Last update :- 21st March, 2005
7448 items listed
This page presents a searchable, comprehensive list of the programs you may find that run when you switch on your PC as typically identified by MSCONFIG or the registry "Run" keys - and whether you need them.
This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.
To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.
There are viruses and other pests that can add any number of different entries to the startups. They make additional entries under the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\ Run and RunOnce keys, allowing them to run at startup. In all cases below, %system% is a variable - by default this is C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP):
Check CastleCops for information about these types of program. They have very active forums. You may also want to try SpywareInfo for their forums and a list of startup program managers
o-----------------------------o
This search works with IE4+, NS4 and Mozilla/NS7+ but not NS6. Alternatively use your browsers search facility - Ctrl+F for IE users.
Key:
"Y" - Normally leave to run at start-up
"N" - Not required - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
"?" - Unknown
Name/Startup Item | Command | Comments | |
X | system32.exe | Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field | |
Y | !1_pgaccount | pgaccount.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
Y | !1_ProcessGuard_Startup | procguard.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
N | !NoLoad | winrecon.exe | WinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
? | $EnterNet | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
X | $WindowsRegKey%update | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
N | %cmpmixtitle% | %cmpmixstr% | Possibly related to C-Media Mixer Control panel? |
? | %FP%012-L2TP fts.exe | fts.exe | 012.Net ISP software - what does it do and is it required? |
? | %FP%012-L2TP FWPortal.exe | FWPortal.exe | 012.Net ISP software - what does it do and is it required? |
? | %FP%1776 Internet fts.exe | fts.exe | 1776 Internet ISP software - what does it do and is it required? |
? | %FP%1776 Internet FWPortal.exe | FWPortal.exe | 1776 Internet ISP software - what does it do and is it required? |
? | %FP%Barak013 fts.exe | fts.exe | Barak013 ISP software - what does it do and is it required? |
? | %FP%Barak013 FWPortal.exe | FWPortal.exe | Barak013 ISP software - what does it do and is it required? |
? | %FP%Friendly fts.exe | fts.exe | Friendly ISP software - what does it do and is it required? |
X | (*)API Machine | winSOCKS.exe | Homepage hijacker, see here (* = any digit) |
X | (*)Run | win32API.exe | Homepage hijacker, see here (* = any digit) |
X | (Default) | media_driver.exe | Added by the TUPEG VIRUS! |
X | (Default) | Shania.vbs | Added by the SHANIA TROJAN! |
X | (Default) | NOTEPAD.exe | Added by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor |
X | (default) | [random filename].exe | Added by the BLACKMAL WORM! |
X | (default) | twunk_32.exe | Added by the BLACKMAL.C WORM! |
X | (default) | winhelp.exe | Added by the BLACKMAL.C WORM! |
X | (L4r1$$4) (4nt1) (V1ruz) | SP00Lsv32.pif | Added by the ASSIRAL.B WORM! |
X | *JanisRuckenbrodII | janis.com | Added by the POPS WORM! |
Y | *StateMgr | statemgr.exe | Windows ME default for System Restore. Do NOT disable! |
X | *windows update | wrauclt.exe | Added by the RBOT-QU WORM! |
X | *windows update | wuanclt.exe | Added by the RBOT-PG WORM! |
X | *windows update | wuaucrlt.exe | Added by the SPYBOT.HUR WORM! |
X | *windows update | wuraclt.exe | Added by the RBOT-PO WORM! |
X | *windows update | wurauclt.exe | Added by the RBOT-SY WORM! |
X | *windows update | wsctl.exe | Added by the SPYBOT.PR WORM! |
X | *WinLogon | [trojan path] ren time:[random number] | Added by the VUNDO TROJAN! |
X | ,main drive Loader | wininfo.exe | Suspected malware as it appears in 3 different registry locations - see here |
X | .mscdr | lassa.exe | Added by the WEBUS.C TROJAN! |
X | .mscdr | lsvchost.exe | Added by the WEBUS.D TROJAN! |
X | .mssecure | mssecure.exe | Added by the DDOS_BOXED.X TROJAN! |
? | .NET config | sysmon32.exe | ?? |
X | .norton | rchost.exe | Added by a variant of the BOXED-A TROJAN! |
X | .Prog | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | .Prog | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
X | .TEXTCONV | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | .TEXTCONV | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
X | .WMAudio | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | .WMAudio | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
N | /l:eng | N/A | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
X | 000hpdllhos | hpdllhost.exe | LZIO.com adware downloader |
U | 000StTHK | 000StTHK.exe | Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...) |
U | 00THotkey | 00THotKey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
U | 0190 Warner | WARN0190.EXE | Anti-dialer program (Germany) |
U | 0900 Warner | WARN0900.EXE | Anti-dialer program (Germany) |
X | 123456 | rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl | Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
U | 12Ghosts Popup-Killer | 12popup.exe | 12Ghosts Popup-Killer |
? | 17779Proj2002 | N/A | ?? |
X | 180adsolution | 180adsolution.exe | 180Solutions/N-Case adware variant |
X | 180ax | 180ax.exe | 180Solutions/N-Case adware variant |
N | 1: | hpdrv.exe | HP utility for monitoring when and how many recoveries have been done |
N | 1A:MacVisionTrayMonitor | TrayMonitor.exe | Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) |
Y | 1A:Stardock MCP | mcpserver.exe | Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications |
Y | 1A:Stardock TrayMonitor | TrayServer.exe | For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX |
? | 1CmailS | NETMAIL.EXE | ?? |
X | 1on1 | 1on1.exe | Adult content dialler |
U | 1Srv32 | SpyAgent4.exe | SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
U | 1Win32Cfg | SpyBuddy.exe | SpyBuddy monitoring software |
U | 1Win32Cfg | Keyloggerpro.exe | KeyloggerPro - monitoring software |
X | 1WinCfg32 | WebMailSpy.exe | WebMailSpy spyware |
X | 2020Downloader | mssvr.exe | 2020Search Toolbar related. Reported to be auto-installed |
X | 2thousandbuck | [path to file] | Added by the RANKY.L TROJAN! |
U | 2wSysTray | 2portalmon.exe | 2Wire Homeportal user interface |
X | 32-bit Thunking service | thunk32.exe | Added by the DERDERO.A WORM! |
? | 39ELTFH25Z8SKF | Ezg1q5.exe | Seems to be associated with software by Resplendence SP ? |
Y | 3c1807pd | 3cmlink.exe 3cpipe-3c1807pd | 3Com WinModem driver. See here for more WinModem information |
Y | 3capplnk | 3capplnk.exe | US Robotics Modem driver |
N | 3cdminic | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
? | 3CM Link | 3cmcnkw.exe | ?? |
Y | 3Cmlink | 3CmlinkW.exe | For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information |
N | 3ComDMIAgent | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
Y | 3cpipe-USRpdA | USRmlnkA.exe | Modem driver files from US Robotics |
X | 3D Text | 3D Text.scr | Added by the JERMY.A WORM! |
U | 3Deep Control Panel | 3DeepCTL.EXE | From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games |
X | 3Dfx Acc | GFXACC.EXE | Added by the GIBE WORM! |
N | 3dfx Task Manager | 3dfxMan.exe | System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
Y | 3dfx Tools | 3dfxCmn.dll | Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards |
Y | 3dfxv2ps.dll | 3dfxv2ps.dll | Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
? | 3Dlabs Taskbar Display Manager | 3DLman.exe | 3DLabs graphics driver related. System Tray access to display settings? |
U | 3DLabsHelperDemon | 3dldemon.exe | Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled |
U | 3qdctl.exe | 3qdctl.exe | Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ |
Y | 3ware 3DM | 3dm.exe | Monitors status of the disk array on 3ware IDE RAID controllers |
X | 4wd!!! | Natal!.pif | Added by the OPASERV.AI WORM! |
X | 5-1-61-96 | members-area.exe | Adult content dialler |
X | 5-2-46-112 | 5-2-46-112.exe | Adult content pop-up dialler. Removal instructions here |
X | 666 | Ska.exe | Added by the PIPES TROJAN! |
X | 9xHtProtect | AVprotect9x.exe | Added by the NETSKY.M WORM! |
X | ;Rundll | [filename] | Added by the PWSLEGMIR.E TROJAN! |
X | @ | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
N | @Hoc Toolbar | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info |
N | @loha | reminder.exe | Registration reminder for @loha@home E-mail utility |
X | @tour_ww | @tour_ww[1].exe | Adult content dialler |
X | a | a.exe | Commercials file that registers itself in the system registry and redirects IE to a certain commercial website |
U | a-squared | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a˛ 'Background Guard' real time protection feature |
Y | a-winpoet-service | winpppoverethernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
U | A1000 Settings Utility | cpqa1000.exe | Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features |
U | A4Proxy | A4Proxy.exe | Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites |
? | AAACLEAN | AAACLEAN.INF | ?? |
? | AAAKeyboard | ?? | ?? |
N | AAATraySaver | TraySaver.exe | System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray |
U | AAK | aak.exe | Advanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere" |
X | Aaou | amee.exe | PurityScan/Clickspring adware |
? | ab EazyScheduler | ezsched.exe | ?? |
N | ABBYY Community Agent | CAGENT.EXE | Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software |
X | ABC | keylogger.exe | Monitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by SpyCop in their FAQ |
U | ABIT uGuru | uGuru.exe | Provides quick access to several Abit motherboard utilities - such as monitoring cpu temperature, fan speeds, overclocking, flashing of BIOS |
U | Absolute Shield | dseraser.exe | Absolute Shield/Evidence Eliminator - iternet history eraser |
U | Absolute StartUp monitor | ASMon.exe | Absolute Startup - startup monitor from F-Group Software |
X | ABsr | absr.exe | Added by the AUTOUPDER TROJAN! |
X | absr | mwsvm.exe | SeekSeek search hijacker related - as seen here |
X | abtu | mp3serch.exe | Loads the executable for Lop.com. mp3serch.exe is the final version |
X | abtu | lopsearch.exe | Loads the executable for Lop.com. lopsearch.exe is the beta version |
U | AbyssWebServer | abyssws.exe | Abyss web server |
Y | AcBtnMgr_Xxx | AcBtnMgr_Xxx.exe | Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation |
U | acc | acc.exe | Advanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem" |
X | ACCDEFRAGINFO | [path to worm] | Added by the DARBY-O WORM! |
U | Accelerate | accelerate.exe | Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection |
N | Access Ramp Monitor | armon32.exe | Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again |
N | AccessRamp Monitor01 | ARMon32a.exe | From a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service." |
N | AccessRampLAN01 | ARUpld32.exe | Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003 |
U | AcctMgr | AcctMgr.exe | Norton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities—all from the safety of your own PC |
N | AccuWeather.com® Desktop | ?? | Desktop weather from AccuWeather.com |
? | Ace bows | Ace bows.exe | ?? |
N | AceGain LiveUpdate | LiveUpdate.exe | AceGain_LiveUpdate. "AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences." |
U | AcerNotebookManager | almxptray.exe | System Tray access on some Acer Notebooks to give faster access to system settings |
U | AcerPowerkey | Powerkey.exe | PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3 |
N | Acme.PCHButton | pchbutton.exe | Used by HP Instant Support |
Y | ACMonitor_Xxx | ACMonitor_Xxx.exe | Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation |
X | acocash | fastdown.exe | Adult content dialler |
X | acocash | fastdown.exe | Adult content dialler |
U | Acombo3dmouse | Acombo3d.exe | Mouse driver - required if you use non-standard Windows driver features |
X | Aconti | aconti.exe | Adult content dialler |
U | acoustic | acoustic.exe | Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained |
N | acpart | agpart11.exe | Program for finding trucks on-line |
U | Acrobat Assistant *.* | ACROTRAY.EXE | Used to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation. *.* represents the version |
U | Acronis Scheduler2 Service | schedhlp.exe | Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images |
N | Acronis TrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
N | AcronisTrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
N | Acronis True Image Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
N | Action Manager 32 | am32.exe | Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs |
? | ActionAgent | actionagent.exe | "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required? |
N | Activation | Activation.exe | Part of Microsoft Money |
U | Activboard | MMKeybd.exe | Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys |
U | Active shield | Activeshield.exe | Active Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses" |
X | ActiveDesktop | systray32.exe | Added by the DABOOM WORM! |
X | ACTIVEDS | ACTIVEDS.EXE | Added by the OPASERV.T WORM! |
N | ActiveEyes | ActiveEyes.exe | ActiveEyes from TFI Technology |
U | ActiveMenu | ActiveMenu.exe | WildTangent games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
U | ActivePlus | activeplus.exe | Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) |
Y | ActiveShield | MCVSSHLD.EXE | McAfee VirusScan On-line. See also the McAgentExe entry |
N | ActivSurf | backweb*****.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates |
U | ActMaker | ActMak25.exe | "ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer" |
U | ACU | ACU.exe | Atheros wireless Client Utility For HP Compaq |
U | Ad Blocker | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads |
U | Ad Blocker Pro | Ad Blocker Pro.exe | Ad Away popup and banner remover |
U | Ad Muncher | AdMunch.exe | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
? | Ad Online Guide | adonlineguide.exe | ?? |
N | Ad-aware | Ad-aware.exe | Ad-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs |
U | Ad-Muncher | ADMUNCH.EXE | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
U | Ad-watch | Ad-watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
U | AD2KClient | AD2KClient.exe | Executable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk |
N | Adaptec DirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
N | AdaptecDirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
N | Adaware Bootup | ad-aware.exe | Ad-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs |
X | Adaware lptt01 | adaware.exe | Variant of the RapidBlaster parasite (in a "Adaware" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware |
X | Adaware ml097e | adaware.exe | Variant of the RapidBlaster parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | AddClass | AddClass.exe | CoolWebSearch parasite variant |
X | AddClass | [Installation_Path] | Added by the Startpage.F hijacker |
U | AdDelete | AdDelete.exe | Banner advertisment blocker |
X | AdDestroyer | AdDestroyer.exe | Like VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code |
? | ADG | ADG.exe | SoundBlaster Audigy related? |
N | ADGJdet | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
