| |
Name/Startup Item |
Command |
Comments |
| X | | system32.exe | Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | pathex.exe | Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | svchost.exe | Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the Winnt or Windows folder. Note - has a blank
entry under the Startup Item/Name field |
| X | | MSPF.EXE | Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.exe | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.dll | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.js | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | ajsha5.exe | Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | ne.exe | Added by the IRCBOT-ZL TROJAN! |
| X | SystemBoot | services.exe | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a HelpHelp subfolder of the Windows or Winnt
folder |
| X | WinCheck | services.exe | Added by the SOBER-S WORM! Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a "ConnectionStatusMicrosoft" subfolder of the
Windows or Winnt folder |
| X | Windows | services.exe | Added by the SOBER.X WORM! Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a "WinSecurity" subfolder of the Windows or
Winnt folder |
| X | WinStart | services.exe | Added by the SOBER.O WORM! Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a Connection WizardStatus subfolder of the
Windows or Winnt folder |
| X | winsystem.sys | smss.exe | Added by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a msagentwin32 subfolder of the Winnt or
Windows folder |
| Y | !1_pgaccount | pgaccount.exe | DiamondCS ProcessGuard
security software - stops malicious worms and trojans from being
executed silently in the background, as well as a variety of other
attacks. You will see one instant of pgaccount.exe for every active
account on your system, and this is essential for PG to work properly |
| Y | !1_ProcessGuard_Startup | procguard.exe | DiamondCS ProcessGuard
security software - stops malicious worms and trojans from being
executed silently in the background, as well as a variety of other
attacks |
| U | !AVG Anti-Spyware | avgas.exe | Part of AVG Anti-Spyware from Grisoft |
| U | !ewido | ewido.exe | Part of Ewido anti-spyware |
| N | !NoLoad | winrecon.exe | WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
| ? | $EnterNet | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
| X | $sys$cmp | $sys$xp.exe | Added by the RYKNOS.B
TROJAN! Attempts to utilize the Sony Rootkit A.K.A.
SecurityRisk.First4DRM security risk to hide itself on the compromised
computer |
| X | $sys$crash | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$crash | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$crash | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$drv | $sys$drv.exe | Added by the RYKNOS
TROJAN! Attempts to utilize the Sony Rootkit A.K.A.
SecurityRisk.First4DRM security risk to hide itself on the compromised
computer |
| X | $sys$momomomochin | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$momomomochin | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$momomomochin | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| U | $Volumouse$ | volumouse.exe | Volumouse
from Nirsoft. "Provides you a quick and easy way to control the sound
volume on your system - simply by rolling the wheel of your wheel mouse" |
| X | $WindowsRegKey%update | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe
process which is always located in the Program FilesInternet Explorer
folder and should not normally figure in Msconfig/Startup! This file is
located in the System (9x/Me) or System32 (NT/2K/XP) folder |
| N | %cmpmixtitle% | %cmpmixstr% | Possibly related to C-Media Mixer Control panel? |
| N | %FP%012-L2TP fts.exe | fts.exe | 012.Net.il Israeli ISP software front-end |
| U | %FP%012-L2TP FWPortal.exe | FWPortal.exe | 012.Net.il Israeli ISP dial-up software |
| N | %FP%1776 Internet fts.exe | fts.exe | 1776 Internet US ISP software ISP software front-end |
| U | %FP%1776 Internet FWPortal.exe | FWPortal.exe | 1776 Internet US ISP dial-up software |
| N | %FP%AIRTEL fts.exe | fts.exe | Bharti Airtel Broadband - Indian ISP software front-end |
| N | %FP%Barak013 fts.exe | fts.exe | Barak013 Israeli ISP software front-end |
| U | %FP%Barak013 FWPortal.exe | FWPortal.exe | Barak013 Israeli ISP dial-up software |
| N | %FP%Friendly fts.exe | fts.exe | Friendly ISP software front-end |
| U | µTorrent | utorrent.exe | µTorrent
- BitTorrent client for Windows sporting a very small footprint. It was
designed to use as little cpu, memory and space as possible while
offering all the functionality expected from advanced clients |
| X | (*)API Machine | winSOCKS.exe | Homepage hijacker, see here (* = any digit) |
| X | (*)Run | win32API.exe | Homepage hijacker, see here (* = any digit) |
| X | (default) | [random filename].exe | Added by the BLACKMAL
WORM! Note - this malware actually changes the default value data of
the registry "Run" key in order to force Windows to launch it at boot.
Name field may be empty |
| X | (default) | rundll32.exe [path to DLL file], Do98Work | Added by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | (Default) | 5640.exe | Added by the DOWNLD-ABF TROJAN! |
| X | (L4r1$$4) (4nt1) (V1ruz) | SP00Lsv32.pif | Added by the ASSIRAL.B WORM! |
| X | *Bandook | msdll.exe | Added by an unidentified TROJAN - see here |
| X | *JanisRuckenbrodII | janis.com | Added by the POPS WORM! |
| X | *Microsoft Update | ctxma.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | cxma.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wstcl.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wucxt.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wuytc.exe | Added by the STMU TROJAN! |
| X | *MS Setup | [random filename] | Virtumondo adware, also known as the VUNDO TROJAN! |
| X | *MSConfig32 | aecache.exe | Detected by F-secure as the OBFUSCATED.GP TROJAN! |
| X | *Security Center | secctr.exe | Added by the SDBOT.BRO WORM! |
| Y | *StateMgr | statemgr.exe | Windows ME default for System Restore. Do NOT disable! |
| X | *windows update | wrauclt.exe | Added by the RBOT-QU WORM! |
| X | *windows update | wuanclt.exe | Added by the RBOT-PG WORM! |
| X | *windows update | wuaucrlt.exe | Added by the SPYBOT.HUR WORM! |
| X | *windows update | wuraclt.exe | Added by the RBOT-PO WORM! |
| X | *windows update | wurauclt.exe | Added by the RBOT-SY WORM! |
| X | *windows update | wsctl.exe | Added by the SPYBOT.PR WORM! |
| X | *windows update | wkmst.exe | Added by the SDBOT.AVD WORM! |
| X | *windows update | wscxt.exe | Added by the RBOT.AOS WORM! |
| X | *windows update | waurclt.exe | Added by a variant of the RBOT WORM! |
| X | *Windows [filename] Checker | [filename] | Added by the KEDEBE-B WORM! |
| X | *WindowsAudio | systemupd.exe | Added by the AGENT-TH WORM! |
| X | *WinLogon | [trojan path] ren time:[random number] | Added by the VUNDO TROJAN! |
| X | *winstats | winstats.exe | Added by the GARGAFX TROJAN! |
| X | *wuauclt.exe | w****.exe [* = random char] | Added by a variant of the RBOT-UG
WORM! Note - * in the filename represents a random char; variants
spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
| X | ,main drive Loader | wininfo.exe | Suspected malware as it appears in 3 different registry locations - see here |
| X | -=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ | ISASS.exe | Added by the ASSIRAL.B WORM! |
| Y | -FreedomNeedsReboot | ZkRunOnceR.exe | Internet Security Suite used by ISPs to protect customers against many attacks |
| X | .. | ABC2007.exe | Added by the DLOADR-ASH TROJAN! |
| X | .mscdr | lassa.exe | Added by the WEBUS.C TROJAN!
|
| X | .mscdr | lsvchost.exe | Added by the WEBUS.D TROJAN! |
| X | .mscdsr | lsvchost.exe | Added by the CR TROJAN! |
| X | .mscsbl | svhost.exe | Added by the CMQ TROJAN! |
| X | .msfupdate | msveup.exe | Added by the ALLOCUP.A WORM! |
| X | .mssecure | mssecure.exe | Added by the DDOS_BOXED.X TROJAN! |
| ? | .NET config | sysmon32.exe | ?? |
| X | .NET. | msnmgnr.exe | Added by the DELF.AYF WORM! |
| X | .norton | rchost.exe | Added by the BOXED-H TROJAN! |
| X | .nvsvc | smss.exe | Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
|
| X | .nvsvcb | smssb.exe | Added by the BOXED.CG TROJAN! |
| X | .Prog | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | .Prog | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | .protected | N/A | Smitfraud variant |
| X | .svchost | CSRSS.EXE | Added by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the System folder |
| X | .TEXTCONV | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | .TEXTCONV | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the System folder |
| X | .WMAudio | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | .WMAudio | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the System folder |
| N | /l:eng | N/A | Related
to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If
this item is listed and checked in startup, the System32 Folder will
appear on every startup. A patch is available - filename R75304.EXE -
that fixes the issue. You can find that file at support.dell.com by
typing that name in the 'Search' box available there. It addresses the
root of the problem in Creative's software and corrects it.
Unfortunately there is no direct link to the file, but it's easily
available using the search function |
| U | 000 | pit.exe | PrivateEye surveillance software. Uninstall this software unless you put it there yourself |
| X | 000hpdllhos | hpdllhost.exe | LZIO.com adware downloader |
| U | 000StTHK | 000StTHK.exe | Toshiba
Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock),
Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display
output), etc...) |
| X | 0050726-007-i32-1 | 0050726-007-i32-1.exe | Added by the BANCBAN-EC TROJAN! |
| ? | 00DSKSVR00 | desksaver.exe | Related to Advanced Desktop Shield |
| ? | 00DSKSVR01 | desksaver.exe | Related to Advanced Desktop Shield |
| Y | 00PCTFW | FirewallGUI.exe | PC Tools Firewall Plus
- "powerful free personal firewall for Windows that protects your
computer by preventing unauthorized users from gaining access to your
computer through the Internet or a network" |
| Y | 00TCrdMain | TCrdMain.exe | Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards |
| U | 00THotkey | 00THotKey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
| U | 00THotkey | system32THotkey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
| U | 0190 Warner | WARN0190.EXE | Anti-dialer program (Germany) |
| U | 0900 Warner | WARN0900.EXE | Anti-dialer program (Germany) |
| X | 0mcamcap | 0mcamcap.exe | Added by the COSIAM-H TROJAN!
|
| X | 0utlook Express | *****.exe [* = random char] | Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o" |
| X | 1 | 1.exe | Added by the ESTEEMS TROJAN! |
| X | 1 | lsass.scr | Added by the BANCOS.V TROJAN!
|
| X | 1 | svchost.scr | Added by the BANCOS.X TROJAN! |
| N | 1&1 EasyLogin | EasyLogin.exe | 1&1 EasyLogin - quick access to webhost 1&1's Control Panel, Web-Mail and other applications via the System Tray |
| X | 1029BB4B-16A9-4E77-AA3D-96930BD68EEC | sysockeu.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 1111swapmgr.exe | 1111swapmgr.exe | Added by the IC TROJAN! |
| X | 123456 | rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl | Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
| U | 12Ghosts Backup | 12backup.exe | 12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup" |
| U | 12Ghosts Clip | 12clip.exe | 12Ghosts Clip - "Screen shots made easy" |
| U | 12Ghosts JustAWindow | 12window.exe | 12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see" |
| U | 12Ghosts Popup-Killer | 12popup.exe | 12Ghosts Popup-Killer |
| U | 12Ghosts SaveLayout | 12autosl.exe | 12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons" |
| U | 12Ghosts SetColor | 12color.exe | 12Ghosts SetColor - "Change your desktop icon text colors, also to transparent" |
| U | 12Ghosts ShowTime | 12showtime.exe | 12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones" |
| U | 12Ghosts Synchronize | 12sync.exe | 12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet" |
| U | 12Ghosts Tower | 12tower.exe | 12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)" |
| U | 12Ghosts TrayProtect | 12srvc.exe | 12Ghosts TrayProtect - "Hide tray icons, restore after a crash" |
| U | 12Ghosts Wash | 12wash.exe | 12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files" |
| ? | 17779Proj2002 | N/A | ?? |
| X | 180adsolution | 180adsolution.exe | NCase adware |
| X | 180ax | 180ax.exe | NCase adware |
| X | 180ClientStubInstall | stubinstaller****.exe [* = digit] | 180Solutions adware related |
| X | 180ClientStubInstall | [path to trojan] | 180Solutions adware related |
| X | 180ClientStubInstall | ******.tmp [* = random digit/char] | 180Solutions adware related |
| X | 1916435341.exe | 1916435341.exe | Added by the DLOADR-AXU TROJAN! |
| X | 196_150_ni | 196_150_ni.exe | WinFixer
web installer. Winfixer is "Foistware", pretending to be system
optimization, protection and recovery software - stealth installed, see
here |
| X | 197_150_ni_3 | 197_150_ni_3.exe | WinFixer
web installer. Winfixer is "Foistware", pretending to be system
optimization, protection and recovery software - stealth installed, see
here |
| N | 1: | hpdrv.exe | HP utility for monitoring when and how many recoveries have been done |
| N | 1A:MacVisionTrayMonitor | TrayMonitor.exe | Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) |
| Y | 1A:Stardock MCP | mcpserver.exe | Master
Control Program for Stardock apps, in development. People should leave
it running if they're using any of the Stardock applications |
| Y | 1A:Stardock TrayMonitor | TrayServer.exe | For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX |
| ? | 1CmailS | NETMAIL.EXE | ?? |
| X | 1on1 | 1on1.exe | Adult content dialler |
| U | 1Srv32 | SpyAgent4.exe | SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
| X | 1u7 | 1u7.exe | Added by the MURBAC-A TROJAN! |
| U | 1Win32Cfg | SpyBuddy.exe | SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | 1Win32Cfg | Keyloggerpro.exe | Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | 1WinCfg32 | WebMailSpy.exe | WebMailSpy spyware |
| X | 2020Downloader | mssvr.exe | 2020Search Toolbar |
| X | 2177F056-0AA6-4D6C-A944-13F71F341C29 | sysokuaw.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| U | 24Online Client | CyberoamClient.exe | Related to Cyberroam from Elitecore Technologies Ltd |
| X | 252 | winmgr.exe | Added by the LEGMIR-AT TROJAN! |
| X | 27 | slsorve.exe | Added by the SLSORVE-A TROJAN! |
| X | 27 | csrss32.exe | Added by the SLSORVE-D TROJAN! |
| X | 27 | msm32.exe | Added by the SLSORVE-E TROJAN! |
| X | 2Search | main.exe | 2Search adware |
| X | 2thousandbuck | [path to file] | Added by the RANKY.L TROJAN! |
| U | 2wSysTray | 2portalmon.exe | 2Wire Homeportal user interface |
| X | 32-bit Thunking service | thunk32.exe | Added by the DERDERO.A WORM! |
| X | 333 | svchost.exe | Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This one is located in a "Syswm1i" directory |
| X | 388529725448 | AutomaticUpdates.exe | Added by the SDBOT-DEN WORM! |
| ? | 39ELTFH25Z8SKF | Ezg1q5.exe | Seems to be associated with software by Resplendence SP ? |
| Y | 3c1807pd | 3cmlink.exe 3cpipe-3c1807pd | 3Com WinModem driver. See here for more WinModem information |
| Y | 3capplnk | 3capplnk.exe | US Robotics Modem driver |
| N | 3cdminic | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
| Y | 3CM Link | 3cmcnkw.exe | Required for a US Robotics WinModem as it provides the link to Windows - won't work without it |
| Y | 3Cmlink | 3CmlinkW.exe | For
a US Robotics WinModem. Provides the link to Windows as the CPU does
the processing on WinModems - won't work without it. See here for more WinModem information |
| N | 3ComDMIAgent | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
| Y | 3cpipe-USRpdA | USRmlnkA.exe | Modem driver files from US Robotics |
| X | 3D Text | 3D Text.scr | Added by the JERMY.A WORM! |
| U | 3Deep Control Panel | 3DeepCTL.EXE | Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games |
| X | 3Dfx Acc | GFXACC.EXE | Added by the GIBE WORM!
|
| N | 3dfx Task Manager | 3dfxMan.exe | System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
| Y | 3dfx Tools | 3dfxCmn.dll | Updates
the registry with information that can't be held for Voodoo 3/4/5
series graphics cards. Important for owners of these cards |
| Y | 3dfxv2ps.dll | 3dfxv2ps.dll | Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
| ? | 3Dlabs Taskbar Display Manager | 3DLman.exe | 3DLabs graphics driver related. System Tray access to display settings? |
| U | 3DLabsHelperDemon | 3dldemon.exe | Directly
from the programs author "It is a tiny program that is installed by the
Permedia2/3 and probably other Oxygen-series cards. Normally it sits in
the background doing nothing at all (sleeping on a semaphore), so it
should take zero CPU time and virtually zero memory, since it will all
be paged out to the hard drive." In most cases it can be safely disabled |
| Y | 3DMouse.EXE | 3DMouse.EXE | Dritek System Inc. 3D Mouse driver |
| X | 3d_sound | 3d_sound.exe | Added by the RIADOS-A TROJAN! |
| U | 3qdctl.exe | 3qdctl.exe | Provided
with Terratec 128i PCI and similar sound cards. Loads a sound profile
at bootup, restoring volume and other audio settings to a
pre-determined default. Similar to Creative Lab's AudioHQ |
| Y | 3ware 3DM | 3dm.exe | Monitors status of the disk array on 3ware IDE RAID controllers |
| X | 456655 | explorer.exe | Added by the BIFROSE-DE
TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is
located in the Windows or Winnt folder and would not normally appear in
Msconfig/Startup unless you added it manually! This one is located in
the System folder |
| X | 4684735485910 | netdll32.exe | Added by the SDBOT-DEV WORM! |
| X | 4da92ad5.exe | 4da92ad5.exe | Added by the DLOADR-WZ TROJAN! |
| U | 4oD | KHost.exe | Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
| X | 4wd!!! | Natal!.pif | Added by the OPASERV.AI WORM! |
| X | 5-1-61-96 | members-area.exe | Adult content dialler |
| X | 5-2-46-112 | 5-2-46-112.exe | Adult content pop-up dialler. Removal instructions here |
| X | 55278 | grepclient1.exe | Added by the LINEAGE-S TROJAN! |
| X | 5p4m | [path to trojan] | Added by the LITEBOT-C TROJAN! |
| X | 5whgue21 | 5whgue21.exe | ClearSearch adware |
| X | 666 | Ska.exe | Added by the PIPES TROJAN! |
| X | 678 | lsas32.exe | Added by the SLSORVE-B TROJAN! |
| X | 756349DC-6D9E-4F2A-9B24-269661F073C3 | sysoghcx.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 7f8e | z****.exe 9idf | Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder |
| U | 802.11b+g USB Wireless LAN Utility | ZDWlan.exe | 802.11b+g USB Wireless LAN Utility |
| U | 802.11g Wireless Adatper | Monitor.exe | Related
to wireless card (802.11) adapter/standard. System Tray icon that
provides a shortcut to "Wireless Connection Status" and allows to turn
WL on and off. Supplier unknown. Adapter is miss-spelled |
| X | 852EBF20-A95D-4F1F-B9C2-B2CD24350F3E | sysodkcs.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 98D0CE0C16B1 | rundll32.exe D0CE0C16B1, D0CE0C16B1 | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | 9m | winlog0n.exe | Added by the LEGMIR-AQK TROJAN! |
| Y | 9xadiras | 9xadiras.exe | Allied Telesyn AT series router/modem related - apparently required |
| X | 9xHtProtect | AVprotect9x.exe | Added by the NETSKY.M WORM! |
| X | ;Rundll | [filename] | Added by the PWSLEGMIR.E TROJAN! |
| X | ?ekio Startups | ?nksvc32.exe | Added by the AGOBOT-OV WORM where ? is a random character
|
| X | @ | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| N | @Hoc Toolbar | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info |
| N | @loha | reminder.exe | Registration reminder for @loha@home E-mail utility |
| X | @tour_ww | @tour_ww[1].exe | Adult content dialler |
| X | a | a.exe | Commercials file that registers itself in the system registry and redirects IE to a certain commercial website |
| X | a | jesse.exe | Added by the MELO-A WORM! |
| X | A New Windows Updater | w32NTupdt.exe | Added by the MYTOB.BM WORM! |
| N | A Note | A Note.exe | "A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop" |
| U | A Verizon App | VERIZO~1.EXE | Part of Verizon Online Support Manager |
| U | a-squared | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature |
| Y | a-squared Anti-Dialer | a2adguard.exe | a-sqaured Anti-Dialer |
| Y | a-winpoet-service | winpppoverethernet.exe | WinPoET
is the industry's first Windows-based PPP over Ethernet client.
Developed by iVasion, WinPoET is attractive to equipment providers,
modem suppliers, RBOCs and ISPs. For more info read here.
It uses dial-up networking for new high-speed internet customers who
are more familiar with analogue modems. If unchecked in MSCONFIG it
reports Error 360 - Hardware Error in dial-up networking |
| U | A1000 Settings Utility | cpqa1000.exe | Compaq
A1000 Print Fax All-in-One copy scan printer software. Required in the
Startup in order to scan, print, copy and fax. Only required if you use
these features |
| U | A4Proxy | A4Proxy.exe | Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites |
| X | A70F6A1D-0195-42a2-934C-D8AC0F7C08EB | rundll32.exe E6F1873B.DLL, D9EBC318C | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | a? | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature |
| ? | AAACLEAN | AAACLEAN.INF | ?? |
| ? | AAAKeyboard | ?? | ?? |
| N | AAATraySaver | TraySaver.exe | System Tray management utility from Mike Lin
which allows you to hide, show, restore icons that are lost in an
Explorer crash, remove dead tray icons, minimize any window to the
System Tray |
| U | AAK | aak.exe | Advanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere" |
| U | aaLDISCN32 | LDISCN32.EXE | LANDesk? Management Suite software component |
| U | aaLDTaskCompletion | amclient.EXE | LANDesk? Management Suite software component |
| X | AAMSFree702 | Avengine.com | Added by the DELF.LJ TROJAN! |
| X | AAMSFree702 | sys.exe | Added by the BACKDOOR-CPC TROJAN! |
| X | Aaou | amee.exe | PurityScan/Clickspring adware |
| X | Aapp | adprot.exe | AdBlaster adware |
| ? | aauclient | ACNUpdater.exe | Appears to be related to software from Accenture.com |
| U | AAW | Ad-Aware.exe | Ad-Aware anti-spyware tool from Lavasoft |
| U | AAWTray | AAWTray.exe | System Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool |
| ? | ab EazyScheduler | ezsched.exe | ?? |
| N | ABBYY Community Agent | CAGENT.EXE | Installed
with the Optical Character Recognition (OCR) software that comes
bundled with a Compaq A3000 all-in-one printer/scanner. Its function
appears to be to link you to the internet in an attempt to buy
the 5.0 version of the software |
| U | ABC | keylogger.exe | Keystroke logger/monitoring program - remove unless you installed it yourself!
|
| X | abcdefgh | abcdefgh.exe | EPJ TROJAN!
|
| U | ABIT uGuru | uGuru.exe | ABIT ?Guru
- on motherboards incorporating the ?Guru processor this provides quick
access to "hardware monitoring, overclocking, BIOS flashing and audio
tweakin |
| N | ABITEQ | abiteq.exe | Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds |
| X | Abrada WIN32 | abrada.exe | Added by the DERMON-G TROJAN!
|
| U | Absolute Shield | dseraser.exe | Absolute Shield Evidence Eliminator - internet history eraser
|
| U | Absolute StartUp monitor | ASMon.exe | Absolute Startup - startup monitor from F-Group Software |
| U | AbsoluteShield Internet Eraser | cseraser.exe | AbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities"
|
| X | ABsr | absr.exe | Added by the AUTOUPDER TROJAN! |
| X | absr | mwsvm.exe | SeekSeek search hijacker related - see here
|
| X | abtu | mp3serch.exe | Loads the executable for Lop.com. mp3serch.exe is the final version |
| X | abtu | lopsearch.exe | Loads the executable for Lop.com. lopsearch.exe is the beta version |
| U | AbyssWebServer | abyssws.exe | Abyss web server |
| X | Ac97Sound | snddrv.exe | Detected by Sophos as the SILLYFDC-A TROJAN! |
| U | AcBtnMgr_X63 | AcBtnMgr_X63.exe | "Lexmark
Scan & Copy Control Program" for the Lexmark X63 all-in-one
multifunction printer/copier/scanner. Button manager for features such
as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X73 | AcBtnMgr_X73.exe | "Lexmark
Scan & Copy Control Program" for the Lexmark X73 all-in-one
multifunction printer/copier/scanner. Button manager for features such
as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X83 | AcBtnMgr_X83.exe | "Lexmark
Scan & Copy Control Program" for the Lexmark X83 all-in-one
multifunction printer/copier/scanner. Button manager for features such
as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X84-X85 | AcBtnMgr_X84-X85.exe | "Lexmark
Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one
multifunction printer/copier/scanner. Button manager for features such
as scan, scan to E-mail, copy, etc |
| U | acc | acc.exe | Advanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem" |
| X | ACCDEFRAGINFO | [path to worm] | Added by the DARBY-O WORM! |
| U | Accelerate | accelerate.exe | Webroot
Accelerate - allows you to optimize Windows network registry settings
in order to boost surfing speeds. Leave this enabled if you find it
improves your connection |
| X | Access Control App | winsto.exe | Detected by Kaspersky as the AGENT.DGO TROJAN! See here |
| N | Access Ramp Monitor | armon32.exe | Monitors
your progress on the internet; hang-ups, connection speeds, internet
congestion and traffic flow. It prevents some games from running also.
To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open
the Program Files folder (3) Open the MindSpring folder (4) Open the
AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck
Enable Dialup Monitor and click OK (7) Restart the computer and try
again |
| X | Access WebControl | [path to file] | Added by the PPDOOR-M TROJAN! |
| U | AccessManager | AccessMgr.exe | Part of SmartPipes SecureSite
software. "SecureSite enables rapid turnup and enhanced administration
of VPNs. It automates and simplifies tasks for VPN design and policy
management, access control management, and key management" |
| X | AccessMedia P2P Loader | amp2pl.exe | My AccessMedia toolbar related, stealth installed! |
| U | AccessoriesPlus | clockplus.exe | Clock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clock |
| N | AccessRamp Monitor01 | ARMon32a.exe | From
a visitor "Just wanted to provide you with some info on Access Ramp
software installed with Verizon DSL accounts in those areas that use
the Winpoet PPPoE software. The Access Ramp TSRs are installed as part
of IP Insight software (can't remember the software maker). You can
decline to install IP Insight during Winpoet setup, or go into
Add/Remove programs uninstall IP Insight by hand if it's already
installed. It really doesn't do a darn thing for you. It was intended
to help DSL techs monitor QoS, but the backend part was never
implemented (at least as of earlier this year). This will not affect
the user's ability or inability to access their DSL service." |
| N | AccessRampLAN01 | ARUpld32.exe | Version
of the AccessRamp Monitor01 entry for LAN connections - a history
uploader. The key in turning it off is a file named ARUCfg32.exe. This
file (ARUCfg32.exe) does not show up in the startup process. If you
have this file, you can execute it and remove all the monitoring
activities it does. Removing all the checks in all the boxes (both
tabs) still calls ARUpld32.exe to start when you start the dial up. You
can block it from sending info if you have Zone Alarm installed.
Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The
ARUpld32.exe is not loaded when launching the dial up client. Written
by IP Insight and also included with Earthlink Total Access 2003 |
| U | AcctMgr | AcctMgr.exe | Norton? Password Manager - part of Norton SystemWorks 2004
- stores passwords and other personal information, and retrieves the
data needed for email logins, shopping orders, banking, and other
online activities - all from the safety of your own PC |
| N | AccuWeather.com? Desktop | AccuWeatherDesktop.exe | Desktop weather from AccuWeather |
| X | accwizz.exe | accwizz.exe | Added by the RULAND.A WORM! |
| X | accwizzz.exe | accwizzz.exe | Added by the RULAND.A WORM! |
| X | acdllib3 | bcdlmem.exe | Added by the MAILBOT-BA TROJAN! |
| N | ACDSee | ACDSee8Pro.exe | ACDSee 8 photo software. Organize, manage, enhance, and share all your valued photo memories |
| ? | Ace bows | Ace bows.exe | ?? |
| N | AceGain LiveUpdate | LiveUpdate.exe | "AceGain LiveUpdate
can help to automate and optimize product updates. AceGain LiveUpdate
will automatically detect new patch updates, driver updates or full
product updates and automatically download and install them according
to user configuration" |
| U | Acer ePower Management | Acer ePower Management.exe | Part of Acer Empowering Technology. "Acer ePower Management
is a straightforward interface that allows users to select from
pre-configured power usage profiles, or to create their own customized
profiles" |
| N | Acer ePresentation HPD | ePresentation.exe | Allows you to connect your Acer laptop to a projector |
| N | Acer Product Registration | ACE1.exe | Acer Product Registration - remove when registration is completed |
| N | Acer Tour Reminder | Reminder.exe | Popup reminder to take the tour of your new Acer laptop |
| U | AcerGoto | AcerGoto.exe | Acer
Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive
provides convenient backup of large files, or easy importation of data
from user's previous computer |
| U | AcerNotebookManager | almxptray.exe | System Tray access on some Acer Notebooks to give faster access to system settings |
| U | AcerPowerkey | Powerkey.exe | PowerKey
utility for Acer TravelMate notebook PCs. Allows the user to quickly
switch between different power schemes by pressing Fn+F3 |
| X | Acess2007a | access2007a.exe | Added by the GAOBOT.PQA WORM! |
| X | Aceu | [random filename] | PurityScan/Clickspring adware |
| Y | acEventServ | acevtsrv.exe | ActivCard Gold
from ActivIdentity, Inc. Smart card-based strong authentication
software - for photo IDs, proximity badges for facility access and as
digital identification and authentication |
| U | AClntUsr | AClntUsr.exe | Altiris AClient Service Windows Tray Icon |
| N | Acme.PCHButton | pchbutton.exe | Used by HP Instant Support |
| U | ACMonitor_X63 | ACMonitor_X63.exe | Button
monitor for the Lexmark X63 all-in-one multifunction
printer/copier/scanner. Works in conjuction with the "Lexmark Scan
& Copy Control Program" button manager whose filename is
"AcBtnMgr_X63.exe" |
| U | ACMonitor_X73 | ACMonitor_X73.exe | Button
monitor for the Lexmark X73 all-in-one multifunction
printer/copier/scanner. Works in conjuction with the "Lexmark Scan
& Copy Control Program" button manager whose filename is
"AcBtnMgr_X73.exe" |
| U | ACMonitor_X83 | ACMonitor_X83.exe | Button
monitor for the Lexmark X83 all-in-one multifunction
printer/copier/scanner. Works in conjuction with the "Lexmark Scan
& Copy Control Program" button manager whose filename is
"AcBtnMgr_X83.exe" |
| U | ACMonitor_X84-X85 | ACMonitor_X84-X85.exe | Button
monitor for the Lexmark X85-X85 all-in-one multifunction
printer/copier/scanner. Works in conjuction with the "Lexmark Scan
& Copy Control Program" button manager whose filename is
"AcBtnMgr_X85-X85.exe" |
| X | acocash | fastdown.exe | Adult content dialler |
| X | acocash | fastdown.exe | Adult content dialler |
| U | Acombo3dmouse | Acombo3d.exe | Mouse driver - required if you use non-standard Windows driver features |
| X | Aconti | aconti.exe | Adult content dialler |
| U | acoustic | acoustic.exe | Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained |
| N | acpart | agpart11.exe | Program for finding trucks on-line |
| X | Acrobat | acrmon32.exe | Added by the SMALL-ECT TROJAN! |
| U | Acrobat Assistant *.* | ACROTRAY.EXE | Essential
for creating PDF files with Adobe Acrobat and Acrobat Distiller. For
Win9x/Me systems you can run this file manually beforehand. For WinXP
systems this file must run at startup. Hence the "U" recommendation.
*.* represents the version |
| X | Acrobat Read | acroup32.exe | Added by the VANBOT-BQ TROJAN! |
| N | Acrobat Speed Launch | acrobat_sl.exe | Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards |
| U | ACROMOUSE | ACROMAPP.exe | Related to ACROMOUSE Laser mouse control |
| U | Acronis Popup Blocker | RunDll32.exe [path] Blocker.dll, Run | Part of Acronis Privacy Expert - anti-spyware and security suite
|
| U | Acronis Scheduler Helper | schedhlp.exe | Part of Acronis True Image
backup software. Co-operates with the "schedul2.exe" service to perform
backup/restore tasks correctly. Required if you want to use True Image
to do some real backup/restore tasks - not if you only want to
explore/mount images |
| U | Acronis Scheduler2 Service | schedhlp.exe | Part of Acronis True Image
- backup software. Co-operates with the "schedul2.exe" service to
perform backup/restore tasks correctly. Required if you want to use
True Image to do some real backup/restore tasks - not if you only want
to explore/mount images |
| U | Acronis True Image | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | Acronis True Image Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| N | Acronis TrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| U | AcronisTimounterMonitor | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | AcronisTrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| U | Act! Preloader | Act8.exe | Sage Software's ACT!
"enables individuals and small business customers to instantly access
key contact and customer information, manage and prioritize activities,
and track all contact-related communications so you can grow productive
business relationships" |
| N | Action Manager 32 | am32.exe | Associated
with a Plustech scanner. Small utility that runs in the background for
doing fax/copy/etc. Available via Start -> Programs |
| ? | ActionAgent | actionagent.exe | "A
COM server that runs on the client as part of the Dell OpenManage
Client Instrumentation 6.x package; provides a simple method for a
remote administrator to perform actions on the instrumented client". Is it required? |
| N | Activation | Activation.exe | Part of Microsoft Money |
| U | Activboard | MMKeybd.exe | Packard
Bell ActiveBoard keyboard - multimedia keyboard manager. Required if
you use the additional keys and want to see the status of the Num Lock,
Caps Lock, Scroll Lock keys |
| X | Active Bit Station | abs.exe | Added by the MYTOB.BZ WORM! |
| N | Active CPU | acpu.exe | Active CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity" |
| U | Active Desktop Calendar | ADC.EXE | XemiComputers Active Desktop Calendar |
| U | Active Email Monitor | aem25.exe | Active Email Monitor
checks multiple accounts for email, serves as a SPAM filter and can
also protect you from harmful items that can be sent via email |
| U | Active shield | Activeshield.exe | Active Shield
is "an heuristic screen that actively protects your computer from
trojans, spyware, adware, trackware, dialers, keyloggers, and even some
special kinds of viruses" |
| X | ActiveDesktop | systray32.exe | Added by the DABOOM WORM! |
| X | ACTIVEDS | ACTIVEDS.EXE | Added by the OPASERV.T WORM! |
| N | ActiveEyes | ActiveEyes.exe | ActiveEyes
from TFI Technology is a small utility that you can use to liven up
your desktop. It follows your mouse around and can tell you how far
your cursor has travelled or point out where the cursor is. It's small,
it's free and comes with a range of options and animations. Not needed
- if unavailable via Start -> Programs, create your own shortcut |
| U | ActiveKeys.AAB635BD7D054a37A576 | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" |
| U | ActiveMenu | ActiveMenu.exe | Wild
Tangent demo games that come with some HP computers. Unchecking it can
prevent the games from running occasionally. Note that WildTanget's
privacy policy used to state that they also collect and share
individuals information but this is no longer the case |
| U | ActivePlus | activeplus.exe | Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) |
| X | ActiveScan Antivirus | ActiveScan.exe | Added by the RBOT-FKQ WORM! |
| X | ActiveScript32 | nod.exe | Added by the SOHANA-AJ WORM! |
| Y | ActiveShield | MCVSSHLD.EXE | McAfee VirusScan On-line. See also the McAgentExe entry |
| U | ActiveSpeed | AS.exe | Ascentive ActiveSpeed Internet Optimizer |
| X | ActiveSync | wcescom32.exe | Added by the MANCSYN-E TROJAN! |
| N | ActiveWords | AWMonitor.exe | ActiveWords
from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in
the background and watches as you type. When it recognizes that you?ve
typed an ActiveWord, it takes the associated action, such as replacing
your keystrokes with the text you?ve defined |
| X | ActiveX File Registration Service | filereg.exe | Added by the RBOT-DVD WORM! |
| X | ActiveX Streamer | msgfix.exe | Added by the SDBOT.NQ WORM! |
| X | ActiveXUpdate | svcss.exe | Added by a variant of the DEDLER.C TROJAN! |
| U | Activity | actik.exe | ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself! |
| N | ActivSurf | backweb*****.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates |
| U | ActMaker | ActMak25.exe | "ActMaker
mouse and keyboard toolkit can record the daily operation of your
computer and reduce your workload. You don't need to do any coding, nor
are you required to know a lot about the computer" |
| U | ActMaker | ActMaker25.exe | ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload
|
| U | ACTray | ACTray.exe | System Tray icon for ThinkVantage Access Connections
- "allowing users to seamlessly switch between wired and wireless
environments, managing security settings, printers, home page and other
location-specific settings automatically" |
| U | Actual Window Minimizer | ActualWindowMinimizerCenter.exe | Actual Window Minimizer - "allows minimizing any window to task tray notification area or to the edge of the screen"
|
| X | ACTX1 | v1201.exe | Added by the VB.IS TROJAN! |
| U | ACU | ACU.exe | Atheros wireless Client Utility |
| U | ACU_QSB | ACU.exe | Atheros wireless Client Utility |
| U | ACWLIcon | ACWLIcon.exe | Related to IBM ThinkVantage Connectivity Solution
|
| U | Ad Blocker | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads |
| U | Ad Blocker Pro | Ad Blocker Pro.exe | Ad Away popup and banner remover |
| U | Ad Muncher | AdMunch.exe | Ad Muncher
removes adverts, pop-ups and general annoyances in your browser,
file-sharing and messenger programs. Causes conflicts with Outlook,
game sites and web-building applications |
| ? | Ad Online Guide | adonlineguide.exe | ?? |
| U | Ad-aware | Ad-aware.exe | Ad-aware from Lavasoft - popular spyware/adware removal tool |
| X | Ad-Aware | Ad-Aware.exe | Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-aware spware/adware removal tool and is located in the WinntSystem32 or WindowsSystem32 directory |
| X | Ad-Eliminator | ad-eliminator.exe | Ad-Eliminator spyware remover - not recommended, see here |
| U | Ad-Muncher | ADMUNCH.EXE | Ad Muncher
removes adverts, pop-ups and general annoyances in your browser,
file-sharing and messenger programs. Causes conflicts with Outlook,
game sites and web-building applications |
| U | Ad-Protect | ad-protect.exe | Ad-Protect spyware and spam monitoring tool
|
| U | Ad-watch | Ad-watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
| U | AD2KClient | AD2KClient.exe | Executable for Active Disk
from Iomega disk - allows software applications to be run directly from
an Iomega Zip? disk. Required if you wish the applications to launch on
insertion of a disk |
| N | Adaptec DirectCD | Directcd.exe | DirectCD
primarily allows you to drag and drop files onto a suitably formatted
CD-RW disc. Unless you use this on a frequent basis it isn't required
and is available via Start -> Programs. Start the program before
inserting a DirectCD formatted CD-RW in the drive. A re-boot is
recommended if you close Adaptec DirectCD before re-opening it again
later
|
| N | AdaptecDirectCD | Directcd.exe | DirectCD
primarily allows you to drag and drop files onto a suitably formatted
CD-RW disc. Unless you use this on a frequent basis it isn't required
and is available via Start -> Programs. Start the program before
inserting a DirectCD formatted CD-RW in the drive. A re-boot is
recommended if you close Adaptec DirectCD before re-opening it again
later |
| X | AdAware | wini.exe | Added by the RBOT-XN WORM! |
| U | Adaware Bootup | ad-aware.exe | Ad-aware from Lavasoft - popular spyware/adware removal tool |
| X | Adaware lptt01 | adaware.exe | RapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware |
| X | Adaware ml097e | adaware.exe | RapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware |
| U | AdBin | AdBin.exe | AdBin - "Free and easy solution to managing your Window's hosts file. A fun way to block ads" |
| X | Add**.exe [* = random char] | Add**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Add**32.exe [* = random char] | Add**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | AddClass | AddClass.exe | CoolWebSearch Addclass parasite variant |
| X | AddClass | [Installation_Path] | Added by the STARTPAGE.F hijacker |
| X | AddClass | [path to trojan] | Added by the SECDL-A TROJAN! |
| U | AdDelete | AdDelete.exe | Banner advertisment blocker |
| X | AdDestroyer | AdDestroyer.exe | Virtual Bouncer
- malware from Spyware Labs. It is distributed by the same bundling and
drive-by download techniques as the parasites it claims to remove, so
definitely qualifies as unsolicited commercial software in itself. It
also has an update feature that can download and execute arbitrary
code. Warning - choose "custom" uninstall as "automatic" may remove
other programs - see here |
| X | ADDITIONAL Services | pkgadd.exe | Added by a variant of the IRCBOT TROJAN! |
| ? | addproxy | addproxy.exe | Related to Adobe Photoshop |
| ? | ADG | ADG.exe | SoundBlaster Audigy related? |
| N | ADGJdet | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
| X | aDir | adirss.exe | Added by the SPAMSRV-E TROJAN! |
| Y | Adiras | Adiras.exe | ADSL USB modem related |
| X | adirka | adirka.exe | Added by the TIBS-QT TROJAN! |
| U | AdKiller | AD Defender.exe | Part of Advanced Spyware Remover anti-spyware tool |
| X | adlhidp | psncc32.exe | Detected by Kaspersky as the SLAPER.AI TROJAN! See here |
| X | ADM Library Loader | admlib32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Admanager Controller | AdManCtl.exe | Adware, probably a Windupdates variant |
| X | Admilli Service | AdmilliServ.exe | Windupdates adware variant |
| X | Administrator | svchost.scr | Added by the NOVACAL TROJAN! |
| X | Administrator | winlogon.exe | Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | Administrator di Dago | Dago.exe | Added by the PUNYA-B WORM! |
| X | AdminSoft | sysfile.vbs | Added by the STARGRUB-A WORM! |
| U | admtray.exe | admtray.exe | Related to Acer Inc. destop tray |
| X | Adobe | Adobe.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Adobe | sysconfig.exe | Added by an unidentified WORM or TROJAN! |
| X | adobe | gam.exe | Added by an unidentified WORM or TROJAN! |
| X | Adobe | sysbat32.exe | Added by the LOWZONES.T TROJAN! |
| X | Adobe | zteam.exe | Added by an unidentified TROJAN! |
| N | Adobe Acrobat | READER~1.EXE | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| X | Adobe Acrobat Distiller Application | acrotray.exe | Added by the RANDEX.DFJ WORM! |
| X | Adobe Acrobat Reader CFG | [random filename] | Added by a variant of the RBOT WORM! |
| N | Adobe Acrobat Speed Launcher | acrobat_sl.exe | Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards |
| X | Adobe Filter Platform | afilterplatform.exe | Added by the RBOT-OP WORM! |
| U | Adobe Gamma Loader | Adobe Gamma Loader.exe | Adjusts
monitor colours across all programs, including Photoshop. It is needed
by some graphics professionals who want their monitor calibrated. Most
home users will not need it. In my case I can verify this as Photoshop
loads fine |
| N | Adobe Photo Downloader | apdproxy.exe | Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here) |
| N | Adobe Reader Speed Launch | Reader_sl.exe | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| N | Adobe Reader Speed Launch | READER~1.EXE | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| N | Adobe Reader Speed Launcher | Reader_sl.exe | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| U | Adobe Reader Synchronizer | AdobeCollabSync.exe | Adobe Synchronizer
- installed along with Adobe Reader 8.x. "Synchronizer is a small
application that runs in the background, providing synchronization of
document reviews and Tracker subscriptions so that your data is
available when you need it." See the link for more information |
| U | Adobe Version Cue CS2 | VersionCueCS2Tray.exe | File manager that's part of Adobe Creative Suite 2
- "find files fast, track versions across applications, link files
together, and share them in creative collaboration without fear of
overwriting someone else's work" |
| X | AdobeA | adobes.exe | Added by the FLOOD.BA TROJAN! |
| X | AdobeFonts | fonts.hta | Browser hijacker - redirecting to Hugesearch.net |
| X | adobemgr | adobemgr.exe | Added by the ADCLICKER TROJAN! |
| X | AdobeReader | msni.exe | Added by the RBOT.DAO TROJAN! |
| X | AdobeReaderPro | msnxpsp.exe | Added by the RBOT-ASK or RBOT-AUS WORMS! |
| X | AdobeReaderPro | ntkernell32.exe | Added by the RBOT-ATY WORM! |
| X | AdobeReaderPro | msnserve.exe | Added by the SDBOT-AKH WORM! |
| X | AdobeReaderPro | updt.exe | Added by the IRCBOT-VQ WORM! |
| X | AdobeReaderProfessional | msx64.exe | Added by the RBOT-GAT WORM! |
| X | AdobeReaderPros | sysmsn.exe | Added by the RBOT-BGH WORM! |
| N | AdobeUpdater | AdobeUpdater.exe | Automatic updater for Adobe software - run manually |
| N | AdobeVersionCue | VersionCueTray.exe | "An exclusive feature of the Adobe? Creative Suite, Version Cue? helps you find files fast, track multiple versions of your files, and share your files for creative collaboration" |
| X | adodemaster | adodemaster.exe | Downloader of Korean origin, detected as ADOD.28672 |
| X | Adope File Manager | lsasv.exe | Added by an unidentified WORM or TROJAN! |
| X | adp | adp.exe | Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc |
| X | AdPopup | dcf5678.exe | Added by the AGENT-FZ TROJAN! |
| X | adprot | adprot.exe | AdBlaster adware |
| N | ADQuickAccess | Adtray.exe | After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95 |
| X | ADriver | windrv.exe | Added by the DELF.WG TROJAN! |
| X | AdRoarUpdate | ARUpdate.exe | AdRoar adware updater |
| X | AdRotator.Application | [path to csrss.exe] | Added by the SMALL-AQ TROJAN! Note - this is not the legitimate csrss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| X | AdRotator.Application | services.exe | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in an "Inetsrv" subfolder |
| X | ADS Adware Remover | ADS Adware Remover.exe | ADS Adware Remover - not recommended, see here |
| X | AdsBlocker | stopAds.exe | Reported as DILAER.DW by NOD32 |
| U | AdsCleaner | AdsCleaner.exe | "AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad, kill popup), guard your online privacy" |
| U | ADService | ADService.exe | Part of Iomega's Active Disk
- allows software applications to be run directly from an Iomega Zip?
disk. Required if you wish the applications to launch on insertion of a
disk |
| U | AdsGone | Adsgone.exe | AdsGone - pop-up stopper |
| N | ADSL Diagnostic Tools | mapiicon.exe | System tray access to ADSL modem diagnostic tools. Available via Start -> Programs |
| ? | ADSLSYSTEMTRAY | SystemtrayV100B.exe | Apparently Annex A ADSL modem related. What does it do and is it required? |
| Y | AdslTaskBar | rundll32.exe stmctrl.dll, TaskBar | ISP software, initializes DSL modem |
| X | AdslTaskBars | taskmng.exe | Added by the RBOT-AXZ WORM! |
| ? | ADSL_A2 | A2Installed | Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required? |
| Y | ADSS | ADSS.exe | ADSS is part of Access Denied
security and privacy software (Access Denied Security Server) that
monitors power status and provides some other services for Screen
Guard. Important to keep its running while using Access Denied |
| X | adstartup | automove.exe | Adlogix adware variant |
| X | adstartup | Adstartup.exe | Adlogix adware variant |
| X | AdStatus Service | AdStatServ.exe | WindUpdates AdStatus Service adware |
| U | AdSubtract | adsub.exe | AdSubtract
blocks ads, cookies, pop-up windows, animations, music, and more. Can
be disabled from within AdSubtract. Available via Start -> Programs.
Now superseeded by Trend Micro AntiSpyware |
| X | adtech2005 | adtech2005.exe | Detected by Kaspersky as the STARTPAGE.AW TROJAN! |
| X | adtech2006 | adtech2006.exe | Detected by Kaspersky as the VB.KC WORM! |
| X | Adtools Service | AdTools.exe | Windupdates Adware |
| ? | ADU | adu.exe | Related to Cisco Aironet wireless products. What does it do and is it required? |
| X | AdultX | AdultX.exe | Adult content dialler and hijacker |
| X | Adult_Chat | Adult_Chat.exe | Adult content dialler |
| X | Adult_Chat1 | Adult_Chat1.exe | Adult content dialler |
| X | AdUpdater | sysupudt.exe | Unidentified adware downloader/updater |
| U | ADUserMon | ADUserMon.exe | Part of Iomega's Active Disk
- allows software applications to be run directly from an Iomega Zip?
disk. Required if you wish the applications to launch on insertion of a
disk |
| X | Advanced DHTML Enable | exo32.exe | Added by the RANCK-FI TROJAN! |
| X | Advanced DHTML Enable | [path to trojan] | Added by the AGENT.GLQ TROJAN! |
| X | Advanced Internet Protocol | cerf.exe | Added by a variant of the SPYBOT WORM! |
| X | Advanced Protection System | advpsys.exe | Added by a variant of the RBOT WORM! |
| U | Advanced Spyware Remover | Asr.exe | Advanced Spyware Remover anti spyware tool
|
| X | Advanced Tool Checks | advchks.exe | Added by a variant of the RBOT WORM! |
| N | Advanced Tools Check | ADVCHK.EXE | Checks
when you install a new version of a Norton product that you have
uninstalled all previous versions. Serves as a reminder if you forget |
| U | Advanced Uninstaller PRO Installation Monitor | monitor.exe | Innovative Solutions Advanced Uninstaller PRO - "easy-to-use suite for uninstalling applications and keeping your computer fast, clean, and in its best shape" |
| X | AdvancedCleaner Free | UADC.exe | AdvancedCleaner misleading security software - not recommended, see here |
| X | AdVantage | AdVantage.exe | MediaAdVantage adware |
| X | advap32 | [path to trojan] | Detected by Trend Micro as the MUTANT.AT TROJAN! See here |
| X | Advapi | Advapi.exe | Added by the NETDEVIL.12 WORM! |
| N | ADVCHK | ADVCHK.EXE | Checks
when you install a new version of a Norton product that you have
uninstalled all previous versions. Serves as a reminder if you forget |
| U | Advertising Killer | Akiller.exe | Advertising Killer - popup stopper |
| X | advmon32 | advmon32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | Adware Agent | adware agent.exe | Adware Agent popup blocker |
| X | Adware Spy | AdwareSpy.exe | Adware Spy adware remover - not recommended, see here |
| U | AdwareAlert | AdwareAlert.Exe | Adware program, previously not recommended (see here). It has now been delisted, so make sure you have the latest version |
| X | AdwareDelete | adwaredelete.exe | AdwareDelete adware remover - not recommended, see here |
| X | AdwareKiller_schedules | schedules.exe | EAdwareKiller spyware remover - not recommended, see here |
| X | AdwareKiller_tray | tray.exe | EAdwareKiller spyware remover - not recommended, see here |
| X | AdwareProMFC | Ad-Ware Pro.exe | Ad-Ware Pro spyware remover - not recommended, see here |
| X | AdwareRemover2007 | AdwareRemover2007.exe | AdwareRemover2007 spyware remover - not recommended, see here |
| ? | Aeiwlsta.exe | Aeiwlsta.exe | IBM High Rate Wireless LAN Adapter driver. Is it required? |
| N | AELaunch | AELaunch.exe | Audio Applications Launcher for the Philips Acoustic Edge soundcard |
| X | AERVICESN | AERVICESN.exe | Added by the RANDON-AO WORM! |
| N | AeXAgentLogon | AeXAgentActivate.exe | Altiris Agent transmits information about your machine for the purpose of asset management and deployment |
| ? | AeXSWDUsr | AeXSWDUsr.exe | Altiris Express NS Client Manager software. Is it required? |
| U | AEZBProc | aptezbp.exe | IBM
Aptiva keyboard customizer - enables certain special buttons on
keyboard for CD operation, volume control, and few quickstart buttons.
Keyboard will work without it but you lose the special functions |
| U | AFAFilter | windefault.exe | AFAFilter - internet filter software |
| X | afskfask8 | fsfjasj8.exe | Added by the ONLINEG-L TROJAN! |
| N | AGEIA PhysX SysTray | TrayIcon.exe | System Tray access to display properties for AGEIA PhysX
graphics cards. Unless you change your desktop resolution, etc,
regularily use Control Panel -> Display Properties or right-click on
the desktop |
| N | Agent | Agent.exe | Cyberlink's
Power VCR II 3.0 is a TV tuner recording utility. If you want to
schedule recordings you'll need this, otherwise can be disabled.
