"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly"
Y
!1_ProcessGuard_Startup
procguard.exe
"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks."
U
!NoLoad
winrecon.exe
"WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it"
U
$EnterNet
Enternet.exe
Connection manager for the EnterNet ISP. You can also use RASPPOE
X
$WindowsRegKey%update
IEXPLORE.EXE
"W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually!"
X
(L4r1$$4) (4nt1) (V1ruz)
SP00Lsv32.pif
ASSIRAL.B WORM!
X
*JanisRuckenbrodII
janis.com
POPS VIRUS!
X
*Microsoft Update
ctxma.exe
W32.HLLW.STMU TROJAN!
X
*Microsoft Update
cxma.exe
W32.HLLW.STMU TROJAN!
X
*microsoft update
cxma.exe
W32.HLLW.STMU TROJAN
X
*Microsoft Update
wstcl.exe
W32.HLLW.STMU TROJAN!
X
*Microsoft Update
wucxt.exe
W32.HLLW.STMU TROJAN!
X
*Microsoft Update
wuytc.exe
W32.HLLW.STMU TROJAN!
X
*MS Setup
??
"Virtumondo adware, also known as the VUNDO TROJAN!"
X
*Security Center
secctr.exe
SDBOT.BRO WORM!
Y
*StateMgr
statemgr.exe
Windows ME default for System Restore. Do NOT disable!
X
*windows update
waurclt.exe
variant of the WIN32.RBOT WORM!
X
*windows update
wkmst.exe
SDBOT.AVD WORM!
X
*windows update
wsctl.exe
SPYBOT.PR WORM!
X
*windows update
wscxt.exe
RBOT.AOS WORM!
X
*windows update
wuaucrlt.exe
SPYBOT.HUR WORM!
X
*windows update
wurauclt.exe
W32/RBOT-SY WORM!
X
*WinLogon
??
VUNDO TROJAN!
X
*winstats
winstats.exe
Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
X
*wuauclt.exe
wmsvc.exe
W32/RBOT-UG WORM!
X
",main drive Loader"
wininfo.exe
Suspected malware as it appears in 3 different registry locations - see here
X
.mscdr
lassa.exe
WEBUS.C TROJAN!
X
.mscdr
lsvchost.exe
WEBUS.D TROJAN!
X
.mscdsr
lsvchost.exe
Troj/Bdoor-CR Trojan!
X
.mscsbl
svhost.exe
BACKDOOR-CMQ TROJAN!
X
.msfupdate
msveup.exe
W32.ALLOCUP.A WORM!
X
.mssecure
mssecure.exe
DDOS_BOXED.X TROJAN!
X
.mssecure
mssecure.exe
Troj/Borobot-B Trojan!
X
.norton
rchost.exe
variant of the BOXED-A TROJAN!
X
.Prog
services.exe
NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process
X
.Prog
winlogon.exe
NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
X
.svchost
CSRSS.EXE
"WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
.TEXTCONV
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
.WMAudio
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process"" which provides text window support, shutdown, and hard-error handling"
X
.WMAudio
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
N
/l:eng
??
"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup"
X
;Rundll
??
PWSLEGMIR.E VIRUS!
X
??
??
Troj/StartPa-GL Trojan! Found in the WINDOWS or Winnt directory.
X
??
??
Troj/Mosuck-H TROJAN!
X
??
_autorun.exe
W32/Antinny-L WORM!
X
??
_cfg.exe
W32/Antinny-L WORM!
X
??
_config.exe
W32/Antinny-L WORM!
X
??
_ctcp.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
_env.exe
W32/Antinny-L WORM!
X
??
_loader.exe
W32/Antinny-L WORM!
X
??
_login.exe
W32/Antinny-L WORM!
X
??
_setup.exe
W32/Antinny-L WORM!
X
??
_start.exe
W32/Antinny-L WORM!
X
??
10010.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
321102.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
321102.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
34763.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ABCXYZ.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
abrek.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
acctres8.exe
Adsrv.com/IeDriver adware variant
X
??
ActionScr.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
actxprxy.exe
Adsrv.com/IeDriver adware variant
X
??
admparse.exe
Adsrv.com/IeDriver adware variant
X
??
advpack1.exe
Adsrv.com/IeDriver adware variant
X
??
AliceSD.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
AppMasterCenter.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
asferror.exe
Adsrv.com/IeDriver adware variant
X
??
atitvo32.exe
Adsrv.com/IeDriver adware variant
X
??
atl_helper.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ATLIEHELPER.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
audiosrv.exe
Adsrv.com/IeDriver adware variant
X
??
autodisc.exe
Adsrv.com/IeDriver adware variant
X
??
avicap32.exe
Adsrv.com/IeDriver adware variant
X
??
avifile5.exe
Adsrv.com/IeDriver adware variant
X
??
avpmondll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
awinrar.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
backd.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
backorif.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
barint.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
batmeter.exe
Adsrv.com/IeDriver adware variant
X
??
bhoserv.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
bidispl2.exe
Adsrv.com/IeDriver adware variant
X
??
bingo9.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
bling.exe
W32/RBOT-NI WORM!
X
??
bnui.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Bogobot.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
bootvid2.exe
Adsrv.com/IeDriver adware variant
X
??
bootvid4.exe
Adsrv.com/IeDriver adware variant
X
??
borlandg.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
BoundRec.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
br0ken.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Brong32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
browser8.exe
Adsrv.com/IeDriver adware variant
X
??
cabview1.exe
Adsrv.com/IeDriver adware variant
X
??
catsrvps.exe
Adsrv.com/IeDriver adware variant
X
??
cdmodem4.exe
Adsrv.com/IeDriver adware variant
X
??
charmapnt.exe
Troj/Bancos-DR TROJAN!
X
??
chkdsk.exe
"PurityScan/Clickspring adware - unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2000/NT always be located in the Winnt\System32 or Windows\System32 folder, and ought moreover NOT to figure among the startups!"
X
??
clamav.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
N
??
cmmpu.exe
MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
X
??
cmon14.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
cmon14.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
cmpbk321.exe
Adsrv.com/IeDriver adware variant
X
??
cnftips.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
control64.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
corrida.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
CToolBar.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
CXTPLS_LOADER.EXE
AproposMedia adware
X
??
d?dplay.exe
PurityScan/Clickspring adware
X
??
d?xplore.exe
PurityScan/Clickspring adware
X
??
DCC_send.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
defect08.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
dePloy.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Dest068.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
dexplore.exe
PurityScan/Clickspring adware
X
??
dialer423.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
die.exe
SUMTAX VIRUS!
X
??
diskcheck.exe
BACKDOOR.SINGU.B TROJAN!
X
??
diskserv.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
N
??
dlbabmgr.exe
Dell AIO Printer A940 related. Not Required at Startup
X
??
driver32.exe
variant of the W32/SDBOT WORM!
X
??
driver64.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
DrWatson32.exe
Dremn TROJAN!
X
??
dstart2.exe
Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.alw
X
??
DTOURS.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
dvdplay.exe
PurityScan/Clickspring adware
X
??
ERTYDF.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ExchangeMaster.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
EXE32EXE.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
exe81.exe
"MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on."
X
??
exe82.exe
"MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on."
X
??
expoler.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
FLKPT.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
forces_elite.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ftbar.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
N
??
fts.exe
012 Israeli ISP dialer - can be loaded manually
N
??
FWPortal.exe
012 Israeli ISP dialer - can be loaded manually
X
??
gabber.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
hyandex.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
iehelper.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
iesetupdll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
init32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
InpriseMon.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
install2.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
j?vaw.exe
PurityScan/Clickspring adware
X
??
JAguAr.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
jopplerg.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Kargo.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
keybdll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
KeywordFinder.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
killall.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
l?ass.exe
PurityScan/Clickspring adware
X
??
l?gonui.exe
PurityScan/Clickspring adware
X
??
LOPTCON.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
lsass.scr
Troj/Bancban-CW Trojan!
X
??
m?config.exe
PurityScan/Clickspring adware
X
??
m?dtc.exe
PurityScan/Clickspring adware
X
??
m?iexec.exe
PurityScan/Clickspring adware
X
??
media64.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
mediaplayer32.exe
variant of the WIN32.RBOT WORM!
X
??
MNTP.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
MON76234.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
moniter.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
mozilla-text.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
msag.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
msdos32.exe
variant of the WIN32.AGENT.AH downloader TROJAN!
X
??
ms-its.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
MsNetHelper.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
MSTCPDLL.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
n?lookup.exe
PurityScan/Clickspring adware
X
??
n?pdb.exe
PurityScan/Clickspring adware
X
??
n?tdde.exe
PurityScan/Clickspring adware
X
??
n?tepad.exe
PurityScan/Clickspring adware
X
??
new32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
newbreed.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
nmdllw.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
NopeZ.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
NsCplTray.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
NSYSCPLSTR.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
NukeSpan.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
openstre.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
panel_its.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ParisM.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
PasswdMon.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
pathex.exe
TROJ/MKMOOSE-A WORM!
X
??
ping.exe
PurityScan/Clickspring adware - NOTE - do not confuse with the Microsoft utility of the same name as described here
X
??
pizda.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
powerdll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
PrcIdle.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
prcmon.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Preliminary.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
prgsys0984.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
progmen.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
qtsks.exe
WEBDOR.Y TROJAN
X
??
qwe.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
r?gedit.exe
PurityScan/Clickspring adware
X
??
r?gsvr32.exe
PurityScan/Clickspring adware
X
??
r?ndll.exe
PurityScan/Clickspring adware
X
??
r?ndll32.exe
PurityScan adware variant
X
??
roses.exe
W32/Rbot-AFT Worm!
X
??
RtlFindVal.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
runload32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
SAPSTR.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
sbin.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
scanregw.exe
PurityScan/Clickspring adware
X
??
scanSYS.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
se?vices.exe
PurityScan adware variant
X
??
seli.exe
"MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, ""piz, :C=e, resU and so on."
X
??
Serviceprocess.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
SetupExeDll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Shaitan1678.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
sitebar.exe
unidentified TROJAN!
X
??
slamm.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
sound64.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
spoolsv.exe
PurityScan/Clickspring adware
X
??
SpyElim.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
srbho.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ssweeper.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
StartCpl.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
startman.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
StatusCheck.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
stuffmon.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
svchost.scr
Troj/Bancban-CX and Troj/Bancban-DA TROJANS!
X
??
svchost.scr
Troj/Bancban-CY Trojan!
X
??
svchost.scr
BANKER-CC TROJAN!
X
??
svchostss.exe
variant of the WIN32.RBOT WORM!
X
??
sysconf16.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
SysEntry.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
sysmon12.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
syspanel.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
SysSupport.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
System.exe
Troj/Nethief-N Trojan!
X
??
SYSTRAV.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
t?skmgr.exe
PurityScan/Clickspring adware
X
??
TemplateDongle.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
teqq32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Testimonials.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
TForm1.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
tmservice.exe
variant of the WIN32.RBOT WORM!
X
??
TorontoMail.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Trayz.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
TRPT.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
trycrt.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
ttg.exe
SUMTAX VIRUS!
X
??
typeconf.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
Uint32.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
uio.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
UserSp1.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
utsgmon.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
vxdman.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
w?aclt.exe
PurityScan/Clickspring adware
X
??
w?auboot.exe
PurityScan/Clickspring adware
X
??
w?auclt.exe
PurityScan/Clickspring adware
X
??
w?crtupd.exe
PurityScan/Clickspring adware
X
??
w?nlogon.exe
PurityScan adware variant
X
??
w?nspool.exe
PurityScan/Clickspring adware.
X
??
w?nword.exe
PurityScan adware variant
X
??
w?wexec.exe
PurityScan/Clickspring adware
X
??
WhatsNewBot.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
win32API.exe
"Homepage hijacker, see here (* = any digit)"
X
??
win32snd.exe
W32/RBOT-DQ WORM!
X
??
WinInitDll.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
winSOCKS.exe
"Homepage hijacker, see here (* = any digit)"
X
??
wormexe.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
WTFCTF.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
wuauboot.exe
"PurityScan/Clickspring adware = NOTE: Do NOT confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!"
X
??
wucrtupd.exe
PurityScan/Clickspring adware - do NOT confuse with the Windows Critical Update Notification application as described here
X
??
x1.exe
Troj/Dadobra-A TROJAN!
X
??
x2.exe
Troj/Dadobra-A TROJAN!
X
??
x3.exe
Troj/Dadobra-A TROJAN!
X
??
x4.exe
Troj/Dadobra-A TROJAN!
X
??
x5.exe
Troj/Dadobra-A TROJAN!
X
??
x6.exe
Troj/Dadobra-A TROJAN!
X
??
x7.exe
Troj/Dadobra-A TROJAN!
X
??
XTermInit.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
xwiz.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
xxtoolbar.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
zantu.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
??
zxc.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
?ekio Startups
??
W32/AGOBOT-OV WORM!
X
@
??
SEEKER.K VIRUS!
N
@Hoc Toolbar
AtHoc.exe
One-click activated browsing toolbar used by various web-sites. See here for more info
N
@loha
reminder.exe
Registration reminder for @loha@home E-mail utility
X
@tour_ww
??
Adult content dialler
X
[Ephemeral 2.x] by TreeHugger
??
"LEMOOR.A WORM! where ""x"" represents 3 or 4"
N
[System Mechanic Professional Update [Incinerator.dll]
??
"System_Mechanic's ""Incinerator"" feature securely deletes files and folders from your PC so they can never be recovered again."
X
\TOOLS.exe
tools.exe
Lycos SideSearch/Fastfind.org adware
X
^`d}qZxu
~`d}qzxu3zYF
GAOBOT.GEN!POLY WORM!
U
_AntiSpyware
MssCli.exe
McAfee AntiSpyware
X
_Cat1
nmmst.exe
TROJ_SMALL.SD TROJAN!
X
_Cat2
nmstt.exe
TROJ/SMALL-DT downloader TROJAN!
X
_Cat3
msmsgrxp.exe
variant of the TROJ/SMALL-DT downloader TROJAN
X
_Cat4
msmsgr2.exe
TROJ/SMALL-EB TROJAN!
X
_Hazafibb
??
ZAFI.B WORM! infection
X
_ntrdlhost
_Ntrdlhost.exe
TROJ/DLOADER-JV TROJAN!
X
_ntrRescueService
_ntrrs.exe
TROJ/DLOADER-JV TROJAN!
X
_pnd_Panda Antivirus
??
Malware! - detected by ESET's Nod32 antivirus as Win32/TrojanDropper.Agent.NAK
X
_svchost.con
svchost.com
W32.ERKEZ.C WORM!
X
_System_Run
_svchost_.exe
Troj/Lineage-Z TROJAN!
X
_SystemBoot
services.exe
"TROJ/SOBER-Q TROJAN!! - NOTE - this file is placed in a ""%Windir%\Help\Help"" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
_SystemDriver
csrss.exe
"ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!"
X
_tdiserv_
_tdicli_.exe
W32/Tdibd-A WORM!
X
_tdiserv_
_tdicli_.exe
W32.TDISERV.A WORM!
U
_winadm
winadm.exe
"Parents Friend - ""Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC"""
X
_WinMain
winexec.exe
Malware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.ts
X
_WinStart
services.exe
"W32.SOBER.O WORM! - Note - this file is placed in a ""%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
_winsystem.sys
smss.exe
W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
X
_x-Finder
_x-Finder.exe
Disconnects and redials an ISP modem to an adult content site
U
{0228e555-4f9c-4e35-a3ec-b109a192b4c2}
gnotify.exe
Google Gmail_notifier . Alerts you when you have new Gmail messages.
X
{12EE7A5E-0674-42f9-A76B-000000004D00}
??
BrowserAid/Startium parasite
X
{2CF0B992-5EEB-4143-99C0-5297EF71F444}
??
BrowserAid/Startium parasite
X
{2CF0B992-5EEB-4143-99C2-5297EF71F44B}
??
BrowserAid/Startium parasite
X
000hpdllhos
hpdllhost.exe
LZIO.com adware downloader
U
000StTHK
000StTHK.exe
"Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)"
X
0050726-007-i32-1
0050726-007-i32-1.exe
Troj/Bancban-EC TROJAN!
U
00THotkey
00THotKey.exe
"For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev."
U
0190 Warner
WARN0190.EXE
Anti-dialer program (Germany)
U
0900 Warner
WARN0900.EXE
Anti-dialer program (Germany)
X
0utlook Express
??
W32/RBOT-CC WORM!
X
╜Windows Update
svchosts.exe
FRUTCA TROJAN!
X
1111swapmgr.exe
1111swapmgr.exe
BDOOR-IC TROJAN!
U
12Ghosts Popup-Killer
12popup.exe
12Ghosts Popup-Killer
X
180adsolution
180adsolution.exe
180Solutions/N-Case adware variant
X
180ax
180ax.exe
180Solutions/N-Case adware variant
X
180ClientStubInstall
??
180Solutions adware related
X
180ClientStubInstall
??
180Solutions adware related
X
180ClientStubInstall
??
180Solutions adware related
N
1A:MacVisionTrayMonitor
TrayMonitor.exe
Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
Y
1A:Stardock MCP
mcpserver.exe
"Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications"
Y
1A:Stardock TrayMonitor
TrayServer.exe
For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
X
1on1
1on1.exe
Adult content dialler
U
1Srv32
SpyAgent4.exe
"SpyTech SpyAgent monitoring software. ""Spy software that allows you to monitor EVERYTHING users do on your PC."""
U
1Win32Cfg
Keyloggerpro.exe
KeyloggerPro - monitoring software
U
1Win32Cfg
SpyBuddy.exe
SpyBuddy monitoring software
X
1WinCfg32
WebMailSpy.exe
WebMailSpy SPYWARE!
X
2020Downloader
mssvr.exe
2020Search Toolbar related. Reported to be auto-installed
Y
2kadiras
2kadiras.exe
Allied_Telesyn AT series router/modem related - apparently required
X
2thousandbuck
??
RANKY.L TROJAN!
U
2wSysTray
2portalmon.exe
2Wire Homeportal user interface
X
32-bit Thunking service
thunk32.exe
W32.Derdero.A WORM!
X
357AA41A-B7A8-4632-A27D-5B980B25CF43
??
SMALL-AQ TROJAN!
X
357AA41A-B7A8-4632-A27D-5B980B25CF43
services.exe
"FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
Y
3c1807pd
??
3Com WinModem driver. See here for more WinModem information
Required for a US Robotics WinModem as it provides the link to Windows - won't work without it.
Y
3Cmlink
3CmlinkW.exe
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
"From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games"
X
3Dfx Acc
GFXACC.EXE
GIBE VIRUS!
N
3dfx Task Manager
3dfxMan.exe
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
Y
3dfx Tools
3dfxCmn.dll
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
Y
3dfxv2ps.dll
3dfxv2ps.dll
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
U
3DLabsHelperDemon
3dldemon.exe
"Directly from the programs author ""It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive."" In most cases it can be safely disabled"
Y
3DMouse.EXE
3DMouse.EXE
Dritek System Inc. 3D Mouse driver
U
3qdctl.exe
3qdctl.exe
"Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ"
Y
3ware 3DM
3dm.exe
Monitors status of the disk array on 3ware IDE RAID controllers
X
4wd!!!
Natal!.pif
OPASERV.AI VIRUS!
X
5-1-61-96
members-area.exe
Adult content dialler
X
5-2-46-112
5-2-46-112.exe
Adult content pop-up dialler. Removal instructions here
X
5p4m
??
Troj/Litebot-C TROJAN!
X
98D0CE0C16B1
??
BrowserAid/Startium parasite related
Y
9xadiras
9xadiras.exe
Allied_Telesyn AT series router/modem related - apparently required
X
9xHtProtect
AVprotect9x.exe
W32.NETSKY.M WORM!
X
a
a.exe
Commercials file that registers itself in the system registry and redirects IE to a certain commercial website
X
A New Windows Updater
w32NTupdt.exe
W32.Mytob.BM WORM!
U
A1000 Settings Utility
cpqa1000.exe
"Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features"
U
A4Proxy
A4Proxy.exe
Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
X
A70F6A1D-0195-42a2-934C-D8AC0F7C08EB
??
BrowserAid/Startium parasite related
N
AAATraySaver
TraySaver.exe
"System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray"
U
AAK
aak.exe
"Advanced Anti-Keylogger - ""Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"""
X
Aaou
amee.exe
PurityScan/Clickspring adware
X
Aapp
adprot
AdBlaster adware
N
ABBYY Community Agent
CAGENT.EXE
Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the?5.0 version of the software
X
ABC
keylogger.exe
Monitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by SpyCop in their FAQ
N
ABITEQ
abiteq.exe
"Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds."
U
Absolute Shield
dseraser.exe
Absolute Shield/Evidence Eliminator - iternet history eraser
U
Absolute StartUp monitor
ASMon.exe
Absolute Startup - startup monitor from F-Group Software
X
ABsr
absr.exe
AUTOUPDER VIRUS!
X
absr
mwsvm.exe
SeekSeek search hijacker related - as seen here
X
abtu
lopsearch.exe
Loads the executable for LOP adware - mp3serch.exe is the final version whilst lopsearch.exe is the beta version
X
abtu
mp3serch.exe
Loads the executable for Lop.com. mp3serch.exe is the final version whilst lopsearch.exe is the beta version
U
AbyssWebServer
abyssws.exe
Abyss web server
Y
AcBtnMgr_Xxx
AcBtnMgr_Xxx.exe
"Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation"
U
acc
acc.exe
"Advanced Call Center - ""full-featured yet easy-to-use answering machine software for your voice modem"""
X
ACCDEFRAGINFO
??
W32/Darby-O WORM!
U
Accelerate
accelerate.exe
Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
N
Access Ramp Monitor
armon32.exe
"Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again"
X
Access WebControl
??
TROJ/PPDOOR-M TROJAN!
U
AccessManager
AccessMgr.exe
"Part of SmartPipes SecureSite software - ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"""
X
AccessMedia P2P Loader
amp2pl.exe
"My AccessMedia toolbar related, stealth installed!"
U
AccessoriesPlus
clockplus.exe
"""Clock Plus"", part of Accessories_Plus allows you to select from dozens of alternatives for the Windows clock."
N
AccessRamp Monitor01
ARMon32a.exe
"From a visitor ""Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."""
N
AccessRampLAN01
ARUpld32.exe
"Version of the above for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003"
U
AcctMgr
AcctMgr.exe
"Norton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities?all from the safety of your own PC"
N
AccuWeather.com╜ Desktop
??
Desktop weather from AccuWeather.com
X
accwizz.exe
accwizz.exe
W32.Ruland.A WORM!
X
accwizzz.exe
accwizzz.exe
W32.Ruland.A WORM!
Y
Acecad.Wtxpload
Wtxpload.exe Acecad
driver for an AceCad USB Graphics Tablet
N
AceGain LiveUpdate
LiveUpdate.exe
"AceGain_LiveUpdate . ""AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences."""
U
AcerGoto
AcerGoto.exe
"Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer."
U
AcerNotebookManager
almxptray.exe
System Tray access on some Acer Notebooks to give faster access to system settings
U
AcerPowerkey
Powerkey.exe
PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn F3
X
Aceu
??
PurityScan/Clickspring adware
U
AClntUsr
AClntUsr.exe
Altiris AClient Service Windows Tray Icon
N
Acme.PCHButton
pchbutton.exe
Used by HP Instant Support
Y
ACMonitor_Xxx
ACMonitor_Xxx.exe
"Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation"
X
acocash
fastdown.exe
Adult content dialler
X
acocash
fastfown.exe
Adult content dialler
U
Acombo3dmouse
Acombo3d.exe
Mouse driver - required if you use non-standard Windows driver features
X
Aconti
aconti.exe
Adult content dialler
U
acoustic
acoustic.exe
Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained
N
acpart
agpart11.exe
Program for finding trucks on-line
U
Acrobat Assistant
ACROTRAY.EXE
"Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation"
U
Acronis Scheduler2 Service
schedhlp.exe
"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images"
N
Acronis True Image Monitor
TrueImageMonitor.exe
Part of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
N
Acronis TrueImage Monitor
TrueImageMonitor.exe
Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage
N
AcronisTrueImage Monitor
TrueImageMonitor.exe
Part of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
N
Action Manager 32
am32.exe
Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
N
Activation
Activation.exe
Part of Microsoft Money
U
Activboard
MMKeybd.exe
"Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys"
X
Active Bit Station
abs.exe
W32.MYTOB.BZ WORM!
U
Active Email Monitor
aem25.exe
"Active_Email_Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email."
U
Active shield
Activeshield.exe
"Active_Shield is ""an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses["""
X
ActiveDesktop
systray32.exe
DABOOM VIRUS!
X
ACTIVEDS
ACTIVEDS.EXE
OPASERV.T VIRUS!
N
ActiveEyes
ActiveEyes.exe
ActiveEyes from TFI Technology
U
ActiveMenu
ActiveMenu.exe
Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
U
ActivePlus
activeplus.exe
Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)
Y
ActiveShield
MCVSSHLD.EXE
McAfee VirusScan On-line. See also McAgentExe entry.
U
ActiveSpeed
AS.exe
Ascentive ActiveSpeed Internet Optimizer
X
ActiveX Streamer
msgfix.exe
SDBOT.NQ WORM!
X
ActiveXUpdate
svcss.exe
variant of the DEDLER.C TROJAN!
U
Activity
actik.exe
ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself!
N
ActivSurf
??
Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
U
ActMaker
ActMak25.exe
"The ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer."
U
ACU
ACU.exe
Atheros wireless Client Utility For HP Compaq
U
ACU_QSB
ACU.exe
Atheros wireless Client Utility For HP Compaq
U
Ad Blocker
blocker.exe
"Ad Blocker - blocks popups, and also removes banners, image ads and flash ads"
U
Ad Blocker Pro
Ad Blocker Pro.exe
"""Ad Away"" popup and banner remover"
U
Ad Muncher
AdMunch.exe
"Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications"
U
AD2KClient
AD2KClient.exe
Executable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip╜ disk. Required if you wish the applications to launch on insertion of a disk
N
Adaptec DirectCD
Directcd.exe
DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
N
AdaptecDirectCD
Directcd.exe
DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
X
AdAware
wini.exe
W32/RBOT-XN WORM!
N
Ad-aware
Ad-aware.exe
"Ad-aware from Lavasoft. Checks your PC for ""Spyware"" which reports back your internet activities to ""base"". Available via Start -> Programs"
X
Ad-Aware
Ad-Aware.exe
W32/Rbot-ADJ Worm!
N
Adaware Bootup
ad-aware.exe
"Ad-aware from Lavasoft. Checks your PC for ""Spyware"" which reports back your internet activities to ""base"". Available via Start -> Programs"
X
Adaware lptt01 or Adaware ml097e
adaware.exe
"Variant of the RapidBlaster parasite (in a ""Adaware"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware"
X
Add**.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
Add**32.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log."
U
AdDelete
AdDelete.exe
Banner advertisment blocker
X
AdDestroyer
AdDestroyer.exe
"Like VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code"
N
ADGJdet
ADGJDet.exe
Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Y
Adiras
Adiras.exe
ADSL USB modem related
X
ADM Library Loader
admlib32.exe
variant of the SDBOT WORM!
X
Admanager Controller
AdManCtl.exe
WindUpdates ADW_WINAD.M adware
X
Admilli Service
AdmilliServ.exe
WindUpdates AdmilliServ adware
X
AdminSoft
sysfile.vbs
VBS/STARGRUB-A WORM!
U
Ad-Muncher
ADMUNCH.EXE
"Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications"
X
Adobe
Adobe.exe
unidentified VIRUS!
X
adobe
gam.exe
unidentified WORM or TROJAN!
X
Adobe
sysbat32.exe
TROJ_LOWZONES.T TROJAN!
X
Adobe
sysconfig.exe
unidentified WORM or TROJAN!
X
Adobe
zteam.exe
unidentified TROJAN!
X
Adobe Acrobat Distiller Application
acrotray.exe
W32.RANDEX.DFJ WORM!
X
Adobe Acrobat Reader CFG
??
variant of the WIN32.RBOT WORM!
U
Adobe Gamma Loader
Adobe Gamma Loader.exe
"Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine"
X
Adobe Photoshop 7.0
AdobePhotoshop.exe
variant of the W32/SDBOT WORM! - NOTE: Do NOT confuse with the Adobe photo editing software of the same name!
N
Adobe Reader Speed Lauch
reader_sl.exe
Speeds up the lauch of Adobe (Acrobat) Reader 7
N
Adobe Reader Speed Lauch
READER~1.EXE
Speeds up the lauch of Adobe (Acrobat) Reader 7
N
Adobe Reader Speed Launch
reader_sl.exe
"Speeds up the time it takes to load the Adobe_Reader application. Your choice, but not required for Adobe Reader to function properly"
X
AdobeA
adobes.exe
FLOOD.BA VIRUS!
X
AdobeFonts
fonts.hta
Browser hijacker - redirecting to Hugesearch.net
N
AdobeVersionCue
VersionCueTray.exe
"""An exclusive feature of the Adobe(r) Creative Suite, Version_ Cue(tm) helps you find files fast, track multiple versions of your files, and share your files for creative collaboration"""
X
Adope File Manager
lsasv.exe
unidentified WORM or TROJAN!
X
adp
adp.exe
"Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc"
X
adprot
adprot.exe
AdBlaster adware variant
N
ADQuickAccess
Adtray.exe
After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
X
AdRoarUpdate
ARUpdate.exe
AdRoar adware updater
X
AdRotator.Application
csrss.exe
"AdRotator adware variant - Note - do NOT be confuse with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt\System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
AdRotator.Application
services.exe
"FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
U
ADService
ADService.exe
Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip╜ disk. Required if you wish the applications to launch on insertion of a disk
U
AdsGone
Adsgone.exe
AdsGone - pop-up stopper
N
ADSL Diagnostic Tools
mapiicon.exe
System tray access to ADSL modem diagnostic tools. Available via Start -> Programs
Y
AdslTaskBar
??
"ISP software, initializes DSL modem"
Y
ADSS
ADSS.exe
ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied
X
adstartup
Adstartup.exe
Adlogix adware
X
adstartup
automove.exe
Adlogix adware variant
X
AdStatus Service
AdStatServ.exe
WindUpdates AdStatus_Service adware
U
AdSubtract
adsub.exe
"AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs"
X
Adtools Service
AdTools.exe
Windupdates Adware
X
Adult_Chat
Adult_Chat.exe
Adult content dialler
X
Adult_Chat1
Adult_Chat1.exe
Adult content dialler
X
AdultX
AdultX.exe
Adult content dialler and hijacker
X
AdUpdater
sysupudt.exe
Unidentified adware downloader/updater
U
ADUserMon
ADUserMon.exe
Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip╜ disk. Required if you wish the applications to launch on insertion of a disk
X
Advanced Internet Protocol
cerf.exe
W32.SpyBot worm variant
X
Advanced Protection System
advpsys.exe
variant of the WIN32.RBOT WORM!
X
Advanced Tool Checks
advchks.exe
variant of the WIN32.RBOT WORM!
N
Advanced Tools Check or ADVCHK
ADVCHK.EXE
Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
U
Advanced Uninstaller PRO Installation Monitor
monitor.exe
Innovative Solutions The user can choose whether or not to monitor installs.
X
Advapi
Advapi.exe
NETDEVIL.12 (NetDevil 1.2) VIRUS!
U
Advertising Killer
Akiller.exe
AKiller - pop-up stopper
X
advmon32
advmon32.exe
Crypter.C trojan variant infection
U
Adware Agent
adware agent.exe
Adware Agent popup blocker
N
Adware Spy
AdwareSpy.exe
"Adware remover - not recommended, see Rogue/Suspect_list"
X
AdwareAlert
AdwareAlert.Exe
"""Spyware remover"" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites"
U
Ad-watch
Ad-watch.exe
Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
N
AELaunch
AELaunch.exe
Audio Applications Launcher for the Philips Acoustic Edge soundcard
X
AERVICESN
AERVICESN.exe
W32/RANDON-AO WORM!
N
AeXAgentLogon
AeXAgentActivate.exe
Altiris Agent transmits information about your machine for the purpose of asset management and deployment
U
AEZBProc
aptezbp.exe
"IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions"
U
AFAFilter
windefault.exe
AFAFilter - internet filter software
N
Agent
Agent.exe
"Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs"
X
Agent Browser
??
PPdoor.M-bdr backdoor TROJAN!
X
Agent Explorer
??
Unidentified adware
X
agentsvr
agentsvr.exe
"Malware, detected by Kaspersky antivirus as AdWare.Monker.a - NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder."
U
AgfaCLnk
AgfaCLnk.exe
For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
X
agp
agp32.exe
W32.Gaobot.SY worm
Y
AGRSMMSG
AGRSMMSG.exe
IBM AMR modem driver
N
AGSatellite
AGSatellite.exe
Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
X
AGSeyApp
AGSeyApp.exe
GoldenEye SPYWARE!
N
ahfpor and ahfprog
ahfp.exe
"Advanced Hide Folders - ""is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"""
U
AHNSD
AhnSD.exe
AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis
N
AHQInit
ahqinit.exe
Part of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
X
Ahst
iebs.exe
PurityScan/Clickspring adware
X
Aica
tuaa.exe
PurityScan/Clickspring adware
X
Aida
eetu.exe
PurityScan/Clickspring adware
X
Aida
ttuh.exe
PurityScan/Clickspring adware
U
aiepk
aiepk2.exe
Another IE Popup Killer - pop-up stopper
N
AIM
aim.exe
"AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs"
X
AIM Instant Message Cookies
??
W32/RBOT-AFV WORM!
X
Aim Quick Start
Aim.exe
W32/Forbot-BB worm infection
X
AIM reminder
AIM reminder.exe
BUDDY VIRUS!
X
AIM95 Startup
aim95.exe
AGOBOT.AEE WORM!
X
aimaol lptt01 or aimaol ml097e
aimaol.exe
"Variant of the RapidBlaster parasite (in a ""Aimaol"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
U
aimb.exe
aimb.exe
"IMSufSentinel is a Spyware program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it."
N
AimingClick
AimingClick.exe
AimingClick from AimingTech. Web searching tool. Available via Start -> Programs
N
AIMster
??
Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
N
AIMWDInstall
AIMWDInstall.exe
"WildTangent on-line games installer as part of AOL Instant Messenger. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case"
Y
Aiptek Graphics Tablet (USB)
atwtusb.exe
USB interface for Aiptek Graphics Tablet (USB)
X
aircity
aircity.exe
"Related to ""Prutect"" malware from e2Give"
X
AKEYNAME
WinServ.exe
EVILBOT.C TROJAN!
U
AKiller
akiller.exe
BuyPin Advertising Killer - popup killer
U
ala.exe
ala.exe
Access_Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer.
U
Alarm Manager
Alarm.app.exe
Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop
N
Album Fast Start
ABMTSR.EXE
"Scanner software, not required for scanner to work"
X
Alchem
Alchem.exe
Transponder parasite updater/installer
X
alcmtr
ALCMTR.EXE
"Realtek AC97 Audio - Event Monitor. ""Sypware"" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers"
"RealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one."
X
AlcxMonitor
Alcxmntr.exe
"Realtek AC97 Audio - Event Monitor. ""Sypware"" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers"
X
aldefr ere service
tay0x.exe
W32/RBOT-XS WORM!
X
Alevir
Alevir.exe
OPASERV.A VIRUS!
X
Alevir
Alevir.exe
OPASERV.F or OPASERV.G VIRUSES!
X
AlevirOld
??
OPASERV.G VIRUS!
N
Alexa
Alexa.exe?
"Alexa Toolbar""is a downloadable toolbar that helps you navigate the Internet as you surf, by instantly providing you with related information about the site you're viewing"". Available via Start -> Programs"
X
ALG.EXE
iexplorer .exe
W32/DEMOTRY-B WORM!
X
ALG32
ALG32.EXE
StartPage.K TROJAN!
X
ALGU
ALGU.EXE
TROJ/CWS-I TROJAN!
N
Alias SketchBook Snapshot
ALIASS~2.EXE
Screen-capture utility for Alias Sketchbook
N
AlienAutopsy
Test_BS.exe
Alienware computer technical support software
Y
ALiSndMgr
ALiSndMg.exe
ALi AC97 Sound driver
X
alkasr
??
BALKART VIRUS
U
All Aboard Status
stswin.exe
All Aboard! Internet Connection Sharing status icon
X
All Sea screen saver
TaskTray.exe
"""Free screensaver"", installs lots of foistware. See here. Get rid of it"
X
All Sea web link
FWLink.exe
"""Free screensaver"", installs lots of foistware. See here. Get rid of it"
N
AllerCalc
AllerCalc.exe
AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually.
U
AllSeeingEye
ase.exe
"All-Seeing_Eye security software - ""monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions."""
U
allSnap
allSnap.exe
"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
X
Alogrithm Link Queue
alq.exe
variant of the W32/SDBOT WORM!
U
Alogserv
Alogserv.exe
"From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up"
U
ALPass
ALPass.exe
ALPass password manager
Y
Alps Electric USB Server
Monserv.exe
Alps Electric USB Server - required according to this article
U
AlpsPoint
Apoint.exe
Touchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
N
Altnet
points manager.exe
Altnet TopSearch adware
N
Altnet Points Manager
points manager.exe
Altnet TopSearch adware
X
AltnetPointsManager
points manager.exe
Altnet TopSearch adware
U
AltoMB_service
AltoMBsrv.exe
Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management
U
ALUAlert
ALUNotify.exe
Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
N
Aluria Security Center
SecurityCenter.exe
"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here"
U
Aluria's Pop-Up Stopper
eps.exe
Aluria Pop-Stopper
N
Aluria's Spyware Eliminator
ASE.exe
"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here"
U
AlwaysOnTopMaker
AlwaysOnTopMaker.exe
"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
X
AmazingTens
AmazingTens.exe
Premium rate adult content dialer
N
AME_CSA
"rundll32 amecsa.cpl, RUN_DLL"
Loads ADSL modem Control Panel applet
N
America Online *.* Tray Icon
aoltray.exe
Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
U
AModemLockDown
ModemLockDown.exe start
"ModemLockDown allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc"
Y
Amon
AMON.EXE
Monitoring part of Eset's NOD32 virus-scanner
Y
Amonitor
amon.exe
Tiny Personal Firewall
U
AMP WinOFF
winoff.exe
"WinOFF is "" a utility designed to shut down Windows computers automatically, in a fully configurable way."""
U
AMSN
amsn.exe
aMSN P2P client - can be started manually
X
anbv32
nabv32.exe
TITOG.C VIRUS!
Y
ANIWZCS2Service
WZCSLDR2.exe
ALPHA_Networks wireless driver
N
Announcements
Annclist.exe
MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
N
Anntext
Anntext.exe
Caere Pagekeeper text annotation server
U
ANONYMIZER_SPYWAREKILLER
AnonAntiSpyware.exe
Anonymizer Spyware Killer; see here
U
ANONYMIZER_SPYWAREKILLER
SpyWareKiller.exe
Anonymizer Spyware Killer; see here
U
Another Internet Explorer Popup Killer
aiepk.exe
Another IE Popup Killer - pop-up stopper
X
ansjava
??
W32/Randon-AN Worm!
X
Anskya
PYSKY.NET.exe
TROJ/DLOADER-MW TROJAN!
X
Answer Problem
dSAFsqs.exe
W32/SDBOT-SC WORM!
X
Anti
Isass.exe
WIN32.BROPIA.K WORM!
X
Anti Spam Service
spamsvc.exe
W32/Mytob-BK Worm!
U
Anti Trojan Elite
TJEnder.exe
Anti_Trojan_Elite trojan remover
U
antidialer.co.uk
Dialer_Watcher.exe
Dialer_Watcher is an application that allows you to detect Dialers on your computer.
U
Anti-keylogger check
antikey.exe
Anti-keylogger - protects against keylogger programs monitoring your keystrokes
U
AntiPopUp
AntiPopUp.exe
AntiPopUp for IE - pop-up stopper
U
Anti-Trojan-Watch
ATWatch.exe
Anti-Trojan Watch - trojan detector
Y
AntiVir XP
AVwin.exe
AntiVir antivirus
X
Antivirus
av.exe
SINKIN VIRUS! Resets IE start page to realphx.com
X
Antivirus
iexpl0res.exe
unidentified WORM or TROJAN!
X
AntiVirus
kaspery.exe
variant of the WIN32.RBOT WORM!
X
Antivirus
maja.exe
W32.NETSKY.H WORM!
X
Antivirus Installer
??
Troj/Badgent-A Trojan!
X
Anti-Virus Product Sync
??
W32.Kedebe.D WORM!
X
Anti-Virus Update Scheduler
??
"variant of the HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more..."
X
Anti-Virus Update Scheduler
winsp3.exe
Malware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system.
X
Anti-Virus Update Scheduler V1.39.12R
??
"HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more..."
X
antivirus32
antivirus.exe
W32.Spybot.KAI WORM!
X
AntivirusGold
AntivirusGold.exe
Malware masquerading as an antivirus - also installs the Winnook TROJAN!
X
antiware
??
Troj/Dloader-HW TROJAN!
U
AntiWindowsMessenger
AntiMsMsg.exe
Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory.
Y
AnVir
AnVir.exe
AnVir Task Manager - protects computer against viruses and manages running processes and startup files
U
anvshell
anvshell.exe
System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
N
AnyDVD
AnyDVD.exe
"AnyDVD is a driver, which descrambles DVD-Movies automatically in the background. This DVD appears unprotected and region code free for all applications and the Windows operating system as well"
N
AO Tray or AOTray
AOTray.Exe
System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
X
AOL 9.0 Optimized
AOLClient.exe
Backdoor.Spyboter.A TROJAN!
X
AOL 9.0 Optimized
AOLClient.exe
Backdoor.Spyboter.gen TROJAN!
U
AOL Broadband Check-Up
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in ""add/remove programs"" some help menus in help and support will not be available. You decide"
N
AOL Companion
companion.exe
"Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use."
X
Aol Configuration Loader
aimsng.exe
W32/SDBOT-XE WORM!
X
AOL Instant Messanger
aim.exe
W32/Sdbot-YT Worm!
X
AOL Instant Messengar
aol.exe
W32/AGOBOT-FN WORM!
X
Aol Instant Messenger
aolmsg.exe
W32.Kelvir.AL WORM!
X
AOL Instant Messenger 7.213
aim9283.exe
W32/Sdbot-ZF Worm!
X
Aol Instant Messenger Fix
aolfix.exe
W32/Sdbot-ABJ WORM!
X
AOL Messenger
??
Unidentified worm or trojan
X
AOL Messenger
aolmsngr.exe
W32/SDBOT-JF WORM!
U
AOL Spyware Protection
AOLSP Scheduler.exe
AOL's spyware protection program
U
AOL TopSpeedMonitor
aoltsmon.exe
AOL's TopSpeed web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up.
U
AolAcsDaemon1
Acsd.exe
AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
Y
AolAcsDaemon1
AOLACSD.EXE
"AOLacsd.exe is a part of the AOL Internet Software and relates to the connection driver, essential to Internet connection. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems"
X
AolCon
config.com
TAPLAK VIRUS!
N
AOLDialer
AOLDial.exe
AOL ISP software dialer; can be activated through a desktop shortcut
N
AolFix
AolFix.exe
"Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL? to run correctly. Not seen much any more and should only run once"
X
Aornum
aornum.exe
Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware
Y
APC UPS Status
Display.exe
APC PowerChute Personal Edition status icon
U
APC_SERVICE
mainserv.exe
"PowerChute╜ Personal Edition - ""safe system shutdown software with sophisticated power management functions"""
Y
apc_tray
apc_tray.exe
Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
X
Api**.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
Api**32.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
API32
api32.exe
IRCBOT-B TROJAN!
X
APIMon
apimonx.exe
TIBSER.A downloader TROJAN!
X
APIMon
msreg.exe
TROJ_DROPPER.Z TROJAN!
X
APIMon
winapix.exe
variant of the TIBSER.A downloader TROJAN!
X
apisvc.exe
apisvc.exe
variant of the Lamebot TROJAN!
U
APL
APL.exe
"Sage_Software's_ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application."
U
Apoint
Apoint.exe
Touchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
X
App.EXEName
??
BODIRU VIRUS!
X
App32dll
msnavc32.exe
VX2 adware related
U
Appcon
vAppCon.exe
"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the ""Auto-start when OS starts"" option. Required for a connection to be established"
X
appconn
appconn.exe
CARGAO trojan
U
AppExtender
AppExtCB.exe
Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received
X
appis.exe
appis.exe
AGENT-BC TROJAN!
Y
Application
mdmsetsp.exe
Aztech Labs modem driver
U
Application Explorer
Naldesk.exe
"Novell Zenworks Application Explorer Executable; ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
X
Application Layer Gateway Service
algs.exe
W32.LINKBOT.M WORM!
U
AppPlus
AppPlus.exe
"AppPlus - ""menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)"""
Y
Apvxd or Apvxdwin
APVXDWIN.EXE
Part of Panda Anti-Virus. Required to enable permanent virus protection
Y
Apwheel
Apwheel.exe
Wheel support for an Alps mouse?
X
apyginapygin
simenu.exe
SDBOT.BTR WORM!
X
AQ3HelperStartUp
AQ3HEL~1.EXE
"ScreenScenes ""Aquatica Water Worlds"" screensaver. Comes with GAIN spyware"
X
aqadcup
aqadcup.exe
Backdoor.Agent.bg worm
X
Aqujyjax
??
TROJ/RANCK-CQ TROJAN!
X
Aqujyjax
aqujyjax.exe
W32/SDBOT-YC WORM!
X
Archive
archive.exe
Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Centim.a
X
ARCHIVE CONTROL
fixupdattr.exe
W32.MYTOB.GU WORM!
N
ARCSolo Recovery
??
Backup software by Computer Associates - no longer supported
N
ares
ares.exe
"Ares is ""a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"""
N
areslite
AresLite.exe
"Ares Lite Edition is ""a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"""
X
Aritima
aritima.exe
ARITIMA VIRUS!
U
Artera
arteraui.exe
"Artera Turbo Internet Accelerator - ""surf faster, boost download speed"". Only required if you find it helps improve your performance"
X
ASDPLUGIN
100171be.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
100176br.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
adult1.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
Austria.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
belgium_nm.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
canada.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
czech.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
dbaccess.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
dsldbaccess.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
dslgeaccess.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
Finland.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
france.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
fullgames.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
geaccess.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
mexico.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
netherlands.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
temp532.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
turkey.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
uk_nm.exe
AsdPlug premium rate adult content dialer variant
X
ASDPLUGIN
Xadult1.exe
AsdPlug premium rate adult content dialer variant
X
asdx
xwinrpc32.exe
AGOBOT.VO WORM!
N
ASE Scheduler
ASE Scheduler.exe
"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here"
U
Ashampoo PopUpBlocker
PopUpKiller.exe
"Ashampoo popup blocker, part of Privacy Protector Plus; see here"
Y
ashAvast
ashAvast.exe
Part of Avast antivirus
X
ASHLT
Ashlt.exe
Ashlt adware
Y
ashMaiSv
ashmaisv.exe
Part of Avast! anti-virus software
U
AsioReg
??
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
U
ASK
??
StealthKeylog surveillance software. Uninstall this software unless you put it there yourself.
X
asl
Aslru.exe
TROJ/BANCOS-CU TROJAN!
U
Asmw Soft Popups Burner
popups burner.exe
"Popup blocker, part of Asmw Soft PC_Optimizer"
X
ASP.NET State Service
csrss.exe
"TROJ/DLOADER-QI TROJAN! NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
N
asp4tray
asp4tray.exe
System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
Y
AspireTimeMachine
acertmb.exe
"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry"
U
a-squared
a2guard.exe
"a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the a 'Background Guard' real time protection feature"
X
assistse
ASSISTSE.EXE
CnsMin (Chinese_Keywords) related
X
AST
AST
WIN32.VB.AH TROJAN!
X
AST
AST.exe
AutoStarter parasite
X
AStart
AStart
WIN32.VB.AH TROJAN!
U
ASTART
astart.exe
ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
N
asTray
Astray.exe
Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer
N
Astro
Astro.exe
Checks for updates to Quicken on a system reboot
N
ASUS Live Update
ALU.exe
ASUS Live Update utility - reportedly not required
N
ASUS Probe
AsusProb.exe
ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
U
ASUS SmartDoctor
VGAProbe.exe
ASUS video card fan/thermal monitor
U
ASUS TweakEnable
astart.exe
Restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
N
ASUSKey
V38SHELL.EXE
System tray Icon for quickly changing video modes
U
asustweakenable
ATweak.exe
Asus Tweaking Utility - for fine tuning the settings of your ASUS display card
N
ASWDP
ASWDP.exe
MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market
X
ASWnk
aswnk.exe
Adult content dialler
X
atapidrv
atapidrv.exe
W32/AGOBOT-SL WORM!
U
Athan
Athan.exe
Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world.
N
ATI CATALYST
CLI.exe
"System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLE.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
N
ATI CATALYST System Tray
CLI.exe SystemTray
"System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
X
Ati Control Panel
atiphexx.exe
SDBOT.CC worm infection
N
ATI DeviceDetect
ATIDtct.EXE
This utility was meant for future use of the ATI TV WONDER? USB 2.0 video driver and can be disabled.
N
ATI GART Set-up Utility
Atigart.exe
"Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed"
U
ATI Launchpad
launchpd.exe
"Convenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu"
X
ATI Rage3d Pro
AtiRage4dPro.exe
W32/AGOBOT-OG WORM!
Y
ATI Remote Control
ATIRW.exe
Driver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
Y
ATI Remote Control
ATIX10.exe
Driver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
N
ATI Scheduler
Atisched.exe
Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
N
ATI Task Application
Atitkad.exe
System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
N
ATI Task Application (Atikey)
Atitask.exe
System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
X
ATI Technology Startup
techstart.exe
W32/Rbot-AEU Worm!
X
ATI VIDEO REGKEY
ati2vid.exe
SDBOT.UR WORM!
N
Ati2mdxx
Ati2mdxx.exe
For ATI video cards. System Tray access to display mode changing
N
ATICCC
CLI.exe
"System Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has ""SystemTray"" appended to CLE.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
U
ATICCC
cli.exe runtime
"ATI's CATALYST(tm) CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. If not you can start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime"
X
AtiCpanel
atiphexx.exe
AGOBOT.IL worm infection
X
aticpaxx.exe
aticpaxx.exe
W32/RBOT-XP WORM!
U
AtiCwd
AtiCwd.exe
This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
U
AtiCwd32
AtiCwd32.exe
This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
X
AtiDisplayDrv
atidrvxx.exe
W32/RBOT-VZ WORM!
N
AtiKey
Atikey32.exe
System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
N
AtiKey
atiptkad.exe
System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
N
Atikey
Atitask.exe
System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
U
ATIModeChange
Ati2mdxx.exe
System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
X
atipatxx
atipatxx.exe
TROJ/SMALL-ED TROJAN!
U
ATIPOLAB
ati2evae.exe
ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
U
ATIPOLAB or ATIPOLL
ati2evxx.exe
"ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces? on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources"
U
AtiPTA
??
"Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings"
U
AtiPTAAA
??
"Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings"
U
atiptaxx
??
"Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings"
X
atiptext
atiptext.exe
COSIAM-A TROJAN!
U
AtiQiPcl
AtiQiPcl.exe
Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
U
ATISmart
ati2s9ag.exe
"ATI's ""SMARTGART"", which is included with the ""Catalyst"" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings"
X
atisrc2
windfind.exe
"Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return"
X
ATITech
Active.exe
Troj/Roamer-A TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
atitray or AtiTrayTools
atitray.exe
ATI Tray Tool - allows quick access to ATI graphics card settings
X
atiupdate
??
DEBESKI.A VIRUS!
X
atiupdate
msshed32.exe
DELF.EP downloader TROJAN!
X
ATIUpdater
atiupdxx.exe
W32/RBOT-ABX WORM!
X
Atiupdpl
atiupdpl.exe
TROJ_SMALL.AOS TROJAN!
X
ativopen
ativopen.exe
Premium rate adult material dialer
U
ATIX10
atix10.exe
ATI Remote Wonder - PC wireless remote control
X
ATM Control
adpn.exe
MMS.A VIRUS!
N
ATnotes
atnotes.exe
Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
U
Atomic.exe
Atomic.exe
Atomic_Clock_Sync synchronizes your computer's time with the NIST time server.
N
Atomica
atomica.exe
Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key
U
AtomicTime
ATOMICTIME.EXE
AtomicTime - utility that synchronizes your PC clock to an atomic clock
U
Atrack
atrack.exe
"New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert"
U
Atray
Atray.exe
Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons
U
ATSpooler
AppsTraka.exe
AppsTraka surveillance software. Uninstall this software unless you put it there yourself.
U
ATTBroadbandUpdate
SAUpdate.exe
Big Brother from Quest Software. System and network monitor
U
ATTRedUpdate
AutoUpdate.exe
Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
X
AttuneClientEngine
attune_ce.exe
"""Attune is a revolutionary service that provides you with targeted Intelligram messages to help you avoid common computer problems. Attune may also let you know when you need a specific product, service, or upgrade to optimise the use of your computer"". Not required - treated as adware"
X
AttuneContentUpdater
attune_cu.exe
Related to the above. All needed for the program to do its job properly
X
AttuneDiscovery
attune_di.exe
Related to the above. All needed for the program to do its job properly
X
AttuneSystray
attune_st.exe
Related to the above. All needed for the program to do its job properly
N
aTuner
atuner.exe
aTuner - tweak tool for GeForce based graphics cards
U
AT-Watch
ATWatch.exe
Anti-Trojan Watch - trojan detector
Y
atwtusb
atwtusb.exe
USB interface for Aiptek Graphics Tablet (USB)
X
AtxBrw
Iexplor.exe
"""Pop Marketing"" adware"
U
AU Agent
AUagent.exe
Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon
X
au.exe
au.exe
Added as the result of the BEAGLE.B WORM!
Y
AUCBPNP
aucbnpn.exe
Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
X
Aucompat
Aucompat.exe
GEMA TROJAN!
X
Audcntr
audcntr.exe
WIN32.GEMA TROJAN!
X
AUDIO
SOUND.exe
Dial/Ployb-A TROJAN!
X
Audiocntl
audiocntl.exe
Crypter.C trojan variant infection
N
AudioDeck
ADeck.exe
ADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items.
X
Audiodrv
audiodrv.exe
CRYPTER-C TROJAN!
N
AudioHQ
Ahqtb.exe
For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
X
audioinf
audioinf.exe
Crypter.C trojan variant infection
X
AUNPS2
"RUNDLL32 AUNPS2.DLL,_Run@16"
AlwaysUpdatedNews.com parasite related - More_information
X
aupd
symcsvc.exe
ABWIZ.D TROJAN!
X
aupd
sysvcs.exe
ABWIZ.C TROJAN!
Y
Aureal A3D Interactive Audio
sa3dsrv.exe
For Aureal based 3D soundcards. A3D sound features won't work with this disabled
Y
Aureal A3D Interactive Audio Init
A3dInit.exe
For Aureal based 3D soundcards. A3D sound features won't work with this disabled
X
ausvc
ausvc.exe
AUTOUPDER VIRUS!
X
Auth Starter Ident
startauth.exe
W32/RBOT-WP WORM!
U
AuthConsoleStart
AuthStart.exe
"Security Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private."
X
authz
authz.exe
unidentified virus
X
Auto CD-ROM Startup
cdaccess.exe
SPYBOT.BLA WORM!
X
auto repair system
qualityx.exe
"Unidentified worm, probably a W32.SpyBot variant"
N
Auto T Bar or autotbar
autotbar.exe
If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled
X
Auto updat
crcss.exe
SDBOT.AAG WORM!
X
Auto updat
crsrs.exe
W32/FORBOT-BP WORM!
X
Auto updat
crsrs.exe
W32/FORBOT-BP WORM!
X
Auto updat
SysDebug.exe
W32/Forbot-BA worm infection
X
Auto Updat
WindowsSys32.exe
variant of the W32/FORBOT WORM!
X
"Auto updat, various other names"
crsrs.exe
W32/Forbot-AK worm infection
X
Auto Update
AUP.exe
unididentified WORM or TROJAN!
X
Auto Update
svchost.exe
"TROJ/DUMARDL-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Auto Updates
svchost.exe
Troj/Cheuko-A TROJAN!
X
Auto WinUpdate
taskmrg.exe
W32/Rbot-AFA Worm!
U
Autobar
autobar.exe
"Connect buttons on the keyboard for internet direct access, etc. on HP computers"
U
AutoCAD Startup Accelerator
acstart16.exe
Preloads some libraries that are used by AutoCAD in order to make the software load faster
Y
autoclk
autoclk.exe
Sagem Modem driver. Installed and required on systems running Windows 98 or ME
N
AutoEA
Ahqrun.exe
For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
X
AUTOEXE
AUTOEXE.exe
W32/SEMAPI-A WORM
X
Autoloaderaproposclient
Apropos_Client_Loader.exe
AproposMedia adware
X
Autoloaderaproposclient
cxtpls_loader.exe
AproposMedia adware
X
AutoLoaderEnvoloAutoUpdater
auto_update_loader.exe
Envolo/AproposMedia adware updater
N
AutoMate Task Service
automate.exe
Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs
X
Automatic Defrag Manager
defrag.exe
W32/Rbot-AKE WORM!
X
Automatic Microsoft Windows Updater
suchost.exe
W32/RBOT-EQ WORM!
X
Automatic Windows Updater
Update.exe
GAOBOT.AO WORM!
N
Automatically launches the United Devices Age
UD.EXE
The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
X
Autopdate
Autopdate.exe
W32/Rbot-AGL WORM!
N
AUTOPROP
"REGPROP.EXE, WMPADDIN.DLL"
"Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension"
X
AUTOPROTECTU
navapq32.exe
unidentified WORM or TROJAN!
X
autorepair
dexs.exe
variant of the W32/SDBOT WORM!
U
AutoSizer
AUTOSIZER.EXE
AutoSizer - utility that automatically maximizes windows when they're opened
N
AutoSpell 5
ASWATC32.EXE
AutoSpell - spell checker
N
AutoTKit
AUTOTKIT.EXE
On HP PC\'s. Unclear what purpose it serves - but there\'s a known issue with Internet Explorer Toolbar settings not being saved with it enabled
N
autoupd
autoupd.exe
"Raxco Software Auto Update utility.""Used to keep your software up-to-date"""
X
autoupd
autoupd.exe
VIRUS! - found in a folder of the same name
X
autoupdate
??
variant of the QOOLOGIC TROJAN!
X
autoupdate
??
variant of the QOOLOGIC TROJAN!
X
autoupdate
"WINUP2DATE.DLL,SHStart"
Unidentified adware - detected by Panda antivirus as Trj/Clicker.CY
X
Autoupdate Service
kaka.exe
TROJ/SYMPE-B TROJAN!
X
AutoUpdater
aupdate.exe
"Aupdate, Tinybar variant. Spyware"
X
AutoUpdater
AutoUpdate.exe
PeopleonPage foistware
X
AutoVirusProtection
ciscv.exe
variant of the WIN32.RBOT WORM!
X
aux.exe
aux.exe
BACKDOOR.ZINS TROJAN!
X
auxAudioDevice
aux32.exe
W32/Zusha-C WORM!
N
AUXXTRAY
au30setp.exe
System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
X
AV
??
MIDFIN WORM!
X
AV UpDate
Update.exe
theTROJ/FUROOT-A TROJAN!
Y
avast!
ashDisp.exe
Part of Avast! anti-virus software
Y
Avast!
ashserv.exe
Avast! anti-virus software
Y
avast! Web Scanner
Ashwebsv.exe
Avast! antivirus
Y
Avast32
Astart32.exe
Part of Avast! anti-virus software
X
avc
avmon.exe
unidentified TROJAN!
U
AvconsoleEXE
Avconsol.exe
From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
X
AveoAttune
atmdlusr.exe
Related to AttuneClientEngine above
X
AvG
svchost323.exe
W32/RBOT-ZA WORM!
X
AVG Grisoft Updater
updater.exe
W32/AGOBOT-OT WORM!
Y
AVG_CC or avgcc32
avgcc32.exe
"AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates"
Y
AVG_EMC
AVGEMC.exe
AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
Y
AVG_RegCleaner
AVGREGCL.exe
AVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems
Y
AVG7_AMSVR
Avgamsvr.exe
AVG antivirus related
Y
AVG7_CC
AVGCC.exe
"AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates"
Y
AVG7_EMC
AVGEMC.exe
AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
Y
AVG7_Run
avgw.exe
Part of AVG Anti-Virus 7.0
Y
avgamsvr.exe
Avgamsvr.exe
AVG antivirus related
Y
AVGCtrl
AVGCTRL.EXE
Background task of the AntiVir antivirus program which scans files transparently in the background
Y
AVGCtrl
AVGNT.EXE
Background task of the AntiVir antivirus program which scans files transparently in the background
Y
avgmsvr.exe
avgmsvr.exe
Required for AVG Anti-Virus 7.0 to function
Y
Avgserv9.exe
Avgserv9.exe
Background monitoring program for AVG anti-virus
Y
AVGuard
AVGNT.EXE
Background task of the AntiVir antivirus program which scans files transparently in the background
Y
AVGuard
AVGUARD.EXE
Background task of the AntiVir antivirus program which scans files transparently in the background
X
avidrv
drvsc.exe
Detected as the Trojan-Downloader.Win32.Agent.ph TROJAN! by Kaspersky Anti-Virus. Note: No URL available at this time.
X
Avimgt
Avimgt.exe
GEMA TROJAN!
X
Avimgt32
Avimgt32.exe
GEMA TROJAN!
Y
avinit
AVINIT9X.EXE
Command antivirus related
Y
AVK Mail Checker
AVKPop.exe
eXtendia AVK AntiVirus email checker
Y
AVKBar
AVKBar.exe
GData AntiVirusKit Anti-virus
Y
AvMaiSrv
Avmaisrv.exe
Avast32 anti-virus - E-mail scanner
X
avnort
formatsys.exe
W32.Serflog.A WORM!
X
avnort
msmbw.exe
W32.Serflog.A WORM!
X
avnort
serbw.exe
W32.Serflog.A WORM!
X
AVP
??
Troj/Mutbo-A TROJAN!
Y
avpcc
avpcc.exe
Kaspersky Labs anti-virus
Y
avpm
avpm.exe
Kaspersky antivirus
X
Avpr
avpr.exe
W32.Mydoom.AF WORM!
X
Avril Lavigne - Muse
??
AVRIL-A VIRUS!
Y
AVSCHED32
AVSched32.exe
AntiVir anti-virus from H BDEV
Y
AVSchedScan
SCHSC9X.EXE
Command antivirus related
X
AvSer
dsm.exe
W32.Serflog.B WORM
X
AvSer
msmpatch.exe
W32.Serflog.B WORM!
X
AvSer
svosm.exe
W32.Serflog.B WORM!
X
AvSer
sysup.exe
W32.Serflog.B WORM!
X
avserve.exe
avserve.exe
SASSER VIRUS!
X
avserve2.exe
avserve2.exe
SASSER.B or SASSER.C VIRUSES!
X
avserve3.exe
avserve3.exe
SASSER.G worm
N
Avtray
Avtray.exe
Command Antivirus tray icon
U
AVWUpd32
AVWUPD32.EXE
"AntiVir updater. Useful, but can be run manually"
Y
avx communicator
xcommsur.exe
Anti-virus part of BitDefender virus scanner/firewall
Y
Avxlive
avxlive.exe
Bullguard or BitDefender antivirus
Y
avxlni
avxinit.exe
Anti-virus part of BitDefender virus scanner/firewall
U
AWatch
Awatch.exe
"Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products."
N
awhost32
awhost32.exe
"Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended"
Y
a-winpoet-service
winpppoverethernet.exe
"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking"
U
AWMON
Ad-Monitor.exe
F-Secure_Anti-Spyware
U
AWMON
Ad-Watch.exe
Part of Lavasoft Ad-aware SE Plus and Pro - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
U
awxDTools
??
"AwxDTools related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools. (i.e.: *.cue, *.iso, *.ccd ...)"
X
AxFilter
"Rundll32 AXFILTER.DLL, Rundll32"
CnsMin (Chinese_Keywords) related
Y
azmodem
azexe.exe
Aztech_Labs modem driver
N
B.Reader
remin.exe
Birthday Reminder 5.0 - as the name implies
X
b3d
BDEsecureinstall.exe
"B3d Projector - installed along with the KaZaA file sharing utility. Causes a program called ""ZUPDATE.EXE"" to periodically try to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
X
b3dUpdate
Zupdate.exe
Same as above but not installed via KaZaA
U
b9
B9.exe
"FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. ""Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"""
X
b99
msmm.exe
ClientMan parasite variant
X
babeie
"rundll32 cnbabe.dll, dllstartup"
CommonName Toolbar spyware. To uninstall see here
N
Babylon Client
Babylon.exe
"Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"""
N
Babylon Translator
Babylon.exe
"""Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"""
X
Back Updates
Uninstall.log.vbs
VBS.YPSAN.D WORM!
X
Backdoor.NuAgent
agent.exe
AGENT-DP TROJAN!
X
Background Intelligent Transfer Service
rundll32.exe
"TROJ/VB-ZD TROJAN! - Note: this file is located in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file!"
U
BackgroundSwitcher
bgswitch.exe
"Background Switcher Powertoy. Included with the last beta version of the XP Powertoys. Whenever a user right clicked his desktop and chose properties he could see a new tab which allowed him to enable a ""Desktop Slide Show."" This would automatically change the Windows Desktop at an interval specified by the user. Available here"
N
Backpack UDF
bpudfmon.exe
Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk
X
Backup Service
backup.svc
Unidentified adware
U
BackupExecScheduler
besch.exe
"Veritas ""Back Up My PC"" software"
N
BackWeb
backweb.exe
Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
N
Backwork
Backwork.exe
Backwork trojan detector
U
BACPI10
bacpi10a.exe
"Known as ""PowerKey"" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray"
N
BacsTray
BacsTray.exe
Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
X
BADDATE
BADDATE.EXE
unidentified VIRUS!
X
BagleAV
csrss.exe
"W32.NETSKY.AB WORM! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
Bakra
IEHost.EXE
IEDriver adware variant
X
Band-Aid
??
BACKDOOR.RANKY.O TROJAN!
U
Banpopup by Pratik
Banpopup.exe
Banpopup - popup killer
X
Bar Ding lolt
Analiz.exe
RBOT-RP WORM!
X
bargains
bargains.exe
Bargain Buddy - advertising spyware installed with Net2Phone & LimeWire amongst others. Some further information here
X
bargains
barginbuddy.exe
Bargain Buddy - advertising spyware installed with Net2Phone & LimeWire amongst others. Some further information here
N
bascstray
BascsTray.exe
Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
X
Bat
secure2.bat
ZCREW.C VIRUS!
N
Batchreg1
??
"Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here"
U
BatInfEx
rundll32.exe
Displays battery status information on an IBM Thinkpad
U
Battery Scope
batmgr.exe
Monitors battery levels on a notebook/laptop PC
U
BatteryBar
batterybar.exe
"BatteryBar - displays battery usage, and the current percentage of battery power left"
X
BatzBack
BatzBack.scr
BACKZAT VIRUS!
U
BAUSB
BAUSB.exe
"Boston Acoustics Audio, USB driver"
X
bawindo
bawindo.exe
BEAGLE.AR WORM!
X
bawindo
bawindo.exe
W32.BEAGLE.AU WORM!
U
BayMgr
DockApp.exe
Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices?
U
Bayswap
bayswap.exe
Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
U
Bayswap2
TbUpdate.exe
Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
U
BBC News alerts
skinkers.exe
BBC News Desktop Alerts service; see here - The BBC News desktop alert and breaking news e-mail services let you find out about all the latest news as it happens.
N
bbSysTray
bbSysTray.exe
"Philips CD-RW related - ""the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"""
U
bbui
bbui.exe
AOL DSL status monitor displaying a red/green icon indicating if you have a connection
Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
Y
BCMDMMSG
bcmdmmsg.exe
BCM voicemodem driver. Required for dial-up if you have one of these modems
U
BCMHal
??
"BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings"
Y
BCMSMMSG
BCMSMMSG.exe
BCM voicemodem driver. Required for dial-up if you have one of these modems
X
bcnswSX
??
Ranck-AJ trojan infection
N
BCNT
bcnt.exe
AWS Weatherbug related. What does it do?
X
BCPC
bcpc.exe
BroadcastPC adware variant
X
bcpc_c
bcpc_c.exe
BroadcastPC adware variant
U
BCTweak
bctweak.exe
"BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings"
X
Bcvsrv32
bcvsrv32.exe
W32/AGOBOT-TD WORM!
N
BCWipeTM
bcwipetm.exe
"BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed"
X
BD
dc.exe
Troj/Rasdoor-A TROJAN!
Y
BDMCon
Bdmcon.exe
Either BitDefender or BullGuard antivirus
Y
BDNewsAgent
bdnagent.exe
BitDefender antivirus - updater
Y
BDOESRV
bdoesrv.exe
Bitdefender 8 antivirus and firewall
Y
BDSwitchAgent
bdswitch.exe
Bitdefender 8 antivirus and firewall
N
BearShare
bearshare.exe
BearShare file sharing client. Versions known to include spyware - see here
U
BeFaster
befaster3.exe
BeFaster internet connection optimization tool
N
Belkin PCMCIA WLAN Monitor
monitorbk.exe
Belkin USB Network Adapter Management utility - can be started manually
U
BelNotify
"NPBelv32.dll,RunDll32_BelNotify"
"BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service."
X
Belt
Belt.exe
Transponder parasite updater/installer
X
Benadril Alert Tool
benadrilalert.exe
Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
N
BestPopUpKiller
BestPopupKiller.exe
"Popup killer by Swanksoft - not recommended, see Rouge/Suspect_list"
X
BeSys
??
BeSys ADWARE!
Y
bg
bullguard.exe
Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster
U
BGInfo
Bginfo.exe
"BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more."
Y
BGNewsAgent
bgnewsag.exe
BullGuard antivirus updater
N
bgsmsnd
bgsmsnd.exe
Printer driver to generate PDF files from any program
N
BHOCop
BHOCop.exe
ZDNet's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware
U
BHODemon 2.0
BHODemon.exe
"BHODemon ""protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!"" If you prefer forgoing resident protection, the application can also be run on demand."
U
BI1HelperStartUp
BI1HEL~1.EXE
Beach_Islands Screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
X
BIE
??
BDplugin parasite
N
bigfix
BIGFIX.EXE
"BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet╜ Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog"
U
BigPond Toolbar
bpumTray.exe
"Telstra BigPond Toolbar - ""Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"""
N
BigPondCable
bpcable.exe
Telstra Bigpond Cable login software. Can be started manually.
N
Billminder
Billmind.exe
Can be setup in Quicken to remind user of due payments. Available via Start -> Programs
BitComet P2P client - can be launched from Start Menu > Programs
X
BitDefender Antivirus
BITDEFENDERX.EXE
variant of the W32.SPYBOT WORM!
Y
BitDefender Communicator
xcommsvr.exe
BitDefender antivirus
U
BitDefender for MSN Messenger
msnmon.exe
Bitdefender anti-virus for MSN Messenger. Unless you have MSN Messenger running all the time start it manually
U
BitDefender for Yahoo! Messenger
yahmon.exe
BitDefender Antivirus for Yahoo! Messenger - free AV add-on for Yahoo! Messenger
Y
BitDefender Live! Init
bdinit.exe
BitDefender antivirus
Y
BitDefender Scan Server
bdss.exe
BitDefender antivirus
Y
BitDefender Virus Shield
vsserv.exe
BitDefender antivirus
U
BitDefender_P2P_Startup
BitDefender_P2P_Startup.exe
Bitdefender anti-virus for file transfers via internet messaging clients such as ICQ and MSN Messenger. Unless you have these running all the time start it manually
Y
bitdefenderlive
avxlive.exe
Main program of BitDefender virus scanner/firewall
N
BitWare Print Monitor
bwprnmon.exe
FaxServe network fax software
N
BJ Printer Status Monitor
Cjstsr.exe
Canon BJ printer status monitor
N
BJ Status Monitor 5xx
CJSTRxx.EXE
"Canon printer status monitor - where ""xx"" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers"
N
bjcfd
CFD.exe
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
N
BlackICE PC Protection or BlackIce Utility
blackice.exe
"Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - \'(the user interface) starts in the ""Startup"" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.\' See also LoadBlackD"
X
Blah service
CCAPPS32.EXE
RBOT.TV WORM!
X
blah service
FaLeH.exe
W32/Rbot-AES Worm!
X
blah service
internet.exe
variant of the WIN32.RBOT WORM!
X
blah service
microsoft.exe
variant of the WIN32.RBOT WORM!
X
blah service
msnmsgrr.exe
RBOT.PZ WORM!
X
blah service
smnp.exe
RBOT.IZ WORM!
X
blah service
tazkmgr.exe
RBOT.UA WORM!
X
blah service
winsysengine.exe
W32/Rbot-KI worm infection
X
blah service
winupdate.exe
GAOBOT.BIA WORM!
X
blahh service
msengine.exe
variant of the WIN32.RBOT WORM!
X
blahx service
msnjompa.exe
SDBOT.AML WORM!
N
BlazeChanger
FBZPaper.exe
"Ember graphic file viewer, manager, and touch-up system"
N
bldbubg
bldbubg.exe
Part of Dell Alerts which provides customers with an update on latest updates for his/her system
X
Bles
bles.exe
TROJ/BLESH-A TROJAN!
U
blinkx
blinkx.exe
"Blinkx_Desktop ""Smart Folders"" software"
X
BLMessagingIntegration
blengine.exe
BuddyLinks adware
U
BlockAds
blads.exe
"A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks"
X
BlockChecker
Block-checker.exe
BlockChecker adware
X
Blocker System611 Monitoring
PopUpBlocker611.exe
RBOT.BLJ WORM!
N
BlockTracker
BlockTracker.exe
If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
U
blsloader
blsloader.exe
BellSouth ISP Internet_Tools
X
blss
blss.exe
Backdoor.Blarul TROJAN!
N
BLSTAPP
blstapp.exe
Puts access to Creative's BlasterControl in the System Tray
X
bluestart
rraut.exe
VB.GY.2 downloader TROJAN!
U
BlueToothAuthentication Agent
??
"Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, ""Rundll irprops.cpl missing entry Bluetooth authentication agent"", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup."
U
BluetoothAuthenticationAgent
??
"Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate."
U
Blueyonder Instant Support Tool
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide"
N
BMail Installation
FTP_back.exe
Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not
X
BMan
BMan1.exe
Abcsearch.com/DealHelper adware variant
U
BMMGAG
"Rundll32 PWRMONIT.DLL, StartPwrMonitor"
Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window
U
BMMLREF
BMMLREF.EXE
Battery Manager for IBM ThinkPad laptops
U
BMO MasterCard Wallet
EWALLET.EXE
"The wallet conveniently stores billing, shipping and payment information on your PC"
N
BMupdate
BMupdate.exe
"Related to BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install"
X
BMZ
bmz.exe
nCase adware
X
Bndt32
Bndt32.exe
LACON VIRUS!
X
Bnexe
??
KITRO.D (or ARGEN.A) VIRUS!
U
BO1HelperStartUp
BO1HEL~1.EXE
ScreenScenes Butterfly_Oasis screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
U
BO1HelperStartUp
Bo1helper.exe
ScreenScenes Butterfly_Oasis screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
X
Boarddata
??
variant of the RANDON.AN WORM!
Y
BOC412
BOC412.exe
Version 4.12 of NSClean's BOClean anti-trojan software
Y
BOCleanautostart
Boclean.exe
NSClean's BOClean anti-trojan software
U
bombshel
BOMB32.EXE
Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
X
Bonzi Buddy
??
Spyware - read here for information and here for removal instructions
X
boo
boo.exe
Adware downloader - detected by Kaspersky antivirus as Trojan.Win32.Favadd.o
X
BookedSpace
??
"Adware, related to the Remanent parasite"
N
BookmarkCentral
BMLauncher.exe
"Bookmark Express - ""offers a more flexible way to manage Web site bookmarks, regardless of which browser you use"""
U
Boost XP Service
bxservice.exe
Boost XP from Systweak - WinXP tweaking utility?
X
boot
boot.exe
Troj/Puppet-A Trojan!
X
Boot Manager
bootmng.exe
variant of the W32.SPYBOT WORM!
X
Boot Manager
Njgal.exe
KILO VIRUS!
X
boot_reg
??
TROJ/BANCBAN-CA TROJAN!
X
BootCfg
Install.log.vbs
VBS.YPSAN.D WORM!
X
BootCTRL
bootctrl.exe
unidentified WORM or TROJAN!
X
BootLoader
BootLoader.exe.vbs
WATERWORKS VIRUS!
X
bootpd.exe
bootpd.exe
Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.vk
X
bootpd.exe
bootpd.exe
Troj/Agent-DT Trojan!
X
BootsCfg
??
VBS.SPILTRON WORM!
X
BootsCfg
??
VBS.SPILTRON WORM!
X
BootsCfg
??
VBS.YPSAN.E WORM!
X
BootsCfg
Date.POP.vbs
VBS.KUULLIO WORM!
U
BootStatus
BOOTST~1.EXE
"Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day.? Once you exit it, it has no more effect on resources"
U
BootWarn
BootWarn.exe
"From here : ""Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from ?Start \ Programs \ Norton AntiVirus?. If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab ║ it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages."""
N
Bose Wave/PC Monitor
wavepcmonitor.exe
System Tray access for this system (more info on the system here). Available via Start -> Programs
X
BossIdea
winlogin.exe
TROJ/LINEAGE-I TROJAN!
X
Bot Loader
svchostt.exe
W32.GAOBOT.ALV WORM!
X
Bouncer RunStartup
bouncer.exe
"VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs"
X
Bouncer RunStartup
LiveUpdate.exe
"VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs"
U
bpcpost.exe
bpcpost.exe
MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X
BPCv2
BPCv2.exe
BroadcastPC adware
X
BPCv2_re
bpc2_re_inst.exe
BroadcastPC adware variant
U
BPK
bpk.exe
"Blazing Tools Perfect Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove"
U
BPK
nvsr32.exe
"Blazing Tools Perfect Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove"
N
BPServer
G6FTPSrv.exe
BulletProof FTP Server
X
BPT
bpt.exe
BroadcastPC adware
U
BQTray.exe
BQTray.exe
"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually"
X
Brasil
Brasil.exe
OPASERV.E VIRUS!
X
Brasil
BRASIL.PIF
OPASERV.E VIRUS!
X
BrasilOld
??
OPASERV.P VIRUS!
X
Brct
trdb.exe
Reported as Win32.PurityScan.y TROJAN! by Kaspersky Anti-Virus. Class: Trojan-Downloader. Note: Lowers Internet Explorer security settings and downloads unwanted files.
U
Break_Reminder
BREAK REMINDER.exe
Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here
X
Breg
bcre.exe
BroadcastPC adware variant
X
Breg
bptre.exe
BroadcastPC adware variant
X
Breg
breg.exe
BroadcastPC adware variant
X
Bridge
??
Flingstone.com browser hijacker
Y
Brindys BriTray
BRITRAY.EXE
"Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired"
U
BrmfRmPA
BrmfRmPA.exe
Brother resource manager - needed for a Brother MFC printer/copier/scanner and PC to properly communicate
N
Broadband Wizard
bbwiz.exe
Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs
N
BrowseProxy
FindService.exe
"Actual Names - ""It is now possible to enter a particular word or keyword phrase that is associated with your business, and immediately be directed to YOUR WEBSITE! The Actual Names technology can do this for you"""
X
browser
msgaol.exe
WIN32.TACTSLAY.C TROJAN!
X
browser
s_menu.exe
WIN32.TACTSLAY.C TROJAN!
X
browser aid
browseraid.exe
BrowserAid/BrowserPal foistware
Y
Browser Hijack Blaster
bhblaster.exe
Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings
U
Browser Launcher
Commandr.exe
"Logitech internet keyboard ""Commander"" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys"
X
Browser Pal
adblck.exe
BrowserAid/BrowserPal foistware
U
Browser Sentinel
BrowserSentinel.exe
"Browser Sentinel. Notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page. See here"
N
BrowserWebCheck
loadwc.exe
Checks to make sure that IE is still your default browser
N
BS Player
bsplayer.exe
"BSplayer - A video player used to play avi, mpg, wmv and other multimedia files."
N
BsCLiP
BSCLIP.exe
CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
N
B'sCLiP
BSCLIP.exe
CD recording utility that comes with a lot of CDR/CDRW drives and isn't required
X
Bsoft lppt01
Bsoft.exe
"New variant of the RapidBlaster parasite (in a ""BelmontSoft"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Bsx3
??
BookedSpace parasite variant
X
BT
??
Troj/Litebot-B TROJAN!
U
BT Broadband Help
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide"
U
BTModemProtection
BTModemProtection.lnk
"BT Privacy Online modem protection software, see here"
U
BtStart
btstart.exe
Broadcorp (formerly WIDCOMM) Bluetooth Connectivity Software
U
bttray
bttray.exe
"System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device"
Y
BTUSRBDG
BtUsrBdg.exe
Used with a Mitsumi_USB_Bluetooth adaptor (and maybe others)
Y
BTUSRBDGF
BtUsrBdg.exe
Used with a Mitsumi USB Bluetooth adaptor
X
BTV
btv.exe
BroadcastPC adware
N
Buddyizer
Buddyizer.exe
Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
U
bugwatcher service
bugwatcher.exe
"Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures"
N
BuildBU
bldbubg.exe
Part of Dell Alerts which provides customers with an update on latest updates for his/her system
X
BuildLab
winlogon.exe
NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
X
BuildLabs
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
BuildLabs
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
U
Bulldog Service
upsd.exe
Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
Y
BullGuard
mgui.exe
Part of Bullguard antivirus
U
BullGuard Update
avxlive.exe
Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions
Y
BullGuard XComm
XCOMMSVR.EXE
Part of Bullguard antivirus
Y
BullGuardInit
AVXINIT.EXE
Part of Bullguard antivirus
Y
BullguardoptIn
bulldownload.exe
Part of Bullguard antivirus
X
BullsEye
bargains.exe
eXact Advertising BargainBuddy/Bullseye adware
X
BullsEye Network
bargains.exe
eXact Advertising BargainBuddy/Bullseye adware
X
Bunx
beagle.exe
W32/Lebreat-E WORM!
N
BurnQuick Queue
BQTray.exe
"System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually"
U
Button Server
bttnserv.exe
"Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required"
N
ButtonKey
ButtonKey.exe
CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut
N
Buzme
Bmui.exe
"Buzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem"
U
BuzMe
RCUI.exe
Display Client for the BuzMe Internet Call Waiting Service.
U
Buzof.exe
buzof.exe
"Buzof from Basta Computing ""enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"""
X
bxsx5
??
BookedSpace parasite variant
X
bxxs5
??
BookedSpace parasite
X
Bymer.Scanner
Msinit.exe
BYMER WORM!
X
Bymer.Scanner
Wininit.exe
BYMER WORM!
X
c
c:\archiv~1\win.com
CUYDOC VIRUS!
X
C:\WINDOWS\IEXPLOR.EXE
IEXPLOR.EXE
"""Pop Marketing"" adware"
X
C:\WINDOWS\VCMnet11.exe
VCMnet11.exe
"""Windows AFA Internet Enhancement"" - a browser hijacker, redirecting to adsourcecorp.com - see here"
X
C:\WINDOWS\WinTask.exe
WinTask.exe
"""Pop Marketing"" adware"
U
C2K
CYB2K.EXE
CYBERsitter 2000 or 2001 -? anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
U
c32cs2
c32cs2.exe
Cyber_Sentinel Internet filtering software
X
C7
??
W32.MEDIAKILL.A WORM!
U
CA-AMAgent
amagent.exe
"Unicenter_Asset_Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting."
Y
CaAvTray
CAVTray.exe
eTrust? EZ_Antivirus system tray application from Computer Associates
X
Cabchk
Cabchk.exe
GEMA TROJAN!
X
Cabchk32
Cabchk32.exe
GEMA TROJAN!
X
CABCInstall
CABCInstall.exe
CABC content delivery software
U
CacheBoost
trayicon.exe
"CacheBoost ""optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost"""
X
CacheLoader
??
Troj/Dloader-NZ TROJAN!
N
Cacheman
Cacheman.exe
Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up
Y
CacheMgr
CacheMgr.exe
Sophos Antivirus Remote Update
N
CACStarter
cacstart.exe
Cash A Check - check writing software
U
Caddais BackupOnDemand
BODMon.exe
"Caddais BackupOnDemand - ""runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"""
U
Cadenza
CdzSvc.exe
Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices
U
CADS
cads.exe
Cyber Sentinel internet filtering software
N
CAgent
CAgent.exe
Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents
X
cAgOu
??
KAKWORM VIRUS!
N
CahootWebcard
CahootWebcard.exe
"""The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details"". Run manually when needed"
Y
CAISafe
isafe.exe
Part of Computer Associates eTrust EZAntivirus
N
Cal Reminder Shortcut
calrem.exe
Produces a pop-up reminder of events scheduled using the MS Office Calendar
X
Calc Microsoft Windows
wincalc.exe
unidentied WORM or TROJAN!
N
Calendar 200X Reminder
calendar.exe
"Calendar200X - shows holidays, reminders of various anniversaries,tasks etc"
U
Calendarscope
cs.exe
Calendarscope calendar software
X
calk
calk.exe
TROJ/STARTPA-FH TROJAN!
U
CallCenter Main Application
V3calmcp.exe
"""V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications."" Main application"
U
CallCenter Printer Interface
V3faxecp.exe
"""V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications."" Fax printer"
N
CallControl
ftctrl32.exe
"FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows"
N
CamCheck
CamCheck.exe
NuCam camera software related
U
Cameno
Cameno.exe
Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above
N
Camera Detector
??
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
N
Camera Detector
??
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
N
Camera Detector
Camdetect.exe
ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
N
Camio Viewer x
IXApplet.exe
"Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. ""x"" in the name is the version"
N
Canada
Canada.exe
Known to be a dialler - but is it maliscous or clean?
N
Canary
canary-std.exe
"Canary monitoring program. Keylogger, monitors all computer activity"
X
candy
command32.exe
W32/Rbot-LV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
candynet
Taskmsg.exe
W32/Rbot-NA WORM!
N
Canon Printer Monitor BJCxxx
Cjstlst.exe
Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs
N
Capfax
capfax.exe
PhoneTools fax software
Y
Capon
Capon.exe
Canon printer driver
Y
Capon
Caponn.exe
Canon printer driver
X
CaptionMgr32
crssr.exe
W32.ZAR.A WORM!
N
Capture Express 2000
capexp.exe
Capture Express - screen capture utility
N
Card Monitor
REGCNT09.exe
For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
X
Care20
Care20.exe
TopMoxie adware
U
Care2GTU
Care2GTU.exe
"Care2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it keep it"
X
CARPserver
CARPserver.exe
TROJ/BANKER-AN TROJAN!
U
CARPservice
carpserv.exe
"Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example"
X
cartao
??
TROJ/DLOADER-QD TROJAN!
X
cartao
conflicted.exe
TROJ/DADOBRA-DV TROJAN!
X
cartao
killing.exe
TROJ/DLOADER-QN TROJAN!
X
CAS Client
casclient.exe
CasinoClient adware
U
CasAgnt
CasAgnt.exe
Program by Extended Systems which allows you to sync your Casio PDA with your PC
X
Casdvqwa
bmqnzkg.exe
RANDEX.BE VIRUS!
X
caseyvideo
CaseyVideo.exe
malware causing p0rn popups
X
CashBack
cashback.exe
eXact Advertising BargainBuddy/CashBack adware
X
CashFiesta
Cashfiesta.exe
CASHFIESTA.A pay-per-surf adware
N
Cashsurfers Cashbar Navigator
Cashbar.Exe
"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
X
CashToolbar
CD_Load.exe
"""CashToolbar"" Downloader-MY TROJAN!"
X
CashToolbar
svchost.exe
"""CashToolbar"" Downloader-MY TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
X
Cassandra
cassandra.exe
Melkosoft_Cassandra adware - also detected as a variant of the WIN32.KREPPER TROJAN!
X
Cassandra and or Control handler
??
Troj/Krepper-AI Trojan!
X
CasStub
casstub.exe
Troj/Cass-A TROJAN!
Y
CAVRID
CAVRID.exe
eTrust? EZ_Antivirus Real Time Infection Report from Computer Associates
Y
CAVS
CAVS.exe
"Cheyenne, ( now eTrust ) antivirus"
X
CAZNOVAS
CAZNOVAS.exe
CAZNO VIRUS!
X
CBACK.EXE
CBACK.EXE
Troj/Penta-A TROJAN!
U
CBWAttn
CBWAttn.exe
"Required for Bitware to answer incoming faxes, can cause sleep mode problems"
U
CBWHost
CBWHost.exe
"Required for Bitware to answer incoming faxes, can cause sleep mode problems"
X
CC2KUI
comet.exe
Comet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See here for more information and for the uninstall procedure
X
ccApp
??
OBSORB VIRUS! Note the random filename compared to the valid Norton AntiVirus entry above
X
ccApp
??
W32/RBOT-LJ WORM!
Y
ccApp
ccApp.exe
Part of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this
X
ccApp
gcasServ.exe
variant of the WIN32.RBOT WORM! - do NOT confuse with the Microsoft AntiSpyware executable of the same name as described here
X
ccApp
WMADZ.EXE
W32/RBOT-LJ WORM!
X
ccAppr
expIorer.exe
WIN32.TACTSLAY.A TROJAN!
X
ccAppr
outIook.exe
WIN32.TACTSLAY.A TROJAN!
X
ccAppr
svcrhost.exe
WIN32.TACTSLAY.A TROJAN!
X
ccAppr
svcshost.exe
WIN32.TACTSLAY.A TROJAN!
X
ccApps
services.exe
NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
X
ccApps
winlogon.exe
NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
U
CCD Manager
DDS.EXE
Project Labs Century CD manager for their CD/DVD storage device
N
Ccdecode
??
Part of the closed caption decdoder/MS VBI codec. Should only run once
Y
CCDoctorLogonTesting
ccdoctor.exe
"Checks your system to make sure it's configured properly for running Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product"
Y
ccenter
CCenter.exe
RAV AntiVirus
Y
CcEvtMgr
ccEvtMgr.exe
"Part of Norton AntiVirus 2003.Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
X
ccEvtMrg.exe
ccEvtMrg.exe
RBOT.GZ WORM!
X
ccExecute
bootcfg1.exe
W32/NEMSI-B VIRUS!
X
ccHelp
ccHelp.hta
"""Searchq"" adware"
X
ccpApps
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
ccpApps
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
U
ccProxy
CCPROXY.EXE
"Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage."
Y
CcPxySvc
CCPXYSVC.exe
"Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall"
X
ccreg
explorer.exe
ZCREW VIRUS! Note - this is not the valid explorer.exe
Y
CcRegVfy
ccRegVfy.exe
"Part of Norton AntiVirus 2003. ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
X
ccRegVfY
expIorer.exe
WIN32.TACTSLAY.A TROJAN!
X
ccRegVfY
outIook.exe
WIN32.TACTSLAY.A TROJAN!
X
ccRegVfY
svcrhost.exe
WIN32.TACTSLAY.A TROJAN!
X
ccRegVfY
svcshost.exe
WIN32.TACTSLAY.A TROJAN!
Y
ccSetMgr
ccSetMgr.exe
Part of Norton AntiVirus 2004. What does it do?
X
ccUpdate
ccUpdate.exe
AGOBOT.YS WORM!
U
ccWasher
aolwasher.exe
"Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL"
U
CCWC7a
ac.exe
"Cache, Cookie & Windows Cleaner Ver. 7, Auto clean. Created by moleculesoft"
U
CCWC7I
idxl.exe
"Cache, Cookie & Windows Cleaner 7 created by moleculesoft.com"
U
CCWC7s
stealth.exe
"Cache, Cookie & Windows Cleaner 7, stealth mode. Created by moleculesoft"
N
CD Storage Master
cdstorager.exe
"CD_Storage_Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection."
X
cd1
cd1.exe
Premium rate adult content dialer
N
CDANTSRV
CDANTSRV.exe
"C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually"
X
Cdcompat
Cdcompat.exe
GEMA TROJAN!
X
cddrv32
cddrv32.exe
Crypter.C trojan variant infection
N
CDInterceptor
cdi.exe
CD indexer for measuring the speed of CD players
X
Cdrom Controller
cdromcntrl.exe
TROJ/BATTRY-A TROJAN!
N
CDTray
CDTray.exe
"On HP PCs, this is the small CD icon next to the time"
U
CeEPOWER
cepmtray.exe
"Toshiba\'s Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times"
X
Cekirge
??
KERGEZ.A VIRUS!
X
center
??
W32.BOFRA.A WORM!
X
CentralProcessor
taskimgr.exe
BANCOS.J VIRUS!
X
cesmain.dll
"cmail.dll, Rundll32"
CnsMin (Chinese_Keywords) related
X
CEventMgr
Cell.exe
Troj/Bifrose-AK TROJAN!
N
CFD
CFD.exe
BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
X
CFDStart
WinMuschi.exe
WINMUSCHI dialler
X
cfgboost
cfgboot.exe
unidentified WORM or TROJAN!
Y
cfgintpr
cfgintpr.exe
Configuration Interpreter - part of Tiny Personal Firewall V4
X
cfgmgr51
??
BookedSpace adware variant
X
cfgmgr52
??
BookedSpace adware variant
N
cfgwiz
cfgwiz.exe
"Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it"
U
cFosSpeed
cFosSpeed.exe
cFos_Software Internet acceleration program related. Note: May be necessary for the software to work properly.
X
cftmon32
taskmgr#.exe
SOWSAT.C and SOWSAT.J VIRUSES! where # is a number greater than or equal to zero
X
cfy
cfy.exe
Surfenhance.com SearchForIt adware variant
U
CGServer
cgserver.exe
Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs
X
Cgtask Services
cgtask.exe
LALA.B VIRUS!
X
Cgywin
cgywin32.exe
W32/Rbot-AEI Worm!
U
ChamClock
ChamClock.exe
Chameleon Clock - system tray clock replacement
U
ChangeICON
SPMSMON.EXE
Card reader related program. Note: May cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem.
X
change-me-now
msgfix1.exe
SDBOT.ZD WORM!
N
Chatango
Chatango.exe
"Chatango ""allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!."" The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately."
N
Chcenter
chcenter.exe
"IMSI HiJaak - ""the easiest way to convert, capture, and manage all your graphic files"""
X
che32
che.ocx.vbs
WM97/Adenu-B VIRUS!
X
Cheatle
GigaByte.exe
SHODI.B VIRUS!
N
Check for One Touch Update
wiseupdt.exe
Checks for updates for Visioneer OneTouch scanners
N
Check for TWS Updates
WiseUpdt.exe
Interactive Brokers - check for update to their standalone Java-based trading platform
U
Check Messenger
cmesseng.exe
Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account
N
CheckCustomWorksUpdate
CheckCWupdate.exe
"Update checker, part of CustomWorks - ""customize any embroidery designs to design your own unique creations"""
U
CheckIt
ToolBox.exe
"CheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify"
U
CheckIt 86
CheckIt86.exe
CheckIt_86 popup blocker
Y
CheckMsgPlus
??
"MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info."
X
checkrun
??
EliteBar adware
X
CheckScan32
regload16.exe
AEBOT.K WORM!
U
CherryKeyMan
KeyMan.exe
Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys
X
china11msn
CHINA11MSN.EXE
W32.ENVID.O WORM!
U
ChineseStar
cstar.exe
Chinese language support software
U
CHIPDRIVEPinManager
sokscmpn.exe
ChipDrive Smartcard software
U
CHIPDRIVESmartcardManager
SCMgr.exe
ChipDrive Smartcard software
N
CHKADMIN
CHKADMIN.EXE
"Compaq Network Management System. When running, it places an icon in the system tray titled ""Intelligent Manageability"""
N
chkhbci
chkhbci.exe
Smart Card reader software for Omnikey readers
X
Choke
Choke.exe-blahh
CHOKE VIRUS!
X
chope
runlli32.exe
Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
chostsv
chostsv.exe
BANPAES.C VIRUS!
U
CHotKey
mhotkey.exe
"Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features"
U
CHotKey
MK9805.EXE
"Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features"
U
CHotKey
zHotkey.exe
"Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features"
N
Christmas Music Player
TTEST6.EXE
"""Christmas Music Playerbrings the music of the Christmas Holiday to your desktop"""
X
CiaBackdoor
msldr.com
VIRUS!
X
cihost.exe
cihost.exe
LINST VIRUS!
N
CIJxP2PSERVER
CIJxP2PS.EXE
"Compaq printer utility which is required in order to make the printer work correctly - ""x"" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7"
U
Cisco Systems VPN Client
ipsecdialer.exe
The Cisco VPN_Client Lets local users gain Administrator privileges on the operating system
U
Cisco Systems VPN Client
vpngui.exe
Sets up IPSec communications for Cisco's VPN_Client
N
CISrvr Program
CISRVR.EXE
Related to internet setup on Compaq PC's
X
Cissi
Cissi.exe
CISSI.A VIRUS!
U
CitiUCS
CitiUCS.exe
Citibank Virtual_Account_Numbers
N
CitiVAN
CitiVAN.exe
Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again
X
CJET
CJet.exe
Adware.FFToolBar adware toolbar.
Y
Cjstcom
Cjstcom.exe
Canon printer BJ status language monitor
Y
ClamWin
ClamTray.exe
ClamWin antivirus
X
Classes
int1.exe
"""Switch"" adult content dialler"
X
Classes
intl.exe
"""Switch"" adult content dialler"
X
Classes
MSTAR2.EXE
"""Switch"" adult content dialer"
X
Classes
mstart.exe
"""Switch"" adult content dialer"
X
Classes
run_21.exe
"""Switch"" adult content dialler"
X
Classes
srv.exe
"""Switch"" adult content dialler"
X
Classes
srv2.exe
"""Switch"" adult content dialler"
U
CLBOOT32
CLBOOT32.EXE
"PC-Duo_Remote_Control from Vector. ""System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!"". For tech support users to provide remote assistance"
U
CLCLSet
CLCL.exe
CLCL clipboard caching utility
X
clean_service
clean_service.cmd
W32.Refaz WORM!
U
CleanSweep Smart Sweep- Internet Sweep
Csinsm32.exe
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
N
CleanSweep Useage Watch
CSUSEM32.EXE
Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
U
CleanTemp
CLEANT~1.EXEBCleanTemp.exe
CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
Y
CleanUp
mcappins.exe
Used by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled.
N
Cleanup
ONICTASK.EXE
Internet Cleanup from Aladdin Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet
X
clfmon.exe
clfmon.exe
TROJ/AGENT-BJ TROJAN!
N
Click Radio Tuner
clickr~1.exe
ClickRadio - subscription service playing radio music via the internet
N
Click Tray Calendar
ClickT~1.EXE
"ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc"
"""ClickTheButton"" Downloader-MY TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!"
X
ClickTheButton
CTB.exe
"""ClickTheButton"" Downloader-MY TROJAN!"
X
ClickTheButton
MSCStat.exe
"""ClickTheButton"" Downloader-MY TROJAN!"
X
CLICONFG
CLICONFG.EXE
OPASERV.T VIRUS!
U
Client Access API Daemon
cwbappcd.exe
"IBM iSeries Client Access, see here"
N
Client Access Check Version
cwbckver.exe
"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to.?Not required - and can be turned off in the Client Access properties. It's a waste of resources"
N
Client Access Help Update
cwbinhlp.exe
"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries"
N
Client Access Service
CwbSvStr.Exe
"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources"
U
Client Access Taskbar
cwbuitsk.exe
"IBM iSeries Client Access taskbar, see here"
X
Client Agent
??
Troj/PPdoor-J TROJAN!
X
Client Agent
ipxwping.exe
Troj/PPdoor-N TROJAN!
X
Client for Microsoft Networks
msclient32.exe
W32/Sdbot-BXQ Worm!
X
Client Server Runtime Process
csrs.exe
W32.LINKBOT.M WORM!
X
Client Server Runtime Process
csrsss.exe
W32/SDBOT-LD WORM!
X
Client Update
wup.exe
variant of the W32/OPANKI-A WORM!
X
ClientMan1
mscman.exe
"Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,? ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"""
N
Clik Status Monitor
toolsclickstat.exe
Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
N
Clipbook Service
Clipsrv.exe
"Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks"
N
ClipMate5x
ClipMt5x.exe
Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
N
Clipmate6
CLIPMT60.EXE
Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
N
Clipomatic
Clipomatic.exe
"Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data"
X
ClipSrv
clipserv.exe
W32/SDBOT-AAV WORM!
N
Clipsrv
Clipsrv.exe
"Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks"
U
ClipTrak
ClipTrak.exe
ClipTrak clipboard extender
N
ClipTrakker
ClipTrakker.exe
Cliptrakker - clipboard extender
U
CLMFrontPanel
clmpanel.exe
"System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost"
"ClockSynck - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available"
U
ClockWise
CLOCKWISE.EXE
"ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync"
U
CloneCD or CloneCDTray
CloneCDTray.exe
"System tray for CloneCD - the only useful option is ""Hide CDR Media"" only available via this tray. Has additional unknown functions in later versions"
U
CloneCDElbyCDFL
ElbyCheck.exe
From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
X
ClrSchLoader
Loader.exe
Lycos/IGetNet.ClearSearch parasite
X
CLSID
com.exe
Adult content dialler
X
CLSID
dll.exe
Adult content dialler
X
CLSID
msgplus.exe
"Premium rate adult content dialer - NOTE: this is NOT the MSN Messenger 'MessengerPlus' extension, as described here"
X
CLSID
plugin.exe
Adult content dialler
X
CLSID
sed.exe
Adult content dialler
U
cma
cma.exe
"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
X
CMAPP
cmappclient.exe
CasClient adware - also detected as Trojan.Cmapp
N
Cmaudio
"Rundll32 cmicnfg.cpl, CMICtrlWnd"
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
X
Cmd
cmd32.exe
P2P.TANKED VIRUS!
X
cmd32
configs.exe
"Hijacker, also detected as the QURL-2 TROJAN!"
X
cmdcon
cmdcon.exe
CRYPTER.A TROJAN!
X
CmdPrompt32.pif
CmdPrompt32.pif
W32.Assiral.B WORM!
X
CME
cme.exe
Part of Gator advertising spyware - see here for removal instructions
U
C-Media Echo Control
EchoCtrl.exe
C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
N
C-Media Mixer
Mixer.exe
C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
X
CmeSYS
CMEsys.exe
Part of Gator advertising spyware - see here for removal instructions
X
CmeUPD
CMEupd.exe
Part of Gator advertising spyware - see here for removal instructions
X
Cmmon32Sys
cmmon32.exe
WIN32.SMALL.CL TROJAN!
U
CmPCIaudio
"RunDll32 CMICNFG3.CPL,CMICtrlWnd"
Registers the Control Panel applet for a C-Media PCI sound card
U
CMPDPSRV
CMPDPSRV.EXE
"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). ""Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more."" Installed with some Compaq and Lexmark printers"
X
Cmpnt
Devices2.exe
Troj/Tompai-D TROJAN!
X
Cmpnt
mainsv.exe
Troj/Tompai-C TROJAN!
X
cmrss
??
Troj/Dloader-QQ TROJAN!
X
cmrss
cmrss.exe
DELF.DU and Troj/Dloader-NK TROJANS!
X
cmrss
crmss.exe
DLOADER-EK TROJAN!
X
cmrst
cmrst.exe
PWSteal.Bancos.S TROJAN!
X
cmrst
cmrst.scr
Troj/Dloader-FP TROJAN!
X
CMS_Update
ms_update.exe
eBoard adware variant
U
CMSETTINGS
ctmn.exe
Part of NetNanny Chat_Monitor
X
cmsound
vcpdll.exe
TCXMEDI-D downloader TROJAN!
X
cmsound
vcsystem.exe
TCXMEDI-D downloader TROJAN!
X
cmss
system.exe
variant of the WIN32.RBOT WORM!
X
cmssapp
iexplore_.exe
Troj/Bancban-CQ Trojan!
X
cmssSystemProcess
csms.exe
AGENT-Y TROJAN!
X
cmssSystemProcess
csmss.exe
TROJ/AGENT-CO TROJAN!
X
cmssSystemProcess
mcsmss.exe
REPSAMO TROJAN!
X
cmt101
cmt101.exe
Crypter.C trojan variant infection
X
cmx32
cmx32.exe
W32.GEMA.D TROJAN!
X
Cn323
cnfrm33.exe
W32.MIMAIL.G WORM!
X
CNBABE
CNBABE.EXE
Appears to be spyware KAZAA (and maybe others) that displays pop-up ads whilst you\'re browsing
N
cnet
kontiki.exe
Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
X
Cnfrm32
cnfrm.exe
W32.MIMAIL.D WORM!
X
CnsMax
Internat.exe
POINTEX VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
X
CnsMin
??
CnsMin (Chinese_Keywords) related
Y
CnxAdslL
CnxAdslL.exe
"DLink, Zoom, or Conexant modem driver"
N
CnxDslTaskBar
CnxDslTb.exe
Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
U
Codename Dashboard
dashboard.exe
"Codename: Dashboard - ""an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"""
X
Coldlife -icmp
Systray.exe
IRC/FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process
U
coloreal
coloreal.exe
"Makes colours sharper and brighter, but will only work with coloreal capable monitors"
N
Colorific Control Panel
Hgcctl95.exe
From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor
X
COM Service
mscom32.com
BEASTY.H VIRUS!
X
COM Service
msdrce.com
BEASTY.I trojan
X
COM Service
msjclh.com
PLUX VIRUS!
X
COM Service
msynvr.com
BEASTY.G VIRUS!
X
COM+ Event System
DRWTSN16.EXE
variant of the LOVGATE WORM!
X
COM+ EventSystem Services
ECSERVER.EXE
variant of the W32/SDBOT WORM!
X
Com+ Sys
csrs.exe
W32/FORBOT-BT WORM!
X
COM+ System Applications
lsas.exe
AGOBOT.SE WORM!
X
COM++ System
exploier.exe
variant of the LOVGATE WORM!
X
COM++ System
suchost.exe
variant of the LOVGATE WORM!
X
COM++ System
svchost.exe
variant of the LOVGATE WORM!
U
ComAgent
ComAgent.exe
"ComAgent, MDaemon's instant messaging client"
X
combo.exe
combo.exe
Troj/Chimo-C TROJAN!
X
combop.exe
combop.exe
"Troj/Bckdr-CSJ TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. When run, this file together with its little friend combo.exe send spam from your machine."
X
combop.exe
combop.exe
Troj/Bowfeed-A TROJAN!
X
Comcast Network
ribiva.exe
IRC_TROJAN variant!
X
ComcastSUPPORT
tgkill.exe
"Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an ""enhanced"" support and self-repairing tool. This is ""beta"" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs"
X
COMCFG
comcfg.exe
TOADCOM.A VIRUS!
X
comctl32
comctl32.exe
Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am
U
COMDRV32
svdhost.exe
"Orvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
N
COM-IP
COMIP.EXE
COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
U
Comm Driver
commh32.exe
"G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!"
X
COMMAND
command.exe
QQPASS.E VIRUS!