Y | Adiras | Adiras.exe | ADSL USB modem related |
X | ADM Library Loader | admlib32.exe | Added by a variant of the SDBOT TROJAN! |
X | Admanager Controller | AdManCtl.exe | Adware, probably a Windupdates variant |
X | Admilli Service | AdmilliServ.exe | Windupdates adware variant |
X | Adobe | Adobe.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Adobe | sysconfig.exe | Added by an unidentified WORM or TROJAN! |
X | adobe | gam.exe | Added by an unidentified WORM or TROJAN! |
X | Adobe | sysbat32.exe | Added by the LOWZONES.T TROJAN! |
X | Adobe Filter Platform | afilterplatform.exe | Added by the RBOT-OP WORM! |
U | Adobe Gamma Loader | Adobe Gamma Loader.exe | Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine |
N | Adobe Reader Speed Launch | reader_sl.exe | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
X | AdobeA | adobes.exe | Added by the FLOOD.BA TROJAN! |
X | AdobeFonts | fonts.hta | Browser hijacker - redirecting to Hugesearch.net |
N | AdobeVersionCue | VersionCueTray.exe | "An exclusive feature of the Adobe® Creative Suite, Version Cue™ helps you find files fast, track multiple versions of your files, and share your files for creative collaboration" |
X | Adope File Manager | lsasv.exe | Added by an unidentified WORM or TROJAN! |
X | adp | adp.exe | Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc |
N | ADQuickAccess | Adtray.exe | After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95 |
X | AdRoarUpdate | ARUpdate.exe | AdRoar adware updater |
X | AdRotator.Application | [path to csrss.exe] | Added by the SMALL-AQ TROJAN! |
U | ADService | ADService.exe | Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk |
U | AdsGone | Adsgone.exe | AdsGone - pop-up stopper |
N | ADSL Diagnostic Tools | mapiicon.exe | System tray access to ADSL modem diagnostic tools. Available via Start -> Programs |
Y | AdslTaskBar | rundll32.exe stmctrl.dll, TaskBar | ISP software, initializes DSL modem |
? | ADSL_A2 | A2Installed | Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required? |
Y | ADSS | ADSS.exe | ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied |
X | adstartup | automove.exe | Adlogix adware variant |
X | adstartup | Adstartup.exe | Adlogix adware variant |
X | AdStatus Service | AdStatServ.exe | Unidentified adware |
U | AdSubtract | adsub.exe | AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs |
X | Adtools Service | AdTools.exe | Windupdates adware variant |
X | AdultX | AdultX.exe | Adult content dialler and hijacker |
X | Adult_Chat | Adult_Chat.exe | Adult content dialler |
X | Adult_Chat1 | Adult_Chat1.exe | Adult content dialler |
U | ADUserMon | ADUserMon.exe | Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk |
X | Advanced Internet Protocol | cerf.exe | Added by a variant of the SPYBOT WORM! |
N | Advanced Tools Check | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget |
X | Advapi | Advapi.exe | Added by the NETDEVIL.12 WORM! |
N | ADVCHK | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget |
U | Advertising Killer | Akiller.exe | AKiller - pop-up stopper |
X | advmon32 | advmon32.exe | Added by a variant of the CRYPTER.C TROJAN! |
U | Adware Agent | adware agent.exe | Adware Agent popup blocker |
N | Adware Spy | AdwareSpy.exe | Bogus adware remover, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
? | Aeiwlsta.exe | Aeiwlsta.exe | IBM High Rate Wireless LAN Adapter driver. Is it required? |
N | AELaunch | AELaunch.exe | Audio Applications Launcher for the Philips Acoustic Edge soundcard |
? | AeXSWDUsr | AeXSWDUsr.exe | Altiris Express NS Client Manager software. Is it required? |
U | AEZBProc | aptezbp.exe | IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions |
U | AFAFilter | windefault.exe | AFAFilter - internet filter software |
N | Agent | Agent.exe | Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs |
? | Agente | Remupd.exe | Part of Panda Antivirus Titanium. Is this an update reminder (guess because of the name), virus definition update reminder or something similar? |
U | AgfaCLnk | AgfaCLnk.exe | For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive |
X | agp | agp32.exe | Added by the GAOBOT.SY WORM! |
Y | AGRSMMSG | AGRSMMSG.exe | IBM AMR modem driver |
N | AGSatellite | AGSatellite.exe | Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs |
U | ahfp | ahfp.exe | Advanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either" |
U | ahfprog | ahfp.exe | Advanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either" |
U | AHNSD | AhnSD.exe | AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis |
? | AHNUE | AHNUE.exe | ?? |
N | AHQInit | ahqinit.exe | Part of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required |
X | Ahst | iebs.exe | PurityScan/Clickspring adware |
X | AHU | [path to worm] | Added by the ANACON-B WORM! |
X | Aica | tuaa.exe | PurityScan/Clickspring adware |
X | Aida | ttuh.exe | PurityScan/Clickspring adware |
U | aiepk | aiepk2.exe | Another IE Popup Killer - pop-up stopper |
N | AIM | aim.exe | AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs |
X | AIM reminder | AIM reminder.exe | Added by the BUDDY TROJAN! |
X | aimaol lptt01 | aimaol.exe | Variant of the RapidBlaster parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | aimaol ml097e | aimaol.exe | Variant of the RapidBlaster parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
N | AimingClick | AimingClick.exe | AimingClick from AimingTech. Web searching tool. Available via Start -> Programs |
N | AIMster | ?? | Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs |
N | AIMWDInstall | AIMWDInstall.exe | Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
Y | Aiptek Graphics Tablet (USB) | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) |
X | AKEYNAME | WinServ.exe | Added by the EVILBOT.C TROJAN! |
U | AKiller | akiller.exe | BuyPin Advertising Killer - popup killer |
X | ala.exe | ala.exe | Access Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer |
U | Alarm Manager | Alarm.app.exe | Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop |
? | AlarmWatcher | AlarmWatcher.exe | Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required? |
N | Album Fast Start | ABMTSR.EXE | Scanner software, not required for scanner to work |
X | Alchem | Alchem.exe | Transponder parasite updater/installer |
X | alcmtr | ALCMTR.EXE | Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers |
U | Alcohol | Alcohol.exe | Alcohol 120% - CD/DVD emulation/writing/copying software |
U | Alcohol Autorun | Alcohol.exe | Alcohol 120% - CD/DVD emulation/writing/copying software |
? | Alcom PCL Capture | FMW_PCAP.EXE | ?? |
N | AlcWzrd | ALCWZRD.EXE | RealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one |
X | AlcxMonitor | Alcxmntr.exe | Realtek AC97 Audio - Event Monitor. Sypware file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but is being used by Realtek to gather data about customers |
X | Alevir | Alevir.exe | Added by the OPASERV.A or OPASERV.F or OPASERV.G WORMS! |
X | AlevirOld | [worm filename] | Added by the OPASERV.G WORM! |
N | Alexa | Alexa.exe? | Alexa Toolbar "is a downloadable toolbar that helps you navigate the Internet as you surf, by instantly providing you with related information about the site you're viewing". Available via Start -> Programs |
? | ALFY Accellerator | AlfyAC~1.exe | ?? |
X | ALG32 | ALG32.EXE | Added by the Startpage.K hijacker |
N | Alias SketchBook Snapshot | ALIASS~2.EXE | Screen-capture utility for Alias Sketchbook |
N | AlienAutopsy | Test_BS.exe | Alienware computer technical support software |
Y | ALiSndMgr | ALiSndMg.exe | ALi AC97 Sound driver |
? | AliUSBfix | GREENMK.exe | May be realted to a USB 2.0 PCI card - the IOgear GIC220OU? |
X | alkasr | ÎäŇíŃ.exe | Added by the BALKART TROJAN! |
U | All Aboard Status | stswin.exe | All Aboard! Internet Connection Sharing status icon |
X | All Sea screen saver | TaskTray.exe | "Free screensaver", installs lots of foistware. See here. Get rid of it |
X | All Sea web link | FWLink.exe | "Free screensaver", installs lots of foistware. See here. Get rid of it |
U | allSnap | allSnap.exe | "allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop" |
U | Alogserv | Alogserv.exe | From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up |
Y | Alps Electric USB Server | Monserv.exe | Alps Electric USB Server - required according to this article |
U | AlpsPoint | Apoint.exe | Touchpad software for laptop PC's. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work |
? | ALServ | ALServ.exe | Altec Lansing AMS speaker related. What does it do and is it required? |
N | Altnet | points manager.exe | Altnet Points Manager - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required |
N | AltnetPointsManager | points manager.exe | Altnet Points Manager - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required |
U | AltoMB_service | AltoMBsrv.exe | Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management |
U | ALUAlert | ALUNotify.exe | Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis |
U | AlwaysOnTopMaker | AlwaysOnTopMaker.exe | Always On Top Maker - utilty to enable an application to always be displayed "on top" of others on the desktop |
X | AmazingTens | AmazingTens.exe | Premium rate adult content dialler |
N | America Online *.* Tray Icon | aoltray.exe | Puts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs |
N | AME_CSA | rundll32 amecsa.cpl, RUN_DLL | Loads ADSL modem Control Panel applet |
Y | Amon | AMON.EXE | Monitoring part of Eset's NOD32 virus-scanner |
Y | Amonitor | amon.exe | Tiny Personal Firewall |
X | anbv32 | nabv32.exe | Added by the TITOG.C WORM! |
? | ANIWZCSService | WZCSLDR.exe | D-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity |
? | AnnotateCheck | AnnCheck.exe | Genius Wizard Pen Tablet driver related. Is it required? |
N | Announcements | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
N | Anntext | Anntext.exe | Caere Pagekeeper text annotation server |
U | ANONYMIZER_SPYWAREKILLER | SpyWareKiller.exe | Anonymizer Spyware Killer |
U | Another Internet Explorer Popup Killer | aiepk.exe | Another IE Popup Killer - pop-up stopper |
U | Anti-keylogger check | antikey.exe | Anti-keylogger - protects against keylogger programs monitoring your keystrokes |
U | Anti-Trojan-Watch | ATWatch.exe | Anti-Trojan Watch - trojan detector |
U | AntiPopUp | AntiPopUp.exe | AntiPopUp for IE - pop-up stopper |
Y | AntiVir XP | AVwin.exe | AntiVir antivirus |
X | Antivirus | av.exe | Added by the SINKIN TROJAN! Resets IE start page to realphx.com |
X | Antivirus | maja.exe | Added by the NETSKY.H WORM! |
X | Antivirus | iexpl0res.exe | Added by an unidentified WORM or TROJAN! |
X | antivirus32 | antivirus.exe | Added by the SPYBOT.KAI WORM! |
? | AntiVirusProtection | qumk.exe | ?? |
X | antiware | elite***32.exe [*** = random char] | Added by the DLOADER-HW TROJAN! |
U | AntiWindowsMessenger | AntiMsMsg.exe | Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory |
Y | AnVir | AnVir.exe | AnVir Task Manager - protects computer against viruses and manages running processes and startup files |
Y | AnVir Task Manager | AnVir.exe | AnVir Task Manager - protects computer against viruses and manages running processes and startup files |
U | anvshell | anvshell.exe | System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar |
? | anycom bluetooth | ftflauncher.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? |
N | AnyDVD | AnyDVD.exe | "AnyDVD is a driver, which descrambles DVD-Movies automatically in the background. This DVD appears unprotected and region code free for all applications and the Windows operating system as well" |
N | AO Tray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
X | AOL 9.0 Optimized | AOLClient.exe | Added by the SPYBOTER.A TROJAN! |
U | AOL Broadband Check-Up | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
N | AOL Companion | companion.exe | Part of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use |
? | AOL Instant Messenger | AlM.EXE | That is an L between the A and M, the start up location is wrong for AIM. What does this relate to? |
X | AOL Messenger | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! |
X | AOL Messenger | aolmsngr.exe | Added by the SDBOT-JF WORM! |
U | AOL Spyware Protection | AOLSP Scheduler.exe | AOL's spyware protection program |
Y | AolAcsDaemon1 | Acsd.exe | AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually |
Y | AolAcsDaemon1 | AOLACSD.EXE | AOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually |
X | AolCon | config.com | Added by the TAPLAK WORM! |
N | AOLDialer | AOLDial.exe | AOL ISP software dialer - can be activated through a desktop shortcut |
N | AolFix | AolFix.exe | Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL to run correctly. Not seen much any more and should only run once |
X | Aornum | aornum.exe | Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware |
N | AOTray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
Y | APC UPS Status | Display.exe | APC PowerChute Personal Edition status icon |
U | APC_SERVICE | mainserv.exe | PowerChute® Personal Edition - "safe system shutdown software with sophisticated power management functions" |
Y | apc_tray | apc_tray.exe | Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure |
X | API32 | api32.exe | Added by the IRCBOT-B TROJAN! |
X | APIMon | apimonx.exe | Added by the TIBSER.A downloader TROJAN! |
X | APIMon | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
? | Apmsrv9x | APMSRV9X.EXE | Intel AnyPoint Wireless II Home Network related. What does it do and is it required? |
U | Apoint | Apoint.exe | Touchpad software for laptop PC's. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work |
X | App.EXEName | [path to worm].exe | Added by the BODIRU WORM! |
U | Appcon | vAppCon.exe | Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established |
X | appconn | appconn.exe | Added by the CARGAO WORM! |
U | AppExtender | AppExtCB.exe | Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received |
X | appis.exe | appis.exe | Added by the AGENT-BC TROJAN! |
Y | Application | mdmsetsp.exe | Aztech Labs modem driver |
U | Application Explorer | Naldesk.exe | Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components." |
U | AppPlus | AppPlus.exe | AppPlus - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)" |
Y | Apvxd | APVXDWIN.EXE | Part of Panda Anti-Virus. Required to enable permanent virus protection |
Y | Apvxdwin | APVXDWIN.EXE | Part of Panda Anti-Virus. Required to enable permanent virus protection |
Y | Apwheel | Apwheel.exe | Wheel support for an Alps mouse |
X | aqadcup.exe | aqadcup.exe | Added by the AGENT.BG WORM! |
X | ara-key | [random filename] | Added by the ANTINNY WORM! |
X | Archive | archive.exe | Adware, recognized by Kaspersky antivirus as Trojan-Downloader.Centim.a |
N | ARCSolo Recovery | N/A | Backup software by Computer Associates - no longer supported |
N | ares | ares.exe | Ares is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download" |
N | areslite | AresLite.exe | Ares Lite Edition is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download" |
X | Aritima | aritima.exe | Added by the ARITIM WORM! |
U | Artera | arteraui.exe | Artera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance |
X | ASDPLUGIN | dsldbaccess.exe | ClickYes2Enter premium rate adult content dialler |
X | asdx | xwinrpc32.exe | Added by the AGOBOT.VO WORM! |