Available via Start -> Programs
|
| X | Agent | alsys.exe | Added by the DREF-V VIRUS! |
| X | agent | ppl.exe | Added by the DREF-U VIRUS! |
| X | Agent Browser | [random filename] | Added by the PPdoor.M-bdr backdoor TROJAN! |
| X | Agent Explorer | [random filename] | Unidentified adware |
| ? | Agente | Remupd.exe | Part of Panda Antivirus . Is this an update reminder (guess because of the name), virus definition update reminder or something similar? |
| X | agentsvr | agentsvr.exe | Malware, detected by Kaspersky as AdWare.Monker.a. NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the WindowsMsagent folder |
| U | AgfaCLnk | AgfaCLnk.exe | For
Agfa digital cameras connected via USB. Enables Windows to access the
contents of the memory stick (while the stick's still on the camera)
via a virtual drive |
| X | agp | agp32.exe | Added by the GAOBOT.SY WORM! |
| Y | AGRSMMSG | AGRSMMSG.exe | IBM AMR modem driver |
| N | AGSatellite | AGSatellite.exe | Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs |
| U | ahfp | ahfp.exe | Advanced Hide Folders
- "is powerful file security program. It allows to hide folders or hide
files. Advanced Hide Folders is very useful to keep your personal data
away from others. Others will not know where your personal files exist
and they will not be able to accidentally view, delete or modify them
either" |
| U | ahfprog | ahfp.exe | Advanced Hide Folders
- "is powerful file security program. It allows to hide folders or hide
files. Advanced Hide Folders is very useful to keep your personal data
away from others. Others will not know where your personal files exist
and they will not be able to accidentally view, delete or modify them
either" |
| Y | AHNSD | AhnSD.exe | AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis |
| ? | AHNUE | AHNUE.exe | ?? |
| X | ahost | ahost.exe | Added by a variant of the SDBOT WORM! |
| N | AHQInit | ahqinit.exe | Part
of AudioHQ for the Soundblaster Live!. Appears as though it makes the
AudioHW toolbar drop down from the top of the desktop and isn't required |
| X | Ahst | iebs.exe | PurityScan/Clickspring adware |
| X | AHU | [path to worm] | Added by the ANACON-B WORM! |
| X | AHU | ANACON.EXE | Added by the NACO.A WORM! |
| X | ahui32.exe | ahui32.exe | Added by the CERTIF-M TROJAN! |
| U | Ai Nap | AiNap.exe | Part
of the "Ai Suite" utility supplied with some Asus motherboards. "With
AI Nap, users can instantly snooze your PC without terminating the
tasks. System will continue operating at minimum power and noise when
user is temporarily away" |
| N | Ai Quicker Help | AsRc.exe | ASUS
DH Remote media portal launcher for their Digital Home range of
motherboards that are designed for users to control the computer at a
distance away, such as the M2N DH.
"ASUS DH Remote is a convenient PC remote controller that gives users
unprecedented control over their PCs from the comfort of their couches" |
| X | Aica | tuaa.exe | PurityScan/Clickspring adware |
| X | Aida | ttuh.exe | PurityScan/Clickspring adware |
| X | Aida | eetu.exe | PurityScan/Clickspring adware |
| ? | AidemHotKey | DVMAIN.EXE | Keyboard related |
| ? | AidemHotKey | KEYAPP.EXE | Keyboard related |
| U | aiepk | aiepk2.exe | Another IE Popup Killer - pop-up stopper |
| N | AIM | aim.exe | AOL
Instant Messenger. If connected to the internet, automatically runs up
AIM. Convenience more than anything. Available via Start -> Programs |
| U | AIM | AIM+.exe | AIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software |
| X | AIM Instant Message Cookies | [random filename] | Added by the RBOT-AFV WORM! |
| N | AIM Logger | AIMLogger.exe | AIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM |
| X | Aim Plugin | aimplugin.exe | Added by the GUAP-F WORM! |
| X | AIM reminder | AIM reminder.exe | Added by the BUDDY TROJAN! |
| N | Aim6 | AOLLaunch.exe | AOL Instant Messenger - start it when you want to use it |
| N | Aim6 | aim6.exe | AOL Instant Messenger - start it when you want to use it |
| X | AIM95 Startup | aim95.exe | Added by the AGOBOT.AEE WORM! |
| X | aimaol lptt01 | aimaol.exe | RapidBlaster variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
| X | aimaol ml097e | aimaol.exe | RapidBlaster variant (in a "Aimaol" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
| U | aimb.exe | aimb.exe | IMSufSentinel
is a spy program which can record IM conversations, log keystrokes,
record URLs visited, and take screenshots. If you didn't install this
yourself remove it |
| N | AimingClick | AimingClick.exe | AimingClick from AimingTech. Web searching tool. Available via Start -> Programs |
| U | AIMPro | aimpro.exe | AIM Pro - secure instant messaging, video conferencing, on-line meetings and desktop and file sharing |
| N | AIMster | ?? | Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs |
| N | AIMWDInstall | AIMWDInstall.exe | Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| Y | Aiptek Graphics Tablet (USB) | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) |
| X | aircity | aircity.exe | Related to "Prutect" malware from e2Give |
| U | AirPort Base Station Agent | APAgent.exe | Airport Base Station Agent utility for Apple's AirPort
wi-fi basestations. "Wireless solution for home, school, and business.
As it blankets your space with a blazing-fast, secure wireless network,
it opens up a world of possibilities for home entertainment, backups,
printing, and more" |
| X | AKEYNAME | WinServ.exe | Added by the EVILBOT.C TROJAN! |
| U | akeys | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" |
| X | akgkagaksad9 | fsakfask9.exe | Added by the ONLINEG-M TROJAN! |
| U | AKiller | akiller.exe | Advertising Killer - popup stopper |
| X | ala.exe | ala.exe | Access Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer |
| U | Alarm Manager | Alarmapp.exe | Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop |
| ? | AlarmWatcher | AlarmWatcher.exe | Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required? |
| N | Album Fast Start | ABMTSR.EXE | Scanner software, not required for scanner to work |
| ? | AlcFDMonitor | ALCFDRTM.EXE | RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup? |
| ? | ALCFDRTM16 | ALCFDRTM16.com | RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup? |
| X | Alchem | Alchem.exe | ClickAlchemy adware |
| U | Alcmtr | Alcmtr.exe | Installed
with hardware drivers for a Realtek AC97 audio device. It's believed
that Realtek uses this file in order to data about the customer. Some
users report problems with their on-board sound if this is disabled -
hence the "U" recommendation |
| U | Alcohol | Alcohol.exe | Alcohol 120% - CD/DVD emulation/writing/copying software |
| U | Alcohol Autorun | Alcohol.exe | Alcohol 120% - CD/DVD emulation/writing/copying software |
| U | AlcoholAutomount | axcmd.exe | Alcohol 120%
is a powerful Windows application that makes it easy to create backups
of DVDs* and CDs. In addition, the program lets you store your most
used CDs as images on your computer, so you can call them up at the
click of a button. This part automounts images disc images |
| ? | Alcom PCL Capture | FMW_PCAP.EXE | ?? |
| N | AlcWzrd | ALCWZRD.EXE | RealTek
High Definition audio driver related - detects new devices when plugged
in, then pops up a dialog box. If everything works as expected you
should be able to disable this one |
| U | AlcxMonitor | Alcxmntr.exe | Installed
with hardware drivers for a Realtek AC97 audio device. It's believed
that Realtek uses this file in order to gather data about the customer.
Some users report problems with their on-board sound if this is
disabled - hence the "U" recommendation |
| X | aldefr ere service | tay0x.exe | Added by the RBOT-XS WORM! |
| X | alerter | alerter.exe | Added by the MAHA.F TROJAN! |
| X | Alevir | Alevir.exe | Added by the OPASERV-A WORM!
|
| X | AlevirOld | [worm filename] | Added by the OPASERV WORM!
|
| N | Alexa | alexa.exe | Related
to Alexa. Note - collects and stores information about the web pages
you view, the data you enter in online forms and search programs and,
with versions 5.0 and higher, the products you purchase online whilst
using the toolbar. Although Alexa state's they do not attempt to
analyze the data it may collect about you to determine who you are,
some of your information collected by the software is personally
identifiable. Please read the Privacy Policy. Not Recommended |
| X | AlexaToolbar | alt.exe | Reported as the DELF.EB hijacker by Ewido Security Suite |
| X | AlfaCleaner | AlfaCleaner.exe | AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware
|
| U | AlfaClock Classic | AlfaClock.exe | AlfaClock
from AlfaSoft Research Labs - "enhances your taskbar clock (tray clock)
with fully customizable clock display, alarms, time synchronization and
more"
|
| U | AlfaClock2 | AlfaClock2.exe | AlfaClock2 - tray/desktop clock and time synchronization software |
| ? | ALFY Accellerator | AlfyAC~1.exe | ?? |
| X | ALG.EXE | iexplorer .exe | Added by the DEMOTRY-B WORM! |
| X | ALG32 | ALG32.EXE | Added by the STARTPAGE.K hijacker |
| X | algchk.exe | algchk.exe | Detected by Kaspersky as the VB.ATE TROJAN! |
| X | ALGU | ALGU.EXE | Added by the CWS-I TROJAN! |
| U | ALi5289 | ALi5289.exe | Related to Uli Integrated Drivers from Uli Electronics Inc |
| N | Alias SketchBook Snapshot | ALIASS~2.EXE | Screen-capture utility for Alias Sketchbook |
| N | AlienAutopsy | Test_BS.exe | Alienware computer technical support software |
| Y | ALiSndMgr | ALiSndMg.exe | ALi AC97 Sound driver |
| ? | AliUSBfix | GREENMK.exe | May be realted to a USB 2.0 PCI card - the IOgear GIC220OU? |
| X | Alive SYstem | scchost.exe | Added by the TOFDROP-B TROJAN! |
| X | Alive SYstem | scchostc.exe | Added by the TOFDROP-B TROJAN! |
| X | alkasr | ?????.exe | Added by the BALKART TROJAN! |
| U | All Aboard Status | stswin.exe | All Aboard! Internet Connection Sharing status icon |
| X | All Sea screen saver | TaskTray.exe | "Free screensaver", installs lots of foistware. See here. Get rid of it |
| X | All Sea web link | FWLink.exe | "Free screensaver", installs lots of foistware. See here. Get rid of it |
| N | AllerCalc | AllerCalc.exe | AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually |
| X | Allopassw | [path to trojan] | Added by the RANKY.CU TROJAN! |
| U | AllSeeingEye | ase.exe | All-Seeing_Eye
security software - "monitors everything that takes place on your
computer, and alerts the user as soon as anything suspicious or
out-of-the-ordinary is happening, providing the user with alternatives
for possible actions" |
| U | allSnap | allSnap.exe | "allSnap
is a small system tray app that makes all top level windows
automatically align like they do in programs such as Winamp or
Photoshop" |
| U | AllToTray | ALLTOTRAY.EXE | AlltoTray from DNTSoft - minimize any program to your System Tray
|
| X | Alogrithm Link Queue | alq.exe | Added by a variant of the SDBOT WORM! |
| U | Alogserv | Alogserv.exe | From
McAfee VirusScan for logging scanning activities. In some cases, if
left running it can cause CPU % usage to go between 5-95% or go to and
stay at 100%. Disabling it impacts on the reported last scan date. It
is reported to cause jerky graphics response in many games. As of
version 6, this is a critical component of McAfee and disabling it can
cause a PC to lock up |
| U | ALPass | ALPass.exe | ALPass password manager |
| X | alpha | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| Y | Alps Electric USB Server | Monserv.exe | Alps Electric USB Server - required according to this article
|
| U | AlpsPoint | Apoint.exe | Touchpad
software for laptop PC's. For instance it is found on the Panasonic and
Sony Vaio machines and allows part of the touchpad to be used for
document or Web-page scrolling. Required for proper functioning of the
pointing software but not required for the laptop to work |
| ? | ALServ | ALServ.exe | Altec Lansing AMS speaker related. What does it do and is it required? |
| X | Altnet | points manager.exe | Altnet TopSearch adware |
| X | AltnetPointsManager | points manager.exe | Altnet TopSearch adware |
| U | AltoMB_service | AltoMBsrv.exe | Alto Memory Booster from Alto Software
- boost the computers performance via more intelligent and efficient
memory management. MS MVPs (Most Valued Professional) recommend not
using memory managers with Win98/SE/ME. See this article and make up your own mind |
| U | ALTOOLS | AccessL.exe | ALTools family of PC utilities
|
| X | AltPayments | AltPayments.exe | WeirdOnTheWeb adware |
| N | ALU Scheduler Service | ALUSchedulerSvc.exe | Symantec LiveUpdate scheduler for programs such as Norton AV or Internet Security |
| U | ALUAlert | ALUNotify.exe | Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis |
| N | Aluria Security Center | SecurityCenter.exe | Aluria
Software's spyware removal tool - we can't really recommend this
product as Aluria have recently partnered with WhenU, the well known
adware company, see here |
| U | Aluria's Pop-Up Stopper | eps.exe | Aluria Pop-Stopper |
| N | Aluria's Spyware Eliminator | ASE.exe | Aluria
Software's spyware removal tool - we can't really recommend this
product as Aluria have recently partnered with WhenU, the well known
adware company, see here |
| U | AlwaysOnTopMaker | AlwaysOnTopMaker.exe | Always On Top Maker - utilty to enable an application to always be displayed "on top" of others on the desktop |
| N | AlwaysReady Power Message APP | ARPWRMSG.EXE | Related to HP and Compaq Desktop PCs. Read this article |
| X | AmazingTens | AmazingTens.exe | Premium rate adult content dialler |
| U | AMD PowerNow! | GemBack.exe | AMD PowerNow!
- "an innovative solution available on all AMD mobile processor-based
notebooks that can effectively increase notebook battery life, while
delivering performance on demand" |
| Y | amd_dc_opt | amd_dc_opt.exe | AMD Dual-Core Optimizer
- "can help improve some PC gaming video performance by compensating
for those applications that bypass the Windows API for timing by
directly using the RDTSC (Read Time Stamp Counter) instruction" |
| N | America Online *.* Tray Icon | aoltray.exe | Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs |
| N | AME_CSA | rundll32 amecsa.cpl, RUN_DLL | Loads ADSL modem Control Panel applet |
| U | AModemLockDown | ModemLockDown.exe | ModemLockDown - allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc |
| Y | Amon | AMON.EXE | Monitoring part of Eset's NOD32 virus-scanner |
| Y | Amonitor | amon.exe | Tiny Personal Firewall |
| U | AMP WinOFF | winoff.exe | WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way" |
| U | AMSG | Amsg.exe | Part of the IBM ThinkVantage Productivity Center. "The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online" |
| X | amsgupdate | ams.exe | Added by a variant of the MAILBOT TROJAN! |
| N | AMSN | amsn.exe | aMSN Messenger is a multiplatform MSN messenger clone |
| X | amsn | amsn.exe | Added by the BANKER-BNZ TROJAN! |
| X | amva | amvo.exe | Added by the SILLYFDC-BR WORM! |
| N | Anapod Manager | anamgr.exe | Anapod Explorer
"is the most advanced Windows iPod software available, offering iPod
management through full Windows Explorer integration under My Computer" |
| X | anbv32 | nabv32.exe | Added by the TITOG.C WORM! |
| X | angeleyes | msdll.exe | Detected by Kaspersky as the VB.PI TROJAN! See here |
| Y | ANIWZCS2Service | WZCSLDR2.exe | ALPHA Networks wireless driver |
| ? | ANIWZCSService | WZCSLDR.exe | D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity |
| ? | AnnotateCheck | AnnCheck.exe | Genius Wizard Pen Tablet driver related. Is it required? |
| N | Announcements | Annclist.exe | MS
WebTV for Windows. Used to display TV on your PC via a compatible video
card with in-built tuner (such as ATI All-In-Wonder). If you don't use
it - uninstall it |
| N | Anntext | Anntext.exe | Caere Pagekeeper text annotation server |
| U | AnonymityGateway | Anonymity Gateway.exe | Anonymity Gateway
- privacy protection tool that conceals IP address preventing your
surfing habits and your internet activity form being tracked by
websites or Internet Service Providers |
| U | Anonymizer Total Net Shield | AnonTns.exe | Anonymizer Total Net Shield - ID protection and privacy software |
| U | ANONYMIZER_SPYWAREKILLER | SpyWareKiller.exe | Anonymizer Spyware Killer - now Anti-Spyware |
| U | ANONYMIZER_SPYWAREKILLER | AnonAntiSpyware.exe | Anonymizer Spyware Killer - now Anti-Spyware |
| U | Another Internet Explorer Popup Killer | aiepk2.exe | Another IE Popup Killer - pop-up stopper |
| X | ansjava | [path to worm] | Added by the RANDON-AN WORM! |
| X | Anskya | PYSKY.NET.exe | Added by the DLOADER-MW TROJAN! |
| X | Answer Problem | dSAFsqs.exe | Added by the SDBOT-SC WORM! |
| U | AnswerTool | AnswerTool.exe | AnswerTool - save your E-mail replies in AnswerTool, then reuse them again and again
|
| X | Anti | Isass.exe | Added by the BROPIA.K WORM! |
| X | Anti Spam Service | spamsvc.exe | Added by the MYTOB-BK WORM! |
| N | Anti-Blaxx Manager | Anti-Blaxx.exe | Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives
|
| U | Anti-keylogger check | antikey.exe | Anti-keylogger - protects against keylogger programs monitoring your keystrokes |
| U | Anti-Trojan-Watch | ATWatch.exe | Anti-Trojan Watch - trojan detector |
| X | Anti-Virus | vpms.exe | Added by a variant of the SLAPER TROJAN! |
| X | Anti-Virus | [random filename].exe | Added by the CAPROBAD-A TROJAN! |
| X | Anti-Virus Product Sync | [unprintable character][3 characters]log.exe | Added by the KEDEBE.D WORM! |
| X | Anti-Virus Update Scheduler | [path to trojan] | Added by the SPAMMIT-A TROJAN! |
| X | Anti-Virus Update Scheduler | winsp3.exe | Malware - detected by Kaspersky as the AGENT.FP TROJAN! |
| X | Anti-Virus Update Scheduler V1.39.12R | [path to trojan] | Added by the HEPLANE or STAPREW.B
TROJANS! - different filenames have been spotted; examples: msvc.exe,
kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe,
alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe,
xps2.exe, dns2.exe, ikav32.exe and more... |
| X | AntiClicker | SVCHST32.EXE | Added by the CBH TROJAN! |
| U | antidialer.co.uk | Dialer_Watcher.exe | Dialer_Watcher is an application that allows you to detect dialers on your computer |
| X | antihost | ahr.exe | Added by the BANCBAN-QJ TROJAN! |
| U | AntiPopUp | AntiPopUp.exe | AntiPopUp for IE - pop-up stopper |
| X | AntiSpyKit *.* | AntiSpyKit *.*.exe | EAdwareKiller spyware remover, where *.* represents the version number - not recommended, see here |
| X | AntispyStorm | AntispyStorm.exe | AntiSpyStorm misleading security software - not recommended, see here |
| X | AntiSpyware | Antispyware.exe | AntiSpywareApp spyware remover - not recommended, see here |
| X | AntiSpywareBot | AntiSpywareBot.exe | AntiSpywareBot spyware remover - not recommended, see here |
| X | AntiSpywareMaster | asm.exe | AntiSpywareMaster spyware remover - not recommended, see here |
| X | AntiSpywareShield | AntiSpywareShield.exe | AntiSpywareShield spyware remover - not recommended, see here |
| X | AntiVerminser | AntiVerminser.exe | AntiVerminser spyware remover - not recommended, see here |
| X | antiviirus | antiviirus.exe | Added by a variant of the AGENT.KEU TROJAN! |
| X | Antivir | svchst.exe | Added by the RAGRUK-A TROJAN! |
| X | AntiVir | scvhost.exe | Added by the AGENT-DSF TROJAN! |
| X | AntiVir | winlog.exe | Added by the IRCBOT-TJ TROJAN! |
| Y | AntiVir XP | AVwin.exe | AntiVir? PersonalEdition Classic - antivirus
|
| X | AntiVirGear *.* | AntiVirGear *.*.exe | AntiVirGear misleading security software, where *.* represents the version number - not recommended, see here |
| X | Antivirus | av.exe | Added by the SINKIN TROJAN! Resets IE start page to realphx.com |
| X | Antivirus | maja.exe | Added by the NETSKY.H WORM! |
| X | Antivirus | iexpl0res.exe | Added by an unidentified WORM or TROJAN! |
| X | AntiVirus | kaspery.exe | Added by a variant of the RBOT WORM! |
| X | AntiVirus | AntiVirus.exe | Added by the BANKER-EHB TROJAN! |
| X | Antivirus Installer | [path to trojan] | Added by the BADGENT-A TROJAN! |
| X | AntiVirus Process | virprot.exe | Added by a variant of the SDBOT WORM! |
| X | Antivirus Protection Services | ccapp2.exe | Added by the RBOT.EXI WORM! |
| X | AntiVirus Update | updates.exe | Added by the RBOT-JF WORM! |
| X | AntiVirus Update | antivirus.exe | Added by the RBOT-IF WORM! |
| X | Antivirus-Golden | Antivirus-Golden.exe | Antivirus-Golden misleading security software - not recommended, see here |
| X | antivirus32 | antivirus.exe | Added by the SPYBOT.KAI WORM! |
| X | AntivirusGold | AntivirusGold.exe | AntivirusGold malware |
| X | AntiVirusPro | AntiVirusPro.exe | AntiVirusPro misleading security software - not recommended, see here |
| X | AntiVirusProMFC | Antivirus Pro.exe | AntiVirusPro misleading security software - not recommended, see here |
| ? | AntiVirusProtection | qumk.exe | ?? |
| X | AntiVituS | Base.exe | Added by the BAS.A WORM! |
| X | antiware | elite***32.exe [*** = random char] | Added by the DLOADER-HW TROJAN! |
| U | AntiWindowsMessenger | AntiMsMsg.exe | Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory |
| X | anti_troj | anti_troj.exe | Added by the LODEAR.D TROJAN! |
| Y | AnVir | AnVir.exe | AnVir Task Manager - protects computer against viruses and manages running processes and startup files |
| Y | AnVir Task Manager | AnVir.exe | AnVir Task Manager - protects computer against viruses and manages running processes and startup files |
| U | anvshell | anvshell.exe | System
Tray tool for ASUS video cards. If disabled you lose all the ASUS
specific video card options in Control Panel -> Display Properties
-> Advanced as well as the System Tray shortcuts toolbar |
| U | Any To-Do List | anytodo.exe | Any To-Do List "the ultimate software solution to keep yourself organized and reminded"
|
| ? | anycom bluetooth | ftflauncher.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? |
| U | AnyDVD | AnyDVD.exe | AnyDVD
- descrambles DVD-Movies automatically in the background and the DVD
appears unprotected and region code free. Also removes prohibited
operations from the DVD such as skipping adverts - hence the "U"
recommendation |
| N | AO Tray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
| Y | aol | avp.exe | AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory |
| X | AOL 9.0 Optimized | AOLClient.exe | Added by the SPYBOTER.A TROJAN! |
| U | AOL Broadband Check-Up | matcli.exe | "matcli.exe
is a motive Assistant Command line interface that gathers information
about your system's identity like your name email address, city,
county, etc and gets written to a log file". The AOL Self Support Tool
is required to run with the Help and Support program. If you uncheck
AOL and and then run Help and Support it will add another AOL entry in
the startup menu. If you remove this software in "add/remove programs"
some help menus in help and support will not be available. You decide |
| N | AOL Companion | companion.exe | Part
of the AOL Connection Suite and installs an icon on the system tray
offering easy access to AOL's additional utilities and functions. This
program is a non-essential process, and is installed for ease of use
|
| X | Aol Configuration Loader | aimsng.exe | Added by the SDBOT-XE WORM! |
| ? | AOL Fast Start | AOL.exe | AOL ISP software related. What does it do and is it required? |
| X | AOL Instant Messanger | aim.exe | Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility |
| X | AOL Instant Messengar | aol.exe | Added by the AGOBOT-FN WORM! |
| ? | AOL Instant Messenger | AlM.EXE | That is an L between the A and M, the start up location is wrong for AIM. What does this relate to? |
| X | Aol Instant Messenger | aolmsg.exe | Added by the KELVIR.AL WORM! |
| X | AOL Instant Messenger | aimsgr.exe | Added by the IRCBOT.N TROJAN! |
| X | AOL Instant Messenger 7.213 | aim9283.exe | Added by the SDBOT-ZF WORM! |
| X | Aol Instant Messenger Fix | aolfix.exe | Added by the SDBOT-ABJ WORM! |
| X | AOL Messenger | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | AOL Messenger | aolmsngr.exe | Added by the SDBOT-JF WORM! |
| X | AOL Messenger Optimized | AOLOpt.exe | Added by the AOLOPT TROJAN!
|
| X | AOL Services Hosts | aolserviceshosts.exe | Added by an unidentified WORM or TROJAN! |
| U | AOL Spyware Protection | AOLSP Scheduler.exe | AOL's spyware protection program |
| U | AOL TopSpeedMonitor | aoltsmon.exe | AOL's TopSpeed
web acceleration technology supposedly helps to make web browsing
faster. Most important for those users who still access AOL via dial-up |
| Y | AolAcsDaemon1 | Acsd.exe | AOL
Connectivity Service - starts an automatic function that restores the
connection should you lose it while online. Negates having to go
through the procedure of signing back on manually |
| Y | AolAcsDaemon1 | AOLACSD.EXE | AOL
Connectivity Service - starts an automatic function that restores the
connection should you lose it while online. Negates having to go
through the procedure of signing back on manually |
| ? | AOLCC | ACCAgnt.exe | AOL ISP software related, file located in a "AOL Computer Check-Up" folder. What does it do and is it required? |
| X | AolCon | config.com | Added by the TAPLAK WORM! |
| N | AOLDialer | AOLDial.exe | AOL ISP software dialer - can be activated through a desktop shortcut |
| N | AolFix | AolFix.exe | Run
on Gateway Astra computers, and maybe a few others. Designed to repair
a bad registry key in Gateway computers that would not allow AOL
to run correctly. Not seen much any more and should only run once |
| X | AOLRegKey32 | AOREGSVR512.EXE | Unidentified malware - see here
|
| ? | AOLSAV | AOLAgent.exe | AOL ISP related. What does it do and is it required? |
| X | AOLStart | AOLStart.exe | Added by the KRAIMER.12 TROJAN! |
| X | aolupdater.exe | aolupdater.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Aornum | aornum.exe | Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware |
| N | AOTray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
| X | aouei | sysrtmvs.exe | Chivio dialer |
| Y | APC UPS Status | Display.exe | APC PowerChute Personal Edition status icon |
| U | APC_SERVICE | mainserv.exe | PowerChute? Personal Edition - "safe system shutdown software with sophisticated power management functions" |
| Y | apc_tray | apc_tray.exe | Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure |
| X | APD123 | APD123.exe | PacerD Media/Pacimedia.com adware |
| X | Api**.exe [* = random char] | Api**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Api**32.exe [* = random char] | Api**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | API32 | api32.exe | Added by the IRCBOT-B TROJAN! |
| X | APIClass | lexplore_.exe | Added by the MSNOPT-A TROJAN! |
| X | APIMon | apimonx.exe | Added by the TIBSER.A downloader TROJAN! |
| X | APIMon | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | APIMon | msreg.exe | Added by the DROPPER.Z TROJAN! |
| X | apisvc.exe | apisvc.exe | Added by a variant of the LAMEBOT TROJAN! |
| U | APL | APL.exe | Sage Software's ACT!
The application pre-loader (apl.exe) is a self contained executable
that pre-loads the necessary .NET framework and ACT! 2005 assemblies.