X
Command
Gotit.exe
TITOG VIRUS!
X
command
javaw.exe
W32/Agobot-LG WORM!
X
Command
system.exe
GATECRASH.A or GATECRASH.B VIRUSES!
X
command32
command32.exe
Troj/LineaDl-A TROJAN!
N
CommCtr
commctr.exe
"""Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!"". Available via Start -> Programs"
U
Compaq Alerter
CPQAlert.exe
"Compaq's Insight Manager Agent - a tool that allows for ""fault, performance, and configuration management"". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information"
N
Compaq Computer Corp SCCenter Module
SCCENTER.EXE
For Compaq PC's. Part of Backweb
N
Compaq DMI
cpqdmi.exe
Compaq version of the Desktop Management Interface
X
Compaq Drivers
F1rewalls.exe
W32/SDBOT-WD WORM!
N
Compaq Internet Setup
inetwizard.exe
For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
X
Compaq Jes Drivers
winjes.exe
W32/SDBOT-XR WORM!
U
Compaq Knowledge Center
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support"". You decide"
U
Compaq Knowledge Center
silent.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support"". You decide"
N
Compaq Message Server
COMPAQ-RBA.EXE
"Applies to CPQBootPerfDB below as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the ""Compaq Advisor/Compaq Message Screener"" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the ""advanced"" tab. Not required and can cause problems"
U
Compaq PK Daemon
cpqkl.exe
For Compaq laptops for programming user configurable keys. Not required unless you use them
X
Compaq Print Fax
cpqa1000.exe
W32/SDBOT-WL WORM!
X
Compaq Service Drivers
amsn.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
compq.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
compqs.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
msnsvc.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
msnt.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
navapqwa.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
NtKernelSystem.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
systeminfos.exe
W32/SDBOT-XC WORM!
X
Compaq Service Drivers
wincmd.exe
RBOT.ATV WORM!
X
Compaq Service Drivers
wind32.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers
winmsn.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivers 32
compq32.exe
variant of the W32/SDBOT WORM!
X
Compaq Service Drivrs
copq.exe
variant of the WIN32.RBOT WORM!
X
Compaq Sound Drivers For WINDOWS
sounddr.exe
W32/SDBOT-XG WORM!
N
Compaq Video CD Watcher
??
For Compaq PC's. MPEG viewer
X
Compaq32 Service Drivers
ms32.exe
SDBOT.BWH WORM!
X
Compaq32 Service Drivers
msconfig32.exe
W32/SDBOT-ADC WORM!
X
Compaq32 Service Drivers
msnt32.exe
variant of the WIN32.RBOT WORM!
N
CompaqHW Comp Manager
cpqhcm.exe
"Compaq_Intelligent_Managability agent; ""a solution that simplifies inventory management by automating the collection of hardware asset data for Compaq servers running in a NetWare environment""."
N
CompaqPrinTray
printray.exe
Puts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
X
Compaqs Service Drivers
compqs.exe
variant of the W32/SDBOT WORM!
N
CompaqSystray
cpqpscp.exe
Compaq System Tray icon
X
Compatibility Service Process
regsvs.exe
GAOBOT.YN WORM!
X
Compd Service Drivrs
codq.exe
variant of the W32/SDBOT WORM!
X
Computing Technologie Firewall
lsauth.exe
W32/SDBOT-WX WORM!
N
COMSMDEXE
comsmd.exe
3Com tray icon
X
ComTry Web Searcher
wstray.exe
Comtry MP3 Downloader related - spyware
X
comxt
comxt.exe
Comxt trojan infection
X
Config
service.exe
ISRAZ.B VIRUS!
X
Config Loadation
iEEexplore.exe
SDBOT.H WORM!
X
Config Loadatiorin
I3Explorer.exe
SDBOT.H WORM!
X
Config Loader
scvhost.exe
GAOBOT.AE or GAOBOT.AO WORMS!
X
Config Loader
svchosl.exe
GAOBOT.P WORM!
X
Config Loader
svhost.exe
variant of the AGOBOT/GAOBOT WORM!
X
Config Loader
sysldr32.exe
GAOBOT WORM!
X
Config Loader for Microsoft Windows
mwincfg32.exe
AGOBOT.BD WORM!
X
Config Loader2
explores.exe
GAOBOT.BT WORM!
X
Config Loadr
winsys32.exe
AGOBOT-HN WORM!
X
Config33.exe
Config33.exe
SDBOT.T backdoor TROJAN!
X
ConfiggLoader
cart322.exe
GAOBOT.DJ WORM!
U
ConfigSafe
AUTOCHK.EXE
"ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice"
U
ConfigSafe
CFGSAFE.EXE
"ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice"
N
ConfigServices
Config.exe
Part of initial setup on a Compaq PC
X
Configuration
??
W32/SDBOT-ML WORM!
X
configuration
apphost.exe
W32/SDBOT-VP WORM!
X
Configuration
ntsys32.exe
W32/SDBOT-LN WORM!
X
Configuration Default
Wuxat.exe
W32/SPYBOT-CA WORM!
X
Configuration File
Winset32.exe
BackDoor.Flux.101 TROJAN!
X
Configuration Loaded
lssas.exe
variant of the W32/SDBOT WORM!
X
Configuration Loaded
wupdated.exe
MOEGA or MOEGA.AG or MOEGA.AP VIRUSES!
X
Configuration Loader
aim95.exe
LOADCFG or SDBOT TROJANS
X
Configuration Loader
botss.exe
W32/SDBOT-XS WORM!
X
Configuration Loader
ccSort.exe
AGOBOT.SR WORM!
X
Configuration Loader
cmd32.exe
"LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files"
X
Configuration Loader
confgldr.exe
POLYBOT VIRUS!
X
Configuration Loader
crcss.exe
AGOBOT.ADG WORM!
X
Configuration Loader
dezi.exe
W32/SDBOT-OB WORM!
X
Configuration Loader
dosrun32.exe
GAOBOT.AO WORM!
X
Configuration Loader
IEXPL0RE.EXE
"LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files"
X
Configuration Loader
ldasp.exe
AGOBOT.BH WORM!
X
Configuration Loader
lexplore.exe
W32/RBOT-AGX WORM!
X
Configuration Loader
microsoft.exe
GAOBOT.JB WORM!
X
Configuration Loader
mouse.exe
variant of the AGOBOT/GAOBOT WORM!
X
Configuration Loader
msg.exe
SDBOT.BT WORM!
X
Configuration Loader
msgcfgsrv.exe
variant of the AGOBOT/GAOBOT WORM!
X
Configuration Loader
msgfix.exe
W32/SDBOT-QG and W32/Sdbot-BTE WORMS!
X
Configuration Loader
msnss.exe
GAOBOT.AUS worm
X
Configuration Loader
MSTasks.exe
"LOADCFG or SDBOT TROJAN!. Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files"
X
Configuration Loader
scvhost.exe
W32/AGOBOT-AAE and Backdoor.Sdbot.AR WORMS!
X
Configuration Loader
seru32.exe
W32/SDBOT-VR WORM!
X
Configuration Loader
Service.exe
GAOBOT.AO WORM!
X
Configuration Loader
service5.exe
GAOBOT.AF WORM!
X
Configuration Loader
Servicess.exe
GAOBOT.AO WORM!
X
Configuration Loader
smsai.exe
W32/SDBOT-YE WORM!
X
Configuration Loader
smss32.exe
AGOBOT.MB WORM!
X
Configuration Loader
svchost.exe
W32/ParaDrop-A WORM!
X
Configuration Loader
svchost2.exe
AGOBOT.JR WORM!
X
Configuration Loader
svhst.exe
GAOBOT.YC WORM!
X
Configuration Loader
svupdate.exe
W32.RANDEX.DXP WORM!
X
Configuration Loader
sw32.exe
AGOBOT.BQ WORM!
X
Configuration Loader
sycfg34.exe
GAOBOT.AN WORM!
X
Configuration Loader
syscfg32.exe
SDBOT.B WORM!
X
Configuration Loader
sysinfo.exe
GAOBOT.FQ WORM!
X
Configuration Loader
System.exe
GAOBOT.AO WORM!
X
Configuration Loader
systemry.exe
variant of the AGOBOT/GAOBOT WORM!
X
Configuration Loader
wincffg.exe
AGOBOT.A3 WORM!
X
Configuration Loader
wincrt32.exe
GAOBOT.BF WORM!
X
Configuration Loader
windex.exe
GAOBOT.BM WORM!
X
Configuration Loader
windex.exe
GAOBOT.BZ WORM!
X
Configuration Loader
WinHelper.exe
variant of the AGOBOT/GAOBOT WORM!
X
configuration loader
winicfg32.exe
GAOBOT.GEN!POLY WORM!
X
Configuration Loader
Winreg.exe
GAOBOT.AO WORM!
X
Configuration Loader Service
devl32.exe
W32/SDBOT-XY WORM!
X
Configuration Loader Service
Winsys32.exe
W32/RBOT-YV WORM!
X
Configuration Loader Service
winsys32.exe
W32/RBOT-YV WORM!
X
Configuration Loader10
ip7.exe
W32/AGOBOT-ANZ WORM!
X
Configuration Loading
configldr.exe
AGOBOT-EC WORM!
X
Configuration Loading
svchos1.exe
GAOBOT.DK WORM!
X
Configuration Loading Service
wscel.exe
W32/SDBOT-WJ WORM!
X
Configuration Manager
CNFGLD32.EXE
SDBOT WORM!
X
Configuration Manager
Cnfgldr.exe
SDBOT WORM!
X
Configuration Service
suchost.exe
TREB VIRUS!
X
Configuration Services
mswords.exe
W32/SDBOT-YM WORM!
N
Configuration Utility
CONFIG.EXE
Controls linksys wireless connection. Available from the Desktop
U
Configuration Utility
wlanutil.exe
NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
N
Configuration Wizard
Cfgwiz32.exe
"variation of the HACKTACK VIRUS! Not to be confused with the valid MS ""ISDN Configuration Wizard"" (Cfgwiz32.exe) in C:\Windows\System"
X
Configuration32 Loader32
winamp32.exe
W32/Sdbot-BIC WORM!
X
ConfLoader
sysconf16.exe
TROJ/SDBOT-FB TROJAN!
N
Conmgr
conmgr.exe
Starts Winfax pro at startup
U
ConMgr.exe
conmgr.exe
Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut?
X
Connect2Party
connect2party.exe
Adult content dialler
N
Connection Manager
CManager.exe
SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
X
Connectivity Tool
??
Troj/Litebot-E TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Connector
sms.EXE
Dial/ExDial-B Dialer! Note: Dial/ExDial-B is a premium rate porn dialer.
X
Connector
SYS.EXE
Dialer.Nunci premium dialer.
X
Cons
consol32.exe
"Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed"
X
conscorr
conscorr.exe
Transponder parasite updater/installer
X
Console de Gerenciamento Microsoft
csrss.exe
Troj/Bancban-ET TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
ContentDownload
??
MatrixDialer related
X
ContentService
winservn.exe
Homepage hijacker
X
ContinueInstall
bpsinstall.exe
BrowserAid parasite
X
Control
??
CoolWebSearch parasite related
X
Control handler
??
CoolWebSearch parasite variant
X
Control handler
ahjinst.exe
CoolWebSearch parasite variant
N
control panel
smctrlw.exe
System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
X
Control Panel
System.exe
DANI VIRUS!
X
Controladores
??
Troj/Telefo-A Trojan!
N
ControlCenter2.0
brctrcen.exe
Brother scanner 'Control Center' application; can be started manually
N
ControlCentreTray
XWCTray.exe
"System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc"
X
Controlled Resource System Service
crss.exe
"variant of the AGOBOT.GEN WORM! **Note - this is NOT the legitimate crss.exe process, which should NOT figure in Msconfig/Startup!"
N
Controller
WFXCTL32.EXE
From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
"Browser hijacker, also detected as TROJ/STARTPA-FX"
U
Cookie Cop 2
CookieCop.exe
"Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
U
Cookie Pal
CPBRWTCH.EXE
"Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
U
CookieJar
Cookiejar.exe
"Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
U
CookiePatrol
CookiePatrol.exe
CookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies
U
CookieWall
cookie.exe
"CookieWall from Analog X. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
U
Cool Desk
cdesk.exe
"Cool Desk is a virtual desktops manager. ""Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them"". Not required but may be of use to you"
X
CoolDownloads
??
MatrixDialer related
X
CoolMP3
??
MatrixDialer related
U
CoolSwitch
taskswitch.exe
ALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
N
Coolwallpaper
cwm_tray.exe
Cool_Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers
X
coolwebprogram
clrssn.exe
CoolWebSearch parasite related
U
Copernic Desktop Search
CopernicDesktopSearch.exe
"Copernic Desktop_Search - ""Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures."""
U
CopernicPerUserTaskMgr
CopernicPerUserTaskMgr.exe
Automatic tasking feature of Copernic Pro multi-search engine tool
U
Copy handler
Copy Handler.exe
"Copy_Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes."
N
Copyright
mwcpyrt.exe
Displays copyright information on IBM ThinkPads
N
Corel Colleagues & Contacts Reminders
cffrem.exe
"Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office"
N
Corel Desktop Application Director
dadx.exe
The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
N
Corel Family & Friends reminders
CFFREM.EXE
"Corel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic"
N
Corel Registration or Corel Registration Remi
Remind32.exe
If you don\'t want to register Corel products and be reminded about it every 2 weeks disable it
N
Corel Reminder
NAVBROWSER.EXE
If you don't want to register Corel products and be reminded about it every 2 weeks disable it
N
CorelCENTRAL 10
I_26dadCC.exe
CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
X
CorelDraw Toolbox
CorelDraw.exe
W32/SDBOT-VZ WORM!
N
CorelMedia FoldersIndexer8
MFindexer.exe MFINDE~1.EXE
"Part of CorelDraw bundles for indexing media files - similar to ""fast find"" in MS Office"
X
CoreSrv
coresrv.exe
Some IRC trojans/worms use this - see here for more information
N
CorrectConnect
CConnect.exe
Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
"Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you\'ve set the modem up to the chosen country it\'s not required"
X
couponica
couponica.exe
Adware - see here
U
CP32NOT
CP32BTN.EXE
"For the programmable ""one-touch"" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons"
U
CP4HPOT
OneTouch.EXE
One Touch keyboard driver. Required if you use the additional keys
U
CPATR10
CPATR10.EXE
"Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast"
U
CPBrWtch
CPBrWtch.exe
"Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add ""cookies"" related to their sites for the next time you return"
Y
CPD_EXE
CPD.EXE
Firewall bundled with McAfee VirusScan 6.*
X
cpl
deamon.exe
WIN32.TACTSLAY.C TROJAN!
X
cpl
msgaol.exe
WIN32.TACTSLAY.C TROJAN!
X
cpl
s_menu.exe
WIN32.TACTSLAY.C TROJAN!
N
CplBTQ00
CplBTQ00.EXE
Related to the EZbutton quick launcher
N
CPLDBL10
CPLDBL10.exe
Related to the EZbutton quick launcher
X
cpntmgc
navpmc.exe
MagicControl downloader trojan variant
X
cpntmgc
simcss.exe
MagicControl downloader trojan variant
X
cpntmgc
wincomp.exe
Remote-control trojan from Electronic Group - see here
X
cpntmgc
winmgts.exe
Remote-control trojan from Electronic Group - see here
Y
CPQAcDc
CPQAcDc.exe
Compaq PowerCon power management software for laptops
U
CPQAlert
CPQAlert.exe
"Compaq's Insight Manager Agent - a tool that allows for ""fault, performance, and configuration management"". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information"
N
CPQBootPerfDB
CPQBootPerfDB.EXE
See the entry for Compaq Message Server
Y
CPQCalib
CPQCalib.exe
Compaq PowerCon power management software for laptops
N
CPQDFWAG
CpqDfwAg.exe
For Compaq PC's. Runs Compaq diagnostics on every boot
U
CPQEASYACC
cpqeadm.exe
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U
CPQEASYACC
StartEAK.exe
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U
cpqeaui
cpqeaui.exe
For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U
cpqek
kcpqek.exe
For Compaq PC's. Easy Access button support for the keyboard
X
CPQHotkeys
hotkeysvc.exe
W32.Kelvir.A or W32.Kelvir.B WORM!
U
CPQInet Runtime Service
CpqInet.exe
For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers
N
CPQINKAGENT
cpqinkag.exe
"That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)"
U
cpqns
cpqnpcss.exe
Related to Compaq.Net - not required if you don't use that
N
Cpqset
Cpqset.exe
Default settings software in Hewlett Packard notebook
Y
CPQSTUTFIX
stutfix.exe
For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
X
cpr
cpr
Adroar.com adware downloader
X
CPU Manager
cpumgr.exe
PANDEM.B VIRUS!
X
CPU Temp Control
wuitgurd.exe
W32/RBOT-AHV WORM!
X
CPU Watcher
??
TROJ/DLOADER-LO TROJAN!
X
CPU Windows Status
cpustats.exe
variant of the WIN32.RBOT WORM!
U
CPUcool
Cpucool.exe
"Program to keep the processor cool when idle in ""overclocked"" systems. Also available via Start -> Settings -> Control Panel"
X
Cpusave
Cpusave.exe
GEMA TROJAN!
X
Cpusave32
Cpusave32.exe
GEMA TROJAN!
X
cpyt
hidep.exe
Troj/Mirjack-A Trojan!
X
cqlyg
world_cup_.bat
WCUP VIRUS!
U
cracked_windows1
cracked_windows1.exe
Cracked Windows popup killer
N
CrazyTalk Serve
??
"CrazyTalk from Reallusion - ""the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions."" Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS"
X
CRC Value Verifier
crsss.exe
SPYBOT.UK WORM!
X
CRC Value Verifier
crsss32.exe
variant of the WIN32.RBOT WORM!
X
CRC Value Verifier
Crsss64.exe
W32/Rbot-NY WORM!
X
CRC Value Verifier
svchost32.exe
W32/RBOT-OA WORM!
X
Crc32stats Dependencies
Crc32stats.exe
W32.MYTOB.GT WORM!
U
Creata Mail
JMSrvr.exe
"Creata_Mail . Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express."
X
Create A Monster
createAMonster.exe
Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related
N
CreateCD
Createcd.exe
Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
N
CreateCD50
Createcd50.exe
Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
N
Creative AGP Wizard
agpwiz.exe
Part of Creative's BlasterControl
N
Creative Launcher
CTLauncher.exe
For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
N
Creative MediaSource Go
CTCMSGo.exe
"""Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"""
N
Creative PCI Audio Configuration Utility
starter.exe
System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer
N
Creative Service for CDROM Access
Ctsvccda.exe
Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
N
Creative WebCam Tray
Camtray.exe
Creative WebCam tray control; can be started manually.
X
Creative.exe
Creative.exe
PROLIN VIRUS!
N
CreativeDiscNotifier
CTNOTIFY.EXE
"For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel"
U
CreativeMixer
CTMIX32.EXE
"Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the ""speaker"" icon. Not required unless you adjust any settings otherwise available via the standard icon"
X
Critical Update Check
battlenet.exe
Troj/Delf-LB TROJAN!
N
CriticalUpdate
Wucrtupd.exe
"MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site"
X
Crnsava
scrnsave.pif
W32/Sdbot-ZV WORM!
X
cronos
MARCO!.SCR
OPASERV.G VIRUS!
U
CrossMenu
CrossMenu
Toshiba CrossMenu Utility - allows the user to create their own menus
X
crs
crs.exe
W32/Agobot-TJ WORM! Note: This worm\trojan file is found in the Root folder. Example: ( C:\ )
X
Crusty
dmcpl.exe
Added as the result of the RUSTY VIRUS!
X
cryptdlg
cryptdlg.exe
unidentified TROJAN!
X
Cryptographic Service
??
Win32.Korgo.AB worm
N
csaRem
spqmdmui.exe
Compaq modem country selection
Y
CSAV_CheckViruses
vchk.exe
Part of Command AntiVirus
X
CSCRS Value
cscrs.exe
W32/RBOT-AAA WORM!
X
CSCRS Value Check
MsPMSPSd.exe
variant of the W32/SDBOT WORM!
U
CSINJECT.EXE
CSINJECT.EXE
"Part of Quarterdeck/Norton CleanSweep. For a full description see here. An excerpt - ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes."""
X
csm Win Updates
csm.exe
W32/ZOTOB.B WORM!
X
csoftok
softok.exe
TROJAN.PWS.QQPASS.G TROJAN!
X
csrsc
csrsc.exe
unidentified VIRUS!
U
csrss
csrss.exe
"Spyware.BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. - NOTE - this file is placed in the Program Files\Supremtec folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
CSRSS
CSRSS.EXE
"Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling"
X
Csrss
csrss.exe
"W32.Chod WORM! Note - This will be installed in a random folder and is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
Csrss
csrss.exe
"W32.CHOD.B WORM! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!"
X
CSRSS Loader
csrsss.exe
AGOBOT.TX WORM!
X
csrssLevel4
csrss.exe
"Unidentified malware - NOTE - this file is placed in a C:\Windows\System\Level4 folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
CSRSSU
CSRSSU.exe
CoolWebSearch parasite related - hijacking to Slawsearch.com. Also see here
X
CSRSSW
CSRSSW.EXE
TROJ/CWS-F TROJAN!
X
CSRSWIN
??
WINSHELL.50 VIRUS!
X
CSRSX
??
WINSHELL.50.B VIRUS!
U
CSS Server
CSSServer.exe
ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself.
U
CSS_Central
CSS_1631.EXE
"CSS Communication Agent (95 Host) from Command Software Systems""CSS Central? provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console."""
Y
CSScheduleCheck
SCHWIZEX.EXE
"Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot"
X
cssrs
cssrs.exe
Troj/Bancban-DW TROJAN!
X
csss
Csss.exe
BALICK VIRUS!
X
CSV10P70
CSv10P070.exe
ClearSearch adware related
X
CSV7P26
CSV7P26.exe
ClearSearch adware related
X
CSV7P70
CSV7P070.exe
ClearSearch adware related
X
CSV7P91
CSV7P91.exe
ClearSearch adware related
U
csvdea
csvdea.exe
SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself.
Y
ct
ct.exe
ct.exe is a file is for the HP Learning Adventure software?and if you use this software it is required to run it
X
CT Control Settings
CTSVCCD.EXE
W32/RBOT-YS WORM!
N
CTAVTray
CTAvTray.exe
For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
U
CTCMonitor
CTCMonitor.exe
"Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required"
N
CTDVDDet
CTDetect.exe
"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again"
N
CTDVDDet
CTDVDDet.exe
"Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again"
X
ctflog manager
ctflog.exe
DONBOMB.A TROJAN!
X
CTFM0N.exe
CTFM0N.exe
STARTPAGE.P TROJAN!
X
ctfmon
cftmon.exe
TROJ/DELIVE-A TROJAN!
X
ctfmon
ctfmon.exe
Troj/SDBot-06 Trojan!
X
ctfmon
ctfmon.exe
Adware responsible for tenmonkey.com popups - file located in the Winnt or Windows folder - NOTE: do not confuse with the MS Office file of the same name as described here
X
ctfmon
mIRC.dll
Troj/Delbot-E Trojan!
X
ctfmon
taskmgr32#.exe
SOWSAT.B VIRUS! where # is a number from 0 to 9
X
ctfmon
WinConst.exe
Troj/Assasin-G Trojan!
U
ctfmon.exe
ctfmon.exe
"CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don\'t need these features. For more info on ctfmon see here;en-us;282599 . CTFMON can be disabled from Control Panel, Text & Speech Services. NOTE: The file will always be located in the System32 folder. If it is located elsewhere, it will likely be a worm or trojan!"
X
ctfmon.exe
ctfmon.exe
PWSteal.Raidys TROJAN!
X
Ctfmon.exe
ctfmon32.exe
CoolWebSearch parasite related
X
CTFMON32
CTFMON32.EXE
CoolWebSearch parasite related - also detected as the TROJ/CWS-E TROJAN!
X
CTFMONSS
CTFMONSS.EXE
TROJ/CWS-F TROJAN!
X
ctfnom
rundIl32.exe
Troj/LegMir-AW TROJAN! Note: This is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling). This trojan file (rundIl32.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
ctfnom.exe
OSRSS.exe
Troj/Dloader-UQ TROJAN! Note: This trojan file (OSRSS.exe) is found in the Windows or Winnt folder.
X
ctfnom.exe
SVOHOST.exe
Troj/Digidor-A or Troj/StartPa-HA TROJAN!
X
cthelp
cthelp.exe
SDBOT TROJAN!
N
CTHELPER
CTHELPER.EXE
"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a ""leave alone"" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it"
X
CTHelper
cthelper.exe
W32/RBOT-XB WORM! - NOTE - do NOT confuse with the Creative application of the same name described here
X
CTime
??
CoolWebSearch parasite related
X
CTin10
CTin10.exe
BANCOS.E VIRUS!
N
CTRegRun
CTRegRun.exe
For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
U
CtrlVol
CtrlVol.exe
Acer's on screen volume control using the Fn key
N
CTStartup
CTEaxSpl.exe
Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
U
CTsysVol
CTSYSVOL.exe
Creative sound card volume controls
X
CTUpdate
ctupdclt.exe
W32/RBOT-ABG WORM!
X
Ctykd
??
TSPY_SMALL.SN spyware
Y
cuagentExe
Cuagent.exe
Command Antivirus related
X
cuo
cuo.exe
BUGBEAR VIRUS!
X
Current Security Config
csecure.exe
W32/Rbot-AMO WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
cursor
Screendragon_VS_Taskbar.exe
ScreenDragon video player
N
CursorXP
CursorXP.exe
CursorXP from Stardock - tool for creating mouse cursors
U
CurtainsSysSvc
AuthSL.exe
"Security Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private."
U
Customizer2000
logon.exe
"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"""
N
CuteMX
CuteMX.EXE
File sharing utility
X
cvmonitor.exe
cvmonitor.exe
WORM_SDBOT.BV
Y
CVPND
cvpnd.exe
Sub-system used by?Cisco VPN client?for making a connection to a remote IPSec server
U
CW
cw4.exe
"Chat_Watch ""is a monitoring and logging software for online chat and instant messaging programs"""
U
CWatch
cw.exe
ChatWatch - chat monitoring tool
N
cwbckver
cwbckver.exe
"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to.?Not required - and can be turned off in the Client Access properties. It's a waste of resources"
N
cwbinhlp
cwbinhlp.exe
"Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries"
N
cwbsvstr
cwbsvstr.exe
"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources"
U
cwupdate
cwupdate.exe
"ContentProtect, from ContentWatch - http://www.contentwatch.com/products/contentprotect.phpinternet filter"
N
CXMon
Hpi_Monitor.exe
"Autodetects when a HP camera is attached to the computer and launches the ""HP Photoimaging Software"". Available via Start -> Programs"
N
Cyber
cyberchk.exe
"Part of Belkins ""Multimedia Cleaning Kit"" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after ""x"" amount of time has passed"
U
Cyber Trio
showmode.exe
"From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs"
U
Cyber-Defender 2003
uwcdsvr.exe
Cyber Defender 2003
X
cyberfree.exe
??
Unidentified adware
U
CyberLat Ram Cleaner
CLRamCleaner.exe
"CyberLat RAM Cleaner is a program that Frees, Optimizes and Defrags your system\'s wasted memory (RAM). Some users swear by programs such as this but I suggest you read this article and make up your own mind"
N
CyberMedia Agent
CMAGENT.EXE
"Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled"
X
CyberWolf
CyberWolf.exe
KICKIN.A (or CYDOG.C) VIRUS!
X
CyDoor or CydoorUpdate
CD_Load.exe
Adware. Check here for information about Cy-Door and here for a program that can remove it
N
CyphTray
CyphTray.exe
Cypherus - encryption software
N
D066UUtility
D066UUTY.EXE
TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
X
D3**.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
D3**32.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
d3dupdate.exe
bbeagle.exe
BEAGLE.A WORM!
U
D4
D4.exe
Dimension 4 - network time synchronization software
N
DACONFIGEXE
daconfig.exe
3Com NIC Diagnostics. Available via Start -> Programs
Y
DadApp
dadapp.exe
"""DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked"" - direct from Dell"
X
Daemon
daemon.exe c daemon2.exe
W32.Selotima.A WORM!
N
Daemon
DAEMON32.EXE
Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
U
Daemon or DAEMON Tools-1033
Daemon.exe
"Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive"
N
Daily Planner
dayplan.exe
"Daily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them"
X
Daily Weather Forecast
weather.exe
DLOADER-IP TROJAN!
U
Dancer
DncLE.exe
Part of Microsoft Plus! Digital Media Edition - see here
X
Danton
??
DANTON VIRUS!
N
Dap
DAP.exe
Download Accelerator Plus from SpeedBit - download manager/accelerator
X
dark
imgrt.scr
Troj/Bancban-DU WORM!
X
dark
imgst.scr
PWSTEAL.BANCOS.U TROJAN!
X
DarkDevil.Grasiele.BR
Grasiele.VBS
LEMBRA VIRUS!
X
DarKNesS LsasS
LsasS23.exe
unidentified WORM or TROJAN!
X
dasxdads
fsdqd.exe
GAOBOT.BIQ WORM!
X
data
msngs.exe
W32/RBOT-ADQ WORM!
X
Data
System.dat.vbs
BISCUIT.A VIRUS!
N
Data LifeGuard
BACKWE~1.EXE
Data LifeGuard diagnostic tools for Western Digital\'s series of hard drives
N
Data LifeGuard LifeLine Lite installer
DLGLI.EXE
Backweb installer - see here
X
Data Restore Service
prq8.exe
W32.Kelvir.AI WORM!
X
Data789
??
Homepage hijacker
X
DATABASE MySql
??
variant of the RANDON.AN WORM!
N
DataCaching
FlashKsk.exe
"SmartMedia Card management from the installation of a SanDisk reader for a camera\'s SmartMedia card and also adds the ""Unplug and Eject Hardware"" System Tray icon"
U
DataLayer
DataLayer.exe
"Nokia PC Suite 5 - ""A collection of powerful tools that you can use to manage your phone features and data."" Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on"
U
DataViz Inc Messenger
DvzIncMsgr.exe
"Installed with DataViz ""Documents to Go"" software"
N
DataViz Messenger
DvzMsgr.exe
"DataViz Documents to Go - ""allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"""
X
Datcheck
datcheck.exe
KEYPANIC VIRUS!
X
Date Manager
datemanager.exe
DateManager - calendar program. Contains Gain adware
X
DateMakerIntl
DateMakerIntl.exe
Premium rate dialler also referred to as the PORNSPA.F VIRUS!
X
Daudi
daudi.exe
"Malware, as yet unidentified"
X
DAupdate
DAupdate.exe
NavEnhance adware
U
DayToday
DAYTODAY.EXE
DayToday from RoboMagic Software Corp. Displays the date on the taskbar
U
DAZEL Delivery Agent
DcDaemon.exe
"Control and send documents, etc, to any destination - see here"
N
dbserv
dbserv.exe
Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
N
DBTMON
dbtmon.exe
Dell button monitor for 9XX series printer most commonly associated with 922. Can safely be turned off does not hamper printer operations. Can be accessed from the start menu
X
DCE Manager
dcemgr.exe
TUMAG.A TROJAN!
U
DCfssvc or dcfssve
dcfssvc.exe
"Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can\'t load pictures from your camera/dock - Kodak\'s dock is an example"
X
Dcom System Patch
Microsoft.exe
RANDEX.MS WORM!
U
DDCActiveMenu
DDCActiveMenu.exe
Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
X
DDCM or DDCMan
DDCMan.exe
Digital Distribution Channel from Wild Tangent - adware
X
ddeproc
ddeproc.exe
Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here
X
DDialler
DDialler.exe
Adult content dialler
X
de32gen
de32gen.exe
CRYPTER.C trojan variant infection
N
DeadAIM
??
DeadAIM - feature enhancing product for AOL\'s Instant Messenger program
X
DealHelperBrwsr
dhbrwsr.exe
DealHelper adware
X
DealHelperDown
download.exe
DealHelper adware
X
DealHelperUpdate
DHUpdt.exe
DealHelper adware
X
Debug
DebugW32.exe
GUBED VIRUS!
X
DebugMonitor
debugmonitor.exe
W32.Mydoom.BG WORM!
U
DeeEnEs
DeeEnEs.exe
DeeEnEs - automatically updates a dynamic IP address when it changes.
X
deejay
forboo.exe
Added as result of a Forbot-AY worm infection
X
Default
explore.vbs
VBS.Allem WORM!
X
Default
mtask.vbe
VBS.Allem WORM!
X
default
shell32.exe
Backdoor.Binghe TROJAN!
X
Default System Research
vhchost.exe
TARNO.I VIRUS!
X
Default web browser
IexpIore.exe
"OBLIVION.B VIRUS! Note - don not confuse ""IexpIore.exe"" with ""iexplore.exe"" (Internet Explorer), the first has a captial ""i"" in place of lower case ""L"""
X
Default_Page_URL
http://find.naupoint.com
Naupoint browser hijacker
X
Default_Search_URL
http://find.naupoint.com
Naupoint browser hijacker
X
defragm_check
defragment.exe
CoolWebSearch parasite related
U
defwatch
defwatch.exe
Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
U
Delay or Delayrun
delayrun.exe
On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
X
Delete Me
worm.exe
Added as the result of the DOOMHUNTER VIRUS!
N
Dell Alert
DAMon.exe
"""Dell Alert"" utility, that's supposed to make interaction with Support easier"
N
Dell QuickSet
quickset.exe
ell taskbar icon allowing you to quickly change settings
U
DELLMMKB or DellTouch
DELLMMKB.EXE
Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
N
DellSC
dellsc.exe
Dell Solution Center - web-based troubleshooting tools and educational offerings
U
DellSupport
DSAgnt.exe
Dell Support Agent offers additional support and update features for your Dell computer or laptop.
U
DellTouch
MMKeybd.exe
Dell multimedia keyboard manager. Required if you use the additional keys
X
delmsbb
delmsbb.exe
nCase adware
X
delsaap
delsaap.exe
nCase adware
X
delsubmit
??
CoolWebSearch parasite related
N
DeltTray
deltray.exe
"System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel"
X
Deneca
Virus salvado
W97M.DELUZ VIRUS!
U
DepFrez
frzstate.exe
"Deep Freeze from Hyper Technologies. ""Freezes"" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example"
X
Desire
desires.exe
Adult content dialler
X
DeskAd Service
DeskAdServ.exe
DeskAd.Service adware
N
DeskColor
DESKCOLOR.EXE
Provides transparent icon text backgrounds and coloured icon text
N
Deskflag
Deskflag.exe
DeskFlag - animated USA flag on the desktop
N
DeskMateAutoUpdate
DeskMateAutoUpdate.exe
DeskMates: Virtual scantily clad girls enhance your desktop - according to PestPatrol BargainBuddy adware related
X
DeskMateAutoUpdate
DeskMateAutoUpdate.exe
DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related
U
Desksite CMA
cma.exe
"DeskSite CMA siftware - ""retrieves new content from the DeskSite Data Center"""
X
Desktop
??
BOOKMARKER VIRUS!
X
desktop
desktop.exe
SDBOT.MD WORM!
X
desktop
desktop.exe
W32.Kobot.L WORM!
N
Desktop Architect
DATRAY.EXE
"Desktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc"
N
Desktop Plant
AZARE10S.PLT
"Vritual plant from here - this version is an Azalea, there are others so the filename may be different"
X
Desktop Search
desktop.exe
"iSearch ""Desktop Search"" hijacker"
N
Desktop Weather
THE WEATHER CHANNEL.exe
"Desktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc"
N
Desktop Weather 3
THE WEATHER CHANNEL.exe or THEWEA~1.EXE
"Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc"
N
desktopmgr
desktopmgr.exe
"Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the ""Blackberry"""
X
DesktopUpdate
??
MatrixDialer related
U
DesktopX
DESKTOPX.EXE
"A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking"
N
deskup
deskup.exe
Adds Iomega Zip drive icons to the desktop
X
destroyb11
destroyb11.exe
Troj/Delf-KO TROJAN!
U
detect
idetect.exe
"iNTERNET Turbo from Clasys Ltd. ""It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds"". If you find it helps your connectivity leave it enabled"
N
Detector
detector.exe
"USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software"
U
DEventAgent
eventagt.exe
DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
X
Device Configuration Loader
msdvc32.exe
variant of the GAOBOT/AGOBOT WORM!
U
Device Detector
DevDetect.exe
Watches for external digital imaging products being connected from ACD Systems
N
Device Detector 2
DevDtct2.exe
"Installed by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a ""high"" priority level which can negatively impact system resources"
U
DeviceDiscovery
hpotdd01.exe
"Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products"
X
DevicePath
??
GRUEL VIRUS!
U
Devices
olesvr.exe
Salfeld Child Control 2003 - parental control software
U
devldr16.exe
devldr16.exe
"Associated with some Creative Labs sound cards.? Provides audio support for DOS applications.? Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
X
dgtstart
dgtstart.exe
DigitalNames.g adware
N
dguard
dguard.exe
eAcceleration Stop-Sign related; not recommended; see note
X
DHCP Server
regsvr.exe
W32/RBOT-PR WORM!
Y
dhcpagnt
dhcpagnt.exe
Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
N
diagent
diagent.exe
System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
X
Diagnostic
diagnostic.exe
Troj/Alpha-C TROJAN!
X
Dial22 or Dial33
dlm.exe
Adult content dialler
X
Dialer
??
Unidentfied malware
U
Dialer Control
dc.exe
Dialer-Control . Detects and protects from premium rate p0rn dialers
U
Dialer Detect
dd.exe
"DialerDetect detects stealth installed premium rate dialers, and sounds the alarm when such a connection is being installed without you knowing it."
U
Dialgo SDK
PhoneAnswer.exe
"Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"""
X
DialNet
mxt32.exe
Adult content dialler
N
Dialog Box Assistant
OSDEx.exe
Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
N
Dialog Helper
PDDLGHLP.EXE
Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
X
DialUp Network Application
Rnaap.exe
variant of the W32/SDBOT WORM!
X
DIECOX
csrss.exe
BackDoor-ATM.gen trojan variant
X
Diesel
Recalculate.exe /reloadenterpice
Lazar TROJAN!
U
DietK
DietK.exe
"DietK - add-on for Kazaa Media Desktop; ""removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results."""
X
DigiD
DigitalSound.exe
Adware downloader
N
DigiGuide
CLIENT.EXEclient01.exe
TV guide and reminder
N
Digital Dashboard
CPQMLDET.exe
For Compaq PC's. Loads Digital Dashboard options
N
Digital Dashboard
devgulp.exe
For Compaq PC's. Loads Digital Dashboard options
N
Digital Line Detect
DLG.exe
Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
N
Digital River eBot
downlo~1.exe
"Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here"
X
DigitalNames
DigitalNamesStart.exe
DigitalNames spyware variant
N
DigitalWizard
ISWizard.exe
"InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content"
N
DigitalWizard Monitor
dwMon.exe
"InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content"
N
DIGStream
digstream.exe
DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
U
Dimension
Dimension.exe
"Dimension, a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol."
U
Dimension4
d4.exe
"Atomic clock synchronisation freeware - starts-up, adjusts the system clock, then shuts down"
X
Dino3
dino3.exe
Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
X
Dinst
dinst.exe
GrandStreet parasite variant - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Intexp.d
X
Dir1
caKe
CAKE VIRUS!
X
Direct settings
sdchost.exe
TROJ/DAEMONI-I TROJAN!
U
Direct Update
DUControl.exe
DirectUpdate dynamic DNS updater
X
Direct X Direct3D
dxd3d.exe
variant of the W32/SDBOT WORM!
X
Direct X Opengl
dxopengl.exe
variant of the W32/RBOT-CJ WORM!
X
direct3d.exe
direct3d.exe
TROJ/CERTIF-F TROJAN!
N
DirectCD
DirectCD.exe
DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
X
directs.exe
directs.exe
BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!
U
DIRECTVDSL
Directvdsl.exe
Starts DirectTV DSL modem at boot up. Can also be started manually
X
directx
??
SDBOT.D WORM!
X
DirectX
ddhelp32.exe
BIONET.318 VIRUS! Note - not the DirectX helper which is ddhelp.exe
X
DirectX
DirectX.exe
BLAXE or LOGPOLE VIRUSES!
X
DirectX
directx32.exe
AGOBOT.CG WORM!
X
DirectX 32
directx32.exe
variant of the AGOBOT/GAOBOT WORM!
X
DirectX for Microsoft Windows
dtxservice.exe
PROGENT TROJAN!
X
DirectX for Microsoft Windows
Fservice.exe
PRORAT TROJAN!
X
DirectX for Microsoft Windows
Sservice.exe
PRORAT TROJAN!
X
DirectX For Microsoft╜ Windows
fservice.exe
Troj/Prorat-P TROJAN!
X
DirectX shell driver
??
Troj/MarktMan-B TROJAN!
X
DirectX Video Driver
dxterm5.exe
W32/WILAB-A TROJAN!
X
DirectX64
DirectXset.exe
BROWNEY.A VIRUS!
X
DirectX9 Diag
dx9diag.exe
W32/RBOT-ALT WORM!
U
Dirkey
Dirkey.exe
Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl Alt 1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl 1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders?
N
Disc Detector
CtNotify.exe
"For Creative sound cards. Detects when you insert a CD, DVD, etc"
N
DiscoverDeskshop
Deskshop.exe
"Discover Deskshop - single use ""virtual"" credit card"
X
Disk Keeper
keep.exe
Mslware - recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.ve
X
Disk Keeper
SECURITY.EXE
WEBSEARCH TROJAN - a variant of Daoser-A
X
Disk Manager
diskver.exe
RBOT.AQT WORM!
X
Disk Master
??
DISTER VIRUS! - a spam relayer
U
Disk_Monitor
Disk_Monitor.exe
"Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader"
X
DiskCheck
msdarkend.exe
unidentified WORM or TROJAN!
N
DiskeeperSystray
DkIcon.exe
DisKeeper defragmentation software - can be started manually.
X
diskinf
diskinf.exe
CRYPTER.A trojan infection
N
Disknag
disknag.exe
Dell program that reminds you to make your? backup diskettes
X
Diskstart
cat.exe
MS-Connect dialler
X
Diskstart
Code.exehit.exeSnt.exe
Adult content dialler
U
display
The_Eye.exe
ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself.
X
Display Drivers
cssrs.exe
AGOBOT.FX WORM!
N
Display Settings
hptasks.exe
"Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers."
N
DisplayTrayIcon
TrayIcon.exe
"System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display"
U
Disspy
disspy.exe
Disspy spyware detection and removal software
N
Distiller Assistant 3.01
DISTASST.EXE
From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
X
Distributed File System
blade.exe
W32.MYFIP.AC WORM!
X
Distributed File System
Dfsvc.exe
MYFIP.A or MYFIP.K WORMS!
X
Distributed File System
kernel32dll.exe
W32.MYFIP-C or W32.MYFIP.K or W32.Myfip.T WORMS!
X
Distributed File System
win.exe
W32.MYFIP.AB WORM!
U
distributed.net client
DNETC.EXE
Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses
Y
Dit
dit.exe
"""Drive Icon and Label Utility"" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found"
N
DiTask.exe
DiTask.exe
"Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs"
X
divx
divxenc.exe
Added to the Spbot.B TROJAN!
X
DivX MediaPlayer 7.0
Dr.DivX.exe
ALADINZ.G VIRUS!
X
DivX Player
DivXPlayer.exe
variant of the WIN32.RBOT WORM!
X
DivX Updater
DivX.Exe
NALDEM or MASTAK VIRUSES!
X
Divx4 codec
devldr32.exe
unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file
N
DJREGFIX
??
"DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
Y
DkService
DkService.exe
From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. Used to schedule defragmenting on a regular basis and not required if you do so manually.
X
DKTime
dktime.exe
Downloader.Lunii trojan infection
X
Dkware lptt01 or Dkware ml097e
dkware.exe
"Variant of the RapidBlaster parasite (in a ""DonkeySoft"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
Y
dla
tfswctrl.exe
"Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
N
DlaTray
Dlatray.exe
"System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
X
dlder
dlder.exe
"Advertising spyware. Considered to be one oft the worst - even creating a fake ""explorer.exe"" file. Can be installed via versions of ""Grokster"", ""Lime Wire"" and ""KaZaA"" amongst other file-sharing utilities (see here). Reported in the past as a virus"
X
DlDir1
caKe
CAKE VIRUS!
N
DLF_00000B00
Vcdlf.exe
"Known to cause problems with ""Out of memory"" errors (see here). Otherwise, it's purpose is unknown"
N
DLG
DLGCHBW.exe
Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
N
DLHelperEXE
WATCH.exe
Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
X
DLHelperEXE.exe
??
Downloader for Microgaming/Casino software - stealth installed
X
dlhost
dlhost.exe
Troj/ExpHook-A TROJAN!
Y
D-Link Air USB Utility
AirCFG.exe
D-Link wireless PCI adapter related
Y
D-Link Air Utility
AirCFG.exe
D-Link wireless PCI adapter related
N
D-Link AirPlus DWL-650+ Utility
WLANMON.exe
D-Link Air Plus Wireless PC modem connection monitor
Y
D-Link AirPlus G
AirGCFG.exe
D-Link Airplus Wireless Router driver
X
Dlite
dllmanager.exe
WOOTBOT.DN WORM!
X
Dll Boot Loader on Startup (do not remove this)
??
unidentified TROJAN!
X
DLL Manager
dllmngr32.exe
variant of the WIN32.RBOT WORM!
X
DLL Service Manager
??
RPCBOT.F VIRUS!
X
DLL32
dllmem32.exe
KWBOT.E VIRUS!
X
DllCacherv2
dllcachev2.exe
BACKDOOR.LATEDA TROJAN!
X
dlldmt
dlldmt.exe
CRYPTER.C trojan variant infection
X
DllExecutable
??
W32/VB-SP WORM!
X
dllhelp
dllhelp.exe
W32/Startpage.DQ hijacker infection
X
dllhelp
dllhlp.exe
Downloader-HI TROJAN!
X
dllhostxp.exe
dllhostxp.exe
browser hijacker and adware downloader
X
DllLoader
lssas.exe
TROJ/BDOOR-JE WORM!
X
Dlload
killer.exe
Troj/KillAV-FK TROJAN!
X
dllreg
dllreg.exe
CRYPTER.A trojan infection
X
DLLService32
dllsvc32.exe
AGOBOT.VX WORM!
X
dluca
dluca.exe
Adult content dialler - see here
X
dluca
dluca.exe
DLUCA.C VIRUS!
X
dluxde
dluxde.exe
All-In-One-Telcom (adult content dialler) variant
X
Dluxjp
cnfrm.exe
DLUCA.D VIRUS!
X
DM mgr
dm_mgr.exe
JITTAR VIRUS!
X
DM_server
dmserver.exe
Comet Cursor adware
X
dm_service
??
MITGLIEDER.P TROJAN!
N
DMILDR
dmildr.exe
"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs?"
N
DMISL
DMISL.EXE
DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
N
DMISLAPP
DMISLAPP.exe
DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
X
Dmsvc32
Dmsvc32.exe
AGOBOT.ABU WORM!
X
dmtdll
dmtdll.exe
Crypter.C trojan variant infection
U
DMXLauncher
DMXLauncher.exe
"Part of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files."
X
Dnar
Dnar.exe
"Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here"
Y
DNE Binding Watchdog
"rundll dnes.dll, DnDneCheckBindings"
Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
Y
DNE DUN Watchdog
"rundll dnes.dll, DnDneCheckDUN13"
Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
X
DNS
mc-110-12-0000079.exe
TrojanDownloader.Agent.rv TROJAN!
X
DNS
mc-58-12-0000080.exe
"""Shorty"" adware component, also detected as the AGENT.FD TROJAN!"
X
DNS
mc-58-12-0000093.exe
Nail/Aurora related malware
X
DNS
mc-58-12-0000120.exe
"""Shorty"" adware component, also detected as the AGENT.FD TROJAN!"
X
DNS
mc-58-12-0000140.exe
"""Shorty"" adware component, also detected as the AGENT.FD TROJAN!"
X
Dns Resolver
dnsrslve.exe
W32/RBOT-WS WORM!
X
DNS Service
dnsresolver.exe
W32/RBOT-PQ WORM!
X
DNSCacheBoost
dnsping.exe
TROJ/DNSBUST-A TROJAN!
X
dnscleaner
dnscleaner.exe
CoolWebSearch parasite related
X
DocTor
Doctor.exe
DOTOR VIRUS!
N
DocuMagix Init
PWATCH.EXE
"PaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed"
X
Doggy Style
MsPMSPSd.exe
W32/Sdbot-AAP WORM!
X
DOGStart
GSDOGST.EXE
unidentified VIRUS! A possibility is a trojan known as PENIS
X
doit.exe
doit.exe
W32/FORBOT-EK WORM!
U
Don't Panic
dontpanicdemodp.exe
"30-day trial version of Don't Panic privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite."""
U
Don't Panic Pop-Up Stopper
dpps2.exe
Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
X
dos
dos64.exe
adware downloader trojan
X
Dos Prompt Loader
cygwin.exe
W32/SDBOT-VV WORM!
X
Dot.net Networking
Snss32.exe
variant of the IRC_TROJAN !
N
DoUWantIt
duwi.exe
DoUWantIt - online shopping assistant. Start it manually
X
down
hlp32.exe
TROJ_DLOADER.BG TROJAN!
N
Download Accelerator Plus 5.0
DAP.exe
"Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is ""adware"" based"
X
Download Plus
DownloadPlus.exe
DownloadPlus parasite - opens pop-up adverts
N
Download Wonder
DownloadWonder.exe
"Download Wonder from Forty Software. Download manager for resuming downloads, amongst other features"
N
DownloadAccelerator
DAP.EXE
"Download_Accelerator_Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based"
X
DownloadLegalMusic
??
MatrixDialer related
X
DownloadWare
dw.exe
"DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent"
X
DownloadWare Engine
Dwe.exe
"DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent"
X
Downxz
Downxz.bat
W32.Mydoom.W WORM!
N
DPAgnt
DPAgnt.exe
digitalPersona fingerprint scanner
Y
Dpcnav
dpcnav.exe
DirecWay from DirectTV satellite based high-speed internet access
N
DPConfig
DPConfig.exe
"Compuware DevPartner Studio Configuration Utility, a tool for software developers - system tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when needed."
X
dpcproxy
dpcproxy.exe
Troj/GoldenP-A trojan infection
Y
DPCProxyLoadOnStartup
dpcstart.exe
DirecWay from DirectTV satellite based high-speed internet access
U
Dpcstart
dpcstart.exe
"Startup program for Direcway 2-way satellite internet service. Loads DirecWay\'s Navigator, tray icon, etc"
Y
Dpcstart
dpcstart.exe
DirecWay from DirectTV satellite based high-speed internet access. Proxy software
X
dpi
dpi.exe
"Delfin_Media_Viewer or ""Promulgate"" adware"
U
dpps2
dpps2.exe
Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
X
dps
dps.exe
"SmartestSearch parasite -poses as a foistware, bogus adware/spyware remover called ""scumware-remover"""
X
DR_S
DR_S.exe
AdShooter adware
N
DragnDrop_Autolaunch
Autolaunch.exe
Iomega_HotBurn - CD-RW burning software
N
Drag'n'Drop_Autolaunch
Autolaunch.exe
Iomega HotBurn - CD-RW burning software
X
DrefIW
SysDref.exe
W32/Dref-D WORM!
X
DrefIW
SysDrefIWv2.exe
W32/DREF-C WORM!
N
DrgToDsc
DrgToDsc.exe
"Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly"
N
DriveLED
OODLed.exe
O&O DriveLED - displays your HDD LED on your monitor. Start manually
X
Driver
gbot.exe
JUNTADOR.K VIRUS!
X
Driver32
Scam32.exe
SIRCAM VIRUS!
X
DriverCheck
svchost.exe
"TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
DriverDB
svcmdx32.exe
BACKDOOR.BERPI TROJAN!
X
DriverLoad
svchost.exe
"TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
N
DriveSelect
driveselect.exe
DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
U
dRMON SmartAgent
SmartAgt.exe
Part of the network monitoring program group for 3Com NIC cards. See here for more info
X
drmu
W95Mm.exe
Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread
X
drocher
d.exe
Premium rate adult content dialer
X
Drvddll_exe
drvddll.exe
BEAGLE.X WORM!
U
drvlsnr
drvlsnr.exe
Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
X
drvr32h
drvr32h.exe
unidentified VIRUS!
X
drvrmanager
drvrquery32.exe
BOOHOO VIRUS!
X
drvsys.exe
drvsys.exe
BEAGLE.W WORM!
X
drvupd
??
"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
X
DrWatson
drwatson_.exe
TROJ/LOHAV-S TROJAN!
X
DrWatson
drwatson_32.exe
TROJ/LOHAV-S TROJAN!
X
DrWeb Antivirus
DRWEBAV.EXE
unidentified WORM or TROJAN!
Y
Drwebscheduler
Drwebscd.exe
"Dr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem"
U
DS Clock
dsclock.exe
Digital desktop clock including synchronization with atomic servers - see here
X
dsa
dsa.exe
Homepage hijacker - redirecting to downseek.com
X
DSAcass
??
RANKY.M backdoor TROJAN!
X
DSB
DSB.exe
EnergyPlugin adware
N
DSentry
DSentry.exe
"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts"
X
Dsi
??
unidentified adware where ****** are random characters
X
Dskcompat
Dskcompat.exe
GEMA TROJAN!
N
DSL Monitor
spdstrm.exe
Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
U
DSLagentexe
DSLagent.exe
Enables the Media Center software on a Media Center PC to be lauched via the button on the remote. Required if you prefer not to double-click the desktop icon first
Y
dslmon
dslmon.exe
Sagem DSL modem related. Apparently needed to detect the modem.
U
DSLSTATEXE
dslstat.exe
System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
X
DsmSer
dsm.exe
W32.Serflog.B WORM
X
DsmSer
msmpatch.exe
W32.Serflog.B WORM
X
DsmSer
svosm.exe
W32.Serflog.B WORM
X
DsmSer
sysup.exe
W32.Serflog.B WORM
X
DSS
??
Troj/DSSDoor-C TROJAN!
X
DSS
dssagent.exe
DSSAgent by Br?derbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info
X
DSService
dmrss.exe
W32/AGOBOT-XX WORM!
N
DU Meter
DUMETER.EXE
Hagel Technologies internet bandwidth monitor
X
duck
duck.exe
W32/Agobot-AVG Worm!
N
dumprep 0 -kordumprep 0 -u
dumprep 0 -kdumprep 0 -u
"Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out"
X
DUN_SERVICES3
dun3.exe
Trojan.Sokiron TROJAN!
X
Duweculey
yujixit.exe
SDBOT.BRP WORM!
U
DVD43
DVD43.exe
DVD43 is a small tool that overrides CSS copy-protection found on DVD movies.
N
dvd43
DVD43_Tray.exe
"DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies."""
X
dvd98
windvd98.exe
CULT.P VIRUS!
U
DVDBitSet
DVDBitSet.exe
DVD RW Drive/Disc Compatibility Setting. Installed with HP DVD RW drives to enhance compatibility with existing readers. You can also set a DVD RW default drive write mode which is always used
X
Dvdcompat
Dvdcompat.exe
GEMA TROJAN!
U
DVDLauncher
DVDLauncher.exe
A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use
N
DVDSentry
DSentry.exe
"Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts"
Y
Dvp95
Dvp95.exe
Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine
Y
dvpapi9x
DVPAPI9X.exe
Command AntiVirus for Windows 95/98/Me
Y
DvpInitExe
Dvpinit.exe
Command Antivirus related
Y
dvprpt
Dvprpt.exe
Command Antivirus real time protection
X
dvraudio
dvraudio.exe
Crypter.C trojan variant infection
X
dvsfss
fbsfsdrs.exe
W32/Sdbot-QA worm infection
U
DVSync
dvsync.exe
DVSync is the program that allows you to synchronize your daVinci?s PDA's data with your Personal Information Manager on the PC
X
Dvx
wsxsvc.exe
"Delfin_Media_Viewer or ""Promulgate"" adware variant"
X
dw
dw.exe
"DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent"
U
DW4
Weather.exe
Desktop_Weather
U
DWHeartbeatMonitor
DWHeartbeatMonitor.exe
DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
N
DwlClient
support.exe
Download manager for Dell support alerts
Y
dwStart
FireWall.exe
The_Shield Firewall
X
Dx
sys#.exe
DEXTER.A VIRUS! where # is a random number
X
Dx8compat
Dx8compat.exe
GEMA TROJAN!
X
dxdiags.exe
dxdiags.exe
Troj/Certif-G TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
dxdll32
ntxdll.exe
W32.Gaobot.CPX WORM!
N
DXDllRegExe
dxdllreg.exe
"Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it"
X
DxLoad
DX3DRndr.exe
GIBE.B VIRUS!
N
DXM6Patch_981116
p_981116.exe
Win32 cabinet self extractor. More info here
X
dxmsrv
dxmsrv.exe
unidentified WORM or TROJAN!
X
Dxsty
Dxsty.exe
GEMA TROJAN!
X
Dxupdate.exe
Dxupdate.exe
MAFEG VIRUS!
X
DyFuCA
optimize.exe
Adult content dialler - see here
X
DyFuCA Active Alert
actalert.exe
Adult content dialler - see here
X
Dynamic Dns Binary
CMD16.EXE
W32/RBOT-XM WORM!
X
Dynamic Dns Binary
dynitora.exe
W32/RBOT-WT WORM!
X
Dynamic Dns Binary
WinHelpcfn.exe
variant of the WIN32.RBOT WORM!
X
Dynamic Dns Binary
winxp34.exe
variant of the WIN32.RBOT WORM!
X
Dynamic Link Library loader
Loader32.exe
BACKDOOR.KOL TROJAN!
U
DynDNS Updater
DynDNS.exe
"Dynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org."
N
DynDNS-Updater Traytool
ddutray.exe
DynDNS updater tray icon; allows easy configuration of the Dynamic DNSSM service.; can be run manually
X
DynHttp Dns Binary
dynizari.exe
variant of the WIN32.RBOT WORM!
U
DynSite
DynSite.exe
"DynSite is a dynamic DNS client, also called an automatic IP updater."
U
Dynu Basic Client
dynubas.exe
Dynu online dynamic IP update client. Useful when using a dial up modem.
U
E_S10IC2
E_S10IC2.exe
"Epson Stylus printer monitor - for checking ink levels, etc."
U
E_S23
E_SICN03.exe
"Epson printer status monitor - for checking ink levels, etc."
U
E_SOEIC1
E_SOEIC1.exe
"Epson Stylus printer monitor - for checking ink levels, etc."
N
E6TaskPanel
TaskPanl.exe
"Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space"
U
eabconfg.cpl
EabServr.exe
Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
X
Eac Download
download.exe
Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here
X
Eac_Cnry
canary.exe
CANARY VIRUS!
U
EACLEAN
eaclean.exe
For Compaq PC's. Easy Access button support for the keyboard
N
eanth_critical_update_alert
sys_alert.exe
eAcceleration Stop-Sign related; not recommended; see note
N
eanth_system_patcher
sys_alert.exe
eAcceleration Stop-Sign related; not recommended; see note
N
eanthology_install.exe
eanthology_install.exe
eAcceleration Stop-Sign related; not recommended - see note
N
EanthologyApp
EANTHO~1.EXE
eAcceleration Stop-Sign related; not recommended; see note
N
EanthologyApp
eanthology.exe
eAcceleration Stop-Sign related; not recommended; see note
N
Eapcisetup
sbsetup.exe
Rockwell RipTide soundcard application software. Sound works without it
N
EAPCISETUP
wizard.exe
Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
N
EarthLink ToolBar 5.0
etoolbar.exe
"EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time"
N
Easy Start Button
esb.exe
Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
X
EasyAV
EasyAV.exe
W32.NETSKY.S or W32.NETSKY.T WORM!
X
EasyDates
EasyDates.exe
Premium rate adult content dialer
X
EasyDates_nl
EasyDates_nl.exe
Adult content dialler
U
EasyKey or Easy Key
easykey.exe
For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
U
EasyKeyboardLogger
epl.exe
EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
U
EasyMessage
em2.exe
"Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here"
U
Easy-PrintToolBox
BJPSMAIN.EXE
A utility to launch the applications that are bundled with a Canon bubblejet printer
X
EasySearchBar
ESBUpdate.exe
EasySearchBar adware downloader
X
easyServ
Server.exe
EASYSERV VIRUS!
U
EasySync Pro
XCPCMenu.exe
EasySync Pro is a Lotus program for synchronizing a PDA with Lotus Notes
U
EasyTuneIII
EasyTune.exe
Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
U
EasyTuneIV
ET4Tray.exe
Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
X
easywww
??
EasyWWW adware
X
EbatesMoeMoneyMaker
??
Ebates adware
X
EbatesMoeMoneyMaker0
EbatesMoeMoneyMaker0.exe
Ebates adware
X
eBay Toolbar
EBAYTBAR.EXE
"eBay Toolbar - reportes as spyware as it ""phones home"""
U
eBayToolbar
eBayTBDaemon.exe
eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites.
U
eBoard or eMachines eBoard
Eboard.exe
eMachines multimedia keyboard manager. Required if you use the extra keys
N
eBot
DownloadWizard.exe
"eBot from Digital River - ""helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'."" Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs"
X
E-Card
ecard.exe
YODI VIRUS!
U
E-color
IconMgr.Exe
Sets the colour of your monitor when running games that recognise E-Color so that you get \'what the game designer intended\' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
U
eCopy Desktop Printer Service
mrmlnc32.exe
"eCopy Suite software connects your Canon imageRUNNER or document scanner to your company?s e-mail and other networked enterprise applications for easy, instantaneous distribution and management of scanned documents."
N
edexter
edexter.exe
eDexter supplements Internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser.
X
editpad
editpad.exe
CoolWebSearch parasite related
X
editpad
editpad.exe
Consper-B trojan infection
N
EDLoader
DTLoader.exe
Effective Desktop from MiniStars Software - desktop management software no longer being supported
U
EDRestore
??
"Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
X
educational writer
??
W32/Rbot-LZ worm infection
U
Edwizard
Edwizard.exe
"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"""
U
eFax DllCmd
J2GDllCmd.exe
eFax_Messenger fax software
U
eFax Tray Menu
J2GTray.exe
eFax_Messenger fax software tray menu
N
eFax.com Tray Menu
HotTray.exe
eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
X
efaxs lptt01 or efaxs ml097e
efaxs.exe
"Variant of the RapidBlaster parasite (in an ""efaxs"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
U
EFI Job Monitor
"efjm.dll,run"
Ricoh Imagio Printer/Scanner driver status monitor
U
Efpap.exe
Efpap.exe
"Easy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching"
U
ehTray
ehtray.exe
Windows XP Media_Center_Edition 2005. Enables the user to access Windows Messenger from within Media Center
X
ei10.exe
ei10.exe
AGOBOT-NK WORM!
U
Eicon NetworksLAN_DAEMON or Eicon TechnologyL
watch.exe
Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
X
eixfi
china.bat
WCUP VIRUS!
X
ekor.exe
igamatu
BACKDOOR.SDBOT.AQ TROJAN!
U
Elbycheck
ElbyCheck.exe
From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
U
Electron Microscope
EMIII.exe
"Electron Microscope, or EM , is a program used to track Stanford?s distributed computing program client called Folding at Home, FAH It will monitor up to 50 clients and give you the details about each client?s progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues."
X
Element
Element.txt
ELEM TROJAN!
X
element furth
??
variant of the RANDON.AN WORM!
N
elm
Elmenv.exe
"ViaTech eLicense for securing, distributing and selling music online"
X
ELNKProxy
smproxy.exe
Surfmonkey adware
U
ELSA WINman Suite
Winmsuit.exe
"Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU"
Y
ElsaCapiCtl
Rcapi.exe
"Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem"
U
ELSAChipGuard
elsavect.exe
"ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking"
U
ELSBLaunch
ELSBLaunch.exe
EarthLink SpamBlocker
U
EM_EXEC
EM_EXEC.EXE
"Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
N
EMA.exe
EMA.EXE
Time management system which helps you to manage your time and appointments
N
eMailEncryption
velozsys.exe
eAcceleration Stop-Sign related; not recommended; see note
X
eMakeSV
EMAKESV.EXE
Switch premium rate adult content dialer variant
X
emoc0re
emo.exe
W32/AGOBOT-AGE WORM!
X
empin
e121307.exe
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
empin
e121307.Stub.exe
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
emsw.exe
emsw.exe
"Believed to be spyware - made by a company called Alset. Also known as ""HelpExpress"". Will install itself if you have previously had Attune by Aveo installed as they're by the same company. Uninstall via Add/Remove programs"
X
emule
emule.exe
W32/Rbot-ALZ WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
eMusicClient Systray
eMusicClient.exe
eMusic MP3 download software
N
EN4060C Taskbar
en4060ct.exe
Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
X
enBrowser
??
WINBO adware component
N
Encarta Dictionary Quickshelf
QSHLFED.EXE
Provides quick access to Encarta's Dictionary features?
N
ENCMONITOR
monitor.exe
The Encompass Monitor. This program is the Connect Direct Program.? It is more trouble than it is worth and few use it
N
Encoder Agent
WMENCAGT.EXE
"MS Windows Media Encoder, which?already has a shortcut in?the Start Menu if installed"
U
Encompass_ENCMONTR
ENCMONTR.EXE
Optional simple browser from Yahoo (Encompass)
U
Energizer FileSaver
Energizer FileSaver.exe
Energizer FileSaver - UPS back-up utility for Energizer UPS products
X
EnergyPlugIn
EnergyPlugin.exe
EnergyPlugin adware variant
U
enginecs2
enginecs2.exe
Cyber_Sentinel Internet filtering software
Y
EngUtil
EngUtil.exe
"Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking"
X
Enh Win Updt
enhupdt.exe
Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h
X
enhance32
enhance32.exe
CRYPTER.A trojan infection
N
EnigmaPopupStop
EnigmaPopupStop.exe
"Part of Enigma SpyHunter - not recommended, see note"
U
EnsoniqMixer
starter.exe
"Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
X
Enumerate Service
wsys.exe
MANIFEST VIRUS!
Y
EnvyHFCPL
EnMixCPL.exe
VIA Envy24 PCI Audio Controller driver
U
eonemng
eOneMng.exe
"eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC"
N
EPoXUSDM
USDM.EXE
"EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc"
N
ePrint 4.0 Service
EPRINT4.EXE
"A component of the LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more! - Can be started manually."
U
ePrompter
ePrompter.exe
ePrompter - E-mail notification software
N
EPS
e_srcv02.exe
"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
N
EPS
e_srcv03.exe
"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
N
EPSON Background Monitor
STMS.EXE
Supposed to keep an Epson printer ready for quick printing.? Users report little difference whether it is on or not
U
EPSON CardMonitor
EPSON CardMonitor1.0.exe
Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
N
EPSON Status Monitor 3 Environment Check
e_srcv02.exe
"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
N
EPSON Status Monitor 3 Environment Check
e_srcv03.exe
"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
U
EPSON Stylus C44 Series
E_S10IC2.EXE
"Epson Stylus C44 Series printer monitor - for checking ink levels, etc."
U
EPSON Stylus C46 Series
E_S4I0T1.EXE
"Epson Stylus C46 Series printer monitor - for checking ink levels, etc."
U
Epson Stylus C62 Series
E-S0BIC1.EXE
Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
U
Epson Stylus C82 Series
e_s0hic1.EXE
Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
U
EPSON Stylus Photo R300 Series
E_S4I2F1.EXE
Epson Status Monitor - gets installed with many Epson printers and gives you a progress of your print jobs as they are printing.
U
EpsonPhotoStarter
EPSON_PhotoStarter.exe
Only needed if you want to make full use of the capabilities of an Epson printer that included this?
U
Eraser
eraser.exe -hide
Eraser allows for complete removal of data from your hard drive
U
eRecoveryService
check.exe
"Acer Notebook related - Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity."
N
EReg
reg32.exe
"EReg is a software registration tool incorporated on products such as those by Br?derbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it"
X
erghgjhgdr
windlhhl.exe
W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM!
N
Eror Nuker
ErrorNuker.exe
ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required.
X
eros.exe
eros.exe
Adult content dailler
X
ErrorGuard
ErrorGuard.exe
Spyware remover of dubious repute - see here
X
erthegdr
windll2.exe
W32.Beagle.CG WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
erthgdr
svc.exe
W32.Beagle.BK WORM!
X
erthgdr
svc.exe
W32.BEAGLE.BN or W32.Beagle.BP WORM!
X
erthgdr
windll.exe
BAGLE.BD WORM!
X
erthgdr2
svc23.exe
BAGLE.CG WORM!
U
ERUNT AutoBackup
AUTOBACK.EXE
"ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored if desired."
Y
eSafe Protect
ESPWatch.exe
eSafe from Aladdin - internet security for gateway and E-mail servers
U
ESB
esb.exe
Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
Y
eScan Monitor
AVKWCTL9X.EXE
eScan antivirus
U
eScan Scheduler
avkserv.exe
eScan antivirus scheduler
U
eScan Updater
Trayicos.exe
eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
X
EScorcher
escorcher.exe
Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
N
ESFTP
esftp.exe
ESftp - FTP client for transfering files between a local PC and another remote computer
X
Esoh
Esoh123.exe
AGOBOT.FF WORM!
X
Especial
Deneca.bat
W97M.DELUZ VIRUS!
N
ESPN BottomLine
bline.exe
"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."""
Y
Essdc
essdc.exe
Related to an ESS Solo soundcard. Seems as though it's required
Y
ESSOLO
ESSOLO.exe
Sound card driver that re-instates itself every time it's removed
Y
esspk
esspk.exe
ESS Technology modem speaker driver file. Required to get on-line with this modem
U
EssSpkPhone
essspk.exe
"ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets"
X
ETB Tester
etbtest.exe
W32/RBOT-ABR WORM!
X
etbrun
??
EliteBar adware variant
X
ethernet
airftp.exe
variant of the W32/SDBOT WORM!
X
ethernet
msftp.exe
SDBOT.BXJ WORM!
X
ethernet
msnger.exe
variant of the W32/SDBOT WORM!
N
Ethernet
tcaudiag.exe
3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
X
Ethernet Drivers
ethernet.exe
W32.GAOBOT.CEZ WORM!
X
Ethernet Drivers
smrrs.exe
W32/RBOT-AAK WORM!
X
Etraffic
JavaRun.exe
Marketing software from TopMoxie
Y
eTrust EZ Firewall
efpeadm.exe
eTrust EZ Firewall
U
eTrust PestPatrol Active Protection
PPActiveDetection.exe
"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
Y
eTrustCIPE
ezdsmain.exe
eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
X
eTunnel
winfw.exe
unidentified TROJAN!
U
EuroGlot
EuroGlot.exe
"Euroglot - ""multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"""
N
Event Planner Reminders
PLNRnote.exe
Sierra Event Planner tray icon
N
Event Reminder
pmremind.exe
A calendar/alarm program that installs with Br?derbund Printmaster
U
EVENTLISTENER
EvLstnr.exe
Used with a Nikon digital camera to recognize when the camera is plugged in
N
eventmgr
eventmgr.exe
Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
U
Evidence Cleaner
ecleaner.exe
Evidence_Cleaner cleans up tracks left by your PC and Internet activities
N
Evidence Eliminator
ee.exe
Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
X
Evil
Evil.exe
W32.Mytob.JM WORM! Note: This worm file may be found in the Windows or Winnt folder.
N
evntsvc
evntsc.exe
"Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it"
U
EVOLOSTA
EVOLOSTA.EXE
"Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it"
X
EvtHtm
evthtm.exe
Premium rate adult material dialer
U
EW Message Server
msg32.exe
Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
N
eWare Startup
iWareStart.exe
eWare iWare task bar. Not required
X
ewupdater
ewupdater.exe
EasyWebSearch adware updater
N
Excite Platform
Exlaunch.exe
Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
N
ExciteAssistantEXE
ASSISTANT.EXE
"With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open"
X
exe lptt01 or exe ml097e
exe.exe
"Variant of the RapidBlaster parasite (in an ""Exe"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
execfg4
execfg4.exe
ELECTRON VIRUS!
X
ExeName32
Warm.scr
SCOLD VIRUS!
U
Exif Launcher
Exiflaquickdcr.exe
USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U
Exif Launcher
QuickDCF.exe
USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U
ExitKiller
Ekiller.exe
Exit Killer - automatically closes pop-up windows in your browser
X
exp.exe
exp.exe
variant of the SMALL.ABD downloader TROJAN!
X
EXPL0RE.EXE
EXPL0RE.EXE
Troj/Popno-A TROJAN! Note: Notice that (EXPL0RE.EXE) is spelled using the number 0 instead of the letter O. This trojan is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
expler
Updadv.exe
Troj/QQPass-N TROJAN!
X
Explkw
expup.exe
Keywords hijacker
X
explore
explore.exe
W32.Hawawi WORM!
X
Explore
explore.exe
Adult content dialler
X
Explore
Explorer.exe
"IRC.FLOOD.G VIRUS! Note - this is not the valid Windows ""explorer.exe"""
X
explore manager
explore.exe
DONBOMB.A TROJAN!
X
explore.exe
Explore.exe
GRAYBIRD.G VIRUS!
X
Explorer
??
AUTEX VIRUS!
X
Explorer
config_.com
W32/Floppy-D WORM!
X
Explorer
drv.exe
Troj/Small-FD TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
EXPLORER
EXPL0RER.EXE
Troj/BeastDo-Y TROJAN!
X
explorer
expl32.exe
RATSOU VIRUS!
U
explorer
explorer.exe
Starts Windows Explorer. Unless this has been manually added to startups or another program it could be a WORM! such as PE_BISTRO or DVLDR or MYDOOM.B or Troj/Torpig-A . Note that it is also not the explorer.exe task/service you'll see when via CTRL ALT DEL
X
explorer
explorer.exe
"PWS.ZAYA TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is installed in a C:\Windows\System\Service folder. Moreover, the valid explorer.exe will only figure among the startups if you intentionally placed it there!"
X
Explorer
shellexp.exe
variant of the Backdoor.Sheldor TROJAN!
X
Explorer
shellexpl.exe
GPIX and SHELDOR VIRUSES!
X
EXPLORER
sys.exe
TROJ/SILLYFDC-A TROJAN!
X
explorer
wscript.exe
Sneaky way to start any VBS script. Many viruses use VBS files
X
Explorer Loader
explr32.exe
AGOBOT.N WORM!
X
Explorer lptt01 or Explorer ml097e
explorer.exe
"Variant of the RapidBlaster parasite (in an ""explorer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Explorer which has the same executable name"
X
EXPLORER MICROSOFT SYSTEM
explore.exe
variant of the WIN32.RBOT WORM!
X
Explorer Updater
IEXPLORE.exe
W32/Sdbot-WO worm infection
X
Explorer32
efsdfgxg.exe
TROJ/CLICKER-Y TROJAN!
X
Explorer32
Expl32.exe
HACKTACK VIRUS!
X
Explorer32
explorer6s4.exe
Downloader.Win32.Small.biq TROJAN!
X
exporet
winset.exe
TROJ/QQPASS-I TROJAN!
U
Exshow95
EXSHOW95.exe
Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
X
External Dependencies
External.exe
W32.Mytob.EC WORM!
U
ExtraDNS
ExtraDNS.exe
ExtraDNS - DNS configuration tool
N
Eye Tide Launcher
oneeyetideone.exe
Nascar wallpaper
Y
EZ Firewall
ca.exe
eTrust EZ_Armor Internet Security
N
ezagent
ezagent.exe
EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs
N
EzButton
EzButton.EXE
EZbutton is a quick launcher for the Media player app that comes with certain laptops. Typically installed in a C:\Program Files\EzButton folder
N
EZDesk
EZDESK.EXE
Utility that remembers icon locations for each user and resolution. Available here
N
EzEjMnAp
EzEjMnAp.exe
"For IBM Thinkpad Notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually"". Available via Start -> Programs"
X
eZmmod
mmod.exe
eZula TopText adware
Y
ezShieldProtector for PxorezPS_Px
ezSP_Px.exe
Engine that allows PrimoDVD from Veritas (was Prassi) and Drag\'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
Y
ezShieldProtector for PxorezPS_Px
ezSP_PxEngine.exe
Engine that allows PrimoDVD from Veritas (was Prassi) and Drag\'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
U
EZSMART App
ezsmart.exe
EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
X
ezula
eZmmod.exe
eZula TopText adware
X
eZulaMain
eZulaMain.exe
eZula TopText adware
X
eZuluMain
eZuluMain.exe
"Comes with ""KaZaA"" installation. Advertising Spyware. Not required but KaZaA won't work"
X
eZWO
wo.exe
eZula TopText adware
X
f~a
ra32.exe
BackDoor-CAY TROJAN!
U
f1Tray.exe
F1TRAY.EXE
System Tray icon for FusionOne?s MightyPhone software. MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer.
X
f607
f607.exe
URAT.B VIRUS!
X
f73cdc8ee94e
btsendto.exe
Associated with mysearchnow.com/searchbar.html
U
FamilyKeyLogger
cisvc.exe
"""Family Keylogger - is your best choice, if you want to know what other users on your machine are typing"". Note! - this is not the cisvc.exe service."
X
Fantasia injector
wincfg.exe
AGOBOT.US WORM!
X
farmmext
farmmext.exe
Transponder parasite updater/installer
X
Fash
Fash.exe
Ibis toolbar adware related
N
Fast
fast.exe
Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
N
FAST Defrag
FAST2.EXE
FastDefrag defragmenting software
X
Fast Search
svcnv.exe
"Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf"
X
Fast start
Ntut.exe
unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i
X
Fast start
svcnt.exe
unidentified adware - recognized by Kaspersky antivirus as a variant of the Win32.Favadd TROJAN!
U
FastCache
fc.exe
FastCache from AnalogX - speeds up browsing by resolving DNS requests locally
X
FastStart
ntnut32.exe
StartPage.L TROJAN!
X
FastStart
svcnut.exe
Browser hijacker - a variant of the STARTPAGE.L TROJAN!
X
FastStart
svcnut32.exe
Browser hijacker - a variant of the STARTPAGE.L TROJAN!
N
FastTrack Accelerator
SPEED UP.EXE
"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus"
N
FastUser
fast.exe
Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
U
FatPipe
DHCP
Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
U
Fatpipe Dialer
fpdialer.exe
Dialler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
U
FaxCenterServer
fm3032.exe
"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others."
U
FBDirect
FBDirect.exe
"Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs"
X
fc
runfc.exe
CAMPURF VIRUS!
U
FD_SAP
FD.exe
Reported to be the autopassword program from the Sony Microvault thumb drive.
X
Fdr Command Module
sp2.exe
SDBOT.WP WORM!
X
feelalright
mirc.exe
W32/IRCFlood-M WORM!
U
FEELitDeviceManager
feelitdm.exe
Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
X
fegoze
SVCH0ST.EXE
"GRAYBIRD.D VIRUS! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
U
Fellowes Proxy
R3proxy.exe
Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
X
Fen Startups
fensvc32.exe
W32.RANDEX.CCF WORM!
U
FerrariWallPaper
FerrariWP.exe
Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
X
ffis
ffisearch.exe
"iSearch ""Desktop Search"" hijacker"
U
FG1_00
frntgate.exe
FrontGate MX - e-mail spam blocker
X
fGQEGqHOME
gwwgtp.exe
BACKDOOR.RANKY.J TROJAN!
U
Fhtisxk
fhtisxk.exe
"XtraKeys - keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove via Spybot S&D (for example)"
U
FieldForms Sync
SyncService.exe
"Resco FieldForms . A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well."
X
FiendlyType
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
FILE
abcdefg.exe
W32.Kelvir.DD Worm!
X
file laoder configuration
rnd32.exe
RBOT.BQJ WORM!
X
File System
taskmqrs.exe
variant of the WIN32.TOXBOT/CODBOT WORM!
X
File System Service
wmiprvsc.exe
AGOBOT-HZ TROJAN!
X
File0_0
MD1.exe
Troj/Dloader-OR Trojan!
X
File1
Dia Claro.htm
Troj/Dloader-OR Trojan!
N
FileFreedom_Plugin
wtm.exe
FileFreedom peer-to-peer sharing program
X
FileManager32
??
NOTUP.A VIRUS!
X
FileSoft
??
SST.B VIRUS!
U
FilterGate
filtergate.exe
"Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items"
U
Filterguard
Filtrgrd.exe
"An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ?short-cut? to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by ?right-clicking? on the icon"
X
Find
find.exe
W32.OPANKI WORM!
X
Find Fast
Findfast.exe
Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
Y
Find Virus Launch Program
fvlaunch.exe
Part of Dr. Solomon's Antivirus
N
FinePrint Dispatcher vx
FPDISPxA.EXE
"FinePrint - virtual printer for use with any printer. Search for ""dispatcher"" here for more information. If removed, it will re-install when program is run - hence the Y recommendation"
N
FineReader7NewsReaderPro
AbbyyNewsReader.exe
ABBYY FineReader OCR software
X
FireFox Service Drivers
ssmss.exe
variant of the W32/SDBOT WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item.
X
Firewall
Firewall.bat
VBS.Ypsan.G WORM!
X
Firewall
SP2 UPDATE.exe
W32.ELITPER.E WORM!
X
Firewall
wmlaunch .exe
W32.ELIPTER.A or W32.ELIPTER.B or W32.ELIPTER.D WORM!
Y
Firewall Client Connectivity Monitor
ISATRAY.EXE
MS Internet Security and Acceleration Server - see here
X
Firewall Sp2 system
sys32Conf.exe
W32/Rbot-ABT WORM!
X
Firewall Updater
msnupdateit.exe
W32/RBOT-AAQ WORM!
X
firewall_anti
firewall_anti.exe
Trojan.Fantibag.A or Troj/Netdeny-B TROJAN!
U
FirewallStartup
Firewallstartup.exe
Innovative Solutions The user can choose whether or not to monitor installs when loaded.
X
FirewallSvr
FirewallSvr.exe
W32.NETSKY.X or W32.NETSKY.Y WORM!
X
FireWire Driver
samx.exe
BACKDOOR.SDBOT.AE WORM!
X
FireWire Service
nvscv32.exe
variant of the W32/SDBOT WORM!
X
FireWire Services
nvcsv32.exe
variant of the W32.SPYBOT WORM!
X
First Home Page
http://find.naupoint.com
Naupoint browser hijacker
X
FIX =
WinFIX1.0.vbs
VBS/Gormlez-A Worm!
Y
Fix-it
mxtask.exe
"Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required"
Y
Fix-it AV
memcheck.exe
Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
X
Fixnice
vcvw.exe
SDBOT TROJAN!
U
FjMenu
FjMenu.exe
"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable."
N
fkSysMon
fksysmon.exe
"fkWrae SysMon - system monitor - ""displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"""
X
FlaCPY
flacpy.exe
FlashEnhancer adware variant
U
FlashEnc
FlashEnc.exe
Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission. which is a pain. No need for it if you do not want these features
X
Flashget Download Manager
Flashget.exe
W32/RBOT-AGZ WORM!
N
FlashPath Status or FlashPath Monitor
SDSTAT.EXE FLSHSTAT.EXE
System Tray icon that you can\'t get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
X
FlenCPY
flencpy.exe
FlashEnhancer Adware variant
U
Flexicd
Flexicd.exe
CD player - part of the Win95 Power Toys
U
FLMK08KB
MMKEYBD.EXE
Multimedia keyboard manager. Required if you use the additional keys
U
FLMOFFICE4DMOUSE
moffice.exe
Mouse properties for Logytech Typhoon Office Mouse
X
FlnCPY
flncpy.exe
FlashEnhancer adware variant
X
FLooDNeT
FLooDeR.exe
FLOODNET VIRUS!
X
Floppy Master
??
Troj/Zonit-F TROJAN!
X
flps
flps.vbs
BYRON VIRUS!
X
flpycntl
flpycntl.exe
CRYPTER.C trojan infection
Y
FltProcess
msinet.exe
Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
X
FlyswatDesktop
flydesk.exe
Advertising spyware
U
FmctrlTray
Fmctrl.EXE
Genius SM-Live Control Panel. Enhances?audio output?through Genius sound cards (makes a big difference and?worth the 3MB Ram used)
X
fmnwebassist
fmnwebassist.exe
Adware popup generator
U
FMStart
Fmstart.exe
"GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop"
X
fmsz
fmsz.exe
FMSZ trojan
X
fnmwebassist
fnmwebassist.exe
WinPL adware
X
Folder Service
wssdtu.exe
MANIFEST VIRUS!
U
Folder View
folderview.exe
Folder_View enhances the Windows file Explorer by making all folders you need available in a single click.
N
Folding@home
WINFAH.EXE
"Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs"
N
FoneSyncSystemTray
FoneSyncSystemTray.exe
System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
X
FontFix
fontfix.exe
unidentified VIRUS!
X
FontsLoader
ldfnt32.hta
Unidentified malware
X
FONTVIEW
FONTVIEW.EXE
OPASERV.T VIRUS!
X
foobin lptt01 or foobin ml097e
adaware.exe
"Variant of the RapidBlaster parasite (in a ""foo1"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
Y
FoolProof
fpwinldr.exe
FoolProof Security PC security software from SmartStuff
Y
FoolProofSweep
??
Part of FoolProof Security PC security software from SmartStuff
N
Forbes
ForbesAlerts.exe
Forbes Business News Alerts - displays business news headlines in a little window on the screen
X
ForceShow
??
AdultLinks/QAbar parasite related
N
Forget Me Not
AGRemind.exe
Calendar reminder part of American Greetings╜ CreataCard╜
U
Fortis Secure Layer Config
cseinst.exe
Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information.
N
FotoStation Easy AutoLaunch
FotoStation Easy AutoLaunch.exe
Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
U
Foul PX
FoulPX.exe
"Foul PX, Optusnet usage stat checker"
U
FourthDay
FourthDay.exe
"The Fourth Day - ""astronomical clock and almanac for your system tray"""
X
foxdh
foxdhend.exe
PWSteal.Menghuan TROJAN!
Y
foxie firewall
firewall.exe
"Foxie Security Firewall - Part of Foxie Security, Privacy and Productivity Suite"
Y
foxie update
update.exe
"Foxie Secure Update - Part of Foxie Security, Privacy and Productivity Suite"
X
foxwudy9912
service.exe
TROJ/BANCOS-BT TROJAN!
Y
FP Loader
loadfp.exe
FoolProof Security - PC security software from SmartStuff
N
Fpx
mnmsrvc.exe
Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
X
France
svchost.exe
variant of W32.MIMAIL.C WORM! **Note this is not the valid svchost.exe as described for Win2K or WinXP
N
Fraps
fraps.exe
Fraps Real-Time Video Capture software
U
Free Download Manager
fdm.exe
"""Free Download Manager"" See here"
U
Free Ram Optimizer
fro.exe
"Free_Ram_Optimizer monitors your memory, and frees up ram if it falls below a certain minimum."
Y
Freedom
Freedom.exe
"Zero Knowledge Freedom - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more"
U
FreeMem Pro
FMEMPRO.EXE
Some users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
U
FreeMemVn2
FreeMem.exe
Some users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
X
FreeMP3download
??
MatrixDialer related
U
FreeRAM XP
FREERAM XP PRO 1.40.EXE
FreeRAM_XP is a freeware application to free and defragment your computer?s RAM
U
FreeRAM XP
FreeRAM XP Pro x.exe
"Some users swear by memory management utilities such as FreeRAM XP Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind. ""x"" indicates the version number"
U
freesurfer
fs20.exe
EMS Free Surfer mk II - pop-up stopper
U
Fresh Desktop
freshdesktop.exe
Fresh_Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals.
X
FriendlyType
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
X
FriendlyTypeName
Services.exe
NEVEG.A or NEVEG.B WORM! - Note - this is not the valid Windows Service Controller services.exe process
X
FriendlyTypeName
winlogon.exe
"NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!"
N
FriendlyWebQuick-Launch
SELFCERT.EXE
selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
U
FRISK FP-Scheduler
F-Sched.exe
Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis
U
FRITZ!webProtect
FwebProt.exe
Firewall included in FRITZ! ISP DSL software
N
Fromine WinPopup
winpopup.exe
Instant Messenger program
X
Frsk
frsk.exe
Unidentified adware downloader trojan
Y
FRW_EXE
FRW.EXE
ConSeal Signal9 firewall - now McAfee Personal firewall
Y
frxmxins
frxmxins.exe
ATI 3D Studio MAX/VIZ driver
X
FS Agent
fagent.exe
TROJ/VOLVER-B TROJAN!
Y
fsaa
fsaa.exe
F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers
F-Secure Antivirus - carry out scheduled virus scans automatically
Y
F-Secure Startup Wizard
FSSW.EXE
F-Secure antivirus
Y
F-Secure TNB
TNBUtil.exe
F-Secure antivirus
U
fsp
fsp.exe
Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents
Y
fspr
FolderShield.exe
Folder Shield - hide personal files and folders
N
FSScrCtl
FSScrCtl.exe
"Screen saver control applet used by the ""Stardust Screen Saver Toolkit"" and ""SolidWorks Screen Saver"""
U
fsserv
fserv.exe
Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
Y
F-StopW
F-StopW.exe
F-Prot anti-virus background scanner by F-Risk Software
X
FSW
FSW.exe
FreeScratchAndWin parasite
U
FSWebServer
fsws.exe
Easy_File_Sharing_Web_Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services.
X
FtkCPY
ftkcpy.exe
FlashEnhancer adware variant
U
FTMSFLT(USB)
FTMSFLTU.EXE
Fujitsu\'s Touch Panel Message Notifier
X
FTP FOR WINDOWS
ftpwin32.exe
variant of the WIN32.RBOT WORM!
X
FTPGraber
FTPGraber.exe
DLOADER-DT TROJAN!
N
FTPManager
FTPDM.ex
"Robust_FTP is a Windows-based file transfer client application that transfers files between a user?s local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (With upload transfer resume and download transfer resume) - can be started manually."
U
Ftpqueue
Ftpsched.exe
Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers
U
Fujitsu Menu
FjMnuIco.exe
"From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable."
X
fukerservice
fukerz.exe
Win32.Rbot worm variant
X
FUKLBAR
bar.exe
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
X
fvek
fvek.exe
Troj/Drivol-A TROJAN!
Y
fwenc.exe
fwenc.exe
"Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"""
X
Fwr Command Module
fwr.exe
W32/Sdbot-PP worm infection
N
fwrastrc
fwrastrc.exe
Dial-up software for Friendly Technologies/1NationOnLine free ISP
N
fwservice
fwservice
eAcceleration Stop-Sign related; not recommended; see note
X
FX
ieloader.exe
WIN32.SMALL.RR downloader TROJAN!
U
fxredir
fxredir.exe
Canon MultiPASS fax redirector
X
g.exe
g.exe
Backdoor.Graybird.Q TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X
G_Server.exe
G_Server.exe
TROJ/FEUTEL-C and Troj/Feutel-J TROJANS!
X
G00123
??
BUGBROS VIRUS!
X
G0mez =
G0mez.vbs
VBS/Gormlez-A Worm!
X
G3
GSMedia3.exe
Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
N
Gadu-Gadu
gg.exe
Polish language Instant Messaging client
N
Gadwin PrintScreen
PrintScreen.exe
"Gadwin PrintScreen - utility to capture, print or save the current window"
X
GAELICUM.EXE
GAELICUM.EXE
Troj/Penta-A TROJAN!
X
gah95on6
gah95on6.exe
ShopAtHome/SAHagent adware
U
gaim
gaim.exe
"Gaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks."
U
Gainward
TBPanel.exe
Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
U
gameutil.exe
gameutil.exe
Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
U
GammaHotKeys
setgamma.exe
Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
X
gaSrv
gaSrv.exe
"Adware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ"
X
gaSrve
gaSrve.exe
"Adware downloader, identified by Panda antivirus as Trj/Downloader.ALQ"
X
Gate Personal Firewall
Systpl.exe
RBOT.ADC WORM
X
Gate Personal Firewall
Systpl.exe
RBOT.ADC WORM
X
Gator
gator.exe
Spyware - see here for removal instructions
X
Gator eWallet
gator.exe
Gator eWallet - also see here
U
GazelDisplay
gsyno.exe
BT Digital Access USB - Gazel ISDN installation System Tray icon
U
GBTray or GoBack
GBTray.exe
"System Tray icon access to Roxio\'s (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users"
X
gcasDtServ
gcasDtServ.exe
"unidentified WORM or TROJAN. - Note - there IS in fact also a Microsoft Antispyware process bearing the same name, but it will not figure among the startup items!"
U
gcasServ
gcasServ.exe
"Microsoft, formerly Giant AntiSpyware"
X
gcasServ
realsched.exe
variant of the WIN32.TACTSLAY.A TROJAN! - NOTE - do NOT confuse with the Real Player executable as described here
N
GCS
GrabClipSave.exe
GrabClipSave screen capture tool
X
GDAX
??
BACKDOOR.RANKY.K TROJAN!
X
gdien32
gdien32.exe
Troj/Singu-P Trojan!
U
GDMgr.exe
gdmgr.exe
GuardMon is a commercial spyware program designed to monitor all forms of user activity on a computer
N
GDrive
GDriver.exe
Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
N
Gearbox
confsvr.exe
NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here
N
GEARsec
gearsec.exe
Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
X
GEDZAC
GEDZAC.exe
GEMEL VIRUS!
N
GemStRmW
GemStRmW.exe
"For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually"
U
Gene USB Monitor
USBMonit.exe
Monitors USB ports for insertion of Sandisk USB flashdrives.
X
general lptt01 or general ml097e
general.exe
"Variant of the RapidBlaster parasite (in a ""General"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Generic host proccess for windows
SVCHOSTS.EXE
W32/SPYBOT-GQ WORM!
X
Generic Host Process
SCHOST.EXE
W32/RBOT-NC WORM!
X
Generic Host Process
svchost.exe
Troj/Dloader-NX Trojan!
X
Generic Host Process for Win32 Services
bazzi.exe
W32.AHKER.E WORM!
X
Generic Host Process for Win32 Services
intspvc.exe
DINFOR.D VIRUS!
X
Generic Host Process for Win32 Services
ntspcv.exe
SDBOT.S WORM!
X
Generic Host Process for Win32 Services
winsvc.exe
W32/Sdbot-O worm infection
X
Generic Host Process for Win32 Services
winsvc32.exe
W32/SDBOT-P WORM!
X
Generic Host Process326a System Backup
scvhost326a.exe
variant of the W32/SDBOT WORM!
X
Generic Host Service
lshost.exe
RBOT.LU worm infection
X
Generic Service Process
nvsvc.exe
AGOBOT.BY WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here
X
Generic Service Process
regsvc32.exe
GAOBOT.UJ or GAOBOT.UL WORMS!
X
Generic Service Process
regsvc32.exe
W32.GAOBOT.UJ WORM!
X
Generic Service Process
serv1ces.exe
W32/Agobot-JK WORM!
X
Generic Services Process
regsvc32.exe
W32.Gaobot.SY worm
Y
Genie USB Monitor
USBmonitor.exe
Port monitor for an external USB hard drive. Required to enable access to the drive
X
Geography TX 1.0 NT
CompuSpeed.vbs
VBS/NEWLEY-A WORM!
X
Gestionnaire de disques universel
sysoobe.exe
Troj/Toader-A TROJAN! Note: This trojan file is found in the System\oobe (95/98/Me) or System32\oobe (Nt/2000/XP) folder.
N
Get Smile
getsmile.exe
Puts smilie faces in your E-mail. Run manually when required
N
GetRight Tray Icon
GETRIGHT.EXE
GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
X
GetTheMusic
??
MatrixDialer related
N
GhostStartService
GhostStartService.exe
Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard
N
GhostStartTrayApp
GhostStartTrayApp.exe
System Tray access to Norton Ghost - added from the 2003 version
X
gigabit.exe
gigabit.exe
BEAGLE.U WORM!
X
GigaByte
Cheatle.exe
SHODI.B VIRUS!
Y
Gilat SOM Enumerator
dllhost.exe
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Y
GilatFTC
ftc.exe
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
X
GinaDll
ntgina.dll
ANIG.A worm infection
U
Glass2k
Glass2k.exe
"""Glass2k is a small little program that allows Win2K/XP users to make any window transparent"""
X
GLF Network Lan Monitor
NPFMNTOR.exe
W32/RBOT-AGY WORM!
Y
Glide
Glidew32.exe
Cirque touchpad driver
X
GLSetIT32
isass.exe
variant of the OPTIX PRO series of VIRUSES!
X
GLSetIT32
msiexec16.exe
OPTIX PRO series of VIRUSES!
X
GLSetT32
smsiexec.exe
TROJ/OPTIX-D TROJAN!
X
glv
glv.exe
DLOADER-NG TROJAN!
X
GMedia2
GSM2.exe
Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
X
GMedia2
GSMedia3.exe
Malware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
Y
Gmouse
Gmouse.exe
Amouse mouse driver - required if you use non-standard Windows driver features
U
Gnetmous
gnetmous.exe
Genius NetScroll mouse driver - required if you use non-standard Windows driver features
X
GNP Generic Host Process
svchost.exe
"Troj/Zapchas-R NOTE - This file is placed in the C:\Winnt\System or C:\Windows\System folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Go!Zilla
gozilla.exe
Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
X
Go!Zilla Monster Downloads
Go.exe
Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
U
GoBack
GBMenu.exe
"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users"
U
GoBack Polling Service
GBPoll.exe
"Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users"
U
GoBack Tray Icon
GBTray.exe
System Tray icon access to GoBack (above)
X
GOG
GOG.exe
PHILIS.B VIRUS!
X
goidr
goidr.exe
Goidr adware
U
Goldensoft_MndlSvr
MndlSvr.exe
"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking"
X
Golum
services.exe
"GOLUM.A TROJAN! - Note - this services.exe file is placed in a Winnt\System32\Golum or Windows\System32\Golum subdirectory, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
golumm
services.exe
"CoolWebSearch parasite variant. Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
google
google.exe
W32/Rbot-AMW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
U
Google Desktop Search
GoogleDesktop.exe
"Google_Desktop_Search - ""a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks."""
N
Google Earth Viewer
GOOGLEMAPS.EXE
"Google_Earth ""combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips."""
X
google toolbar
ggtb32.exe
W32/AGOBOT-RR WORM!
Y
googleadbgone
googleadbgone.exe
Googleadbgone - advertising / popup blocking program
N
GoogleDCClient
GoogleDCC.exe
"Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click ""Stop Computing"""
U
googletalk
googletalk.exe
"Google_Talk ""enables you to call or send instant messages to your friends for free║anytime, anywhere in the world"". Can be launched manually."
U
GoToMyPC
g2svc.exe
ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
X
GotSmiley
GotSmiley.exe
"Gator GotSmiley - adware based, also see here"
X
gouday.exe
readme.exe
BEAGLE.C WORM!
N
GRA
gra.exe
"Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag?and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility"
X
Graphic Driver
smss32.exe
variant of the WIN32.RBOT WORM!
X
Graphic Loader
ntvdm32.exe
variant of the WIN32.RBOT WORM!
U
Gravis Appawareloader
dbserver.exe
"Looks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them"
U
Gravis Xperience Driver Support
Grxp4exe.exe
Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
N
Greetings Workshop
GWREMIND.EXE
You really want to be reminded about somebody's birthday at the expense of resources?
X
gremier
??
GPREMIER VIRUS!
X
Gremlin
intrenat.exe
DOOMJUICE VIRUS!
N
Grokster
Grokster.exe
Groster Peer-To-Peer File Sharing program
Y
GrpConv
grpconv.exe
"Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article,"
X
GsAds
gms2.exe
PacerD_Media/Pacimedia.com adware component
X
gshp
zzgshp.vbs
Homepage hi-jacker
N
Gsiconexe
Gsicon.exe
ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
N
GSOrganizer
GSOrganizer.exe
GoldenSection Organizer - personal information manager
X
gssomatic
gssomatic.exe
Searchcentrix hijacker
X
GStartup
GMT.exe
Gator spyware component - see here
X
gsv
gsv.exe
ROBAL 1.0 backdoor TROJAN!
N
Gtwatch
gtwatch.exe
Associated with a Mustec scanner and not required
N
Guardian
CMGrdian.exe
"McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic"
X
guarnset
guarnset.exe
Adlogix adware
U
GuruNet
GuruNet.exe
GuruNet lets you click on any word on your screen to get the relevant information you want.
X
GustavVED
??
OPASERV.H VIRUS!
X
gvagfxj
??
"Unidentified adware, spyware or virus"
Y
gw port controller
PORTCT95.EXE
"From a visitor - ""I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work"". From the file properties, the file is known as ""Smart Thru Fax Drive Spy"" and is supplied by Samsung"
N
GWInkMonitor
GWInkMonitor.exe
"Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!"
N
GWMDMMSG
GWMDMMSG.exe
"Used with internal modems on Gateway and vprMatrix PCs. This is the ""GTW modem messaging applet"" and is not required for the modem to work correctly"
U
GWMDMpi
GWMDMpi.exe
Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information
U
gwum
gwum.exe
"Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system ""tweakers"""
U
H/PC Connection Agent
WCESCOMM.EXE
Active sync for use with Windows CE based palm PC
X
h4te Service Drivers
h4te.exe
variant of the WIN32.RBOT WORM!
X
hachimitsu-lemon
hachimitsu-lemon.exe
HACHILEM TROJAN!
X
hagent
avp.exe
"""Herman Agent"" remote access TROJAN!"
U
HalifaxHowardCluster
skinkers.exe
Howard_the_Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
U
HaMFrontPanel
hampanel.exe
"Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless"
U
Handy Backup 3.9
hbagent.exe
Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
U
Hardware Doctor
Hwdoctor.exe
"Winbond Hardware Doctor - as included on some motherboard using Winbond\'s hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you\'re concerned about your system temperature - typically for ""overclocked"" systems"
X
Hardware Monitor Service
mshms.exe
Troj/Wollf-A TROJAN!
X
Hardware Profile
hxdef.exe
variant of the LOVGATE WORM!
U
Hardware Sensors Monitor
hmonitor.exe
"Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for ""overclocked"" systems"
U
Hare
hare.exe
Hare - improve and optimize performance of desktop/laptop PCs
U
HawkEye
HAWK_95.EXE
"Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs"
U
HawkEye IV Control Panel
HAWK_32.EXE
"Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs"
X
Hbinst
Hbinst.exe
Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
N
HC Reminder
hc.exe
"For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed"
N
HCDetect
HCDetect.exe
"MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem"
U
hcenter
tgcmd.exe
"See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
X
hclean32.exe
hclean32.exe
"TROJAN downloader/installer! - assumed to be associated with Wareout, malware masquerading as a spyware and dialer remover, see here"
U
Hcontrol
hcontrol.exe
Hotkeys on an ASUS Notebook. Only required if you use the additional keys
X
HDAudio Driver 1.0
??
Troj/Teadoor-D TROJAN!
X
HDAudio Driver 2.0
??
Troj/Teadoor-E TROJAN!
U
HDDHealth
hddhealth.exe
"HDD_Health is a ""full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure."""
U
HDDlife
HDDlife.exe
HDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks.
N
HDtray
HDtray.exe
Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
X
he3bbcff
??
LZIO.com adware downloader
X
he3e3fc4
??
LZIO.com adware downloader
X
HELLBOT TEST
1hellbot.exe
W32.MYDOOM.BO WORM!
X
hellodolly
shost.exe
YODO VIRUS!
X
helloworld
nb32ext2.exe
W32/MYDOOM.BV WORM!
X
helloworld
nb32ext3.exe
MYTOB.JT WORM!
X
Help Temp Files
netreg.exe
W32/FORBOT-EM WORM!
X
helpctl.exe
helpctl.exe
GASLIDE VIRUS!
X
HELPER
canada.exe
AsdPlug premium rate adult content dialer variant
X
Helper
eschlp.exe
BLASTER.T VIRUS!
X
HELPER
france.exe
AsdPlug premium rate adult content dialer variant
X
HELPER
greece_nm.exe
AsdPlug premium rate adult content dialer variant
X
HELPER
Netherlands.exe
AsdPlug premium rate adult content dialer variant
X
HELPER
new_zealand.exe
AsdPlug premium rate adult content dialer variant
X
HELPER
sweden.exe
AsdPlug premium rate adult content dialer variant
X
HELPER
temp532.exe
AsdPlug premium rate adult content dialer variant
X
helper.dll
??
CnsMin (Chinese_Keywords) related
X
HelpExp.exe
HelpExp.exe
Attune HelpExpress. Disable - see here
X
helpmanager
spoler.exe
RANDEX.J VIRUS!
X
helpw
helpw.exe
adware downloader
X
hErcUnes
softhost.exe
W32.GARROCH WORM!
U
Hermes Messenger
DGDRHE~1.EXE
A LAN messenger alternative to WinPopUp - Digital Dreams Software
N
Hewlett Packard Recorder
Remind32.exe
HP multifunction registration
U
Hf
Hf.exe
Hide Folders - hide your folders so only you can view them
X
HF Security
hfsecure.exe
W32/AGOBOT-TI WORM!
U
hffsrv
hffsrv.exe
"Hide_Files_&_Folders is a password-protected security utility working at the Windows kernel level allowing you to password-protect files and folders, or to hide them securely from viewing and searching."
U
hfxp
hfxp.exe
Hide Folders XP - hide your folders so only you can view them
X
hgqhp.exe
hgqhp.exe
FLUSH.F TROJAN!
N
HGTXPEI
FirstReboot.exe
Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
U
Hibernation
hib32.exe
"Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly"
X
Hid.exe
hid.exe
RATSOU.B VIRUS!
X
hiden
hiden.exe
AGENT-IW TROJAN!
U
HideOE
HideOE.exe
HideOE - allows you to 'hide' Outlook Express or minimize it to the sytem tray.
X
HideRun.exe
Hiderun.exe
BOOHOO VIRUS!
X
HideRun.exe
pro.gif
BOOHOO VIRUS!
X
HideRun.exe
svhost.exe
BOOHOO VIRUS!
U
hidserv
hidserv.exe
"This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and?PS/2 keyboards"
N
High Definition Audio Property Page Shortcut
HDAudPropShortcut.exe
"Realtek audio card related; probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required."
U
HijackThis startup scan
HijackThis.exe
"HijackThis lists the contents of key areas of the Registry and hard drive--areas that are used by both legitimate programmers and hijackers. The program is continually updated to detect and remove new hijacks. It does not target specific programs and URLs, only the methods used by hijackers to force you onto their sites. As a result, false positives are imminent, and unless you're sure about what you're doing, you always should consult with knowledgable folks before deleting anything. Required if you'd like Hijack This to run a scan at startup, and show the results when new items are found (if so, check the appropriate box in the ""Config"" section"")"
N
HistoryKill
histkill.exe
"HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs"
U
HitwarePKLite
HITWAR~1.EXE
Hitware Popup Killer Lite
X
HIV
HIV.exe
HIVA VIRUS!
U
hk
hk.exe
KeyLoggerExp keystroke logger/monitoring program - remove unless you installed it yourself!
U
hkcmd
hkcmd.exe
"Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel"
Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
U
HKSERV.EXE
HKserv.exe
Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
U
hkss
hkss.exe
Compaq HotKey Support - multimedia keyboard support
X
hlhtxo.exe
hlhtxo.exe
QLOWZONES-27 TROJAN!