N | ASE Scheduler | ASE Scheduler.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here |
U | Ashampoo PopUpBlocker | PopUpKiller.exe | Ashampoo popup blocker, part of Privacy Protector Plus - see here |
X | ASHLT | Ashlt.exe | Adware - leads back to an ad server |
Y | ashMaiSv | ashmaisv.exe | Part of Avast! anti-virus software - E-mail scanner |
U | AsioReg | regsvr32.exe ctasio.dll | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
N | asp4tray | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
Y | AspireTimeMachine | acertmb.exe | System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry |
X | assistse | ASSISTSE.EXE | CnsMin (Chinese_Keywords) related |
X | AST | AST | Added by the TROJANDOWNLOADER.WIN32.VB.AH VIRUS! |
X | AST | AST | Added by the VB.AH TROJAN! |
U | ASTART | astart.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings |
X | AStart | AStart | Added by the VB.AH TROJAN! |
N | asTray | Astray.exe | Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer |
N | Astro | Astro.exe | Checks for updates to Quicken on a system reboot |
N | ASUS Probe | AsusProb.exe | ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area |
U | ASUS SmartDoctor | VGAProbe.exe | ASUS video card fan/thermal monitor |
U | ASUS TweakEnable | astart.exe | Restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings |
N | ASUSKey | V38SHELL.EXE | System tray Icon for quickly changing video modes |
N | ASWDP | ASWDP.exe | MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market |
X | ASWnk | aswnk.exe | Adult content dialler |
U | AT-Watch | ATWatch.exe | Anti-Trojan Watch - trojan detector |
U | Athan | Athan.exe | Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world |
N | ATI CATALYST System Tray | CLI.exe SystemTray | System Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop |
N | ATI DeviceDetect | ATIDtct.EXE | Utility meant for future use of the ATI TV WONDER™ USB 2.0 video driver and can be disabled |
N | ATI GART Set-up Utility | Atigart.exe | Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed |
U | ATI Launchpad | launchpd.exe | Convenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu |
Y | ATI Remote Control | ATIRW.exe | Driver for the ATI REMOTE WONDER™ RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it |
N | ATI Scheduler | Atisched.exe | Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see |
N | ATI Task Application | Atitkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display |
N | ATI Task Application (Atikey) | Atitask.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display |
X | ATI VIDEO REGKEY | ati2vid.exe | Added by the SDBOT.UR WORM! |
? | Ati2cwxx | Ati2cwxx.exe | For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it |
N | Ati2mdxx | Ati2mdxx.exe | For ATI video cards. System Tray access to display mode changing |
N | ATICCC | cli.exe runtime | ATI's CATALYST™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. Recommend that start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime as it can casue problems when starting Windows |
U | AtiCwd | AtiCwd.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
U | AtiCwd | AtiCwd32.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
U | AtiCwd | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
U | AtiCwd32 | AtiCwd.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
U | AtiCwd32 | AtiCwd32.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
U | AtiCwd32 | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card |
N | AtiKey | AtiKey32.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display |
? | AtiKey | atiptkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display |
U | ATIModeChange | Ati2mdxx.exe | System Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager |
U | ATIPOLAB | ati2evxx.exe | ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources |
U | ATIPOLL | ati2evxx.exe | ATI External Event Utility EXE Module. This task can comsume lots of CPU resournces on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources |
U | AtiPTA | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | AtiPTA | Atiptaxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | AtiPTAAA | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | AtiPTAAA | Atiptaxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | atiptaxx | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | atiptaxx | Atiptaxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings |
U | AtiQiPcl | AtiQiPcl.exe | Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's |
U | ATISmart | ati2s9ag.exe | ATI's "SMARTGART", which is included with the "Catalyst" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings |
X | atisrc2 | windfind.exe | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return |
U | atitray | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings |
U | AtiTrayTools | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings |
X | atiupdate | ATIUPDATE5.EXE | Added by the DEBESKI.A TROJAN! |
X | atiupdate | msshed32.exe | Added by the DELF.EP downloader TROJAN! |
X | ativopen | ativopen.exe | Premium rate adult content dialler |
U | ATIX10 | atix10.exe | ATI Remote Wonder - PC wireless remote control |
X | ATM Control | adpn.exe | Added by the MMS.A WORM! |
N | ATnotes | atnotes.exe | Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs |
U | Atomic.exe | Atomic.exe | Atomic Clock Sync - synchronizes your computer's time with the NIST time server |
N | Atomica | atomica.exe | Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key |
U | AtomicTime | ATOMICTIME.EXE | AtomicTime - utility that synchronizes your PC clock to an atomic clock |
U | Atrack | atrack.exe | New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert |
U | Atray | Atray.exe | Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons |
U | ATTBroadbandUpdate | SAUpdate.exe | Big Brother from Quest Software. System and network monitor |
U | ATTRedUpdate | AutoUpdate.exe | Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates |
X | AttuneClientEngine | attune_ce.exe | Spyware - part of an automated helpdesk software called Aveo Attune |
X | AttuneContentUpdater | attune_cu.exe | Spyware - part of an automated helpdesk software called Aveo Attune |
X | AttuneDiscovery | attune_di.exe | Spyware - part of an automated helpdesk software called Aveo Attune |
X | Attunel | Attunel.exe | Spyware - part of an automated helpdesk software called Aveo Attune |
X | AttuneSystray | attune_st.exe | Spyware - part of an automated helpdesk software called Aveo Attune |
N | aTuner | atuner.exe | aTuner - tweak tool for GeForce based graphics cards |
Y | atwtusb | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) |
U | AU Agent | AUagent.exe | Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon |
X | au.exe | au.exe | Added by the BEAGLE.B WORM! |
Y | AUCBPNP | aucbnpn.exe | Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot |
X | Aucompat | Aucompat.exe | Added by the GEMA TROJAN! |
? | AudCtrl | RunDll32 AudCtrl.dll, RCMonitor | Audio control panel? |
X | Audiocntl | audiocntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
N | AudioHQ | Ahqtb.exe | For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs |
X | audioinf | audioinf.exe | Added by a variant of the CRYPTER.C TROJAN! |
Y | Aureal A3D Interactive Audio | sa3dsrv.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
Y | Aureal A3D Interactive Audio Init | A3dInit.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled |
X | ausvc | ausvc.exe | Added by the AUTOUPDER TROJAN! |
X | authz | authz.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | auto repair system | qualityx.exe | Added by an unidentified WORM or TROJAN - probably a SPYBOT variant |
N | Auto T Bar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled |
X | Auto updat | crsrs.exe | Added by the FORBOT-AK WORM! |
X | Auto Updat | WindowsSys32.exe | Added by a variant of the FORBOT WORM! |
X | Auto Update | AUP.exe | Added by an unididentified WORM or TROJAN! |
U | Autobar | autobar.exe | Connect buttons on the keyboard for internet direct access, etc. on HP computers |
N | AutoEA | Ahqrun.exe | For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ |
X | Autoloaderaproposclient | Apropos_Client_Loader.exe | AproposMedia adware |
N | AutoMate Task Service | automate.exe | Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs |
X | Automatic Microsoft Windows Updater | suchost.exe | Added by the RBOT-EQ WORM! |
X | Automatic Windows Updater | Update.exe | Added by the GAOBOT.AO WORM! |
N | Automatically launches the United Devices Agent when you start your computer | UD.EXE | The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs |
N | AUTOPROP | REGPROP.EXE WMPADDIN.DLL | Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension |
? | AutoShutdown | pssvc.exe | Utility to fix vCard Export in MS Outlook 2000 - although why are these together? |
U | AutoSizer | AUTOSIZER.EXE | AutoSizer - utility that automatically maximizes windows when they're opened |
N | AutoSpell 5 | ASWATC32.EXE | AutoSpell - spell checker |
N | autotbar | autotbar.exe | If you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled |
N | AutoTKit | AUTOTKIT.EXE | On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled |
N | autoupd | autoupd.exe | Raxco Software Auto Update utility."Used to keep your software up-to-date" |
X | autoupd | autoupd.exe | Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name |
X | AutoUpdater | aupdate.exe | Aupdate, Tinybar variant. Spyware |
X | AutoUpdater | AutoUpdate.exe | PeopleonPage foistware |
X | aux.exe | aux.exe | Added by the ZINS TROJAN! |
X | auxAudioDevice | aux32.exe | Added by the AIZU WORM! |
N | AUXXTRAY | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
X | AV | UPDATE-28062004.exe[25 blank spaces].vbs | Added by the MIDFIN WORM! |
X | AV Client | patch31345.exe | Added by the MYDOOM.AD WORM! |
X | AV Industry | patch31345.exe | Added by the MYDOOM.AD WORM! |
Y | Avast! | ashserv.exe | Avast! anti-virus software |
Y | avast! | ashDisp.exe | Part of Avast! anti-virus software |
Y | Avast32 | Astart32.exe | Part of Avast! anti-virus software |
X | avc | avmon.exe | Added by an unidentified TROJAN! |
U | AvconsoleEXE | Avconsol.exe | From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it |
X | AveoAttune | atmdlusr.exe | Spyware - part of an automated helpdesk software |
X | AVG Grisoft Updater | updater.exe | Added by the AGOBOT-OT WORM! |
Y | AVG7_AMSVR | Avgamsvr.exe | AVG antivirus related |
Y | AVG7_CC | AVGCC.exe | AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates |
Y | AVG7_EMC | AVGEMC.exe | AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses |
Y | AVG7_Run | avgw.exe | AVG Anti-Virus 7.0 related |
Y | avgamsvr.exe | Avgamsvr.exe | AVG antivirus related |
Y | avgcc32 | avgcc32.exe | AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates |
Y | AVGCtrl | AVGCTRL.EXE | Background task of the AntiVir antivirus program which scans files transparently in the background |
Y | avgmsvr.exe | avgmsvr.exe | AVG Anti-Virus 7.0 related |
Y | Avgserv9.exe | Avgserv9.exe | AVG antivirus background monitoring |
Y | AVG_CC | avgcc32.exe | AVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates |
Y | AVG_EMC | AVGEMC.exe | AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses |
Y | AVG_RegCleaner | AVGREGCL.exe | AVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems |
X | Avimgt | Avimgt.exe | Added by the GEMA TROJAN! |
X | Avimgt32 | Avimgt32.exe | Added by the GEMA TROJAN! |
Y | AvMaiSrv | Avmaisrv.exe | Part of Avast! anti-virus software - E-mail scanner |
X | avnort | formatsys.exe | Added by the SERFLOG.A WORM! |
X | avnort | msmbw.exe | Added by the SERFLOG.A WORM! |
X | avnort | serbw.exe | Added by the SERFLOG.A WORM! |
Y | avpcc | avpcc.exe | Kaspersky Labs anti-virus |
Y | avpm | avpm.exe | Kaspersky antivirus |
X | Avpr | avpr.exe | Added by the MYDOOM.AF WORM! |
X | Avril Lavigne - Muse | [random filename] | Added by the AVRIL-A WORM! |
Y | AVSCHED32 | AVSched32.exe | AntiVir anti-virus from H+BDEV |
X | AvSer | dsm.exe | Added by the SERFLOG.B WORM! |
X | AvSer | msmpatch.exe | Added by the SERFLOG.B WORM! |
X | AvSer | svosm.exe | Added by the SERFLOG.B WORM! |
X | AvSer | sysup.exe | Added by the SERFLOG.B WORM! |
X | avserve.exe | avserve.exe | Added by the SASSER WORM! |
X | avserve2.exe | avserve2.exe | Added by the SASSER.B or SASSER.C WORMS! |
X | avserve3.exe | avserve3.exe | Added by the SASSER.G WORM! |
N | Avtray | Avtray.exe | Command Antivirus tray icon |
? | AVWLPSTA | AVWLPSTA.exe | PRISM Status Tray Applet - but what is it for and is it required? |
U | AVWUpd32 | AVWUPD32.EXE | AntiVir updater. Useful, but can be run manually |
Y | avx communicator | xcommsur.exe | Anti-virus part of BitDefender virus scanner/firewall |
Y | Avxlive | avxlive.exe | Bullguard or BitDefender antivirus |
Y | avxlni | avxinit.exe | Anti-virus part of BitDefender virus scanner/firewall |
? | Avxnews | ?? | ?? |
X | Awatch | Awatch.exe | Fritz!_DSL ISP software related. What does it do and is it required? |
N | awhost32 | awhost32.exe | Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended |
U | AWMON | Ad-Watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
? | AxFilter | Rundll32 AXFILTER.DLL, Rundll32 | ?? |
? | a_vpd | vpd.exe | Located in the IBMTOOLSVPD sub-directory. What does it do and is it required?" |
U | a˛ | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a˛ 'Background Guard' real time protection feature |
N | B'sCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required |
N | B.Reader | remin.exe | Birthday Reminder 5.0 - as the name implies |
X | b3d | BDEsecureinstall.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents |
X | b3dUpdate | Zupdate.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents |
U | b9 | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" |
X | b99 | msmm.exe | ClientMan parasite variant |
X | babeie | rundll32 cnbabe.dll, dllstartup | CommonName Toolbar spyware. To uninstall see here |
N | Babylon Client | Babylon.exe | Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on" |
N | Babylon Translator | Babylon.exe | "Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on" |
U | BackgroundSwitcher | bgswitch.exe | Background Switcher Powertoy. Included with the last beta version of the XP Powertoys. Whenever a user right clicked his desktop and chose properties he could see a new tab which allowed him to enable a "Desktop Slide Show." This would automatically change the Windows Desktop at an interval specified by the user. Available here |
N | Backpack UDF | bpudfmon.exe | Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk |
U | BackupExecScheduler | besch.exe | Veritas "Back Up My PC" software |
? | BackupNotify | backupnotify.exe | HP Digital Imaging related. What does it do and is it required? |
N | BackWeb | backweb.exe | Automatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs |
N | Backwork | Backwork.exe | Backwork trojan detector |
U | BACPI10 | bacpi10a.exe | Known as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray |
N | BacsTray | BacsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems |
X | BADDATE | BADDATE.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
X | BagleAV | csrss.exe | Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
X | Bakra | IEHost.EXE | IEDriver adware variant |
