafeWin.exe PWSteal.Focosenha trojan infection. X SafeGuard Popup Blocker Updater ?? SafeguardProtect/Veevo X SafeGuard Popup Blocker Updater (required) ?? SafeGuardProtect/Veevo X SafeGuard Popup Updater (required) ?? SafeguardProtect/Veevo hijacker U SafeHouseSystemTray SDWTRAY.EXE "SafeHouse ""Personal Privacy"" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them ""invisible"" and encrypted." N SafeInstall.exe SAFEIN~1.EXE Monitors a download and ensures an newer version of a file isn't replaced by an older one N SafeOFF SafeOff.exe Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation X SafeSearch safesearch.exe AutoSearch parasite variant X SafeSurfingUpdate SSUpdate.exe DyFuCa/MoneyTree parasite variant U Safeworld Freedom.exe SafeWorld Internet Security X Sagate Security Firewall sagate.exe W32.GAOBOT.BOW WORM! N SAgent2ExePath SAgent2.exe Seiko Epson printer status agent. Disable if printer is not used often U SAGENTSERVICE Sagent.exe -start TinySpyAgent **Note this application must be manually installed. X sagnt sagnt.exe Adware web downloader X SAHagent Sahagent.exe ShopAtHomeSelect adware X SAHBundle bundle.exe ShopAtHomeSelect adware X SAHBundle shop1003.exe ShopAtHomeSelect adware X saie saie.exe 180Solutions/N-Case adware variant U SAIMON SaiMon.exe Saitek joystick driver X sain sain.exe 180Solutions/N-Case adware variant X sais sais.exe 180Solutions/N-Case adware variant U SaitekAutoConfigure saicnfig.exe Configuration for Saitek game controllers X Sakemsneql simenu.exe SDBOT.BTO WORM! X salm salm.exe 180Solutions/N-Case adware variant U SAMcal SAMcal.exe SamCal - calendar/reminder program U Sametime Connect Connect.exe IBM Lotus Instant Messaging and Conferencing software X Samsong Samsong.exe SDBOT.BNE WORM! X Samsung Samsungs.exe IRC_TROJAN variant! X Sam-sung Sam-sung.exe variant of the W32/SDBOT WORM! N SandIcon SandIcon.exe "SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources" X sapp sapp.exe 180Solutions/N-Case adware variant X saSyncMgr ?? Browser hijacker - redirecting to Searchant.com U SATARaid SATARaid.exe RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives X satmat satmat.exe Transponder parasite updater/installer X sau sau.exe 180Solutions/180Search adware U SAUpdate SAUpdate.exe Big Brother from Quest Software. System and network monitor U SAutoLaunchExe SAutoLaunchExe.exe "Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook." Y SAVAgent SAVAgent.exe "Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users" X Save Save.exe SaveNow adware X SaveDate SaveStartDate.Exe Unidentified adware X Savenow SaveNow.exe SaveNow adware X Savenow savenow.exe SaveNow adware X SAW saw.exe SmartAdware adware U Say The Time 5.0 SAYTIME.EXE "This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly" U SB sb.exe Acer Soft Button on Acer Tablet PCs N SB Audigy 2 Startup Menu ?? "Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function" X SB Watchdog SBWatchdog.exe Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information U SBAutoUpdate sbautoupdate.exe SpywareBlaster auto-updater U SBC Self Support Tool matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in ""add/remove programs"" some help menus in help and support will not be available. You decide" N SBC Yahoo! Connection Manager ConnectionManager.exe The cmanager.exe process is used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection. U SBDrvDet SBDrv.exe "Detects the ""Easy Front-Panel Audio Connectivity Drive Internal Drive Bay"" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one" N sbdrvdet sbdrvdet.exe Checks to see if Creative sound card driver should be updated X SBHC sbhc.exe SuperBar parasite - uninstall available here X SBMPOP SBMPop.exe SearchByMedia adware N SBMX sbmx.exe SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) X sbss Launcher sbss.exe SideBySide adware U SbUsb AudCtrl "RunDll32 sbusbdll.dll,RCMonitor" Control for Soundblaster MP3 external (USB) sound card U sc run.exe "All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file." U sc sc.exe Watchdog 2.0 Software - monitoring program N sc scrubxp.exe "ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc" Y SC3300CC SC3300CC.exe SiPix digital camera Twain device driver X scain s030109.Stub.exe "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X ScamDisk SVOHOST.exe LEWOR.D WORM! X scan mscman.exe "Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,? ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!""" X Scan Register ssms.exe W32/RBOT-AT WORM! X ScanDisc satan.exe GregStar backdoor TROJAN! X ScanDisk ScanDisk.exe "GANDA.A VIRUS! Note - this is not the valid ""ScanDisk"" Win9x/Me standard disk error checker" X scands32.exe scands32.exe variant of the Adclicker TROJAN! N Scanner Detector SDetect.exe "ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the ""GO"" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the ""GO"" button" X Scanreg ?? QQPASS.E VIRUS! X ScanRegistry nsrvnt.exe NERTE VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe X ScanRegistry scanregv.exe MASTERLOCK VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe X ScanRegistry Scanregw.exe "W32.STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt). Runs from the registry RunServices key as opposed to the Run key" X ScanRegistry Scanregw.exe "GWGHOST VIRUS!. Not to be confused with the real ScanRegistry above - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt)" Y ScanRegistry Scanregw.exe "Scans the Windows 98 and Millennium system Registry and makes back-ups at start-up. This is vital should the registry become corrupt. The ""Scanregw.exe"" executable is located in %windir% (the Windows directory - typically C:\Windows)" X ScanSpyware v * Scanner.exe """Spyware remover"" (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" N SCardSvr scardsvr.exe Related to SmartCard readers and sometimes uses lots of system resources X SCardSvr SCardSvr32.Exe MOFEI.B VIRUS! X scheck scheck**.exe KETCH VIRUS! where ** represents a number X scheck45 scheck45.exe Related to unknown Malware - hidden installer associated with it X ScheduIe nrchk.exe Premium rate adult content dialer N Scheduled Maintenance Scheduled_Maintenance.exe Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs X Scheduler expIorer.exe WIN32.TACTSLAY.A TROJAN! X Scheduler MSMSGS.EXE "TROJ/HOSTBANK-A TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32\Config or Winnt\System32\Config folder, and should not be mistaken for the MSN Messenger file of the same name!" X Scheduler outIook.exe WIN32.TACTSLAY.A TROJAN! U Scheduler Scheduler daemon.exe "Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings." X Scheduler svcrhost.exe WIN32.TACTSLAY.A TROJAN! X Scheduler svcshost.exe WIN32.TACTSLAY.A TROJAN! X Scheduler winagent.exe WIN32.TACTSLAY.B TROJAN! X Scheduler Service wsass.exe WIN32.LIOTEN.KX WORM! X SchedulerMgr navchk.exe Premium rate adult material dialer X Scheduling Agent Scheduler.exe SUBWOOFER VIRUS! Note - this is not the real MS Scheduling agent as the executable is incorrect X SchedulingAgant MMTASK.EXE YAB.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename U SchedulingAgent mstask.exe "Windows Task Scheduler, displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on." U SchedulingAgent mstinit.exe "MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans" U Schmaili Schmaili.exe Schmaili - insert animated smilies into your e-mail U Schoolpop0 Schoolpop0.exe Schoolpop Shopping Buddy Y SCHWIZEX SCHWIZEX.EXE "Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot" X ScManager scman.exe W32/FORBOT-CW WORM! X scopedll scopedll.exe CRYPTER.C trojan variant infection N Scotia OnLine Recovery or Scotia OnLine Secur etdirrcv.exe Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process X Scr scr.scr OPASERV.T VIRUS! N ScrapPad Scrappad.exe "ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper" U Screen Calendar scrcal.exe Screen_Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler. U Screen Guard launch.exe Part of Access Denied security and privacy software U Screen Guard Message Scan sgms.exe Part of Access Denied security and privacy software X Screen Saver scrnsaver.scr W32/Rbot-AGP WORM! N Screen Saver Control FSScrCtl.exe Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon N ScreenPrint32 ScreenPrint32.exe ScreenPrint32 screen capture software - can be launched manually. Y ScriptBlocking SBServ.exe Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information Y ScriptSentry Scriptsentry.exe Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly U Scroll-In-Mouse V2.0 SCROLL.EXE Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features X scrsvc scrsvc.exe "Hijacker, a CoolWebSearch parasite variant - also detected as the Troj/Agent-DS Trojan!" X ScrSvr ScrSvr.exe OPASOFT.A VIRUS! X ScrSvr ScrSvr.exe OPASERV VIRUS! X ScrSvrOld ?? OPASERV VIRUS! Y Scsi Scsi.exe SCSI Miniport driver U scvhost scvhost.exe "Wiretap is a spyware program that monitors and records keystrokes, programs executed, Web sites visited, and Instant Messenger conversations. If you didn't install this yourself, remove it." X scvhost scvhost.exe "Hijacker, redirecting to bestsearch.cc - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.rw" X scvhost svzhost.exe variant of the W32.SPYBOT WORM! X scvhost loader ixplore.exe SDBOT-CY TROJAN! X scvhost.exe scvhost.exe Troj/Lohav-N trojan infection X scvhost.exe scvhost.exe W32/AGOBOT-RA WORM! X sd32info sd32info.exe CRYPTER.A trojan infection U SDaemon sdaemon.exe "PC Security from Tropical Software. 'PC Security? 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, ""Drag and Drop"" support, plus many other handy features'" X SDAv csnss.exe W32.Serflog.C WORM! X SDAv svhost.exe W32.Serflog.C WORM! X sdchosts32 vbdd.exe WIN32.RANKY.AG backdoor TROJAN! N SDetect SDetect.exe "ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the ""GO"" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the ""GO"" button" X sdfsdfsdf sp2update.exe W32.SpyBot worm variant X SDIN Adapter sdin.exe W32/Forbot-AP worm infection X SDK Codre Function22 sdkimddprovment2.exe W32/SDBOT-YJ WORM! X SDK Core Component SDKC0RE.exe W32/SDBOT-WC WORM! X SDK Core Component sdkcore.exe W32/SDBOT-WC WORM! X SDK Core Function sdkimprovment.exe RBOT.BHL WORM! X SDK Core Function2 sdkimprovment2.exe W32.SPYBOT.OGX WORM! X SDKcore Update Components2 SDKC0R3.exe W32/RBOT-ABA WORM! X sdkupdate22 SDK0mCORE.exe W32/FORBOT-DT WORM! N SDPhotoBar.exe SDPhotoBar.exe "SmartDraw_Photo . Organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics." X sdrss sdrss.exe W32/SDBOT-SQ WORM! U sds20 svchost.exe InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. U SDTray sdtray.exe "RSA Keon Web_PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed." U sealmon sealmon.exe "SealedMedia enables you to combine document protection and control with your existing applications, such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email." X Search Bar taskbar.exe W32/OPANKI-F WORM! X Search Page http://find.naupoint.com Naupoint browser hijacker X searchbar vnmispoisn_downloader.exe SearchBarCash adware variant X SearchEnhancement scbar.exe IE search hijacker X Search-Exe SE.exe Hijacker - redirecting to Search-exe.com X Search-Exe se.exe Search-Exe hijacker X searchnav searchnav.exe SearchNav adware - IEFeatures/Popnav variant X SearchNavVersion searchnavversion.exe SearchNav adware - IEFeatures/Popnav variant X SearchSetter searchsetter[1].exe "browser hijacker, redirecting to FindWhateverNow.com" X SearchSquire33 SearchUpdate33.exe SearchSquire parasite X SearchUpgrader SearchUpgrader.exe eUniverse/KeenValue adware related hijacker X secboot mszx23.exe variant of the HAXDOOR.D TROJAN! X secboot vtd_16.exe TROJ/HAXDOOR-AE TROJAN! X Secboot w32tm.exe HAXDOOR.D TROJAN! U SecondChance sctray.exe Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash X Secret Secret.exe Troj/Delf-LW TROJAN! X Secret-Crush start.exe Hijacker that may reset your browser's home page and/or search settings to point to undesired sites U SECRETMAKER secretmaker.exe "SECRETMAKER is a combonation of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner." U SecretSmileys ss.exe "Secret_Smileys is an add-on for AIM˝ that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window." X secserv.exe secserv.exe Reported by Panda as an EasySearch Adware variant. Note: EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer. X secsvc32 secsvcnt.exe Global_Patrol TROJAN! U Secsys Secsys.exe "Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it" X secure ?? DealHelper adware X secure secure.exe DealHelper adware X secure svshost.exe W32/Rbot-AFO Worm! N SecureClean4RegManager scregmanager4.exe "WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually" N SecureClean4Tray sctray4.exe "WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually" N SecureCleanIEClean SCIEClean.exe "SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches" U SecureItPro Secureitpro470p.exe "SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop" X SecureLogin Mslg32.exe REDZED VIRUS! X Security Accounts Manager SM samsm.exe SPYBOT.JE WORM! X Security Agent Manager mssams.exe W32/RBOT-SV WORM! N Security iGuard Security iGuard.exe """Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" U Security Manager SecurityManager.exe "A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private." X Security Patch scmss.exe W32/RBOT-ZW WORM! X Security Patch WinUpdate32.exe W32/SDBOT-BM WORM! X Security Patches msnkn.exe RBOT.WW WORM! X Security Patches WinLab32.exe W32/SDBOT-KB WORM! X security service syss.exe unidentified WORM or TROJAN! X securw Nctrup.exe W32.NOPIR.A WORM! Y SECWIZ98 SECWIZ98.EXE Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here X seeve seeve.exe MediaMotor/Popuppers adware variant U SeMS SeMS.exe PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone U Sensiva Sensiva.exe "Symbol_Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly." X SENTRY SENTRY.exe "From IP Insight. Allows website owners ""to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website"". Will be detected by most firewalls and the majority of home users should disable it?" X Sepate Security Firewall sepate.exe variant of the WIN32.RBOT WORM! X Serials serials.exe Any one of a variety of worms and trojans X serpe formatsys.exe W32.Serflog.A WORM! X serpe msmbw.exe W32.Serflog.A WORM! X serpe serbw.exe W32.Serflog.A WORM! Y serrdctl.exe serrdctl.exe """Shared Modem Service Client Event Viewer"" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems" X SERV PacK2 nerx.exe W32/SDBOT-ACP WORM! X server server.exe Troj/Singu-Q TROJAN! X server system.exe Troj/Meths-A TROJAN! X Server Backbone server05.exe W32/RBOT-ZM WORM! X SERVER.EXE SERVER.EXE BUSHTRO122 or SMOKODOOR VIRUSES! X serverex Server.txt.vbs DELTAD.A VIRUS! X Service ?? KAITEX.E VIRUS! U Service service.exe ALADINZ.H VIRUS! X Service Service.pif W32/ASSIRAL-C WORM! X Service services.exe "W32.NETSKY or W32.NETSKY.B WORM! **Note - not to be confused with the valid Windows ""services.exe"" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt" X service services.exe "W32.NETSKY.AI WORM! - Note - this is NOT the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X Service SYSNT.exe BACKDOOR-CHA TROJAN! X service wN2S.exe variant of the WIN32.RBOT WORM! X Service Cleaner filen.exe RBOT.BRH WORM! N Service Connection "sccenter.exe, bwtray.exe" For Compaq PC's. Part of Backweb X Service Controller Csrrs.exe GAOBOT.AO WORM! X Service Controller service.exe PREVERT TROJAN! X Service Drivers abl.exe W32/Sdbot-YX Worm! X Service Drivers Compt.exe W32/RBOT-ZJ WORM! X Service Drivers msnpg.exe RBOT.BMD WORM! X Service Drivers PC.EXE W32/SDBOT-WK WORM! X Service Host ?? TORVEL.B VIRUS! X Service Host spoolos.exe TORVEL VIRUS! X Service Host SVCHOST.EXE "DAOSER-A TROJAN! - NOTE - this file is placed in a subfolder of WINDOWS\System32\Services, and is not to be confused with the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" X Service Host Driver svchost.exe "HITON VIRUS! This is not the valid svchost.exe as described here. Located in a Windows directory, and not in Windows\System32" X Service Manager DXSOUND.EXE Proxy-Gric TROJAN! X service manager service.exe DONBOMB.A TROJAN! X Service Manager SERVICEMGR.EXE W32/PASSMAIL-D VIRUS! N Service Manager sqlmangr.exe "SQL Server?Service Manager - provides tray access to SQL server,?the server agent and MSDTC. Available via Start -> Programs" X Service Monitor filen.exe variant of the WIN32.RBOT WORM! X Service Monitor msnfilen.exe W32/Rbot-ALE WORM! X Service Pack ?? W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif X Service Pack DLL Runtime spdll32.exe variant of the WIN32.RBOT WORM! X Service Process service.exe Troj/Dcmbot-C TROJAN! X Service Process SVCHOST.EXE DARKER VIRUS! Note - not the valid svchost.exe as described here. Located in %Windir% not %Sysdir% X Service Process winset.exe variant of the W32.SPYBOT WORM! X Service Registry NT Save jdbgmgrnt.exe TROJ/BANCOS-DM! Note: This trojan file is found in the Windows or Winnt folder X Service Registry NT Save regeditnt.exe TROJ/BANCOS-BM TROJAN! X Service Registry NT Save taskmgrnt.exe TROJ/BANCOS-BY TROJAN! X Service Scheduler scheduler.exe W32/AGOBOT-PH WORM! X Service System kernels32.exe TROJ/BANCOS-DA TROJAN! X service updaer qualityz.exe "Unidentified worm, probably a W32.SpyBot variant" X Service.exe Service.exe """servedby.advertising"" popup generator" X service32 service32.exe W32/AGOBOT-ST WORM! U ServiceConfig ispbeg.exe "Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation" X serviceconnect serviceconnect.exe AGOBOT.AIR WORM! Y ServiceLayer ServiceLayer.exe Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly. X services ?? Troj/Gpcode-B TROJAN! X Services ?? unidentified VIRUS! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe X Services csrss.exe variant of the BACKDOOR.RANKY.U TROJAN! X Services kirby.exe Proxy-Agent trojan variant X Services mshost.exe TROJ/LANFILT-J TROJAN! X Services scks32.exe Proxy_Trojan variant X Services services.exe "W32.MYDOOM.BB WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X services socks.exe WIN32.SMALL.N Proxy TROJAN! - A PT is a backdoor trojan which allows a remote hacker to connect to other systems via the compromised system. X Services sockys32.exe WIN32.RANKY.L Proxy_Trojan X services start.bat ZCREW VIRUS! X services Svchosts.exe SDBOT.N WORM! X Services sys.exe Proxy_Trojan variant X Services windns.exe variant of the WIN32.RBOT WORM! X services windows32.exe W32/FlyVB-C WORM! X Services winread.exe Unidentified trojan X Services Administrator localsvc.exe Troj/Dloader-NY Trojan! X Services Administrator netsvc.exe Troj/Dloader-NY Trojan! X Services Administrator spoolsvc.exe Troj/Dloader-NY Trojan! X Services Administrator svcadmin.exe Troj/Dloader-NY Trojan! X Services Administrator svcman.exe Troj/Dloader-NY Trojan! X Services Administrator svcrun.exe Troj/Dloader-NY Trojan! X Services Administrator tcpsvc.exe Troj/Dloader-NY Trojan! X Services Administrator websvc.exe Troj/Dloader-NY Trojan! X Services Controller lsassa.exe CIADOOR.122 VIRUS! X Services Controller services.exe "TROJ/CIADOOR-F TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Services Host Scchost.exe DONK VIRUS! Note - this is not the valid svchost.exe as described here X Services Host svchost32.exe W32/Agobot-TG WORM! Note: (svchost32.exe) is not the legitimate Windows Process. (Notice the 32 that's been added.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Services Logon services.exe "W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X Services Process services.exe unidentified spyware - recognized by Kaspersky antivirus as TrojanSpy.Win32.Small.x X Services Process smss.exe Troj/Small-EK Trojan! X Services Startup services.exe "W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X Services Startup svhost33.exe variant of the WIN32.RBOT WORM! X Services.dll smss.exe W32.Sober.L WORM! **Note: this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! X Services.dll smss.exe "W32/SOBER-L WORM! - NOTE - this file is placed in a %WinDir%\msagent\system folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Services.EXE services.exe KAZPING VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process X services.exe Services.exe "CIADOOR-F TROJAN! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!" X Services004 ?? BUGBROS VIRUS! X services32 mc-110-12-0000079.exe TrojanDownloader.Agent.rv TROJAN! X services32 mc-58-12-0000120.exe """Shorty"" adware component, also detected as the AGENT.FD TROJAN!" X services32 mc-58-12-0000140.exe """Shorty"" adware component, also detected as the AGENT.FD TROJAN!" X Services32 Startup win32dll.exe W32/SDBOT-XO WORM! X ServicesLog ccapp32.exe W32/Rbot-AMX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Servicing hostd.exe SDBOT.BUI WORM! X Servicio Local svhost.exe variant of the WIN32.RBOT WORM! X servics servics.exe Troj/Singu-J Trojan! N Serv-U serv-u32.exe FTP server X Serv-U wssdsu.exe MANIFEST VIRUS! U Session Client sescli.exe SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself! X Session Manager Subsystem smssa.exe W32/Rbot-AGS WORM! X SESync sed.exe Downloadware/SED adware downloader N SetDefPrt BrStDvPt.exe Used to set a Brother MFC printer/copier/scanner as the default printer after installation N setdefprt setdefprt.exe Used to set a Brother MFC printer/copier/scanner as the default printer after installation U SetecCertUtil Certutil.exe "Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV" X setFTPBack createsw.exe FTP_BMAIL VIRUS! N SetHook SetHook.exe "Fellowes Neato CD label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar""" N seticlient or SETI@home SETI@home.exe SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data N SetIcon SetIcon.exe "Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog" N SetiQueue Setiqu~1.exe Provides work unit buffering for Seti@Home clients - see here for more details N SetiSpy SetiSpy.exe "From the site - 'SETI Spy is a little program I wrote to ""spy"" on the progress and performance of the SETI@home client. I call it a ""spy"" because I tried to make it as unobtrusive as possible'" X SetPoint SetPoint.exe W32/RBOT-BWI WORM! X SETPOINT Logitech Inc KHALMNP.exe W32/RBOT-AAX WORM! X Setting sysweb.exe SDBOT.GEN WORM! X Setup experation svchost.exe "TOFGER-AW TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which is located in the System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X setupa runt32.exe TROJ/QQPASS-K TROJAN! N SetupICWDesktop icwconn1.exe "Appears to be the ""Internet Connection Wizard"" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway" X setupuser regedit.exe setupuser.log CoolWebSearch parasite related. X SetVrc setvrc.exe HUNTOCX VIRUS! X Sex Teris st01b.exe REPAD VIRUS! X Sexnow Sexnow.exe Dial/Senow-B premium rate porn dialer X Sexy_sg Sexy_sg.exe Premium rate adult content dialer X sf sf.exe SurfEnhance adware component X sfita sfita.exe Troj/Favadd-H TROJAN! also known as SurfEnhance adware component. N SFP vzSFPWin.EXE "Verizon Online Support Center, promps for online updates" U sfpc sfpc.exe "Spy4PC is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it." X SFtrb Service cftrb32.exe SOBIG.D VIRUS! U SfWinStartInfo sfWinStartupInfo.exe SFIRM32 Online Banking software U Sgecrypt Sgecrypt.exe "SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks""" U Sgeecview Ecview.exe "SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks""" N sginst sginst.exe eAcceleration Stop-Sign related; not recommended; see note U sgtray sgtray.exe "StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups" X shambl3r cnf.bat REMABL VIRUS! X shambl3r* shambl3r.exe REMABL VIRUS! where * is 2 to 11 X Shania Shania.vbs "SHANIA VIRUS! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." U Shareaza bindata.exe Shareaza P2P client related N Shareaza Shareaza.exe Shareaza P2P client X sharedprem sharedprem.exe MAKECALL VIRUS! N Share-to-Web Namespace Daemon hpgs2wnd.exe """HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites."" In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs" Y Sharing and Mapping Software DShmap.exe Intel AnyPoint internet sharing software N SharkEject AEJCT32.exe "Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required" N Shcenter chcenter.exe "IMSI HiJaak - ""the easiest way to convert, capture, and manage all your graphic files""" X SheduIer shch.exe TROJ/BDOOR-EB TROJAN! X SheduIer svchst.exe Premium rate adult content dialer X SheduIer svchst.exe TROJ/BDOOR-EB TROJAN! X SheduIer winagent.exe TROJ/BDOOR-EB TROJAN! X Sheduler nerocheck.exe WIN32.TACTSLAY.B TROJAN! X shell explorer.exe Trojan.Kakkeys Trojan! X Shell ibm00001.exe Troj/Torpig-C TROJAN! X Shell iexplore.exe W32/Kipis-U WORM! X Shell msmsgs.exe Zhopa TROJAN! X Shell Open32.exe Troj/Small-DL TROJAN! X Shell ray.exeTray.exe Homepage hijacker re-directing browsers to adult content websites X Shell Shell32.exe BADSECTOR TROJAN! X Shell sound_drive16.exe TROJ/BDOOR-GP TROJAN! X Shell svchost.exe Doyorg TROJAN! X Shell wmedia16.exe GOLDUN TROJAN! X Shell API32 svcnet.exe WIN32.TIBICK.C WORM! X Shell Extension spollsv.exe variant of the LOVGATE WORM! X Shell Monitor services32.exe variant of the WIN32.RBOT WORM! X Shell Tray Window ShellTraywnd.exe TROJ/STULTDOR-A TROJAN! X shell update shellexec.exe W32/Agobot-TH WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X shell32 ntldrt.exe W32/Jlok-A WORM! X Shell32 Shell32.vbs VBS.Scafene WORM! X ShellApi SHELLMSN.EXE NETDEV.B VIRUS! X Shellapi32 mcvsrte.exe "unidentified WORM! - Note, do do confuse with the McAfee SecurityCenter file of the same name described here" X Shellapi32 Shellapi32.exe NETDEVIL (or NERTE) VIRUS! X Shellapi32 svcnet.exe W32/TIBICK-C WORM! X ShellCommand ?? Troj/Remcon-A TROJAN! X ShellEx ShellEx.exe ANAKHA VIRUS! X ShellOS A+++.exe WIN32.VB.AV keylogger TROJAN! X Shellspl lsas.exe TROJ/YALER-A TROJAN! X Shellspl spools.exe PROXAGE-A TROJAN! X shellsystem shellsystem.exe UPCHAN TROJAN! X shhost shhost.exe BACKDOOR.WIN32.AGENT.CE TROJAN! N shicoxp shicoxp.exe Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer. X Shine Shine.exe HAPPYLOW or W32/Nishe-A VIRUS! X Shmgrate.exe ibot4.exe GASTER VIRUS! N shockmachinereminder SmReminder.exe "Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version" X Shockwave csrss.exe "SNDOG VIRUS! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" N Shockwave Init SWINIT.EXE Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs N ShortKeys 99 SHORTKEY.EXE ShortKeys from Insight Software Solutions - allows you to program keys with text strings X Showbehind SHOWBEHIND.EXE Advertisement display which can be stopped here X ShowFF ShowFF.exe Adware.FFToolBar adware toolbar. X ShowWnd ShowWnd.exe unidentified backdoor TROJAN! U SHPC32 SHPC32.exe Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled Y ShStatEXE SHSTAT.EXE "From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs" U Shutdownaware shutdownaware.exe Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system U ShutDownPro ShutDownPro.exe "ShutDownPro - shutdown, reboot, logoff your System with one mouse click" X si91e44b ?? LZIO.com adware downloader X Sicom Sicom.exe NETLIP VIRUS! U SideACT SideACT.exe SideACT organizer software X Sidebar Sidebar.exe Searchcentrix hijacker N SideWinderTrayV4 or SWTrayV4 SWTrayV4.exe MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs X SigXC SigX.exe "SigX is a ""dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more.""" N Simcast SimcastAlerts.exe Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say. U SimpLite-MSN SimpLite-MSN.exe Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service) X Singapore singapore.exe Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself X SiS Dns dnssvc.exe Troj/Dloader-UE TROJAN! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N SiS KHooker khooker.exe SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required U SiS Tray or sistray sistray.exe System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System U SiS Windows KeyHook keyhook.exe "SIS graphics cards related: ""Super VGA Keyboard Daemon"" - hooks into the keyboard processing chain in order to enable hotkey settings." Y SiS7012Utility SiSAudUt.exe SiS Corporation sound card driver N SiSAudio MP_S3.exe WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems U siscolor color.exe Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board U siService.exe siService.exe Spam Inspector - anti email spam software U SiSSWLED sisswled.exe System Tray utility for SiS 900 network cards X sistrai.exe sistrai.exe PROVA VIRUS! X sistray sistray.exe PROVA VIRUS! Note - this resides in C:\Windows\Command X Sistray32 remotehost.pif W32.Holcas.A WORM! X Sistray32 virus.exe Troj/Tometa-C TROJAN! X Sistray32 win.bat W32.Jumpred.A WORM! X sistry sistry.exe CEBE VIRUS! N SiSUSBRG SiSUSBrg.exe SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP X sixtysix sixtypopsix.exe MediaMotor/Popuppers adware downloader U SK51 SK51.EXE SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself! U SK60 SK60.EXE SaveKeys surveillance software. Uninstall this software unless you put it there yourself. U SK9910DM SK9910DM.EXE Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys U SKDAEMON SKDAEMON.EXE Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys? U skinkers skinkers.exe "Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's ""Desktop Ozzy"" and Arsenal's ""Desktop Wenger"" - see here" X sks-32 SKS32P~1.EXE SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address. Y SkyBlaster Scheduler SSFSch.exe For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system X skynetave.exe skynetave.exe SASSER.D VIRUS! X SkynetRevenge winlogon.scr W32.NETSKY.AA WORM! N Skype Skype.exe """Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes""" Y SkySurfer Management Service SmaServ.exe For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system X sl4 rules rbot32.exe W32/SDBOT-QC WORM! N SleepManager SleepMgr.exe "This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode" U SlickRun sr.exe """SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:\Program Files\Outlook Express\msimn.exe becomes MAIL""" X slide Iexplore.exe "GASLIDE VIRUS! Note - this is not the valid Internet Explorer file ""iexplore.exe""" N slimp3 SliMP3 Server.exe "Slimp3 Server - ""presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC""" N Slingshot SLINGS~1.EXE "Atomica Slingshot -?""reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more""" X slmss slmss.exe SeekSeek search hijacker related - as seen here X sload sload.exe "Win SynchroAd adware, also detected as TROJ/DLOADER-QG TROJAN!" X slvchost32 slvchost32.exe Unidentified worm or trojan X sm sa_exe.exe OLFEB.A TROJAN! X sm sf_exe.exe OLFEB.A TROJAN! X sm sm_exe.exe OLFEB.A TROJAN! X sm sr_exe.exe LUKUSPAM TROJAN! N Sm56acl sm56hlpr.exe Helper utility for Motorola based SM56 software modems - resides in the System Tray X sman ?? Unidentified adware N Smapp smtray.exe System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller N Smart Card Service ScardSvr.exe "For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly" U Smart Connect Monitor SCMon.exe Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio U Smart Connect Setup SCSetup.exe Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio N Smart Label O Server ssloserv.exe Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely N Smart Label RFViewer SSLFVIEW.EXE Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely N Smart Type Assistant sta.exe "Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer" U Smartalec pcaccel.exe Smartalec PC Accelerator - system optimization utility N SmartBarXP SmartBarXP.exe "SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few" N sMaRTcaPs SMARTC~1.EXE "sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys" U Smarthruengine QS.exe "Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers" U SmartPCXL pcaccel.exe Smartalec PC Accelerator - system optimization utility N SMax4 SMax4.exe System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel U SMax4PNP SMax4PNP.exe "SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments" X smcserv winsrv.exe W32/AGOBOT-OU WORM! Y SmcService smc.exe Sygate Personal Firewall N Smith Micro try smiptray.exe Smith Micro shared files. Comes with D-Link web cam N SmoothView SmoothView.exe "TOSHIBA Zooming Utility - allows ""automatic"" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe-Reader and also desktop icons." U SMS Application Launcher LAUNCH32.EXE Microsoft Systems Management Server - used to manage computers on a network remotely U SMS Client Service clisvc95.exe "When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)" X Sms System32 SmsSystem32.exe Unidentified malware U SMS Win9x Message Agent SMSMsg.exe This program assigns a user to a Systems Management Server site Y Smserial sm56hlpr.exe Motorola based modem driver N SMSI Loader SMLoader.exe Smith Micro HotFax - fax software X smsm smsm.exe Troj/Banker-CO Trojan! X smsrv smsrv.exe W32/Agobot-SX Worm! X smss ?? ALADINZ.F VIRUS! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! X SMSS SMSS.EXE Troj/Borobot-K TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X Smss ssms.exe RBOT.OP WORM! X smssLevel4 smss.exe "UNidentified malware - NOTE - this file is placed in a C:\Program Files\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4 folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SMSSS smsss.exe SDBOT.ZD WORM! X SMSSS Loader smsss.exe AGOBOT.MQ WORM! X SMSSU SMSSU.EXE "Hijacker, detected by Norton antivirus as Trojan.StartPage.O" X smsys Explorer.exe "CLICKER-C VIRUS! Note - the valid ""explorer.exe"" is located in C:\Windows or C:\Winnt whereas this one is located in a C:\Windows\Template or C:\Winnt\Template subdirectory" X smsys vi.exe Adult content dialler U Smt SMT.exe Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself! N SMToolbar SMToolbar.exe StartMake.com toolbar X SMTP32 Mailing Protocol smtp32.exe variant of the WIN32.RBOT WORM! X snapple snapple.exe W32/FORBOT-EG WORM! X snbupt snbupt.exe UpSpiralBar adware component X sncntr sncntr.exe Troj/Dluca-I TROJAN! X snd332 snd332.exe """B1ld0"" AIM WORM!" X Sndcompat Sndcompat.exe GEMA TROJAN! U SNDMon SNDMon.exe "Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the ""U"" recommendation" X SndPnpMix wauctlxp4.exe WIN32.MUDROP.N TROJAN! X Sndsaver Sndsaver.exe GEMA TROJAN! X SNInstall ?? "SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe" U Snippet SnippingTool.exe "The Snipping Tool (part of the Experience_Pack for Tablet PC) allows you to easily ""cut out"" anything on screen and share it with other people. The whole screen becomes an ""inkable"" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an e-mail message." X SNP Generic Host Process svchost.exe Troj/Zapchas-O TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. N Snsicon Snsicon.exe Launches a screensaver program from Second Nature X SNSS.EXE SNSS.EXE Dialer.Nunci premium dialer. X Soar Rwon.exe PurityScan/Clickspring adware X Social Security Agency rpcxsocsa.exe variant of the WIN32.RBOT WORM! X Sock32 sock32.exe SDBOT WORM! Y SoDA Startup SodaStartup.exe Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software N soffice SOFFICE.EXE Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory). X Soft Profile Inc ?? variant of the LOVGATE WORM! X softIce Update 32 wininits.exe W32/Rbot-ANB WORM! Note: This worm/trojan file is found in the Windows or Winnt folder. U SoftickPPP PPPGate.exe Softick_PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer. Y SOFTinst ?? For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out U SoftStuff Wallpaper Changer softstrt.exe AzureBay wallpaper changer X Software software.exe TROJ/CRABTON-B downloader TROJAN! Y Solo Sentry Solosent.exe Solo Antivirus U SoloSchedule Solocfg.exe Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis U SoloSysCheck Syscheck.exe "Solo_antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors." X somatic somatic.exe Searchcentrix hijacker N Sonic A3D Control vrtxctrl.exe Sound related options X Sonic RecordNow! smsc.exe variant of the W32/SDBOT WORM! N SoniqueQuickStart sqstart.exe Quickstart for Sonique audio player. Available via Start -> Programs X SOS SOS.exe PHILLIS VIRUS! N SOS SQL Database scm.exe SQL Server Service Control Manager. Available via Start -> Programs X Sound Loader sndloader.exe AGOBOT-BV WORM! X Sound services SOUND32.EXE AGOBOT.GG WORM! X Sound System WinSound1.exe unidentified worm or trojan infection X soundcontrl soundcontrl.exe GAOBOT.AFJ WORM! X sounddrv sndbdrv3104.exe CoolWebSearch parasite related. N soundman soundman.exe System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel X SOUNDMAN Microsoft Help soun.pif W32/RBOT-AIU WORM! U SoundMAX SMax4.exe System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel X SoundMAX SoundMAX.exe "W32/RIZON-A WORM! - NOTE - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards!" U SoundMAXPnP SMax4PNP.exe "SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments" X SoundMixer smvss.exe TROJ/DEDLER-G TROJAN! X Soundmx Soundmx.exe CoolWebSearch parasite related. X soundtask soundtask.exe AGOBOT.VQ WORM! X soundtask soundtask.exe AGOBOT-MD WORM X soundtasks soundtasks.exe Crypter.C trojan variant infection X soundtctrls soundtctrls.exe W32/Agobot-ZV WORM! X SoundView msdview32.exe trojan downloader X sounofts sounofts.exe W32/Agobot-ND WORM! X sountskmanager sountaskmgr unidentified WORM or TROJAN! N SourcePath gwreg.exe Used to update Gateway registry settings for System Restoration Kit and Web update programs X sp ?? "Malicious javascript annoyance that changes the default search engine in IE to one of many including ""topsearcher"". See here for more and a fix" X sp ?? Troj/Ablank-W and Troj/Ablank-Z TROJANS! X sp ?? "StartPage.M TROJAN, a CoolWebSearch parasite variant" X sp sp.reg IE search hijacker - changes the default search to http://www.gocybersearch.com/ U SP TimeSync SP TimeSync.exe SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server). X SP00LSV Sp00lsv.exe GRAYBIRD.E VIRUS! U SP2 Connection Patcher SP2ConnPatcher.exe Changes limit of concurrent TCP connections of Windows Service Pack 2. X SP2 data ?? variant of the RANDON.AN WORM! X SP2 Firewall/Internet Updater crssrs.exe RBOT.BJO WORM! X sp2chk.exe sp2chk.exe Aluroot.A TROJAN! X sp2ctr sp2ctr.exe Troj/Dluca-M trojan infection X sp2update sp2update.exe ADWARE! Adware.SP2Update Tracks URLs visited and search terms entered into Internet Explorer. X Spam Blocker for Outlook Express SBInst.exe HotBar related U Spam Sleuth SpamSleuth.exe Spam Sleuth E-mail spam detection program U SPAMfighter Agent SFAgent.exe SPAMfighter anti email spam filter U spamihilator spamihilator.exe Spamihilator spam filter U SpamPal spampal.exe SpamPal - anti-spam tool U SpamSubtract SpamSubtract.exe Intermute SpamSubtract - junk email detection and removal program N spc_w blspc.exe NetZero Search Enhancement related N spc_w hcm.exe NetZero Search Enhancement related N spc_w nzspc.exe NetZero Search Enhancement related N Spdstart Spdstart.exe "Norton Utilities Speed Start. ""This feature optimizes the start up speed of launching applications, such as Word and Excel.""" U Speaking Clock Deluxe SpClDlx.exe "Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly" X Special Firewall Service avguard.exe W32.NETSKY.G WORM! X SpecialOffers ?? SpecialOffers adware X SpecialOffers SpecialOffers.exe SpecialOffers adware X specific specixic.exe variant of the W32/SDBOT WORM! N Speed racer CTSRReg.exe Software for a Creative sound card U Speed Tec speedtec.exe Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled X SpeedBoss ?? OPASERV.AD VIRUS! U Speedkey SPEEDKEY.EXE Additional keyboard shortcuts on MS programmable keyboard U SpeedMeter SpeedMeter.exe Application measuring upload and download speed U SpeedOptimizer spo.exe "SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication." U SpeedswitchXP SpeedswitchXP.exe SpeedswitchXP is a CPU frequency control for notebooks running Windows XP U Speedtouch USB Diagnostics Dragdiag.exe For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an \'at-a-glance\' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line) U SpeedUpMyPC SpeedUpMyPC.exe "SpeedUpMyPC ""automatically fine-tunes all your resources including hardware, system settings and internet usage to operate at peak performance at all times.""" X Spees1 speedy.scr OPASERV.Y VIRUS! X Spees2 Speedy.bat OPASERV.AD VIRUS! X Spees3 SPEEDY.PIF OPASERV.AD VIRUS! N Spellex Anywhere sa.exe Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used Y SpIDerMail spiderml.exe DrWeb antivirus Spider Mail e-mail scanner N Spinner Plus spinner.exe """Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness"". Available via Start -> Programs" X SPINX OXNEY.B.VBS VBS.YENO.C WORM! X SPnt SPnt.exe Premium rate adult material dialer U SpokeSysTray SpokeSysTray.exe "Spoke_Software client application. Spoke ""uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry.""" X spolsvr2 spolsvr2.exe "Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X spoo1sv spoo1sv.exe SOULJET VIRUS! X Spool ?? RANKY.R TROJAN! X Spool msvc.exe RANKY.R TROJAN! X Spool wys.exe WhileUSurf adware component X SPOOL Configuration spoolsvc.exe W32/Sdbot-KD worm X Spool Loader spool.exe variant of the WIN32.RBOT WORM! X Spool LoadKIt spoolv.exe variant of the WIN32.RBOT WORM! X Spool lptt01 or Spool ml097e spool.exe "Variant of the RapidBlaster parasite (in a ""spool"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Spool Server Daemon SPOOLSVD32.EXE Win32.Rbot worm variant X Spool32 pool32.exe ASSASIN-F TROJAN! X spoolax ?? Troj/Perda-D TROJAN! X Spooler Service Spoolsrv.exe JOINER.C1 VIRUS! X Spooler Sub System Process SPOOL32.EXE YAB.A VIRUS! X Spooler Subsystem spoolsub.exe W32/SDBOT-ABG TROJAN! X Spooler SubSystem App spooIsv.exe W32.LINKBOT.M WORM! X Spooler SubSystem App spoolsvc.exe W32/POEBOT-J WORM! Note: Spoolsvc.exe is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (spoolsv.exe) should not be seen in Msconfig or as a Startup item...Also search for fccj.bat if found this is the W32/Poebot-M variant. X Spooler SubSystem Application localsvc.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application netsvc.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application spoolsvc.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application svcadmin.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application svcman.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application svcrun.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application tcpsvc.exe Troj/Dloader-NY Trojan! X Spooler SubSystem Application websvc.exe Troj/Dloader-NY Trojan! X Spooler Subsytem App spoolsvc.exe TROJ/SDBOT-MM WORM! X SpoolerSubSystemProcess SpooI32.exe "SPY.EHKS.21 VIRUS! Note - the ""I"" between ""o"" and ""3"" is a captial ""i"" not a lower case ""L""" X Spools Service Controller spools.exe W32/KASSBOT-C and W32/Kassbot-E WORMS ! X spoolserv spoolserv.exe W32/Sdbot-PN worm infection X SpoolService spolsv.exe W32/AGOBOT-CS WORM! X spoolsv scvhosts.exe TROJ/SMALL-AW TROJAN! X Spoolsv Spoolsv.exe "CIADOOR.121 VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file" X spoolsv manager SpoolMgr.exe W32.Assiral WORM! X spoolsv service spoolsv32.exe W32/RBOT-AHP WORM! X SPOOLSV32 SPOOLSV32.EXE TROJ/CWS-I TROJAN! X spoolsvc spoolsvc.exe TROJ/DROPPER-AT TROJAN! X spoolsvr32 csmss.exe AGENT-AU TROJAN! X spoolsvr32 csmss32.exe variant of the AGENT-AU TROJAN! X spoolsvs.exe spoolsvs.exe Troj/Dloader-RK TROJAN! X SPOOLSVU SPOOLSVU.EXE StartPage.K TROJAN! X spoolsvv spoolsvv.exe Searchcentrix hijacker X Spoolvs spoolvs.exe SDBOT.AUS WORM! X Spore MsNews.vbs VBS.SORPE.A WORM! X Spore.b Scmhlpr.vbs VBS.SORPE.B WORM! X spp ?? IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ U SPSTEALT SmartProtectorPro.exe "Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc" U Spy Blocker spyblocker.exe "SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all" X SpyBan SpyBan.exe """Spyware remover"" of dubious repute - see this list of non-Recommended anti parasite software" X SpyBlast SpyBlast.exe "Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others" U SpyBlocker spyblocker.exe "SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all" X SpyBlocs GLFF.exe Rogue anti-spyware program. X SpyBlocs SpyBlocs.exe Rogue anti-spyware program. X SpyBlocs3.0 SpyBlocs3.0.exe Rogue anti-spyware program. U SpybotSD TeaTimer TeaTimer.exe "Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla. TeaTimer.exe monitors certain changes to the registry and notifies when browser plugins and activeX controls get installed, allowing you to block/reverse this." U SpyBotSnD Spybotsd.exe Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla X Spybott lptt01 or Spybott ml097e spybott.exe "Variant of the RapidBlaster parasite (in a ""Spybott"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Spy-Control Spy-Control.exe """Spyware remover"" of dubious repute - see this list of non-recommended anti parasite software" U SpyCop ScanCheck MAIN.EXE SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan X SpyEx Winllogo.exe W32/PrsKey-A WORM! N SpyHunter Spyhunter.exe SpyHunter - spyware remover of somewhat dubious repute; see note U Spy-Keylogger skl.exe SpyKeylogger is a security risk that records keystrokes. If you didn't install it yourself remove it. U Spykiller Spykiller.exe "Shareware ""Spyware remover"" of questionable quality and repute. There are better alternatives that are freeware to boot. See this page on Rogue/Suspect Anti-Spyware Products & Web Sites" X SpyNuker Spynuker.exe "A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ±TrekData? and ±Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages" X SpySheriff SpySheriff.exe SpySheriff malware N SpySpotter SpySpotter.exe """Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" U SpyStopper spystopper.exe "SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked" U SpySubtract SpySub.exe SpySubtract - multi spyware removal tool U SpySweeper SpySweeper.exe Spy Sweeper - detects and removes spyware X SpyTrooper SpyTrooper.exe "SpyTrooper, malware, posing as a spyware remover - alse see here" X Spyware Spyware.exe "BPS Spyware Remover - reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!" N Spyware Begone freescan.exe Spyware BeGone - free spyware removal utility; not recommended; see note N Spyware Begone SpywareBegone.exe Spyware BeGone - free spyware removal utility; not recommended; see note U Spyware Doctor spydoctor.exe Spyware_Doctor spyware remover U Spyware Doctor swdoctor.exe Spyware_Doctor spyware remover U Spyware Guard Control Panel spywar~1.exe """SpywareGuard provides a real-time protection solution against spyware""" X Spyware Nuker swn2.exe "A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ±TrekData? and ±Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages" X Spyware Nuker Installer SpywareNukerInstaller.exe "A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ±TrekData? and ±Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages" X Spyware remover Remove_spyware.exe "Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related!" N Spyware Scanner AseScanner.exe "Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here" U SpyWare Shield Shield.exe Acronis Privacy Expert Spyware_Shield prevents spyware and other suspicious programs from being installed on desktop PCs and laptops. X Spyware Slayer SpywareSlayer.Exe """Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" N Spyware Stormer SpywareStormer.Exe SpywareStormer spyware remover; not recommended: see here X Spyware Vanisher FreeScanner.exe """Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" U Spyware X-terminator SpywareX.exe Spyware_X-terminator spyware remover X Spyware-Cop Spyware-Cop.exe "Spyware-Cop alias SpywareKilla - ""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites" X SpywareGuard deinst_qfe001.exe variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application as described here U SpywareGuard sgmain.exe """SpywareGuard provides a real-time protection solution against spyware""" X Spywareguard lptt01 or Spywareguard ml097e Spywareguard.exe "Variant of the RapidBlaster parasite (in a ""Spyguard"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X SpywareGuardPlus winmm64.exe """Trojan.Win32.StartPage.ht"" homepage hijacker" N SpywareKilla SpywareKilla.exe "Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on ""Rogue/Suspect Anti-Spyware Products & Web Sites""" X SpywareNo SpywareNo.exe "Bogus ""Spyware remover"" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites" U SPYWATCH SpyWatch.exe "BPS Spyware Remover - reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!" X SQConfigChecker cc.exe Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants X SQInstaller SQInstaller.exe Xupiter hijacker N SQL Server scm.exe SQL Server Service Control Manager. Available via Start -> Programs X SQL Server Service sql.exe W32/Rbot-ADF X sqservices wins32.exe Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder. X SQUpdatesChecker uc.exe Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants X sqvynikp sqvynikp.exe Free_Scratch_Cards foistware X sr64 ?? "Adware, as yet unidentified" X SrchfstUpdate srchupdt.exe SearchFast adware downloader X sre ?? "CoolWebSearch parasite variant, also detected by Kaspersky antivirus as Trojan.Downloader.Agent.Fc" U Srmclean srmclean.exe "Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - ""If you disable the entry from loading into startup, then you will not be able to use the features of the sound card""" X SRNG srng.exe Search hijacker - see here U SRP Startup srrpro.exe "System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium ""features."" This is enabled if you tick the ""Remove unnecessary System Restore information on startup"" box. Available via Start -> Settings -> Control Panel" Y SRS Applet SrsTray.Exe S3 Sonic Vibes sound card drivers - if disabled you loose sound X Srv RPCrom NClienti386.exe W32.Watsoon.A TROJAN! X Srv32 Srv32.exe OPASERV.J VIRUS! X Srv32 Srv32.exe OPASERV.S VIRUS! X srv32 srv32.exe W32/AGOBOT-AMI WORM! X Srv32 spool service runsrv32.exe "Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b" X Srv32 spool service spoolsrv32.exe SPYRE.B and Troj/Dloader-ON TROJANS! X Srv325 Srv325.exe W32/AGOBOT-PR WORM! X Srv32Old ?? OPASERV.J VIRUS! where is the original worm name U Srv32Win SpyAgent4.exe "SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it" U Srv32Win Svchost.exe "Realtime-Spy keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn\'t treat it as ""X"" and uninstall or remove" U Srv32Win sysdiag.exe NetVizor surveillance software - uninstall this software unless you put it there yourself! U srv32win win16dll.exe "Screenspy captures screenshots silently. If you didn't install this yourself, remove it." X Srvce Pack Updte svcpack.exe variant of the WIN32.RBOT WORM! X srvexc.exe srvexc.exe BACKDOOR.SERVSAX TROJAN! U srvprc srvprc.exe Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself. X ssate.exe irun4.exe BEAGLE.J WORM! X ssate.exe winsys.exe BEAGLE.K WORM! N SSBkgdUpdate SSBkgdupdate.exe ScanSoft OmniPage auto updater. Can be disabled using the main program's options. U SSC Service Utility ssc_serv.exe SSC Service Utility is a printer utility for refilled Epson cartridges U SSCFBTN.EXE SSCFBTN.EXE "Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers" Y Ssd Std.exe Stealthdisk - file and folder hiding/locking utility N SSDPSRV ssdpsrv.exe "Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play" X ssgrate.exe irun.exe MITGLIEDER.D VIRUS! X ssgrate.exe irun4.exe MITGLIEDER.F VIRUS! X ssgrate.exe sysdoor.exe Trojan.Mitglieder.N X ssgrate.exe system.exe MITGLIEDER.C VIRUS! X ssgrate.exe winerdir.exe MITGLIEDER.O VIRUS! X ssgrate.exe winsystems.exe TROJ/BAGLEDL-J TROJAN! X ssgrate.exe wintems.exe Trojan.Mitglieder.Q Trojan! U SSh32 SSh32.exe 2Spy keystroke logger/monitoring program - remove unless you installed it yourself! X SSK Service winssk32.exe SOBIG.E VIRUS! X SSL svchost.exe unidentified VIRUS! U ssmmgr ssmmgr.exe "Samsung printer monitor - for checking ink levels, etc." X ssms.exe SSMS.EXE W32.GISMOR WORM! U SSPY SSYTEM.EXE SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself! X sssasasb32 sssasasb32.exe WIN32.TACTSLAY.F TROJAN! X sstata dwdas.exe Dasda trojan X SStb.exe SStb.exe "Adpowerzone.com ""ServerSide"" keyword hijacker" N sstray sstray.exe "nVidia nForce Taskbar Utility - quick access to the nForce2 ""Sound Storm"" control panel and related utilitys" X SSUpdate SSUpdate.exe DyFuCa/MoneyTree parasite variant X ssvchost ssvchost.exe HELIOS.B VIRUS! X SSWPlauncher ?? CometCursor by Comet Systems N Stacmon Stacmon.exe Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects U StarSkin starskin.exe StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes. Y Start Quick95.exe For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone X Start windows.vbs Homepage hijacker X start extracting spoolvs.exe RBOT.AKC WORM! X start extracting spoolvse.exe W32/RBOT-XF WORM! N Start Getright getright.exe See Getright Tray Icon X Start It Upping svchosets.exe variant of the WIN32.RBOT WORM! X Start Page http://find.naupoint.com Naupoint browser hijacker X Start Page svcnt32.exe "Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks" Y Start RF Wireless Keyboard ktrexe.exe Yuanxun Electronics RF wireless keyboard driver Y Start RF Wireless Mouse cm20.exe Yuanxun Electronics RF wireless mouse driver U Start Service upssrv.exe "Cyber Power PowerPanelPlus software. ""In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner.""" U Start Up Cop startcop.exe StartUp Cop - startup manager X start uploading smsss.exe variant of the W32/SDBOT WORM! X Start Upping mcrt32.exe variant of the W32.SPYBOT WORM! X Start Upping SVCHOSTES.EXE W32/RBOT-NB WORM! X Start Upping taksmgr.exe W32/RBOT-QK WORM! X Start Upping taskmrg.exe W32/Rbot-MA worm infection X Start Upping windupds.exe SDBOT.AFH WORM! X Start Upping windupdts.exe variant of the WIN32.RBOT WORM! X Start Upping xdcc.exe SPYBOT.OY WORM! X Start Uppings mssupdate.exe variant of the WIN32.RBOT WORM! X Start Uppings svcchosts.exe SDBOT.VY WORM! N Start Wingman Profiler "lwtest.exe, lwemon.exe" "Logitech Wingman software required to operate Logitech joysticks and gamepads.? Unless you're a hard-core gamer, it's best to leave it unchecked" U Startacc startacc.exe "Launches Webroot\'s Accelerate 2000 software that ""speeds up your Internet connection by up to 300%"". Leave enabled if you find it improves internet connection" U StartEAK cpqeadm.exe Easy_Access Button Support for Compaq PCs. Required if you use these Y StartEAK StartEAK.exe Easy Access Button Support for Compaq PCs. Required if you use these X Starter scvhosting.exe WORM_SDBOT.RU X starter scvhostingg.exe W32/FORBOT-FB WORM! X Starting up wvsvc.exe RBOT.QQ worm infection N startl.exe startl.exe Lingocom LingoWare - translates any application into your language X StartMenu deamon.exe WIN32.TACTSLAY.C TROJAN! X StartMenu msgaol.exe WIN32.TACTSLAY.C TROJAN! X StartMenu s_menu.exe WIN32.TACTSLAY.C TROJAN! U STARTPAGE start1.exe NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder. X startpage startpage.exe Browser hijacker - redirecting to pages2start.com U StartStop STARTSTOP.EXE StartStop from TFI Technology - startup manager U StartSurfing STARTS.exe "Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a ""filter"" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs" N Startup ?? Related to an Iomega drive X Startup WinlogonStartup Unidentified malware U Startup Manager Scanner StartupMonitor.exe "Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware." X Startup Update Cvshost.exe GAOBOT.AO WORM! X StartupBin iwnujdss.exe W32/SDBOT-XZ WORM! U StartupMonitor StartupMonitor.exe "Mike Lin\'s StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu" X startwin startwin.exe W32.ANTIMAN.A WORM! X startwindowskeyuser rundle2.exe JAVAKILLER VIRUS! N Stat 'n' Perf StatnPerf.exe Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes X StatBar STATBAR.exe "StatBar?(system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me" X State Service csrss.exe "TROJ/DADOBRA-CP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" N Status Monitor BrMfcWnd.exe Brother scanner status monitor - can be started manually N Status Monitor XE ENGSS.EXE The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs N Stay Connected! StayCon.exe "More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs" U StayAlive sa.exe "StayAlive from TFI Technology.?""This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work.""" N STBWEBTV STBWEBTV.EXE Used to display TV on your PC X stcinstaller id53.exe Add as a result of TROJ_SCTHOUGHT.L TROJAN! X stcloader stcloader.exe Popup adware by 2ndThought software Y STCPO STCPO.exe Sophos Sweep antivirus software X stdlib ?? TROJ/PERDA-E TROJAN! Y STDSB STDSB.exe "Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling." U Stealth Anonymizer 2.5 stealth25.exe Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy N Steam steam.exe "Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game. Can be started mnaually." X steam steam.exe W32/Rbot-AJT WORM! Note: The file steam.exe will be found in the Windows System folder. N Stickies STICKIES.EXE "Stickies - utility that allows you to put yellow ""Post-It"" type messages on your desktop and can be used to set reminders. Available via Start -> Programs" N Sticky Notes stikynot.exe Microsoft Sticky Notes - virtual sticky notes tool N StickyNote StickyNote.exe "Utility that allows you to put yellow ""Post-It"" type messages on your desktop. Available via Start -> Programs" U StillImageMonitor Stimon.exe "Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners" X stisrv stisrv.exe RBOT.BQF WORM! X stlbdist ?? Hijacker pointing to www.searchandclick.com X stlbupdt ?? BrowserAid/Startium parasite X stmha wkfxi.js JS.SPETH WORM! N StopSignStatus "stopsinfo.dll"",VerifyStatus" eAcceleration Stop-Sign related; not recommended; see note U STOPzilla Stopzilla.exe STOPzilla popup blocker U STOPzilla Service SZNTSVC.EXE STOPzilla popup blocker U StorageGuard sgtray.exe "StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups?" X Stratas ggfig.exe OPANKI.W WORM! X stratas lockx.exe W32/SDBOT-ADD WORM! X stratas xmconfig.exe W32/Rbot-AHR WORM! U StreamZap Remote zremote.exe "StreamZap_PC_Remote - Control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applications" U StrgSync.exe StrgSync.exe "SimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders." X strmsnmsgr msnmsgrs.exe W32/RBOT-ACQ WORM! X strmsnmsgrs msnmsgrsc.exe variant of the WIN32.RBOT WORM! X strmsnnms msnmegrs.exe Troj/Sdbot-YU TROJAN! X strmsnnrs msnmcgrs.exe TROJ/RBOT-ACT TROJAN! X strmsoums msnmegrse.exe Troj/Sdbot-ZK Trojan! X Strng32 strngbox.exe STRANO VIRUS! X strto strto.exe TROJ/KILLPROC-F or KillProc-G TROJAN! Note: File name may be different. X Sts iwnujdss2.exe W32/SDBOT-YI WORM! X Stubbish Stubbish.exe W32/STUBBOT-A WORM! X StubPath Sservice.exe PRORAT VIRUS! X stxrmsgms mstats.exe TROJ/IRCBOT-AE TROJAN! U StyleXP StyleXP.exe "StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it" X SubAH SubAH.exe SubAH backdoor TROJAN! N Subtract the Ads AdSub.exe Removes adverts from web pages. Although useful - not required X suck l0ad.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" U Suitcase Startup Suitcase.exe Suitcase . System font manager start up utility. Used for dynamic managment of fonts on your system. X Suite SuiteOffices.exe /cleandb Lazar TROJAN! X SULFNBJ.EXE SULFNBJ.EXE "Left as the result of being infected by the PE_MAGISTR.DAM virus. This virus infects system files and renames them (changing one letter) before adding them to the Run keys in the registry. Once the virus is removed via anti-virus software, delete the infected file and remove the key from the registry" U sunasDTServ sunasDTServ.exe SunBelt CounterSpy spyware detection and removal software U sunasServ sunasServ.exe SunBelt CounterSpy spyware detection and removal software X SunJavaSched ccEvtMngr.exe W32/Sdbot-YP Worm! X SunJavaSched Updater avamx.exe W32/RBOT-ABJ WORM! X SunJavaUpdate smvss.exe TROJ/DEDLER-G TROJAN! X SunJavaUpdateSched javamx.exe W32/SDBOT-WI WORM! N SunJavaUpdateSched jusched.exe Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel X SunJavaUpdateSched scvhost.exe W32/SDBOT-AVX WORM! U Sunkist shwicon98.exe "Card reader for memory cards from digital cameras, etc" U Sunkist2k shwicon2k.exe "Card reader for memory cards from digital cameras, etc" U SunKistEM shwiconem.exe Used by your computer to communicate with your Alcor_Micro Multimedia Card Reader - necessary if you're using this software U SuNotification suatshut.exe "ShadowSurfer - ""provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode? system state no matter what changes have occurred to your PC.""" U SunProtectionServer SunProtectionServer.exe CounterSpy antispyware software U SunServer SunServer.exe CounterSpy antispyware software N Supastatus status.exe Supanet ISP software X super fuckbx.exe LINEAGE-H TROJAN! X super super.exe W32/AGOBOT-QT WORM! U Super Popup Blocker popkill.exe Saga Super Popup Blocker - pop-up stopper U SuperAdBlocker SAdBlock.exe SuperAdBlocker X SuperBar.Component services.exe "FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetsrv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" U Supercleaner Supercleaner.exe Supercleaner - all in one disk cleaner for your computer U SuperCool Compress Backup Main.exe """SuperCool Zip Backup software is a data backup,restore and file synchronization program""" X SuperHeissSex SuperHeissSex.exe HeissSex premium rate adult content dialer! X supernews12 newsd32.exe "Adware, also detected as the TROJ/DLOADER-JN TROJAN!" X Supernova ?? SURNOVA (or SUPOVA) VIRUS! .exe is the chosen name X superslut msslut32.exe SLUTER-A VIRUS! U SuperSpamKiller Pro Ssk.exe SuperSpamKiller_Pro email spam blocker X supporter5 supporter5.exe Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead X support-reverse-smileys ?? Backdoor.IRC.Litebot TROJAN! U SureCleanProfessional SRClean.exe SureClean PC and Internet tracks cleaner U Sureshotpopupkiller pusak.exe Stop-the-Pop-Up popup blocker U Sureshotpopupkiller Stopthepop.exe Stop-the-Pop-Up popup blocker X SurfAccuracy sacc.exe SurfAccuracy adware X SurfBuddy ?? SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps! U SurfChoice SCMan.exe "SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa" X Surfer lptt01 or Surfer ml097e surfer.exe "Variant of the RapidBlaster parasite (in a ""mssurfer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" U SurfinGuard Pro winsfcm.exe SurfinGuard Pro - internet protection software U SurfSecret ss2-full.exe """House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache""" X SurfSideKick 2 Ssk.exe SurfSideKick adware X SurfSideKick 3 Ssk.exe SurfSideKick adware U SurfStream SurfStream.exe "Conceiva ""SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings.""" X Surs awab.exe PurityScan/Clickspring adware X Susp Susp.exe Transponder parasite updater/installer X Sustem explorer.exe Undentified VIRUS! X SustemUpdate explorer.exe Undentified VIRUS! X SV00LSV SV00LSV.EXE GRAYBIRD-C TROJAN! X SVA Player SVAplayer.exe QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it X Svc svc.exe "Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND VIRUS!" U SVC svchost.exe "ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! - this file should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SVC Service svcinit.exe SINIT VIRUS! X SVC Service svcinit.exe CoolWebSearch parasite related. X SVC Service svcpack.exe CoolWebSearch parasite related. X SVC Socks mstaskm.exe CoolWebSearch parasite related. X Svced Svced.exe DELF.F VIRUS! X SvcH0st msexploren.exe BackDoor-CGZ trojan infection! X SvcH0st SHCH.EXE TROJ/BDOOR-EB TROJAN! X SVCH0ST spoo1sv.exe Troj/VB-HF TROJAN! X SVCH0ST SVCH0ST.EXE "Troj/VB-IK TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X SvcH0st SVCHST.EXE TROJ/BDOOR-EB TROJAN! X SvcH0st WINAGENT.EXE TROJ/BDOOR-EB TROJAN! X svchost ?? HAZZER VIRUS!. This is not the valid svchost.exe as described here X svchost ?? SETCLO WORM! X svchost ADMAGIC.EXE SMIBAG VIRUS!. This is not the valid svchost.exe as described here X SVCHOST mrowyekdc.exe GOTORM VIRUS!. This is not the valid svchost.exe as described here X svchost olehelp.exe Olehelp adware component X SVCHOST scvhost.exe W32.Mytob.E or W32.Mytob.G WORM! X SVCHOST SPOOLSV.EXE W32/Baitap-A WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the Windows or Winnt folder. X SVCHOST SVCH0ST.EXE "Troj/MMThief-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X Svchost svchosl.pif W32.INZAE.A WORM! X SVCHOST svchost.exe System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the valid svchost.exe as described here X svchost svchost.exe "MORB or TARNO VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32" X Svchost svchost.exe W32/Moze-A worm infection X svchost svchost.exe /nosplash Troj/Bancban-DH TROJAN! X SVCHOST taskgmr.exe W32.Mytob.F WORM! X SVCHOST taskmgr.exe W32.Mytob.H WORM! X SVCHOST updater32.exe W32.RANTS.A WORM! X SVCHOST var.txt.exe PWSteal.Ldpinch.C trojan infection. X