This pre-loading of assemblies enhances ACT! startup, view load and
dialog load times in some areas of the application |
| ? | Apmsrv9x | APMSRV9X.EXE | Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required? |
| U | Apoint | Apoint.exe | Touchpad
software for laptop PC's. For instance it is found on the Panasonic and
Sony Vaio machines and allows part of the touchpad to be used for
document or Web-page scrolling. Required for proper functioning of the
pointing software but not required for the laptop to work |
| X | App**32.exe [* = random char] | App**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | App.EXEName | [path to worm].exe | Added by the BODIRU WORM! |
| U | Appcon | vAppCon.exe | Vital Application Console - part of POS-partner 2000
point-of-sale software from Vital. This is the taskbar icon and is
enabled at startup by the "Auto-start when OS starts" option. Required
for a connection to be established |
| X | appconn | appconn.exe | Added by the CARGAO WORM! |
| U | AppExtender | AppExtCB.exe | Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received |
| X | appis.exe | appis.exe | Added by the AGENT-BC TROJAN! |
| X | AppletINIT | INITIATE.EXE | Added by the AGOBOT.XV TROJAN! |
| Y | Application | mdmsetsp.exe | Aztech Labs modem driver |
| X | Application Adapter | abvsvc.exe | Added by the CHECKOUT WORM! See here |
| U | Application Explorer | Naldesk.exe | Novell
Zenworks Application Explorer Executable. "For almost all users the
Novell ZENworks agent (either Application Launcher or Application
Explorer) will be run via the user's login script on each successful
login. ZENworks is used to periodically deliver software updates and is
also used to install the remote management components." |
| U | Application Explorer | NalView.exe | Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications |
| U | Application Launcher | Application Launcher.exe | Application launcher from the Sony Ericsson PC Suite for their mobile phones |
| X | Application Layer Browser | abgsvc.exe | Added by the ULPM.FX TROJAN! |
| X | Application Layer Browser | apnsvc.exe | Added by the CHECKOUT WORM! See here |
| X | Application Layer Gateway Service | algs.exe | Added by the LINKBOT.M WORM! |
| X | Application Layer Scheduler | agtsvc.exe | Detected by PCTools as the IRCBOT.BJJ TROJAN! See here |
| X | Application Layer Services | avrsvc.exe | Detected by PCTools as the IRCBOT.BJM TROJAN! See here |
| X | Application Manager | acnsvc.exe | Added by a variant of the IRCBOT TROJAN! |
| X | ApplicationProtocolRun | smsbvl32.exe | Added by the IRCBOT-CX TROJAN! |
| U | AppPlus | AppPlus.exe | AppPlus
- "menu bar or tray launcher that docks to your desktop, floats or sits
in your System Tray. Create graphic/text-based buttons that launch any
number of programs, Websites, e-mail addresses or folders (which open
in the AppPlus Menu System)" |
| Y | Apvxd | APVXDWIN.EXE | Part of Panda Antivirus. Required to enable permanent virus protection |
| Y | Apvxdwin | APVXDWIN.EXE | Part of Panda Antivirus. Required to enable permanent virus protection |
| U | APVXDWIN | ClShield.exe | "Panda ClientShield with TruPrevent
is designed for companies that want the best protection for their
workstations. It protects against viruses and other known and unknown
threats including spam, spyware, dangerous or time-wasting content,
phishing scams, hackers and intruders" |
| Y | Apwheel | Apwheel.exe | Wheel support for an Alps mouse |
| X | apyginapygin | simenu.exe | Added by the SDBOT.BTR WORM! |
| U | AQ3HelperStartUp | AQ3HEL~1.EXE | ScreenScenes "Aquatica Water Worlds" screensaver. The freeware version comes with GAIN
branded ads (pop-ups and others). ScreenScenes do however offer you the
option of doing away with the ads by purchasing the screensaver for a
whopping $30. Please note that Claria Corporation no longer support
GAIN-Supported software - see here |
| X | aqadcup.exe | aqadcup.exe | Added by the AGENT.BG WORM! |
| Y | Aqua Dock | Aqua Dock.exe | Aqua Dock
- "free program that allows you to have an ?OS X? style, nice animated
launchbar / taskbar on your screen that reacts to your mouse when you
mouse over it. Users can customize the look of each item on the dock
and set various animation options for when the mouse is over an item on
the dock. It is very easy to configure" |
| X | Aqujyjax | [path to file] | Added by the RANCK-CQ TROJAN! |
| X | Aqujyjax | aqujyjax.exe | Added by the SDBOT-YC WORM! |
| X | ara-key | [random filename] | Added by the ANTINNY WORM! |
| X | arcaderockstar | arcaderockstar32.exe | Arcade Rockstar (now Gamevance)
- free arcade games and prize tournaments. The program itself is clean,
but the TOS and privacy statement say that you agree to allow the
program to track/report your surfing and put popup advertising on your
computer |
| X | Archive | archive.exe | Adware - detected by Kaspersky as the CENTIM.A TROJAN! |
| X | ARCHIVE CONTROL | fixupdattr.exe | Added by the MYTOB.GU WORM! |
| N | ARCSolo Recovery | N/A | Backup software by Computer Associates - no longer supported |
| U | Ardamax Keylogger | akl.exe | Ardakey B keystroke logger/monitoring program - remove unless you installed it yourself!
|
| N | ares | ares.exe | "Ares
is a free open source file sharing program that enables users to share
any digital file including images, audio, video, software, documents,
etc" |
| N | areslite | AresLite.exe | "Ares
is a free open source file sharing program that enables users to share
any digital file including images, audio, video, software, documents,
etc" |
| U | Argentum Backup | ab.exe | Argentum Backup - a small backup program that lets you easily back up your documents and folders |
| X | Aritima | aritima.exe | Added by the ARITIM WORM! |
| N | ARMOR2NET | Armor2net.exe | Related
to Armor2net personal firewall (possibly contains or is related to an
anti-spyware product known as ArmorWall, which is a spyware remover -
not recommended, see here |
| X | aromis | aromis.exe | Added by the NUWAR.JQ WORM! |
| N | AROReminder | aro.exe | Advanced Registry Optimizer
- "scan, identify, clean and repair errors in your Windows registry
with a single click". Reminder that states that you are in trial mode |
| N | ARPWRMSG | ARPWRMSG.EXE | Related to HP and Compaq Desktop PCs. Read this article |
| U | Artera | arteraui.exe | Artera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance |
| ? | AS00 Gear511 | Gear511.exe | Software
for Netgear wireless network cards. Unknown whether it is required for
the wireless card to run but does not seem to be a resource hog. Not
required for laptop to run if the wireless network card will not be
used. Is it at all required? |
| N | AS00_Gear511 | Gear511.exe | Netgear wireless LAN configuration utility |
| U | AS00_WN511B | WN511B.exe | Netgear RangeMax NEXT wireless adapter configuration utility |
| ? | AS00_WPN511 | WPN511.exe | NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? |
| X | ASDPLUGIN | dsldbaccess.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | canada.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | france.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | fullgames.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | 100171be.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | 100176br.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | adult1.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | Austria.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | belgium nm.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | czech.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | dbaccess.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | dslgeaccess.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | Finland.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | geaccess.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | mexico.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | netherlands.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | turkey.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | uk nm.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | Xadult1.exe | AsdPlug premium rate adult content dialer variant |
| X | ASDPLUGIN | temp532.exe | AsdPlug premium rate adult content dialer variant |
| X | asdsaxcxz13 | dasxcsx13.exe | Added by the LEGMIR-ARF TROJAN! |
| X | asdx | xwinrpc32.exe | Added by the AGOBOT.VO WORM! |
| N | ASE Scheduler | ASE Scheduler.exe | Aluria
Software's spyware removal tool - we can't really recommend this
product as Aluria have recently partnered with WhenU, the well known
adware company, see here and here |
| Y | Ashampoo FireWall | FireWall.exe | Ashampoo FireWall Free version |
| Y | Ashampoo FireWall PRO | FireWall.exe | Ashampoo FireWall PRO version |
| U | Ashampoo PopUpBlocker | PopUpKiller.exe | Ashampoo popup blocker, part of Magical Security (was Privacy Protector Plus) |
| Y | ashAvast | ashAvast.exe | Part of Avast antivirus |
| X | ASHLT | Ashlt.exe | Ashlt adware |
| Y | ashMaiSv | ashmaisv.exe | Part of Avast! anti-virus software - E-mail scanner |
| X | Asicfc | icfca.exe | Added by the AGENT.AAJE WORM! |
| U | AsioReg | regsvr32.exe ctasio.dll | ASIO
(Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series
soundcards - for recording and home project studios. Required if you
use this functionality |
| U | AsioThk32Reg | rregsvr32.exe ctasio.dll | ASIO
(Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series
soundcards - for recording and home project studios. Required if you
use this functionality |
| U | ASK | rundll32.exe [path] ASK.dll rdl | Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | asl | Aslru.exe | Added by the BANCOS-CU TROJAN! |
| U | ASM | ASMonitor.exe | Active Security Monitor
from AOL - helps you determine how vulnerable your PC is to computer
viruses, spyware and other dangers and learn what steps you can take to
improve your protection |
| U | Asmw Soft Popups Burner | popups burner.exe | Popup blocker, part of Asmw Soft PC Optimizer |
| X | asnconsole | msasn.exe | Added by the RBOT.EVU TROJAN! |
| X | ASocksrv | SocksA.exe | Added by the VB.CBW WORM! |
| X | asp-srvc | asp-srvc.exe | Added by the AGOBOT-KE WORM! |
| X | ASP.NET State Service | csrss.exe | Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the Windows or Winnt folder |
| X | ASP.NET State Service | crsass.exe | Added by the BANLOAD-M TROJAN! |
| X | ASP.NET State Service | servicos..exe | Added by the DADOBRA-I TROJAN! |
| N | asp4tray | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
| Y | AspireTimeMachine | acertmb.exe | System
recovery software supplied with some Acer notebook PCs. Similar to
GoBack and the restore program in WinXP, allowing you to restore a PC
back to a working state with minimal re-entry |
| X | asrupdate.exe | asrupdate.exe | Added by the VB.ATZ TROJAN! |
| X | assistse | ASSISTSE.EXE | CnsMin (Chinese Keywords) hijacker related |
| X | AST | AST | Added by the TROJANDOWNLOADER.WIN32.VB.AH VIRUS! |
| X | AST | AST | Added by the VB.AH TROJAN! |
| X | AST | AST.exe | AutoStarter parasite
|
| U | ASTART | astart.exe | ASUS
TweakEnable - restores manually changed settings for ASUS based video
cards such as overclocking. Only required if you use non-standard
settings |
| X | AStart | AStart | Added by the VB.AH TROJAN! |
| N | asTray | Astray.exe | Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer |
| N | Astro | Astro.exe | Checks for updates to Quicken on a system reboot |
| N | ASUS Live Update | ALU.exe | ASUS Live Update utility for their motherboards |
| N | ASUS Probe | AsusProb.exe | ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area |
| U | ASUS SmartDoctor | VGAProbe.exe | ASUS video card fan/thermal monitor |
| U | ASUS TweakEnable | astart.exe | Restores
manually changed settings for ASUS based video cards such as
overclocking. Only required if you use non-standard settings |
| N | ASUSKey | V38SHELL.EXE | System tray Icon for quickly changing video modes |
| U | asustweakenable | ATweak.exe | Asus tweaking utility - for fine tuning the settings of your ASUS display card |
| N | ASWDP | ASWDP.exe | MLS Pulse
- real estate software. Keeps the home buyer/seller continually
informed on the status of his/her local/regional real estate market |
| X | ASWnk | aswnk.exe | Adult content dialler |
| U | AT-Watch | ATWatch.exe | Anti-Trojan Watch - trojan detector |
| X | atapidrv | atapidrv.exe | Added by the AGOBOT-SL WORM! |
| U | atchk | atchk.exe | AMT Status Message from Intel. Users can manage this, read the article. See here for more information on Intel AMT |
| U | Athan | Athan.exe | Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world |
| X | ATI Active Graphics Card Monitor | atievx.exe | Added by the IRCBOT-TL WORM! |
| X | ATI AS Filter | msnse.exe | Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines, preventing access to the virus cleaning websites |
| N | ATI CATALYST System Tray | CLI.exe SystemTray | System
Tray access to ATI's CATALYST? CONTROL CENTER. Note that this has
"SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG.
Not required to run the control center - which is available via a
right-click on the desktop |
| N | ATI DeviceDetect | ATIDtct.EXE | Utility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled |
| X | ATI Display | ATIDisplay.exe | Added by the BDOOR-AFH TROJAN! |
| X | ATI Display Driver | atixd.exe | Added by the RBOT-FOV WORM! |
| X | Ati Display Settings | atividx.exe | Added by the RBOT-GAS WORM! |
| N | ATI GART Set-up Utility | Atigart.exe | Program
that checks the motherboard chipset and determines which GART driver
bundle to install on ATI video cards. If you have one, once installed
it shouldn't be needed |
| U | ATI Launchpad | launchpd.exe | Convenient
way to start all your Multimedia Center applications (DVD, Video CD, CD
Audio, File Player). You can right-click LaunchPad, and uncheck Load on
Startup in the menu |
| X | ATI Rage3d Pro | AtiRage4dPro.exe | Added by the AGOBOT-OG WORM! |
| Y | ATI Remote Control | ATIRW.exe | Driver for the ATI REMOTE WONDER? RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it |
| Y | ATI Remote Control | ATIX10.exe | ATI Remote Wonder? - PC wireless remote control driver. Required if you use it |
| N | ATI Scheduler | Atisched.exe | Component
that remains resident in memory and automatically launches the ATI
VIDEO PLAYER at a user selected time and date. Delete the shortcut in
the Start -> Programs -> Startup folder as well. Functions could
re-enable the program to load at start-up and re-introduce the
shortcut. Try it and see |
| N | ATI Task Application | Atitkad.exe | System
Tray access and key-combo shortcuts to common display functions on ATI
video cards. Can be run from Start -> Settings -> Control Panel
-> Display |
| N | ATI Task Application (Atikey) | Atitask.exe | System
Tray access and key-combo shortcuts to common display functions on ATI
video cards. Can be run from Start -> Settings -> Control Panel
-> Display |
| X | ATI Technology Startup | techstart.exe | Added by the RBOT-AEU WORM! |
| X | ATI Video Driver Control | atigfx.exe | Added by the RBOT-FWL WORM! |
| X | ATI Video Driver Control | btorrent.exe | Added by a variant of the IRCBOT TROJAN! |
| X | ATI Video Driver Controls | [path to worm] | Added by the SDBOT-DDS WORM! |
| X | ATI VIDEO REGKEY | ati2vid.exe | Added by the SDBOT.UR WORM! |
| ? | Ati2cwxx | Ati2cwxx.exe | For
some ATI video cards. Probably used to access features and may not be
required - for example the ATI Radeon works fine without it |
| X | Ati2evxx | Ati2evxx.com | Added by the BACKDOOR-CPC TROJAN! |
| X | ati2f104 | ati2f104.exe | Added by the DLOADR-BBW TROJAN! |
| U | Ati2mdxx | Ati2mdxx.exe | System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager |
| N | ATICCC | cli.exe runtime | ATI's
CATALYST? CONTROL CENTER. Required if you want to change graphics
settings on a regular basis but you must have internet access and
Microsoft's .NET framework installed. Note that this has "runtime"
appended to cli.exe in the "Command" column of MSCONFIG. Recommend that
start the program manually via Start -> Programs -> ATI Catalyst
Control Center -> Advanced -> Restart Runtime as it can casue
problems when starting Windows |
| N | ATICCC | CLIStart.exe | Puts the ATI Catalyst? Control Center Icon/Shortcut on the System Tray - available via Start -> Programs |
| X | aticpaxx.exe | aticpaxx.exe | Added by the RBOT-XP WORM! |
| U | AtiCwd | AtiCwd.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| U | AtiCwd | AtiCwd32.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| U | AtiCwd | Ati2cwad.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| U | AtiCwd32 | AtiCwd.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| U | AtiCwd32 | AtiCwd32.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| U | AtiCwd32 | Ati2cwad.exe | This
utility adds the ATI tab in the advanced display properties (gives the
option for TV out). Do not uncheck if there is TV out on the video card |
| X | AtiDisplayDrv | atidrvxx.exe | Added by the RBOT-VZ WORM! |
| X | atidriver | reaIplayer.exe | Added by the WARPIGS-E WORM! Note the uppercase "I" in the filename, rather than a lower case "L" |
| N | AtiKey | AtiKey32.exe | System
Tray access and key-combo shortcuts to common display functions on ATI
video cards. Can be run from Start -> Settings -> Control Panel
-> Display |
| ? | AtiKey | atiptkad.exe | System
Tray access and key-combo shortcuts to common display functions on ATI
video cards. Can be run from Start -> Settings -> Control Panel
-> Display |
| N | Atikey | Atitask.exe | System
Tray access and key-combo shortcuts to common display functions on ATI
video cards. Can be run from Start -> Settings -> Control Panel
-> Display |
| U | ATIMACE | MACE.exe | ATI
Technologies Control Centre - installed alongside ATI graphics hardware
and provides additional configuration options for these devices in the
Managed Access to Catalyst Environment (MACE) component
|
| U | ATIModeChange | Ati2mdxx.exe | System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager |
| X | AtiPanel | atip.exe | Added by the TACTSLAY.U TROJAN! |
| X | atipatxx | atipatxx.exe | Added by the SMALL-ED TROJAN! |
| U | ATIPOLAB | ati2evxx.exe | ATI
External Event Utility EXE Module. This task can comsume lots of CPU
resournces on some computers, but it can help with graphics card
problems. Leave enabled unless it consumes too many CPU resources |
| U | ATIPOLAB | ati2evae.exe | ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks |
| U | ATIPOLL | ati2evxx.exe | ATI
External Event Utility EXE Module. This task can comsume lots of CPU
resournces on some computers, but it can help with graphics card
problems. Leave enabled unless it consumes too many CPU resources |
| U | AtiPTA | Ati2ptxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| U | AtiPTA | Atiptaxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| U | AtiPTAAA | Ati2ptxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| U | AtiPTAAA | Atiptaxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| U | atiptaxx | Ati2ptxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| U | atiptaxx | Atiptaxx.exe | Control
panel for the ATI series of video cards allowing access to such
features as display resolution, colour depth, etc. Available via Start
-> Settings -> Control Panel -> Display. Some users may need
it if they have optimised their settings |
| X | atiptext | atiptext.exe | Added by the COSIAM-A TROJAN! |
| U | AtiQiPcl | AtiQiPcl.exe | Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's |
| U | ATISmart | ati2s9ag.exe | ATI's "SMARTGART", which is included with the "Catalyst" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings |
| U | AtiSound | csrss.exe | WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate csrss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the "ComRoot" subfolder |
| X | atisrc2 | windfind.exe | Added by the WINDFIND-A TROJAN!
|
| X | ATITech | Active.exe | Added by the ROAMER-A TROJAN! |
| U | atitray | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings |
| U | AtiTrayTools | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings |
| X | atiupdate | ATIUPDATE5.EXE | Added by the DEBESKI.A TROJAN! |
| X | atiupdate | msshed32.exe | Added by the DELF.EP downloader TROJAN! |
| X | ATIUpdater | atiupdxx.exe | Added by the RBOT-ABX WORM! |
| X | Atiupdpl | atiupdpl.exe | Added by the SMALL.AOS TROJAN! |
| X | ativopen | ativopen.exe | Premium rate adult content dialler |
| Y | ATIX10 | atix10.exe | ATI Remote Wonder? - PC wireless remote control driver. Required if you use it |
| ? | ATKMEDIA | DMEDIA.EXE | ATK Media utility for ASUS laptops - what does it do and is it required? |
| X | Atl**.exe [* = random char] | Atl**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Atl**32.exe [* = random char] | Atl**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | ATM Control | adpn.exe | Added by the MMS.A WORM! |
| N | ATnotes | atnotes.exe | Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs |
| U | Atomic Time Synchronizer | TimeSync.exe | TimeSync - lets you synchronize your computer's clock with any internet atomic clock |
| X | Atomic-x27 | Atomic-x27.exe | Added by the KATOMIK-A WORM! |
| X | Atomic-x27C | AtomicpartC.exe | Added by the KATOMIK-A WORM! |
| U | Atomic.exe | Atomic.exe | Atomic Clock Sync - synchronizes your computer's time with the NIST time server |
| N | Atomica | atomica.exe | Atomica
runs from the System Tray and allows the user to find out more about a
word or phrase on any screen by pointing at it with the mouse and
clicking button one while holding down the Alt key |
| U | AtomicTime | ATOMICTIME.EXE | AtomicTime - utility that synchronizes your PC clock to an atomic clock |
| U | Atrack | atrack.exe | New
feature of Norton Internet Security (NIS) and Norton Personal Firewall
(NPF) 3.0 is the Alert Tracker, an instant notification feature. The
Alert Tracker displays information about events as they happen. This
way, when a rule has been triggered or an access to the Internet made,
you know about it immediately rather than finding out about it when you
check your logs or notice that the NIS icon indicates a security alert |
| U | Atray | Atray.exe | Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons |
| U | ATSpooler | AppsTraka.exe | DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | ATTBroadbandUpdate | SAUpdate.exe | Big Brother from Quest Software. System and network monitor |
| U | ATTRedUpdate | AutoUpdate.exe | Additional
item added to start-ups after AT&T took over the now bankrupt
Excite@home high-speed internet service. Included for automatically
downloading and installing updates. Leave it unless you plan to
regularly run it to check for updates |
| X | AttuneClientEngine | attune_ce.exe | Aveo Attune automated helpdesk software - adware/spyware |
| X | AttuneContentUpdater | attune_cu.exe | Aveo Attune automated helpdesk software - adware/spyware |
| X | AttuneDiscovery | attune_di.exe | Aveo Attune automated helpdesk software - adware/spyware |
| X | Attunel | Attunel.exe | Aveo Attune automated helpdesk software - adware/spyware |
| X | AttuneSystray | attune_st.exe | Aveo Attune automated helpdesk software - adware/spyware |
| N | aTuner | atuner.exe | aTuner - tweak tool for GeForce based graphics cards |
| Y | atwtusb | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) |
| X | AtxBrw | Iexplor.exe | "Pop Marketing" adware |
| U | au | DealioAu.exe | Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products |
| U | AU Agent | AUagent.exe | Au Agent
from Zilab Software. Win2K/NT enhancement tool. Allows you to run
applications under any security context without closing the whole logon
session to process a new logon |
| X | au.exe | au.exe | Added by the BEAGLE.B WORM! |
| Y | AUCBPNP | aucbnpn.exe | Adaptec
USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which
provides USB 2.0 ports for laptop users via a PCMCIA card slot |
| X | Aucompat | Aucompat.exe | Added by the GEMA TROJAN! |
| X | Audcntr | audcntr.exe | Added by the GEMA TROJAN! |
| ? | AudCtrl | RunDll32 AudCtrl.dll, RCMonitor | Audio control panel? |
| X | audi32 | audi32.exe | Added by the RANCK-FL TROJAN! |
| X | AUDIO | SOUND.exe | Added by the PLOYB-A TROJAN! |
| X | Audio Device Manager | winfp.exe | Detected by PCTools as the IRCBOT.BIV TROJAN! See here |
| X | Audio Device Manager | WinNT.exe | Added by the BANKER.BTG TROJAN! |
| X | Audio Device Manager | WNDXP.exe | Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here |
| X | audiocfg.exe | audiocfg.exe | Added by the VB.ATE WORM! |
| X | Audiocntl | audiocntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | AudioDeck | ADeck.exe | ADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items |
| X | Audiodrv | audiodrv.exe | Added by the CRYPTER-C TROJAN! |
| U | AudioDrvEmulator | DLLML.exe AudDrvEm.dll | Related to Creative
DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This
program is non-essential process to the running of the system, but
should not be terminated unless suspected to be causing problems |
| N | AudioHQ | Ahqtb.exe | For
Creative Soundblaster Live! series soundcards. System tray application
for SB Live! functions. Available via Start -> Programs |
| X | AudioHQ | audiohq.exe | Added by the BANKER-EHK TROJAN! |
| N | AudioHQU | AHQTBU.EXE | System Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
|
| X | audioinf | audioinf.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | audlmne32 | dcmsxe.exe | Added by the MAILBOT-CF TROJAN! |
| X | auloadplx | mplprogsm.exe | Added by the SLAPER.K TROJAN! |
| X | AUNPS2 | RUNDLL32 AUNPS2.DLL, _Run@16 | AUNPS adware |
| X | aupd | symcsvc.exe | Added by the ABWIZ.D TROJAN! |
| X | aupd | sysvcs.exe | Added by the ABWIZ.C TROJAN! |
| X | aupd | sywsvcs.exe | Added by the ORSE-M TROJAN! |
| Y | Aureal A3D Interactive Audio | sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
| Y | Aureal A3D Interactive Audio Init | A3dInit.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
| X | ausvc | ausvc.exe | Added by the AUTOUPDER TROJAN! |
| X | Auth Starter Ident | startauth.exe | Added by the RBOT-WP WORM! |
| Y | Authentic-ID Toolbar | wintmr.exe | System Tray access to Child Control parental control software by Salfield |
| Y | Authentic-ID Toolbar | rundll32.exe [path] ToolbarATL.dll, LoadTrayIcon | Authentic-ID Toolbar - website authentication utility. Warns you when a site is recognized for phishing or isn't authentic, for example |
| X | authz | authz.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | auto | win32.exe | Added by the SMALL!SD5 TROJAN!