X
hlinstaller1
hlinstaller1.exe
Identified by Kasperksy_Labs as Trojan.Win32.SecondThought.aa
X
HLL Data Parameter
hllcxpa.exe
RBOT.AFG WORM!
X
HMI PowerSystem
hmisvc32.exe
W32.RANDEX.CZZ WORM!
X
HML PowerSource
hmlsvc32.exe
W32/SDBOT-XL WORM!
U
Hmonitor
Hmonitor.exe
Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
X
HMV PowerSource
hmusvc32.exe
W32/Sdbot-YW Worm!
X
HOI Services
holsvc32.exe
W32/AGOBOT-SF WORM!
N
Holiday Lights
Holiday Lights.exe
Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
X
Hollaback
slvhosts.exe
SDBOT.BMO WORM!
N
Home Theater SchSvr
SchSvr.exe
"WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs"
U
HomeAlarm
HomeAlarm.exe
Chameleon Clock - system tray clock replacement
X
Homeland Network
HomelandNetwork.exe
"Homeland_Network Notifier - Pops ads, see their privacy_policy"
U
Hook99startup
hk2re.exe
"""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"""
U
HookSys
HookSys.exe
"SurfinGuard Pro - protects against all malicious code delivered through executables, scripting files, ActiveX and Java"
Y
HorngTech4D
bally4d.exe
HorngTech 4D mouse driver
X
Host
??
POPDIS VIRUS!
X
hostdll.exe
hostdll.exe
BANKER-BO TROJAN!
X
Hostren.exe
Hostren.exe
"PWS.BANKER.F, a variant of the BANKER-BO TROJAN!"
X
hostserv
hostserv.exe
RBOT.BPZ WORM!
X
hostserv
wiz98.exe
variant of the W32/SDBOT WORM!
X
HostSVC syse
HostSVC.exe
W32/RBOT-ANZ WORM!
U
Hot Corners
Hotc.exe
"Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
U
Hot Key Kbd 2690 Daemon
SK9910DM.exe
Multimedia keyboard manager - required if you use any special keys
U
Hot Key Keybd 9910 Daemon
SK9910DM.exe
Multimedia keyboard manager - required if you use any special keys
X
Hot_Kiss
Hot_Kiss.exe
Adult content dialler
X
Hot_Tarts
Hot_Tarts.exe
adult material dialer
X
Hot_Tarts_**
Hot_Tarts_**
Premium rate adult content dialer (where * is a random char)
X
Hotbar
Hbinst.exe
Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
X
Hotbar
HbOEAddOn.exe
Hotbar adware
X
Hotfix Updat
svdhost32.exe
GAOBOT.ZW WORM!
U
HotIDE
hotide.exe
HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
U
HotkeyApp
HotkeyApp.exe
Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
U
HotKeysCmds
hkcmd.exe
"Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties"
X
HotPix
hotpix.exe
Adult content dialler
X
hotplug
hotplug.exe
Trojan.Downloader.Agent.AM
X
HotSurprise
HotSurprise.exe
Premium rate adult content dialer
N
HotSync Manager
hotsync.exe
Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing.? Available via Start -> Programs
X
hotwetlove
hotwetlove.exe
Adult content dialler. Will not uninstall - components have to be manually deleted
U
HoverDesk
HoverDesk.exe
HoverDesk - desktop replacement software
U
HP AutoIndexer
hppautoindexer.exe
"Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup"
N
HP CD-DVD or HP CD Writer
hpcdtray.exe
System Tray access to a HP CD-Writer\'s functions. Available via Start -> Programs
X
hp center
BACKWEB-137903.exe
"Based upon HP's own description from here - ""With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music"" I have classified this as adware.?The number may change - if yours is different let me know"
X
hp center UI
ShadowBar.exe
User Interface for HP Center
N
HP Component Manager
hpcmpmgr.exe
"Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can\'t shutdown the computer because hpcmpmgr.exe can\'t be ended"""
X
HP Deskjet
HP_DeskJet_500.exe
W32/FORBOT-DA WORM!
U
HP Digital Imaging Monitor
hpqtra08.exe
"System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos from a camera, for example"
U
HP Display Settings
hpdisply.exe
"Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
N
HP Image Zone Fast Start
hpqthb08.exe
"Improves the startup time of HP Image Zone. If you disable it, HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time"
N
HP Info Express
??
"On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb"
U
HP Instant Support
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide"
N
HP Internet Center
SURFBRD.EXE
Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
N
HP JetDiscovery
HPJETDSC.EXE
HP JetAdmin software which monitors printing jobs on a network environment
N
HP JetSpeed Autostart
AUTOSTART.EXE
Autostart executable for the old multiplayer game HP Jetspeed
U
HP Laser Jet Director
hppdirector.exe
"System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc"
N
HP Network Registry Agent
hpnra.exe
"Hewlett-Packard Network Registry Agent background task installed by the drivers for many of HP?s printers since 2002. See here under ""hpnra.exe"""
N
HP Parallel Port Test
hppt.exe
Associated with a HP ScanJet scanner
X
HP Photo Manager
HPPhotoManager.exe
SDBOT.AXU WORM!
N
HP Precision Scan
hpmdlbwx.exe
HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
N
HP Presentation Ready
PresRdy.exe
"HP Omnibook related:? ""Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"""
U
hp psc 2000 Series
hpobnz08.exe
System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
U
HP RecordNow
??
"From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."""
U
HP ScanPatch
HPScanFix.exe
"Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting"
N
HP ScanPicture
hpsplmwa.exe
HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
U
HP SchedIndexer
hppschedindexer.exe
"Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup"
X
HP Service Drivers
hdsys.exe
W32/Sdbot-ZE Worm!
N
HP Simple Trax
Hpcron.exe
Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
N
HP software update
HPWuSchd.exe
"HP software updates. If a shortcut doesn't exist, create your own and run it manually"
N
HP software update
HPWuSchd2.exe
"HP software updates. If a shortcut doesn't exist, create your own and run it manually"
N
HP Status
hpstatus.exe
HP Printer Status and Alerts
U
HP TV Now
HpTvNow.exe
Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) - user's choice!
N
HP Updates
??
"On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb"
N
HP_dla
dlatray.exe
"On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD"
N
HP-Aio Flight
Remind32.exe
HP multifunction registration
N
HPAIO_PrintFolderMgr
hpoopm07.exe
"Directly from HP: ""This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port."" For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to ""hpodir07.exe"" works just fine if you need to use the scanner"
N
hpaiodevice
hpodev07.exe
"Direct from HP - ""Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when ""portable"" is chosen during installation)"". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to ""hpodir07.exe"" works just fine if you need to use the scanner"
N
HPAiODevice(hp psc 900 series) -1
hpobrt07.exe
"Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry"
U
HPDJ Taskbar Utility
??
(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info
N
hpfsched
hpfsched.exe
HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
U
HPGamesActiveMenu
ActiveMenu.exe
Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
N
hpgs2wnd
hpgs2wnd.exe
"""HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites.""Available via Start -> Programs"
U
Hpha1mon
Hpha1mon.exe
Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature.
U
HPHAxMON
HPHAxMON.EXE
"Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. ""x"" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards"
U
HPHmon**
??
Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn\'t inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don\'t use the reader
U
HPHmon04
hphmon04.exe
Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
U
HPHmon06
hphmon06.exe
"Related to the Hewlett Packard software HP Photosmart printer, it provides easy access to flash card reading functions. This program is not essential to the running of the system. Your choice."
X
Hphome
hphome.js
Homepage hijacker
N
HPHUPD**
hphupd**.exe
HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs
N
hphupd04
hphupd04.exe
HP Photosmart software update checker and wizard launcher. Available via Start -> Programs
N
HPHUPD06
hphupd06.exe
Belongs to the HP Photosmart application and is responsible for keeping this software upto date. This program is not essential to the running of the system
X
HPl Services
hmlsvc32.exe
W32/AGOBOT-SI or W32/Agobot-SM or W32/Agobot-SN and W32/Agobot-ATK WORMS!
Y
HpLamp
HPLAMP.EXE
HP Scanner Utility that controls your scanner?s light bulb. Needed if it's switched on. Also refer here for troubleshooting
U
hplampc
hplampc.exe
HP Scanner Lamp Utility. Fixes an issue with the scanner lamp not going off.
U
HPLaptopGamesActiveMenu
ActiveMenu.exe
Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
U
HPLogiFinder
hp_finder.exe
HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
U
HpMmKbd
HpMmKbd.exe
HP?s multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
N
hpodblia
hpodblia.exe
HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
N
hpodlb08
hpodlb08.exe
HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
Y
hpotdd01.exe
hpotdd01.exe
"hpotdd01.exe is installed alongside HP Multimedia products and is responsible for digital imaging. ""This program is a non-essential process, but should not be terminated unless suspected to be causing problems."""
Y
hpppta
HPPPTA.exe
HP parallel port driver for certain hardware
X
HpPrinter
hpserver.exe
Troj/CmjSpy-W Trojan!
N
HPPROPTY
HPPROPTY.EXE
HP LaserJet Toolbox
U
HPPWRSAV
HPPWRSAV.EXE
"Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the?instructions and you will find an updated lamp control patch"
U
HPSCANMonitor
hpsjvxd.exe
HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
N
hpsjbmgr
hpsjbmgr.exe
"HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment"
N
HPStart
hpstart.wsf
This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
X
hpsysconf1
??
VIVIA.A trojan variant
U
hpsysdrv
hpsysdrv.exe
"This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working"
N
HPU
ProvenTactics.exe
Proven Internet Marketing software
N
HPZTS04
hpzts04.exe
Hewlett Packard printer toolbox shortcut that resides in the system tray
X
HQI Services
hqisvc32.exe
W32/AGOBOT-RO WORM!
X
HQI Services
hqlsvc32.exe
W32/AGOBOT-RP WORM!
U
HR
Hr.exe
HiddenRecorder periodically takes screenshots of the computer. If you didn't install this yourself remove it.
Y
HREF.OCX
??
HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller
X
hsim
isearch.exe
Unidentified Malware
X
hsim
sexgame.exe
Unidentified Malware
X
hsim
toolbar.exe
Unidentified Malware
U
HSLAB Logger
logger.exe
HSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it.
U
Hti
npdor.exe
Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
U
HTpatch
htpatch.exe
HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
X
HtProtect
AVprotect.exe
W32.NETSKY.L WORM!
X
http://www.lienvandekelder.be
Lien Van de Kelder.exe
W32/Mytob-CP or W32/Mytob-CO or W32.Mytob.GK WORMS!
X
http://www.lienvandekelder.be
Lien Vande Kelder.exe
W32/Mytob-AQ Worm!
X
http://www.lienvandekelder.be
Lien vd Kelder.exe
W32/Mytob-M Worm!
X
http://www.lienvandekelder.be
Lien.exe
W32/Mytob-CZ Worm!
X
http://www.lienvandekelder.be
Lientjeuh.exe
W32/Mytob-P Worm!
X
http://www.lienvandekelder.be
LienVandeKelder.exe
W32/MYTOB-AZ WORM!
X
http://www.lienvandekelder.be
LienVdK.exe
W32/MYTOB-U WORM!
X
http://www.lienvandekelder.be
Van de Kelder Lien.exe
W32/Mytob-BF Worm!
X
http://www.lienvandekelder.be
We Love Lien Van de Kelder.exe
W32/Mytob-CV Worm!
X
httpd
c_pan.exe
infection by a Troj/Delf-A trojan variant!
X
httpd
deamon.exe
WIN32.TACTSLAY.C TROJAN!
X
httpd
msgaol.exe
WIN32.TACTSLAY.C TROJAN!
X
httpd
s_menu.exe
WIN32.TACTSLAY.C TROJAN!
X
https-ssl
https.exe
MOEGA.D VIRUS!
X
huigezi
HgzServer.exe
GRAYBIRD.C VIRUS!
X
Hvid
Hvid.exe
GEMA TROJAN!
X
HWINFO**
HWINFO**
PUROL VIRUS! where * is a random character
Y
HWinst
??
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
X
Hwp
system_wc.exe
Eziin adware
X
hxadsec
??
Troj/AdClick-AP TROJAN!
X
HXDL.EXE
HXDL.EXE
"Believed to be spyware - made by a company called Alset. Also known as ""HelpExpress"". Will install itself if you have previously had Attune by Aveo installed as they\'re by the same company. Uninstall via Add/Remove programs"
U
HydarVisionDesktopManager
desk95.exe
"ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this_one . HydraVision can be uninstalled through Add/Remove Programs."
U
HydarVisionViewport
viewport.exe
ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
U
HydraVisionDesktopManager
desk98.exe
ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
U
HydraVisionViewport
viewport.exe
ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
X
Hyper Start
instantmsgrs.exe
W32/RBOT-NH WORM!
X
I am not Ranky. I am eTunnel!
disney.exe
unidentified WORM or TROJAN!
X
I am not Ranky. I am eTunnel!
msyervice.exe
unidentified WORM or TROJAN!
X
I am not Ranky. I am eTunnel!
winsys.exe
unidentified WORM or TROJAN!
X
I/O Controllers
svcnet.exe
TROJ/TIBIK-B TROJAN!
X
I386
I386.exe
MYPOWER VIRUS!
U
i8kfangui
i8kfangui.exe
Graphical interface for fan speed control
U
IAAnotif
iaanotif.exe
"IAA Event Monitor User Notification Tool - part of Intel╜ Application Accelerator - ""a performance software package for desktop PCs using select Intel╜ chipsets"" that ""replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs."" If you use the RAID version it\'s required to notify you if a RAID 1 disk has failed"
Y
iamapp
iamapp.exe
"AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well"
X
Iamnacho On Irc.MusIrc.com Is a Homosexual!
XBox64.exe
RANDEX.Y VIRUS!
U
ias
ias.exe
InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
IASHLPR
IASHLPR.EXE
OPASERV.T VIRUS!
X
ibin
??
Troj/Perda-C Trojan!
X
ibm
ibm.exe
Troj/LegMir-AH Trojan!
N
ibmmessages
ibmmessages.exe
"Allows IBM to push messages onto users' computers. Quote: ""The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"""
U
Ibmpmsvc
ibmpmsvc.exe
"Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes"
U
IBMUltraBayHotSwapCPLLoader
IBMBAY2N.EXE
Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
U
IBWin Background process
IBackground.exe
IBackup for Windows
U
IBWin Monitor
IBMonitor.exe
IBackup for Windows
N
IC_KEY_3
spvic.exe
Instant Chess related
X
icasServ
icasServ.exe
"Browser hijacker, redirecting to Searchforfree.info, also detected as TROJ/ICASERV-A"
X
ICcontrol
iccontrol.exe
ICcontrol premium rate adult content dialer
X
icdd7ee6
??
LZIO.com adware downloader
X
icddefff
??
LZIO.com adware downloader
N
ICH Synth
eusexe.exe
"Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with ""SoundMAX integrated Digital Audio"" (Analog Devices Inc.) devices"
X
icifati
yujixit.exe
SDBOT.ZZH WORM!
U
iClean
iClean.exe
"IEClean - ""advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"""
N
iCn
NAG.EXE
"iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist"
N
ICO
ICO.EXE
Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
N
Icon Animation
HDE.EXE
Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
N
Icon Hearit 95
hearit95.exe
Audio desktop customization utility from Moon Valley Software. Resource hog
N
Icon Hearit 98
hearit98.exe
Audio desktop customization utility from Moon Valley Software. Resource hog
X
Icon lptt01 or Icon ml097e
icon.exe
"Variant of the RapidBlaster parasite (in an ""Icon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
Y
ICONCLNT
iconclnt.exe
APC PowerChute Tray Icon. Associated with the UPS listing
U
ICONDESK
ICONDESK.EXE
Small utility which will allow you the option of hiding or showing your desktop icons
N
Iconfig.exe
Iconfig.exe
"Icon for LS-120 ""Superdisk"""
X
iConfigLoader
DIIhost.exe
GAOBOT.AO WORM!
N
Iconoid
Iconoid.exe
Iconoid is a desktop icon manager
N
Iconsaver
Iconsaver.exe
IconSaver is a desktop icon manager
X
ICQ =
ICQNET.vbs
VBS/Gormlez-A Worm!
X
ICQ Center
consoles.exe
RANDIN VIRUS!
X
ICQ Chat Service
icqjdhs.exe
variant of the WIN32.RBOT WORM!
X
ICQ Hacking Pro
ICQpro.exe
version of the NETSPY VIRUS!
N
ICQ Lite
ICQLite.exe
ICQ Lite - compact version of the popular messaging program
X
ICQ Lite Messenger
??
"Unidentified worm or trojan. Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory."
X
ICQ Messenger 2002
ICQ2002.exe
W32/Sdbot-AB WORM!
X
ICQ Net
winlogon.exe
W32.NETSKY.C or W32.NETSKY.D or W32.NETSKY.E or W32.NETSKY.K WORM! **Note - this is NOT the legitimate Windows winlogon.exe process
X
ICQ Net
winlogon.exe
"Win32.Netsky.D WORM! - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!"
N
ICQ Plus
vplus.exe
ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
X
IcqBeta
webcamupdate.exe
unidentified TROJAN!
X
ICQNet
winlogon.exe
"W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
U
ICSDCLT
??
Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
N
ICServer
Icserver.exe
Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
Y
ICSMGR
ICSMGR.EXE
Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you?re sharing the internet on various computers
N
ID Commander
IDCom.exe
Caller ID utility for identifying incoming telephone numbers
X
ID8525
ID8525.exe
ID8525 VIRUS and homepage hijacker!
X
ID8525
id85255.exe
ID8525 VIRUS and homepage hijacker!
X
IDE
ide.exe
ASSASIN.F VIRUS!
X
IDE Loader
IDElibr32.exe
"XILON VIRUS!. Related to the game ""Diablo II"""
X
idecntl
idecntl.exe
Crypter.C trojan variant infection
U
iDesktop
idesktop.exe
Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
N
IDMan
IDMan.exe
"Internet Download Manager - download files faster, schedule and resume"
N
IDW Logging Tool
idwlog.exe
Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
X
IE configure
explorer.exe
Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the Windows or Winnt folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
U
IE Doctor
IEDoctor.exe
"IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"""
"IE New Window Maximizer, see here - automatically maximize new Internet Explorer and Outlook Express windows."
X
IE Runtime
wini.exe
W32.Picrate.B WORM!
X
IE Runtime
wini.exe
W32/RBOT-ABK and W32/Rbot-ADM WORMS!
X
IE Runtimes
winis.exe
W32/Rbot-ADZ Trojan!
X
IE**.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
IE**32.exe (* = random char)
??
"CoolWebSearch/HomeSearch adware component - for examples, see this log"
X
IE6
ssmss.exe
W32.Gaobot.DXO WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item.
Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
U
IECleanAux
Ieboot6.exe
"IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup"
X
iedll
iedll.exe
"Homepage hijacker, redirecting to coolwwwsearch.com"
X
IEDriver
IEDriver.exe
Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
X
IEDriver
TD.exe
IEDriver adware variant
X
IEDriver
xplore.exe
IEDriver adware variant
X
IEengine
IEeng.exe
TROJ_STARTPAG.AI hijacker
X
ieexec.exe
ieexec.exe
TROJ/MULTIDR-DY TROJAN!
X
IEFeatures
??
POPMON.A VIRUS! - also known as PopMonster adware
X
IefxTray
IefxTray.exe
RILER-H TROJAN!
X
ieharv.exe
ieharv.exe
Troj/Banker-HH TROJAN!
X
Iehelper
syslaunch.exe
Outwar adware downloader
X
iel2cde8
??
LZIO.com adware downloader
X
ielcaabe
??
LZIO.com adware downloader
X
IELoader32
iexplore32.exe
W32.Spex or W32.Spex.B WORM!
X
Iesar
Iesar.exe
Browser hijacker - redirecting to an adult web page
X
Iesearch.exe
Iesearch.exe
LookNSearch adware
X
IEService.exe
IEService.exe
FastFind parasite variant
X
iestart
iexp1orer.exe
NEMOG.C VIRUS!
N
ietsr
ietsr.exe
"IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc"
X
ieupdate
MCP****.exe
ASOXY VIRUS! where **** are random characters
X
ieupdate
mcpdll32.exe
Adware downloader trojan
X
IEXPL0RER
IEXPL0RER.EXE
W32/AGOBOT-QL WORM!
X
iexpl0res
iexpl0res.exe
"RBOT.AEX WORM! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot"
X
Iexploit
Iexploit.html
VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder.
X
Iexplore
iexplore.exe
BOXER VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder
X
IEXPLORE
iexplore.exe
"APHEXDOOR VIRUS! Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) wheras the valid ""iexplore.exe"" (IE) resides in C:\Program Files"
X
Iexplore Services
iexplore.exe
unidentified VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder
X
IExplorer
Iexplor32.exe
TROJ/BDOOR-BY TROJAN!
X
IExplorer
IExplorer.EXE
BANCOS-CH and Troj/Bancos-CW TROJANS!
X
iexplorer lptt01 or iexplorer ml097e
iexplorer.exe
"Variant of the RapidBlaster parasite (in an ""iexplorer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)"
X
Iexplorer.exe
Iexplorer.exe
TROJ/BANCBAN-EN TROJAN!
X
IExplorer32 Java Scripting
IExplore32b.exe
RBOT.ABO WORM!
X
IExplorer32c Java Scripting
IExplore32cb.exe
RBOT.ABN WORM!
X
IExplorer6 Java Scripting
IExplore326.exe
variant of the W32/SDBOT WORM!
X
IExplorer7 Java Scripting
IExplore327.exe
variant of the W32/SDBOT WORM!
U
IFSplash.exe
IFSplash.exe
I-FORCE driver for force feedback steering wheel
X
igamatu
atecaca.exe
IRCBOT.R WORM!
N
igfxtray
igfxtray.exe
"Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel"
X
igsex2x
igsex2x.exe
NewDial premium rate adult content dialler
X
iilc
IILC.EXE
Homepage hijacker
X
Iinl
iptl.exe
PurityScan/Clickspring adware
X
iisvers
iisvers.exe
unidentified TROJAN or adware
N
iIWiper
Systemwiper.exe
System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
Y
IJ75P2PSERVER
IJ75P2PS.EXE
Printer utility which is required in order to make the printer work correctly
Y
IKE Service 95
IKEService.exe
"Associated with PGP. The PGP Tray can bedisabled, but without IKESERVICE you won\'t be able to de- or encrypt anything"
U
iKeyWorks
IKEYMAIN.EXE
A4Tech wireless keyboard driver and utility
X
iLLeGaL or iLLeGaL.exe
Mplayer.exe
HOLAR.C (or GALIL@MM) VIRUS! Note - this should not be comfused with Windows Media Player which has the same filename
U
iLyric
iLyric.exe
iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
N
iM Start Center
iM_Tray.exe
Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
X
Image
??
CoolWebSearch parasite related
Y
Image & Restore
IMAGE32.exe
"Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run"
N
Image Transfer
SonyTray.exe
Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually.
U
Imagefox
imagefox.exe
"ImageFox 2.0 is an ""add-on"" graphics previewer for most Windows Open/Save As dialog boxes"
X
Imagemgt32
Imagemgt32.exe
GEMA TROJAN!
X
ImagePath
taskbarmngr.exe
W32/SDBOT-XB WORM!
X
IMClass
Svhosl.exe
unidentified WORM od TROJAN!
N
imekrig
imekrig.exe
"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)"
N
IMEKRMIG6.1
IMEKRMIG.EXE
"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)"
N
Imesh
??
Imesh is a file sharing system
N
Imesh Auto Update
??
"Update check for the Imesh, http://www.imesh.com file sharing system. Turn the update off under ""options"""
U
ImgIcon
ImgIcon.exe
"Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running"
X
imgit
??
BANKER-EM TROJAN!
N
ImgStart
ImgStart.exe
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
N
imjpmig or Imjpmig8.1
IMJPMIG.EXE
"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)"
U
IMOL
IMOLApp.exe
IncrediMail for Office Outlook_Add-On
N
Imonitor
Plguni.exe
McAfee QuickClean 3.0 - removes internet clutter and unwanted programs
U
IMONTRAY
imontray.exe
"System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you ""overclock"" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards"
U
IMStart
IMStart.exe
InterMute security software related
X
IMwire
imwireup.exe
SafeSurfing parasite variant
Y
InCD
incd.exe
"Ahead_InCD packet writing software. Similar to DirectCD. - For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. - For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows."
N
IncMail
IncMail.exe
"""IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"""
N
InControl Desktop Manager
DMHKEY.EXE
For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
N
Incredimail
IncMail.exe
"""IncrediMail"" is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"""
N
Incredimail
incredimail.exe
"""IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"""
X
Index Service
dllhost32.exe
AGOBOT.CH WORM!
U
Index Washer
WashIdx.exe
"Windows_Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG"
X
Indexindicator
Indexindicator.exe /check
Lazar TROJAN!
N
IndexSearch
IndexSearch.exe
Associated with PaperPort scanner software from ScanSoft
X
ine
svchosts.exe
WIN32.RBOT.BNL WORM!
X
Inet DataBase
Inetdbs.exe
W32.QEDS WORM!
X
Inet Delivery
inetdl.exe
Inet_Delivery adware
X
Inet Delivery
inetdl_2.exe
Inet_Delivery adware
X
Inetapi
Netapi.exe
NETDEVIL.14 (NetDevil 1.4) VIRUS!
U
inetcntrl
inetcntrl.exe
Bsafe Online - internet filter
U
Inetd
INETD32.EXE
"Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
U
inetinfo.exe
inetinfo.exe
"Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code ( more)"
X
inetinfomon manager
inetinfomon.exe
DONBOMB.A TROJAN!
X
inetmgr
inetmgr.exe
Actual Names (AdvSearch) Internet Keywords parasite
X
InetMSN
msnet.exe
variant of the SDBOT WORM!
X
InetServices
wsock32.exe
Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN!
U
Info Select
is.exe
Info Select from Micro Logic - personal information manager
X
Info32x
Info32x.exe
GEMA TROJAN!
U
InfoPenMSN
InfoPenIM.exe
InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand
U
Infra-red Monitor
IRMON.EXE
System Tray access to infra-red devices. Not required unless you use infra-red devices
X
infus
infus.exe
Adult content dialler
U
Infuzer
Infuzer.exe
"Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"""
X
infwin
infwin.exe
Msview parasite variant
X
Init32
Init32.exe
W32.WINEX.A TROJAN!
X
Initial Page
install.exe
"""EasySearch"" browser hijack installer"
Y
Initialize8x8
8x8_init.exe
Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
X
injob
injobs.exe
Trojan.Binjo TROJAN!
N
Ink Monitor
InkMonitor.exe
Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
N
InkWatch
InkWatch.exe
Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Y
InoRPC
InoRpc.exe
Associated with eTrust Antivirus/InoculateIT
Y
InoRT
InoRT9x.exe
Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here
U
InoTask
InoTask.exe
Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here
X
InstaFinderK
InstaFinderK_inst.exe
InstaFinder adware
N
InstallAurealDemos
InstallAurealDemos.js
Used to initialize the Aureal A3D demos InstallShield wizard
U
InstallBuddy
Ibtna.exe
"InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync"
X
Installed shell32.dll
Office.exe...
variant of the LOVGATE WORM!
X
Installer
dial.exe
Malware - detected by Kaspersky antivirus as trojan-dropper.win32.agent.mm
"From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG.? PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner"
U
Instant Wireless Configuration Utility
WPC11Cfg.exe
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
U
Instant Wireless Configuration Utility
WUSB11cfg.exe
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
N
InstantAccess
INSTAN~1.EXE
From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
U
InstantDrive
InstantDrive.exe
Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer?s hard drive. Part of InstantCD/DVD burning software
X
InstantPleasure
instantpleasure.exe
Adult content dialler
X
InstantPleasureXXX
instantpleasurexxx.exe
Adult content dialler
N
InstantTray
PCLETray.exe
Pinnacle_InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually..
X
instit
instit.bat
OPASERV.H VIRUS!
X
instit
INSTIT.BAT
OPASERV.K VIRUS!
X
intdctrr
idctup20.exe
SafeSurfing parasite variant
U
Intel Active Monitor
imontray.exe
"System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you ""overclock"" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards"
U
Intel File Transfer
xfr.exe
Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
U
Intel PDS
pds.exe
Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
U
Intel Product Number Utility
IntelProcNumUtility.exe
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
N
Intel PROSet Tray Icon
promon.exe
System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
X
Intel system tool
hookdump.exe
Topantispyware adware - also detected as the SPYRE-H TROJAN!
X
Intel system tool
winnook.exe
Troj/Spyre-C Trojan! A.K.A WIN32.TOPANTISPYWARE.L
X
Intel system works
iis.exe
RBOT.QGA WORM!
N
Intel╜ Common User Interface
igfxtray.exe
"Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel"
X
intel32.exe
intel32.exe
SmitFraud alias FakeAle or SPYJACK-B TROJAN!
X
InteliSys
smss.exe
"Advertisingvision adware - file is located in C:\Windows or C:\Winnt, and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file which would normally NOT figure in Msconfig/Startup!"
X
intell32.exe
intell32.exe
SmitFraud alias Desktophijack.C TROJAN!
U
IntelliPoint
point32.exe
Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
U
Intellitype
type32.exe
"For MS programmable keyboards. If you disable Intellitype in Startup, any ""Hot Keys"" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them"
U
IntelMem
IntelMem.exe
"Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line"
U
IntelProcNumUtility
cpunumber.exe
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
Y
IntelWireless
ifrmewrk.exe
Associated with the Intel PRO/Set Wireless software.
Y
InterCheck Monitor
Icmon.exe
Part of Sophos ant-virus sofware
X
Interdll
Interdll.exe
DELF family of VIRUSES!
X
Internal
??
SMOTHER & TRANSLAT VIRUSES!
X
Internal
??
FORTNIGHT.D VIRUS!
X
InternalSystray
Kazza.exe
"OPTIXPRO.12.C VIRUS! Note - unlike the valid KaZaA executable, this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP)"
X
internat
internat.exe
TROJ/LYDRA-F TROJAN!
X
internat
internat.exe
Troj/Lydra-B Trojan!
X
Internat
msgsrv32.exe
TROJ/NYRUBOT-A WORM!
X
Internat
systray.exe
"IRC.ALADINZ.P TROJAN! ** Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
X
Internat Conf
bootconf.exe
"Homepage hijacker, redirecting to coolwwwsearch.com; see for example here"
N
internat.exe
internat.exe
Language selection icon in system tray
X
Internat.exe
internat.exe
"NETSNAKE VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a ""?"" icon wheras this version resides in %windir% and has a ZIP icon"
X
Internat32
internat32.exe
Octa-B trojan infection
X
internct
WinSocks5.exe
GRAYBIRD.F VIRUS!
X
Internet
Internet.exe
Troj/PWS-CS TROJAN!
X
Internet
recruit.exe
W32/Rbot-AJG WORM!
X
internet
smss.exe
Troj/Mifeng-K TROJAN!
U
Internet Answering Machine
IAM.exe
From Callwave It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
U
Internet Answering Machine
IAMNET~1.EXE
From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
X
Internet Config
svchosts.exe
SDBOT WORM!
X
Internet Connection Wizard
??
Troj/SmutSrch-A Trojan!
X
Internet Connection Wizard
stisvsq.exe
EasySearch adware
X
Internet Content Publisher
ICP.EXE
W32/RBOT-UD WORM!
U
Internet Download Accelerator
ida.exe
Internet_Download_Accelerator download manager
X
Internet Exploere Services
urlmon32.dll.exe
EVIAN.C VIRUS!
X
Internet Explorer
http.exe
"Added as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed."
X
Internet Explorer
IEXPLORE.EXE
Rbot-EY worm infection
X
Internet Explorer
iexplorer.exe
"LORSIS VIRUS! Note - the valid Internet Explorer would not normally run at startup unless added manually by the user and would not run from the registry ""RunServices"" key as this does"
X
Internet Explorer
IExplorer.exe
Troj/Nethief-O Trojan!
X
Internet Explorer Security
iexplore.pif
W32/Rbot-ALQ WORM!
X
Internet Explorer Updater
iexplorer.exe
REUR.B VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
X
Internet Explorer Updater
lexbac.exe
DOWNLOAD VIRUS!
U
Internet History Eraser
HERASER.exe
Internet History Eraser - deletes your browsing tracks
X
Internet Loader1
MSInstall61.exe
KWBOT.B VIRUS!
X
Internet Mail and News
??
Troj/SmutSrch-A Trojan!
X
Internet Mail and News
msqdevl.exe
EasySearch adware
X
Internet Optimizer
optimize.exe
Internet_Optimizer parasite
X
Internet Protocol Configuration Loader
ipcl32.exe
SDBOT TROJAN!
X
Internet Send
More log.exe
Unidentfied adware
X
Internet Service
intersvc.exe
W32/SPYBOT-DE WORM!
X
internet service
ssvhost.exe
variant of the WIN32.RBOT WORM!
X
internet service
syscfg32.exe
W32/RBOT-QS WORM!
X
Internet Services
internet.exe
W32.MYTOB.BT WORM!
X
Internet Services
interserv.exe
RBOT.BNT WORM!
X
Internet Services
systemdev.exe
W32/Sdbot-PW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
INTERNET SERVISES
winz32.exe
KWBOT.Z VIRUS!
Y
Internet Sharing Server
iss_srvr.exe
Intel AnyPoint internet sharing software
X
Internet Suspention
story.exe
WOOTBOT.HV WORM!
N
Internet Sweeper
Sweeper.exe
Internet Sweeper - removes unnecessart left over files after browsing the internet
U
Internet Timer
ITIMER.exe
Shareware dial-up connection call cost calculator from Ratsoft
X
Internet.exe
Internet.exe
MAGICCALL VIRUS!
X
internet.exe
yinyin3345.vbs
XM97/YINI-A macro VIRUS!
X
INTERNET_SERVISES
winz32.exe
SDBOT.Q WORM!
X
Internet2 Optimizer
wkfix.exe
variant of the WIN32.RBOT WORM!
X
InternetWasherPro or Internet Washer Pro
iw.exe
"Internet Washer manages temporary browser files, cookies, etc - a \'trial\' Internet Washer Pro seems to have been widely stealth-installed around March 2003"
U
InternodeUsage
mum.exe
Australian ISP's free monthly download meter
X
Internt
Internt.exe
PEEPER or CARUFAX.A VIRUSES!
X
Intersoft Msngr
intersoftmsngr.exe
W32/AGOBOT-NW WORM!
N
InterTrust Quick Start
it_cpq~1.exe
InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business
X
InterU
WINDRV.EXE
IRCINTER.A VIRUS!
N
Intervideo WinCinema Manager
WinCinemaMgr.exe
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
N
Intervideo WinScheduler
WinScheduler.exeSchSvr.exe
"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs"
U
InterWARN
interwarn.exe
"InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs"
X
Intespention
IEXPLORE.exe
W32/Forbot-FL WORM! Note: This is not the legitimate Windows Process IExplore.exe (Which is found in the Internet Explorer folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item unless you put it there. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Intmgr
Intmgr.exe
GEMA TROJAN!
X
Intrenat
Intrenat.exe
LEMIR.E VIRUS!
N
Introducing Media Manager
SPLASHA.EXE
MS Media Manager tour. Not required
N
Introduction-Registration
??
"For Compaq PC's. Should only run first time, PC Introduction & Compaq registration"
X
IntruderAlert
ia99.exe
Intruder Alert '99 from Bonzi - spyware
X
Ioadqm
Media Player.exe
HAWAWI VIRUS!
U
iolo Task Agent
Task_Agent.exe
iOlo System Mechanic Task Agent. Scheduled maintenance
N
iolo Utility Bar
SMUtilityBar.exe
"Iolo ""System Mechanic"" Utility_Bar - can be launched manually."
U
Iomega Automatic Backup or Iomega Automatic B
ibackup.exe
Iomega Automatic Backup - automatic backups for use with Iomega portable HDD?
N
Iomega Backup Scheduler
dtiom98.exe
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
U
Iomega Disk Icons or Iomega Drive Icons
IMGICON.EXE
"Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running"
U
Iomega ImIconXP
imiconxp.exe
"Iomega REV_System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks."
N
Iomega Startup Options
IMGSTART.EXE
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
N
Iomega Watch
IOWATCH.EXE
Used by Iomega drives. Available via Start -> Programs
N
IomegaWare
COMMANDER.EXE
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
U
Iomon98.exe
Iomon98.exe
PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
X
IP Stack
ipstack.exe
AGOBOT.CW WORM!
N
iPalm
mon.exe
Installed with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded
X
IPC Connection
ipcconn.exe
W32/Rbot-AEG Worm!
X
IPC Spool Manager
winspec.exe
W32/SDBOT-BLU WORM!
X
IPC Spool Manager
wnmgre.exe
W32/SDBOT-ZC WORM!
X
ipcfg.exe
ipcfg.exe
Adware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan
X
IPConfig
svcxnv32.exe
HACARMY.E TROJAN!
X
IPConfig
svcxnw32.exe
variant of the HACARMY.E TROJAN!
X
IpCtrl
ipcon32.exe
unidentified WORM or TROJAN!
X
IPInSightLAN 01
ipclient.exe
"Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly ""phones home"" and wastes resource - hence the ""X"" status"
N
IPInSightMonitor 01
ipmon32.exe
Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information
Y
IPinst
??
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
X
ipmon.exe
ipmon.exe
RECERV or R3C.B VIRUSES!
X
Ipnuker
Ipnuker.vbs
VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder.
X
iPOD USB Driver
IPODUSB.EXE
variant of the WIN32.RBOT WORM!
X
iPod USB Service
iPODService.exe
"variant of the WIN32.RBOT WORM! - Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program Files\iPod\bin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup!"
U
iPodManager
iPodManager.exe
"Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods"
X
IPOT Service Drivers
compaq.exe
variant of the FUROOTKIT TROJAN!
X
IPOT USB Service DRIVER
hpsebc087.exe
W32/SDBOT-WA WORM!
X
IPOT USB Service DRV32
hpsebc08.exe
W32/SDBOT-WH WORM!
N
iPrint Tray
iprntctl.exe
Novell╜ iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net.
U
iProtectYou
ip.exe
iProtectYou - internet filtering/parental control and network monitoring software
The Cisco VPN_Client lets local users gain Administrator privileges on the operating system
U
ipsecdialer
ipsecdialer.exe
The Cisco VPN_Client lets local users gain Administrator privileges on the operating system
Y
IPSecMon
IPSecMon.exe
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
X
IPTable Configuration
Winipcfgs.exe
variant of the WIN32.RBOT WORM!
X
IPv6 Helper Driver
csass.exe
AGOBOT.TC WORM!
X
IPv6 STUN Service
netstun.exe
variant of the W32/SDBOT WORM!
X
ipwf
ipwf.exe
Trojan.Schoeberl TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
ir_ftp
ir_ftp.exe
IRFTP VIRUS!
X
ir_ftp
irwftp.exe
BANCOS.H VIRUS!
X
irc session
sessionmgr.exe
W32/SDBOT-ACE WORM!
Y
IREIKE
IreIKE.exe
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
N
iRis Active Monitor
winmon32.exe
"Iris Antivirus - discontinued, replace with good alternative"
N
iRiS AntiVirus Active Monitor
WIMMUN32.exe
"Iris Antivirus - discontinued, replace with good alternative"
U
iRiver AutoDB
MLService.exe
Associated with the iRiver Music Manager
N
iRiver Updater
Updater.exe
Updates for the iRiver Music Manager - used with their digital music players
U
IrMon
IRMON.EXE
System Tray access to infra-red devices. Not required unless you use infra-red devices
X
Irwftp
??
BANCOS.CR trojan infection
X
irwftp
ftpmon.exe
TROJ/BANCBAN-BO TROJAN!
X
irwftp
iexplorer.exe
TROJ/BANKER-AN TROJAN!
U
IrXfer
IrXfer.exe
Microsoft Infrared Transfer application
N
IS CfgWiz
cfgwiz.exe
Norton Internet Security configuration wizard
X
Isass
Isass.exe
BACKDOOR.FUTRO TROJAN!
N
isdbdc
isdbdc.exe
For Compaq PC's. May install properties in dial-up networking when you register with an ISP
U
isDeleteMe
isDel.bat
Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product.
N
ISDN Monitor
Linksts.exe
"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon"
U
ISDNwatch
IWatch.exe
"FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
U
ISHelp
help.exe
ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it.
N
ISLP2STA
ISLP2STA.EXE
Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though
Y
islp2sta
islp2sta.exe
A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers.
U
iSpyNOW
ispynow.exe
iSpyNOW - remote monitoring and surveillance software
X
Israfel
Israfel.vbs
GAGGLE.D VIRUS!
X
issEnc32Svr
issEnc32.exe
variant of the WIN32.RBOT WORM!
U
ISStart
ISStart.exe
"LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation"
Y
ISSVC
ISSVC.exe
Part of Norton Internet Security Suite
X
IST Service
istsvc.exe
ISTBar foistware
X
ist service uninstall
HIDES.EXE
ISTBar parasite related
X
ist service uninstall
mstasks2.exe
ISTBar parasite related
X
ist service uninstall
wow.exe
ISTBar parasite related
X
istinstall_zazzer.exe
istinstall_zazzer.exe
Unidentified adware downloader/installer
N
ISUSPM Startup
ISUSPM.exe
InstallShield Update Service related; Automatically searches for and performs any updates to the software. Not required.
N
ISUSScheduler
issch.exe
InstallShield Update Service Scheduler; automatically searches for and performs any updates to the software so you?re always working with the most current version. Not required.
"In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it"
U
iTouch
iTouch.exe
"iTouch loads the iTouch configuration program for Logitech keyboards. It?s needed if your keyboard has shortcut buttons and if you use them. It?s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock"
N
ItsDeductiblePopUp
ItsDeductible.exe
ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
X
Itunes
dials.exe
Detected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus. Note: A Url is not available at this time.
X
ITUNES
itune.exe
W32/RBOT-ZU WORM!
X
ITUNES
itunes.exe
W32/OSCABOT-L WORM!
Y
iTunesHelper
iTunesHelper.exe
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
N
Iusage
netdet.exe
Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up
N
IVPServiceMgr
ivpsvmgr.exe
"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba?s equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates. Not required."
U
IW ControlCenter
iwctrl.exe
"Pinnacle_Systems InstantWrite - enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM."
U
iwctrl
iwctrl.exe
"Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis"
X
I-Worm.GiGu
uGiG.eXe
GINK VIRUS!
X
ixplore
ixplore.exe
"unidentified WORM or TROJAN! - NOTE: although this file is placed in the Internet Explorer folder in Program Files, it is most certainly malware, and not to be confused with the legitimate IE executable, which is spelled iExplore.exe!"
X
iyelejiv
yujixit.exe
SDBOT.BJK WORM!
N
j2 Tray Menu
HotTray.exe
eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
X
JA Cfg Util v2
jacfg2.exe
W32/RBOT-AL WORM!
U
Jammer
jammer.exe
"Jammer by Agnitum - ""Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"""
X
Jammer2nd
JAMMER2ND.EXE
W32.NETSKY.Z WORM!
X
Jammer2nd
Jammer2nd.exe
W32.Netsky.Z WORM!
X
Java applet
javaup.exe
W32/Sdbot-ACF WORM!
X
Java Runtimes
iexplore.exe
KILLAV.B VIRUS! Note - this is not the valid IE (iexplore.exe) file as it's located in C:\Winnt\Java\Java rather than C:\Program Files\Internet Explorer
X
Java Virtual Machine
javaw.exe
variant of the WIN32.RBOT WORM!
X
JavaScript Debugging Service
JsDbgMan.exe
W32.Derdero.E WORM!
X
JavaUpdate0.07
??
BACKDOOR.JUPDATE TROJAN!
X
JavaUpdateSched
jusched32.exe
Troj/Bckdr-CKB TROJAN!
X
JavaVM
java.exe
"W32.MYDOOM.M or W32.MYDOOM.N or W32.MYDOOM.BB WORM! **Note - This is not the valid Windows ""java.exe"" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt"
X
jawa32
jawa32.exe
Backdoor.Agent.bg trojan
X
Jawa322
jawa32.exe
variant of the Backdoor.Agent.bg trojan
N
JB
Jiffybar.exe
"""Get Paid As You surf"" application"
N
Jet Detection
ADGJDet.exe
Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Y
JetAdmin Discovery Indicator
HPJETDSC.EXE
"HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator"
X
jete
yujixit.exe
SDBOT.BRT WORM!
X
jijbl
ezlwy.bat
REDDW VIRUS!
U
JobHisInit
JobHisInit.exe
Used by Ricoh network printers to enable network printing from the client
U
Job-oversigt
taskmon.exe
"Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)"
U
JogServ2 or Jog Serve
JogServ2.exe
"""Jog Dial"" on a Sony Vaio laptop.? The dial can select various functions such as control audio. Needed if you use its features"
X
Jreg
Jreg2b.exe
BroadcastPC adware variant
X
Jufualt
winxp2.exe
W32/SDBOT-AAB WORM!
N
jusched
jusched.exe
Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
X
jushed32.exe
jushed32.exe
CoolWebSearch parasite related
X
jutsu
jutsu.exe
W32/RBOT-LS WORM!
U
jv16 PT TempFileTool
TempTool.exe
jv16 PowerTools' temporary file remover
U
jv16PT - Privacy Protector
Task.jvb
jv16 PowerTools 2005 - Privacy_Protector allows you to protect your privacy by clearing the unwanted history items and cookies from you computer every time you startup your computer.
U
Jv16pt Network Resident
jv16pt_network.exe
jv16 PowerTools' network resident program. Only needed if you are using the program's network features
X
jvdnlssn
fljzsshc.exe
Flingstone.com adware - and its Golden Palace Casino program
X
JVM0.12
??
TEADOOR-A TROJAN!
X
JVM0.14
??
TROJ/TEADOOR-B TROJAN!
X
jxef1104
jxef1104.exe
W32/XIPI-A WORM!
X
K2ps_full.task
K2ps_full.exe
JUNTADOR.K VIRUS!
N
K6CPU.EXE
K6CPU.EXE
Authenticates CPU as K6 in system properties
X
Kadoc
??
Staprew TROJAN!
X
Kadoc
??
Staprew TROJAN!
X
kak
kak.hta
KAKWORM VIRUS!
U
Kalibump
Kalibump.exe
Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
X
kalvsys
??
EliteBar/SearchMiracle adware
N
Kana Reminder
Reminder.exe
Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time
U
Karen's Once-A-Day II
PTOAD.exe
"Karen's_Once-A-Day_II is a scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time Windows starts each day, or the first time a particular user logs on each day."
U
KASP
OESpamTest.exe
Kaspersky_Anti-Spam
X
Kasper Antivirus
KASPERANTIVIRUS.EXE
SPYBOTER.GEN TROJAN!
X
Kasper Antivirus
KASPERANTIVIRUS.EXE
variant of the W32.SPYBOT WORM!
Y
Kaspersky Anti-Hacker
KAVPF.exe
Kaspersky Anti-Hacker firewall
X
Kaspersky Antivirus
KasperskyAV.exe
variant of the WIN32.RBOT WORM!
X
KasperskyAv
kaspersky.exe
W32.MIMAIL.T WORM! **Note - This has nothing to do with Kaspersky AntiVirus
X
KasperskyAVEng
Kasperskyaveng.exe
W32.NETSKY.V WORM!
Y
kav50
kav.exe
Part of Kaspersky Anti-Virus program
X
KAVFOX
win1ogoin.exe
Troj/GWGhost-M TROJAN!
X
KAVPersonal
svchost.exe
"Troj/Lineage-V TROJAN! Note:This is NOT the legitimate Windows svchost.exe process, which should NOT figure in Startup!"
Y
KAVPersonal50
Kav.exe
Kaspersky Anti-Virus Personal 5.0
Y
KavPFW
KavPFW.exe
KingSoft Personal Firewall
X
KavRuns
Windll.exe
TRYNOMA VIRUS!
Y
KavStart
KAVStart.exe
KingSoft Personal Firewall
X
KavSvc
??
QOOLOGIC TROJAN!
X
kavsvc
??
"QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe)"
Y
kavsvc
kavsvc.exe
Kaspersky antivirus
X
KAVutil
??
WINTOO.B VIRUS!
N
KAZAA
kazaa.exe
"KAZAA is a file-sharing program which unfortunately being ad-based includes ""Cy-door"" adware. Check here for information about ""Cy-door"" and here for a program that can remove it"
X
Kazaa Download Accelerator Updater
??
SafeguardProtect/Veevo
X
Kazaa Download Accelerator Updater (required)
??
SafeguardProtect/Veevo
X
Kazaa lptt01 or Kazaa ml097e
kazaa.exe
"Variant of the RapidBlaster parasite (in a ""kazaa"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X
KAZAACuf
??
KITRO.D (or ARGEN.A) VIRUS!
N
kazaalite
kazaalite.exe
"Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms"
N
KaZooM
KaZooM.Exe
"KaZoom from Blue Haven Media - ""add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"""
Y
KB891711
KB891711.exe
"Installed by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup."
U
KBD
KBD.EXE
Multimedia keyboard manager. Required if you use the multimedia keys
U
KBD MediaCenter
MEDIACTR.EXE
Multimedia keyboard manager. Required if you use the multimedia keys
X
kbddrv32
kbddrv32.exe
CRYPTER.A trojan infection
X
kbddrvinf
kbddrvinf.exe
CRYPTER.A trojan infection
N
KCeasy
KCeasy.exe
KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella.
U
KClient
kstatus.exe
KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet.
N
kdx
KHost.exe
"KonTiki Secure Delivery Plug In related. ""The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers"""
U
KE9801
DriBat32.exe
KE-9801 multimedia keyboard - required if you use the multimedia keys
X
Keenvalue
Keenvalue.exe
eUniverse/KeenValue adware
U
KEMailKb
KEMailKb.EXE
Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down
U
Kerio VPN Client
kvpnclient.exe
Kerio VPN Client
X
kern64dll
??
PWSteal.Tarno.J trojan infection.
X
Kernal Fault Check
ntosrkl.exe
variant of the W32/SDBOT WORM!
X
kernctl32
"rundll32 kctl32.dll,initialize"
Trojan.Proxy.Agent.AT infection
X
Kernel
bboy.exe
MUMU.B VIRUS!
X
KERNEL 32
SKERNEL32.com
W32/SEMAPI-A WORM
X
Kernel Faults
ftphost.exe
RBOT.BHU WORM!
X
Kernel Loader
ntkrnl.exe
CERVIVEC.A VIRUS!
X
Kernel Services
service32.exe
TROJ/PRX-B TROJAN!
X
kernel system daemon
ACTIVAT0R.exe
RANDEX.AW VIRUS!
X
Kernel_check
wmiprvse.exe
W32/SONEBOT-B WORM!
X
kernel12.exe
kernel12.exe
unidentified WORM or TROJAN!
X
kernel32
kern32.exe
BADTRANS.A VIRUS!
X
kernel32
kernel.dli
NETDEVIL.B VIRUS!
X
Kernel32
Kernel.dll
REDLOF.M VIRUS!
X
kernel32
kernel32.dlI
NETDEVIL.15 VIRUS!
X
Kernel32
Kernel32.exe
"number of VIRUSES - such as BABYLONIA, KERNEL and HOOKER"
X
Kernel32
Kernel32.win
GAGGLE.D VIRUS!
X
Kernel32
kernel32s.exe
W32/SDBOT-PU TROJAN!
X
Kernel32
krnl32.exe
EPON VIRUS!
X
kernel32dll
guardpc.exe
W32/FORBOT-CU WORM!
X
KernelCheck
??
unidentified TROJAN!
N
KernelFaultCheck
dumprep 0 -k
"Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out"
N
kernelfaultcheck
dumprep 0 -u
"Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out"
X
KernelFaultChk
sms.exe
"DEADHAT VIRUS! Do not confuse with the valid ""kernelfaultcheck"" which runs ""dumprep 0 -k"" or ""dumprep 0 -u"""
X
Kernell
systems.exe
TARNO.C VIRUS!
X
Kernell32
Kernell.dll
DESTINY VIRUS!
X
KernellApps
csrss.exe
BANCBAN-AC TROJAN!
X
KernellApps
lexplore.exe
Troj/Bancban-BS TROJAN!
X
KernellApps
svshosti.exe
Bancban-V trojan infection
X
Kernelw
Kernelw32.exe
INDOR.E VIRUS!
X
key
sys_xp.exe
BEAGLE.AC WORM!
X
key
sysxp.exe
BEAGLE.AB WORM!
X
key
winxp.exe
BEAGLE.AG WORM!
X
Key Logger
csrss.exe
W32.Buchon.A worm.
X
Key1
Rlid.exe
LIXY VIRUS!
Y
KeyAccess
keyacc32.exe
"KeyServer KeyAccess client software - ""when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"""
X
Keybdcntl
keybdcntl.exe
Crypter.C trojan variant infection
U
Keyboard Manager
MMKeybd.exe
Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as MULTIMEDIA KEYBOARD
Y
Keyboard Preload Check
Preload.exe
Millenium Multi-Function Keyboard driver
X
keyboard_enum
keyboard_enum.exe
TROJ/BDOOR-GP TROJAN!
U
KeyMaestro
kmaestro.exe
Multimedia keyboard manager. Required if you use the multimedia keys
U
keymap
keymap.exe
System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
"KeyPatrol - detects Key Loggers (""keyboard loggers"" or ""keyloggers"") using both behavioral and pattern-matching algorithms"
U
keystroke
keystroke
QuickLaunch is a spyware program that logs keystrokes and captures screenshots. If you didn't install this yourself remove it.
N
KeyText
KeyText.exe
Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
U
KeyWallet
KWallet.exe
"""KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"""
X
kfienq
masbl.bat
KIFER VIRUS!
X
kgjdi27
kgjdie27.exe
Sdbot.AP WORM!
N
khooker
khooker.exe
SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
U
KICKMON.EXE
KICKMON.EXE
"KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required"
U
Kill Popup
KillPopup.exe
KillPopup Pop-up stopper
N
Kinberlink
Kinberlink.exe
Kinberlink network messaging. Available via Start -> Programs
U
KK Loader
loadkk.exe
"KeyKey XP Professional from KeyKey.com. ""Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user."""
U
KLog
Keyspy.exe
Hacktool.KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!
U
klp
explorer.exe
"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in a C:\WINDOWS\System\PAL\CSS folder (Win 98/ME) or in the C:\Winnt\System\PAL\CSS or C:\Windows\System\PAL\CSS subfolder (Windows 2000 and Win XP)"
U
klp
run32dll.exe
PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online
U
KM9801U
MMHotKey.exe
Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
U
kmw_run.exe
kmw_run.exe
Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
U
kmw_show.exe
kmw_show.exe
Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features
N
Kodak Batch Transfer
pezdow1.exe
"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC"
U
Kodak EasyShare software
EasyShare.exe
Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually.
N
Kodak Picture Easy *.* Batch Transfer
PezDownload.exe
"Part of ""Kodak Picture Easy"" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version"
N
Kodak Picture Transfer Software
pts.exe
Looks for Kodak camera connection and media insertion. Available via Start -> Programs
N
Kodak Software Updater
??
Software updater for Kodak Easyshare digital cameras
Y
KodakCCS
KodakCCS.exe
Kodak DC File System Driver
U
Komunikator
tlen.exe
Tlen - a Polish language Instant Messaging client
N
Konni Symbol Autostart
KonniSymbol.exe
Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5
N
kontiki
kontiki.exe
Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
Y
KPDrv4XP
KPDrv4XP.exe
MediaKey USB Keypad Driver
U
KREC32
krec32.exe
StarrCommander Pro Keystroke logging software
X
Krnlcheck
csrss.exe
"BACKDOOR.BOTNACHALA TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!"
U
Krnlmod
Krnlmod.exe
"Keylogger - see here. Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't, treat it as ""X"" and uninstall or remove via Spybot S&D (for example)"
X
Ksrv32
Ksrv32.exe
W32/Agobot-PI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
U
ktchnsnk
ktchnsnk.exe
HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
X
KV2005
word.EXE
TROJ/VB-IW TROJAN!
X
kv3000
lover.vbe
ZSYANG.B VIRUS!
X
kvern16.dll
??
DailyWinner adware
X
kw3eef76
??
LZIO.com adware downloader
N
kX Mixer
kxmixer.exe
Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards.
X
KYK Control Settings
KYSVCXD.EXE
variant of the WIN32.RBOT WORM!
X
KYM Control Settings
phqghum.exe
RBOT.BQD WORM!
X
L4r1$$a
L4r1$$a.pif
W32/ASSIRAL-C WORM!
X
laltin
L90112201.Stub.exe
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
LAN Driver
landriver32.exe
RBOT.BT WORM!
X
lanbrup
lanbrup.exe
SafeSurfing adware
U
LanguageMonitor
Oplmsb01.exe
OKI Printer language support monitor
X
LanGuard
languard.exe
Adware downloader - also detected as the TROJ/SECONDT-C TROJAN!
U
LanSpeed2
LanSpeed2.exe
Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
U
laokey.exe
LaoKey.exe
Lao Script for Windows (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications.
U
LapLink scheduler
Llsched.exe
Utility that automatically performs file transfers as unattended background operations
X
lar
??
ROXY.C VIRUS!
X
Lar
Llass.exe
INOR-A VIRUS!
X
LARISSA ANTI VIRUS
LARISSA_ANTI_VIRUS.exe
Klassir TROJAN!
X
LAsIAf32
RePEAtLD.exe
REPEATLD VIRUS!
Y
LASTinst
??
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
U
LaunApp
LaunApp.exe
Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
U
Launch Ai Booster
OverClk.exe
The ASUS Ai_Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup.
N
Launch YahooPOPs! at Windows startup
YAHOOPOPS.EXE
YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs
U
LaunchAp
LaunchAp.exe
Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
U
LaunchApp
Alaunch.exe
Acer Launch tool utility on laptops
U
Launchboard
lnchbrd.exe
"""LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions"""
X
Launcher
launcher.exe
Spyware component related to DownloadWare and found in Program FilesKFH
N
Launcher
relaunch.exe
Audio Applications Launcher for the Philips Rythmiic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs
X
Lavasoft Ad-Aware
Ad-Aware.exe
"W32/RBOT-SO WORM! - NOTE: this is NOT the popular spyware remover, as described here"
U
Lavasoft Adwatch
Ad-watch.exe
Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
Y
laxmsp32.exe
laxmsp32.exe
Lexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work?
X
Laz
Kernn.exe
TROJ/BANCOS-LN WORM!
U
LCDC
LCDC.exe
LCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins
Y
LCDPlayer
LCDPlyer.exe
Related to SuperAdBlocker
N
lcfep
lcfep.exe
"Tivoli ▒TME? System Tray icon - ""\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"""
U
LClock
lclock.exe
LClock is a program that makes the Windows' clock look like a Windows Longhorn Clock.
X
lcvga
lcvga.exe
Hostol-A TROJAN!
X
ld
ld.exe
CoolWebSearch parasite variant
N
LDM
??
"Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech. Also listed under Logitech Desktop Messenger"
Installs a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work
"Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut"
U
Lexmark **** Series
lxbmbmgr.exe
"Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut"
U
Lexmark **** series
lxbtbmgr.exe
"Lexmark System Tray application (where ""****"" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut"
Y
Lexmark 2200 Series Button Manager
lxbvbmgr.exe
Lexmark printer button manager. Required for correct operation
Y
Lexmark 3100 Series
lxbrbmgr.exe
Lexmark printer button manager. Required for correct operation.
U
Lexmark X5100 Series
lxbabmgr.exe
System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Y
Lexmark X6100 Series
lxbfbmgr.exe
Lexmark X6100 printer button manager - required for correct operation
U
Lexmark X74-X75
lxbabmgr.exe
System Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
Y
Lexmark Xxx Button Monitor
ACMonitor_Xxx.exe
"Associated with the Lexmark Xxx (where ""xx"" is the model) all-in-one printer/scanner/copier. Required for correct operation"
N
LexmarkPrinTray
printray.exe
Lexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
X
lexplore
lexplore.exe
"W32.BROPIA WORM! - NOTE: this process is spelled ""LEXPLORE.exe"" (with an ""L""), not Iexplore.exe like the familar Internet Explorer executable!"
N
lexpps
lexpps.exe
"For Lexmark printers. From Lexmark: ""This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all"". It is known that firewalls can however alert you to ""lexpps.exe"" requesting server privileges"
U
LexStart
lexstart.exe
Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
X
Lfh
Lfh.exe
TROJ/ZAURGA-A TROJAN!
U
Lfsndmng
lfsndmng.exe
"LightningFAX Enterprise Fax Server - ""puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents"""
N
lhttseng
??
Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine
X
li01f948
??
LZIO.com adware downloader
N
LicCrtl
runservice.exe
"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program"
U
LicCtrl
??
"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program"
U
LidPolicy
pwrschem.exe
A utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery.
N
LifeScape Media Detector
PicasaMediaDetector.exe
Media detector for Picasa's automatic photo organizer
X
lify
yujixit.exe
variant of the W32/SDBOT WORM!
U
Lightning Download
Lightning.exe
"Lightning_Download download manager. Can be launched manually, but will need to start up if you want it to ""catch clicks"" off Internet Explorer"
X
Limewire
LimeWire.exe
W32/Rbot-AGH WORM!
N
LimeWire x.x
LimeWire.exe
LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware
X
Limpet
explorer16.exe
W32/Rbot-AJD WORM!
X
li-multi****
li-multi****.exe
Adult web-dialler - **** is random
N
Line Speed Meter V3.0
LineSpeedMeter.exe
LineSpeedMeter - detect the download and upload speed of your internet connection
N
Linksts
linksts.exe
"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon"
X
Linksts
linksts.exe
"Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon"
X
Linux
Linux.vbs
LOVELETTER.AS VIRUS!
U
LiquidView
lviewj.exe
"""Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display\'s native resolution. The software lets you increase the size of items that are hard to read on your monitor"""
X
Lisa
Lisa.exe
DIAL/SCOM-D premium rate adult content dialer.
X
li-speed****
dlres.exe
Adult web-dialler - **** is random
X
List checker 32 BIT
list32.exe
W32/Rbot-AHO WORM!
X
Litebot
??
Troj/Litebot-A TROJAN!
N
LIU
LIU.exe
"Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway"
N
LIU
Rubicon.exe
"Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway"
N
Live Menu
Dllcmd32.exe
eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here
N
LiveMonitor
LMonitor.exe
MSI Live Update2 - auto-detects and suggests the latest BIOS/Driver/Utilities information
N
LiveNote
Livenote.exe
Asus graphics card driver live update feature
X
LiveSexCams
LiveSexCams.exe
Premium rate adult content dialer
U
LiveUpdate
LiveUpdate.exe
Web-update utility as used by various types of software - see http://liveupdate.openwares.org/
X
li-vita****
li-vita****.exe
Adult web-dialler - **** is random
X
Livre
Dibane.bat
W97M.BANEDI VIRUS!
X
llsass
llsass.exe
"TROJ/PROXY-GG TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
N
LM Status
LMSTATUS.EXE
Xerox WorkCenter XE - language monitor status application
U
LManager
HotkeyApp.exe
Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
U
LManager
QtZgAcer.EXE
Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
U
LManager
QtZpAcer.exe
Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
X
lMAPl
lMAPl.exe
W32/AGOBOT-RE WORM!
U
LMgrOSD
OSDCtrl.exe
"OSD (on-screen-display) utility - Part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language - User's choice!"
N
LMonitor
LMonitor.exe
Lmonitor utility comes with MSI\'s LiveUpdate Version 3 - periodically checks for updated drivers and utilities
X
lmrt
lmrt.exe
Unidentified adware
N
LMSTATUS
LMSTATUS.EXE
Xerox WorkCenter XE - language monitor status application
X
lmu
LMU.exe
"Downloader trojan, recognized by Kaspersky antivirus as Backdoor.Win32.Agent.bg"
X
lnternet Explorer
AMSNDMGR.EXE
"KWBOT.R VIRUS! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
X
load
??
W32.Kelvir.AI WORM!
X
load
_Kerne1.exe
Troj/Lineage-AN TROJAN!
X
load
Internat.exe
PWSteal.Wowcraft TROJAN!
X
Load
mdm.exe
Backdoor.Binghe TROJAN!
X
load
msgsr32.exe
W32/SDBOT-QR WORM!
X
Load
MyGame.exe
W32/LameYear-A Worm!
X
load
rundll32.exe
PWSteal.Wowcraft TROJAN!
X
load
svchsot.exe
Troj/GWGhost-O TROJAN! Note: (svchsot.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
load
svhost32.exe
PWSteal.Wowcraft TROJAN!
U
LOAD WB
LOADWB.EXE
"Part of Stardock's WindowBlinds custom desktop program. ""WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much?more"". If you use it - keep it if not then uninstall it"
Y
load=
01comm32.exe
"Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those."
X
load=
a1g.exe
ATAK.B WORM!
N
load=
adw30.exe
After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Y
load=
AICLIENT.EXE
Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system
U
load=
asistat.exe
Status monitor for an NEC SuperScript printer
Y
load=
Bfrecv.exe
Bitware modem driver
X
load=
dapdll.exe
W32.ATAK.E WORM!
U
load=
esspk.exe
Speakerphone capability through a soundcard for an ESS modem
X
load=
hint.exe
W32.ATAK WORM!
Y
load=
hotkey.exe
Solo 5300 display driver for Win2K on some Gateway laptops
N
load=
HPWHRC.EXE
Loads the Status Window software for the HP Laserjet printers
X
load=
inetinfo.exe
TROJ/PROXY-GG TROJAN!
X
load=
msater.exe
RETSAM VIRUS!
X
load=
shambl3r.exe
REMABL VIRUS!
X
load=
Spoolsv.exe
"CIADOOR.B VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file"
X
load=
svhost32.exe
TROJ/LINEAGE-AB TROJAN!
N
load=
vi_grm.exe
Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
Y
load=
wpshrc.exe
Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
X
load32
1111a.exe
W32.Dumaru.AH WORM!
X
load32
l32x.exe
W32.DUMARU.Z W32.DUMARU.Y or DUMARU.AD WORM!
X
load32
load32.exe
W32.DUMARU WORM!
X
load32
load32.exe
NIBU or W32.Bambo TROJAN!
X
LOAD32
Lorena.exe
W32.Mapson.C WORM!
X
load32
netda.exe
NIBU.E TROJAN!
X
load32
swchost.exe
TURTA.A WORM!
X
load32
swchost.exe
NIBU.I TROJAN! and the W32/Dumaru-AK WORM!
X
load32
winldra.exe
BACKDOOR.NIBU.J or DUMARU-BI and Troj/Dumaru-N TROJANS! Note: Also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this KeyLogger. For more information Click_Here
X
Loadab1
explorer.exe
Troj/Lineage-AJ TROJAN!
Y
LoadBlackD
blackd.exe
"This is the ""intrusion detection system"" of the BlackICE PC Protection (was Defender) firewall which loads independently of the ""user interface"" (BlackICE Utility)"
X
LoadDBackUp
BcTool.exe
GIBE VIRUS!
X
loaddll
loaddll.exe
Winvest SPYWARE!
X
loader
loader.exe
"Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe"
X
loader
WMPLAYER.EXE
Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn\'t load at startup
X
loader32
??
Domcom TROJAN!
X
loader32
Loader32.exe
unidentified TROJAN!
X
loadfax
loadfax.exe
Troj/Winflux-C TROJAN!
X
LoadFonts
"LoadFonts.vbs, Tahoma.vbs"
Homepage hijacker that changes your homepage to an adult content site
X
LoadGolfCourses
LoadGolfCourses.exe
PlayMiniGolf.com foistware - stealth installed!
X
Load-Guard
LGuarg.exe.vbs
VBS.YENO.C WORM!
X
LoadHTML
??
Mshtmpre adware
X
LoadingAgent
msload32.exe
OBLIVION TROJAN!
X
LoadingAgent
ZipLoader32.exe
OBLIVION TROJAN!
X
LoadManager
msload.exe
OPASERV.T VIRUS!
X
loadMecq0
explorer.exe
MUMUBOU.C TROJAN! ** Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X
loadMecq3
rundll32.exe
Troj/LegMir-AS TROJAN!
X
loadMect1
explorer.exe
"TROJ/LINEAGE-L TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Program Files folder! Note: The LINEAGE-AD variant will drop the ct1dll.dll file in the system folder."
X
loadMefs
rundll32.exe
"TROJ/LEGMIR-JA TROJAN! - NOTE: this file is found in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!"
X
loadMefs
rundll32.exe
"Troj/LegMir-JB TROJAN! Note: This is not the legitimate Windows Process rundll32.exe, Which is found in the Windows folder(98\ME) or the System32 folder(NT\2000\XP). This trojan file is found in the Windows\inf or Winnt\inf folder."
X
loadMefs
smss32.exe
TROJ/FLOOD-EL TROJAN!
N
LoadMSvcmm
msvcmm32.exe
Auto-update for Movielink - internet movie rental System Tray access
X
LoadOrderVerification
??
"TRON VIRUS! * is a random file name, possibly Pthymvfr.exe"
U
Loadout Manager
nost_LM.exe
Manager for the Belkin Nostromo n50 SpeedPad game controller - see here
X
LoadPFW
wmimgr.exe
W32/Qeds-B Worm!
U
LoadPowerProfile
??
"Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings"
X
LoadPowerProfile
ASDAPI.EXE
CABRO VIRUS! Not to be confused with the valid entry below
X
LoadPowerProfile
rundl.exe
TOFAZZOL VIRUS! Note - do not confuse with the valid LoadPowerProfile entry above!
X
LoadPowerProfile
Rundll.exe powerprof.dll
"LOXOSCAM TROJAN! **Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
X
LoadPowerProfile
Rundll32.exe
"MIROOT VIRUS! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
X
LoadPowerScheme
??
Ulubione adult content dialer
U
LoadQM
loadqm.exe
"Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the ""users choice"" recommendation. If you have problems leave it, otherwise I recommend you disable it"
X
loads.exe
loads.exe
MediaMotor/Popuppers adware downloader
X
loads.exe
medload.exe
MediaMotor/Popuppers adware downloader
X
loads.exe
suploads.exe
MediaMotor/Popuppers adware downloader
X
LoadService
"Maaf, tempatmu bukan di sin"
Troj/Kagen-A TROJAN!
X
LoadService
Rest In Peace
W32/KANGAROO-A WORM!
X
LoadService
Virus
CAGER.A WORM!
X
LoadSIPS
??
123Mania adware
X
loadwin
winset.exe
TROJ/QQPASS-I TROJAN!
X
loadwin
winsys.exe
TROJ/QQPASS-J TROJAN!
X
LoadWindowsFile
??
DELF.B VIRUS! where <filename> is the infected file
X
Local Area Network
OpenGL.exe
variant of the WIN32.RBOT WORM!
X
Local Internet Connection
LIC.exe
W32/SDBOT-YA WORM!
X
LOCAL INTERNET WEB DRIVERS FOR WIN32
phqghume.exe
variant of the WIN32.RBOT WORM!
X
Local Page
http://find.naupoint.com
Naupoint browser hijacker
X
Local runole service
srvc32.exe
TROJ/SMALL-DP TROJAN!
X
Local Security Authority Service
Isass.exe
W32.LINKBOT.M WORM!
X
Local Security Authority Service
lssas.exe
W32/POEBOT-J WORM!
X
Local Service
Intenat.exe
Troj/Nuclear-J TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Local-Settings-of-[User Name]
??
W32.Gavgent.A WORM!
U
Lock My PC
lockpc.exe
"Lock_My_PC . A tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse."
U
Logi_Mwx
Logi_MwX.exe
"Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
U
Logi_Mwx
Logi_MwX.Exe
"Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
U
Login
winlog.exe
Salfeld Child Control 2003 - parental control software
X
Login Screen Saver
login.scr
variant of the WIN32.RBOT WORM!
X
Login Service
??
MIGMAF VIRUS!
X
LoginPassport
Lgnpsp32.exe
REDIST.C VIRUS!
X
Logitech
Logitech.exe
RBOT.BJH WORM!
X
Logitech Camera
Soundcane.exe
SDBOT.MUC WORM!
X
Logitech Desktop
ApPache.exe
W32/RBOT-YP WORM!
X
Logitech Desktop
IPCONN.EXE
W32/SDBOT-WE WORM!
X
Logitech Desktop Controller
wrcam.exe
variant of the WIN32.RBOT WORM!
N
Logitech Desktop Messenger
??
"Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech"
U
Logitech SetPoint
KEM.exe
Keyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
U
Logitech Utility
Logi_MwX.exe
"Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
U
Logitech Utility
Logi_MwX.Exe
"Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
N
Logitech Wakeup
lgwakeup.exe
Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
X
Logitech Wireless
logitechwls.exe
W32/Mytob-BS Worm!
U
LogitechGalleryRepair
ISStart.exe
"LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation"
N
LogitechImageStudioTray
LogiTray.exe
Logitech Image Studio - installed with Logitech QuickCams
X
Logitechs
Logitechs.exe
SDBOT.BWE WORM!
U
LogitechVideoRepair
ISStart.exe
"LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the ""U"" rather than ""Y"" recommendation"
N
LogitechVideoTray
LogiTray.exe
Logitech Image Studio - installed with Logitech QuickCams
N
LogiTray
LogiTray.exe
Logitech Image Studio - installed with Logitech QuickCams
U
LogMeIn GUI
LogMeInSystray.exe
"RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone."
U
LogMeIn GUI
ragui.exe
"RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone."
X
Logo
??
Troj/Dloader-RH TROJAN!
U
Logon Loader
LogonLoader.exe
Logon_Loader - customize Boot & Login Screens
U
Logon Loader Random
LogonLoader.exe
Logon_Loader - customize Boot & Login Screens
X
Logon.exe
logon.exe
BKDR_ZINS.A TROJAN!
X
logon.exe
logon.exe
Zins.B TROJAN!
U
LogonStudio
logonstudio.exe
"WinCustomize LogonStudio - ""Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users"""
X
LogService
lsass.exe
"Troj/Bdoor-IU TROJAN! Note:This is NOT the legitimate Windows lsass.exe process, which should NOT figure in Startup!"
X
LogService
wincalc.exe
BACKDOOR.PAPROXY TROJAN!
U
LogWatch
logwat95.exe
Licensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see here. Not required if you already have a newer version or the patch has been applied
X
longos
WIWT.EXE
BANKER-CD TROJAN!
Y
Look 'n' Stop
looknstop.exe
Look 'n' Stop personal firewall
U
LookNMeet
Agent.exe
LooknMeet dating service
X
Lookup_Sys
lookupsys.exe
P04n trojan
N
Lotus Organizer EasyClip
easyclip.exe
"""The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page."" Available via Start -> Programs"
N
Lotus QuickStart
smartctr.exe
"Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs"
U
Lotus SuiteStart
suitest.exe
"Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as ""Lotus SuiteStart 97 Edition"". All individual components available via Start -> Programs"
X
LowVersionSupport
??
LASTRAS VIRUS! where <filename> is the name of the file dropped by the virus
X
Lpr
Lpr123.exe
REMPSTEAL password stealer TROJAN!
U
LPS
Lps.exe
"Local Port Scanner - ""With LPS you're able to check your computer for open or listening ports"""
U
LPtask
lptask.exe
"Program Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted"
X
LRBZ Utility 32
lrbz32.exe
W32/AGOBOT-JQ WORM!
N
LS120 Superdisk
??
"Supposed to accelerate transfer rate on LS-120, contributes to system lockups"
X
LSA
lsa.exe
W32/SDBOT-YV WORM!
X
LSA
wfdmgr.exe
W32.Mytob.C WORM!
X
LSA Service
LSASS.exe
"W32.Ahker.G WORM! **Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!"
X
LSA Shell (Export Version)
LSASS.exe
"several variants of the AHKER WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
lsass
??
ALADINZ.F VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
X
lsass
??
EliteBar adware variant
X
Lsass
kavmm.exe
"unidentified WORM or TROJAN! - NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here . Contrary to this impostor, the legitimate file will always be located in the Kaspersky Lab folder in Program Files."
X
lsass
lsasrv.exe
W32.Mydoom.AU WORM!
X
lsass
lsasrv.exe
SAVAGE.A WORM!
X
lsass
lsasrv.exe
W32.Mydoom.AS WORM!
X
lsass
lsass.exe
RATSU.B VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
X
lsass
start.bat
ZCREW VIRUS!
X
Lsass
woekd.exe
unidentified WORM or TROJAN!
X
LSASS 32
ISASS32.pif
W32/ASSIRAL-C WORM!
X
LSASS Authority
lshosts32.exe
SDBOT-UY TROJAN!
X
LSASS Authority
lsvhosts.exe
SDBOT.BCE WORM!
X
LSASS Daemon
LSASSd.exe
variant of the AGOBOT/GAOBOT WORM!
X
lsass service
lsass2.exe
variant of the GAOBOT/AGOBOT WORM!
X
lsass2k Update
lsass2k.exe
variant of the WIN32.RBOT WORM!
X
LSASS32
Isass32.exe
W32.KELVIR.M WORM!
X
lsass32
lsass32.exe
Troj/Lydra-B Trojan!
X
lsass64BiT.exe
lsass64BiT.exe
W32/FORBOT-CK WORM!
X
lsassig
lsassig.exe
Troj/Bancos-EC TROJAN! Note: This trojan file is found in the System\drivers (95/98/Me) or System32\drivers (Nt/2000/XP) folder.
X
lsasss
lsasss.exe
Troj/Geekmy-A TROJAN! Note: lsasss.exe (notice the extra s) is not the legitimate Windows Process. (lsass.exe) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
lsasss.exe
lsasss.exe
Sasser.E worm
N
lsburnwatcher
lsburnwatcher.exe
Used for automatically updating HP programs
X
lsess
lsess.exe
W32.SINNAKA.A WORM!
X
lsmss.exe
lsmss.exe
TROJ/PROXY-GG TROJAN!
N
LSPFix
LSPmonitor.exe
"eAcceleration Stop-Sign related - not recommended, see note"
N
LSPmonitor
LSPmonitor.exe
"eAcceleration Stop-Sign related - not recommended, see note"
X
lssass
lssas.exe
AGOBOT.RL WORM!
X
LSvr
LSvr.exe
PowerStrip foistware
Y
LT DAEMON
ltdaemon.exe
Acts as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used
X
LTDMgr
LTDMgr.exe
PowerStrip foistware
X
LTM2
bible.exe
LITMUS VIRUS Variant!
X
LTM2
MPGSRV32.EXE
LITMUS VIRUS variant!
X
LTM2
MSGSRV32.EXE
LITMUS VIRUS variant! (Note: MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:\Windows\System)
X
LTM2
MSGSRV320.EXE
LITMUS VIRUS Variant!
X
LTM2
winscan.exe
TROJ/LITMUS-B TROJAN!
X
LTM2
winupdate.exe
LITMUS VIRUS Variant!
U
LtMoh
Ltmoh.exe
Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Y
LTMSG
ltmsg.exe
"One of the ""popular"" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
N
LTSMMSG
LTSMMSG.exe
"Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too"
X
LTSMSG
Shell32.exe
PWSteal.Lemir.B TROJAN!
Y
LTWinModem1
ltmsg.exe
"One of the ""popular"" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
X
ltwob
formatsys.exe
W32.Serflog.A WORM!
X
ltwob
msmbw.exe
W32.Serflog.A WORM!
X
ltwob
serbw.exe
W32.Serflog.A WORM!
U
LUGuard
LUGuard.exe
"PC-Duo Remote_Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN, WAN or internet."
Y
Lusetup
LUSetup.exe
"Symantec, LiveUpdate_installer , required to install a new version of the application - will only run once, and the entry is automatically deleted after a reboot."
U
LVComs
lvcoms.exe
Lvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera
U
LVCOMSX
LVCOMSX.EXE
"It provides extra functionality for Logitech multimedia webcam devices. It is non-essential to the running of the system, but should not be terminated unless suspected to be causing problems."
U
LWBMOUSE
"lwbwheel.exe, MOUSE32A.EXE"
Mouse driver - required if you use non-standard Windows driver features
N
Lwinst Run Profiler
lwtest.exe
Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
Y
lxbrbmgr
lxbrbmgr.exe
Lexmark printer button manager. Required for correct operation.
N
LXSUPMON
LXSUPMON.EXE
Lexmark Printer. The printer should work fine without it
X
LzioMediaUpdater
LzioMediaUpdater.exe
LZIO.com adware downloader
X
M_S DVD DirectX Dll Drivers
msxdl.exe
W32/SDBOT-BJN WORM!
X
M1cr0s0ft S3rcurity
systemconfig.exe
RBOT.BKB WORM!
X
M1cr0s0ft Upd4t4zS
update32.exe
W32/RBOT-MI WORM!
X
m32info
m32info.exe
CRYPTER.A trojan infection
N
M3Tray
m3tray.exe
Movielink - internet movie rental System Tray access
X
m4n70s Personal Firewall
m4n70s.exe
variant of the W32.SPYBOT WORM!
X
Macfee Security Patch
Mpfsheild.exe
W32/RBOT-NP WORM!
U
Machine Debug Manager
mdm.exe
"Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to ""hang"" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable"
X
Machine Debug Manager
msdn.exe
variant of the WIN32.RBOT WORM!
X
Machine Update Soft
wusas.exe
unidfentified WORM!
N
MacLic
MacLic.exe
Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
N
MacName
MacName.exe
Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
X
Macromedia Dreamweaver XM
macdwXM.exe
W32/AGOBOT-RI WORM!
X
Macromedia Drive
Iexplor32.exe
variant of the WIN32.RBOT WORM!
X
Macromedia Flash Update
scvhost.exe
variant of the WIN32.RBOT WORM!
Y
MAD.EXE
MAD.EXE
MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?
N
MadExe
LaunchRA.exe
Dell Resolution Assistant
U
MAFWTaskbarApp
MAFWTray.exe
Drivers for the M-Audio Firewire Audiophile - Interface
U
MagicDsk
MAGICDSK.EXE
Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
U
MagicLinker3
MagicLnk.exe
ThaiSoftware Thai Dictionary
N
Magitime
Magitime.exe
"Magitime - connection tracking utility which monitors online time, expense, data transfer"
X
Mail_Check
Mail_Check.exe
PANOIL.C VIRUS!
U
MailBell
mailbell.exe
MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
U
Mailbox Verifier
mboxvrfy.exe
Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
N
MailCleaner
MAILCLEANER.EXE
"MailCleaner ""protect your computer from viruses sent to your machine via the popular e-Mail reader Incredimail. In addition the program will check all incoming files downloaded by Internet Explorer, Netscape Navigator, ICQ and iMesh"" - not recommended as it bundles Gator/Gain/Claria adware"
X
mailman.exe
mailman.exe
CERTIF-E TROJAN!
Y
MailScan Dispatcher
Launch.exe
"MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned"
U
MAIN
main.exe
SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
X
main16
main16.exe
CRYPTER.A trojan infection
X
main32
main32.exe
CRYPTER.A trojan infection
X
MainStart
svcmfte32.exe
Troj/Stinx-A Trojan!
X
mainviewex
mainviewex.exe
W32.GEMA.D TROJAN!
X
Major Microsoft Windows Driver Boot loader
bpool.exe
W32.MYTOB.AJ WORM!
N
Mania Win Restore
RESWIN.EXE
Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
X
Mantis
??
MANTIBE VIRUS! where <filename> is the filename
X
MapiDrv
mpisvc.exe
MIPSIV VIRUS!
X
mapisvc32
mapisvc32.exe
KX VIRUS and also recognised by Symantec as FPAI adware
X
Martini
pinmart.exe
variant of the W32/SDBOT WORM!
X
Mascro soft SDK updates2
SDKrepair2.exe
SDBOT.BXM WORM!
X
Mascro soft SDK updates2
SDKrepair2.exe
variant of the W32/SDBOT.W WORM!
N
masqform.exe
masqform.exe
"PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms"
N
Mass storage check registry
??
Used with a USB based smartmedia card reader
U
Master Volume Spy
MASTERVOLUMESPY.EXE
"Volume control for the Gateway Destination ""DestiVu"" media interface"
For Matrox video cards. Quick access to changing colors
N
Matrox Control Center
mgactrl.exe
For Matrox video cards. Quick access to settings
N
Matrox Diagnostic
mgadiag.exe
For Matrox video cards. Quick access to diagnostics
N
Matrox Powerdesk
PDesk.exe
For Matrox video cards. Quick access to tweak your card to your liking
N
Matrox QuickDesk
mgaqdesk.exe
For Matrox video cards. Quick access to tweak your card to your liking
X
MaxAlerts
max.exe
Bonzi MaxALERT - spyware
Y
MaxtorCombo
ComboButton.exe
Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
U
MaxtorOneTouch
OneTouch.exe
Maxtor OneTouch Hard Drives/OneTouch Family hard disk backup software
U
MaxtorReg
AUTOREG.EXE
Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
Y
MayaPan
MayaPan.Exe
Audiotrak Maya soundcard driver
U
MBM 4
MBM4.exe
Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
U
MBM 5
MBM5.exe
Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
U
MBNet
mbnet.exe
MBNet (Portugal) Credit Card Processing software
U
MBProbe
mbrpobe.exe
MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
X
MC
wintrims.exe
WINTRIM VIRUS!
Y
mc or SMC Service or SmcServices
smc.exe spfsmc.exe
Sygate Firewall
X
Mcafee Anti Scan
NortonScn.exe
Win32.Rbot worm variant
X
McAfee Antivirus
McAfeeAV.exe
variant of the WIN32.RBOT WORM!
X
Mcafee Antivirus Monitoring System326
VSStatmn326.exe
variant of the W32/SDBOT WORM!
X
Mcafee Antivirus Monitoring System32mn
VSStatmn32.exe
variant of the WIN32.RBOT WORM!
X
McAfee Antivirus Protection
mcafeeAV.exe
variant of the WIN32.RBOT WORM!
X
Mcafee Auto Protect
mcafeshield.exe
W32/RBOT-UH WORM!
Y
McAfee Firewall
CPD.EXE
Firewall bundled with McAfee VirusScan 6.*.?Can also be listed as CPD_EXE
N
McAfee Guardian
CMGRDIAN.EXE
"McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic"
N
McAfee QuickClean Imonitor
Plguni.exe
McAfee_QuickClean_3.0 - removes internet clutter and unwanted programs
X
McAfee Windows Protection
mcafee32.exe
variant of the W32.SPYBOT WORM!
N
McAfee Winguage
??
"Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious"". Resource hog. Available via Start -> Programs"
U
McAfee.InstantUpdate.Monitor
RuLaunch.exe
"Instant Updater for McAfee\'s VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis"
X
McAfeeScanPlus
McAfeeScanPlus.exe
Backdoor.Mepcod TROJAN! Note: This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder.
Y
McAfeeUpdaterUI
UpdaterUI.exe
Associated with McAfee Enterprise 7.0.0. - background process
Y
McAfeeVirusScanService
Avsynmgr.exe
"From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application"
Y
McAfeeWebscanX
WebScanX.exe
"From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc"
X
Mcaffe Antivirus
Mcafeescn.exe
W32.SpyBot worm variant
U
McAgentExe
mcagent.exe
"From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed"
Y
Mcappins.exe
mcappins.exe
Used by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled.
N
MChanger
MChanger.exe
"Media Changer - utility that allows you to change wallpapers, sounds, themes, etc"
X
MCM3
mcm3.exe
ShopAtHome/SAHagent adware variant
X
Mcrosoftr Update
Mcrosoftr.exe
variant of the WIN32.RBOT WORM!
X
MCUpdateExe
mcagent.exe
TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
U
McUpdateExe
mcupdate.exe
From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions
Y
mcupdmgr.exe
MCUPDMGR.EXE
McAfee antivirus SecurityCenter Update Manager
Y
McVsRte
mcvsrte.exe
Part of McAfee's SecurityCenter. Must remain checked but one? user reports Windows glitches with no response from McAfee as to why
Y
mcvsshld
mcvsshld.exe
McAfee VirusScan On-line. See also McAgentExe entry.
X
MD IE Plugin
md.exe
Marketdart spyware
X
MD IE Plugin
winy.exe
Adware
N
mdac_runonce
runonce.exe
"Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete ""runonce.exe"".?"
N
MDDiskProtect.exe
MDDiskProtect.exe
"MediaFour MacDrive for Windows - easily open, edit and save files from Mac-formatted disks, format Mac disks and burn Mac CDs and DVDs!"
X
mdetect
??
SPABOT VIRUS!
X
Mdm
Mdm.vbs
WHITEHO or TRAPPY VIRUSES!
U
MDM7
mdm.exe
"Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to ""hang"" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable"
X
Mdmdll
mdmdll.exe
WIN32.CRYPTER downloader TROJAN!
X
Mdmdll32
mdmdll32.exe
Crypter.C trojan variant infection
X
MDN
MDN.exe
RBOT.AOA WORM!
X
MDN
MDNS.exe
W32.Spybot.JPB WORM!
X
MDN
MDNZ.exe
RBOT.AQD WORM!
X
mds.exe
mds.exe
TROJ/MADS-A TROJAN!
X
mdwmdmsp
mdwmdmsp.exe
Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am
N
MECA
Meca.exe
Meca instant messenging client
X
MedGS
MEDGS1.exe
PacerD_Media/Pacimedia.com adware component
X
Media Access
MediaAccK.exe
Windupdates MEDIAPAS.A adware
X
Media Gateway
MediaGateway.exe
180Solutions Windupdates adware variant - also see here
X
Media Load
msn32.exe
Unidentified backdoor trojan
U
Media Manager Indexer
AIRSVCU.EXE
"Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here"
X
Media Pass
MediaPass.exe
WindUpdates MediaPass adware
X
Media Pass
MediaPassK.exe
MediaPass adware
X
Media Player
media.exe
FLDMEDIA-A VIRUS!
X
Media Player
Sysdll.exe
TROJ/BANKER-BR TROJAN!
X
Media Player
Sysnet.exe
BANKER.MW WORM!
X
Media Player
wmplayer.exe
W32/Agobot-BM WORM!
X
Media Player Update
xpsp1mfh.exe
variant of the WIN32.RBOT WORM!
X
Media Plug x.1.2
msdm.exe
MULDROP.352 VIRUS!
X
Media Service
msn64.exe
SPYBOT.EV worm infection
X
Media service
msnmsgxr.exe
WORM_SDBOT.TF
X
Media service
notpad.exe
variant of the AGOBOT/GAOBOT WORM!
X
Media service
SYSTEM64.EXE
RBOT.QV worm infection
X
Media Software UPdater
sscs.exe
W32/RBOT-ABE WORM!
X
Media X Services
MSNGRx.exe
RBOT.AUL WORM!
X
media_driver
media_driver.exe
"TUPEG VIRUS! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
media_manager
mediaman.exe
"Mini-Player,? IMESH related foistware, see here"
X
media_stub
stub.exe
"Mini-Player,? IMESH related foistware, see here"
X
MEDIA32
??
Troj/PurScan-Z Trojan!
N
MediaFace Integration
Sethook.exe
"Fellowes Neato? cd label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
U
Mediafour Mac Volume Notifications
Macvntfy.exe
Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
U
Mediafour XPlay Tray Notification Icon
Xptryicn.exe
Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
U
MediaKey
MediaKey.exe
Multimedia keyboard manager. Required if you use the multimedia keys
X
MediaLoads or MediaLoads Installer
dw.exe
Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
N
MediaMonitor
Mediam~1.exe
Installed by Smartdisk MVP CD burning software. Software will work fine without it
X
mediamotor.exe
mmups.exe
MediaMotor/Popuppers adware
X
MediaPath
??
GRUEL VIRUS!
X
mediapluscash.exe
mediapluscash.exe
MediaMotor/Popuppers adware component
N
MediaRing Talk
mrtalk.exe
"Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs"
X
MediaXPServicePack
mxpsp.exe
variant of the WIN32.RBOT WORM!
X
Media-XP-Service-Pack3
msnzx.exe
W32/Sdbot-ACW WORM!
X
Meeting Connection
comsutil.exe
PPDOOR-E TROJAN!
X
Meeting Connection
wowdache.exe
TROJ/PPDOOR-D TROJAN!
X
Members area
??
Premium rate adult content dialer
X
MemConfig
SetupIE.com
TAPLAK VIRUS!
U
MemMonster
memmnstr.exe
MemMonster is a memory manager which enables your computer to work more efficiently.
U
MemoKit
MK.EXE
Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
X
memory
outlookrem.exe
W32.Nopir.C Worm!
X
Memory Check
memore.exe
KILLAV.C VIRUS!
U
Memory Stick Monitor
MSstat.exe
Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
N
Memory Stick Monitor
MSTAT.exe
"Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer"
X
Memory Watcher
MemoryWatcher.exe
MemoryWatcher spyware
U
Memory+
tfimemsr.exe
Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
X
MemoryMeter
MemoryMeter.exe
Autoinstalling spyware by Total Velocity
X
MEMreaload
MEMreaload.exe /checkmouse /updateration
Lazar TROJAN!
N
MemScanner
MemScanner.exe
SpyHunter - spyware remover of somewhat dubious repute; see note
U
MemTurbo
memturbo.exe
MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
N
MenuSnap
MenuSnap.exe
"MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing ""Sort by Name"" if availabe"
X
Message Queuing
msmqs.exe
FREEFORS VIRUS!
U
Message_Blocker
messageblock.exe
"Message Blocker - ""prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"""
N
MessagerStarter Freeserve
StartMessager.exe
Freeserve Messenger
X
Messanger
deamon.exe
WIN32.TACTSLAY.C TROJAN!
X
Messanger
msgaol.exe
WIN32.TACTSLAY.C TROJAN!
X
Messanger
s_menu.exe
WIN32.TACTSLAY.C TROJAN!
X
Messanger
trillian.exe
variant of the AGOBOT/GAOBOT WORM!
X
Messenger
messenger.exe
KUTEX VIRUS!
X
Messenger
ntsubsys.exe
SDBOT.BGE WORM!
X
Messenger
Wmsngr.exe
variant of the WIN32.RBOT WORM!
X
Messenger Block
msngrblock.exe
PATOO VIRUS!
X
Messenger Protocol
netsender.exe
W32/Sdbot-ACC WORM!
X
Messenger Service
msmsgs.exe
W32/SDBOT-ZB WORM!
X
Messenger Service
nvhost.exe
MYTOB.IF WORM!
X
Messenger Service Updater
svshost.exe
MYTOB.GC WORM!
X
Messenger start-up
Msgran.exe
GRAMOS VIRUS!
X
Messenger6
command.pif
W32.INZAE.B WORM!
U
MessengerDiscovery
MessengerDiscovery.exe
"MessengerDiscovery is a MSN Messenger add-on, adding over 70 new features."
N
MessengerPlus
MsgPlus.exe
"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
N
MessengerPlus2
MsgPlus.exe
"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
N
MessengerPlus3
MsgPlus.exe
"MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
X
messnger
??
DELODER VIRUS! where <filename> is the worm name
X
messnger
Dvldr32.exe
DELODER.A VIRUS!
X
MeTaLRoCk (irc.musirc.com) has sex with printers
metalrock-is-gay.exe
RANDEX.Q WORM!
X
MeuPrograma
accwizz.exe
W32.Ruland.A WORM!
X
mfin32
mfin32.exe
MyFreeInternetUpdate - adware downloader
N
MGA Quickdesk
MGAQDESK.EXE
For Matrox video cards. Quick access to tweak your card to your liking
N
MGA_CD_Install
mgasetup.exe
Matrox Millennium video driver. Not required once drivers installed
Y
mgavctrl or mgavrtclexe
mgavrtcl.exe mgavrte.exe
McAfee\'s Virus Scan Online
X
mgmtapi
mgmtapi.exe
Unidentified malware
X
MHDOGStart
mhdogst.EXE
unidentified VIRUS! A possibility is a trojan known as PENIS
N
MHINIT
MHINIT.EXE
Part of the Cybermedia Clean Sweep package
X
Micr Update
soundblaster.exe
WORM_SDBOT.NP
X
Micr0s0ft Upd4t4z
svchost32.exe
variant of the WIN32.RBOT WORM!
X
Micrcoft Exploerer
spoolsal.exe
W32/Rbot-AKK WORM!
X
Micrcoft Updat
Internet.exe
W32/Rbot-ANA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Micrcoft Updat
spoolsae.exe
W32/Rbot-AIB WORM!
X
Micrcoft Updat
spoolsaex.exe
W32/Rbot-AJM WORM!
X
Micro Process
appconf.exe
unidentified WORM or TROJAN!
X
Micro Update
dailin.exe
W32/RBOT-ER WORM!
U
Microangelo Desktop
Muamgr.exe
"Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs"
N
microAttuneDownload
atmdlusr.exe
USR (US Robotics) modem auto updater. May be a sub-set of Attune
X
MicroCQ0
explorer.exe
Troj/Lineage-AK Note: This trojan file (explorer.exe) is found in the Program Files folder and is not the legitimate Windows file (explorer.exe) that is found in the Windows folder.
U
MicroDialler
atdialler1.exe
Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered
X
MicroedSoft Toolbar
Smoked.exe
W32/RBOT-ALN WORM!
X
Microfinder lptt01 or Microfinder ml097e
mcf.exe
"Variant of the RapidBlaster parasite (in a ""mcf"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Microft Exploerer
spoolsac.exe
W32/Rbot-AMD WORM! Note: This is not the legitimate Windows Process spoolsv.exe. (Notice the difference in the spelling) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
MicroLoad
??
DARBY VIRUS!
X
Micromedia Flash Update
wdfmrg.exe
variant of the W32/SDBOT WORM!
X
Microoft Timing
pupdate.exe
variant of the WIN32.RBOT WORM!
X
microsft windows updates
mwupdate32.exe
variant of the WIN32.TOXBOT/CODBOT WORM!
X
Microsof Windows Host
svhost32.exe
RBOT.ADY WORM!
X
Microsof Winlog Host
wilogon32.exe
RBOT.XC WORM!
X
Microsofot x386 System Monitor
system32.exe
WORM_WOOTBOT.M
X
microsoft
microsoft.hta
HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X
microsoft
svchost.exe
ASTEF or RESPAN VIRUSES! Note - this is not the valid svchost.exe as described here
X
Microsoft
win32.exe
BACKDOOR.DARKMOON TROJAN!
X
Microsoft (C) HTML Application host
??
W32/Rbot-YB WORM!
X
Microsoft .NET Confingurator
msnconf.exe
unidentified VIRUS!
X
Microsoft 16Bit Update
wuapdate16.exe
WORM_RBOT.CZ
X
Microsoft 64 Bit Runtime Updater
wupdt64.exe
variant of the WIN32.RBOT WORM!
X
Microsoft ActiveX Debugger NT
??
Troj/Bancos-DO TROJAN!
X
Microsoft ADservice
??
variant of the WIN32.RBOT WORM!
X
Microsoft ADservice
adservice.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Agent
mdss32.exe
KEYLOG-AG TROJAN!
X
Microsoft ALG32 Protocol
alg32.exe
variant of the W32.SPYBOT WORM!
N
Microsoft Announcement Listener
Annclist.exe
MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X
Microsoft Ansti Update
msie.exe
W32/Rbot-LE worm infection
X
Microsoft AntiSpyware
Bazzi.exe
AHKER.J WORM!
X
Microsoft AOL Instant Messenger
MSAOL32.exe
W32/RBOT-AAI WORM!
X
Microsoft AOL32 Protocol
aol32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Application Center
mappc.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Application Manager
msapl32.exe
TROJ/BROPIA-AE TROJAN!
X
"Microsoft Associates, Inc."
iexplorer.exe
variant of the LOVGATE WORM!
X
Microsoft AUT Update
MSlti16.exe
RBOT.EB WORM!
X
Microsoft AUT Update
MSlti32.exe
W32/Rbot-X worm
X
Microsoft Authority Service
lsass.exe
W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
X
Microsoft auto update
winupdate.exe
BMBOT VIRUS!
X
Microsoft Automatic Update Serivce
msautou.exe
W32/Rbot-AOB WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Automatic Updater
Explorer.exe
W32/RBOT-SG WORM!
X
Microsoft AutoUpdater
svhost.exe
RBOT.QG worm infection
X
Microsoft Bool Value
MV2.exe
variant of the WIN32.RBOT WORM!
X
Microsoft boot system cfg32
actboost.exe
W32.Bropia.R WORM!
X
Microsoft Cab Manager
exec.exe
Affilred.B adware
X
Microsoft checker
MsPMSPTv.exe
variant of the W32/SDBOT WORM! - do not confuse with the Microsoft's Digital Rights Management file described here
X
Microsoft Client
mshost.exe
W32/Rbot-AND WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Client/Server Runtime Server Subsystem
csrs.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Client/Server Runtime Server Subsystem
csrssa.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Command Line
wincmd.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Conf Ldr
sysconf.exe
variant of the SDBOT WORM!
X
Microsoft Config
msconf.exe
RBOT.PV WORM!
X
Microsoft Config
MSCONF.EXE
RBOT-LG WORM!
X
Microsoft Config 32bit
mscnfg32.exe
W32/RBOT-Z WORM!
X
Microsoft Config File
config.exe
Win32.KillFiles.gr TROJAN! - This is malware that will attempt to delete all system dlls!
X
Microsoft Configuration Utility
msconf.exe
W32/RBOT-AFX WORM!
X
Microsoft Connection Manager Monitor
cmmon.pif
W32/Rbot-AKV WORM!
X
Microsoft Control Center
crtl.exe
W32/RBOT-VX WORM!
X
Microsoft Core Support
MSxUP32.exe
W32/Rbot-ANR WORM!
X
Microsoft Corporation
??
"various VIRUSES such as VISAGES, BABYBEAR and TOFACED"
X
Microsoft CronD Service
MSCRON.EXE
Unidentified AIM-based worm/trojan
X
Microsoft Crs Fix Serv
wincrs.exe
SDBOT.BWF WORM!
X
Microsoft CSRSS32 Protocol
csrss32.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft CSRSS386 Protocol
csrss386.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Cvrt
mscvrt32.exe
"unidentified VIRUS!. Named almost, but not exactly like the legitimate msvcrt or msvcrt20.dll"
X
Microsoft Data Helper
cihost.exe
"Malware, possibly a Linst trojan variant"
X
Microsoft Data Machine
csdata32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Database Handler
mssql32.exe
RANDEX.AX VIRUS!
X
Microsoft Datalog Application
msdata.exe
variant of the W32/SDBOT WORM!
X
Microsoft DDE Control
wupades.exe
variant of the W32/SDBOT WORM!
X
Microsoft DDEs Control
Erun.pif
W32/Rbot-AMU WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Debug Service
dbgbgr.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Decryption Technology
Msfenoe.exe
W32/SPYBOT-DG WORM!
X
Microsoft Desktop Manager
msdesk32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Dev
iexplorer32.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Development Debugger
msdev.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Device Manager
msdevmgr32.exe
LATEDA.B TROJAN!
X
Microsoft Diagnostic
??
ACEBOT VIRUS! The <filename>.exe will be random and must be deleted after the virus has been removed. Not to be confused with the DOS based MSD.EXE
X
Microsoft Diagnostic
msdiag32.exe
W32/RBOT-UC WORM!
X
Microsoft Digital Clock
msclock.exe
W32/Nackbot-D worm infection
X
Microsoft DirectX
PDSched.exe
SDBOT.CN WORM!
X
Microsoft DirectX
rasmngr.exe
Win32.Rbot worm variant
X
Microsoft DirectX
Spoolserv.exe
DINFOR VIRUS!
X
Microsoft DirectX
time123.exe
SDBOT.MD WORM!
X
Microsoft DirectX
wuamgrd.exe
SDBOT.MY WORM!
X
Microsoft DLL Extensions
SystemDll.exe
W32/Rbot-ADV or W32/Rbot-AJR WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Dll Management
windll.exe
W32/RBOT-MT WORM!
X
Microsoft Dll Printer Manager
dllpt.exe
SDBOT.BIH WORM!
X
Microsoft DLL Verifier
chkfile.exe
W32/Rbot-AOC WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft DLL Verifier
file.exe
W32/Rbot-AED Worm!
X
Microsoft DLLSet32
dllset32.exe
RBOT.OZ WORM!
X
Microsoft DNS Query
msdns.exe
variant of the W32/WOOTBOT WORM!
X
Microsoft Document
krisp.exe
W32/SDBOT-RQ WORM!
X
Microsoft Driver
faet.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Driver Manager
mswindrv.exe
W32/FORBOT-EZ WORM!
X
Microsoft driver update
Mshome.exe
SDBOT.BL WORM!
X
Microsoft Drivers
WSconf.exe
variant of the W32/SDBOT WORM!
X
Microsoft ErgoPack
wserb32.exe
W32/RBOT-RI WORM!
X
Microsoft EV32 Service
MSev32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Excel
msexcel.exe
W32/RBOT-TQ WORM!
X
Microsoft Excell
wuamngr32.exe
W32/RBOT-QH WORM!
X
Microsoft Executing
microsoft.exe
AGOBOT.UV WORM!
X
Microsoft Explorer
explorer.pif
W32/Sdbot-ACX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Explorer
explorer.scr
W32/Rbot-ADH Worm!
X
Microsoft Explorer
svapache.exe
W32/RBOT-VR WORM!
X
Microsoft Explorer2
bitchbot.exe
SDBOT.EV WORM!
X
Microsoft Explorer2
nome.exe
RANDEX.AA WORM!
X
Microsoft Explorer2
system.exe
BKDR_IRCBOT.BS TROJAN!
X
Microsoft EXPLOREXP Protocol
explorexp.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Features
ms32cfg.exe
WORM_RBOT.HO
X
Microsoft Features
msie.exe
variant of the WIN32.RBOT WORM!
X
Microsoft File Demand Manager
wmgrdf.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Find Fast
Findfast.exe
Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
X
Microsoft Firewall
firewallsp2.exe
W32/Rbot-MC worm infection
Y
MICROSOFT FIREWALL CLIENT
ISATRAY.EXE
MS Internet Security and Acceleration Server - see here
X
Microsoft Games
gamemanager.exe
SPYBOT.AHQ WORM!
X
Microsoft Gina V Encryption
MSGINAV.EXE
Unidentified worm or trojan
N
Microsoft Greetings Reminder
MHPRMINF.EXE
You really want to be reminded about somebody's birthday at the expense of resources?
U
Microsoft Greetings Reminders
MHPRMIND.EXE
Microsoft Home Publishing greetings reminder
N
Microsoft Greetings Workshop Reminder
Gwremind.exe
You really want to be reminded about somebody's birthday at the expense of resources?
X
Microsoft Help
svh0st.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Help SVC
msnmngr.exe
W32/Sdbot-PQ worm infection
X
Microsoft Help System
mshelp32.exe
CoolWebSearch parasite variant
X
Microsoft Host Protocol
svhost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Host Service
mswinexect.exe
RBOT.ZU WORM!
X
Microsoft Hosting Service
WINHOSTING.EXE
RBOT.AEV WORM!
X
Microsoft Hosts Service
Isass.exe
variant of the WIN32.RBOT WORM!
X
Microsoft IDCN
mshe1p.exe
unidentified TROJAN!
X
Microsoft IE
Iexplore.exe
W32/Forbot-AG worm infection
X
Microsoft IE Execute shell
IEExec.exe
ALADINZ.N VIRUS!
X
MicroSoft IE Sasser
ISASS.EXE
SDBOT.MX WORM!
X
Microsoft IIS
??
W32/Francette-S Worm!