X | Band-Aid | [path to file] | Added by the RANKY.O TROJAN! |
U | Banpopup by Pratik | Banpopup.exe | Banpopup - popup killer |
X | Bar Ding lolt | Analiz.exe | Added by the RBOT-RP WORM! |
X | bargains | bargains.exe | BargainBuddy foistware |
X | bargains | bargainbuddy.exe | BargainBuddy foistware |
? | Bart Station | station.sbrt | Related to PeoplePC ISP. May be a dialler for dial-up accounts? |
N | bascstray | BascsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems |
X | Bat | secure2.bat | Added by the ZCREW.C TROJAN! |
N | Batchreg1 | N/A | Part of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here |
U | BatInfEx | rundll32.exe | Displays battery status information on an IBM Thinkpad |
U | Battery Scope | batmgr.exe | Monitors battery levels on a notebook/laptop PC |
U | BatteryBar | batterybar.exe | BatteryBar - displays battery usage, and the current percentage of battery power left |
X | BatzBack | BatzBack.scr | Added by the BACKZAT WORM! |
U | BAUSB | BAUSB.exe | Boston Acoustics Audio, USB driver |
X | bawindo | bawindo.exe | Added by the BEAGLE.AR or BEAGLE.AU WORMS! |
U | BayMgr | DockApp.exe | Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices |
U | Bayswap | bayswap.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices |
U | Bayswap2 | TbUpdate.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices |
? | BBDial | BT Broadband.exe | Part of BT Broandband - is it required? |
N | bbSysTray | bbSysTray.exe | Philips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions" |
U | bbui | bbui.exe | AOL DSL status monitor displaying a red/green icon indicating if you have a connection |
U | bca | bca.exe | BeClean Agent - registry, history, temp files, etc cleaner |
U | BCDetect | bcdetect.exe | Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see |
Y | BCMDMMSG | bcmdmmsg.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems |
U | BCMHal | rundll32.exe bcmhal9x.dll, bcinit | BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings |
Y | BCMSMMSG | BCMSMMSG.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems |
? | bcmwltry | bcmwltry.exe | Broadcom Corporation Wireless Network Tray Applet. Is it required? |
N | BCNT | bcnt.exe | AWS Weatherbug related. What does it do? |
X | BCPC | bcpc.exe | BroadcastPC adware variant |
X | bcpc_c | bcpc_c.exe | BroadcastPC adware variant |
U | BCTweak | bctweak.exe | BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings |
N | Bcvsrv32 | bcvsrv32.exe | Added by the GAOBOT.BQJ WORM! |
N | BCWipeTM | bcwipetm.exe | BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed |
Y | BDMCon | Bdmcon.exe | BitDefender antivirus |
Y | BDNewsAgent | bdnagent.exe | BitDefender antivirus - updater |
Y | BDOESRV | bdoesrv.exe | Bitdefender 8 antivirus and firewall |
Y | BDSwitchAgent | bdswitch.exe | Bitdefender 8 antivirus and firewall |
N | BearShare | bearshare.exe | BearShare file sharing client. Versions known to include spyware - see here |
? | BEEI | beei.exe | ?? |
? | BEHL | BEHL.exe | ?? |
? | BEHLO | BEHLO.exe | ?? |
N | Belkin PCMCIA WLAN Monitor | monitorbk.exe | Belkin USB Network Adapter Management utility - can be started manually |
U | BelNotify | [path] NPBelv32.dll, RunDll32_BelNotify | "BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service" |
? | BELORVBI | BELORVBI.exe | ?? |
? | Belsta.exe | Belsta.exe | Configuration tool for Belkin wireless network cards. Required to change the card’s configuration. Is it required for correct operation once the confuiguration is changed? |
X | Belt | Belt.exe | Transponder parasite updater/installer |
X | Benadril Alert Tool | benadrilalert.exe | Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril |
N | BestPopUpKiller | BestPopupKiller.exe | Popup killer of dubious repute by SwankSoft.com. For more info about the company, do a search for 'SwankSoft' on this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites" |
Y | bg | bullguard.exe | Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster |
U | BGInfo | Bginfo.exe | BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more |
Y | BGNewsAgent | bgnewsag.exe | BullGuard antivirus updater |
N | bgsmsnd | bgsmsnd.exe | Printer driver to generate PDF files from any program |
N | BHOCop | BHOCop.exe | ZDNet's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware |
U | BHODemon 2.0 | BHODemon.exe | BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!". If you prefer forgoing resident protection, the application can also be run on demand |
X | BIE | Rundll32.exe BDSrHook.dll, Rundll32 | BDplugin parasite |
N | bigfix | BIGFIX.EXE | BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog |
U | BigPond Toolbar | bpumTray.exe | Telstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier" |
N | BigPondCable | bpcable.exe | Telstra Bigpond Cable login software - can be started manually |
N | Billminder | Billmind.exe | Can be setup in Quicken to remind user of due payments. Available via Start -> Programs |
X | bin32hpu | ppstub.exe | PrecisionPop adware |
X | bingdian | Bingdian.vbs | Added by the BINGD WORM! |
? | Bingo Charm | charms.exe | Some kind of screen icon kind of like desk flag, but it gives you a choice of icons? |
X | Bios | Bios32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | BIOS1 | BIOS1.EXE | Added by the OPASERV.T WORM! |
? | BIOVCIP | BIOVCIP.exe | ?? |
Y | BitDefender Communicator | xcommsvr.exe | BitDefender antivirus |
U | BitDefender for MSN Messenger | msnmon.exe | Bitdefender anti-virus for MSN Messenger. Unless you have MSN Messenger running all the time start it manually |
U | BitDefender for Yahoo! Messenger | yahmon.exe | BitDefender Antivirus for Yahoo! Messenger - free AV add-on for Yahoo! Messenger |
Y | BitDefender Live! Init | bdinit.exe | BitDefender antivirus |
Y | BitDefender Scan Server | bdss.exe | BitDefender antivirus |
Y | BitDefender Virus Shield | vsserv.exe | BitDefender antivirus |
Y | bitdefenderlive | avxlive.exe | Main program of BitDefender virus scanner/firewall |
U | BitDefender_P2P_Startup | BitDefender_P2P_Startup.exe | Bitdefender anti-virus for file transfers via internet messaging clients such as ICQ and MSN Messenger. Unless you have these running all the time start it manually |
N | BitWare Print Monitor | bwprnmon.exe | FaxServe network fax software |
N | BJ Printer Status Monitor | Cjstsr.exe | Canon BJ printer status monitor |
N | BJ Status Monitor 5xx | CJSTRxx.EXE | Canon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers |
N | bjcfd | cdf.exe | BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs |
N | BlackICE PC Protection | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD |
N | BlackIce Utility | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' See also LoadBlackD |
U | blads | blads.exe | A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks |
X | blah service | winupdate.exe | Added by the GAOBOT.BIA WORM! |
X | blah service | winsysengine.exe | Added by the RBOT-KI WORM! |
X | blah service | internet.exe | Added by a variant of the RBOT WORM! |
X | blah service | smnp.exe | Added by the RBOT.IZ WORM! |
X | blah service | msnmsgrr.exe | Added by the RBOT.PZ WORM! |
X | blah service | tazkmgr.exe | Added by the RBOT.UA WORM! |
N | BlazeChanger | FBZPaper.exe | Ember graphic file viewer, manager, and touch-up system |
? | bldbubg | bldbubg.exe | Found on a Dell machine?? |
X | BLMessagingIntegration | blengine.exe | BuddyLinks adware |
U | BlockAds | blads.exe | A Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks |
N | BlockTracker | BlockTracker.exe | If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file |
X | blss | blss.exe | Added by the BLARUL TROJAN! |
N | BLSTAPP | blstapp.exe | Puts access to Creative's BlasterControl in the System Tray |
U | BlueToothAuthentication Agent | RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent | Associated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
U | Blueyonder Instant Support Tool | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide |
N | BMail Installation | FTP_back.exe | Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not |
U | BMMGAG | Rundll32 PWRMONIT.DLL, StartPwrMonitor | Displays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window |
U | BMMLREF | BMMLREF.EXE | Battery Manager for IBM ThinkPad laptops |
? | BMMMONWND | rundll32.exe [path] BatInfEx.dll, BMMAutonomicMonitor | IBM Thinkpad related. What does it do and is it required? |
U | BMO MasterCard Wallet | EWALLET.EXE | The wallet conveniently stores billing, shipping and payment information on your PC |
N | BMupdate | BMupdate.exe | Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install |
X | BMZ | bmz.exe | nCase adware |
X | Bndt32 | Bndt32.exe | Added by the LACON WORM! |
X | Bnexe | [random filename] | Added by the KITRO.D (or ARGEN.A) WORM! |
Y | BOC412 | BOC412.exe | Version 4.12 of NSClean's BOClean anti-trojan software |
Y | BOCleanautostart | Boclean.exe | NSClean's BOClean anti-trojan software |
U | bombshel | BOMB32.EXE | Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems |
X | Bonzi Buddy | ?? | Spyware - read here for information and here for removal instructions |
X | BookedSpace | bs2.dll,DllRun | Adware, related to the Remanent parasite |
N | BookmarkCentral | BMLauncher.exe | Bookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use" |
N | BookMarkSink | syncit.exe | Bookmark synchronization utility |
N | BookMarkSync | syncit.exe | Bookmark synchronization utility |
N | BookMarkSync2It | sync2it.exe | Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser" |
U | Boost XP Service | bxservice.exe | Boost XP from Systweak - WinXP tweaking utility |
X | boot | boot.exe | Added by the ELEM TROJAN! |
X | Boot Manager | Njgal.exe | Added by the KILO TROJAN! |
X | BootLoader | BootLoader.exe.vbs | Added by the WATERWORKS WORM! |
U | BootStatus | BOOTST~1.EXE | Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resources |
U | BootWarn | BootWarn.exe | From here: "Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from “Start Programs Norton AntiVirus”. If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab – it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages" |
N | Bose Wave/PC Monitor | wavepcmonitor.exe | System Tray access for this system (more info on the system here). Available via Start -> Programs |
? | Boston | Boston.exe | Part of the Boston Acoustics USB speaker systems. What does it do and is it required? |
X | Bouncer RunStartup | bouncer.exe | VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs |
X | Bouncer RunStartup | LiveUpdate.exe | VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs |
U | bpcpost.exe | bpcpost.exe | MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
U | BPK | bpk.exe | Blazing Tools Perfect Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
N | BPServer | G6FTPSrv.exe | BulletProof FTP Server |
U | BQTray.exe | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually |
X | Brasil | Brasil.exe | Added by the OPASERV.E WORM! |
X | Brasil | BRASIL.PIF | Added by the OPASERV.E WORM! |
X | BrasilOld | [worm filename] | Added by the OPASERV.P WORM! |
U | Break_Reminder | BREAK REMINDER.exe | Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here |
X | Breg | bcre.exe | BroadcastPC adware variant |
X | Bridge | rundll32.exe ...Bridge.dll | Flingstone.com browser hijacker |
Y | Brindys BriTray | BRITRAY.EXE | Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired |
N | Broadband Wizard | bbwiz.exe | Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs |
N | BrowseProxy | FindService.exe | Actual Names - "It is now possible to enter a particular word or keyword phrase that is associated with your business, and immediately be directed to YOUR WEBSITE! The Actual Names technology can do this for you" |
X | browser aid | browseraid.exe | BrowserAid/BrowserPal foistware |
Y | Browser Hijack Blaster | bhblaster.exe | Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings |
U | Browser Launcher | Commandr.exe | Logitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys |
X | Browser Pal | adblck.exe | BrowserAid/BrowserPal foistware |
U | Browser Sentinel | BrowserSentinel.exe | Browser Sentinel. Notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page. See here |
N | BrowserWebCheck | loadwc.exe | Checks to make sure that IE is still your default browser |
N | BsCLiP | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required |
X | Bsoft lppt01 | Bsoft.exe | New variant of the RapidBlaster parasite (in a "BelmontSoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Bsx3 | Rundll32.exe bs3.dll, DllRun | BookedSpace parasite variant |
U | BT Broadband Help | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide |
? | btinst | btinst.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? |
U | BtStart | btstart.exe | Broadcorp (formerly WIDCOMM) Bluetooth Connectivity Software |
U | bttray | bttray.exe | System tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device |
Y | BTUSRBDG | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) |
Y | BTUSRBDGF | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) |
X | BTV | btv.exe | BroadcastPC adware variant |
N | Buddyizer | Buddyizer.exe | Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network |
U | bugwatcher service | bugwatcher.exe | Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures |
? | BuildBU | bldbubg.exe | Found on a Dell machine?? |
X | BuildLab | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | BuildLab | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
X | BuildLabs | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
U | Bulldog Service | upsd.exe | Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link |
Y | BullGuard | mgui.exe | Part of Bullguard antivirus |
U | BullGuard Update | avxlive.exe | Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions |
Y | BullGuard XComm | XCOMMSVR.EXE | Part of Bullguard antivirus |
Y | BullGuardInit | AVXINIT.EXE | Part of Bullguard antivirus |
Y | BullguardoptIn | bulldownload.exe | Part of Bullguard antivirus |
X | BullsEye Network | bargains.exe | BargainBuddy foistware |
? | BullsEye Tracker | BeTrack.exe | Bullseye - intelligent research assistant |
N | BurnQuick Queue | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually |
U | Button Server | bttnserv.exe | Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required |
N | ButtonKey | ButtonKey.exe | CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut |
N | Buzme | Bmui.exe | Buzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem |
U | Buzof.exe | buzof.exe | Buzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes" |
X | bxsx5 | RunDLL32.EXE bsx5.dll | BookedSpace parasite variant |
X | bxxs5 | RunDLL32.EXE bxxs5.dll, dllrun | BookedSpace parasite |
X | Bymer.Scanner | Wininit.exe | Added by the BYMER WORM! |
X | Bymer.Scanner | Msinit.exe | Added by the BYMER WORM! |
X | c | c:archiv~1win.com | Added by the CUYDOC TROJAN! |
U | C-Media Echo Control | EchoCtrl.exe | C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer |
N | C-Media Mixer | Mixer.exe | C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs |
U | C2K | CYB2K.EXE | CYBERsitter 2000 or 2001 - anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser |
U | CA-AMAgent | amagent.exe | Unicenter Asset Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting |
X | Cabchk | Cabchk.exe | Added by the GEMA TROJAN! |