|
| X | Auto CD-ROM Startup | cdaccess.exe | Added by the SPYBOT.BLA WORM! |
| U | Auto EPSON Stylus C45 Series on X | E_S4I3T1.EXE | Epson
Status Monitor 3 for the Stylus C45 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C48 Series on X | E_S10IC2.EXE | Epson
Status Monitor 3 for the Stylus C48 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C60 Series on X | E_S10IC2.EXE | Epson
Status Monitor 3 for the Stylus C60 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C62 Series on X | E_S10IC2.EXE | Epson
Status Monitor 3 for the Stylus C62 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C82 Series on X | E_S0HIC1.EXE | Epson
Status Monitor 3 for the Stylus C82 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C84 Series on X | E_S4I2D1.EXE | Epson
Status Monitor 3 for the Stylus C84 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus C87 Series on X | E_FATIABL.EXE | Epson
Status Monitor 3 for the Stylus C87 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX3200 on X | E_S10IC2.EXE | Epson
Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer
status, checking ink levels, etc. "X" represents the computer's network
name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX3600 Series on X | E_FATI9BE.EXE | Epson
Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX3800 Series on X | E_FATIACA.EXE | Epson
Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX4200 Series on X | E_FATIAEA.EXE | Epson
Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring
printer status, checking ink levels, etc, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX4500 Series on X | E_FATI9AP.EXE | Epson
Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX5400 on X | E_S4I2G1.EXE | Epson
Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX6000 Series on X | E_FATIBIA.EXE | Epson
Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX6400 on X | E_S4I2L1.EXE | Epson
Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer
status, checking ink levels, etc. "X" represents the computer's network
name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX6600 Series on X | E_FATI9EE.EXE | Epson
Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus CX7800 Series on X | E_FATIACA.EXE | Epson
Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus D78 Series on X | E_FATIBGE.EXE | Epson
Status Monitor 3 for the Stylus D78 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus D88 Series on X | E_FATIABE.EXE | Epson
Status Monitor 3 for the Stylus D88 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus DX3800 Series on X | E_FATIACE.EXE | Epson
Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus DX4800 Series on X | E_FATIADE.EXE | Epson
Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus DX6000 Series on X | E_FATIBIE.EXE | Epson
Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R1800 on X | E_FATI9LA.EXE | Epson
Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R200 Series on X | E_S4I2H1.EXE | Epson
Status Monitor 3 for the Stylus Photo R200 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R200 Series on X | E_S4I0H2.EXE | Epson
Status Monitor 3 for the Stylus Photo R200 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R220 Series on X | E_FATIAIE.EXE | Epson
Status Monitor 3 for the Stylus Photo R220 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R260 Series on X | E_FATIBNA.EXE | Epson
Status Monitor 3 for the Stylus Photo R260 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R300 Series on X | E_S4I2F1.EXE | Epson
Status Monitor 3 for the Stylus Photo R300 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo R320 Series on X | E_FATI9FA.EXE | Epson
Status Monitor 3 for the Stylus Photo R320 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo RX420 Series on X | E_FATI9CE.EXE | Epson
Status Monitor 3 for the Stylus Photo RX420 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo RX500 on X | E_S4I2K1.EXE | Epson
Status Monitor 3 for the Stylus Photo RX500 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Photo RX600 on X | E_S4I2M1.EXE | Epson
Status Monitor 3 for the Stylus Photo RX600 Series printer - for
monitoring printer status, checking ink levels, etc. "X" represents the
computer's network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| U | Auto EPSON Stylus Pro 7600 on X | E_S10IC2.EXE | Epson
Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring
printer status, checking ink levels, etc. "X" represents the computer's
network name, ie, PAULS-PC, PETES-LAPTOP, etc |
| X | Auto File System Conversion Utility | scricon.exe | Added by the SDBOT.EYB WORM! |
| X | auto repair system | qualityx.exe | Added by an unidentified WORM or TROJAN - probably a SPYBOT variant |
| U | Auto Switch | TASKBAR.exe | Related to 2-port Bitronics AutoSwitch kit from Belkin |
| N | Auto T Bar | autotbar.exe | If
you disable the HP VIEW toolbar in IE and rearrange the toolbars on a
reboot they will be back as they were before if this is left enabled |
| X | Auto Updat | WindowsSys32.exe | Added by a variant of the FORBOT WORM! |
| X | Auto updat | crcss.exe | Added by the SDBOT.AAG WORM! |
| X | Auto Update | AUP.exe | Added by an unididentified WORM or TROJAN! |
| X | Auto Update | dma.exe | Added by the RBOT-AVO WORM! |
| X | Auto Update | svchost.exe | Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the Winnt or Windows folder |
| X | Auto Updates | svchost.exe | Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the Winnt or Windows folder |
| X | Auto WinUpdate | taskmrg.exe | Added by the RBOT-AFA WORM! |
| X | AutoAdministrator | SERVICES.EXE | Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| U | Autobar | autobar.exe | Connect buttons on the keyboard for internet direct access, etc. on HP computers |
| U | AutoCAD Startup Accelerator | acstart16.exe | Preloads some libraries that are used by AutoCAD in order to make the software load faster |
| U | autoclk | autoclk.exe | Autoclik is a Windows utility "that allows you to perform all mouse activity with absolutely no clicking" |
| N | AutoEA | Ahqrun.exe | For
Creative Soundblaster Live! series soundcards. Specify for any audio
application what audio preset to automatically associate with currently
active speaker output. Available via AudioHQ |
| X | AUTOEXE | AUTOEXE.exe | Added by the SEMAPI-A WORM! |
| X | autoload | cftmon.exe | Detected by Symantec as the SILLYFDC WORM! See here |
| X | autoload | spooll.exe | Detected by Symantec as the SILLYFDC WORM! See here |
| X | autoload | windowsupdate.exe | Detected by Trend Micro as the POLYCRYP.DY TROJAN! See here |
| X | Autoloaderaproposclient | Apropos_Client_Loader.exe | AproposMedia adware |
| X | Autoloaderaproposclient | cxtpls_loader.exe | AproposMedia adware |
| X | AutoLoaderEnvoloAutoUpdater | auto_update_loader.exe | Envolo/AproposMedia adware updater |
| N | AutoMate Task Service | automate.exe | Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs |
| U | AutoMate5 | Am5HkWnd.exe | "Automate
is the Leading Software for Automation of front and back-office
business processes.It provides all the tools necessary to completely
automate business processes, regardless of their complexity" |
| U | AutoMate6 | AMEM.exe | AutoMate 6 for automating repetitive tasks |
| X | Automated Windows Updates | wauclt.exe | Added by the GAOBOT.AJD WORM! |
| X | Automatic Defrag Manager | defrag.exe | Added by the RBOT-AKE WORM! |
| X | Automatic Media Update | CACHE.RVD | Added by an unidentified WORM/TROJAN! |
| X | Automatic Media Update | HPLNT32.RVD | Added by an unidentified WORM/TROJAN! |
| X | Automatic Microsoft Windows Updater | suchost.exe | Added by the RBOT-EQ WORM!
|
| X | Automatic Updates | algs.exe | Added by the IRCBOT-AAM TROJAN! |
| X | Automatic Windows Updater | Update.exe | Added by the GAOBOT.AO WORM! |
| N | Automatically launches the United Devices Agent when you start your computer | UD.EXE | The
United Devices Agent can recycle your PC's unused resources and use
them to perform valuable scientific and medical research without
disturbing your usual computer use - similar to SETI@home but for
medical research. Available via Start > Programs |
| X | Autopdate | Autopdate.exe | Added by the RBOT-AGL WORM! |
| N | AUTOPROP | REGPROP.EXE WMPADDIN.DLL | Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension |
| X | AUTOPROTECTU | navapq32.exe | Added by an unidentified WORM or TROJAN! |
| X | autorepair | dexs.exe | Added by a variant of the SDBOT WORM! |
| U | Autoroute SMTP | AutoSmtp.exe | Autoroute SMTP
- "automatic switching between SMTP servers depending on what network
you are currently working in." You need to have two Internet service
providers |
| X | autorun | autorun.exe | Added by the AUTOM-B WORM! |
| X | autorun | sxs.exe | Added by the SMALLVBS-A WORM! |
| X | autorun | winmain.exe | Added by a variant of the DLEF.CNS TROJAN! |
| X | autorundemo | [path to trojan] | Added by the AGENT-FPX TROJAN! |
| ? | AutoShutdown | pssvc.exe | Utility to fix vCard Export in MS Outlook 2000 - although why are these together? |
| U | AutoSizer | AUTOSIZER.EXE | AutoSizer - utility that automatically maximizes windows when they're opened |
| N | AutoSpell | autospel.exe | AutoSpell - spell checker (version 6.*) |
| N | AutoSpell 5 | ASWATC32.EXE | AutoSpell - spell checker |
| U | AutoSys | autosys.exe | Winguardian surveillance software. Uninstall this software unless you put it there yourself |
| N | autotbar | autotbar.exe | If
you disable the HP VIEW toolbar in IE and rearrange the toolbars on a
reboot they will be back as they were before if this is left enabled |
| N | AutoTKit | AUTOTKIT.EXE | On
HP PC's. Unclear what purpose it serves - but there's a known issue
with Internet Explorer Toolbar settings not being saved with it enabled |
| N | autoupd | autoupd.exe | Raxco Software Auto Update utility."Used to keep your software up-to-date" |
| X | autoupd | autoupd.exe | Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name |
| X | autoupdate | WINUP2DATE.DLL, SHStart | Unidentified adware - detected by Panda antivirus as the CLICKER.CY TROJAN! |
| X | autoupdate | rundll32 DATADX.DLL, SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "DATADX.DLL" file is found in the System
(9x/Me) or System32 (NT/2K/XP) folder |
| X | autoupdate | rundll32 SUPDATE.DLL, SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "SUPDATE.DLL" file is found in the System
(9x/Me) or System32 (NT/2K/XP) folder |
| X | AutoUpdate | smss.exe | Added by a variant of the WINSPY.AA TROJAN! Note - this is not the legitimate smss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in a "debug64" subfolder of the Winnt or Windows
folder |
| X | Autoupdate Service | kaka.exe | Added by the SYMPE-B TROJAN! |
| X | AutoUpdater | aupdate.exe | Tinybar variant |
| X | AutoUpdater | AutoUpdate.exe | PeopleonPage foistware |
| X | autoupdatev2 | [path to file] | Added by the DROPPER-BM TROJAN! |
| X | autoupdatev2 | autoupdatev2.exe | Detected by Kaspersky as the AGENT.FQ TROJAN! |
| X | AutoVirusProtection | ciscv.exe | Added by a variant of the RBOT WORM! |
| X | auto__antiav__key | antiav_exe.exe | Added by the BAGLEDI-AA TROJAN! |
| X | auto__hloader__key | hloader_exe.exe | Added by the BAGLE.AB TROJAN! |
| X | aux.exe | aux.exe | Added by the ZINS TROJAN! |
| X | auxAudioDevice | aux32.exe | Added by the AIZU WORM! |
| N | AUXXTRAY | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
| X | AV | UPDATE-28062004.exe[25 blank spaces].vbs | Added by the MIDFIN WORM! |
| X | AV Client | patch31345.exe | Added by the MYDOOM.AD WORM! |
| X | AV Industry | patch31345.exe | Added by the MYDOOM.AD WORM! |
| X | AV UpDate | Update.exe | Added by the FUROOT-A TROJAN! |
| N | AvaFind | AvaFind.exe | AvaFind file search utility |
| X | AVantivirus | Avconsol.exe | Added by the MSNVB-D WORM! |
| X | avast | troyan.exe | Added by the SMALL.CZ TROJAN! |
| Y | Avast! | ashserv.exe | Part of Avast! anti-virus software |
| Y | avast! | ashDisp.exe | Part of Avast! anti-virus software |
| Y | avast! Web Scanner | Ashwebsv.exe | Part of Avast! anti-virus software |
| Y | Avast32 | Astart32.exe | Part of Avast! anti-virus software |
| X | avc | avmon.exe | Added by an unidentified TROJAN! |
| U | AvconsoleEXE | Avconsol.exe | From
McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to
schedule regular scans. If you don't have scans scheduled you don't
need it |
| X | Avengine | Avengine.com | Added by the DELF.LJ TROJAN! |
| X | AveoAttune | atmdlusr.exe | Aveo Attune automated helpdesk software - adware/spyware |
| U | AVFX Engine | StartFX.exe | Advanced Video FX
- supported by a number of Creative Web Cameras. "Have more fun by
adding a wide range of special effects and backgrounds to your video
chat with Advanced Video FX" |
| X | AvG | svchost323.exe | Added by the RBOT-ZA WORM! |
| Y | AVG Anti-Virus system | avgcc.exe | AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates |
| X | Avg Antivirus | icpldrvx.exe | Added by the BANKER.BYU TROJAN! |
| X | AVG Grisoft Updater | updater.exe | Added by the AGOBOT-OT WORM! |
| Y | AVG7_AMSVR | Avgamsvr.exe | AVG antivirus related |
| Y | AVG7_CC | AVGCC.exe | AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates |
| Y | AVG7_CC | avgcc.exe | AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates |
| Y | AVG7_EMC | AVGEMC.exe | AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses |
| Y | AVG7_Run | avgw.exe | AVG Anti-Virus 7.0 related |
| U | AVG8_TRAY | avgtray.exe | System Tray access to AVG internet security software |
| Y | avgamsvr.exe | Avgamsvr.exe | AVG antivirus related |
| Y | avgcc32 | avgcc32.exe | AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates |
| Y | AVGCtrl | AVGCtrl.exe | Part of AntiVir? PersonalEdition Classic antivirus |
| Y | avgfwsrv | AVGFWSRV.EXE | Firewall part of the AVG Plus Firewall Edition |
| Y | avgmsvr.exe | avgmsvr.exe | AVG Anti-Virus 7.0 related |
| Y | AVGnt | AVGnt.exe | AntiVir? PersonalEdition Classic antivirus. System Tray icon and control program
|
| Y | Avgserv9.exe | Avgserv9.exe | AVG antivirus background monitoring |
| Y | AVGuard | AVGuard.exe | AntiVir? PersonalEdition Classic antivirus. Background task which scans files transparently
|
| Y | AVG_CC | avgcc32.exe | AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates |
| Y | AVG_EMC | AVGEMC.exe | AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses |
| Y | AVG_RegCleaner | AVGREGCL.exe | AVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems |
| X | avidrv | drvsc.exe | Detected by Kaspersky as the AGENT.PH TROJAN! |
| X | Avimgt | Avimgt.exe | Added by the GEMA TROJAN! |
| X | Avimgt32 | Avimgt32.exe | Added by the GEMA TROJAN! |
| Y | avinit | AVINIT9X.EXE | Command Antivirus related |
| Y | AVK Mail Checker | AVKPop.exe | eXtendia AVK AntiVirus email checker |
| Y | AVKBar | AVKBar.exe | GData AntiVirusKit Anti-virus |
| U | AVKTray | AVKTray.exe | System Tray access to AntiVirenKit InternetSecurity from G DATA Software AG |
| Y | AvMaiSrv | Avmaisrv.exe | Part of Avast! anti-virus software - E-mail scanner |
| Y | AVMWlanClient | wlangui.exe | Related to broadband products from avm.de |
| X | avnort | formatsys.exe | Added by the SERFLOG.A WORM! |
| X | avnort | msmbw.exe | Added by the SERFLOG.A WORM! |
| X | avnort | serbw.exe | Added by the SERFLOG.A WORM! |
| Y | avp | avp.exe | Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory |
| X | AVP | [path to trojan] | Added by the MUTBO-A TROJAN! |
| X | avp | avp.exe | Detected by Kaspersky as the ALPHABET.B TROJAN! |
| X | avp | win*.tmp.exe [* is a number] | Added by a variant of the ALPHABET TROJAN! |
| X | avp | xar6000v7.exe | Detected by Kaspersky as the ALPHABET.B TROJAN! |
| X | AVP-SE | avp-32.exe | Added by the AGOBOT.FS WORM! |
| X | avpa | avpo.exe | Added by the LEGMIR-ARK TROJAN! |
| Y | avpcc | avpcc.exe | Kaspersky Labs anti-virus |
| Y | avpm | avpm.exe | Kaspersky anti-virus |
| X | AvpM | AvpM.exe | Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in the WINDOWSpchealthUploadLBConfig directory |
| X | avpms | avpms.exe | Detected by Kaspersky as the ONLINEGAMES.CPV TROJAN! See here |
| X | Avpr | avpr.exe | Added by the MYDOOM.AF WORM! |
| X | AVPSrv | AVPSrv.exe | Added by the ONLINE-GEN TROJAN! |
| X | avptask | [path to trojan] | Added by the NOFERE-G TROJAN! |
| X | avptask | expl0rer.exe | Added by the AGENT.JJO TROJAN! |
| X | Avptask | rund1132.exe | Added by the AGENT.PKZ TROJAN! |
| X | AvpWx | WErcx.exe | Detected by Kaspersky as a variant of the AGENT.A TROJAN! |
| X | Avril Lavigne - Muse | [random filename] | Added by the AVRIL-A WORM! |
| Y | AVSCHED32 | AVSched32.exe | AntiVir? PersonalEdition Classic - antivirus
|
| Y | AVSchedScan | SCHSC9X.EXE | Command Antivirus related |
| X | AvSer | dsm.exe | Added by the SERFLOG.B WORM! |
| X | AvSer | msmpatch.exe | Added by the SERFLOG.B WORM! |
| X | AvSer | svosm.exe | Added by the SERFLOG.B WORM! |
| X | AvSer | sysup.exe | Added by the SERFLOG.B WORM! |
| X | avserve.exe | avserve.exe | Added by the SASSER WORM! |
| X | avserve2.exe | avserve2.exe | Added by the SASSER.B or SASSER.C WORMS! |
| X | avserve3.exe | avserve3.exe | Added by the SASSER.G WORM! |
| U | AVStation premium | AVStation agent.exe | Related to Samsung AV Station - instant playback of music, photos, videos |
| X | avtapi | avtapi.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
| N | Avtray | Avtray.exe | Command Antivirus tray icon |
| X | AVupdate32 Update | AVupdate32.exe | Added by the RBOT.CNI TROJAN! |
| ? | AVWLPSTA | AVWLPSTA.exe | PRISM Status Tray Applet - but what is it for and is it required? |
| Y | AVWUpd32 | AVWUPD32.EXE | AntiVir? PersonalEdition Classic - updater
|
| Y | avx communicator | xcommsur.exe | Anti-virus part of BitDefender virus scanner/firewall |
| Y | Avxlive | avxlive.exe | Bullguard or BitDefender antivirus |
| Y | avxlni | avxinit.exe | Anti-virus part of BitDefender virus scanner/firewall |
| ? | Avxnews | ?? | ?? |
| U | Awatch | Awatch.exe | Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products |
| U | AwaySch | AwaySch.EXE | Part of the IBM ThinkVantage Productivity Center. "The Away Manager application allows you preselect and run routine tasks to maintain your system's performance" |
| N | awhost32 | awhost32.exe | Part of Symantec's pcAnywhere
remote PC management software. Provides an automatic startup of the
client PC in host mode in conjuction with a host-definition file, so
system administrators can access the machine. Can cause a 10% reduction
in speed and not recommended |
| U | AWMON | Ad-Watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
| U | AWMON | Ad-Monitor.exe | F-Secure Anti-Spyware |
| U | awplite | awplite.exe | AllWallpapers Lite desktop wallpaper channger |
| ? | AWUSGSTA | AWUSGSTA.exe | Reportedly related to a USB Wifi Adapter - is it required at startup?
|
| U | awxDTools | awxDTools.dll, awxRegisterDll | AwxDTools
related - a Windows Shell-Extension for the Daemon-Tools. It extends
the context-menu of ImageFiles supported by Daemon-Tools (i.e.: *.cue,
*.iso, *.ccd ...) |
| ? | AxFilter | Rundll32 AXFILTER.DLL, Rundll32 | ?? |
| X | AXVenore | AXVenore.exe | Added by an unidentified TROJAN - see here |
| U | AzMixerSel | AzMixerSel.exe | Related to Realtek_Azalia Mixer Selector |
| Y | azmodem | azexe.exe | Aztech Labs modem driver |
| ? | a_vpd | vpd.exe | Located in the IBMTOOLSVPD sub-directory. What does it do and is it required? |
| N | B'sCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required |
| X | b.exe | b.exe | Added by the SDBOT.BND WORM! |
| N | B.Reader | remin.exe | Birthday Reminder 5.0 - as the name implies |
| X | b3d | BDEsecureinstall.exe | B3d Projector
foistware - periodically trys to access the internet. (1) Uninstall it
via Start -> Settings -> Control Panel -> Add/Remove Programs.
(2) Remove the BDEsecureinstall.exe if still present in the "System"
directory. (3) Disable and ideally delete it from the registry. (4)
Remove the "BDE" directory and all its contents |
| X | b3dUpdate | Zupdate.exe | Associated with B3d Projector foistware - see here |
| U | b9 | B9.exe | FireTrust Benign
- allows you to receive e-mail which is safe from viruses, worms,
scripts, web bugs, privacy threats and other security risks, without
affecting your e-mail. "Benign neutralizes or strips out the code that
makes viruses, worms, scripts and other potentially harmful things run" |
| X | b99 | msmm.exe | ClientMan parasite variant |
| X | bab | svchst32.exe | Added by the AGENT.Q TROJAN! |
| X | babeie | rundll32 cnbabe.dll, dllstartup | CommonName Toolbar spyware. To uninstall see here |
| N | Babylon Client | Babylon.exe | Babylon-Pro
is a powerful information tool that instantly provides relevant
information, translations & conversions for any word or value you
click on" |
| N | Babylon Translator | Babylon.exe | "Babylon-Pro
is a powerful information tool that instantly provides relevant
information, translations & conversions for any word or value you
click on" |
| X | Back Updates | Uninstall.log.vbs | Added by the YPSAN.D WORM! |
| U | Back2zip | Back2zip.exe | Back2zip
is a simple and elegant backup solution which uses the industry's most
powerful ZIP and ZIP-64 technologies to constantly monitor your
documents and make sure that they are always properly backed up |
| X | Backdoor.NuAgent | agent.exe | Added by the AGENT-DP TROJAN! |
| X | Background Intelligent Transfer Service | rundll32.exe | Added by the VB-ZD TROJAN! Note - this file is located in the C:Windowshelp folder, and is not to be confused with the legitimate rundll32.exe file! |
| U | BackgroundSwitcher | bgswitch.exe | Originally included with Microsoft's XP PowerToys (but now withdrawn - see here, Background Switcher allows your desktop background to periodically change |
| U | BackgroundSwitcher | BackgroundSwitcher.exe | John?s Background Switcher
(or JBS for short) periodically changes the background image on your
computer (like every hour or every day) to something interesting |
| N | Backpack UDF | bpudfmon.exe | Backpack UDF
packet writing software for Microssolutions' Back Pack external CD-RW
drive. Similar to DirectCD. Run manually before insert an appropriately
formatted CD-RW disk |
| X | backup | [path to worm] | Added by the AGOBOT-H WORM! |
| X | Backup Service | backup.svc | Unidentified adware |
| U | Backup4all OTB Agent | B4AOTB.exe | "Backup4all
is an award-winning data backup software for Windows. This backup
utility was designed to protect your valuable data from partial or
total loss by automating backup tasks, password protecting and
compressing it to save storage space" |
| U | BackupExecScheduler | besch.exe | Veritas "Back Up My PC" software |
| ? | BackupNotify | backupnotify.exe | HP Digital Imaging related. What does it do and is it required? |
| N | BackWeb | backweb.exe | Automatically
detects an internet connection and downloads any available updates.
Typical on Compaq and HP PC's but not restricted to those OEM's.
Resource hog and often causes malfunctions. Available via Start ->
Programs |
| N | Backwork | Backwork.exe | Backwork trojan detector |
| U | BACPI10 | bacpi10a.exe | Known
as "PowerKey" - a minimalistic keyboard driver that allows power
management keys on BTC keyboards to function properly in older OS's
(i.e. Win95/98/NT4). Also adds an icon to the system tray |
| N | BacsTray | BacsTray.exe | Broadcom
Advanced Control Suite - for modems and set top boxes based upon
Broadcom chipsets. Not required unless you have networking problems |
| X | BADDATE | BADDATE.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | BagleAV | csrss.exe | Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the Windows or Winnt folder |
| X | Bakra | IEHost.EXE | Added by the MULTIDR-AH TROJAN! |
| X | bal | SYSMONMS.EXE | Added by the FAKEALERT TROJAN! |
| X | Band-Aid | [path to file] | Added by the RANKY.O TROJAN! |
| U | bandmon | bandmon.exe | Rokario Bandwidth Monitor |
| X | Bandook | ali.exe | Added by the EXEMAS-B TROJAN! |
| U | Bandwidth Monitor Pro | Bandwidth Monitor Pro.exe | Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP
|
| U | Banpopup by Pratik | Banpopup.exe | Banpopup - popup killer |
| X | bantool | ie_ban.exe | Detected as the VB.PO TROJAN! |
| X | Bar Ding lolt | Analiz.exe | Added by the RBOT-RP WORM! |
| X | bargains | bargains.exe | BargainBuddy foistware |
| X | bargains | bargainbuddy.exe | BargainBuddy foistware |
| ? | Bart Station | station.sbrt | Related to PeoplePC ISP. May be a dialler for dial-up accounts? |
| U | Bart Station | PPCOLink.exe | Dialer for PeoplePC ISP |
| X | BarTheme | bartent32.exe | Added by the AGOBOT-UG WORM! |
| N | bascstray | BascsTray.exe | Broadcom
Advanced Control Suite - for modems and set top boxes based upon
Broadcom chipsets. Not required unless you have networking problems |
| X | Bat | secure2.bat | Added by the ZCREW.C TROJAN! |
| N | Batchreg1 | N/A | Part
of the Windows System Recovery process. Added to the registry via
Msbatch.inf. The existence of this key or process after the last reboot
during installation indicates an unsuccessful installation, as that key
should be deleted automatically. See here |
| U | BatInfEx | rundll32.exe | Displays battery status information on an IBM Thinkpad |
| X | BatSrv | batserv2.exe | Detected by Kaspersky as the LOCKSY.M WORM! |
| U | Battery Scope | batmgr.exe | Monitors battery levels on a notebook/laptop PC |
| U | BatteryBar | batterybar.exe | BatteryBar - displays battery usage, and the current percentage of battery power left |
| X | BatzBack | BatzBack.scr | Added by the BACKZAT WORM! |
| U | BAUSB | BAUSB.exe | Boston Acoustics Audio, USB driver |
| X | bawindo | bawindo.exe | Added by the BEAGLE.AR or BEAGLE.AU WORMS! |
| U | BayMgr | DockApp.exe | Hot-swappable
drive management on laptops allowing you to change drives without
closing down Windows. Only required if you frequently swap bay
devices |
| U | Bayswap | bayswap.exe | Hot-swappable
drive management on Compaq Notebooks which allows you to swap drives
without closing down Windows. Only required if you frequently swap bay
devices |
| U | Bayswap2 | TbUpdate.exe | Hot-swappable
drive management on Compaq Notebooks which allows you to swap drives
without closing down Windows. Only required if you frequently swap bay
devices |
| N | BBC Alerts | BBC_Alerts.exe | BBC Alerts
- "You can now have all the latest news and sports headlines delivered
straight to your desktop with the new BBC Alerts service" |
| U | BBC News alerts | skinkers.exe | BBC News Desktop Alerts service - see here. Desktop alert and breaking news e-mail services let you find out about all the latest news as it happens |
| ? | BBDial | BT Broadband.exe | Part of BT Broandband - is it required? |
| N | BBLauncher.exe | BBLauncher.exe | BounceBack Professional - back-up software |
| N | bbSysTray | bbSysTray.exe | Philips
CD-RW related - "the 'Blue Button' feature gives users the chance to
receive convenient online support for their possible device problems or
questions" |
| U | bbui | bbui.exe | AOL DSL status monitor displaying a red/green icon indicating if you have a connection |
| U | bca | bca.exe | BeClean Agent - registry, history, temp files, etc cleaner |
| U | BCDetect | bcdetect.exe | Bcdetect.exe
searches the system to make sure Creative drivers are installed for the
video card. It loads the BlasterControl when the drivers are detected.