X
Microsoft IIS
syshost.exe
FRANCETTE VIRUS!
X
Microsoft Inc.
iexplorer.exe
variant of the LOVGATE WORM!
X
Microsoft Incroporate
mfs.exe
W32/RBOT-ANF WORM!
X
Microsoft Inet Xp..
teekids.exe
BLASTER.C VIRUS!
X
Microsoft Instant Messenger
msngmsngr32.exe
Win32.Spyboter.gen TROJAN!
X
Microsoft Int Service
MsIntSrv.exe
variant of the WIN32.RBOT WORM!
U
Microsoft Intellitype Pro
speedkey.exe
Additional keyboard shortcuts on MS programmable keyboard
X
Microsoft Internal AntiVirus Systems
dIlhost.exe
W32/Rbot-AEV Worm!
X
Microsoft Internet
expl0rer.exe
W32.SpyBot worm variant
X
Microsoft Internet
msnm.exe
W32/Sdbot worm variant
X
Microsoft Internet
wincfg16.exe
variant of the W32/SDBOT WORM!
X
Microsoft Internet
windows32.exe
W32/SdBot-F worm infection
X
Microsoft Internet Acceleration Utility
??
Troj/SmutSrch-A Trojan!
X
Microsoft Internet Acceleration Utility
??
TROJ/AGENT-CX TROJAN!
X
Microsoft Internet Acceleration Utility
iau.exe
EasySearch adware
X
Microsoft Internet Exp
iiexplorer.exe
W32/Rbot-KX worm infection
X
Microsoft Internet Explorer
crsys32.exe
RBOT.UZ WORM!
X
Microsoft Internet Explorer
iexplore.exe
"W32/POEBOT-J or W32/Mytob-CW WORM! - NOTE - This file is installed in the Windows\System32 or Winnt\System32 folders and is NOT to be confused with the Internet Explorer executable, which will always be located in the Internet Explorer folder in Program Files!"
X
Microsoft Internet Explorer
iexplorer.exe
W32/SDBOT-XN WORM!
X
Microsoft Internet Explorer
mccagent.exe
TROJ/DLOADER-UD TROJAN!
X
Microsoft Internet Explorer
movies.exe
Troj/Bancos-DZ TROJAN!
X
Microsoft Internet Explorer
msngrt.exe
W32/SdBot-GU worm infection
X
Microsoft Internet Explorer
smiissm.exe
TROJ/DLOADER-JQ TROJAN!
X
Microsoft Internet Explorer
svchosts.exe
Bancban-U trojan infection
X
Microsoft Internet Explorer
svzhost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Internet Firewall Manager
GMT16.exe
RANDEX.AT VIRUS!
X
Microsoft Internet Services
Smss32.exe
WORM_RBOT.MS
X
"Microsoft Internet, varying file names"
dmsvc32.exe
W32/Sdbot-AZ worm infection
X
Microsoft Intrenet Explorer
Soundsyst.exe
variant of the WIN32.RBOT WORM!
X
Microsoft IPC
svshost.exe
unidentified VIRUS!
X
Microsoft IPC
system.exe
NULLBOT VIRUS!
X
Microsoft IT Update
??
variant of the Win32.Rbot WORM!
X
Microsoft IT Update
IEserv.exe
variant of the Win32.Rbot WORM!
X
Microsoft IT Update
msupdate.exe
variant of the Win32.Rbot WORM!
X
Microsoft IT Update
svchsst.exe
W32/RBOT-DH WORM!
X
Microsoft IT Update
win43.exe
SPYBOT.BI WORM!
X
Microsoft IT Update
winn43.exe
variant of the Win32.Rbot WORM!
X
Microsoft IT Update
winsyst32.exe
W32/RBOT-FC WORM!
X
Microsoft Java Virtual Machine
javavm.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Java Virtual Machine
MsConfiG.exe
W32/FORBOT-DV WORM!
X
Microsoft Java Virtual Machine
msjvm.exe
variant of the W32/SDBOT WORM!
X
Microsoft Java Virtual Machine
msvmjava.exe
RBOT.ER WORM!
X
Microsoft Java Virtual Machine
winscr32.exe
variant of the W32/WOOTBOT WORM!
X
Microsoft Java Windows Update
??
W32/RBOT-DZ WORM!
X
Microsoft JavaVM
msjarun.exe
W32/Rbot-JW worm
X
Microsoft Kernel
Windows_kernel32.exe
W32.NETSKY.AE WORM!
X
Microsoft LAN32 Protocol
lanXp.exe
W32/RBOT-SS WORM!
X
Microsoft Legacy Device
trass.exe
W32/Rbot-AIX WORM!
X
Microsoft Lmhosting Service
lmhosts.exe
W32/RBOT-RC WORM!
X
Microsoft Locals 332
??
W32/Rbot-KU worm infection
X
Microsoft Login
winlogin.exe
W32/Rbot-AJP WORM!
X
Microsoft LSA layer
MSLSA32.exe
W32/Rbot-AKZ WORM!
X
Microsoft LSASS386 Protocol
scvhost32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft LV
??
TROJ/BDOOR-BDL TROJAN!
X
Microsoft Machine
winjava.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Macro Protection SubSsy
msacroprots386.exe
W32/Rbot-KE worm infection
X
Microsoft Macro Protection Subsystems
Msmacroprot32.exe
RBOT.KN WORM!
X
Microsoft Macro Protection Subsystems
msmacroprotxz.exe
W32.SpyBot worm variant
X
Microsoft Management
lmas.exe
W32/FORBOT-CZ WORM!
X
Microsoft Management Console
??
Troj/SmutSrch-A Trojan!
X
Microsoft Management Console
lssas.exe
EasySearch adware
X
Microsoft Map PC
mappc.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Mapped PC
mappedpc.exe
variant of the WIN32.RBOT WORM!
X
Microsoft media
winmplayers.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Media player 9
msmedia32.exe
W32/RBOT-ADO WORM!
X
Microsoft media services
Iassd.exe
variant of the GAOBOT/AGOBOT WORM!
X
Microsoft media services
winmplayer.exe
RBOT.ZO worm infection
X
Microsoft MediaScope
winmes.exe
W32/RBOT-XU WORM!
X
Microsoft Message Machine
msmesg32.exe
SPYBOT.BI WORM!
X
Microsoft Messenger Service
msmsg32.exe
RBOT.BOK WORM!
X
Microsoft Messenger XP
MSMSN32.exe
W32/RBOT-ZP WORM!
X
Microsoft MicroP Protocol
wdgmr32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Movie Maker
Mmaker.exe
IRCBOT.C VIRUS! Note that this is not a valid Microsoft program
X
Microsoft MSGPLUS32 Protocol
msgplus32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft MSNGR32 Protocol
msngr32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft MsnST
msnst32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft MSUPDATE
SpoolSvc.exe
SXTB-A VIRUS!
X
Microsoft Neser Experience
nese.exe
W32/RBOT-YH WORM!
X
"Microsoft NetMeeting Associates, Inc."
NetMeeting.exe
variant of the LOVGATE WORM!
X
Microsoft Netview
gesfm32.exe
RANDEX.C VIRUS!
X
Microsoft Netview
mssvc32.exe
unidentified VIRUS!
X
Microsoft Netview Component v5.1
msnv32.exe
RANDEX.F VIRUS!
X
Microsoft Network
msnet.exe
MOCKBOT.A VIRUS!
X
Microsoft Network
Networksystem.exe
W32/SDBOT-AAI WORM!
X
Microsoft Network Daemon for Win32
Netd32.exe
SDBOT.R WORM!
X
Microsoft Network Services Controller
mmsvc32.exe
W32/NANPY-A WORM!
X
Microsoft Networking Agent For SP2
msnac32.exe
W32.SPYBOT.PEN WORM!
X
Microsoft NotePad
notepad.exe
variant of the WIN32.RBOT WORM!
X
Microsoft NT Update
winexec32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Office
lserv.exe
SDBOT.MH WORM!
X
Microsoft Office
Microsoft Office.hta
HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X
Microsoft Office
MSMSGR.exe
GAOBOT.BB WORM!
N
Microsoft Office
Msoffice.exe
"Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly."
X
Microsoft Office
msoicons.exe
W32/RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups!
X
Microsoft Office
Nxcao.exe
W32/RBOT-ZE WORM!
X
Microsoft Office
nxcxtpr.exe
W32/RBOT-YG WORM!
N
Microsoft Office
OSA.EXE
"Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show."
X
Microsoft Office
svxhost.exe
variant of the WIN32.RBOT WORM!
N
Microsoft Office Fast Cache
Fastboot.exe
Part of MS Office 95 (v7.0). According to this;en-us;Q132755 it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled
U
Microsoft Office OneNote 2003 Quick Launch
ONENOTEM.EXE
ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work.
N
Microsoft Office Shortcut Bar
Msoffice.exe
"Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly."
X
Microsoft Office Start
winupdates.exe
GAOBOT.BC WORM!
N
Microsoft Office Startup
Osa9.exe
"Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show."
X
Microsoft Office Studio
scvhvst.exe
W32.Randex.CST WORM!
X
Microsoft OfficeXP
officeXP.exe
KILLAV.MA WORM!
X
Microsoft Opeions
IEXwe.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Outlook Express Protocol
svchst.exe
variant of the WIN32.RBOT WORM!
X
Microsoft PCHealth32
??
TROJ/NICE-A TROJAN!
X
Microsoft PCI Manager
mspci.exe
variant of the W32/SDBOT WORM!
X
Microsoft Personal Firewalls
bakw.exe
W32/Rbot-KS worm infection
X
Microsoft Proc Driver32
msprc.exe
variant of the W32/WOOTBOT WORM!
X
Microsoft Procedure Call
MSPCALL.exe
variant of the WIN32.RBOT WORM!
X
Microsoft PSTCP32 Data
pstcp32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft QMGR
msnqmgr.exe
TROJ/IRCBOT-S TROJAN!
X
Microsoft RDLL
sysconf32.exe
variant of the SDBOT WORM!
X
Microsoft Registro
svchostt.exe
TROJ/BANCOS-DH TROJAN!
X
Microsoft Registry
csrse.exe
W32/RBOT-PC WORM!
X
MicroSoft Remote Secure Service
MSRSS.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Restore
scrgrd.exe
SPYBOT.BR WORM!
X
Microsoft Rundll
windos.exe
W32/SDBOT-WF WORM!
X
Microsoft Runtime
CfgDll32.exe
RANDEX.BD VIRUS!
X
Microsoft Scanreg
microsoftscanreg.exe
FRANRIV.A VIRUS!
X
Microsoft SCVHOST32 Protocol
scvhost32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft sdk temp
sdktemp.exe
W32/Rbot-ANP WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Secure Messenger.NET Service
securitychk.exe
WORM_SDBOT.VT
X
Microsoft Security
winService.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Security Center
savservices.exe
W32/RBOT-ANU WORM!
X
Microsoft Security Controlers
fxsecues.exe
variant of the W32/SDBOT WORM!
X
Microsoft Security GManagers
??
variant of the W32/SDBOT WORM!
X
Microsoft Security Hot Fix Update
mshotfix.exe
Affilred adware
X
Microsoft Security Management
msisrv32.exe
W32/Rbot-ML worm infection
X
Microsoft Security Management
winamp.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Security Management
winnt.exe
W32/RBOT-MQ WORM!
X
Microsoft Security Management
winserv.exe
W32/Rbot-MJ WORM!
X
Microsoft Security Management
wuauct1.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Security Manager
winamp.exe
RBOT.TU WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
X
Microsoft Security Panager
??
W32/RBOT-ANL WORM!
X
Microsoft Security Panagers
??
W32/RBOT-AIG WORM!
X
Microsoft Server Applacations
msnmsg.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Server Applacations
wuauct1.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Server Application
Sound.exe
W32/RBOT-NE WORM!
X
microsoft server base
lass.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Service
microhost.exe
W32/Rbot-LC worm infection
X
Microsoft Service
winsvc.exe
W32/Spybot-DB worm infection
X
Microsoft Service Controller
services.exe
W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
X
Microsoft Service Drivers
System.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Service Drivers
VSADNIM.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Service Host Process
svchost.exe
"KRYNOS.B WORM! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
X
Microsoft Service Pack
WindowsSP.exe
W32/RBOT-RF WORM!
X
Microsoft Service Pack2.1
svchost2.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Services
bsc32.exe
BDOOR-AW TROJAN!
X
Microsoft Services
lsrv.exe
W32/Rbot-BK worm
X
Microsoft Services
lssrv.exe
WORM_RBOT.CW
X
Microsoft Services
services.exe
ALETS VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process
X
Microsoft Services
Smss32.exe
W32/RBOT-AD WORM!
X
Microsoft Services
svshost.exe
BACKDOOR.ALETS.B TROJAN!
X
Microsoft Services
svssshost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Services Unitd
MSU32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Session Manager Subsystem
smss.exe
W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
N
Microsoft Sidewinder Game Controller Software
SWTRAY.EXE
MS SideWinder game controller system tray icon. Available via Start -> Programs
X
Microsoft Sinsup
odjiwjf.exe
W32/RBOT-DN WORM!
X
microsoft software
??
unidentified WORM or TROJAN! (where * stands for a random character)
X
Microsoft software
cdaccess.exe
RBOT.ABK WORM!
X
Microsoft Software
sysinfo33.exe
RBOT.LS worm infection
X
Microsoft Software Update
nmon.exe
RBOT.HZ worm infection
X
Microsoft Sound Driver
sound32.exe
W32.SpyBot worm variant
X
Microsoft Sound Technology
winsound.exe
W32/Rbot-AGG WORM!
N
Microsoft Sound Volume Tool
mssvol.exe
This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
X
Microsoft SourceSafe
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
Microsoft SpA Service
msapps.exe
W32/RBOT-VI WORM!
X
Microsoft SpA Service
win32.exe
RBOT.ATS WORM!
X
Microsoft SpA Service
Winupd32.exe
RBOT.LT WORM!
X
Microsoft Special offer
infoebay.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Spool Server for Win32
spoolsrv.exe
RANDEX.H VIRUS!
X
Microsoft SSISVRI32 Protocol
ssisvri.exe
variant of the W32.SPYBOT WORM!
X
Microsoft standard protector
winsocks5.exe
variant of the TROJ/STOX-B TROJAN!
X
Microsoft Sum32
sum32.exe
W32/RBOT-YW TROJAN!
X
Microsoft Sum32
sum32.exe
W32/RBOT-YW WORM!
X
Microsoft Support
sys32ms.exe
W32/RBOT-AHI WORM!
X
Microsoft Synchronization Manager
___synmgr.exe
W32.MASLAN.C WORM!
X
Microsoft Synchronization Manager
al.exe
OPTXPRO.132 TROJAN!
X
Microsoft Synchronization Manager
asgard.exe
SDBOT.PH worm infection
X
Microsoft Synchronization Manager
bot.exe
SDBOT.IH worm infection
X
Microsoft Synchronization Manager
devldr32.exe
variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs devldr32.exe file
X
Microsoft Synchronization Manager
java.exe
variant of the W32/SDBOT WORM!
X
Microsoft Synchronization Manager
netscape.exe
RANDEX.AE worm infection
X
Microsoft Synchronization Manager
screen.exe
W32/SDBOT-ACO WORM!
X
Microsoft Synchronization Manager
slhost.exe
SDBOT.YH worm infection
X
Microsoft Synchronization Manager
svchosts.exe
W32/SDBOT-LM WORM!
X
Microsoft Synchronization Manager
svhost.exe
W32/Sdbot-PY And W32/Sdbot-YR WORMS!
X
Microsoft Synchronization Manager
svxhost.exe
W32/Sdbot-ZU WORM!
X
Microsoft Synchronization Manager
win.exe
SDBOT.AK WORM!
X
Microsoft Synchronization Manager
wincfg32.exe
SDBOT.DO WORM!
X
Microsoft Synchronization Manager
WinLoginnn.exe
SPYBOT.FO worm infection
X
Microsoft Synchronization Manager
winlogon32.exe
SDBOT.AEU WORM!
X
Microsoft Synchronization Manager
winupdate.exe
SDBOT.ER worm infection
X
Microsoft Synchronization Manager
xXx.exe
W32/Sdbot-KZ worm infection
X
Microsoft System
msupdtm.exe
W32.Spybot.PKC Worm!
X
Microsoft System Backup
??
W32/Rbot-AGM WORM!
X
Microsoft System Checkup
Cool.exe
W32.HLLW.Donk.B WORM!
X
Microsoft System Checkup
dbnetlib.exe
W32.HLLW.Donk.L WORM!
X
Microsoft System Checkup
inetman.exe
W32.HLLW.Donk.O WORM!
X
Microsoft System Checkup
Keymgr.exe
W32.HLLW.Donk.M WORM!
X
Microsoft System Checkup
libsys32.exe
W32/SDBOT-ACK WORM!
X
Microsoft System Checkup
libsysmgr.exe
W32/SDBOT-CAF WORM!
X
Microsoft System Checkup
netapi32.exe
W32/DONK-E WORM!
X
Microsoft System Checkup
ntsysman.exe
W32/SDBOT-QW WORM!
X
Microsoft System Checkup
ntsysmgr.exe
W32.Donk.S WORM!
X
Microsoft System Checkup
sysmgr.exe
SDBOT-OO TROJAN!
X
Microsoft System Checkup
Wnetlib.exe
W32.HLLW.Donk.C WORM!
X
Microsoft System Checkup
wnetmgr.exe
W32.DONK.Q WORM!
X
Microsoft System Debug
services32.exe
RBOT.AKH WORM!
X
Microsoft System DLL Services Configuration
windir32.exe
W32/Sdbot-ACY Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft System NT
svhost.exe
IRC/SDBOT.COU WORM!
X
Microsoft System Restore Configuration
CBRSS.EXE
variant of the SPYBOT VIRUS!
X
Microsoft System Services
msmsgr.exe
W32/RBOT-ZH WORM!
X
Microsoft System Services
msnmgsr.exe
W32.KELVIR.K WORM!
X
Microsoft System Update
sysupdate.exe
SDBOT.DG WORM!
X
Microsoft Taskmanager Updater
keyboard.exe
W32/RBOT-ALU WORM!
X
Microsoft Telecom Center
tellecom.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Telecoma Center
tellcoma.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Time Manager
dveldr.exe
W32/Rbot-HQ worm
X
MicroSoft Toolbar
key.exe
W32/Rbot-AEW Worm!
X
Microsoft Transfer File Server
mtfs.exe
RBOT.AFE WORM!
X
Microsoft Tray
??
DELF.BZ VIRUS!
X
Microsoft U
wuamkopxp.exe
W32/RBOT-AHC WORM!
X
Microsoft UMA Update
MSuma32.exe
RBOT.FS WORM!
X
MICROSOFT UNPACCKER SYSTEM
unpak32.exe
variant of the WIN32.RBOT WORM!
X
MICROSOFT UNPACK SYSTEM
winrarx.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updat3
mswkst32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
aaupdt.exe
W32/RBOT-RQ WORM!
X
Microsoft Update
ascdl.exe
W32.Gaobot.SY WORM!
X
Microsoft Update
automgr32.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update
Botnet.exe
RBOT.AFL WORM!
X
Microsoft Update
devmks32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
Isac.exe
W32/Rbot-AU WORM!
X
Microsoft Update
Kkk.exe
W32/RBOT-AHL WORM!
X
Microsoft Update
lsac.exe
GAOBOT.XW WORM!
X
Microsoft Update
mcupdate.exe
"variant of the WIN32.RBOT WORM! - NOTE - this file is located in the Windows\System32 or Winnt\System32 folder, and must NOT be confused with the McAfee antivirus executable as described here"
X
Microsoft Update
mediap.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update
Micr0s0ft.exe
AGOBOT.AAR WORM!
X
Microsoft Update
Microsoft.exe
GAOBOT.AFJ WORM!
X
Microsoft Update
Microsoftx.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update
mixer.exe
W32/Rbot-AIR WORM!
X
Microsoft Update
ms.exe
BKDR_SDBOT.CC WORM!
X
Microsoft Update
msawindows.exe
GAOBOT.AFJ WORM!
X
Microsoft Update
msconfg.exe
Win32.Rbot.H WORM!
X
Microsoft Update
msiwin84.exe
GAOBOT.AFJ WORM!
X
Microsoft Update
Mslti32.exe
W32/Rbot-LX WORM!
X
Microsoft Update
Msnmsngr.exe
RBOT.BQS WORM!
X
Microsoft Update
mssmgrd.exe
SDBOT.JT WORM!
X
Microsoft Update
msupdate.exe
TROJ/BOROBOT-I TROJAN!
X
Microsoft Update
msupdate32.exe
SPYBOT.LZ WORM!
X
Microsoft Update
muamgrd.exe
variant of the AGOBOT.GEN WORM!
X
Microsoft Update
mvsc.exe
variant of the W32.Spybot.DAZ WORM!
X
Microsoft Update
NAV.exe
W32/RBOT-IV WORM!
X
Microsoft Update
navmgrd.exe
BKDR_SDBOT.DP TROJAN!
U
Microsoft Update
phqghumea.exe
Identified as unknown malware W32/Backdoor by Norman
X
Microsoft Update
prowind32.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Update
scvhost.exe
W32/Rbot-AEM Worm!
X
Microsoft Update
sghost.exe
SDBOT.AKV WORM!
X
Microsoft Update
Smss32.exe
W32/Rbot-CB WORM!
X
Microsoft Update
snlogsvc.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
svghost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
svhost.exe
W32/RBOT-PI WORM!
X
Microsoft Update
svzhost.exe
RBOT.OX WORM!
X
Microsoft Update
sys.exe
W32/RBOT-AJ WORM!
X
Microsoft Update
sys32cfg.exe
RBOT.DR WORM!
X
Microsoft Update
systemi32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Update
up2dat5.exe
variant of the W32/SDBOT WORM!
X
Microsoft Update
update_w.exe
W32/RBOT-EW WORM!
X
Microsoft Update
VPC32.EXE
AGOBOT.XM WORM!
X
Microsoft Update
wauguard.exe
RBOT.AEE WORM!
X
Microsoft Update
webm.exe
SDBOT.WK WORM!
X
Microsoft Update
win32.exe
variant of the W32/SDBOT WORM!
X
Microsoft Update
winamp.exe
variant of the WIN32.RBOT WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
X
Microsoft Update
windows24.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
wingrd32.exe
W32/RBOT-DW WORM!
X
Microsoft Update
wingrd32.exe
W32/RBOT-DW WORM!
X
Microsoft Update
wininit.exe
W32/Rbot-AKR WORM!
X
Microsoft Update
win-mang.exe
W32/Rbot-AFK Worm!
X
Microsoft Update
winscv.exe
W32/RBOT-BH WORM!
X
Microsoft Update
winsys.exe
W32/RBOT-GV WORM!
X
Microsoft Update
winsys32.exe
variant of the Win32.Rbot WORM!
X
Microsoft update
winupdate.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
WinUpdate32.exe
W32/RBOT-TI WORM!
X
Microsoft Update
winupdater.exe
RBOT.BIN WORM!
X
Microsoft Update
wkfix.exe
W32/RBOT-ABZ WORM!
X
Microsoft Update
wserv32.exe
RBOT.AF WORM!
X
Microsoft Update
wssvr.exe
W32/RBOT-OD WORM!
X
Microsoft Update
wtm32.exe
W32/RBOT-AQ WORM!
X
Microsoft Update
wuagmrd.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
wuagmsd.exe
W32/RBOT-AX WORM!
X
Microsoft Update
wuagrd.exe
W32/RBOT-FK WORM!
X
Microsoft Update
wuamagr32.exe
SPYBOT.CG WORM!
X
Microsoft Update
wuamgrd.exe
W32/RBOT-YI WORM!
X
Microsoft Update
wuamgrd3.exe
W32/Rbot-AMC WORM!
X
Microsoft Update
wuamgrd32.exe
RBOT.ZB WORM!
X
Microsoft Update
wuamk0032.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
wuamk032.exe
W32/RBOT-AHD WORM!
X
Microsoft Update
wuamk0p32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
wuamkop.exe
W32/Rbot-AFI Worm!
X
Microsoft Update
wuamkop32.exe
RBOT.BGU WORM!
X
Microsoft Update
wuammgr32.exe
variant of the W32/Rbot-AW WORM!
X
Microsoft Update
wuampd.exe
W32/RBOT-UT WORM!
X
Microsoft Update
wuampkd.exe
SDBOT.BBX WORM!
X
Microsoft Update
Wudates.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update
wudmate.exe
RBOT.AP WORM!
X
Microsoft Update
wumgrd.exe
W32/SDBOT-KY WORM!
X
Microsoft Update
xpupdate.exe
W32/RBOT-QE WORM!
X
Microsoft Update 23
NtKernelSystem.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 23
spoolvs.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 32
??
W32/Rbot-AJJ WORM!
X
Microsoft Update 32
explore32.exe
W32.Spybot.CYM WORM!
X
Microsoft Update 32
mscnfg.exe
W32/Rbot-ALM WORM!
X
Microsoft Update 32
mssetup32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 32
MSupdate32.exe
variant of the Win32.SpyBot WORM!
X
Microsoft Update 32
servic.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 32
wiit.exe
W32/Rbot-AMS WORM!
X
Microsoft Update 32
wininit.exe
W32/RBOT-ANY WORM!
X
Microsoft Update 32
wininit32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 32
winitXP32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update 64 BIT
schvost.exe
RBOT.CAU WORM!
X
Microsoft Update 64 BIT
wininit32.exe
W32/RBOT-AHE WORM!
X
Microsoft Update 64 BIT
winman32.exe
W32/Rbot-AKI WORM!
X
MICROSOFT UPDATE CONFIGURATION
WIN32SNC.exe
W32/Rbot-AI WORM!
X
Microsoft Update Control
Ms64.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Debugger
wincfg32.exe
SPYBOT.ZC WORM!
X
Microsoft Update DLL
rxxhost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Emulator
kern-mxe.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Loader
??
variant of the Win32.Rbot WORM!
X
Microsoft Update Loaders 2005
winusers.exe
W32/RBOT-AIQ WORM!
X
Microsoft Update Loaders 2006
winusersystem32.exe
variant of the AGOBOT/GAOBOT WORM!
X
Microsoft Update Machine
??
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
crss32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
expl0rer.exe
variant of the SDBOT.OK WORM!
X
Microsoft Update Machine
linux.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
lmrss.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
lsasse.exe
W32/RBOT-DI WORM!
X
Microsoft Update Machine
memstat.exe
W32/RBOT-OM WORM!
X
Microsoft Update Machine
MSOICONS.EXE
variant of the WIN32.RBOT WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups!
X
Microsoft Update Machine
ntce.exe
W32/RBOT-FA WORM!
X
Microsoft Update Machine
qwerty.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
rxhost.exe
RBOT.FC WORM!
X
Microsoft Update Machine
rxxhost.exe
RBOT.EP WORM!
X
Microsoft Update Machine
scvhost.exe
W32/RBOT-GS WORM!
X
Microsoft Update Machine
servicez.exe
SPYBOT.BI WORM!
X
Microsoft Update Machine
servicz.exe
W32/Rbot-HU WORM!
X
Microsoft Update Machine
serviz.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
SP2.exe
SPYBOT.FP WORM!
X
Microsoft Update Machine
spoolserv.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
svshost.exe
RBOT.AK WORM!
X
Microsoft Update Machine
system.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
system03.exe
W32/RBOT-NM WORM!
X
Microsoft Update Machine
systemll.exe
W32/RBOT-JT WORM!
X
Microsoft Update Machine
Systemnt.exe
RBOT.DA WORM!
X
Microsoft Update Machine
systemse.exe
W32/RBOT-BD WORM!
X
Microsoft Update Machine
TASKMAN4.EXE
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
taskmngrs.exe
W32/RBOT-CR WORM!
X
Microsoft Update Machine
TMEMSER.EXE
W32/RBOT-NQ WORM!
X
Microsoft Update Machine
wftestb.exe
W32/Rbot-AFZ Worm!
X
Microsoft Update Machine
Win32.exe
SDBOT.UV WORM!
X
Microsoft Update Machine
windns.exe
RBOT.EF WORM!
X
Microsoft Update Machine
windowsu.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
windowsup.exe
W32/RBOT-FV WORM!
X
Microsoft Update Machine
winini.exe
W32/Rbot-KV WORM!
X
Microsoft Update Machine
wininigo.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
winmgr.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
Winmsixp32.exe
RBOT.DN WORM!
X
Microsoft Update Machine
winnie.exe
W32/RBOT-ACD WORM!
X
Microsoft Update Machine
winortho.exe
W32/RBOT-NW WORM!
X
Microsoft Update Machine
Winregs32.exe
RBOT.DN WORM!
X
Microsoft Update Machine
wins32.exe
RBOT.EZ WORM!
X
Microsoft Update Machine
winss.exe
RBOT.JU WORM!
X
Microsoft Update Machine
winupdt.exe
W32/RBOT-FP WORM!
X
Microsoft Update Machine
winxpini.exe
variant of the Win32.Rbot WORM!
X
Microsoft Update Machine
wuagrd.exe
W32/RBOT-GF WORM!
X
Microsoft Update Machine
wuamgard.exe
SPYBOT.CS WORM!
X
Microsoft Update Machine
wuamgd.exe
SDBOT.HQ WORM!
X
Microsoft Update Machine
wuamgrd.exe
WindUpdates SyncroAd adware
X
Microsoft Update Machine
wuawx.exe
W32/RBOT-CE WORM!
X
Microsoft Update Machine
wupdate32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Machine
wupdt32x.exe
variant of the W32/SDBOT WORM!
X
Microsoft Update Machine
xvshost.exe
RBOT.QP WORM!
X
Microsoft Update Machine
zonealarm.exe
W32/RBOT-BZ WORM! - NOTE: this is not the valid Zone Labs firewall program!
X
Microsoft Update Manager
svshost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Manager
WINRLS.EXE
RBOT-AF WORM!
X
Microsoft Update Mechene
Updatez.exe
W32/RBOT-GI WORM!
X
Microsoft Update Process
wmipcvse.exe
TROJ/AGOBOT-JF TROJAN!
X
Microsoft Update Security Patch
mssecurityupdatepatch.exe
Win32.Agent.ef backdoor TROJAN!
X
Microsoft Update Server
mssrv.exe
"Worm or trojan, as yet unidentified"
X
Microsoft Update Service
csrss32.exe
W32/Agobot-HC WORM!
X
Microsoft Update Service
mswin32.exe
variant of the Win32.Spybot WORM!
X
Microsoft Update SERVICE
phqghum.exe
variant of the WIN32.RBOT WORM!
X
Microsoft update service
systemm.exe
variant of the W32/SDBOT WORM!
X
Microsoft Update Services
wcsnfty.exe
W32/RBOT-AGK WORM!
X
Microsoft Update Services
wsnfty.exe
W32/RBOT-AFU WORM!
X
Microsoft Update Time
wuam.exe
W32/Rbot-M WORM!
X
Microsoft Update USB2
wuammgrd32.exe
W32/Rbot-ADT Worm!
X
Microsoft Update v2.6
lxxex.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Update Win32a
winupdate32a.exe
W32/Rbot-LO WORM!
X
Microsoft Update Win32x
winupdate32x.exe
W32/Rbot-AJN WORM!
X
Microsoft Updater
Winsys32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updater
wuamgrds.exe
BKDR_RBOT.A!
X
Microsoft Updater Resources
WinFixd32.exe
SPYBOT.CA WORM!
X
Microsoft UPDATER32
lsass.exe
RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup
X
Microsoft Updaters
sysconfigs.exe
W32/RBOT-DF TROJAN!
X
Microsoft Updaters
tskmgr.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updaters Pros
WINDLL32XP.EXE
SPYBOTTER.GEN VIRUS!
X
Microsoft Updates
systemc32.exe
W32/RBOT-GR WORM!
X
Microsoft Updates
wkssvr.exe
RBOT.R WORM!
X
Microsoft Updates
wkssvrs.exe
W32/RBOT-EB WORM!
X
Microsoft Updates
wtemp32.exe
W32/Rbot-AHQ WORM!
X
Microsoft Updates
wuamgrd.exe
W32/RBOT-CO WORM!
X
Microsoft Updates 2 USB
wgafixer.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updates 5 USB
sp3fixer.exe
W32/Rbot-ADS Worm!
X
Microsoft Updates Resources
WinFixIDs.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updating
navguard.exe
RBOT.HW WORM!
X
Microsoft Updating
syswr.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Updating
wuamguards.exe
W32/RBOT-BY WORM!
X
Microsoft Updating Client
websvc.exe
RBOT.AQ WORM!
X
Microsoft Updating Machine
sysc0de.exe
RBOT.RB WORM!
X
Microsoft Updatting
miroupdate.exe
variant of the WIN32.RBOT WORM!
X
Microsoft UpMachine
doezs.exe
RBOT.BCT WORM!
X
Microsoft upnp Update
msie.exe
W32/Rbot-LQ worm infection
X
Microsoft uptime Service
sycuptime.exe
W32/RBOT-AHY WORM!
X
Microsoft uptime Service
sysuptime.exe
W32/RBOT-ACG WORM!
X
Microsoft UpToDate Driver (32-bits)
??
W32.SPYBOT.LXJ WORM!
X
Microsoft USB2 Driver
crmss.exe
W32/RBOT-VK WORM!
X
Microsoft Utility Startup
OSA9.exe
Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants
X
Microsoft Vertupdate
MSvert32.exe
W32/MYTOB-CY WORM!
X
Microsoft Video Capture Controls
MSsrvs32.exe
W32/SDBOT-AAK WORM!
X
Microsoft Video Controls
tskmsgr.exe
W32.SpyBot worm variant
X
Microsoft Virual Machine
sms.exe
W32/RBOT-SP WORM!
X
Microsoft Visual SourceSafe
services.exe
"W32.Neveg.B worm. Note - this is NOT the legitimate services.exe system file, which should NOT figure in Msconfig/Startup"
X
Microsoft Visual SourceSafe
winlogon.exe
W32.Neveg.B worm
X
Microsoft Visual Studio VSA
varpc32.exe
W32.SpyBot worm variant
X
Microsoft Web Device
wdevice.exe
variant of the W32/SDBOT WORM!
U
Microsoft Webserver
svctrl.exe
Personal web server program which enables you to create and host a web server from your computer. Not required for most people
X
MicroSoft Wind0ws Updater
winsupdater.exe
variant of the WIN32.RBOT WORM!
X
MicroSoft Window Updater
winsupdater.exe
W32/RBOT-ZZ WORM!
X
Microsoft Windows
atup
variant of the WIN32.RBOT WORM!
X
Microsoft Windows
explorar.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows
Microsoft Windows.hta
HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X
Microsoft Windows
mstask0.exe
SDBOT.FQ WORM!
X
Microsoft Windows 16Bit
mswinn16.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Windows 2000
Winupdsdgm.exe
GAOBOT.AO WORM!
X
Microsoft Windows 32Bit
mswinn32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows 64 Bit
mswin32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Control
mswctl32.exe
RBOT.JP WORM!
X
Microsoft Windows CSRSS
csrss.exe
"W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Microsoft Windows DHCP
___r.exe
W32.Maslan.A or W32.Maslan.C WORMS!
X
Microsoft Windows DLL 32-BIT
msncheck32.exe
W32/SDBOT-XX WORM!
X
Microsoft Windows DLL Services
mwindll.exe
W32/SDBOT-VX WORM!
X
Microsoft Windows DLL Services Configuration
dllmanager32.exe
variant of the W32/SDBOT WORM!
X
Microsoft Windows DLL Services Configuration
newdll.exe
W32/Sdbot-ZR WORM!
X
Microsoft Windows DLL Services Configuration
newdll2.exe
W32/SDBOT-ABD WORM!
X
Microsoft Windows DLL Services Configuration
poker.exe
W32/SDBOT-ZY WORM!
X
Microsoft Windows DLL Services Configuration
poker3.exe
W32/SDBOT-AAH WORM!
X
Microsoft Windows DLL Services Configuration
proxy.exe
W32/Sdbot-ZL Worm!
X
Microsoft Windows DLL Services Configuration
regscv.exe
variant of the W32/SDBOT WORM!
X
Microsoft Windows DLL Services Configuration
windir32.exe
SDBOT.BHF WORM!
X
Microsoft Windows DLL Services Configuration
windir32a.exe
variant of the SDBOT.BHF WORM!
X
Microsoft Windows DLL Services Configuration
windll32.exe
SDBOT.BHD WORM!
X
Microsoft Windows DLL Services Configuration
winDSL.exe
W32/Sdbot-ZG Worm!
X
Microsoft Windows DLLHandler
bitpaint.exe
SDBOT.AHG WORM!
X
Microsoft Windows Explorer
iexplorer.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Files Loader
cgy32win.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows GUI
msmonk32.exe
W32/SDBOT-PE WORM!
X
Microsoft Windows GUI
Windowz.exe
RANDEX.AEV VIRUS!
X
Microsoft Windows Kernel Services
winkrnl386.exe
ZEBROXY VIRUS!
X
Microsoft Windows Loader
wloader.exe
variant of the GAOBOT/AGOBOT WORM!
X
Microsoft Windows Media Player
mediaplayer.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Media Player
wimp.exe
W32/RBOT-FN WORM!
X
Microsoft Windows Registry Service
wregistry.exe
AGOBOT.AKG WORM!
X
Microsoft Windows Registry Updater
wreg.exe
W32/FORBOT-DN WORM!
X
Microsoft Windows Secure Server
rpcxWindows.exe
W32/Rbot-LL worm infection
X
Microsoft Windows Secure Update
rpcxwinupdt.exe
unidentified WORM or TROJAN!
X
Microsoft Windows Securety
wurguar.exe
W32/RBOT-KY WORM!
X
Microsoft Windows Security
spvsper.exe
variant of the W32/SDBOT WORM!
X
Microsoft Windows Security
wscndrives.exe
W32/Rbot-AJK WORM!
X
Microsoft Windows Service
winsys.exe
W32/Rbot-ADP Worm!
X
Microsoft Windows Services Controller
wservices.exe
WIN32.RBOT.FD WORM!
X
Microsoft Windows Storage Machine Service
winms.exe
W32/RBOT-AHK WORM!
X
Microsoft Windows System Service Manager
winsvc.exe
SPYBOT.LR WORM!
X
Microsoft Windows Task Manger
Mstosk.exe
W32/Sdbot-WW worm infection
X
Microsoft Windows Updata
scvhost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Update
MSNMSGR.EXE
W32/SDBOT-WM WORM!
X
Microsoft Windows Update
msoffice2.exe
W32/Rbot-GB worm infection
X
Microsoft Windows Update
rundlls.exe
HABRACK VIRUS!
X
Microsoft Windows Update
scvvhost.exe
W32/Forbot-FH WORM!
X
Microsoft Windows Update
spools.exe
WORM_SDBOT.TD
X
Microsoft Windows Update
svchos.exe
Backdoor.Sdbot.AC worm infection.
X
Microsoft Windows Update
svcshost.exe
W32/FORBOT-CF WORM!
X
Microsoft Windows Update
svmhost.exe
W32/FORBOT-CH WORM!
X
Microsoft Windows Update
svshost.exe
WOOTBOT.CJ WORM!
X
Microsoft Windows Update
svzhost.exe
W32/FORBOT-EV WORM!
X
Microsoft Windows Update
swwhost.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Update Application
wuap.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Update Logon
win-logon.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Update Service
wupdmgr32.exe
DOS.AUTOCAT VIRUS!
X
Microsoft Windows Update XP64
??
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Updater
msnupdateit.exe
W32/AGOBOT-RL WORM!
X
Microsoft Windows Updater
spoolvs.exe
RBOT.ACQ WORM!
X
Microsoft Windows Updater
suvhost.exe
variant of the W32/SDBOT WORM!
X
Microsoft Windows Updater
svchostz.exe
DAEMONI-E VIRUS!
X
Microsoft Windows Updater
TMNTSrv.exe
variant of the WIN32.RBOT WORM!
X
Microsoft Windows Updater
win32upd.exe
W32/RBOT-EC WORM!
X
Microsoft Windows Updater
windates.exe
SDBOT.TE WORM!
X
Microsoft Windows Updater
WINIUPDATES.EXE
W32/Rbot-KK worm infection
X
Microsoft Windows Updater
WINUPDATE.EXE
W32/SDBOT-PU WORM!
X
Microsoft Windows Updater
winupdgm.exe
GAOBOT.BI WORM!
X
Microsoft Windows updaterD
log32zx.exe
W32.Mydoom.W WORM!
X
Microsoft Windows Updates
explorer32.exe
SDBOT.VQ WORM!
X
Microsoft Windows W32 Services
mssw32.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Windows WKS Service
gt.exe
SDBOT.FV WORM!
X
Microsoft Windows XP Configuration Loader
m32svco.exe
W32/SDBOT.WORM.48548
X
Microsoft WinRaR
winrar.exe
W32/Rbot-AEC Worm!
X
Microsoft Winsock
mswinsck.exe
W32/RBOT-ANK WORM!
X
Microsoft Winsock Service
msusvc.exe
W32/Rbot-ANS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoft Winsock Wrapper
ws2_32s.exe
variant of the W32.SPYBOT WORM!
X
Microsoft Winsocks 32 Controller
MSWSCK32.exe
variant of the WIN32.RBOT WORM!
X
Microsoft WinSound
??
variant of the WIN32.RBOT WORM!
X
Microsoft WinUpdate
mntcgf032.exe
W32/RBOT-PF WORM!
X
Microsoft WinUpdate
spfix.exe
variant of the WIN32.RBOT WORM!
X
Microsoft WinUpdate
svh0st.exe
SPYBOT.DL worm infection
X
Microsoft WinUpdate
syslx32.exe
Unidentified worm or trojan
X
Microsoft WinUpdate
syswin32.exe
W32/Rbot-HO WORM!
X
Microsoft WinUpdate
Winamp61.exe
variant of the WIN32.RBOT WORM!
X
Microsoft WinUpdate
WinNTinit32.exe
RBOT.VS WORM!
X
Microsoft WinUpdate
Winupd32.exe
RBOT.MQ WORM!
X
Microsoft WinUpdates
serm32.exe
RBOT.GE worm
X
Microsoft WM
mswm32.exe
TROJ/BCKDR-AM TROJAN!
X
Microsoft Word
BootSector.exe
variant of the AGOBOT alias GAOBOT WORM!
X
Microsoft Word Profissional
csrss.exe
Troj/Bancban-DB or Troj/Bancos-DP TROJAN! (Note:) May also be found in the \protect\ or \JavaVM\ folder.
X
Microsoft Word Profissional
Java Plug In close.exe
Troj/Banker-EL TROJAN!
N
Microsoft Works Calendar Reminders
wkcalrem.exe
Produces a pop-up reminder of events scheduled using the MS Works Calendar
N
Microsoft Works Portfolio
WksSb.exe
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
N
Microsoft Works Update Detection
"wkdetect.exe, WkUFind.exe"
Checks for updates to MS Works
X
Microsoft World Service
winworld.exe
unidentified IRC worm with backdoor capability!
X
Microsoft Wxdate
Syswu32.exe
SPYBOT.HZ WORM!
X
Microsoft X Update
wuamkoppnp.exe
W32/RBOT-ANI WORM!
X
microsoft xdaemon 2.0
xdaemon.exe
DELF.D VIRUS!
X
Microsoft XML Service
msxmlx.exe
WORM_RBOT.KS
X
Microsoft Xp Systems loader
winsystem32xp.exe
W32.KELVIR.W WORM!
X
Microsoft Xp Systems loaders
win32xpsys.exe
W32.SPYBOT.NYT WORM!
X
Microsoft XPSP Protocol
xp386.exe
variant of the WIN32.RBOT WORM!
X
Microsoft xpsp2
Networksystem.exe
variant of the W32/SDBOT WORM!
X
Microsoft xpsp2
xpsp2.exe
W32/Sdbot-YQ Worm!
X
Microsoft? PID Lex
PIDLex.exe
NIOVADOOR VIRUS!
X
Microsoft? ActiveX Debugger NT
setdebugnt.exe
Troj/Bancos-CZ Trojan!
X
Microsoft╜ System Mapper
SysMap.exe
MAPSY VIRUS!
X
Microsoft32.exe
Microsoft32.exe
Unidentified worm or trojan
X
microsoft420
microsoft420.exe
MENACE.B (or W32.SOFUNNY) VIRUS!
X
Microsoftf DDEs ContDLL
rune.pif
W32/Rbot-AGF WORM!
X
Microsoftf DDEs ContrDL
runm.pif
W32/Rbot-AFQ Worm!
X
Microsoftf DDEs Control
Erun.pif
variant of the WIN32.RBOT WORM!
X
Microsoftf DDEs Control
FEnR.exe
W32/RBOT-AIM WORM!
X
Microsoftf DDEs Control
lxes.exe
RBOT.BOF WORM!
X
Microsoftf DDEs Control
soff.pif
W32/Rbot-AKH WORM!
X
Microsoftf DDEs Control
wees.exe
variant of the the RBOT.BOF WORM!
X
Microsoftf DDEs Control
why-.exe
W32/Rbot-AMV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Microsoftkeysd
systemproc.exe
W32/FORBOT-BI WORM!
X
Microsoftkeysd
systemwin32.exe
variant of the WIN32.RBOT WORM!
X
Microsoftkeysd
systemwin32s.exe
WOOTBOT.CO WORM!
X
Microsoftkeysds
lass32.exe
variant of the WIN32.RBOT WORM!
X
MicrosoftKs
Drivers.bat
Troj/Shutdown-F TROJAN!
X
microsoftm eegs cuntrol
loor.pif
variant of the WIN32.RBOT WORM!
X
Microsoftmsn32.exe
microsoftmsn32.exe
TROJ/CERTIF-C TROJAN!
X
MicrosoftMultimediaTask
Mmtask.exe
Adware downloader - not the valid MusicMatch Jukebox which shares the same filename
X
MicrosoftNetwork Daemon for Win32
NETD32.EXE
RANDEX.F VIRUS!
X
MicrosoftOEM
smvss.exe
TROJ/DEDLER-G TROJAN!
X
Microsofts media
wingtp.exe
W32/RBOT-VO WORM!
X
Microsofts media
winmplayd.exe
undidentified WORM or TROJAN!
X
Microsofts MediaScope
winmedplay.exe
variant of the WIN32.RBOT WORM!
X
Microsofts MediaScope
winmep.exe
W32/Rbot-WB WORM!
X
Microsofts Security Manager
??
RBOT-WH TROJAN!
X
Microsofts Service
lcsrv16.exe
variant of the WIN32.RBOT WORM!
X
Microsoft's System Module
Sysmodule.exe
TROJ/BDOOR-FJ TROJAN!
X
Microsofts Updates
lsasss.exe
W32/Rbot-AEX Worm!
X
Microsofts Updatez
cmsssr.exe
Unidentified worm or trojan
X
Microsofts Updatez
exploirez.exe
variant of the WIN32.RBOT WORM!
X
MicrosoftServiceManager
EXPLORERE.EXE
YAHA.AB VIRUS!
X
MicrosoftServiceManager
mstask32.exe
YAHA.P VIRUS!
X
MicrosoftServiceManager
msupdat.exe
YAHA.AA VIRUS!
X
MicrosoftServiceManager
Wintsk32.exe
YAHA.U VIRUS!
X
Microsoft-software
??
variant of the WIN32.RBOT WORM!
X
MicrosoftSourceSafe
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
X
MicrosoftSys
SPOOLSYS.exe
PWSteal.Tarno.N TROJAN!
X
MicrosoftUpdate
syshelper.exe
WOOTBOT.AC WORM!
X
MicrosoftUpdate
WinUp32.exe
unidentified worm
X
Microsoft-Update
wngard.exe
W32/Rbot-JV worm infection
X
MicrosoftUpdates
syshelped.exe
W32/Forbot-AZ worm infection
X
Microsoft-Updates
svxhost.exe
W32/Rbot-CT WORM!
X
Microsoft--Updates
sxvhost.exe
W32/Rbot-FH worm infection
X
MicrosoftValue
syscnfg.exe
"Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside"
X
Microsoftvirus
sysoverload.exe
W32/FORBOT-AL WORM!
X
Microsoftz turn Control
aexl.exe
SDBOT.BCO WORM!
X
Microsoftz turn Control
read.pif
W32/Rbot-AFS Worm!
X
Microsong
svchosts11.exe
W32/SDBOT-EV WORM!
X
Microszoft Update Mach1nezs
svchst.exe
W32/RBOT-ED WORM!
X
Microzoft_Ofiz
KdzEregli.exe
AMUS.A VIRUS!
X
Micrsoft CFG 32
lrbzus32.exe
variant of the AGOBOT/GAOBOT WORM!
X
Micrsoft Driver
msdriver.exe
W32/SDBOT-XD WORM!
X
Micrsoft Driver
windrive.exe
BACKDOOR.SDBOT.AF WORM!
X
Micsorosft Security Center
wcnsfty.exe
W32/RBOT-AHU WORM!
N
MightyFAX Controller
MFNTCTL.EXE
"Mighty FAX from RKS Software - ""installs a printer driver so that you can fax directly from Windows software"""
N
MimBoot
mimboot.exe
Starts Musicmatch_Jukebox at bootup - can be started manually.
X
Mincer
Mincer.exe
WM97/Minceme-A Worm!
X
MINIBUG
MINIBUG.EXE
Displays ads inside Weatherbug - see here
N
MINIFERT.EXE
MINIFERT.EXE
Part of Backweb
U
minilog
MINILOG.EXE
If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
N
MiniMavis
MiniMavis.exe
Mavis Beacon typing tutor
X
minimo
??
TROJ/MOSUCK-X TROJAN!
N
MiniNote
MININOTE.EXE
"Mini NoteTab was the first in the family of ""NoteTab"" text and HTML editors from Fookes Software"
X
MiniPortRt
miniport_mp.exe
Malware - see here
U
MinMaxExtender
Mmext.exe
MinMaxExtender - window handling tool
X
Miosf Update
wimsqaad.exe
BACKDOOR.SDBOT.AG WORM!
N
Mirabilis ICQ
icq.exe
"If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs"
N
Mirabilis ICQ
ICQNet.exe
"If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs"
N
Mirabilis ICQ
NDetect.exe
"If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs"
U
"Miramar Systems, Inc."
atmsg.exe
Miramar PC/Mac networking software
N
Miranda IM
miranda32.exe
Miranda Instant Messaging client
X
Mirate Sp 2 Information
miratesp2.exe
RBOT.QH WORM!
X
Mircosoft Sockets SP2
mssck.exe
MYTOB.ET WORM!
X
Mircosoft Update
wuampkd.exe
variant of the W32/SDBOT WORM!
X
Mircrosoft Svchost32
svchost32.exe
W32/RBOT-AZW WORM!
X
Mircrosoft Windows Config DLL
rundllc32b.exe
W32/RBOT-ZY WORM!
N
miroVIDEO Tray Tool
misitray.exe
"Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card,?e.g. for the above actions"
U
MirrorFolderShell
mrfshl.exe
MirrorFolder backup software
X
Mismo
win32x.exe
W32/RBOT-JP WORM!
N
Mixer
Mixer.exe
C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
N
Mixghost
mixghost.exe
"Management software for Altec Lansing speakers.? If a change is needed, the user can launch it from the Start menu"
X
ml00!.exe
ml00!.exe
"Malware, detected by Panda antivirus as Trj/Downloader.BWD"
U
ML1HelperStartUp
ML1HEL~1.EXE
Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
U
ML1HelperStartUp
ML1Helper.exe
Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
X
mload
lxmstart.exe
unidentified VIRUS!
X
MMB2
explorer.exe
"unidentified WORM or TROJAN - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)"
X
MMC
inisys.exe
W32/Oscabot-I Worm!
X
mmcndmgr
mmcndmgr.exe
unidentified worm or trojan
N
MMCWINMGMT
winmgmt.exe
"Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here"
X
Mmessenger
messenger.exe
AGOBOT.GM WORM!
X
Mmgsvc
mmgsvc.exe
Spyware.Mmgsvc
U
MMhid
mmhid.dll
"This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP"
N
MMHotKey
MMHotKey.exe
Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
U
MMKeybd
MMKeybd.exe
Multimedia keyboard manager. Required if you use the additional keys
X
mmod
mmod.exe
eZula TopText adware
N
mmpti
m1mmpti.exe
Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
X
MMSystem
??
FUNNER.A worm infection
X
MMSystem
RunDll32
W32/FUNNER-A WORM!
N
mmtask
mmtask.exe
Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
Y
MMTASK
mmtask.tsk
"A check on the file\'s properties reveals ""Multimedia background task support module"". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc"
X
MMtask Service
mmtask.exe
BACKGAT.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename
N
MMTray
mm_tray.exe
MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
N
MMTray
MMTray.exe
Part of Morgan Multimedia Codecs. Only required when the codecs are used
N
MMTray2K
MMTray2K.exe
Part of Morgan Multimedia Codecs. Only required when the codecs are used
N
MMTrayLSI
MMTrayLSI.exe
Part of Morgan Multimedia Codecs. Only required when the codecs are used
X
mmxp2passion.exe
mmxp2passion.exe
MediaMotor/Popuppers adware component
X
mmxrun
msosa.exe
"Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return"
X
mmxrun
mswinindex.exe
TwoSeven SPYWARE!
X
mnklins
mnklins.exe
Transponder parasite related
X
mnpol
mnpol.exe
DOWNLOADER.DLUCA.B TROJAN!
U
MNS
MNS.exe
"Mobile_Net_Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more."
X
mnsvc
mnsvc.exe
AUTOUPDER VIRUS!
X
mnsvcsp
mnsvcsp.exe
VIRUS!
N
mobsync
mobsync.exe
"MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages"
X
MOBSYNC32.EXE
mobsync32.exe
FINERO VIRUS!
N
MOD
muamgr.exe
"MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them"
X
Modem
locatesvc.exe
variant of the W32.SPYBOT WORM!
X
Modem Driverz Updates
mdmdrv.exe
variant of the W32/SDBOT WORM!
U
MODEMBTR
MODEMBTR.EXE
Modem Booster from inKline Global to improve ISP connections
X
Modeminf
Modeminf.exe
CRYPTER.C trojan variant infection
U
ModemOnHold
MOH.EXE
NetWaiting Modem-on-Hold Application
N
ModemUtility
mdmsetpe.exe
System Tray configuration icon for Aztech modems
X
ModularConfig
syscnfg.exe
"Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside"
X
Module Call initialize
??
variant of the LOVGATE WORM!
X
Modulo 00FE0F01 Host Internet
syschost.exe
TROJ/DELF-KW TROJAN!
X
MOJNPluginSrIvcs
neomonap23.exe
variant of the W32/SDBOT WORM!
N
Money Express
moneyexpress.exe
Part of MS Money. Available via Start -> Programs
N
MoneyAgent
mnyexpr.exe
Microsoft Money
N
MoneyAgent
money express.exe
Part of MS Money. Available via Start -> Programs
N
MoneyStartUp
Money Startup.exe
Microsoft Money
N
MoneyStartUp10.0
Activation.exe
Part of MS Money 2002. Available via Start -> Programs
X
monitor
monitor.exe
"Browser hijacker, redirecting to NCM Search"
U
Monitor Apache Servers
ApacheMonitor.exe
Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
U
Monitor_Helper
monitor.exe
MyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
Monitoring Service
svchost.exe
"CONE.C VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32"
X
Monitormgt
Monitormgt.exe
GEMA TROJAN!
X
MonitorSD
SDMonitor.exe
"Max Spyware Detector, bogus ""Spyware remover"" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""spywaredetector.net"""
X
MONPluginSrIvcs
n3monap23.exe
variant of the WIN32.RBOT WORM!
N
Monstersoundtray
Freectrl.exe
Diamond Multimedia sound card control panel
X
MonTest
vccxzq.exe
W32/SDBOT-EA WORM!
U
MoodBook
mb.exe
MoodBook is a free Windows utility that brings art to your desktop
N
moon phase
moon.exe
Moon Phase - tray icon that indicates the phases of the moon
N
Morpheus
morpheus.exe
"MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes ""I have seen no instance of any since using it"""
X
morphstb
morphstb.exe
Adware downloader - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Stubby.c
X
mosearch
mosearch.exe
Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here
X
Motherboard Config
Ati2xxx.exe
W32/RBOT-AIK WORM!
X
MotherBoard Sounds
Sounds.exe
W32/RBOT-AAP WORM!
N
Motive SmartBridge
BTHelpNotifier.exe
"System tray icon for the Virtual Assistant from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required"
N
Motive SmartBridge
MotiveSB.exe
"System tray icon for the Virtual Assistant from AT&T_Broadband , used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required"
N
Motive SmartBridge
mpbtn.exe
"System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required"
U
MotiveMonitor
motmon.exe
Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required
N
MotiveSB
MotiveSB.exe
The same as Motive SmartBridge below
U
MotMon
motmon.exe
Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used?the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required
X
motoin
mm15201518.Stub.exe
Delfin_Promulgate adware variant
U
Mount Safe & Sound
Fbmount.exe
From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
X
mouse
mouse.exe
W32/Rbot-AHJ WORM!
N
Mouse 32A
Mouse32A.exe
Mouse driver to control mouse functions from Azona. Available via Start -> Programs
N
Mouse Suite 98 Daemon
ICO.EXE
Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
N
Mouse Suite 98 Daemon
pelmiced.exe
Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
X
mousebut
mousebut.exe
CRYPTER.A trojan infection
X
Mousecntl
mousecntl.exe
Crypter.C trojan variant infection
N
MouseCount
MC.exe
"MouseCount by Kittyfeet Software. ""Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year."" Not required"
X
MouseDrv
??
W32/Zoload-B WORM!
X
mousedrv
mousedrv.exe
CRYPTER.A trojan infection
X
MouseDrv
update.exe
ZOTOB.N WORM!
U
mouseElf
gnetmous.exe
Genius_NetScroll mouse driver - required if you use non-standard Windows driver features
U
mouseElf
MC.exe
System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
U
mouseElf
mouseElf.exe
System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
U
MouseImp
MImpHost.exe
"MouseImp Pro - ""A reliable assistant that turns your mouse into a simple, native but powerful controlling device"""
U
Mousinfo
mousinfo.exe
MS mouse information tool - for troubleshooting mouse problems
N
Movielink Manager Uninstall
msvcmm32.exe
Auto-update for Movielink - internet movie rental System Tray access
X
MovieNetworks
MovieNetworks.exe
MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:\Program Files\MovieNetworks directory
X
Movieplace
Movieplace.exe
MoviePlace malware
X
Mozila Firefox
firebox.exe
W32/RBOT-AIP WORM!
X
Mozilla Firefox
F1REF0X.EXE
variant of the W32/SDBOT WORM!
N
Mozilla Quick Launch
Netscp6.exeMozilla.exe
Netscape 6 and Mozilla browsers
X
MP Tcloaxs
mptcloaxs.exe
RANDEX.CT VIRUS!
X
Mp3 Loader
Sysdata.EXE /S
W32/Avette-A VIRUS!
X
MP3download
??
MatrixDialer related
U
MPEO
Csinsm32.exe
Automatic logging of installs from Norton CleanSweep - available via Start -> Programs
X
MPFExe
mcagent.exe
TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
Y
MPFExe
mpf.exe
McAfee Personal Firewall
Y
MPFExe
MpfTray.exe
McAfee Personal Firewall
X
MPL32 driver
MPL32.exe
Loony-M trojan infection
U
MplSetup
MplSetup.exe
Used by Ricoh network printers to enable network printing from the client
X
MPM Manager
MPM.exe
DONBOMB.A TROJAN!
U
MPower
MPower.exe
"MPower from MindBeat. ""Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load"". Some users swear by programs such as this but I suggest you read this article and make up your own mind"
X
MPR MSG
mprmsg32.exe
W32.MYTOB.CF WORM!
X
MPREXE
MPREXE.EXE
OPASERV.T VIRUS! Note - this is not the legitimate Mprexe.exe system file
Y
MPREXE.exe
mprexe.exe
WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don\'t know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
X
MprHTML
MprHTML.exe
variant of the VAGRNOCKER VIRUS!
X
mprocessor
mprocessor.exe
InstallDollars.com foistware
U
MPSExe
mscifapp.exe
"McAfee.com Privacy Service - ""combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"""
Y
MpsOnn
MpsOnn.exe
Canon printer driver
X
MPtask Services
mptask.exe
LALA or DOWNLOADER-BN.B or AOT VIRUSES!
N
MPTBox
MPTBOX.EXE
Cannon Multi-Pass toolbox - a button bar
X
mptsgsvc.exe
mptsgsvc.exe
"Hacker_Tool - detected by TDS-3 antitrojan as ""HackTool.Win32.Hidd.j"""
N
MPXTray
mpxptray.exe
"Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc"
X
mqbkup
mqbkup.exe
OPASERV.K VIRUS!
N
mrtMngr
mrtMngr.exe
Maintenance Release Task Manager for Intuit?s QuickBooks or Quicken
U
MRUBlaster
indexcleaner.exe
MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder
U
MRU-Blaster Scheduler
scheduler.exe
MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer
N
MRU-Blaster Silent Clean
mrublaster.exe
MRU-Blaster - performs silent cleaning of MRU lists at boot
X
MS Auto-IPSec Protection
MSASP32.exe
W32/Rbot-AER Worm!
X
MS Autoloader 32
MSAuto32.exe
SPYBOT.BD WORM!
X
Ms Builders
Wupated.exe
W32/AGOBOT-SS WORM!
X
MS Config Loader
MSWin32bck.exe
GAOBOT.AA WORM!
X
MS Config Loader
svchos1.exe
AGOBOT.R WORM!
X
MS Config Loader
svcrhost.exe
variant of the WIN32.RBOT WORM!
X
MS Config Service
Msloader32.exe
W32/Rbot-KJ WORM!
X
MS Config v13
lrbz32.exe
W32.GAOBOT.AOL WORM!
X
Ms Configuration
microsoftsa32.exe
W32.KELVIR.X WORM!
X
MS Configuration
MSFramer.exe
RANDEX.OL VIRUS!
X
MS Decryption Software
active.exe
MediaTickets adware variant
X
MS DVD DirectX Dll Drivers
mdxdl.exe
W32/SDBOT-XI WORM!
X
MS DVD DirectX Sound Drivers
msdrvdx.exe
W32/SDBOT-XJ WORM!
X
MS Explorer
mexplore.exe
YAHA.AE VIRUS!
X
MS FIREWALL
msfirewall.exe
W32/SDBOT-QH WORM!
X
MS FIREWALL
msfrewall.exe
W32/SDBOT-PU WORM!
X
MS HTML
msHtml.exe
PESTDOOR.31 VIRUS!
X
MS HTML
mslat.exe
LATINUS.SVR VIRUS!
X
MS HTML Location Class
MSHTML32.exe
W32/RBOT-YD WORM!
X
MS Internet Executor 32
MSIXEC32.exe
W32/Rbot-AEQ Worm!
X
MS lsass Startup
lsass135.exe
RBOT.WM WORM!
X
MS lsass6 Startup
lsass1356.exe
variant of the W32/SDBOT WORM!
X
MS Microsoft Socket Deamon
MSSCKD32.exe
variant of the WIN32.RBOT WORM!
X
MS MSN Menssenger 7.0
MSEXPORT.exe
variant of the W32/SDBOT WORM!
X
MS MSN Menssenger 7.0
MSMSN7.exe
W32/RBOT-ACA WORM!
X
MS Network Control
mswin.exe
DUMBA VIRUS!
X
ms ownage
winPE.exe
W32/Rbot-AJL WORM!
X
MS PLUS INC
wpad.exe
W32/MYTOB-AN WORM!
X
Ms Processe Manager
msproc.exe
RBOT.ATO WORM!
X
MS Real Player
RealPlyr.exe
RBOT.MR WORM!
X
MS Registry Service
MSRMS32.exe
W32/Rbot-AKP WORM!
X
MS Remote Procedure Call
msrpc32.exe
W32/RBOT-QL WORM!
X
MS Screen Saver
scrsave.scr
W32/Rbot-AGT WORM!
X
MS Security Authority Service
lsass.exe
W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
MS Security Hotfix
service5.exe
GAOBOT.AG WORM!
X
MS service
msservice.exe
W32/RBOT-ZG WORM!
X
MS Sound Config 16bit
sndcfg16.exe
SdBot.MB backdoor trojan
X
Ms Sound Drivers
msdrv.exe
W32/SDBOT-WR WORM!
X
Ms Spool32
MS SPOOL32.EXE
ASASSIN VIRUS!
X
MS SyS Restore
sysrestore.exe
RBOT.XM WORM!
X
Ms task manager
tskmgr.exe
SDBOT.CCD WORM!
X
MS taskbar
crssr.exe
W32/Rbot-AGO WORM!
X
MS taskbar
nts.exe
W32/RBOT-AGB WORM!
X
MS taskbar
taskbars.exe
RBOT.BRW WORM!
X
MS Taskbars
taskbars.exe
W32/Sdbot-ACV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
MS taskmanager
tskmgr.exe
W32/Rbot-AKA WORM!
X
MS UniX
navupdate64.exe
variant of the WIN32.RBOT WORM!
X
MS Unix Binary
msmq2inst.exe
W32/RBOT-YF WORM!
X
MS Unix Binary
msnq3insller.exe
variant of the WIN32.RBOT WORM!
X
MS Unix Binary
msnupdate.exe
W32/RBOT-AAM WORM!
X
MS Unix Binary
Norton2005Update.exe
variant of the WIN32.RBOT WORM!
X
MS Unix Binary
outlookexpressupdate.exe
W32/RBOT-YU WORM!
X
MS Unix Binary
trmupdate.exe
W32/RBOT-ACC WORM!
X
MS Unix Binary
win32ttb.exe
SPYBOT.OQ WORM!
X
MS Unix Binary
Win32Update.exe
W32/RBOT-BAS WORM!
X
MS Unix Binary
WinGuard.exe
W32/RBOT-ACL WORM!
X
MS Update
syshost.exe
W32/Evaman-F worm infection
X
MS Updates
aupd.exe
Spyware web downloader
X
MS Updates
mscache.exe
Spyware web downloader
X
MS Updates
syshosts.exe
W32.Mydoom.Y WORM!
X
MS Updating Utility
msupdater.exe
W32/RBOT-XR WORM!
X
MS USB 2.0 Windows Support
msusb32.exe
variant of the WIN32.RBOT WORM!
X
Ms Valud Loader
Svhots.exe
W32/AGOBOT-SP WORM!
X
ms window update
??
variant of the WIN32.RBOT WORM!
X
MS windows Data list process
MSDATLST.exe
unidentified WORM or TROJAN!
X
MS Windows procces 32
msprocces.exe
W32/Rbot-AEZ Worm!
X
MS Windows Process Class
MSPRCSS32.exe
W32/RBOT-YQ WORM!
X
MS Windows Security Updater
updater.pif
W32/RBOT-AKY WORM!
X
MS Windows Update
scguard.exe
W32/RBOT-YZ WORM!
X
MS_LARISSA
MS_LARISSA.exe
W32.Assiral WORM!
X
MS_NETD_WIN32
netd32.EXE
RANDEX.F VIRUS!
X
MS_SETUP.EXE
MS_SETUP.EXE
CHARGE VIRUS!
X
MS_Update Check
wdfmgr.exe
W32/AGOBOT-TB WORM!
X
ms64.exe
ms64.exe
variant of the WIN32.RBOT WORM!
X
MS7531
ms7531.exe
Homepage hijacker
X
MSACM
msacm.exe
W32/Opaserv-O worm infection
X
msadcheck
msadcheck32.exe
"Browser hijacker, redirecting to search-system.com"
X
MSAdmin
jdbgmrg.exe
DASMIN.A VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here
X
msadp32
msadp32.exe
Octa-B trojan infection
X
MSAgent
mshtm.exe
"Browser hijacker, redirecting to buldog-search.com"
U
msaim
msaolim.exe
MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
MSBB
msbb.exe
nCase adware
X
Msbb.exe
msbb.exe
nCase adware
X
MsBootMgr.exe
MsBootMgr.exe
BACKDOOR.VERIFY TROJAN!
X
msbsc
??
Troj/Banker-DF Trojan!
X
MSChoExE
suge.exe
variant of the Win32.Rbot WORM!
X
mscman
mscman.exe
"Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"""
U
mscn
mscn.exe
Part of the SafeChildNet internet filtering program - required if you use it
X
Mscnt
mscnt.exe
Troj/Dluca-C TROJAN!
X
Mscolour
mscolour.exe
WIN32.GEMA TROJAN!
X
MSCommX
mscommx.exe
Win32.Rbot worm variant
X
MSCONFG32.EXE
MSCONFG32.EXE
OPTIX.04.C VIRUS!
X
MSCONFG32.EXE
MSCONFG32.EXE
OPTIX.04.C VIRUS!
X
msconfig
msconfig.exe
CoolWebSearch parasite related. **Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
N
MSConfig
MSCONFIG32.EXE
"Unidentified adware, spyware or virus"
X
MSConfig
MSCONFIG35.EXE
variant of the W32.SPYBOT WORM!
X
msconfig
wins.exe
RBOT.PF WORM!
X
Msconfig lptt01 or Msconfig ml097e
msconfig.exe
"Variant of the RapidBlaster parasite (in a ""msconfig"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
X
MSConfig Manager
msupdate.exe
"CoolWebSearch parasite related,"
N
MSConfig or MSConfigReminder
msconfig.exe
"This is an entry that appears when you uncheck an item in the Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode"
X
msconfig service
MSupdate32.exe
W32.SpyBot worm variant
X
msconfig.exe
proxy.exe
variant of the WIN32.AGENT.AH downloader TROJAN!
X
msconfig.exe
uline.exe
variant of the WIN32.AGENT.AH downloader TROJAN!
X
MSConfig45
MSConfig45.exe
SDBOT.OJ WORM!
X
MSConfigr
jdbgmrg.exe
DASMIN.C VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here
X
MsConfigs
MsConfigs.exe
ALCAN.A WORM!
X
MS-Connect
arr.execdm.exegame.exemsite18.exeweb.exe
Adult content dialler - see here
X
MSCORE
syscnfg.exe
"Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside"
X
Mscsgs
MSCSGS.EXE
ZEZER VIRUS!
X
Mscsgs32
MSCSGS32.EXE
ZEZER VIRUS!
X
mscsvc.exe
mscsvc.exe
PWSTEAL.BANCOS.T and Troj/Banker-CK TROJANS!
X
Msctrl32
Msctrl32.scr
REDIST VIRUS!
X
MSCVT
MSCVT.exe
SLIDESHOW VIRUS!
X
MSDcom
MSDcom.exe
variant of the W32/SDBOT WORM!
X
msdev
msconfig.exe
"AGOBOT.AAU WORM! - Note, this is NOT the legitimate Windows System Configuration Utility as described here"
X
msdev
msdev.exe
FORBOT-CR WORM!
X
MSDLL
syscnfg.exe
"Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside"
X
Msdmxm
msdmxm.exe
Troj/Dload-DC TROJAN!
X
MSDN
nese.exe
SDBOT.AHY WORM!
X
MSDN HELP
msdn.exe
AGOBOT.AIB WORM!
X
MS-DOS Boot Service
Boot32.pif
W32/Rbot-AMF WORM!
X
MS-DOS Boot Service
boot32.pif
variant of the WIN32.RBOT WORM!
X
MSDOS Security Service
msdos.pif
W32/Rbot-AMP WORM!
X
MS-DOS Security Service
ms-dos.pif
W32/Rbot-AMR WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
MSDOS Service
MSDOS.PIF
W32/RBOT-AIY WORM!
X
MS-DOS Service
MS-DOS.pif
W32/Rbot-AII WORM!
X
MSDOS Windows Service
MSDOS.PIF
W32/Rbot-AKF WORM!
X
MS-DOS Windows Service
MS-DOS.PIF
W32/Rbot-AJW WORM!
X
Msdos32
Msdos32.pif
RECORY VIRUS!
X
msdos423
msdos423.exe
MENACE.A (or W95.SOFUNNY.WORM@M) VIRUS!
N
MSDTC
msdtc.exe
MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
X
Msemu32
Msemu32.exe
Unidentified spyware/adware/hijacker
X
mservices.exe
mservices.exe
SDBOT.WJ WORM!
X
Msfind
Msfind.exe
CoolWebSearch parasite related.
X
MSFind32
msfind32.exe
CAYAM VIRUS!
X
msfindosa.exe
msfindosa.exe
DOWNLOADER-BS VIRUS!
X
MSFTP Service Config
r3grun.exe
variant of the W32/SDBOT WORM!
X
MSFWAVTSM
FTPDev.exe
W32/RBOT-ACF WORM!
X
Msg Fixage
msgfixed.exe
SDBOT.ZD WORM!
X
MsgApi
??
Dedler-D trojan infection
X
msgb1
msgb1.exe
Win32.Dluca.gen trojan infection
N
MsgCenterExe
RealOneMessageCenter.exe
RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way.
X
msgex32
msgex32.exe
W32/APPFLET-A WORM!
X
Msgmgr
??
BABYBEAR VIRUS!
X
msgserv_
Syss.exe
FANTA TROJAN!
X
Msgsrv16
Msgsrv16.exe
DELF family of VIRUSES!
Y
MSGSRV32.exe
msgsrv32.exe
"Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background"
X
MsgSvcMgr32
cmdzxdll.exe
W32/Rbot-AEK Worm!
X
msgsvr32
msgsvr32.exe
"Added as the result of the DEADHAT.B VIRUS! Note - not to be confused with the valid ""msgsrv32.exe"" file which resides in the same directory (C:\Windows\System) on a Win9x/Me machine"
U
MSGTAG
MSGTAG.exe
MSGTAG is an application that tells you when your emails have been received and opened.
X
Msgtray
sys16.exe
unknown VIRUS!
X
Mshelp32
mshelp32.exe
CoolWebSearch parasite variant
X
MSHT@
MSHT@.EXE
MAGISTR.A VIRUS!
X
MS-HTML
??
LATINUS.15 VIRUS!
X
msident
msident.exe
Unidentified adware or trojan
X
msidle
msidle.exe
W32/Opaserv-O worm infection
X
MsIdle32.exe
MsIdle32.exe
BACKDOOR.VERIFY TROJAN!
X
MSIdll
winmp.exe
variant of the WIN32.RBOT WORM!
X
MSIE Parsers
MSIE32ab.exe
SDBOT.MV WORM!
X
msiew
mseiw.exe
LITTLOG TROJAN!
X
MSIEXEC
MSIEXEC.EXE
VBS/YOSENIO-A VIRUS!
X
MSIEXEC
MSIEXEC32.exe
AINESEY.A VIRUS!
X
MSIMN32
MSIMN32.EXE
Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx
X
Msinet
Msinet.exe
W32/Rbot-AOA WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
MSInfo
AVBgle.exe
W32.NETSKY.O WORM!
X
MSInfo
msinfo.exe
ALADINZ.M VIRUS!
X
MSInstall
smvss.exe
TROJ/DEDLER-G TROJAN!
X
msjava service
xpcd.exe
SDBOT.VM worm infection
U
MSKAGENTEXE
MskAgent.exe
Part of McAfee Spamkiller
X
MSKCES32
??
CLONER VIRUS!
U
MSKDetectorExe
MSKDetct.exe
Part of McAfee Spamkiller
X
MSkernel32
??
TUXDER VIRUS!
X
MSKernel32
MSKernel32.vbs
LOVELETTER (I LOVE YOU) VIRUS!
U
MSKExe
spamkiller.exe
McAfee SpamKiller
X
mskj
mskj.exe
Kaemon TROJAN!
U
MSKServerExe
MSKSrvr.exe
Part of McAfee Spamkiller
X
mslagent
mslagent.exe
Troj/Wintrim-F TROJAN!
X
MSLARISSA
MSLARISSA.pif
ASSIRAL.B WORM!
X
MSLog
MicrosoftLog.exe
variant of the W32/SDBOT WORM!
X
Mslogon lptt01 or Mslogon ml097e
mslogon.exe
"Variant of the RapidBlaster parasite (in a ""Mslogon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
MsManager
msmgr32.exe
YAHA.AF VIRUS!
X
msmanager32
msmngr32.exe
RANDON-R (or WOMANIZ.A) VIRUS!
X
msmautoprotect
msmssgs.exe
TROJ/BIFROSE-AJ TROJAN!
X
msmc
??
ClientMan parasite variant
X
msmc
mscpbo.exe
ClientMan parasite variant
X
msmc
msmc.exe
ClientMan parasite variant
X
MSMcAfeee
Avsynmgr32e.exe
FRAMAR VIRUS!
X
MSMcAfeeh
Avsynmgr32h.exe
FRANGO VIRUS!
X
MSMcAfeeS
Avsynmgr32S.exe
VOLAC or VOLAC.DR VIRUSES!
X
MSMessnger
msnupd.exe
W32/Rbot-ADY Worm!
X
msMGR
rtkmsg.exe
W32/SDBOT-BPY WORM!
X
Msmgt
msmgt.exe
Total Velocity adware/hijacker
X
MSMNTJBE
MSMNTJBE.EXE
Troj/Bancos-EF TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
MSMNTMTS
MSMNTMTS.EXE
TROJ/BANKER-GZ TROJAN!
X
msmon
msmon.exe
variant of the Win32.GEMA.D TROJAN!
U
MSMSGS
msmsgs.exe
"Windows Messenger utility. If you don\'t use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck ""Run this program when Windows starts"""
X
MsMsgSrv
msmsgsrv.exe
BACKDOOR-CQO TROJAN!
X
MSMsgSvc
MSMSGSVC.exe
"Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!"
X
msmsngr
msmsngr.exe
W32/DOPBOT-B WORM!
X
MSN
ctfmoons.exe
SPYBOT.HI WORM!
X
MSN
msn16.exe
W32/SDBOT-VN WORM!
X
MSN
msnmesengers.exe
W32/Rbot-ME worm infection
X
MSN
msnmesengers.exe
RBOT-ME WORM!
X
msn
msnmsg.exe
W32/Rbot-GO worm
X
MSN
msnmsgr.exe
W32.Mytob or W32.Mytob.B WORM! **Note - this is not the valid MSN_Messenger utility
X
MSN
msnmsgs.exe
W32/Rbot-KL worm infection
X
MSN
msnsgr.exe
unidentified WORM or TROJAN!
X
msn
msnsvc.exe
variant of the W32/SDBOT WORM!
X
msn
system32.exe
KITRO.A VIRUS!
X
MSN 9.0 Plus
??
W32/Rbot-ALY WORM!
X
MSN Administration For Windows
msnadp32.exe
BROPIA.W WORM!
X
MSN ang
cssrss.exe
W32/FORBOT-CE WORM!
X
MSN BETA
service.exe
RBOT.AUU WORM!
X
Msn Config
msngf.exe
W32/RBOT-QG WORM!
X
Msn Configuration Loader
msngms.exe
W32.KELVIR.T WORM!
N
MSN Internet Access
trayclnt.exe
"Quick way to connect to MSN internet service - replaces ""MSN Quick View"" from V5.6 onwards"
X
MSN Manager
cvss.exe
W32.SpyBot worm variant
X
MSN Manager
mscmgr.exe
Unidentified malware - causes multiple browser windows to open
X
MSN Message Background loader
msnmesg.exe
variant of the WIN32.RBOT WORM! Note: File name may be different with some of the other variants.
X
MSN Messages
msnmesg.exe
W32/RBOT-ACN WORM!
X
MSN Messanger
msnmsng.exe
SDBOT.XN worm infection
X
Msn Messeng
windns.exe
variant of the WIN32.RBOT WORM!
X
MSN Messenger
IExplorer.exe
Troj/Banker-EU TROJAN!
X
MSN messenger
messenger.exe
"Unidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread"
X
MSN MESSENGER
msmmsgr.exe
W32.KELVIR.Q WORM!
X
MSN Messenger
msmsgs.exe
"TROJ/DLOADER-LN or ZLOB-C and Troj/ZlobDrop-C TROJANS! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!"
X
MSN Messenger
msmsgs.exe
Zhopa TROJAN!
X
MSN Messenger
msnmsgr.exe
AGOBOT.AOQ WORM! - Note - this is not the valid MSN Messenger utility as described here
X
Msn Messenger
msnmsgs.exe
"TROJ/LOONY-P TROJAN or the W32.MYTOB.AD WORM! - NOTE: not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!"
X
MSN Messenger
msnmsngr.exe
variant of the WIN32.RBOT WORM!
X
MSN Messenger
Reosmsngr.exe
variant of the W32.SPYBOT WORM!
X
MSN messenger service
mssgs.exe
"Unidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread"
X
Msn Messenger Update
msnupdate.exe
variant of the WIN32.RBOT WORM!
X
MSN Messenger User Controls
msmsgr.exe
W32.Kelvir.HI WORM!
X
Msn Messengers
MSNMSGR.EXE
RBOT.KX worm infection
X
MSN MMISSENGER
mssmmspgr.exe
W32.KELVIR.AJ WORM!
X
Msn Patch
msndp.exe
RBOT.AAI WORM!
X
Msn Patches
msndr.exe
variant of the W32/SDBOT WORM!
X
Msn Plus Updater
msnplus.exe
W32/RBOT-MU WORM!
X
Msn Processe Manager
msni32.exe
W32/Rbot-ADX Worm!
N
MSN Quick View
Msndc.exe
Quick way to connect to MSN internet service
X
MSN Registry loader
msmnwin.exe
W32.Kelvir.FK WORM!
X
MSN Service
amsnmsgrs.exe
variant of the W32/SDBOT WORM!
X
Msn Service
matrixcam.exe
MYTOB.JH WORM!
X
MSN service
msnmgr16.exe
variant of the WIN32.RBOT WORM!
X
MSN service
NTDKRN.EXE
RBOT.UJ WORM!
X
Msn Service
raloded.exe
W32/Mytob-DY WORM!
X
MSN Start
msnmsgr7.exe
W32/RBOT-PH WORM!
X
MSN Update
msn32.exe
RBOT.AHN WORM!
X
Msn Update Manager (Sp2)
MSMSGS.EXE
W32/AGOBOT-NL WORM!
X
Msn Update Service
userx.exe
W32.Mytob.JF WORM!
X
MSN Updater
msnms.exe
FORBOT-CG WORM!
X
Msn Updater
msnplugins.exe
W32/RBOT-HS WORM!
X
Msn Updater
windatemanager.exe
SDBOT.TS WORM!
X
MSN UPDATERS
virtualmemory.exe
Rbot-JK worm infection
X
MSN Updates
spoolsv32.exe
variant of the WIN32.RBOT WORM!
X
msn.exe
son.exe
Troj/StartPa-GS TROJAN!
X
MSN32 X Service
MSN32x.EXE
unidentified WORM!
X
MSN8m Startup
msn8m.exe
variant of the WIN32.RBOT WORM!
X
msnager32
svchostt.exe
WOMANIZ.E TROJAN!
N
msnappau
msnappau.exe
"Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to ""update"" the toolbar"
X
Msnarrator
msnarrator.exe
NARAT.A VIRUS! - also identified as MPGCOM Toolbar adware
X
MSNavWH
MSWkwrH.exe
W32/ANAV-A WORM!
X
MSNET
msnet.exe
BOA VIRUS!
X
MsnExplorer
MSEXPLOREN.EXE
TROJ/BDOOR-EB TROJAN!
X
MsnExplorer
SHCH.EXE
TROJ/BDOOR-EB TROJAN!
X
MsnExplorer
SVCHST.EXE
TROJ/BDOOR-EB TROJAN!
X
MsnExplorer
winagent.exe
TROJ/BDOOR-EQ TROJAN!
X
MSNGrabber
MSNgrabber.exe
W32.ENVID.A WORM!
X
msngta32
msngta32.exe
variant of the WIN32.RBOT WORM!
N
MSNIA
MSNIASVC.EXE
Added with MSN version 9. Resets certain internet settings upon bootup and can\'t be disabled via MSCONFIG
"MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck ""Run this program when Windows starts"""
X
MsnMsgr
MsnMsgrs.exe
W32/NETSKY-AD WORM!
X
msnmsgr32-.exe
msnmsgr-.exe
W32.SpyBot worm variant
X
MSNMSGR5
MSNMSGR5.exe
RBOT.PQ worm infection
X
MSNMSGRE
swef.bat
IRC worm or backdoor trojan!
X
MSNMSGRE
swef.bat
IRC worm or backdoor trojan!
X
MSNMSGRR
swin.bat
IRC backdoor trojan or worm!
X
MSNMSGRS
swe.bat
IRC worm or backdoor trojan!
X
MSNMSGRS
swiss.bat
IRC worm or backdoor trojan!
X
MSNMSGRS1
swed.bat
IRC worm or backdoor trojan!
X
msnmsgsgs
msnmsgsgs.exe
"""Catal"" alias Spy.Delitall.B backdoor TROJAN!"
X
msnmsgy
??
TROJ/BANKER-EQ TROJAN!
X
MSNPluginSrIvcs
n3vasap23.exe
variant of the WIN32.RBOT WORM!
X
MSNPluginSrvcs
p6.exe
SDBOT.AKJ or W32/Rbot-VJ WORM!
X
MSNPluginSrvcs
sagate.exe
SDBOT.AKJ WORM!
N
MSNProxy
MSNProxy.exe
MSNProxy - SOCKS4 proxy for MSN Messenger. Desktop shortcut available
X
msnsched2
msnsched2.exe
W32.SPYBOT.NNT WORM!
X
MSNService
MSNService.exe
CARPET.C VIRUS!
X
msnsgs
msnsgs.exe
Troj/Cheuko-B TROJAN!
X
msnshed
msnshed.exe
W32/RBOT-YN WORM!
X
MSNSysRestore
pc32.exe
variant of the MASTAK VIRUS!
X
msnToolbaar
msnmsgesc.exe
RBOT.BMF WORM!
X
MSObject32
MSObject32.js
PUN VIRUS!
X
Msoffice
msoffice.hta
Hijacker - redirecting to Searchdot.net
X
MSOffice
services.exe
"Browser hijacker. The file is placed in a newly created MSOffice folder in System32 - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
MSOfficeCfg
msocfg.exe
Premium rate adult material dialer
X
MSOfficeCfg
navchk.exe
Premium rate adult material dialer
X
MSOfficeCfg
qservice.exe
Premium rate adult material dialer
X
MSOfficeCfg
shman.exe
Premium rate adult material dialer
X
MSOfficeCfg
ssvr.exe
Premium rate adult material dialer
X
M-soft Office
M-soft Office.hta
HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
X
MSOleath32
winss.exe
KATHER TROJAN!
X
MSOOBD
MSOOBD.EXE
MAGISTR.A VIRUS!
X
mspaint.exe
check32.exe
WIN32.AGENT.AH TROJAN!
X
Mspatch69
??
MPROX VIRUS!
X
Mspatch89
cnqmax.exe
RANDEX.P VIRUS!
X
msping
msping.exe
Trojan.Floodblack Trojan!
X
MSPluginSrvc
p3.exe
W32/RBOT-WV WORM!
X
MSPLUS
msplus32.exe
W32/MYTOB-AM or W32/MYTOB-CL WORMS!
X
MSPQFile
MSA****.TMP
Homepage hijacker. See here for more information. **** can be anything
X
MSPRO32
??
W32.Iberio WORM!
X
MSPRO32
pnp.exe
ZOTOB.O WORM!
X
MSprotect.exe
MSprotect.exe
W32/Dabyrev-A WORM!
U
mspwr
pupstman.exe
"""Transparent icon background"" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)?"
U
mspwr
pupxpman.exe
Related to Ashampoo's PowerUp_XP
N
MSPY2002
ImScInst.exe
"Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word"
X
MSR
msr.exe
AGOBOT.RT WORM!
X
Msrc
Msrc.exe
KRYPTONIC GHOST VIRUS!
X
msreg.exe
msrege.exe
ZINX VIRUS!
X
msReg32 Loader
msreg32.exe
AGOBOT.IU WORM!
X
MSREGIT
Msgp.exe
KRYPGHOS (Kryptonic Ghost) VIRUS!
U
MSRegScan
ETNKL.exe
ComKeylogger surveillance software. Uninstall this software unless you put it there yourself.
U
MSRegScan
SGP.exe
"SpyGator is a spyware program that monitors Internet activity, logs keystrokes, and takes screenshots."
X
MSRegSvc
regsvc32.exe
Homepage hijacker that changes your homepage to an adult content site
X
msrepair
msrepair.exe
SDBOT.AFL WORM!
X
msresear
??
Troj/Weasyw-B TROJAN!
X
msresearch
msresearch.exe
TROJAN! - 180SearchAssistant adware related
X
msrundll
msrund1l32.exe
Backdoor.Binghe TROJAN!
X
MS-RunKey
arr.exe
MS-Connect dialler/hijacker
X
msrunocx32
msrunocx32.exe
SKUS VIRUS!
X
Msrv32
Msrv32.exe
AGOBOT-NB WORM!
U
MSSCDL
MSSCDLL.exe
SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!
X
msserv
lvsrev.exe
TROJ/BROWMON-B TROJAN!
X
msserv
msserv.exe
TROJ/BLACKLOG-A TROJAN!
X
msserv32
msserv32.exe
W32/RBOT-ACK WORM!
X
msservice
msserv.exe
HYD VIRUS!
X
mssfos
sfool.exe
W32.Randex.EUS WORM!
X
MSSGisg
??
RANKY.N TROJAN!
X
MSShow
MSShow.exe
Troj/QQRob-M TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
MSSHVC
MSSHVC.exe
NUFFY.A VIRUS!
X
mssoul
msmscc2.exe
"Win32.Dapizl.A banker WORM!: ( a ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
X
mssp3
mssp22.exe
TROJ/IBANK-D TROJAN!
X
MSSQL
Mssql.exe
SDBOT WORM!
X
Msstart
msstart.exe
LIVUP.C VIRUS!
X
MSStartOptimizer
Iexpres.exe
POLDO.B VIRUS!
X
MSStartOptimizer
WINUPD.EXE
"Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return"
X
msstask
msstask.exe
MYPARTY VIRUS!
X
mssurfer lptt01 or mssurfer ml097e
mssurfer.exe
"Variant of the RapidBlaster parasite (in a ""surfer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware"
X
mssvc
??
PSK VIRUS!
X
MSSVC
svcsys.exe
FATOOS-C TROJAN!
Y
MSSVC.EXE
MSSVC.EXE
"Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection"
X
mssvc32
mssvc32.exe
W32/Agobot-ME WORM!
X
mssys
mssys.exe
MYSS.B VIRUS!
X
mssysint
comime.exe
TROJ/NETSNAKE-I TROJAN!
X
mssysint
Iexplore .exe
PWSTEAL.ABCHLP and PSPIDER.310.B VIRUSES! Note - this is not the valid Internet Explorer (iexplore.exe)
X
mssyslanhelper
msmsgri32.exe
RANDEX.D VIRUS!
X
MsSystem
msdos.exe
Adult content downloader - see here
X
MsSystem
mssys.exe
VANTA.A VIRUS!
X
MSSYSTEM
svcsys.exe
FATOOS-C TROJAN!
X
Mstapi
Mstapi.exe
Keylogger trojan
X
Mstask
mstask.exe
"OPASERV.N VIRUS! Note - this is not the ""Scheduling Agent"" and the executable resides in C:\Windows or C:\WINNT"
X
mstask
mstask.exe
"Browser hijacker, redirecting to find-more.net"
X
MSTask
run_dll.exe
Yuupsearch adware
X
MStask
svchost.exe
"TROJ/LDPINCH-BV TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
MSTaskbar 32
tbsvc32.exe
RBOT.BQZ WORM!
X
mstasks
mstasks.exe
PWSTEAL.OMERSTROKE TROJAN!
X
Mstng32
MSTng32.exe
TANG VIRUS!
X
MSUpdate
criticalUpdate.exe
Affilred adware
X
Msupdate
expIorer.exe
WIN32.TACTSLAY.A TROJAN!
X
msupdate
msupdate.exe
W32/RBOT-MZ WORM!
X
Msupdate
outIook.exe
WIN32.TACTSLAY.A TROJAN!
X
MSUpdate
svchosthlp.exe
BLASTER.T VIRUS!
X
Msupdate
svchosts.exe
variant of the WIN32.TACTSLAY TROJAN!
X
Msupdate
svcrhost.exe
WIN32.TACTSLAY.A TROJAN!
X
Msupdate
svcshost.exe
WIN32.TACTSLAY.A TROJAN!
X
msupdate
update.exe
variant of the W32/SDBOT WORM!
X
MSUpdate
wupd.exe
ALADINZ.M VIRUS!
X
MSupdate.exe
??
CoolWebSearch parasite related.
X
MSUpdateDevKit
axfd.exe
W32/SDBOT-ZD WORM!
X
MsUpdater System
udpsys32.exe
RBOT.AAA WORM!
X
MSupdater.exe
??
CoolWebSearch parasite related.
X
msupdates
msupdt.exe
W32/Rbot-JO worm infection
X
MSUpdSrv
msupdsrv.exe
"Browser hijacker, redirecting to a porn site"
X
msurl
msurl32.exe
CRYPTER.A trojan infection
X
msuser32.exe
msuser32.exe
ANDROV VIRUS!
X
MsVBdll
MsVBdll.pif
W32.Aimdes.A WORM!
X
MsVBdll
sys32dll.exe
W32.Aimdes.B or W32.Aimdes.C WORM!
X
MSVBVM60
MSVBVBM60.pif
SCOLD.C WORM!
X
MSVBVM60
msvbvm60.pif
W32/SCOLD-B WORM!
X
msvc32
msvc32.exe
ClientMan parasite variant
X
msvc32
msvc32.exe
W32/AGOBOT-NT WORM!
X
msvcc
msvchost.exe
XOMBE VIRUS!
X
MSVersion
??
POPMON.A VIRUS! - also known as PopMonster adware
X
msvload32
msvload32.exe
W32/RBOT-ACI WORM!
X
msvsc32
msdev.exe
W32/RBOT-GJ WORM!
X
MSVsmt
rpcxctx.exe
unidentified WORM or TROJAN!
X
MSVSync
videosync.exe
W32.SpyBot worm variant
X
MSVXD
MSVXD.EXE
DATOM.A VIRUS!
X
msw
msw.exe
Abcsearch.com/DealHelper adware variant
X
mswave
mswave.exe
CRYPTER.A trojan infection
X
Mswavedll
mswavedll.exe
CRYPTER-C TROJAN!
U
MSwheel
mswheel.exe
Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
X
MSWin
mswin.exe
BANKER-CU TROJAN!
X
Mswincfg
Mswincfg32.exe
BACKDOOR.CYBSPY TROJAN!
X
MsWindows SysDate
sysmsvc.exe
W32.Spybot.FCD WORM!
X
MSWindows Syspg
mspg32.exe
W32/Rbot-TB WORM!
X
MSWindowsUpdate
Systern.exe
W32/Rbot-AFD Worm!
X
Mswinpid32
mswinpid32.exe
Win32.Lapos.A TROJAN! This is a a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
"New variant of the RapidBlaster parasite (in a ""Msyss"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Msys32
morfitwebentrance.exe
"Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage?"
X
MSysDrv
msdrv.exe
Win32.VB.wf backdoor TROJAN!
N
MtdAcq
MtdAcq.exe
"Creative_MediaSource ""Sound Sniffer"", monitors the drive for new media files then automatically adds them to the media library."
X
Mtr2
mtr2.exe
KRYPTONIC GHOST VIRUS!
U
MUAL
mual.exe
Millesky video mail updater and launcher
U
muamgr
muamgr.exe
"Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs"
U
MultiCAM Initializer
MCamBoot.exe
The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled
U
Multi-function keyboard
GWHotkey.exe
"Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)"
X
Multimedia Codecs
mcc.exe
TROJ/DLOADER-MB TROJAN!
X
Multimedia extensions
??
Troj/SmutSrch-A Trojan!
X
Multimedia extensions
mservice.exe
EasySearch adware
U
Multimedia KBD
MMKeybd.exe
Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as Keyboard Manager
U
MULTIMEDIA KEYBOARD
MMKeybd.exe
Multimedia keyboard manager. Required if you use the additional keys. Can also be listed as Keyboard Manager
U
MultiRes
MultiRes.exe
MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP
U
MUPS
MUPS.exe
Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions
Y
murphy shield
lmgui.exe
Firewall part of BitDefender virus scanner/firewall
ScreenScenes MagicWaterfall screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
U
mwavscan
mwavscan.com
"MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive."
N
MWProEng
MWProEng.exe
Logitech Mouseware Pro software - only required when using special functions
N
MWSnap
MWSnap.exe
MWSnap - screen capture utility. Start manually when required
X
mwsoemon
mwsoemon.exe
"""My Web Search"" malware"
X
Mwsvm
mwsvm.exe
SeekSeek search hijacker related - as seen here
X
MxHLp32
MxHLp32.exe
variant of the VAGRNOCKER VIRUS!
U
MXO Auto Loader
MXOaldr.exe
Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
U
MXOBG
MXOALDR.EXE
Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
U
MxRunner
MxRunner.exe
EasyUninstall from Aladdin Systems (formerly by Ontrack)
X
My Agent
msagent.exe
NEGASMS.A VIRUS!
X
My App
SMSSvc.exe
NEGASMS.A VIRUS!
X
My Search Bar Eq
S4BAREQ.EXE
MySearch bar parasite
X
MyAccessMedia
??
"My AccessMedia toolbar related, stealth installed!"
U
MyAgtTry
MyAgtTry.exe
System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
X
Myapp
??
FATEE.B VIRUS!
X
Myapp
service.exe
Homepage hijacker
X
MyAV
avpguard.exe
W32.NETSKY.J WORM!
Y
MyCIO Agent Service
myagtsvc.exe
McAfee VirusScan ASaP Agent service
U
myCIO.com ASaP
MyAgtTry.exe
System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
N
myCIO.com Splash
Splash.exe
Splash screen for McAfee VirusScan ASaP on-line scanner
X
MyCometCursor
MYCOME~1.EXE
Comet Cursor adware
X
MyDailyHoroscope
MYDAIL~1.EXE
eConfidence MyDailyHoroscope foistware
X
MyDailyHoroscope
MyDailyHoroscope.exe
eConfidence MyDailyHoroscope foistware
X
MyFastAccess
myfastupdate.exe
My-Fast-Access toolbar updater
U
MyIE.exe
MyIE.exe
MyIE2/Maxthon browser related
X
MyLife
CmdServ.exe
HOLAR.A VIRUS!
U
myNetWatchman
nwclient.exe
"Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running"
X
MyPointsPointAlert
??
"""With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles"". Dubious privacy policy"
U
myprint mileage
mpm.exe
Reports battery status on a portable printer
X
MySLScan
msvc32.exe
W32/FORBOT-EH WORM!
X
mysoft
winexplor.exe
"Browser hijacker, also detected as the TROJ/STARTPA-JR TROJAN!"
U
MytekSystrayExePath
MyTekSystray.exe
MyTek system tray - web site providing computer tech support in Australia
X
MyTotalSearch Email Plugin
mtsoemon.exe
MyTotalSearchBar adware
X
MyVBApp
SysNT.exe
ReferAd adware
X
MyVirt.exe
MyVirt.exe
REMADM-C TROJAN!
U
MyVitalAgent
VtlAgent.exe
"MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs"
X
MyWebSearch Email Plugin
mwsoemon.exe
MyWebSearch parasite
U
N2PTray
Net2fone.exe
"An Internet telephony application. Needed only if you have an account at Net2Phone, Inc"
N
NADaemon
NADAEMON.EXE
"Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after ""digital rights management"". One user reports disabling it has no detrimental affect - not required"
N
Naggerrunkey
nagger.exe
Packard Bell Free Internet Signup screen
Y
Naimagent_service
EPOAgentnaimas32.exe
"Networked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages"
Y
Naimagent_UI
??
Workstation background program for Network Associates? McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
X
Name
Iexplorer0.exe
THREADSYS VIRUS!
X
NAP32
NAP32.exe
Premium rate adult content dialer
X
Narrator
??
QOOLOGIC TROJAN!
X
Natal
Natal.scr
OPASERV.AE VIRUS!
X
NAV
RuxDLL32.exe
MAPSON.D VIRUS!
X
nAv AGENT
??
"RIOSYS VIRUS! Note the lower-case ""n"" and ""v"" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes"
Y
NAV Agent
navapw32.exe
Norton Anti-Virus's background scanning process
X
NAV Agent
systems.exe
TARNO.C VIRUS! Note - this is not the valid Norton Antivirus entry of the same name
X
NAV Agent
winsnav.vbs
W32.ANPES WORM!
X
NAV Agent
wmilib32.exe
Troj/VB-XU TROJAN!
X
NAV Auto Prot
navprot1.exe
RBOT.ZAC WORM!
X
NAV Auto Protect
dnsserv.exe
variant of the W32/SDBOT WORM!
X
NAV Auto Protect
mcafee32.exe
variant of the W32.SPYBOT WORM!
X
NAV Auto Protect
msfwe1.exe
variant of the WIN32.RBOT WORM!
X
NAV Auto Protect
navprotect.exe
variant of the WIN32.RBOT WORM!
X
NAV Auto Update
Navautoupdate.exe
SPYBOT VIRUS!
X
NAV Auto Updates
csrssp.exe
variant of the W32/SDBOT WORM!
X
NAV Auto Updates
navupdaters.exe
W32/RBOT-UN WORM!
X
NAV Auto Updates
navupdaterx.exe
variant of the WIN32.RBOT WORM!
X
NAV Auto Updates
navwindows.exe
variant of the W32/SDBOT WORM!
X
NAV Auto Updates
slserver.exe
variant of the W32/SDBOT WORM!
X
NAV Auto Updates
slserves.exe
variant of the W32/SDBOT WORM!
N
NAV CfgWiz or NAV Configuration Wizard
cfgwiz.exe
"Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it"
U
NAV DefAlert
DefAlert.exe
Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
X
NAV Live Update
??
DEBORMS.C VIRUS! <filename> represents the path to the worm. Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec
X
NAV Scan Service
NAVSCAN32.EXE
SDBOT.VG worm infection
X
NAV_Update
NAV_Update.exe
Unidentified WORM or TROJAN!
X
NavAgent32
lasvr32.exe
FEMOT.D VIRUS!
X
NavAgent32
SCardSvr32.Exe
MOFEI.B VIRUS!
X
navapp
navapp.exe
NavExcel adware variant
Y
navapw32
navapw32.exe
Norton Anti-Virus's background scanning process
X
NAVCheck
navchk.exe
Premium rate adult material dialer
X
NAVCheck
shman.exe
Adult material premium rate dialer
U
Naviscope
naviscope.exe
"Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more"
X
NaviSearch
nls.exe
eXact Advertising BargainBuddy/NaviSearch adware
X
navman_20
sysnav32.exe
CoolWebSearch parasite related.
X
NAVNet
??
Unidentified adware
X
navp.exe
navp.exe
W32/AGOBOT-OE WORM!
X
NavPass
NavPass.exe
Free system for gaining access to and downloading from adult content web-sites
N
NavRegReminder
NavLoad.ini
"Corel, HP or ScanSoft registration reminder; not required"
X
NavScan
??
OBSORB VIRUS!
X
NAVSCAN32.EXE
NAVSCAN32.exe
W32/SDBOT-DO WORM!
X
NAVSCANNER32
NAVSCANNER32.EXE
RBOT.QC WORM!
X
NAVUpd
??
NAVU VIRUS!
X
nawadll32
nawadll32.exe
W32/Sdbot-ZI Worm!
X
nawdll32
nawdll32.exe
W32/Sdbot-ZM Worm!
N
NB Common Dialog Enhancements
COMDLGEX.EXE
"Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs"
N
NB Start Menu
STARTM.EXE
Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
N
NB Windows Patterns
WINDBKGND.EXE
"Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows"
U
NBJ
NBJ.exe
Ahead Nero BackItUp backup program. Only required for if you have scheduled back-ups
U
NbkCtrl
NbkCtrl.exe
Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
X
NBT System alias
??
variant of the RANDON.AN WORM!
X
Ncao
osoa.exe
PurityScan/Clickspring adware
X
Ncao
urpo.exe
PurityScan/Clickspring adware
N
NCD
ncd.exe
Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
N
NCS_SS
Csinsm32.exe
Same as CleanSweep Smart Sweep-Internet Sweep
X
NDAv
csnss.exe
W32.Serflog.C WORM!
X
NDAv
svhost.exe
W32.Serflog.C WORM!
X
NDIS Adapter
lsass2.exe
WOOTBOT.CW WORM!
X
NDIS Adapter
ndis.exe
SDBOT.VF worm infection
X
NDIS Adapter
servenxpp.exe
W32/FORBOT-GP WORM!
X
NDIS Adapter
servenxpp.exe
W32/Forbot-GP WORM!
X
NDIS Adapter
windows.exe
W32/FORBOT-BR WORM!
X
NDplDeamon
nstask32.exe
RANDEX.E WORM!
X
NDplDeamon
winlogin.exe
RANDEX.E WORM!
U
NDPS
DPMW32.EXE
Novell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature
X
NDrv
NDrv.exe
PurityScan/Clickspring adware
U
NDSTray
NDSTray.exe
"ConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have."
N
Necbar
Necbar.exe
"Nec Assistant; Ark's Navigator, a graphical interface for NEC computers"
Y
NECMFK
necmfk.exe
NEC wireless keyboard driver
U
Necutray
Necutray.exe
"Driver for external USB storage devices (hard drives, flsh disks, etc)"
X
nero
nrchk.exe
Premium rate adult content dialer
X
Nero
shch.exe
variant of the TROJ/BDOOR-EB TROJAN!
X
Nero Updater.6.12
wmp9.exe
W32/Agobot-AAG Worm!
X
Nero.ma
??
JONBARR.D VIRUS! where <digits> is 2 or 3 random digits
X
NeroAutoStartClient
NeroASM.exe
AGOBOT.VG WORM!
U
NeroCheck
nerocheck.exe
"Associated with ""Nero Burning Rom"" CD writing software. Checks for driver issues"
X
NeroCheck
regedit.exe
"DOOMJUICE.B VIRUS! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)"
U
NeroFilterCheck
NeroCheck.exe
"Associated with ""Nero Burning Rom"" CD writing software. Checks for driver issues"
X
NeroLoader
NeroLoader.exe
Troj/Bancban-EJ TROJAN!
N
NeroNETTrayIcon
NNServiceCtrl.exe
System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network
X
NeroUpdater6.8
winjava.exe
AGOBOT.AMK WORM!
X
Net
WINREG.EXE
ASSASIN.D VIRUS!
U
Net Accelerator
NetAccelerator.exe
"Rizal NetAccelerator - ""Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???"". Only required if you find it helps improve your performance"
U
Net Activity Diagram
nad.exe
Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
X
NET Bios Stats
ntbstats.exe
W32/Sdbot-ZX WORM!
U
NetAccelerator
NetAccel.exe
"NetAccelerator is a ""software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance"
X
NetAdm7
NETADM7.EXE
BANCOS.F VIRUS!
X
Netapi
Netapi.exe
NETDEVIL.14 (NetDevil 1.4) VIRUS!
X
netapi32
netapi32.exe
unidentified TROJAN!
X
NetApp
winserv.exe
SHADOWTHIEF VIRUS!
X
Netbios Helper
nbthlp.exe
PWS-BANKER.Y password stealing TROJAN!