Svchost winhost.exe LOLAWEB.A VIRUS!. This is not the valid svchost.exe as described here X SVCHOST Generic application svchost.exe "TROJ/DAEMONI-K TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SVCHOST.EXE SVCHOST.EXE "TROJ/WRMSCAN-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X svchost.exe svchost.exe Troj/PWSjx-A TROJAN! X svchost.exe svchost32.exe CoolWebSearch parasite related. X svchost1 svchost1.exe AGOBOT.ZZ WORM! X SvcHost32 svchost32.exe W32.MIMAIL.I or W32.MIMAIL.J WORM! X svchost64 svchost64.exe SDBOTER.G WORM! X svchosta svchosta.exe TROJ/SNIFFER-I TROJAN! X svchostb svchostb.exe TROJ/SNIFFER-J TROJAN! X SvcHosto v1rg1n.exe W32/Agobot-TK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X svchostr svchostr.exe unidentified WORM or TROJAN! X svchosts svchosts.exe Troj/Bancban-DC or the Troj/Banker-ED TROJANS! X svchosts.exe svchosts.exe W32/AGOBOT-JN WORM! X svchosts.scr svchosts.scr Troj/Bancban-DQ TROJAN! X svcinfo svcinfo.exe CRYPTER.A trojan infection X Svclhost svcchost.exe unidentified WORM or TROJAN! U svcmon svcmon.exe Spyware.PersonInspect surveillance software. Remove unless you installed it yourself! X svcroot svcroot.exe TROJ/KEYLOG-AC TROJAN! X SvcSys ?? PWSTEAL.BANCOS.Z TROJAN! X Svcsys Registry Manager svcsysreg.exe TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.cv X svctask svctask.exe Troj/Chuckyb-A TROJAN! X svcwinprocess32 ?? UPERING VIRUS! X SVHOST SVCHOST.EXE W32.Zori.A VIRUS! X SVHOST svhost.exe W32.Mydoom.I WORM! X Svhost Loader svshost.exe AGOBOT.G WORM! X svhost updates Svhost.exe variant of the WIN32.RBOT WORM! X svhost windows services svhost8.exe W32/RBOT-WQ WORM! X sVideo2 vxdrun6.exe """Switch"" premium rate adult content dialer" X sviload32 sviload32.exe W32/RBOT-AAS WORM! X svnlitup32 svnlitup32.exe RBOT.CBJ WORM! X svnloader svnload32.exe W32/RBOT-ACU WORM! X svphost.exe svphost.exe TROJ_AGENT.CS TROJAN! X svrrun svrrun.exe adware hailing from Deskwizz.com X svsekin svsekt.exe TROJAN.PWS.QQPASS.G TROJAN! X svshost messenger.exe TROJ/LOONY-G TROJAN! X svshost svshost.exe W32/CHODE-H WORM! X svshost32 msgrsv32.exe WIN32.RANKY.AJ TROJAN! X svshost32 svshost32.exe variant of the W32/SDBOT WORM! X svshostdriver svshost.exe TROJ/SDBOT-HN TROJAN! X svwin32 unninst32.exe W32/AGOBOT-NF WORM! X SVX Control Service svxhost.exe W32/Rbot-K WORM! N Swap Nut javaw.exe "SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network" X SWCaller SWcaller.exe Homepage hijacker - see here X SWCaller Swcaller2.exe Homepage hijacker - see here U SWClient swsys.exe ActivMonAgent Keyboard logger/monitoring program - remove unless you installed it yourself! X swcroot swcroot.exe Unidentified adware X swcroot swcroot.exe Troj/Soleno-A TROJAN! N SWd winwd.exe "PC Security from Tropical Software - lock files, password protect, etc" Y Sweep95 ICLOAD95.EXE Part of Sophos ant-virus sofware X Swf32 _backup.exe SYMTEN VIRUS! X Swf32 AVupdate.exe MERKUR VIRUS! Y swift sweeper sweeper.exe "Foxie Swift Sweeper - Part of Foxie Security, Privacy and Productivity Suite" X SwimSuitNetwork SwimSuitNetwork.exe Advertising spyware X swingsys SWINGSYS.EXE Troj/Bancos-CX Trojan! U Switch Off swoff.exe "Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc" N Switchboard.com Toolbar AtHoc.exe Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com X switp switpa.exe OfferAgent adware component U SWL ?? Stealth.Weblog surveillance software. Uninstall this software unless you put it there yourself. X sws.exe ?? Haldex type adult content dialler X sws.exe gd-dial.exe "Component of the ""GlobalDialer"" adult content premium rate dialer" X sws.exe svchost.exe "GlobalDialer premium rate adult content dialer. The file is located in a GlobalDialer or HaldexLtd folder in Program Files - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" N SwTray SWTRAY.EXE MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it X sxrrv sxrrv.pif Troj/Vax-A TROJAN! X SyBot v2.1 By Sky-Dancer HPSV.exe ZOTOB.I WORM! X SYDNEY ?? SYNEY VIRUS! X Sygate Personal 3 svrv.exe W32/RBOT-XD WORM! X Sygate Personal Block Studio.exe W32/RBOT-TW WORM! X Sygate Personal Firewall explorer1.exe variant of the W32/SDBOT WORM! X Sygate Personal Firewall host32.exe W32/RBOT.ALD WORM! X Sygate Personal Firewall hostserv.exe RBOT.BKO WORM! X Sygate Personal Firewall Mcafeeupdate.exe RBOT.YN WORM! X Sygate Personal Firewall msnmsgrs.exe RBOT.XN WORM! X Sygate Personal Firewall MSNSRV32.exe variant of the WIN32.RBOT WORM! X Sygate Personal Firewall service.exe variant of the WIN32.RBOT WORM! X Sygate Personal Firewall sexy.exe W32/RBOT-XY WORM! X Sygate Personal Firewall spoolsrv.exe W32.SpyBot worm variant X Sygate Personal Firewall Sygat.exe variant of the WIN32.RBOT WORM! X Sygate Personal Firewall Sygate.exe W32/RBOT-PN WORM! X Sygate Personal Firewall Sygate32.exe SDBOT.WW WORM! X Sygate Personal Firewall sys.exe W32/RBOT-ZC WORM! X Sygate Personal Firewall syserror.exe RBOT.UC WORM! X Sygate Personal Firewall sysgut.exe SDBOT.WM WORM! X Sygate Personal Firewall system32.exe RBOT.VI WORM! X Sygate Personal Firewall t1ktik.exe W32/RBOT-VP WORM! X Sygate Personal Firewall Win32x.exe W32/Rbot-KZ worm infection X Sygate Personal Firewall wins.exe RBOT.AOB WORM! X Sygate Personal Firewall winxpstat.exe variant of the WIN32.RBOT WORM! X Sygate Personal Firewall Start servic.exe W32/RBOT-RY WORM! X Sygate Personal Firewall Start services32.exe W32/Rbot-MB worm infection X Sygate Personal Port crss.exe W32/RBOT-PX WORM! X Sygate Personal Port Blocker volume.exe variant of the WIN32.RBOT WORM! X Sygate Personal Port Blocker winupdate.exe variant of the WIN32.RBOT WORM! X Sygate Personals Firewalls ccsrn.exe variant of the WIN32.RBOT WORM! U SyGateService sgserv95.exe SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs X Symantec ccapp.exe W32.Reatle WORM! Note: This is not a Symantec file. X Symantec Anti Virus symantec32.exe variant of the W32/WOOTBOT WORM! X Symantec Autoscan ?? W32/Rbot-AJO WORM! X Symantec Configuration Loader ccApp32.exe variant of the GAOBOT.GEN WORM! Y Symantec Core LC symlcsvc.exe Part of Norton AntiVirus 2004. What does it do? N Symantec Fax Starter Edition Port OLFSNT40.EXE Offers a virtual printer as a fax machine. Can be run via a desktop shortcut U Symantec NetDriver Monitor SNDMon.exe "Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the ""U"" recommendation" U Symantec NetDriver Warning SNDWarn.exe Part of Symantec Live Update - displays the warning when you need to update the firewall database. X Symantec Security symantec32.exe RANDEX.PR or RANDEX.YR VIRUSES! X Symantec Security Addon nvsvc.exe variant of the GAOBOT/AGOBOT WORM! X Symantec Security Routine Addon for Microsoft Windows navpxaw32.exe AGOBOT-GJ TROJAN! X SymAV SymAV.exe W32.NETSKY.U WORM! U SymKeepAlive CKA.exe Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive X SymRun ccApps.exe Troj/Kagen-A TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N SymTray - Norton SystemWorks SYMTRAY.EXE "Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray" U Sync Data Hndsync.exe Pocket Real Estate - mobile synchronization manager U SyncAgent syncagent.exe "Ghost Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove" X Synchronization Manage rservers.exe W32/Forbot-FM WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N Synchronization Manager mobsync.exe Find more information about its use here U Sync-It Syncit.exe Sync-It - synchronizes the system clock with time servers on the internet X syncman winsync.exe Troj/MancSyn-A TROJAN! X SyncManager msorunner.exe variant of the WIN32.TACTSLAY TROJAN! X SyncMon adslcomdos.exe CLUNKY-A TROJAN! X Syntax windows32.exe SDBOT.CQ WORM! X Syntax Script systacq.exe SDBOT.AI WORM! U SynTPEnh syntpenh.exe Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll Y SynTPLpr syntplpr.exe Synaptics touchpad driver helper. Required for touchpad features to work X sys ?? Hijacker X sys sysdllwm.reg CoolWebSearch parasite related. X Sys Ren SysRen.exe Part of FlashEnhancer adware X SYS_CLEAN Service.exe FLOPCOPY VIRUS! X Sys_Run ghost.exe Troj/Lineage-N Trojan! X sys_Runtt1 explorer.exe "LINEAGE-M TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the Program Files folder!" X sys008 sys008.exe "Hijacker, also detected as the TROJ/STARTPA-GK TROJAN!" X sys009 sys009.exe Troj/StartPa-ZB TROJAN! X sys201 sys209.exe Troj/StartPa-ZY TROJAN! X Sys29 ?? EliteBar adware X sys32 sys32.exe FLUX.E Backdoor TROJAN! X sys32 sysx32.exe W32/Kvex-A VIRUS! X sys32dll sys32dll.exe W32.Aimdes.B WORM! U sys32sql sys32win.exe Active_Keylogger surveillance software. Uninstall this software unless you put it there yourself. X SysA ?? EliteBar adware U SysAgent SysAgent.exe SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of X SysAI SysAI.exe AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located U Sysbot sysbot.exe Spector - spying (or monitoring) software to record internet activity X syscfg syscfg32.exe KWBOT.S VIRUS! X syscfg34.exe syscfg34.exe ELECTRON VIRUS! X syscheck iexplorer.exe "Win32.Agent.dm downloader trojan infection. NOTE - This is NOT the Internet Explorer file, which is called Iexplore.exe, and will always be located in the Internet Explorer folder in Program Files!" X Syscheck win.hta Browser hijacker X sysclx ntldrt.exe W32/Jlok-A WORM! X syscm Syscm.exe Vanish adware X syscon syscon.exe W32.APRILCONE.A WORM! X syscon lptt01 or syscon ml097e syscon.exe "Variant of the RapidBlaster parasite (in a ""Syscon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X sysconfig iexplorer.exe CULT.C VIRUS!. Note - iexplorer.exe is not to be confused with Interrnet Explorer (iexplore.exe) X sysconfig iexplorer.exe CULT.H VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe) U Sysconfig Stealth KeySpy.exe StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself! X SysConfig syscfg35.exe KAZMOR.C VIRUS! X SysConfig wincfg32.exe SDBOT.ZD WORM! X Syscpy Syscpy.exe "Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE VIRUS!" X SysCtl sysctl.exe AOK VIRUS! X Sysctrls procdll.exe WEEDBOTZ.14 VIRUS! X sysdat.dll sysdat.dll.exe Nishica 1.1 backdoor TROJAN! X sysdir winrun.exe WINBUR.B VIRUS! X sysdll ?? Trojan.Hugesot TROJAN! X Sysdpt sysdpt.exe TrojanDownloader.Win32.Crypt X sysdxvid sysdxvid.exe Premium rate adult content dialer X sysdxvid sysdxvid.exe /nocomm Troj/Dluca-S TROJAN! X SysEQ svclgx32.exe TROJ/IRCBOT-AC TROJAN! X sysfiler sysfiler.exe RETSAM VIRUS! X SYSfit SYSfit.exe AdShooter adware variant X sysflg32 sysflg32.exe Crypter.C trojan variant infection X sysformat sysformat.exe W32/BAGLE-BK WORM! X syshelp syshelp.exe variant of the LOVGATE WORM! X sysin ?? TROJ/DSRC-A TROJAN! X sysinfo sysinfo.exe BEDRILL VIRUS! X sysinfo.exe sysinfo.exe BEAGLE.V WORM! X sysinit services.exe Troj/NewIfrm-A trojan X SysInit wininit32.exe XABOT VIRUS! X Sysino lsess.exe W32/FORBOT-BF WORM! X sysint16 sysint16.exe Crypter.A trojan variant infection X Syskey sysinit.exe W32.BEAGLE.AX WORM! X Syslib Syslib.exe Adult content related downloader trojan X Syslog lptt01 or Syslog ml097e Syslog.exe "Variant of the RapidBlaster parasite (in a ""Syslog"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X syslogin.exe syslogin.exe W32/Bagz-B worm infection U Sysman Sysman KeyTrap is a spyware program that records all keyboard activities. If you didn't install it yourself remove it. X sysmem mmsete.exe W32.Nopir.C Worm! X sysmem outlookrem.exe W32/Nopir-C Worm! X SysMemory manager mdms.exe Troj/Cimuz-B TROJAN! U SysMetrix SysMetrix.exe SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics X sysmod sysmod.exe W32/Spybot-DU WORM! X Sysmon rpcmon.exe RANDEX.ATX VIRUS! X sysmon sysmon.exe BIZEX VIRUS! X sysmon sysmon44.exe variant of the BackDoor-CBA TROJAN! X SysMon wowexece.exe Troj/Mulan-A TROJAN! X sysmon12 ?? "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X sysmonnt sysmonnt Transponder parasite related X sysmonnt sysmonnt.exe SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server X SysMonXP SysMonXP.exe W32.NETSKY.Q WORM! X sysnate sysnate.exe MEDIAS VIRUS! X Sysnet snuninst.exe Unidentified adware X sysnet sysnet.exe CasClient adware - also detected as the CMAPP TROJAN! X sysobj.exe sysobj.exe "TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here" X SysOps SysOps MSNCORRUPT VIRUS! X syspare syspare.exe Troj/Bifrose-AN TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X syspath drv.exe SOBER VIRUS! X sysPersonalFirewall msnmssgr.exe variant of the WIN32.RBOT WORM! X sysPersonalFirewall system.exe WOOTBOT.FH WORM! X sysPersonalFirewall tskm0nitor.exe variant of the WIN32.RBOT WORM! U SysPilot fdxxl.exe "G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!" X sysPnP bootconf.exe "Homepage hijacker, redirecting to coolwwwsearch.com; see for example here" X SysPnP "rundll32 setupapi, InstallHinfSection.... oemsyspnp.inf" Search hijacker - see here X syspol syspol.exe "TROJ/DREMN-B TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." Y SysPool Mssvc.exe "StealthDisk - hides folders, files and applications. Will also encrypt them for better protection" X sysprocessor Update sysprocessor.exe Win32.Rbot worm variant X SysProtect System.exe NETSPY VIRUS! X syspw32.exe syspw32.exe W32.Appflet WORM! X Sysr sysmd.exe Ulubione adult content dialer X SysReg SysReg.exe CCINVADER2 VIRUS! X SysReg SysReg.exe SearchSeekFind textual marketing foistware X SysRes IExpIore .exe W32.ELITPER.E WORM! X Sysres Sysres.exe LOGMOD VIRUS! X SysRes TASKMANAGER.exe W32.Elitper.A WORM! X SysRes WWE DIVAS.exe W32.Elitper.D WORM! X SysScan bvt.exe AUTOUPDER VIRUS! X SysSearch ?? "Hijacker, also detected as the TROJ/STARTPA-ME TROJAN!" X SysSearch ?? StartPage-FN browser hijacker X SysSearch ?? STARTPA-ME TROJAN! X sysser ?? W32.RAHACK WORM! or the Troj/RaHack-B TROJAN! U SysService SERVICES.EXE "NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\NSkeylogger folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SysService SysService.exe TROJ/BDFORM-A TROJAN! X SysService32 "SysService32.exe, ln32k.dll" KINDAL VIRUS! X SysService32l systask32l.exe THEUG VIRUS! X SYSsfitb SYSsfitb.exe Searchforit browser hijacker X SysStart ?? "Adware, probably VX2/Transponder related - filenames spotted include jdisysi6.exe, hjisysi6.exe, ffgsysi6.exe and more." X syst syst.exe "JOKE_DUMB.A ""Joke"" virus" X System abcdefg.exe W32/Harwig-B WORM! X System abcdefg.exe W32/HARWIG-C WORM! X System Atira.exe KOTIRA VIRUS! X System cber.exe unidentified TROJAN! X System csrss.exe Troj/LdPinch-PT TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder. X System dcomx.exe CIREBOT VIRUS! X system Explorer.exe "GRAYBIRD VIRUS! Note - this is located in this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) rather than the valid Windows Explorer which is located in C:\Windows or C:\Winnt" X System kernels32.exe VICSFRAM TROJAN! X SYSTEM lsas.exe SPYBOT.CJ worm X system lsasse.exe W32/RBOT-YL WORM! X system messenger.exe unidentified WORM or TROJAN! X system outlook.exe W32.MIMAIL.Q WORM! **Note - Microsoft's outlook.exe resides in the Program Files sub-directory whereas this resides in C:\Windows or C:\Winnt X system regedit -s system.dll Homepage hijacker X System run322.exe LANFILT VIRUS! X System serwin.exe TROJ/LDPINCH-BN TROJAN! X System SPOOLSU.EXE Troj/Banker-FC TROJAN! Note: SPOOLSU.EXE (Notice it's spelled with a U) is not the legitimate Windows Process. The legitimate Windows Process (Spoolsv.exe) is found in the System32. This trojan file is found in the Windows or Winnt folder. X System svch?st.exe Troj/LdPinch-BF TROJAN! X System svchost.exe "LDPINCH-AU or Troj/LdPinch-BD and Troj/LdPinch-BH TROJANS! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" X System sysctrl.exe /a "WinGuardian **Note: This Commercial_keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware." X System system.exe "number of VIRUSES, including CHILI, NULLBOT, FULAMER.25, NETCONTROLL, NETCONTROLL, GATECRASH.A, GATECRASH.B, NTCONTROL.A, BUSHTRO122& VIVAEL" X System system23.exe W32/Lebreat-D WORM! X system systemsearch.hta Jetseeker.com hijacker X System systray.exe TROJ/PISABOY-A TROJAN! - NOTE - this is NOT the valid System Tray application as described here X System windowsps.exe variant of the WIN32.RBOT WORM! X System WINL0G0N.EXE /nosplash Troj/Bancos-DB TROJAN! X System wumgrd32.exe variant of the WIN32.RBOT WORM! X System YPager.exe JUNTADOR.K VIRUS! Note! - this is not Yahoo! Messenger X System 64 Driver for Games sys64dvr.exe SDBOT WORM! X System Applications Profile sap.exe W32/RBOT-QF WORM! X System backup ?? "ADMINCASH.B TROJAN! - NOTE multiple different file names have been spotted; examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on." X System Backup msystem.exe Adult content dialler X System Backup Services backups32.exe variant of the WIN32.RBOT WORM! X System Buffer Application buffer32.exe W32/SDBOT-UD WORM! X System Cache SysCache.exe Unidentified worm or trojan U System Check ?? "XPCSpy Pro keylogger, surveillance and monitoring software" X System Check ?? XpcSpy SPYWARE! X system check updater.exe Unidentified adware downloader X System Checking wasul.exe RBOT.BHM WORM! X System Config BF3.EXE W32/Spybot-DT WORM! X System Config Manager crss.exe AGOBOT.GH WORM! X System Config Manager smssl.exe W32/Agobot-ZJ WORM! X System Configuration iexplore.exe "RANDEX.AD VIRUS! Note that the real ""iexplore.exe"" is located in Program Files\Internet Explorer" X System Configuration syscfg32.exe W32.Mytob.EA WORM! X system configure svchost.exe Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X System CPL manager ?? W32/RBOT-SR WORM! X System CSRSS Patch scrtkfg.exe variant of the WIN32.RBOT WORM! X System CSRSS Patch SCRTKFG.EXE W32/RBOT-ADA WORM! X System Database administration systemDA.exe W32.Derdero.B WORM! X System Database Administration Support Process sysdasp.exe W32.Derdero.C WORM! X System Diagnostics sysdiag32.exe SDBOT.GEN WORM! N System DLF cpqdiaga.exe Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs U System DLL Resources sysdll.exe SnapKey SPYWARE! **Note if you did not intentionally install this remove it. X System Document Application msdocument.exe W32.Randex.COX WORM! X System Document Application nmod.exe W32/SDBOT-ABB WORM! X System Document Application wins.exe SDBOT.AUB WORM! X System driver Messenger.exe WOOTBOT.GI WORM! X System Drivers wingmt.exe W32/SDBOT-MG WORM! X System Efficiency Monitor mscedit32.exe SDBOT.P WORM! X System Efficiency Monitor mscommand.exe KWBOT.P VIRUS! X System Event Manager secsvc.exe RBOT.BMY WORM! X System Executable DLL Library EXECDLL32.exe RANDEX.AZ VIRUS! X System Failure Statistic cnstat.exe W32/Rbot-LF worm infection X System Failure Statistic cnstat.exe W32/RBOT-LF WORM! X System File Drivers nvsysvc32.exe AGOBOT.WJ WORM! X system firewall makeini32.exe W32/AGOBOT-PS WORM! X System Guard mhguard.exe W32/Rbot-AGU WORM! X System Handler LSASS.EXE NIMOS VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! X System Host Manager syshost.exe W32/BANWORM-C WORM! X System Host Service svchost.exe CONE.F VIRUS! Note - this is not the valid svchost.exe as described here X System Information Manager Msbb.exe variant of the BACKDOOR.IRC.BOT TROJAN! X System Information Manager Navcpe.exe W32/Sdbot-QB worm infection X System Initialization "msmsgri32.exe, payload.dat" RANDEX.D or ROXY or ROXY.B VIRUSES! X System Kernal Support system.exe SDBOT.BWV and W32/Rbot-AEA WORMS! X System Kernel lsass.exe Troj/VBbot-G TROJAN! U System LifeGuard Scheduler Slsched.exe System LifeGuard scheduler X System Log Event csrss32.exe W32/Agobot-JI WORM! X System Management Service smsc.exe W32/RBOT-ANN WORM! X System Manager svchost.exe "TROJ/BANKER-AE TROJAN! Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!" X system manager System.exe W32/FORBOT-BO WORM! X System Manager winsrv32.exe unidentified WORM or TROJAN! X System Manager Updates winsvc.exe AGOBOT.AEM WORM! U System Mechanic Popup Stopper Popupstopper.exe "Iolo ""System Mechanic"" popup stopper" X SYSTEM MESSAGER wmisg.exe W32.Mytob.ES WORM! X System Messenger SYSMSG32.EXE W32/SPYBOT-DK WORM! U System Monitor SYSMON.EXE "Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal" X System Monitor Sysmon16.exe SDBOT WORM! X System MScvb mscvb32.exe SOBIG.C VIRUS! X System Net sys32.exe W32/Forbot-FX WORM! X System Net Database sysnd.exe W32/RBOT-AAW WORM! X System Networking sysnet.exe RBOT.API WORM! X System Process CSRSR.exe W32/AGOBOT-SQ WORM! X System Process csrss.exe "TROJ/ADCLICK-AG TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X System Process lsass.exe "TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows lsass.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X System Process svchost.exe "TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!" X System Profile Regsrv.exe BDS/OPTIXPRO.12 VIRUS! X System Reboot rebootsys.exe W32/RBOT-WU WORM! X System Redirect sysbho.exe "Downloader trojan, ""Melkosoft"" adware related" X System Restore svcnet.exe W32.TIBICK WORM X System Restore Data ?? RANDON.AN WORM! X System Restore DLLs ixplorer.exe variant of the W32/SDBOT WORM! X System Service coderxt.exe W32/Rbot-ALD WORM! X System Service exp0lrer.exe variant of the WIN32.RBOT WORM! X System Service MSREXE.EXE AML VIRUS! X System Service servicent.exe W32/Rbot-AJI WORM! X system service spoolcrv.cpl INSPIR.11 VIRUS! X System service system.exe PWSteal.Bancos.AA TROJAN! X System Service systems.exe AGOBOT.VZ WORM! X SYSTEM service helper svchelper.exe W32/MONKBD-A WORM! X SYSTEM service helper syshelp.exe variant of the W32/MONKBD-A WORM! X System service61 pokapoka61.exe EliteBar adware component X System service62 pokapoka62.exe EliteBar adware component X System service62 pokapoka63.exe EliteBar adware component X System service63 pokapoka63.exe EliteBar adware component X System service63 pokapoka64.exe EliteBar adware component X System service63 pokapoka66.exe EliteBar adware component X System service65 pokapoka65.exe EliteBar adware component X System service66 pokapoka66.exe EliteBar adware component X System service67 pokapoka67.exe EliteBar adware component X System Services ?? variant of the WIN32.RBOT WORM! X System Services connection.exe unidentified WORM or TROJAN! X System Services ssms.exe variant of the WIN32.RBOT WORM! X System Services svcsenes.exe variant of the WIN32.RBOT WORM! X System Services svcsenes32a.exe W32/Rbot-AFG Worm! X System Session Manager smss.exe W32/Kalel-E WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X System settings burndl32.exe W32/SDBOT-ZO WORM! X System Setup rpcxcmod.exe unidentified WORM or TROJAN! X System Soap Pro soap.exe System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided U System startup charmapx.exe Only required if using an oriental language X System Startup kimochi.exe variant of the WIN32.RBOT WORM! X System Startup Voltio.exe RBOT.NJ worm infection X System Stats SystemStats.exe variant of the W32/WOOTBOT WORM! X System Support syscfg.exe W32/Rbot-AGQ WORM! X System Support system32.exe W32/RBOT-AHA WORM! X System Terminal SYSTEM2.EXE Troj/Spybot-BZ trojan infection X System time updator CSysTime.exe RANDEX.S VIRUS! X System Toolkit Systools.exe RONOPER-G VIRUS! X System Tray msccn32.exe W32/SOBIG.B Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray ( SysTray.exe) X System Tray systray.exe W32/Fan-A WORM! X System Tray Services spooles32.exe AGOBOT.ZH WORM! X System Tray32 SysTray32.exe REPAD VIRUS! X System Unix syscfg32.exe W32/RBOT-ZD WORM! X system updata updata.exe Troj/Lineage-C TROJAN! X System Update ?? Troj/Soromo-A TROJAN! X System Update wauluclt.exe SDBOT.EF WORM! X System Update wupdmgr.exe Troj/Soromo-A trojan infection X System Update Service system.pif W32/Rbot-ALL WORM! X System Update Service update.pif W32.Spybot.WOE WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X System Update Service winupd32.exe ADTODA-A TROJAN! X System Update2 explorer.exe Autotroj-C TROJAN! X System Update2 services.exe Autotroj-C TROJAN! X System Update2 svchost.exe Autotroj-C TROJAN! X System Update2 system.exe Autotroj-C TROJAN! X System Update2 taskman.exe Autotroj-C TROJAN! X System Update2 taskmon.exe Autotroj-C TROJAN! X System Update2 update.exe Autotroj-C TROJAN! X System Update2 webcheck.exe Autotroj-C TROJAN! X System Update2 wininet.exe Autotroj-C TROJAN! X System Update2 winlogon.exe Autotroj-C TROJAN! X System Update2 winspool.exe Autotroj-C TROJAN! X System Update2 wupdmgr.exe Autotroj-C TROJAN! X System Updater Service wmiprvsw.exe GAOBOT.AFC WORM! X System Updates winsci.exe variant of the WIN32.RBOT WORM! X System Updates 4 mssysfix.exe W32/Rbot-ADU Worm! X System Updates Manager winserv32.exe W32/Agobot-AGA Worm! X System Updates Service updates.pif W32/Rbot-AMA WORM! X System Uptime Server SYSENTRY.EXE RBOT.LK worm infection X System Uptime Server SYSENTRY32.EXE RBOT.LK worm infection X system xp acdsee demo.exe W32.SALGA.A WORM! X system. system..exe OPTIXPRO.13.C VIRUS! X system... system...exe OPTIXPRO.13.C VIRUS! X system.exe system.exe PWSTEAL.JGINKO TROJAN! U System_Messages pprsen.exe "TerminatorX - ""offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like""" X System132 Csrtss.exe LANFILT-I TROJAN! X system23 notPad.exe ESTEEMS.D TROJAN! X System32 crsvvc.exe RBOT.BLY WORM! X System32 lsasss.exe W32/RBOT-XW WORM! X system32 NeT-BoT.exe W32/AGOBOT-LJ WORM! U System32 sysdiag.exe SpyAgent.B surveillance software - uninstall this software unless you put it there yourself! X System32 system.exe BUSHTRO122 VIRUS! X System32 system.exe BushTro122 trojan infection X System32 "system32,1.exe" "worm or trojan, as yet unidentified" X System32 System32.exe "MARI, SYSXXX and other VIRUSES!" X System32 PCI Manager syspci32.exe W32/Rbot-AFR Worm! X System32 TCP Manager systcpm.exe variant of the WIN32.RBOT WORM! X System32 TCP Manager systerm.exe RBOT.AFD WORM! X System32 Temp Service systmp.exe W32/Rbot-AET Worm! X system32.dll sysdll32.exe CoolWebSearch parasite related. X system32.dll systeminit.exe CoolWebSearch parasite related. X system32.exe services32.exe variant of the BACKDOOR.IRC.BOT TROJAN! X system32.exe system32.exe Backdoor.Graybird.P TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder. X System32Dll DLL32SYS.EXE W32/Spybot-CZ worm infection X System32Ex System32Ex.exe Backdoor.IrcContact trojan infection U System32kfvw? sysdiag.exe SpyAgent.B surveillance software - uninstall this software unless you put it there yourself! X System33 FB_PNU.EXE NICHELLO-A VIRUS! X System4224411 Virus CAGER.A WORM! X SystemAdministration Wincmp32.exe ASYLUM VIRUS! U SystemAgent Sage.exe """Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times""" X SystemB MessengerStopper.exe MessStopper adware X SystemBackup MicroLog.exe MICROLOG.A VIRUS! X SystemBackup mtx.exe MTX VIRUS! X SystemBoot ?? Adult content dialler X Systemboot msnsngr.exe variant of the WIN32.RBOT WORM! X SystemBoot services.exe "W32.SOBER.P WORM! - NOTE - this file is placed in a ""%Windir%\Help\Help"" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SystemCheck services.exe "W32/SOBER-M WORM! - Note - this file is placed in a %WINDOWS%\Config\system subfolder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SystemCheck svchost.exe "TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SystemCheck SysCheckBop32.exe WINBO adware component X SystemCheck Systemcheck.exe LAVITS VIRUS! X SystemChecker Syschk.exe GAIL.F VIRUS! X SystemCONF98i SystemCONF98i.exe FROZEN BOT VIRUS! X System-Config msptmf32.com Win32.Lioten.FA worm infection X SystemDebug Sysdeb32.exe SYSBUG VIRUS! X SystemDll SystemDll.exe LOXOSCAM TROJAN! X systemdll32.exe systemdll32.exe FEUTEL-F TROJAN! X SystemDriver csrss.exe "ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!" X SystemDriverCheck svchost.exe "TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X SystemDriverLoad svchost.exe "TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X systemdrv ms32sys.exe WORM related - most likely GAOBOT X SystemExplorer explore.exe "Homepage hijacker - file located in the ""Services"" folder in Common Files" X SystemFile SystemFile.exe Troj/Dulldoor-A Trojan! X SystemFTP VSENMB.exe "Malware (ie, malicious software).? Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well" X Systemidle stemIdle.exe WOOTBOT.AO VIRUS! X SystemInit iservc.exe FIZZER VIRUS! X Systemiom Updater Systemiom.exe WORM_SPYBOT.TY X SystemLoad32 sysload32.exe W32.MIMAIL.E WORM! X SystemManager Sysman32.exe DOWNLOADER-BW.B VIRUS! X SystemMap32 Netisp32.vbs REDIST.C VIRUS! X SystemMD md.exe Homepage hijacker X SystemMonitor Sysmon32.exe AIDID.A worm infection X SystemMonitor SYSMON32.exe W32.Aidid VIRUS! X SystemNetwork NETSERV.EXE NETCONTROL VIRUS! X SystemNetwork sysnet.exe variant of the WIN32.RBOT WORM! X SystemNT SystemNT.exe TROJ/PWSVB-EG TROJAN! X SystemNT SystemNT.exe TROJ/PWSVB-EG WORM! X systemr d11host.exe Troj/VB-GX Trojan! X systemr gedit.exe Troj/StartPa-HC TROJAN! X systemr gedit.exe Troj/AdClick-AQ TROJAN! X SystemReg svchost.exe DEWIN.E VIRUS! Note - this is not the valid svchost.exe as described here X SystemReg WINREG.EXE DEWIN.A VIRUS! X Systems itDDD.exe Troj/Dloader-PP TROJAN! X Systems itDDD.exe Troj/VIXUP-G WORM! X Systems scchost.exe Troj/Tofger-AK TROJAN! Note: This trojan file scchost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. X Systems svch0st.exe "W32.MYDOOM.BI WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X Systems Systems.exe TROJ/BANKBOA-A TROJAN! X Systems Backups windrives.exe W32/AGOBOT-RB WORM! X Systems Restart ?? Best_Search browser hijacker! X Systems Restart ?? StartPage.J TROJAN! X Systems Restart ?? Startpage.I browser hijacker X Systems Restart ?? variant of the StartPage.J TROJAN! X Systems Restart slchost.exe BANCOS.RF TROJAN! X Systems Restart spchost.exe variant of the BANCOS.RF TROJAN! U Systems.exe Systems.exe "Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it" U systems.exe Systems.exe "KGBSpy is a commercial spyware program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode." U SystemSafe Syssafe.exe System Safety Monitor - system monitoring tool with additional application firewalling X SYSTEMSars32 csrss.exe "AHLEM.A VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling" X SystemSAS System32.exe KWBOT.C VIRUS! X SystemSearch regedit.exe -s c:\ie.reg Installs a Seachxl.com browser page hijack X SystemSearch regedit.exe -s c:\sys.reg Installs a i--search.com browser page hijack X SystemService msocfg.exe Premium rate adult material dialer X SystemService navchk.exe Premium rate adult material dialer U SystemService nsserver.exe NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself! X SystemService pokapoka62.exe EliteBar adware component X SystemService qservice.exe Premium rate adult material dialer X SystemService shman.exe Premium rate adult material dialer X System-Service EXPLORER.SCR BENJAMIN VIRUS! KaZaA file-sharing users beware! X SystemSettingf TRUG.vbs TRUG.B VIRUS! U SystemSuite Task Manager MXTASK.EXE vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro X SystemTasks filez.exe Adult content dialler X SystemTasks loaded.exe Adult content dialler X SystemTasks sexypicz.exe Adult content dialler X SystemTools kernels32.exe VICSFRAM TROJAN! X SystemTra CDPlay.EXE variant of the LOVGATE WORM! X Systemtra Systra.exe variant of the LOVGATE WORM! X SystemTray SystemTray.exe BIGFOOT TROJAN! Note - this is not the valid SystemTray ( SysTray.exe ) X SystemTray SysTray.exe "IRC.ALADINZ.P TROJAN! ** Note - Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file" U SystemTray or SysTray SysTray.Exe "SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they\'re available via Start -> Settings -> Control Panel" X SystemTraySD SDSystemTray.exe "Max Spyware Detector, bogus ""Spyware remover"" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""spywaredetector.net""" N SystemUpd SystemUpd.exe "Updater for Swapoo.com, a kind of Napster for games" X SystemWideHook for Windows NT WinHook32.exe W32.Mydoom.AC WORM! U SystemWizard Sniffer Sniffer.exe SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC X systemyom Updater systemyom.exe variant of the BACKDOOR.IRC.BOT TROJAN! X SYSTEMZ Patch SYSZ.exe ALADINZ.P VIRUS! X Systes jrdtifkkxbbsa.exe W32/Rbot-ADC Worm! X Systesms.exe systesms.exe W32/Rbot-HI worm infection N Systest Systest.exe Clean Space temp files cleaner X systhread winkernal.exe LIAMED VIRUS! X SysTime systime.exe "Troj/StartPa-CR , a CoolWebSearch parasite variant" X Systmesy Systmesy.exe W32/Rbot-KQ worm infection X Systoan32 systoan.exe Added as the result of an unidentified VIRUS! X systrans ?? Troj/StartPa-GZ TROJAN! X Systray "a.exe, b.exe" Winfavorites adware X SysTray Snnpapi.exe unidentified TROJAN! X Systray Systray_.Exe KERGEZ.A VIRUS! X SYSTRAY UNMT.EXE W32/Sdbot worm infection X SYSTRAY UNMT.EXE Proxy-Agent trojan variant X SYSTRAY UNMT.EXE TROJ/DLOADER-LQ TROJAN! X Systray w32explorer.exe W32/Rbot-AJY WORM! X Systray driver systray.exe IRC.MUTEBOT TROJAN! ** Note - this is not the legitimate systray.exe process. X SystrayServices Msxpw.exe CITOR VIRUS! X Systry ?? AUTEX VIRUS! X SYStry spoolsvr.exe SDBOT.GN WORM! X Systryt ?? AUTEX VIRUS! U systune systune.exe AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed. U Systweak Memory Optimizer memtuneup.exe Part of SysTweak Advanced System Optimizer X sysu sysu.exe Dynamic Desktop Media adware - see here X sysug32.exe sysug32.ex unidentified TROJAN or WORM! X Sysupd Sysupd.exe VirtuMonde adware X Sysvupex Sysvupex.exe MEDIAS VIRUS! U SysW8 csta.exe Clean Space - privacy and perfomance enhancer U SYSWB6 SYSWB6.exe "We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content" X SysWin SysWin.exe Backdoor.IrcContact trojan infection X Syswin32 syswin32.exe Backdoor.IrcContact trojan infection X syswin32 syswin32.exe W32.SpyBot worm variant X syswin32 syswin32.exe SDBOT TROJAN! X Syswindow Syswindow.exe COW VIRUS! X SysWy rundll32.exe "TROJ/LINEAGE-JH TROJAN! - NOTE: this file is found in the C:\Windows\System folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!" X sysX3 sys22.exe W32.RANTS.C WORM! U SZMsgSvc.exe SZMsgSvc.exe StopZilla! - pop-up killer X t xclean.exe Flashtrack.B adware U Taakcontrole taskmon.exe "Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)" X Taba stte.exe Clickspring spyware N Tablet Tablet.exe "Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL ALT DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds)" Y tablet s tablet s Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful) X Tablet Task tabletsk32.exe W32/Rbot-AJB WORM! U TabletTip tabtip.exe "The Microsoft Tablet PC Input Panel converts handwriting to text dynamically, and you can make corrections quickly and easily before inserting text." Y TabUserW TabUserW.exe Wacom pen tablet driver N Tad tad.exe From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute N Tahni Deskmate Tahni.exe "Tahni Deskmate - ""Interactive cartoon character that lives on your Windows desktop""" X TakeMP3 ?? MatrixDialer related X TAKSMGN taskmr.exe W32/Rbot-AHS WORM! N TalkingReminder TALKINGREMINDER.EXE Talking Reminder from Software River Solutions - talking calendar reminder X TANG_INA_MO AutoRun.bat W32.Filukin.A WORM! X Tapicfg Tapicfg.exe CoolWebSearch parasite related. X Tapisys tss.exe Trojan.Win32.Small variant U TapiTNA TapiTNA.exe Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys U Tardis Tardis.exe Tardis - time synchronization software X Task tasker.exe W32.Mydoom.R WORM! X Task Bar TASKBAR.EXE FRETHEM.J VIRUS! X Task Commander regsvc32.exe W32/AGOBOT-RX WORM! X Task Debugger sysdll.exe W32/RBOT-CQ WORM! X Task Help wualcts.exe variant of the WIN32.RBOT WORM! X Task Manager prcview.exe W32/AGOBOT-RT WORM! X Task manager taskemngr.exe W32/Rbot-AGA Worm! X Task Manager taskman.exe W32/FORBOT-T WORM! X Task Manager taskmngr.exe RBOT.Y worm infection X Task manager TikTo.exe RBOT.LV WORM! X Task Monitoring Service svchost.exe "CONE.D VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32" X Task service taskmgs.exe variant of the WIN32.RBOT WORM! X task service taskservices.exe variant of the WIN32.RBOT WORM! X TASK SETUP tasksetup.exe W32/RBOT-YR WORM! N TaskBar CTLTask.exe "The Creative Sound Blaster Audigy Taskbar is used to choose between different types of EAX Effects - not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article." N Taskbar Taskbar.exe Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards N Taskbar Display Controls "RunDLL deskcp16.dll, QUICKRES_RUNDLLENTRY" "Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes ""Powertoy"" installed" X Taskbar Service taskbar.svc Unidentified adware X Taskbar System tasksys.exe variant of the W32/SDBOT WORM! X Taskbell.exe Rund1.exe Added as a resukt of the YIPID trojan X TaskList tasklist32.exe TROJ/BANCOS-DX TROJAN! X TaskMan rundll32.exe "DVLDR VIRUS! Note - this is not the valid ""rundll32.exe"" as it\'s in the Windows\Fonts directory" X taskmanager taskmanager.exe W32/AGOBOT-TF WORM! X taskmanager taskmgr.com BEREB VIRUS! X taskmanger taskmanger.exe variant of the WIN32.RBOT WORM! X Taskmgo ?? TROJ/BANCBAN-T TROJAN! X Taskmgr system.exe TROJ_PAKES.G TROJAN! X Taskmgr Taskmgr.exe System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory X taskmgr taskmgr.exe Startpage.G hijacker - NOTE: this is NOT the Windows Task Manager file! X Taskmgr tskmgr32.exe Homepage hi-jacker X taskmgr.exe mirc.exe variant of the WIN32.AGENT.AH TROJAN! X taskmgr.exe paint.exe variant of the WIN32.AGENT.AH downloader TROJAN! X taskmgr.exe paintms.exe variant of the WIN32.AGENT.AH TROJAN! N taskmgr.exe taskmgr.exe "Windows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut" X TASKMGRU TASKMGRU.EXE Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx X taskmngr ?? FLOOD-EK TROJAN! X taskmngr lptt01 or taskmngr ml097e taskmngr.exe "Variant of the RapidBlaster parasite (in a ""Taskmngr"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X TaskMon taskmon.exe "MYDOOM.A or MYDOOM.J WORMS! Note - this is not the valid Win98/Me file of the same name which resides in C:\Windows as this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). It is not normally on a WinXP system" X Taskmon driver winampa.exe LOONY-I TROJAN X taskmone taskmone.exe TROJ/SINGU-S TROJAN! U TaskMonitor taskmon.exe "The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)" X TaskMrg schwoch.exe Troj/LDPinch-Y trojan infection X taskmrg.exe taskimg.exe TROJ/DLOADER-QZ TROJAN! X taskopen.exe taskopen.exe HackTool.Win32.Hidd.c TROJAN! N TaskPlus TASKPL~1.EXE "Task and calendar management software available as freeware or as a ""Professional"" version for sharing over a LAN" N TaskPlus TASKPLUS0.EXE "Task and calendar management software available as freeware or as a ""Professional"" version for sharing over a LAN" X TaskReg ?? CBLAD VIRUS! is the full path and name of the infected file X TaskS manager taskmgrs.exe AGOBOT.QU WORM! X Taskschd TRAYWND.EXE LITMUS.002 VIRUS! U TaskScheduler TaskSch.exe ProSeries accounting software related N taskswitch taskswitch.exe ALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen X tasksys tasksys.vbs BYRON VIRUS! N Tasktray CTLTray.exe Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster?Audigy from a systray icon.? Also allows you to launch the Taskbar via right-click -> Show Taskbar. The tasktray can be accessed via Start -> Programs -> Creative -> Sound Blaster Audigy -> Taskbar X Tasmgr Taskmgr.bat VBS.Ypsan.G WORM! X tat tatss.exe Delfin_Promulgate adware variant Y Tau monitor Taumon.exe """Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system.""" X TB_setup tb_setup.exe HuntBar parasite toolbar installer U TB2PROEXE tb2start.exe Timbuktu Pro - remote desktop access software U TBC Pro tbcpro.exe "TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus" U TBC.exe Tbc.exe TitleBarClock software N tbctray tbctray.exe Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel Y TBLFUNC tblmouse.exe Aiptek HyperPen driver U TBPanel TBPanel.exe Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel X TBPS TBPS.exe "WebSearch toolbar, HuntBar parasite variant" N TBTray tbtray.exe VLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start -> Settings -> Control Panel Y tcactive tca.exe Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage N TCASUTIEXE TCASUTI.exe Associated with the 3COM diagnostic module (3COM NIC Doctor).?No further information is available N TCAUDIAG -off or TCASUTIEXE tcaudiag.exe Associated with the 3COM diagnostic module (3COM NIC Doctor).? No further information is available U TClock TCLOCK.EXE Kazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start -> Programs U TClockEx TCLOCKEX.EXE Puts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks U tcmonitor tcm.exe Part of The Cleaner from MooSoft - warns of changes to the registry U TCOYFReminder tcoyftray.exe My_ParenTime Fertility Planner Reminder. (The Calendar provides a quick overview of the status of your fertility.) X Tcp Application Manager localsvc.exe Troj/Dloader-NY Trojan! X Tcp Application Manager netsvc.exe Troj/Dloader-NY Trojan! X Tcp Application Manager spoolsvc.exe Troj/Dloader-NY Trojan! X Tcp Application Manager svcadmin.exe Troj/Dloader-NY Trojan! X Tcp Application Manager svcman.exe Troj/Dloader-NY Trojan! X Tcp Application Manager svcrun.exe Troj/Dloader-NY Trojan! X Tcp Application Manager tcpsvc.exe Troj/Dloader-NY Trojan! X Tcp Application Manager websvc.exe Troj/Dloader-NY Trojan! X tcp checker tcpcheck.exe TROJ/VBBOT-A TROJAN! X TCP Monitoring LanNSvc.exe RANDEX.AAS VIRUS! X TCPXP Update tcpxp.exe W32/RBOT-UL WORM! X tcupdater tcupdater.exe Topconverting.com/180Search adware updater U TDKSTART TDKSTART.EXE Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. N TDKTASK TDKTASK.EXE "Taskbar utility for a ""control panel"" for a CD-RW" U TDS3 TDS-3.exe "DiamondCS TDS3 antitrojan . Can be used to scan on demand, but required in startup if you prefer real time protection" N T-DSL SpeedMgr speedmgr.exe T-Online ISP SpeedManager; shows upload and download speed; also checks for updates automatically. N Teach In Box teachbox.exe Tutoring program that comes with a SystemAX Computer Y Tech-In-A-Box techbox.exe "Tech-in-a-Box ""provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running""" U "Telechips,Mass" patch.exe Removable Disk Driver for the Muro MP3 player N Telemeter 3.0 telemeter3.exe Internet connection bandwidth meter from a user ISP Y Telepath telepath.exe "Drivers for the WinModem versions of the US Robotics ""Telepath"" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information" Y TELUS Security service freedom.exe "Freedom Internet Security, provided by TELUS Communications Inc" X TempCom ?? W32/TRAXG-B WORM! X TempCom ?? TRAXG VIRUS! X tempx tempx.exe TEMPEX.A TROJAN! X Tencent QQ "Rund1132.exe qq.dll, Rundll32" Added as the result of the QQPASS.F VIRUS! X Terminal Update biosefui.exe Troj/PPdoor-O TROJAN! X Terminate Popup FPUK.exe Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.? Also see here X Terminate Popup ZPU.exe Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.? Also see here U TEscKey TEscKey.exe Toshiba Escape Key handler. Enables you to program and use the key combination to perform a specific function N Tesco.net ?? Tesco.net dial-up ISP software - not required X test i love you.exe Troj/Singu-T TROJAN! X Testing 123 msdata.dat W32.Nits.A WORM! X testit.exe testit.exe ISTbar/XXXToolbar adware component N TextAloud TextAloudMP3.exe TextAloud MP3 - convert text into spoken words and MP3s N Textbridge Instant Access OCR telepath.exe TextBridge from Scansoft. OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs X TEXTCONV lsass.exe "Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup" X TEXTCONV services.exe NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process X TEXTCONV winlogon.exe NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup! U TFncKy TFncky.exe Deals with the - key combinations on a Toshiba laptop U TFNF5 TFNF5.exe "Toshiba Hotkey Utility for Display Devices. By pressing , a window appears showing the displays that can be chosen ş LCD, LCD CRT, CRT, TV" Y tfswctrl tfswctrl.exe "Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones""" X TFTP### tftp### SPYBOT VIRUS! where # can be any number U TFunckey TFuncKey.exe Deals with the - key combinations on a Toshiba laptop N TgAddServer tgfix.exe "Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and ""self-healing"". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove, Charter offer some uninstallation instructions involving a registry patch that you may be able to modify for your proivder or try here" X tgbcde module32.exe WIN32.REIGN.R TROJAN! U Tgcmd tgcmd.exe "This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. ""tgcmdprovidersbc"" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation" U tgcmdprovidersbc tgcmd.exe "This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. ""tgcmdprovidersbc"" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation" N TGCMG ?? "Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work" X TGDC IE Plugin tgdc.exe ShopForGood spyware - see here X tgkill tgkill.exe "Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an ""enhanced"" support and self-repairing tool. This is ""beta"" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs" U Tgsetsite tgfix.exe "See TgAddserver and Tgcmd above. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation" N Thdetrf thdetr32.exe Appears to be related to Lycos advertising X ThE wind0s.exe unidentified WORM or TROJAN! U The Easy Bee's Hive ATCEgSvr.exe "The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence" X The Ethernet ethernet.exe variant of the W32/SDBOT WORM! X The Intranet intranet.exe variant of the W32/SDBOT WORM! U THGuard TH_Guard.exe Resident memory scanning for TrojanHunter U THGuard THGuard.exe Resident memory scanning for TrojanHunter X "This is a virus, please delete it" bigbadvirus.exe RANDEX.F VIRUS! U THOTKEY THotkey.exe "Associated with the Fn keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen" X Threaded intcp32.exe RANDEX.UG VIRUS! U ThrustTSR TMTMTSR.exe "Thrustmaster Thrustmapper. ""The Thrustmapper - t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly""" X Thumbs Plus X.X thmbplusXX.exe W32/Agobot-AAF WORM! (XX is a combination of random digit and character.) X tibs3 tibs3.exe Premium rate adult content dialer - see here X tibs5 tibs5.exe Premium rate adult content dialer - see here X Tiger Shine.exe HAPPYLOW or W32/Nishe-A VIRUS! U TiKL tikl.exe TinyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! X Time Manager TimeManager.exe W32/Mytob-BV WORM! X Time Zone Synchronization wscript zshell.js NETDEX-A VIRUS! N TimeCalendar tc.exe TimeCalender - calendar reminder U TimeCalendar TC.exe TimeCalendar digital planner N Timed Backups Manager Startup BACKTIME.EXE Backup Plus - backup software U TimeLeft TimeLeft.exe "TimeLeft is a countdown, reminder, clock, alarm clock, stopwatch, timer, sticker and time synchronization utility which uses Winamp skins to show digits and text." U Timemanager.exe Timemanager.exe "Time_Manager will let you track billable and non-billable time by customer, by category and by associate and then integrate directly to our custom billing package." N TimeOnline TIMEONLINE.EXE Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs X Timer comm.exe TROJ/BDOOR-IP TROJAN! X TIMER TIMER.EXE TIMESE.AG VIRUS! X TimeService trun.exe TlfLic-A premium rate adult content dialer. X TimeSink Add Client TSADBOT.EXE TimeSink Ad Client - advertising spyware X TimeSyncApp TimeSynchronize.exe DealHelper adware N TimeUp Timeup.exe TimeUp - internet online timer U Timezone TimeZone.exe Microsoft Daylight Saving Time Update Utility - see here N TINTSETP TINTSETP.EXE "Part of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word" X Tiny AV fooding.exe W32.Netsky.I WORM! Y Tiny Personal Firewall persfw.exe Tiny Personal Firewall U tinySpell tinyspell.exe "Tinyspell - ""allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard""" U TiomanExe Tioman.Exe Agate Tioman - warm and hot swap removable bay device manager for IBM laptops N Tips mousetips.exe Suggests tips on using your mouse U TiTleBarClock TiTleBarClock.exe "TitleBarClock displays the day/month/time and free physical RAM on the right hand side of an open window, replacing the system tray clock at startup" N Tivoli LCFEP.EXE "Tivoli ±TME? System Tray icon - ""\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally""" U TIxDSL tidslmon.exe Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs X TizzleTalk TizzleTalk.exe "TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messengers. Bundles adware, hence not recommended. From their EULA : ""As a result of installing the Company's Software, you will see occasional banner ads, pop-up or pop-under ads, or other types of ads selected based on your online activities .../... Occasionally, we may automatically or through other remote means, update, upgrade, patch or uninstall the Company's Software, including the Company's advertising-supported software, without further notice to you. These upgrades also may include installation of additional applications from the Company as well as third party applications.""" X tjstartup ?? BACKDOOR.TJSERV.C TROJAN! X tjstartup svchost.exe CURDEAL TROJAN! **Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! N TkBell.Exe evntsvc.exe "Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" N TkBell.Exe realsched.exe "Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" N TkBell.Exe tkbell.exe "Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" N TkBellExe evntsvc.exe "Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" N TkBellExe realsched.exe "Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" N TkBellExe tkbell.exe "Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK" X TkBellExee realschd.exe unidentified downloader TROJAN! X TkNetDriver Monitor lexbce.exe W32/SDBOT-ADF WORM! N tkonnect TKONNECT.EXE Dialer for the Tiscali internet service provider. Available as a desktop shortcut X tlc ?? Hijacker installer U TLogonPath tb2logon.exe Timbuktu Pro - remote desktop access software U TM Outbreak Agent TMOAgent.exe Trend Micro Internet Security anti-virus software virus outbreak warnings. Notifies users of virus outbreaks and offers to update the scanner U TMA distribution cfinst.exe Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients X tmax pupdate.exe Adware pop-up generator X tmchook tmchook.exe Detected by Kaspersky as the TrojanDownloader.Win32.VB.aa VIRUS! U TMESBS TMESBS21.exe Toshiba Mobile Extension Selectable Bay Service for WinXP - support for docking stations. Not required if you don't use a docking station N TMESRV31 TMESRV31.EXE Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station U TMExLogon TMESRV.EXE Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station X TmNetDriver Monitor exbce.exe W32/Sdbot-ABR WORM! X Tmntsrv32 Tmntsrv32.exe "Hijacker, detected by Norton antivirus as Trojan.StartPage.O" U TMOUSE tmouse.exe "Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint" Y tmproxy tmproxy.exe Trend Micro PC-cillin 2003 antivirus software N TMTMTSR TMTMTST.exe "Installed with Thrustmaster game controllers. It launches the Thrustmapper utility. Not required if you install the ""driver only"" from Thrustmaster website" U TNTClk TNTCLK.exe "Overclocking program for?TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked?to let it?run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job" U ToADiMon.exe ToADiMon.exe T-Online ISP software connection assistant U TopDesk TopDesk.exe "TopDesk; puts an icon in your system tray that when clicked upon, opens a pop-up menu that gives instant access to all of your desktop programs without having to minimize, resize, move or close other programs or files." X ToPicks Starter Idhost.exe ToPicks parasite related X topmoxie JavaRun.exe Marketing software from TopMoxie X TopSearch TopSearch.exe TopSearch adware variant Y Toshiba Fan fan.exe Toshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat U Toshiba Key State KEYSTATE.EXE "Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start -> Programs" N ToshibaPinger pinger.exe "Pinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification. Disabling instructions here" U TOSHIBSU Toshibsu.exe "Reduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly" U TosHKCW TosHKCW.exe Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed) Y TosMem tosmem.exe Toshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem U TosRotation TRot.exe TOSHIBA Rotation Utility - allows users to rotate a notebook's screen image 180 degrees in order to share information on the screen with others seated across a table or desk U TotRecSched TotRecSched.exe Scheduler for Total_Recorder from High Criteria Inc - audio capture utility Y ToUcamVProperty VProperty.exe "Philips Web Camera model name pcvc740k, ToUcam driver configuration tray icon." U Touch Manager WinLED.exe Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality U TouchED TouchED.exe TouchPad On/Off Utility on a Toshiba laptop N tour regedit ..tour.reg Edits registry values to keep the WinMe tour in Task Scheduler N Tour wincool.exe "Component of WinME that's annoying as hell. Pop\'s up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only" N tourpath ?? "Edits registry values to keep the Win 2000 ""tour"" in Task Scheduler" U TP4EX tp4ex.exe Adds accessibility options for an IBM TrackPoint U tp4serv tp4serv.exe "Supports the ""pointer stick"" on Thinkpads in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work" N TP98UTIL TP98.EXE IBM Thinkpad feature setup & configuration utility X tpcupdater updatetc.exe "Adware, probably 180Solutions related" U TpHotKey TPHKMGR.EXE "Activates ""ThinkPad Help"" when the ""Thinkpad key"" is pressed on an IBM ThinkPad laptop. Also activates the audio buttons (volume up/down, mute) on models such as the Thinkpad T30" U TpKmapMn TpKmapMn.exe "Create Keyboard combinations for special Thinkpad buttons when using an external keyboard, e.g. ""Ctrl-arrow up"" for ""volume up"". Only required when using an external keyboard. Available via Start -> Programs" N TPNF TPTray.exe Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel U tpopservice tpopservice.exe DirecWay two-way satellite internet service enhanced POP proxy server for email U TPP Auto Loader Tppaldr.exe "Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives.?System tray icon allowing the user to disconnect the external drive without an error message being displayed" U Tprtray Tprtray.exe Displays the Power icon in the System Tray on a Toshiba laptop Y TpShocks TpShocks.exe "Responsible for controlling the IBM Hard Drive Active Protection system found on newer models of IBM Thinkpads, including T41, T42, X40, R50, and R51. The Hard Drive Active Protection system is based on a technology similar to that used in automobiles to deploy airbags on contact: An accelorometer on the motherboard detects physical acceleration--such as when the notebook falls--and in response the system temporarily parks the hard drive's read/write head until stability returns" N TPTray TPTray.exe Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel Y TPWRTRAY Tpwrtray.exe Toshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use U tqrecv tqrecv.exe Tellique satellite broadcast reception software N Traceless launch.exe "Traceless 2003 - clear your cookies, temp directories and browser history with a click of a button. It also clears the recent documents and the IE drop down auto complete box" U Track4WinMonitor STMonitor.exe Track4Win is a spyware program that takes screenshots and logs user activity such as URLs and currently running processes. It uploads the logs and screenshots to a preconfigured server. If you didn't install this yourself remove it U TrackpointSrv daemon.exe "Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work" U TrackPointSrv tp4mon.exe "Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work" U TrackpointSrv tp4serv.exe "Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work" U Tracks Eraser or Tracks Eraser Pro te.exe "Tracks Eraser Pro from Acesoft - ""Erases all tracks of your internet activity""?" U Tranicon tranicon.exe "A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent" U Transparent ?? "Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here" U TransparentIcons tranicon.exe "A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent" U TransTask transtask.exe Tweak-XP_Pro related; feature to make the Windows XP taskbar transparent U Trashgrd TRASHGRD.EXE "Part of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin" U Tray Pilot Lite TrayPlt.exe Tray_Pilot allows you to hide the System Tray window. N Tray Temperature Weatherbug.exe "Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs" N tray_helper tray_helper.exe "Tray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder" X Traybar lsass.exe W32.Mydoom.L WORM! U traydate.exe TRAYDATE.EXE Displays the date as well as the time in the System Tray. Available from TUCOWS U TrayManager Trayman.exe TrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded) U Traymon traymon.exe Netropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news N TraySantaCruz tbctray.exe Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel N TrayServer TrayServer.exe For monitoring tray icons X TrayX winppr32.exe SOBIG.F VIRUS! U Trend Micro Anti-Spyware Tmas.exe Trend_Micro_Anti-Spyware - required when using real time monitoring Y TrendMicro Antivirus Aveagent.exe Virus scanner Y TrendMicro OfficeScan NT TMLISTEN.EXE Virus scanner X Trickler ?? Gator adware X Trickler ?? Gator adware X Trickler ?? Gator adware X Trickler fsg.exe Gator adware Y TridentTVIcon tvicon.exe "Trident Microsystems, Inc Display driver" U Trillian trillian.exe Part of Trillian ICR client Y trirot trirot.exe Trident Microsystems 3D video driver U Trojancheck 6 Guard tcguard.exe TrojanCheck anti-trojan software U TrojanScanner Trjscan.exe Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed U TrojanShield Init.exe TrojanShield anti-hacker/anti-trojan software U TrojanShield Protector Port.exe TrojanShield anti-hacker/anti-trojan software U True Internet Color Icon internetcolor.exe "Part of Colorific & 3Deep from LightSurf Technologies (nee E-Color). ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images""" X TrueFonts fonts.hta Browser hijacker - redirecting to Hugesearch.net N TrueSync Launcher tstool.exe "Starfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services" Y TrueVector VSMON.EXE Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this X TrustyHound-TS TrustyHound-TS.exe TrustyHound spyware X tsa tsm.exe TargetSaver adware X Tsa2 tsm2.exe TargetSaver adware X Tsa2 tsm2.exe TargetSaver adware X TsAdbot TSADBOT.EXE TimeSink Ad Client - advertising spyware U TSE_PLUtil PLBkMon.exe Prolific USB Flash Disk Log On Application X Tsk Mng Hlp wins32.exe W32/AGOBOT-JB WORM! X tskdbg tskdbg.exe FLOOD.E VIRUS! X Tsl tsl.exe Uploader-R adware X Tsl2 tsl2.exe TargetSaver adware N TSMsger TSMsger.exe "Epson scannner software - required for ""one-touch"" operation. Can be launched manually" X tsvcin n20050308.EXE "Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!" X TSystem ?? Troj/Nsys-A Trojan! X ttaa tata.exe TROJ/LINEAGE-T TROJAN! X TTS Sync testtts.exe SDBOT.BVA WORM! X ttupt ttupt.exe eZula TopText adware component U TuneUp MemOptimizer memoptimizer.exe "Part of ""TuneUp Utilities"", specifically 2003 version. ""Monitors and optimizes free memory in the background."" Basically, it cleans RAM and also allows you to clear the clipboard" U TurboExplorer TE.exe "Web accelerator - ""TurboExplorer˝ 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer˝ 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing" U TurboMemoryCharger turbomemorycharger.exe Some users swear by memory management utilities such as Turbo Memory Charger but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind N TurboNote tbnote.exe Post-It's on your desktop. Available via Start -> Programs U TurboTop TurboTop.exe "TurboTop - make any window ""Always on top""" X TV Media Tvm.exe CleverIEHooker hijacker variant U TV Scheduler TVSCHL.EXE ProLink PlayTVpro TV tuner software scheduler X TVMD tvmd.exe "Total Velocity - ""Secure commerce company that enables the ±checkout? process for our customers in order to safely and securely purchase our award winning software"". Autointsalling spyware" U TvNow TvNow.exe Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts). X tvs_b tvs_b.exe BroadcastPC adware variant X tvs_b tvs_ln.exe BroadcastPC adware variant X tvs_re tvs_re_inst.exe BroadcastPC adware variant X TVTMD TVTMD.EXE Total Velocity variant - autoinstalling spyware N TVWakeup tvwakeup.exe MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it X Twain image mmp32.exe DailyWinner adware related U TWarnMsg twarnmsg.exe "Toshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops" U Tweak UI ?? "Automatically logs you on if you have Microsoft\'s Tweak UI ""powertoy"" installed" U Tweak UI ?? "Restores settings that can\'t be retained if you have Microsoft\'s Tweak UI ""powertoy"" installed" X Tweak UI "RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup" "SUBWOOFER VIRUS! Note - the real Tweak UI entry for this is ""rundll32.exe tweakui.cpl, tweakmeup""" U Tweak UI 1.33 deutsch ?? "Restores settings that can't be retained if you have Microsoft's Tweak UI ""powertoy"" installed - German version" U TweakDUN tweakdun.exe Utility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets U Tweaki4PU twksup.exe """Tweaki puts several Windows utilities into one easy to use program while adding hundreds of additional tweaks not found in other system tweakers""" U TweakMASTER TMTray.exe TweakMASTER Internet Optimizer U Tweak-Me TWEAK-ME.exe "3rd party version of Miscrosoft'sTweak UI ""powertoy"" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here" U Tweak-xp Tweak-xp.exe Main program for Tweak-XP - a WinXP tweaking utility U twister twister.exe "Twister ""AntiTrojanVirus""" N TwkSCardSrv SCardS32.Exe Used with Towitoko SmartCard Readers for card recognition X twunk service twunk16.exe RBOT.BAT WORM! X twunk_32 twunk_32.exe "BLACKMAL.C WORM! - This malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X Twunk_64 twunk_64.exe System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a Windows\System\1060 directory X tyack drive tyack.pif W32/Rbot-AMT WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. N type32 type32.exe "For MS programmable keyboards. If you disable Intellitype in Startup, any ""Hot Keys"" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them" N TypingSatellite KBOOST.exe Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs X Uate oocs.exe PurityScan/Clickspring adware U UBSShell UBSShell.exe UBS (United Bank of Switzerland) banking software N UC_SMB ucstart.exe Part of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed N uc_start ucstartup.exe "Auto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc" U UCmore XP - The Search Accelerator ?? UCmore toolbar - search accelerator U UD Agent UD.EXE The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs U Ueproc32 UEPROC32.exe Part of Norton Utilities - most likely associated with the Unerase Wizard in older versions N Uidler Uidler.exe Uniloc Titlewave Browser used with some shareware N UIWatcher UIWatcher.exe Ashampoo Uninstaller Suite - installation watcher. Available via Start -> Programs X UKVideo2 ukvideo2.exe Adult content dialler N Ulead Photo Express x.0 Calendar calcheck.exe "Ulead Calendar Checker - part of Ulead Photo Express, where ""x"" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions" N UltimateZip Quick Start uzqkst.exe UltimateZip - file compression utility N Ultra Hal Assistant 4.5 Startup HalAsst.exe Zabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion X Ulubione ?? Ulubione adware component N UMAX VistaAccess vsaccess.exe VistaAccess gives you quick and easy access to scanning functions right from your desktop U UMonit umonit.exe Alerts when USB device is plugged in Y umxagent umxagent.exe Tiny Personal Firewall V4 - main engine Y umxldra umxldra.exe User mode executive module DLL loader - part of Tiny Personal Firewall V4 Y UMXLDRW UMXLDRW.exe Tiny Personal Firewall (pre V4) X un32info un32info.Exe CRYPTER.A trojan infection X UNERI yujixit.exe SDBOT.BOO WORM! U UnHackMe Monitor hackmon.exe "UnHackMe allows you to detect and remove a new generation of 'invisible' Trojan programs called ""rootkits""." X uninstal ?? CoolWebSearch parasite related. X Uninstall#### upd.exe Adult content based screen saver where #### can be any number X Uninstall_TBPS TBuninst.exe /remove "WebSearch toolbar related, HuntBar parasite variant" U Uninstall_WinTools WTuninst.exe "WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable." N UninstallAbility uability.exe UninstallAbility uninstaller U UniPrint SetDfltSettings.exe "Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix." U UniSc Unisc.exe McAfee UnInstaller X Universal USB Service svchost32.exe W32.KELVIR.R WORM! X Unix File Support init3.exe W32/RBOT-ZN WORM! X unldr16 unldr16.exe CRYPTER.C trojan variant infection X unldr32 unldr32.exe Crypter.C trojan variant infection X UnSpyPC UnSpyPC.exe """Spyware remover"" of dubious repute - see the authoritative SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites" Y untray untray.exe Part of Command AntiVirus N uoltray exec.exe Netzero free ISP software - not required N UpConfgVer UpgConf.exe "Panda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function." X UpData wupdata.exe TROJ/IRCBOT-AA TROJAN! X Update ?? LYNDEGG VIRUS! X Update CDUpdater.exe """Carpe Diem"" adult premium rate dialler related" X Update mshtm.exe "Browser hijacker, redirecting to buldog-search.com" X update r00t.exe W32/RBOT-ACO WORM! X UpDate RAuth.exe TROJ/DLOADER-UL TROJAN! X Update Sysupd.exe SLACKBOT VIRUS! X update winis.exe W32/RBOT-VD WORM! X UPDATE = WinUpdater5.0.vbs VBS/Gormlez-A Worm! X Update for Windows ?? W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif N Update Grokster WiseUpdt.exe "Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor" X Update Install Schost.exe GAOBOT.AO WORM! N Update Manager UpdateManager.exe Searches for updates for the Rogers Yahoo!