Your choice - try it and see |
| Y | BCMDMMSG | bcmdmmsg.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems |
| U | BCMHal | rundll32.exe bcmhal9x.dll, bcinit | BlasterControl
for Creative video cards - controls for desktop settings, monitor
configuration, colour adjustments and performance tuning. May be needed
to retain settings |
| Y | BCMSMMSG | BCMSMMSG.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems |
| ? | bcmwltry | bcmwltry.exe | Broadcom Corporation Wireless Network Tray Applet. Is it required? |
| N | BCNT | bcnt.exe | AWS Weatherbug related. What does it do? |
| X | BCPC | bcpc.exe | BroadcastPC adware variant |
| X | bcpc_c | bcpc_c.exe | BroadcastPC adware variant |
| U | BCTweak | bctweak.exe | BlasterControl
for Creative video cards - controls for desktop settings, monitor
configuration, colour adjustments and performance tuning. May be needed
to retain settings |
| X | Bcvsrv32 | bcvsrv32.exe | Added by the GAOBOT.BQJ WORM! |
| X | Bcvsrv32 | he3.exe | Added by the AGOBOT.AKB WORM! |
| X | Bcvsrv32 | msxml22.exe | Added by the AGOBOT.AKH WORM! |
| N | BCWipeTM | bcwipetm.exe | BCWipe
Task Manager - scheduler for BCWipe so that it runs at convenient
times. You can set a time for running the task, as well as special
options for the task. Run manually when needed |
| X | BD | dc.exe | Added by the RASDOOR-A TROJAN! |
| U | BDAgent | bdagent.exe | BitDefender antivirus |
| Y | BDMCon | Bdmcon.exe | BitDefender antivirus |
| Y | BDNewsAgent | bdnagent.exe | BitDefender antivirus - updater |
| Y | BDOESRV | bdoesrv.exe | Bitdefender 8 antivirus and firewall |
| Y | BDSwitchAgent | bdswitch.exe | Bitdefender 8 antivirus and firewall |
| U | BearFlix | BearFlix.exe | BearFlix is optimized for the fast download of video files |
| N | BearShare | bearshare.exe | BearShare file sharing client. Versions known to include spyware - see here |
| U | BeatNik Internet Clock | BeatNik.exe | BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock |
| X | Beawver | saqevre.exe | Added by a variant of the RANKY TROJAN! |
| X | Beegees Update | beegees.exe | Added by the SDBOT-ADK WORM! |
| ? | BEEI | beei.exe | ?? |
| U | BeFaster | befaster3.exe | BeFaster internet connection optimization tool |
| ? | BEHL | BEHL.exe | ?? |
| ? | BEHLO | BEHLO.exe | ?? |
| U | beidsystemtray | beidsystemtray.exe | Related to Belgium Identity Card card reader |
| N | Belkin PCMCIA WLAN Monitor | monitorbk.exe | Belkin USB Network Adapter Management utility - can be started manually |
| N | Belkin Wireless Utility | Belkinwcui.exe | Wireles configuration utility for some Belkin cards such as the Wireless G Desktop Card |
| U | BellSouthAlertManager.exe | BellSouthAlertManager.exe | Related to BellSouth Alert Manager |
| U | BelNotify | rundll32.exe [path] NPBelv32.dll, RunDll32_BelNotify | "BelTech from Belarc
enables licensees to offer automated, Web-based problem resolution to
their end-users. BelTech allows the end-user to simply go to a web page
and automatically resolve their problem or point them to the right
solution. BelTech Manager allows non-programmers to rapidly and easily
deploy and maintain this service" |
| ? | BELORVBI | BELORVBI.exe | ?? |
| ? | Belsta.exe | Belsta.exe | Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed? |
| X | Belt | Belt.exe | VX2.Transponder parasite updater/installer related |
| X | Benadril Alert Tool | benadrilalert.exe | Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril |
| U | BestCrypt Auto Open | BestCrypt.exe | BestCrypt
from Jetico, Inc. "Keeps your confidential data in a strongly encrypted
form on your disk and provides you with transparent access" |
| X | BestPopUpKiller | BestPopupKiller.exe | Popup killer by Swanksoft - not recommended, see here |
| X | BeSys | [path to file] | BeSys adware |
| X | beta | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| X | BF4P | bf4p.exe | Added by the IRCBOT.GEN WORM! |
| Y | bg | bullguard.exe | Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster |
| U | BGInfo | Bginfo.exe | BGinfo
automatically displays relevant information about a Windows computer on
the desktop's background, such as the computer name, IP address,
service pack version, and more |
| U | BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMBgMonitor.exe | Associated with Nero Scout,
added by version 7 of the Nero digital media suite (CD & DVD
burning, authoring, etc). Thanks to Help2Go.com, if you feel this is
draining more resources that necessary you can disable it by clicking here |
| Y | BGNewsAgent | bgnewsag.exe | BullGuard antivirus updater
|
| N | bgsmsnd | bgsmsnd.exe | Printer driver to generate PDF files from any program |
| X | Bharatayuda | GNB.exe | Added by the BHARAT.A WORM! |
| N | BHOCop | BHOCop.exe | PC Magazine's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware |
| U | BHODemon 2.0 | BHODemon.exe | BHODemon
"protects you from unknown Browser Helper Objects (BHOs), by letting
you enable/disable them individually. When running, it also monitors
your Registry and alerts you when a BHO is installed. Best of all,
BHODemon knows about the most common BHOs - the good ones, and the
not-so-good ones!". If you prefer forgoing resident protection, the
application can also be run on demand |
| U | BHR | BHR.exe | Browser Hijack Retaliator - recovers your browser after it has been hijacked by spyware, adware, etc |
| U | BI1HelperStartUp | BI1HEL~1.EXE | ScreenScenes "Beach Islands" screensaver. The freeware version comes with GAIN
branded ads (pop-ups and others). ScreenScenes do however offer you the
option of doing away with the ads by purchasing the screensaver for a
whopping $30. Please note that Claria Corporation no longer support
GAIN-Supported software - see here |
| X | BIE | Rundll32.exe [path] BDSrHook.dll, Rundll32 | BDplugin parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | BIG | biggy.exe | Added by the DELBOT-AG WORM! |
| U | BigDog303 | VM303_STI.EXE | Related to VIMICRO USB for PC Camera |
| N | BigDog305 | VM305_STI.EXE | Vmicro
webcam USB utility - allows the webcam to initiate data transfer to a
program. Create a shortcut and start it manually when needed |
| ? | BigDogPath | VM_STI.EXE | Bundled with some software for digital cameras that use a USB connection - what does it do and is it required? |
| N | bigfix | BIGFIX.EXE | BigFix
can automatically download and read technical support information
provided by computer and software manufacturers and other technical
support experts (published in the form of Fixlet? Messages) and can
automatically check your computer for bugs, configuration conflicts,
and security holes. Should only be started manually as it's a resource
hog |
| X | bigoris | bigoris.exe | Added by the DORF-AZ TROJAN! |
| U | BigPond Toolbar | bpumTray.exe | Telstra BigPond
Toolbar - "Introducing the free and easy to use BigPond Toolbar that is
designed to make your internet experience and managing your Telstra
internet account a whole lot easier" |
| N | BigPondCable | bpcable.exe | Telstra Bigpond Cable login software - can be started manually
|
| Y | BigPondWirelessBroadbandCM | BigPond_CM.exe | Related to BigPond_Wireless_Broadband Service by Telstra |
| X | bikini | bikini.exe | Added by the LOWZONE-CX TROJAN! |
| X | BillGatesLoh.exe | BillGatesLoh.exe | Added by the AGENT-FZO TROJAN! |
| N | Billminder | Billmind.exe | Can be setup in Quicken to remind user of due payments. Available via Start -> Programs |
| X | bin32hpu | ppstub.exe | PrecisionPop adware |
| X | bingdian | Bingdian.vbs | Added by the BINGD WORM! |
| ? | Bingo Charm | charms.exe | Some kind of screen icon kind of like desk flag, but it gives you a choice of icons? |
| U | Biomenu | menusw.exe | Related to Sony VAIO - passwords, encryption, and a biometric fingerprint sensor |
| X | Bios | Bios32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | bios | bios.exe | Added by the BANCBAN-PW TROJAN! |
| X | BIOS XP Loader | [random filename] | Added by the RBOT-IC WORM! |
| X | BIOS1 | BIOS1.EXE | Added by the OPASERV.T WORM! |
| ? | BIOVCIP | BIOVCIP.exe | ?? |
| N | BitComet | BitComet.exe | BitComet P2P client - can be launched from Start -> Programs |
| Y | BitDefender Antiphishing Helper | IEShow.exe | Antiphishing component of BitDefender 2008 products |
| X | BitDefender Antivirus | BITDEFENDERX.EXE | Added by a variant of the SPYBOT WORM! |
| Y | BitDefender Communicator | xcommsvr.exe | BitDefender antivirus |
| U | BitDefender for MSN Messenger | msnmon.exe | Bitdefender anti-virus for MSN Messenger - no longer supported at the BitDefender website |
| U | BitDefender for Yahoo! Messenger | yahmon.exe | Bitdefender anti-virus for Yahoo! Messenger - no longer supported at the BitDefender website |
| Y | BitDefender Live! Init | bdinit.exe | BitDefender antivirus |
| Y | BitDefender Scan Server | bdss.exe | BitDefender antivirus |
| Y | BitDefender Virus Shield | vsserv.exe | BitDefender antivirus |
| Y | bitdefenderlive | avxlive.exe | Main program of BitDefender virus scanner/firewall |
| U | BitDefender_P2P_Startup | BitDefender_P2P_Startup.exe | Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website |
| U | BitTorrent DNA | btdna.exe | "BitTorrent DNA
is a content delivery service that uses a secure, private, managed peer
network to power faster, more reliable, more efficient delivery of
richer content" |
| N | BitWare Print Monitor | bwprnmon.exe | FaxServe network fax software |
| N | BJ Printer Status Monitor | Cjstsr.exe | Canon BJ printer status monitor |
| N | BJ Status Monitor 5xx | CJSTRxx.EXE | Canon
printer status monitor - where "xx" is different depending upon the
version. Not required as you can check the printer status via My
Computer -> Printers |
| N | bjcfd | cdf.exe | BroadJump
Client Foundation. Broadband troubleshooting software installed by
various companies. Not required and you can remove it via Add/Remove
programs |
| U | BJPD HID Control | TVMon.exe | Related to Canon Photo viewer |
| N | BlackICE PC Protection | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site
- '(the user interface) starts in the "Startup" menu and adds itself to
the taskbar. The user interface is independent from the rest of the
system and only displays the output or reconfigures the system. It does
not need to be running for the rest of the system to run.' See also
LoadBlackD |
| N | BlackIce Utility | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site
- '(the user interface) starts in the "Startup" menu and adds itself to
the taskbar. The user interface is independent from the rest of the
system and only displays the output or reconfigures the system. It does
not need to be running for the rest of the system to run.' See also
LoadBlackD |
| U | blads | blads.exe | A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks |
| X | blah service | winupdate.exe | Added by the GAOBOT.BIA WORM! |
| X | blah service | winsysengine.exe | Added by the RBOT-KI WORM! |
| X | blah service | internet.exe | Added by a variant of the RBOT WORM! |
| X | blah service | smnp.exe | Added by the RBOT.IZ WORM!
|
| X | blah service | msnmsgrr.exe | Added by the RBOT.PZ WORM! |
| X | blah service | tazkmgr.exe | Added by the RBOT.UA WORM! |
| X | blah service | FaLeH.exe | Added by the RBOT-AES WORM! |
| X | blah service | microsoft.exe | Added by a variant of the RBOT WORM! |
| X | blah service | evosys.exe | Added by a variant of the RBOT WORM! |
| X | blah service | win32.exe | Added by the RBOT-AXO WORM! |
| X | Blah service | CCAPPS32.EXE | Added by the RBOT.TV WORM! |
| X | blah services | iczw.exe | Added by the RBOT-GMP WORM! |
| X | blahh service | msengine.exe | Added by a variant of the RBOT WORM! |
| X | blahx service | msnjompa.exe | Added by the SDBOT.AML WORM! |
| X | Blank AntiViri | AUT0EXEC.BAT | Detected by Symantec as the SILLYFDC WORM! See here |
| N | BlazeChanger | FBZPaper.exe | Ember graphic file viewer, manager, and touch-up system |
| N | bldbubg | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system |
| X | BLF | blf.exe | Added by the DELBOT-M WORM! |
| U | blinkx | blinkx.exe | Blinkx Desktop "Smart Folders" software |
| N | Blitzz BWI715 | WLANmon.exe | Blitzz Technology BWI715 Wireless PC modem connection monitor |
| X | BLMessagingIntegration | blengine.exe | BuddyLinks adware |
| U | BlockAds | blads.exe | A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks |
| X | BlockChecker | Block-checker.exe | BlockChecker adware |
| X | Blocker System611 Monitoring | PopUpBlocker611.exe | Added by the RBOT.BLJ WORM! |
| N | BlockTracker | BlockTracker.exe | If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file |
| U | BLOG | rundll32.exe [path] BatLogEx.DLL, StartBattLog | IBM Thinkpad battery management utility that logs changes in battery conditions such as charging, discharging, etc |
| U | blsloader | blsloader.exe | BellSouth ISP Internet Tools |
| X | blss | blss.exe | Added by the BLARUL TROJAN! |
| N | BLSTAPP | blstapp.exe | Puts access to Creative's BlasterControl in the System Tray |
| N | Blubster | Blubster.exe | Related to Blubster Music sharing service |
| U | Blue Frog | bluefrog.exe | Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive |
| X | Blue Service | [path to trojan] | Added by the BANCOS-BCW TROJAN! |
| ? | BlueLight_uoltray | exec.exe | Related to BlueLight Internet. What does it do and is it required? |
| U | BlueSoleil | BLUESO~1.EXE | BlueSoleil Bluetooth wireless manager from IVT Corporation |
| U | BlueSpace NE | BlueSpaceNE.exe | "BlueSpace
NE is a utility program used to run the Bluetooth function on VAIO
computers that support the Bluetooth function or on VAIO computers
connected to the Bluetooth USB adapter". Shortcut available via Start
-> Programs |
| X | Bluetooth Config | btwindin32.exe | Added by the SDBOT-DFN WORM! |
| U | BlueToothAuthentication Agent | RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent | Associated
with BlueTooth software, designed to allow bluetooth mobile devices to
authenticate to the computer, when connecting a PDA to your computer -
necessary for the computer and the PDA to communicate. Should you get
the error message, "Rundll irprops.cpl missing entry Bluetooth
authentication agent", click here
for more information. In case you no longer have BlueTooth support
installed, and don't need it, simply uncheck the entry in Msconfig >
Startup |
| U | Blueyonder Instant Support Tool | matcli.exe | "matcli.exe
is a motive Assistant Command line interface that gathers information
about your system's identity like your name email address, city, state,
etc and gets written to a log file". Blueyonder Instant Support is
required to run with the Help and Support program. If you uncheck it
and and then run Help and Support it will add another Blueyonder
Instant Support in the startup menu. If you remove Blueyonder Instant
Support in add/remove programs some help menus in help and support will
not be available. You decide |
| N | BMail Installation | FTP_back.exe | Part of iMesh
- a file sharing system. Reported by Norton AntiVirus as a trojan. Once
deleted does not prevent file sharing working. Older versions of iMesh
re-instate this but the newer versions do not |
| X | Bman | BMan1.exe | Abcsearch.com/DealHelper adware variant |
| U | BMMGAG | Rundll32 PWRMONIT.DLL, StartPwrMonitor | Displays
a battery gauge icon in the Taskbar (not the System Tray). Provides
shortcuts to IBM's proprietary power saving settings and to a battery
information window |
| U | BMMLREF | BMMLREF.EXE | Battery Manager for IBM ThinkPad laptops |
| U | BMMMONWND | rundll32.exe [path] BatInfEx.dll, BMMAutonomicMonitor | Battery power management utility for Lenovo (IBM) ThinkPad laptops |
| U | BMO MasterCard Wallet | EWALLET.EXE | The wallet conveniently stores billing, shipping and payment information on your PC |
| N | BMupdate | BMupdate.exe | Related
to the BookmarkCentral entry. Typically added after downloading drivers
for Visioneer scanners for example, and you install the driver
self-install |
| X | BMZ | bmz.exe | NCase adware |
| X | Bndt32 | Bndt32.exe | Added by the LACON WORM! |
| X | Bnexe | [random filename] | Added by the KITRO.D (or ARGEN.A) WORM! |
| U | BO1HelperStartUp | BO1HEL~1.EXE | ScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with GAIN
branded ads (pop-ups and others). ScreenScenes do however offer you the
option of doing away with the ads by purchasing the screensaver for a
whopping $30. Please note that Claria Corporation no longer support
GAIN-Supported software - see here |
| U | BO1HelperStartUp | Bo1helper.exe | ScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with GAIN
branded ads (pop-ups and others). ScreenScenes do however offer you the
option of doing away with the ads by purchasing the screensaver for a
whopping $30. Please note that Claria Corporation no longer support
GAIN-Supported software - see here |
| X | Boarddata | [path] repcale.exe [path] palsp.exe | Added by a variant of the RANDON.AN WORM! |
| X | boat32 | boat32.exe | Added by a variant of the RBOT WORM! |
| X | boby | csrs.scr | Added by the BANCBAN-PC TROJAN! |
| Y | BOC-423 | BOC423.exe | NSClean BOClean
(now Comodo) anti-malware software - "Protect yourself from online
identity theft. The greatest threat on the Internet today is having
your personal information hijacked remotely". Version 4.23 |
| Y | BOC-424 | BOC424.exe | NSClean BOClean
(now Comodo) anti-malware software - "Protect yourself from online
identity theft. The greatest threat on the Internet today is having
your personal information hijacked remotely". Version 4.24 |
| Y | BOC-425 | BOC425.exe | Comodo BOClean
anti-malware software - "Protect yourself from online identity theft.
The greatest threat on the Internet today is having your personal
information hijacked remotely". Version 4.25 |
| Y | BOC412 | BOC412.exe | Version 4.12 of NSClean's BOClean anti-trojan software |
| Y | BOCleanautostart | Boclean.exe | NSClean's BOClean anti-trojan software |
| U | BOINC Manager | boincmgr.exe | BOINC manager - "controls the use of your computer's disk, network, and processor resources" |
| U | Boingo Wireless Utility | Icon###XXX#X#.exe | Starts the Boingo Wireless utility, used to detect and login into Boingo
wireless hotspots. The filename may be autogenerated when installing,
two different variations along the lines listed here, where # is a
number and X is a letter. Shortcut available via Start -> Programs |
| X | bolenja | bolenja.exe | Added by the WANTVI.BF TROJAN! |
| X | bolenjx | bolenjx.exe | Added by the ELDYCOW.O TROJAN! |
| X | boler.exe | syser.exe | Added by the RBOT-AYS WORM! |
| U | bombshel | BOMB32.EXE | Part
of McAfee Nuts & Bolts. Protects your Windows system from
application failure and crashes - similar to Norton Crashguard. Your
choice - may cause problems |
| X | Bonzi Buddy | ?? | Bonzi Buddy adware - see here for removal instructions |
| X | boo | boo.exe | Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN! |
| X | BookedSpace | RunDLL32.EXE bs2.dll, DllRun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "bs2.dll" file is located in the Winnt or
Windows folder |
| N | BookmarkCentral | BMLauncher.exe | Bookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use" |
| N | BookMarkSink | syncit.exe | Bookmark synchronization utility |
| N | BookMarkSync | syncit.exe | Sync2IT BookMarkSync
- "real-time automatic synchronization service that allows you to
access your bookmarks, favorites and favorite files from any computer
or any browser". Only installed with the users explicit permission and
generally only remains running if the user decides to subscribe to the
service. If it is no longer required it should be uninstalled to
prevent a large number of clients 'checking in' to the server that have
no chance of synchronizing |
| N | BookMarkSync2It | sync2it.exe | Sync2IT BookMarkSync
- "real-time automatic synchronization service that allows you to
access your bookmarks, favorites and favorite files from any computer
or any browser". Only installed with the users explicit permission and
generally only remains running if the user decides to subscribe to the
service. If it is no longer required it should be uninstalled to
prevent a large number of clients 'checking in' to the server that have
no chance of synchronizing |
| U | Boost XP Service | bxservice.exe | Boost XP from Systweak - WinXP tweaking utility |
| X | boot | boot.exe | Added by the PUPPET-A TROJAN! Located in the System (9x/Me) or System32 (NT/2K/XP) folder |
| U | Boot | Boot.exe | Part of Acer Empowering Technology. "Acer ePower Management
is a straightforward interface that allows users to select from
pre-configured power usage profiles, or to create their own customized
profiles". Located in the "AcerEmpowering TechnologyePower" directory |
| X | Boot Check | bootchk.exe | Added by the DELBOT-AB WORM! |
| X | Boot Config | bootconfig.exe | Added by the FLOOD-EV TROJAN! |
| X | Boot Manager | Njgal.exe | Added by the KILO TROJAN! |
| X | Boot Manager | bootmng.exe | Added by a variant of the SPYBOT WORM! |
| X | BootCfg | Install.log.vbs | Added by the YPSAN.D WORM! |
| X | BootCTRL | bootctrl.exe | Added by an unidentified WORM or TROJAN! |
| X | BootLoader | BootLoader.exe.vbs | Added by the WATERWORKS WORM! |
| X | bootpd.exe | bootpd.exe | Added by the AGENT-DT TROJAN! |
| X | BootsCfg | wscript.exe [path] Date.POP.vbs | Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe [path] All Users.vbs | Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe [path] All Users.vbe | Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe Install.log.vbs | Added by the YPSAN.E WORM! Note that wscript.exe
is a legitimate Microsoft file used to launch script files and
shouldn't be deleted. The "Install.log.vbs" file is found in the System
(9x/Me) or System32 (NT/2K/XP) folder |
| U | BootStatus | BOOTST~1.EXE | Visual
Basic program that pops up a small window on startup telling you how
many times the machine has been booted that day. Once you exit
it, it has no more effect on resources |
| U | BootWarn | BootWarn.exe | From here:
"Norton AntiVirus Boot Warning. This program is installed as a startup
item when you install Norton AntiVirus, and also sometimes when you do
a LiveUpdate which updates Norton AntiVirus significantly enough that a
reboot is needed to complete the installation. We believe its purpose
to be to warn the end-user that he must reboot his PC before using
Norton AntiVirus in those cases when a reboot did not happen with the
result that Norton AntiVirus did not fully complete its installation or
software updating. Recommendation : Start Norton AntiVirus from "Start
Programs Norton AntiVirus". If Norton AntiVirus comes up without
problems, then fix this entry from the Msconfig Startup tab - it was
left behind by mistake and is no longer needed now that Norton
AntiVirus is fully installed and opens without error messages" |
| X | boot_reg | [path to file] | Added by the BANCBAN-CA TROJAN! |
| N | Bose Wave/PC Monitor | wavepcmonitor.exe | System Tray access for this system (more info on the system here). Available via Start -> Programs |
| X | BossIdea | winlogin.exe | Added by the LINEAGE-I TROJAN! |
| ? | Boston | Boston.exe | Part of the Boston Acoustics USB speaker systems. What does it do and is it required? |
| X | Bot Loader | svchostt.exe | Added by the GAOBOT.ALV WORM! |
| X | Bouncer RunStartup | bouncer.exe | Virtual Bouncer
- malware from Spyware Labs. It is distributed by the same bundling and
drive-by download techniques as the parasites it claims to remove, so
definitely qualifies as unsolicited commercial software in itself. It
also has an update feature that can download and execute arbitrary
code. Warning - choose "custom" uninstall as "automatic" may remove
other programs - see here |
| X | Bouncer RunStartup | LiveUpdate.exe | Virtual Bouncer
- malware from Spyware Labs. It is distributed by the same bundling and
drive-by download techniques as the parasites it claims to remove, so
definitely qualifies as unsolicited commercial software in itself. It
also has an update feature that can download and execute arbitrary
code. Warning - choose "custom" uninstall as "automatic" may remove
other programs - see here |
| X | boy lovers of bsd | ilikeboys.exe | Added by the MYTOB.LY WORM! |
| U | bpcpost.exe | bpcpost.exe | MS
TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to
display TV on your PC via a compatible video card with in-built tuner
(such as ATI All-In-Wonder). If you don't use it - uninstall it |
| X | BPCv2 re | bpc2 re inst.exe | BroadcastPC adware variant |
| U | BPK | bpk.exe | Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself!
|
| N | BPServer | G6FTPSrv.exe | BulletProof FTP Server |
| U | BQTray.exe | BQTray.exe | System Tray access to BurnQuick
CD burning software. Only required if you use the queueing facility,
hence the U recommendation. Create your own desktop shortcut to start
manually |
| X | Brasil | Brasil.exe | Added by the OPASERV.E WORM! |
| X | Brasil | BRASIL.PIF | Added by the OPASERV.E WORM! |
| X | BrasilOld | [worm filename] | Added by the OPASERV.P WORM! |
| X | BraveSentry | BraveSentry.exe | BraveSentry spyware remover - not recommended, see here |
| X | braviax | braviax.exe | Added by an unidentified malware |
| X | Brct | trdb.exe | Detected by Kaspersky as the PURITYSCAN.Y TROJAN! |
| U | Break_Reminder | BREAK REMINDER.exe | Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here |
| Y | Bredbandsbolaget | servicecenter.exe | Related to the Brebband Swedish Broadband provider |
| X | Breg | bcre.exe | BroadcastPC adware variant |
| X | Breg | bptre.exe | BroadcastPC adware variant |
| X | Breg | breg.exe | BroadcastPC adware variant |
| X | Bridge | rundll32.exe ...Bridge.dll | Flingstone.com browser hijacker |
| Y | Brindys BriTray | BRITRAY.EXE | Main
process for the following applications: GEDEX, SICARIO, BRINOTES,
BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from
Brindys Software).