X
netconfig
netconfig.exe
NETCONF VIRUS!
U
NetCruiser Dialer
NCDialer.exe
"NetCruiser Dialer from NetCruiser Software. ""An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"""
X
netdaemon
netdaemon /v
"Malware designed to ""kill"" a number of antispyware applications: (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)"
X
netdll32
netdll32.exe
CRYPTER.A trojan infection
X
netdllex
netdllex.Exe
CRYPTER.A trojan infection
X
NetDy
VisualGuard.exe
W32.NETSKY.N or W32.NETSKY.W WORM!
X
NETFP32.EXE
NETFP32.EXE
TrojanDownloader.Win32.Agent.cd
U
NetGuard
NetGuard.exe
FBM Software ZeroSpyware 2004 spyware detector and remover; real time monitor.
N
Net-It Launcher
NILaunch.exe
Net-It - web publishing software
U
Netlimiter
Netlimiter.exe
"Netlimiter - ""An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."""
N
Netline User
netchk.exe
"Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example"
X
NetLink
netlink32.exe
GAOBOT.WO WORM!
X
NetLogon
userint.exe
W32/SDBOT-BC WORM!
U
NetManageImport
nmcpdata.exe
NetManage business software related
X
NetManagerService
ntss.exe
BESTPICS.A VIRUS!
X
NetMeter
NetMeter.exe
NetRatings Premeter spyware
X
NetMon
netmon.exe
W32.MIMAIL.M WORM!
X
Netmonw
Netmonw.exe
TROJ/BDOOR-FX TROJAN!
U
netmsg
netmsg.exe
"Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well."
NetPerSec - measures the real-time speed of your Internet connection
X
NetPumper
NetPumperIEProxy.exe
"NetPumper download manager - bundles Cydoor and SaveNow adware, see here"
X
NetReach
nrcheck.exe
unidentified VIRUS!
X
Netropa Internet Receiver
Netropa.exe
Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
U
NetRun
NetRun.exe
"NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost"
N
Netscape Messenger
NETSCAPE.EXE
"In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed"
N
Netscp6
Netscp6.exe
Netscape 6
U
NetScreen-Remote
SafeCfg.exe
NetScreen_Remote VPN Client Software
X
NetService
ntsvc.exe
Troj/QQPass-DU TROJAN!
X
NetService
ntsvc.exe
Troj/QQPass-DU TROJAN!
X
NETServices
csxrs.exe
variant of the W32/SDBOT WORM!
X
netservices
recall.exe
variant of the W32/SDBOT WORM!
X
netservices
svchostn.exe
SDBOT.GI WORM!
U
NetShow Powerpoint Helper
NSPPTHLP.EXE
"If disabled, user created fonts can no longer be seen by other programs"
N
NetStat Live
Nsl.exe
AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data
X
netsv32
netsv32.exe
W32/Sdbot-PX worm infection
U
NetTime
NETTIME.EXE
"From a visitor - ""This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."""
U
NetTurbo
netturbo.exe
"NetTurbo from SharewareOnline.com. ""Accelerate Your Internet Connections by up to 600%"". If you find it helps your connectivity leave it enabled"
X
Netunit32
wunit32.exe
unidentified WORM or TROJAN!
X
NetWatch32
netwatch.exe
W32.MIMAIL.C WORM!
N
Netword Agent
nwant33.exe
"An interesting browser utility that allows you to navigate by typing a single word or phrase (a ""NetWord"") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs"
X
NetWork
csrs.exe
AGOBOT.JJ WORM!
X
Network Access
winssh.exe
variant of the W32/SDBOT WORM!
X
Network Administration
NAS.exe
ANTILAM.20.Q VIRUS!
X
Network Administration Service
rsvc32.exe
RBOT.ABH WORM!
U
Network Associates Error Reporting Service
TBMon.exe
Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
X
Network Connections
internat.exe
TROJ/VB-ZD TROJAN!
X
network device driver
msfirewall.exe
Troj/Delf-LB TROJAN!
U
NetWork Device Switch
NetDevSW.exe
Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
X
Network Host Controller
??
WHISPER VIRUS!
X
Network protocol service
wintcp.exe
variant of the GAOBOT/AGOBOT WORM!
X
Network Protocol Service
wuamgrd.exe
WORM_RBOT.EA
X
Network Security
secsvc.exe
W32/Rbot-ALX WORM!
X
Network Security Guard
??
Troj/Colem-A TROJAN!
X
Network Security Guard
??
CoolWebSearch parasite related.
X
Network Service
svchost.exe
"Hijacker, also detected as Win32.Omal.C Trojan."
X
Network Service
svhost.exe
Troj/HacDef-K TROJAN!
X
Network Service Manager
netsvc.exe
variant of the GAOBOT/AGOBOT WORM!
X
NetworkAssociates Inc
internet.exe
variant of the LOVGATE WORM!
X
NetworkClient
NetworkClient.exe
LEMUR VIRUS!
X
Networks Configurator
NetConfs.exe
W32/RBOT-OX WORM!
X
Networks Controler
Netsis.exe
W32/RBOT-NG WORM!
N
NetworkSetup
dlink.exe
D-Link System Tray icon
N
NetZero_uoltray
exec.exe regrun
Netzero free ISP software - not required
X
Netzip Smart Downloader
npnzdad.exe
Advertising spyware
N
NetZIPFolders
nzfprop.exe
Netzip Classic zip file manager
X
NeuroMedia(IESpeaker)
NeuroMedia.exe
Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available
N
NeuroSpeech OESpeaker
OEMonitor.exe
Part of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not
X
New Csnm Manager
csmn.exe
SDBOT.BZS WORM!
X
New.net or NEWDOT~1
??
NewDotNet foistware
X
New.net Startup
??
NewDotNet foistware
N
Newsalrt
NEWSALRT.EXE
MSNBC News system tray utility to alert you to new news
X
Newsgroup lptt01 or Newsgroup ml097e
newsgroup.exe
"Variant of the RapidBlaster parasite (in a ""newsgroup"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
N
NewsUpd
newsupd.exe
For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here.
X
NewtonKnowsUpd
??
NewtonKnow hijacker
U
NFM Service
NPDOR9x.exe
Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
N
nForce Tray Options
sstray.exe
"nVidia nForce Taskbar Utility - quick access to the nForce2 ""Sound Storm"" control panel and related utilitys"
U
NGClient
ngctw32.exe
"Symantec Ghost Server software - needed for a ""a Ghost multicast"" (transfer images to multiple machines). Can be launched manually"
X
ngpw36
ngpw36.exe
AdBlaster adware variant
N
NGServer
ngserver.exe
Symantec/Norton Ghost Console service
X
NI.UWFX5
UWFX5NetInstaller.exe
"WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here"
X
NI.UWFX5LP_0001_0802
UWFX5LP_0001_0802NetInstaller.exe
"WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here"
X
NI.UWFX5LP_0001_0803
UWFX5LP_0001_0803NetInstaller.exe
"WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here"
X
NI.UWFX5V_0001_0802
UWFX5V_0001_0802NetInstaller.exe
"WinFixer web installer - Winfixer is ""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here"
X
NiceDownloads
??
MatrixDialer related
N
Nielsen NetRatings
insight.exe
"Nielsen NetRatings -? ""Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site?s audience and your customers"". Is it required?"
X
nikLaus
nikLaus.exe
NIKLAS VIRUS!
N
NInit
NInit.exe
Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
Y
nisserv
NISSERV.EXE
Norton Personal Firewall
Y
Nisum
NISUM.EXE
Norton Personal Firewall
U
niSvcLoc
niSvcLoc.exe
Related to National Instruments Corp. LabView
X
NJG40
NJG40.EXE
BANCOS.D VIRUS!
N
NkvMon.exe
NkvMon.exe
Nikon View 5 - for transferring pictures from Nikon digital cameras
N
NkVwMon.exe
NkVwMon.exe
Nikon View - for transferring pictures from Nikon digital cameras
X
NLS Keyboard
keyboard.exe
variant of the W32.SPYBOT WORM!
Y
NMSVC
nmSvc.exe
"Covenant Eyes -?surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it"
X
nnmgr
nnmgr.exe
Adware.FFToolBar adware toolbar.
U
NNSvc
nnsvc.exe
NetNanny internet filter
X
No Credit Card
plugin-.exe
Adult content pop-up dialler
U
NoAds
NoAds.exe
Blocks advertisement banners in Internet Explorer
U
NoAdware
NoAdware
"NoAdware Adware/Spyware remover - initially considerered a ""rogue"" program - see here . The latest version has since apparently mended its ways: see note"
U
NoAdware3
NoAdware3
"NoAdware Adware/Spyware remover - initially considerered a ""rogue"" program - see here . Has since apparently mended its ways: see note"
X
Nod32 Free antivirus
nod32krn.exe
W32/RBOT-AAO WORM!
U
Nod32CC
nod32cc.exe
Control Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
Y
NOD32kernel
Nod32krn.exe
Nod32 Antivirus Version 2
Y
nod32kui
nod32kui.exe
Nod32 Antivirus Version 2
Y
NOD32POP3
Pop3scan.exe
POP3 E-mail part of Eset's NOD32 virus-scanner
X
Nod3d2 Free antivirus
N0D32KRN.EXE
W32/RBOT-ABQ WORM!
X
nodriver
AUEKXRZ.EXE
variant of the SPYBOT VIRUS!
X
Noha
aasd.exe
PurityScan/Clickspring adware
U
No-IP DUC
DUC20.exe
Part of http://www.no-ip.com?provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available
N
Nokia Connection Monitor
NclConf.exe
"Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required"
U
Nokia Tray Application
NclTray.exe
"Nokia PC Suite 5 - ""A collection of powerful tools that you can use to manage your phone features and data."" Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on"
U
NOMAD Detector
ctmnrun.exe
Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
N
NomdCheck
nomdchek.exe
Part of Intel's Native Audio
U
Norman ZANDA
ZLH.EXE
System Tray icon for Norman Antivirus
X
NortE Antivirus
norte.exe
RBOT.BQQ WORM!
X
NortE Antivirus
norten.exe
W32/Rbot-AFF Worm!
X
Norton Antivirus 7.0a
??
PERDA-B or RANCK-CT TROJAN
Y
Norton AntiVirus AutoProtect
navapw32.exe
Norton Anti-Virus's background scanning process.
X
Norton Antivirus AV
FVProtect.exe
W32.NETSKY.P WORM! **Note - this is not the popular AV software!
X
Norton AntiVirus Sys
NAVsys32.exe
variant of the W32/WOOTBOT WORM!
X
Norton Auto Protect
crss32.exe
SDBOT.ATF WORM!
X
Norton Auto Protect
nava.exe
unidentified WORM or TROJAN!
X
Norton Auto-Protect
ccApp.exe
"W32.Ahker.D WORM! **Note - for the valid Norton AV entry the filename is ""navapexe"". This is also not the valid Norton_AV_2003 file with the same filename"
Y
Norton Auto-Protect
navapw32.exe
"Norton Anti-Virus's background scanning process. Can be inconvenient because it scans files when Run/Opened or Downloaded/Created and you can scan files manually via right-click after downloading/copying. However, in light of some of the viruses around these days it's probably best to put up with the inconvenience"
X
Norton Auto-Protect
SERVICES.exe
W32.Ahker.B WORM!
X
Norton AV Protection Startup
Ati2xxx.exe
variant of the WIN32.RBOT WORM!
N
Norton Crashguard Monitor
cgmenu.exe
Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
N
Norton Disk Doctor
Ndd32.exe
"Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well"
Y
Norton eMail Protect
POPROXY.EXE
"Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it"
X
Norton Firewall
??
Troj/Banker-ET TROJAN!
N
Norton Ghost 9.0
GhostTray.exe
Norton_Ghost tray icon - the application can be launched manually
X
Norton Guard 32
ntguard32.exe
variant of the WIN32.RBOT WORM!
X
Norton Live Update Server
cpsdv.exe
AGOBOT.EW WORM!
X
Norton Live Updater
Cavapsvc.exe
GAOBOT.AO WORM!
X
Norton Live Updater
Sochost.exe
GAOBOT.AO WORM!
N
Norton Navigator Loader
nnloader.exe
An older Norton utility for file management under Windows 95. More information here
Y
Norton Personal Firewall
IntroWiz.exe
Part of Norton Personal Firewall or Norton Internet Security
X
Norton Personal Firewall
jah.exe
variant of the W32/SDBOT WORM!
X
Norton Personal Firewall
lah.exe
variant of the WIN32.RBOT WORM!
X
Norton Personal Firewall
npfw.exe
W32/RBOT-UI WORM!
X
Norton Personal Firewall
npfw32.exe
W32/RBOT-UQ WORM!
U
Norton Program Scheduler
NPSsvc.exe
"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans"
U
Norton Program Scheduler
nsched32.exe
"Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans"
X
Norton Protect
npprotect.exe
W32/RBOT-WW WORM!
X
Norton protect
nvsvc.exe
variant of the WIN32.RBOT WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here
X
Norton Protect Activies
csrss.exe
Troj/Banker-CZ TROJAN!
X
Norton Service Driver
wsul.exe
W32/RBOT-ABI WORM!
X
Norton Service Process
navapvc.exe
variant of the AGOBOT/GAOBOT WORM!
X
Norton SpySweeper AutoUpdate
navsw.exe
W32/Forbot-AS worm infection
X
Norton Swap Cleaner
nortonswap.exe
W32/Rbot-MH worm infection
N
Norton System Doctor
Sysdoc32.exe
"Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well"
N
Norton SystemWorks
cfgwiz.exe
Norton SDystem Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
X
Norton Update
ccUpdate.exe
variant of the GAOBOT/AGOBOT WORM!
X
Norton Update
winsvc.exe
AGOBOT.ALP WORM!
X
Norton updated
NVSV32.EXE
SDBOT.ABH WORM!
X
Norton Updater
ccUpdate.exe
variant of the AGOBOT/GAOBOT WORM!
X
Norton Updater
lsa.exe
variant of the WIN32.RBOT WORM!
X
Norton Updater
navupdtr.exe
SDBOT.AXV WORM!
X
Norton Updater
NortonUpdate.exe
unidentified WORM or TROJAN!
X
Norton Updater
winset.exe
variant of the W32.SPYBOT WORM!
X
Norton Wizzard
nwiz.exe
GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name
X
norton32
norton32.exe
Unidentified worm or trojan
X
NortonAntivirus
LSASS.exe
W32.Pexmor WORM! Note: This (LSASS.exe) is not the legitimate Windows Process and has nothing to do with NortonAntivirus. The legitimate Windows Process (Lsass.exe) is found in the System32 folder and should not be seen in Msconfig or as a Startup item. This worm file is found in the Windows\Temp or Winnt\Temp folder.
X
NortonAV
norton_antivirus.exe
BACKDOOR.NETJOE TROJAN! **Note: this is not the legitimate Symantec AV program
X
Nortons AV SYSTEM
scvchost.exe
variant of the WIN32.RBOT WORM!
X
nortonsantivirus
ccEvtMngr.exe
TROJ/HZDOOR-A TROJAN!
X
NortonVPlus
svchost.exe
Troj/Roamer-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
U
Notebook Maximizer
maximizer_startup.exe
Toshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency
X
NOTEPAD
NOTEPAD.exe
"Added as the result of the RUSTY VIRUS! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! - This malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
Notepad lptt01 or Notepad ml097e
notepad.exe
"Variant of the RapidBlaster parasite (in a ""nvd32"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name"
X
notepad.exe
msmsgs.exe
TROJ/ZLOB-I and Troj/Zlob-H TROJANS!
X
notepad.exe
msmsgs.exe
"variant of the Troj/FAKESPY-B TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!"
X
notepad.exe
upx.exe
variant of the WIN32.AGENT.AH TROJAN!
X
notepad2.exe
popuper.exe
Troj/Puper-C and TROJ/PUPER-E TROJANS!
X
notes
notepaad.exe
RBOT.BME WORM!
X
Notn
Eber.exe
PurityScan/Clickspring adware
X
Notn
wtta.exe
PurityScan/Clickspring adware
U
NovaBackup * Tray Control
NbkCtrl.exe
Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html * represents the version number
U
Novast or Schedulerd
SCHENGD.EXE
NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
X
NOYPI_KANG_ASTIG
Exit to DosPrompt.pif
W32.Filukin.A WORM!
X
NPF Value
NPFMONTR.exe
variant of the W32.SPYBOT WORM!
U
NPROTECT
nprotect.exe
Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here
X
NS
ns.exe
W32/AGOBOT-HS WORM!
X
NSCheck
NSCHECK.EXE
NetSetter/Marketscore foistware
X
nscntrl
nscntrl.exe
Troj/Dload-DC TROJAN!
X
nsdcmd services
nsdcmdav.exe
variant of the AGOBOT/GAOBOT WORM!
X
nsdcmd vid process
nsdcmdwin.exe
variant of the AGOBOT/GAOBOT WORM!
X
nsdlua
nsdlua.exe
All-In-One Telcom - adult content dialler
X
nsdriver
nssys32.exe
NetShagg adware
X
nse
nse.exe
AGOBOT-ML WORM!
U
Nsengine
Nsengine.exe
Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
U
NSHelper
aexnsinstallhelper.exe
Altiris Express Notification Server Install helper - monitors integrity of the installation
X
nssysconf
??
VIVIA.A trojan variant
X
nstat
netstat.exe
adult material dialer
X
NsUpdate
NsUpdate.exe
Dial/Laet-B Dialer! Note: This is a premium rate dialer application and can run up very large phone bills.
X
Nsv
nsvsvc.exe
Delfin_Promulgate adware
X
nsvcin
n20050308.exe
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
Nsvdr
nsvdr.exe
Adult content dialler
U
nsys
nsys.exe
NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
nsys32
nsys32.exe
W32/Agobot-SU Worm!
N
NSystemMonitor
Symmon.exe
Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
N
NT Kernel Patch
ntkrnlpt.exe
FaxServe network fax software
X
NT Logging Service
Syslog32.exe
W32/SDBOT-ACK WORM!
X
NT MICROSOFT SVCD
ntvsvcd.exe
variant of the WIN32.RBOT WORM!
X
NT security
rundll32.com
W32/Rbot-AJC WORM!
X
NT Service
NTOKSRNL.EXE
W32/RBOT-AAG WORM!
X
NT Services
ntsvc.exe
AGOBOT.VJ WORM!
X
NT Video API32
NTAPI32.exe
W32/RBOT-FW WORM!
X
NT Virtual Machine
??
W32/SCAERBOT-A WORM!
X
Ntcheck
mapserver.exe
TROJ/TOMPAI-B WORM!
X
ntddetect
ntddetect.exe
TROJ/AGENT-CU or BDOOR-ZAU TROJANS!
X
NTdhcp
NTdhcp.exe
TROJ/QQROB-F TROJAN!
X
ntdll
ntdll.exe
BIONET.404 VIRUS!
X
NTDLM
csrss.exe
"HALE VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling as this resides in c:\winnt\system32\qossrv"
X
Ntech.patchs
??
LEMIR.G VIRUS!
X
ntechin
n20050308.exe
"Adware downloader, Delphin_Media_Viewer related, also detected as the DELMED.A TROJAN!"
X
NTFS16
ntfs16.exe
W32/Rbot-LY worm infection
Y
NTFSCLUP
NTFSCLUP.EXE
"Part of ConfigSafe- ""checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99 % of the time it will only execute about a dozen instructions before exiting"""
X
ntfsmonitorpro
ntfs64.exe
W32/FORBOT-EB WORM!
X
NTFSS Microsoft System
filees.exe
RBOT.GAB WORM!
X
NTFSS MICROSOFT SYSTEM
filess.exe
RBOT.AXZ WORM!
X
ntldr
ntldr.exe
"Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: * Creates file C:\WINDOWS\SYSTEM\ntldr.exe. * Creates file C:\m.exe. * Creates file C:\WINDOWS\Search-For-You.url. * Creates file C:\n.bat. * Deletes file c:\q.exe. * Creates file C:\q.exe. * Creates file C:\r.bat"
N
ntlfreedom
"RyDial.dll, QuickStart"
NTL Freedom ISP software - reportedly not required
X
ntmsevt
ntmsevt.exe
TROJ/STOPED-B TROJAN.
X
NTP Server
??
RANKY.F VIRUS!
Y
nTrayFw
ntrayfw.exe
Software interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
N
NTrtc
ntrtc.exe
Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here
X
NTSet32
services.exe
Troj/WinSpy-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\dll32 or Winnt\dll32 folder.
X
NTSF MICROSOFT SYSTEM
fufffy.exe
W32/Rbot-AEL Worm!
X
NTSF Microsoft System
fylez.exe
variant of the WIN32.RBOT WORM!
X
NTSF Microsoft System
ntsf.exe
RBOT.ARQ WORM!
X
NTSF MICROSOFT SYSTEM
ntssf.exe
variant of the WIN32.RBOT WORM!
X
NTSF MICROSOFT SYSTEM
scvhost.exe
variant of the WIN32.RBOT WORM!
X
NTSF MICROSOFT SYSTEM
winsis32.exe
variant of the WIN32.RBOT WORM!
X
NTSF MICROSOFT SYSTEM
wntsf.exe
RBOT.ATC WORM!
X
ntsmod
ntsmod.exe
"adware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!"
X
NTsocket
NoeWinnt.exe
Ataka-E TROJAN!
X
NTsrv.exe
NTsrv.exe
variant of the SERVU-O TROJAN!
U
nTune
nTune.exe
nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
X
ntupd32
ntupd32.exe
See_Here
X
ntupdate
dnsvc.exe
W32/SDBOT-TC WORM!
U
NTVDM
NTVDM.EXE
"Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS\'s (Windows NT, 2K and XP). Required if hardware on a machine with these OS\'s needs 16-bit DOS drivers. You can find a bit more about NTVDM here"
X
ntvdmd
ntvdmd.exe
Adware downloader - also detected as the TROJ/DLOADER-YP TROJAN!
X
ntvdscm
ntvdscm.exe
Troj/ScKeyLog-I TROJAN!
X
NT-Virtual Device Manager
ntvdmn.exe
W32/SDBOT-AAA WORM!
Y
NuTCSetupEnviron
ncoeenv.exe
"Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone"
X
NvagNT
nvagNT.exe
W32/AGOBOT-RV WORM!
X
nvc Win32
nvcvc.exe
W32/Rbot-ADD Worm!
X
NvClipRsv
rsv32.exe
Troj/Tofger-X trojan infection
X
NvClipRsv
svchost.exe
W32/Dumaru-AK WORM!
X
NvClipRsv
swchost.exe
W32/Dumaru-AK WORM!
X
NVCOM
NVCOM.exe
W32/AGOBOT-SB WORM!
X
NvCpl
??
W32/AGOBOT-APJ WORM!
U
NvCpl
??
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
X
NvCpl
NvCpl.EXE
W32.YANZ.B WORM!
U
NvCpl
NvStartup
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
X
NvCpl
windowsp.exe
variant of the W32/SDBOT WORM!
X
NvCplD
m2gr32.exe
"""Switch"" premium rate adult content dialer"
X
NvCplD
ntcpl.exe
"""Switch"" adult content dialer"
U
NvCplDaemon
??
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
N
NvCplDaemon
??
"System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the ""NVIDIA Driver Helper Service"" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)"
U
NvCplDaemon
NvStartup
Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
X
NvCplDaemon32
anvshell32.exe
Troj/VB-XU TROJAN!
X
NvCplDeamon
nvdisp.exe
Troj/PeepVie-I TROJAN!
X
NvCplDmn
NAVSVC.EXE
unidentified VIRUS!
X
NvCplScan
kav32.exe
W32/FORBOT-EW WORM!
X
NvCplScan
msc32.exe
W32/FORBOT-DD WORM!
X
NvCplScan
nvsc32.exe
W32.Kelvir.D WORM!
X
NvCplScan
winasp.exe
FORBOT.BZ WORM!
X
nvd32 lptt01 or nvd32 ml097e
nvd32.exe
"Variant of the RapidBlaster parasite (in a ""nvd32"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Nvid
??
Unidentified adware
X
Nvid32
Nvid32.exe
GEMA TROJAN!
X
Nvidex32
Nvidex32.exe
GEMA TROJAN!
Y
NVIDIA ActiveArmor
ntrayfw.exe
Software interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
X
Nvidia Control Daemon
nksvc32.exe
W32/AGOBOT-OV WORM!
X
Nvidia Control Panel
ncsvc32.exe
"Worm, as yet unidentified"
X
NVIDIA Driver
MSPMSPSU.EXE
WORM_WOOTBOT.Y infection
N
NVIDIA nForce APU1 Utilities
NVATray.exe
"nVidia's nForce Audio Processing Unit (APU) ; provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time."
U
NVIDIA nTune
nTune.exe
nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
U
NVidia System Utility
NVSystemUtility.exe
"The NVidia_System_Utility lets you adjust bus speeds, hardware voltages, memory controller timings, and fan speed as well as additional settings to increase performance aggressiveness and hardware voltages. Will also display a dynamic graph of CPU and system temperatures, hardware voltages, and memory bus speeds."
X
NVIDIA Video drivers
video_32D.exe
AGOBOT.KV WORM!
X
NVIDIA Video drivers
video_32sD.exe
W32/RBOT-BB WORM!
X
Nvidia32
nvidia32.exe
CoolWebSearch parasite related.
N
NvidiaQuickTweak or NVQuickTweak
??
System Tray icon used to change display settings for nVidia based graphics cards. Unnecessary since you can easily configure these settings the way you want them in the Display Properties
X
nvidll32
nvidll32.exe
W32/RBOT-XK WORM!
U
NVIEW
??
This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers
X
nviload32
nviload32.exe
W32/SDBOT-VT WORM!
X
nviload32
nviload32.exe
W32/SDBOT-VT WORM!
N
NvInitialize
??
Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled
X
nvirundll
nvirundll.exe
W32.SPYBOT.NPS WORM!
X
nvjxue
nvjxue.exe
W32/EYEVEG-J WORM!
Y
NVmax
NVmax.exe
NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
N
NVMCTRAY
??
"System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties"
N
NvMediaCenter
??
"System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties"
N
NVMixerTray
NVMixerTray.exe
System Tray access to audio controls from nVidia's motherboard ForceWare software
X
nvmsgdwn
NVMSGDWN.EXE
Troj/Graber-D TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X
NvMsnW
Isass.exe
WIN32.BROPIA.K WORM!
Y
NVRaidService
nvraidservice.exe
nVidia NVRaid - hard disk striping/mirroring utility for increased performance and reliability. Required if you have a RAID setup
N
NVRT
nvrt.exe
NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
X
nvsv32.exe
asr_fnt.exe
WOOTBOT.GE WORM!
X
nvsv32.exe
cstr.exe
variant of the W32/SDBOT WORM!
X
nvsv32.exe
nvsv32.exe
W32/FORBOT-DI WORM!
X
nvsv32.exe
nvsv33.exe
WOOTBOT.FP WORM!
N
NvSvc
nvsvc.exe
"NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that"
X
NVSVC
nvsvc.exe
AGOBOT.ALX WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file as described here
X
nvsvca32
nvsvca32.exe
WIN32.TACTSLAY.E TROJAN!
X
NVSystem32
nvscv32.exe
W32/Agobot-NO WORM!
X
NvUpdater
nwiz32.exe
variant of the WIN32.RBOT WORM!
X
NvXplDeamon
xstyles.exe
SMALL.AJ VIRUS!
N
nwiz
nwiz.exe
"Associated with the newer versions of nVidia graphics cards drivers.? Allows you to immensely improve desktop layouts by setting preferences and optimizations.? However, this isn't necessary for the operation of your system"
X
nwiz32
nwiz32.exe
Troj/Sinbank-A TROJAN!
Y
Nwpopup
Nwpopup.exe
"Broadcast message handler part of Novell_Netware that displays server, printer and other messages."
U
nwrecmsg
nwrecmsg.exe
"Broadcast message handler part of Novell_Netware that displays server, printer and other messages - can cause crashes"
U
nwss
Sp0.exe
SpyOutside surveillance software. Uninstall this software unless you put it there yourself.
Y
NWTRAY
nwtray.exe
"Novell Netware. Displays the red ""N"" tray icon which can be disabled (by right-click on the icon) but is also needed by the client"
Y
oahstifr
oahstifr.exe
"Comes with HyperTextStudio. From the supplier - ""The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."""
U
OAKSTART
OAKSTART.EXE
Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
N
OAKTASK
OAKTASK.EXE
"Taskbar utility for a ""control panel"" for a CD-RW"
Y
Object Store Server
osserver.exe
"Comes with HyperTextStudio. From the supplier - ""The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."""
N
OCAudioIni
OCAudioIni.exe
One-click Audio Converter - allows you to convert files of multiple audio formats right from Windows Explorer
N
ocraware
ocraware.exe
"Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs"
X
ocx32
ocx32.exe
ASTEF or RESPAN VIRUSES!
X
OCXUPDT32
ocxupdt32.exe
W32/AGOBOT-IF WORM!
X
OD
SYSCNTR.EXE
HotVideo dialler
U
ODBC BackUp
fdxxl.exe
"G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!"
X
oddworldz.exe
oddworldz.exe
Troj/Multidr-EG TROJAN!
X
od-matrxx
od-matrxx.exe
Adult dialler - xx can be any number
N
Odometer
Odometer.EXE
Mouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available
U
ODSPConfig
ODSPConfig.exe
DsktopSurveil surveillance software - get rid of it unless you installed it yourself!
Resets OEM installation settings at bootup. Not required unless you\'re new to PC\'s
U
OEMRUNONCE
oemrun.exe
Windows Millennium file - used by setup when installing the OEM 'express' version of the operating system. Uncheck after setup has finished.
U
oeplugin
bxOEPlugin.exe
noHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple text.
U
OESpamTest
OESpamTest.ExE
Kaspersky_Anti-Spam
N
OEXCheck
EA2Check.exe
"Express Assist from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others"
X
Offer Companion or Offers
offers.exe
Advertising spyware
X
Office Startup
Exploer.exe
GAOBOT.BV WORM! **Note - This is not a valid MS Office entry
X
Office Startup
exploer.exe
AGOBOT.BV WORM!
N
Office Startup
"Osa.exe, Osa9.exe"
"Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show."
X
OfficeAgent
expIorer.exe
WIN32.TACTSLAY.A TROJAN!
X
OfficeAgent
outIook.exe
WIN32.TACTSLAY.A TROJAN!
X
OfficeAgent
svcrhost.exe
WIN32.TACTSLAY.A TROJAN!
X
OfficeAgent
svcshost.exe
WIN32.TACTSLAY.A TROJAN!
X
OfficeDeamon
msorunner.exe
variant of the WIN32.TACTSLAY TROJAN!
Y
OfficeGuard RegChecker
ogrc.exe
Kaspersky Labs anti-virus
X
OfficeGuardUI
svcss.exe
DEDLER-C TROJAN!
X
OfficeQuickAccess
OfficeHost.vbs
W32.Pexmor WORM! Note: This worm file is found in the Windows\Temp or Winnt\Temp folder.
Autodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs
Y
ogrc
ogrc.exe
Kaspersky Labs anti-virus
N
Oil Change
OCTray32.exe
From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs
X
OLE
??
STAWIN or TARNO.D VIRUSES!
X
oleaccrc
oleaccrc.exe
Adware downloader - recognized by Kaspersky antivirus as TrojanDownloader.Win32.Agent.am
X
OLEDb Service
runoledb32.exe
variant of the SPYRE.B TROJAN!
X
Olehelp
Olehelp.exe
CoolWebSearch parasite related.
X
olehelp
olehelp.exe
BOOKMARKER.D or BOOKMARKER.G hijacker/viruses
X
OleLoader
ole32.exe
BACKDOOR.WIN32.DELF.BR TROJAN!
U
olesvr
olesvr.exe
Salfeld Child_Control_2003 - parental control software
X
Olive System
Szchost.exe
MERCURYCAS.A VIRUS!
X
Olympic
IE4321.exe
Adult content premium rate dialer - also detected as Trojan.Win32.Small.CZ
X
Omf4
OMF4.EXE
FREEMEGA VIRUS!
N
OmgStartup
omgstartup.exe
Sony program called OpenMG Jukebox - player and music organizer
U
OmniHTTPd
ohttpd.exe
OmniHTTPd web server from Omnicron
N
OmniPage
Opware32.exe
"Part of OmniPage Pro from Scansoft (was Caere) - ""the fastest, easiest way to turn paper documents into digital files you can edit."" Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs"
U
OmniPass
scureapp.exe
OmniPass from Softex Inc. - secure password management software
U
On Screen Display
OSD.EXE
"By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a ""hot key"" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don\'t adjust things regularly - can also freeze"
N
One Touch Monitor
1tou~2.exe
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
N
OneTouch Monitor
OneTouchMon.exe
"""Finds"" the Visioneer scanner to see if it's on then loads it in the tray for quick access which delays the initial boot to desktop process. According to the Windows_Startup_Online_Repository , with the icon in the tray, if you restart or leave desktop, on your return, it again looks for the scanner and again bogs down your system. A desktop icon or star t > programs will provide access without the constant delays. Advise not to load this one in the tray."
N
OneTouchMonitor
OneTouchMonitor.exe
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner
X
Onflow
onflow.exe
Onflow is a internet company that offers an online advertising program. Not required - uninstall
X
Online Service
svchost.exe
"HOSTIDEL.B or TARNO.B VIRUSES! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32"
X
Online Service
svchost.exe
HOSTIDEL.C VIRUS!. This is not the valid svchost.exe as described here
X
online_party
online_party.exe
Adult content dialler
U
OnlinePCfix SmoothSurfer
SS.exe
"Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists"
N
OnlineTime
onlinetime.exe
OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs
X
Onluna Sarvice
sachost.exe
TROJ/TOFGER-AA TROJAN!
X
Onlune Sarvice
sachost.exe
TROJ/DAEMONI-J TROJAN!
X
OnSrvr
OnSrvr.exe
OnWebMedia adware
X
oo4
??
BookedSpace parasite variant
N
OP12 Reminder
Ereg.exe
Registration reminder for OmniPage Pro 12 from ScanSoft
X
Open Service Drivers
opiater.exe
variant of the WIN32.RBOT WORM!
X
Open Site
opensite.exe
OpenSite adware
X
Open Site
opnste.exe
OpenSite adware
X
Open2Enter
runme.exe
Adult Content Dialler
X
Open2Enter
runme2.exe
Adult Content Dialler
X
Open32
Open32.exe
Horseserver.net browser hijacker
X
OpenGL Drivers
0penGLD.exe
W32/YIMP-A WORM!
X
OpenMstart
mcmgr32.exe
"""Switch"" adult content dialer"
X
OpenMstart
mmgr32.exe
"""Switch"" adult content dialer"
X
OpenMstart
Snt.exe
"""Switch"" adult content dialer"
U
OpenOffice.org *.*.*
quickstart.exe
"OpenOffice.org office suite quick start (where ""*.*.*"" is the version number)"
N
OpenOffice.org x
QUICKS~1.EXE
"Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). ""x"" represents the version number"
U
Openwares LiveUpdate
LiveUpdate.exe
Web-update utility as used by various types of software - see here
N
Operator
??
"Media Pilot operator, in Win.ini. Locks port open"
U
Operator
xtmop.exe
Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported
N
OpiStat
OPISTAT.EXE
OpiStat is a European Research Institute whose goal is to understand consumer needs and opinions better
X
OPQFile
??
Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
X
opr
opr.exe
MediaMotor/Popuppers adware component
X
opsql update check
opsql.exe
W32/RBOT-ACJ WORM!
X
OPTIMIZER
iexplore.exe
"EVIVINC VIRUS! Note - ""iexplore.exe"" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid ""iexplore.exe"" (IE) resides in C:\Program Files"
X
Optimum Online
Netsurf.exe
OptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity.
X
Optional Web Drivers For WIN32
phqghume.exe
variant of the WIN32.RBOT WORM!
U
Optus Cable Data Monitor
datamonitor.exe
"Allows Optus customers to monitor their actual data usage against Optus' ""data allowance limits""."
U
OptusNetUsage
OptusNet Usage Meter.exe
"This product is designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be."
N
Opware12
Opware12.exe
OmniPage Pro 12 from ScanSoft
N
Opware14
Opware14.exe
"ScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs"
N
OpwareSE2
OpwareSE2.exe
"ScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via ""File, Acquire Page."" Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs"
The HP Order Reminder utility is installed with the HP LaserJet printer software and allows you to set specific times for reminders to check the current level of toner in the print cartridge - it also contains an Order Now link to a Web page that helps you order supplies online from a reseller of your choice.
X
OrgyCam
OrgyCam.exe
Adult content dialler
U
OrigRage128Tweaker
RAGE128TWEAK.EXE
Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com
U
ORiNOCO
Cmluc.exe
Client Manager software for an ORiNOCO wireless LAN card
"OStivity - ""a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system"""
X
Osus
acao.exe
PurityScan/Clickspring adware
X
Osus
rrup.exe
"PurityScan/Clickspring -Adware - The executable is located in the user's ""Application Data"" folder or the Program Files\htwu folder."
X
otcx
otcxxh.exe
CAROOL VIRUS!
X
outlook
outlook.exe
W32/SDBOT-RU WORM!
X
Outlook Express Config
??
variant of the WIN32.RBOT WORM!
X
Outlook Express Protocol
look.exe
W32/RBOT-ACS WORM!
X
OutLooks
InSane.exe
SWOOP TROJAN!
Y
Outpost Firewall
outpost.exe
Outpost personal firewall
X
outpostupdate
outpostupdate.exe
Troj/Cosiam-C TROJAN!
X
Outwar
syslaunch.exe
Outwar adware downloader
N
Overnet
Overnet.exe
Overnet peer-to-peer (P2P) file sharing program
X
ovyriwi
telace.exe
SDBOT.BVS WORM!
U
OWCCardbusTray
ocbtray.exe
Icon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface
U
OWCWebCamDV
wcdvtray.exe
"WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam"
X
OWMngr
OWMngr.exe
OnWebMedia/SearchSeekFind advertising foistware
U
OxigenClientAdmin
Oxigen.exe
Open University Oxigen screensaver admin client. Downloads the latest information from the net to display in the screen saver.
X
oz2
oz2.exe
W32.Mydoom.W WORM!
N
p_981116
p_981116.exe
Win32 cabinet self extractor. More info here
X
P2P Networking
P2P
P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately.
X
P2P NETWORKING
P2P Networking.exe
P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately.
X
P2P NETWORKING
p2pautostart.exe
P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately.
X
P2P Networking2
P2P Networking2.exe
P2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately.
N
P2P Networking3
P2P Networking3.exe
"P2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required; see here"
X
p2pnetwork
p2pnetwork.exe
ALCAN.A WORM!
X
p2pnetworking
p2pnetworking.exe
W32/Rbot-AFL Worm!
X
P3p4chk
P3p4chk.exe
GEMA TROJAN!
X
p4mx4
p4mx4.exe
CRYPTER.A trojan infection
X
PaciSoft
pacis.exe
PacerD_Media/Pacimedia.com adware installer
N
PadTouch
PadExe.exe
"Toshiba Touch and Launch, offers easy movement and freedom of programs navigation with TouchPad."
U
Pagekeeper Jobs or Pagekeeper Lite
pkjobs.exe
"PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc"
X
PAgent
PAgent.exe
"Scans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See here for more info"
N
Pagis Scheduler
Monitor.exe
Scheduler for the Pagis scanning suite from Scansoft.?
N
Pagoo
PAGOO.EXE
Pagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
X
paint.exe
shnlog.exe
TROJ/PUPER-A And Troj/Puper-D TROJANS!
X
PaintingRoom evidence monitor
paintingroom.exe
Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
X
PaintingRoom smile monitor
paintingroom.exe
Paintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
N
Palm.exe
Palm.exe
Palm Desktop Software for use with Palm handheld devices. Available via Start -> Programs
X
PalNetaware
pnetaware.exe
PalTalk
N
PaltalkNetaware.exe
PALNETAW~1.EXE
Voice chat program. This program stores all buddy list info?apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated
U
pamela.exe
pamela.exe
Pamela is a plug-in or add-on that adds features to Skype peer to peer voice service. Note: Located in the Program files\Pamela folder.
U
Panda Antispam Server Service
PasSrv.exe
"AntiSpam software, part of Panda Platinum_Internet_Security"
Y
Panda Cleaner
pavdr.exe
Panda Antivirus related - possibly Panda ActiveScan
X
PandaAVEngine
PandaAVEngine.exe
W32.NETSKY.R WORM!
U
PandaScheduler
pavsched.exe
Panda Antivirus scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it
X
Pantera
pantera.exe
SDBOT.AYN WORM!
N
Paperport
runppdrv.exe
Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here
N
PaperPort PTD
pptd40nt.exe
"""PaperPort"" software associated with scanners"
N
PaperQuote System Tray Icon
PQTRAY.EXE
"PaperQuote is a ""wallpaper"" changer with daily quotes that are either for inspiration or motivation"
X
Parallel Tasking
ptask.exe
TROJ/SMALL-CJ TROJAN!
U
PartSeal
PartSeal.exe
System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
U
Password Door Loader
PDMonitor.exe
Password Door - password protection software
N
PasteLister
plister.exe
PasteLister - clipboard extender. Start manually when required
X
Patch
patch.exe
W32/NetBus TROJAN!
X
Patches Value
WinGamed.exe
SDBOT.BR worm infection
X
pathname
pathname.exe
BACKDOOR.IRCCONTACT TROJAN!
X
PAV.EXE
??
KITRO.D (or ARGEN.A) VIRUS!. %Number% can be any number
Y
PAV.EXE
PAV.EXE
PER Antivirus
Y
PAVFIRES
PavFires.exe
Panda Antivirus
Y
PAVFNSVR
PavFnSvr.exe
Panda Titanium Antivirus
Y
PavProc
PavPrS9x.exe
Panda Titanium Antivirus
Y
PavProt
PavProt.exe
Panda Titanium Antivirus
X
PayTime
paytime.exe
Troj/StartPa-YR Trojan!
U
pbagent
pbagent.exe
Probot keystroke logger/monitoring program - remove unless you installed it yourself!
U
PC Alert III
alert.exe
"MSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock"
U
PC Booster
pcbooster.exe
"PC Booster from inKline Global - ""easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"""
U
PC Dynamics SdwMon32
sdwmon32.exe
"SafeHouse ""Personal Privacy"" protects and hides your private and personal photos, videos, files and folders by making them ""invisible"" and encrypted."
U
pcAnywhere Agent
pcamgt.exe
Part of pcAnywhere 9.0 or later. This process listens for incoming PC Anywhere connections if your PC is configured as a PC Anywhere host.
Y
PCBODYGUARD or PCBG
PCBODYGUARD.EXE
"PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc"
Y
PCCClient.exe
PCCClient.exe
PC-Cillin 2002 antivirus software
Y
pccguide.exe
pccguide.exe
PC-Cillin 2002 antivirus software
Y
PCCIOMON.EXE
PCCIOMON.EXE
PC-Cillin 2000 antivirus software. This is the actual virus-scanner
Y
PCClient.exe
PCClient.exe
Trend Micro PC-cillin Internet Security
X
PC-Config32
corona.exe
CORONEX.A VIRUS!
Y
PccPfw
PccPfw.exe
Trend Micro PC-Cillin personal firewall
Y
PcCtlCom
Pcctlcom.exe
Trend Micro PC-cillin Internet Security
N
PCDRealtime
realtime.exe
"Apparently the monitoring device for PC Doctor Online. It provides a ""free"" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to ""order"" the fee-based fixes from its web site."
U
PC-Duo System Snapshot
CLBOOT32.EXE
"PC-Duo_Remote_Control from Vector. ""System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!"". For tech support users to provide remote assistance"
X
PcEXPLODE
specialfile.exe
RBOT.RH worm infection
N
PCHbutton
PCHbutton.exe
Used by HP Instant Support
N
PCHealth
pchschd.exe
"This is a ""scheduler"" and does not turn off PC Health. For more information refer here"
X
PCHEasySearch
STUpdate.exe
PCH EasySearch bar
U
PCLEPCI
ppe.exe
"Pinnacle Systems PCI Performance Enhancer. ""This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards."""
X
PCprot
crcss.exe
unidentified WORM!
U
PCRecSA
PCRecSA.exe
"Part of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a ""clean"" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to"
X
pcServer
server.exe
"""Ssppyy"" spyware"
X
PCShield
??
"SafeguardProtect/Veevo malware, where * is a random char or digit"
N
PCStart
Pcm25.exe
Runs as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big
N
PCSuiteTrayApplication
LaunchApplication.exe
"System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu."
N
PCSuiteTrayApplication
TrayApplication.exe
"System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu."
X
Pcsv
pcsvc.exe
"Delfin_Media_Viewer or ""Promulgate"" adware"
N
PcSync
PcSync.exe
"If a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs"
X
PcSync
PCsync.exe
W32/RBOT-XJ WORM! - NOTE: do NOT confuse with the Nokia application described here
U
pctspk
pctspk.exe
Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
U
PCTVOICE
pctspk.exe
Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
U
PCTVOICE
pctvoice.exe
"The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It?s better to leave it"
U
PCWatch
pcwatch.exe
Spyware.PCWatch surveillance software. Uninstall this software if you did not install it yourself.
X
PDASCAN
pdascan.exe
W32/AGOBOT-QY WORM!
U
PDEngine
PDEngine.exe
PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot
N
pdexplo
PDEXPLO.EXE
PowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs
N
pdfFactory Pro Dispatcher v1
fppdis1.exe
"""With pdfFactory you can create PDF documents from any program printing to the virtual PDF printer"". Available via a desktop shortcut or Start -> Programs"
U
pdfMachine dispatcher
mapisnd.exe
pdfMachine Windows print driver
N
pdfSaver3
pdfSaver3.exe
"PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc."
N
PDirect
PDirect.exe
IBM Presentation Director software
U
pdp Server
ctpdpsrvr.exe
Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
U
PDVDServ
PDVDServ.exe
"Remote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one"
N
Pe2ckfnt SE
chkfont.exe
"Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu"
N
PeerGuardian
PeerGuardian_1.99b_pr14.exe
"PeerGuardian ""is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections."""
U
PeerGuardian
pg2.exe
"PeerGuardian is an IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists, a list editor, automatic blocklist updates, and blocking all of IPv4 (TCP, UDP, ICMP, etc)."
U
Pent@VALUE 3.2
Pent@VALUE.exe
Pent@VALUE Digital Satellite Internet PC Receiver
X
PeqBL100
PEQBL100.exe
W32.PEQ WORM!
Y
PER Email Protection
pavmail.exe
PER Antivirus
N
PerfectPrint
pfppop70.exe
Print engine used by Corel WordPerfect 7 and Presentations 7
X
Perfomance Monitor
davcsync.exe
W32/Lamud-A Worm!
X
Perfomance Settings
svchost.exe
"TROJ/TOFGER-AP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
PerformCl
perfcl.exe
adware downloader and installer
Y
PersFw
PersFw.exe
Kerio or Tiny Personal Firewall
N
Persistence
igfxpers.exe
Associated with the Common User Interface module for Intel graphics cards
X
Personal Computer
scvhost.exe
W32/Rbot-AJE WORM! Note: This trojan file scvhost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item.
X
Personal Firwall
ptmedsrv.exe
SDBOT.XY WORM!
U
Pervasive.SQL Workgroup Engine
W3dbsmgr.exe
Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
U
PestPatrol Control Center
PPControl.exe
PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
U
PestPatrolCL
PestPatrolCL.exe
"PestPatrol's command line scanner, combines with the Windows Task scheduler and is required in cases where schedules for regular scanning are set"
U
Petit Larousse 2001
HIPL2000Popup.exe
Popup dictionary tool
X
PgMonitr
PgMonitr.exe
Delfin_Promulgate adware variant
Y
PGPSDKSVC
pgpsdkserv.exe
"PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality"
U
PGPSERVICE
pgpservice.exe
"PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a ""fall-back"" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference"
N
PGPtray
pgptray.exe
PGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs
X
pgtaff
pgtaff.exe
AdRotator adware variant
N
Phime2002a or PHIME2002ASync
TINTSETP.EXE
"Part of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word"
U
PhoneFree version 6.2
PHONEF??.EXE
An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here
N
Photo Express Calendar Checker SE
CALCHECK.EXE
"If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly"
N
Photo Loader supervisory
Plauto.exe
"Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures"
N
PhotoShow Deluxe Media Manager
mssysmgr.exe
"Simple Star PhotoShow_Deluxe photo editing and organizing software; makes it easy to send and share digital photos.. Bundled with software from Nero, ComCast, SnapFish, MacroMedia and others."
N
PhotoWise QuickLink
quicklnk.exe
"Agfa PhotoWise - ""PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more."""
N
Picasa Media Detector
PicasaMediaDetector.exe
Media detector for Picasa's automatic photo organizer
N
PicasaNet
Hello.exe
"Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs."
N
Pickatag
pickatag.exe
"Pick-a-tag - ""Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages"""
N
PICPRTR
PICPRTR.EXE
Program for viewing and measuring a variety of 3D CAD data formats
X
picsvr
picsvr.exe
Delfin_Promulgate adware
N
pictureBUZZTray
swtray.exe
System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually
U
PiDunHK
PIDUNHK.EXE
"Part of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens"
U
piiserviceOE
??
Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE
X
pilif
pilif.exe
W32.Fili worm infection
N
Pinger
pinger.exe
"Pinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification"
X
PingTimeout Institution
pingchek.exe
W32/SDBOT-VY WORM!
Y
PinnacleDriverCheck
PSDrvCheck.exe
Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
N
Piolet
piolet.exe
Piolet - peer-to-peer file sharing client
N
Piracy
SysUtil.exe
"""Software Piracy Alert"" feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: ""The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users."""
N
PivotSoftware
wpctrl.exe
"PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties"
X
Pixel32
Pixel32.exe
GEMA TROJAN!
X
Pixelpwr32
Pixelpwr32.exe
GEMA TROJAN!
X
Pixelsvr
Pixelsvr.exe
GEMA TROJAN!
U
pjWebCam
pjWebCam.exe
Webcam automation software that saves regular photos from webcam and can also act as HTTP server
X
PK Guard
pkguard32.exe
W32.Guapim WORM!
X
PK Services
pksvc.exe
W32/FORBOT-BW WORM!
U
PktAnything
PocketCompanion.exe
"PocketAnything lets you save anything on your computer to your mobile, with one click."
U
Planl?gningsagent
mstask.exe
"Windows Task Scheduler (on Danish language versions of Windows) - displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on."
U
PlaxoUpdate
InstallStub.exe
"Installstub.exe is is Plaxo's core executable program, which is used to check for new or updated information from the Plaxo Network. This program also interacts with Outlook."
U
PLEAPCPUCPL
pleapu.exe
CPU Control Panel for the Powerleap CPU upgrade
N
Plguni
Plguni.exe
McAfee QuickClean 3.0 - removes internet clutter and unwanted programs
U
plmg.exe
plmg.exe
Paragon Last Minute Bidder - auction assistant software
X
Plob
kernel.com
OPTIXPRO.12 VIRUS!
X
Plook
plook.exe
Affiliatetarget.com adware
U
Pluck Tray
PluckTray.exe
RSS (XML TAGS) reader program
N
PluckSvr
PluckUpdater.exe
Pluck Toolbar updater
X
Plug And Play
msnmsg.exe
W32/RBOT-ID WORM!
U
PLXSTART
PLXSTART.EXE
"Sets the spindown timeout and access speeds at startup and displays the ""Plextor Manager 2000"" splash screen for Plextor CD-RW."
N
PLXTASK
PLXTASK.EXE
"Taskbar utility for a ""control panel"" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)"
X
pm32ctrl
pwr32crtl.exe
CRYPTER.A trojan infection
X
pm32info
pm32info.exe
CRYPTER.A trojan infection
X
pmc
764.exe
Adult content dialler
X
PMedia
winsrvc.exe
Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B VIRUS!
X
pmr
pmr.exe
Powerstrip foistware variant
U
PMT
personalmoneytree.exe
According to the web site Personal_Money_Tree is an automatic cash rebate program. Note: Not recommended.
N
PMTSHOOT
pmtshoot.exe
MS tool for troubleshooting power management problems
U
PMXInit
pmxinit.exe
Restores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma?
N
PNAgent
PNAgent.exe
"PhatNoise Music Manager - manages WMA, MP3, WAV, etc music files"
X
PNP
wuaaclt.exe
W32/Lilbre-A WORM!
X
PnP Driver
playboy.exe
"W32/Forbot-FR WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. Added Note: This malware can collect system information, add or delete shares and users, kill processes, download and execute files, send email, remotely control a connected web cam, sniff network traffic or launch a denial-of-service attack!"
X
PNP FIX
??
W32/Rbot-AKQ WORM!
U
Pnpchk
Pnpchk.exe
Aztech Labs Sound 3 PnP driver
X
pnpsvc_lock
??
browser hijacker
X
pnpsvc_lock
startsvs.exe
browser hijacker
U
PNSetup
PNSetup.exe
PopNot - pop-up killer
X
PNtask Services
pntask.exe
LALA.C VIRUS!
U
Pocket Sheet Sync
PSXLTRAY.EXE
Casio Pocket Sheet synchronization software
X
Poet
Poet.exe
DOEP.A VIRUS!
X
Pofatch
nstrue.exe
RANDEX.Z VIRUS!
U
point32
point32.exe
Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
U
POINTER
point32.exe
Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
N
Points Manager
points manager.exe
Altnet TopSearch adware
X
Pollon
pollone.exe
SPYBOT.FW WORM!
X
POP
PopSrv***.exe
"PeopleonPage foistware, bundled with Grokster where *** are random digits"
PopOpen makes your windows spring open with animation effects
Y
Poproxy
POPROXY.EXE
"Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it"
X
popsrv146
popsrv146.exe
"PeopleOnPage online dating browser enhancement - also adware and privacy issues, see here. For removal instructions see here"
U
PopSubtract
PopSub.exe
PopSubtract - pop-up killer
U
Popup Ad Filter
PopFilter.exe
Popup Ad Filter - pop-up killer
X
Popup Blocker System
PopUpBlocker.exe
variant of the WIN32.RBOT WORM!
X
Popup Blocker System326a Monitoring
PopUpBlocker6a.exe
RBOT.AUH WORM!
X
Popup Blocker System8 Monitoring
PopUpBlocker8.exe
variant of the WIN32.RBOT WORM!
X
Popup Blocker Updater
??
SafeguardProtect/Veevo
X
Popup Defence Updater
??
SafeguardProtect/Veevo hijacker
X
Popup Defence Updater (required)
??
SafeguardProtect/Veevo hijacker
U
Popup Defender
PD.exe
Popup Defender - pop-up killer
U
Pop-Up Smasher
PopupSmasher.exe
Pop-Up Smasher - pop-up killer
U
Pop-Up Stopper
dpps2.exe
Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
U
Popup Terminator
GLADManager.exe
Popup Terminator - pop-up killer
U
Pop-Up_Blocker
Popup.exe
"A Tweak-XP component, blocks advertisement pop-up windows in Internet Explorer. Can be enabled/disabled via Tweak-XP -> Internet Tweaks"
U
Pop-Up_Scanner
Popupscn.exe
Panicware popup blocker
U
PopupEliminator
Popup Eliminator.exe
Popup Eliminator - pop-up killer
U
PopUpKiller
PopUpKiller.exe
PopUpKiller - pop-up killer
X
popuppers
newpop63.exe
Popuppers adware variant
X
popuppers64
a64sddd.exe
"Popuppers adware, also detected as the TROJ/LOWZONE-AA TROJAN!"
X
popuppers65
a64sddd.exe
Popuppers adware variant
X
popuppers65
a65d.exe
Popuppers adware variant
U
PopUpStopperCompanion
PSComp.exe
PopupStopper_Companion popup blocker
U
PopUpStopperFreeEdition
PSFREE.EXE
Pnaicware's Pop-Up Stopper - free limited features version
U
PopUpStopperProfessional
PopUpStopperProfessional.exe
Panicware's Pop-Up Stopper - paid for version
U
PopupVanish
PopupVanish.exe
Pop-up blocker
U
PopUpWasher
PopUpWasher.exe
PopUpWasher pop-up killer
U
PopUpWatch
PopUpWatch.exe
"Part of BPS Trace Remover - made by the folks who ""developed"" BPS Spyware Remover which reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!"
N
Post-It(r) Software
Psnotes.exe
"Pop-up ""yellow"" notes on screen. Available via Start -> Programs"
U
POW!
pow.exe
Pop-up killer
X
Power Scan
powerscan.exe
"""Foistware"" by Integrated Search Technologies - the people behind the ISTbar parasite"
U
Power_Gear
BatteryLife.exe
Power management for all Asus notebook. Useful but not critical.
N
PowerBar
Powerbar.exe
"Part of CyberLink's PowerDVD software; not sure what exactly it does, but not required in startup"
Y
PowerChute
Pwrchute.exe
"""During a power outage, if you're not available to save your files & close down Windows....PowerChute will do that for you. PowerChute will save your application files, close your applications and shut down your computer just like you would...otherwise, the APC UPS (Uninterruptible Power Supply) unit would go to battery until it wore down, then your computer would shutoff"""
U
PowerDOCSAPIHost
papihost.exe
"Hummingbird PowerDOCS - ""delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"""
N
PowerDVD
PowerDVD.exe
"Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled, PowerDVD will open automatically when a DVD movie is inserted. Launch manually"
U
PowerKey
PowerKey.exe
Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
X
PowerManagement
Rundlll.exe
SURDUX VIRUS!
X
PowerManager
Svchost.exe
JEEFO VIRUS! Note - this is not the valid svchost.exe as described here
Y
PowerPanel
POWPANEL.EXE
Power management utility on notebooks/laptops - automatically switches modes when running on battery
X
PowerPrifile
"rundl132 kenel.dll, PowerProfileEnable"
INMOTA VIRUS!
U
PowerPro
powerpro.exe
"Part of the power professional program that loads the floating menu bar. Can be accessed from Start -> Programs, but I'd leave it alone if you use this program"
X
PowerProf
PowerProf.exe
WIN32.LOREX.B TROJAN!
X
PowerProfile
mfcp30.exe
RINDAS-A TROJAN!
N
PowerQuest Startup Utility
PQINIT.EXE
"From a visitor - ""This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems"""
N
PowerReg Scheduler
PowerReg Scheduler.exe
"PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others"
N
PowerReg SchedulerV2
PowerReg SchedulerV2.exe
"PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others"
N
PowerReg SchedulerV3
PowerReg SchedulerV3.exe
"PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others"
N
PowerStrip
powerstrip.exe
PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
N
PowerStrip
pstrip.exe
PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
U
PowerTools Tray Icon
pttray.exe
PowerTools - add-on for AOL
U
Powertweak
PT2.EXE
"""Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured."" This item is added to startup if \'Use predefined settings\' is enabled in the programs options"
U
Powertweak
PTCTRL.EXE
"""Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured."" This item is added to startup if \'Configure system at logon\' is enabled in the programs options"
N
PP****usb
FBDirect.exe
"Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs"
U
PP2000 Instaupdate
PPInupdt.exe
Protector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
Y
PP2000 Real Time Scan
PPVstop.exe
Protector Plus anti-virus software - real time scanner
Y
PP2000 Taskbar Control
PPTbc.exe
Protector Plus anti-virus software - system tray access
N
PP3100b
flatbed.exe
"Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop"
U
ppass
Antispy.exe
"AntiSpy firewall - ""program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide"""
U
PPControl
PPControl.exe
PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
U
PPHIDPAD
pphidpad.exe
PenPower Chinese handwriting recognition software
U
PPK Setup(Server)
SEServe.exe
"Programmable Power Key on Sony Vaio laptops. ""Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended"""
U
PPMemCheck
ppmemcheck.exe
"PPMemCheck - ""extends PestPatrol's power so that the most dangerous Pests -- those that are about to execute -- are found, terminated, and cleaned from a user's system"""
X
PPPOEO
pingppac.exe
W32.Spybot WORM!
X
PPPOEOE
WINLITE.EXE
W32/RBOT-AAN WORM!
N
PProTray
pprotray.exe
Part of the power professional program. Loads the System Tray control
U
PPSVC
??
"PC_Police is spyware that logs keystrokes, files looked at, applications used, and chats on either MSN, Yahoo, ICQ or AOL. This information can then be transmitted to a remote user. If you didn't install this yourself remove it."
N
pptd40nt
pptd40nt.exe
"""PaperPort"" software associated with scanners"
U
PPUpdate
ppupdater.exe
"PPUpdater - ""is the update program that ships with PestPatrol. It is able to update licensed and evaluation versions, and presents a visual display of what it is doing"". Run manually unless you think you'll forget to check for updates on a regular basis"
N
PPWWebCap
PPWebCap.exe
"""PaperPort"" software associated with scanners"
X
pqhelper
pqhelper.exe
Searchcentrix hijacker
U
PractiSearch
PSearch.exe
PractiSearch web search software
U
Praize Messenger
itLoad.exe
Praize IM Christian chat instant messenger
U
Prayer
PTW.EXE
Islamic Adhan program (call fpr daily prayers)
X
prdtect
prdtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prmtect.exe and so forth!"
N
Precision Time Clock Checker
PrecisionTime.exe
Precision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
X
PrecisionTime
PrecisionTime.exe
PrecisionTime - clock synchronizing software containing adware by Claria/GAIN
X
precpop2
starter.exe
PrecisionPop adware
X
Prein
??
Unidentified adware
Y
Preload
Preload.exe
Millenium Multi-Function Keyboard driver
X
Premeter
nrpr.exe
"NetRatings software by Opistat . ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!"
X
Premeter
prmt.exe
"NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!"
X
Preview AdService
PrevAdServ.exe
Windupdates Adware Variant
Y
PrevxHome
SAGUI.exe
PrevX_Home intrusion prevention software
Y
PrevxPro
SAGUI.exe
Prevx_Home intrusion prevention software
X
prgtect
prgtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
Pribi.exe
Pribi.exe
FastFind adware variant
N
Price Patrol
neo.exe
Price Patrol by Half.com - internet shopping companion for finding the best on-line prices
U
Primax 3D Mouse
3dmoused.exe
Enables the scroll button on the Primax 3-D Scroll mouse
X
Print Driver Helper Service
crsrr.exe
AGENT-BC TROJAN!
N
Print Master Event Reminder
PMremind.exe
"Print Master Gold - calander feature that pops up reminders, such as birthdays"
N
Print Screen Deluxe
psdeluxe.exe
"Utility allows ""Print Scrn"" or ""Print Screen"" key to capture, print or save the current window"
X
Print Services
spolserv32.exe
RBOT.ZP WORM!
X
print sharing
??
ZCREW.B VIRUS! Note - this is not the valid Windows Explorer (explorer.exe)
X
print sharing
start.bat
ZCREW VIRUS!
X
Print Spooler
spool.exe
TROJ/BDOOR-IS TROJAN!
X
Print Spooler
spools.exe
W32/Rbot-LD worm infection
X
Print Spooler
Spoolsv.exe
"CIADOOR.B VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file"
X
Print Spooler
spoolsv32.exe
RBOT.SW WORM!
X
Print Spooler
spoolsvc32.exe
SDBOT.BB WORM!
X
Printer
dipset.exe
variant of the Proxy-FBSR TROJAN!
X
Printer
private.exe
Win32.Rbot worm variant
X
Printer
Spyassault.exe
"Bogus ""Spyware remover"" - see this list of non-Recommended anti parasite software"
U
printer
SpyAssaultScanner.exe
"Bogus ""Spyware remover"" - see this list of non-Recommended anti parasite software"
X
printer
sysprinter.exe
TROJ_SMALL.ZY TROJAN!
X
Printer Monitor
webprinter.exe
TROJ/IRCBOT-Z TROJAN!
X
Printer Spool
updater.exe
variant of the WIN32.RBOT WORM!
X
Printer spool Service
spool.exe
W32/RBOT-ACP WORM!
X
printer spooler
commonaccess.exe
Troj/Delf-LB TROJAN!
X
Printer Spooler Subsystem
spoolss.exe
"variant of the WIN32.RBOT WORM! - Note - this is NOT the legitimate Windows spoolss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
PrinterSpool
??
ALADINZ.K VIRUS!
X
Printing Driver
msprint.exe
RBOT.JH WORM!
N
Printkey2000
printkey2000.exe
Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
X
PrintMngr
system.exe
unidentified TROJAN!
N
printnow
printnow.exe
"PrintNow - a utility that primarily allows ""Print Srceen"" or ""Alt Print Screen"" screenshots to be sent directly to a printer"
N
PrinTray
Printray.exe
Lexmark/Compaq printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. See also LexmarkPrintray and CompaqPrinTray
N
PrintScreen
UNWISE.EXE
"Gadwin PrintScreen - utility to capture, print or save the current window"
N
Printscreen 95
PRT95MIN.EXE
"Printscreen 95 - utility to capture, print or save the current window"
X
PrintSpoolSv
System.exe
Troj/Bdoor-S worm infection
U
PRISMSTA.EXE
PRISMSTA.EXE
Creates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
Y
privacy cleaner
cleaner.exe
"Foxie Privacy Cleaner - Part of Foxie Security, Privacy and Productivity Suite"
N
Privacy Eraser Pro
PrivacyEraser.exe
Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities
U
PrivacyKeyboard
PrivacyKeyboard.exe
"PrivacyKeyboard is a product ""that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices, both known and unknown, currently in use or presently being developed worldwide."""
X
PrivacyScanner
pscan.exe
"""Privacy Champion"", a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to porn websites, and then offers to ""clean"" them.. Produces loads of False Positives as goad to purchase."
X
PrivateNet
??
Premium rate adult content dialer
U
Privoxy
privoxy.exe
"Privoxy - web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk"
X
PrizeSurfer
prizesurfer.exe
"""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
X
prjtect
prjtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prktect
prktect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prltect
prltect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prmt
prmt.exe
"NetRatings software by Opistat. ""OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits"". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!"
X
prmtect
prmtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!"
U
PrnSys Executable
PrnSys.exe
"Print screen utility bundled with some HP printer software; not required, but your choice if you like that feature."
U
Pro PCL Status Monitor
PENGSS.EXE
Xerox printer/fax/copier status monitor (PCL = printer control language)
X
process.exe
process.exe
PWSTEAL.BANCOS.P TROJAN!
U
ProcessGovernor
processgovernor.exe
"Process Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions."
U
ProcessSupervisorGUI
ProcessSupervisor.exe
"Process Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions."
X
procmon
procmon.exe
BIONET.40A VIRUS!
N
ProdikeysAutorun
Prodload.exe
"Creative Prodikeys software. ""an interactive music entertainment device which not only functions as a full-featured, ergonomic ?QWERTY? keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop."""
N
ProDsl
ProDsl.exe
Intel Pro/DSL 2100 modem connection manager. Available via Start -> Programs
X
Profile
Profile.vbs
WHITEHO or TRAPPY VIRUSES!
U
ProfileAMP
Profile8
"WinAmp media player add-on; ""will replace %s with the current Winamp song and %m with current memory stats every song change. Change the color of your links, have a count down to a certain date. Works for all versions of Winamp."""
X
profiler
liteout.exe
TROJ/ZAPCHAS-G WORM!
X
profiler
prof.exe
TROJ/ZAPCHAS-G WORM!
N
Profiler
Profiler.exe
"Enables the ""Profiler"" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs"
X
Prog
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
Prog
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
X
Program File
Progmon.exe
PEEPER VIRUS!
X
Program in Windows
iexplore.exe
variant of the LOVGATE WORM!
U
Program Neighborhood Agent
pnagent.exe
Citrix_Program_Neighborhood_Agent
N
projselector
projselector.exe
Roxio Project Selector; can be started manually
N
Promon.exe
promon.exe
System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
X
PromulGate
PgMonitr.exe
Delfin_Promulgate adware variant
N
PRONoMgr.exe
PRONoMgr.exe
System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
U
PRONoMgrWired
PRONoMgr.exe
Intel?s Pro 100 Ethernet card manager
U
Propel Accelerator
PropelAC.exe
Propel Internet Accelerator
U
ProPort Startup
ProPort.exe
"Proport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolving"
X
ProSiteFinder
prositefinder.exe
Adware by 180Solutions
X
Prote??o de tela
ssmaze.scr
BANCBAN-FB TROJAN!
X
protect
protect.scr
Troj/Dloader-TQ TROJAN!
U
Protect
SHVRTF.EXE
"PC_Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry."
X
Protected Storage
??
variant of the LOVGATE WORM!
X
Protection
??
variant of the Downloader.Agent.3.AU TROJAN!
X
Protection
Firewall.exe
W32.Elitper.A WORM!
X
Protection
Iexplore .exe
W32.Elitper.D WORM!
X
Protection
Norton Internet Security.exe
W32.ELITPER.E WORM!
X
Protection
Protection.exe
W32/FEBELNECK-A WORM!
X
Provan Security
psecure.exe
RBOT.BRV WORM!
N
PROXOMITRON
PROXOM~1.EXE
HTML proxy
N
Proxomitron
Proxomitron.exe
HTML Proxy
U
ProxyWay
proxyway.exe
ProxyWay anonymous proxy surfing software
U
PRPCMonitor
PRPCUI.exe
"Intel╜ SpeedStep? interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40%"
X
prqtect
prqtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prrtect
prrtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prstect
prstect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prtcct
prtcct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prttect
prttect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prutcct
prutcct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D."
X
prutdct
prutdct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutgct
prutgct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
pruthct
pruthct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutict
prutict.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutlct
prutlct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutpct
prutpct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutqct
prutqct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prutsct
prutsct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
pruttct
pruttct.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!"
X
prvtect
prvtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
prxtect
prxtect.exe
"""Prutect"" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!"
X
ps1
ps1.exe
PacerD_Media/Pacimedia.com adware component
U
PS2
ps2.exe
"Multimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lost."
X
psaload32
psaload32.exe
W32/Rbot-ADL Worm!
X
PSD Tools Channel
ChannelUp.exe
BuddyLinks adware
Y
PSDrvCheck
PSDrvCheck.exe
Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
X
PService
svcnow32.exe
TROJ/SPYBOT-DJ TROJAN!
U
PSFree
PSFree.exe
Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
X
PSGuard
PSGuard.exe
Bogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN!
X
PSGuard spyware remover
PSGuard.exe
Bogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN!
X
pshower
pshwr.exe
SafeSurfing adware variant
Y
PSIMSVC
PSIMSVC.exe
Panda Titanium Antivirus
N
PSIWin2.3 Connection Server
Psconsv.exe
Allows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
U
pskl
keyspy.exe
KeyboardLogger logs keystrokes and records the windows in which they were entered. If you didn't install it yourself remove it.
U
PsMFCard
PsMFCard.exe
"Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in use"
Y
PSNotify
psnotify.exe
"Pharos SignUp Vx - ""PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries"""
X
PSof1
PSof1.exe
PacerD_Media/Pacimedia.com adware installer
X
PSoft1
psoft1.exe
PacerD_Media/Pacimedia.com adware installer
U
PspContr
pspcontr.exe
Driver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver
U
PsSound
PsSound.exe
"On a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delay"
U
pst
memaker2.exe
SpymodePCSpy surveillance software. Uninstall this software unless you put it there yourself.
X
ptech
ptech.exe
"Related to ""Prutect"" malware from e2Give"
N
ptfb
ptfb.exe
"Push the Freakin' Button - ""When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"""
X
PtiuPbmd
??
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required?
U
PTRUN32
ptr32w.exe
Spyware.ParentTools surveillance software. Remove unless you installed it yourself!
U
ptrun32
ptrun32.exe
Parent Tools for AIM
N
Ptsnoop
Ptsnoop.exe
These descriptions I've come across - all valid as far as I can see :-
U
pttrun
pttrun.exe
"Transmeta Crusoe processor related. Reduces application launch times and makes the computer ""more responsive"""
N
PtUDFApp
PtUDFApp.exe
"Sony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start -> Programs. Note that you must add a /T switch to the command line to get it to load to the taskbar"
X
Public Microsoft ODBC
??
MASLAN.D WORM!
N
Pure Networks Port Magic
PortAOL.exe
"Pure Networks Port Magic, as available in the latest version of the AOL╜ 9.0 Optimized SE software; automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and video. See here"
U
Purgative
PURGATIVE100.EXE
AIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
X
Purgatory
Purga.exe
W32/Purgory-B WORM!
N
Push Client
pull.exe
Client software from Interwise that MS use for their webcasts
N
Push The Freakin' Button
ptfb.exe
"Push the Freakin' Button - ""When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"""
N
PUSH6599
PUSH6599.EXE
Scan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software
X
PutA!!
PutA!!.exe
OPASERV.L VIRUS!
X
PutAS!
PutA!!.com
OPASERV.Z VIRUS!
X
putil
??
Troj/LdPinch-AA trojan infection
X
putil
??
LDPINCH VIRUS!
U
PV92TRAY
PV92Tray.exe
PCtel HSP V.92 modem Configuration Utility
N
PVR
PVR.exe
Pocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card
U
PVUnInst1
PVUnInst1.exe
"Privacy_View is privacy software that ensures that all your private computer files, photos, documents, and websites remain secure from prying eyes."
N
pwindicator
pwic.exe
ParaWin XP - International Language Software for Windows XP/NT/2000
X
Pwr32ctr
Pwr32ctr.exe
GEMA TROJAN!
X
Pwr32ctrl
Pwr32ctrl.exe
GEMA TROJAN!
X
Pwr32mgt
Pwr32mgt.exe
GEMA TROJAN!
Y
Pwrmonit
Rundll32 PwrMonit.dll
IBM's proprietary 'battery maximiser' and power monitoring software for laptops
X
Pwroff
Pwroff.exe
GEMA TROJAN!
U
Pwrsave
Pwrsave.exe
Toshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
U
PwrupTweakMe
PUPXPTWK.EXE
"""Ashampoo PowerUp XP is a convenient tool for fine-tuning your Windows╜ NT4, 2000 and XP configuration to suit your precise needs and wishes. It gives you direct access to many frequently-required settings and parameters, enabling you to make your operating system behave the way you want.""?Boot-up options won't work if disabled?"
U
PWS Tray
PwsTray.exe
"Microsoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start -> Programs"
N
Q152404
??
Appears to run Scandisk at bootup on NEC PCs
X
q36i36O
lms2cenu.exe
SECONDTHOUGHT VIRUS!
N
QAGENT
qagent.exe
"Quicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the Internet"
X
qappsrvc32.exe
qappsrvc32.exe
Proxy_Trojan variant - identified by Kaspersky antivirus as Trojan-Proxy.Win32.Webber.m
N
QBCD autorun
autorun.exe
Quick Books CD
X
qbkupdbs
mqbkup.exe
OPASERV.K VIRUS!
X
qbotd
??
BOTTEN VIRUS!
X
QBRSR
QuickBrowser.exe
QuickBrowser/Top-banners.com adware
U
Qchex Tray Icon
Qchex.exe
Related to G7_Productivity_Systems Check Software.
U
QCTRAY
Qctray.exe
"System Tray icon providing access to the ""IBM Access Connections"" wizard on ThinkPad laptops and also allows to change the network environment. Not the same as QCWLIcon, which is pertinent only to the Wireless LAN"
U
QCWLICON
Qcwlicon.exe
"Used by IBM Thinkpad laptops with built-in wireless card (802.11). System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off"
N
QD FastAndSafe
QDCSFS.exe
Automatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
U
QDM or QDMStart
QdmStart.exe
"QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI\'s series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc"
X
qgqqft
??
Ranky.T TROJAN!
Y
QH Live Update Scheduler
UPSCHD.EXE
Quick_Heal Anti-Virus
Y
QH Office 2K Check
O2KCHECK.EXE
Quick_Heal Anti-Virus MS Office documents virus checker
N
QNPlus
QNPlus.exe
Quick Notes Plus by Conceptworld - sticky notes tool
U
Qoeloader
Qoeloader.exe
Qurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs
X
QQ
sendmess.exe
SEMES VIRUS!
X
QQServer
QQ.exe
Troj/DownLdr-AN TROJAN!
X
qservices
qservice.exe
Troj/Progent-A TROJAN!
X
qservices
qservice.exe
Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
N
QSort2000
QSORT.EXE
"Utility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose ""Sort by Name"""
U
QT4HPOT
OneTouch.exe
Hewlett Packard One Touch keyboard driver. Required if you use the additional keys
U
QTaskStartup
qtask.exe
"Feature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts feature"
X
QTime
nrchk.exe
Premium rate adult content dialer
N
QTSTUB.EXE
Qtstub.exe
Part of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders
X
QTSvc
msocfg.exe
Adult material premium rate dialer
X
QTSvc
navcke.exe
Adult material premium rate dialer
X
QTSvc
shman.exe
Adult material premium rate dialer
X
QTSvc
ssvr.exe
Adult material premium rate dialer
N
qttask
Qttask.exe
"System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards"
X
Quantifier Security
qsecue.exe
W32.Spybot.UOL WORM!
U
Quick Controls
Astrotoolbar.exe
Gateway Astro Screen and Sound Controls tray icon
U
Quick Heal Messenger
QHM32.EXE
"Quick_Heal Anti-Virus Messenger - Keeps you informed about the latest threats, hoaxes etc."
Y
Quick Heal On-Line Protection
Cateye.exe
Quick Heal - virus scanner
Y
Quick Heal Startup Scan
QHSTRT32.EXE
Quick Heal - virus scanner
N
Quick Shelf xx
qushelfxx.exe
"Places an icon in the system tray for launching MS Bookshelf. Available via Start -> Programs""xx"" represents the version number - ie, 98, 99"
Y
Quick Startup
Fquick32.exe
For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
X
Quick Time file manager
quicktimeprom.exe
SDBOT TROJAN!
N
Quick View Plus
QVP32.EXE
Quick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs
N
QuickBooks Delivery Agent
QBDAGENT.EXE
As far QAGENT but for QuickBooks. Can also have the version number in the name
N
Quickbooks Update Agent
qbupdate.exe
Associated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
U
QuickCamPro
QuickCamPro.exe
"System Tray for Picture Capture utility that can run unattended. Pictures every 30 seconds for example, auto FTP Upload, etc"
X
quicken
quicken.exe
CoolWebSearch parasite related.
X
quicken
Waol.exe
CoolWebSearch parasite related.
X
quicken
Winrar.exe
CoolWebSearch parasite related.
N
Quicken Scheduled Updates
bagent.exe
Quicken background downloading module
N
Quicken Startup
QWDLLS.EXE
Quicken option to load DLLs at startup
N
QuickenSEMessage
Qsemsg.exe
Quicken option
N
QuickFinder Scheduler
QFSCHD100.exe
Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
N
QuickFinder Scheduler
QFSched.exe
Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
Y
QuickLaunchEr
QuickLaunchEr.Exe
QuickLaunchEr - allows you to quickly launch programs from an icon in the system tray
N
Quicklink III
QL.EXE
"HP fax program and only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start -> Programs"
N
Quicknote
quicknote.exe
JC&MB Quicknote Virtual Scrapbook
U
QuickPassword
agquickp.exe
Smart card-based authentication and digital signature client software
N
QuickRes
QUICKRES.EXE
Utility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel -> Display. Not required unless you have to change resolutions on a regular basis
N
quickset
quickset.exe
Dell taskbar icon allowing you to quickly change settings
X
Quicktime
qttasks.exe
TROJ/ADCLICK-AK TROJAN!
X
Quicktime
shch.exe
variant of the TROJ/BDOOR-EB TROJAN!
X
Quicktime Mediaplayer
winmplyer32.exe
W32/RBOT-PM WORM!
X
Quicktime Mediaplayr
wnmplyr.exe
variant of the WIN32.RBOT WORM!
X
Quicktime Pro 3.0
winuodps.exe
GAOBOT.BH WORM!
X
Quicktime Runtime
Qtimer.exe
W32.SpyBot worm variant
X
Quicktime Task
??
NetVision dialer
N
QuickTime Task
Qttask.exe
"System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards"
X
QuickTime Task
qttasks.exe
CoolWebSearch parasite related.
N
QuickTime Update Completion x
quicktimeupdatehelper.exe
"Different numbers caused by number of launches. So if 3 updates are made separately, 3 would appear (in theory)"
X
QuicktimeMngr
QUICKTIMEMNGR.EXE
WOOTBOT.AW worm infection
X
Quicktlme
ru.exe
Adult content dialler
U
QuickTV
QuickTV.exe
Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control
X
Quickzip
Ls.exe
MsConnect browser hijacker and dialler
X
QuickZip
lu.exe
MsConnect browser hijacker and dialler
N
QuikShield
qkshield.exe
"QuikShield popup blocker - reportedly stealth installed, see here"
N
QuikSync
QUIKSYNC.EXE
Used by Iomega drives. Available via Start -> Programs
X
qwe
qwe.exe
TROJ/LINEAGE-F TROJAN!
U
QWS3270 Sessions
sessions.exe
QWS3270 Secure terminal emulation software
Y
r_server
r_server.exe
Radmin - remote admistrator server
X
r_server
service.exe
TROJ/MULTIDR-CP TROJAN!
X
RA Server
Slave.exe
RA VIRUS!
X
RabbitWannaHome
rabbit.exe
W32.MIMAIL.S WORM!
Y
Rabo Session Monitor
RaboSessionMon.exe
Related to RaboBank electronic banking software
N
RadarSync
RadarSync.exe
"Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically"
U
RadBoot
RadBoot.exe
RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
U
RadioSvr
RadioSvr.EXE
Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
U
Rainlendar
Rainlendar.exe
Rainlendar is a customizable calendar that displays the current month.
U
RAM Idle Professional
RAM_XP.exe
"RAM_Idle - a memory management program which manages the free RAM that is available to Windows, thus preventing your computer from running progressively slower over time."
U
RAMASST
RAMASST.exe
"Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP\'s CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs"
X
RamBooster2
rb.exe
AKAK VIRUS!
U
RAMDef
ramdef.exe
Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind
U
RAMDrive
RDTask.exe
Virtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarStone
U
RamIdle
ramidle.exe
"RAM Idle - ""A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by? freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows."" Some users swear by programs such as this but I suggest you read this article and make up your own mind"
U
RAMpage
RAMpage.exe
"Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source"
X
Randex virus built for IRBMe
irbme.exe
W32.Randex.RH worm infection
X
random 10-character filename
Winupdates.exe
W32/Rbot-MM worm infection
X
RandomWin32
mgnwin32.exe
W32/SDBOT-DV WORM!
X
rant
rant.exe
W32/RBOT-ZB WORM!
Y
RapApp
RAPAPP.EXE
"Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch"
X
Rapdata
ravsecs.exe
Troj/QQPass-V TROJAN!
X
Rapdatae
rabseuser.exe
TROJ/QQPASS-S TROJAN!
U
Rapid Restore
rrpcsb.exe
"XPoint ""Rapid Restore PC""; a ""Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user."""
X
RapidBlaster
rb32.exe
Homepage hijacker (adult content) - see this newsgroup thread
Y
Raptor Mobile
vpnservices.exe
"Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking"
X
RasCon Remote Access Service Manager
rasmngr.exe
WORM_SPYBOT.EM
X
rasctrs
rasctrs.exe
"Hijacker, also detected as the ADWAHECK TROJAN!"
X
Rase
boln.exe
PurityScan/Clickspring adware
X
RasMan.exe
RasMan.exe
Troj/Feutel-H Trojan!
X
rate.exe
??
Unidentified adware
X
rate.exe
i11r54n4.exe
BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS!
Y
RAV8Tray
ravtray8.exe
RAV anti-virus related
X
RAVEN_VLZS.EXE
RAVEN_VLZS.EXE
Another eAcceleration program - spyware. Read their privacy statement here
Y
RavMon
RavMon.exe
RAV AntiVirus
X
RavTime
Mstray.exe
WUKILL.A VIRUS!
Y
RavTimer
RavTimer.exe
RAV AntiVirus
X
RavTimeXP
??
WULLIK.B VIRUS!
X
RavTimeXP
Virus
CAGER.A WORM!
X
RavTimXP
??
WULLIK.B VIRUS!
X
RavUptpe
ravsesur.exe
TROJ/QQPASS-T TROJAN!
N
Ray Process Killer
Prkill.exe
"Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click ""Ok"" to terminate it. Use CTRL ALT DEL instead"
Y
razertra
razertra.exe
razer diamondback mouse driver
X
rb32 lptt01 or rb32 ml097e
rb32.exe
"Variant of the RapidBlaster parasite (in a ""RapidBlaster"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
rbenh ml***e
rbenh.exe
"Variant of the RapidBlaster parasite (in a ""RBEnhance"" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Rcf Driver
rcf.exe
RANDEX.BLD VIRUS!
X
rCron
dservice.exe
"""Switch"" premium rate adult content dialer"
X
rCron
rcron.exe
"""Switch"" adult content dialer"
U
RCScheduleCheck
RCSCHED.EXE
"Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
X
RCSync
RCSync.exe
"PrizeSurfer related. ""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
U
RDClient
RDCLIENT.EXE
Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection
X
RDLL
RunDll16.exe
SDBOT.F WORM!
X
rdvs
??
ULTIMAX VIRUS! <filename.exe> is the worm filename created
X
Reactor3
??
W32.BOFRA.A WORM!
X
Reactor5
??
W32.BOFRA.D WORM!
X
Reactor6
??
W32.BOFRA.C WORM!
X
Reactor6
??
W32.Mydoom.AK WORM!
X
Reactor7
??
W32.BOFRA.B WORM!
X
Reactor8
??
W32.BOFRA.E WORM!
X
Reactor9
??
W32.BOFRA.E WORM!
X
readdb40
??
LZIO.com adware downloader
X
Real Internet Player
Reaiplay.exe
variant of the W32.SPYBOT WORM!
X
Real player updater
realupd.exe
PARLAY VIRUS!
X
real scheduler
real scheduler.hta
CEEGAR TROJAN!
U
Real Spy Monitor
Winrsm.exe
Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
X
Real Statics Agent
ccreal.exe
variant of the WIN32.RBOT WORM!
X
RealAudio
RealAudio.exe
CEEGAR TROJAN!
N
RealDownload
RealPlay.exe
Download manager. Available via Start -> Programs
X
RealDownload Express
npnzdad.exe
Advertising spyware
N
Reality Fusion GameCam SE
RFTRay.exe
System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs
N
RealJukeboxSystray
tsystray.exe
System Tray icon for RealJukebox
X
realone_nt2003
moniker.exe
SNONE.A VIRUS!
X
RealP1ayer
??
"RPLAY.A TROJAN! **Note that the name has a number ""1"" in place of the second lower case ""L"""
N
realplay
realplay.exe
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X
realplay lptt01 or realplay ml097e
realplay.exe
"Variant of the RapidBlaster parasite (in a ""RealPlay"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name"
X
Realplayer Codec Support
realsched.exe
W32/AGOBOT-AAD WORM - NOTE - do NOT confuse with the Real Player executable as described here
X
Realplayer One
realplay.exe
W32/RBOT-NK WORM!
N
RealPlayer2
MsgCenterExe
RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way.
X
RealPlayerUpdater
realupd32.exe
TROJ/LOHAV-T TROJAN!
N
Realsched
realsched.exe
"Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry"
X
Real-Tens
Real-Tens.exe
DownloadWare based advetising spyware
U
Realtime Audio Engine
mmrtkrnl.exe
Associated with ALCATech BPM_Studio
Y
Realtime Monitor
realmon.exe
Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates
N
RealTray
RealPlay.exe
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X
RealUpdater
realupd.exe
PARLAY or MITGLIEDER.I VIRUSES!
X
RebateNation0
RebateNation0.exe
WebRebates adware variant
N
Reboot
Reboot.exe
MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
Y
Recguard
recguard.exe
"On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense"
N
Reclip
reclip.exe
Reclip Popup Clipboard manager
X
Recommended Hotfix - {0421701D-CF13-4E70-ADF0
RH.DLL
SmartPops adware
N
Recover
??
Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
N
RecShe
RecSche.exe
Recording scheduler for WatchTV Capture Card (TV Tuner card)
X
Recycle Bin Handler
recycler.exe
TROJ/SHUCKBOT-A TROJAN!
X
Recycle Bin Handler 2005
system.exe
TROJ/BDOOR-HO TROJAN!
X
RecycleSTR
msreg32.exe
W32/RBOT-TC WORM!
N
Red Flag
redflag.exe
PMS prediction program with modes for guys and girls - no longer available
X
Red Swoosh EDN Client
RSEDNClient.exe
Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network
X
redirect
redirect*.exe
Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit
N
Redline Taskbar
taskbar.exe
Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
X
REEGRUN
??
SECDROP.AI TROJAN
X
Reek 32 Server
reek32.exe
RANDEX.AL WORM!
U
Referee
referee.exe
MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run
N
Refresh
Refresh.exe
(Iomega) Refresh - loads the Iomega desktop icons at startup
X
Reg
Reg.hta
Homepage hi-jacker. Removal instructions here
X
Reg Service
ipcfg.exe
W32/Agobot-SO Worm!
X
Reg Service
REGSRV32.EXE
RBOT.ZW WORM!
X
Reg Service
WinnConfig.exe
W32/Agobot-PF Worm!
X
Reg Service
winslogon.exe
W32/AGOBOT-SC or W32/Agobot-SY WORM!
X
Reg Service
winsy.exe
variant of the W32.SpyBot WORM!
X
Reg Services
Winboot32.exe
WORM_RBOT.PB
X
reg_key
FUKULAMER.exe
BEAGLE.AH WORM!
X
reg_key
loader_name.exe
BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!
X
reg_run
Systen.exe
TROJ/BANCOS-BS TROJAN!
X
Reg_WFT
Regsysw.com
WILSEF VIRUS!
X
Reg_WFT
scanreg32.com
Troj/SennaSpy-F Trojan!
X
reg1.reg
vuamgard.exe
variant of the BACKDOOR.IRC.BOT TROJAN!
U
reg2.0
SVCH0ST.EXE
"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
Reg32
Reg32.exe
Hijacker - redirecting to only-virgins.com
X
reg32
reg32.exe
NOUPDATE.B VIRUS!
X
Reg32
reg33.exe
CoolWebSearch parasite related.
X
regcheck
??
SERVPAM TROJAN!
X
Regcheck
~CAB001.EXE
CYBERSPY VIRUS!
X
RegCleaner
SYSio32.exe
unidentified virus VIRUS!. Note - do not confuse this with the popular RegCleaner registry cleaner freeware
X
RegCompres
Regcpm32.exe
POLDO.B VIRUS!
X
RegCompres
REGCPM32.EXE
"Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return"
X
Regcxdinaf
REGCXDINAF.EXE
TROJ/BANCOS-BW TROJAN!
X
Regcxn
Regcxn.exe
COIBOA-D TROJAN!
U
regdefend
regdefend.exe
"RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage."
X
RegDone
services.exe
NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
X
RegDone
winlogon.exe
NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup!
X
RegDone Ex
csrss.exe
"WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
RegDoneEx
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
X
regedit
autoexe.exe
variant of the WIN32.RBOT WORM!
X
regedit
regedit.exe
"BRID.A VIRUS! Note - resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). The valid ""regedit.exe"" resides in C:\Windows (Win9x/Me/XP) or C:\Winnt (WinNT/2K)"
X
REGEDIT
Regsrv32.com
SOUTHGHOST VIRUS!
X
regedit
svchost.exe ccRegVfy
Trojan.Rona Trojan!
X
Regexit
runlli32.exe
Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Regexit
Updadv.exe
Troj/QQPass-N TROJAN!
U
RegFreeze
regfreeze.exe
RegFreeze anti-spyware software
X
reggsdg
spoolserv.exe
W32/SDBOT-MS WORM!
U
RegHelp
svchosts.exe
"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
U
REGIST~1
REGIST~1.EXE
"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X
Register Manager
RegistryManage.exe
SDBOT.AYH WORM!
N
Register MediaRing Talk
register.exe
If you don't want to register MediaRing and be reminded about it every bootup disable it
U
RegisterDropHandler
REGIST~1.EXE
"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation?"
X
Registration Service
toker.exe
W32/SDBOT-BB WORM!
N
Registration-Studio 8
RegTool.exe
Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems
U
Registry
??
"Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it."
X
Registry
wscript.exe
VBSWG VIRUS!
X
Registry Checker
Regrun.exe
SDBOT TROJAN!
X
Registry Checkup
winreg.exe
unidentified WORM or TROJAN!
X
Registry Checkup System326a Monitor
Winregs326a.exe
variant of the W32/SDBOT WORM!
X
Registry Integrity Checker
regintmon.exe
variant of the AGOBOT/GAOBOT WORM!
X
Registry Integritycheck
WCPDT.EXE
W32/AGOBOT-RF WORM!
X
Registry Loader
regloadr.exe
GAOBOT.AO WORM!
X
Registry Loader
winhlpp32.exe
GAOBOT.AO WORM!
X
Registry oidet
win32.exe
RBOT.BMT WORM!
X
Registry Scanner
regscanr.exe
OPTIX LITE FIREWALL BYPASS VIRUS!
X
Registry Server
regsrv32.exe
W32/Rbot-GM WORM!
X
Registry Service
REGSRV32.EXE
variant of the WIN32.RBOT WORM!
X
Registry Services
Registry.exe
DOWNLOADER.CILE VIRUS!
X
Registry System16 Checkup Monitor
SystemReg16.exe
variant of the WIN32.RBOT WORM!
X
Registry System166 Checkup Monitor
SystemReg166.exe
variant of the WIN32.RBOT WORM!
X
Registry Value Name
service.exe
W32/RBOT-AHT WORM!
X
Registry Value Name
winapi32.exe
variant of the WIN32.RBOT WORM!
X
Registry Value Name Start
MsPMSPSa.exe
variant of the W32/SDBOT WORM!
X
RegistryCheck
??
Ulubione adult content dialer
X
RegistryChk
winbackup.exe
MERTIAN VIRUS!
U
RegistryMechanic
RegMech.exe
"Registry Mechanic for Windows - ""you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"""
X
RegistryMonitor
registry.pif
Affilred adware
X
Regkey for autostart
winservice.exe
W32/RBOT-NU WORM!
Y
RegProt
Regprot.exe
RegistryProt from Diamond Computer Systems - protects the system registry against changes
X
Regptmens
REGPTMENS.EXE
Troj/Bancos-ED TROJAN!
X
REGRUN
??
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
X
REGRUN
dialer.exe
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
X
RegRun
mActiveX.exe
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
X
REGRUN
regeditt.exe
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
X
REGRUN
sory.exe
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
X
REGRUN
winfix22490.exe
Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
U
RegRun WinBait
winbait.exe
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
Y
Regrun2
WatchDog.exe
"Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc?"
X
REGRUNM
autoprotect.exe
unidentified WORM or TROJAN!
X
Regrx
rundll32.exe
"TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!"
X
RegScan
DLLSRV32.EXE
AGOBOT.AEW WORM!
X
RegScan
Regscan.exe
BACKDOOR.TALEX TROJAN!
X
Regscan
regscanr.exe
TROJ/OPTIX-SE TROJAN!
X
regservices.exe
regservices.exe
W32/Rbot-MN worm infection
N
RegShave
regshave.exe
"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly"
X
regsrv
regsrv.exe
OPTIXPRO.11 VIRUS!
X
regsrv
scvhost.exe
AGOBOT.E WORM!
X
regsrvc
regsrvc.exe
TROJ/STOPED-A TROJAN!
X
Regsv
regsv.exe
Search hijacker - redirecting to scheo.com
X
Regsvc
regsv.exe
unidentified TROJAN!
U
regsvc
systune
AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
X
regsvc32
regsvc32.exe
Homepage hijacker that changes your homepage to an adult content site
X
regsvr
regsvr.exe
WEBMONEY-G TROJAN!
U
REGSVR32
??
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
X
RegSvr32
msmsgs.exe
Trojan.Zlob.B or Troj/Zlob-M TROJAN!
X
regsync
regsync.exe
SafeSurfing adware
U
RegTweak
RegTwk.exe
"Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface"
X
RegVer
REGVER.EXE
LATINUS.16 VIRUS!
X
RegWrite
csrss.exe
"SOKACAPS VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling"
U
Regx10EXE
atix10.exe
ATI Remote Wonder - PC wireless remote control
U
ReleaseRAM
RRAM.exe
"""Release RAM allows your computer to run faster and uses your computer's RAM more efficiently"". Some users swear by programs such as this but I suggest you read this article and make up your own mind"
X
Reload
reload.exe /reloadenterpice
Lazar TROJAN!
X
reload
reload.vbs
LOVELETTER.AS VIRUS!
N
RemHelp
Remhelp.exe
BT Voyager ADSL Modem Help related
N
Remind_XP
Remind_XP.exe
"Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package"
N
Reminder
Remind_XP.exe
"Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package"
N
Reminder
reminder.exe
From MS Money. Reminds you of your bills
N
Reminder-cpqXXXXX
remind32.exe
Compaq printer Registration
N
Reminder-hpcXXXXX
remind32.exe
HP CD-Writer Registration
N
Reminder-ranXXXXX
remind32.exe
Registration reminder widget for Rand Mcnally maps
N
reminder-ScanSoft Product Registration
remind32.exe
Registration reminder for ScanSoft products such as PaperPort
U
RemindMe
RemindMe.exe
Remind-Me - calendar software
X
Remndr
CsRemnd.exe
CasinoOnline foistware
U
Remote Access
rnaapp.exe
"Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed"
X
Remote Access Slave
Synchost.exe
RIPJAC VIRUS!
N
Remote Control
Rc.exe
Hinet Hi-Five ISP software
N
Remote Controller
TVRMVCR.EXE
ProLink PlayTVpro TV tuner software
U
Remote Desktop Computing
marspc.exe
Marspc Remote Desktop Computing
U
Remote Management Agent
zenrc32.exe
"Part of Novell's ZENworks - ""Complete End-to-End Directory-enabled Network Management"". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation"
U
remote master
remote master.exe
Required if you want your ASUS Remote control to work at all. Available via Start -> Programs
X
Remote Procedure Call
winrpc.exe
W32/Rbot-KM worm infection
X
Remote Procedure Call
winsysrpc.exe
W32/Sdbot-PS worm infection
X
Remote Procedure Call For Windows 32bit
rpc.exe
W32/Rbot-MD worm infection
X
Remote Procedure Call Locator
??
variant of the LOVGATE WORM!
X
Remote Procedure Calls
mswinc.exe
W32/RBOT-IT WORM!
X
Remote Procedure Calls
mswinrpc.exe
RBOT.KJ worm infection
X
Remote Procedure Calls
win.exe
W32/SDBOT-QI WORM!
Y
Remote Update Monitor
imonitor.exe
Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer.
N
Remote_Agent
RemoteAgent.exe
"Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs"
Y
RemoteAgent
RAUAgent.exe
"Trend Micro's Office Scan Client, see here ; ""Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates""."
U
RemoteCenter
RcMan.exe
"Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats"
U
RemoteControl
PDVDServ.exe
"Remote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one"
U
RemoteControl
rmctrl.exe
"Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one"
X
REMOVE ME
windos.exe
SDBOT.EE WORM!
N
Removecpl
Removecpl.exe
Related to a Belkin 54Mbps Wireless Utility Control Panel applet
X
Removed.exe
Removed.exe
GatorCheat - adware downloader
U
RepliGo Assistant
RepliGoMon.exe
"Cerience RepliGo software - ""any document you have on your PC can be transferred to your mobile device"""
U
ReproPRD
PrdUsb.exe
"Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work"
X
requester
requester.*.exe
"variant of the Win32.Muquest.A trojan - NOTE: the asterisk stands for a digit, examples: requester.5.exe, requester.10.exe"
X
Required Service Drivers
micront.exe
W32/RBOT-ABD WORM!
X
resagnt
restun.exe
Adware downloader - detected by Panda antivirus as Trj/Downloader.ALQ
X
reseurce
??
Troj/Lineage-AI TROJAN!
N
Resolution Assistant
matcli.exe
"Dell Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide"
N
Resource Meter
rsrcmtr.exe
Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes
U
Restart WSC Setting
wscrestp.exe
WinStart Commander - part of Ultra_WinCleaner_Utility_Suite . Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes.
Y
RestoreIT!
VBPTASK.EXE
"RestoreIT! from FarStone ""allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure."""
X
restory
restory.exe
RETSAM VIRUS!
U
Resume Copy
copyfstq.exe
Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function
U
ResumeFixClocks
resumefix.exe
Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards
X
retime
retime.exe
GIPMA VIRUS!
U
RetrieverScheduler
retrieverscheduler.exe
"80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information"". Real-time scheduler - shortcut available"
U
RevoTaskbarApp
RevoTask.exe
Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it; but changes to speaker setup and sound modification (Bass/Treble etc) will not be available.
N
RexSyMon
rexsymon.exe
Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC
X
RF
EC.exe
Troj/Lineage-U TROJAN!
U
rfagent
rfagent.exe
"Registry_First_Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders"
X
RFTray
RFTRay.exe
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
Y
rfw
Rfw.exe
RAV AntiVirus
N
RFX_auto_upgrade
??
A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade
U
RH
rh32.exe
EuroFonts - adds Euro symbols to pre-Euro computers
X
Rhino
??
W32.BOFRA.A WORM!
U
RhinoBlocker
RhinoBlocker.exe
RhinoBlocker - pop-up stopper
N
RHSI SHS
SHS.exe
"Rogers Hi-Speed Internet software. ""Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash"""
X
richup
richup.exe
SafeSurfing parasite variant
U
Ring Central Fax
rcenterrll.exe
Only needed if you want a PC to answer faxes automatically
X
rIOphosIs
rIOPHosIs.vBS
RIOSYS VIRUS!
U
RivaTuner or RivaTunerStartupDaemon
RivaTuner.exe
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes
U
rmctrl
rmctrl.exe
"Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one"
N
rmmon
mprmmon.exe
Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card
X
rn4d
dirote.exe
BKDR_MAROON.A TROJAN!
X
RNBc Test
bvldv32.exe
W32/Rbot-AJF WORM!
X
RNBc Test
wf32vbs.exe
W32/Rbot-AGR WORM!
U
RNBOStart
sentstrt.exe
Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
X
RNBz Test
wf32vbc.exe
W32/Rbot-AEY Worm!
X
RNDc Test
wf32b.exe
variant of the W32/SDBOT WORM!
X
rngmf
??
RANKY.C VIRUS!
X
Rnudll32
tadxtr.exe
TROJ/QQPASS-O TROJAN!
X
Roam04
ActiveX.exe
Troj/Roamer-A TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder.
N
RoboForm
RoboTaskBarIcon.exe
"Roboform - password manager and web form filler. Will work without this startup entry, as the ""active"" component is an integrated Internet Explorer browser plugin"
N
RoboFormWatcher
RoboFormWatcher.exe
AI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs
U
Rocket.Time
RocketTime.exe
Time synchronization software from Rocket Software
X
rollbk
dsm.exe
W32.Serflog.B WORM
X
rollbk
msmpatch.exe
W32.Serflog.B WORM
X
rollbk
svosm.exe
W32.Serflog.B WORM
X
rollbk
sysup.exe
W32.Serflog.B WORM
X
romahere
matrixhere.exe
SuperSpider hijacker - a CoolWebSearch parasite variant
X
romahere2
??
SuperSpider hijacker - a CoolWebSearch parasite variant
X
romahere3
??
SuperSpider hijacker - a CoolWebSearch parasite variant
X
Root_Machine
??
Troj/Bancban-DI TROJAN!
X
ROOT_Machine
winlogon.exe
Troj/Banker-FI TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\inf or Winnt\inf folder.
N
RoxAssist
RoxAssist.exe
"Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message ""Engine initialized successfully with full recorder support"". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use ""Add Remove Programs"" in ""Control Panel"".) .Can be run manually"
N
RoxioAudioCentral
RxMon.exe
"Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. ""Includes a player, media manager, ripper, tag and sound editor - integrated in a single application"". Not required for Roxio to work properly."
N
RoxioDragToDisc
DrgToDsc.exe
"Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly"
Y
RoxioEngineUtility
EngUtil.exe
"Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking"
U
RP32
rp32.exe
ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems.
X
RPC
MSschost.exe
variant of the GAOBOT/AGOBOT WORM!
X
RPC Patcher
??
BOLGI VIRUS!
X
rpc Win32
shost32.exe
W32/RBOT-ABL WORM!
X
rpc Win32
spoolscv.exe
variant of the WIN32.RBOT WORM!
X
rpcda Win32
rpcda.exe
W32/Rbot-AE Worm!
X
RPCserv32
services.exe
"W32.MYDOOM.AL WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
RPCserv32g
CSRSS.EXE
"BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
RPCserv32g
MSDEFR.EXE
BOBAX.AD WORM!
X
RPCserv32g
NB32EXT2.EXE
BOBAX.AD WORM!
X
RPCserv32g
services.exe
"MYDOOM.BH WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
RPCserv32g
services.exe
"W32.BOBAX.AA WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
RPCserv32g
services.exe
"W32/MYDOOM.BV WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
RPCserv32g
SMSS.EXE
"BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
RPCserv32g
WINLOGON.EXE
"BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
Y
RPCSS.exe
rpcss.exe
"Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here"
X
RpcxWindows Extensions
rpcxwinex.exe
RBOT.ACP WORM!
X
rreg
rreg.exe
Unidentified adware
X
RRMedic
rrmedic.exe
Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection
U
rscmpt
rscmpt.exe
Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status
RssReader - a free RSS reader able to display any RSS and Atom news feed (XML)
X
RSync
netsync.exe
SafeSurfing adware
X
rtcdll
rtcdll.exe
Unidentified adware
N
RtlMon.exe
RtlMon.exe
Monitor for RealTek network card
Y
RTMonitor
RTMonitor.exe
"Cheyenne, ( now eTrust ) antivirus"
X
rtos
rtos.exe
IRC trojan
Y
rtvscn95
RTVSCN95.EXE
Real-time virus scanner component of Norton Anti-Virus Corporate Edition
X
Ruby13
Ruby13.exe
MEXER.E worm
X
Ruby14
Ruby14.exe
W32/FIGHTRUB-A WORM!
X
ruin
system32.exe
TROJ/DELF-JM TROJAN!
U
RuLaunch
RuLaunch.exe
"Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis"
X
run
Autoexec.com
HOLCAS.A WORM!
X
run
dec25.exe
W32.ATAK.F WORM!
X
run
inetinfo.exe
Backdoor.Binghe TROJAN!
X
Run Msn Messenger
msnmgr.exe
AGOBOT.HA WORM!
X
Run MSupdt32
wscript MSupdt32.vbs
CASER VIRUS!
U
Run POPFile in background
perl.exewperl.exe
POPFile - E-mail spam blocker
X
Run Services as Application
localsvc.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
netsvc.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
svcman.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
svcrun.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Run Services as Application
websvc.exe
Troj/Dloader-NY Trojan!
U
Run StartupMonitor
StartupMonitor.exe
"Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu"
X
Run TaskMrg
csrss.exe
TROJ/LDPINCH-W TROJAN!
X
run windows
servic.bat
REBOOT-AP TROJAN!
X
Run XP Service Pack
xpservicepack.exe
Sdbot.AQA worm infection
X
Run[0]
syscnfg.exe
"Added as the result of an unidentified VIRUS!. ""syscnfg.exe"" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside"
X
Run_cd
Run_cd.exe
GHOST.23 VIRUS!
Y
run=
asistat.exe
"Used with some models of Panasonic, Epson and NEC printers - required for printer to work."