X | Cabchk32 | Cabchk32.exe | Added by the GEMA TROJAN! |
X | CABCInstall | CABCInstall.exe | CABC content delivery software |
U | CacheBoost | trayicon.exe | CacheBoost "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost" |
N | Cacheman | Cacheman.exe | Freeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up |
Y | CacheMgr | CacheMgr.exe | Sophos Antivirus Remote Update |
N | CACStarter | cacstart.exe | Cash A Check - check writing software |
U | Caddais BackupOnDemand | BODMon.exe | Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location" |
U | CADS | cads.exe | Cyber Sentinel internet filtering software |
N | CAgent | CAgent.exe | Abbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents |
X | cAgOu | [filename].hta | Added by the KAKWORM WORM! |
N | CahootWebcard | CahootWebcard.exe | "The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed |
Y | CAISafe | isafe.exe | Part of Computer Associates eTrus EZ Antivirus |
N | Cal Reminder Shortcut | calrem.exe | Produces a pop-up reminder of events scheduled using the MS Office Calendar |
X | Calc Microsoft Windows | wincalc.exe | Added by an unidentied WORM or TROJAN! |
N | Calendar 200X Reminder | calendar.exe | Calendar 200X - shows holidays, reminders of various anniversaries,tasks etc |
? | CallBumping | cbpopw.exe | ?? |
N | CallControl | ftctrl32.exe | FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows |
N | CamCheck | CamCheck.exe | NuCam camera software related |
N | Camera Detector | CAMDET~*.EXE | ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically |
N | Camera Detector | Camdetect.exe | ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically |
N | Camio Viewer x | IXApplet.exe | Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version |
? | CamMonitor | hpqcmon.exe | From HP and related to digital imaging |
N | Canada | Canada.exe | Known to be a dialler - but is it maliscous or clean? |
N | Canary | canary-std.exe | Canary monitoring program. Keylogger, monitors all computer activity |
X | candy | command32.exe | Added by the RBOT-LV WORM! |
X | candynet | Taskmsg.exe | Added by the RBOT-NA WORM! |
N | Canon PC1200 iC D600 iR1200G Status Window | CAPM1LAK.EXE | Canon P1200 printer status |
N | Canon Printer Monitor BJCxxx | Cjstlst.exe | Trayicon for Canon printer. xxx denotes model. Available via Start -> Programs |
N | Capfax | capfax.exe | PhoneTools fax software |
Y | Capon | Capon.exe | Canon printer driver |
X | CaptionMgr32 | crssr.exe | Added by the ZAR.A WORM! |
N | Capture Express 2000 | capexp.exe | Capture Express - screen capture utility |
N | Card Monitor | REGCNT09.exe | For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs |
X | Care20 | Care20.exe | TopMoxie adware |
X | CARPserver | CARPserver.exe | Added by the BANKER-AN TROJAN! |
U | CARPservice | carpserv.exe | Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example |
U | CasAgnt | CasAgnt.exe | Program by Extended Systems which allows you to sync your Casio PDA with your PC |
X | Casdvqwa | bmqnzkg.exe | Added by the RANDEX.BE WORM! |
X | caseyvideo | CaseyVideo.exe | Malware causing p0rn popups |
X | caseyvideo | caseyvideo[*].exe [* = digit] | Malware causing p0rn popups |
X | CashBack | cashback.exe | Part of eXact Advertising Software, consisting of "CashBack by BargainBuddy", BullsEye Network and NaviSearch |
N | Cashsurfers Cashbar Navigator | Cashbar.Exe | Cashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals" |
X | CashToolbar | CD_Load.exe | CashToolbar Downloader-MY adware |
X | CashToolbar | svchost.exe | CashToolbar Downloader-MY adware. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
Y | CAVS | CAVS.exe | Cheyenne (now eTrust) antivirus |
X | CAZNOVAS | CAZNOVAS.exe | Added by the CAZNO TROJAN! |
U | CBWAttn | CBWAttn.exe | Required for Bitware to answer incoming faxes, can cause sleep mode problems |
U | CBWHost | CBWHost.exe | Required for Bitware to answer incoming faxes, can cause sleep mode problems |
? | CBWUser | CBWDial.exe | Associated with Bitware that integrates fax, voice, pager, and data communications on your desktop |
X | CC2KUI | comet.exe | Comet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See here for more information and for the uninstall procedure |
Y | ccApp | ccApp.exe | Part of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this |
X | ccApp | [random filename] | Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus |
X | ccApp | WMADZ.EXE | Added by the RBOT-LJ WORM! |
X | ccAppr | svcrhost.exe | Premium rate adult content dialler |
X | ccApps | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | ccApps | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
U | CCD Manager | DDS.EXE | Project Labs Century CD manager for their CD/DVD storage device |
N | Ccdecode | rundll32.exe streamci, StreamingDeviceSetup | Part of the closed caption decdoder/MS VBI codec. Should only run once |
Y | CCDoctorLogonTesting | ccdoctor.exe | Checks your system to make sure it's configured properly for running Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product |
Y | ccenter | CCenter.exe | RAV AntiVirus |
Y | CcEvtMgr | ccEvtMgr.exe | Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this |
X | ccpApps | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | ccpApps | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
U | ccProxy | CCPROXY.EXE | Part of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage |
Y | CcPxySvc | CCPXYSVC.exe | Part of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall |
X | ccreg | explorer.exe | Added by the ZCREW TROJAN! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in a C:WindowsSystem or C:WinntSystem subdirectory |
Y | CcRegVfy | ccRegVfy.exe | Part of Norton AntiVirus 2003. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack" |
Y | ccSetMgr | ccSetMgr.exe | Part of Norton AntiVirus 2004. What does it do? |
X | ccUpdate | ccUpdate.exe | Added by the AGOBOT.YS WORM! |
U | ccWasher | aolwasher.exe | Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL |
U | CCWC7a | ac.exe | Moleculesoft Cache, Cookie & Windows Cleaner Ver. 7 - auto clean |
U | CCWC7I | idxl.exe | Moleculesoft Cache, Cookie & Windows Cleaner Ver. 7 - auto clean |
U | CCWC7s | stealth.exe | Moleculesoft Cache, Cookie & Windows Cleaner Ver. 7 |
X | cd1 | cd1.exe | Premium rate adult content dialler |
N | CDANTSRV | CDANTSRV.exe | C-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually |
X | Cdcompat | Cdcompat.exe | Added by the GEMA TROJAN! |
X | cddrv32 | cddrv32.exe | Added by a variant of the CRYPTER.C TROJAN! |
N | CDInterceptor | cdi.exe | CD indexer for measuring the speed of CD players |
N | CDTray | CDTray.exe | On HP PCs, this is the small CD icon next to the time |
? | CeEKEY | CeEKey.exe | Toshiba Satellite E-Key related. Is it required? |
U | CeEPOWER | cepmtray.exe | Toshiba's Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times |
? | Ceic | Ceic.exe | ?? |
X | Cekirge | [path to worm] | Added by the KERGEZ.A WORM! |
X | center | [random name]32.exe | Added by the BOFRA.A WORM! |
X | CentralProcessor | taskimgr.exe | Added by the BANCOS.J TROJAN! |
? | CEPA | wsot.exe | ?? |
X | cesmain.dll | cmail.dll, Rundll32 | CnsMin "Chinese Keywords" hijacker related |
N | CFD | CFD.exe | BroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs |
X | CFDStart | WinMuschi.exe | WINMUSCHI dialler |
Y | cfgintpr | cfgintpr.exe | Configuration Interpreter - part of Tiny Personal Firewall V4 |
N | cfgwiz | cfgwiz.exe | Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
? | cFosDNT | cFosDNT.exe | cFos DSL Modem driver related. What does it do and is it required? |
? | cFosInst_Check | cfosinst.exe | cFos DSL Modem driver related. What does it do and is it required? |
X | cftmon32 | taskmgr*.exe [* = number] | Added by the SOWSAT.C and SOWSAT.J WORMS! |
U | CGServer | cgserver.exe | Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs |
X | Cgtask Services | cgtask.exe | Added by the LALA.B TROJAN! |
U | ChamClock | ChamClock.exe | Chameleon Clock - system tray clock replacement |
X | change-me-now | msgfix1.exe | Added by the SDBOT.ZD WORM! |
? | ChangeLines | chngline.exe | ?? |
N | Chatango | Chatango.exe | Chatango - "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately |
N | Chcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
X | Cheatle | GigaByte.exe | Added by the SHODI.B VIRUS! |
N | Check for One Touch Update | wiseupdt.exe | Checks for updates for Visioneer OneTouch scanners |
U | Check Messenger | cmesseng.exe | Check Messenger from Qchex.com - program that helps you manage the activity of your Qchex account |
U | CheckIt | ToolBox.exe | CheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify |
Y | CheckMsgPlus | MsgPlusH.dll, VerifyInstallation | Added by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info. |
? | checktime | ct.exe | Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required? |
U | CherryKeyMan | KeyMan.exe | Multimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys |
U | ChineseStar | cstar.exe | Chinese language support software |
N | CHKADMIN | CHKADMIN.EXE | Compaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability" |
X | chkdsk | c:autoexec.bat | Added by the ANPES WORM! |
X | Choke | Choke.exe-blahh | Added by the CHOKE WORM! |
X | chostsv | chostsv.exe | Added by the BANPAES.C TROJAN! |
U | CHotKey | mhotkey.exe | Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features |
U | CHotKey | MK9805.EXE | Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol+, vol-, mute, etc. Only required for extended features |
U | CHotKey | zHotkey.exe | Enables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features |
N | Christmas Music Player | TTEST6.EXE | "Christmas Music Player brings the music of the Christmas Holiday to your desktop" |
? | ChromeMark | keysh.exe | Related to this. Don't know what keysh.exe does though and if it's required |
? | ChronitelInitTV | CHTVINIT.EXE | ?? |
X | CiaBackdoor | msldr.com | Added by a VIRUS! |
X | cihost.exe | cihost.exe | Added by the LINST TROJAN! |
N | CIJxP2PSERVER | CIJxP2PS.EXE | Compaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7 |
U | Cisco Systems VPN Client | ipsecdialer.exe | Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
N | Cisco Systems VPN Client | vpngui.exe | Sets up IPSec communications for Cisco's VPN Client |
N | CISrvr Program | CISRVR.EXE | Related to internet setup on Compaq PC's |
X | Cissi | Cissi.exe | Added by the CISSI.A WORM! |
N | CitiVAN | CitiVAN.exe | Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again |
Y | Cjstcom | Cjstcom.exe | Canon printer BJ status language monitor |
Y | ClamWin | ClamTray.exe | ClamWin antivirus |
X | Classes | int1.exe | "Switch" adult content dialler |
X | Classes | intl.exe | "Switch" adult content dialler |
X | Classes | run_21.exe | "Switch" adult content dialler |
X | Classes | srv.exe | "Switch" adult content dialler |
X | Classes | srv2.exe | "Switch" adult content dialler |
X | Classes | MSTAR2.EXE | "Switch" adult content dialler |
X | Classes | mstart.exe | "Switch" adult content dialler |
U | CLCLSet | CLCL.exe | CLCL clipboard caching utility |
? | CleanEasyImg | cleanall.exe | ?? |
U | CleanSweep Smart Sweep- Internet Sweep | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
N | CleanSweep Useage Watch | CSUSEM32.EXE | Quarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time |
U | CleanTemp | CLEANT~1.EXEB | CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
U | CleanTemp | CleanTemp.exe | CleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory |
N | Cleanup | ONICTASK.EXE | Internet Cleanup from Aladdin Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet |
? | CleanupProgram | cleanup.exe | In a C:Sonysys folder - Sony Vaio related? |
X | clean_service | clean_service.cmd | Added by the REFAZ WORM! |
N | Click Radio Tuner | clickr~1.exe | ClickRadio - subscription service playing radio music via the internet |
N | Click Tray Calendar | ClickT~1.EXE | ClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc |
U | Clickoff | Clickoff.exe | Clickoff automatically dismisses annoying dialog boxes |
X | ClickTheButton | CTB.EXE | ClickTheButton Downloader-MY adware |
X | ClickTheButton | csrss.exe | ClickTheButton Downloader-MY adware. Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | ClickTheButton | MSCStat.exe | ClickTheButton Downloader-MY adware |
X | CLICONFG | CLICONFG.EXE | Added by the OPASERV.T WORM! |
N | Client Access Check Version | cwbckver.exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources |
? | Client Access Express Welcome | cwbwlwiz.exe | Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
N | Client Access Help Update | cwbinhlp.exe | Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries |
N | Client Access Service | CwbSvStr.Exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources |
? | Client agent for ARCserve | W95AGENT.EXE | Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required? |
X | Client Server Runtime Process | csrsss.exe | Added by the SDBOT-LD WORM! |
X | ClientMan1 | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
N | Clik Status Monitor | toolsclickstat.exe | Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed |
N | Clipbook Service | Clipsrv.exe | Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
N | ClipMate5x | ClipMt5x.exe | Clip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
N | Clipmate6 | CLIPMT60.EXE | Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs |
N | Clipomatic | Clipomatic.exe | Mike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data |
N | Clipsrv | Clipsrv.exe | Supports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks |
N | ClipTrak | ClipTrak.exe | ClipTrak - clipboard extender |
N | ClipTrakker | ClipTrakker.exe | Cliptrakker - clipboard extender |
U | CLMFrontPanel | clmpanel.exe | System tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost |
? | clnwall | rundll.exe setupx.dll, InstallHinfSection ..delwall.inf | ?? |
X | clock | [various filenames] | LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe |
X | ClockSync | Sync.exe | ClockSync - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available |
U | ClockWise | CLOCKWISE.EXE | ClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync |
U | CloneCD | CloneCDTray.exe | System tray for CloneCD - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
U | CloneCDElbyCDFL | ElbyCheck.exe | From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it |
U | CloneCDTray | CloneCDTray.exe | System tray for CloneCD - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions |
? | Clotusorgreg0 | prtStart.exe Orgprt.exe | Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does? |
X | ClrSchLoader | Loader.exe | Clearsearch variant of IGetNet |
X | CLSID | com.exe | Adult content dialler |
X | CLSID | dll.exe | Adult content dialler |
X | CLSID | msgplus.exe | Adult content dialler |
X | CLSID | plugin.exe | Adult content dialler |
X | CLSID | sed.exe | Adult content dialler |
X | CLSID | msgplus.exe | Premium rate adult content dialer. Note - this is NOT the MSN Messenger 'MessengerPlus' extension |
? | CM-SmWizard | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
U | cma | cma.exe | DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center" |
N | Cmaudio | Rundll32 cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
X | Cmd | cmd32.exe | Added by the TANKED WORM! |