Performs the following tasks [un]installation, web software autoupdate,
notification windows, interprocess communication, tray bar icons &
menus, alarms (brinotes), and common web launching from the mentioned
applications. Can be stopped safely once run if so desired |
| U | BrmfRmPA | BrmfRmPA.exe | Brother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate |
| U | broadband medic | matcli.exe | "matcli.exe
is a motive Assistant Command line interface that gathers information
about your system's identity like your name email address, city,
county, etc and gets written to a log file". ntlbroadband Help is
required to run with the Help and Support program. If you uncheck
ntlbroadband Help and and then run Help and Support it will add another
ntlbroadband Help in the startup menu. If you remove the ntlbroadband
Help in the add/remove program some help menus in help and support will
not be available. You decide |
| N | Broadband Wizard | bbwiz.exe | Starts Broadband Wizard
so it runs in the System Tray. This application tests and optimizes
your Cable or DSL connection. Available via Start -> Programs |
| N | BroadCamRun | broadCam.exe | BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone |
| U | Broadcom Wireless Manager UI | bcmntray.exe | Related to Broadcom
Network Adapters for additional configuration options for these
devices. Should not be terminated unless suspected to be causing
problems |
| N | Broadcom Wireless Manager UI | wltray.exe | System tray access to wireless LAN card configuration options
|
| X | Bron-Spizaetus | CVT.exe | Added by the RONTOKBRO WORM! |
| X | Bron-Spizaetus | norBtok.exe | Added by the RONTOKBRO.B WORM! |
| X | Bron-Spizaetus | [path to file] | Added by the BRONTOK-F WORM! |
| X | Bron-Spizaetus | bronstab.exe | Added by the RONTOKBRO.C WORM! |
| X | Bron-Spizaetus | eksplorasi.exe | Added by the RONTOKBRO.J WORM! |
| X | Bron-Spizaetus | ElnorB.exe | Added by the RONTOKBRO.D WORM! |
| X | Bron-Spizaetus | sempalong.exe | Added by the BRONTOK-E WORM! |
| X | Bron-Spizaetus | RakyatKelaparan.exe | Added by the BRONTOK-J or BRONTOK-L WORMS! |
| X | Bron-Spizaetus-5118REPM | komodo-6321422.exe | Added by the BRONTOK-R WORM! |
| X | Bron-Spizaetus-cfgmktoq | bbm-qotkmgfc.exe | Added by the BRONTOK-M WORM! |
| X | Bron-Spizaetus-cfgmmnru | bbm-urnmmgfc.exe | Added by the BRONTOK-N WORM! |
| X | BrowseProxy | FindService.exe | Actual Names (AdvSearch) Internet Keywords parasite |
| X | browser | msgaol.exe | Added by the TACTSLAY.C TROJAN! |
| X | browser | s_menu.exe | Added by the TACTSLAY.C TROJAN! |
| X | browser | browse.exe | Added by the TACTSLAY.C TROJAN! |
| X | browser | deamon.exe | Added by the TACTSLAY.C TROJAN! |
| X | browser | msgaol.exe | Added by the TACTSLAY.C TROJAN! |
| X | browser aid | browseraid.exe | BrowserAid/BrowserPal foistware |
| X | Browser Help Svc | BHSV.EXE | Added by the RBOT-AVQ WORM! |
| Y | Browser Hijack Blaster | bhblaster.exe | Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard |
| U | Browser Launcher | Commandr.exe | Logitech
internet keyboard "Commander" software - loads the software for the
shortcut keys on the keyboard. Not required unless you want to use the
short cut keys |
| X | Browser Pal | adblck.exe | BrowserAid/BrowserPal foistware |
| U | Browser Sentinel | BrowserSentinel.exe | Browser Sentinel
- notifies you if a program wants to penetrate into Internet explorer,
add itself to the Windows auto-run list or change your home page |
| X | BrowserUpdateSched | [random filename] | ZenoSearch adware |
| N | BrowserWebCheck | loadwc.exe | Checks to make sure that IE is still your default browser |
| X | BrO_AcT | BrO-AcT.exe | Added by the SILLYFDC-D WORM! |
| X | brwdiag | [path to worm] | Added by the STRATIO-BN WORM! |
| N | BS Player | bsplayer.exe | BSplayer - A video player used to play avi, mpg, wmv and other multimedia files |
| N | BsCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required |
| X | Bsoft lppt01 | Bsoft.exe | RapidBlaster variant (in a "BelmontSoft" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
| N | bsplayer | bsplayer.exe | BSplayer - a video player used to play avi, mpg, wmv and other multimedia files |
| X | BSserver | FileKan.exe | Added by the VB.CBW WORM! |
| X | BSVCHOST | SVCH0ST.EXE | Added by the VOXOM TROJAN! |
| X | Bsx3 | RunDLL32.EXE bs3.dll, DllRun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "bs3.dll" file is located in the Winnt or
Windows folder |
| X | BT | [path to trojan] | Added by the LITEBOT-B TROJAN! |
| U | BT Broadband Desktop Help | matcli.exe | "matcli.exe
is a motive Assistant Command line interface that gathers information
about your system's identity like your name email address, city,
county, etc and gets written to a log file". BT Broadband Help is
required to run with the Help and Support program. If you uncheck BT
Broadband Help and and then run Help and Support it will add another BT
Broadband Help in the startup menu. If you remove the BT Broadband Help
in the add/remove program some help menus in help and support will not
be available. You decide |
| U | BT Broadband Help | matcli.exe | "matcli.exe
is a motive Assistant Command line interface that gathers information
about your system's identity like your name email address, city,
county, etc and gets written to a log file". BT Broadband Help is
required to run with the Help and Support program. If you uncheck BT
Broadband Help and and then run Help and Support it will add another BT
Broadband Help in the startup menu. If you remove the BT Broadband Help
in the add/remove program some help menus in help and support will not
be available. You decide |
| X | BT00003* | abcdefg23.exe | Added by the VB-VT TROJAN where * = 5,6 or 7! |
| X | BT00003* | hiklmnop27.exe | Added by the VB-VT TROJAN where * = 2,3 or 4! |
| U | btbb_wcm_McciTrayApp | McciTrayApp.exe | System tray access to Motive's Broadband 2.0 configuration and repair utility |
| ? | btinst | btinst.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? |
| U | BTModemProtection | BTModemProtection.exe | BT Privacy Online modem protection software, see here |
| U | BTopenworld | DialBTYahoo.exe | BT Yahoo! internet connection manager
|
| ? | BTSETBOOTKEY | BTSetBootKey.exe | Related to a USB Bluetooth adaptor. What does it do and is it required? |
| U | BtStart | btstart.exe | Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software |
| U | bttray | bttray.exe | System
tray icon which shows the status of a BlueTooth wireless module. Most
systems with such a module installed can enable/disable the module. The
system tray icon changes from blue/white to blue/red when the module is
turned off. Allows access to explore bluetooth places, setup wizard,
advanced configuration, quick connect and shutdown device |
| Y | BTUSRBDG | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) |
| Y | BTUSRBDGF | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) |
| X | BTV | btv.exe | BroadcastPC adware variant |
| Y | Bubble | Bubble.exe | Added by Windows SteadyState
which "helps make it easy for you to keep your computers running the
way you want them to, no matter who uses them." Bubble allows
notification messages to appear on a computer managed by Windows
SteadyState |
| N | Buddyizer | Buddyizer.exe | Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network |
| U | BUFFALO Power Save Utility for HD | HDManage.exe | Power Save utility for Buffalo backup hard discs |
| N | Bug Eliminator | Bug_Elim.exe | Bug Eliminator - "performs a complete health check on your computer safely, securely, and silently!" |
| U | bugwatcher service | bugwatcher.exe | Bugtoaster
is a service that sends reports on system/program crashes (certain
types) back to Bugtoaster. They relay information to program authors
and provide, if available, any known solutions to the crashes. It
doesn't take up any room in memory, just activates in the event of
certain program failures |
| N | BuildBU | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system |
| X | BuildLab | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | BuildLab | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | BuildLabs | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | BuildLabs | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the System folder |
| U | Bulldog Service | upsd.exe | Belkin's
Bulldog Plus control software which runs under Windows 95 or later and
monitors the UPS (Uninterrupted Power Supply) via a serial or USB link |
| N | BulletProof FTP Server | bpftpserver.exe | BulletProof FTP Server |
| Y | BullGuard | mgui.exe | Part of Bullguard antivirus |
| Y | BullGuard | BullGuard.exe | Part of BullGuard antivirus |
| U | BullGuard Update | avxlive.exe | Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions |
| Y | BullGuard XComm | XCOMMSVR.EXE | Part of Bullguard antivirus |
| Y | BullGuardInit | AVXINIT.EXE | Part of Bullguard antivirus |
| Y | BullguardoptIn | bulldownload.exe | Part of Bullguard antivirus |
| X | BullsEye | bargains.exe | BargainBuddy adware |
| X | BullsEye Network | bargains.exe | BargainBuddy adware |
| ? | BullsEye Tracker | BeTrack.exe | Bullseye - intelligent research assistant |
| X | Bunx | beagle.exe | Added by the LEBREAT-E WORM! |
| N | BurnQuick Queue | BQTray.exe | System Tray access to BurnQuick
CD burning software. Only required if you use the queueing facility,
hence the U recommendation. Create your own desktop shortcut to start
manually |
| U | Button Server | bttnserv.exe | Found
on a Compaq PC, for the extra buttons on the keyboard for the speaker
volume, media player, sleep and internet buttons. If the buttons aren't
used on the keyboard or your's doesn't have them, then it isn't required |
| N | ButtonKey | ButtonKey.exe | CyberView TWAIN driver for the Pacific Image
range of 35mm film scanners. Enables the one touch scanning button and
places an icon an the System Tray. Use your scanners software or run it
manually by creating a shortcut |
| N | Buzme | Bmui.exe | Buzme
by RingCentral, Inc - internet call waiting. Intercepts telephone calls
like an answering machine and plays the voice message on your PC. Only
required when you're on-line and via dial-up modem |
| U | BuzMe | RCUI.exe | Display Client for the BuzMe Internet Call Waiting Service |
| U | Buzof.exe | buzof.exe | Buzof
from Basta Computing "enables you to automatically answer, close or
minimize virtually any recurring window including messages, prompts,
and dialog boxes" |
| N | bwprnmon.exe | bwprnmon.exe | FaxServe network fax software |
| X | bxproxy | bxproxy.exe | Added by the BXPROXY TROJAN! |
| X | bxproxy | [random].dll | Spyware Soft Stop misleading security software - not recommended, see here and here |
| X | bxsx5 | RunDLL32.EXE bsx5.dll, DllRun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "bsx5.dll" file is located in the Winnt or
Windows folder |
| X | bxxs5 | RunDLL32.EXE bxxs5.dll, dllrun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "bxxs5.dll" file is located in the Winnt or
Windows folder |
| X | Bymer.Scanner | Wininit.exe | Added by the BYMER WORM! |
| X | Bymer.Scanner | Msinit.exe | Added by the BYMER WORM! |
| U | BySoft FreeRAM | FreeRAM.exe | "Bysoft FreeRAM
is a program that frees up ram manually or automatically. It shows
current memory status , memory load and CPU usage graphically". MS MVPs
(Most Valued Professional) recommend not using memory managers with
Win98/SE/ME. See this article and make up your own mind |
| X | c | c:archiv~1win.com | Added by the CUYDOC TROJAN! |
| U | C-Media Echo Control | EchoCtrl.exe | C-Media
produce audio chipsets that are often found on popular motherboards
with on-board audio. You may need it if you use the echo control
feature of C-Media Mixer
|
| N | C-Media Mixer | Mixer.exe | C-Media
produce audio chipsets that are often found on popular motherboards
with on-board audio. Provides System Tray access to change audio
settings. Available via Start -> Settings -> Control Panel or
Start -> Programs |
| U | C2K | CYB2K.EXE | CYBERsitter
2000 or 2001 - anti-adult content filter primarily. Required if you
want the sites you visit filtered without having to load the software
every time you launch your browser |
| U | c32cs2 | c32cs2.exe | Cyber Sentinel - internet filtering software |
| X | C7 | [path to worm] | Added by the MEDIAKILL.A WORM! |
| U | C:\Program Files\NetMeter\NetMeter.exe | NetMeter.exe | "Net Meter
is a small, customizable network bandwidth monitoring program for
Win9x/Me/NT4/2K/XP. NetMeter is and will always stay freeware. The
program has been tested extensively on Win2K/XP, but it should work
just as well on all other Win32 operating systems" |
| X | C:\WINDOWS\IEXPLOR.EXE | IEXPLOR.EXE | "Pop Marketing" adware |
| X | C:\WINDOWS\system32\SetupCmd.exe | SetupCmd.exe | Detected by Kaspersky as the AGENT.AAW TROJAN! |
| X | C:\WINDOWS\WinTask.exe | WinTask.exe | "Pop Marketing" adware |
| U | CA-AMAgent | amagent.exe | Unicenter Asset Management
is a solution for proactively managing IT assets in a business
environment. It provides full-featured asset tracking capabilities
through automated discovery, hardware inventory, network inventory,
software inventory, configuration management, software usage
monitoring, license management and extensive cross-platform reporting |
| Y | CaAvTray | CAVTray.exe | eTrust? EZ Antivirus system tray application from Computer Associates |
| X | Cabchk | Cabchk.exe | Added by the GEMA TROJAN! |
| X | Cabchk32 | Cabchk32.exe | Added by the GEMA TROJAN! |
| X | CABCInstall | CABCInstall.exe | Ignite Technologies (was CABC) content delivery software |
| X | Cable Modem Adapter | WindowsSec.exe | Added by the WOOTBOT.A WORM! |
| U | CacheBoost | trayicon.exe | CacheBoost "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost" |
| X | CacheLoader | [path to trojan] | Added by the DLOADER-NZ TROJAN! |
| N | Cacheman | Cacheman.exe | Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up |
| Y | CacheMgr | CacheMgr.exe | Sophos Antivirus Remote Update |
| U | CacheSentry Pro | CacheSentry Pro.exe | "CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache" |
| U | CacheSentry Pro | CacheSentry Pro.exe | "CacheSentry Pro is a program that takes over the management of the Internet Explorer (and AOL) web browser cache" |
| N | CACStarter | cacstart.exe | Cash A Check - check writing software |
| U | Caddais BackupOnDemand | BODMon.exe | Caddais BackupOnDemand
- "runs in the background and monitors your important files for
changes. Within seconds of changing, modified files are automatically
backed up to an archive location" |
| U | Cadenza | CdzSvc.exe | Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices |
| U | CADS | cads.exe | Cyber Sentinel - internet filtering software |
| U | CafeStation | CafeStation.exe | "CafeSuite
is the solution for your internet cafe. Our software provides you with
ameans to control the workstations, manage customer database, sell
products and generate detailed reports and statistics"
|
| Y | cafwc | cafw.exe | CA Personal Firewall - part of the CA Internet Security Suite |
| N | CAgent | CAgent.exe | Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents |
| X | cAgOu | [filename].hta | Added by the KAKWORM WORM! |
| N | CahootWebcard | CahootWebcard.exe | "The
Cahoot Webcard is a virtual card that allows you to use your Cahoot
credit card online without ever having to expose your real card numbers
over the web. It works by generating one-off transaction numbers as a
substitute for your real cahoot credit card details". Run manually when
needed |
| X | caidiysetup | diynetsetupuni.exe | DIYNet adware |
| Y | CAISafe | isafe.exe | Part of Computer Associates eTrust EZ Antivirus |
| U | CaISSDT | caissdt.exe | Computer Associates Dashboard Tray applet
|
| N | Cal Reminder Shortcut | calrem.exe | Produces a pop-up reminder of events scheduled using the MS Office Calendar |
| X | Calc Microsoft Windows | wincalc.exe | Added by an unidentied WORM or TROJAN! |
| X | CALC32 | CALC32.EXE | Added by the SPYBOT-EC WORM! |
| N | Calendar 200X Reminder | calendar.exe | Calendar 200X - shows holidays, reminders of various anniversaries,tasks etc |
| U | Calendarscope | cs.exe | Calendarscope calendar software |
| X | calk | calk.exe | Added by the STARTPA-FH TROJAN! |
| X | Call Function System32 | sddriver.exe | Added by a variant of the SDBOT TROJAN! |
| X | Call32 | Call32.exe | Added by the SPAMMIT-H TROJAN! |
| Y | CallBumping | cbpopw.exe | Related to the Gazel 128 PCI ISDN adapter. Required if you use it |
| U | CallCenter Main Application | V3calmcp.exe | "V3 Inc. CallCenter
is a free 32-bit, integrated fax, voicemail and data communications
application with a simple to use interface providing fax send and
receive functionality, basic (single mailbox) answering machine
capability, and sophistcated data communications." Main application |
| U | CallCenter Printer Interface | V3faxecp.exe | "V3 Inc. CallCenter
is a free 32-bit, integrated fax, voicemail and data communications
application with a simple to use interface providing fax send and
receive functionality, basic (single mailbox) answering machine
capability, and sophistcated data communications." Fax printer |
| N | CallControl | ftctrl32.exe | FaxTalk
Messenger Pro is a Windows TAPI based 32-bit application. When
installed, the software automatically loads FaxTalk CallControl when
you start Windows. When FaxTalk CallControl is running, any TAPI
compliant application can request to use the modem from Windows |
| N | CamCheck | CamCheck.exe | NuCam camera software related |
| U | Cameno | Cameno.exe | Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above |
| U | Camera Detector | CAMDET~*.EXE | ACDSee
Auto Device Detector detects when a device is connected to your PC and
gives you the option to acquire images from it automatically |
| U | Camera Detector | Camdetect.exe | ACDSee
Auto Device Detector detects when a device is connected to your PC and
gives you the option to acquire images from it automatically |
| U | Camera Detector | DEVDET~*.EXE | ACDSee
Auto Device Detector detects when a device is connected to your PC and
gives you the option to acquire images from it automatically |
| N | Camio Viewer x | IXApplet.exe | Image
viewing program that comes with digital cameras. Shows pictures that
are in the camera before downloading them. "x" in the name is the
version |
| ? | CamMonitor | hpqcmon.exe | From HP and related to digital imaging |
| N | Canada | Canada.exe | Known to be a dialler - but is it maliscous or clean? |
| U | Canary | canary-std.exe | Canary keystroke logger/monitoring program - remove unless you installed it yourself!
|
| X | candy | command32.exe | Added by the RBOT-LV WORM! |
| X | candynet | Taskmsg.exe | Added by the RBOT-NA WORM! |
| U | Canon MultiPASS Status Monitor | monitr32.exe | Cannon Multi-Pass status monitor - your choice |
| ? | Canon PC1200 iC D600 iR1200G Status Window | CAPM1LAK.EXE | Cannon printer related - is it required in startup? |
| N | Canon Printer Monitor BJCxxx | Cjstlst.exe | Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs |
| U | CanonMyPrinter | BJMyPrt.exe | Printer software for Canon Bubblejet printers |
| U | CanonSolutionMenu | CNSLMAIN.exe | Canon's Solution Menu dialog box leads you quickly toward documentation, utilities, and help files |
| ? | CAP3ON | CAP3ONN.EXE | Canon driver, purpose unknown. Is it required in startup? |
| Y | capfasem | capfasem.exe | CA Personal Firewall - part of the CA Internet Security Suite |
| N | Capfax | capfax.exe | PhoneTools fax software |
| U | capfupgrade | capfupgrade.exe | CA Personal Firewall - part of the CA Internet Security Suite |
| U | CAPing | CAPing.exe | Citibank Citianywhere software |
| Y | Capon | Capon.exe | Canon printer driver |
| Y | Capon | Caponn.exe | Canon printer driver |
| X | CaptionMgr32 | crssr.exe | Added by the ZAR.A WORM! |
| X | capture | capture.exe | Added by the THEEF-B TROJAN! |
| N | Capture Express 2000 | capexp.exe | Capture Express - screen capture utility |
| N | Carbonite Backup | CarboniteUI.exe | "Carbonite?s online backup service starts automatically and works quietly and continuously in the background protecting your data" |
| N | Card Monitor | REGCNT09.exe | For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs |
| X | Care20 | Care20.exe | TopMoxie adware |
| U | Care2GTU | Care2GTU.exe | Care2
Green Thumbs-Up (from the Care2 site). Every online purchase helps
environmental causes; tells you how eco-friendly a company really is,
thanks to over 200 company profiles from Coop America. Saves 1 square
foot of rainforest every day you use it. If it works and you like it,
keep it |
| U | carpserv | carpserv.exe | Associated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
| X | CARPserver | CARPserver.exe | Added by the BANKER-AN TROJAN! |
| U | CARPservice | carpserv.exe | Associated with Zoltrix and Conexant modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
| X | cartao | [path to file] | Added by the DLOADER-QD TROJAN! |
| X | cartao | conflicted.exe | Added by the DADOBRA-DV TROJAN! |
| X | cartao | killing.exe | Added by the DLOADER-QN TROJAN! |
| X | CAS Client | casclient.exe | CasinoClient adware |
| X | Cas2Stub | cas2stub.exe | CasinoClient adware |
| U | CasAgnt | CasAgnt.exe | Program by Extended Systems which allows you to sync your Casio PDA with your PC |
| X | Casdvqwa | bmqnzkg.exe | Added by the RANDEX.BE WORM! |
| X | caseyvideo | CaseyVideo.exe | Malware causing p0rn popups |
| X | caseyvideo | caseyvideo[*].exe [* = digit] | Malware causing p0rn popups |
| X | CashBack | cashback.exe | Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch |
| X | CashFiesta | Cashfiesta.exe | CASHFIESTA.A pay-per-surf adware |
| N | Cashsurfers Cashbar Navigator | Cashbar.Exe | Cashsurfers
CashBar Navigator - "The CashBar rotates banner advertisements once per
minute and provides you with access to up to date special offers and
deals" |
| X | CashToolbar | CD_Load.exe | CashToolbar Downloader-MY adware |
| X | CashToolbar | svchost.exe | CashToolbar Downloader-MY adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Casino Royale | jamesbond.exe | Added by the RBOT-FZO WORM! |
| X | Cassandra | [10 to 14 random char]THD.EXE | Added by the KREPPER-AI TROJAN! |
| X | Cassandra | cassandra.exe | SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as a variant of the KREPPER TROJAN! |
| X | CasStub | casstub.exe | Added by the CASS-A TROJAN! |
| X | Catalyst Control Centre | atixvdm.exe | Added by the RBOT.DMW TROJAN! |
| X | catsrv | catsrv.exe | Added by the PAPLOK TROJAN! |
| Y | CAVRID | CAVRID.exe | eTrust? EZ Antivirus Real Time Infection Report from Computer Associates |
| Y | CAVS | CAVS.exe | Cheyenne (now eTrust) antivirus |
| X | CAZNOVAS | CAZNOVAS.exe | Added by the CAZNO TROJAN! |
| X | CBACK.EXE | CBACK.EXE | Added by the PENTA-A TROJAN! |
| U | CBWAttn | CBWAttn.exe | Required for Bitware to answer incoming faxes, can cause sleep mode problems |
| U | CBWHost | CBWHost.exe | Required for Bitware to answer incoming faxes, can cause sleep mode problems |
| ? | CBWUser | CBWDial.exe | Associated with Bitware that integrates fax, voice, pager, and data communications on your desktop |
| X | CC2KUI | comet.exe | Comet Cursor adware |
| X | Ccao | regedit.exe | Probably
a variant of MediaTickets adware. Note - this is not the valid Windows
registry editor which resides in Windows or Winnt and will not figure
in Msconfig/Startup! This version resides in a "mduu" subfolder, which
may change |
| Y | ccApp | ccApp.exe | Part of Norton AntiVirus. Auto-protect and E-mail check will not function without this |
| X | ccApp | [random filename] | Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus |
| X | ccApp | WMADZ.EXE | Added by the RBOT-LJ WORM! |
| X | ccApp | .EXE | Added by the RBOT-LJ WORM! |
| X | ccApp | gcasServ.exe | Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name |
| X | ccAppr | svcrhost.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccAppr | expIorer.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccAppr | outIook.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccAppr | svcshost.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccApps | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | ccApps | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | ccApps | N/A | Added by the KANGAROO-A TROJAN! |
| X | ccApps | ccApps.exe | Added by the KANGAROO-B WORM! |
| X | ccctp | HistoryJMTi.exe | Added by the GANBATE.A WORM! |
| U | CCD Manager | DDS.EXE | Project Labs Century CD manager for their CD/DVD storage device |
| N | Ccdecode | rundll32.exe streamci, StreamingDeviceSetup | Part of the closed caption decdoder/MS VBI codec. Should only run once |
| Y | CCDoctorLogonTesting | ccdoctor.exe | Checks your system to make sure it's configured properly for running IBM Rational ClearCase,
a source code management tool. ClearCase is fairly sophisticated so
there are a lot of system-related things that can cause it grief. If
you run ClearCase you should not disable this as it provides a valuable
service, but technically it isn't required to use the ClearCase product |
| Y | ccenter | CCenter.exe | RAV AntiVirus
|
| Y | CcEvtMgr | ccEvtMgr.exe | Part of Norton AntiVirus 2003. Event
manager for scheduling weekly scans and or automatic virus updates.
Used to start automatically via "ccApp" and was not required as a
seperate entry but a recent update changed this |
| X | ccEvtMrg.exe | ccEvtMrg.exe | Added by the RBOT.GZ WORM! |
| X | ccExecute | bootcfg1.exe | Added by the NEMSI-B VIRUS! |
| X | ccHelp | ccHelp.hta | "Searchq" adware |
| U | ccleaner | ccleaner.exe | CCleaner - removes unused files from your system
|
| X | ccpApps | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | ccpApps | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup!
This file is located in the System folder |
| U | ccProxy | CCPROXY.EXE | Part
of Norton Internet Security, proxy server that is used to support the
parental controls. If you turn parental controls off at user level the
process is not loaded. Reported to cause excessive CPU usage |
| X | ccPrxy.exe | ccPrxy.exe | Added by the SHIPUP-H WORM! |
| Y | CcPxySvc | CCPXYSVC.exe | Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall |
| X | ccreg | explorer.exe | Added by the ZCREW
TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is
located in the Windows or Winnt folder and would not normally appear in
Msconfig/Startup unless you added it manually! This one is located in
the System subfolder |
| Y | CcRegVfy | ccRegVfy.exe | Part of Norton AntiVirus 2003.