X
run=
Autoexec.com
HOLCAS.A WORM!
X
run=
Celine.scr
TROJ/CELINE-A TROJAN!
X
run=
clean_service.cmd
W32.Refaz WORM!
X
run=
cyxid98.exe
Unidentified malware
X
run=
dllreg.exe
TROJ/DUMARU-L TROJAN!
X
run=
DRDOOM.EXE
W32/SEMAPI-A WORM
N
run=
fmedia.exe
FMedia FaxWorks related - can be run manually
X
run=
fntldr.exe
CoolWebSearch parasite related.
N
run=
hpfsched
HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
X
run=
htmlsync.exe
Searchforfree.info browser hijacker
X
run=
iexpIore.exe
OBLIVION-B TROJAN!
X
run=
info32.exe
CoolWebSearch parasite variant.
N
run=
lxdboxcp.exe
Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
X
run=
mdm.exe
TROJ/PROXY-GG TROJAN!
X
run=
mouse_configurator.win
VBS.GAGGLE.E WORM!
X
run=
msoffice.exe
"ADWARELOADER TROJAN! - NOTE: Do NOT confuse with the (legitimate) Microsoft Office file, which would typically be located in the Program Files\Microsoft Office\Office folder!"
X
run=
msreg32.exe
BACKDOOR-FORCEDENTRY TROJAN!
X
run=
Msvxd.exe
W32.DATOM WORM!
X
run=
msxmidi.exe
CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
N
run=
pcfix2k.exe
pcfix2k splash screen
X
run=
ptlseq.cpl
PhoenixNet BIOS adware. See here
U
run=
ramsys.exe
Advanced Startup Manager from Rays Lab
X
run=
RAVMOND.exe
variant of the LOVGATE WORM!
X
run=
real.exe
variant of the LOVGATE WORM!
X
run=
RegistryReminder.exe
APSTROJAN.OB TROJAN!
X
run=
services.exe
"Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!"
X
run=
services.exe
"TROJ/KREPPER-N TROJAN! - NOTE - this file is placed in a inet10066 folder in Winnt or Windows , and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
Y
run=
smsrun16.exe
"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs"
X
run=
svcinit.exe
CoolWebSearch parasite related.
X
run=
svhost.exe
ADMINCASH.B TROJAN!
X
run=
winlogon.exe
CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process!
X
run=
wmplayer.exe
CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable!
Y
run=
wswpd.exe
"Used with some models of Panasonic, Epson and NEC printers - required for printer to work."
X
Run05
rundll_32.exe
Troj/Bancos-DT TROJAN!
X
Run32dll
ocxdll.exe
Unidentified mIRC VIRUS!
X
run32dll
task32.exe
Unidentified mIRC VIRUS!
X
run32dll
WINClock.exe
Unidentified mIRC VIRUS!
U
RunAlert
AService.exe
"MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system"
N
runAP
runAP.exe
Not required but what is it?
X
Runapp32
Runapp32.exe
NEODURK VIRUS!
Y
RunCA
InvokeSvc3.exe
Wireless-G USB Wireless Network Adapter related - would appear to be required
X
rund1132
rund1132.exe
W32/DOPBOT-A WORM!
X
Rund1132.exe
Rund1132.exe
Troj/StartPa-HS TROJAN!
X
Rund1l32
Winfi1e32.exe
MERTIAN VIRUS!
X
Rundil32
runlli32.exe
Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Rundil32
Updadv.exe
Troj/QQPass-N TROJAN!
X
rundl332
math.exe ...pluged.exe
DOOMJUICE VIRUS!
X
rundli32
rundli32.exe
LADE VIRUS!
X
Rundli32
runlli32.exe
Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Rundll
??
MYTOB.IG WORM!
X
RunDLL
??
Flingstone.com browser hijacker
X
Rundll
Rundll~.exe
W32/DELF-KT TROJAN!
X
Rundll16
Rundll16.exe
any number of VIRUSES!
X
rundll32
??
AUTEX VIRUS!
U
rundll32
??
Associated with a Bluetooth adapter. If disabled the error dialogue box disappears
N
RunDLL32
??
"System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game ""Everquest"". Otherwise, settings can be changed manually via Display Properties"
N
RUNDLL32
??
"System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the ""NVIDIA Driver Helper Service"" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)"
U
rundll32
??
Loads default settings for Leadtek Winfast graphics cards
X
rundll32
csrss.exe
"GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!"
X
RUNDLL32
rundl32.exe
W32/Demotry-A Worm!
X
Rundll32
Rundll32.exe
"DVLDR VIRUS! Note - this is not the valid ""Rundll32.exe"" as it\'s in the Windows\Fonts directory"
X
rundll32
rundll32.exe
"SANKER VIRUS! Note that the valid ""rundll32.exe"" resides in C:\Windows\System32 wheras this version resides in C:\Windows"
X
Rundll32
Windows.exe
QQPASS.E VIRUS!
X
RunDLL32
winupdate.exe
Unidentified VIRUS! - possibly a BMBOT variant
N
Rundll32 cmicnfg
"Rundll32 cmicnfg.cpl, CMICtrlWnd"
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
X
runing
win.exe
Troj/Delf-LC TROJAN!
X
RUNLOAD
l0ad.exe
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
X
RUNLOUD
loud.exe
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
U
RunOnce
RUNONCE.EXE
Part of MS Data Access Components - only required if you use these
X
RunProg
Server.exe
OPTIX.04.A VIRUS!
X
RunProg
wini.exe
OPTIX.04.D VIRUS!
X
runreper
viewer.exe
W32.REPER.A WORM!
X
runs
run.exe
W32/Rbot-BWF WORM!
X
RunServices
runsvc32.exe
AGOBOT.QJ WORM!
X
runSubvalues
??
TROJ/DLOADER-QY TROJAN!
U
RunSysd32
RunSysd32.exe
DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
X
Runtt1
Internat.exe
Troj/Lineage-R Trojan!
X
Runtt1
Internet.exe
Troj/Lineage-Q Trojan!
X
RunWin
??
TROJ/BANKER-ES TROJAN!
X
runwin32
runwin32.exe
Troj/ESearch-A trojan
X
RunWindowsUpdate
uptodate.exe
BrowserAid/BrowserPal foistware
U
Rupsw32
Rupsw32.exe
"MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems."
X
RVC6Player
tskdbg.exe
TROJ/ZAPCHAS-M TROJAN!
X
rvde
??
Related to li-speed****
X
RVP
bpc.exe
BroadcastPC adware
N
RxMon
rxmon9x.exe
Dell Resolution Assistant
X
S0undMan
svch0st.exe
"variant of the LOVGATE WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
S3 Internal Chip
s3serv.exe
W32/AGOBOT-DD WORM!
N
S3apphk
S3apphk.exe
A tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems.
N
S3TRAY
S3Tray.exe
S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
U
S4F
S4F.exe
S4F internet filtering software
X
s4helper
s4helper.exe
Searchcentrix hijacker
N
Sa3dsrv
Sa3dsrv.exe
3D sound extension for Windows
X
saap
saap.exe
180Solutions/N-Case adware variant
N
Sabreserver
SABSERV.EXE
Airline reservation software from Sabre. Available via Start -> Programs
X
sac
sac.exe
180Solutions/N-Case adware variant
X
SACC
sacc.exe
SurfAccuracy adware
N
SAClient
RegCon.exe
"AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you\'re immediately notified by e-mail, pager, or text messaging"
X
Safe
??
Troj/Banker-DT TROJAN!
X
Safe
SafeWin.exe
PWSteal.Focosenha trojan infection.
X
SafeGuard Popup Blocker Updater
??
SafeguardProtect/Veevo
X
SafeGuard Popup Blocker Updater (required)
??
SafeGuardProtect/Veevo
X
SafeGuard Popup Updater (required)
??
SafeguardProtect/Veevo hijacker
U
SafeHouseSystemTray
SDWTRAY.EXE
"SafeHouse ""Personal Privacy"" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them ""invisible"" and encrypted."
N
SafeInstall.exe
SAFEIN~1.EXE
Monitors a download and ensures an newer version of a file isn't replaced by an older one
N
SafeOFF
SafeOff.exe
Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
X
SafeSearch
safesearch.exe
AutoSearch parasite variant
X
SafeSurfingUpdate
SSUpdate.exe
DyFuCa/MoneyTree parasite variant
U
Safeworld
Freedom.exe
SafeWorld Internet Security
X
Sagate Security Firewall
sagate.exe
W32.GAOBOT.BOW WORM!
N
SAgent2ExePath
SAgent2.exe
Seiko Epson printer status agent. Disable if printer is not used often
U
SAGENTSERVICE
Sagent.exe -start
TinySpyAgent **Note this application must be manually installed.
X
sagnt
sagnt.exe
Adware web downloader
X
SAHagent
Sahagent.exe
ShopAtHomeSelect adware
X
SAHBundle
bundle.exe
ShopAtHomeSelect adware
X
SAHBundle
shop1003.exe
ShopAtHomeSelect adware
X
saie
saie.exe
180Solutions/N-Case adware variant
U
SAIMON
SaiMon.exe
Saitek joystick driver
X
sain
sain.exe
180Solutions/N-Case adware variant
X
sais
sais.exe
180Solutions/N-Case adware variant
U
SaitekAutoConfigure
saicnfig.exe
Configuration for Saitek game controllers
X
Sakemsneql
simenu.exe
SDBOT.BTO WORM!
X
salm
salm.exe
180Solutions/N-Case adware variant
U
SAMcal
SAMcal.exe
SamCal - calendar/reminder program
U
Sametime Connect
Connect.exe
IBM Lotus Instant Messaging and Conferencing software
X
Samsong
Samsong.exe
SDBOT.BNE WORM!
X
Samsung
Samsungs.exe
IRC_TROJAN variant!
X
Sam-sung
Sam-sung.exe
variant of the W32/SDBOT WORM!
N
SandIcon
SandIcon.exe
"SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources"
X
sapp
sapp.exe
180Solutions/N-Case adware variant
X
saSyncMgr
??
Browser hijacker - redirecting to Searchant.com
U
SATARaid
SATARaid.exe
RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
X
satmat
satmat.exe
Transponder parasite updater/installer
X
sau
sau.exe
180Solutions/180Search adware
U
SAUpdate
SAUpdate.exe
Big Brother from Quest Software. System and network monitor
U
SAutoLaunchExe
SAutoLaunchExe.exe
"Sharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook."
Y
SAVAgent
SAVAgent.exe
"Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users"
X
Save
Save.exe
SaveNow adware
X
SaveDate
SaveStartDate.Exe
Unidentified adware
X
Savenow
SaveNow.exe
SaveNow adware
X
Savenow
savenow.exe
SaveNow adware
X
SAW
saw.exe
SmartAdware adware
U
Say The Time 5.0
SAYTIME.EXE
"This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly"
U
SB
sb.exe
Acer Soft Button on Acer Tablet PCs
N
SB Audigy 2 Startup Menu
??
"Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function"
X
SB Watchdog
SBWatchdog.exe
Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information
U
SBAutoUpdate
sbautoupdate.exe
SpywareBlaster auto-updater
U
SBC Self Support Tool
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file"". The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in ""add/remove programs"" some help menus in help and support will not be available. You decide"
N
SBC Yahoo! Connection Manager
ConnectionManager.exe
The cmanager.exe process is used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection.
U
SBDrvDet
SBDrv.exe
"Detects the ""Easy Front-Panel Audio Connectivity Drive Internal Drive Bay"" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one"
N
sbdrvdet
sbdrvdet.exe
Checks to see if Creative sound card driver should be updated
X
SBHC
sbhc.exe
SuperBar parasite - uninstall available here
X
SBMPOP
SBMPop.exe
SearchByMedia adware
N
SBMX
sbmx.exe
SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)
X
sbss Launcher
sbss.exe
SideBySide adware
U
SbUsb AudCtrl
"RunDll32 sbusbdll.dll,RCMonitor"
Control for Soundblaster MP3 external (USB) sound card
U
sc
run.exe
"All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file."
U
sc
sc.exe
Watchdog 2.0 Software - monitoring program
N
sc
scrubxp.exe
"ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc"
Y
SC3300CC
SC3300CC.exe
SiPix digital camera Twain device driver
X
scain
s030109.Stub.exe
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
ScamDisk
SVOHOST.exe
LEWOR.D WORM!
X
scan
mscman.exe
"Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,? ""able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"""
X
Scan Register
ssms.exe
W32/RBOT-AT WORM!
X
ScanDisc
satan.exe
GregStar backdoor TROJAN!
X
ScanDisk
ScanDisk.exe
"GANDA.A VIRUS! Note - this is not the valid ""ScanDisk"" Win9x/Me standard disk error checker"
X
scands32.exe
scands32.exe
variant of the Adclicker TROJAN!
N
Scanner Detector
SDetect.exe
"ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the ""GO"" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the ""GO"" button"
X
Scanreg
??
QQPASS.E VIRUS!
X
ScanRegistry
nsrvnt.exe
NERTE VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe
X
ScanRegistry
scanregv.exe
MASTERLOCK VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe
X
ScanRegistry
Scanregw.exe
"W32.STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt). Runs from the registry RunServices key as opposed to the Run key"
X
ScanRegistry
Scanregw.exe
"GWGHOST VIRUS!. Not to be confused with the real ScanRegistry above - which is a vital Windows file. The executable ""Scanregw.exe"" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt)"
Y
ScanRegistry
Scanregw.exe
"Scans the Windows 98 and Millennium system Registry and makes back-ups at start-up. This is vital should the registry become corrupt. The ""Scanregw.exe"" executable is located in %windir% (the Windows directory - typically C:\Windows)"
X
ScanSpyware v *
Scanner.exe
"""Spyware remover"" (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
N
SCardSvr
scardsvr.exe
Related to SmartCard readers and sometimes uses lots of system resources
X
SCardSvr
SCardSvr32.Exe
MOFEI.B VIRUS!
X
scheck
scheck**.exe
KETCH VIRUS! where ** represents a number
X
scheck45
scheck45.exe
Related to unknown Malware - hidden installer associated with it
X
ScheduIe
nrchk.exe
Premium rate adult content dialer
N
Scheduled Maintenance
Scheduled_Maintenance.exe
Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs
X
Scheduler
expIorer.exe
WIN32.TACTSLAY.A TROJAN!
X
Scheduler
MSMSGS.EXE
"TROJ/HOSTBANK-A TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32\Config or Winnt\System32\Config folder, and should not be mistaken for the MSN Messenger file of the same name!"
X
Scheduler
outIook.exe
WIN32.TACTSLAY.A TROJAN!
U
Scheduler
Scheduler daemon.exe
"Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings."
X
Scheduler
svcrhost.exe
WIN32.TACTSLAY.A TROJAN!
X
Scheduler
svcshost.exe
WIN32.TACTSLAY.A TROJAN!
X
Scheduler
winagent.exe
WIN32.TACTSLAY.B TROJAN!
X
Scheduler Service
wsass.exe
WIN32.LIOTEN.KX WORM!
X
SchedulerMgr
navchk.exe
Premium rate adult material dialer
X
Scheduling Agent
Scheduler.exe
SUBWOOFER VIRUS! Note - this is not the real MS Scheduling agent as the executable is incorrect
X
SchedulingAgant
MMTASK.EXE
YAB.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename
U
SchedulingAgent
mstask.exe
"Windows Task Scheduler, displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on."
U
SchedulingAgent
mstinit.exe
"MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans"
U
Schmaili
Schmaili.exe
Schmaili - insert animated smilies into your e-mail
U
Schoolpop0
Schoolpop0.exe
Schoolpop Shopping Buddy
Y
SCHWIZEX
SCHWIZEX.EXE
"Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot"
X
ScManager
scman.exe
W32/FORBOT-CW WORM!
X
scopedll
scopedll.exe
CRYPTER.C trojan variant infection
N
Scotia OnLine Recovery or Scotia OnLine Secur
etdirrcv.exe
Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
X
Scr
scr.scr
OPASERV.T VIRUS!
N
ScrapPad
Scrappad.exe
"ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper"
U
Screen Calendar
scrcal.exe
Screen_Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler.
U
Screen Guard
launch.exe
Part of Access Denied security and privacy software
U
Screen Guard Message Scan
sgms.exe
Part of Access Denied security and privacy software
X
Screen Saver
scrnsaver.scr
W32/Rbot-AGP WORM!
N
Screen Saver Control
FSScrCtl.exe
Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
N
ScreenPrint32
ScreenPrint32.exe
ScreenPrint32 screen capture software - can be launched manually.
Y
ScriptBlocking
SBServ.exe
Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information
Y
ScriptSentry
Scriptsentry.exe
Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly
U
Scroll-In-Mouse V2.0
SCROLL.EXE
Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features
X
scrsvc
scrsvc.exe
"Hijacker, a CoolWebSearch parasite variant - also detected as the Troj/Agent-DS Trojan!"
X
ScrSvr
ScrSvr.exe
OPASOFT.A VIRUS!
X
ScrSvr
ScrSvr.exe
OPASERV VIRUS!
X
ScrSvrOld
??
OPASERV VIRUS!
Y
Scsi
Scsi.exe
SCSI Miniport driver
U
scvhost
scvhost.exe
"Wiretap is a spyware program that monitors and records keystrokes, programs executed, Web sites visited, and Instant Messenger conversations. If you didn't install this yourself, remove it."
X
scvhost
scvhost.exe
"Hijacker, redirecting to bestsearch.cc - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.rw"
X
scvhost
svzhost.exe
variant of the W32.SPYBOT WORM!
X
scvhost loader
ixplore.exe
SDBOT-CY TROJAN!
X
scvhost.exe
scvhost.exe
Troj/Lohav-N trojan infection
X
scvhost.exe
scvhost.exe
W32/AGOBOT-RA WORM!
X
sd32info
sd32info.exe
CRYPTER.A trojan infection
U
SDaemon
sdaemon.exe
"PC Security from Tropical Software. 'PC Security? 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, ""Drag and Drop"" support, plus many other handy features'"
X
SDAv
csnss.exe
W32.Serflog.C WORM!
X
SDAv
svhost.exe
W32.Serflog.C WORM!
X
sdchosts32
vbdd.exe
WIN32.RANKY.AG backdoor TROJAN!
N
SDetect
SDetect.exe
"ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the ""GO"" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the ""GO"" button"
X
sdfsdfsdf
sp2update.exe
W32.SpyBot worm variant
X
SDIN Adapter
sdin.exe
W32/Forbot-AP worm infection
X
SDK Codre Function22
sdkimddprovment2.exe
W32/SDBOT-YJ WORM!
X
SDK Core Component
SDKC0RE.exe
W32/SDBOT-WC WORM!
X
SDK Core Component
sdkcore.exe
W32/SDBOT-WC WORM!
X
SDK Core Function
sdkimprovment.exe
RBOT.BHL WORM!
X
SDK Core Function2
sdkimprovment2.exe
W32.SPYBOT.OGX WORM!
X
SDKcore Update Components2
SDKC0R3.exe
W32/RBOT-ABA WORM!
X
sdkupdate22
SDK0mCORE.exe
W32/FORBOT-DT WORM!
N
SDPhotoBar.exe
SDPhotoBar.exe
"SmartDraw_Photo . Organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics."
X
sdrss
sdrss.exe
W32/SDBOT-SQ WORM!
U
sds20
svchost.exe
InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it.
U
SDTray
sdtray.exe
"RSA Keon Web_PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed."
U
sealmon
sealmon.exe
"SealedMedia enables you to combine document protection and control with your existing applications, such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email."
X
Search Bar
taskbar.exe
W32/OPANKI-F WORM!
X
Search Page
http://find.naupoint.com
Naupoint browser hijacker
X
searchbar
vnmispoisn_downloader.exe
SearchBarCash adware variant
X
SearchEnhancement
scbar.exe
IE search hijacker
X
Search-Exe
SE.exe
Hijacker - redirecting to Search-exe.com
X
Search-Exe
se.exe
Search-Exe hijacker
X
searchnav
searchnav.exe
SearchNav adware - IEFeatures/Popnav variant
X
SearchNavVersion
searchnavversion.exe
SearchNav adware - IEFeatures/Popnav variant
X
SearchSetter
searchsetter[1].exe
"browser hijacker, redirecting to FindWhateverNow.com"
X
SearchSquire33
SearchUpdate33.exe
SearchSquire parasite
X
SearchUpgrader
SearchUpgrader.exe
eUniverse/KeenValue adware related hijacker
X
secboot
mszx23.exe
variant of the HAXDOOR.D TROJAN!
X
secboot
vtd_16.exe
TROJ/HAXDOOR-AE TROJAN!
X
Secboot
w32tm.exe
HAXDOOR.D TROJAN!
U
SecondChance
sctray.exe
Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash
X
Secret
Secret.exe
Troj/Delf-LW TROJAN!
X
Secret-Crush
start.exe
Hijacker that may reset your browser's home page and/or search settings to point to undesired sites
U
SECRETMAKER
secretmaker.exe
"SECRETMAKER is a combonation of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner."
U
SecretSmileys
ss.exe
"Secret_Smileys is an add-on for AIM╜ that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window."
X
secserv.exe
secserv.exe
Reported by Panda as an EasySearch Adware variant. Note: EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer.
X
secsvc32
secsvcnt.exe
Global_Patrol TROJAN!
U
Secsys
Secsys.exe
"Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it"
X
secure
??
DealHelper adware
X
secure
secure.exe
DealHelper adware
X
secure
svshost.exe
W32/Rbot-AFO Worm!
N
SecureClean4RegManager
scregmanager4.exe
"WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually"
N
SecureClean4Tray
sctray4.exe
"WhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually"
N
SecureCleanIEClean
SCIEClean.exe
"SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches"
U
SecureItPro
Secureitpro470p.exe
"SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop"
X
SecureLogin
Mslg32.exe
REDZED VIRUS!
X
Security Accounts Manager SM
samsm.exe
SPYBOT.JE WORM!
X
Security Agent Manager
mssams.exe
W32/RBOT-SV WORM!
N
Security iGuard
Security iGuard.exe
"""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
U
Security Manager
SecurityManager.exe
"A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private."
X
Security Patch
scmss.exe
W32/RBOT-ZW WORM!
X
Security Patch
WinUpdate32.exe
W32/SDBOT-BM WORM!
X
Security Patches
msnkn.exe
RBOT.WW WORM!
X
Security Patches
WinLab32.exe
W32/SDBOT-KB WORM!
X
security service
syss.exe
unidentified WORM or TROJAN!
X
securw
Nctrup.exe
W32.NOPIR.A WORM!
Y
SECWIZ98
SECWIZ98.EXE
Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here
X
seeve
seeve.exe
MediaMotor/Popuppers adware variant
U
SeMS
SeMS.exe
PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone
U
Sensiva
Sensiva.exe
"Symbol_Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly."
X
SENTRY
SENTRY.exe
"From IP Insight. Allows website owners ""to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website"". Will be detected by most firewalls and the majority of home users should disable it?"
X
Sepate Security Firewall
sepate.exe
variant of the WIN32.RBOT WORM!
X
Serials
serials.exe
Any one of a variety of worms and trojans
X
serpe
formatsys.exe
W32.Serflog.A WORM!
X
serpe
msmbw.exe
W32.Serflog.A WORM!
X
serpe
serbw.exe
W32.Serflog.A WORM!
Y
serrdctl.exe
serrdctl.exe
"""Shared Modem Service Client Event Viewer"" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems"
X
SERV PacK2
nerx.exe
W32/SDBOT-ACP WORM!
X
server
server.exe
Troj/Singu-Q TROJAN!
X
server
system.exe
Troj/Meths-A TROJAN!
X
Server Backbone
server05.exe
W32/RBOT-ZM WORM!
X
SERVER.EXE
SERVER.EXE
BUSHTRO122 or SMOKODOOR VIRUSES!
X
serverex
Server.txt.vbs
DELTAD.A VIRUS!
X
Service
??
KAITEX.E VIRUS!
U
Service
service.exe
ALADINZ.H VIRUS!
X
Service
Service.pif
W32/ASSIRAL-C WORM!
X
Service
services.exe
"W32.NETSKY or W32.NETSKY.B WORM! **Note - not to be confused with the valid Windows ""services.exe"" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt"
X
service
services.exe
"W32.NETSKY.AI WORM! - Note - this is NOT the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
Service
SYSNT.exe
BACKDOOR-CHA TROJAN!
X
service
wN2S.exe
variant of the WIN32.RBOT WORM!
X
Service Cleaner
filen.exe
RBOT.BRH WORM!
N
Service Connection
"sccenter.exe, bwtray.exe"
For Compaq PC's. Part of Backweb
X
Service Controller
Csrrs.exe
GAOBOT.AO WORM!
X
Service Controller
service.exe
PREVERT TROJAN!
X
Service Drivers
abl.exe
W32/Sdbot-YX Worm!
X
Service Drivers
Compt.exe
W32/RBOT-ZJ WORM!
X
Service Drivers
msnpg.exe
RBOT.BMD WORM!
X
Service Drivers
PC.EXE
W32/SDBOT-WK WORM!
X
Service Host
??
TORVEL.B VIRUS!
X
Service Host
spoolos.exe
TORVEL VIRUS!
X
Service Host
SVCHOST.EXE
"DAOSER-A TROJAN! - NOTE - this file is placed in a subfolder of WINDOWS\System32\Services, and is not to be confused with the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
X
Service Host Driver
svchost.exe
"HITON VIRUS! This is not the valid svchost.exe as described here. Located in a Windows directory, and not in Windows\System32"
X
Service Manager
DXSOUND.EXE
Proxy-Gric TROJAN!
X
service manager
service.exe
DONBOMB.A TROJAN!
X
Service Manager
SERVICEMGR.EXE
W32/PASSMAIL-D VIRUS!
N
Service Manager
sqlmangr.exe
"SQL Server?Service Manager - provides tray access to SQL server,?the server agent and MSDTC. Available via Start -> Programs"
X
Service Monitor
filen.exe
variant of the WIN32.RBOT WORM!
X
Service Monitor
msnfilen.exe
W32/Rbot-ALE WORM!
X
Service Pack
??
W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
X
Service Pack DLL Runtime
spdll32.exe
variant of the WIN32.RBOT WORM!
X
Service Process
service.exe
Troj/Dcmbot-C TROJAN!
X
Service Process
SVCHOST.EXE
DARKER VIRUS! Note - not the valid svchost.exe as described here. Located in %Windir% not %Sysdir%
X
Service Process
winset.exe
variant of the W32.SPYBOT WORM!
X
Service Registry NT Save
jdbgmgrnt.exe
TROJ/BANCOS-DM! Note: This trojan file is found in the Windows or Winnt folder
X
Service Registry NT Save
regeditnt.exe
TROJ/BANCOS-BM TROJAN!
X
Service Registry NT Save
taskmgrnt.exe
TROJ/BANCOS-BY TROJAN!
X
Service Scheduler
scheduler.exe
W32/AGOBOT-PH WORM!
X
Service System
kernels32.exe
TROJ/BANCOS-DA TROJAN!
X
service updaer
qualityz.exe
"Unidentified worm, probably a W32.SpyBot variant"
X
Service.exe
Service.exe
"""servedby.advertising"" popup generator"
X
service32
service32.exe
W32/AGOBOT-ST WORM!
U
ServiceConfig
ispbeg.exe
"Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation"
X
serviceconnect
serviceconnect.exe
AGOBOT.AIR WORM!
Y
ServiceLayer
ServiceLayer.exe
Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly.
X
services
??
Troj/Gpcode-B TROJAN!
X
Services
??
unidentified VIRUS! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
X
Services
csrss.exe
variant of the BACKDOOR.RANKY.U TROJAN!
X
Services
kirby.exe
Proxy-Agent trojan variant
X
Services
mshost.exe
TROJ/LANFILT-J TROJAN!
X
Services
scks32.exe
Proxy_Trojan variant
X
Services
services.exe
"W32.MYDOOM.BB WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
services
socks.exe
WIN32.SMALL.N Proxy TROJAN! - A PT is a backdoor trojan which allows a remote hacker to connect to other systems via the compromised system.
X
Services
sockys32.exe
WIN32.RANKY.L Proxy_Trojan
X
services
start.bat
ZCREW VIRUS!
X
services
Svchosts.exe
SDBOT.N WORM!
X
Services
sys.exe
Proxy_Trojan variant
X
Services
windns.exe
variant of the WIN32.RBOT WORM!
X
services
windows32.exe
W32/FlyVB-C WORM!
X
Services
winread.exe
Unidentified trojan
X
Services Administrator
localsvc.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
netsvc.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
svcman.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
svcrun.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Services Administrator
websvc.exe
Troj/Dloader-NY Trojan!
X
Services Controller
lsassa.exe
CIADOOR.122 VIRUS!
X
Services Controller
services.exe
"TROJ/CIADOOR-F TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Services Host
Scchost.exe
DONK VIRUS! Note - this is not the valid svchost.exe as described here
X
Services Host
svchost32.exe
W32/Agobot-TG WORM! Note: (svchost32.exe) is not the legitimate Windows Process. (Notice the 32 that's been added.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Services Logon
services.exe
"W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
Services Process
services.exe
unidentified spyware - recognized by Kaspersky antivirus as TrojanSpy.Win32.Small.x
X
Services Process
smss.exe
Troj/Small-EK Trojan!
X
Services Startup
services.exe
"W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
Services Startup
svhost33.exe
variant of the WIN32.RBOT WORM!
X
Services.dll
smss.exe
W32.Sober.L WORM! **Note: this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
X
Services.dll
smss.exe
"W32/SOBER-L WORM! - NOTE - this file is placed in a %WinDir%\msagent\system folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Services.EXE
services.exe
KAZPING VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process
X
services.exe
Services.exe
"CIADOOR-F TROJAN! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!"
X
Services004
??
BUGBROS VIRUS!
X
services32
mc-110-12-0000079.exe
TrojanDownloader.Agent.rv TROJAN!
X
services32
mc-58-12-0000120.exe
"""Shorty"" adware component, also detected as the AGENT.FD TROJAN!"
X
services32
mc-58-12-0000140.exe
"""Shorty"" adware component, also detected as the AGENT.FD TROJAN!"
X
Services32 Startup
win32dll.exe
W32/SDBOT-XO WORM!
X
ServicesLog
ccapp32.exe
W32/Rbot-AMX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Servicing
hostd.exe
SDBOT.BUI WORM!
X
Servicio Local
svhost.exe
variant of the WIN32.RBOT WORM!
X
servics
servics.exe
Troj/Singu-J Trojan!
N
Serv-U
serv-u32.exe
FTP server
X
Serv-U
wssdsu.exe
MANIFEST VIRUS!
U
Session Client
sescli.exe
SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
Session Manager Subsystem
smssa.exe
W32/Rbot-AGS WORM!
X
SESync
sed.exe
Downloadware/SED adware downloader
N
SetDefPrt
BrStDvPt.exe
Used to set a Brother MFC printer/copier/scanner as the default printer after installation
N
setdefprt
setdefprt.exe
Used to set a Brother MFC printer/copier/scanner as the default printer after installation
U
SetecCertUtil
Certutil.exe
"Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV"
X
setFTPBack
createsw.exe
FTP_BMAIL VIRUS!
N
SetHook
SetHook.exe
"Fellowes Neato CD label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
N
seticlient or SETI@home
SETI@home.exe
SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
N
SetIcon
SetIcon.exe
"Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog"
N
SetiQueue
Setiqu~1.exe
Provides work unit buffering for Seti@Home clients - see here for more details
N
SetiSpy
SetiSpy.exe
"From the site - 'SETI Spy is a little program I wrote to ""spy"" on the progress and performance of the SETI@home client. I call it a ""spy"" because I tried to make it as unobtrusive as possible'"
X
SetPoint
SetPoint.exe
W32/RBOT-BWI WORM!
X
SETPOINT Logitech Inc
KHALMNP.exe
W32/RBOT-AAX WORM!
X
Setting
sysweb.exe
SDBOT.GEN WORM!
X
Setup experation
svchost.exe
"TOFGER-AW TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which is located in the System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
setupa
runt32.exe
TROJ/QQPASS-K TROJAN!
N
SetupICWDesktop
icwconn1.exe
"Appears to be the ""Internet Connection Wizard"" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway"
X
setupuser
regedit.exe setupuser.log
CoolWebSearch parasite related.
X
SetVrc
setvrc.exe
HUNTOCX VIRUS!
X
Sex Teris
st01b.exe
REPAD VIRUS!
X
Sexnow
Sexnow.exe
Dial/Senow-B premium rate porn dialer
X
Sexy_sg
Sexy_sg.exe
Premium rate adult content dialer
X
sf
sf.exe
SurfEnhance adware component
X
sfita
sfita.exe
Troj/Favadd-H TROJAN! also known as SurfEnhance adware component.
N
SFP
vzSFPWin.EXE
"Verizon Online Support Center, promps for online updates"
U
sfpc
sfpc.exe
"Spy4PC is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it."
X
SFtrb Service
cftrb32.exe
SOBIG.D VIRUS!
U
SfWinStartInfo
sfWinStartupInfo.exe
SFIRM32 Online Banking software
U
Sgecrypt
Sgecrypt.exe
"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"""
U
Sgeecview
Ecview.exe
"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"""
N
sginst
sginst.exe
eAcceleration Stop-Sign related; not recommended; see note
U
sgtray
sgtray.exe
"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups"
X
shambl3r
cnf.bat
REMABL VIRUS!
X
shambl3r*
shambl3r.exe
REMABL VIRUS! where * is 2 to 11
X
Shania
Shania.vbs
"SHANIA VIRUS! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
U
Shareaza
bindata.exe
Shareaza P2P client related
N
Shareaza
Shareaza.exe
Shareaza P2P client
X
sharedprem
sharedprem.exe
MAKECALL VIRUS!
N
Share-to-Web Namespace Daemon
hpgs2wnd.exe
"""HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites."" In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs"
Y
Sharing and Mapping Software
DShmap.exe
Intel AnyPoint internet sharing software
N
SharkEject
AEJCT32.exe
"Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required"
N
Shcenter
chcenter.exe
"IMSI HiJaak - ""the easiest way to convert, capture, and manage all your graphic files"""
X
SheduIer
shch.exe
TROJ/BDOOR-EB TROJAN!
X
SheduIer
svchst.exe
Premium rate adult content dialer
X
SheduIer
svchst.exe
TROJ/BDOOR-EB TROJAN!
X
SheduIer
winagent.exe
TROJ/BDOOR-EB TROJAN!
X
Sheduler
nerocheck.exe
WIN32.TACTSLAY.B TROJAN!
X
shell
explorer.exe
Trojan.Kakkeys Trojan!
X
Shell
ibm00001.exe
Troj/Torpig-C TROJAN!
X
Shell
iexplore.exe
W32/Kipis-U WORM!
X
Shell
msmsgs.exe
Zhopa TROJAN!
X
Shell
Open32.exe
Troj/Small-DL TROJAN!
X
Shell
ray.exeTray.exe
Homepage hijacker re-directing browsers to adult content websites
X
Shell
Shell32.exe
BADSECTOR TROJAN!
X
Shell
sound_drive16.exe
TROJ/BDOOR-GP TROJAN!
X
Shell
svchost.exe
Doyorg TROJAN!
X
Shell
wmedia16.exe
GOLDUN TROJAN!
X
Shell API32
svcnet.exe
WIN32.TIBICK.C WORM!
X
Shell Extension
spollsv.exe
variant of the LOVGATE WORM!
X
Shell Monitor
services32.exe
variant of the WIN32.RBOT WORM!
X
Shell Tray Window
ShellTraywnd.exe
TROJ/STULTDOR-A TROJAN!
X
shell update
shellexec.exe
W32/Agobot-TH WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
shell32
ntldrt.exe
W32/Jlok-A WORM!
X
Shell32
Shell32.vbs
VBS.Scafene WORM!
X
ShellApi
SHELLMSN.EXE
NETDEV.B VIRUS!
X
Shellapi32
mcvsrte.exe
"unidentified WORM! - Note, do do confuse with the McAfee SecurityCenter file of the same name described here"
X
Shellapi32
Shellapi32.exe
NETDEVIL (or NERTE) VIRUS!
X
Shellapi32
svcnet.exe
W32/TIBICK-C WORM!
X
ShellCommand
??
Troj/Remcon-A TROJAN!
X
ShellEx
ShellEx.exe
ANAKHA VIRUS!
X
ShellOS
A+++.exe
WIN32.VB.AV keylogger TROJAN!
X
Shellspl
lsas.exe
TROJ/YALER-A TROJAN!
X
Shellspl
spools.exe
PROXAGE-A TROJAN!
X
shellsystem
shellsystem.exe
UPCHAN TROJAN!
X
shhost
shhost.exe
BACKDOOR.WIN32.AGENT.CE TROJAN!
N
shicoxp
shicoxp.exe
Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer.
X
Shine
Shine.exe
HAPPYLOW or W32/Nishe-A VIRUS!
X
Shmgrate.exe
ibot4.exe
GASTER VIRUS!
N
shockmachinereminder
SmReminder.exe
"Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version"
X
Shockwave
csrss.exe
"SNDOG VIRUS! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
N
Shockwave Init
SWINIT.EXE
Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
N
ShortKeys 99
SHORTKEY.EXE
ShortKeys from Insight Software Solutions - allows you to program keys with text strings
X
Showbehind
SHOWBEHIND.EXE
Advertisement display which can be stopped here
X
ShowFF
ShowFF.exe
Adware.FFToolBar adware toolbar.
X
ShowWnd
ShowWnd.exe
unidentified backdoor TROJAN!
U
SHPC32
SHPC32.exe
Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
Y
ShStatEXE
SHSTAT.EXE
"From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs"
U
Shutdownaware
shutdownaware.exe
Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
U
ShutDownPro
ShutDownPro.exe
"ShutDownPro - shutdown, reboot, logoff your System with one mouse click"
X
si91e44b
??
LZIO.com adware downloader
X
Sicom
Sicom.exe
NETLIP VIRUS!
U
SideACT
SideACT.exe
SideACT organizer software
X
Sidebar
Sidebar.exe
Searchcentrix hijacker
N
SideWinderTrayV4 or SWTrayV4
SWTrayV4.exe
MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
X
SigXC
SigX.exe
"SigX is a ""dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more."""
N
Simcast
SimcastAlerts.exe
Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say.
U
SimpLite-MSN
SimpLite-MSN.exe
Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
X
Singapore
singapore.exe
Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself
X
SiS Dns
dnssvc.exe
Troj/Dloader-UE TROJAN! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
SiS KHooker
khooker.exe
SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
U
SiS Tray or sistray
sistray.exe
System Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
U
SiS Windows KeyHook
keyhook.exe
"SIS graphics cards related: ""Super VGA Keyboard Daemon"" - hooks into the keyboard processing chain in order to enable hotkey settings."
Y
SiS7012Utility
SiSAudUt.exe
SiS Corporation sound card driver
N
SiSAudio
MP_S3.exe
WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
U
siscolor
color.exe
Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
U
siService.exe
siService.exe
Spam Inspector - anti email spam software
U
SiSSWLED
sisswled.exe
System Tray utility for SiS 900 network cards
X
sistrai.exe
sistrai.exe
PROVA VIRUS!
X
sistray
sistray.exe
PROVA VIRUS! Note - this resides in C:\Windows\Command
X
Sistray32
remotehost.pif
W32.Holcas.A WORM!
X
Sistray32
virus.exe
Troj/Tometa-C TROJAN!
X
Sistray32
win.bat
W32.Jumpred.A WORM!
X
sistry
sistry.exe
CEBE VIRUS!
N
SiSUSBRG
SiSUSBrg.exe
SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
X
sixtysix
sixtypopsix.exe
MediaMotor/Popuppers adware downloader
U
SK51
SK51.EXE
SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
U
SK60
SK60.EXE
SaveKeys surveillance software. Uninstall this software unless you put it there yourself.
U
SK9910DM
SK9910DM.EXE
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
U
SKDAEMON
SKDAEMON.EXE
Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys?
U
skinkers
skinkers.exe
"Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's ""Desktop Ozzy"" and Arsenal's ""Desktop Wenger"" - see here"
X
sks-32
SKS32P~1.EXE
SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address.
Y
SkyBlaster Scheduler
SSFSch.exe
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
X
skynetave.exe
skynetave.exe
SASSER.D VIRUS!
X
SkynetRevenge
winlogon.scr
W32.NETSKY.AA WORM!
N
Skype
Skype.exe
"""Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes"""
Y
SkySurfer Management Service
SmaServ.exe
For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
X
sl4 rules
rbot32.exe
W32/SDBOT-QC WORM!
N
SleepManager
SleepMgr.exe
"This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode"
U
SlickRun
sr.exe
"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:\Program Files\Outlook Express\msimn.exe becomes MAIL"""
X
slide
Iexplore.exe
"GASLIDE VIRUS! Note - this is not the valid Internet Explorer file ""iexplore.exe"""
N
slimp3
SliMP3 Server.exe
"Slimp3 Server - ""presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"""
N
Slingshot
SLINGS~1.EXE
"Atomica Slingshot -?""reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more"""
X
slmss
slmss.exe
SeekSeek search hijacker related - as seen here
X
sload
sload.exe
"Win SynchroAd adware, also detected as TROJ/DLOADER-QG TROJAN!"
X
slvchost32
slvchost32.exe
Unidentified worm or trojan
X
sm
sa_exe.exe
OLFEB.A TROJAN!
X
sm
sf_exe.exe
OLFEB.A TROJAN!
X
sm
sm_exe.exe
OLFEB.A TROJAN!
X
sm
sr_exe.exe
LUKUSPAM TROJAN!
N
Sm56acl
sm56hlpr.exe
Helper utility for Motorola based SM56 software modems - resides in the System Tray
X
sman
??
Unidentified adware
N
Smapp
smtray.exe
System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller
N
Smart Card Service
ScardSvr.exe
"For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly"
U
Smart Connect Monitor
SCMon.exe
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
U
Smart Connect Setup
SCSetup.exe
Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
N
Smart Label O Server
ssloserv.exe
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
N
Smart Label RFViewer
SSLFVIEW.EXE
Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely
N
Smart Type Assistant
sta.exe
"Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer"
U
Smartalec
pcaccel.exe
Smartalec PC Accelerator - system optimization utility
N
SmartBarXP
SmartBarXP.exe
"SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few"
N
sMaRTcaPs
SMARTC~1.EXE
"sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys"
U
Smarthruengine
QS.exe
"Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers"
U
SmartPCXL
pcaccel.exe
Smartalec PC Accelerator - system optimization utility
N
SMax4
SMax4.exe
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
U
SMax4PNP
SMax4PNP.exe
"SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments"
X
smcserv
winsrv.exe
W32/AGOBOT-OU WORM!
Y
SmcService
smc.exe
Sygate Personal Firewall
N
Smith Micro try
smiptray.exe
Smith Micro shared files. Comes with D-Link web cam
N
SmoothView
SmoothView.exe
"TOSHIBA Zooming Utility - allows ""automatic"" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe-Reader and also desktop icons."
U
SMS Application Launcher
LAUNCH32.EXE
Microsoft Systems Management Server - used to manage computers on a network remotely
U
SMS Client Service
clisvc95.exe
"When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)"
X
Sms System32
SmsSystem32.exe
Unidentified malware
U
SMS Win9x Message Agent
SMSMsg.exe
This program assigns a user to a Systems Management Server site
Y
Smserial
sm56hlpr.exe
Motorola based modem driver
N
SMSI Loader
SMLoader.exe
Smith Micro HotFax - fax software
X
smsm
smsm.exe
Troj/Banker-CO Trojan!
X
smsrv
smsrv.exe
W32/Agobot-SX Worm!
X
smss
??
ALADINZ.F VIRUS! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
X
SMSS
SMSS.EXE
Troj/Borobot-K TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
Smss
ssms.exe
RBOT.OP WORM!
X
smssLevel4
smss.exe
"UNidentified malware - NOTE - this file is placed in a C:\Program Files\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4 folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SMSSS
smsss.exe
SDBOT.ZD WORM!
X
SMSSS Loader
smsss.exe
AGOBOT.MQ WORM!
X
SMSSU
SMSSU.EXE
"Hijacker, detected by Norton antivirus as Trojan.StartPage.O"
X
smsys
Explorer.exe
"CLICKER-C VIRUS! Note - the valid ""explorer.exe"" is located in C:\Windows or C:\Winnt whereas this one is located in a C:\Windows\Template or C:\Winnt\Template subdirectory"
X
smsys
vi.exe
Adult content dialler
U
Smt
SMT.exe
Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself!
N
SMToolbar
SMToolbar.exe
StartMake.com toolbar
X
SMTP32 Mailing Protocol
smtp32.exe
variant of the WIN32.RBOT WORM!
X
snapple
snapple.exe
W32/FORBOT-EG WORM!
X
snbupt
snbupt.exe
UpSpiralBar adware component
X
sncntr
sncntr.exe
Troj/Dluca-I TROJAN!
X
snd332
snd332.exe
"""B1ld0"" AIM WORM!"
X
Sndcompat
Sndcompat.exe
GEMA TROJAN!
U
SNDMon
SNDMon.exe
"Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the ""U"" recommendation"
X
SndPnpMix
wauctlxp4.exe
WIN32.MUDROP.N TROJAN!
X
Sndsaver
Sndsaver.exe
GEMA TROJAN!
X
SNInstall
??
"SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe"
U
Snippet
SnippingTool.exe
"The Snipping Tool (part of the Experience_Pack for Tablet PC) allows you to easily ""cut out"" anything on screen and share it with other people. The whole screen becomes an ""inkable"" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an e-mail message."
X
SNP Generic Host Process
svchost.exe
Troj/Zapchas-O TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
N
Snsicon
Snsicon.exe
Launches a screensaver program from Second Nature
X
SNSS.EXE
SNSS.EXE
Dialer.Nunci premium dialer.
X
Soar
Rwon.exe
PurityScan/Clickspring adware
X
Social Security Agency
rpcxsocsa.exe
variant of the WIN32.RBOT WORM!
X
Sock32
sock32.exe
SDBOT WORM!
Y
SoDA Startup
SodaStartup.exe
Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software
N
soffice
SOFFICE.EXE
Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
X
Soft Profile Inc
??
variant of the LOVGATE WORM!
X
softIce Update 32
wininits.exe
W32/Rbot-ANB WORM! Note: This worm/trojan file is found in the Windows or Winnt folder.
U
SoftickPPP
PPPGate.exe
Softick_PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer.
Y
SOFTinst
??
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
U
SoftStuff Wallpaper Changer
softstrt.exe
AzureBay wallpaper changer
X
Software
software.exe
TROJ/CRABTON-B downloader TROJAN!
Y
Solo Sentry
Solosent.exe
Solo Antivirus
U
SoloSchedule
Solocfg.exe
Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis
U
SoloSysCheck
Syscheck.exe
"Solo_antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors."
X
somatic
somatic.exe
Searchcentrix hijacker
N
Sonic A3D Control
vrtxctrl.exe
Sound related options
X
Sonic RecordNow!
smsc.exe
variant of the W32/SDBOT WORM!
N
SoniqueQuickStart
sqstart.exe
Quickstart for Sonique audio player. Available via Start -> Programs
X
SOS
SOS.exe
PHILLIS VIRUS!
N
SOS SQL Database
scm.exe
SQL Server Service Control Manager. Available via Start -> Programs
X
Sound Loader
sndloader.exe
AGOBOT-BV WORM!
X
Sound services
SOUND32.EXE
AGOBOT.GG WORM!
X
Sound System
WinSound1.exe
unidentified worm or trojan infection
X
soundcontrl
soundcontrl.exe
GAOBOT.AFJ WORM!
X
sounddrv
sndbdrv3104.exe
CoolWebSearch parasite related.
N
soundman
soundman.exe
System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel
X
SOUNDMAN Microsoft Help
soun.pif
W32/RBOT-AIU WORM!
U
SoundMAX
SMax4.exe
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
X
SoundMAX
SoundMAX.exe
"W32/RIZON-A WORM! - NOTE - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards!"
U
SoundMAXPnP
SMax4PNP.exe
"SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments"
X
SoundMixer
smvss.exe
TROJ/DEDLER-G TROJAN!
X
Soundmx
Soundmx.exe
CoolWebSearch parasite related.
X
soundtask
soundtask.exe
AGOBOT.VQ WORM!
X
soundtask
soundtask.exe
AGOBOT-MD WORM
X
soundtasks
soundtasks.exe
Crypter.C trojan variant infection
X
soundtctrls
soundtctrls.exe
W32/Agobot-ZV WORM!
X
SoundView
msdview32.exe
trojan downloader
X
sounofts
sounofts.exe
W32/Agobot-ND WORM!
X
sountskmanager
sountaskmgr
unidentified WORM or TROJAN!
N
SourcePath
gwreg.exe
Used to update Gateway registry settings for System Restoration Kit and Web update programs
X
sp
??
"Malicious javascript annoyance that changes the default search engine in IE to one of many including ""topsearcher"". See here for more and a fix"
X
sp
??
Troj/Ablank-W and Troj/Ablank-Z TROJANS!
X
sp
??
"StartPage.M TROJAN, a CoolWebSearch parasite variant"
X
sp
sp.reg
IE search hijacker - changes the default search to http://www.gocybersearch.com/
U
SP TimeSync
SP TimeSync.exe
SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server).
X
SP00LSV
Sp00lsv.exe
GRAYBIRD.E VIRUS!
U
SP2 Connection Patcher
SP2ConnPatcher.exe
Changes limit of concurrent TCP connections of Windows Service Pack 2.
X
SP2 data
??
variant of the RANDON.AN WORM!
X
SP2 Firewall/Internet Updater
crssrs.exe
RBOT.BJO WORM!
X
sp2chk.exe
sp2chk.exe
Aluroot.A TROJAN!
X
sp2ctr
sp2ctr.exe
Troj/Dluca-M trojan infection
X
sp2update
sp2update.exe
ADWARE! Adware.SP2Update Tracks URLs visited and search terms entered into Internet Explorer.
X
Spam Blocker for Outlook Express
SBInst.exe
HotBar related
U
Spam Sleuth
SpamSleuth.exe
Spam Sleuth E-mail spam detection program
U
SPAMfighter Agent
SFAgent.exe
SPAMfighter anti email spam filter
U
spamihilator
spamihilator.exe
Spamihilator spam filter
U
SpamPal
spampal.exe
SpamPal - anti-spam tool
U
SpamSubtract
SpamSubtract.exe
Intermute SpamSubtract - junk email detection and removal program
N
spc_w
blspc.exe
NetZero Search Enhancement related
N
spc_w
hcm.exe
NetZero Search Enhancement related
N
spc_w
nzspc.exe
NetZero Search Enhancement related
N
Spdstart
Spdstart.exe
"Norton Utilities Speed Start. ""This feature optimizes the start up speed of launching applications, such as Word and Excel."""
U
Speaking Clock Deluxe
SpClDlx.exe
"Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly"
X
Special Firewall Service
avguard.exe
W32.NETSKY.G WORM!
X
SpecialOffers
??
SpecialOffers adware
X
SpecialOffers
SpecialOffers.exe
SpecialOffers adware
X
specific
specixic.exe
variant of the W32/SDBOT WORM!
N
Speed racer
CTSRReg.exe
Software for a Creative sound card
U
Speed Tec
speedtec.exe
Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled
X
SpeedBoss
??
OPASERV.AD VIRUS!
U
Speedkey
SPEEDKEY.EXE
Additional keyboard shortcuts on MS programmable keyboard
U
SpeedMeter
SpeedMeter.exe
Application measuring upload and download speed
U
SpeedOptimizer
spo.exe
"SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication."
U
SpeedswitchXP
SpeedswitchXP.exe
SpeedswitchXP is a CPU frequency control for notebooks running Windows XP
U
Speedtouch USB Diagnostics
Dragdiag.exe
For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an \'at-a-glance\' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
U
SpeedUpMyPC
SpeedUpMyPC.exe
"SpeedUpMyPC ""automatically fine-tunes all your resources including hardware, system settings and internet usage to operate at peak performance at all times."""
X
Spees1
speedy.scr
OPASERV.Y VIRUS!
X
Spees2
Speedy.bat
OPASERV.AD VIRUS!
X
Spees3
SPEEDY.PIF
OPASERV.AD VIRUS!
N
Spellex Anywhere
sa.exe
Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used
Y
SpIDerMail
spiderml.exe
DrWeb antivirus Spider Mail e-mail scanner
N
Spinner Plus
spinner.exe
"""Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness"". Available via Start -> Programs"
X
SPINX
OXNEY.B.VBS
VBS.YENO.C WORM!
X
SPnt
SPnt.exe
Premium rate adult material dialer
U
SpokeSysTray
SpokeSysTray.exe
"Spoke_Software client application. Spoke ""uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry."""
X
spolsvr2
spolsvr2.exe
"Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
spoo1sv
spoo1sv.exe
SOULJET VIRUS!
X
Spool
??
RANKY.R TROJAN!
X
Spool
msvc.exe
RANKY.R TROJAN!
X
Spool
wys.exe
WhileUSurf adware component
X
SPOOL Configuration
spoolsvc.exe
W32/Sdbot-KD worm
X
Spool Loader
spool.exe
variant of the WIN32.RBOT WORM!
X
Spool LoadKIt
spoolv.exe
variant of the WIN32.RBOT WORM!
X
Spool lptt01 or Spool ml097e
spool.exe
"Variant of the RapidBlaster parasite (in a ""spool"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Spool Server Daemon
SPOOLSVD32.EXE
Win32.Rbot worm variant
X
Spool32
pool32.exe
ASSASIN-F TROJAN!
X
spoolax
??
Troj/Perda-D TROJAN!
X
Spooler Service
Spoolsrv.exe
JOINER.C1 VIRUS!
X
Spooler Sub System Process
SPOOL32.EXE
YAB.A VIRUS!
X
Spooler Subsystem
spoolsub.exe
W32/SDBOT-ABG TROJAN!
X
Spooler SubSystem App
spooIsv.exe
W32.LINKBOT.M WORM!
X
Spooler SubSystem App
spoolsvc.exe
W32/POEBOT-J WORM! Note: Spoolsvc.exe is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (spoolsv.exe) should not be seen in Msconfig or as a Startup item...Also search for fccj.bat if found this is the W32/Poebot-M variant.
X
Spooler SubSystem Application
localsvc.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
netsvc.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
svcman.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
svcrun.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Spooler SubSystem Application
websvc.exe
Troj/Dloader-NY Trojan!
X
Spooler Subsytem App
spoolsvc.exe
TROJ/SDBOT-MM WORM!
X
SpoolerSubSystemProcess
SpooI32.exe
"SPY.EHKS.21 VIRUS! Note - the ""I"" between ""o"" and ""3"" is a captial ""i"" not a lower case ""L"""
X
Spools Service Controller
spools.exe
W32/KASSBOT-C and W32/Kassbot-E WORMS !
X
spoolserv
spoolserv.exe
W32/Sdbot-PN worm infection
X
SpoolService
spolsv.exe
W32/AGOBOT-CS WORM!
X
spoolsv
scvhosts.exe
TROJ/SMALL-AW TROJAN!
X
Spoolsv
Spoolsv.exe
"CIADOOR.121 VIRUS! Note - ""Spoolsv.exe"" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file"
X
spoolsv manager
SpoolMgr.exe
W32.Assiral WORM!
X
spoolsv service
spoolsv32.exe
W32/RBOT-AHP WORM!
X
SPOOLSV32
SPOOLSV32.EXE
TROJ/CWS-I TROJAN!
X
spoolsvc
spoolsvc.exe
TROJ/DROPPER-AT TROJAN!
X
spoolsvr32
csmss.exe
AGENT-AU TROJAN!
X
spoolsvr32
csmss32.exe
variant of the AGENT-AU TROJAN!
X
spoolsvs.exe
spoolsvs.exe
Troj/Dloader-RK TROJAN!
X
SPOOLSVU
SPOOLSVU.EXE
StartPage.K TROJAN!
X
spoolsvv
spoolsvv.exe
Searchcentrix hijacker
X
Spoolvs
spoolvs.exe
SDBOT.AUS WORM!
X
Spore
MsNews.vbs
VBS.SORPE.A WORM!
X
Spore.b
Scmhlpr.vbs
VBS.SORPE.B WORM!
X
spp
??
IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/
U
SPSTEALT
SmartProtectorPro.exe
"Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc"
U
Spy Blocker
spyblocker.exe
"SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all"
X
SpyBan
SpyBan.exe
"""Spyware remover"" of dubious repute - see this list of non-Recommended anti parasite software"
X
SpyBlast
SpyBlast.exe
"Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others"
U
SpyBlocker
spyblocker.exe
"SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all"
X
SpyBlocs
GLFF.exe
Rogue anti-spyware program.
X
SpyBlocs
SpyBlocs.exe
Rogue anti-spyware program.
X
SpyBlocs3.0
SpyBlocs3.0.exe
Rogue anti-spyware program.
U
SpybotSD TeaTimer
TeaTimer.exe
"Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla. TeaTimer.exe monitors certain changes to the registry and notifies when browser plugins and activeX controls get installed, allowing you to block/reverse this."
U
SpyBotSnD
Spybotsd.exe
Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla
X
Spybott lptt01 or Spybott ml097e
spybott.exe
"Variant of the RapidBlaster parasite (in a ""Spybott"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Spy-Control
Spy-Control.exe
"""Spyware remover"" of dubious repute - see this list of non-recommended anti parasite software"
U
SpyCop ScanCheck
MAIN.EXE
SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
X
SpyEx
Winllogo.exe
W32/PrsKey-A WORM!
N
SpyHunter
Spyhunter.exe
SpyHunter - spyware remover of somewhat dubious repute; see note
U
Spy-Keylogger
skl.exe
SpyKeylogger is a security risk that records keystrokes. If you didn't install it yourself remove it.
U
Spykiller
Spykiller.exe
"Shareware ""Spyware remover"" of questionable quality and repute. There are better alternatives that are freeware to boot. See this page on Rogue/Suspect Anti-Spyware Products & Web Sites"
X
SpyNuker
Spynuker.exe
"A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ▒TrekData? and ▒Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages"
X
SpySheriff
SpySheriff.exe
SpySheriff malware
N
SpySpotter
SpySpotter.exe
"""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
U
SpyStopper
spystopper.exe
"SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked"
U
SpySubtract
SpySub.exe
SpySubtract - multi spyware removal tool
U
SpySweeper
SpySweeper.exe
Spy Sweeper - detects and removes spyware
X
SpyTrooper
SpyTrooper.exe
"SpyTrooper, malware, posing as a spyware remover - alse see here"
X
Spyware
Spyware.exe
"BPS Spyware Remover - reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!"
N
Spyware Begone
freescan.exe
Spyware BeGone - free spyware removal utility; not recommended; see note
N
Spyware Begone
SpywareBegone.exe
Spyware BeGone - free spyware removal utility; not recommended; see note
U
Spyware Doctor
spydoctor.exe
Spyware_Doctor spyware remover
U
Spyware Doctor
swdoctor.exe
Spyware_Doctor spyware remover
U
Spyware Guard Control Panel
spywar~1.exe
"""SpywareGuard provides a real-time protection solution against spyware"""
X
Spyware Nuker
swn2.exe
"A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ▒TrekData? and ▒Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages"
X
Spyware Nuker Installer
SpywareNukerInstaller.exe
"A ""spyware removal program"" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ▒TrekData? and ▒Blue Haven Media?, who distribute spyware through ActiveX drive-by-download on web pages"
X
Spyware remover
Remove_spyware.exe
"Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related!"
N
Spyware Scanner
AseScanner.exe
"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here"
U
SpyWare Shield
Shield.exe
Acronis Privacy Expert Spyware_Shield prevents spyware and other suspicious programs from being installed on desktop PCs and laptops.
X
Spyware Slayer
SpywareSlayer.Exe
"""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
N
Spyware Stormer
SpywareStormer.Exe
SpywareStormer spyware remover; not recommended: see here
X
Spyware Vanisher
FreeScanner.exe
"""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
U
Spyware X-terminator
SpywareX.exe
Spyware_X-terminator spyware remover
X
Spyware-Cop
Spyware-Cop.exe
"Spyware-Cop alias SpywareKilla - ""Spyware remover"" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites"
X
SpywareGuard
deinst_qfe001.exe
variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application as described here
U
SpywareGuard
sgmain.exe
"""SpywareGuard provides a real-time protection solution against spyware"""
X
Spywareguard lptt01 or Spywareguard ml097e
Spywareguard.exe
"Variant of the RapidBlaster parasite (in a ""Spyguard"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
SpywareGuardPlus
winmm64.exe
"""Trojan.Win32.StartPage.ht"" homepage hijacker"
N
SpywareKilla
SpywareKilla.exe
"Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on ""Rogue/Suspect Anti-Spyware Products & Web Sites"""
X
SpywareNo
SpywareNo.exe
"Bogus ""Spyware remover"" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites"
U
SPYWATCH
SpyWatch.exe
"BPS Spyware Remover - reportedly uses an old, ""borrowed"" SpyBot database. Read this and this. Do not support these guys!"
X
SQConfigChecker
cc.exe
Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
X
SQInstaller
SQInstaller.exe
Xupiter hijacker
N
SQL Server
scm.exe
SQL Server Service Control Manager. Available via Start -> Programs
X
SQL Server Service
sql.exe
W32/Rbot-ADF
X
sqservices
wins32.exe
Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
X
SQUpdatesChecker
uc.exe
Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
X
sqvynikp
sqvynikp.exe
Free_Scratch_Cards foistware
X
sr64
??
"Adware, as yet unidentified"
X
SrchfstUpdate
srchupdt.exe
SearchFast adware downloader
X
sre
??
"CoolWebSearch parasite variant, also detected by Kaspersky antivirus as Trojan.Downloader.Agent.Fc"
U
Srmclean
srmclean.exe
"Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - ""If you disable the entry from loading into startup, then you will not be able to use the features of the sound card"""
X
SRNG
srng.exe
Search hijacker - see here
U
SRP Startup
srrpro.exe
"System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium ""features."" This is enabled if you tick the ""Remove unnecessary System Restore information on startup"" box. Available via Start -> Settings -> Control Panel"
Y
SRS Applet
SrsTray.Exe
S3 Sonic Vibes sound card drivers - if disabled you loose sound
X
Srv RPCrom
NClienti386.exe
W32.Watsoon.A TROJAN!
X
Srv32
Srv32.exe
OPASERV.J VIRUS!
X
Srv32
Srv32.exe
OPASERV.S VIRUS!
X
srv32
srv32.exe
W32/AGOBOT-AMI WORM!
X
Srv32 spool service
runsrv32.exe
"Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b"
X
Srv32 spool service
spoolsrv32.exe
SPYRE.B and Troj/Dloader-ON TROJANS!
X
Srv325
Srv325.exe
W32/AGOBOT-PR WORM!
X
Srv32Old
??
OPASERV.J VIRUS! where <filename> is the original worm name
U
Srv32Win
SpyAgent4.exe
"SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it"
U
Srv32Win
Svchost.exe
"Realtime-Spy keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn\'t treat it as ""X"" and uninstall or remove"
U
Srv32Win
sysdiag.exe
NetVizor surveillance software - uninstall this software unless you put it there yourself!
U
srv32win
win16dll.exe
"Screenspy captures screenshots silently. If you didn't install this yourself, remove it."
X
Srvce Pack Updte
svcpack.exe
variant of the WIN32.RBOT WORM!
X
srvexc.exe
srvexc.exe
BACKDOOR.SERVSAX TROJAN!
U
srvprc
srvprc.exe
Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself.
X
ssate.exe
irun4.exe
BEAGLE.J WORM!
X
ssate.exe
winsys.exe
BEAGLE.K WORM!
N
SSBkgdUpdate
SSBkgdupdate.exe
ScanSoft OmniPage auto updater. Can be disabled using the main program's options.
U
SSC Service Utility
ssc_serv.exe
SSC Service Utility is a printer utility for refilled Epson cartridges
U
SSCFBTN.EXE
SSCFBTN.EXE
"Samsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers"
Y
Ssd
Std.exe
Stealthdisk - file and folder hiding/locking utility
N
SSDPSRV
ssdpsrv.exe
"Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play"
X
ssgrate.exe
irun.exe
MITGLIEDER.D VIRUS!
X
ssgrate.exe
irun4.exe
MITGLIEDER.F VIRUS!
X
ssgrate.exe
sysdoor.exe
Trojan.Mitglieder.N
X
ssgrate.exe
system.exe
MITGLIEDER.C VIRUS!
X
ssgrate.exe
winerdir.exe
MITGLIEDER.O VIRUS!
X
ssgrate.exe
winsystems.exe
TROJ/BAGLEDL-J TROJAN!
X
ssgrate.exe
wintems.exe
Trojan.Mitglieder.Q Trojan!
U
SSh32
SSh32.exe
2Spy keystroke logger/monitoring program - remove unless you installed it yourself!
X
SSK Service
winssk32.exe
SOBIG.E VIRUS!
X
SSL
svchost.exe
unidentified VIRUS!
U
ssmmgr
ssmmgr.exe
"Samsung printer monitor - for checking ink levels, etc."
X
ssms.exe
SSMS.EXE
W32.GISMOR WORM!
U
SSPY
SSYTEM.EXE
SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
sssasasb32
sssasasb32.exe
WIN32.TACTSLAY.F TROJAN!
X
sstata
dwdas.exe
Dasda trojan
X
SStb.exe
SStb.exe
"Adpowerzone.com ""ServerSide"" keyword hijacker"
N
sstray
sstray.exe
"nVidia nForce Taskbar Utility - quick access to the nForce2 ""Sound Storm"" control panel and related utilitys"
X
SSUpdate
SSUpdate.exe
DyFuCa/MoneyTree parasite variant
X
ssvchost
ssvchost.exe
HELIOS.B VIRUS!
X
SSWPlauncher
??
CometCursor by Comet Systems
N
Stacmon
Stacmon.exe
Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
U
StarSkin
starskin.exe
StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes.
Y
Start
Quick95.exe
For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
X
Start
windows.vbs
Homepage hijacker
X
start extracting
spoolvs.exe
RBOT.AKC WORM!
X
start extracting
spoolvse.exe
W32/RBOT-XF WORM!
N
Start Getright
getright.exe
See Getright Tray Icon
X
Start It Upping
svchosets.exe
variant of the WIN32.RBOT WORM!
X
Start Page
http://find.naupoint.com
Naupoint browser hijacker
X
Start Page
svcnt32.exe
"Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks"
Y
Start RF Wireless Keyboard
ktrexe.exe
Yuanxun Electronics RF wireless keyboard driver
Y
Start RF Wireless Mouse
cm20.exe
Yuanxun Electronics RF wireless mouse driver
U
Start Service
upssrv.exe
"Cyber Power PowerPanelPlus software. ""In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner."""
U
Start Up Cop
startcop.exe
StartUp Cop - startup manager
X
start uploading
smsss.exe
variant of the W32/SDBOT WORM!
X
Start Upping
mcrt32.exe
variant of the W32.SPYBOT WORM!
X
Start Upping
SVCHOSTES.EXE
W32/RBOT-NB WORM!
X
Start Upping
taksmgr.exe
W32/RBOT-QK WORM!
X
Start Upping
taskmrg.exe
W32/Rbot-MA worm infection
X
Start Upping
windupds.exe
SDBOT.AFH WORM!
X
Start Upping
windupdts.exe
variant of the WIN32.RBOT WORM!
X
Start Upping
xdcc.exe
SPYBOT.OY WORM!
X
Start Uppings
mssupdate.exe
variant of the WIN32.RBOT WORM!
X
Start Uppings
svcchosts.exe
SDBOT.VY WORM!
N
Start Wingman Profiler
"lwtest.exe, lwemon.exe"
"Logitech Wingman software required to operate Logitech joysticks and gamepads.? Unless you're a hard-core gamer, it's best to leave it unchecked"
U
Startacc
startacc.exe
"Launches Webroot\'s Accelerate 2000 software that ""speeds up your Internet connection by up to 300%"". Leave enabled if you find it improves internet connection"
U
StartEAK
cpqeadm.exe
Easy_Access Button Support for Compaq PCs. Required if you use these
Y
StartEAK
StartEAK.exe
Easy Access Button Support for Compaq PCs. Required if you use these
X
Starter
scvhosting.exe
WORM_SDBOT.RU
X
starter
scvhostingg.exe
W32/FORBOT-FB WORM!
X
Starting up
wvsvc.exe
RBOT.QQ worm infection
N
startl.exe
startl.exe
Lingocom LingoWare - translates any application into your language
X
StartMenu
deamon.exe
WIN32.TACTSLAY.C TROJAN!
X
StartMenu
msgaol.exe
WIN32.TACTSLAY.C TROJAN!
X
StartMenu
s_menu.exe
WIN32.TACTSLAY.C TROJAN!
U
STARTPAGE
start1.exe
NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder.
X
startpage
startpage.exe
Browser hijacker - redirecting to pages2start.com
U
StartStop
STARTSTOP.EXE
StartStop from TFI Technology - startup manager
U
StartSurfing
STARTS.exe
"Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a ""filter"" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs"
N
Startup
??
Related to an Iomega drive
X
Startup
WinlogonStartup
Unidentified malware
U
Startup Manager Scanner
StartupMonitor.exe
"Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware."
X
Startup Update
Cvshost.exe
GAOBOT.AO WORM!
X
StartupBin
iwnujdss.exe
W32/SDBOT-XZ WORM!
U
StartupMonitor
StartupMonitor.exe
"Mike Lin\'s StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu"
X
startwin
startwin.exe
W32.ANTIMAN.A WORM!
X
startwindowskeyuser
rundle2.exe
JAVAKILLER VIRUS!
N
Stat 'n' Perf
StatnPerf.exe
Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes
X
StatBar
STATBAR.exe
"StatBar?(system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me"
X
State Service
csrss.exe
"TROJ/DADOBRA-CP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
N
Status Monitor
BrMfcWnd.exe
Brother scanner status monitor - can be started manually
N
Status Monitor XE
ENGSS.EXE
The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
N
Stay Connected!
StayCon.exe
"More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs"
U
StayAlive
sa.exe
"StayAlive from TFI Technology.?""This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."""
N
STBWEBTV
STBWEBTV.EXE
Used to display TV on your PC
X
stcinstaller
id53.exe
Add as a result of TROJ_SCTHOUGHT.L TROJAN!
X
stcloader
stcloader.exe
Popup adware by 2ndThought software
Y
STCPO
STCPO.exe
Sophos Sweep antivirus software
X
stdlib
??
TROJ/PERDA-E TROJAN!
Y
STDSB
STDSB.exe
"Scrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling."
U
Stealth Anonymizer 2.5
stealth25.exe
Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy
N
Steam
steam.exe
"Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game. Can be started mnaually."
X
steam
steam.exe
W32/Rbot-AJT WORM! Note: The file steam.exe will be found in the Windows System folder.
N
Stickies
STICKIES.EXE
"Stickies - utility that allows you to put yellow ""Post-It"" type messages on your desktop and can be used to set reminders. Available via Start -> Programs"
N
Sticky Notes
stikynot.exe
Microsoft Sticky Notes - virtual sticky notes tool
N
StickyNote
StickyNote.exe
"Utility that allows you to put yellow ""Post-It"" type messages on your desktop. Available via Start -> Programs"
U
StillImageMonitor
Stimon.exe
"Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners"
X
stisrv
stisrv.exe
RBOT.BQF WORM!
X
stlbdist
??
Hijacker pointing to www.searchandclick.com
X
stlbupdt
??
BrowserAid/Startium parasite
X
stmha
wkfxi.js
JS.SPETH WORM!
N
StopSignStatus
"stopsinfo.dll"",VerifyStatus"
eAcceleration Stop-Sign related; not recommended; see note
U
STOPzilla
Stopzilla.exe
STOPzilla popup blocker
U
STOPzilla Service
SZNTSVC.EXE
STOPzilla popup blocker
U
StorageGuard
sgtray.exe
"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups?"
X
Stratas
ggfig.exe
OPANKI.W WORM!
X
stratas
lockx.exe
W32/SDBOT-ADD WORM!
X
stratas
xmconfig.exe
W32/Rbot-AHR WORM!
U
StreamZap Remote
zremote.exe
"StreamZap_PC_Remote - Control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applications"
U
StrgSync.exe
StrgSync.exe
"SimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders."
X
strmsnmsgr
msnmsgrs.exe
W32/RBOT-ACQ WORM!
X
strmsnmsgrs
msnmsgrsc.exe
variant of the WIN32.RBOT WORM!
X
strmsnnms
msnmegrs.exe
Troj/Sdbot-YU TROJAN!
X
strmsnnrs
msnmcgrs.exe
TROJ/RBOT-ACT TROJAN!
X
strmsoums
msnmegrse.exe
Troj/Sdbot-ZK Trojan!
X
Strng32
strngbox.exe
STRANO VIRUS!
X
strto
strto.exe
TROJ/KILLPROC-F or KillProc-G TROJAN! Note: File name may be different.
X
Sts
iwnujdss2.exe
W32/SDBOT-YI WORM!
X
Stubbish
Stubbish.exe
W32/STUBBOT-A WORM!
X
StubPath
Sservice.exe
PRORAT VIRUS!
X
stxrmsgms
mstats.exe
TROJ/IRCBOT-AE TROJAN!
U
StyleXP
StyleXP.exe
"StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it"
X
SubAH
SubAH.exe
SubAH backdoor TROJAN!
N
Subtract the Ads
AdSub.exe
Removes adverts from web pages. Although useful - not required
X
suck
l0ad.exe
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
U
Suitcase Startup
Suitcase.exe
Suitcase . System font manager start up utility. Used for dynamic managment of fonts on your system.
X
Suite
SuiteOffices.exe /cleandb
Lazar TROJAN!
X
SULFNBJ.EXE
SULFNBJ.EXE
"Left as the result of being infected by the PE_MAGISTR.DAM virus. This virus infects system files and renames them (changing one letter) before adding them to the Run keys in the registry. Once the virus is removed via anti-virus software, delete the infected file and remove the key from the registry"
U
sunasDTServ
sunasDTServ.exe
SunBelt CounterSpy spyware detection and removal software
U
sunasServ
sunasServ.exe
SunBelt CounterSpy spyware detection and removal software
X
SunJavaSched
ccEvtMngr.exe
W32/Sdbot-YP Worm!
X
SunJavaSched Updater
avamx.exe
W32/RBOT-ABJ WORM!
X
SunJavaUpdate
smvss.exe
TROJ/DEDLER-G TROJAN!
X
SunJavaUpdateSched
javamx.exe
W32/SDBOT-WI WORM!
N
SunJavaUpdateSched
jusched.exe
Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
X
SunJavaUpdateSched
scvhost.exe
W32/SDBOT-AVX WORM!
U
Sunkist
shwicon98.exe
"Card reader for memory cards from digital cameras, etc"
U
Sunkist2k
shwicon2k.exe
"Card reader for memory cards from digital cameras, etc"
U
SunKistEM
shwiconem.exe
Used by your computer to communicate with your Alcor_Micro Multimedia Card Reader - necessary if you're using this software
U
SuNotification
suatshut.exe
"ShadowSurfer - ""provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode? system state no matter what changes have occurred to your PC."""
U
SunProtectionServer
SunProtectionServer.exe
CounterSpy antispyware software
U
SunServer
SunServer.exe
CounterSpy antispyware software
N
Supastatus
status.exe
Supanet ISP software
X
super
fuckbx.exe
LINEAGE-H TROJAN!
X
super
super.exe
W32/AGOBOT-QT WORM!
U
Super Popup Blocker
popkill.exe
Saga Super Popup Blocker - pop-up stopper
U
SuperAdBlocker
SAdBlock.exe
SuperAdBlocker
X
SuperBar.Component
services.exe
"FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetsrv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
U
Supercleaner
Supercleaner.exe
Supercleaner - all in one disk cleaner for your computer
U
SuperCool Compress Backup
Main.exe
"""SuperCool Zip Backup software is a data backup,restore and file synchronization program"""
X
SuperHeissSex
SuperHeissSex.exe
HeissSex premium rate adult content dialer!
X
supernews12
newsd32.exe
"Adware, also detected as the TROJ/DLOADER-JN TROJAN!"
X
Supernova
??
SURNOVA (or SUPOVA) VIRUS! <filename>.exe is the chosen name
X
superslut
msslut32.exe
SLUTER-A VIRUS!
U
SuperSpamKiller Pro
Ssk.exe
SuperSpamKiller_Pro email spam blocker
X
supporter5
supporter5.exe
Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
X
support-reverse-smileys
??
Backdoor.IRC.Litebot TROJAN!
U
SureCleanProfessional
SRClean.exe
SureClean PC and Internet tracks cleaner
U
Sureshotpopupkiller
pusak.exe
Stop-the-Pop-Up popup blocker
U
Sureshotpopupkiller
Stopthepop.exe
Stop-the-Pop-Up popup blocker
X
SurfAccuracy
sacc.exe
SurfAccuracy adware
X
SurfBuddy
??
SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!
U
SurfChoice
SCMan.exe
"SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa"
X
Surfer lptt01 or Surfer ml097e
surfer.exe
"Variant of the RapidBlaster parasite (in a ""mssurfer"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
U
SurfinGuard Pro
winsfcm.exe
SurfinGuard Pro - internet protection software
U
SurfSecret
ss2-full.exe
"""House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache"""
X
SurfSideKick 2
Ssk.exe
SurfSideKick adware
X
SurfSideKick 3
Ssk.exe
SurfSideKick adware
U
SurfStream
SurfStream.exe
"Conceiva ""SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings."""
X
Surs
awab.exe
PurityScan/Clickspring adware
X
Susp
Susp.exe
Transponder parasite updater/installer
X
Sustem
explorer.exe
Undentified VIRUS!
X
SustemUpdate
explorer.exe
Undentified VIRUS!
X
SV00LSV
SV00LSV.EXE
GRAYBIRD-C TROJAN!
X
SVA Player
SVAplayer.exe
QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it
X
Svc
svc.exe
"Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND VIRUS!"
U
SVC
svchost.exe
"ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! - this file should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SVC Service
svcinit.exe
SINIT VIRUS!
X
SVC Service
svcinit.exe
CoolWebSearch parasite related.
X
SVC Service
svcpack.exe
CoolWebSearch parasite related.
X
SVC Socks
mstaskm.exe
CoolWebSearch parasite related.
X
Svced
Svced.exe
DELF.F VIRUS!
X
SvcH0st
msexploren.exe
BackDoor-CGZ trojan infection!
X
SvcH0st
SHCH.EXE
TROJ/BDOOR-EB TROJAN!
X
SVCH0ST
spoo1sv.exe
Troj/VB-HF TROJAN!
X
SVCH0ST
SVCH0ST.EXE
"Troj/VB-IK TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
SvcH0st
SVCHST.EXE
TROJ/BDOOR-EB TROJAN!
X
SvcH0st
WINAGENT.EXE
TROJ/BDOOR-EB TROJAN!
X
svchost
??
HAZZER VIRUS!. This is not the valid svchost.exe as described here
X
svchost
??
SETCLO WORM!
X
svchost
ADMAGIC.EXE
SMIBAG VIRUS!. This is not the valid svchost.exe as described here
X
SVCHOST
mrowyekdc.exe
GOTORM VIRUS!. This is not the valid svchost.exe as described here
X
svchost
olehelp.exe
Olehelp adware component
X
SVCHOST
scvhost.exe
W32.Mytob.E or W32.Mytob.G WORM!
X
SVCHOST
SPOOLSV.EXE
W32/Baitap-A WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the Windows or Winnt folder.
X
SVCHOST
SVCH0ST.EXE
"Troj/MMThief-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
Svchost
svchosl.pif
W32.INZAE.A WORM!
X
SVCHOST
svchost.exe
System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the valid svchost.exe as described here
X
svchost
svchost.exe
"MORB or TARNO VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32"
X
Svchost
svchost.exe
W32/Moze-A worm infection
X
svchost
svchost.exe /nosplash
Troj/Bancban-DH TROJAN!
X
SVCHOST
taskgmr.exe
W32.Mytob.F WORM!
X
SVCHOST
taskmgr.exe
W32.Mytob.H WORM!
X
SVCHOST
updater32.exe
W32.RANTS.A WORM!
X
SVCHOST
var.txt.exe
PWSteal.Ldpinch.C trojan infection.
X
Svchost
winhost.exe
LOLAWEB.A VIRUS!. This is not the valid svchost.exe as described here
X
SVCHOST Generic application
svchost.exe
"TROJ/DAEMONI-K TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SVCHOST.EXE
SVCHOST.EXE
"TROJ/WRMSCAN-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
svchost.exe
svchost.exe
Troj/PWSjx-A TROJAN!
X
svchost.exe
svchost32.exe
CoolWebSearch parasite related.
X
svchost1
svchost1.exe
AGOBOT.ZZ WORM!
X
SvcHost32
svchost32.exe
W32.MIMAIL.I or W32.MIMAIL.J WORM!
X
svchost64
svchost64.exe
SDBOTER.G WORM!
X
svchosta
svchosta.exe
TROJ/SNIFFER-I TROJAN!
X
svchostb
svchostb.exe
TROJ/SNIFFER-J TROJAN!
X
SvcHosto
v1rg1n.exe
W32/Agobot-TK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
svchostr
svchostr.exe
unidentified WORM or TROJAN!
X
svchosts
svchosts.exe
Troj/Bancban-DC or the Troj/Banker-ED TROJANS!
X
svchosts.exe
svchosts.exe
W32/AGOBOT-JN WORM!
X
svchosts.scr
svchosts.scr
Troj/Bancban-DQ TROJAN!
X
svcinfo
svcinfo.exe
CRYPTER.A trojan infection
X
Svclhost
svcchost.exe
unidentified WORM or TROJAN!
U
svcmon
svcmon.exe
Spyware.PersonInspect surveillance software. Remove unless you installed it yourself!
X
svcroot
svcroot.exe
TROJ/KEYLOG-AC TROJAN!
X
SvcSys
??
PWSTEAL.BANCOS.Z TROJAN!
X
Svcsys Registry Manager
svcsysreg.exe
TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.cv
X
svctask
svctask.exe
Troj/Chuckyb-A TROJAN!
X
svcwinprocess32
??
UPERING VIRUS!
X
SVHOST
SVCHOST.EXE
W32.Zori.A VIRUS!
X
SVHOST
svhost.exe
W32.Mydoom.I WORM!
X
Svhost Loader
svshost.exe
AGOBOT.G WORM!
X
svhost updates
Svhost.exe
variant of the WIN32.RBOT WORM!
X
svhost windows services
svhost8.exe
W32/RBOT-WQ WORM!
X
sVideo2
vxdrun6.exe
"""Switch"" premium rate adult content dialer"
X
sviload32
sviload32.exe
W32/RBOT-AAS WORM!
X
svnlitup32
svnlitup32.exe
RBOT.CBJ WORM!
X
svnloader
svnload32.exe
W32/RBOT-ACU WORM!
X
svphost.exe
svphost.exe
TROJ_AGENT.CS TROJAN!
X
svrrun
svrrun.exe
adware hailing from Deskwizz.com
X
svsekin
svsekt.exe
TROJAN.PWS.QQPASS.G TROJAN!
X
svshost
messenger.exe
TROJ/LOONY-G TROJAN!
X
svshost
svshost.exe
W32/CHODE-H WORM!
X
svshost32
msgrsv32.exe
WIN32.RANKY.AJ TROJAN!
X
svshost32
svshost32.exe
variant of the W32/SDBOT WORM!
X
svshostdriver
svshost.exe
TROJ/SDBOT-HN TROJAN!
X
svwin32
unninst32.exe
W32/AGOBOT-NF WORM!
X
SVX Control Service
svxhost.exe
W32/Rbot-K WORM!
N
Swap Nut
javaw.exe
"SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network"
X
SWCaller
SWcaller.exe
Homepage hijacker - see here
X
SWCaller
Swcaller2.exe
Homepage hijacker - see here
U
SWClient
swsys.exe
ActivMonAgent Keyboard logger/monitoring program - remove unless you installed it yourself!
"Foxie Swift Sweeper - Part of Foxie Security, Privacy and Productivity Suite"
X
SwimSuitNetwork
SwimSuitNetwork.exe
Advertising spyware
X
swingsys
SWINGSYS.EXE
Troj/Bancos-CX Trojan!
U
Switch Off
swoff.exe
"Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc"
N
Switchboard.com Toolbar
AtHoc.exe
Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com
X
switp
switpa.exe
OfferAgent adware component
U
SWL
??
Stealth.Weblog surveillance software. Uninstall this software unless you put it there yourself.
X
sws.exe
??
Haldex type adult content dialler
X
sws.exe
gd-dial.exe
"Component of the ""GlobalDialer"" adult content premium rate dialer"
X
sws.exe
svchost.exe
"GlobalDialer premium rate adult content dialer. The file is located in a GlobalDialer or HaldexLtd folder in Program Files - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
N
SwTray
SWTRAY.EXE
MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
X
sxrrv
sxrrv.pif
Troj/Vax-A TROJAN!
X
SyBot v2.1 By Sky-Dancer
HPSV.exe
ZOTOB.I WORM!
X
SYDNEY
??
SYNEY VIRUS!
X
Sygate Personal 3
svrv.exe
W32/RBOT-XD WORM!
X
Sygate Personal Block
Studio.exe
W32/RBOT-TW WORM!
X
Sygate Personal Firewall
explorer1.exe
variant of the W32/SDBOT WORM!
X
Sygate Personal Firewall
host32.exe
W32/RBOT.ALD WORM!
X
Sygate Personal Firewall
hostserv.exe
RBOT.BKO WORM!
X
Sygate Personal Firewall
Mcafeeupdate.exe
RBOT.YN WORM!
X
Sygate Personal Firewall
msnmsgrs.exe
RBOT.XN WORM!
X
Sygate Personal Firewall
MSNSRV32.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personal Firewall
service.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personal Firewall
sexy.exe
W32/RBOT-XY WORM!
X
Sygate Personal Firewall
spoolsrv.exe
W32.SpyBot worm variant
X
Sygate Personal Firewall
Sygat.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personal Firewall
Sygate.exe
W32/RBOT-PN WORM!
X
Sygate Personal Firewall
Sygate32.exe
SDBOT.WW WORM!
X
Sygate Personal Firewall
sys.exe
W32/RBOT-ZC WORM!
X
Sygate Personal Firewall
syserror.exe
RBOT.UC WORM!
X
Sygate Personal Firewall
sysgut.exe
SDBOT.WM WORM!
X
Sygate Personal Firewall
system32.exe
RBOT.VI WORM!
X
Sygate Personal Firewall
t1ktik.exe
W32/RBOT-VP WORM!
X
Sygate Personal Firewall
Win32x.exe
W32/Rbot-KZ worm infection
X
Sygate Personal Firewall
wins.exe
RBOT.AOB WORM!
X
Sygate Personal Firewall
winxpstat.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personal Firewall Start
servic.exe
W32/RBOT-RY WORM!
X
Sygate Personal Firewall Start
services32.exe
W32/Rbot-MB worm infection
X
Sygate Personal Port
crss.exe
W32/RBOT-PX WORM!
X
Sygate Personal Port Blocker
volume.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personal Port Blocker
winupdate.exe
variant of the WIN32.RBOT WORM!
X
Sygate Personals Firewalls
ccsrn.exe
variant of the WIN32.RBOT WORM!
U
SyGateService
sgserv95.exe
SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs
X
Symantec
ccapp.exe
W32.Reatle WORM! Note: This is not a Symantec file.
X
Symantec Anti Virus
symantec32.exe
variant of the W32/WOOTBOT WORM!
X
Symantec Autoscan
??
W32/Rbot-AJO WORM!
X
Symantec Configuration Loader
ccApp32.exe
variant of the GAOBOT.GEN WORM!
Y
Symantec Core LC
symlcsvc.exe
Part of Norton AntiVirus 2004. What does it do?
N
Symantec Fax Starter Edition Port
OLFSNT40.EXE
Offers a virtual printer as a fax machine. Can be run via a desktop shortcut
U
Symantec NetDriver Monitor
SNDMon.exe
"Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the ""U"" recommendation"
U
Symantec NetDriver Warning
SNDWarn.exe
Part of Symantec Live Update - displays the warning when you need to update the firewall database.
X
Symantec Security
symantec32.exe
RANDEX.PR or RANDEX.YR VIRUSES!
X
Symantec Security Addon
nvsvc.exe
variant of the GAOBOT/AGOBOT WORM!
X
Symantec Security Routine Addon for Microsoft Windows
navpxaw32.exe
AGOBOT-GJ TROJAN!
X
SymAV
SymAV.exe
W32.NETSKY.U WORM!
U
SymKeepAlive
CKA.exe
Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive
X
SymRun
ccApps.exe
Troj/Kagen-A TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
SymTray - Norton SystemWorks
SYMTRAY.EXE
"Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray"
U
Sync Data
Hndsync.exe
Pocket Real Estate - mobile synchronization manager
U
SyncAgent
syncagent.exe
"Ghost Keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove"
X
Synchronization Manage
rservers.exe
W32/Forbot-FM WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
Synchronization Manager
mobsync.exe
Find more information about its use here
U
Sync-It
Syncit.exe
Sync-It - synchronizes the system clock with time servers on the internet
X
syncman
winsync.exe
Troj/MancSyn-A TROJAN!
X
SyncManager
msorunner.exe
variant of the WIN32.TACTSLAY TROJAN!
X
SyncMon
adslcomdos.exe
CLUNKY-A TROJAN!
X
Syntax
windows32.exe
SDBOT.CQ WORM!
X
Syntax Script
systacq.exe
SDBOT.AI WORM!
U
SynTPEnh
syntpenh.exe
Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
Y
SynTPLpr
syntplpr.exe
Synaptics touchpad driver helper. Required for touchpad features to work
X
sys
??
Hijacker
X
sys
sysdllwm.reg
CoolWebSearch parasite related.
X
Sys Ren
SysRen.exe
Part of FlashEnhancer adware
X
SYS_CLEAN
Service.exe
FLOPCOPY VIRUS!
X
Sys_Run
ghost.exe
Troj/Lineage-N Trojan!
X
sys_Runtt1
explorer.exe
"LINEAGE-M TROJAN! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the Program Files folder!"
X
sys008
sys008.exe
"Hijacker, also detected as the TROJ/STARTPA-GK TROJAN!"
X
sys009
sys009.exe
Troj/StartPa-ZB TROJAN!
X
sys201
sys209.exe
Troj/StartPa-ZY TROJAN!
X
Sys29
??
EliteBar adware
X
sys32
sys32.exe
FLUX.E Backdoor TROJAN!
X
sys32
sysx32.exe
W32/Kvex-A VIRUS!
X
sys32dll
sys32dll.exe
W32.Aimdes.B WORM!
U
sys32sql
sys32win.exe
Active_Keylogger surveillance software. Uninstall this software unless you put it there yourself.
X
SysA
??
EliteBar adware
U
SysAgent
SysAgent.exe
SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
X
SysAI
SysAI.exe
AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located
U
Sysbot
sysbot.exe
Spector - spying (or monitoring) software to record internet activity
X
syscfg
syscfg32.exe
KWBOT.S VIRUS!
X
syscfg34.exe
syscfg34.exe
ELECTRON VIRUS!
X
syscheck
iexplorer.exe
"Win32.Agent.dm downloader trojan infection. NOTE - This is NOT the Internet Explorer file, which is called Iexplore.exe, and will always be located in the Internet Explorer folder in Program Files!"
X
Syscheck
win.hta
Browser hijacker
X
sysclx
ntldrt.exe
W32/Jlok-A WORM!
X
syscm
Syscm.exe
Vanish adware
X
syscon
syscon.exe
W32.APRILCONE.A WORM!
X
syscon lptt01 or syscon ml097e
syscon.exe
"Variant of the RapidBlaster parasite (in a ""Syscon"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
sysconfig
iexplorer.exe
CULT.C VIRUS!. Note - iexplorer.exe is not to be confused with Interrnet Explorer (iexplore.exe)
X
sysconfig
iexplorer.exe
CULT.H VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
U
Sysconfig
Stealth KeySpy.exe
StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!
X
SysConfig
syscfg35.exe
KAZMOR.C VIRUS!
X
SysConfig
wincfg32.exe
SDBOT.ZD WORM!
X
Syscpy
Syscpy.exe
"Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE VIRUS!"
X
SysCtl
sysctl.exe
AOK VIRUS!
X
Sysctrls
procdll.exe
WEEDBOTZ.14 VIRUS!
X
sysdat.dll
sysdat.dll.exe
Nishica 1.1 backdoor TROJAN!
X
sysdir
winrun.exe
WINBUR.B VIRUS!
X
sysdll
??
Trojan.Hugesot TROJAN!
X
Sysdpt
sysdpt.exe
TrojanDownloader.Win32.Crypt
X
sysdxvid
sysdxvid.exe
Premium rate adult content dialer
X
sysdxvid
sysdxvid.exe /nocomm
Troj/Dluca-S TROJAN!
X
SysEQ
svclgx32.exe
TROJ/IRCBOT-AC TROJAN!
X
sysfiler
sysfiler.exe
RETSAM VIRUS!
X
SYSfit
SYSfit.exe
AdShooter adware variant
X
sysflg32
sysflg32.exe
Crypter.C trojan variant infection
X
sysformat
sysformat.exe
W32/BAGLE-BK WORM!
X
syshelp
syshelp.exe
variant of the LOVGATE WORM!
X
sysin
??
TROJ/DSRC-A TROJAN!
X
sysinfo
sysinfo.exe
BEDRILL VIRUS!
X
sysinfo.exe
sysinfo.exe
BEAGLE.V WORM!
X
sysinit
services.exe
Troj/NewIfrm-A trojan
X
SysInit
wininit32.exe
XABOT VIRUS!
X
Sysino
lsess.exe
W32/FORBOT-BF WORM!
X
sysint16
sysint16.exe
Crypter.A trojan variant infection
X
Syskey
sysinit.exe
W32.BEAGLE.AX WORM!
X
Syslib
Syslib.exe
Adult content related downloader trojan
X
Syslog lptt01 or Syslog ml097e
Syslog.exe
"Variant of the RapidBlaster parasite (in a ""Syslog"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
syslogin.exe
syslogin.exe
W32/Bagz-B worm infection
U
Sysman
Sysman
KeyTrap is a spyware program that records all keyboard activities. If you didn't install it yourself remove it.
X
sysmem
mmsete.exe
W32.Nopir.C Worm!
X
sysmem
outlookrem.exe
W32/Nopir-C Worm!
X
SysMemory manager
mdms.exe
Troj/Cimuz-B TROJAN!
U
SysMetrix
SysMetrix.exe
SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics
X
sysmod
sysmod.exe
W32/Spybot-DU WORM!
X
Sysmon
rpcmon.exe
RANDEX.ATX VIRUS!
X
sysmon
sysmon.exe
BIZEX VIRUS!
X
sysmon
sysmon44.exe
variant of the BackDoor-CBA TROJAN!
X
SysMon
wowexece.exe
Troj/Mulan-A TROJAN!
X
sysmon12
??
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
sysmonnt
sysmonnt
Transponder parasite related
X
sysmonnt
sysmonnt.exe
SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server
X
SysMonXP
SysMonXP.exe
W32.NETSKY.Q WORM!
X
sysnate
sysnate.exe
MEDIAS VIRUS!
X
Sysnet
snuninst.exe
Unidentified adware
X
sysnet
sysnet.exe
CasClient adware - also detected as the CMAPP TROJAN!
X
sysobj.exe
sysobj.exe
"TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here"
X
SysOps
SysOps
MSNCORRUPT VIRUS!
X
syspare
syspare.exe
Troj/Bifrose-AN TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
syspath
drv.exe
SOBER VIRUS!
X
sysPersonalFirewall
msnmssgr.exe
variant of the WIN32.RBOT WORM!
X
sysPersonalFirewall
system.exe
WOOTBOT.FH WORM!
X
sysPersonalFirewall
tskm0nitor.exe
variant of the WIN32.RBOT WORM!
U
SysPilot
fdxxl.exe
"G Data ""PC Spion"". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!"
X
sysPnP
bootconf.exe
"Homepage hijacker, redirecting to coolwwwsearch.com; see for example here"
"TROJ/DREMN-B TROJAN! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
Y
SysPool
Mssvc.exe
"StealthDisk - hides folders, files and applications. Will also encrypt them for better protection"
X
sysprocessor Update
sysprocessor.exe
Win32.Rbot worm variant
X
SysProtect
System.exe
NETSPY VIRUS!
X
syspw32.exe
syspw32.exe
W32.Appflet WORM!
X
Sysr
sysmd.exe
Ulubione adult content dialer
X
SysReg
SysReg.exe
CCINVADER2 VIRUS!
X
SysReg
SysReg.exe
SearchSeekFind textual marketing foistware
X
SysRes
IExpIore .exe
W32.ELITPER.E WORM!
X
Sysres
Sysres.exe
LOGMOD VIRUS!
X
SysRes
TASKMANAGER.exe
W32.Elitper.A WORM!
X
SysRes
WWE DIVAS.exe
W32.Elitper.D WORM!
X
SysScan
bvt.exe
AUTOUPDER VIRUS!
X
SysSearch
??
"Hijacker, also detected as the TROJ/STARTPA-ME TROJAN!"
X
SysSearch
??
StartPage-FN browser hijacker
X
SysSearch
??
STARTPA-ME TROJAN!
X
sysser
??
W32.RAHACK WORM! or the Troj/RaHack-B TROJAN!
U
SysService
SERVICES.EXE
"NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\NSkeylogger folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SysService
SysService.exe
TROJ/BDFORM-A TROJAN!
X
SysService32
"SysService32.exe, ln32k.dll"
KINDAL VIRUS!
X
SysService32l
systask32l.exe
THEUG VIRUS!
X
SYSsfitb
SYSsfitb.exe
Searchforit browser hijacker
X
SysStart
??
"Adware, probably VX2/Transponder related - filenames spotted include jdisysi6.exe, hjisysi6.exe, ffgsysi6.exe and more."
X
syst
syst.exe
"JOKE_DUMB.A ""Joke"" virus"
X
System
abcdefg.exe
W32/Harwig-B WORM!
X
System
abcdefg.exe
W32/HARWIG-C WORM!
X
System
Atira.exe
KOTIRA VIRUS!
X
System
cber.exe
unidentified TROJAN!
X
System
csrss.exe
Troj/LdPinch-PT TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
X
System
dcomx.exe
CIREBOT VIRUS!
X
system
Explorer.exe
"GRAYBIRD VIRUS! Note - this is located in this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) rather than the valid Windows Explorer which is located in C:\Windows or C:\Winnt"
X
System
kernels32.exe
VICSFRAM TROJAN!
X
SYSTEM
lsas.exe
SPYBOT.CJ worm
X
system
lsasse.exe
W32/RBOT-YL WORM!
X
system
messenger.exe
unidentified WORM or TROJAN!
X
system
outlook.exe
W32.MIMAIL.Q WORM! **Note - Microsoft's outlook.exe resides in the Program Files sub-directory whereas this resides in C:\Windows or C:\Winnt
X
system
regedit -s system.dll
Homepage hijacker
X
System
run322.exe
LANFILT VIRUS!
X
System
serwin.exe
TROJ/LDPINCH-BN TROJAN!
X
System
SPOOLSU.EXE
Troj/Banker-FC TROJAN! Note: SPOOLSU.EXE (Notice it's spelled with a U) is not the legitimate Windows Process. The legitimate Windows Process (Spoolsv.exe) is found in the System32. This trojan file is found in the Windows or Winnt folder.
X
System
svch?st.exe
Troj/LdPinch-BF TROJAN!
X
System
svchost.exe
"LDPINCH-AU or Troj/LdPinch-BD and Troj/LdPinch-BH TROJANS! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
X
System
sysctrl.exe /a
"WinGuardian **Note: This Commercial_keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware."
X
System
system.exe
"number of VIRUSES, including CHILI, NULLBOT, FULAMER.25, NETCONTROLL, NETCONTROLL, GATECRASH.A, GATECRASH.B, NTCONTROL.A, BUSHTRO122& VIVAEL"
X
System
system23.exe
W32/Lebreat-D WORM!
X
system
systemsearch.hta
Jetseeker.com hijacker
X
System
systray.exe
TROJ/PISABOY-A TROJAN! - NOTE - this is NOT the valid System Tray application as described here
X
System
windowsps.exe
variant of the WIN32.RBOT WORM!
X
System
WINL0G0N.EXE /nosplash
Troj/Bancos-DB TROJAN!
X
System
wumgrd32.exe
variant of the WIN32.RBOT WORM!
X
System
YPager.exe
JUNTADOR.K VIRUS! Note! - this is not Yahoo! Messenger
X
System 64 Driver for Games
sys64dvr.exe
SDBOT WORM!
X
System Applications Profile
sap.exe
W32/RBOT-QF WORM!
X
System backup
??
"ADMINCASH.B TROJAN! - NOTE multiple different file names have been spotted; examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on."
X
System Backup
msystem.exe
Adult content dialler
X
System Backup Services
backups32.exe
variant of the WIN32.RBOT WORM!
X
System Buffer Application
buffer32.exe
W32/SDBOT-UD WORM!
X
System Cache
SysCache.exe
Unidentified worm or trojan
U
System Check
??
"XPCSpy Pro keylogger, surveillance and monitoring software"
X
System Check
??
XpcSpy SPYWARE!
X
system check
updater.exe
Unidentified adware downloader
X
System Checking
wasul.exe
RBOT.BHM WORM!
X
System Config
BF3.EXE
W32/Spybot-DT WORM!
X
System Config Manager
crss.exe
AGOBOT.GH WORM!
X
System Config Manager
smssl.exe
W32/Agobot-ZJ WORM!
X
System Configuration
iexplore.exe
"RANDEX.AD VIRUS! Note that the real ""iexplore.exe"" is located in Program Files\Internet Explorer"
X
System Configuration
syscfg32.exe
W32.Mytob.EA WORM!
X
system configure
svchost.exe
Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
System CPL manager
??
W32/RBOT-SR WORM!
X
System CSRSS Patch
scrtkfg.exe
variant of the WIN32.RBOT WORM!
X
System CSRSS Patch
SCRTKFG.EXE
W32/RBOT-ADA WORM!
X
System Database administration
systemDA.exe
W32.Derdero.B WORM!
X
System Database Administration Support Process
sysdasp.exe
W32.Derdero.C WORM!
X
System Diagnostics
sysdiag32.exe
SDBOT.GEN WORM!
N
System DLF
cpqdiaga.exe
Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
U
System DLL Resources
sysdll.exe
SnapKey SPYWARE! **Note if you did not intentionally install this remove it.
X
System Document Application
msdocument.exe
W32.Randex.COX WORM!
X
System Document Application
nmod.exe
W32/SDBOT-ABB WORM!
X
System Document Application
wins.exe
SDBOT.AUB WORM!
X
System driver
Messenger.exe
WOOTBOT.GI WORM!
X
System Drivers
wingmt.exe
W32/SDBOT-MG WORM!
X
System Efficiency Monitor
mscedit32.exe
SDBOT.P WORM!
X
System Efficiency Monitor
mscommand.exe
KWBOT.P VIRUS!
X
System Event Manager
secsvc.exe
RBOT.BMY WORM!
X
System Executable DLL Library
EXECDLL32.exe
RANDEX.AZ VIRUS!
X
System Failure Statistic
cnstat.exe
W32/Rbot-LF worm infection
X
System Failure Statistic
cnstat.exe
W32/RBOT-LF WORM!
X
System File Drivers
nvsysvc32.exe
AGOBOT.WJ WORM!
X
system firewall
makeini32.exe
W32/AGOBOT-PS WORM!
X
System Guard
mhguard.exe
W32/Rbot-AGU WORM!
X
System Handler
LSASS.EXE
NIMOS VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
X
System Host Manager
syshost.exe
W32/BANWORM-C WORM!
X
System Host Service
svchost.exe
CONE.F VIRUS! Note - this is not the valid svchost.exe as described here
X
System Information Manager
Msbb.exe
variant of the BACKDOOR.IRC.BOT TROJAN!
X
System Information Manager
Navcpe.exe
W32/Sdbot-QB worm infection
X
System Initialization
"msmsgri32.exe, payload.dat"
RANDEX.D or ROXY or ROXY.B VIRUSES!
X
System Kernal Support
system.exe
SDBOT.BWV and W32/Rbot-AEA WORMS!
X
System Kernel
lsass.exe
Troj/VBbot-G TROJAN!
U
System LifeGuard Scheduler
Slsched.exe
System LifeGuard scheduler
X
System Log Event
csrss32.exe
W32/Agobot-JI WORM!
X
System Management Service
smsc.exe
W32/RBOT-ANN WORM!
X
System Manager
svchost.exe
"TROJ/BANKER-AE TROJAN! Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"
X
system manager
System.exe
W32/FORBOT-BO WORM!
X
System Manager
winsrv32.exe
unidentified WORM or TROJAN!
X
System Manager Updates
winsvc.exe
AGOBOT.AEM WORM!
U
System Mechanic Popup Stopper
Popupstopper.exe
"Iolo ""System Mechanic"" popup stopper"
X
SYSTEM MESSAGER
wmisg.exe
W32.Mytob.ES WORM!
X
System Messenger
SYSMSG32.EXE
W32/SPYBOT-DK WORM!
U
System Monitor
SYSMON.EXE
"Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal"
X
System Monitor
Sysmon16.exe
SDBOT WORM!
X
System MScvb
mscvb32.exe
SOBIG.C VIRUS!
X
System Net
sys32.exe
W32/Forbot-FX WORM!
X
System Net Database
sysnd.exe
W32/RBOT-AAW WORM!
X
System Networking
sysnet.exe
RBOT.API WORM!
X
System Process
CSRSR.exe
W32/AGOBOT-SQ WORM!
X
System Process
csrss.exe
"TROJ/ADCLICK-AG TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
System Process
lsass.exe
"TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows lsass.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
System Process
svchost.exe
"TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!"
X
System Profile
Regsrv.exe
BDS/OPTIXPRO.12 VIRUS!
X
System Reboot
rebootsys.exe
W32/RBOT-WU WORM!
X
System Redirect
sysbho.exe
"Downloader trojan, ""Melkosoft"" adware related"
X
System Restore
svcnet.exe
W32.TIBICK WORM
X
System Restore Data
??
RANDON.AN WORM!
X
System Restore DLLs
ixplorer.exe
variant of the W32/SDBOT WORM!
X
System Service
coderxt.exe
W32/Rbot-ALD WORM!
X
System Service
exp0lrer.exe
variant of the WIN32.RBOT WORM!
X
System Service
MSREXE.EXE
AML VIRUS!
X
System Service
servicent.exe
W32/Rbot-AJI WORM!
X
system service
spoolcrv.cpl
INSPIR.11 VIRUS!
X
System service
system.exe
PWSteal.Bancos.AA TROJAN!
X
System Service
systems.exe
AGOBOT.VZ WORM!
X
SYSTEM service helper
svchelper.exe
W32/MONKBD-A WORM!
X
SYSTEM service helper
syshelp.exe
variant of the W32/MONKBD-A WORM!