X | cmdcon | cmdcon.exe | Added by the CRYPTER.A TROJAN! |
X | CME | cme.exe | Part of Gator advertising spyware - see here for removal instructions |
X | CmeSYS | CMEsys.exe | Part of Gator advertising spyware - see here for removal instructions |
X | CmeUPD | CMEupd.exe | Part of Gator advertising spyware - see here for removal instructions |
? | CMGrdian | CMGrdian.exe | One of the McAfee shared components. What does it do and is it required? |
X | Cmmon32Sys | cmmon32.exe | Added by the SMALL.CL TROJAN! |
U | CMPDPSRV | CMPDPSRV.EXE | Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more." Installed with some Compaq and Lexmark printers |
X | cmsound | vcpdll.exe | Added by the TCXMEDI-D downloader TROJAN! |
X | cmsound | vcsystem.exe | Added by the TCXMEDI-D downloader TROJAN! |
X | cmssSystemProcess | csmss.exe | Added by the AGENT-CO TROJAN! |
X | cmssSystemProcess | mcsmss.exe | Added by a variant of the AGENT.EI TROJAN! |
X | cmt101 | cmt101.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | cmx32 | cmx32.exe | Added by the GEMA.D TROJAN! |
X | Cn323 | cnfrm33.exe | Added by the MIMAIL.G WORM! |
X | CNBABE | CNBABE.EXE | Appears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you're browsing |
N | cnet | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
X | Cnfrm32 | cnfrm.exe | Added by the MIMAIL.D WORM! |
X | CnsMax | Internat.exe | Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) whereas this version resides in %windir% |
X | CnsMin | Rundll32.exe CNSMIN.DLL, Rundll32 | CnsMin "Chinese Keywords" hijacker related |
N | CnxDslTaskBar | CnxDslTb.exe | Connexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems |
U | Codename Dashboard | dashboard.exe | Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time" |
X | Coldlife -icmp | Systray.exe | Added by the FLOOD.AV TROJAN! Note - this is not the legitimate SysTray.exe |
U | coloreal | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
N | Colorific Control Panel | Hgcctl95.exe | From E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor |
X | COM Service | mscom32.com | Added by the BEASTY.H TROJAN! |
X | COM Service | msynvr.com | Added by the BEASTY.G TROJAN! |
X | COM Service | msjclh.com | Added by the PLUX TROJAN! |
X | COM Service | msdrce.com | Added by the BEASTY.I TROJAN! |
X | COM+ Event System | DRWTSN16.EXE | Added by a variant of the LOVGATE WORM! |
X | Com+ Sys | csrs.exe | Added by the FORBOT-BT WORM! |
X | COM+ System Applications | lsas.exe | Added by the AGOBOT.SE WORM! |
X | COM++ System | exploier.exe | Added by a variant of the LOVGATE WORM! |
X | COM++ System | suchost.exe | Added by a variant of the LOVGATE WORM! |
X | COM++ System | svchost.exe... | Added by a variant of the LOVGATE WORM! |
N | COM-IP | COMIP.EXE | COM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212) |
U | ComAgent | ComAgent.exe | ComAgent - MDaemon's instant messaging client |
X | ComcastSUPPORT | tgkill.exe | Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs |
X | COMCFG | comcfg.exe | Added by the TOADCOM.A TROJAN! |
X | comctl32 | comctl32.exe | Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am |
U | COMDRV32 | svdhost.exe | Orvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/ |
U | Comm Driver | commh32.exe | G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
X | Command | system.exe | Added by the GATECRASH.A or GATECRASH.B TROJANS! |
X | Command | Gotit.exe | Added by the TITOG WORM! |
X | COMMAND | command.exe | Added by the QQPASS.E TROJAN! |
X | Command Prompt32 | CmdPrompt32.pif | Added by the ASSIRAL.B WORM! |
N | CommCtr | commctr.exe | "Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs |
U | Compaq Alerter | CPQAlert.exe | Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information |
N | Compaq Computer Corp SCCenter Module | SCCENTER.EXE | For Compaq PC's. Part of Backweb |
? | Compaq Computer Security | Rundll32.exe SECURE32.CPL, Service | ?? |
N | Compaq DMI | cpqdmi.exe | Compaq version of the Desktop Management Interface |
N | Compaq Internet Setup | inetwizard.exe | For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list |
U | Compaq Knowledge Center | silent.exe & matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide |
N | Compaq Message Server | COMPAQ-RBA.EXE | Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems |
U | Compaq PK Daemon | cpqkl.exe | For Compaq laptops for programming user configurable keys. Not required unless you use them |
N | Compaq Video CD Watcher | ?? | For Compaq PC's. MPEG viewer |
? | CompaqHW Comp Manager | cpqhcm.exe | Running on a Compaq laptop - any ideas? |
N | CompaqPrinTray | printray.exe | Puts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop |
N | CompaqSystray | cpqpscp.exe | Compaq System Tray icon |
X | Compatibility Service Process | regsvs.exe | Added by the GAOBOT.YN WORM! |
N | COMSMDEXE | comsmd.exe | 3Com tray icon |
X | ComTry Web Searcher | wstray.exe | Comtry MP3 Downloader related - spyware |
X | comxt | comxt.exe | Added by the COMXT TROJAN! |
X | Config | service.exe | Added by the ISRAZ.B WORM! |
X | Config Loadation | iEEexplore.exe | Added by the SDBOT.H TROJAN! |
X | Config Loadatiorin | I3Explorer.exe | Added by the SDBOT.H TROJAN! |
X | Config Loader | svchosl.exe | Added by the GAOBOT.P WORM! |
X | Config Loader | sysldr32.exe | Added by the GAOBOT WORM! |
X | Config Loader | scvhost.exe | Added by the GAOBOT.AE or GAOBOT.AO WORMS! |
X | Config Loader for Microsoft Windows | mwincfg32.exe | Added by the AGOBOT.BD WORM! |
X | Config Loader2 | explores.exe | Added by the GAOBOT.BT WORM! |
X | Config Loadr | winsys32.exe | Added by the AGOBOT-HN WORM! |
X | Config33.exe | Config33.exe | Added by the SDBOT.T TROJAN! |
X | ConfiggLoader | cart322.exe | Added by the GAOBOT.DJ WORM! |
U | ConfigSafe | CFGSAFE.EXE | ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice |
U | ConfigSafe | AUTOCHK.EXE | ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice |
N | ConfigServices | Config.exe | Part of initial setup on a Compaq PC |
X | Configuration | [filename] | Added by the SDBOT-ML WORM! |
X | Configuration Default | Wuxat.exe | Added by the SPYBOT-CA WORM! |
X | Configuration File | Winset32.exe | Added by the FLUX.101 TROJAN! |
X | Configuration Loaded | wupdated.exe | Added by the MOEGA or MOEGA.AG or MOEGA.AP WORMS! |
X | Configuration Loader | aim95.exe | Added by the LOADCFG or SDBOT TROJANS! |
X | Configuration Loader | cmd32.exe | Added by the LOADCFG or SDBOT TROJANS! |
X | Configuration Loader | service5.exe | Added by the GAOBOT.AF WORM! |
? | Configuration Loader | lfass.exe | ?? |
X | Configuration Loader | sycfg34.exe | Added by the GAOBOT.AN WORM! |
X | Configuration Loader | wincrt32.exe | Added by the GAOBOT.BF WORM! |
X | Configuration Loader | windex.exe | Added by the GAOBOT.BZ WORM! |
X | Configuration Loader | dosrun32.exe | Added by the GAOBOT.AO WORM! |
X | Configuration Loader | Service.exe | Added by the GAOBOT.AO WORM! |
X | Configuration Loader | Servicess.exe | Added by the GAOBOT.AO WORM! |
X | Configuration Loader | sw32.exe | Added by the AGOBOT.BQ WORM! |
X | Configuration Loader | System.exe | Added by the GAOBOT.AO WORM! |
X | Configuration Loader | Winreg.exe | Added by the GAOBOT.AO WORM! |
X | Configuration Loader | sysinfo.exe | Added by the GAOBOT.FQ WORM! |
X | Configuration Loader | microsoft.exe | Added by the GAOBOT.JB WORM! |
X | Configuration Loader | confgldr.exe | Added by the POLYBOT WORM! |
X | configuration loader | winicfg32.exe | Added by the GAOBOT.GEN!POLY WORM! |
X | Configuration Loader | svhst.exe | Added by the GAOBOT.YC WORM! |
X | Configuration Loader | msgfix.exe | Added by the GAOBOT.AUS or SDBOT.J or SDBOT-QG WORMS! |
X | Configuration Loader | msnss.exe | Added by the GAOBOT.AUS WORM! |
X | Configuration Loader | IEXPL0RE.EXE | Added by the LOADCFG or SDBOT TROJANS! |
X | Configuration Loader | loadcfg32.exe | Added by the LOADCFG or SDBOT TROJANS! |
X | Configuration Loader | MSTasks.exe | Added by the LOADCFG or SDBOT TROJANS! |
X | Configuration Loader | systemry.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Configuration Loader | ccSort.exe | Added by the AGOBOT.SR WORM! |
X | Configuration Loader | smss32.exe | Added by the AGOBOT.MB WORM! |
X | Configuration Loader | wincffg.exe | Added by the AGOBOT.A3 WORM! |
X | Configuration Loader | syscfg32.exe | Added by the SDBOT.B TROJAN! |
X | Configuration Loading | svchos1.exe | Added by the GAOBOT.DK WORM! |
X | Configuration Loading | configldr.exe | Added by the AGOBOT-EC WORM! |
X | Configuration Manager | CNFGLD32.EXE | Added by the SDBOT TROJAN! |
X | Configuration Manager | Cnfgldr.exe | Added by the SDBOT TROJAN! |
X | Configuration Service | suchost.exe | Added by the TREB TROJAN! |
N | Configuration Utility | CONFIG.EXE | Controls linksys wireless connection. Available from the Desktop |
U | Configuration Utility | wlanutil.exe | NetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards) |
X | Configuration Wizard | Cfgwiz32.exe | Added by a variant of the HACKTACK TROJAN! Not to be confused with the legitimate MS "ISDN Configuration Wizard" (Cfgwiz32.exe) |
X | ConfLoader | sysconf16.exe | Added by the SDBOT-FB TROJAN! |
N | Conmgr | conmgr.exe | Starts Winfax pro at startup |
U | ConMgr.exe | conmgr.exe | Connection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut |
X | Connect2Party | connect2party.exe | Adult content dialler |
N | Connection Manager | CManager.exe | SBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service |
X | Cons | consol32.exe | Hijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed |
X | conscorr | conscorr.exe | Transponder parasite updater/installer |
? | Contacte | contacte.exe | Some kind of driver? |
X | ContentDownload | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
X | ContentService | winservn.exe | Homepage hijacker |
X | ContinueInstall | bpsinstall.exe | BrowserAid parasite |
X | Control | rundll32.exe ctrlpan.dll, Restore ControlPanel | CoolWebSearch parasite variant |
X | Control handler | ***********.exe [* = random char] | CoolWebSearch parasite variant |
N | control panel | smctrlw.exe | System Tray icon for a Silicon Motion LynxEM based PCI Graphics Card |
X | Control Panel | System.exe | Added by the DANI TROJAN! |
N | ControlCenter2.0 | brctrcen.exe | Brother scanner 'Control Center' application - can be started manually |
N | ControlCentreTray | XWCTray.exe | System Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc |
X | Controlled Resource System Service | crss.exe | Added by the AGOBOT.GH WORM! |
N | Controller | WFXCTL32.EXE | From Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
X | ControlPanel | rundll32 internat.dll, LoadKeyboardProfile | CoolWebSearch parasite variant |
X | ControlPanel | host32.exe internat.dll, LoadKeyboardProfile | Added by a vairant of the DELF.DW TROJAN! |
X | ControlPanel | [path] cmd32.exe internat.dll, LoadKeyboardProfile | Awmcash.biz foistware |
U | Cookie Cop 2 | CookieCop.exe | Cookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
U | Cookie Pal | CPBRWTCH.EXE | Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
U | CookieJar | Cookiejar.exe | Cookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
U | CookiePatrol | CookiePatrol.exe | CookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies |
U | CookieWall | cookie.exe | CookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
U | Cool Desk | cdesk.exe | Cool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you |
X | CoolDownloads | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
X | CoolMP3 | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
U | CoolSwitch | taskswitch.exe | ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen |
N | Coolwallpaper | cwm_tray.exe | Cool Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers |
X | coolwebprogram | clrssn.exe | CoolWebSearch parasite variant |
N | Copernic Desktop Search | DesktopSearch.exe | Copernic Desktop Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures" |
U | CopernicPerUserTaskMgr | CopernicPerUserTaskMgr.exe | Automatic tasking feature of Copernic Pro multi-search engine tool |
N | Copyright | mwcpyrt.exe | Displays copyright information on IBM ThinkPads |
U | CoreCenter | CoreCenter.exe | MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking |
U | CoreCenter | CORECE~1.EXE | MSI Core Center - motherboard utility for monitoring CPU speed, voltages, temperatures and fans speeds as well as overclocking |
N | Corel Colleagues & Contacts Reminders | cffrem.exe | Corel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office |
N | Corel Desktop Application Director | dadx.exe | The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs |
N | Corel Family & Friends reminders | CFFREM.EXE | Corel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic |
N | Corel Registration | Remind32.exe | If you don't want to register Corel products and be reminded about it every 2 weeks disable it |
N | Corel Registration Reminder | Remind32.exe | If you don't want to register Corel products and be reminded about it every 2 weeks disable it |
N | Corel Reminder | NAVBROWSER.EXE | If you don't want to register Corel products and be reminded about it every 2 weeks disable it |
N | CorelCENTRAL 10 | I_26dadCC.exe | CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs |
N | CorelMedia FoldersIndexer8 | MFindexer.exe | Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office |
N | CorelMedia FoldersIndexer8 | MFINDE~1.EXE | Part of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office |
X | CoreSrv | coresrv.exe | Some IRC trojans/worms use this - see here for more information |
? | CORESYS | coresys.exe | ?? |
N | CorrectConnect | CConnect.exe | Broadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available |
X | cosine | cosine.exe | Added by the RBOT-SW WORM! |
U | CostAware | niIPCApp.exe | NetInternals CostAware - download quota measuring tool |
N | Country Select | pctptt.exe | Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required |
N | CountrySelection | pctptt.exe | Country selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not required |
? | Coupon Offers | ?? | ?? |
X | couponica | couponica.exe | Adware - see here |
U | CP32NOT | CP32BTN.EXE | For the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons |
U | CP4HPOT | OneTouch.EXE | One Touch keyboard driver. Required if you use the additional keys |
? | CPA9P2PSERVER | CPA9P2PS.exe | Found on a Compaq Presario but what is it? |
U | CPATR10 | CPATR10.EXE | Dritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast |
U | CPBrWtch | CPBrWtch.exe | Kookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return |
Y | CPD_EXE | CPD.EXE | Firewall bundled with McAfee VirusScan 6.* |
X | cpntmgc | wincomp.exe | MagicControl downloader trojan variant |
X | cpntmgc | simcss.exe | MagicControl downloader trojan variant |
X | cpntmgc | navpmc.exe | MagicControl downloader trojan variant |
X | cpntmgc | winmgts.exe | MagicControl downloader trojan variant |
? | CPortPatch | cppatch.exe | CPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though? |
Y | CPQAcDc | CPQAcDc.exe | Compaq PowerCon power management software for laptops |
U | CPQAlert | CPQAlert.exe | Compaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information |
N | CPQBootPerfDB | CPQBootPerfDB.EXE | See the entry for Compaq Message Server |
Y | CPQCalib | CPQCalib.exe | Compaq PowerCon power management software for laptops |