"ccRegVfy.exe is responsible for checking the integrity of the NAV
registry entries to make sure that the information has not been changed
by a malicious threat or a hack" |
| X | ccRegVfY | expIorer.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccRegVfY | svcrhost.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccRegVfY | svcshost.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccRegVfY | outIook.exe | Added by the TACTSLAY.A TROJAN! |
| X | ccrss | msdtc.exe | Added by the STAP-C WORM! |
| Y | ccSetMgr | ccSetMgr.exe | Part of Norton AntiVirus 2004. What does it do? |
| X | ccSvcHst.exe | ccSvcHst.exe | Added by the SDBOT-DIW WORM! |
| X | ccsvit.exe | ccsvit.exe | Added by the STARTPA-HP TROJAN! |
| U | cctray | cctray.exe | Part of CA Internet Security Suite |
| X | ccUpdate | ccUpdate.exe | Added by the AGOBOT.YS WORM! |
| U | ccUpdMgr | ccUpdMgr.exe | In Loco Parentis remote surveillance software. Uninstall this software unless you put it there yourself! |
| U | CCUTRAYICON | CCU_TrayIcon.exe | Related to Traybar Launcher from Intel Corporation belonging to Intel(R) Viiv? |
| U | ccWasher | aolwasher.exe | Webroot
Cache & Cookie Washer - cleaning browser tracks, including cache,
cookies, history, mail trash, drop-down address bar, auto-complete
forms and downloaded program files for IE, Netscape and AOL |
| U | CCWC7a | ac.exe | Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
| U | CCWC7I | idxl.exe | Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
| U | CCWC7s | stealth.exe | Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
| Y | CCWinTray | wintmr.exe | System Tray access to Child Control parental control software by Salfield |
| N | CD Storage Master | cdstorager.exe | CD Storage Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection |
| X | cd1 | cd1.exe | Premium rate adult content dialler |
| N | CDANTSRV | CDANTSRV.exe | C-Dilla
License Management software. Used for any program that uses C-dilla
Protection, example: 3D Studio Max 4.x. It loads as a service
automatically but is not needed unless you run said program. Can be
started and stopped manually |
| X | Cdcompat | Cdcompat.exe | Added by the GEMA TROJAN! |
| X | cddrv32 | cddrv32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | CDInterceptor | cdi.exe | CD indexer for measuring the speed of CD players |
| Y | cdloader | cdloader2.exe | From MagicJack
- "A softphone device that allows you to attach an analog phone into
the PC so you can have a traditional-style phone system in your house
without any monthly charge" |
| X | CdnCtr | cdnup.exe | CNNIC Update pest |
| X | CDriver | windrv.exe | Added by the DELF.WG TROJAN! |
| X | CDriver | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe
process which is always located in the System (9x/Me) or System32
(NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| X | Cdrom Controller | cdromcntrl.exe | Added by the BATTRY-A TROJAN! |
| X | cds | cds.exe | Added by the SPYMON TROJAN! |
| X | CDSpeed.exe | CDSpeed.exe | Detected by Kaspersky as the IRCBOT.AEX TROJAN! |
| N | CDTray | CDTray.exe | On HP PCs, this is the small CD icon next to the time |
| U | CeEKEY | CeEKey.exe | Hot Key utility included on Toshiba Satellite laptops |
| U | CeEPOWER | cepmtray.exe | Toshiba's
Power Management Utility - allows the user to setup different profiles
for both AC power and Battery Power on laptops. Contols CPU speed,
Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System
Stand-by and System Hibernate times |
| ? | Ceic | Ceic.exe | ?? |
| X | Cekirge | [path to worm] | Added by the KERGEZ.A WORM! |
| X | center | [random name]32.exe | Added by the BOFRA.A WORM! |
| X | CentralProcessor | taskimgr.exe | Added by the BANCOS.J TROJAN! |
| ? | CEPA | wsot.exe | ?? |
| U | CertificateRegistration | SafeSignCertReg.exe | SafeSign Certificate Registration Utility for Microsoft Crypto applications |
| U | CertReg | certreg.exe | Related to Gemplus Card Reader
|
| Y | CertStoreInit | CertStoreInit | Aladdin eToken authentication and password management |
| N | CesarFTP FTP Server | server.exe | CesarFTPd - FTP server |
| X | cesmain.dll | Rundll32.exe [path] cmail.dll, Rundll32 | CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | CEventMgr | Cell.exe | Added by the BIFROSE-AK TROJAN! |
| N | CFD | CFD.exe | BroadJump
Client Foundation. Broadband troubleshooting software installed by
various companies. Not required and you can remove it via Add/Remove
programs |
| X | CFDStart | WinMuschi.exe | WINMUSCHI dialler |
| X | cfgboost | cfgboot.exe | Added by an unidentified WORM or TROJAN! |
| Y | cfgintpr | cfgintpr.exe | Configuration Interpreter - part of Tiny Personal Firewall V4 |
| X | cfgmgr51 | RunDLL32.EXE cfgmgr51.dll, DllRun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "cfgmgr51.dll" file is located in the Winnt
or Windows folder |
| X | cfgmgr52 | RunDLL32.EXE cfgmgr52.dll, DllRun | BookedSpace parasite. Note that rundll32.exe
is a legitimate Microsoft file used to launch DLL file types and
shouldn't be deleted. The "cfgmgr52.dll" file is located in the Winnt
or Windows folder |
| N | cfgwiz | cfgwiz.exe | Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
| ? | cFosDNT | cFosDNT.exe | cFos DSL Modem driver related. What does it do and is it required? |
| ? | cFosInst_Check | cfosinst.exe | cFos DSL Modem driver related. What does it do and is it required? |
| U | cFosSpeed | cFosSpeed.exe | cFos Software Internet acceleration program related. Note - may be necessary for the software to work properly |
| U | CFSServ.exe | CFSServ.exe | Belongs to Toshiba's configfree utility and searches for Wireless Devices |
| X | cftmon | sfcmonit.exe | Added by a variant of the AGENT.ERG TROJAN! |
| X | cftmon32 | taskmgr*.exe [* = number] | Added by the SOWSAT.C and SOWSAT.J WORMS! |
| X | cfy | cfy.exe | Surfenhance.com SearchForIt adware variant |
| X | CGI Firewall Script | CGIAGENT.EXE | Added by the BROPIA-U WORM! |
| U | CGServer | cgserver.exe | Associated with an Eicon Networks
ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and
blocks incoming or outgoing calls. You need cgard.exe (from Startmenu)
to configure cgserver with rules and telephone numbers. Good against
unwanted dialer programs |
| X | Cgtask Services | cgtask.exe | Added by the LALA.B TROJAN! |
| X | Cgywin | cgywin32.exe | Added by the RBOT-AEI WORM! |
| U | ChamClock | ChamClock.exe | Chameleon Clock - system tray clock replacement |
| X | change-me-now | msgfix1.exe | Added by the SDBOT.ZD WORM! |
| U | ChangeICON | SPMSMON.EXE | Card
reader related program. Note - may cause problems with My Computer
loading at startup. Disabling through MsConfig seems to solve the
problem |
| ? | ChangeLines | chngline.exe | ?? |
| Y | Charter High-Speed Security Suite | fspex.exe | Charter High-Speed Security Suite - security software in collaboration with F-Secure |
| N | Chatango | Chatango.exe | Chatango
- "allows people to be connected in real time through their Web
browsers. Include your Chatango contact link or button when you create
eBay auctions, blogs, personal websites, Friendster profiles, and your
visitors will be able to contact you instantly, without downloading
anything, or registering. Alo use it to send email to your friends,
allowing them to respond to you in real time!." The 'MessageCatcher'
icon in the System Tray notifies you when you get a message. When you
get a message, a little alert pops up, which you can click on and start
chatting immediately |
| U | ChatStat | ChatStat.exe | ChatStat
from ChatStat Technologies, Inc. Provides live chat assistance in up to
16 languages allows your operators to be more productive |
| N | Chcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
| X | Chckup | Netverchk.exe | Covert Sys Exec malware variant |
| X | chcp.exe | chcp.exe | Detected by Kaspersky as the SDBOT.BMH WORM! See here |
| X | che32 | che.ocx.vbs | Added by the ADENU-B VIRUS! |
| X | Cheatle | GigaByte.exe | Added by the SHODI.B VIRUS! |
| X | Check | Check.exe | Added by the VB-DRN WORM! |
| N | Check for One Touch Update | wiseupdt.exe | Checks for updates for Visioneer OneTouch scanners |
| N | Check for TWS Updates | WiseUpdt.exe | Interactive Brokers - check for update to their standalone Java-based trading platform |
| U | Check Messenger | cmesseng.exe | Check
Messenger from Qchex.com - program that helps you manage the activity
of your Qchex account. Qchex appear to be no longer in buisness |
| U | Check&Get | Check&Get.exe | Check&Get
from ActiveURLs. Manages your browser bookmarks and favorites. Monitors
Web sites for changes and updates, captures and highlights the changed
contents |
| N | CheckCustomWorksUpdate | CheckCWupdate.exe | Update checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations" |
| U | CheckDialer | ChkDial.exe | Added by the CheckDialer modem connection monitoring tool |
| X | Checkdisk | mscas.exe | Added by the VAGON-A TROJAN! |
| X | CheckFaultKernel | mswdm.exe | Added by the SMALL-CSK TROJAN! |
| U | CheckIt | ToolBox.exe | CheckIt Toolbox from WinCheckIt Diagnostic Software.
Toolbox automatically backs up critical system files (such as .ini
files and the Windows Registry), and performs a check on various system
parameters at intervals you specify |
| U | CheckIt 86 | CheckIt86.exe | CheckIt 86 popup blocker |
| Y | CheckMsgPlus | MsgPlusH.dll, VerifyInstallation | Added by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info. |
| X | checkrun | elite***32.exe [* = random char] | EliteBar adware
|
| X | checkrun | elitelsj32.exe | Added by the MULTIDR-ER TROJAN! |
| X | CheckScan32 | regload16.exe | Added by the AEBOT.K WORM! |
| ? | checktime | ct.exe | Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required? |
| Y | CheckVCR | IOMagic.exe | Driver for the I/OMagic Personal Video Recorder (DR-PCTV100) |
| X | CheckWinPerf | perfinfo.exe | Added by a variant of the IRCBOT TROJAN! |
| U | CherryKeyMan | KeyMan.exe | Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys |
| X | chiCkie | chiCkie.exe | Added by the CHIKO WORM! |
| U | ChicoSys | webtmr.exe | Child Control parental control software |
| U | ChikkaDefault | ChikkaLauncher.exe | Chikka PC text messanger and IM client |
| X | china11msn | CHINA11MSN.EXE | Added by the ENVID.O WORM! |
| U | ChineseStar | cstar.exe | Chinese language support software |
| U | CHIPDRIVEPinManager | sokscmpn.exe | ChipDrive Smartcard software |
| U | CHIPDRIVESmartcardManager | SCMgr.exe | ChipDrive Smartcard software |
| N | CHKADMIN | CHKADMIN.EXE | Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability" |
| X | ChkDisk | chk_disk.exe | Added by an unidentified WORM or TROJAN! |
| X | chkdrv | iemon.exe | Detected by Symantec as the ADCLICKER TROJAN! |
| X | chkdsk | autoexec.bat | Added by the ANPES WORM! |
| U | ChkMail | ChkMail.exe | Mail-checking program supplied with Acer notebooks |
| U | ChoiceMail | CHOICEMAIL.EXE | ChoiceMail from DigiPortal Software. Block spam with an Email firewall |
| X | Choke | Choke.exe-blahh | Added by the CHOKE WORM! |
| X | chope | runlli32.exe | Added by the QQPASS-U TROJAN! |
| X | chostsv | chostsv.exe | Added by the BANPAES.C TROJAN! |
| U | CHotKey | mhotkey.exe | Enables
special keys on Chicony keyboards. Special combinations include
Internet, E-mail, vol+, vol-, mute, etc. Only required for extended
features |
| U | CHotKey | MK9805.EXE | Enables
special keys on Chicony keyboards. Special combinations include
Internet, E-mail, vol+, vol-, mute, etc. Only required for extended
features |
| U | CHotKey | zHotkey.exe | Enables
special keys on Chicony keyboards. Special combinations include
Internet, E-mail, vol , vol-, mute, etc. Only required for extended
features |
| N | Christmas Music Player | TTEST6.EXE | "Christmas Music Player brings the music of the Christmas Holiday to your desktop" |
| ? | ChromeMark | keysh.exe | Related to this. Don't know what keysh.exe does though and if it's required |
| ? | ChronitelInitTV | CHTVINIT.EXE | ?? |
| U | chrono | chrono.exe | Chronograph
is a simple utility that synchronizes internal computer clock to the
atomic time. Chronograph automatically maintains correct time using
atomic clock servers of the National Institute of Standards and
Technology (NIST)." Shows seconds and shows the date without having to
hover the mouse. Shows a calendar when hovered over |
| X | ci1gnt | ci1gnt.exe | Detected by Kaspersky as the AGENT.DHU TROJAN! |
| X | CiaBackdoor | msldr.com | Added by a VIRUS! |
| X | cihost.exe | cihost.exe | Added by the LINST TROJAN! |
| N | CIJxP2PSERVER | CIJxP2PS.EXE | Compaq
printer utility which is required in order to make the printer work
correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7 |
| Y | Cingular Communication Manager | CingularCCM.exe | Cingular Communication Manager
- now taken over by AT&T. "provides a robust set of wireless
communication tools for businesses and individuals. With wireless
access to email, the Internet, business applications and corporate
intranets, mobile users can be more productive while they're out of the
office" |
| X | Cinnabd Prompt32 | CmdPrompt32.pif | Added by the ASSIRAL-B WORM! |
| N | CIO | che7e1~1.exe | ChatItOut webcam chat program |
| X | CirebonPunya | XXrocks.exe | Added by the BHARAT.A WORM! |
| U | Cisco Systems VPN Client | ipsecdialer.exe | Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
| N | Cisco Systems VPN Client | vpngui.exe | Sets up IPSec communications for Cisco's VPN Client |
| N | CISrvr Program | CISRVR.EXE | Related to internet setup on Compaq PC's |
| X | Cissi | Cissi.exe | Added by the CISSI.A WORM! |
| U | CitiUCS | CitiUCS.exe | Citibank Virtual Account Numbers - "With this free service for Citi cardmembers, you never have to give out your real credit card number online" |
| N | CitiVAN | CitiVAN.exe | Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again |
| X | cjb | cjb.exe | Added by and unidentified WORM or TROJAN! See here |
| X | CJET | CJet.exe | Added by the Adware.FFToolBar adware toolbar |
| Y | Cjstcom | Cjstcom.exe | Canon printer BJ status language monitor |
| Y | ClamWin | ClamTray.exe | ClamWin antivirus |
| X | Classes | int1.exe | "Switch" premium rate adult content dialler variant |
| X | Classes | intl.exe | "Switch" premium rate adult content dialler variant |
| X | Classes | run_21.exe | "Switch" premium rate adult content dialler variant |
| X | Classes | srv.exe | "Switch" premium rate adult content dialler variant |
| X | Classes | srv2.exe | "Switch" premium rate adult content dialler variant |
| X | Classes | MSTAR2.EXE | "Switch" premium rate adult content dialler variant |
| X | Classes | mstart.exe | "Switch" premium rate adult content dialler variant |
| X | clcbt.exe | clcbt.exe | Added by the AGENT.CBA TROJAN! |
| X | clcl3 | clcl3.exe | Added by the AGENT.ES TROJAN! |
| X | clcl7 | clcl7.exe | Added by a variant of the Covert Sys Exec TROJAN! |
| U | CLCLSet | CLCL.exe | CLCL clipboard caching utility |
| N | Clean Access Agent | CCAAgent.exe | Cisco Clean Access Agent from Cisco Systems, Inc |
| X | Clean up | service.exe | Added by the AGENT-FPY TROJAN! |
| ? | CleanEasyImg | cleanall.exe | ?? |
| ? | CleanRegPath | CleanReg.exe | Apparently Annex A ADSL modem related. What does it do and is it required? |
| U | CleanSweep Smart Sweep- Internet Sweep | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
| N | CleanSweep Useage Watch | CSUSEM32.EXE | Quarterdeck/Norton
CleanSweep component - tracks how often you use files and alerts you to
files that have not been used for a specified period of time |
| U | CleanTemp | CLEANT~1.EXEB | CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
| U | CleanTemp | CleanTemp.exe | CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
| N | Cleanup | ONICTASK.EXE | Internet Cleanup from Allume Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet |
| Y | CleanUp | mcappins.exe | Used
by McAfee Virusscan to perform product updates. When updates are
available the program will download and install them automatically.
Recommended to leave enabled |
| ? | CleanupProgram | cleanup.exe | In a C:Sonysys folder - Sony Vaio related? |
| X | clean_service | clean_service.cmd | Added by the REFAZ WORM! |
| U | CleverKeys | CK.exe | CleverKeys
- "is free software that provides instant access to definitions at
Dictionary.com, synonyms at Thesaurus.com, facts at Reference.com and
more ? from almost all Windows programs, including word processors, Web
browsers and most e-mail programs" |
| X | clfmon | clfmon.exe | Added by the TACTSLAY.E TROJAN! |
| X | clfmon | nvsvca32.exe | Added by the TACTSLAY.E TROJAN! |
| X | clfmon.exe | clfmon.exe | Added by the AGENT-BJ TROJAN! |
| N | Click Radio Tuner | clickr~1.exe | ClickRadio - subscription service playing radio music via the internet |
| N | Click Tray Calendar | ClickT~1.EXE | ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc |
| N | ClickMe | ClickMe.exe | ClickM "JOKE" program |
| U | Clickoff | Clickoff.exe | Clickoff automatically dismisses annoying dialog boxes |
| X | ClickTheButton | CTB.EXE | ClickTheButton Downloader-MY adware |
| X | ClickTheButton | csrss.exe | ClickTheButton Downloader-MY adware! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup! |
| X | ClickTheButton | MSCStat.exe | ClickTheButton Downloader-MY adware |
| X | CLICONFG | CLICONFG.EXE | Added by the OPASERV.T WORM! |
| U | Client Access API Daemon | cwbappcd.exe | IBM iSeries Client Access, see here |
| N | Client Access Check Version | cwbckver.exe | Part of IBM's iSeries
(nee As/400) Client Access - communications suite that allows desktop,
browser and wireless access to iSeries servers. Checks the software
version on your PC to that of the iSeries it is connected to. Not
required - and can be turned off in the Client Access properties. It's
a waste of resources |
| ? | Client Access Express Welcome | cwbwlwiz.exe | Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
| N | Client Access Help Update | cwbinhlp.exe | Client Access Help Registry Update Function - part of IBM's iSeries
(nee As/400) Client Access - communications suite that allows desktop,
browser and wireless access to iSeries servers. It only updates the
help files on your PC to match the level of the attached iSeries |
| N | Client Access Service | CwbSvStr.Exe | Part of IBM's iSeries
(nee As/400) Client Access - communications suite that allows desktop,
browser and wireless access to iSeries servers. Useful if you are going
to access the iSeries through Windows Explorer to move files back and
forth between Windows folders and iSeries folders. This is a tool that
is only used by Client Access administrators (usually) so it is not
required - a waste of resources |
| U | Client Access Taskbar | cwbuitsk.exe | IBM iSeries Client Access taskbar, see here |
| X | Client Agent | ipxwping.exe | Added by the PPDOOR-N TROJAN! |
| X | Client Agent | photes.exe | Added by the PPDOOR-P TROJAN! |
| X | Client Agent | [path to file] | Added by the PPDOOR-J TROJAN! |
| ? | Client agent for ARCserve | W95AGENT.EXE | Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? |
| X | Client for Microsoft Networks | msclient32.exe | Added by the SDBOT-BXQ WORM! |
| X | Client Server Control Process | [path to trojan] | Added by the AGENT-HR TROJAN! |
| X | Client Server Run Time Proccess | csrsrv.exe | Added by a variant of the SDBOT WORM! |
| X | Client Server Runtime | [path to worm] | Added by the POEBOT-KR WORM! |
| X | Client Server Runtime Process | csrsss.exe | Added by the SDBOT-LD WORM! |
| X | Client Server Runtime Process | csrs.exe | Added by the LINKBOT.M WORM! |
| X | Client Server Runtime Process | smmss.exe | Backdoor TROJAN! Possible SDBOT-GEN variant |
| X | Client Update | wup.exe | Added by a variant of the OPANKI-A WORM! |
| X | ClientMan1 | mscman.exe | ClientMan parasite variant
|
| N | Clik Status Monitor | toolsclickstat.exe | Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed |
| X | clipboard.exe | clipboard.exe | Added by an unidentified WORM or TROJAN! |
| N | Clipbook Service | Clipsrv.exe | Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
| N | ClipMate5x | ClipMt5x.exe | Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
| N | Clipmate6 | CLIPMT60.EXE | Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
| N | ClipMate7 | ClipMate.exe | Clip Mate 7 by Thornsoft - utility that allows you to store more than one item in the clipboard
|
| N | Clipomatic | Clipomatic.exe | Mike Lin's Clipomatic
is a clipboard cache program - it remembers what was copied to the
clipboard even after new data is copied, and allows you to retrieve the
old data |
| N | Clipsrv | Clipsrv.exe | Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
| X | ClipSrv | clipserv.exe | Added by the SDBOT-AAV and SDBOT-AFE WORMS! |
| X | ClipSrv | CLIPBRD3D.EXE | Added by the MOFEI-D WORM! |
| N | ClipTrak | ClipTrak.exe | ClipTrak - clipboard extender |
| N | ClipTrakker | ClipTrakker.exe | Cliptrakker - clipboard extender |
| N | CLISTART | CLIStart.exe | Puts the ATI Catalyst? Control Center Icon/Shortcut on the System Tray - available via Start -> Programs |
| X | clkhost | [path to trojan] | Added by the WIXUD-B TROJAN! |
| U | CLMFrontPanel | clmpanel.exe | System
tray status/display/configuration utility for a number of modems. Can
be disabled by right-clicking on the tray icon. If disabled, connection
status is lost |
| ? | clnwall | rundll.exe setupx.dll, InstallHinfSection ..delwall.inf | ?? |
| X | clock | [various filenames] | LiveChat
Adware - known file names include: mssetup.exe, kstatus.exe,
spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe |
| X | Clock Manager | amsngr.exe | Added by the SDBOT-XM TROJAN! |
| X | ClockSync | Sync.exe | ClockSync
- synchronizes your system clock with an internet time server. It's by
WhenU, the makers of the Save Now spyware, and they're usually seen in
tandem, so it's advised to replace it with one of may spyware free
alternatives available |
| U | ClockWise | CLOCKWISE.EXE | ClockWise
- produced by R J Software - a time utility. It is a schedueler not
only for dates, but you can choose it to run programs at any time. It
also updates the time by connecting to an atomic clock server. This is
a spyware-free alternative to ClockSync |
| U | ClocX | ClocX.exe | ClocX - places a clock on the desktop that can be moved and then changed into a calendar plus you can set alarms etc? |
| U | CloneCD | CloneCDTray.exe | System tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
| U | CloneCDElbyCDFL | ElbyCheck.exe | From Elaborate Bytes
who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs.
Note - under Win2K removing this from startup causes the CD drive in
the computer to not be recognized in the OS and after rechecking it
prompts that the driver has been corrupted and asks you to restart the
computer to fix it |
| U | CloneCDTray | CloneCDTray.exe | System tray for the now discontinued CloneCD. The only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
| ? | Clotusorgreg0 | prtStart.exe [path] Orgprt.exe | IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does? |
| X | Clre | mmdc.exe | Added by the PURSCAN-AI TROJAN! |
| X | ClrSchLoader | [path to file] | ClearSearch adware |
| X | CLSID | com.exe | Adult content dialler |
| X | CLSID | dll.exe | Adult content dialler |
| X | CLSID | msgplus.exe | Adult content dialler |
| X | CLSID | plugin.exe | Adult content dialler |
| X | CLSID | sed.exe | Adult content dialler |
| X | CLSID | msgplus.exe | Premium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension
|
| X | CLSRSS | LSACS.EXE | Added by the SILLYFDC-X WORM! |
| ? | CM-SmWizard | SmWizard.exe | SmartWizard
MFC Application - associated with C-Media who produce audio chipsets
commonly used for on-board sound on motherboards. What does it do and is it required? |
| U | cma | cma.exe | DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center" |
| X | CMAPP | cmappclient.exe | CasClient adware - also detected as the CMAPP TROJAN! |
| N | Cmaudio | Rundll32 cmicnfg.cpl, CMICtrlWnd | System
tray control panel for C-Media based soundcards - often included on
popular motherboards with in-built audio. Available via Start ->
Settings -> Control Panel |
| X | Cmd | cmd32.exe | Added by the TANKED WORM! |
| X | cmd32 | configs.exe | Hijacker, also detected as the QURL-2 TROJAN! |
| X | cmd64 | cmd64.exe | CoolWebSearch Search X parasite variant |
| X | cmdbcs | cmdbcs.exe | Added by the LINEAG-GKW TROJAN! |
| X | cmdcon | cmdcon.exe | Added by the CRYPTER.A TROJAN! |
| X | cmds | vtsqn.dll | Added by a variant of the VUNDO TROJAN! |
| X | CmdShell.exe | CmdShell.exe | Added by the BCKDR-QHY TROJAN! |
| X | CME | cme.exe | Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | CmeSYS | CMEsys.exe | Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | CmeUPD | CMEupd.exe | Part of Gator advertising spyware - see here for removal instructions. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | CMFibula | CMFibula.exe | CASClient adware |
| N | CmFlywaveName | CmFlywav.exe | Driver for Linksys Wireless-G Music Bridge
|
| ? | CMGrdian | CMGrdian.exe | One of the McAfee shared components. What does it do and is it required? |
| X | CMMan | CMMan.exe | Added by the CMAPP TROJAN! |
| X | Cmmon32Sys | cmmon32.exe | Added by the SMALL.CL TROJAN! |
| X | cmonitor | startupmon.exe | SystemDoctor misleading security software - not recommended, see here |
| U | CmPCIaudio | RunDll32 CMICNFG3.CPL, CMICtrlWnd | Registers the Control Panel applet for a C-Media PCI sound card |
| U | CMPDPSRV | CMPDPSRV.EXE | Printer
Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.).
"Printer Driver Plus seamlessly integrates all the necessary components
of a printer driver, plus more". Installed with some Compaq and Lexmark
printers |
| X | Cmpnt | Devices2.exe | Added by the TOMPAI-D TROJAN! |
| X | Cmpnt | mainsv.exe | Added by the TOMPAI-C TROJAN! |
| X | cmrss | cmrss.exe | Added by the DELF.DU TROJAN! |
| X | cmrss | crmss.exe | Added by the DLOADER-EK TROJAN! |
| X | cmrss | [path to trojan] | Added by the DLOADER-QQ TROJAN! |
| X | cmrst | cmrst.exe | Added by the BANCOS.S TROJAN! |
| X | cmrst | cmrst.scr | Added by the DLOADER-FP TROJAN! |
| X | cms | iserver.exe | Added by the DLOADER-WK TROJAN! |
| U | CMSETTINGS | ctmn.exe | Part of NetNanny Chat Monitor |
| X | cmsound | vcpdll.exe | Added by the TCXMEDI-D downloader TROJAN! |
| X | cmsound | vcsystem.exe | Added by the TCXMEDI-D downloader TROJAN! |
| X | cmss | system.exe | Added by a variant of the RBOT WORM! |
| X | cmssapp | iexplore_.exe | Added by the BANCBAN-CQ TROJAN! |
| X | cmssapp | iexplore.exe | Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe
process which is always located in the Program FilesInternet Explorer
folder and should not normally figure in Msconfig/Startup! This file is
located in the Windows or Winnt folder |
| X | cmssSystemProcess | csmss.exe | Added by the AGENT-CO TROJAN!
|
| X | cmssSystemProcess | mcsmss.exe | Added by a variant of the AGENT.EI TROJAN! |
| X | cmssSystemProcess | csms.exe | Added by the AGENT-Y TROJAN! |
| X | CMSystem | CMSystem.exe | CASClient adware |
| X | cmt101 | cmt101.exe | Added by a variant of the CRYPTER.C TROJAN! |
| ? | CmUCRRun | CmUCReye.exe | Related to Medion Display Information. What does it do and is it required? |
| X | cmx32 | cmx32.exe | Added by the GEMA.D TROJAN! |
| X | Cn323 | cnfrm33.exe | Added by the MIMAIL.G WORM! |
| X | Cn911 | ODBCJET.exe | Added by the BIFROSE-PR TROJAN! |
| X | CNBABE | CNBABE.EXE | Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing |
| N | cnet | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
| Y | cnfgCav | CMain.exe | Part of Comodo Antivirus |
| X | Cnfrm32 | |