X
System service61
pokapoka61.exe
EliteBar adware component
X
System service62
pokapoka62.exe
EliteBar adware component
X
System service62
pokapoka63.exe
EliteBar adware component
X
System service63
pokapoka63.exe
EliteBar adware component
X
System service63
pokapoka64.exe
EliteBar adware component
X
System service63
pokapoka66.exe
EliteBar adware component
X
System service65
pokapoka65.exe
EliteBar adware component
X
System service66
pokapoka66.exe
EliteBar adware component
X
System service67
pokapoka67.exe
EliteBar adware component
X
System Services
??
variant of the WIN32.RBOT WORM!
X
System Services
connection.exe
unidentified WORM or TROJAN!
X
System Services
ssms.exe
variant of the WIN32.RBOT WORM!
X
System Services
svcsenes.exe
variant of the WIN32.RBOT WORM!
X
System Services
svcsenes32a.exe
W32/Rbot-AFG Worm!
X
System Session Manager
smss.exe
W32/Kalel-E WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
System settings
burndl32.exe
W32/SDBOT-ZO WORM!
X
System Setup
rpcxcmod.exe
unidentified WORM or TROJAN!
X
System Soap Pro
soap.exe
System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided
U
System startup
charmapx.exe
Only required if using an oriental language
X
System Startup
kimochi.exe
variant of the WIN32.RBOT WORM!
X
System Startup
Voltio.exe
RBOT.NJ worm infection
X
System Stats
SystemStats.exe
variant of the W32/WOOTBOT WORM!
X
System Support
syscfg.exe
W32/Rbot-AGQ WORM!
X
System Support
system32.exe
W32/RBOT-AHA WORM!
X
System Terminal
SYSTEM2.EXE
Troj/Spybot-BZ trojan infection
X
System time updator
CSysTime.exe
RANDEX.S VIRUS!
X
System Toolkit
Systools.exe
RONOPER-G VIRUS!
X
System Tray
msccn32.exe
W32/SOBIG.B Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray ( SysTray.exe)
X
System Tray
systray.exe
W32/Fan-A WORM!
X
System Tray Services
spooles32.exe
AGOBOT.ZH WORM!
X
System Tray32
SysTray32.exe
REPAD VIRUS!
X
System Unix
syscfg32.exe
W32/RBOT-ZD WORM!
X
system updata
updata.exe
Troj/Lineage-C TROJAN!
X
System Update
??
Troj/Soromo-A TROJAN!
X
System Update
wauluclt.exe
SDBOT.EF WORM!
X
System Update
wupdmgr.exe
Troj/Soromo-A trojan infection
X
System Update Service
system.pif
W32/Rbot-ALL WORM!
X
System Update Service
update.pif
W32.Spybot.WOE WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
System Update Service
winupd32.exe
ADTODA-A TROJAN!
X
System Update2
explorer.exe
Autotroj-C TROJAN!
X
System Update2
services.exe
Autotroj-C TROJAN!
X
System Update2
svchost.exe
Autotroj-C TROJAN!
X
System Update2
system.exe
Autotroj-C TROJAN!
X
System Update2
taskman.exe
Autotroj-C TROJAN!
X
System Update2
taskmon.exe
Autotroj-C TROJAN!
X
System Update2
update.exe
Autotroj-C TROJAN!
X
System Update2
webcheck.exe
Autotroj-C TROJAN!
X
System Update2
wininet.exe
Autotroj-C TROJAN!
X
System Update2
winlogon.exe
Autotroj-C TROJAN!
X
System Update2
winspool.exe
Autotroj-C TROJAN!
X
System Update2
wupdmgr.exe
Autotroj-C TROJAN!
X
System Updater Service
wmiprvsw.exe
GAOBOT.AFC WORM!
X
System Updates
winsci.exe
variant of the WIN32.RBOT WORM!
X
System Updates 4
mssysfix.exe
W32/Rbot-ADU Worm!
X
System Updates Manager
winserv32.exe
W32/Agobot-AGA Worm!
X
System Updates Service
updates.pif
W32/Rbot-AMA WORM!
X
System Uptime Server
SYSENTRY.EXE
RBOT.LK worm infection
X
System Uptime Server
SYSENTRY32.EXE
RBOT.LK worm infection
X
system xp
acdsee demo.exe
W32.SALGA.A WORM!
X
system.
system..exe
OPTIXPRO.13.C VIRUS!
X
system...
system...exe
OPTIXPRO.13.C VIRUS!
X
system.exe
system.exe
PWSTEAL.JGINKO TROJAN!
U
System_Messages
pprsen.exe
"TerminatorX - ""offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like"""
X
System132
Csrtss.exe
LANFILT-I TROJAN!
X
system23
notPad.exe
ESTEEMS.D TROJAN!
X
System32
crsvvc.exe
RBOT.BLY WORM!
X
System32
lsasss.exe
W32/RBOT-XW WORM!
X
system32
NeT-BoT.exe
W32/AGOBOT-LJ WORM!
U
System32
sysdiag.exe
SpyAgent.B surveillance software - uninstall this software unless you put it there yourself!
X
System32
system.exe
BUSHTRO122 VIRUS!
X
System32
system.exe
BushTro122 trojan infection
X
System32
"system32,1.exe"
"worm or trojan, as yet unidentified"
X
System32
System32.exe
"MARI, SYSXXX and other VIRUSES!"
X
System32 PCI Manager
syspci32.exe
W32/Rbot-AFR Worm!
X
System32 TCP Manager
systcpm.exe
variant of the WIN32.RBOT WORM!
X
System32 TCP Manager
systerm.exe
RBOT.AFD WORM!
X
System32 Temp Service
systmp.exe
W32/Rbot-AET Worm!
X
system32.dll
sysdll32.exe
CoolWebSearch parasite related.
X
system32.dll
systeminit.exe
CoolWebSearch parasite related.
X
system32.exe
services32.exe
variant of the BACKDOOR.IRC.BOT TROJAN!
X
system32.exe
system32.exe
Backdoor.Graybird.P TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder.
X
System32Dll
DLL32SYS.EXE
W32/Spybot-CZ worm infection
X
System32Ex
System32Ex.exe
Backdoor.IrcContact trojan infection
U
System32kfvw?
sysdiag.exe
SpyAgent.B surveillance software - uninstall this software unless you put it there yourself!
X
System33
FB_PNU.EXE
NICHELLO-A VIRUS!
X
System4224411
Virus
CAGER.A WORM!
X
SystemAdministration
Wincmp32.exe
ASYLUM VIRUS!
U
SystemAgent
Sage.exe
"""Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"""
X
SystemB
MessengerStopper.exe
MessStopper adware
X
SystemBackup
MicroLog.exe
MICROLOG.A VIRUS!
X
SystemBackup
mtx.exe
MTX VIRUS!
X
SystemBoot
??
Adult content dialler
X
Systemboot
msnsngr.exe
variant of the WIN32.RBOT WORM!
X
SystemBoot
services.exe
"W32.SOBER.P WORM! - NOTE - this file is placed in a ""%Windir%\Help\Help"" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SystemCheck
services.exe
"W32/SOBER-M WORM! - Note - this file is placed in a %WINDOWS%\Config\system subfolder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SystemCheck
svchost.exe
"TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SystemCheck
SysCheckBop32.exe
WINBO adware component
X
SystemCheck
Systemcheck.exe
LAVITS VIRUS!
X
SystemChecker
Syschk.exe
GAIL.F VIRUS!
X
SystemCONF98i
SystemCONF98i.exe
FROZEN BOT VIRUS!
X
System-Config
msptmf32.com
Win32.Lioten.FA worm infection
X
SystemDebug
Sysdeb32.exe
SYSBUG VIRUS!
X
SystemDll
SystemDll.exe
LOXOSCAM TROJAN!
X
systemdll32.exe
systemdll32.exe
FEUTEL-F TROJAN!
X
SystemDriver
csrss.exe
"ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!"
X
SystemDriverCheck
svchost.exe
"TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
SystemDriverLoad
svchost.exe
"TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
systemdrv
ms32sys.exe
WORM related - most likely GAOBOT
X
SystemExplorer
explore.exe
"Homepage hijacker - file located in the ""Services"" folder in Common Files"
X
SystemFile
SystemFile.exe
Troj/Dulldoor-A Trojan!
X
SystemFTP
VSENMB.exe
"Malware (ie, malicious software).? Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well"
X
Systemidle
stemIdle.exe
WOOTBOT.AO VIRUS!
X
SystemInit
iservc.exe
FIZZER VIRUS!
X
Systemiom Updater
Systemiom.exe
WORM_SPYBOT.TY
X
SystemLoad32
sysload32.exe
W32.MIMAIL.E WORM!
X
SystemManager
Sysman32.exe
DOWNLOADER-BW.B VIRUS!
X
SystemMap32
Netisp32.vbs
REDIST.C VIRUS!
X
SystemMD
md.exe
Homepage hijacker
X
SystemMonitor
Sysmon32.exe
AIDID.A worm infection
X
SystemMonitor
SYSMON32.exe
W32.Aidid VIRUS!
X
SystemNetwork
NETSERV.EXE
NETCONTROL VIRUS!
X
SystemNetwork
sysnet.exe
variant of the WIN32.RBOT WORM!
X
SystemNT
SystemNT.exe
TROJ/PWSVB-EG TROJAN!
X
SystemNT
SystemNT.exe
TROJ/PWSVB-EG WORM!
X
systemr
d11host.exe
Troj/VB-GX Trojan!
X
systemr
gedit.exe
Troj/StartPa-HC TROJAN!
X
systemr
gedit.exe
Troj/AdClick-AQ TROJAN!
X
SystemReg
svchost.exe
DEWIN.E VIRUS! Note - this is not the valid svchost.exe as described here
X
SystemReg
WINREG.EXE
DEWIN.A VIRUS!
X
Systems
itDDD.exe
Troj/Dloader-PP TROJAN!
X
Systems
itDDD.exe
Troj/VIXUP-G WORM!
X
Systems
scchost.exe
Troj/Tofger-AK TROJAN! Note: This trojan file scchost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item.
X
Systems
svch0st.exe
"W32.MYDOOM.BI WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
Systems
Systems.exe
TROJ/BANKBOA-A TROJAN!
X
Systems Backups
windrives.exe
W32/AGOBOT-RB WORM!
X
Systems Restart
??
Best_Search browser hijacker!
X
Systems Restart
??
StartPage.J TROJAN!
X
Systems Restart
??
Startpage.I browser hijacker
X
Systems Restart
??
variant of the StartPage.J TROJAN!
X
Systems Restart
slchost.exe
BANCOS.RF TROJAN!
X
Systems Restart
spchost.exe
variant of the BANCOS.RF TROJAN!
U
Systems.exe
Systems.exe
"Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it"
U
systems.exe
Systems.exe
"KGBSpy is a commercial spyware program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode."
U
SystemSafe
Syssafe.exe
System Safety Monitor - system monitoring tool with additional application firewalling
X
SYSTEMSars32
csrss.exe
"AHLEM.A VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling"
X
SystemSAS
System32.exe
KWBOT.C VIRUS!
X
SystemSearch
regedit.exe -s c:\ie.reg
Installs a Seachxl.com browser page hijack
X
SystemSearch
regedit.exe -s c:\sys.reg
Installs a i--search.com browser page hijack
X
SystemService
msocfg.exe
Premium rate adult material dialer
X
SystemService
navchk.exe
Premium rate adult material dialer
U
SystemService
nsserver.exe
NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
SystemService
pokapoka62.exe
EliteBar adware component
X
SystemService
qservice.exe
Premium rate adult material dialer
X
SystemService
shman.exe
Premium rate adult material dialer
X
System-Service
EXPLORER.SCR
BENJAMIN VIRUS! KaZaA file-sharing users beware!
X
SystemSettingf
TRUG.vbs
TRUG.B VIRUS!
U
SystemSuite Task Manager
MXTASK.EXE
vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro
X
SystemTasks
filez.exe
Adult content dialler
X
SystemTasks
loaded.exe
Adult content dialler
X
SystemTasks
sexypicz.exe
Adult content dialler
X
SystemTools
kernels32.exe
VICSFRAM TROJAN!
X
SystemTra
CDPlay.EXE
variant of the LOVGATE WORM!
X
Systemtra
Systra.exe
variant of the LOVGATE WORM!
X
SystemTray
SystemTray.exe
BIGFOOT TROJAN! Note - this is not the valid SystemTray ( SysTray.exe )
X
SystemTray
SysTray.exe
"IRC.ALADINZ.P TROJAN! ** Note - Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
U
SystemTray or SysTray
SysTray.Exe
"SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they\'re available via Start -> Settings -> Control Panel"
X
SystemTraySD
SDSystemTray.exe
"Max Spyware Detector, bogus ""Spyware remover"" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""spywaredetector.net"""
N
SystemUpd
SystemUpd.exe
"Updater for Swapoo.com, a kind of Napster for games"
X
SystemWideHook for Windows NT
WinHook32.exe
W32.Mydoom.AC WORM!
U
SystemWizard Sniffer
Sniffer.exe
SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC
X
systemyom Updater
systemyom.exe
variant of the BACKDOOR.IRC.BOT TROJAN!
X
SYSTEMZ Patch
SYSZ.exe
ALADINZ.P VIRUS!
X
Systes
jrdtifkkxbbsa.exe
W32/Rbot-ADC Worm!
X
Systesms.exe
systesms.exe
W32/Rbot-HI worm infection
N
Systest
Systest.exe
Clean Space temp files cleaner
X
systhread
winkernal.exe
LIAMED VIRUS!
X
SysTime
systime.exe
"Troj/StartPa-CR , a CoolWebSearch parasite variant"
X
Systmesy
Systmesy.exe
W32/Rbot-KQ worm infection
X
Systoan32
systoan.exe
Added as the result of an unidentified VIRUS!
X
systrans
??
Troj/StartPa-GZ TROJAN!
X
Systray
"a.exe, b.exe"
Winfavorites adware
X
SysTray
Snnpapi.exe
unidentified TROJAN!
X
Systray
Systray_.Exe
KERGEZ.A VIRUS!
X
SYSTRAY
UNMT.EXE
W32/Sdbot worm infection
X
SYSTRAY
UNMT.EXE
Proxy-Agent trojan variant
X
SYSTRAY
UNMT.EXE
TROJ/DLOADER-LQ TROJAN!
X
Systray
w32explorer.exe
W32/Rbot-AJY WORM!
X
Systray driver
systray.exe
IRC.MUTEBOT TROJAN! ** Note - this is not the legitimate systray.exe process.
X
SystrayServices
Msxpw.exe
CITOR VIRUS!
X
Systry
??
AUTEX VIRUS!
X
SYStry
spoolsvr.exe
SDBOT.GN WORM!
X
Systryt
??
AUTEX VIRUS!
U
systune
systune.exe
AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
U
Systweak Memory Optimizer
memtuneup.exe
Part of SysTweak Advanced System Optimizer
X
sysu
sysu.exe
Dynamic Desktop Media adware - see here
X
sysug32.exe
sysug32.ex
unidentified TROJAN or WORM!
X
Sysupd
Sysupd.exe
VirtuMonde adware
X
Sysvupex
Sysvupex.exe
MEDIAS VIRUS!
U
SysW8
csta.exe
Clean Space - privacy and perfomance enhancer
U
SYSWB6
SYSWB6.exe
"We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content"
X
SysWin
SysWin.exe
Backdoor.IrcContact trojan infection
X
Syswin32
syswin32.exe
Backdoor.IrcContact trojan infection
X
syswin32
syswin32.exe
W32.SpyBot worm variant
X
syswin32
syswin32.exe
SDBOT TROJAN!
X
Syswindow
Syswindow.exe
COW VIRUS!
X
SysWy
rundll32.exe
"TROJ/LINEAGE-JH TROJAN! - NOTE: this file is found in the C:\Windows\System folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!"
X
sysX3
sys22.exe
W32.RANTS.C WORM!
U
SZMsgSvc.exe
SZMsgSvc.exe
StopZilla! - pop-up killer
X
t
xclean.exe
Flashtrack.B adware
U
Taakcontrole
taskmon.exe
"Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)"
X
Taba
stte.exe
Clickspring spyware
N
Tablet
Tablet.exe
"Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL ALT DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds)"
Y
tablet s
tablet s
Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful)
X
Tablet Task
tabletsk32.exe
W32/Rbot-AJB WORM!
U
TabletTip
tabtip.exe
"The Microsoft Tablet PC Input Panel converts handwriting to text dynamically, and you can make corrections quickly and easily before inserting text."
Y
TabUserW
TabUserW.exe
Wacom pen tablet driver
N
Tad
tad.exe
From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute
N
Tahni Deskmate
Tahni.exe
"Tahni Deskmate - ""Interactive cartoon character that lives on your Windows desktop"""
X
TakeMP3
??
MatrixDialer related
X
TAKSMGN
taskmr.exe
W32/Rbot-AHS WORM!
N
TalkingReminder
TALKINGREMINDER.EXE
Talking Reminder from Software River Solutions - talking calendar reminder
X
TANG_INA_MO
AutoRun.bat
W32.Filukin.A WORM!
X
Tapicfg
Tapicfg.exe
CoolWebSearch parasite related.
X
Tapisys
tss.exe
Trojan.Win32.Small variant
U
TapiTNA
TapiTNA.exe
Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys
U
Tardis
Tardis.exe
Tardis - time synchronization software
X
Task
tasker.exe
W32.Mydoom.R WORM!
X
Task Bar
TASKBAR.EXE
FRETHEM.J VIRUS!
X
Task Commander
regsvc32.exe
W32/AGOBOT-RX WORM!
X
Task Debugger
sysdll.exe
W32/RBOT-CQ WORM!
X
Task Help
wualcts.exe
variant of the WIN32.RBOT WORM!
X
Task Manager
prcview.exe
W32/AGOBOT-RT WORM!
X
Task manager
taskemngr.exe
W32/Rbot-AGA Worm!
X
Task Manager
taskman.exe
W32/FORBOT-T WORM!
X
Task Manager
taskmngr.exe
RBOT.Y worm infection
X
Task manager
TikTo.exe
RBOT.LV WORM!
X
Task Monitoring Service
svchost.exe
"CONE.D VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32"
X
Task service
taskmgs.exe
variant of the WIN32.RBOT WORM!
X
task service
taskservices.exe
variant of the WIN32.RBOT WORM!
X
TASK SETUP
tasksetup.exe
W32/RBOT-YR WORM!
N
TaskBar
CTLTask.exe
"The Creative Sound Blaster Audigy Taskbar is used to choose between different types of EAX Effects - not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article."
N
Taskbar
Taskbar.exe
Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
N
Taskbar Display Controls
"RunDLL deskcp16.dll, QUICKRES_RUNDLLENTRY"
"Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes ""Powertoy"" installed"
X
Taskbar Service
taskbar.svc
Unidentified adware
X
Taskbar System
tasksys.exe
variant of the W32/SDBOT WORM!
X
Taskbell.exe
Rund1.exe
Added as a resukt of the YIPID trojan
X
TaskList
tasklist32.exe
TROJ/BANCOS-DX TROJAN!
X
TaskMan
rundll32.exe
"DVLDR VIRUS! Note - this is not the valid ""rundll32.exe"" as it\'s in the Windows\Fonts directory"
X
taskmanager
taskmanager.exe
W32/AGOBOT-TF WORM!
X
taskmanager
taskmgr.com
BEREB VIRUS!
X
taskmanger
taskmanger.exe
variant of the WIN32.RBOT WORM!
X
Taskmgo
??
TROJ/BANCBAN-T TROJAN!
X
Taskmgr
system.exe
TROJ_PAKES.G TROJAN!
X
Taskmgr
Taskmgr.exe
System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory
X
taskmgr
taskmgr.exe
Startpage.G hijacker - NOTE: this is NOT the Windows Task Manager file!
X
Taskmgr
tskmgr32.exe
Homepage hi-jacker
X
taskmgr.exe
mirc.exe
variant of the WIN32.AGENT.AH TROJAN!
X
taskmgr.exe
paint.exe
variant of the WIN32.AGENT.AH downloader TROJAN!
X
taskmgr.exe
paintms.exe
variant of the WIN32.AGENT.AH TROJAN!
N
taskmgr.exe
taskmgr.exe
"Windows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut"
X
TASKMGRU
TASKMGRU.EXE
Hijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx
X
taskmngr
??
FLOOD-EK TROJAN!
X
taskmngr lptt01 or taskmngr ml097e
taskmngr.exe
"Variant of the RapidBlaster parasite (in a ""Taskmngr"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
TaskMon
taskmon.exe
"MYDOOM.A or MYDOOM.J WORMS! Note - this is not the valid Win98/Me file of the same name which resides in C:\Windows as this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). It is not normally on a WinXP system"
X
Taskmon driver
winampa.exe
LOONY-I TROJAN
X
taskmone
taskmone.exe
TROJ/SINGU-S TROJAN!
U
TaskMonitor
taskmon.exe
"The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)"
X
TaskMrg
schwoch.exe
Troj/LDPinch-Y trojan infection
X
taskmrg.exe
taskimg.exe
TROJ/DLOADER-QZ TROJAN!
X
taskopen.exe
taskopen.exe
HackTool.Win32.Hidd.c TROJAN!
N
TaskPlus
TASKPL~1.EXE
"Task and calendar management software available as freeware or as a ""Professional"" version for sharing over a LAN"
N
TaskPlus
TASKPLUS0.EXE
"Task and calendar management software available as freeware or as a ""Professional"" version for sharing over a LAN"
X
TaskReg
??
CBLAD VIRUS! <filename.exe> is the full path and name of the infected file
X
TaskS manager
taskmgrs.exe
AGOBOT.QU WORM!
X
Taskschd
TRAYWND.EXE
LITMUS.002 VIRUS!
U
TaskScheduler
TaskSch.exe
ProSeries accounting software related
N
taskswitch
taskswitch.exe
ALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
X
tasksys
tasksys.vbs
BYRON VIRUS!
N
Tasktray
CTLTray.exe
Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster?Audigy from a systray icon.? Also allows you to launch the Taskbar via right-click -> Show Taskbar. The tasktray can be accessed via Start -> Programs -> Creative -> Sound Blaster Audigy -> Taskbar
X
Tasmgr
Taskmgr.bat
VBS.Ypsan.G WORM!
X
tat
tatss.exe
Delfin_Promulgate adware variant
Y
Tau monitor
Taumon.exe
"""Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system."""
X
TB_setup
tb_setup.exe
HuntBar parasite toolbar installer
U
TB2PROEXE
tb2start.exe
Timbuktu Pro - remote desktop access software
U
TBC Pro
tbcpro.exe
"TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus"
U
TBC.exe
Tbc.exe
TitleBarClock software
N
tbctray
tbctray.exe
Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
Y
TBLFUNC
tblmouse.exe
Aiptek HyperPen driver
U
TBPanel
TBPanel.exe
Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
X
TBPS
TBPS.exe
"WebSearch toolbar, HuntBar parasite variant"
N
TBTray
tbtray.exe
VLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start -> Settings -> Control Panel
Y
tcactive
tca.exe
Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage
N
TCASUTIEXE
TCASUTI.exe
Associated with the 3COM diagnostic module (3COM NIC Doctor).?No further information is available
N
TCAUDIAG -off or TCASUTIEXE
tcaudiag.exe
Associated with the 3COM diagnostic module (3COM NIC Doctor).? No further information is available
U
TClock
TCLOCK.EXE
Kazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start -> Programs
U
TClockEx
TCLOCKEX.EXE
Puts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks
U
tcmonitor
tcm.exe
Part of The Cleaner from MooSoft - warns of changes to the registry
U
TCOYFReminder
tcoyftray.exe
My_ParenTime Fertility Planner Reminder. (The Calendar provides a quick overview of the status of your fertility.)
X
Tcp Application Manager
localsvc.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
netsvc.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
svcman.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
svcrun.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Tcp Application Manager
websvc.exe
Troj/Dloader-NY Trojan!
X
tcp checker
tcpcheck.exe
TROJ/VBBOT-A TROJAN!
X
TCP Monitoring
LanNSvc.exe
RANDEX.AAS VIRUS!
X
TCPXP Update
tcpxp.exe
W32/RBOT-UL WORM!
X
tcupdater
tcupdater.exe
Topconverting.com/180Search adware updater
U
TDKSTART
TDKSTART.EXE
Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
N
TDKTASK
TDKTASK.EXE
"Taskbar utility for a ""control panel"" for a CD-RW"
U
TDS3
TDS-3.exe
"DiamondCS TDS3 antitrojan . Can be used to scan on demand, but required in startup if you prefer real time protection"
N
T-DSL SpeedMgr
speedmgr.exe
T-Online ISP SpeedManager; shows upload and download speed; also checks for updates automatically.
N
Teach In Box
teachbox.exe
Tutoring program that comes with a SystemAX Computer
Y
Tech-In-A-Box
techbox.exe
"Tech-in-a-Box ""provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running"""
U
"Telechips,Mass"
patch.exe
Removable Disk Driver for the Muro MP3 player
N
Telemeter 3.0
telemeter3.exe
Internet connection bandwidth meter from a user ISP
Y
Telepath
telepath.exe
"Drivers for the WinModem versions of the US Robotics ""Telepath"" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
Y
TELUS Security service
freedom.exe
"Freedom Internet Security, provided by TELUS Communications Inc"
X
TempCom
??
W32/TRAXG-B WORM!
X
TempCom
??
TRAXG VIRUS!
X
tempx
tempx.exe
TEMPEX.A TROJAN!
X
Tencent QQ
"Rund1132.exe qq.dll, Rundll32"
Added as the result of the QQPASS.F VIRUS!
X
Terminal Update
biosefui.exe
Troj/PPdoor-O TROJAN!
X
Terminate Popup
FPUK.exe
Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.? Also see here
X
Terminate Popup
ZPU.exe
Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.? Also see here
U
TEscKey
TEscKey.exe
Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
N
Tesco.net
??
Tesco.net dial-up ISP software - not required
X
test
i love you.exe
Troj/Singu-T TROJAN!
X
Testing 123
msdata.dat
W32.Nits.A WORM!
X
testit.exe
testit.exe
ISTbar/XXXToolbar adware component
N
TextAloud
TextAloudMP3.exe
TextAloud MP3 - convert text into spoken words and MP3s
N
Textbridge Instant Access OCR
telepath.exe
TextBridge from Scansoft. OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs
X
TEXTCONV
lsass.exe
"Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup"
X
TEXTCONV
services.exe
NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
X
TEXTCONV
winlogon.exe
NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup!
U
TFncKy
TFncky.exe
Deals with the <Fn> - <Function> key combinations on a Toshiba laptop
U
TFNF5
TFNF5.exe
"Toshiba Hotkey Utility for Display Devices. By pressing <FN> <F5>, a window appears showing the displays that can be chosen ║ LCD, LCD CRT, CRT, TV"
Y
tfswctrl
tfswctrl.exe
"Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
X
TFTP###
tftp###
SPYBOT VIRUS! where # can be any number
U
TFunckey
TFuncKey.exe
Deals with the <Fn> - <Function> key combinations on a Toshiba laptop
N
TgAddServer
tgfix.exe
"Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and ""self-healing"". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove, Charter offer some uninstallation instructions involving a registry patch that you may be able to modify for your proivder or try here"
X
tgbcde
module32.exe
WIN32.REIGN.R TROJAN!
U
Tgcmd
tgcmd.exe
"This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. ""tgcmdprovidersbc"" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
U
tgcmdprovidersbc
tgcmd.exe
"This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. ""tgcmdprovidersbc"" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
N
TGCMG
??
"Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work"
X
TGDC IE Plugin
tgdc.exe
ShopForGood spyware - see here
X
tgkill
tgkill.exe
"Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an ""enhanced"" support and self-repairing tool. This is ""beta"" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs"
U
Tgsetsite
tgfix.exe
"See TgAddserver and Tgcmd above. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the ""U"" recommendation"
N
Thdetrf
thdetr32.exe
Appears to be related to Lycos advertising
X
ThE
wind0s.exe
unidentified WORM or TROJAN!
U
The Easy Bee's Hive
ATCEgSvr.exe
"The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence"
X
The Ethernet
ethernet.exe
variant of the W32/SDBOT WORM!
X
The Intranet
intranet.exe
variant of the W32/SDBOT WORM!
U
THGuard
TH_Guard.exe
Resident memory scanning for TrojanHunter
U
THGuard
THGuard.exe
Resident memory scanning for TrojanHunter
X
"This is a virus, please delete it"
bigbadvirus.exe
RANDEX.F VIRUS!
U
THOTKEY
THotkey.exe
"Associated with the Fn keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen"
X
Threaded
intcp32.exe
RANDEX.UG VIRUS!
U
ThrustTSR
TMTMTSR.exe
"Thrustmaster Thrustmapper. ""The Thrustmapper - t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"""
X
Thumbs Plus X.X
thmbplusXX.exe
W32/Agobot-AAF WORM! (XX is a combination of random digit and character.)
X
tibs3
tibs3.exe
Premium rate adult content dialer - see here
X
tibs5
tibs5.exe
Premium rate adult content dialer - see here
X
Tiger
Shine.exe
HAPPYLOW or W32/Nishe-A VIRUS!
U
TiKL
tikl.exe
TinyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!
X
Time Manager
TimeManager.exe
W32/Mytob-BV WORM!
X
Time Zone Synchronization
wscript zshell.js
NETDEX-A VIRUS!
N
TimeCalendar
tc.exe
TimeCalender - calendar reminder
U
TimeCalendar
TC.exe
TimeCalendar digital planner
N
Timed Backups Manager Startup
BACKTIME.EXE
Backup Plus - backup software
U
TimeLeft
TimeLeft.exe
"TimeLeft is a countdown, reminder, clock, alarm clock, stopwatch, timer, sticker and time synchronization utility which uses Winamp skins to show digits and text."
U
Timemanager.exe
Timemanager.exe
"Time_Manager will let you track billable and non-billable time by customer, by category and by associate and then integrate directly to our custom billing package."
N
TimeOnline
TIMEONLINE.EXE
Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
X
Timer
comm.exe
TROJ/BDOOR-IP TROJAN!
X
TIMER
TIMER.EXE
TIMESE.AG VIRUS!
X
TimeService
trun.exe
TlfLic-A premium rate adult content dialer.
X
TimeSink Add Client
TSADBOT.EXE
TimeSink Ad Client - advertising spyware
X
TimeSyncApp
TimeSynchronize.exe
DealHelper adware
N
TimeUp
Timeup.exe
TimeUp - internet online timer
U
Timezone
TimeZone.exe
Microsoft Daylight Saving Time Update Utility - see here
N
TINTSETP
TINTSETP.EXE
"Part of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word"
X
Tiny AV
fooding.exe
W32.Netsky.I WORM!
Y
Tiny Personal Firewall
persfw.exe
Tiny Personal Firewall
U
tinySpell
tinyspell.exe
"Tinyspell - ""allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard"""
U
TiomanExe
Tioman.Exe
Agate Tioman - warm and hot swap removable bay device manager for IBM laptops
N
Tips
mousetips.exe
Suggests tips on using your mouse
U
TiTleBarClock
TiTleBarClock.exe
"TitleBarClock displays the day/month/time and free physical RAM on the right hand side of an open window, replacing the system tray clock at startup"
N
Tivoli
LCFEP.EXE
"Tivoli ▒TME? System Tray icon - ""\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"""
U
TIxDSL
tidslmon.exe
Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs
X
TizzleTalk
TizzleTalk.exe
"TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messengers. Bundles adware, hence not recommended. From their EULA : ""As a result of installing the Company's Software, you will see occasional banner ads, pop-up or pop-under ads, or other types of ads selected based on your online activities .../... Occasionally, we may automatically or through other remote means, update, upgrade, patch or uninstall the Company's Software, including the Company's advertising-supported software, without further notice to you. These upgrades also may include installation of additional applications from the Company as well as third party applications."""
X
tjstartup
??
BACKDOOR.TJSERV.C TROJAN!
X
tjstartup
svchost.exe
CURDEAL TROJAN! **Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
N
TkBell.Exe
evntsvc.exe
"Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
N
TkBell.Exe
realsched.exe
"Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
N
TkBell.Exe
tkbell.exe
"Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
N
TkBellExe
evntsvc.exe
"Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
N
TkBellExe
realsched.exe
"Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
N
TkBellExe
tkbell.exe
"Application Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
X
TkBellExee
realschd.exe
unidentified downloader TROJAN!
X
TkNetDriver Monitor
lexbce.exe
W32/SDBOT-ADF WORM!
N
tkonnect
TKONNECT.EXE
Dialer for the Tiscali internet service provider. Available as a desktop shortcut
X
tlc
??
Hijacker installer
U
TLogonPath
tb2logon.exe
Timbuktu Pro - remote desktop access software
U
TM Outbreak Agent
TMOAgent.exe
Trend Micro Internet Security anti-virus software virus outbreak warnings. Notifies users of virus outbreaks and offers to update the scanner
U
TMA distribution
cfinst.exe
Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
X
tmax
pupdate.exe
Adware pop-up generator
X
tmchook
tmchook.exe
Detected by Kaspersky as the TrojanDownloader.Win32.VB.aa VIRUS!
U
TMESBS
TMESBS21.exe
Toshiba Mobile Extension Selectable Bay Service for WinXP - support for docking stations. Not required if you don't use a docking station
N
TMESRV31
TMESRV31.EXE
Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
U
TMExLogon
TMESRV.EXE
Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
X
TmNetDriver Monitor
exbce.exe
W32/Sdbot-ABR WORM!
X
Tmntsrv32
Tmntsrv32.exe
"Hijacker, detected by Norton antivirus as Trojan.StartPage.O"
U
TMOUSE
tmouse.exe
"Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint"
Y
tmproxy
tmproxy.exe
Trend Micro PC-cillin 2003 antivirus software
N
TMTMTSR
TMTMTST.exe
"Installed with Thrustmaster game controllers. It launches the Thrustmapper utility. Not required if you install the ""driver only"" from Thrustmaster website"
U
TNTClk
TNTCLK.exe
"Overclocking program for?TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked?to let it?run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job"
U
ToADiMon.exe
ToADiMon.exe
T-Online ISP software connection assistant
U
TopDesk
TopDesk.exe
"TopDesk; puts an icon in your system tray that when clicked upon, opens a pop-up menu that gives instant access to all of your desktop programs without having to minimize, resize, move or close other programs or files."
X
ToPicks Starter
Idhost.exe
ToPicks parasite related
X
topmoxie
JavaRun.exe
Marketing software from TopMoxie
X
TopSearch
TopSearch.exe
TopSearch adware variant
Y
Toshiba Fan
fan.exe
Toshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat
U
Toshiba Key State
KEYSTATE.EXE
"Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start -> Programs"
N
ToshibaPinger
pinger.exe
"Pinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification. Disabling instructions here"
U
TOSHIBSU
Toshibsu.exe
"Reduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly"
U
TosHKCW
TosHKCW.exe
Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed)
Y
TosMem
tosmem.exe
Toshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem
U
TosRotation
TRot.exe
TOSHIBA Rotation Utility - allows users to rotate a notebook's screen image 180 degrees in order to share information on the screen with others seated across a table or desk
U
TotRecSched
TotRecSched.exe
Scheduler for Total_Recorder from High Criteria Inc - audio capture utility
Y
ToUcamVProperty
VProperty.exe
"Philips Web Camera model name pcvc740k, ToUcam driver configuration tray icon."
U
Touch Manager
WinLED.exe
Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
U
TouchED
TouchED.exe
TouchPad On/Off Utility on a Toshiba laptop
N
tour
regedit ..tour.reg
Edits registry values to keep the WinMe tour in Task Scheduler
N
Tour
wincool.exe
"Component of WinME that's annoying as hell. Pop\'s up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only"
N
tourpath
??
"Edits registry values to keep the Win 2000 ""tour"" in Task Scheduler"
U
TP4EX
tp4ex.exe
Adds accessibility options for an IBM TrackPoint
U
tp4serv
tp4serv.exe
"Supports the ""pointer stick"" on Thinkpads in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
N
TP98UTIL
TP98.EXE
IBM Thinkpad feature setup & configuration utility
X
tpcupdater
updatetc.exe
"Adware, probably 180Solutions related"
U
TpHotKey
TPHKMGR.EXE
"Activates ""ThinkPad Help"" when the ""Thinkpad key"" is pressed on an IBM ThinkPad laptop. Also activates the audio buttons (volume up/down, mute) on models such as the Thinkpad T30"
U
TpKmapMn
TpKmapMn.exe
"Create Keyboard combinations for special Thinkpad buttons when using an external keyboard, e.g. ""Ctrl-arrow up"" for ""volume up"". Only required when using an external keyboard. Available via Start -> Programs"
N
TPNF
TPTray.exe
Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel
U
tpopservice
tpopservice.exe
DirecWay two-way satellite internet service enhanced POP proxy server for email
U
TPP Auto Loader
Tppaldr.exe
"Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives.?System tray icon allowing the user to disconnect the external drive without an error message being displayed"
U
Tprtray
Tprtray.exe
Displays the Power icon in the System Tray on a Toshiba laptop
Y
TpShocks
TpShocks.exe
"Responsible for controlling the IBM Hard Drive Active Protection system found on newer models of IBM Thinkpads, including T41, T42, X40, R50, and R51. The Hard Drive Active Protection system is based on a technology similar to that used in automobiles to deploy airbags on contact: An accelorometer on the motherboard detects physical acceleration--such as when the notebook falls--and in response the system temporarily parks the hard drive's read/write head until stability returns"
N
TPTray
TPTray.exe
Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel
Y
TPWRTRAY
Tpwrtray.exe
Toshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use
U
tqrecv
tqrecv.exe
Tellique satellite broadcast reception software
N
Traceless
launch.exe
"Traceless 2003 - clear your cookies, temp directories and browser history with a click of a button. It also clears the recent documents and the IE drop down auto complete box"
U
Track4WinMonitor
STMonitor.exe
Track4Win is a spyware program that takes screenshots and logs user activity such as URLs and currently running processes. It uploads the logs and screenshots to a preconfigured server. If you didn't install this yourself remove it
U
TrackpointSrv
daemon.exe
"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
U
TrackPointSrv
tp4mon.exe
"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
U
TrackpointSrv
tp4serv.exe
"Supports the ""pointer stick"" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the ""scroll"" button to work"
U
Tracks Eraser or Tracks Eraser Pro
te.exe
"Tracks Eraser Pro from Acesoft - ""Erases all tracks of your internet activity""?"
U
Tranicon
tranicon.exe
"A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent"
U
Transparent
??
"Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here"
U
TransparentIcons
tranicon.exe
"A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent"
U
TransTask
transtask.exe
Tweak-XP_Pro related; feature to make the Windows XP taskbar transparent
U
Trashgrd
TRASHGRD.EXE
"Part of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin"
U
Tray Pilot Lite
TrayPlt.exe
Tray_Pilot allows you to hide the System Tray window.
N
Tray Temperature
Weatherbug.exe
"Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs"
N
tray_helper
tray_helper.exe
"Tray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder"
X
Traybar
lsass.exe
W32.Mydoom.L WORM!
U
traydate.exe
TRAYDATE.EXE
Displays the date as well as the time in the System Tray. Available from TUCOWS
U
TrayManager
Trayman.exe
TrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded)
U
Traymon
traymon.exe
Netropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news
N
TraySantaCruz
tbctray.exe
Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
N
TrayServer
TrayServer.exe
For monitoring tray icons
X
TrayX
winppr32.exe
SOBIG.F VIRUS!
U
Trend Micro Anti-Spyware
Tmas.exe
Trend_Micro_Anti-Spyware - required when using real time monitoring
Y
TrendMicro Antivirus
Aveagent.exe
Virus scanner
Y
TrendMicro OfficeScan NT
TMLISTEN.EXE
Virus scanner
X
Trickler
??
Gator adware
X
Trickler
??
Gator adware
X
Trickler
??
Gator adware
X
Trickler
fsg.exe
Gator adware
Y
TridentTVIcon
tvicon.exe
"Trident Microsystems, Inc Display driver"
U
Trillian
trillian.exe
Part of Trillian ICR client
Y
trirot
trirot.exe
Trident Microsystems 3D video driver
U
Trojancheck 6 Guard
tcguard.exe
TrojanCheck anti-trojan software
U
TrojanScanner
Trjscan.exe
Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed
U
TrojanShield
Init.exe
TrojanShield anti-hacker/anti-trojan software
U
TrojanShield Protector
Port.exe
TrojanShield anti-hacker/anti-trojan software
U
True Internet Color Icon
internetcolor.exe
"Part of Colorific & 3Deep from LightSurf Technologies (nee E-Color). ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"""
X
TrueFonts
fonts.hta
Browser hijacker - redirecting to Hugesearch.net
N
TrueSync Launcher
tstool.exe
"Starfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services"
Y
TrueVector
VSMON.EXE
Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
X
TrustyHound-TS
TrustyHound-TS.exe
TrustyHound spyware
X
tsa
tsm.exe
TargetSaver adware
X
Tsa2
tsm2.exe
TargetSaver adware
X
Tsa2
tsm2.exe
TargetSaver adware
X
TsAdbot
TSADBOT.EXE
TimeSink Ad Client - advertising spyware
U
TSE_PLUtil
PLBkMon.exe
Prolific USB Flash Disk Log On Application
X
Tsk Mng Hlp
wins32.exe
W32/AGOBOT-JB WORM!
X
tskdbg
tskdbg.exe
FLOOD.E VIRUS!
X
Tsl
tsl.exe
Uploader-R adware
X
Tsl2
tsl2.exe
TargetSaver adware
N
TSMsger
TSMsger.exe
"Epson scannner software - required for ""one-touch"" operation. Can be launched manually"
X
tsvcin
n20050308.EXE
"Adware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!"
X
TSystem
??
Troj/Nsys-A Trojan!
X
ttaa
tata.exe
TROJ/LINEAGE-T TROJAN!
X
TTS Sync
testtts.exe
SDBOT.BVA WORM!
X
ttupt
ttupt.exe
eZula TopText adware component
U
TuneUp MemOptimizer
memoptimizer.exe
"Part of ""TuneUp Utilities"", specifically 2003 version. ""Monitors and optimizes free memory in the background."" Basically, it cleans RAM and also allows you to clear the clipboard"
U
TurboExplorer
TE.exe
"Web accelerator - ""TurboExplorer╜ 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer╜ 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing"
U
TurboMemoryCharger
turbomemorycharger.exe
Some users swear by memory management utilities such as Turbo Memory Charger but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
N
TurboNote
tbnote.exe
Post-It's on your desktop. Available via Start -> Programs
U
TurboTop
TurboTop.exe
"TurboTop - make any window ""Always on top"""
X
TV Media
Tvm.exe
CleverIEHooker hijacker variant
U
TV Scheduler
TVSCHL.EXE
ProLink PlayTVpro TV tuner software scheduler
X
TVMD
tvmd.exe
"Total Velocity - ""Secure commerce company that enables the ▒checkout? process for our customers in order to safely and securely purchase our award winning software"". Autointsalling spyware"
U
TvNow
TvNow.exe
Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts).
X
tvs_b
tvs_b.exe
BroadcastPC adware variant
X
tvs_b
tvs_ln.exe
BroadcastPC adware variant
X
tvs_re
tvs_re_inst.exe
BroadcastPC adware variant
X
TVTMD
TVTMD.EXE
Total Velocity variant - autoinstalling spyware
N
TVWakeup
tvwakeup.exe
MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X
Twain image
mmp32.exe
DailyWinner adware related
U
TWarnMsg
twarnmsg.exe
"Toshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops"
U
Tweak UI
??
"Automatically logs you on if you have Microsoft\'s Tweak UI ""powertoy"" installed"
U
Tweak UI
??
"Restores settings that can\'t be retained if you have Microsoft\'s Tweak UI ""powertoy"" installed"
X
Tweak UI
"RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup"
"SUBWOOFER VIRUS! Note - the real Tweak UI entry for this is ""rundll32.exe tweakui.cpl, tweakmeup"""
U
Tweak UI 1.33 deutsch
??
"Restores settings that can't be retained if you have Microsoft's Tweak UI ""powertoy"" installed - German version"
U
TweakDUN
tweakdun.exe
Utility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets
U
Tweaki4PU
twksup.exe
"""Tweaki puts several Windows utilities into one easy to use program while adding hundreds of additional tweaks not found in other system tweakers"""
U
TweakMASTER
TMTray.exe
TweakMASTER Internet Optimizer
U
Tweak-Me
TWEAK-ME.exe
"3rd party version of Miscrosoft'sTweak UI ""powertoy"" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here"
U
Tweak-xp
Tweak-xp.exe
Main program for Tweak-XP - a WinXP tweaking utility
U
twister
twister.exe
"Twister ""AntiTrojanVirus"""
N
TwkSCardSrv
SCardS32.Exe
Used with Towitoko SmartCard Readers for card recognition
X
twunk service
twunk16.exe
RBOT.BAT WORM!
X
twunk_32
twunk_32.exe
"BLACKMAL.C WORM! - This malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
Twunk_64
twunk_64.exe
System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a Windows\System\1060 directory
X
tyack drive
tyack.pif
W32/Rbot-AMT WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
N
type32
type32.exe
"For MS programmable keyboards. If you disable Intellitype in Startup, any ""Hot Keys"" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them"
N
TypingSatellite
KBOOST.exe
Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs
X
Uate
oocs.exe
PurityScan/Clickspring adware
U
UBSShell
UBSShell.exe
UBS (United Bank of Switzerland) banking software
N
UC_SMB
ucstart.exe
Part of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
N
uc_start
ucstartup.exe
"Auto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc"
U
UCmore XP - The Search Accelerator
??
UCmore toolbar - search accelerator
U
UD Agent
UD.EXE
The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
U
Ueproc32
UEPROC32.exe
Part of Norton Utilities - most likely associated with the Unerase Wizard in older versions
N
Uidler
Uidler.exe
Uniloc Titlewave Browser used with some shareware
N
UIWatcher
UIWatcher.exe
Ashampoo Uninstaller Suite - installation watcher. Available via Start -> Programs
X
UKVideo2
ukvideo2.exe
Adult content dialler
N
Ulead Photo Express x.0 Calendar
calcheck.exe
"Ulead Calendar Checker - part of Ulead Photo Express, where ""x"" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions"
N
UltimateZip Quick Start
uzqkst.exe
UltimateZip - file compression utility
N
Ultra Hal Assistant 4.5 Startup
HalAsst.exe
Zabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion
X
Ulubione
??
Ulubione adware component
N
UMAX VistaAccess
vsaccess.exe
VistaAccess gives you quick and easy access to scanning functions right from your desktop
U
UMonit
umonit.exe
Alerts when USB device is plugged in
Y
umxagent
umxagent.exe
Tiny Personal Firewall V4 - main engine
Y
umxldra
umxldra.exe
User mode executive module DLL loader - part of Tiny Personal Firewall V4
Y
UMXLDRW
UMXLDRW.exe
Tiny Personal Firewall (pre V4)
X
un32info
un32info.Exe
CRYPTER.A trojan infection
X
UNERI
yujixit.exe
SDBOT.BOO WORM!
U
UnHackMe Monitor
hackmon.exe
"UnHackMe allows you to detect and remove a new generation of 'invisible' Trojan programs called ""rootkits""."
X
uninstal
??
CoolWebSearch parasite related.
X
Uninstall####
upd.exe
Adult content based screen saver where #### can be any number
"WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable."
N
UninstallAbility
uability.exe
UninstallAbility uninstaller
U
UniPrint
SetDfltSettings.exe
"Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix."
U
UniSc
Unisc.exe
McAfee UnInstaller
X
Universal USB Service
svchost32.exe
W32.KELVIR.R WORM!
X
Unix File Support
init3.exe
W32/RBOT-ZN WORM!
X
unldr16
unldr16.exe
CRYPTER.C trojan variant infection
X
unldr32
unldr32.exe
Crypter.C trojan variant infection
X
UnSpyPC
UnSpyPC.exe
"""Spyware remover"" of dubious repute - see the authoritative SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites"
Y
untray
untray.exe
Part of Command AntiVirus
N
uoltray
exec.exe
Netzero free ISP software - not required
N
UpConfgVer
UpgConf.exe
"Panda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function."
"Browser hijacker, redirecting to buldog-search.com"
X
update
r00t.exe
W32/RBOT-ACO WORM!
X
UpDate
RAuth.exe
TROJ/DLOADER-UL TROJAN!
X
Update
Sysupd.exe
SLACKBOT VIRUS!
X
update
winis.exe
W32/RBOT-VD WORM!
X
UPDATE =
WinUpdater5.0.vbs
VBS/Gormlez-A Worm!
X
Update for Windows
??
W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
N
Update Grokster
WiseUpdt.exe
"Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor"
X
Update Install
Schost.exe
GAOBOT.AO WORM!
N
Update Manager
UpdateManager.exe
Searches for updates for the Rogers Yahoo!_Browser - can be run manually
X
update run dos
logon.exe
variant of the W32/SDBOT WORM!
X
Update Run MSword
LOGON.EXE
RBOT.TY WORM!
X
update service
svxhost.exe
RBOT-MG WORM!
Y
Update Service
Update.exe
Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall
X
Update Service
winu32.exe
W32/RBOT-MG WORM!
X
update service
winx.exe
variant of the WIN32.RBOT WORM!
X
Update ver 1.0
Swap.exe
W32/SWAP-C WORM!
X
"Update"" -s setup"
Zupdate.exe
"B3d Projector foistware - periodically tries to access the internet. (1) Uninstall via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
X
Update.exe
ravseuper.exe
Troj/QQPass-P TROJAN!
N
UPDATE~1
UPDATE~1.EXE
"Once a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually"
X
Update32
configs.exe
"Hijacker, also detected as the QURL-2 TROJAN!"
X
UpdateCheck
winstall.exe
W32/SPYBOT-CY WORM!
X
UpdateComponent
CNF UPD.EXE
SPYBOT.GEN VIRUS!
X
updatelavasoft
updatelavasoft.exe
"CoolWebSearch related hijacker, redirecting to lalasearch.com"
U
UpdateManager
sgtray.exe
"StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups"
X
UpdateMedia
UpdateMedia.exe
MediaUpdate foistware
X
UpdateMgr
updmgr.exe
SouthBeachTel premium rate adult content dialer.
N
updatemgr.exe
updatemgr.exe
"Once a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually"
X
UPDATEMSN
svhost.exe
unidentified WORM or TROJAN!
X
Updater
adservernow.exe
AdServerNow adware
X
updater
wisvc.exe
TROJ/ORSE-A TROJAN!
X
updater
wupdater.exe
eUniverse/KeenValue adware
X
Updater Service Process
svhost32.exe
AGOBOT.TY WORM!
X
updater32
winload32.exe
"CULT.M WORM! **Note - not to be confused with the valid Windows ""NOTEPAD"" text editor"
X
Updates
msupdate.exe
CoolWebSearch parasite related.
N
Updates from HP
??
Automatically detects an internet connection and downloads any available updates - * is random digit
N
Updatestats
Updatestats.exe
"Statblaster - ""Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues"""
N
updatev01
updatev01.exe
Ultra-networks.com software updater/downloader
X
upddateit
winit.exe
W32/RBOT-MS WORM!
X
updmgr
rvupdmgr.exe
eUniverse/KeenValue adware
X
Updmgr
updmgr.exe
eUniverse/KeenValue adware related
N
UpdReg
Updreg.exe
Reminder to register Creative Labs SoundBlaster Live! cards
Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss?
X
UPSUtl
web.exe
CoolWebSearch parasite related.
U
Uptimer4
Uptimer4.exe
"Uptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things"
X
UpTimes service
WinUp.exe
W32/Rbot-AKB WORM!
X
UpToDate
uptodate.exe
BrowserAid/BrowserPal foistware
X
upyxo
yujixit.exe
SDBOT.BIX WORM!
Y
URLLSTCK.exe
UrlLstCk.exe
"Part of Norton Internet Security. From Symantec - ""UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled"""
N
URLMAP
Urlmap.exe
"Installed by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it"
Y
UrtSvcExe
Urt95Svc.exe
"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
X
USB 2.0 Driver
updateXP.exe
W32/AGOBOT-QP WORM!
X
USB 2.0 Driver
updateXPSPC.exe
W32/AGOBOT-RJ WORM!
X
USB 2.0 Driver
Winsys32.exe
W32/AGOBOT-QM WORM!
X
USB 2.0 Driver
winsystem.exe
W32/AGOBOT-QS WORM!
X
USB 2.1 Driver
winupdate1.exe
variant of the WIN32.RBOT WORM!
X
USB controller
Svcmm32.exe
SvcMM backdoor parasite downloader
X
USB Device
servicelog.exe
WOOTBOT.CB WORM!
X
USB Device
win32usb.exe
W32/FORBOT-BQ WORM!
X
USB Driver4
UpdateXP2.exe
variant of the W32/SDBOT WORM!
X
USB Driver4
UpdateXP6.exe
variant of the W32/SDBOT WORM!
X
USB Drivers1
msupdate.exe
variant of the WIN32.RBOT WORM!
X
USB Driverz2
msnplus1.exe
W32/SDBOT-XQ WORM!
X
USB Fix 1.1
wuservices.exe
variant of the W32/SDBOT WORM!
X
USB Fixes
wuafix.exe
W32/RBOT-ABV TROJAN!
X
USB Hardware Monitoring
USBhardware.exe
W32/RBOT-NN WORM!
X
USB Hardware326 Monitoring
USBhardware326.exe
variant of the W32.SPYBOT WORM!
X
USB Hardware32c Monitoring
USBHARDWARE32C.EXE
W32/RBOT-UU WORM!
X
USB Host Service
usbsvc.exe
W32/Rbot-GG worm infection
Y
USB SECURITY DEVICE CoInstaller
JupitCo.exe
ButterflyMedia USB Flash drive related - required for the password security feature to work.
X
USB Updates
mservices.exe
variant of the SDBOT WORM! - see here
X
USB Updates
msfirewalls.exe
variant of the WIN32.RBOT WORM!
X
USB Updates 2
wugfixx.exe
variant of the WIN32.RBOT WORM!
X
USBConfigration2
wmmndir.exe
W32/Agobot-SV Worm!
X
UsbD
??
Troj/Cidra-F TROJAN!
X
UsbD
iexplore32.exe
Unidentified worm or trojan
X
UsbD
smss32.exe
Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj
X
UsbD
svhost32.exe
TROJ_AGENT.IB TROJAN!
X
Usbd
usb_d.exe
TROJ/CIDRA-A TROJAN!
U
USBDetector
USBDetector.exe
USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
X
USBDrives
msfirewalI.exe
W32/RBOT-ABP WORM!
X
usbdrv
servicetask.exe
variant of the W32/SDBOT WORM!
X
USBHWDRV
gam.exe
variant of the TROJ/LOWZONE-I TROJAN!
X
USBHWDRV
msdc.exe
variant of the TROJ/LOWZONE-I TROJAN!
X
USBHWDRV
sst4.exe
variant of the TROJ/LOWZONE-I TROJAN!
X
USBHWINFO
mac.exe
TROJ/LOWZONE-I TROJAN!
X
USBHWINFO
mmc.exe
TROJ/LOWZONE-I TROJAN!
X
USBHWINFO
sst6.exe
TROJ/LOWZONE-I TROJAN!
U
USBMMKBD
usbmmkbd.exe
USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information
U
USBMonit.exe
USBMonit.exe
Monitors USB ports for insertion of Sandisk USB flashdrives
X
usbn
??
Troj/Hogil-E TROJAN!
X
usbn
usbn.exe
"Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa"
Y
USBPNP
USBPNP.exe
SiPix digital camera Twain USB driver
N
USBTA
usbtapnp.exe
System Tray access for the BeWAN Gazel 128 USB ISDN adapter
X
useful-soft
svchst.exe
"Browser hijacker, redirecting to elite-glsex.net"
X
user
user32.exe
Backdoor.Binghe TROJAN!
U
User Logger
UsrLog.exe
"UserLogger is a commercial spyware program. It logs keystrokes, programs used and computer ID information. It also captures screenshots, can hide its presence on the computer and can be disguised in the Windows Task list."
X
User Manager
fcllls.exe
ZAGABAN-B TROJAN!
X
User Services
usersvc.exe
REVCUSS.A VIRUS!
X
User23.exe
DIAL.exe
This is a trojan trying to disguise itself as User32.dll
X
User32
??
NETTRASH VIRUS!
N
UserFaultCheck
dumprep 0 -u
"Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out"
X
Userinit
lsass.exe
"variant of the Troj/Dloader-TP TROJAN! - NOTE - this file is placed in the Program Files\Common Files folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
userinit
winlogon.exe
Troj/Dloader-TP TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
X
UserInit StartUp
rpcxuisu.exe
variant of the W32/SDBOT WORM!
X
userint32
userint32.exe
"unidentified TROJAN via an Instant Message that says, ""This was cool, check it out here."" Also contains Aurora popups"
X
USERINTERFACE REPORT3R
M0USE.exe
MYTOB.HS WORM!
X
Userinterface Reporter
fuuuucktttttt.exe
W32/MYTOB-DK WORM!
X
Userinterface Reporter
srv32.exe
ISTbar/XXXToolbar adware downloader
X
ushli
sscbltqu.exe
Obtained from an MP3 search list site. Also generates random processes on reboot
X
usrgtway.exe
syswrun4x.exe
MITGLIEDER.E VIRUS!
N
USRobotics 802.11g Wireless Network Utility
USRWLANG.exe
"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties"
N
Usrobotics Online Registration
??
Pop-up reminding customers to register their products online at US Robotics
Y
USRpdA
??
US_Robotics modem driver
X
Usrr
rncr.exe
PurityScan/Clickspring adware
X
Usrr
rpen.exe
PurityScan/Clickspring adware
N
USSShReg
USSSHREG.EXE
Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
N
UtilityPro
UtilityPro.exe
IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions
Y
UTILsInst
??
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
N
Utopia Angel
Angel.exe
Calculator for the online Utopia game
X
uwyrl
uwyrl.exe
PHEL.A TROJAN!
X
uwyw.exe
yujixit.exe
SDBOT.BGB WORM!
U
V.92 Modem On Hold
Ltmoh.exe
Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
Y
V128IID
??
Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages
U
va10key
va10key.exe
Only required if you use the 10 kay bay unit with a Sony Vaio laptop
X
"Vaganza-XPloit-[User Name]"""
??
W32.GAVGENT.A WORM!
Y
VAGCtrl
VAGCTRL.EXE
Vexira Antivirus - virus scanner from Central Command
Y
VAGuard
VAGNT.exe
Vexira Antivirus - virus scanner from Central Command
U
VAIO Action Setup (Server)
VAServ.exe
"Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB"
U
VAIO Recovery
PartSeal.exe
System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
X
ValidData
??
RANKY.H backdoor WORM!
X
VB_run
comctl_32.exe
Dubious downloader from densmail.com
X
vb6
vb6.exe
W32.MUGLY.D WORM!
X
VBouncer
VirtualBouncer.exe
"Virtual_Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code."
X
VbouncerDL
VBouncerInner.exe
"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself."
X
VbouncerDL
VBouncerInnerxxxx.exe
"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here and here. ""xxxx"" represents 4 random numbers"
X
VBS.Ipnuker@mm
??
VBS.Nukip Worm!
X
VBS_AUTO_UPDATE
0548656X.vbs
VBS/Gormlez-A Worm!
X
VBundleOuterDL
BundleOuter.EXE
"VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs"
U
VC_Log
keylog.exe
PaqKeylog is a spyware program that logs keystrokes and can run in stealth mode. If you didn't install this yourself remove it.
X
VC5MediaPlayer
csmss.exe
W32/DEDLER-B WORM!
N
VC5Play
VC5Play.exe
Virtual CD drive emulator - version 5. Available via Start -> Programs
X
VCatch
Vcatch.exe
"CommonSearch Vcatch - ""antivirus"" software which actually bundles spy/adware itself!"
X
VCatch Premium
VCatchpre.exe
VCatch antivirus. Considered spyware itself - see here
N
VCDPlayer
VCDPlayer.exe
Virtual CD drive emulator. Available via Start -> Programs
N
vcdplayx
vcdplayx.exe
CD emulation part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically?
U
VCDTower
VCDTower.exe
"Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking"
N
VCSPlayer
vcsplay.exe
Virtual CD drive emulator. Available via Start -> Programs
X
VCXD Settings
phqg.EXE
RBOT.BRF WORM!
X
Vdat Update
lalaa.exe
variant of the WIN32.RBOT WORM!
N
vdtask
vdtask.exe
Program part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically?
N
Vegas Palms - Launcher
Launcher.exe
Vegas Palms on-line cassino
X
veja_fotos.exe
veja_fotos.exe
TROJ/MDROP-F TROJAN!
U
VERBATIM STORE 'N' G
verbatim store 'n' go.exe
Loads the driver for the Verbatim Store'n'Go? PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium
X
Verif
vxst.exe
NOPIR.B WORM!
X
Veritas Patch
veritas.exe
W32/RBOT-XT WORM!
N
Verizon Control Pad
cpad.exe
Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience
U
Verizon Online Support Center
matcli.exe
"""matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file"". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decide"
X
vern16.dll
??
DailyWinner adware
X
vernn16.dll
??
DailyWinner adware
U
versato
versato.exe
"""Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards"
X
version
??
DealHelper adware related
X
version
adl_dh.exe
DealHelper adware related
X
Version
"Version.exe, manage.exe"
JRAUN adware variant
Y
Vet Alert
VETMSG.EXE
Computer Associates Vet Anti-Virus software
Y
Vet Alert
vetmsg9x.exe
"Computer Associates ""InnoculateIT"" and Vet Anti-Virus virus software"
Y
Vet Start Up
vet98.exevet32.exe
"Computer Associates ""InnoculateIT""? and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options"
U
VetTray
vettray.exe
"Computer Associates ""InnoculateIT""? and Vet Anti-Virus virus software. System Tray quicklaunch access, not really necessary but only occupies 36k resources"
X
VFW Encoder/Decoder Settings
??
variant of the LOVGATE WORM!
X
VGA Startup
vgacard.exe
variant of the WIN32.RBOT WORM!
X
VgaDriver
RsrVga32.exe
TROJ/KEYLOG-AH TROJAN!
U
VGAUtil
G-VGA.exe
"Gigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical)"
X
vid32cntl
vid32cntl.Exe
CRYPTER.A trojan infection
X
vidcntl
vidcntl.Exe
CRYPTER.A trojan infection
X
Vidcompat
Vidcompat.exe
GEMA TROJAN!
X
vidctrl
vidctrl.exe
Delfin_Promulgate adware variant
X
Video
explored.exe
GAOBOT.RF WORM!
X
Video
winamp32.exe
W32/AGOBOT-NG WORM!
X
Video Lan Player
VideoLanPlayer.exe
W32/RBOT-MY WORM!
X
Video Manager
videomgr.exe
PANDEM.C VIRUS!
X
Video Multimedia Driver
ndrives32.exe
W32/Rbot-DK worm infection
X
Video Proces
winaps.exe
AGOBOT.HD WORM!
X
Video Process
??
RBOT-LM WORM!
X
Video Process
MS32x16.exe
RBOT.RH worm infection
X
Video Process
MSlti64.exe
AGOBOT.UE WORM!
X
Video Process
netsvcs.exe
AGOBOT.LH WORM!
X
Video Process
sysconf.exe
GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!
X
Video Process
winasp.exe
W32/AGOBOT-IS WORM!
X
Video Services
explore.exe
W32.Gaobot.GL worm infection
X
Video Services
sys32.exe
AGOBOT.PS WORM!
X
Video Services
videol_32.exe
W32/Agobot-DM WORM!
X
Videocntl
Videocntl.exe
variant of the Win32.GEMA.D TROJAN!
X
VideoDriver
??
GSPOT20.A VIRUS!
X
VideoDriver
gspotbot.exe
SPIGOT.C VIRUS!
X
VideoDriver
videodrv.exe
W32.MIMAIL.A WORM!
X
Videool32
VIDEOL32.EXE
AGOBOT.EC WORM!
X
videoporno.exe
videoporno.exe
Premium rate adult content dialer
N
VidSvr
vidsvr.exe
MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
X
vietato.exe
vietato.exe
Adult content dialler
X
VIEW POINT DRIVERS
phqghum.exe
RBOT.BRX WORM!
X
VIEW POINT DRIVERS FOR WIN32
phqghu.exe
variant of the WIN32.RBOT WORM!
N
ViewMgr
ViewMgr.exe
"Viewpoint_Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc). Can be run manually via Start -> Settings -> Control Panel by enabling auto-updates temporarily, re-booting and then disabling again"
X
Virt.exe
Virt.exe
REMADM-C TROJAN!
U
VirtuaGirl
Vg.exe
"VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request..."
U
VirtuaGirl2
VirtuaGirl2
"VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request..."
X
virtual
wini.exe
W32/RBOT-YX WORM!
X
virtual
winit.exe
variant of W32.Mugly.A WORM!
X
virtual
winprotect.exe
W32.MUGLY.C WORM!
U
Virtual Access Scheduler
VASCHD32.EXE
The scheduler for mail and usenet tool
X
Virtual Bouncer
VirtualBouncer.exe
"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here and here"
X
Virtual CDROM
deamon.exe
RBOT.VP WORM!
N
VirtualCloneDrive
VCDDaemon.exe
"Virtual Clone Drive, part of CloneCD CD/DVD copying sofware; discontinued"
N
VirtualDrive
VDTask.exe
VirtualDrive from Farstone - virtual CD drive emulator. Available via Start -> Programs
X
virtual-machine
svchosts.exe
W32/RBOT-US WORM!
X
virtual-machine
wini.exe
W32/RBOT-WR WORM!
X
virtual-machine
winlogin.exe
W32/RBOT-VU WORM!
U
VirtuaReminder
VirtuaReminder.exe
"VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments, birthdays, etc."
U
Virtuele Katja
VKatja.exe
"Virtuele_Katja - have an attractive moviestar parade on your Desktop and help you search the Dutch ""Gouden_Gids"" business directory too..."
X
Virus
Anti.exe
WIN32.SEENBOT.O WORM!
X
Virus Protect
vrsprtc.exe
W32/RBOT-APR WORM!
X
Virus Removal Tool
??
Troj/Tometa-B Trojan!
X
Virus Scan
virscana.exe
VIRUS!
X
Virus_Scanner
Virus_Cleaner.exe
PANOL VIRUS!
X
VirusCheckII
AVIRCHK.EXE
DASMIN VIRUS!
X
VirusScan Online
mcagent.exe
TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
Y
VirusScan Online
mcvsshld.exe
McAfee VirusScan On-line. See also McAgentExe entry
N
visionGS
VISIONGS.EXE
visionGS webcam software
N
Vistascan
vistascan.exe
"Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users, you'll see a scanner icon in the Windows Tray of the Taskbar. Click this icon and a menu opens"
X
Visual Element FX5
??
ClearStream Accelerator adware
X
VisualStudio
msorunner.exe
variant of the WIN32.TACTSLAY TROJAN!
X
VITAL BOOT PROCESS
taskmngr.exe
variant of the WIN32.RBOT WORM!
X
VITAL BOOT PROCESS
taskmnsgr.exe
W32/Rbot-VY WORM!
X
Vital Load Process
Spoolsvr.exe
RBOT.AIF WORM!
X
VividGalut
VividGalut.exe
Adult content related web downloader
X
vmcleaner
gxlib.exe
TROJ/SMALL-HS TROJAN!
Y
VMDFW
vmdfw.exe
VirusMD Personal Firewall
X
Vmmon32
vmmon32.exe
browser hijacker
X
vmsnGraber
VMSNGRABER.EXE
ENVID.B WORM!
X
vmss
vmss.exe
"Delfin_Media_Viewer or ""Promulgate"" adware variant"
X
vmtuner
gclib.exe
Hijacker - detected by Kaspersky antivirus as Trojan-Clicker.Win32.Small.fh
X
VnCplUpdate
msdm.exe
Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisory
X
vnmispoisn_downloader.exe
vnmispoisn_downloader.exe
SearchBarCash adware variant
U
VOBID
InstantDrive.exe
Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer?s hard drive. Part of InstantCD/DVD burning software
Y
VOBRegCheck
VOBRegCheck.exe
Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
X
Voltage Manager
??
W32.DREFFORT WORM!
X
Volume Controller
VolumeControl.exe
SDBOT.AYI WORM!
U
Vonage
click2call.exe
Vonage Voice over IP Internet phone service
U
VoodooBanshee
??
Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not?
N
Vortex Tray
asp4setp.exe
System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
N
VortexTray
??
System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
N
VoyetraTray
vtray.exe
This provides an abbreviated Control Group for the Turtle Beach Montego II sound functions/associated with AudioStation 3 and 32
U
VPCUserServices
VMUSrvc.exe
"Part of ""DOS_Virtual_Machine_Additions"" for Microsoft Virtual_PC , software virtualization software that allows you to run multiple PC-based operating systems simultaneously on one workstation. This process provides additional functionalities such as Shared Folders."
X
VPCUserServices
VMUSrvc.exe
unidentified TROJAN!
U
Vpop3 Mail Server
vpop3.exe
Mail server from Paul Smith Computer Services. Runs in system tray to collect mail. Can be run from a shortcut and if it isn't running then it won't get your email!
U
vptray
vptray.exe
System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here
Y
Vrmon
vrmonnt.exe
HAURI Anti-Virus
Y
Vrmon
vrmonnt.exe
HAURI Anti-Virus
Y
VrSchedule
Vrres.exe
HAURI Anti-Virus
X
vsadmin
smrs.exe
W32/AGOBOT-RC WORM!
X
Vsample
winxpsock.exe
SDBOT.BLK WORM!
N
vsc32cnf
vsc32cnf.exe
"Part of Roland's Virtual_Sound_Canvas software synthesizer gives the ""ability to turn MIDI files into a stereo wave file with the touch of a button"""
X
vscanner
spooll32.exe
OPTIXPRO VIRUS!
N
vscvol
vscvol.exe
"Part of Roland's Virtual_Sound_Canvas software synthesizer gives the ""ability to turn MIDI files into a stereo wave file with the touch of a button"""
N
VsEcomrEXE
VSECOMR.EXE
"From McAfee VirusScan up to version 4.x. This executable is responsible for the periodic ""update"" prompts"
Y
Vshwin32EXE
VSHWIN32.EXE
From McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
N
VSN
VSN.exe
Software to share photographs across the internet
X
VSOCheckTask
mcagent.exe
TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
Y
VSOCheckTask
MCMNHDLR.EXE
Part of McAfee's SecurityCenter and Virusscan Online. Must be enabled for scanning to work
N
vspdfprsrv.exe
vspdfprsrv.exe
Visage PDF Printer
Y
VsStatEXE
VSSTAT.EXE
From McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
N
vTPass
vtpassld.exe
"Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs, create your own shortcut for the ""vtpass.exe"" file"
U
VTPreset
VTPreset.exe
Savage Pro S3 graphics software
U
vTTIMER
VTTIMER.EXE
A device driver for VIA/S3G UniChrome IGP graphics controller and VIA/S3G KM400/KN400 graphics card. It is located in \WINDOWS\SYSTEM\ on Windows 95/98/ME and \WINDOWS\SYSTEM32\ on Windows XP and \WINNT\SYSTEM32\ on Windows NT/2000 Viaarena
N
vTunerStartUp
vTuner.exe
"vTuner - ""an easy way to find and listen to radio and TV broadcasts over the Internet"""
X
vuaaa
reg.exe
variant of the WIN32.RBOT WORM!
X
VVSN
VVSN.exe
SaveNow adware
X
W1NTASK
taskgmr.exe
W32/MYTOB-BZ WORM!
X
w32
w32.exe
SOKEVEN VIRUS!
X
W32.Scran
Scran.exe
W32.Narcs WORM!
X
w32alanis
mope.scr
SINALA VIRUS!
X
W32data
eworo.exe
variant of the WIN32.RBOT WORM!
X
W32Load
??
CASPID VIRUS!
X
w32sup
w32sup.exe
Adult content dialler
X
W32Tc
WTC32.scr
VOTE.D or VOTE.K VIRUSES!
X
W3KNetwork
??
Advertising spyware. Check here for more info on this particular one
Y
W75P2PSERVER
W75P2PS.EXE
Printer utility which is required in order to make the printer work correctly
U
wait4IP
wait4IP.exe
Packard Bell net2Plug allows you to network PCs anywhere in your house
U
wallchgr.exe wstart
Wallchgr.exe
Blue Tree Software
N
Wanadoo Messenger.exe
Wanadoo Messenger.exe
Wanadoo ISP instant messenger client
Y
WanMPSvc
WanMPSvc.exe
"An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn?t help"
X
WAPI
??
PurityScan/Clickspring adware
X
Wardo
syslaunch.exe
ADLCICKER.G VIRUS!
X
WareOut
WareOut.exe
"Malware masquerading as a spyware and dialer remover, see here"
N
warez
warez.exe
Warez P2P client
N
war-ftpd.exe
WAR-FTPD.EXE
War FTP Daemon from JGAA's Internet - FTP client
U
Warner
warner.exe
"Also known as ""CyberWarner"". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files"
U
Warnet
warnet.exe
Warnet - system cleanup software
U
Warning: do not remove it!
fpplock.exe
"Part of Folder Password Expert by ZQS Software Team - ""a software program to restrict access to the folders that contain your sensitive data"""
N
WARSVR
war-ftpd.exe
"""War FTP Daemon - the original free FTP server for windows"""
U
WashAndGo - Cleanup of old Backupfiles
checker.exe
WashAndGo - temp file cleaner
N
Washer
washer.exe
"Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG"
N
Washerie.exe
washerie.exe
"Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs"
U
washindex
washidx.exe
"Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG"
X
Wast
wast.exe
Grokster ads updater
X
wast
wast2.exe
Grokster ads updater
N
Watch
watch.exe
Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
N
Watch Dog Program
watchdog.exe
For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
N
Watchdog
Watchdog.exe
"Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage"
N
WaveTop Launcher
WaveTop.exe
"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
N
WaveTop Receiver 1
??
"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
N
WaveTop Receiver 2
??
"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
N
WaveTop Upload Manager
??
"WaveTop - ""Get push content from TV without an Internet connection"" - now possibly a defunct system in the US included as an optional part of WebTV in Win98"
N
Wbiff
Wbiff.exe
Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
N
WCESCOMM
WCESCOMM.EXE
Active sync for use with Windows CE based palm PC
X
WCESMngr
spoolsb.exe
W32/AGOBOT-QZ WORM!
X
WCESMngr
WCEMNGR.EXE
W32/AGOBOT-QX WORM!
U
wcmdmgr
wcmdmgrl.exe
Checks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information
N
wcmdmgr.exe
wcmdmgr.exe
"It will periodically contact Wild Tangent servers to see if an update is available for your system and allows us to make the product exceptionally reliable. You can control its behavior, or disable it completely, inside your Windows Control Panel. Note that Wild Tanget's privacy policy used to stae they also collect and share individuals information, but this is no longer the case"
U
WCOLOREAL
coloreal.exe
"Makes colours sharper and brighter, but will only work with coloreal capable monitors"
X
WCPC
wintsvcc.exe
PurityScan/Clickspring adware
X
WCPI
wintsvit.exe
PurityScan/Clickspring adware
X
WCPS
??
PurityScan/Clickspring adware
X
WCPT
wintsvtr.exe
PurityScan/Clickspring adware
U
WD Button Manager
WDBtnMgr.exe
Button manager installed with a western digital external disk drive. Allows you to back up your system with one click.
X
WDInfo
wdinfo.exe
DOWNLOADER.DLUCA.B TROJAN!
X
WDNS SYSTEM
nibie.exe
W32/Mytob-BY WORM!
X
WDNS SYSTEM
skybotx.exe
W32/Mytob-BY WORM!
X
WDNS SYSTEM
wdns33.exe
MYTOB.EV and W32/Mytob-BY WORMS!
X
wdskctl
??
Waltun-A trojan infection
X
wdskctl
wdskctl.exe
IePlugin adware
X
wdwctrl
wdwctrl.exe
Troj/Dload-DC TROJAN!
N
WEATHER
WEATHER.EXE
"Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs"
N
WeatherCast
Weather.exe
Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
X
WeatherOnTray
WeatherOnTray.exe
Hotbar' s Weather Forecast tool for your desktop
X
Weatherscope
Weatherscope.exe
WeatherScope software - bundles Gain/Gator adware
N
WeatherWatcher
ww.exe
WeatherWatcher - weather reporting in the System Tray
X
web
??
variant of the Win32/TrojanDownloader.Easto.A TROJAN!
"Web_Army_Knife , a suite of web site developer's tools."
X
webassist
webassist.exe
Adware popup generator
N
WebcamRT.exe
WEBCAMRT.exe
For Logitech Web Cams. Not required - camera works fine without it
X
Webcelerator
webcel.exe
Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here
X
WebCheck
WebCheck.pif
CONE.C or CONE.F VIRUSES!
X
WebCpr0
WebCpr0.exe
Web_CPR/TopMoxie adware
X
Webdav.exe
webdav.exe
IRC DDoS bot which gives the hacker full control over your system
X
WebHancer Agent
whagent.exe
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
X
webHancer Survey Companion
whSurvey.exe
"WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there"
X
"WebInstall, WebInstall2"
WebInstall.exe
ClipGenie adware downloader
N
WebKey
WebKey.exe
WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
N
WebLink
WebLink.exe
"Softex WebLink is a ""cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a a persistent link."""
N
WebOutfitterTray
sttray.exe
Intel WebOutfitter service System Tray icon
N
Webposition Gold 2
wpsche~1.exe
Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
X
WebRebates0
WebRebates0.exe
WebRebates adware
X
WebRun
??
ADWARELOADER TROJAN!
X
WebRun
msxmidi.exe
ADWARELOADER TROJAN!
X
WebRun
sm.exe
ADWARELOADER TROJAN!
X
WebRun
web.exe
Adwareloader TROJAN!
X
WebRun
wmplayer.exe
ADWARELOADER TROJAN!
U
websaverlive
websaverlive.exe
WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
X
WebSavingsfromEbates
WebSavingsfromEbatesrun.exe
"""Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows"
X
WebSavingsFromEbates0
WebSavingsFromEbates0.exe
"""Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows"
N
WebScan
DEFSCANGUI.EXE
eAcceleration Stop-Sign related; not recommended; see note
N
webscan
stopsignav.exe
eAcceleration Stop-Sign related; not recommended; see note
Y
WebScanX
WebScanX.exe
"From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc"
X
websearch
??
"""Web Savings"" From Ebates Software, a shopping tool that opens pop-up windows"
X
WebSecureAlert
WebSecureAlert.exe
"WebSecureAlert. ""Can help protect your browser security and privacy""; however, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior"
"Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web."
U
Webshots
websho~1.exe
"Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web."
U
Webshots
Webshots Tray.exe
"Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web."
X
Website Administrator Info
webadmin.exe
W32/FORBOT-FY WORM!
X
WebSpecials
??
WebSpecials adware downloader
X
Websx
??
Adult content dialler - where ***** are random
Y
Webtrap
webtrap.exe
Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
Y
WebTrapNT.exe
WebTrapNT.exe
Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
U
WebWasher
wwasher.exe
Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
X
WeirdOnTheWeb
WeirdOnTheWeb.exe
Adware.WeirdOnTheWeb ADWARE!
N
Welcome
Welcome.exe
Launches the Welcome to Windows tutorial on boot up
X
wersds
doriot.exe
JECT.C VIRUS!
X
wesumu
wiustv.exe
Troj/QQPass-L TROJAN!
N
WetSock
wetsock.exe
RoboMagic Wetsock - weather reporting in the System Tray
N
WFGStartup
WFGStartup.exe
"World Weather. ""This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"""
U
wfips
iphider.exe
"ICQ (messaging/chat program) anti-bomb software. ""WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed."" For more information about ICQ bombs see here"
N
WFXCTL32.EXE
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Y
wfxsnt40
wfxsnt40.exe
WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
Y
WG511WLU
WG511WLU.exe
Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
U
WGWLocalManager
WGWLocalManager.exe
"Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system"
X
whagent
whagent.exe
System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
U
WhatPulse
WHATPU~1.EXE
"WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day."
U
WheelMouse
4DMAIN.EXE
"Mouse software for ""Fellowes"" Wheelman mouse. Has caused some users problems but shouldn\'t be needed if you don\'t use any enhanced features it may provide"
U
WheelMouse
AMOUMAIN.EXE
A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features
X
WhenUSave
Save.exe
SaveNow adware
X
WhenUSearch
Search.exe
SaveNow adware
X
WhenUSearchWHSE
whse.exe
SaveNow adware
X
Whistler
whismng.exe
WHISTLER-F TROJAN!
X
Whitechix
brightx.exe
variant of the W32/SDBOT WORM!
X
Whvlxd
Whvlxd.exe
W32.LXD.Mirc VIRUS!
N
WIAWizardMenu
??
Still Image Class Installer - installed with a webcam
X
Widnows Xp Web scan
xpscan.exe
variant of the W32/SDBOT WORM!
X
wifeman
wifeman.exe
Unidentified malware
N
WildTangent CDA
??
WildTangent on-line games related; not required for the games to work.
U
WildTangent Web Driver updater
wcmdmgrl.exe
Checks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information
N
Wildwire Monitor
WWMon.exe
This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
N
Willow Road
WillowRoad.exe
Willow Road Screen Saver
X
win
??
SEEKER.K VIRUS!
X
WIN
ehshell.exe
W32/Mytob-CQ Worm\Trojan!
X
WIN
windows.exe
W32.Reatle.C WORM!
X
win
xwinxrpc.exe
AGOBOT-MV WORM!
X
win
xwinxrpc32.exe
W32/Agobot-MV WORM!
U
Win Chimes
winchi~1.exe
WinChimes - enhancement software for the system clock that runs in the system tray
X
Win Comm
WinComm.exe
WebRebates related adware
X
Win Command
command32.exe
AGOBOT.XQ WORM!
X
win ctl app
wuctl.exe
variant of the W32/SDBOT WORM!
X
Win Drivers SSL
hpws.exe
WIN32/IRCBOT.67098 WORM!
X
Win Drivers SSL
TASKMAN4.exe
variant of the WIN32.RBOT WORM!
X
WIN HOST PROCESS
WIN HOST PROCESS.EXE
KEYLOGGER.CLONE VIRUS!
X
Win l5oahder
winampa.exe
variant of the AGOBOT/GAOBOT WORM!
X
Win Microsoft 98
win14.exe
W32/RBOT-AKX WORM!
X
Win Microsoft Config
wnmsconfig.exe
variant of the WIN32.RBOT WORM!
X
Win Patch
ntldr.exe
W32/SDBOT-GS WORM!
X
Win Secure Update
??
W32/Rbot-AGI WORM!
X
Win Server
winserv.exe
IMISERV.A TROJAN!
X
Win Server Updt
pxckdla.exe
IEPlugin adware component
X
Win Server Updt
winserver.exe
variant of the WIN32.IMISERV TROJAN!
X
Win Server Updt
wupdt.exe
IEPlugin adware
X
Win TaskLoader
msgmr.exe
W32.MYTOB.L WORM!
X
win update
wapdate.exe
variant of the WIN32.RBOT WORM!
X
win update
wupda32.exe
SDBOT.J worm infection
X
Win Updater
WINUPDATER.EXE
RBOT.IP WORM!
X
Win Updator Services
ctfnom.exe
variant of the W32/WOOTBOT WORM!
X
WIN USB 2.0
usbsystem.exe
unidentified WORM of TROJAN!
X
WIN USB 2.0
winusb.exe
variant of the WIN32.RBOT WORM!
X
Win USB 2.0 USB Driver
HPPrint.exe
SPYBOT.DNB WORM!
X
WIN USB SUPPORT
grxsrv.exe
variant of the WIN32.RBOT WORM!
X
Win WinAmp
winamp.exe
RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
X
Win_api_driver
system.exe
REVIRD VIRUS!
X
Win_Library
INISvc.exe
ANARCH VIRUS!
X
win_spool2
win_spool2.exe
TROJ_SCKEYLOG.B TROJAN!
X
win_upd.exe
WINdirect.exe
MITGLIEDER.M VIRUS!
X
win_upd2.exe
WINdirect.exe
BEAGLE.AO WORM!
X
Win_vader
Win_vader.vbs
INVASION.A VIRUS!
U
win16.dll
win16dll.exe
"Screenspy captures screenshots silently. If you didn't install this yourself, remove it."
X
Win2Drv
??
WINTOO VIRUS!
X
Win32
arsetup.exe
WIN32.SPAZBOX.A TROJAN!
X
Win32
Game.exe.vbs
VBS.Scafene WORM!
X
win32
Setup_32.exeWinSetup.exe
EVILBOT.B VIRUS!
X
win32
Shakira_1997_Part_1_.Mpeg_.scr
MYLIFE.N VIRUS!
X
Win32
system32.vbs
VBS.SWERUN VIRUS!
X
WIN32
WIN32.EXE
WIN32/MYTOB.AD WORM!
X
Win32
Win32.exe
ISRAZ.A VIRUS!
X
win32
winhost.exe
W32.BROPIA.J WORM!
X
win32
winsrv32.exe
ADUENT VIRUS! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
X
Win32 Bios
Winbios.exe
W32/SEMAPI-A WORM!
X
Win32 Configuration
dllhelp.exe
SDBOT.UL infection
X
Win32 Configuration
mplayer.exe
W32/FORBOT-BZ WORM!
X
Win32 Configuration
videosd32.exe
WORM_SDBOT.TT
X
WIN32 DDOSSER
dos.exe
W32.Kelvir.F WORM!
X
Win32 Debug Manager
Win32Debug.exe
variant of the W32/WOOTBOT WORM!
X
Win32 Device Loader
Win32ldr.exe
variant of the GAOBOT/AGOBOT WORM!
X
Win32 Driver
svchosts.exe
W32/Forbot-FD WORM!
X
Win32 Drivers
winlogons.exe
W32/Forbot-FG WORM!
X
Win32 DRK Driver
wdrk32.exe
WOOTBOT.CY WORM!
X
Win32 exe file
winstr32.exe
W32.SpyBot worm variant
X
Win32 Explorer
Explorer32.exe
StartPa-MN homepage hijacker
X
Win32 Firewall Driver
winfw.exe
variant of the WIN32.RBOT WORM!
X
Win32 FRT Driver
msfr32.exe
variant of the W32/FORBOT WORM!
X
win32 internet server
winserver.exe
TROJ/DERMON-D WORM!
X
Win32 Kernel core component
Kernel32.pif
MOKS VIRUS!
X
Win32 LSA Driver
lsa.exe
W32/Forbot-FJ WORM!
X
Win32 Ms Auto Updater
AutomsUPD.exe
Win32.Rbot worm variant
X
Win32 NDIS Driver
xpndis.exe
variant of the WIN32.RBOT WORM!
X
Win32 Network Driver
crss.exe
variant of the AGOBOT/GAOBOT WORM!
X
Win32 NT Adv Services
taskmngr.exe
W32/Rbot-ADE WORM!
X
Win32 nvc
nvcva.exe
W32/RBOT-ABF WORM!
X
Win32 NVIDIA Driver
MSPMSPSU.EXE
variant of the WOOTBOT.Y WORM!
X
win32 regedit
msn32.exe
unidentified WORM or TROJAN!
X
Win32 Rundll Loader
Rundll32.exe
"SDBOT.A WORM! Note: Rundll32.exe is a valid Windows application called ""Run a DLL as an App"" and stored in the C:\Windows directory. The version created by this virus is saved in the C:\Windows\System directory"
X
Win32 Secure
msconfigsvc.exe
variant of the W32/SDBOT WORM!
X
Win32 Service
bazzi.exe
AHKER.E WORM!
X
Win32 Services Config
winwkys.exe
RBOT.BKY WORM!
X
Win32 Services1
wuamngr1.exe
W32/Sdbot-PV worm infection
X
Win32 Src Service
win32src.exe
W32/RBOT-SX WORM!
X
Win32 SSL Driver
winssv.exe
W32/FORBOT-BH WORM!
X
Win32 Svchosts Driver
svchosts.exe
W32/Forbot-FO WORM! Note: (svchosts.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
win32 system server
winserver.exe
TROJ/DERMON-C TROJAN!
X
Win32 System Spool
spoolsvc.exe
WORM_SDBOT.UK
X
Win32 Test
bleatest.exe
variant of the WIN32.RBOT WORM!
X
Win32 Usb Driver
AvpG.exe
W32/FORBOT-BX WORM!
X
Win32 USB Driver
mvsecn.exe
W32/FORBOT-BK WORM!
X
Win32 Usb Driver
svhosint32.exe
W32/FORBOT-BE WORM!
X
Win32 Usb Driver
usb32.exe
W32/SDBOT-OV WORM!
X
Win32 USB Driver
winxpinit.exe
SDBOT.AA WORM!
X
Win32 USB Driver
winxpinit.exe
BACKDOOR.SDBOT.AA TROJAN!
X
Win32 USB2
wins32.exe
variant of the WIN32.RBOT WORM!
X
Win32 USB2 Driver
msn.exe
W32/FORBOT-EX WORM!
X
Win32 USB2 Driver
smsc.exe
SDBOT.FO WORM!
X
Win32 USB2 Driver
svchosting.exe
W32/Forbot.J or SDBOT.HU worm infection
X
Win32 USB2 Driver
sys32.exe
WORM_WOOTBOT.X
X
Win32 USB2 Driver
sys32snd.exe
W32/Forbot-AN worm infection
X
Win32 USB2 Driver
syscfg32.exe
W32/FORBOT-R WORM!
X
Win32 USB2 Driver
updatemgr.exe
variant of the W32/FORBOT WORM!
X
Win32 USB2 Driver
win32usb.exe
W32.Spybot.DHV worm
X
Win32 USB2 Driver
wind32.exe
W32/Forbot-AH worm
X
Win32 USB2 Driver
winsnd32.exe
variant of the W32/SDBOT WORM!
X
Win32 USB2 Driver
winupdate.exe
AGOBOT.YE WORM!
X
Win32 USB2.0 Driver
386.exe
W32.IRCBot.D worm
X
Win32 USB2.0 Driver
rundll16.exe
WORM_WOOTBOT.H
X
Win32 USB2.0 Driver
service.exe
W32/SDBOT-QF WORM!
X
Win32 USB2.0 Driver
w32usb2.exe
WORM_SPYBOT.DN
X
Win32 USB3 Driver
win32tool.exe
variant of the WIN32.RBOT WORM!
X
Win32 Wmls Driver
winitr32.exe
WOOTBOT.B worm
X
Win32 Word Services
msword32.exe
variant of the WIN32.RBOT WORM!
X
win32.exe
win32.exe
STARTPAGE VIRUS!
X
Win32.exe
Win32.exe
BKDR_AWQ.A TROJAN!
X
win32_i lptt01 or win32_i ml097e
win32_i.exe
"Variant of the RapidBlaster parasite (in a ""win32_i"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
win32app
winpup32.exe
ADCLICKER VIRUS!
X
Win32BaseServiceMOD
Wintask.exe
NAVIDAD VIRUS!
X
win32beta
win32sys4.exe
Troj/Banker-DA Trojan!
X
win32clf
win32clf.exe
unidentified VIRUS!
X
Win32dll
Win32dll.exe
BANPAES VIRUS!
X
Win32DLL
Win32DLL.vbs
LOVELETTER (I LOVE YOU) VIRUS!
X
WIN32DS
clienttimer.exe
Eziin adware
X
Win32G
Kernel32.comScandisk.com
ESTRELLA VIRUS!
X
win32gb
win32gb.exe
All-In-One-Telcom (adult content dialler) variant
X
Win32Host Process
webemir.exe
Troj/Turgen-A TROJAN!
X
win32info
win32info.exe
Win32.Dluca.C downloader trojan infection
X
win32ini
systroy.exe
IRC.ALADINZ.C VIRUS!
X
WIN32io
clienttimer.exe
Eziin adware
X
Win32R
Server.com
ESTRELLA VIRUS!
X
WIn32S Java DLL
kavsvx.exe
W32/AGOBOT-RZ WORM!
X
win32servv
load.exe
unidentified trojan or adware
X
win32servv
ms1.exe
iSearch adware component
Y
WIN32SL
Win32sl.exe
"Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work"
X
WIN32SNDS
banc.exe
unidentified WORM or TROJAN!
X
Win32system
??
DDV.B VIRUS!
X
Win32System
win32s.exe
W32.Mydoom.V WORM!
X
Win32SystemMonitor
??
browser hijacker
X
Win32SysV
xin.exe
W32/FORBOT-EO WORM!
X
win32us
win32us.exe
All-In-One-Telcom (adult content dialler) variant
X
win32usbd
ssrs.exe
W32/RBOT-RA WORM!
X
WIN32WN
system_wc.exe
Eziin adware
X
Win386
sp32.dll
Homepage hijacker. Not a dll but a regfile in disguise
X
Win386
Win386.exe
GOSUSUB VIRUS!
X
WIN3S2SNDS
winabsmod.exe
"TrojanDownloader.Win32.Agent.dn infection; known to BOClean as ""CWS/INDEX"" , ""shuts down anything that wants to open and is used as a spam proxy as well"""
X
Win64 Compatibility Check
load win64.drv
CoolWebSearch parasite related.
X
WIN95DEFVIEW
csmss.exe
TROJ/DEDLER-D TROJAN!
X
win98 DNS
wingrd.exe
variant of the WIN32.RBOT WORM!
X
WinAC v4
klsuicbn.exe
W32/FORBOT-CS WORM!
U
Winacsr
Winacsr.exe
AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
X
winactive
WINACTIVE.EXE
Active variant of LOP.com hijacker - see here
X
WinActiveJ
WinActiveJ.exe
ROTARRAN VIRUS!
X
Winad Client
Winad.exe
WinAd adware by eXact Advertising
X
WinAdCnt.exe
WinAdCnt.exe
TROJ/BANKER-BU TROJAN!
X
winadm
winadm.exe
Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
X
Winahlp.exe
Winahlp.exe
variant of the VAGRNOCKER VIRUS!
X
winallap
winallap.exe
DELF.E VIRUS!
X
winallapu
winallapu.exe
DELF.E VIRUS!
X
winamp
winamp.exe
AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe)
X
Winamp
winamp.hta
re-directing to adult content sites. Note - this isn't the real Winamp
X
WinAMP
winamp62.exe
W32/SDBOT-WN WORM!
X
Winamp Agent
winamp.exe
W32/POEBOT-I WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
X
Winamp media player
winapa.exe
Unidentified worm
U
Winamp to Google Talk
winamptogoogletalk.exe
"Winamp to Google Talk, available here shows your current Winamp track in your Google_Talk status"
X
Winamp Update
yhn.exe
W32/Sdbot-ACR WORM!
U
Winampa
WINAMPa.exe
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
X
Winampa
winampa.exe
W32/AGOBOT-GS WORM!
X
Winampa Agent
WINAMPA.EXE
"W32/SPYBOT-BR WORM! - NOTE: this is NOT the Winamp Media Player, as described here"
X
WinAmpAgent
Msexploren.exe
"TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here"
X
WinAmpAgent
Shch.exe
"TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here"
X
WinAmpAgent
svchst.exe
"TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here"
X
WinAmpAgent
Winagent.exe
"TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here"
X
WinAmpAgent
winagent.exe
WIN32.TACTSLAY.B TROJAN!
U
WinampAgent
WINAMPa.exe
Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
X
WinAntiSpyware 2005
was5.exe
"WinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for ""WinAntiSpyware 2005"""
X
WinApi
winapix.exe
variant of the TIBSER.A downloader TROJAN!
X
WINAPLOGUPD
WINAPLOGUPD.EXE
W32/CAPSIDE-C WORM!
X
Winapp
winpup32.exe
Produces popup ads to adult content sites
X
WinApp32
msapp.exe
RSBOT VIRUS!
U
WinAppLog
svchost.exe
"StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\StingWare folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
WinAuth
winlogon.exe
"Hijacker, also indentified as the STRTPAGE.BE TROJAN!"
X
WinAwk
WinAwk.exe
2/SDBOT-AYF WORM!
U
WinBackup Scheduler
Wbsched.exe
LIUtilities WinBackup scheduler - backup software
U
WinBar
WinBar.exe
"""WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"""
X
winbas12
winbas12.exe
"Adware, CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
winbas12
winbas12.exe
"Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du"
X
Winbed
winbed.exe
Hijacker
X
winbin32
win32exe.exe
W32/RBOT-ZL WORM!
X
winbot
winbot.exe
Troj/Midrug-A TROJAN!
X
WIN-BUGSFIX
WIN-BUGSFIX.EXE
LOVELETTER (I LOVE YOU) VIRUS!
X
WinCheck
WinCheck.exe
PWS-CY VIRUS!
X
winchost
winchost.exe
Troj/Dloader-PV TROJAN!
N
WINCINEMAMGR
WINCIN~1.EXE
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
N
WINCINEMAMGR
WinCinemaMgr.exe
WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
X
wincmap
wincmapp.exe
CasClient adware variant - also known as Trojan.Cmapp
X
wincms
wincms.exe
"RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry ""Run"" key in order to force Windows to launch it at boot. Name field may be empty."
X
WinCSRSS
MSGRT32.EXE
Troj/Rewindo-A TROJAN!
X
WINCX
wincore332.exe
W32/AGOBOT-MG WORM!
X
Wind Logd File
servicelogd.exe
variant of the WIN32.RBOT WORM!
X
wind.exe
wind.exe
"This Trojan allows the infected computer to be used as a proxy mail server. Trojan horse Proxy.5.AP, TrojanProxy.Win32.Mitglieder.bd More info on TrojanProxy"
X
WIND0WS
mella.bat
VBS.ALLEM WORM!
X
WIND0WS
WIND0WS.exe
WORM_SPYBOT.DQ
X
Wind0ws Sharing
ssprotecter.exe
W32/RBOT-AHW WORM!
N
WinDates
windates.exe
"WinDates is a calendar, date organizer and event reminder program from Rockin\' Software"
"STARR key logger. ""It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren\'t keyed in, all web sites visited, every program launched including the path to that program, and more"""
X
Windll.exe
Windll.exe
STEALER VIRUS!
X
WinDll32
_WIN32.EXE
LEGMIR.AQ TROJAN!
X
Windll32
Windll32.exe
MSNPWS VIRUS!
X
windllsys32.exe
windllsys32.exe
variant of the Win32.Mitglieder.by TROJAN!
X
WinDNS
windns32.exe
GAOBOT.WX WORM!
X
Windoes Kernel
kernel32.exe
KICKIN.A (or CYDOG.C) VIRUS!
X
Window
explore.exe
GAOBOT.ADW WORM!
X
Window Loader
Dos32.exe
GAOBOT.AO WORM!
X
Window Monitor
winmon32.exe
SDBOT.RT worm infection
X
Window service
??
W32/RBOT-ACH WORM!
U
Window Washer
wwDisp.exe
"Webroot Window Washer - ""Wash away online and offline traces of PC and Internet activity to protect your privacy and improve PC performance"""
X
window.exe
window.exe
MITGLIEDER.H or MITGLIEDER.J VIRUS!
X
Window_Protect
winsi32.exe
variant of the WIN32.RBOT WORM!
X
window2
ssvchost.exe
IRCBOT.H VIRUS!
U
WindowBlinds
wbload.exe
WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
X
WindowEnhancer
Winex.exe
SCbar foistware variant
U
WindowFX
wfxload.exe
"Stardock WindowFX - ""Allows you to add an unprecedented number of special effects to windows"""
X
windown
wiusyt.exe
Troj/QQPass-M TROJAN!
X
WindowRegKey update
wins.exe
SPYBOT.I WORM!
X
windows
??
AIMWIN VIRUS!
X
Windows
explorer.exe
unidentified VIRUS! Note - this is not the valid Windows Explorer (explorer.exe). It was found in the C:\Windows directory on a WinNT machine and the wheras the valid explorer.exe would be found in C:\Winnt
X
Windows
gearsec.exe
W32/STUBBOT-B TROJAN!
X
windows
hkey.exe
GAOBOT.AFW WORM!
X
Windows
Kernel32.exe
TENDOOLF VIRUS!
X
Windows
msdos98.exe
PWSTEAL VIRUS!
X
Windows
run.exe
W32.SPYBOT.OFN WORM!
X
Windows
services.exe
"Unidentified worm or trojan. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!"
X
windows
system copy.exe
W23.SALGA.A WORM!
X
Windows
system.exe
W32.Spybot.OBB WORM!
X
WINDOWS
windows.exe
Troj/Monbot-A TROJAN!
X
Windows
Windows.exe
"KAZMOR, BOBBINS& ALADINZ.D VIRUSES!"
X
Windows .Net Manager
localsvc.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
netsvc.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
svcman.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
svcrun.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Windows .Net Manager
websvc.exe
Troj/Dloader-NY Trojan!
X
Windows 128 Module
win128.exe
W32/FORBOT-ES WORM!
X
Windows 2004
CSRSS.exe
Troj/Banker-DY trojan infection
X
Windows 32 Editor
Win32edit.exe
WOOTBOT.GQ WORM!
X
Windows 32 Rescue
win32resc.exe
W32/FORBOT-EU WORM!
X
Windows 32 Update
Windows-Update.exe
variant of the WIN32.RBOT WORM!
U
Windows Accelerators
setup.exe
"KeySpy keylogger (monitoring program). Given a ""U"" recommendation because it depends if you intentionally installed it. If you didn't treat it as ""X"" and uninstall or remove"
X
Windows AdControl
WinAdCtl.exe
WindUpdates adware variant
X
Windows AdService
WinAdServ.exe
WindUpdates WinAdServ adware variant
X
Windows AdStatus
WinStat.exe
W32.Bleshare!dr VIRUS!
X
Windows AdTools
WinAdTools.exe
WindUpdates Windows_AdTools adware
X
Windows Anti-Virus Built 32
AntiVirus32.exe
SDBOT-BG WORM!
X
Windows API Control Task
apitsk32.exe
W32.MYTOB.HI WORM!
X
Windows Application Layer
walg32.exe
AGOBOT.ATN WORM!
X
Windows Application Layer Gateway
walg32.exe
W32/AGOBOT-AAZ WORM!
X
Windows ASN Service
??
W32/AGOBOT-TC WORM!
X
Windows auto update
bazzi.exe
AHKER.E WORM!
X
Windows auto update
LSASS.exe
"W32.AHKER.G WORM! - Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!"
X
windows auto update
msblast.exe
BLASTER.B VIRUS!
X
windows auto update
penis32.exe
BLASTER (or MSBLAST.A) VIRUS!
X
Windows Auto Update
winupdater.exe
SDBOT.TF WORM!
X
Windows Automatic Update
wuamgrder.exe
variant of the WIN32.RBOT WORM!
X
Windows Automatic Updates
dvldr.exe
RBOT.MF WORM!
X
Windows AutomaticUpdater
runddls.exe
variant of the WIN32.RBOT WORM!
X
Windows Automation
msdspr.exe
SOLAME.A VIRUS!
X
windows automation
mslaugh.exe
BLASTER.E VIRUS!
X
Windows Autostart Loader
notepad32.exe
variant of the WIN32.RBOT WORM!
X
Windows Ba?lang?? Dosyas?
sistem.exe
MUZK VIRUS!
X
Windows backup
systemss.exe
W32.SpyBot worm variant
X
Windows Backup Configuration
IEXPLORER.exe
GAOBOT.AZ WORM!. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
X
Windows Bootup
ms-wks32.exe
W32/Rbot-AFM Worm!
X
Windows Bootup
Systemwks32.exe
variant of the WIN32.RBOT WORM!
X
Windows Client Service 32
csrss.exe
W32/Rbot-ALB WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
Windows Client/Server Runtime Server
csrs.exe
RBOT.KD WORM!
X
Windows Command
wincmd.exe
RBOT.ANV WORM!
X
Windows Communicator
wincomm.exe
AGOBOT-BH WORM!
X
Windows Compliant
??
W32/Rbot-IR worm infection
X
Windows Compliant
winole.exe
variant of the W32/SDBOT WORM!
X
Windows Config
SSYS.EXE
W32/Spybot-DA worm infection
X
Windows Config
wins.exe
SPYBOT.JR WORM!
X
Windows Config Loader
Wincfg32.exe
SILVERFTP VIRUS!
X
Windows Config Manager
winconf.exe
W32/RBOT-AIT WORM!
X
Windows Configuration
wincfg32.exe
W32.Mytob.ED WORM!
X
Windows Configuration
wsys32.exe
GAOBOT.FB WORM!
X
Windows Console Monitor
??
W32.Kedebe WORM!
X
Windows Console Monitor
gcasAV32.exe
W32/KEDEBE-A WORM!
X
Windows Control
Control.exe
"Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!"
X
Windows ControlAd
WinCtlAd.exe
WindUpdates WinCtrlAd adware
X
Windows CPU host
winbog32.exe
variant of the WIN32.RBOT WORM!
X
Windows Data Server
??
W32/Spybot-DS WORM!
X
Windows Data Server
autodisc.exe
W32/SPYBOT-CB WORM!
X
Windows Database
wiinsvc.exe
W32/AGOBOT-RU WORM!
X
Windows Database
WinDat.exe
unidentified WORM or TROJAN!
X
Windows Dcom2 Fix
mscom32.exe
W32/RBOT-QT WORM!
X
Windows DDE Loader
windde32.exe
W32/SDBOT-UZ WORM!
X
Windows debug logging
winlogg.exe
W32/RBOT-OY WORM!
X
Windows debug logging
winloggs.exe
W32/RBOT-QN WORM!
X
Windows Debugger
msdbg32.exe
variant of the WIN32.RBOT WORM!
X
Windows Debugger
windbg.exe
unknown worm or trojan infection!
X
Windows Debugger
windbg32.exe
W32.Zotob.L WORM!
X
WINDOWS DENEME
deneme.exe
W32/Mytob-CR WORM!
X
Windows Desktop Controler
windesktop.exe
W32/SDBOT-XH WORM!
X
Windows Desktop Daemon
winpadg.exe
variant of the W32.SPYBOT WORM!
X
Windows Dialup Service
dialup.exe
AGOBOT.AAH WORM!
X
Windows DLL Host
dllhost32.exe
unidentified WORM or TROJAN!
X
Windows DLL host
winupd32.exe
variant of the W32.SPYBOT WORM!
X
Windows DLL Loader
defragfat32.exe
W32/SDBOT-SS WORM!
X
Windows DLL Loader
defragfat32abc.exe
W32/RBOT-RG WORM!
X
Windows DLL Loader
defragfat32pi.exe
W32/RBOT-QQ WORM!
X
Windows DLL Loader
defragfat32z.exe
W32/EGGDROP-G WORM!
X
Windows DLL Loader
defragfat39.exe
W32/POEBOT-C WORM!
X
Windows DLL Loader
defragfatx.exe
W32/POEBOT-F WORM!
X
Windows DLL Loader
defragfatz.exe
W32.LINKBOT.H WORM!
X
Windows DLL Loader
PASSCFG16.EXE
W32/Domwis-C IRC backdoor worm infection
X
Windows DLL Loader
"RUNDLL16.EXE, SYSCFG16.EXE"
DOMWIS VIRUS!
X
Windows DLL Loader
rundll32.exe
"W32/WHIPSER-B WORM! - NOTE: This particular rundll32.exe file is placed in the Windows\System folder, wheras the legitimate Windows file of the same name is located in the Windows folder on Win 98 or ME systems, and in Winnt\System32 or Windows\System32 in Windows 2000 or XP"
X
Windows DLL Loader
SYSCFG16.EXE
W32/Domwis-N WORM!