N | CPQDFWAG | CpqDfwAg.exe | For Compaq PC's. Runs Compaq diagnostics on every boot |
U | CPQEASYACC | cpqeadm.exe | For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
U | cpqeaui | cpqeaui.exe | For Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
U | cpqek | kcpqek.exe | For Compaq PC's. Easy Access button support for the keyboard |
U | CPQInet Runtime Service | CpqInet.exe | For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers |
N | CPQINKAGENT | cpqinkag.exe | That is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed) |
U | cpqns | cpqnpcss.exe | Related to Compaq.Net - not required if you don't use that |
N | Cpqset | Cpqset.exe | Default settings software in Hewlett Packard notebook |
Y | CPQSTUTFIX | stutfix.exe | For Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton |
X | cpr | cpr | Adroar.com adware downloader |
X | CPU Manager | cpumgr.exe | Added by the PANDEM.B WORM! |
U | CPUcool | Cpucool.exe | Program to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel |
X | Cpusave | Cpusave.exe | Added by the GEMA TROJAN! |
X | Cpusave32 | Cpusave32.exe | Added by the GEMA TROJAN! |
X | cqlyg | world_cup_.bat | Added by the WCUP.A WORM! |
? | CQSCP2P SERVER | ?? | "Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed |
? | CQSCP2PS | ?? | "Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed |
U | cracked_windows1 | cracked_windows1.exe | Cracked Windows popup killer |
N | CrazyTalk Serve | rundll32.exe CrazyTalk.dll, DIIServeMediaFile | CrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS |
X | CRC Value Verifier | crsss32.exe | Added by a variant of the RBOT WORM! |
X | CRC Value Verifier | Crsss64.exe | Added by the RBOT-NY WORM! |
X | CRC Value Verifier | svchost32.exe | Added by the RBOT-OA WORM! |
U | Creata Mail | JMSrvr.exe | Creata_Mail. Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express |
X | Create A Monster | createAMonster.exe | Kudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related |
N | CreateCD | Createcd.exe | Adaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs |
N | CreateCD50 | Createcd50.exe | Adaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs |
N | Creative AGP Wizard | agpwiz.exe | Part of Creative's BlasterControl |
N | Creative Launcher | CTLauncher.exe | For Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs |
N | Creative MediaSource Go | CTCMSGo.exe | "Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats" |
N | Creative PCI Audio Configuration Utility | starter.exe | System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer |
N | Creative Service for CDROM Access | Ctsvccda.exe | Resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs |
N | Creative WebCam Tray | Camtray.exe | Creative WebCam tray control - can be started manually |
X | Creative.exe | Creative.exe | Added by the PROLIN WORM! |
N | CreativeDiscNotifier | CTNOTIFY.EXE | For Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel |
U | CreativeMixer | CTMIX32.EXE | Creative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon |
N | CriticalUpdate | Wucrtupd.exe | MS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site |
X | cronos | MARCO!.SCR | Added by the OPASERV.G WORM! |
X | Crusty | dmcpl.exe | Added by the RUSTY WORM! |
X | Cryptographic Service | ******.exe [* = random char] | Added by the KORGO.W or KORGO.X or KORGO.AB WORMS! |
? | Crystal 3D Audio Control | CWD3DSND.EXE | Crystal 3D Audio sound driver. Is it required? |
N | csaRem | spqmdmui.exe | Compaq modem country selection |
Y | CSAV_CheckViruses | vchk.exe.exe | Part of Command AntiVirus |
? | csc | csc.exe | ?? |
U | CSINJECT.EXE | CSINJECT.EXE | Part of Quarterdeck/Norton CleanSweep. For a full description see here. An excerpt - "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes." |
X | csrsc | csrsc.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | CSRSS | CSRSS.EXE | Search page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling |
X | Csrss | csrss.exe | Added by the CHOD WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup and the executeable resides in a random folder name |
X | CSRSS Loader | csrsss.exe | Added by the AGOBOT.TX WORM! |
X | CSRSSU | CSRSSU.exe | CoolWebSearch parasite related - hijacking to Slawsearch.com. Also see here |
X | CSRSWIN | [trojan filename] | Added by the WINSHELL.50 TROJAN! |
X | CSRSX | [trojan filename] | Added by the WINSHELL.50.B TROJAN! |
Y | CSScheduleCheck | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
X | csss | Csss.exe | Added by the BALICK TROJAN! |
U | CSS_Central | CSS_1631.EXE | CSS Communication Agent (95 Host) from Command Software Systems "CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console." |
X | CSV10P70 | CSv10P070.exe | ClearSearch adware related |
X | CSV7P26 | CSV7P26.exe | ClearSearch adware related |
X | CSV7P70 | CSV7P070.exe | ClearSearch adware related |
X | CSV7P91 | CSV7P91.exe | ClearSearch adware related |
Y | ct | ct.exe | ct.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it |
N | CTAVTray | CTAvTray.exe | For Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ |
U | CTCMonitor | CTCMonitor.exe | Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required |
N | CTDVDDet | CTDVDDet.exe | Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again |
N | CTDVDDet | CTDetect.exe | Auto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again |
U | ctfmon | ctfmon.exe | CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here |
X | ctfmon | taskmgr32*.exe [* = number] | Added by the SOWSAT.B WORM! |
X | Ctfmon.exe | ctfmon32.exe | CoolWebSearch parasite related - hijacking to Slawsearch.com |
U | CTHELPER | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
X | CTime | [path to trojan] | Added by the HTTPDOS TROJAN! |
X | CTin10 | CTin10.exe | Added by the BANCOS.E TROJAN! |
? | CTPDPSRV | CTPDPSRV.EXE | Printer driver (in the WINDOWSSystem32spoolDRIVERSW32X86 folder). Is it required? |
N | CTRegRun | CTRegRun.exe | For Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative |
U | CtrlVol | CtrlVol.exe | Acer's on screen volume control using the Fn key |
N | CTStartup | CTEaxSpl.exe | Splash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard |
U | CTsysVol | CTSYSVOL.exe | Creative sound card volume controls |
? | cttdpsrv | cttdpsrv.exe | ?? |
Y | cuagentExe | Cuagent.exe | Command Antivirus related |
X | cuo | cuo.exe | Added by the BUGBEAR.A WORM! |
N | cursor | Screendragon_VS_Taskbar.exe | ScreenDragon video player |
N | CursorXP | CursorXP.exe | CursorXP from Stardock - tool for creating mouse cursors |
U | Customizer2000 | logon.exe | Automatic logon feature of Customizer 2000 - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes" |
N | CuteMX | CuteMX.EXE | File sharing utility |
X | cvmonitor.exe | cvmonitor.exe | Added by the SDBOT.BV WORM! |
Y | CVPND | cvpnd.exe | Sub-system used by Cisco VPN client for making a connection to a remote IPSec server |
U | CWatch | cw.exe | ChatWatch - chat monitoring tool |
N | cwbckver | cwbckver.exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources |
N | cwbinhlp | cwbinhlp.exe | Client Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries |
N | cwbsvstr | cwbsvstr.exe | Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources |
? | cwbwlwiz | cwbwlwiz.exe | Welcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required? |
? | Cwcdschk.exe | Cwcdschk.exe | IBM Thinkpad related? |
U | cwupdate | cwupdate.exe | ContentProtect from ContentWatch - internet filter |
N | CXMon | Hpi_Monitor.exe | Autodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs |
N | Cyber | cyberchk.exe | Part of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after "x" amount of time has passed |
U | Cyber Trio | showmode.exe | From G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs |
U | Cyber-Defender 2003 | uwcdsvr.exe | Cyber Defender 2003 |
X | cyberfree.exe | ****.dat [* = random char] | Unidentified adware |
U | CyberLat Ram Cleaner | CLRamCleaner.exe | CyberLat RAM Cleaner is a program that Frees, Optimizes and Defrags your system's wasted memory (RAM). Some users swear by programs such as this but I suggest you read this article and make up your own mind |
N | CyberMedia Agent | CMAGENT.EXE | Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled |
X | CyberWolf | CyberWolf.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
X | CyDoor | CD_Load.exe | Adware. Check here for information about Cy-Door and here for a program that can remove it |
X | CydoorUpdate | CD_Load.exe | Adware. Check here for information about Cy-Door and here for a program that can remove it |
N | CyphTray | CyphTray.exe | Cypherus - encryption software |
Y | D-Link Air USB Utility | AirCFG.exe | D-Link wireless PCI adapter related |
Y | D-Link Air Utility | AirCFG.exe | D-Link wireless PCI adapter related |
N | D-Link AirPlus DWL-650+ Utility | WLANMON.exe | D-Link Air Plus Wireless PC modem connection monitor |
N | D066UUtility | D066UUTY.EXE | TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software |
X | d3dupdate.exe | bbeagle.exe | Added by the BEAGLE.A WORM! |
U | D4 | D4.exe | Dimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down |
N | DACONFIGEXE | daconfig.exe | 3Com NIC Diagnostics. Available via Start -> Programs |
Y | DadApp | dadapp.exe | "DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell |
N | Daemon | DAEMON32.EXE | Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs |
U | Daemon | Daemon.exe | Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive |
X | Daemon | daemon.exe c daemon2.exe | Added by the SELOTIMA.A WORM! |
U | DAEMON Tools-1033 | Daemon.exe | Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive |
N | Daily Planner | dayplan.exe | Daily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them |
X | Danton* | [random filename] | Added by the DANTON TROJAN! where * = random number |
N | Dap | DAP.exe | Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based |
X | DarkDevil.Grasiele.BR | Grasiele.VBS | Added by the LEMBRA WORM! |
? | DashIE | N/A | Could be related to "Dash Power Shopping" tool bar in IE? |
X | dasxdads | fsdqd.exe | Added by the GAOBOT.BIQ WORM! |
X | Data | System.dat.vbs | Added by the BISCUIT.A WORM! |
N | Data LifeGuard | BACKWE~1.EXE | Data LifeGuard diagnostic tools for Western Digital's series of hard drives |
N | Data LifeGuard LifeLine Lite installer | DLGLI.EXE | Backweb installer - see here |
X | Data789 | Regedit.exe ....data789.tmp | Homepage hijacker |
X | DATABASE MySql | [path] repcale.exe [path] beird.exe | Added by a variant of the RANDON.AN WORM! |
N | DataCaching | FlashKsk.exe | SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon |
U | DataLayer | DataLayer.exe | Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on |
N | DataViz Messenger | DvzMsgr.exe | DataViz Documents to Go - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts" |
X | Datcheck | datcheck.exe | Added by the KEYPANIC TROJAN! |
X | Date Manager | datemanager.exe | Date Manager - calender program. Spyware/adware based provided by The Gator Corporation |
? | Datechecker | N/A | Could be related to this? |
X | DateMakerIntl | DateMakerIntl.exe | Premium rate adult content dialler |
X | DAupdate | DAupdate.exe | NavEnhance adware |
? | DAW9532.exe | DAW9532.EXE | Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required? |
U | DayToday | DAYTODAY.EXE | DayToday from RoboMagic Software Corp. Displays the date on the taskbar |
U | DAZEL Delivery Agent | DcDaemon.exe | Control and send documents, etc, to any destination - see here |
N | dbserv | dbserv.exe | Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled |
X | DCE Manager | dcemgr.exe | Added by the TUMAG TROJAN! |
U | DCfssvc | dcfssvc.exe | Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example |
U | dcfssve | dcfssvc.exe | Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example |
N | DDCActiveMenu | DDCActiveMenu.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | DDCM | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case" target="_blank">privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | DDCMan | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case" target="_blank">privacy policy used to state that they also collect and share individuals information but this is no longer the case |
X | ddeproc | ddeproc.exe | Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here |
X | DDialler | DDialler.exe | Adult content dialler |
? | DDT | N/A | ?? |
X | de32gen | de32gen.exe | Added by a variant of the CRYPTER.C TROJAN! |
N | DeadAIM | rundll32.exe DeadAIM.ocm, ExportedCheckODLs | DeadAIM - feature enhancing product for AOL's Instant Messenger program |
X | DealHelperBrwsr | dhbrwsr.exe | DealHelper adware |
X | DealHelperDown | download.exe | DealHelper adware |
X | DealHelperUpdate | DHUpdt.exe | DealHelper adware |
X | Debug | DebugW32.exe | Added by the GUBED TROJAN Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
X | deejay | forboo.exe | Added by the FORBOT-AY WORM! |
X | Default | explore.vbs | Added by the ALLEM WORM! |
X | Default | mtask.vbe | Added by the ALLEM WORM! |
X | default | shell32.exe | Added by the BINGHE TROJAN! |
X | Default System Research | vhchost.exe | Added by the TARNO.I TROJAN! |
X | Default web browser | IexpIore.exe | Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L" |
X | Default_Page_URL | http://find.naupoint.com | Naupoint browser hijacker |
X | Default_Search_URL | http://find.naupoint.com | Naupoint browser hijacker |
X | defragm_check | defragment.exe | CoolWebSearch parasite variant |
U | defwatch | defwatch.exe | Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis |
U | Delay | delayrun.exe | On HP PCs this program is used to help prevent conflicts or timing issues on fast computers |
U | Delayrun | delayrun.exe | On HP PCs this program is used to help prevent conflicts or timing issues on fast computers |
? | delcab | deltreew.exe C:cabs | ?? |
X | Delete Me | worm.exe | Added by the DOOMHUNTER WORM! |
N | Dell AIO Printer A*** | dlbabmgr.exe | Dell AIO Printer A*** related (*** = model). Not Required at Startup |
N | Dell AIO Printer A*** | dlbfbmgr.exe | Dell AIO Printer A*** related (*** = model). Not Required at Startup |
N | Dell AIO Printer A*** | dlbkbmgr.exe | Dell AIO Printer A*** related (*** = model). Not Required at Startup |
N | Dell Alert | DAMon.exe | "Dell Alert" utility, that's supposed to make interaction with Support easier |
N | Dell QuickSet | quickset.exe | Dell taskbar icon allowing you to quickly change settings |
? | DellDMI | delldmi.exe | Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards? |
U | DELLMMKB | DELLMMKB.EXE | Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys |
N | DellSC | dellsc.exe | Dell Solution Center - web-based troubleshooting tools and educational offerings |
U | DellTouch | MMKeybd.exe | Dell multimedia keyboard manager. Required if you use the additional keys |
U | DellTouch | DELLMMKB.EXE | Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys |
X | delmsbb | delmsbb.exe | nCase adware |
X | delsubmit | rundll32.exe advpack.dll, DelNodeRunDLL32 submit.exe | CoolWebSearch parasite variant |
? | DelTmp | DelTemp.exe | Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete? |
N | DeltTray | deltray.exe | System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel |
? | demon | demon.exe | Part of the French Wanadoo ADSL extense pack. What does it do and is it required? |