_Browser - can be run manually X update run dos logon.exe variant of the W32/SDBOT WORM! X Update Run MSword LOGON.EXE RBOT.TY WORM! X update service svxhost.exe RBOT-MG WORM! Y Update Service Update.exe Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall X Update Service winu32.exe W32/RBOT-MG WORM! X update service winx.exe variant of the WIN32.RBOT WORM! X Update ver 1.0 Swap.exe W32/SWAP-C WORM! X "Update"" -s setup" Zupdate.exe "B3d Projector foistware - periodically tries to access the internet. (1) Uninstall via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents" X Update.exe ravseuper.exe Troj/QQPass-P TROJAN! N UPDATE~1 UPDATE~1.EXE "Once a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually" X Update32 configs.exe "Hijacker, also detected as the QURL-2 TROJAN!" X UpdateCheck winstall.exe W32/SPYBOT-CY WORM! X UpdateComponent CNF UPD.EXE SPYBOT.GEN VIRUS! X updatelavasoft updatelavasoft.exe "CoolWebSearch related hijacker, redirecting to lalasearch.com" U UpdateManager sgtray.exe "StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups" X UpdateMedia UpdateMedia.exe MediaUpdate foistware X UpdateMgr updmgr.exe SouthBeachTel premium rate adult content dialer. N updatemgr.exe updatemgr.exe "Once a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually" X UPDATEMSN svhost.exe unidentified WORM or TROJAN! X Updater adservernow.exe AdServerNow adware X updater wisvc.exe TROJ/ORSE-A TROJAN! X updater wupdater.exe eUniverse/KeenValue adware X Updater Service Process svhost32.exe AGOBOT.TY WORM! X updater32 winload32.exe "CULT.M WORM! **Note - not to be confused with the valid Windows ""NOTEPAD"" text editor" X Updates msupdate.exe CoolWebSearch parasite related. N Updates from HP ?? Automatically detects an internet connection and downloads any available updates - * is random digit N Updatestats Updatestats.exe "Statblaster - ""Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues""" N updatev01 updatev01.exe Ultra-networks.com software updater/downloader X upddateit winit.exe W32/RBOT-MS WORM! X updmgr rvupdmgr.exe eUniverse/KeenValue adware X Updmgr updmgr.exe eUniverse/KeenValue adware related N UpdReg Updreg.exe Reminder to register Creative Labs SoundBlaster Live! cards X Upgrade Sarvice sxchost.exe variant of the TROJ/TOFGER-I TROJAN! X Upgrade Service sxchost.exe TROJ/TOFGER-I TROJAN! X Upgrade Service winupd.exe TROJ/TOFGER-U TROJAN! X upme ?? W32.MUGLY.F WORM! X Upme DLLMAN.EXE MUGLY.I WORM! X UPnP Manager upnpman.exe variant of the Win32.Agobot.gen WORM! X UPNPService WinSVCservice.exe AGOBOT.UN WORM! U Upromise0 Upromise0.exe Upromise college savings progrram Y UPS ups.exe PowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon) X UPS UPS32.exe -v W32.Femot.O Worm! Y UPSentry 2000 or UPSlim upsd.exe Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss? X UPSUtl web.exe CoolWebSearch parasite related. U Uptimer4 Uptimer4.exe "Uptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things" X UpTimes service WinUp.exe W32/Rbot-AKB WORM! X UpToDate uptodate.exe BrowserAid/BrowserPal foistware X upyxo yujixit.exe SDBOT.BIX WORM! Y URLLSTCK.exe UrlLstCk.exe "Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled""" N URLMAP Urlmap.exe "Installed by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it" Y UrtSvcExe Urt95Svc.exe """Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources""" X USB 2.0 Driver updateXP.exe W32/AGOBOT-QP WORM! X USB 2.0 Driver updateXPSPC.exe W32/AGOBOT-RJ WORM! X USB 2.0 Driver Winsys32.exe W32/AGOBOT-QM WORM! X USB 2.0 Driver winsystem.exe W32/AGOBOT-QS WORM! X USB 2.1 Driver winupdate1.exe variant of the WIN32.RBOT WORM! X USB controller Svcmm32.exe SvcMM backdoor parasite downloader X USB Device servicelog.exe WOOTBOT.CB WORM! X USB Device win32usb.exe W32/FORBOT-BQ WORM! X USB Driver4 UpdateXP2.exe variant of the W32/SDBOT WORM! X USB Driver4 UpdateXP6.exe variant of the W32/SDBOT WORM! X USB Drivers1 msupdate.exe variant of the WIN32.RBOT WORM! X USB Driverz2 msnplus1.exe W32/SDBOT-XQ WORM! X USB Fix 1.1 wuservices.exe variant of the W32/SDBOT WORM! X USB Fixes wuafix.exe W32/RBOT-ABV TROJAN! X USB Hardware Monitoring USBhardware.exe W32/RBOT-NN WORM! X USB Hardware326 Monitoring USBhardware326.exe variant of the W32.SPYBOT WORM! X USB Hardware32c Monitoring USBHARDWARE32C.EXE W32/RBOT-UU WORM! X USB Host Service usbsvc.exe W32/Rbot-GG worm infection Y USB SECURITY DEVICE CoInstaller JupitCo.exe ButterflyMedia USB Flash drive related - required for the password security feature to work. X USB Updates mservices.exe variant of the SDBOT WORM! - see here X USB Updates msfirewalls.exe variant of the WIN32.RBOT WORM! X USB Updates 2 wugfixx.exe variant of the WIN32.RBOT WORM! X USBConfigration2 wmmndir.exe W32/Agobot-SV Worm! X UsbD ?? Troj/Cidra-F TROJAN! X UsbD iexplore32.exe Unidentified worm or trojan X UsbD smss32.exe Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj X UsbD svhost32.exe TROJ_AGENT.IB TROJAN! X Usbd usb_d.exe TROJ/CIDRA-A TROJAN! U USBDetector USBDetector.exe USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware X USBDrives msfirewalI.exe W32/RBOT-ABP WORM! X usbdrv servicetask.exe variant of the W32/SDBOT WORM! X USBHWDRV gam.exe variant of the TROJ/LOWZONE-I TROJAN! X USBHWDRV msdc.exe variant of the TROJ/LOWZONE-I TROJAN! X USBHWDRV sst4.exe variant of the TROJ/LOWZONE-I TROJAN! X USBHWINFO mac.exe TROJ/LOWZONE-I TROJAN! X USBHWINFO mmc.exe TROJ/LOWZONE-I TROJAN! X USBHWINFO sst6.exe TROJ/LOWZONE-I TROJAN! U USBMMKBD usbmmkbd.exe USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information U USBMonit.exe USBMonit.exe Monitors USB ports for insertion of Sandisk USB flashdrives X usbn ?? Troj/Hogil-E TROJAN! X usbn usbn.exe "Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa" Y USBPNP USBPNP.exe SiPix digital camera Twain USB driver N USBTA usbtapnp.exe System Tray access for the BeWAN Gazel 128 USB ISDN adapter X useful-soft svchst.exe "Browser hijacker, redirecting to elite-glsex.net" X user user32.exe Backdoor.Binghe TROJAN! U User Logger UsrLog.exe "UserLogger is a commercial spyware program. It logs keystrokes, programs used and computer ID information. It also captures screenshots, can hide its presence on the computer and can be disguised in the Windows Task list." X User Manager fcllls.exe ZAGABAN-B TROJAN! X User Services usersvc.exe REVCUSS.A VIRUS! X User23.exe DIAL.exe This is a trojan trying to disguise itself as User32.dll X User32 ?? NETTRASH VIRUS! N UserFaultCheck dumprep 0 -u "Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out" X Userinit lsass.exe "variant of the Troj/Dloader-TP TROJAN! - NOTE - this file is placed in the Program Files\Common Files folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X userinit winlogon.exe Troj/Dloader-TP TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder. X UserInit StartUp rpcxuisu.exe variant of the W32/SDBOT WORM! X userint32 userint32.exe "unidentified TROJAN via an Instant Message that says, ""This was cool, check it out here."" Also contains Aurora popups" X USERINTERFACE REPORT3R M0USE.exe MYTOB.HS WORM! X Userinterface Reporter fuuuucktttttt.exe W32/MYTOB-DK WORM! X Userinterface Reporter srv32.exe ISTbar/XXXToolbar adware downloader X ushli sscbltqu.exe Obtained from an MP3 search list site. Also generates random processes on reboot X usrgtway.exe syswrun4x.exe MITGLIEDER.E VIRUS! N USRobotics 802.11g Wireless Network Utility USRWLANG.exe "USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties" N Usrobotics Online Registration ?? Pop-up reminding customers to register their products online at US Robotics Y USRpdA ?? US_Robotics modem driver X Usrr rncr.exe PurityScan/Clickspring adware X Usrr rpen.exe PurityScan/Clickspring adware N USSShReg USSSHREG.EXE Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers N UtilityPro UtilityPro.exe IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions Y UTILsInst ?? For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out N Utopia Angel Angel.exe Calculator for the online Utopia game X uwyrl uwyrl.exe PHEL.A TROJAN! X uwyw.exe yujixit.exe SDBOT.BGB WORM! U V.92 Modem On Hold Ltmoh.exe Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet Y V128IID ?? Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages U va10key va10key.exe Only required if you use the 10 kay bay unit with a Sony Vaio laptop X "Vaganza-XPloit-[User Name]""" ?? W32.GAVGENT.A WORM! Y VAGCtrl VAGCTRL.EXE Vexira Antivirus - virus scanner from Central Command Y VAGuard VAGNT.exe Vexira Antivirus - virus scanner from Central Command U VAIO Action Setup (Server) VAServ.exe "Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB" U VAIO Recovery PartSeal.exe System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere X ValidData ?? RANKY.H backdoor WORM! X VB_run comctl_32.exe Dubious downloader from densmail.com X vb6 vb6.exe W32.MUGLY.D WORM! X VBouncer VirtualBouncer.exe "Virtual_Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code." X VbouncerDL VBouncerInner.exe "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself." X VbouncerDL VBouncerInnerxxxx.exe "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here and here. ""xxxx"" represents 4 random numbers" X VBS.Ipnuker@mm ?? VBS.Nukip Worm! X VBS_AUTO_UPDATE 0548656X.vbs VBS/Gormlez-A Worm! X VBundleOuterDL BundleOuter.EXE "VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs" U VC_Log keylog.exe PaqKeylog is a spyware program that logs keystrokes and can run in stealth mode. If you didn't install this yourself remove it. X VC5MediaPlayer csmss.exe W32/DEDLER-B WORM! N VC5Play VC5Play.exe Virtual CD drive emulator - version 5. Available via Start -> Programs X VCatch Vcatch.exe "CommonSearch Vcatch - ""antivirus"" software which actually bundles spy/adware itself!" X VCatch Premium VCatchpre.exe VCatch antivirus. Considered spyware itself - see here N VCDPlayer VCDPlayer.exe Virtual CD drive emulator. Available via Start -> Programs N vcdplayx vcdplayx.exe CD emulation part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically? U VCDTower VCDTower.exe "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking" N VCSPlayer vcsplay.exe Virtual CD drive emulator. Available via Start -> Programs X VCXD Settings phqg.EXE RBOT.BRF WORM! X Vdat Update lalaa.exe variant of the WIN32.RBOT WORM! N vdtask vdtask.exe Program part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically? N Vegas Palms - Launcher Launcher.exe Vegas Palms on-line cassino X veja_fotos.exe veja_fotos.exe TROJ/MDROP-F TROJAN! U VERBATIM STORE 'N' G verbatim store 'n' go.exe Loads the driver for the Verbatim Store'n'Go? PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium X Verif vxst.exe NOPIR.B WORM! X Veritas Patch veritas.exe W32/RBOT-XT WORM! N Verizon Control Pad cpad.exe Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience U Verizon Online Support Center matcli.exe """matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decide" X vern16.dll ?? DailyWinner adware X vernn16.dll ?? DailyWinner adware U versato versato.exe """Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards" X version ?? DealHelper adware related X version adl_dh.exe DealHelper adware related X Version "Version.exe, manage.exe" JRAUN adware variant Y Vet Alert VETMSG.EXE Computer Associates Vet Anti-Virus software Y Vet Alert vetmsg9x.exe "Computer Associates ""InnoculateIT"" and Vet Anti-Virus virus software" Y Vet Start Up vet98.exevet32.exe "Computer Associates ""InnoculateIT""? and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options" U VetTray vettray.exe "Computer Associates ""InnoculateIT""? and Vet Anti-Virus virus software. System Tray quicklaunch access, not really necessary but only occupies 36k resources" X VFW Encoder/Decoder Settings ?? variant of the LOVGATE WORM! X VGA Startup vgacard.exe variant of the WIN32.RBOT WORM! X VgaDriver RsrVga32.exe TROJ/KEYLOG-AH TROJAN! U VGAUtil G-VGA.exe "Gigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical)" X vid32cntl vid32cntl.Exe CRYPTER.A trojan infection X vidcntl vidcntl.Exe CRYPTER.A trojan infection X Vidcompat Vidcompat.exe GEMA TROJAN! X vidctrl vidctrl.exe Delfin_Promulgate adware variant X Video explored.exe GAOBOT.RF WORM! X Video winamp32.exe W32/AGOBOT-NG WORM! X Video Lan Player VideoLanPlayer.exe W32/RBOT-MY WORM! X Video Manager videomgr.exe PANDEM.C VIRUS! X Video Multimedia Driver ndrives32.exe W32/Rbot-DK worm infection X Video Proces winaps.exe AGOBOT.HD WORM! X Video Process ?? RBOT-LM WORM! X Video Process MS32x16.exe RBOT.RH worm infection X Video Process MSlti64.exe AGOBOT.UE WORM! X Video Process netsvcs.exe AGOBOT.LH WORM! X Video Process sysconf.exe GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS! X Video Process winasp.exe W32/AGOBOT-IS WORM! X Video Services explore.exe W32.Gaobot.GL worm infection X Video Services sys32.exe AGOBOT.PS WORM! X Video Services videol_32.exe W32/Agobot-DM WORM! X Videocntl Videocntl.exe variant of the Win32.GEMA.D TROJAN! X VideoDriver ?? GSPOT20.A VIRUS! X VideoDriver gspotbot.exe SPIGOT.C VIRUS! X VideoDriver videodrv.exe W32.MIMAIL.A WORM! X Videool32 VIDEOL32.EXE AGOBOT.EC WORM! X videoporno.exe videoporno.exe Premium rate adult content dialer N VidSvr vidsvr.exe MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it X vietato.exe vietato.exe Adult content dialler X VIEW POINT DRIVERS phqghum.exe RBOT.BRX WORM! X VIEW POINT DRIVERS FOR WIN32 phqghu.exe variant of the WIN32.RBOT WORM! N ViewMgr ViewMgr.exe "Viewpoint_Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc). Can be run manually via Start -> Settings -> Control Panel by enabling auto-updates temporarily, re-booting and then disabling again" X Virt.exe Virt.exe REMADM-C TROJAN! U VirtuaGirl Vg.exe "VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request..." U VirtuaGirl2 VirtuaGirl2 "VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request..." X virtual wini.exe W32/RBOT-YX WORM! X virtual winit.exe variant of W32.Mugly.A WORM! X virtual winprotect.exe W32.MUGLY.C WORM! U Virtual Access Scheduler VASCHD32.EXE The scheduler for mail and usenet tool X Virtual Bouncer VirtualBouncer.exe "Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here and here" X Virtual CDROM deamon.exe RBOT.VP WORM! N VirtualCloneDrive VCDDaemon.exe "Virtual Clone Drive, part of CloneCD CD/DVD copying sofware; discontinued" N VirtualDrive VDTask.exe VirtualDrive from Farstone - virtual CD drive emulator. Available via Start -> Programs X virtual-machine svchosts.exe W32/RBOT-US WORM! X virtual-machine wini.exe W32/RBOT-WR WORM! X virtual-machine winlogin.exe W32/RBOT-VU WORM! U VirtuaReminder VirtuaReminder.exe "VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments, birthdays, etc." U Virtuele Katja VKatja.exe "Virtuele_Katja - have an attractive moviestar parade on your Desktop and help you search the Dutch ""Gouden_Gids"" business directory too..." X Virus Anti.exe WIN32.SEENBOT.O WORM! X Virus Protect vrsprtc.exe W32/RBOT-APR WORM! X Virus Removal Tool ?? Troj/Tometa-B Trojan! X Virus Scan virscana.exe VIRUS! X Virus_Scanner Virus_Cleaner.exe PANOL VIRUS! X VirusCheckII AVIRCHK.EXE DASMIN VIRUS! X VirusScan Online mcagent.exe TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here Y VirusScan Online mcvsshld.exe McAfee VirusScan On-line. See also McAgentExe entry N visionGS VISIONGS.EXE visionGS webcam software N Vistascan vistascan.exe "Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users, you'll see a scanner icon in the Windows Tray of the Taskbar. Click this icon and a menu opens" X Visual Element FX5 ?? ClearStream Accelerator adware X VisualStudio msorunner.exe variant of the WIN32.TACTSLAY TROJAN! X VITAL BOOT PROCESS taskmngr.exe variant of the WIN32.RBOT WORM! X VITAL BOOT PROCESS taskmnsgr.exe W32/Rbot-VY WORM! X Vital Load Process Spoolsvr.exe RBOT.AIF WORM! X VividGalut VividGalut.exe Adult content related web downloader X vmcleaner gxlib.exe TROJ/SMALL-HS TROJAN! Y VMDFW vmdfw.exe VirusMD Personal Firewall X Vmmon32 vmmon32.exe browser hijacker X vmsnGraber VMSNGRABER.EXE ENVID.B WORM! X vmss vmss.exe "Delfin_Media_Viewer or ""Promulgate"" adware variant" X vmtuner gclib.exe Hijacker - detected by Kaspersky antivirus as Trojan-Clicker.Win32.Small.fh X VnCplUpdate msdm.exe Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisory X vnmispoisn_downloader.exe vnmispoisn_downloader.exe SearchBarCash adware variant U VOBID InstantDrive.exe Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer?s hard drive. Part of InstantCD/DVD burning software Y VOBRegCheck VOBRegCheck.exe Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled X Voltage Manager ?? W32.DREFFORT WORM! X Volume Controller VolumeControl.exe SDBOT.AYI WORM! U Vonage click2call.exe Vonage Voice over IP Internet phone service U VoodooBanshee ?? Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not? N Vortex Tray asp4setp.exe System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel N VortexTray ?? System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel N VoyetraTray vtray.exe This provides an abbreviated Control Group for the Turtle Beach Montego II sound functions/associated with AudioStation 3 and 32 U VPCUserServices VMUSrvc.exe "Part of ""DOS_Virtual_Machine_Additions"" for Microsoft Virtual_PC , software virtualization software that allows you to run multiple PC-based operating systems simultaneously on one workstation. This process provides additional functionalities such as Shared Folders." X VPCUserServices VMUSrvc.exe unidentified TROJAN! U Vpop3 Mail Server vpop3.exe Mail server from Paul Smith Computer Services. Runs in system tray to collect mail. Can be run from a shortcut and if it isn't running then it won't get your email! U vptray vptray.exe System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here Y Vrmon vrmonnt.exe HAURI Anti-Virus Y Vrmon vrmonnt.exe HAURI Anti-Virus Y VrSchedule Vrres.exe HAURI Anti-Virus X vsadmin smrs.exe W32/AGOBOT-RC WORM! X Vsample winxpsock.exe SDBOT.BLK WORM! N vsc32cnf vsc32cnf.exe "Part of Roland's Virtual_Sound_Canvas software synthesizer gives the ""ability to turn MIDI files into a stereo wave file with the touch of a button""" X vscanner spooll32.exe OPTIXPRO VIRUS! N vscvol vscvol.exe "Part of Roland's Virtual_Sound_Canvas software synthesizer gives the ""ability to turn MIDI files into a stereo wave file with the touch of a button""" N VsEcomrEXE VSECOMR.EXE "From McAfee VirusScan up to version 4.x. This executable is responsible for the periodic ""update"" prompts" Y Vshwin32EXE VSHWIN32.EXE From McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs N VSN VSN.exe Software to share photographs across the internet X VSOCheckTask mcagent.exe TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here Y VSOCheckTask MCMNHDLR.EXE Part of McAfee's SecurityCenter and Virusscan Online. Must be enabled for scanning to work N vspdfprsrv.exe vspdfprsrv.exe Visage PDF Printer Y VsStatEXE VSSTAT.EXE From McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs N vTPass vtpassld.exe "Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs, create your own shortcut for the ""vtpass.exe"" file" U VTPreset VTPreset.exe Savage Pro S3 graphics software U vTTIMER VTTIMER.EXE A device driver for VIA/S3G UniChrome IGP graphics controller and VIA/S3G KM400/KN400 graphics card. It is located in \WINDOWS\SYSTEM\ on Windows 95/98/ME and \WINDOWS\SYSTEM32\ on Windows XP and \WINNT\SYSTEM32\ on Windows NT/2000 Viaarena N vTunerStartUp vTuner.exe "vTuner - ""an easy way to find and listen to radio and TV broadcasts over the Internet""" X vuaaa reg.exe variant of the WIN32.RBOT WORM! X VVSN VVSN.exe SaveNow adware X W1NTASK taskgmr.exe W32/MYTOB-BZ WORM! X w32 w32.exe SOKEVEN VIRUS! X W32.Scran Scran.exe W32.Narcs WORM! X w32alanis mope.scr SINALA VIRUS! X W32data eworo.exe variant of the WIN32.RBOT WORM! X W32Load ?? CASPID VIRUS! X w32sup w32sup.exe Adult content dialler X W32Tc WTC32.scr VOTE.D or VOTE.K VIRUSES! X W3KNetwork ?? Advertising spyware. Check here for more info on this particular one Y W75P2PSERVER W75P2PS.EXE Printer utility which is required in order to make the printer work correctly U wait4IP wait4IP.exe Packard Bell net2Plug allows you to network PCs anywhere in your house U wallchgr.exe wstart Wallchgr.exe Blue Tree Software N Wanadoo Messenger.exe Wanadoo Messenger.exe Wanadoo ISP instant messenger client Y WanMPSvc WanMPSvc.exe "An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn?t help" X WAPI ?? PurityScan/Clickspring adware X Wardo syslaunch.exe ADLCICKER.G VIRUS! X WareOut WareOut.exe "Malware masquerading as a spyware and dialer remover, see here" N warez warez.exe Warez P2P client N war-ftpd.exe WAR-FTPD.EXE War FTP Daemon from JGAA's Internet - FTP client U Warner warner.exe "Also known as ""CyberWarner"". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files" U Warnet warnet.exe Warnet - system cleanup software U Warning: do not remove it! fpplock.exe "Part of Folder Password Expert by ZQS Software Team - ""a software program to restrict access to the folders that contain your sensitive data""" N WARSVR war-ftpd.exe """War FTP Daemon - the original free FTP server for windows""" U WashAndGo - Cleanup of old Backupfiles checker.exe WashAndGo - temp file cleaner N Washer washer.exe "Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG" N Washerie.exe washerie.exe "Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs" U washindex washidx.exe "Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG" X Wast wast.exe Grokster ads updater X wast wast2.exe Grokster ads updater N Watch watch.exe Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted N Watch Dog Program watchdog.exe For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do N Watchdog Watchdog.exe "Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage" N WaveTop Launcher WaveTop.exe "WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98" N WaveTop Receiver 1 ?? "WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98" N WaveTop Receiver 2 ?? "WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98" N WaveTop Upload Manager ?? "WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98" N Wbiff Wbiff.exe Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received N WCESCOMM WCESCOMM.EXE Active sync for use with Windows CE based palm PC X WCESMngr spoolsb.exe W32/AGOBOT-QZ WORM! X WCESMngr WCEMNGR.EXE W32/AGOBOT-QX WORM! U wcmdmgr wcmdmgrl.exe Checks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information N wcmdmgr.exe wcmdmgr.exe "It will periodically contact Wild Tangent servers to see if an update is available for your system and allows us to make the product exceptionally reliable. You can control its behavior, or disable it completely, inside your Windows Control Panel. Note that Wild Tanget's privacy policy used to stae they also collect and share individuals information, but this is no longer the case" U WCOLOREAL coloreal.exe "Makes colours sharper and brighter, but will only work with coloreal capable monitors" X WCPC wintsvcc.exe PurityScan/Clickspring adware X WCPI wintsvit.exe PurityScan/Clickspring adware X WCPS ?? PurityScan/Clickspring adware X WCPT wintsvtr.exe PurityScan/Clickspring adware U WD Button Manager WDBtnMgr.exe Button manager installed with a western digital external disk drive. Allows you to back up your system with one click. X WDInfo wdinfo.exe DOWNLOADER.DLUCA.B TROJAN! X WDNS SYSTEM nibie.exe W32/Mytob-BY WORM! X WDNS SYSTEM skybotx.exe W32/Mytob-BY WORM! X WDNS SYSTEM wdns33.exe MYTOB.EV and W32/Mytob-BY WORMS! X wdskctl ?? Waltun-A trojan infection X wdskctl wdskctl.exe IePlugin adware X wdwctrl wdwctrl.exe Troj/Dload-DC TROJAN! N WEATHER WEATHER.EXE "Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs" N WeatherCast Weather.exe Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight X WeatherOnTray WeatherOnTray.exe Hotbar' s Weather Forecast tool for your desktop X Weatherscope Weatherscope.exe WeatherScope software - bundles Gain/Gator adware N WeatherWatcher ww.exe WeatherWatcher - weather reporting in the System Tray X web ?? variant of the Win32/TrojanDownloader.Easto.A TROJAN! X WEB DRIVERS FOR WIN32 phqgh.exe variant of the WIN32.RBOT WORM! X Web Offer ezStub.exe eZula TopText adware X Web Offer EZSTUB22.EXE eZula TopText adware X Web Offer vl_ezstub.exe eZula TopText adware X Web Service ?? ADMINCASH TROJAN! X Web Service sm.exe W32/BUBE-F VIRUS! Y web3trap web3trap.exe "PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc?" X webalize webalize.exe Searchcentrix hijacker N WebArmyKnife WAK.exe "Web_Army_Knife , a suite of web site developer's tools." X webassist webassist.exe Adware popup generator N WebcamRT.exe WEBCAMRT.exe For Logitech Web Cams. Not required - camera works fine without it X Webcelerator webcel.exe Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here X WebCheck WebCheck.pif CONE.C or CONE.F VIRUSES! X WebCpr0 WebCpr0.exe Web_CPR/TopMoxie adware X Webdav.exe webdav.exe IRC DDoS bot which gives the hacker full control over your system X WebHancer Agent whagent.exe System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here X webHancer Survey Companion whSurvey.exe "WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there" X "WebInstall, WebInstall2" WebInstall.exe ClipGenie adware downloader N WebKey WebKey.exe WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet N WebLink WebLink.exe "Softex WebLink is a ""cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a a persistent link.""" N WebOutfitterTray sttray.exe Intel WebOutfitter service System Tray icon N Webposition Gold 2 wpsche~1.exe Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines X WebRebates0 WebRebates0.exe WebRebates adware X WebRun ?? ADWARELOADER TROJAN! X WebRun msxmidi.exe ADWARELOADER TROJAN! X WebRun sm.exe ADWARELOADER TROJAN! X WebRun web.exe Adwareloader TROJAN! X WebRun wmplayer.exe ADWARELOADER TROJAN! U websaverlive websaverlive.exe WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle X WebSavingsfromEbates WebSavingsfromEbatesrun.exe """Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows" X WebSavingsFromEbates0 WebSavingsFromEbates0.exe """Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows" N WebScan DEFSCANGUI.EXE eAcceleration Stop-Sign related; not recommended; see note N webscan stopsignav.exe eAcceleration Stop-Sign related; not recommended; see note Y WebScanX WebScanX.exe "From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc" X websearch ?? """Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows" X WebSecureAlert WebSecureAlert.exe "WebSecureAlert. ""Can help protect your browser security and privacy""; however, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior" X WebSecureAlert WebSecureAlert.exe WebSecureAlert software - - bundles Claria/Gain/Gator adware U Webshots Launcher.exe "Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web." U Webshots websho~1.exe "Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web." U Webshots Webshots Tray.exe "Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web." X Website Administrator Info webadmin.exe W32/FORBOT-FY WORM! X WebSpecials ?? WebSpecials adware downloader X Websx ?? Adult content dialler - where ***** are random Y Webtrap webtrap.exe Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating Y WebTrapNT.exe WebTrapNT.exe Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements U WebWasher wwasher.exe Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs X WeirdOnTheWeb WeirdOnTheWeb.exe Adware.WeirdOnTheWeb ADWARE! N Welcome Welcome.exe Launches the Welcome to Windows tutorial on boot up X wersds doriot.exe JECT.C VIRUS! X wesumu wiustv.exe Troj/QQPass-L TROJAN! N WetSock wetsock.exe RoboMagic Wetsock - weather reporting in the System Tray N WFGStartup WFGStartup.exe "World Weather. ""This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones""" U wfips iphider.exe "ICQ (messaging/chat program) anti-bomb software. ""WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed."" For more information about ICQ bombs see here" N WFXCTL32.EXE WFXCTL32.EXE From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs Y wfxsnt40 wfxsnt40.exe WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax Y WG511WLU WG511WLU.exe Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card U WGWLocalManager WGWLocalManager.exe "Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system" X whagent whagent.exe System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here U WhatPulse WHATPU~1.EXE "WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day." U WheelMouse 4DMAIN.EXE "Mouse software for ""Fellowes"" Wheelman mouse. Has caused some users problems but shouldn\'t be needed if you don\'t use any enhanced features it may provide" U WheelMouse AMOUMAIN.EXE A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features X WhenUSave Save.exe SaveNow adware X WhenUSearch Search.exe SaveNow adware X WhenUSearchWHSE whse.exe SaveNow adware X Whistler whismng.exe WHISTLER-F TROJAN! X Whitechix brightx.exe variant of the W32/SDBOT WORM! X Whvlxd Whvlxd.exe W32.LXD.Mirc VIRUS! N WIAWizardMenu ?? Still Image Class Installer - installed with a webcam X Widnows Xp Web scan xpscan.exe variant of the W32/SDBOT WORM! X wifeman wifeman.exe Unidentified malware N WildTangent CDA ?? WildTangent on-line games related; not required for the games to work. U WildTangent Web Driver updater wcmdmgrl.exe Checks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information N Wildwire Monitor WWMon.exe This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem N Willow Road WillowRoad.exe Willow Road Screen Saver X win ?? SEEKER.K VIRUS! X WIN ehshell.exe W32/Mytob-CQ Worm\Trojan! X WIN windows.exe W32.Reatle.C WORM! X win xwinxrpc.exe AGOBOT-MV WORM! X win xwinxrpc32.exe W32/Agobot-MV WORM! U Win Chimes winchi~1.exe WinChimes - enhancement software for the system clock that runs in the system tray X Win Comm WinComm.exe WebRebates related adware X Win Command command32.exe AGOBOT.XQ WORM! X win ctl app wuctl.exe variant of the W32/SDBOT WORM! X Win Drivers SSL hpws.exe WIN32/IRCBOT.67098 WORM! X Win Drivers SSL TASKMAN4.exe variant of the WIN32.RBOT WORM! X WIN HOST PROCESS WIN HOST PROCESS.EXE KEYLOGGER.CLONE VIRUS! X Win l5oahder winampa.exe variant of the AGOBOT/GAOBOT WORM! X Win Microsoft 98 win14.exe W32/RBOT-AKX WORM! X Win Microsoft Config wnmsconfig.exe variant of the WIN32.RBOT WORM! X Win Patch ntldr.exe W32/SDBOT-GS WORM! X Win Secure Update ?? W32/Rbot-AGI WORM! X Win Server winserv.exe IMISERV.A TROJAN! X Win Server Updt pxckdla.exe IEPlugin adware component X Win Server Updt winserver.exe variant of the WIN32.IMISERV TROJAN! X Win Server Updt wupdt.exe IEPlugin adware X Win TaskLoader msgmr.exe W32.MYTOB.L WORM! X win update wapdate.exe variant of the WIN32.RBOT WORM! X win update wupda32.exe SDBOT.J worm infection X Win Updater WINUPDATER.EXE RBOT.IP WORM! X Win Updator Services ctfnom.exe variant of the W32/WOOTBOT WORM! X WIN USB 2.0 usbsystem.exe unidentified WORM of TROJAN! X WIN USB 2.0 winusb.exe variant of the WIN32.RBOT WORM! X Win USB 2.0 USB Driver HPPrint.exe SPYBOT.DNB WORM! X WIN USB SUPPORT grxsrv.exe variant of the WIN32.RBOT WORM! X Win WinAmp winamp.exe RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) X Win_api_driver system.exe REVIRD VIRUS! X Win_Library INISvc.exe ANARCH VIRUS! X win_spool2 win_spool2.exe TROJ_SCKEYLOG.B TROJAN! X win_upd.exe WINdirect.exe MITGLIEDER.M VIRUS! X win_upd2.exe WINdirect.exe BEAGLE.AO WORM! X Win_vader Win_vader.vbs INVASION.A VIRUS! U win16.dll win16dll.exe "Screenspy captures screenshots silently. If you didn't install this yourself, remove it." X Win2Drv ?? WINTOO VIRUS! X Win32 arsetup.exe WIN32.SPAZBOX.A TROJAN! X Win32 Game.exe.vbs VBS.Scafene WORM! X win32 Setup_32.exeWinSetup.exe EVILBOT.B VIRUS! X win32 Shakira_1997_Part_1_.Mpeg_.scr MYLIFE.N VIRUS! X Win32 system32.vbs VBS.SWERUN VIRUS! X WIN32 WIN32.EXE WIN32/MYTOB.AD WORM! X Win32 Win32.exe ISRAZ.A VIRUS! X win32 winhost.exe W32.BROPIA.J WORM! X win32 winsrv32.exe ADUENT VIRUS! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites X Win32 Bios Winbios.exe W32/SEMAPI-A WORM! X Win32 Configuration dllhelp.exe SDBOT.UL infection X Win32 Configuration mplayer.exe W32/FORBOT-BZ WORM! X Win32 Configuration videosd32.exe WORM_SDBOT.TT X WIN32 DDOSSER dos.exe W32.Kelvir.F WORM! X Win32 Debug Manager Win32Debug.exe variant of the W32/WOOTBOT WORM! X Win32 Device Loader Win32ldr.exe variant of the GAOBOT/AGOBOT WORM! X Win32 Driver svchosts.exe W32/Forbot-FD WORM! X Win32 Drivers winlogons.exe W32/Forbot-FG WORM! X Win32 DRK Driver wdrk32.exe WOOTBOT.CY WORM! X Win32 exe file winstr32.exe W32.SpyBot worm variant X Win32 Explorer Explorer32.exe StartPa-MN homepage hijacker X Win32 Firewall Driver winfw.exe variant of the WIN32.RBOT WORM! X Win32 FRT Driver msfr32.exe variant of the W32/FORBOT WORM! X win32 internet server winserver.exe TROJ/DERMON-D WORM! X Win32 Kernel core component Kernel32.pif MOKS VIRUS! X Win32 LSA Driver lsa.exe W32/Forbot-FJ WORM! X Win32 Ms Auto Updater AutomsUPD.exe Win32.Rbot worm variant X Win32 NDIS Driver xpndis.exe variant of the WIN32.RBOT WORM! X Win32 Network Driver crss.exe variant of the AGOBOT/GAOBOT WORM! X Win32 NT Adv Services taskmngr.exe W32/Rbot-ADE WORM! X Win32 nvc nvcva.exe W32/RBOT-ABF WORM! X Win32 NVIDIA Driver MSPMSPSU.EXE variant of the WOOTBOT.Y WORM! X win32 regedit msn32.exe unidentified WORM or TROJAN! X Win32 Rundll Loader Rundll32.exe "SDBOT.A WORM! Note: Rundll32.exe is a valid Windows application called ""Run a DLL as an App"" and stored in the C:\Windows directory. The version created by this virus is saved in the C:\Windows\System directory" X Win32 Secure msconfigsvc.exe variant of the W32/SDBOT WORM! X Win32 Service bazzi.exe AHKER.E WORM! X Win32 Services Config winwkys.exe RBOT.BKY WORM! X Win32 Services1 wuamngr1.exe W32/Sdbot-PV worm infection X Win32 Src Service win32src.exe W32/RBOT-SX WORM! X Win32 SSL Driver winssv.exe W32/FORBOT-BH WORM! X Win32 Svchosts Driver svchosts.exe W32/Forbot-FO WORM! Note: (svchosts.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X win32 system server winserver.exe TROJ/DERMON-C TROJAN! X Win32 System Spool spoolsvc.exe WORM_SDBOT.UK X Win32 Test bleatest.exe variant of the WIN32.RBOT WORM! X Win32 Usb Driver AvpG.exe W32/FORBOT-BX WORM! X Win32 USB Driver mvsecn.exe W32/FORBOT-BK WORM! X Win32 Usb Driver svhosint32.exe W32/FORBOT-BE WORM! X Win32 Usb Driver usb32.exe W32/SDBOT-OV WORM! X Win32 USB Driver winxpinit.exe SDBOT.AA WORM! X Win32 USB Driver winxpinit.exe BACKDOOR.SDBOT.AA TROJAN! X Win32 USB2 wins32.exe variant of the WIN32.RBOT WORM! X Win32 USB2 Driver msn.exe W32/FORBOT-EX WORM! X Win32 USB2 Driver smsc.exe SDBOT.FO WORM! X Win32 USB2 Driver svchosting.exe W32/Forbot.J or SDBOT.HU worm infection X Win32 USB2 Driver sys32.exe WORM_WOOTBOT.X X Win32 USB2 Driver sys32snd.exe W32/Forbot-AN worm infection X Win32 USB2 Driver syscfg32.exe W32/FORBOT-R WORM! X Win32 USB2 Driver updatemgr.exe variant of the W32/FORBOT WORM! X Win32 USB2 Driver win32usb.exe W32.Spybot.DHV worm X Win32 USB2 Driver wind32.exe W32/Forbot-AH worm X Win32 USB2 Driver winsnd32.exe variant of the W32/SDBOT WORM! X Win32 USB2 Driver winupdate.exe AGOBOT.YE WORM! X Win32 USB2.0 Driver 386.exe W32.IRCBot.D worm X Win32 USB2.0 Driver rundll16.exe WORM_WOOTBOT.H X Win32 USB2.0 Driver service.exe W32/SDBOT-QF WORM! X Win32 USB2.0 Driver w32usb2.exe WORM_SPYBOT.DN X Win32 USB3 Driver win32tool.exe variant of the WIN32.RBOT WORM! X Win32 Wmls Driver winitr32.exe WOOTBOT.B worm X Win32 Word Services msword32.exe variant of the WIN32.RBOT WORM! X win32.exe win32.exe STARTPAGE VIRUS! X Win32.exe Win32.exe BKDR_AWQ.A TROJAN! X win32_i lptt01 or win32_i ml097e win32_i.exe "Variant of the RapidBlaster parasite (in a ""win32_i"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X win32app winpup32.exe ADCLICKER VIRUS! X Win32BaseServiceMOD Wintask.exe NAVIDAD VIRUS! X win32beta win32sys4.exe Troj/Banker-DA Trojan! X win32clf win32clf.exe unidentified VIRUS! X Win32dll Win32dll.exe BANPAES VIRUS! X Win32DLL Win32DLL.vbs LOVELETTER (I LOVE YOU) VIRUS! X WIN32DS clienttimer.exe Eziin adware X Win32G Kernel32.comScandisk.com ESTRELLA VIRUS! X win32gb win32gb.exe All-In-One-Telcom (adult content dialler) variant X Win32Host Process webemir.exe Troj/Turgen-A TROJAN! X win32info win32info.exe Win32.Dluca.C downloader trojan infection X win32ini systroy.exe IRC.ALADINZ.C VIRUS! X WIN32io clienttimer.exe Eziin adware X Win32R Server.com ESTRELLA VIRUS! X WIn32S Java DLL kavsvx.exe W32/AGOBOT-RZ WORM! X win32servv load.exe unidentified trojan or adware X win32servv ms1.exe iSearch adware component Y WIN32SL Win32sl.exe "Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work" X WIN32SNDS banc.exe unidentified WORM or TROJAN! X Win32system ?? DDV.B VIRUS! X Win32System win32s.exe W32.Mydoom.V WORM! X Win32SystemMonitor ?? browser hijacker X Win32SysV xin.exe W32/FORBOT-EO WORM! X win32us win32us.exe All-In-One-Telcom (adult content dialler) variant X win32usbd ssrs.exe W32/RBOT-RA WORM! X WIN32WN system_wc.exe Eziin adware X Win386 sp32.dll Homepage hijacker. Not a dll but a regfile in disguise X Win386 Win386.exe GOSUSUB VIRUS! X WIN3S2SNDS winabsmod.exe "TrojanDownloader.Win32.Agent.dn infection; known to BOClean as ""CWS/INDEX"" , ""shuts down anything that wants to open and is used as a spam proxy as well""" X Win64 Compatibility Check load win64.drv CoolWebSearch parasite related. X WIN95DEFVIEW csmss.exe TROJ/DEDLER-D TROJAN! X win98 DNS wingrd.exe variant of the WIN32.RBOT WORM! X WinAC v4 klsuicbn.exe W32/FORBOT-CS WORM! U Winacsr Winacsr.exe AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself! X winactive WINACTIVE.EXE Active variant of LOP.com hijacker - see here X WinActiveJ WinActiveJ.exe ROTARRAN VIRUS! X Winad Client Winad.exe WinAd adware by eXact Advertising X WinAdCnt.exe WinAdCnt.exe TROJ/BANKER-BU TROJAN! X winadm winadm.exe Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! X Winahlp.exe Winahlp.exe variant of the VAGRNOCKER VIRUS! X winallap winallap.exe DELF.E VIRUS! X winallapu winallapu.exe DELF.E VIRUS! X winamp winamp.exe AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) X Winamp winamp.hta re-directing to adult content sites. Note - this isn't the real Winamp X WinAMP winamp62.exe W32/SDBOT-WN WORM! X Winamp Agent winamp.exe W32/POEBOT-I WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe) X Winamp media player winapa.exe Unidentified worm U Winamp to Google Talk winamptogoogletalk.exe "Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status" X Winamp Update yhn.exe W32/Sdbot-ACR WORM! U Winampa WINAMPa.exe Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs X Winampa winampa.exe W32/AGOBOT-GS WORM! X Winampa Agent WINAMPA.EXE "W32/SPYBOT-BR WORM! - NOTE: this is NOT the Winamp Media Player, as described here" X WinAmpAgent Msexploren.exe "TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here" X WinAmpAgent Shch.exe "TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here" X WinAmpAgent svchst.exe "TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here" X WinAmpAgent Winagent.exe "TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here" X WinAmpAgent winagent.exe WIN32.TACTSLAY.B TROJAN! U WinampAgent WINAMPa.exe Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs X WinAntiSpyware 2005 was5.exe "WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""WinAntiSpyware 2005""" X WinApi winapix.exe variant of the TIBSER.A downloader TROJAN! X WINAPLOGUPD WINAPLOGUPD.EXE W32/CAPSIDE-C WORM! X Winapp winpup32.exe Produces popup ads to adult content sites X WinApp32 msapp.exe RSBOT VIRUS! U WinAppLog svchost.exe "StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\StingWare folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X WinAuth winlogon.exe "Hijacker, also indentified as the STRTPAGE.BE TROJAN!" X WinAwk WinAwk.exe 2/SDBOT-AYF WORM! U WinBackup Scheduler Wbsched.exe LIUtilities WinBackup scheduler - backup software U WinBar WinBar.exe """WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls""" X winbas12 winbas12.exe "Adware, CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X winbas12 winbas12.exe "Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du" X Winbed winbed.exe Hijacker X winbin32 win32exe.exe W32/RBOT-ZL WORM! X winbot winbot.exe Troj/Midrug-A TROJAN! X WIN-BUGSFIX WIN-BUGSFIX.EXE LOVELETTER (I LOVE YOU) VIRUS! X WinCheck WinCheck.exe PWS-CY VIRUS! X winchost winchost.exe Troj/Dloader-PV TROJAN! N WINCINEMAMGR WINCIN~1.EXE WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs N WINCINEMAMGR WinCinemaMgr.exe WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs X wincmap wincmapp.exe CasClient adware variant - also known as Trojan.Cmapp X wincms wincms.exe "RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty." X WinCSRSS MSGRT32.EXE Troj/Rewindo-A TROJAN! X WINCX wincore332.exe W32/AGOBOT-MG WORM! X Wind Logd File servicelogd.exe variant of the WIN32.RBOT WORM! X wind.exe wind.exe "This Trojan allows the infected computer to be used as a proxy mail server. Trojan horse Proxy.5.AP, TrojanProxy.Win32.Mitglieder.bd More info on TrojanProxy" X WIND0WS mella.bat VBS.ALLEM WORM! X WIND0WS WIND0WS.exe WORM_SPYBOT.DQ X Wind0ws Sharing ssprotecter.exe W32/RBOT-AHW WORM! N WinDates windates.exe "WinDates is a calendar, date organizer and event reminder program from Rockin\' Software" X windbs winxtc.exe W32/Agobot-WD WORM! X Winde winde.exe DLUCA VIRUS! X windef Win32sp.vbs -quiet W32.ANPES WORM! X Windeows NetStart Service2 tesakrmger.exe W32/Rbot-AMY WORM! X windhost.exe osrwin32.exe BANKER-CB TROJAN! X windhost.exe oswin32.exe "unidentified password-stealing ""Banker"" TROJAN!" X windhost.exe windhost.exe TROJ/BANKER-BV TROJAN! X windhost.exe winos.exe TROJ/PWSAGENT-A WORM! X windir winrun.exe WINBUR.B VIRUS! X Windll Windll.exe TRYNOMA VIRUS! X windll windll32.exe ASTEF or RESPAN VIRUSES! U WINDLL WSYS.EXE "STARR key logger. ""It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren\'t keyed in, all web sites visited, every program launched including the path to that program, and more""" X Windll.exe Windll.exe STEALER VIRUS! X WinDll32 _WIN32.EXE LEGMIR.AQ TROJAN! X Windll32 Windll32.exe MSNPWS VIRUS! X windllsys32.exe windllsys32.exe variant of the Win32.Mitglieder.by TROJAN! X WinDNS windns32.exe GAOBOT.WX WORM! X Windoes Kernel kernel32.exe KICKIN.A (or CYDOG.C) VIRUS! X Window explore.exe GAOBOT.ADW WORM! X Window Loader Dos32.exe GAOBOT.AO WORM! X Window Monitor winmon32.exe SDBOT.RT worm infection X Window service ?? W32/RBOT-ACH WORM! U Window Washer wwDisp.exe "Webroot Window Washer - ""Wash away online and offline traces of PC and Internet activity to protect your privacy and improve PC performance""" X window.exe window.exe MITGLIEDER.H or MITGLIEDER.J VIRUS! X Window_Protect winsi32.exe variant of the WIN32.RBOT WORM! X window2 ssvchost.exe IRCBOT.H VIRUS! U WindowBlinds wbload.exe WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins X WindowEnhancer Winex.exe SCbar foistware variant U WindowFX wfxload.exe "Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows""" X windown wiusyt.exe Troj/QQPass-M TROJAN! X WindowRegKey update wins.exe SPYBOT.I WORM! X windows ?? AIMWIN VIRUS! X Windows explorer.exe unidentified VIRUS! Note - this is not the valid Windows Explorer (explorer.exe). It was found in the C:\Windows directory on a WinNT machine and the wheras the valid explorer.exe would be found in C:\Winnt X Windows gearsec.exe W32/STUBBOT-B TROJAN! X windows hkey.exe GAOBOT.AFW WORM! X Windows Kernel32.exe TENDOOLF VIRUS! X Windows msdos98.exe PWSTEAL VIRUS! X Windows run.exe W32.SPYBOT.OFN WORM! X Windows services.exe "Unidentified worm or trojan. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!" X windows system copy.exe W23.SALGA.A WORM! X Windows system.exe W32.Spybot.OBB WORM! X WINDOWS windows.exe Troj/Monbot-A TROJAN! X Windows Windows.exe "KAZMOR, BOBBINS& ALADINZ.D VIRUSES!" X Windows .Net Manager localsvc.exe Troj/Dloader-NY Trojan! X Windows .Net Manager netsvc.exe Troj/Dloader-NY Trojan! X Windows .Net Manager spoolsvc.exe Troj/Dloader-NY Trojan! X Windows .Net Manager svcadmin.exe Troj/Dloader-NY Trojan! X Windows .Net Manager svcman.exe Troj/Dloader-NY Trojan! X Windows .Net Manager svcrun.exe Troj/Dloader-NY Trojan! X Windows .Net Manager tcpsvc.exe Troj/Dloader-NY Trojan! X Windows .Net Manager websvc.exe Troj/Dloader-NY Trojan! X Windows 128 Module win128.exe W32/FORBOT-ES WORM! X Windows 2004 CSRSS.exe Troj/Banker-DY trojan infection X Windows 32 Editor Win32edit.exe WOOTBOT.GQ WORM! X Windows 32 Rescue win32resc.exe W32/FORBOT-EU WORM! X Windows 32 Update Windows-Update.exe variant of the WIN32.RBOT WORM! U Windows Accelerators setup.exe "KeySpy keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove" X Windows AdControl WinAdCtl.exe WindUpdates adware variant X Windows AdService WinAdServ.exe WindUpdates WinAdServ adware variant X Windows AdStatus WinStat.exe W32.Bleshare!dr VIRUS! X Windows AdTools WinAdTools.exe WindUpdates Windows_AdTools adware X Windows Anti-Virus Built 32 AntiVirus32.exe SDBOT-BG WORM! X Windows API Control Task apitsk32.exe W32.MYTOB.HI WORM! X Windows Application Layer walg32.exe AGOBOT.ATN WORM! X Windows Application Layer Gateway walg32.exe W32/AGOBOT-AAZ WORM! X Windows ASN Service ?? W32/AGOBOT-TC WORM! X Windows auto update bazzi.exe AHKER.E WORM! X Windows auto update LSASS.exe "W32.AHKER.G WORM! - Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!" X windows auto update msblast.exe BLASTER.B VIRUS! X windows auto update penis32.exe BLASTER (or MSBLAST.A) VIRUS! X Windows Auto Update winupdater.exe SDBOT.TF WORM! X Windows Automatic Update wuamgrder.exe variant of the WIN32.RBOT WORM! X Windows Automatic Updates dvldr.exe RBOT.MF WORM! X Windows AutomaticUpdater runddls.exe variant of the WIN32.RBOT WORM! X Windows Automation msdspr.exe SOLAME.A VIRUS! X windows automation mslaugh.exe BLASTER.E VIRUS! X Windows Autostart Loader notepad32.exe variant of the WIN32.RBOT WORM! X Windows Ba?lang?? Dosyas? sistem.exe MUZK VIRUS! X Windows backup systemss.exe W32.SpyBot worm variant X Windows Backup Configuration IEXPLORER.exe GAOBOT.AZ WORM!. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe) X Windows Bootup ms-wks32.exe W32/Rbot-AFM Worm! X Windows Bootup Systemwks32.exe variant of the WIN32.RBOT WORM! X Windows Client Service 32 csrss.exe W32/Rbot-ALB WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X Windows Client/Server Runtime Server csrs.exe RBOT.KD WORM! X Windows Command wincmd.exe RBOT.ANV WORM! X Windows Communicator wincomm.exe AGOBOT-BH WORM! X Windows Compliant ?? W32/Rbot-IR worm infection X Windows Compliant winole.exe variant of the W32/SDBOT WORM! X Windows Config SSYS.EXE W32/Spybot-DA worm infection X Windows Config wins.exe SPYBOT.JR WORM! X Windows Config Loader Wincfg32.exe SILVERFTP VIRUS! X Windows Config Manager winconf.exe W32/RBOT-AIT WORM! X Windows Configuration wincfg32.exe W32.Mytob.ED WORM! X Windows Configuration wsys32.exe GAOBOT.FB WORM! X Windows Console Monitor ?? W32.Kedebe WORM! X Windows Console Monitor gcasAV32.exe W32/KEDEBE-A WORM! X Windows Control Control.exe "Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!" X Windows ControlAd WinCtlAd.exe WindUpdates WinCtrlAd adware X Windows CPU host winbog32.exe variant of the WIN32.RBOT WORM! X Windows Data Server ?? W32/Spybot-DS WORM! X Windows Data Server autodisc.exe W32/SPYBOT-CB WORM! X Windows Database wiinsvc.exe W32/AGOBOT-RU WORM! X Windows Database WinDat.exe unidentified WORM or TROJAN! X Windows Dcom2 Fix mscom32.exe W32/RBOT-QT WORM! X Windows DDE Loader windde32.exe W32/SDBOT-UZ WORM! X Windows debug logging winlogg.exe W32/RBOT-OY WORM! X Windows debug logging winloggs.exe W32/RBOT-QN WORM! X Windows Debugger msdbg32.exe variant of the WIN32.RBOT WORM! X Windows Debugger windbg.exe unknown worm or trojan infection! X Windows Debugger windbg32.exe W32.Zotob.L WORM! X WINDOWS DENEME deneme.exe W32/Mytob-CR WORM! X Windows Desktop Controler windesktop.exe W32/SDBOT-XH WORM! X Windows Desktop Daemon winpadg.exe variant of the W32.SPYBOT WORM! X Windows Dialup Service dialup.exe AGOBOT.AAH WORM! X Windows DLL Host dllhost32.exe unidentified WORM or TROJAN! X Windows DLL host winupd32.exe variant of the W32.SPYBOT WORM! X Windows DLL Loader defragfat32.exe W32/SDBOT-SS WORM! X Windows DLL Loader defragfat32abc.exe W32/RBOT-RG WORM! X Windows DLL Loader defragfat32pi.exe W32/RBOT-QQ WORM! X Windows DLL Loader defragfat32z.exe W32/EGGDROP-G WORM! X Windows DLL Loader defragfat39.exe W32/POEBOT-C WORM! X Windows DLL Loader defragfatx.exe W32/POEBOT-F WORM! X Windows DLL Loader defragfatz.exe W32.LINKBOT.H WORM! X Windows DLL Loader PASSCFG16.EXE W32/Domwis-C IRC backdoor worm infection X Windows DLL Loader "RUNDLL16.EXE, SYSCFG16.EXE" DOMWIS VIRUS! X Windows DLL Loader rundll32.exe "W32/WHIPSER-B WORM! - NOTE: This particular rundll32.exe file is placed in the Windows\System folder, wheras the legitimate Windows file of the same name is located in the Windows folder on Win 98 or ME systems, and in Winnt\System32 or Windows\System32 in Windows 2000 or XP" X Windows DLL Loader SYSCFG16.EXE W32/Domwis-N WORM! X Windows DLL Loader wdevice.exe variant of the W32/SDBOT WORM! X Windows DLL Loader WINCFG32.EXE W32/Agobot-TE WORM! X Windows DLL Services system.exe TSPY_AGENT.H spyware. X Windows DLL Services winsvc32.exe W32/RBOT-ZF WORM! X Windows DLL Tracker spoolsrv.exe variant of the W32/WOOTBOT WORM! X Windows DLL Verifier xptl.exe variant of the WIN32.RBOT WORM! X Windows DNS windns.exe W32/SDBOT-XU WORM! X Windows DNS Daemon windnsd.exe WOOTBOT.AS WORM! X Windows Domain Name Drivers windns.exe W32/FORBOT-EP WORM! X Windows Download Manager windlmngr.exe unidentified TROJAN! X Windows Drive Compatibility System32Driver32.exe SUPOVA.Z VIRUS! X Windows Driver winxpdriver.exe WOOTBOT.EE WORM! X Windows Driver Adapter svchost.exe /driver-auto W32/Antinny-K WORM! X Windows Driver Services msdrvs32.exe WORM_WOOTBOT.L X Windows driver update dmsvc32.exe W32/Sdbot-GP worm infection X Windows drivers update windowsupdate.exe W32/RBOT-ACE WORM! X Windows Dynamic Loading Header winDLL32.exe variant of the W32/SDBOT WORM! X Windows Executable winmys.exe W32/RBOT-ABO WORM! X Windows ExpIorer ?? W32/Rbot-AKO WORM! X Windows Explorer ?? SDBOT WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually X Windows Explorer EEXPLORER.EXE variant of the W32.SPYBOT WORM! X Windows Explorer explorer.exe "W32/POEBOT-J WORM! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)" X Windows Explorer explorer.pif W32/Rbot-AID WORM! X Windows Explorer Lsas.exe GAOBOT.AO WORM! **Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually X Windows Explorer olecom32.exe unidentified WORM or TROJAN! X Windows Explorer system32.exe W32/Rbot-AJH WORM! X Windows Explorer Shell Winexec32.exe REDIST.B VIRUS! X Windows Explorer SP2 csrss.exe Troj/Banker-DM Trojan! X Windows Explorer Update Build 1142 EXPLORER32.EXE KaZaA based KWBOT or KWBOT.Y VIRUSES! X Windows Explorer-3212 WINRE16.EXE HARDOC VIRUS! N Windows Eyes ?? "For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs" X Windows FAT 32 WINFAT32B.exe W32/SPYBOT-AGT WORM! X Windows File Protection winprotect.exe AGOBOT.JB WORM! X Windows Firewal Lsess.exe variant of the WIN32.RBOT WORM! X Windows Firewall WindowsFirewall.exe W32.MYTOB.AO WORM! X Windows Firewall Log winlog.exe unidentified WORM or TROJAN! X Windows Firewall Manager msfw.exe RBOT.WR WORM! X Windows Firewalll scvhost.exe W32/RBOT-EK WORM! X Windows Firewalll sphost.exe variant of the WIN32.RBOT WORM! X Windows Firewalll svvhost.exe variant of the WIN32.RBOT WORM! X Windows Firewalll winmu.exe variant of the WIN32.RBOT WORM! X Windows Fix integator.exe SDBOT.ZAB WORM! X Windows Fixes Systems elite.exe W32.Mytob.EG WORM! X Windows FormatAd WinForm.exe Windupdates adware variant X Windows Frame Works frmwrks32.exe variant of the WIN32.RBOT WORM! X WINDOWS FUCK BY CLASIC fuck.exe ZOTOB.H or W32.Zotob.J WORM! X Windows Generic Proc procmsg.exe W32.ALLIM.B WORM! X Windows Graphics Loaders wingraphics.exe SPYBOT.JG WORM! U Windows Guardian thehel1iawgrd32.exeFawgrd32.exe Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes X Windows Help mailinfo.exe MYTOB.JX WORM! X Windows Help File winhelper32.exe W32/SDBOT-QK TROJAN! X Windows Help Manager svchost32.exe W32/RBOT-OZ WORM! X Windows Help Service winhelpsv.exe W32/Rbot-LP WORM! X Windows Help Service winhlp.pif W32/Rbot-AKW WORM! X Windows Host hosts.exe W32.KELVIR.U WORM! X Windows Host winhost.exe BACKDOOR.PRYSAT TROJAN! X Windows Host Device hostsvc.exe W32/Zooty-A worm infection X Windows Host Name lmass.exe GAOBOT.O WORM! X Windows Host Service host.exe W32.Kelvir.AN WORM! X Windows Host Service scvhosts.exe W32.SPYBOT.NLI WORM! X Windows Host Service svchoste.exe W32.KELVIR.BF WORM! X Windows Host Service svchosts32.exe W32.KELVIR.AW WORM! X Windows Host Service svchosts32.exe W32/Kelvir-AK WORM! X Windows Host32 Starter hostserv.exe W32/SDBOT-WU WORM! X Windows Hosts hosts.exe KELVIR-O TROJAN! X Windows HTML file reader Sysconf32.exe NOOMY.A worm infection X Windows Icons Manager wicomgr.exe W32/Rbot-AIF WORM! X Windows iMessenger Messenger winimsg.exe W32.ALLIM.A WORM! X Windows Incontext InSearch.exe Z-Quest adware downloader/installer variant X Windows Installer ntdll.exe unidentified WORM or TROJAN! X Windows installer winstall.exe SpySheriff malware X Windows Internet Protocol deinst_qfe001.exe variant of the Win32.Small TROJAN! X Windows Internet Protocol winproc32.exe CoolWebSearch parasite related. X Windows IPv6 Drivers wipv6.exe W32/SDBOT-VJ WORM! X Windows Java Update weatherBug32.exe variant of the WIN32.RBOT WORM! X Windows JavaScript Daemon Winjsd.exe WOOTBOT.AF worm infection X Windows kev Messenger mskev.exe W32/SDBOT-XV WORM! X Windows Loader wstart32.exe GAOBOT.CA WORM! X Windows Loader Service civsc.exe variant of the WIN32.RBOT WORM! X windows Loadxm Win_.exe Troj/Fodder-A TROJAN! X Windows Local Services localsvc.exe Troj/Dloader-NY Trojan! X Windows Local Services netsvc.exe Troj/Dloader-NY Trojan! X Windows Local Services spoolsvc.exe Troj/Dloader-NY Trojan! X Windows Local Services svcadmin.exe Troj/Dloader-NY Trojan! X Windows Local Services svcman.exe Troj/Dloader-NY Trojan! X Windows Local Services svcrun.exe Troj/Dloader-NY Trojan! X Windows Local Services tcpsvc.exe Troj/Dloader-NY Trojan! X Windows Local Services websvc.exe Troj/Dloader-NY Trojan! X Windows Logger winlog.exe Troj/Nshadow-B TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Windows logging winlogd.exe W32/RBOT-ON WORM! X Windows Login explored.exe W32.Gaobot.SY worm X Windows Login winlog.exe AGOBOT.MG WORM! X Windows Login Security winlogin.pif unidentified WORM or TROJAN! X Windows Login Service winlog.exe W32/Rbot-AFN Worm! X Windows Login Service winlogin.pif W32/Sdbot-ACU WORM! Note: This worm/trojan file (winlogin.pif) is found in the Windows or Winnt folder. X Windows Logon winlogin.exe TROJ/SPYBOT-C TROJAN! X Windows Logon Application logon.exe W32/POEBOT-J WORM! X Windows Logon Application services.exe Troj/Ciadoor-L TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder. X Windows Logon Application WinIogon.exe """Cruel Intentionz"" backdoor TROJAN!" X Windows Logon Application WinIogon.exe W32.LINKBOT.M WORM! X Windows Logon Manager logon.exe variant of the WIN32.RBOT WORM! X Windows Logon Procedure Svchosta.exe variant of the W32.SPYBOT WORM! X Windows Logon Procedure Svchoste.exe variant of the W32.SPYBOT WORM! X windows logon procedure winlogonpc.exe """WinLogon"" TROJAN!" X Windows Management Instrumentation ?? W32/QEDS-A VIRUS! X Windows Management Instrumentation mwd.exe GRAPS VIRUS! X Windows Management Instrumentation wmimgr.exe W32.Qdens.A Trojan! X WINDOWS MANAGEMENT SYSTEM wm1exe.exe W32/RBOT-VT WORM! X Windows Manager winmants.exe MANTAS VIRUS! X Windows Manager winsrv.exe variant of the AGOBOT/GAOBOT WORM! X Windows Manager Update Inc tgb.exe W32/Sdbot-ACM WORM! X Windows mangement winlogonn.exe RANDEX.FC VIRUS! X Windows Media AP winmapp.exe unidentified WORM or TROJAN! X Windows Media APP wmapp.exe unidentified WORM or TROJAN! X Windows Media Driver msnger.exe variant of the WIN32.RBOT WORM! X Windows Media Player 50cent.exe variant of the WIN32.RBOT WORM! X Windows Media Player mcafe32.exe W32/RBOT-YO WORM! X Windows Media Player MediaPIayer.exe "SDBOT-QO TROJAN! - (note, the executable is called 'MediapIayer', with an 'i' !)" X Windows Media Player mpwe.exe W32/RBOT-TT WORM! X Windows Media Player msa.exe W32/RBOT-SI WORM! X Windows Media Player msams.exe RBOT.AHR WORM! X Windows Media Player msass43.exe variant of the WIN32.RBOT WORM! X Windows Media Player valentine-jessica.exe variant of the WIN32.RBOT WORM! X Windows Media Player wmediaplayer.exe W32/AGOBOT-NQ WORM! X Windows Media Player WMP23.exe variant of the WIN32.RBOT WORM! X Windows Media Player wmplayer.exe W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM! X Windows Media Player 3.6 wmpa36.exe variant of the WIN32.RBOT WORM! X Windows Media Player 3.6b WMPA36B.EXE W32/RBOT-VV WORM! X Windows Media Player 3.6d wmpa36d.exe W32/RBOT-YA WORM! X Windows Media Player 3.6d wmpa36d.exe W32/RBOT-YA WORM! X Windows Media Player 3.9 wmpa36.exe variant of the WIN32.RBOT WORM! X Windows Media Player Update ?? RBOT-ET WORM! N Windows Media Powerpoint Helper NSPPTHLP.EXE German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs X Windows media service crsss.exe RBOT.ACY WORM! X Windows media service crvss.exe SDBOT.VP WORM! X Windows media services cvrsss.exe W32/RBOT-MW WORM! X Windows Media SP.2.37 ?? LEMIR.C VIRUS! X Windows Media Utility wmediautil.exe variant of the W32.SPYBOT WORM! X Windows messenger messengers.exe W32.Mytob.EI WORM! X Windows Messenger msmsgs.exe W32/Forbot-BD worm infection X Windows Messenger msnsmgs.exe W32/RBOT-ANJ WORM! X Windows Messenger Messenger winmsg.exe W32.Velkbot.A WORM! X Windows Messenger Service kaspersky.exe MYTOB.HY WORM! X Windows Messenger Service winsmsgr.exe W32/RBOT-VW WORM! X Windows MeTaLRoCk service metalrock.exe TASTYRED VIRUS! X Windows Micro Drivers wupdates32.exe W32/Rbot-AEH Worm! X Windows Monitor arsetup.exe WIN32.SPAZBOX.A TROJAN! X Windows Monitor winmon.exe SDBOT.VB worm infection X Windows Monitor Services winmonitor.exe W32/RBOT-XX WORM! X Windows Monitoring Service winmon.exe variant of the W32/SDBOT WORM! X Windows More Choice TopContext.exe ZQuest adware X Windows Mouse Utilities mouseutils.exe W32/RBOT-ABU WORM! X Windows ms Drivers msnup32.exe W32/SDBOT-AAL WORM! X Windows MSConfig Startup Logger winlog.exe RBOT.BCU WORM! X Windows NetDDe wrmana32.exe W32.Mytob.IM WORM! X Windows Nets WinNET.exe W32/RBOT-MO WORM! X Windows NetStart Service winsN2S.exe W32/RBOT-ZX WORM! X Windows NetStart Service2 winsN2S.exe W32/RBOT-ABN WORM! X Windows NetStart Service2 winsN2SD.exe variant of the WIN32.RBOT WORM! X Windows Network Controller Mqguard.exe W32/Forbot-CL WORM! X Windows Network Controller Win9x.exe WOOTBOT.I WORM! X Windows Network Controller wingmt.exe variant of the W32/SDBOT WORM! X Windows Network Controller winmms32.exe W32/FORBOT-ED WORM! X Windows Network Controller WinxPupd.exe W32/FORBOT-DK WORM! X Windows Network Firewall firewall.exe W32/POEBOT-J WORM! X Windows Network Service winvc32.exe RBOT.RY WORM! X Windows Networking winsys32.exe GAOBOT.FL WORM! X Windows Networks netcog.exe MYTOB.FH WORM! X Windows Nivedia Driver sysMGT.exe Win32.Rbot worm variant X Windows NNT ?? RANKY.E VIRUS! X Windows NT 32 ntlogin32.exe W32.RANDEX.BRD WORM! X Windows NT Login ntlogin32.exe WORM_SDBOT.WG X Windows NT Login Session Manager WNSM.EXE RBOT.BIV WORM! X Windows NT Logon Application winlogon.scr W32/Rbot-ALP WORM! X Windows NT Service Name winshock.exe W32/RBOT-PK WORM! X Windows NT Update Manager Winlogon.exe "AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o""" X Windows OEM Tools winres32.exe SPYBOT.FD worm infection X Windows OLE Automation Server ole32aut.vbe CoolWebSearch parasite related browser hijacker X Windows Online Updater dllman.exe W32/Rbot-TE WORM! X Windows PDG winpdg.exe W32/Rbot-ADW Worm! X Windows PNP winpnp.exe W32/Rbot-AKN WORM! X Windows PNP Server pnpsrv.exe this variant of the W32/SDBOT WORM! X Windows Print Spooler NavAgent32.exe unidentified VIRUS! X Windows Print Spooler SVEHOST.EXE SPYBOT.H VIRUS! X Windows Process Manager winproc.exe unidentified WORM or TROJAN! X Windows Processe Manager mspn32.exe variant of the WIN32.RBOT WORM! X Windows Protectot boxide.exe variant of the W32/WOOTBOT WORM! X Windows Reg Services dservice.exe TROJ/PRORAT-D TROJAN X Windows Reg Services ffservice.exe Troj/Dloader-PL TROJAN! X Windows Reg Services fservice.exe TROJ/PRORAT-D TROJAN X Windows Reg Services lncom.exe TROJ/PRORAT-O TROJAN! X Windows Reg Services lservice.exe TROJ/PRORAT-O TROJAN! X Windows Reg Services ssservice.exe TROJ/PRORAT-D TROJAN X Windows Reg Services wservice.exe TROJ/PRORAT-O TROJAN! X WINDOWS REGISTER EDIT registr32.exe unidentified WORM or TROJAN! X Windows Register Settings svmhost.exe variant of the W32/FORBOT WORM! X Windows Registry msnmsg.exe Win32.Rbot worm variant X Windows Registry winhost.exe variant of the WIN32.RBOT WORM! X Windows Registry Cleaner winclean.exe W32.SpyBot worm variant X Windows Registry Express Loader regexpress.exe W32/FORBOT-CJ WORM! X Windows Registry Manager tasksmanagers.exe W32.Mytob.ER WORM! X Windows Registry Name ?? W32/Rbot-AEB Worm! X Windows Registry Name winses.exe W32/Rbot-ADB Worm! X Windows Registry Scan regscan.exe W32/Rbot-HA worm infection X Windows Registry Scan regscan23.exe variant of the WIN32.RBOT WORM! X Windows Registry Scan regscan32.exe WORM_RBOT.KE X Windows Registry Scan svcdll.exe W32/RBOT-TP WORM! X Windows Registry Scan timeupdate.exe SPYBOT.JE WORM! X Windows Registry Security crss.exe variant of the BACKDOOR.IRC.BOT TROJAN! X Windows Registry Startup wind32.exe W32/Agobot-BZ WORM! X Windows report swchost.exe Small-BD TROJAN! X windows run system.exe W32/ICPASS-A WORM! X Windows Runtime Help win32hlp.exeWinRunHelp.wrh variant of the AIMVISION VIRUS! X Windows Runtime Proccess 32RUNdll.exe SDBOT.QW WORM! X Windows SA omniscient.exe BLAZEFIND adware X Windows Screensaver Service.exe W32.KELVIR.P or KELVIR-L WORMS! X WINDOWS SCREENSAVER ssaver.scr W32/Sdbot-YZ Worm! X Windows secure setver32.exe WORM_SPYBOT.EP X Windows Secure Connection winsc.exe variant of the WIN32.RBOT WORM! X Windows Secure Messaging System msnmsgrsrvc.exe W32/RBOT-RE WORM! X WINDOWS SECURITY wingrd.exe variant of the WIN32.RBOT WORM! X Windows Security Assistant rundll32.vbe CoolWebSearch parasite related. X Windows Security Assistant winsec.exe CoolWebSearch parasite related. X Windows Security Authority Service lsass.exe "W32/KALEL-A WORM! - NOTE - this should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Windows Security Manager winsecure.exe Affilred.B adware X Windows Security Manager winsecurity.exe W32/AGOBOT-KI WORM! X Windows Security Module module.exe variant of the WIN32.RBOT WORM! X Windows Security Service ?? W32/RBOT-ALV WORM! X Windows Security Update security32.exe Affilred.B adware X Windows Security Updater WINFRW.exe Solufina TROJAN! X Windows Serv Patch Mcaffe2005.exe variant of the WIN32.RBOT WORM! X Windows ServeAd WinServAd.exe WindUpdates WinAd adware X Windows Server Information servinfo.exe W32/FORBOT-EN WORM! X Windows Servic2 winsy.exe W32/Rbot-AIA WORM! X Windows Service dddd.exe "Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans" X Windows Service dstart4.exe unidentified TROJAN! X Windows Service pd14.exe "Adware, detected by TDS-3 as ""TrojanDownloader.Win32.Delf.dg""" X Windows Service pd7.exe TROJ_SMALL.VZ TROJAN! X Windows Service private-zone.exe unidentified TROJAN.CLICKER ! X Windows Service prvdi.exe "Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd" X Windows Service r.exe variant of the TROJ_SMALL.VZ TROJAN X Windows Service services.exe "W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X Windows Service svvhost.exe W32/AGOBOT-HL WORM! X Windows Service video.exe unidentified TROJAN! X Windows Service video2.exe DOWNLOADER.SMALL.MY TROJAN! X Windows Service WINSVC.EXE SDBOT.CL WORM! X Windows Service Controller services.exe W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X Windows Service Host scvhost.exe SDBOT.N WORM! X Windows Service Host svchost.exe "CONE.B VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32" X Windows Service Host svchost.exe W32/Kalel-C WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder. X Windows Service Host Process ?? W32/EZIO-A WORM! X Windows Service Loader Window.exe W32/RBOT-XO WORM! X Windows Service Manager localsvc.exe Troj/Dloader-NY Trojan! X Windows Service Manager msgs.exe W32/OSCABOT-E WORM! X Windows Service Manager msnmrg.exe W32/OSCABOT-G WORM! X Windows Service Manager netsvc.exe Troj/Dloader-NY Trojan! X Windows Service Manager spoolsvc.exe Troj/Dloader-NY Trojan! X Windows Service Manager svcadmin.exe Troj/Dloader-NY Trojan! X Windows Service Manager svcman.exe Troj/Dloader-NY Trojan! X Windows Service Manager svcmgr32.exe W32/OSCABOT-D WORM! X Windows Service Manager svcrun.exe Troj/Dloader-NY Trojan! X Windows Service Manager tcpsvc.exe Troj/Dloader-NY Trojan! X Windows Service Manager userint32.exe W32/OSCABOT-C WORM! X Windows Service Manager websvc.exe Troj/Dloader-NY Trojan! X Windows Service Pack Auto Update ballin.exe unidentified WORM or TROJAN! X Windows Service Pack Auto Update del-me.exe "Adware, also detected as the Lowzones.BH TROJAN!" X Windows Service Pack Auto Update figgaz.exe TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.bt X Windows Service Pack Auto Update winworks.exe "Adware downloader, identified by eScan antivirus as Trojan-Clicker.Win32.Agent.bt" X Windows Service Pack2 svchhost.exe variant of the WIN32.RBOT WORM! X Windows Service Pack2 WIN43.EXE GAOBOT.G WORM! X Windows Service Support Call SVSS32.EXE W32/RBOT-XQ WORM! X Windows Service XP XpFirewall.exe W32.MYTOB.AM WORM! X Windows Services Explorer.exe "W32/SDBOT-WT WORM! - NOTE - the valid ""explorer.exe"" file is located in C:\Windows or C:\Winnt, whereas this one is located in the Windows\System32 or Winnt\System32 folder!" X Windows Services NetworkDriver32.exe W32/RBOT-ACR WORM! X Windows Services NetworkDrivers.exe W32/Sdbot-YO Worm! X Windows Services scmsg.exe variant of the W32/SDBOT WORM! X Windows Services scvhoste.exe W32.Spybot.OBZ WORM! X Windows Services service.exe RANDEX.R VIRUS! X Windows Services smsc.exe variant of the W32/SDBOT WORM! X Windows Services Spool32x.exe variant of the WIN32.RBOT WORM! X Windows Services winsvc32.exe W32/MYTOB-CB WORM! X Windows Services Host svchost.exe "CONE or CONE.E VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32" X Windows Services Hosts svhosts.exe TROJ/SDBOT-YH TROJAN! X Windows Services Ink Platform Tablet Input Subsystem wsiptis.exe RBOT.APC WORM! X Windows Services Update svch0st.exe "variant of the WIN32.RBOT WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X Windows Session Manager smss32.exe variant of the WIN32.RBOT WORM! X Windows Session Manager Subsystem smss.exe W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X Windows Shell shell.exe W32/MYTOB-CA WORM! X Windows Shell taskgmr.exe WIN32/MYTOB.BV WORM! X Windows Shell Library Loader load shell.dll /c /set CoolWebSearch parasite related. X windows shellext.32 mschost.exe BLASTER.K VIRUS! X WINDOWS SKY sky.exe W32.MYTOB.CH WORM! X Windows Smart Manager smart.exe W32/RBOT-SL WORM! X Windows Sound Driver SndMon32.exe W32.SpyBot worm variant X Windows Sound Manager SndMon16.exe variant of the W32/FORBOT WORM! X Windows Sound Manager SndMon32.exe W32/FORBOT-BU WORM! X Windows SP2 Firewall wfirewall7.exe variant of the WIN32.RBOT WORM! X Windows SP2 Update Sp2update.exe WOOTBOT.BS WORM! X Windows SP2 Version Load wuauclt32.exe GAOBOT.CX WORM! X Windows SP4 directCC.exe W32/RBOT-ACX WORM! X Windows Spool Server spoolsrv.exe W32/Sdbot-ACT WORM! Note: This is not the legitimate Windows process spoolsv.exe (Notice the difference in the spelling). This trojan file (spoolsrv.