X
Windows DLL Loader
wdevice.exe
variant of the W32/SDBOT WORM!
X
Windows DLL Loader
WINCFG32.EXE
W32/Agobot-TE WORM!
X
Windows DLL Services
system.exe
TSPY_AGENT.H spyware.
X
Windows DLL Services
winsvc32.exe
W32/RBOT-ZF WORM!
X
Windows DLL Tracker
spoolsrv.exe
variant of the W32/WOOTBOT WORM!
X
Windows DLL Verifier
xptl.exe
variant of the WIN32.RBOT WORM!
X
Windows DNS
windns.exe
W32/SDBOT-XU WORM!
X
Windows DNS Daemon
windnsd.exe
WOOTBOT.AS WORM!
X
Windows Domain Name Drivers
windns.exe
W32/FORBOT-EP WORM!
X
Windows Download Manager
windlmngr.exe
unidentified TROJAN!
X
Windows Drive Compatibility
System32Driver32.exe
SUPOVA.Z VIRUS!
X
Windows Driver
winxpdriver.exe
WOOTBOT.EE WORM!
X
Windows Driver Adapter
svchost.exe /driver-auto
W32/Antinny-K WORM!
X
Windows Driver Services
msdrvs32.exe
WORM_WOOTBOT.L
X
Windows driver update
dmsvc32.exe
W32/Sdbot-GP worm infection
X
Windows drivers update
windowsupdate.exe
W32/RBOT-ACE WORM!
X
Windows Dynamic Loading Header
winDLL32.exe
variant of the W32/SDBOT WORM!
X
Windows Executable
winmys.exe
W32/RBOT-ABO WORM!
X
Windows ExpIorer
??
W32/Rbot-AKO WORM!
X
Windows Explorer
??
SDBOT WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X
Windows Explorer
EEXPLORER.EXE
variant of the W32.SPYBOT WORM!
X
Windows Explorer
explorer.exe
"W32/POEBOT-J WORM! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)"
X
Windows Explorer
explorer.pif
W32/Rbot-AID WORM!
X
Windows Explorer
Lsas.exe
GAOBOT.AO WORM! **Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
X
Windows Explorer
olecom32.exe
unidentified WORM or TROJAN!
X
Windows Explorer
system32.exe
W32/Rbot-AJH WORM!
X
Windows Explorer Shell
Winexec32.exe
REDIST.B VIRUS!
X
Windows Explorer SP2
csrss.exe
Troj/Banker-DM Trojan!
X
Windows Explorer Update Build 1142
EXPLORER32.EXE
KaZaA based KWBOT or KWBOT.Y VIRUSES!
X
Windows Explorer-3212
WINRE16.EXE
HARDOC VIRUS!
N
Windows Eyes
??
"For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs"
X
Windows FAT 32
WINFAT32B.exe
W32/SPYBOT-AGT WORM!
X
Windows File Protection
winprotect.exe
AGOBOT.JB WORM!
X
Windows Firewal
Lsess.exe
variant of the WIN32.RBOT WORM!
X
Windows Firewall
WindowsFirewall.exe
W32.MYTOB.AO WORM!
X
Windows Firewall Log
winlog.exe
unidentified WORM or TROJAN!
X
Windows Firewall Manager
msfw.exe
RBOT.WR WORM!
X
Windows Firewalll
scvhost.exe
W32/RBOT-EK WORM!
X
Windows Firewalll
sphost.exe
variant of the WIN32.RBOT WORM!
X
Windows Firewalll
svvhost.exe
variant of the WIN32.RBOT WORM!
X
Windows Firewalll
winmu.exe
variant of the WIN32.RBOT WORM!
X
Windows Fix
integator.exe
SDBOT.ZAB WORM!
X
Windows Fixes Systems
elite.exe
W32.Mytob.EG WORM!
X
Windows FormatAd
WinForm.exe
Windupdates adware variant
X
Windows Frame Works
frmwrks32.exe
variant of the WIN32.RBOT WORM!
X
WINDOWS FUCK BY CLASIC
fuck.exe
ZOTOB.H or W32.Zotob.J WORM!
X
Windows Generic Proc
procmsg.exe
W32.ALLIM.B WORM!
X
Windows Graphics Loaders
wingraphics.exe
SPYBOT.JG WORM!
U
Windows Guardian
thehel1iawgrd32.exeFawgrd32.exe
Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
X
Windows Help
mailinfo.exe
MYTOB.JX WORM!
X
Windows Help File
winhelper32.exe
W32/SDBOT-QK TROJAN!
X
Windows Help Manager
svchost32.exe
W32/RBOT-OZ WORM!
X
Windows Help Service
winhelpsv.exe
W32/Rbot-LP WORM!
X
Windows Help Service
winhlp.pif
W32/Rbot-AKW WORM!
X
Windows Host
hosts.exe
W32.KELVIR.U WORM!
X
Windows Host
winhost.exe
BACKDOOR.PRYSAT TROJAN!
X
Windows Host Device
hostsvc.exe
W32/Zooty-A worm infection
X
Windows Host Name
lmass.exe
GAOBOT.O WORM!
X
Windows Host Service
host.exe
W32.Kelvir.AN WORM!
X
Windows Host Service
scvhosts.exe
W32.SPYBOT.NLI WORM!
X
Windows Host Service
svchoste.exe
W32.KELVIR.BF WORM!
X
Windows Host Service
svchosts32.exe
W32.KELVIR.AW WORM!
X
Windows Host Service
svchosts32.exe
W32/Kelvir-AK WORM!
X
Windows Host32 Starter
hostserv.exe
W32/SDBOT-WU WORM!
X
Windows Hosts
hosts.exe
KELVIR-O TROJAN!
X
Windows HTML file reader
Sysconf32.exe
NOOMY.A worm infection
X
Windows Icons Manager
wicomgr.exe
W32/Rbot-AIF WORM!
X
Windows iMessenger Messenger
winimsg.exe
W32.ALLIM.A WORM!
X
Windows Incontext
InSearch.exe
Z-Quest adware downloader/installer variant
X
Windows Installer
ntdll.exe
unidentified WORM or TROJAN!
X
Windows installer
winstall.exe
SpySheriff malware
X
Windows Internet Protocol
deinst_qfe001.exe
variant of the Win32.Small TROJAN!
X
Windows Internet Protocol
winproc32.exe
CoolWebSearch parasite related.
X
Windows IPv6 Drivers
wipv6.exe
W32/SDBOT-VJ WORM!
X
Windows Java Update
weatherBug32.exe
variant of the WIN32.RBOT WORM!
X
Windows JavaScript Daemon
Winjsd.exe
WOOTBOT.AF worm infection
X
Windows kev Messenger
mskev.exe
W32/SDBOT-XV WORM!
X
Windows Loader
wstart32.exe
GAOBOT.CA WORM!
X
Windows Loader Service
civsc.exe
variant of the WIN32.RBOT WORM!
X
windows Loadxm
Win_.exe
Troj/Fodder-A TROJAN!
X
Windows Local Services
localsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
netsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
svcman.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
svcrun.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Local Services
websvc.exe
Troj/Dloader-NY Trojan!
X
Windows Logger
winlog.exe
Troj/Nshadow-B TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Windows logging
winlogd.exe
W32/RBOT-ON WORM!
X
Windows Login
explored.exe
W32.Gaobot.SY worm
X
Windows Login
winlog.exe
AGOBOT.MG WORM!
X
Windows Login Security
winlogin.pif
unidentified WORM or TROJAN!
X
Windows Login Service
winlog.exe
W32/Rbot-AFN Worm!
X
Windows Login Service
winlogin.pif
W32/Sdbot-ACU WORM! Note: This worm/trojan file (winlogin.pif) is found in the Windows or Winnt folder.
X
Windows Logon
winlogin.exe
TROJ/SPYBOT-C TROJAN!
X
Windows Logon Application
logon.exe
W32/POEBOT-J WORM!
X
Windows Logon Application
services.exe
Troj/Ciadoor-L TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
X
Windows Logon Application
WinIogon.exe
"""Cruel Intentionz"" backdoor TROJAN!"
X
Windows Logon Application
WinIogon.exe
W32.LINKBOT.M WORM!
X
Windows Logon Manager
logon.exe
variant of the WIN32.RBOT WORM!
X
Windows Logon Procedure
Svchosta.exe
variant of the W32.SPYBOT WORM!
X
Windows Logon Procedure
Svchoste.exe
variant of the W32.SPYBOT WORM!
X
windows logon procedure
winlogonpc.exe
"""WinLogon"" TROJAN!"
X
Windows Management Instrumentation
??
W32/QEDS-A VIRUS!
X
Windows Management Instrumentation
mwd.exe
GRAPS VIRUS!
X
Windows Management Instrumentation
wmimgr.exe
W32.Qdens.A Trojan!
X
WINDOWS MANAGEMENT SYSTEM
wm1exe.exe
W32/RBOT-VT WORM!
X
Windows Manager
winmants.exe
MANTAS VIRUS!
X
Windows Manager
winsrv.exe
variant of the AGOBOT/GAOBOT WORM!
X
Windows Manager Update Inc
tgb.exe
W32/Sdbot-ACM WORM!
X
Windows mangement
winlogonn.exe
RANDEX.FC VIRUS!
X
Windows Media AP
winmapp.exe
unidentified WORM or TROJAN!
X
Windows Media APP
wmapp.exe
unidentified WORM or TROJAN!
X
Windows Media Driver
msnger.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player
50cent.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player
mcafe32.exe
W32/RBOT-YO WORM!
X
Windows Media Player
MediaPIayer.exe
"SDBOT-QO TROJAN! - (note, the executable is called 'MediapIayer', with an 'i' !)"
X
Windows Media Player
mpwe.exe
W32/RBOT-TT WORM!
X
Windows Media Player
msa.exe
W32/RBOT-SI WORM!
X
Windows Media Player
msams.exe
RBOT.AHR WORM!
X
Windows Media Player
msass43.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player
valentine-jessica.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player
wmediaplayer.exe
W32/AGOBOT-NQ WORM!
X
Windows Media Player
WMP23.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player
wmplayer.exe
W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM!
X
Windows Media Player 3.6
wmpa36.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player 3.6b
WMPA36B.EXE
W32/RBOT-VV WORM!
X
Windows Media Player 3.6d
wmpa36d.exe
W32/RBOT-YA WORM!
X
Windows Media Player 3.6d
wmpa36d.exe
W32/RBOT-YA WORM!
X
Windows Media Player 3.9
wmpa36.exe
variant of the WIN32.RBOT WORM!
X
Windows Media Player Update
??
RBOT-ET WORM!
N
Windows Media Powerpoint Helper
NSPPTHLP.EXE
German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
X
Windows media service
crsss.exe
RBOT.ACY WORM!
X
Windows media service
crvss.exe
SDBOT.VP WORM!
X
Windows media services
cvrsss.exe
W32/RBOT-MW WORM!
X
Windows Media SP.2.37
??
LEMIR.C VIRUS!
X
Windows Media Utility
wmediautil.exe
variant of the W32.SPYBOT WORM!
X
Windows messenger
messengers.exe
W32.Mytob.EI WORM!
X
Windows Messenger
msmsgs.exe
W32/Forbot-BD worm infection
X
Windows Messenger
msnsmgs.exe
W32/RBOT-ANJ WORM!
X
Windows Messenger Messenger
winmsg.exe
W32.Velkbot.A WORM!
X
Windows Messenger Service
kaspersky.exe
MYTOB.HY WORM!
X
Windows Messenger Service
winsmsgr.exe
W32/RBOT-VW WORM!
X
Windows MeTaLRoCk service
metalrock.exe
TASTYRED VIRUS!
X
Windows Micro Drivers
wupdates32.exe
W32/Rbot-AEH Worm!
X
Windows Monitor
arsetup.exe
WIN32.SPAZBOX.A TROJAN!
X
Windows Monitor
winmon.exe
SDBOT.VB worm infection
X
Windows Monitor Services
winmonitor.exe
W32/RBOT-XX WORM!
X
Windows Monitoring Service
winmon.exe
variant of the W32/SDBOT WORM!
X
Windows More Choice
TopContext.exe
ZQuest adware
X
Windows Mouse Utilities
mouseutils.exe
W32/RBOT-ABU WORM!
X
Windows ms Drivers
msnup32.exe
W32/SDBOT-AAL WORM!
X
Windows MSConfig Startup Logger
winlog.exe
RBOT.BCU WORM!
X
Windows NetDDe
wrmana32.exe
W32.Mytob.IM WORM!
X
Windows Nets
WinNET.exe
W32/RBOT-MO WORM!
X
Windows NetStart Service
winsN2S.exe
W32/RBOT-ZX WORM!
X
Windows NetStart Service2
winsN2S.exe
W32/RBOT-ABN WORM!
X
Windows NetStart Service2
winsN2SD.exe
variant of the WIN32.RBOT WORM!
X
Windows Network Controller
Mqguard.exe
W32/Forbot-CL WORM!
X
Windows Network Controller
Win9x.exe
WOOTBOT.I WORM!
X
Windows Network Controller
wingmt.exe
variant of the W32/SDBOT WORM!
X
Windows Network Controller
winmms32.exe
W32/FORBOT-ED WORM!
X
Windows Network Controller
WinxPupd.exe
W32/FORBOT-DK WORM!
X
Windows Network Firewall
firewall.exe
W32/POEBOT-J WORM!
X
Windows Network Service
winvc32.exe
RBOT.RY WORM!
X
Windows Networking
winsys32.exe
GAOBOT.FL WORM!
X
Windows Networks
netcog.exe
MYTOB.FH WORM!
X
Windows Nivedia Driver
sysMGT.exe
Win32.Rbot worm variant
X
Windows NNT
??
RANKY.E VIRUS!
X
Windows NT 32
ntlogin32.exe
W32.RANDEX.BRD WORM!
X
Windows NT Login
ntlogin32.exe
WORM_SDBOT.WG
X
Windows NT Login Session Manager
WNSM.EXE
RBOT.BIV WORM!
X
Windows NT Logon Application
winlogon.scr
W32/Rbot-ALP WORM!
X
Windows NT Service Name
winshock.exe
W32/RBOT-PK WORM!
X
Windows NT Update Manager
Winlogon.exe
"AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
X
Windows OEM Tools
winres32.exe
SPYBOT.FD worm infection
X
Windows OLE Automation Server
ole32aut.vbe
CoolWebSearch parasite related browser hijacker
X
Windows Online Updater
dllman.exe
W32/Rbot-TE WORM!
X
Windows PDG
winpdg.exe
W32/Rbot-ADW Worm!
X
Windows PNP
winpnp.exe
W32/Rbot-AKN WORM!
X
Windows PNP Server
pnpsrv.exe
this variant of the W32/SDBOT WORM!
X
Windows Print Spooler
NavAgent32.exe
unidentified VIRUS!
X
Windows Print Spooler
SVEHOST.EXE
SPYBOT.H VIRUS!
X
Windows Process Manager
winproc.exe
unidentified WORM or TROJAN!
X
Windows Processe Manager
mspn32.exe
variant of the WIN32.RBOT WORM!
X
Windows Protectot
boxide.exe
variant of the W32/WOOTBOT WORM!
X
Windows Reg Services
dservice.exe
TROJ/PRORAT-D TROJAN
X
Windows Reg Services
ffservice.exe
Troj/Dloader-PL TROJAN!
X
Windows Reg Services
fservice.exe
TROJ/PRORAT-D TROJAN
X
Windows Reg Services
lncom.exe
TROJ/PRORAT-O TROJAN!
X
Windows Reg Services
lservice.exe
TROJ/PRORAT-O TROJAN!
X
Windows Reg Services
ssservice.exe
TROJ/PRORAT-D TROJAN
X
Windows Reg Services
wservice.exe
TROJ/PRORAT-O TROJAN!
X
WINDOWS REGISTER EDIT
registr32.exe
unidentified WORM or TROJAN!
X
Windows Register Settings
svmhost.exe
variant of the W32/FORBOT WORM!
X
Windows Registry
msnmsg.exe
Win32.Rbot worm variant
X
Windows Registry
winhost.exe
variant of the WIN32.RBOT WORM!
X
Windows Registry Cleaner
winclean.exe
W32.SpyBot worm variant
X
Windows Registry Express Loader
regexpress.exe
W32/FORBOT-CJ WORM!
X
Windows Registry Manager
tasksmanagers.exe
W32.Mytob.ER WORM!
X
Windows Registry Name
??
W32/Rbot-AEB Worm!
X
Windows Registry Name
winses.exe
W32/Rbot-ADB Worm!
X
Windows Registry Scan
regscan.exe
W32/Rbot-HA worm infection
X
Windows Registry Scan
regscan23.exe
variant of the WIN32.RBOT WORM!
X
Windows Registry Scan
regscan32.exe
WORM_RBOT.KE
X
Windows Registry Scan
svcdll.exe
W32/RBOT-TP WORM!
X
Windows Registry Scan
timeupdate.exe
SPYBOT.JE WORM!
X
Windows Registry Security
crss.exe
variant of the BACKDOOR.IRC.BOT TROJAN!
X
Windows Registry Startup
wind32.exe
W32/Agobot-BZ WORM!
X
Windows report
swchost.exe
Small-BD TROJAN!
X
windows run
system.exe
W32/ICPASS-A WORM!
X
Windows Runtime Help
win32hlp.exeWinRunHelp.wrh
variant of the AIMVISION VIRUS!
X
Windows Runtime Proccess
32RUNdll.exe
SDBOT.QW WORM!
X
Windows SA
omniscient.exe
BLAZEFIND adware
X
Windows Screensaver
Service.exe
W32.KELVIR.P or KELVIR-L WORMS!
X
WINDOWS SCREENSAVER
ssaver.scr
W32/Sdbot-YZ Worm!
X
Windows secure
setver32.exe
WORM_SPYBOT.EP
X
Windows Secure Connection
winsc.exe
variant of the WIN32.RBOT WORM!
X
Windows Secure Messaging System
msnmsgrsrvc.exe
W32/RBOT-RE WORM!
X
WINDOWS SECURITY
wingrd.exe
variant of the WIN32.RBOT WORM!
X
Windows Security Assistant
rundll32.vbe
CoolWebSearch parasite related.
X
Windows Security Assistant
winsec.exe
CoolWebSearch parasite related.
X
Windows Security Authority Service
lsass.exe
"W32/KALEL-A WORM! - NOTE - this should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Windows Security Manager
winsecure.exe
Affilred.B adware
X
Windows Security Manager
winsecurity.exe
W32/AGOBOT-KI WORM!
X
Windows Security Module
module.exe
variant of the WIN32.RBOT WORM!
X
Windows Security Service
??
W32/RBOT-ALV WORM!
X
Windows Security Update
security32.exe
Affilred.B adware
X
Windows Security Updater
WINFRW.exe
Solufina TROJAN!
X
Windows Serv Patch
Mcaffe2005.exe
variant of the WIN32.RBOT WORM!
X
Windows ServeAd
WinServAd.exe
WindUpdates WinAd adware
X
Windows Server Information
servinfo.exe
W32/FORBOT-EN WORM!
X
Windows Servic2
winsy.exe
W32/Rbot-AIA WORM!
X
Windows Service
dddd.exe
"Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans"
X
Windows Service
dstart4.exe
unidentified TROJAN!
X
Windows Service
pd14.exe
"Adware, detected by TDS-3 as ""TrojanDownloader.Win32.Delf.dg"""
X
Windows Service
pd7.exe
TROJ_SMALL.VZ TROJAN!
X
Windows Service
private-zone.exe
unidentified TROJAN.CLICKER !
X
Windows Service
prvdi.exe
"Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd"
X
Windows Service
r.exe
variant of the TROJ_SMALL.VZ TROJAN
X
Windows Service
services.exe
"W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
Windows Service
svvhost.exe
W32/AGOBOT-HL WORM!
X
Windows Service
video.exe
unidentified TROJAN!
X
Windows Service
video2.exe
DOWNLOADER.SMALL.MY TROJAN!
X
Windows Service
WINSVC.EXE
SDBOT.CL WORM!
X
Windows Service Controller
services.exe
W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
Windows Service Host
scvhost.exe
SDBOT.N WORM!
X
Windows Service Host
svchost.exe
"CONE.B VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32"
X
Windows Service Host
svchost.exe
W32/Kalel-C WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
X
Windows Service Host Process
??
W32/EZIO-A WORM!
X
Windows Service Loader
Window.exe
W32/RBOT-XO WORM!
X
Windows Service Manager
localsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
msgs.exe
W32/OSCABOT-E WORM!
X
Windows Service Manager
msnmrg.exe
W32/OSCABOT-G WORM!
X
Windows Service Manager
netsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
svcman.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
svcmgr32.exe
W32/OSCABOT-D WORM!
X
Windows Service Manager
svcrun.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Service Manager
userint32.exe
W32/OSCABOT-C WORM!
X
Windows Service Manager
websvc.exe
Troj/Dloader-NY Trojan!
X
Windows Service Pack Auto Update
ballin.exe
unidentified WORM or TROJAN!
X
Windows Service Pack Auto Update
del-me.exe
"Adware, also detected as the Lowzones.BH TROJAN!"
X
Windows Service Pack Auto Update
figgaz.exe
TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.bt
X
Windows Service Pack Auto Update
winworks.exe
"Adware downloader, identified by eScan antivirus as Trojan-Clicker.Win32.Agent.bt"
X
Windows Service Pack2
svchhost.exe
variant of the WIN32.RBOT WORM!
X
Windows Service Pack2
WIN43.EXE
GAOBOT.G WORM!
X
Windows Service Support Call
SVSS32.EXE
W32/RBOT-XQ WORM!
X
Windows Service XP
XpFirewall.exe
W32.MYTOB.AM WORM!
X
Windows Services
Explorer.exe
"W32/SDBOT-WT WORM! - NOTE - the valid ""explorer.exe"" file is located in C:\Windows or C:\Winnt, whereas this one is located in the Windows\System32 or Winnt\System32 folder!"
X
Windows Services
NetworkDriver32.exe
W32/RBOT-ACR WORM!
X
Windows Services
NetworkDrivers.exe
W32/Sdbot-YO Worm!
X
Windows Services
scmsg.exe
variant of the W32/SDBOT WORM!
X
Windows Services
scvhoste.exe
W32.Spybot.OBZ WORM!
X
Windows Services
service.exe
RANDEX.R VIRUS!
X
Windows Services
smsc.exe
variant of the W32/SDBOT WORM!
X
Windows Services
Spool32x.exe
variant of the WIN32.RBOT WORM!
X
Windows Services
winsvc32.exe
W32/MYTOB-CB WORM!
X
Windows Services Host
svchost.exe
"CONE or CONE.E VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32"
X
Windows Services Hosts
svhosts.exe
TROJ/SDBOT-YH TROJAN!
X
Windows Services Ink Platform Tablet Input Subsystem
wsiptis.exe
RBOT.APC WORM!
X
Windows Services Update
svch0st.exe
"variant of the WIN32.RBOT WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
Windows Session Manager
smss32.exe
variant of the WIN32.RBOT WORM!
X
Windows Session Manager Subsystem
smss.exe
W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
Windows Shell
shell.exe
W32/MYTOB-CA WORM!
X
Windows Shell
taskgmr.exe
WIN32/MYTOB.BV WORM!
X
Windows Shell Library Loader
load shell.dll /c /set
CoolWebSearch parasite related.
X
windows shellext.32
mschost.exe
BLASTER.K VIRUS!
X
WINDOWS SKY
sky.exe
W32.MYTOB.CH WORM!
X
Windows Smart Manager
smart.exe
W32/RBOT-SL WORM!
X
Windows Sound Driver
SndMon32.exe
W32.SpyBot worm variant
X
Windows Sound Manager
SndMon16.exe
variant of the W32/FORBOT WORM!
X
Windows Sound Manager
SndMon32.exe
W32/FORBOT-BU WORM!
X
Windows SP2 Firewall
wfirewall7.exe
variant of the WIN32.RBOT WORM!
X
Windows SP2 Update
Sp2update.exe
WOOTBOT.BS WORM!
X
Windows SP2 Version Load
wuauclt32.exe
GAOBOT.CX WORM!
X
Windows SP4
directCC.exe
W32/RBOT-ACX WORM!
X
Windows Spool Server
spoolsrv.exe
W32/Sdbot-ACT WORM! Note: This is not the legitimate Windows process spoolsv.exe (Notice the difference in the spelling). This trojan file (spoolsrv.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Windows SpoolaPrint Service
spoolasrv.exe
W32/Sdbot-AYD WORM!
X
Windows Spooler
SPOOLSRV.EXE
SPYBOT.P VIRUS!
X
Windows Spooler
spoolsv32.exe
unidentified WORM or TROJAN!
X
Windows Spooler Services
spool.exe
W32/AGOBOT-AMO WORM!
X
Windows SpoolPrint Service
spoolersrv.exe
W32/Sdbot-ZT WORM!
X
Windows spoolservr Service
spoolservr.exe
W32/Sdbot-AAN WORM!
X
Windows Spoolsre Service
spoolsre.exe
W32/Sdbot-AAE WORM!
X
Windows Spoolsrv Service
spoolmsv.exe
W32/Sdbot-ZS WORM!
X
windows spoolsrv service
spoolssv.exe
W32/Sdbot-AWV Worm!
X
Windows Spoolsurf Service
spoolsurf.exe
W32/SDBOT-ZZ WORM!
X
Windows SpooltPrint Service
spooltsrv.exe
W32/SDBOT-AYE WORM!
X
Windows Spoolvvv Service
spoolvvv.exe
W32/SDBOT-AAW WORM!
X
Windows sq Drivers
winmsn32.exe
W32/Rbot-ADI Worm!
X
Windows Sql Service For Windows 32 Bit
winsql32.exe
W32/FORBOT-FC WORM!
X
Windows SSL File
winssv.exe
WOOTBOT.CA WORM!
X
Windows Stand Sound Drivers
Sounddrv.exe
W32/SDBOT-XF WORM!
X
Windows Standard Securty
??
W32/Rbot-ALF WORM! Note: May use DOZ.EXE for file name.
X
Windows Start Server 2000
traficy.exe
W32/Rbot-AHM WORM!
X
Windows Startup
services21.exe
W32/Agobot-MX WORM!
X
Windows Startup
Wdrun32.exe
GAOBOT.AO WORM!
X
Windows Startup
winsta~1.exe
Go-Hip browser add-on
X
Windows Startup
winstartup.exe
Go-Hip browser add-on
X
Windows Startup 32 Bits
sysrun32.exe
DarkSun trojan variant
X
Windows Streams Server
localsrv.exe
SDBOT.LN WORM!
X
Windows Subsys
winload.exe
NETSPREE.C WORM!
X
Windows SyncroAd
SyncroAd.exe
Windupdates adware variant
X
WINDOWS SYSTEM
beta.exe
W32.Mytob.DF WORM!
X
WINDOWS SYSTEM
botzor.exe
W32/ZOTOB WORM!
X
WINDOWS SYSTEM
dcomuser.exe
W32.Mytob.EO WORM!
X
WINDOWS SYSTEM
gothica.exe
MYTOB.HU WORM!
X
WINDOWS SYSTEM
lf66prc.exe
W32.Mytob.GC WORM!
X
WINDOWS SYSTEM
logic.exe
W32.MYTOB.IC WORM!
X
WINDOWS SYSTEM
msdev32.exe
W32.Mytob.EH WORM!
X
WINDOWS SYSTEM
msnl.exe
W32.Mytob.IK WORM!
X
WINDOWS SYSTEM
mtrnqs.exe
W32.MYTOB.IG WORM!
X
WINDOWS SYSTEM
nec.exe
W32/Mytob-L or W32/Mytob-CM and W32/Mytob-CN Worms!
X
WINDOWS SYSTEM
nec.exe
W32/Mytob-BH Worm!
X
Windows System
nibie.exe
W32.Mytob.FO WORM!
X
WINDOWS SYSTEM
nibie.exe
W32/Mytob-BY WORM!
X
WINDOWS SYSTEM
ninfoie.exe
W32/Mytob-EP Worm!
X
WINDOWS SYSTEM
per.exe
W32/ZOTOB.C WORM!
X
WINDOWS SYSTEM
servce.exe
W32/Mytob-EI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
WINDOWS SYSTEM
servises.exe
W32/Zotob-I WORM! Note: (servises.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (services.exe) should not be seen in Msconfig or as a Startup item.
X
WINDOWS SYSTEM
skybot.exe
MYTOB.JU WORM!
X
WINDOWS SYSTEM
skybot.exe
W32/Mytob-CX or W32.Mytob.EB WORM!
X
WINDOWS SYSTEM
skybotx.exe
W32.Mytob.FT WORM!
X
WINDOWS SYSTEM
skybotx.exe
W32/Mytob-BY WORM!
X
WINDOWS SYSTEM
smoc.exe
W32.MYTOB.FU WORM!
X
WINDOWS SYSTEM
smsc.exe
W32/MYTOB-BR WORM!
X
WINDOWS SYSTEM
test.exe
W32.Mytob.DJ WORM!
X
WINDOWS SYSTEM
test2.exe
W32.Mytob.DJ WORM!
X
WINDOWS SYSTEM
test3.exe
W32.Mytob.DV WORM!
X
WINDOWS SYSTEM
twunk_65.exe
W32/MYTOB-EG WORM!
X
WINDOWS SYSTEM
wdns33.exe
W32/Mytob-BY WORM!
X
WINDOWS SYSTEM
win.exe.exe
W32.Mytob.FA WORM!
X
WINDOWS SYSTEM
winaup.exe
W32/Mytob-DN WORM!
X
WINDOWS SYSTEM
winligon.exe
W32.Mytob.EP WORM!
X
WINDOWS SYSTEM
winmon.exe
W32.Mytob.GB WORM!
X
WINDOWS SYSTEM
winNTsys32.exe
W32/MYTOB-DM WORM!
X
WINDOWS SYSTEM
winsvc32.exe
W32.MYTOB.HH WORM!
X
Windows System
WINSYS.exe
W32/Mytob-M or W32/Mytob-EK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
WINDOWS SYSTEM
winsys33.exe
W32.Mytob.EK WORM!
X
WINDOWS SYSTEM
winvnc.exe
W32.Mytob.EU WORM!
X
WINDOWS SYSTEM
winxpserv.exe
W32/Mytob-BQ Worm!
X
WINDOWS SYSTEM
xpupdate.exe
W32/ZOTOB-G WORM!
X
WINDOWS SYSTEM
xxx.exe
W32.Mytob.CZ WORM!
X
Windows System 32-Bat Service
win32bat.exe
W32.Mytob.FI WORM!
X
Windows System Backup
SysBackup.exe
Unidentified malware
X
WINDOWS SYSTEM Cleaner
h3.exe
W32.Mytob.EQ WORM!
X
WINDOWS SYSTEM CLEANER
iexplore.exe
W32.Mytob.ET WORM!
X
Windows System Configuration
Passcfg16.exe
DOMWIS-E TROJAN!
X
Windows System Configuration
SYSCFG16.EXE
W32/Domwis-N WORM!
X
Windows System Configuration
wincfg.exe
AGOBOT.OP WORM!
X
Windows System Configuration
WINCFG32.EXE
W32/Agobot-TE WORM!
X
Windows System Configuration
Winfrw.exe
BACKDOOR.SOLUFINA TROJAN or the W32/DOMWIS-J WORM!
X
Windows System Configuration
WinNeth.exe
W32/Rethe-A WORM!
X
WINDOWS SYSTEM Dns
windsns.exe
W32.Mytob.EY WORM!
X
WINDOWS SYSTEM DNSPOOL
hbmail.exe
W32.MYTOB.FW WORM!
X
Windows System File
cmxp.exe
W32.Spybot.KHO WORM!
X
WINDOWS SYSTEM FILE
winload.exe
MYTOB.DK WORM!
X
Windows System Gateway
SPOOLER.EXE
variant of the WIN32.RBOT WORM!
X
Windows System Init
winit32.exe
variant of the WIN32.RBOT WORM!
X
Windows System Manager
crssm.exe
W32/Rbot-AFH Worm!
X
Windows System Manager
smsc.exe
variant of the WIN32.RBOT WORM!
X
Windows System Manager
sysconf.exe
W32.MYTOB.AL WORM!
X
Windows System Manager
winsystem.exe
W32/Rbot-AN worm infection
X
Windows System Manager Loader
smsls.exe
AGOBOT.TF WORM!
X
Windows System Manager Proc
winsmc.exe
RBOT.JH WORM!
X
Windows System Manager Proc
winsmc.exe
RBOT.JH WORM!
X
WINDOWS SYSTEM MEMORY LOADER
memloader.exe
W32/MYTOB-IN WORM!
X
windows system notepad
wnpsm.exe
variant of the AGOBOT/GAOBOT WORM!
X
Windows System Restore Configuration
Sblhost.exe
variant of the SPYBOT.GEN VIRUS!
X
Windows System Restorer
SystemRestorer.exe
DULOAD.C VIRUS!
X
Windows System Security
winmp.exe
RBOT.IV WORM!
X
Windows System Security Monitor
??
W32.Pinkton.A Worm!
X
Windows System Serivce
winserv.exe
variant of the Win32.Rbot WORM!
X
windows system service
winsock.exe
W32/RBOT-MR WORM!
U
Windows System Tray
dlhost.exe
Related to IamBigBrother Internet monitoring software.
U
Windows System Tray
msni.exe
Iambigbrother monitoring software
X
Windows System Tray
swhost.exe
Unidentified worm or trojan
X
WINDOWS SYSTEM UPDATE
xDcc.exe
W32/Mytob-EH WORM!
X
Windows System32
windowsp.exe
MYTOB.GD WORM!
X
Windows System32 Kernel
system32.exe
W32/SDBOT-AAT WORM!
X
Windows Systemnmg
stagmr.exe
W32.MYTOB.S WORM!
X
Windows Sz Host
winshvc.exe
variant of the W32/SDBOT WORM!
X
Windows Task Manager
ACCOUNT_DETAILS.DOC.exe
QUATERS.A VIRUS!
X
Windows Task Manager
taskgmr.exe
W32.Mytob.BJ and W32/Mytob-AJ WORMS!
X
Windows Task Manager
taskmg.exe
"Browser hijacker - identified by DrWeb antivirus as ""Trojan.StartPage.601"""
X
Windows Task Manager
taskmgn.exe
"Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install."
X
Windows Task Manager
taskmrg.exe
W32.MYTOB.AV WORM!
X
Windows Task Manager
taskmngr.exe
W32/Rbot-ANM WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Windows Task Manager Emulator
kennewr.exe
W32/SPYBOT-FA WORM!
X
Windows Task Manager-Emulator
uswtme.exe
W32/Rbot-CG infection
X
Windows Task Scheduler
asijdie.exe
unidentified WORM or TROJAN!
X
Windows TaskAd
Wintaskad.exe
WindUpdates WinTaskAd adware variant
X
Windows Taskbar Manager
??
W32.PROTORIDE.B WORM!
X
Windows Taskbar Manager
internat.exe
PROTORIDE-H WORM!
X
Windows Taskmanager
lsassx.exe
W32.Kelvir.C or W32.Kelvir.E WORM!
X
Windows TCP/IP
wintcp.exe
W32/AGOBOT-ZH WORM!
X
Windows Telnet Server
wintel.exe
W32/AGOBOT-MW WORM!
X
Windows Time
winmgr.exe
W32/RBOT-XC WORM!
X
Windows Time Server
TimeSRV.exe
W32.Spybot.DNC worm
X
Windows TM
rundlI32.exe
variant of the WIN32.RBOT WORM!
X
Windows TM
SVPHOST.exe
variant of the WIN32.RBOT WORM!
X
Windows TM
windowssys32.exe
variant of the WIN32.RBOT WORM!
X
Windows TM
WinxSys.exe
variant of the WIN32.RBOT WORM!
X
Windows Upate
rundll.exe
HAKO TROJAN! - NOTE: this is NOT the Windows system file of the same name as described here
X
Windows Update
??
NORIO VIRUS! Acts as a hi-jacker redirecting to adult content sites
X
Windows Update
ebay.exe
W32.GAOBOT.BUU WORM!
X
Windows Update
host32.exe
W32/RBOT-GU WORM!
X
Windows Update
host32.exe
W32/RBOT-GU WORM!
X
Windows Update
iexplorere.exe
GAOBOT.AP WORM!
X
Windows Update
inetinf.exe
variant of the GAOBOT/AGOBOT WORM!
X
windows update
logonuit.exe
Troj/LegMir-AO TROJAN!
X
windows update
Microsoft.exe
TROJ_LMIR.A TROJAN!
X
Windows Update
mplupdate.exe
W32.HLLW.MOEGA WORM!
X
windows update
msnsever.exe
W32/RBOT-AHN WORM!
X
Windows Update
msnupdates.exe
W32/Rbot-ALK WORM! Note: This file has nothing to do with Windows updates or MSN.
X
Windows Update
msnwinsb.exe
W32/RBOT-AAH WORM!
X
Windows Update
qtask.exe
W32/RBOT-AKU WORM! - NOTE: do NOT confuse with the Quicken file of the same name as described here
X
windows update
real.exe
TROJ/LEGMIR-AU WORM!
X
Windows Update
scvhost.exe
W32/SDBOT-XT WORM!
X
windows update
sychost.exe
LEOX.B VIRUS!
X
Windows Update
taskmr.exe
W32/Mytob-GZ Worm!
X
windows update
uddater.exe
LEOX VIRUS!
X
Windows Update
Update.exe
TROJ/DELF-FN TROJAN!
X
Windows Update
update32.exe
variant of the WIN32.RBOT WORM!
X
Windows Update
windows.exe
W32/RBOT-RB WORM!
X
Windows Update
windowsx.exe
TROJ/BANCD-A TROJAN!
X
Windows Update
wininfo.exe
W32.Mytob.GA WORM!
X
Windows Update
winlogin.exe
Troj/Banker-DV TROJAN!
X
Windows Update
winupdate.exe
W32/SDBOT-WS WORM!
X
windows update
Wruaclt.exe
RBOT.XZ WORM!
X
windows update
Wuacrlt.exe
RBOT.XZ WORM!
X
Windows Update
Wuamgrd.exe
W32.SpyBot worm variant
X
Windows Update
wuampd.exe
RBOT.UM WORM!
X
windows update
Wuanclt.exe
RBOT.XZ WORM!
X
windows update
wuarclt.exe
W32/RBOT-OF WORM!
X
windows update
wuaruclt.exe
variant of the WIN32.RBOT WORM!
X
windows update
wuaucrlt.exe
W32.SPYBOT.HUR WORM!
X
windows update
wuaurlt.exe
RBOT.ADG WORM!
X
Windows Update
wudate.exe
AGOBOT.ML WORM!
X
Windows Update
wupdate.exe
Wengs adware
X
Windows Update
wupdmgr.exe
BANCBAN-FC TROJAN!
X
windows update
wuraclt.exe
W32/RBOT-PO WORM!
X
Windows Update 32
winlogons.exe
W32/Forbot-FI WORM!
X
Windows Update 64
WinV.exe
W32/FORBOT-FP WORM!
X
Windows Update Auto Update
wuaumgr.exe
variant of the W32.SPYBOT WORM!
X
Windows Update AutoUpdate Client Product
wuauct.exe
AGOBOT.ACL WORM!
X
Windows Update Center
svthx.exe
W32.STUBBOT.A WORM!
X
Windows Update Center
W32RSA.exe
unidentified WORM or TROJAN!
X
Windows Update Checker
??
adware downloader trojan
X
Windows Update Checker
deinst_qfe001.exe
variant of the Win32.Small TROJAN!
X
Windows Update Checker
deinst_qfe002.exe
variant of the Win32.Small TROJAN!
X
Windows Update Client
wuclient.exe
WIN32.SMALL.RN downloader TROJAN!
X
Windows Update Client Service
windrvl32.exe
AGOBOT-MM WORM!
X
Windows update config
svhost.exe
W32/Sdbot-PF worm infection
X
windows update configurator
svghost.exe
variant of the W32.SPYBOT WORM!
X
Windows Update Controller
mwoffice.exe
TROJ/BATTRY-A TROJAN!
X
Windows Update Files
dnetc.exe
Unidentified VIRUS! Note - wupdmgr.exe is the real Windows Update
X
Windows Update Manager
Winlog0n.exe
TROJ/AGENT-BO TROJAN!
X
Windows Update Manager
wupdate.exe
variant of the WIN32.RBOT WORM!
X
Windows Update Manager
wupdmngr.exe
W32.RANDEX.BTB WORM!
X
Windows Update Manager for NT
wupdmgr32.exe
BACKDOOR.SDBOT.AH WORM!
X
Windows Update Monitoring Service
winupdt.exe
W32/RBOT-PL WORM!
X
Windows Update Process
wmiprvsc.exe
W32/SDBOT-CB WORM!
X
Windows Update Service
csrs.exe
W32/AGOBOT-NI WORM!
X
Windows Update Service
regscv.exe
W32/AGOBOT-AM WORM!
X
Windows Update Service
smcg.exe
SDBOT.QY worm
X
Windows Update Service
SP00ISS.exe
W32/Sdbot-ZH Worm!
X
Windows Update Service
update32.pif
W32/Rbot-ALC WORM!
X
Windows Update Service 2004/2005
systemupdate.exe
Rbot-JE worm infection
X
Windows Update services
wins32svcs.exe
variant of the WIN32.RBOT WORM!
X
Windows Update services
wservices.exe
variant of the WIN32.RBOT WORM!
X
Windows Update Software
system.exe
TOFGER.BX TROJAN!
X
Windows Update System Shell
svhostcs32.exe
W32/RBOT-AAZ WORM!
X
Windows Update V6
??
W32/Rbot-KT worm infection
X
Windows Update.exe
??
"Homepage hijacker, see here"
X
Windows Updater
iexplorerrs.exe
W32/RBOT-TN WORM!
X
Windows Updater
svigost.exe
W32/RBOT-VS WORM!
X
Windows Updater
wupdate.exe
WOOTBOT.AJ WORM!
X
Windows Updater
wupdmgr32.exe
variant of the DOS.AUTOCAT VIRUS!
X
Windows Updater Online
winupdatexx.exe
variant of the WIN32.RBOT WORM!
X
Windows Updates
lsassx.exe
variant of the W32/SDBOT WORM!
X
Windows Updates
w32dns.exe
W32/Sdbot-BFW Worm!
X
Windows Updates
winupd32.exe
W32.MYTOB.CE WORM!
X
Windows Updating Service
updating.pif
W32/RBOT-ALW WORM!
X
Windows Updtee Mgnr
W1NT45K.exe
W32.Mytob.DC WORM!
X
Windows USB controler
winusb.exe
W32/RBOT-HR WORM!
X
Windows USB Driver Support
Windowsusb.exe
variant of the W32.SPYBOT WORM!
X
Windows USB Service
666.exe
W32.MYTOB.AR WORM!
X
Windows USBD
msifirewall.exe
unidentified WORM or TROJAN!
X
Windows User Mode Driver Manager
wdfmrg.exe
W32/Sdbot-ZN Worm!
X
Windows User Starter
winuser32.exe
RBOT.SN WORM!
N
Windows Version Check
ver_chk.exe
"Version checker for CyberAudioLibrary (""A new way to exchange information through the Internet"")"
X
Windows video
vide_32.exe
variant of the GAOBOT/AGOBOT WORM!
X
Windows Video Acquisition (WVA)
wvsvc.exe
AGOBOT.YM WORM!
X
Windows Video Drivers
videons32.exe
GAOBOT.AZT worm
X
Windows Virus Control
plou.exe
W32/SDBOT-ACZ WORM!
X
Windows Web Services
localsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
netsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
spoolsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
svcadmin.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
svcman.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
svcrun.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
tcpsvc.exe
Troj/Dloader-NY Trojan!
X
Windows Web Services
websvc.exe
Troj/Dloader-NY Trojan!
X
Windows Workstation
mpci.exe
variant of the WIN32.RBOT WORM!
X
Windows Workstation
msup32a.exe
variant of the W32/SDBOT WORM!
X
Windows Workstation Service (32-bits)
wkssvc32.exe
variant of the W32/SDBOT WORM!
X
Windows Workstation Start Service
mslanmgr.exe
variant of the WIN32.RBOT WORM!
X
Windows Xp
nortonguard.exe
W32/Mytob-DZ WORM!
X
Windows XP Automatic Update
wXPupdate.exe
W32/Rbot-AFC Worm!
X
Windows Xp Service Pack 2
svchost.exe
Troj/Xplos-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
X
Windows XP SP2 KeyGen
Windows XP SP2 KeyGen.exe
W32/TIBICK-C WORM!
X
Windows_Protect
lsas.exe
RBOT.ARO WORM!
X
Windows_Protect
wincontrol32.exe
W32/Rbot-ADK Worm!
X
Windows_Protect
winregal.exe
variant of the WIN32.RBOT WORM!
X
Windows_Protect
winsystem.exe
variant of the WIN32.RBOT WORM!
X
Windows_Serivce
SERVICE.exe
WOOTBOT.AH worm infection
X
Windows_Updates
svthost.exe
W32.SpyBot worm variant
X
Windows_VXD
user32.exe
PWSTEAL.PPORT VIRUS!
X
windows16
windows16.exe
Troj/VB-XU TROJAN!
X
Windows32
rundll.exe
AGOBOT-LK or AGOBOT-ND WORMS!
X
windows32
windows32.exe
Troj/VB-XU TROJAN!
X
Windows32
wuuaclt.exe
W32.Bratle.B WORM!
X
Windows32 Configuration Loader
msrf32.exe
W32/Sdbot-ABX WORM!
X
Windows32 Messenger Service
msmsgv.exe
RBOT.ANS WORM!
X
Windows32 Net Database
msnd32.exe
W32/RBOT-AAL WORM!
X
Windows32 Serivces
winser32.exe
SPYBOT.AAF WORM!
X
WindowsAgent
sysexhook.exe
GOP keyboard logger/TROJAN!
X
WindowsAgent
WindowsAgent.exe
GOP.G VIRUS!
X
WindowsAPI.DLL
Server5.exe
"""Fear and Hope"" trojan"
X
WindowsBackup
WINDOWSBACKUP.EXE
W32.Stang WORM!
X
WindowsCRC
wscrc.exe
W32/SDBOT-VU WORM!
X
WindowsCriticalUpdate
windows_critical_update.exe
ASTEF or RESPAN VIRUSES!
X
WINDOWSflashbrg
sqldata1.exe
variant of the AGENT-IC TROJAN!
X
Windowsfw
windowsfw.exe
W32/AGOBOT-TA WORM!
X
WindowsFY
bsw.exe
variant of the DESKTOPHIJACK TROJAN! - for removal see here
X
WindowsFY
wp.exe
"Part of a ""Security IGuard"" parasite infestation - also detected as TROJAN.DESKTOPHIJACK and Troj/FakeAle-A Worm!"
X
WindowsFZ
??
W32.Desktophijack Virus! Also see Trojan.Desktophijack.B Trojan!
X
WindowsFZ
A5281300.so
Variant of the SmitFraud alias FAKEALE-C TROJAN!
X
WindowsFZ
zloader3.exe
Variant of the SmitFraud alias FAKEALE-C TROJAN!
X
WindowsKeyUpdate
master.exe
W32.JOSAM WORM!
X
WindowsMGM
Winmgm32.exe
SOBIG and LALA.C VIRUSES!
X
WindowsRegistration
??
W32/RBOT-NO WORM!
X
WindowsRegKey Autoupdate
Explorer.exe
variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Explorer.exe!
X
WindowsRegKey Autoupdate
Iexplore.exe
variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Internet Explorer file!
X
WindowsRegKey upd4te2d4te
??
RBOT.XQ WORM!
X
WindowsRegKey update
??
RBOT.QT WORM!
X
WindowsRegKey update
16winupdate32.exe
variant of the WIN32.RBOT WORM!
X
WindowsRegKey update
svchoosts.exe
RBOT.ADB WORM!
X
WindowsRegKey update
svchostc.exe
RBOT.IF WORM!
X
WindowsRegKey update
wdnupdate.exe
SDBOT.QX WORM!
X
WindowsRegKey update
win2kup2date.exe
SPYBOT.FK worm infection
X
WindowsRegKey update
windns.exe
RBOT.IE WORM!
X
WindowsRegKey update
Windowsup.exe
SDBOT.PU WORM!
X
WindowsRegKey update
winupdat32.exe
W32/RBOT-AGW WORM!
X
WindowsRegKey update
Winupdate.exe
SDBOT.NT WORM!
X
WindowsRegKey update
WinUpdate32.exe
variant of the WIN32.RBOT WORM!
X
WindowsRegKey update
WINUPDATES.EXE
W32/RBOT-MM WORM!
X
WindowsRegKey update
winupdatexx.exe
RBOT.LW WORM!
X
WindowsRegKey update XP
windexv1.exe
W32/RBOT-ABM WORM!
X
WindowsRegKey%$ update
msi332.exe
W32/Rbot-IX worm infection
X
WindowsRegKey%update
ethernet32m.exe
W32/RBOT-EN WORM!
X
WindowsRegKeys update
windup.exe
variant of the WIN32.RBOT WORM!
X
WindowsRegKeys update
winsysi.exe
SDBOT.WE worm infection
X
WindowsSetup
??
EZBOT VIRUS!
X
WindowsSQL service
boner.exe
SDBOT.XRM WORM!
X
Windows-System
System32.exe
LOGPOLE.C VIRUS!
X
Windows-TCP-IP
rfkampig.exe
GIPMA VIRUS!
X
WindowsUpd
WindowsUpd4.exe
VirtuMonde adware
X
WindowsUpd1.exe
WindowsUpd1.exe
VirtuMonde adware
X
WindowsUpd2.exe
WindowsUpd2.exe
VirtuMonde adware
X
windowsupdate
RPCX1sQ3.exe
IRCBOT.B VIRUS!
X
WindowsUpdate
svchost.exe
"number of worms and trojans: TROJ/AGENT-DR , ASTEF , RESPAN and others"
X
WindowsUpdate
svchost.exe
TROJ/AGENT-V TROJAN!
X
WindowsUpdate
svchost.exe /s
Troj/Bdoor-IK TROJAN!
X
WindowsUpdate
USRINIT.EXE
MADDIS.B VIRUS!
X
WindowsUpdate
windows_update.exe
LOHACK.B VIRUS!
X
windowsupdate
winupdate.exe
W32/WARPI WORM!
X
Windowsupdate Service
csrss.exe
"BUCHON.E WORM! **Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling"
X
WindowsUpdate Service
wuautlc.exe
W32/RBOT-NR WORM!
X
WindowsXP Module
DirectX3D.exe
"Malware, reportedly a keylogger - see here"
X
WindowsXP Update
windowsxpupdate.exe
W32/RBOT-PB WORM!
X
WindowsXPserv
svcnxp32.exe
Addee by the NANINF-A TROJAN!
X
Windows-XP-Service-Pack
xpspz.exe
W32/SDBOT-AAC WORM!
X
Windowz
??
VBS.Nukip Worm!
X
Windowz Update V2.0
Explorer.exe
"YODO VIRUS! Note - the valid ""explorer.exe"" is located in C:\Windows or C:\Winnt whereas this one is located in the System32 sub-directory"
X
Windoxs Update Center
W32RfSA.exe
variant of the W32/SDBOT WORM!
X
WinDrg32
windrg32.exe
DRUDGEBOT.A WORM!
X
WinDriv32
WinDriv32.exe
SMALL-BA TROJAN!
X
WinDriver Configuration
windrvconf.exe
AGOBOT-LX WORM!
X
WINDRUN
taskgmrs.exe
W32/MYTOB-BT WORM!
X
windrv
windrv32.exe
Unidentified VIRUS - possibly a strain of OBLIVION or BIONET
X
WinDrv
windrvx.exe
variant of the TIBSER.A downloader TROJAN!
U
WinDSL MTU-Adjust
WinDSL_MTU.exe
Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
X
WinDSNX
??
DNSX VIRUS!
X
WindUpdates
??
AGENT.BF VIRUS!
X
WindUpdates
WinUpdt.exe
Windupdates adware
N
WINDVDpatch
CTHELPER.EXE
"CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative?s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a ""leave alone"" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it"
N
WinDVR SchSvr
SchSvr.exe
"WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs"
Y
WinDVRCtrl
WDVRCtrl.exe
"Driver task installed by the drivers for some TV capture cards; no further information available, so best left alone."
N
WinDVRCtrl
WinDVRCtrl.exe
Control center software for an AOpen VA1000 TV tuner card
X
Windws Configuration Loader
LEXPLORE.exe
SODABOT VIRUS!
X
WinEssential
Keyhost.exe
Hijacker - hailing from jraun.com
X
WinEssential
keyword.exe
Jraun.com hijacker
X
WinExec
WinExec.exe
W32/Falus-A WORM!
X
WinExec
Winexec.exe.vbs
AINESEY.A VIRUS!
X
WinExec32
WinExec32.exe
KAZWIN VIRUS!
U
WinFast Schedule
Wfwiz.exe
Leadtek WinFast TV tuner scheduler
U
Winfast_2K
WF2k.exe
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
U
WinFast_Gamma
??
Loads if you change the gamma settings on Leadtek WinFast graphics cards
U
WinFast_Taskbar
??
Leadtek WinFast graphics cards related taskbar; can be launched manually.
U
Winfast2KLoadDefault
??
Loads default settings for Leadtek Winfast graphics cards
X
WinFavorites
WinFavorites.exe1
Loudmarketing.com adware downloader
N
WinFax PRO Controller
WFXCTL32.EXE
From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
Y
WinFaxAppPortStarter
wfxsnt40.exe
WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
X
WinFire
WF.exe
Troj/Delf-SY TROJAN!
X
WinFixer 2005
wfx5.exe
"""Foistware"", pretending to be system optimization, protection and recovery software - stealth installed, see here"
X
winfont
winfont.exe
Death backdoor trojan infection
U
WinFoxV2
WF2k.exe
System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
X
WinFX
cssrs.exe
AGOBOT.FX WORM!
X
WinGate
WinGate.exe
variant of the LOVGATE WORM!
U
WinGate Engine Monitor
wgengmon.exe
"WinGate Internet Client Dialup Monitor, component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server."
X
WinGate initialize
WinGate.exe
variant of the LOVGATE WORM!
X
wingo
wingo.exe
W32.BEAGLE.AW or W32.BEAGLE.AV WORM!
N
WinGuage Pro
WGPRO32.EXE
"Part of McAfee Nuts & Bolts. ""WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious"". Resource hog. Available via Start -> Programs"
Y
Winguard
WGFE95.EXE
Dr Solomon's Virex antivirus
U
WinGuard Pro
wgp.exe
Winguard_Pro
N
WinHacker
??
"Tweaking utility by Wedge Software. There are?far better?tweakers and, unlike WinHacker, most are free"
X
winhelp
dns32.exe
variant of the WIN32.RBOT WORM!
X
WinHelp
realsched.exe
variant of the LOVGATE WORM! **Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
X
Winhelp
TkBellExe.exe...
variant of the LOVGATE WORM!
X
winhelp
Updadv.exe
Troj/QQPass-N TROJAN!
X
Winhelp
winhe1p.exe
QQPASS.E VIRUS!
X
Winhelp
winhelp.exe
variant of the LOVGATE WORM!
X
WinHelp
WinHelp.exe
variant of the LOVGATE WORM!
X
winhlp.exe
winhlp.exe
PWSTEAL.FORMGLIEDER TROJAN!
X
winhlp3.exe
winhlp3.exe
variant of the Win32/TrojanDownloader.Easto.A TROJAN!
X
Winhlp32
??
GANT.B VIRUS!
X
winhlp32.exe
winhlp32.exe
Win32/TrojanDownloader.Easto.A TROJAN!
X
winhlpp32.exe
winhlpp32.exe
GAOBOT.SY WORM!
X
Winhost
win.exe
Dloader-AP trojan
X
Winhost
winhost.exe
REATLE.F WORM!
X
Winhost
wintt.exe
LOLAWEB.B VIRUS!
X
Winhost
yahoo.exe
TROJ/DELF-KM TROJAN!
X
winhost.exe
winhost.exe
TROJ/LOHAV-R TROJAN! or the W32.Beagle.BY WORM!
X
winhost32.exe
winhost32.exe
Troj/Banito-F TROJAN!
X
WinIeRun
winierun.exe
Troj/RNWatch-A Worm!
X
winimage
wvsvc.exe
RBOT.TX WORM!
X
wininet32
wininet32.exe
Troj/Raznew-A trojan
X
wininetd
wininetd.exe
WINET VIRUS!
X
WinInit
Win86.exe
TROJ/SMALL-PB TROJAN!
X
wininit
wininit.exe
WOLLF.16 VIRUS!
X
winint
winint.exe
W32/Sdbot-ADA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
winipsec
winipsec.exe
Unidentified malware
U
WinIRXHelper
WinIRXHelper.exe
MSI? Media Center Deluxe software - see here
X
winis
winis.exe
W32/RBOT-WI WORM!
X
Wink*.exe
Wink*.exe
version of the KLEZ VIRUS! * represents any random characters
U
Winkb6
winkb6.exe
"Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed"
X
WinKernel
WinKer.exe
MIRAB or SERVIDOR VIRUSES!
X
winkernel32
wWin32.com
Added as the result of the BANSAP VIRUS!
U
WinKey
winkey.exe
"Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos"
X
winldr
??
VIDLO-P TROJAN!
X
winldr
Rechnung.pdf.exe
DOWNLOADER-ACS TROJAN!
X
winlgz2
winlgz2.exe
TROJ/KILLFIL-Q TROJAN!
X
winlibs.exe
winlibs.exe
EVAMAN.C worm
X
WinLibUpdate
libupdate.exe
BIONET series of VIRUSES such as BIONET.31 or BIONET.310
X
WinLibUpdate32
libupdate32.exe
BIONET.405 VIRUS!
X
WinLibUpdte
libupdte.exe
BIONET.318 VIRUS!
X
Winlink
winlink32.exe
GAOBOT.AAY WORM!
X
Winlme
windll.exe
GOP.F VIRUS!
U
WinLoad
Winload.exe
"PCTattletale is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it."
X
WinLoader
??
versions of the SUBSEVEN VIRUS!
X
winlocatorupdate
updatewinlocator.exe
Locator adult content toolbar related
X
winlog manager
winlog.exe
DONBOMB.A TROJAN!
X
WINLOG0N
WINLOG0N.EXE
W32.MYDOOM.BI WORM!
X
winlogin
win32x.exe
"Browser hijacker, also detetected as the TROJ/STARTPA-DF TROJAN!"
X
WinLogin
winlogin.exe
AGOBOT-IX WORM!
X
Winlogin.exe
log.exe
variant of the WIN32.AGENT.AH downloader TROJAN!
X
winlogin.exe
logfile.exe
WIN32.AGENT.AH TROJAN!
X
winlogin.exe
mspaint.exe
variant of the WIN32.AGENT.AH TROJAN!
X
Winlogin.exe
steam.exe
variant of the WIN32.AGENT.AH TROJAN!
X
WINLOGON
??
VBS.Ypsan.F@ mm Worm!
X
WinLogon
logon.exe
AdultBox foistware
X
winlogon
msreg32.exe
SDBOT.EO WORM!
X
winlogon
winlogin.exe
RANDEX.E or P2LOAD.A WORM!
X
winlogon
winlogon.exe
"Hijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file described here"
X
winlogon
winlogon.exe
"TRODAL VIRUS! - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file"
Y
winlogon
winlogon.exe
Windows Logon Process - handles user logons described here
X
winlogon
winlogon32.exe
WIN32/MASLAN.C WORM!
X
winlogon
wpwlogon.exe
unidentified WORM or TROJAN!
X
winlogon service
urx.exe
SPYBOT.EN WORM!
X
Winlogon Shell
??
W32.Kipis.M WORM!
X
Winlogon.exe
??
CoolWebSearch parasite related.
X
winlogon.exe
helper.exe
FAKESPY-A TROJAN!
X
winlogon.exe
msole32.exe
"Adware, detected as the DOWNLOADER-ACZ TROJAN!"
X
winlogon32_
??
W32.Ruland.A WORM!
X
WinLsass
??
W32/WORT-B TROJAN!
X
WinLsass
servicec.exe
SCANE VIRUS
X
winltmpv
winln.exe
TCXMEDI-C TROJAN!
X
winltmpv
wutop.exe
TCXMEDI-C TROJAN!
X
Winmain
winmain.exe
"One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on ""hot standby"", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a ""rogue"" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!"
U
winmatrix.exe
WinMatrixXP.exe
WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
U
WinMem
WinMem.exe
"WinMem Cleaner, part of Ultra_WinCleaner_Utility_Suite . Makes more memory available for your programs and the Operating System. It also defragments your system's physical memory increasing the efficiency of your CPU and motherboard cache, which prevents crashes and accelerates your system's performance."
X
WinMenssage
winmax.exe
BANCOS.B VIRUS!
X
WinMessenger
syshost.exe
W32/OPANKI-E WORM!
N
WinMgmt
WinMgmt.exe
"Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth ""scheduler"" - refer here"
X
WINMGR
taskgmgr.exe
W32.MYTOB.AN WORM!
X
Winmgr.exe
scvhost.exe
AGOBOT.AFG WORM!
X
WinMgr32
winmgr32.exe
W32.MIMAIL.P WORM!
X
WinMine
D4NG3.vbs
BISCUIT.A VIRUS!
Y
winmodem
wmexe.exe
Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
X
WinMoviePlugIn
WinMoviePlugIn.exe
Sfonditalia adult content premium rate dialer
X
WinMsrv32
WinMsrv32.exe
GAOBOT.AFJ WORM!
N
WinMX
WinMX.exe
WinMX file sharing application
N
winmysqladmin or WinMySQLadmin Tool
winmysqladmin.exe
Starts the MySQL database admin tool
X
winnet
winnet.exe
CommonName Toolbar spyware. To uninstall see here
X
WinNetDDE
??
NETDEPIX.B TROJAN!
X
WinNite
niteaim.exe
W32.Opanki.B Worm!
X
winnt DNS ident
iexplorer.exe
variant of the WIN32.RBOT WORM!
X
winnt DNS ident
pidchk32.exe
W32/RBOT-ACY WORM!
X
Winnt DNS ident
windowsp.exe
RBOT.BAL WORM!
X
winnt DNS ident
windowxp.exe
variant of the WIN32.RBOT WORM!
X
winnt DNS ident
Winupd32.exe
RBOT.AVU WORM!
X
winnt DNS ident
winupdate32.exe
variant of the WIN32.RBOT WORM!
X
winnt DNS ident
wuamgrd32.exe
W32/RBOT-BAU WORM!
X
winnt DNS ident
wuamgrd33.exe
variant of the WIN32.RBOT WORM!
X
winNT updatc
wupgrd.exe
variant of the WIN32.RBOT WORM!
X
WinNtBB
WinntBB.exe
DULOAD.C VIRUS!
X
Winnup
win32nls.exe
variant of the W32.SPYBOT WORM!
X
winocx32
winocx32.exe
Win32.Protoride.I WORM!
X
WINOWS SYSTEM
winnt.exe
MYTOB.ID WORM!
X
Winpack
winpack.exe
Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg
U
WinPatrol
WinPatrol.exe
"WinPatrol - ""Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"""
X
winphonics7536
??
Mutin-C IRC backdoor trojan infection
X
winpipe
winpipe.exe
Browser hijacker redirecting to wow-access.com
U
WinPLOSION
WinPlosion.exe
"WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop."
Y
WinPoet
WinPPPoverEthernet.exe
"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking"
N
WinPopup
WINPOPUP.EXE
"Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won\'t set itself up to run unless the user specifically adds it to startup"
X
winpopup
winupie.exe
Adware by Tradeexit.com
X
Winprocer32 Update
winprocer32.exe
RBOT.GW WORM!
X
winprocessor Update
winprocessor.exe
RBOT.IO WORM!
X
WinProfile
Command.exe
BUDDY VIRUS!
X
winprofile
iexpiore.exe
variant of the MONCHER WORM!
X
WinProfile
iexpIore.exe
Troj/Chum-C Trojan!
X
WinProfile
sndcfg16.exe
Win32.Sndc.A worm
X
WinProt
Winprot.exeserver.exe
CHUPACABRA VIRUS!
X
winprotect
win32.exe
W32.MUGLY.E WORM!
X
winprotect
winprotect.exe
W32/SDBOT-SB WORM!
U
WinProxy
WinProxy.EXE
"""WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"""
X
Winproxy Personal
WINPROXY.EXE
SDBOT.BMF WORM!
X
winpsd
winpsd.exe
W32.Mydoom.Q WORM!
X
winpup32
Winpup32.exe
ADCLICKER VIRUS!
X
winrapid
winrapid.exe
variant of the WIN32.RBOT WORM!
X
winrar
winrar.exe
CoolWebSearch parasite related.
X
winrarshell
winrarshell32.exe
PWSteal.Salira TROJAN!
X
winReg
winReg.exe
YAHA.H or YAHA.J VIRUSES!
X
winreg_32
??
Troj/Banker-DB Trojan!
X
winreg_32
svchosst.exe
BANCOS-CE TROJAN!
X
winreg_32
sysdll.exe
TROJ/DLOADER-IJ TROJAN!
X
winreg_32
Vc030405.exe
TROJ/BANCOS-CT TROJAN!
X
winregsrv
winregsrv.exe
SYNRG VIRUS!
U
WINREMOTE
WinRemote.exe
InterVideo WinCinema Manager - needed for the use of WinDVD_Remote_Control
X
Winres32vis
??
THRAX.A VIRUS!
X
winrestore1
winrestore.exe
TROJ/KILLFIL-Q TROJAN!
X
winreups
winreups.exe
variant of the WIN32.RBOT WORM!
N
winroute
winroute.exe
"Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k"
X
winrun
msconfig.exe
WINUR VIRUS! Note - this is not the real msconfig.exe
X
WINRUN
svchost32.exe
W32/MYTOB-AI WORM!
X
WINRUN
taskgmr.exe
W32/MYTOB-BX WORM!
X
WINRUN
taskgmr32.exe
W32.MYTOB.AP WORM!
X
WINRUN z
W1NT45K.exe
W32.Mytob.BL WORM!
X
WinRunners
WinDrivers.exe
DULOAD.C VIRUS!
X
Wins Update 32
services32.exe
W32/Forbot-FN WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
X
Wins32 Online
cfgpwnz.exe
W32.Bropia.R WORM!
U
Winscheduler
WINSCH~1.EXE
InterVideo WinDVR scheduler
X
WinScMngr
winsmc.exe
W32/SDBOT-BPZ WORM!
X
WinSec
winsec16.exe
AGOBOT.ZF WORM!
X
winsecure
winsecure.exe
"Browser hijacker, redirecting to specificsearches.com"
X
Winsecure Antivirus
Secureantivirus.exe
variant of the W32.SPYBOT WORM!
X
WinSecured32
ssmr.exe
variant of the W32/FORBOT WORM!
X
Winserv
Winserv.ila
W32.NODMIN WORM!
X
winserver
Server.txt.vbs
DELTAD.A VIRUS!
X
Winservice
winmain.exe
porn related malware
U
WinService32
ssmgr.exe
"007 Spy Software - ""stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"""
X
WinService32
svchost.exe
"007_Spy_Software keystroke logger/monitoring program. remove unless self installed! - NOTE - this file is placed in a Program Files\Common Files\Microsoft Shared\DAO\System32 folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
WinServices
WinServices.exe
YAHA.K or YAHA.M VIRUSES!
X
winservit
cassl.exe
de RBOT.ASG WORM!
X
winservn
winservn.exe
PurityScan/Clickspring adware
X
winservs
winservs.exe
PurityScan/Clickspring adware
X
WinSetBrowse
BasicUpdate.dll.vbs
BISCUIT.A VIRUS!
X
winshost.exe
winshost.exe
Tooso or Tooso.B or Tooso.C or Tooso.D or Tooso.E and Trojan.Tooso.I TROJANS!
"Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version"
X
WinSig
NetXP.exe
TROJ/BANKER-FN TROJAN!
X
winsock
svch0st.exe
"SAGE-A WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number ""0"" in the executable filename, not a lower/upper case O."
X
Winsock driver
winnt update.exe
TROJ/SPYBOT-DM TROJAN!
X
Winsock driver
winnt64.exe
W32/Spybot-DR WORM!
X
winsock2
netsvr.exe
AGOBOT.LY WORM!
X
Winsock2 driver
??
SDBOT.T WORM! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program
X
Winsock2 driver
AMSNMGR.EXE
variant of the W32.SPYBOT WORM!
X
Winsock2 driver
MIRC32.exe
SPYBUZZ VIRUS!
X
Winsock2 driver
SDJOIJE.EXE
SPYBOT.DR VIRUS!
X
Winsock2 driver
SPOLSV.EXE
W32/SPYBOT-CM WORM!
X
Winsock2 driver
sysreq.exe
W32/SPYBOT-CC WORM!
X
Winsock2 driver
wincfg.exe
SPYBOT.CO WORM!
X
Winsock2 driver
WINCFG.SCR
W32.SpyBot worm variant
X
Winsock2 driver
winupdate.exe
Spybot-BX worm infection
X
Winsock2 driver
WUAUMQR.EXE
W32/SPYBOT-DP WORM!
X
Winsock2 driver
Zonealarmupdate.exe
variant of the W32.SPYBOT WORM!
X
Winsock2.dll
WINLODR.SCR
unidentified VIRUS!
X
Winsock32 driver
Testing.exe
SPYBOT.B VIRUS!
X
Winsock32driver
sp2XPupdate.exe
BKDR_HACKARMY.S TROJAN!
X
Winsock32driver
svchhost.exe
BKDR_HACKARMY.I TROJAN!
X
Winsock32driver
win32server.exe
BackDoor-AZV TROJAN!
X
Winsock32driver
win32server.exe
HACARMY.F TROJAN!
X
Winsock32driver
win32server.scr
HACARMY TROJAN!
X
Winsock32driver
winXPupdate.exe
HACKARMY.9728 TROJAN!
X
Winsock32driver
ZoneAlarmPr0.exe
Hackarmy-B trojan infection
X
Winsock32driver
ZoneLockup.exe
Hacarmy.D trojan infection
X
winsockdriver
bot.exe
W32/WarPigs-D WORM!
X
winsockdriver
iexplor.exe
W32.BLATIC.A WORM!
X
winsockdriver
tskmg.exe
SDBOT.GEN or WARPIGS.C WORMS!
X
winsockdriver
winsock2.2.exe
variant of the SPYBOT VIRUS!
X
winsockdriver
winsock3.exe
W32/SPYBOT-DO WORM!
X
WinSocketComponent
nthost.exe
unidentified VIRUS!
U
WINSOS VERIFY
WINSOS.EXE
"WinSOS - ""deletes spyware, optimizes your computer - backs up selected data"""
X
WinSP
??
"Hijacker, variant of the TROJ/STARTPA-ME TROJAN!"
X
winspd32dll
winspd32.exe
variant of the AGOBOT/GAOBOT WORM!
X
WinSPF
windrv32.exe
W32.Mydoom.V WORM!
X
WinSPF
winspf32.exe
W32.Mydoom.P WORM!
X
Winspl
winsplx.exe
variant of the TROJ/TROLL-A TROJAN!
X
Winspool
spoolsvr.exe
variant of the W32/SDBOT WORM!
X
WinSrv
kn0x.exe
HOBBIT.F VIRUS!
X
WinSrv
SHIZZLE.EXE
HOBBIT.C VIRUS!
X
Winsrv
winsrv.exe
OPASERV.T VIRUS!
X
WinsSystem
syssmss.exe
BKDR_DELF.IG TROJAN!
X
Winsta~1
winsta~1.exe
GoHip foistware
X
WinStabilizer
WinStabilizer.exe
W32/Agobot-SW Worm!
X
WinStart
??
CIAN.C VIRUS!
X
WinStart
services.exe
"W32.SOBER.O WORM! - Note - this file is placed in a ""%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
WinStart
WinStart.exe
"FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing ""car"" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge"
X
winstart
winstart.exe
TROJ/SCKEYLO-AB TROJAN!
X
WinStart
WinStart.pif
CONE.E VIRUS!
X
WinStart
winstart32.exe
PUROL VIRUS!
X
WinStart001 or WinStart001.EXE
WinStart001.exe
"FromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing ""car"" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge"
X
winstats
winstats.exe
Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
X
WinSth16
WinSth16.exe
CAKE VIRUS!
X
winstro
RUN32DLL.exe
FTP_ANA VIRUS!
X
WinSvc16.exe
WinSvc16.exe
BACKDOOR.SDBOT.FQ TROJAN!
X
winsvc32.exe
winsvc32.exe
GREPAGE TROJAN!
X
Winsvr manager
DDEsvr.exe
W32/TIRBOT-C WORM!
X
winsy32.exe
winsy32.exe
"Trojan, CoolWebSearch parasite related"
X
winsync
??
variant of the QOOLOGIC TROJAN!
X
WINSYS
??
TROJ/BANKER-ER TROJAN!
X
winsys
exploer.exe
TROJ/SPYVB-C TROJAN!
X
winsys
syschost.exe
unidentified TROJAN!
U
Winsys
Winsys.exe
"Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it?"
X
WinSys32
Winsys32.exe
CIGIVIP or RECKUS VIRUSES!
X
WinSys32
Winsys32.exe
BACKDOOR.CIGIVIP TROJAN!
X
WinSys32
Winsys32.exe
W32.HLLW.RECKUS or W32/SDBOT-YL WORMS!
X
winsys32 Driver
winsys32.exe
Loony-O trojan infection
U
WinSysAppMon
WinSysRM.exe
Home & Family Content Filter related. See here
X
winsyslog lptt01
winsyslog.exe
"Variant of the RapidBlaster parasite (in a ""Winsyslog"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
WinSysStartUpWKbLw
TaskSystemDll.Exe
BACKZAT.G VIRUS!
X
WinSyst32
winsyst32.exe
MORB VIRUS!
X
WinSystem
winsystem.exe
WHITEBAIT VIRUS!
X
Winsystem
winsystem.exe
BANCOS.CR trojan infection
U
WinSystem
WinSystems.exe
CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
X
winsystem.sys
smss.exe
W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
X
WINT
??
PurityScan/Clickspring adware
X
WINTASK
iexplorer.exe
W32/MYTOB-CH WORM!
X
WINTASK
msmgrxp.exe
W32.MYTOB.AQ WORM!
X
WINTASK
msvhost.exe
W32/Mytob-AR Worm!
X
WINTASK
sys32.exe
W32.MYTOB.K WORM!
X
WINTASK
sys32.exe
W32/MYTOB-F WORM!
X
WINTASK
t4skgmr.exe
W32.MYTOB.CM WORM!
X
WINTASK
t4skmgr.exe
W32/Mytob-AK Worm!
X
WINTASK
taskfile.exe
W32.Mytob.EF WORM!
X
WINTASK
taskgamr.exe
W32.MYTOB.AU WORM!
X
WINTASK
taskgm.exe
W32/Mytob-AO Worm!
X
WINTASK
taskgmr.exe
W32.MYTOB.I or W32.Mytob.BH and W32/Mytob-AC WORMS!
X
WINTASK
taskgmr32.exe
W32/MYTOB-AK WORM!
X
WINTASK
taskgmr32.exe
W32.Mytob.BU WORM!
X
WINTASK
taskgmr32.exe
W32/Mytob-AK Worm!
X
WINTASK
taskgmrs.exe
W32.Mytob.DH WORM!
X
WinTask
Wintask.exe
HIPO or LEMIR.F VIRUSES!
X
WinTask
wintask.exe
Affilred.B adware
X
WINTASK
yahooicons.exe
W32/MYTOB-HM WORM!
X
WINTASK DLL
jusched32.exe
W32.MYTOB.AI WORM!
X
WINTASK DLL
RealPlayer Ath Check
W32.MYTOB.AG WORM!
X
WINTASK DLL32
smsrss.exe
W32.MYTOB.BS WORM!
X
WinTask driver
wintask.exe
TROJ/DLOADER-NA TROJAN!
X
WINTASK32
taskgmr32.exe
W32.MYTOB.BN WORM!
X
WINTASK32
taskgmrr.exe
W32.Mytob.FX WORM!
X
WINTASKMANAGER
taskgmr.exe
W32/MYTOB-AF WORM!
X
WINTASKMGR
ccsrs.exe
W32.MYTOB.Q WORM!
X
WINTASKS
taskgmr.exe
W32.MYTOB.BO and W32.Mytob.DO WORMS!
X
WINTASKS
winxpro.exe
W32.Mytob.EZ WORM!
X
WinTasks DLL Library (32-bits)
winkll.exe
W32/Rbot-AJZ WORM!
U
WinTasks Traybar
wintasks.exe
"WinTasks - ""Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before"""
X
wintasks.exe
wintasks.exe
Evaman worm
X
Wintbp.exe
wintbp.exe
W32.Zotob.E WORM!
X
Wintbpx.exe
wintbpx.exe
W32.Zotob.F WORM!
U
wintective
wintective.exe
"Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it."
X
winter
happy.exe
W32/SDBOT-YF WORM!
N
Wintercooler Pro
WINCOOL.EXE
"Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed"
N
WinTidy
WinTidy.exe
Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs
U
WinTime
wintime.exe
WinTime Located in the Windows directory.
X
Wintime
Wintime.exe
Harnig TROJAN!
N
Wintime Wtxpload
Wxpload.exe Wintime
"Part of the software to support a Dexxa USB graphics tablet. From a visitor - ""This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG"""
X
WinTimer
msupdate.cmd
"Hijacker, detected by Kaspersky antivirus as Trojan.Win32.StartPage.tj"
X
wintnask32.exe
wintnask32.exe
W32/Rbot-AFP Worm!
X
wintnl
wintnl.exe
variant of the W32.ZOTOB.K WORM!
X
wintnl.exe
wintnl.exe
W32.Zotob.K WORM!
X
wintnpx.exe
wintnpx.exe
W32.ZOTOB.H WORM!
X
WinTools
WToolsA.exe
WinTools adware
N
WinTOTAL Scheduler
guru.exe
WinTOTAL Real estate appraisal software related
X
WinTray
wintray.exe
LEGUARDIEN.B VIRUS!
X
wintsk32dll
wintsk32dll.exe
W32/RBOT-AAJ WORM!
X
winudll.exe
winudll.exe
Troj/Mitglie-CE TROJAN!
X
winupated.exe
winupated.exe
variant of the W32/SDBOT WORM!
X
winupd
??
MOTA.A VIRUS!
X
winupd.exe
winupd.exe
BEAGLE.M or BEAGLE.N WORMS!
X
WinUPD32
explorer.exe
Unidentified VIRUS!
X
winupdat
winupdat.exe
Win32.Canbot.A worm
X
WinUpdate
RBSKQQBO.EXE
VBS.Vbswg2b.A VIRUS!
X
WinUpdate
updsys.exe
variant of the WIN32.RBOT WORM!
X
winupdate
winupdate.exe /auto
WIN32.ALCAN.B WORM!
X
WinUpdate
wmbem.exe
REVCUSS.B VIRUS!
X
WinUpdate Loader
msnnm.exe
UPCHAN TROJAN!
X
winupdate.exe
winupdate.exe
RADO VIRUS!
X
winupdate_
??
W32.COMDOR.A WORM!
X
winupdate2846
??
Mutin-C IRC backdoor trojan infection
X
WinUpdateB
breatle.exe
W32.Bratle.A WORM!
X
winupdateconn
??
W32/COMBRA-A WORM!
X
winupdateconn_
Explorer.EXE
W32/Combra-B WORM!
X
winupdatefiv_
??
COMBRA.C WORM!
U
WinUpdateProtection
csrss.ex
EmployeeWatch is a commercial spyware program designed to monitor user activity on a computer.
U
WinUpdateProtection
csrss.exe
"ICE_Remote_Spy monitoring software, ""secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you."" - Note - this file is installed in a C:\Windowsupdate\Ufp\Irs7 folder, and it is NOT the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which is located in the System32 directory."
X
winupdates
winupdates.exe /auto
W32.Alcra.B WORM!
X
WinUpdsv
winupdsv.exe
X97M.DROPO Macro VIRUS!
X
winupdt
??
Mabutu.a WORM!
X
winupdtl
winupdt.exe
2nd-thought adware variant
X
winupdtl
winupdtl.exe
SecondThought adware variant
X
WinUpgrader
??
Troj/Agent-DZ Trojan!
X
winusb.dll
winguard.exe
W32/FORBOT-CN WORM!
X
WinUser32K
usr32wink.exe
Win32.VB.hk backdoor TROJAN!
X
WinUsr
WinUsr.exe K1S2
W32.CLUNK.A WORM!
X
Winux Piriax Service
PH32.EXE
RANDEX.G VIRUS!
X
winversion
winversion.exe
"Browser hijacker, redirecting to specificsearches.com"
X
WinVNC
iexplorer.exe
EVIVINC VIRUS!
U
WinVNC
WinVNC.exe
WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet
X
winvxd32
winvxd32.exe
W32.Gabloliz.A WORM!
X
winwan lptt01 or winwan ml097e
winwan.exe
"Variant of the RapidBlaster parasite (in a ""Winwan"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
winword
winword.exe
Troj/Torpid-C TROJAN!
X
winXP
33.exe/background
W32.ANPES WORM!
X
WinXP
plugin1.exe
Downloader-JW TROJAN!
X
win-xp
nvsc32.exe
W32.Bropia.N WORM!
X
win-xp
winis.exe
BROPIA.O WORM!
X
win-xp
winis.exe
W32.Bropia.N WORM!
X
WinXP fix
??
BACKDOOR.RANKY.P TROJAN!
X
WinXp Updater
winxp32.exe
W32/RBOT-HG WORM!
X
WinXP-98
CSRSS.exe
"Troj/Banker-DS TROJAN! Note:This is NOT the legitimate Windows CSRSS.exe process, which should NOT figure in Startup!"
X
winxpdll32.exe
winxpdll32.exe
variant of the Win32.SMALL downloader TROJAN!
X
WinXPHome
plugin2.exe
malicious VBS_INOR.T script!
U
WinXPLoad
"Rundll32 LoadDll, LoadExe WinXPLoad.exe"
Compaq hotkey related - required if you use the hotkeys
X
winxpusbd
winxp64.exe
variant of the WIN32.RBOT WORM!
X
winzip
??
BANCOS.G VIRUS! Note - not the popular WinZip file compression utility
X
Winzip
??
W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
N
WinZip Quick Pick
WZQKPICK.EXE
"Added with WinZip version 8.1. ""The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself."". You can right-click and close it - choosing to not re-load it at start-up"
X
WinZip Update
WinZip.exe
variant of the WIN32.RBOT WORM!
X
WIP Config GUI
Winipcfgs.exe
W32/RBOT-CN WORM!
U
Wireless PCI Card Configuration Utility
WMP11Cfg.exe
Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
X
Wireless Provider Server
wpsvr.exe
W32/Forbot-AD worm infection
Y
Wireless-G Notebook Adapter
Gcc.exe
LinkSys Wireless-G Notebook Adapter diver
U
Wireless-G Notebook Adapter Utility
WPC54CFG.EXE
Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
U
Wise-FTP Scheduler
WF_Scheduler.exe
WISE-FTP file transfer software scheduler
N
wjview
wjview.exe
MS tool used to view window-based Java applications from the command line
N
wkcalrem
wkcalrem.exe
Produces a pop-up reminder of events scheduled using the MS Works Calendar
N
WkDetect
WkDetect.exe
Checks for updates to MS Works
N
wkfud
wkfud.exe
A marketing program for MS Works
N
WksSb
WksSb.exe
The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
X
WksSVC
EXPLORER.exe
"W32/MYTOB-BW WORM! - NOTE - the valid ""explorer.exe"" will always be located in C:\Windows or C:\Winnt folder whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)"
N
WkUFind
WkUFind.exe
"MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site"
X
Wlan Drier
Winusb2.exe
WOOTBOT.DC WORM!
X
Wlan Driver
avscan.exe
WOOTBOT.DH WORM!
N
WLAN Status Tray Applet
WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN
Y
WLAN_Cfg.exe
WLAN_Cfg.exe
Linksys Instant Wireless USB Network Adapter driver
U
wlancfg
wlancfg.exe
Inventel wireless router related - required in order to automatically connect to the Net at bootup.
N
WLANSTA.EXE
WLANSTA.EXE
System Tray icon for checking the status of a Wireless LAN
Y
Wm24Pan
Wm24Pan.Exe
ESI external sound card driver
X
wm41a398
??
LZIO.com adware downloader
X
WMAudio
services.exe
NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
X
WMAudio
winlogon.exe
Neveg.A worm
N
WMBoot
??
Associated with Logitech Wingman game controllers. Not required but what does it do?
X
wmcbaaca
??
LZIO.com adware downloader
X
WMI Application Interface
wmiapi.exe
W32.SPYBOT.RBY WORM!
U
WMIEXE.exe
wmiexe.exe
"NT component, used by Windows Millennium to detect? Plug and Play-compliant IEEE 1394 devices during the startup process.?Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading"
X
Wminf
Wminf.exe
GEMA TROJAN!
X
Wminfo
Wminfo.exe
GEMA TROJAN!
X
wmiprv
wmiprv.exe
W32/RBOT-WM WORM!
X
wmon
jusched.exe
W32/AGOBOT-OW WORM!
Y
WMP54Gv4
WMP54Gv4.exe
Linksys WMP54G Wireless-G PCI Adapter driver
X
wmplayer.exe
wmplayer.exe
Troj/Bancban-CZ TROJAN!
X
wmsys32
wmsys32.exe
BANPAES.B VIRUS!
X
wmv
winmonv.exe
TROJ/AGENT-DG TROJAN!
X
WNAD
WNAD.EXE
"Spyware running a program called ""Yo Mama Osama"" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like"
X
wnddrv
svchost.exe
"Aded by an unidentified TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
WNSC
??
PurityScan/Clickspring adware
X
Wnsck2 driver
wlogf.exe
W32/SPYBOT-AF WORM!
X
WNSI
??
PurityScan/Clickspring adware
X
WNSI
wnscpsu.exe
PurityScan/Clickspring adware
X
WNSI
wnscpsv.exe
PurityScan/Clickspring adware
X
WNST
??
PurityScan/Clickspring adware
X
wntlgns
wntlgns.exe
CoolWebSearch parasite related TROJAN!
X
won update
WAPDATE.EXE
WIN32.RBOT.N WORM!
N
WooCnxMon
CnxMon.exe
Wanadoo ISP software related - not required - here's how to bypass it.
N
WOOTASKBARICON
TaskbarIcon.exe
Wanadoo ISP taskbar icon - not required
N
Woowatch
Watch.exe
"Wanadoo ISP software, not required"
X
word pair
bopotsvr.exe
TROJ/SHED-A TROJAN!
Y
WordQ carat flag
WordQcrs.exe
Related to WordQ Writing Aid Software
N
WordWeb
wweb32.exe
WordWeb - free theasaurus and dictionary. Start manually
X
Working System Analyzer
syswork.exe
W32/FORBOT-FZ WORM!
X
worknote1
??
W32.Meetot WORM!
N
Works Calendar Reminder
wkcalrem.exe
Produces a pop-up reminder of events scheduled using the MS Works Calendar
N
WorksFUD
wkfud.exe
A marketing program for MS Works
U
Workstation Scheduler
wm95.exe
"Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog"
X
Workstation Services
wrkstn.exe
W32/RBOT-OJ WORM!
X
Workstation Ver 5.0
vmware.exe
W32/RBOT-AHB WORM!
U
Worm Detector
wd.exe
Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam
X
wormexe
winstart.exe
EARLYBIRD VIRUS!
X
wovax
wovax.exe
Win32.Daqa.A trojan
X
wow
bar.exe
"Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g"
X
wow
wwf.exe
TROJ/LINEAGE-Y TROJAN!
N
Wpctrl or wpctrl95
wpctrlnt.exe wpctrl95.exe
"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties"
Y
WPCycle.exe
WpCycleWin.exe
"Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)"
X
wpds.exe
doriot.exe
TROJ/SMALL-KY TROJAN!
X
wpwmgrs
wpwmgrs.exe
W32/MYTOB-DH WORM!
X
WQK
WQK.exe
version of the KLEZ VIRUS!
N
WrCtrl
WrCtrl.exe
"Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time"
X
WRDialer
WrDialer.exe
WinPoet DSL dialler
U
wrexec
wrexec.exe
"Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online"
X
ws2_32
svchst.exe
TROJ/VOKEN-A TROJAN!
X
ws2help
ws2help.exe
variant of the TROJ_SMALL.AN downloader TROJAN!
X
WSAConfiguration
csrsvcs.exe
AGOBOT.VI WORM!
X
WSAConfiguration
drrss.exe
variant of the AGOBOT/GAOBOT WORM!
X
WSAConfiguration
ntguard32.exe
variant of the AGOBOT/GAOBOT WORM!
X
WSAConfiguration
rpcxmn32.exe
AGOBOT.ABG WORM!
X
WSAConfiguration
svchostt.exe
AGOBOT.ZT WORM!
X
WSAConfiguration
win32upd.exe
variant of the WIN32.RBOT WORM!
X
WSAConfiguration
winlogon32.exe
W32/AGOBOT-WC WORM!
X
WSAConfiguration
wmon32.exe
W32.Gaobot.BAJ WORM!
X
WSAConfiguration1
csass.exe
AGOBOT.WH WORM!
U
WScheduler
WScheduler.exe
"Windows Scheduler - ""schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events."""
X
wscript.exe
vabian.vbs
VABI VIRUS!
X
Wsdata service
WSconf.exe
SDBOT.ZU WORM!
X
wserver
wserver.exe
W32.NETSKY.AC WORM!
U
WService
WService.exe
Tablet client Driver for UC-Logic Pen/Graphics Tablet
U
wsg32
wsg32.exe
GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!
U
wskrnl
wskrnl.exe
Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself.
X
wsock32
svchost.exe
"TROJ/HORST-A WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
wsock32
wsock32.exe
unidentified WORM or TROJAN!
X
WSSAConfiguration
wmmon32.exe
W32/Agobot-KC WORM!
U
wssys
wssys.exe
WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it
X
Wstat32 driver
Wstat32.exe
LOONBOT VIRUS!
Y
wstimeb
wstimeb.exe
Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
U
WSVCS
SERVICES.EXE
WALogger is a spyware program that logs keystrokes. If you didn't install this yourself remove it.
Y
wswpd
wswpd.exe
"Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a ""memory leak"". Needed for printing to work?"
U
wsys.exe
wsys.exe
"SpyloPCMonitor is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it."
N
WT Game Channel
GameChannel.exe
"Wild Tangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case"
N
WT GameChannel
wtgamechannel.exe
"Wild Tangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case"
X
WTF Test
wtftest.exe
W32/RBOT-ACM WORM!
U
WTIndicator
SchedInd.exe
WinTask - software that automates a variety of routine tasks quickly and simply
X
WTSI
wapisvit.exe
PurityScan/Clickspring adware
X
WTSS
??
PurityScan/Clickspring adware
X
WTSS
wapicc.exe
PurityScan/Clickspring adware
X
WTSS
wapiit.exe
PurityScan/Clickspring adware
X
WTSS
wapisu.exe
PurityScan/Clickspring adware
X
WTSS
wapisvsu.exe
PurityScan/Clickspring adware
X
WTST
wapisvtr.exe
PurityScan/Clickspring adware
X
wuanguard
wuanguard32.exe
W32/RBOT-AAF WORM!
Y
WUOLService
WUOLService9x.exe
Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)
X
wuosdial
wuosdial.exe
variant of the WIN32.RBOT WORM!
X
WUPD
iglmtray.exe
TZET VIRUS!
X
wupd
symcsvc.exe
ABWIZ.C TROJAN!
X
wupd
win32.exe
TROJ/ORSE-C TROJAN!
X
wupdate
wi32.exe
"Downloader trojan, detected by Panda antivirus as Adware/Trustbid"
X
wupdate
wisvccz.exe
TROJ/ORSE-B TROJAN!
X
Wupdate driver
??
variant of the W32.SPYBOT WORM!
X
Wupdm32
Wupdm32.exe
W32.MIDLAK WORM!
X
wupdt
wupdt.exe
IMISERV.A TROJAN!
Y
WUSB11B.exe
WUSB11B.exe
Linksys WUSB11 WLAN USB adapter
Y
WUSB54Gv2
InvokeSvc3.exe
Wireless-G USB Wireless Network Adapter related - would appear to be required
Y
WUSB54Gv4
WUSB54Gv4.exe
Wireless-G USB Wireless Network Adapter related - would appear to be required
X
wuviewer
wuviewer.exe
Proxy_Trojan variant
X
wvsvc
wvsvc.exe
AGOBOT.YM WORM!
X
WWKS
wsass.exe
W32/SDBOT-BT WORM!
X
www.hidro.4t.com
enbiei.exe
BLASTER.F VIRUS!
X
www.symantec.com
oz11111.exe
W32.Mydoom.W WORM!
X
WXcmeinst
??
RANCK-CD TROJAN!
X
Wxp4
Norton Update.exe
W32.ERKEZ.D WORM!
N
WXProcMgr Module
WXprocMgr.exe
"TVTonic from Wavexpress - ""enjoy 3 full-screen, DVD-quality video channels for FREE"". Allows data content to be downloaded and synchronized on your system"
X
wzhelper
wzhelper.exe
Searchcentrix hijacker
X
wzservice
hess.exe
Backdoor.Win32.Hackarmy.w TROJAN!
U
X Server
X.exe
"""XoftWare for Windows"" enables you to run network-based UNIX programs (""X programs"" or ""clients"") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a network"
U
X10 Device Network Service
x10nets.exe
Belongs to X10 video streaming device(s).
X
X10Weax
WTHRTRAY.EXE
"WeatherCheck ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads, and contains no uninstaller."
U
x3watch
x3watch.exe
"""program helping with online integrity. Whenever you browse the internet and accesses a site which may contain questionable material, the program will save the site name on your computer. Approximately every 30 days, a person of your choice (an accountabiltiy partner) will receive an e-mail containing all possible questionable sites you may have visited within the month. This information is meant to encourage an open and honest conversation between friends and help us all be more accountable"""
X
x3yy
??
TANNICK trojan infection
N
Xanadu
Xanadu.exe
Xanadu - free language and translation wizard from Foreignword
U
X-Cleaner Deluxe
xcleaner.exe
X-Cleaner_Deluxe - privacy and anti-spy application
U
X-Cleaner Freeware
XCLEAN~1.EXE
X-Cleaner_Freeware
X
Xcpy1
Xcpy1.exe
BroadcastPC adware variant
X
xdxqa
dewa.exe
W32/SDBOT-YB WORM!
U
XE 8x LM Status
lmsxxe.exe
Xerox XE8 series laser printer status monitor
X
Xecuter.bat
psexec.bat
BOOHOO VIRUS!
N
XemiCo
ADC.EXE
XemiComputers Active Desktop Calendar
N
Xfire
Xfire.exe
Terratec DMXFire 1024 soundcard controlpanel
X
xflash
xflash.exe
TROJ/BANCJ-A TROJAN!
X
xftpGraber
Xftpgraber.exe
W32.ENVID.C WORM!
N
X-Grabber
sswizard.exe
ScreenShot Wizard
X
xhi
xhi.exe
Troj/SCLog-A TROJAN!
X
xhrmy
Xhrmy.exe
HyperLinker adware
X
XiD
mmx.exe
ANALOGX VIRUS!
Y
XircWinModem4
ltcm000c.exe
WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
U
xitami
Xiwin32.exe
Xitami Multiplatform Open Source web server
X
xload32
netdd.exe
NETSPY TROJAN!
X
XML Service
msxml.exe
W32/RBOT-HD WORM!
X
XNSearchAssistant
SrchAsst.exe
iWon Search Assistant - spyware
U
XoftSpy
XoftSpy.exe
XoftSpy antispyware software
X
xor
svchost.exe
XORDOOR TROJAN! This is not the valid svchost.exe as described here
X
xp
winis.exe
W32/RBOT-WO WORM!
X
xp service pack 2
xpsp2.exe
Sdded as result of a W32/Rbot-KW worm infection
X
xp_system
services.exe
"Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!"
X
xp_system
services.exe
W32.Conycspa.G WORM!
X
xp_system
winlogon.exe
"Krepper-G trojan, a CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!"
X
xp32win
xpupdater02.exe
TROJ/MOSUCK-A TROJAN!
X
XPCPHOST Settings
xpcphost.exe
variant of the WIN32.RBOT WORM!
X
xpiupdate
xpiupdate.exe
W32/RBOT-AAB WORM!
X
xpiupdate
xpiupdate.exe
W32/RBOT-AFY WORM!
X
XPSoft
CVDAsDW.exe
W32/SDBOT-SY WORM!
X
XPSP2 Firewall
xpsp2fw.exe
WIN32.SMALL.RN downloader TROJAN!
X
xpstart
wini.exe
W32.PICRATE.A WORM!
X
xpstat
winlogins.exe
W32/RBOT-AAR WORM!
X
XPsys
XPsys.exe
DELF-KQ or Troj/Dloader-SG TROJAN!
X
xpsystem
MSXMIDI.EXE
"CoolWebSearch parasite variant, identified by Kaspersky_antivirus as TrojanDropper.Win32.Small.cw"
X
xpsystem
services.exe
CoolWebSearch parasite related.
X
xpsystem
y.exe
CoolWebSearch parasite related
X
xpupdate
updates.exe
W32.Bropia.L WORM!
X
xserv
??
Troj/Stumpy-A TROJAN!
U
XStop95
XStop95.exe
XStop - internet filter
N
xswin
xswin.exe
"Installed with a Xerox Work Centre Pro 555. Unchecking it removes an ""out of system memory"" error"
X
XTN Service Drivers
winxtn.exe
W32/Sdbot-YK WORM!
U
XTNDConnect PC - 3CmPlm
Autodet.exe
Component of EasySync Pro. Synchronisation between Palm PDAs? and Microsoft Outlook
U
XTNDConnect PC - ErPhn2
ErPhn2.exe
Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook
U
XTNDConnect PC - ErTray
ErTray.exe
Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook
U
XTNDConnect PC - LtNts4
NtsAgnt.exe
Component of EasySync Pro
X
Xtray
xtray_link.exe
TROJ_VB.JL trojan
U
XtreamLok License Manager
xl.exe
License manager for xLok (XtreamLok) - prevents software being reverse engineered
U
Xtrem parental control
pcx.exe
ParentXtreme SPYWARE! **Note - If you didn't intentionally install this software remove it.
X
XTServiceUpdate
XTServiceUpdate.exe
hahame.net adware downloader
X
XtTb.exe
XtTb.exe
Top-banners.com adware
X
Xupiter Startup
XupiterStartup.exe
Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
X
XupiterCfgLoader
??
Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
X
xupiterstartup2003
xupiterstartup2003.exe
Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
X
XupiterToolbarLoader
XupiterToolbarLoader.exe
Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
U
xv_ctrl
v_ctrl.exe
"3dfx Underground Tools - ""Gives direct hardware control to your video graphics adapter"""
X
xware
cskware.exe
"Malware downloader from xxsware.com, produces porn popups."
X
xware
xware.exe
"Malware downloader from xxsware.com, causes porn popups"
X
xxcm
sys.exe
W32/KRISWORM-A WORM!
X
xxsrSrv32
xxsrsrv.exe
TROJ/BANCSDE-E TROJAN!
X
XXXmpeg
XXXmpeg.exe
Adult content dialler
X
xxxvideo
xxxvideo.exe
AccessPlugin premium rate adult material dialer
U
Y!TunnelBasic
YTBasic.exe
Y!TunnelBasic software provides additional features to Yahoo! Messenger.
U
Y!TunnelPro
YTPro.exe
"Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia"
U
Y!TunnelPro
YTunnelPro.exe
"Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia"
X
yaemu.exe
yaemu.exe
WIN32.DNSCHANGER.S TROJAN!
X
yahoo groups
upgrdmgr.exe
variant of the WIN32.RBOT WORM!
X
Yahoo Instant Messengar
YahooMsgr.exe
WIN32.SDBOT.GEN TROJAN!
X
Yahoo Messenger
Yahoomsg.exe
unidentified WORM or TROJAN!
X
Yahoo Messenger
YPager.exe
W32/RBOT-QO WORM!
X
Yahoo Update
Yahoo.exe
Yahoo! TROJAN!
X
Yahoo Updater
Messenger.exe
W32/Forbot-FE WORM!
N
Yahoo! Pager
ypager.exe
Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs
X
yahoo_toolbar lptt01 or yahoo_toolbar ml097e
yahoo_toolbar.exe
"Variant of the RapidBlaster parasite (in a ""yahoo_toolbar"" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here"
X
Yahoo2000
Anti.exe
RBOT.ATK WORM!
X
YahooStock
Prmvr.exe
Adtomi adware
X
YahooStock
ystckAO32.exe
Adtomi adware
N
YAMAHA DS-XG Launcher
dslaunch.exe
System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups
N
Yankee Clipper III
YankClip.exe
"Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar ""Outlook"" interface'. Freeware"
N
YBrowser
ybrwicon.exe
SBC Yahoo! Browser system tray icon
X
yeahdude.exe
hallowelt.exe
GAOBOT.RS or GAOBOT.SA WORMS!
N
YOP
yop.exe
Dashboard Module for SBC Yahoo! Online_Protection
U
You've Got Pictures Screensaver
ygpsstra.exe
AOL You've Got Pictures╜ Screensaver
N
ypager
ypager.exe
Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs
U
YPC
ypc.exe
"Yahoo Parental controls - ""Let you decide what type of sites and Yahoo! services your kids can access"""
Y
YTrayMagic Lite 1
YTRAYMAGIC.EXE
YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored
X
Yugoslavia
yugoslavia.exe
Premium rate adult content dialer
U
Yumgo's Homepage Protector V1
YumgoHomepageProtector.exe
Yumgo's Homepage Protector
X
ywzizdon
ywzizdon.exe
Free_Scratch_Cards foistware
X
yyyyyyyy
??
MUMUBOY.B VIRUS!
X
yz.exe
yz.exe
VARDO VIRUS!
X
YZH.SYS
YZH.exe
W32.SOPHILY VIRUS!
X
ZaCker
??
HOLAR.A VIRUS! where <filename> is the worm filename
X
Zacker
Zacker.exe
GEMEL VIRUS!
X
zango
zango.exe
180Solutions/N-Case adware variant
X
Zango TvTimes
ZANGOT~1.EXE
ZangoSearch adware
X
zanu
zanu.exe
180Solutions/N-Case adware variant
Y
Zapro
Zapro.exe
Firewall program from Zonelabs - paid for version
U
zBrowser Launcher
Commandr.exe
"For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc. if it doesn't have them"
U
zBrowser Launcher
iTouch.exe
"For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn\'t have them"
U
Zcfgsvc
ZCfgSvc.exe
"Zero Config MFC Application, part of Intel?s ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing ?Not Responding? or ?End this Program? shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have Windows XP/2003, try setting the ?Wireless Zero Configuration? service to Disabled."
X
zcproo
qssstiej.exe
"Possible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguise. see this thread"
N
zdnet
kontiki.exe
Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
N
Zebus
msdc32.exe
Runs a HTML tutorial on the Zebus web-site
X
Zekio Startups
znksvc32.exe
W32/AGOBOT-AGI WORM!
X
Zen.A
??
Perl/Zoomen-A trojan infection
X
Zenet
"rundll32 CNBabe.dll, DllStartup"
CommonName Toolbar spyware. To uninstall see here
Y
ZENRC
zenrc32.exe
"The main component of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management"".Leave well alone"
Y
ZENRC Tray Icon
zentray.exe
"Part of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management"".Best left alone"
Y
ZENworks Imaging Service
ZISWin.exe
"Imaging Agent. Part of Novell's ZenWorks - ""Complete End-to-End Directory-enabled Network Management"""
U
ZeroAds
??
"ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually"
U
ZeroAds
LAS0Ads.exe
"ZeroAds - culls ads, cookies and pop-ups. Required for the cookie interception to work"
U
ZeroSpyware
ZeroSpyware.exe
FBM Software ZeroSpyware 2004 spyware detector and remover
X
zervpack2
update2.exe
SDBOT.WD WORM!
X
zerzvpack2
uzpdate2.exe
Rbot-KA worm infection
X
ZIBMACC
rundll.exe -> ZIBMACC.INF
ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435)
U
ZingSpooler
ZingSpooler.exe
Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums
N
Zinio DLM
ZDLM.EXE
Zinio - used to read magazines in digital rather than paper format
X
Zip Driver Loader
msload32.exe
OBLIVION TROJAN!
X
Zip Driver Loader
ZipLoader.exe
OBLIVION TROJAN!
U
ZipDisk Icons
IMGICON.EXE
"Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the ""U"" recommendation. Note - FreeCell may not run with ImgIcon running"
N
ZipGenius Clean
zg.exe
ZipGenius file compression utility
X
ziphelp
ziphelp.exe
CoolWebSearch parasite related.
N
ZipMagic
zm32.exe
Zip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first
Y
zlclient or Zone Labs Client
zlclient.exe
Firewall program from Zonelabs. Pro version inlcudes other online security options
U
ZLH
ZLH.EXE
System Tray icon for Norman Antivirus
X
Zonavirus
??
KITRO.D (or ARGEN.A) VIRUS!
X
Zone Alarm
vsmon.exe
WORM_RBOT.BO
X
Zone Labs Client Ex
svchost.exe
"W.32NETSKY.F WORM! **Note This is not the valid svchost.exe as described for WinXP or Win2K . Located in a Windows directory, and not in Windows\System32"
X
Zone system
szchost.exe
TROJ/MULTIDR-AC TROJAN!
X
zonealarm
"mcmm.exe, random file names"
unknown worm or trojan infection
X
Zonealarm
Removeme.exe
W32/FORBOT-BG WORM!
Y
ZoneAlarm
zonealarm.exe
Firewall program from Zonelabs - free version
Y
ZoneAlarm Plus
zaplus.exe
Firewall program from Zonelabs - paid for version
Y
ZoneAlarm Pro
Zapro.exe
Firewall program from Zonelabs - paid for version
U
Zoom
zoom.exe
Zoom - speeds up Windows startup and manages startup applications
Y
ZPOINT32
ZPOINT32.exe
USB graphics/writing tablet driver
X
zSearch
Zstb.exe
TotalVelocity zSearch parasite
X
zsms
smss.exe
"BANCOS-CK TROJAN! - Note - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!"
X
zsmsgs
iservice.exe
TROJ/BANCOS-BU TROJAN!
X
zsmss
smss.exe
Troj/Bancos-DD TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
U
zSPGuard
Spguard.exe
"""StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'."""
X
ZStart
??
"Adware, probably VX2/Transponder related - filenames spotted include rdxregpp.exe, tdxregrs.exe and more."
X
ZtgServerSwitch
server.vbs
ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
X
Zupdate
Zupdate.exe
"B3d Projector - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the ""BDE"" directory and all its contents"
U
z-WrDialer
WrDialer.exe
WinPoet DSL dialer
X
zzb
zzb.exe
IAGold_adware downloader
X
zzb2
zzb2.exe
IAGold_adware downloader
X
zzgshp
gshp.vbs
Homepage hi-jacker that re-defines your IE or Netscape start page
X
zztp
svchost.exe
"TANNICK.B TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!"