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Windows SpoolaPrint Service spoolasrv.exe W32/Sdbot-AYD WORM! X Windows Spooler SPOOLSRV.EXE SPYBOT.P VIRUS! X Windows Spooler spoolsv32.exe unidentified WORM or TROJAN! X Windows Spooler Services spool.exe W32/AGOBOT-AMO WORM! X Windows SpoolPrint Service spoolersrv.exe W32/Sdbot-ZT WORM! X Windows spoolservr Service spoolservr.exe W32/Sdbot-AAN WORM! X Windows Spoolsre Service spoolsre.exe W32/Sdbot-AAE WORM! X Windows Spoolsrv Service spoolmsv.exe W32/Sdbot-ZS WORM! X windows spoolsrv service spoolssv.exe W32/Sdbot-AWV Worm! X Windows Spoolsurf Service spoolsurf.exe W32/SDBOT-ZZ WORM! X Windows SpooltPrint Service spooltsrv.exe W32/SDBOT-AYE WORM! X Windows Spoolvvv Service spoolvvv.exe W32/SDBOT-AAW WORM! X Windows sq Drivers winmsn32.exe W32/Rbot-ADI Worm! X Windows Sql Service For Windows 32 Bit winsql32.exe W32/FORBOT-FC WORM! X Windows SSL File winssv.exe WOOTBOT.CA WORM! X Windows Stand Sound Drivers Sounddrv.exe W32/SDBOT-XF WORM! X Windows Standard Securty ?? W32/Rbot-ALF WORM! Note: May use DOZ.EXE for file name. X Windows Start Server 2000 traficy.exe W32/Rbot-AHM WORM! X Windows Startup services21.exe W32/Agobot-MX WORM! X Windows Startup Wdrun32.exe GAOBOT.AO WORM! X Windows Startup winsta~1.exe Go-Hip browser add-on X Windows Startup winstartup.exe Go-Hip browser add-on X Windows Startup 32 Bits sysrun32.exe DarkSun trojan variant X Windows Streams Server localsrv.exe SDBOT.LN WORM! X Windows Subsys winload.exe NETSPREE.C WORM! X Windows SyncroAd SyncroAd.exe Windupdates adware variant X WINDOWS SYSTEM beta.exe W32.Mytob.DF WORM! X WINDOWS SYSTEM botzor.exe W32/ZOTOB WORM! X WINDOWS SYSTEM dcomuser.exe W32.Mytob.EO WORM! X WINDOWS SYSTEM gothica.exe MYTOB.HU WORM! X WINDOWS SYSTEM lf66prc.exe W32.Mytob.GC WORM! X WINDOWS SYSTEM logic.exe W32.MYTOB.IC WORM! X WINDOWS SYSTEM msdev32.exe W32.Mytob.EH WORM! X WINDOWS SYSTEM msnl.exe W32.Mytob.IK WORM! X WINDOWS SYSTEM mtrnqs.exe W32.MYTOB.IG WORM! X WINDOWS SYSTEM nec.exe W32/Mytob-L or W32/Mytob-CM and W32/Mytob-CN Worms! X WINDOWS SYSTEM nec.exe W32/Mytob-BH Worm! X Windows System nibie.exe W32.Mytob.FO WORM! X WINDOWS SYSTEM nibie.exe W32/Mytob-BY WORM! X WINDOWS SYSTEM ninfoie.exe W32/Mytob-EP Worm! X WINDOWS SYSTEM per.exe W32/ZOTOB.C WORM! X WINDOWS SYSTEM servce.exe W32/Mytob-EI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X WINDOWS SYSTEM servises.exe W32/Zotob-I WORM! Note: (servises.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (services.exe) should not be seen in Msconfig or as a Startup item. X WINDOWS SYSTEM skybot.exe MYTOB.JU WORM! X WINDOWS SYSTEM skybot.exe W32/Mytob-CX or W32.Mytob.EB WORM! X WINDOWS SYSTEM skybotx.exe W32.Mytob.FT WORM! X WINDOWS SYSTEM skybotx.exe W32/Mytob-BY WORM! X WINDOWS SYSTEM smoc.exe W32.MYTOB.FU WORM! X WINDOWS SYSTEM smsc.exe W32/MYTOB-BR WORM! X WINDOWS SYSTEM test.exe W32.Mytob.DJ WORM! X WINDOWS SYSTEM test2.exe W32.Mytob.DJ WORM! X WINDOWS SYSTEM test3.exe W32.Mytob.DV WORM! X WINDOWS SYSTEM twunk_65.exe W32/MYTOB-EG WORM! X WINDOWS SYSTEM wdns33.exe W32/Mytob-BY WORM! X WINDOWS SYSTEM win.exe.exe W32.Mytob.FA WORM! X WINDOWS SYSTEM winaup.exe W32/Mytob-DN WORM! X WINDOWS SYSTEM winligon.exe W32.Mytob.EP WORM! X WINDOWS SYSTEM winmon.exe W32.Mytob.GB WORM! X WINDOWS SYSTEM winNTsys32.exe W32/MYTOB-DM WORM! X WINDOWS SYSTEM winsvc32.exe W32.MYTOB.HH WORM! X Windows System WINSYS.exe W32/Mytob-M or W32/Mytob-EK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X WINDOWS SYSTEM winsys33.exe W32.Mytob.EK WORM! X WINDOWS SYSTEM winvnc.exe W32.Mytob.EU WORM! X WINDOWS SYSTEM winxpserv.exe W32/Mytob-BQ Worm! X WINDOWS SYSTEM xpupdate.exe W32/ZOTOB-G WORM! X WINDOWS SYSTEM xxx.exe W32.Mytob.CZ WORM! X Windows System 32-Bat Service win32bat.exe W32.Mytob.FI WORM! X Windows System Backup SysBackup.exe Unidentified malware X WINDOWS SYSTEM Cleaner h3.exe W32.Mytob.EQ WORM! X WINDOWS SYSTEM CLEANER iexplore.exe W32.Mytob.ET WORM! X Windows System Configuration Passcfg16.exe DOMWIS-E TROJAN! X Windows System Configuration SYSCFG16.EXE W32/Domwis-N WORM! X Windows System Configuration wincfg.exe AGOBOT.OP WORM! X Windows System Configuration WINCFG32.EXE W32/Agobot-TE WORM! X Windows System Configuration Winfrw.exe BACKDOOR.SOLUFINA TROJAN or the W32/DOMWIS-J WORM! X Windows System Configuration WinNeth.exe W32/Rethe-A WORM! X WINDOWS SYSTEM Dns windsns.exe W32.Mytob.EY WORM! X WINDOWS SYSTEM DNSPOOL hbmail.exe W32.MYTOB.FW WORM! X Windows System File cmxp.exe W32.Spybot.KHO WORM! X WINDOWS SYSTEM FILE winload.exe MYTOB.DK WORM! X Windows System Gateway SPOOLER.EXE variant of the WIN32.RBOT WORM! X Windows System Init winit32.exe variant of the WIN32.RBOT WORM! X Windows System Manager crssm.exe W32/Rbot-AFH Worm! X Windows System Manager smsc.exe variant of the WIN32.RBOT WORM! X Windows System Manager sysconf.exe W32.MYTOB.AL WORM! X Windows System Manager winsystem.exe W32/Rbot-AN worm infection X Windows System Manager Loader smsls.exe AGOBOT.TF WORM! X Windows System Manager Proc winsmc.exe RBOT.JH WORM! X Windows System Manager Proc winsmc.exe RBOT.JH WORM! X WINDOWS SYSTEM MEMORY LOADER memloader.exe W32/MYTOB-IN WORM! X windows system notepad wnpsm.exe variant of the AGOBOT/GAOBOT WORM! X Windows System Restore Configuration Sblhost.exe variant of the SPYBOT.GEN VIRUS! X Windows System Restorer SystemRestorer.exe DULOAD.C VIRUS! X Windows System Security winmp.exe RBOT.IV WORM! X Windows System Security Monitor ?? W32.Pinkton.A Worm! X Windows System Serivce winserv.exe variant of the Win32.Rbot WORM! X windows system service winsock.exe W32/RBOT-MR WORM! U Windows System Tray dlhost.exe Related to IamBigBrother Internet monitoring software. U Windows System Tray msni.exe Iambigbrother monitoring software X Windows System Tray swhost.exe Unidentified worm or trojan X WINDOWS SYSTEM UPDATE xDcc.exe W32/Mytob-EH WORM! X Windows System32 windowsp.exe MYTOB.GD WORM! X Windows System32 Kernel system32.exe W32/SDBOT-AAT WORM! X Windows Systemnmg stagmr.exe W32.MYTOB.S WORM! X Windows Sz Host winshvc.exe variant of the W32/SDBOT WORM! X Windows Task Manager ACCOUNT_DETAILS.DOC.exe QUATERS.A VIRUS! X Windows Task Manager taskgmr.exe W32.Mytob.BJ and W32/Mytob-AJ WORMS! X Windows Task Manager taskmg.exe "Browser hijacker - identified by DrWeb antivirus as ""Trojan.StartPage.601""" X Windows Task Manager taskmgn.exe "Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install." X Windows Task Manager taskmrg.exe W32.MYTOB.AV WORM! X Windows Task Manager taskmngr.exe W32/Rbot-ANM WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Windows Task Manager Emulator kennewr.exe W32/SPYBOT-FA WORM! X Windows Task Manager-Emulator uswtme.exe W32/Rbot-CG infection X Windows Task Scheduler asijdie.exe unidentified WORM or TROJAN! X Windows TaskAd Wintaskad.exe WindUpdates WinTaskAd adware variant X Windows Taskbar Manager ?? W32.PROTORIDE.B WORM! X Windows Taskbar Manager internat.exe PROTORIDE-H WORM! X Windows Taskmanager lsassx.exe W32.Kelvir.C or W32.Kelvir.E WORM! X Windows TCP/IP wintcp.exe W32/AGOBOT-ZH WORM! X Windows Telnet Server wintel.exe W32/AGOBOT-MW WORM! X Windows Time winmgr.exe W32/RBOT-XC WORM! X Windows Time Server TimeSRV.exe W32.Spybot.DNC worm X Windows TM rundlI32.exe variant of the WIN32.RBOT WORM! X Windows TM SVPHOST.exe variant of the WIN32.RBOT WORM! X Windows TM windowssys32.exe variant of the WIN32.RBOT WORM! X Windows TM WinxSys.exe variant of the WIN32.RBOT WORM! X Windows Upate rundll.exe HAKO TROJAN! - NOTE: this is NOT the Windows system file of the same name as described here X Windows Update ?? NORIO VIRUS! Acts as a hi-jacker redirecting to adult content sites X Windows Update ebay.exe W32.GAOBOT.BUU WORM! X Windows Update host32.exe W32/RBOT-GU WORM! X Windows Update host32.exe W32/RBOT-GU WORM! X Windows Update iexplorere.exe GAOBOT.AP WORM! X Windows Update inetinf.exe variant of the GAOBOT/AGOBOT WORM! X windows update logonuit.exe Troj/LegMir-AO TROJAN! X windows update Microsoft.exe TROJ_LMIR.A TROJAN! X Windows Update mplupdate.exe W32.HLLW.MOEGA WORM! X windows update msnsever.exe W32/RBOT-AHN WORM! X Windows Update msnupdates.exe W32/Rbot-ALK WORM! Note: This file has nothing to do with Windows updates or MSN. X Windows Update msnwinsb.exe W32/RBOT-AAH WORM! X Windows Update qtask.exe W32/RBOT-AKU WORM! - NOTE: do NOT confuse with the Quicken file of the same name as described here X windows update real.exe TROJ/LEGMIR-AU WORM! X Windows Update scvhost.exe W32/SDBOT-XT WORM! X windows update sychost.exe LEOX.B VIRUS! X Windows Update taskmr.exe W32/Mytob-GZ Worm! X windows update uddater.exe LEOX VIRUS! X Windows Update Update.exe TROJ/DELF-FN TROJAN! X Windows Update update32.exe variant of the WIN32.RBOT WORM! X Windows Update windows.exe W32/RBOT-RB WORM! X Windows Update windowsx.exe TROJ/BANCD-A TROJAN! X Windows Update wininfo.exe W32.Mytob.GA WORM! X Windows Update winlogin.exe Troj/Banker-DV TROJAN! X Windows Update winupdate.exe W32/SDBOT-WS WORM! X windows update Wruaclt.exe RBOT.XZ WORM! X windows update Wuacrlt.exe RBOT.XZ WORM! X Windows Update Wuamgrd.exe W32.SpyBot worm variant X Windows Update wuampd.exe RBOT.UM WORM! X windows update Wuanclt.exe RBOT.XZ WORM! X windows update wuarclt.exe W32/RBOT-OF WORM! X windows update wuaruclt.exe variant of the WIN32.RBOT WORM! X windows update wuaucrlt.exe W32.SPYBOT.HUR WORM! X windows update wuaurlt.exe RBOT.ADG WORM! X Windows Update wudate.exe AGOBOT.ML WORM! X Windows Update wupdate.exe Wengs adware X Windows Update wupdmgr.exe BANCBAN-FC TROJAN! X windows update wuraclt.exe W32/RBOT-PO WORM! X Windows Update 32 winlogons.exe W32/Forbot-FI WORM! X Windows Update 64 WinV.exe W32/FORBOT-FP WORM! X Windows Update Auto Update wuaumgr.exe variant of the W32.SPYBOT WORM! X Windows Update AutoUpdate Client Product wuauct.exe AGOBOT.ACL WORM! X Windows Update Center svthx.exe W32.STUBBOT.A WORM! X Windows Update Center W32RSA.exe unidentified WORM or TROJAN! X Windows Update Checker ?? adware downloader trojan X Windows Update Checker deinst_qfe001.exe variant of the Win32.Small TROJAN! X Windows Update Checker deinst_qfe002.exe variant of the Win32.Small TROJAN! X Windows Update Client wuclient.exe WIN32.SMALL.RN downloader TROJAN! X Windows Update Client Service windrvl32.exe AGOBOT-MM WORM! X Windows update config svhost.exe W32/Sdbot-PF worm infection X windows update configurator svghost.exe variant of the W32.SPYBOT WORM! X Windows Update Controller mwoffice.exe TROJ/BATTRY-A TROJAN! X Windows Update Files dnetc.exe Unidentified VIRUS! Note - wupdmgr.exe is the real Windows Update X Windows Update Manager Winlog0n.exe TROJ/AGENT-BO TROJAN! X Windows Update Manager wupdate.exe variant of the WIN32.RBOT WORM! X Windows Update Manager wupdmngr.exe W32.RANDEX.BTB WORM! X Windows Update Manager for NT wupdmgr32.exe BACKDOOR.SDBOT.AH WORM! X Windows Update Monitoring Service winupdt.exe W32/RBOT-PL WORM! X Windows Update Process wmiprvsc.exe W32/SDBOT-CB WORM! X Windows Update Service csrs.exe W32/AGOBOT-NI WORM! X Windows Update Service regscv.exe W32/AGOBOT-AM WORM! X Windows Update Service smcg.exe SDBOT.QY worm X Windows Update Service SP00ISS.exe W32/Sdbot-ZH Worm! X Windows Update Service update32.pif W32/Rbot-ALC WORM! X Windows Update Service 2004/2005 systemupdate.exe Rbot-JE worm infection X Windows Update services wins32svcs.exe variant of the WIN32.RBOT WORM! X Windows Update services wservices.exe variant of the WIN32.RBOT WORM! X Windows Update Software system.exe TOFGER.BX TROJAN! X Windows Update System Shell svhostcs32.exe W32/RBOT-AAZ WORM! X Windows Update V6 ?? W32/Rbot-KT worm infection X Windows Update.exe ?? "Homepage hijacker, see here" X Windows Updater iexplorerrs.exe W32/RBOT-TN WORM! X Windows Updater svigost.exe W32/RBOT-VS WORM! X Windows Updater wupdate.exe WOOTBOT.AJ WORM! X Windows Updater wupdmgr32.exe variant of the DOS.AUTOCAT VIRUS! X Windows Updater Online winupdatexx.exe variant of the WIN32.RBOT WORM! X Windows Updates lsassx.exe variant of the W32/SDBOT WORM! X Windows Updates w32dns.exe W32/Sdbot-BFW Worm! X Windows Updates winupd32.exe W32.MYTOB.CE WORM! X Windows Updating Service updating.pif W32/RBOT-ALW WORM! X Windows Updtee Mgnr W1NT45K.exe W32.Mytob.DC WORM! X Windows USB controler winusb.exe W32/RBOT-HR WORM! X Windows USB Driver Support Windowsusb.exe variant of the W32.SPYBOT WORM! X Windows USB Service 666.exe W32.MYTOB.AR WORM! X Windows USBD msifirewall.exe unidentified WORM or TROJAN! X Windows User Mode Driver Manager wdfmrg.exe W32/Sdbot-ZN Worm! X Windows User Starter winuser32.exe RBOT.SN WORM! N Windows Version Check ver_chk.exe "Version checker for CyberAudioLibrary (""A new way to exchange information through the Internet"")" X Windows video vide_32.exe variant of the GAOBOT/AGOBOT WORM! X Windows Video Acquisition (WVA) wvsvc.exe AGOBOT.YM WORM! X Windows Video Drivers videons32.exe GAOBOT.AZT worm X Windows Virus Control plou.exe W32/SDBOT-ACZ WORM! X Windows Web Services localsvc.exe Troj/Dloader-NY Trojan! X Windows Web Services netsvc.exe Troj/Dloader-NY Trojan! X Windows Web Services spoolsvc.exe Troj/Dloader-NY Trojan! X Windows Web Services svcadmin.exe Troj/Dloader-NY Trojan! X Windows Web Services svcman.exe Troj/Dloader-NY Trojan! X Windows Web Services svcrun.exe Troj/Dloader-NY Trojan! X Windows Web Services tcpsvc.exe Troj/Dloader-NY Trojan! X Windows Web Services websvc.exe Troj/Dloader-NY Trojan! X Windows Workstation mpci.exe variant of the WIN32.RBOT WORM! X Windows Workstation msup32a.exe variant of the W32/SDBOT WORM! X Windows Workstation Service (32-bits) wkssvc32.exe variant of the W32/SDBOT WORM! X Windows Workstation Start Service mslanmgr.exe variant of the WIN32.RBOT WORM! X Windows Xp nortonguard.exe W32/Mytob-DZ WORM! X Windows XP Automatic Update wXPupdate.exe W32/Rbot-AFC Worm! X Windows Xp Service Pack 2 svchost.exe Troj/Xplos-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. X Windows XP SP2 KeyGen Windows XP SP2 KeyGen.exe W32/TIBICK-C WORM! X Windows_Protect lsas.exe RBOT.ARO WORM! X Windows_Protect wincontrol32.exe W32/Rbot-ADK Worm! X Windows_Protect winregal.exe variant of the WIN32.RBOT WORM! X Windows_Protect winsystem.exe variant of the WIN32.RBOT WORM! X Windows_Serivce SERVICE.exe WOOTBOT.AH worm infection X Windows_Updates svthost.exe W32.SpyBot worm variant X Windows_VXD user32.exe PWSTEAL.PPORT VIRUS! X windows16 windows16.exe Troj/VB-XU TROJAN! X Windows32 rundll.exe AGOBOT-LK or AGOBOT-ND WORMS! X windows32 windows32.exe Troj/VB-XU TROJAN! X Windows32 wuuaclt.exe W32.Bratle.B WORM! X Windows32 Configuration Loader msrf32.exe W32/Sdbot-ABX WORM! X Windows32 Messenger Service msmsgv.exe RBOT.ANS WORM! X Windows32 Net Database msnd32.exe W32/RBOT-AAL WORM! X Windows32 Serivces winser32.exe SPYBOT.AAF WORM! X WindowsAgent sysexhook.exe GOP keyboard logger/TROJAN! X WindowsAgent WindowsAgent.exe GOP.G VIRUS! X WindowsAPI.DLL Server5.exe """Fear and Hope"" trojan" X WindowsBackup WINDOWSBACKUP.EXE W32.Stang WORM! X WindowsCRC wscrc.exe W32/SDBOT-VU WORM! X WindowsCriticalUpdate windows_critical_update.exe ASTEF or RESPAN VIRUSES! X WINDOWSflashbrg sqldata1.exe variant of the AGENT-IC TROJAN! X Windowsfw windowsfw.exe W32/AGOBOT-TA WORM! X WindowsFY bsw.exe variant of the DESKTOPHIJACK TROJAN! - for removal see here X WindowsFY wp.exe "Part of a ""Security IGuard"" parasite infestation - also detected as TROJAN.DESKTOPHIJACK and Troj/FakeAle-A Worm!" X WindowsFZ ?? W32.Desktophijack Virus! Also see Trojan.Desktophijack.B Trojan! X WindowsFZ A5281300.so Variant of the SmitFraud alias FAKEALE-C TROJAN! X WindowsFZ zloader3.exe Variant of the SmitFraud alias FAKEALE-C TROJAN! X WindowsKeyUpdate master.exe W32.JOSAM WORM! X WindowsMGM Winmgm32.exe SOBIG and LALA.C VIRUSES! X WindowsRegistration ?? W32/RBOT-NO WORM! X WindowsRegKey Autoupdate Explorer.exe variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Explorer.exe! X WindowsRegKey Autoupdate Iexplore.exe variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Internet Explorer file! X WindowsRegKey upd4te2d4te ?? RBOT.XQ WORM! X WindowsRegKey update ?? RBOT.QT WORM! X WindowsRegKey update 16winupdate32.exe variant of the WIN32.RBOT WORM! X WindowsRegKey update svchoosts.exe RBOT.ADB WORM! X WindowsRegKey update svchostc.exe RBOT.IF WORM! X WindowsRegKey update wdnupdate.exe SDBOT.QX WORM! X WindowsRegKey update win2kup2date.exe SPYBOT.FK worm infection X WindowsRegKey update windns.exe RBOT.IE WORM! X WindowsRegKey update Windowsup.exe SDBOT.PU WORM! X WindowsRegKey update winupdat32.exe W32/RBOT-AGW WORM! X WindowsRegKey update Winupdate.exe SDBOT.NT WORM! X WindowsRegKey update WinUpdate32.exe variant of the WIN32.RBOT WORM! X WindowsRegKey update WINUPDATES.EXE W32/RBOT-MM WORM! X WindowsRegKey update winupdatexx.exe RBOT.LW WORM! X WindowsRegKey update XP windexv1.exe W32/RBOT-ABM WORM! X WindowsRegKey%$ update msi332.exe W32/Rbot-IX worm infection X WindowsRegKey%update ethernet32m.exe W32/RBOT-EN WORM! X WindowsRegKeys update windup.exe variant of the WIN32.RBOT WORM! X WindowsRegKeys update winsysi.exe SDBOT.WE worm infection X WindowsSetup ?? EZBOT VIRUS! X WindowsSQL service boner.exe SDBOT.XRM WORM! X Windows-System System32.exe LOGPOLE.C VIRUS! X Windows-TCP-IP rfkampig.exe GIPMA VIRUS! X WindowsUpd WindowsUpd4.exe VirtuMonde adware X WindowsUpd1.exe WindowsUpd1.exe VirtuMonde adware X WindowsUpd2.exe WindowsUpd2.exe VirtuMonde adware X windowsupdate RPCX1sQ3.exe IRCBOT.B VIRUS! X WindowsUpdate svchost.exe "number of worms and trojans: TROJ/AGENT-DR , ASTEF , RESPAN and others" X WindowsUpdate svchost.exe TROJ/AGENT-V TROJAN! X WindowsUpdate svchost.exe /s Troj/Bdoor-IK TROJAN! X WindowsUpdate USRINIT.EXE MADDIS.B VIRUS! X WindowsUpdate windows_update.exe LOHACK.B VIRUS! X windowsupdate winupdate.exe W32/WARPI WORM! X Windowsupdate Service csrss.exe "BUCHON.E WORM! **Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling" X WindowsUpdate Service wuautlc.exe W32/RBOT-NR WORM! X WindowsXP Module DirectX3D.exe "Malware, reportedly a keylogger - see here" X WindowsXP Update windowsxpupdate.exe W32/RBOT-PB WORM! X WindowsXPserv svcnxp32.exe Addee by the NANINF-A TROJAN! X Windows-XP-Service-Pack xpspz.exe W32/SDBOT-AAC WORM! X Windowz ?? VBS.Nukip Worm! X Windowz Update V2.0 Explorer.exe "YODO VIRUS! Note - the valid ""explorer.exe"" is located in C:\Windows or C:\Winnt whereas this one is located in the System32 sub-directory" X Windoxs Update Center W32RfSA.exe variant of the W32/SDBOT WORM! X WinDrg32 windrg32.exe DRUDGEBOT.A WORM! X WinDriv32 WinDriv32.exe SMALL-BA TROJAN! X WinDriver Configuration windrvconf.exe AGOBOT-LX WORM! X WINDRUN taskgmrs.exe W32/MYTOB-BT WORM! X windrv windrv32.exe Unidentified VIRUS - possibly a strain of OBLIVION or BIONET X WinDrv windrvx.exe variant of the TIBSER.A downloader TROJAN! U WinDSL MTU-Adjust WinDSL_MTU.exe Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung X WinDSNX ?? DNSX VIRUS! X WindUpdates ?? AGENT.BF VIRUS! X WindUpdates WinUpdt.exe Windupdates adware N WINDVDpatch CTHELPER.EXE "CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a ""leave alone"" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it" N WinDVR SchSvr SchSvr.exe "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs" Y WinDVRCtrl WDVRCtrl.exe "Driver task installed by the drivers for some TV capture cards; no further information available, so best left alone." N WinDVRCtrl WinDVRCtrl.exe Control center software for an AOpen VA1000 TV tuner card X Windws Configuration Loader LEXPLORE.exe SODABOT VIRUS! X WinEssential Keyhost.exe Hijacker - hailing from jraun.com X WinEssential keyword.exe Jraun.com hijacker X WinExec WinExec.exe W32/Falus-A WORM! X WinExec Winexec.exe.vbs AINESEY.A VIRUS! X WinExec32 WinExec32.exe KAZWIN VIRUS! U WinFast Schedule Wfwiz.exe Leadtek WinFast TV tuner scheduler U Winfast_2K WF2k.exe System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card U WinFast_Gamma ?? Loads if you change the gamma settings on Leadtek WinFast graphics cards U WinFast_Taskbar ?? Leadtek WinFast graphics cards related taskbar; can be launched manually. U Winfast2KLoadDefault ?? Loads default settings for Leadtek Winfast graphics cards X WinFavorites WinFavorites.exe1 Loudmarketing.com adware downloader N WinFax PRO Controller WFXCTL32.EXE From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs Y WinFaxAppPortStarter wfxsnt40.exe WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. X WinFire WF.exe Troj/Delf-SY TROJAN! X WinFixer 2005 wfx5.exe """Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here" X winfont winfont.exe Death backdoor trojan infection U WinFoxV2 WF2k.exe System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card X WinFX cssrs.exe AGOBOT.FX WORM! X WinGate WinGate.exe variant of the LOVGATE WORM! U WinGate Engine Monitor wgengmon.exe "WinGate Internet Client Dialup Monitor, component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server." X WinGate initialize WinGate.exe variant of the LOVGATE WORM! X wingo wingo.exe W32.BEAGLE.AW or W32.BEAGLE.AV WORM! N WinGuage Pro WGPRO32.EXE "Part of McAfee Nuts & Bolts. ""WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious"". Resource hog. Available via Start -> Programs" Y Winguard WGFE95.EXE Dr Solomon's Virex antivirus U WinGuard Pro wgp.exe Winguard_Pro N WinHacker ?? "Tweaking utility by Wedge Software. There are?far better?tweakers and, unlike WinHacker, most are free" X winhelp dns32.exe variant of the WIN32.RBOT WORM! X WinHelp realsched.exe variant of the LOVGATE WORM! **Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name X Winhelp TkBellExe.exe... variant of the LOVGATE WORM! X winhelp Updadv.exe Troj/QQPass-N TROJAN! X Winhelp winhe1p.exe QQPASS.E VIRUS! X Winhelp winhelp.exe variant of the LOVGATE WORM! X WinHelp WinHelp.exe variant of the LOVGATE WORM! X winhlp.exe winhlp.exe PWSTEAL.FORMGLIEDER TROJAN! X winhlp3.exe winhlp3.exe variant of the Win32/TrojanDownloader.Easto.A TROJAN! X Winhlp32 ?? GANT.B VIRUS! X winhlp32.exe winhlp32.exe Win32/TrojanDownloader.Easto.A TROJAN! X winhlpp32.exe winhlpp32.exe GAOBOT.SY WORM! X Winhost win.exe Dloader-AP trojan X Winhost winhost.exe REATLE.F WORM! X Winhost wintt.exe LOLAWEB.B VIRUS! X Winhost yahoo.exe TROJ/DELF-KM TROJAN! X winhost.exe winhost.exe TROJ/LOHAV-R TROJAN! or the W32.Beagle.BY WORM! X winhost32.exe winhost32.exe Troj/Banito-F TROJAN! X WinIeRun winierun.exe Troj/RNWatch-A Worm! X winimage wvsvc.exe RBOT.TX WORM! X wininet32 wininet32.exe Troj/Raznew-A trojan X wininetd wininetd.exe WINET VIRUS! X WinInit Win86.exe TROJ/SMALL-PB TROJAN! X wininit wininit.exe WOLLF.16 VIRUS! X winint winint.exe W32/Sdbot-ADA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X winipsec winipsec.exe Unidentified malware U WinIRXHelper WinIRXHelper.exe MSI? Media Center Deluxe software - see here X winis winis.exe W32/RBOT-WI WORM! X Wink*.exe Wink*.exe version of the KLEZ VIRUS! * represents any random characters U Winkb6 winkb6.exe "Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed" X WinKernel WinKer.exe MIRAB or SERVIDOR VIRUSES! X winkernel32 wWin32.com Added as the result of the BANSAP VIRUS! U WinKey winkey.exe "Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos" X winldr ?? VIDLO-P TROJAN! X winldr Rechnung.pdf.exe DOWNLOADER-ACS TROJAN! X winlgz2 winlgz2.exe TROJ/KILLFIL-Q TROJAN! X winlibs.exe winlibs.exe EVAMAN.C worm X WinLibUpdate libupdate.exe BIONET series of VIRUSES such as BIONET.31 or BIONET.310 X WinLibUpdate32 libupdate32.exe BIONET.405 VIRUS! X WinLibUpdte libupdte.exe BIONET.318 VIRUS! X Winlink winlink32.exe GAOBOT.AAY WORM! X Winlme windll.exe GOP.F VIRUS! U WinLoad Winload.exe "PCTattletale is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it." X WinLoader ?? versions of the SUBSEVEN VIRUS! X winlocatorupdate updatewinlocator.exe Locator adult content toolbar related X winlog manager winlog.exe DONBOMB.A TROJAN! X WINLOG0N WINLOG0N.EXE W32.MYDOOM.BI WORM! X winlogin win32x.exe "Browser hijacker, also detetected as the TROJ/STARTPA-DF TROJAN!" X WinLogin winlogin.exe AGOBOT-IX WORM! X Winlogin.exe log.exe variant of the WIN32.AGENT.AH downloader TROJAN! X winlogin.exe logfile.exe WIN32.AGENT.AH TROJAN! X winlogin.exe mspaint.exe variant of the WIN32.AGENT.AH TROJAN! X Winlogin.exe steam.exe variant of the WIN32.AGENT.AH TROJAN! X WINLOGON ?? VBS.Ypsan.F@ mm Worm! X WinLogon logon.exe AdultBox foistware X winlogon msreg32.exe SDBOT.EO WORM! X winlogon winlogin.exe RANDEX.E or P2LOAD.A WORM! X winlogon winlogon.exe "Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file described here" X winlogon winlogon.exe "TRODAL VIRUS! - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file" Y winlogon winlogon.exe Windows Logon Process - handles user logons described here X winlogon winlogon32.exe WIN32/MASLAN.C WORM! X winlogon wpwlogon.exe unidentified WORM or TROJAN! X winlogon service urx.exe SPYBOT.EN WORM! X Winlogon Shell ?? W32.Kipis.M WORM! X Winlogon.exe ?? CoolWebSearch parasite related. X winlogon.exe helper.exe FAKESPY-A TROJAN! X winlogon.exe msole32.exe "Adware, detected as the DOWNLOADER-ACZ TROJAN!" X winlogon32_ ?? W32.Ruland.A WORM! X WinLsass ?? W32/WORT-B TROJAN! X WinLsass servicec.exe SCANE VIRUS X winltmpv winln.exe TCXMEDI-C TROJAN! X winltmpv wutop.exe TCXMEDI-C TROJAN! X Winmain winmain.exe "One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on ""hot standby"", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a ""rogue"" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!" U winmatrix.exe WinMatrixXP.exe WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop U WinMem WinMem.exe "WinMem Cleaner, part of Ultra_WinCleaner_Utility_Suite . Makes more memory available for your programs and the Operating System. It also defragments your system's physical memory increasing the efficiency of your CPU and motherboard cache, which prevents crashes and accelerates your system's performance." X WinMenssage winmax.exe BANCOS.B VIRUS! X WinMessenger syshost.exe W32/OPANKI-E WORM! N WinMgmt WinMgmt.exe "Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here" X WINMGR taskgmgr.exe W32.MYTOB.AN WORM! X Winmgr.exe scvhost.exe AGOBOT.AFG WORM! X WinMgr32 winmgr32.exe W32.MIMAIL.P WORM! X WinMine D4NG3.vbs BISCUIT.A VIRUS! Y winmodem wmexe.exe Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information X WinMoviePlugIn WinMoviePlugIn.exe Sfonditalia adult content premium rate dialer X WinMsrv32 WinMsrv32.exe GAOBOT.AFJ WORM! N WinMX WinMX.exe WinMX file sharing application N winmysqladmin or WinMySQLadmin Tool winmysqladmin.exe Starts the MySQL database admin tool X winnet winnet.exe CommonName Toolbar spyware. To uninstall see here X WinNetDDE ?? NETDEPIX.B TROJAN! X WinNite niteaim.exe W32.Opanki.B Worm! X winnt DNS ident iexplorer.exe variant of the WIN32.RBOT WORM! X winnt DNS ident pidchk32.exe W32/RBOT-ACY WORM! X Winnt DNS ident windowsp.exe RBOT.BAL WORM! X winnt DNS ident windowxp.exe variant of the WIN32.RBOT WORM! X winnt DNS ident Winupd32.exe RBOT.AVU WORM! X winnt DNS ident winupdate32.exe variant of the WIN32.RBOT WORM! X winnt DNS ident wuamgrd32.exe W32/RBOT-BAU WORM! X winnt DNS ident wuamgrd33.exe variant of the WIN32.RBOT WORM! X winNT updatc wupgrd.exe variant of the WIN32.RBOT WORM! X WinNtBB WinntBB.exe DULOAD.C VIRUS! X Winnup win32nls.exe variant of the W32.SPYBOT WORM! X winocx32 winocx32.exe Win32.Protoride.I WORM! X WINOWS SYSTEM winnt.exe MYTOB.ID WORM! X Winpack winpack.exe Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg U WinPatrol WinPatrol.exe "WinPatrol - ""Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs""" X winphonics7536 ?? Mutin-C IRC backdoor trojan infection X winpipe winpipe.exe Browser hijacker redirecting to wow-access.com U WinPLOSION WinPlosion.exe "WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop." Y WinPoet WinPPPoverEthernet.exe "WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking" N WinPopup WINPOPUP.EXE "Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won\'t set itself up to run unless the user specifically adds it to startup" X winpopup winupie.exe Adware by Tradeexit.com X Winprocer32 Update winprocer32.exe RBOT.GW WORM! X winprocessor Update winprocessor.exe RBOT.IO WORM! X WinProfile Command.exe BUDDY VIRUS! X winprofile iexpiore.exe variant of the MONCHER WORM! X WinProfile iexpIore.exe Troj/Chum-C Trojan! X WinProfile sndcfg16.exe Win32.Sndc.A worm X WinProt Winprot.exeserver.exe CHUPACABRA VIRUS! X winprotect win32.exe W32.MUGLY.E WORM! X winprotect winprotect.exe W32/SDBOT-SB WORM! U WinProxy WinProxy.EXE """WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP""" X Winproxy Personal WINPROXY.EXE SDBOT.BMF WORM! X winpsd winpsd.exe W32.Mydoom.Q WORM! X winpup32 Winpup32.exe ADCLICKER VIRUS! X winrapid winrapid.exe variant of the WIN32.RBOT WORM! X winrar winrar.exe CoolWebSearch parasite related. X winrarshell winrarshell32.exe PWSteal.Salira TROJAN! X winReg winReg.exe YAHA.H or YAHA.J VIRUSES! X winreg_32 ?? Troj/Banker-DB Trojan! X winreg_32 svchosst.exe BANCOS-CE TROJAN! X winreg_32 sysdll.exe TROJ/DLOADER-IJ TROJAN! X winreg_32 Vc030405.exe TROJ/BANCOS-CT TROJAN! X winregsrv winregsrv.exe SYNRG VIRUS! U WINREMOTE WinRemote.exe InterVideo WinCinema Manager - needed for the use of WinDVD_Remote_Control X Winres32vis ?? THRAX.A VIRUS! X winrestore1 winrestore.exe TROJ/KILLFIL-Q TROJAN! X winreups winreups.exe variant of the WIN32.RBOT WORM! N winroute winroute.exe "Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k" X winrun msconfig.exe WINUR VIRUS! Note - this is not the real msconfig.exe X WINRUN svchost32.exe W32/MYTOB-AI WORM! X WINRUN taskgmr.exe W32/MYTOB-BX WORM! X WINRUN taskgmr32.exe W32.MYTOB.AP WORM! X WINRUN z W1NT45K.exe W32.Mytob.BL WORM! X WinRunners WinDrivers.exe DULOAD.C VIRUS! X Wins Update 32 services32.exe W32/Forbot-FN WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. X Wins32 Online cfgpwnz.exe W32.Bropia.R WORM! U Winscheduler WINSCH~1.EXE InterVideo WinDVR scheduler X WinScMngr winsmc.exe W32/SDBOT-BPZ WORM! X WinSec winsec16.exe AGOBOT.ZF WORM! X winsecure winsecure.exe "Browser hijacker, redirecting to specificsearches.com" X Winsecure Antivirus Secureantivirus.exe variant of the W32.SPYBOT WORM! X WinSecured32 ssmr.exe variant of the W32/FORBOT WORM! X Winserv Winserv.ila W32.NODMIN WORM! X winserver Server.txt.vbs DELTAD.A VIRUS! X Winservice winmain.exe porn related malware U WinService32 ssmgr.exe "007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP""" X WinService32 svchost.exe "007_Spy_Software keystroke logger/monitoring program. remove unless self installed! - NOTE - this file is placed in a Program Files\Common Files\Microsoft Shared\DAO\System32 folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X WinServices WinServices.exe YAHA.K or YAHA.M VIRUSES! X winservit cassl.exe de RBOT.ASG WORM! X winservn winservn.exe PurityScan/Clickspring adware X winservs winservs.exe PurityScan/Clickspring adware X WinSetBrowse BasicUpdate.dll.vbs BISCUIT.A VIRUS! X winshost.exe winshost.exe Tooso or Tooso.B or Tooso.C or Tooso.D or Tooso.E and Trojan.Tooso.I TROJANS! X winshost.exe winshost.exe BAGLE.CZ TROJAN! X WinShowUpdate copy C:\WINDOWS\winshow.new C:\WINDOWS\winshow.dll "Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version" X WinSig NetXP.exe TROJ/BANKER-FN TROJAN! X winsock svch0st.exe "SAGE-A WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O." X Winsock driver winnt update.exe TROJ/SPYBOT-DM TROJAN! X Winsock driver winnt64.exe W32/Spybot-DR WORM! X winsock2 netsvr.exe AGOBOT.LY WORM! X Winsock2 driver ?? SDBOT.T WORM! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program X Winsock2 driver AMSNMGR.EXE variant of the W32.SPYBOT WORM! X Winsock2 driver MIRC32.exe SPYBUZZ VIRUS! X Winsock2 driver SDJOIJE.EXE SPYBOT.DR VIRUS! X Winsock2 driver SPOLSV.EXE W32/SPYBOT-CM WORM! X Winsock2 driver sysreq.exe W32/SPYBOT-CC WORM! X Winsock2 driver wincfg.exe SPYBOT.CO WORM! X Winsock2 driver WINCFG.SCR W32.SpyBot worm variant X Winsock2 driver winupdate.exe Spybot-BX worm infection X Winsock2 driver WUAUMQR.EXE W32/SPYBOT-DP WORM! X Winsock2 driver Zonealarmupdate.exe variant of the W32.SPYBOT WORM! X Winsock2.dll WINLODR.SCR unidentified VIRUS! X Winsock32 driver Testing.exe SPYBOT.B VIRUS! X Winsock32driver sp2XPupdate.exe BKDR_HACKARMY.S TROJAN! X Winsock32driver svchhost.exe BKDR_HACKARMY.I TROJAN! X Winsock32driver win32server.exe BackDoor-AZV TROJAN! X Winsock32driver win32server.exe HACARMY.F TROJAN! X Winsock32driver win32server.scr HACARMY TROJAN! X Winsock32driver winXPupdate.exe HACKARMY.9728 TROJAN! X Winsock32driver ZoneAlarmPr0.exe Hackarmy-B trojan infection X Winsock32driver ZoneLockup.exe Hacarmy.D trojan infection X winsockdriver bot.exe W32/WarPigs-D WORM! X winsockdriver iexplor.exe W32.BLATIC.A WORM! X winsockdriver tskmg.exe SDBOT.GEN or WARPIGS.C WORMS! X winsockdriver winsock2.2.exe variant of the SPYBOT VIRUS! X winsockdriver winsock3.exe W32/SPYBOT-DO WORM! X WinSocketComponent nthost.exe unidentified VIRUS! U WINSOS VERIFY WINSOS.EXE "WinSOS - ""deletes spyware, optimizes your computer - backs up selected data""" X WinSP ?? "Hijacker, variant of the TROJ/STARTPA-ME TROJAN!" X winspd32dll winspd32.exe variant of the AGOBOT/GAOBOT WORM! X WinSPF windrv32.exe W32.Mydoom.V WORM! X WinSPF winspf32.exe W32.Mydoom.P WORM! X Winspl winsplx.exe variant of the TROJ/TROLL-A TROJAN! X Winspool spoolsvr.exe variant of the W32/SDBOT WORM! X WinSrv kn0x.exe HOBBIT.F VIRUS! X WinSrv SHIZZLE.EXE HOBBIT.C VIRUS! X Winsrv winsrv.exe OPASERV.T VIRUS! X WinsSystem syssmss.exe BKDR_DELF.IG TROJAN! X Winsta~1 winsta~1.exe GoHip foistware X WinStabilizer WinStabilizer.exe W32/Agobot-SW Worm! X WinStart ?? CIAN.C VIRUS! X WinStart services.exe "W32.SOBER.O WORM! - Note - this file is placed in a ""%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X WinStart WinStart.exe "FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing ""car"" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge" X winstart winstart.exe TROJ/SCKEYLO-AB TROJAN! X WinStart WinStart.pif CONE.E VIRUS! X WinStart winstart32.exe PUROL VIRUS! X WinStart001 or WinStart001.EXE WinStart001.exe "FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing ""car"" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge" X winstats winstats.exe Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder. X WinSth16 WinSth16.exe CAKE VIRUS! X winstro RUN32DLL.exe FTP_ANA VIRUS! X WinSvc16.exe WinSvc16.exe BACKDOOR.SDBOT.FQ TROJAN! X winsvc32.exe winsvc32.exe GREPAGE TROJAN! X Winsvr manager DDEsvr.exe W32/TIRBOT-C WORM! X winsy32.exe winsy32.exe "Trojan, CoolWebSearch parasite related" X winsync ?? variant of the QOOLOGIC TROJAN! X WINSYS ?? TROJ/BANKER-ER TROJAN! X winsys exploer.exe TROJ/SPYVB-C TROJAN! X winsys syschost.exe unidentified TROJAN! U Winsys Winsys.exe "Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it?" X WinSys32 Winsys32.exe CIGIVIP or RECKUS VIRUSES! X WinSys32 Winsys32.exe BACKDOOR.CIGIVIP TROJAN! X WinSys32 Winsys32.exe W32.HLLW.RECKUS or W32/SDBOT-YL WORMS! X winsys32 Driver winsys32.exe Loony-O trojan infection U WinSysAppMon WinSysRM.exe Home & Family Content Filter related. See here X winsyslog lptt01 winsyslog.exe "Variant of the RapidBlaster parasite (in a ""Winsyslog"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X WinSysStartUpWKbLw TaskSystemDll.Exe BACKZAT.G VIRUS! X WinSyst32 winsyst32.exe MORB VIRUS! X WinSystem winsystem.exe WHITEBAIT VIRUS! X Winsystem winsystem.exe BANCOS.CR trojan infection U WinSystem WinSystems.exe CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! X winsystem.sys smss.exe W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! X WINT ?? PurityScan/Clickspring adware X WINTASK iexplorer.exe W32/MYTOB-CH WORM! X WINTASK msmgrxp.exe W32.MYTOB.AQ WORM! X WINTASK msvhost.exe W32/Mytob-AR Worm! X WINTASK sys32.exe W32.MYTOB.K WORM! X WINTASK sys32.exe W32/MYTOB-F WORM! X WINTASK t4skgmr.exe W32.MYTOB.CM WORM! X WINTASK t4skmgr.exe W32/Mytob-AK Worm! X WINTASK taskfile.exe W32.Mytob.EF WORM! X WINTASK taskgamr.exe W32.MYTOB.AU WORM! X WINTASK taskgm.exe W32/Mytob-AO Worm! X WINTASK taskgmr.exe W32.MYTOB.I or W32.Mytob.BH and W32/Mytob-AC WORMS! X WINTASK taskgmr32.exe W32/MYTOB-AK WORM! X WINTASK taskgmr32.exe W32.Mytob.BU WORM! X WINTASK taskgmr32.exe W32/Mytob-AK Worm! X WINTASK taskgmrs.exe W32.Mytob.DH WORM! X WinTask Wintask.exe HIPO or LEMIR.F VIRUSES! X WinTask wintask.exe Affilred.B adware X WINTASK yahooicons.exe W32/MYTOB-HM WORM! X WINTASK DLL jusched32.exe W32.MYTOB.AI WORM! X WINTASK DLL RealPlayer Ath Check W32.MYTOB.AG WORM! X WINTASK DLL32 smsrss.exe W32.MYTOB.BS WORM! X WinTask driver wintask.exe TROJ/DLOADER-NA TROJAN! X WINTASK32 taskgmr32.exe W32.MYTOB.BN WORM! X WINTASK32 taskgmrr.exe W32.Mytob.FX WORM! X WINTASKMANAGER taskgmr.exe W32/MYTOB-AF WORM! X WINTASKMGR ccsrs.exe W32.MYTOB.Q WORM! X WINTASKS taskgmr.exe W32.MYTOB.BO and W32.Mytob.DO WORMS! X WINTASKS winxpro.exe W32.Mytob.EZ WORM! X WinTasks DLL Library (32-bits) winkll.exe W32/Rbot-AJZ WORM! U WinTasks Traybar wintasks.exe "WinTasks - ""Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before""" X wintasks.exe wintasks.exe Evaman worm X Wintbp.exe wintbp.exe W32.Zotob.E WORM! X Wintbpx.exe wintbpx.exe W32.Zotob.F WORM! U wintective wintective.exe "Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it." X winter happy.exe W32/SDBOT-YF WORM! N Wintercooler Pro WINCOOL.EXE "Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed" N WinTidy WinTidy.exe Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs U WinTime wintime.exe WinTime Located in the Windows directory. X Wintime Wintime.exe Harnig TROJAN! N Wintime Wtxpload Wxpload.exe Wintime "Part of the software to support a Dexxa USB graphics tablet. From a visitor - ""This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG""" X WinTimer msupdate.cmd "Hijacker, detected by Kaspersky antivirus as Trojan.Win32.StartPage.tj" X wintnask32.exe wintnask32.exe W32/Rbot-AFP Worm! X wintnl wintnl.exe variant of the W32.ZOTOB.K WORM! X wintnl.exe wintnl.exe W32.Zotob.K WORM! X wintnpx.exe wintnpx.exe W32.ZOTOB.H WORM! X WinTools WToolsA.exe WinTools adware N WinTOTAL Scheduler guru.exe WinTOTAL Real estate appraisal software related X WinTray wintray.exe LEGUARDIEN.B VIRUS! X wintsk32dll wintsk32dll.exe W32/RBOT-AAJ WORM! X winudll.exe winudll.exe Troj/Mitglie-CE TROJAN! X winupated.exe winupated.exe variant of the W32/SDBOT WORM! X winupd ?? MOTA.A VIRUS! X winupd.exe winupd.exe BEAGLE.M or BEAGLE.N WORMS! X WinUPD32 explorer.exe Unidentified VIRUS! X winupdat winupdat.exe Win32.Canbot.A worm X WinUpdate RBSKQQBO.EXE VBS.Vbswg2b.A VIRUS! X WinUpdate updsys.exe variant of the WIN32.RBOT WORM! X winupdate winupdate.exe /auto WIN32.ALCAN.B WORM! X WinUpdate wmbem.exe REVCUSS.B VIRUS! X WinUpdate Loader msnnm.exe UPCHAN TROJAN! X winupdate.exe winupdate.exe RADO VIRUS! X winupdate_ ?? W32.COMDOR.A WORM! X winupdate2846 ?? Mutin-C IRC backdoor trojan infection X WinUpdateB breatle.exe W32.Bratle.A WORM! X winupdateconn ?? W32/COMBRA-A WORM! X winupdateconn_ Explorer.EXE W32/Combra-B WORM! X winupdatefiv_ ?? COMBRA.C WORM! U WinUpdateProtection csrss.ex EmployeeWatch is a commercial spyware program designed to monitor user activity on a computer. U WinUpdateProtection csrss.exe "ICE_Remote_Spy monitoring software, ""secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you."" - Note - this file is installed in a C:\Windowsupdate\Ufp\Irs7 folder, and it is NOT the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which is located in the System32 directory." X winupdates winupdates.exe /auto W32.Alcra.B WORM! X WinUpdsv winupdsv.exe X97M.DROPO Macro VIRUS! X winupdt ?? Mabutu.a WORM! X winupdtl winupdt.exe 2nd-thought adware variant X winupdtl winupdtl.exe SecondThought adware variant X WinUpgrader ?? Troj/Agent-DZ Trojan! X winusb.dll winguard.exe W32/FORBOT-CN WORM! X WinUser32K usr32wink.exe Win32.VB.hk backdoor TROJAN! X WinUsr WinUsr.exe K1S2 W32.CLUNK.A WORM! X Winux Piriax Service PH32.EXE RANDEX.G VIRUS! X winversion winversion.exe "Browser hijacker, redirecting to specificsearches.com" X WinVNC iexplorer.exe EVIVINC VIRUS! U WinVNC WinVNC.exe WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet X winvxd32 winvxd32.exe W32.Gabloliz.A WORM! X winwan lptt01 or winwan ml097e winwan.exe "Variant of the RapidBlaster parasite (in a ""Winwan"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X winword winword.exe Troj/Torpid-C TROJAN! X winXP 33.exe/background W32.ANPES WORM! X WinXP plugin1.exe Downloader-JW TROJAN! X win-xp nvsc32.exe W32.Bropia.N WORM! X win-xp winis.exe BROPIA.O WORM! X win-xp winis.exe W32.Bropia.N WORM! X WinXP fix ?? BACKDOOR.RANKY.P TROJAN! X WinXp Updater winxp32.exe W32/RBOT-HG WORM! X WinXP-98 CSRSS.exe "Troj/Banker-DS TROJAN! Note:This is NOT the legitimate Windows CSRSS.exe process, which should NOT figure in Startup!" X winxpdll32.exe winxpdll32.exe variant of the Win32.SMALL downloader TROJAN! X WinXPHome plugin2.exe malicious VBS_INOR.T script! U WinXPLoad "Rundll32 LoadDll, LoadExe WinXPLoad.exe" Compaq hotkey related - required if you use the hotkeys X winxpusbd winxp64.exe variant of the WIN32.RBOT WORM! X winzip ?? BANCOS.G VIRUS! Note - not the popular WinZip file compression utility X Winzip ?? W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif N WinZip Quick Pick WZQKPICK.EXE "Added with WinZip version 8.1. ""The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself."". You can right-click and close it - choosing to not re-load it at start-up" X WinZip Update WinZip.exe variant of the WIN32.RBOT WORM! X WIP Config GUI Winipcfgs.exe W32/RBOT-CN WORM! U Wireless PCI Card Configuration Utility WMP11Cfg.exe Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration X Wireless Provider Server wpsvr.exe W32/Forbot-AD worm infection Y Wireless-G Notebook Adapter Gcc.exe LinkSys Wireless-G Notebook Adapter diver U Wireless-G Notebook Adapter Utility WPC54CFG.EXE Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) U Wise-FTP Scheduler WF_Scheduler.exe WISE-FTP file transfer software scheduler N wjview wjview.exe MS tool used to view window-based Java applications from the command line N wkcalrem wkcalrem.exe Produces a pop-up reminder of events scheduled using the MS Works Calendar N WkDetect WkDetect.exe Checks for updates to MS Works N wkfud wkfud.exe A marketing program for MS Works N WksSb WksSb.exe The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file X WksSVC EXPLORER.exe "W32/MYTOB-BW WORM! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt folder whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)" N WkUFind WkUFind.exe "MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site" X Wlan Drier Winusb2.exe WOOTBOT.DC WORM! X Wlan Driver avscan.exe WOOTBOT.DH WORM! N WLAN Status Tray Applet WLANSTA.EXE System Tray icon for checking the status of a Wireless LAN Y WLAN_Cfg.exe WLAN_Cfg.exe Linksys Instant Wireless USB Network Adapter driver U wlancfg wlancfg.exe Inventel wireless router related - required in order to automatically connect to the Net at bootup. N WLANSTA.EXE WLANSTA.EXE System Tray icon for checking the status of a Wireless LAN Y Wm24Pan Wm24Pan.Exe ESI external sound card driver X wm41a398 ?? LZIO.com adware downloader X WMAudio services.exe NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process X WMAudio winlogon.exe Neveg.A worm N WMBoot ?? Associated with Logitech Wingman game controllers. Not required but what does it do? X wmcbaaca ?? LZIO.com adware downloader X WMI Application Interface wmiapi.exe W32.SPYBOT.RBY WORM! U WMIEXE.exe wmiexe.exe "NT component, used by Windows Millennium to detect? Plug and Play-compliant IEEE 1394 devices during the startup process.?Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading" X Wminf Wminf.exe GEMA TROJAN! X Wminfo Wminfo.exe GEMA TROJAN! X wmiprv wmiprv.exe W32/RBOT-WM WORM! X wmon jusched.exe W32/AGOBOT-OW WORM! Y WMP54Gv4 WMP54Gv4.exe Linksys WMP54G Wireless-G PCI Adapter driver X wmplayer.exe wmplayer.exe Troj/Bancban-CZ TROJAN! X wmsys32 wmsys32.exe BANPAES.B VIRUS! X wmv winmonv.exe TROJ/AGENT-DG TROJAN! X WNAD WNAD.EXE "Spyware running a program called ""Yo Mama Osama"" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like" X wnddrv svchost.exe "Aded by an unidentified TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X WNSC ?? PurityScan/Clickspring adware X Wnsck2 driver wlogf.exe W32/SPYBOT-AF WORM! X WNSI ?? PurityScan/Clickspring adware X WNSI wnscpsu.exe PurityScan/Clickspring adware X WNSI wnscpsv.exe PurityScan/Clickspring adware X WNST ?? PurityScan/Clickspring adware X wntlgns wntlgns.exe CoolWebSearch parasite related TROJAN! X won update WAPDATE.EXE WIN32.RBOT.N WORM! N WooCnxMon CnxMon.exe Wanadoo ISP software related - not required - here's how to bypass it. N WOOTASKBARICON TaskbarIcon.exe Wanadoo ISP taskbar icon - not required N Woowatch Watch.exe "Wanadoo ISP software, not required" X word pair bopotsvr.exe TROJ/SHED-A TROJAN! Y WordQ carat flag WordQcrs.exe Related to WordQ Writing Aid Software N WordWeb wweb32.exe WordWeb - free theasaurus and dictionary. Start manually X Working System Analyzer syswork.exe W32/FORBOT-FZ WORM! X worknote1 ?? W32.Meetot WORM! N Works Calendar Reminder wkcalrem.exe Produces a pop-up reminder of events scheduled using the MS Works Calendar N WorksFUD wkfud.exe A marketing program for MS Works U Workstation Scheduler wm95.exe "Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog" X Workstation Services wrkstn.exe W32/RBOT-OJ WORM! X Workstation Ver 5.0 vmware.exe W32/RBOT-AHB WORM! U Worm Detector wd.exe Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam X wormexe winstart.exe EARLYBIRD VIRUS! X wovax wovax.exe Win32.Daqa.A trojan X wow bar.exe "Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g" X wow wwf.exe TROJ/LINEAGE-Y TROJAN! N Wpctrl or wpctrl95 wpctrlnt.exe wpctrl95.exe "WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties" Y WPCycle.exe WpCycleWin.exe "Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)" X wpds.exe doriot.exe TROJ/SMALL-KY TROJAN! X wpwmgrs wpwmgrs.exe W32/MYTOB-DH WORM! X WQK WQK.exe version of the KLEZ VIRUS! N WrCtrl WrCtrl.exe "Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time" X WRDialer WrDialer.exe WinPoet DSL dialler U wrexec wrexec.exe "Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online" X ws2_32 svchst.exe TROJ/VOKEN-A TROJAN! X ws2help ws2help.exe variant of the TROJ_SMALL.AN downloader TROJAN! X WSAConfiguration csrsvcs.exe AGOBOT.VI WORM! X WSAConfiguration drrss.exe variant of the AGOBOT/GAOBOT WORM! X WSAConfiguration ntguard32.exe variant of the AGOBOT/GAOBOT WORM! X WSAConfiguration rpcxmn32.exe AGOBOT.ABG WORM! X WSAConfiguration svchostt.exe AGOBOT.ZT WORM! X WSAConfiguration win32upd.exe variant of the WIN32.RBOT WORM! X WSAConfiguration winlogon32.exe W32/AGOBOT-WC WORM! X WSAConfiguration wmon32.exe W32.Gaobot.BAJ WORM! X WSAConfiguration1 csass.exe AGOBOT.WH WORM! U WScheduler WScheduler.exe "Windows Scheduler - ""schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events.""" X wscript.exe vabian.vbs VABI VIRUS! X Wsdata service WSconf.exe SDBOT.ZU WORM! X wserver wserver.exe W32.NETSKY.AC WORM! U WService WService.exe Tablet client Driver for UC-Logic Pen/Graphics Tablet U wsg32 wsg32.exe GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself! U wskrnl wskrnl.exe Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself. X wsock32 svchost.exe "TROJ/HORST-A WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X wsock32 wsock32.exe unidentified WORM or TROJAN! X WSSAConfiguration wmmon32.exe W32/Agobot-KC WORM! U wssys wssys.exe WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it X Wstat32 driver Wstat32.exe LOONBOT VIRUS! Y wstimeb wstimeb.exe Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it U WSVCS SERVICES.EXE WALogger is a spyware program that logs keystrokes. If you didn't install this yourself remove it. Y wswpd wswpd.exe "Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a ""memory leak"". Needed for printing to work?" U wsys.exe wsys.exe "SpyloPCMonitor is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it." N WT Game Channel GameChannel.exe "Wild Tangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case" N WT GameChannel wtgamechannel.exe "Wild Tangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case" X WTF Test wtftest.exe W32/RBOT-ACM WORM! U WTIndicator SchedInd.exe WinTask - software that automates a variety of routine tasks quickly and simply X WTSI wapisvit.exe PurityScan/Clickspring adware X WTSS ?? PurityScan/Clickspring adware X WTSS wapicc.exe PurityScan/Clickspring adware X WTSS wapiit.exe PurityScan/Clickspring adware X WTSS wapisu.exe PurityScan/Clickspring adware X WTSS wapisvsu.exe PurityScan/Clickspring adware X WTST wapisvtr.exe PurityScan/Clickspring adware X wuanguard wuanguard32.exe W32/RBOT-AAF WORM! Y WUOLService WUOLService9x.exe Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) X wuosdial wuosdial.exe variant of the WIN32.RBOT WORM! X WUPD iglmtray.exe TZET VIRUS! X wupd symcsvc.exe ABWIZ.C TROJAN! X wupd win32.exe TROJ/ORSE-C TROJAN! X wupdate wi32.exe "Downloader trojan, detected by Panda antivirus as Adware/Trustbid" X wupdate wisvccz.exe TROJ/ORSE-B TROJAN! X Wupdate driver ?? variant of the W32.SPYBOT WORM! X Wupdm32 Wupdm32.exe W32.MIDLAK WORM! X wupdt wupdt.exe IMISERV.A TROJAN! Y WUSB11B.exe WUSB11B.exe Linksys WUSB11 WLAN USB adapter Y WUSB54Gv2 InvokeSvc3.exe Wireless-G USB Wireless Network Adapter related - would appear to be required Y WUSB54Gv4 WUSB54Gv4.exe Wireless-G USB Wireless Network Adapter related - would appear to be required X wuviewer wuviewer.exe Proxy_Trojan variant X wvsvc wvsvc.exe AGOBOT.YM WORM! X WWKS wsass.exe W32/SDBOT-BT WORM! X www.hidro.4t.com enbiei.exe BLASTER.F VIRUS! X www.symantec.com oz11111.exe W32.Mydoom.W WORM! X WXcmeinst ?? RANCK-CD TROJAN! X Wxp4 Norton Update.exe W32.ERKEZ.D WORM! N WXProcMgr Module WXprocMgr.exe "TVTonic from Wavexpress - ""enjoy 3 full-screen, DVD-quality video channels for FREE"". Allows data content to be downloaded and synchronized on your system" X wzhelper wzhelper.exe Searchcentrix hijacker X wzservice hess.exe Backdoor.Win32.Hackarmy.w TROJAN! U X Server X.exe """XoftWare for Windows"" enables you to run network-based UNIX programs (""X programs"" or ""clients"") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a network" U X10 Device Network Service x10nets.exe Belongs to X10 video streaming device(s). X X10Weax WTHRTRAY.EXE "WeatherCheck ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads, and contains no uninstaller." U x3watch x3watch.exe """program helping with online integrity. Whenever you browse the internet and accesses a site which may contain questionable material, the program will save the site name on your computer. Approximately every 30 days, a person of your choice (an accountabiltiy partner) will receive an e-mail containing all possible questionable sites you may have visited within the month. This information is meant to encourage an open and honest conversation between friends and help us all be more accountable""" X x3yy ?? TANNICK trojan infection N Xanadu Xanadu.exe Xanadu - free language and translation wizard from Foreignword U X-Cleaner Deluxe xcleaner.exe X-Cleaner_Deluxe - privacy and anti-spy application U X-Cleaner Freeware XCLEAN~1.EXE X-Cleaner_Freeware X Xcpy1 Xcpy1.exe BroadcastPC adware variant X xdxqa dewa.exe W32/SDBOT-YB WORM! U XE 8x LM Status lmsxxe.exe Xerox XE8 series laser printer status monitor X Xecuter.bat psexec.bat BOOHOO VIRUS! N XemiCo ADC.EXE XemiComputers Active Desktop Calendar N Xfire Xfire.exe Terratec DMXFire 1024 soundcard controlpanel X xflash xflash.exe TROJ/BANCJ-A TROJAN! X xftpGraber Xftpgraber.exe W32.ENVID.C WORM! N X-Grabber sswizard.exe ScreenShot Wizard X xhi xhi.exe Troj/SCLog-A TROJAN! X xhrmy Xhrmy.exe HyperLinker adware X XiD mmx.exe ANALOGX VIRUS! Y XircWinModem4 ltcm000c.exe WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information U xitami Xiwin32.exe Xitami Multiplatform Open Source web server X xload32 netdd.exe NETSPY TROJAN! X XML Service msxml.exe W32/RBOT-HD WORM! X XNSearchAssistant SrchAsst.exe iWon Search Assistant - spyware U XoftSpy XoftSpy.exe XoftSpy antispyware software X xor svchost.exe XORDOOR TROJAN! This is not the valid svchost.exe as described here X xp winis.exe W32/RBOT-WO WORM! X xp service pack 2 xpsp2.exe Sdded as result of a W32/Rbot-KW worm infection X xp_system services.exe "Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!" X xp_system services.exe W32.Conycspa.G WORM! X xp_system winlogon.exe "Krepper-G trojan, a CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!" X xp32win xpupdater02.exe TROJ/MOSUCK-A TROJAN! X XPCPHOST Settings xpcphost.exe variant of the WIN32.RBOT WORM! X xpiupdate xpiupdate.exe W32/RBOT-AAB WORM! X xpiupdate xpiupdate.exe W32/RBOT-AFY WORM! X XPSoft CVDAsDW.exe W32/SDBOT-SY WORM! X XPSP2 Firewall xpsp2fw.exe WIN32.SMALL.RN downloader TROJAN! X xpstart wini.exe W32.PICRATE.A WORM! X xpstat winlogins.exe W32/RBOT-AAR WORM! X XPsys XPsys.exe DELF-KQ or Troj/Dloader-SG TROJAN! X xpsystem MSXMIDI.EXE "CoolWebSearch parasite variant, identified by Kaspersky_antivirus as TrojanDropper.Win32.Small.cw" X xpsystem services.exe CoolWebSearch parasite related. X xpsystem y.exe CoolWebSearch parasite related X xpupdate updates.exe W32.Bropia.L WORM! X xserv ?? Troj/Stumpy-A TROJAN! U XStop95 XStop95.exe XStop - internet filter N xswin xswin.exe "Installed with a Xerox Work Centre Pro 555. Unchecking it removes an ""out of system memory"" error" X XTN Service Drivers winxtn.exe W32/Sdbot-YK WORM! U XTNDConnect PC - 3CmPlm Autodet.exe Component of EasySync Pro. Synchronisation between Palm PDAs? and Microsoft Outlook U XTNDConnect PC - ErPhn2 ErPhn2.exe Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook U XTNDConnect PC - ErTray ErTray.exe Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook U XTNDConnect PC - LtNts4 NtsAgnt.exe Component of EasySync Pro X Xtray xtray_link.exe TROJ_VB.JL trojan U XtreamLok License Manager xl.exe License manager for xLok (XtreamLok) - prevents software being reverse engineered U Xtrem parental control pcx.exe ParentXtreme SPYWARE! **Note - If you didn't intentionally install this software remove it. X XTServiceUpdate XTServiceUpdate.exe hahame.net adware downloader X XtTb.exe XtTb.exe Top-banners.com adware X Xupiter Startup XupiterStartup.exe Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here X XupiterCfgLoader ?? Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here X xupiterstartup2003 xupiterstartup2003.exe Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here X XupiterToolbarLoader XupiterToolbarLoader.exe Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here U xv_ctrl v_ctrl.exe "3dfx Underground Tools - ""Gives direct hardware control to your video graphics adapter""" X xware cskware.exe "Malware downloader from xxsware.com, produces porn popups." X xware xware.exe "Malware downloader from xxsware.com, causes porn popups" X xxcm sys.exe W32/KRISWORM-A WORM! X xxsrSrv32 xxsrsrv.exe TROJ/BANCSDE-E TROJAN! X XXXmpeg XXXmpeg.exe Adult content dialler X xxxvideo xxxvideo.exe AccessPlugin premium rate adult material dialer U Y!TunnelBasic YTBasic.exe Y!TunnelBasic software provides additional features to Yahoo! Messenger. U Y!TunnelPro YTPro.exe "Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia" U Y!TunnelPro YTunnelPro.exe "Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia" X yaemu.exe yaemu.exe WIN32.DNSCHANGER.S TROJAN! X yahoo groups upgrdmgr.exe variant of the WIN32.RBOT WORM! X Yahoo Instant Messengar YahooMsgr.exe WIN32.SDBOT.GEN TROJAN! X Yahoo Messenger Yahoomsg.exe unidentified WORM or TROJAN! X Yahoo Messenger YPager.exe W32/RBOT-QO WORM! X Yahoo Update Yahoo.exe Yahoo! TROJAN! X Yahoo Updater Messenger.exe W32/Forbot-FE WORM! N Yahoo! Pager ypager.exe Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs X yahoo_toolbar lptt01 or yahoo_toolbar ml097e yahoo_toolbar.exe "Variant of the RapidBlaster parasite (in a ""yahoo_toolbar"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here" X Yahoo2000 Anti.exe RBOT.ATK WORM! X YahooStock Prmvr.exe Adtomi adware X YahooStock ystckAO32.exe Adtomi adware N YAMAHA DS-XG Launcher dslaunch.exe System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups N Yankee Clipper III YankClip.exe "Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar ""Outlook"" interface'. Freeware" N YBrowser ybrwicon.exe SBC Yahoo! Browser system tray icon X yeahdude.exe hallowelt.exe GAOBOT.RS or GAOBOT.SA WORMS! N YOP yop.exe Dashboard Module for SBC Yahoo! Online_Protection U You've Got Pictures Screensaver ygpsstra.exe AOL You've Got Pictures˝ Screensaver N ypager ypager.exe Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs U YPC ypc.exe "Yahoo Parental controls - ""Let you decide what type of sites and Yahoo! services your kids can access""" Y YTrayMagic Lite 1 YTRAYMAGIC.EXE YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored X Yugoslavia yugoslavia.exe Premium rate adult content dialer U Yumgo's Homepage Protector V1 YumgoHomepageProtector.exe Yumgo's Homepage Protector X ywzizdon ywzizdon.exe Free_Scratch_Cards foistware X yyyyyyyy ?? MUMUBOY.B VIRUS! X yz.exe yz.exe VARDO VIRUS! X YZH.SYS YZH.exe W32.SOPHILY VIRUS! X ZaCker ?? HOLAR.A VIRUS! where is the worm filename X Zacker Zacker.exe GEMEL VIRUS! X zango zango.exe 180Solutions/N-Case adware variant X Zango TvTimes ZANGOT~1.EXE ZangoSearch adware X zanu zanu.exe 180Solutions/N-Case adware variant Y Zapro Zapro.exe Firewall program from Zonelabs - paid for version U zBrowser Launcher Commandr.exe "For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc. if it doesn't have them" U zBrowser Launcher iTouch.exe "For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn\'t have them" U Zcfgsvc ZCfgSvc.exe "Zero Config MFC Application, part of Intel?s ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing ?Not Responding? or ?End this Program? shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have Windows XP/2003, try setting the ?Wireless Zero Configuration? service to Disabled." X zcproo qssstiej.exe "Possible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguise. see this thread" N zdnet kontiki.exe Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops N Zebus msdc32.exe Runs a HTML tutorial on the Zebus web-site X Zekio Startups znksvc32.exe W32/AGOBOT-AGI WORM! X Zen.A ?? Perl/Zoomen-A trojan infection X Zenet "rundll32 CNBabe.dll, DllStartup" CommonName Toolbar spyware. To uninstall see here Y ZENRC zenrc32.exe "The main component of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management"".Leave well alone" Y ZENRC Tray Icon zentray.exe "Part of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management"".Best left alone" Y ZENworks Imaging Service ZISWin.exe "Imaging Agent. Part of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management""" U ZeroAds ?? "ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually" U ZeroAds LAS0Ads.exe "ZeroAds - culls ads, cookies and pop-ups. Required for the cookie interception to work" U ZeroSpyware ZeroSpyware.exe FBM Software ZeroSpyware 2004 spyware detector and remover X zervpack2 update2.exe SDBOT.WD WORM! X zerzvpack2 uzpdate2.exe Rbot-KA worm infection X ZIBMACC rundll.exe -> ZIBMACC.INF ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435) U ZingSpooler ZingSpooler.exe Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums N Zinio DLM ZDLM.EXE Zinio - used to read magazines in digital rather than paper format X Zip Driver Loader msload32.exe OBLIVION TROJAN! X Zip Driver Loader ZipLoader.exe OBLIVION TROJAN! U ZipDisk Icons IMGICON.EXE "Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running" N ZipGenius Clean zg.exe ZipGenius file compression utility X ziphelp ziphelp.exe CoolWebSearch parasite related. N ZipMagic zm32.exe Zip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first Y zlclient or Zone Labs Client zlclient.exe Firewall program from Zonelabs. Pro version inlcudes other online security options U ZLH ZLH.EXE System Tray icon for Norman Antivirus X Zonavirus ?? KITRO.D (or ARGEN.A) VIRUS! X Zone Alarm vsmon.exe WORM_RBOT.BO X Zone Labs Client Ex svchost.exe "W.32NETSKY.F WORM! **Note This is not the valid svchost.exe as described for WinXP or Win2K . Located in a Windows directory, and not in Windows\System32" X Zone system szchost.exe TROJ/MULTIDR-AC TROJAN! X zonealarm "mcmm.exe, random file names" unknown worm or trojan infection X Zonealarm Removeme.exe W32/FORBOT-BG WORM! Y ZoneAlarm zonealarm.exe Firewall program from Zonelabs - free version Y ZoneAlarm Plus zaplus.exe Firewall program from Zonelabs - paid for version Y ZoneAlarm Pro Zapro.exe Firewall program from Zonelabs - paid for version U Zoom zoom.exe Zoom - speeds up Windows startup and manages startup applications Y ZPOINT32 ZPOINT32.exe USB graphics/writing tablet driver X zSearch Zstb.exe TotalVelocity zSearch parasite X zsms smss.exe "BANCOS-CK TROJAN! - Note - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!" X zsmsgs iservice.exe TROJ/BANCOS-BU TROJAN! X zsmss smss.exe Troj/Bancos-DD TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder. U zSPGuard Spguard.exe """StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'.""" X ZStart ?? "Adware, probably VX2/Transponder related - filenames spotted include rdxregpp.exe, tdxregrs.exe and more." X ZtgServerSwitch server.vbs ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware X Zupdate Zupdate.exe "B3d Projector - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents" U z-WrDialer WrDialer.exe WinPoet DSL dialer X zzb zzb.exe IAGold_adware downloader X zzb2 zzb2.exe IAGold_adware downloader X zzgshp gshp.vbs Homepage hi-jacker that re-defines your IE or Netscape start page X zztp svchost.exe "TANNICK.B TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"