U | DepFrez | frzstate.exe | Deep Freeze from Hyper Technologies. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example |
? | Description of Shortcuts | *.exe | * seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search) |
X | Desire | desires.exe | Adult content dialler |
? | desk-top-service | desk-top-service.exe | ?? |
X | DeskAd Service | DeskAdServ.exe | Windupdates adware variant |
N | DeskColor | DESKCOLOR.EXE | Provides transparent icon text backgrounds and coloured icon text |
N | Deskflag | Deskflag.exe | DeskFlag - animated USA flag on the desktop |
X | DeskMateAutoUpdate | DeskMateAutoUpdate.exe | DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related |
U | Desksite CMA | cma.exe | DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center" |
X | Desktop | rundll32.exe msconfd.dll, Restore ControlPanel | Added by the BOOKMARKER TROJAN! |
X | desktop | desktop.exe | Added by the SDBOT.MD WORM! |
N | Desktop Architect | DATRAY.EXE | Desktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc |
N | Desktop Plant | AZARE10S.PLT | Vritual plant from here - this version is an Azalea, there are others so the filename may be different |
X | Desktop Search | desktop.exe | iSearch "Desktop Search" hijacker |
? | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software - is it required? |
N | Desktop Weather | THE WEATHER CHANNEL.exe | Desktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc |
N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc |
N | Desktop Weather 3 | THEWEA~1.EXE | Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc |
N | desktopmgr | desktopmgr.exe | Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry" |
U | DesktopX | DESKTOPX.EXE | A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking |
N | deskup | deskup.exe | Adds Iomega Zip drive icons to the desktop |
U | detect | idetect.exe | iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled |
? | detect | turbodetect.exe | ?? |
N | Detector | detector.exe | USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software |
U | DEventAgent | eventagt.exe | DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this |
X | Device Configuration Loader | msdvc32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
U | Device Detector | DevDetect.exe | Watches for external digital imaging products being connected from ACD Systems |
N | Device Detector 2 | DevDtct2.exe | Installed by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resources |
U | DeviceDiscovery | hpotdd01.exe | Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems" |
X | DevicePath | Proyecto1.exe | Added by the GRUEL WORM! |
X | DevicePath | Root.exe | Added by the GRUEL WORM! |
U | Devices | olesvr.exe | Salfeld Child Control 2003 - parental control software |
U | devldr16 | devldr16.exe | Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices |
? | Devlog | ?? | ?? |
? | Devlog | devlog.exe | Apparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it required |
? | DGJM | DGJM.exe | ?? |
N | dguard | dguard.exe | eAcceleration Stop-Sign related - not recommended, see note |
X | DHCP Server | regsvr.exe | Added by the RBOT-PR WORM! |
Y | dhcpagnt | dhcpagnt.exe | Intel DSL modem driver - leave enabled or you'll have to re-install the drivers |
? | DHNUXB | DHNUXB.exe | ?? |
N | diagent | diagent.exe | System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs |
X | Dial22 | dlm.exe | Adult content dialler |
X | Dial33 | dlm.exe | Adult content dialler |
X | Dialer | rundll32.exe msa32chk.dll | Unidentfied malware |
U | Dialer Control | dc.exe | Dialer-Control. Detects and protects from premium rate p0rn diallers |
U | Dialer Detect | dd.exe | DialerDetect detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it |
U | Dialgo SDK | PhoneAnswer.exe | Dialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis" |
X | DialNet | mxt32.exe | Adult content dialler |
N | Dialog Box Assistant | OSDEx.exe | Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders |
N | Dialog Helper | PDDLGHLP.EXE | Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs |
X | DIECOX | csrss.exe | Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | Diesel | Recalculate.exe | Added by the LAZAR TROJAN! |
U | DietK | DietK.exe | DietK - add-on for Kazaa Media Desktop; "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results" |
U | DigiCell | DigiCell.exe | MSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center" |
X | DigiD | DigitalSound.exe | Adware downloader |
N | DigiGuide | CLIENT.EXE | TV guide and reminder |
N | DigiGuide | client01.exe | TV guide and reminder |
N | Digital Dashboard | devgulp.exe | For Compaq PC's. Loads Digital Dashboard options |
N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems |
N | Digital River eBot | downlo~1.exe | Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here |
X | DigitalNames | DigitalNamesStart.exe | DigitalNames spyware variant |
N | DigitalWizard | ISWizard.exe | InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content |
N | DigitalWizard Monitor | dwMon.exe | InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content |
N | DIGStream | digstream.exe | DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically |
U | Dimension | Dimension.exe | Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol |
U | Dimension4 | d4.exe | Dimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down |
X | Dino3 | dino3.exe | Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result |
X | Dir1 | caKe | Added by the CAKE WORM! |
X | Direct settings | sdchost.exe | Added by the DAEMONI-I TROJAN! |
U | Direct Update | DUControl.exe | DirectUpdate dynamic DNS updater |
X | Direct X Direct3D | dxd3d.exe | Added by a variant of the SDBOT WORM! |
X | Direct X Opengl | dxopengl.exe | Added by a variant of the RBOT-CJ WORM! |
N | DirectCD | DirectCD.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
X | directs.exe | directs.exe | Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS! |
U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually |
X | DirectX | ddhelp32.exe | Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe |
X | directx | Directx.exe | Added by the SDBOT.D TROJAN! |
X | directx | Sqlexploit.exe | Added by the SDBOT.D TROJAN! |
X | DirectX | DirectX.exe | Added by the BLAXE or LOGPOLE WORMS! |
X | directx | NTCmd.exe | Added by the SDBOT.D TROJAN! |
X | directx | PipeCmd.exe | Added by the SDBOT.D TROJAN! |
X | DirectX For Microsoft Windows | dtxservice.exe | Added by the PROGENT TROJAN! |
X | DirectX for Microsoft Windows | Fservice.exe | Added by the PRORAT TROJAN! |
X | DirectX for Microsoft Windows | Sservice.exe | Added by the PRORAT TROJAN! |
X | DirectX Video Driver | dxterm5.exe | Added by the WILAB-A TROJAN! |
X | DirectX64 | DirectXset.exe | Added by the BROWNEY.A WORM! |
U | Dirkey | Dirkey.exe | Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders |
? | Disable EHCI | nousb20.exe | ?? |
N | Disc Detector | CtNotify.exe | For Creative sound cards. Detects when you insert a CD, DVD, etc |
? | disc detector | qnetquestnotifty.exe | ?? |
? | discoveg | discoveg.exe | ?? |
N | DiscoverDeskshop | Deskshop.exe | Discover Deskshop - single use "virtual" credit card |
X | Disk Master | [trojan name] | Added by the DISTER TROJAN! - a spam relayer |
N | DiskeeperSystray | DkIcon.exe | DisKeeper defragmentation software - can be started manually |
X | diskinf | diskinf.exe | Added by the CRYPTER.A TROJAN! |
? | DISKMON.EXE | DISKMON.EXE | ?? |
N | Disknag | disknag.exe | Dell program that reminds you to make your backup diskettes |
X | Diskstart | Code.exe | Adult content dialler |
X | Diskstart | cat.exe | MS-Connect dialler |
X | Diskstart | hit.exe | Adult content dialler |
X | Diskstart | Snt.exe | Adult content dialler |
U | Disk_Monitor | Disk_Monitor.exe | Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader |
X | Display Drivers | cssrs.exe | Added by the AGOBOT.FX WORM! |
N | Display Settings | hptasks.exe | Allows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers |
N | DisplayTrayIcon | TrayIcon.exe | System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display |
N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs |
X | Distributed File System | Dfsvc.exe | Added by the MYFIP.A or MYFIP.K WORMS! |
X | Distributed File System | kernel32dll.exe | Added by the MYFIP-C or MYFIP.K WORMS! |
U | distributed.net client | DNETC.EXE | Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses |
Y | Dit | dit.exe | "Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found |
N | DiTask.exe | DiTask.exe | Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs |
? | Divamon.exe | Divamon.exe | Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required? |
X | DivX MediaPlayer 7.0 | Dr.DivX.exe | Added by the ALADINZ.G TROJAN! |
X | DivX Player | DivXPlayer.exe | Added by a variant of the RBOT WORM! |
X | DivX Updater | DivX.Exe | Added by the NALDEM TROJAN or MASTAK VIRUS! |
X | Divx4 codec | devldr32.exe | Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file |
N | DJREGFIX | regedit /s c:hpdjregfix.reg | DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers |
Y | DkService | DkService.exe | From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually. |
X | DKTime | dktime.exe | Added by the LUNII TROJAN! |
X | Dkware lptt01 | dkware.exe | Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Dkware ml097e | dkware.exe | Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
? | dkzzixm | dkzzixm.exe | ?? |
Y | dla | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
N | DlaTray | Dlatray.exe | System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
X | dlder | dlder.exe | Advertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see here). Reported in the past as a virus |
X | DlDir1 | caKe | Added by the CAKE WORM! |
? | DLForcerExe | DLForcerEXE.exe | ?? |
N | DLF_00000B00 | Vcdlf.exe | Known to cause problems with "Out of memory" errors (see here). Otherwise, it's purpose is unknown |
N | DLG | DLGCHBW.exe | Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates |
N | DLHelperEXE | WATCH.exe | Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished |
X | DLHelperEXE.exe | N/A | Downloader for Microgaming/Casino software - stealth installed |
X | Dlite | dllmanager.exe | Added by the WOOTBOT.DN WORM! |
X | DLL Service Manager | [path to worm] | Added by the RPCBOT.F TROJAN! |
X | DLL32 | dllmem32.exe | Added by the KWBOT.E WORM! |
X | DllCacherv2 | dllcachev2.exe | Added by the LATEDA TROJAN! |
X | dlldmt | dlldmt.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | dllhelp | dllhelp.exe | Added by the STARTPAGE.DQ hijacker |
X | dllhelp | dllhlp.exe | Added by the Downloader-HI TROJAN! |
X | dllhostxp.exe | dllhostxp.exe | Browser hijacker and adware downloader |
X | dllreg | dllreg.exe | Added by the CRYPTER.A TROJAN! |
X | DLLService32 | dllsvc32.exe | Added by the AGOBOT.VX WORM! |
? | DLT | dlt.exe | ?? |
X | dluca | dluca.exe | Adult content dialler - see here |
X | dluca | dluca.exe | Added by the DLUCA.C TROJAN! |
X | dluxde | dluxde.exe | All-In-One-Telcom (adult content dialler) variant |
X | Dluxjp | cnfrm.exe | Added by the DLUCA.D TROJAN! |
X | DM mgr | dm_mgr.exe | Added by the JITTAR TROJAN! |
N | DMILDR | dmildr.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs |
N | DMISL | DMISL.EXE | DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information |
N | DMISLAPP | DMISLAPP.exe | DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information |
X | Dmsvc32 | Dmsvc32.exe | Added by the AGOBOT.ABU WORM! |
X | dmtdll | dmtdll.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | DM_server | dmserver.exe | Comet Cursor adware |
X | Dnar | Dnar.exe | Unknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here |
Y | DNE Binding Watchdog | rundll dnes.dll, DnDneCheckBindings | Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work |
Y | DNE DUN Watchdog | rundll dnes.dll, DnDneCheckDUN13 | Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work |
X | Dns Resolver | dnsrslve.exe | Added by the RBOT-WS WORM! |
X | DNS Service | dnsresolver.exe | Added by the RBOT-PQ WORM! |
? | DNS2GoClient | dns2goclient.exe | DNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required? |
X | dnscleaner | dnscleaner.exe | CoolWebSearch parasite related |
? | DNXVC | dnxvc.exe | ?? |
X | DocTor | Doctor.exe | Added by the DOTOR.A WORM! |
N | DocuMagix Init | PWATCH.EXE | PaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed |
X | DOGStart | GSDOGST.EXE | Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS |
? | Doing | doing.exe | ?? |
U | Don't Panic | dontpanicdemodp.exe | 30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite." |
U | Don't Panic Pop-Up Stopper | dpps2.exe | Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group |
X | dos | dos64.exe | Adware downloader trojan |
? | Dosbat | ?? | ?? |
N | DoUWantIt | duwi.exe | DoUWantIt - online shopping assistant. Start it manually |
X | down | hlp32.exe | Added by the DLOADER.BG TROJAN! |
N | Download Accelerator Plus 5.0 | DAP.exe | Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based |
X | Download Plus | DownloadPlus.exe | DownloadPlus parasite - opens pop-up adverts |
N | Download Wonder | DownloadWonder.exe | Download Wonder from Forty Software. Download manager for resuming downloads, amongst other features |
N | DownloadAccelerator | DAP.EXE | Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based |
X | DownloadLegalMusic | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
X | DownloadWare | dw.exe | DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent |
X | DownloadWare Engine | Dwe.exe | DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent |
X | Downxz | Downxz.bat | Added by the MYDOOM.W WORM |
N | DPAgnt | DPAgnt.exe | digitalPersona fingerprint scanner |
Y | Dpcnav | dpcnav.exe | DirecWay from DirectTV satellite based high-speed internet access |
X | dpcproxy | dpcproxy.exe | Added by the GOLDENP-A TROJAN! |
Y | DPCProxyLoadOnStartup | dpcstart.exe | DirecWay from DirectTV satellite based high-speed internet access |
Y | Dpcstart | dpcstart.exe | DirecWay from DirectTV satellite based high-speed internet access. Proxy software |
U | Dpcstart | dpcstart.exe | Startup program for Direcway 2-way satellite internet service. Loads DirecWay's Navigator, tray icon, etc |
X | dpi | dpi.exe | Delfin Media Viewer or "Promulgate" adware |
U | dpps2 | dpps2.exe | Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group |
X | dps | dps.exe | scumware-remover.org foistware, bogus adware/spyware remover, is in fact itself a browser hijacker, redirecting to smartestsearch.com |
N | Drag'n'Drop_Autolaunch | Autolaunch.exe | Iomega HotBurn - CD-RW burning software |
? | DragDrop | DragDrop.exe | ?? |
N | DragnDrop_Autolaunch | Autolaunch.exe | Iomega HotBurn - CD-RW burning software |
? | dregfix | ph_finder.exe | ?? |
N | DrgToDsc | DrgToDsc.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly |
? | dried.exe | dried.exe | ?? |
N | DriveLED | OODLed.exe | O&O DriveLED - displays your HDD LED on your monitor. Start manually |
X | Driver | gbot.exe | Added by the JUNTADOR.K TROJAN! |
X | Driver32 | Scam32.exe | Added by the SIRCAM WORM! |
N | DriveSelect | driveselect.exe | DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs |
U | dRMON SmartAgent | SmartAgt.exe | Part of the network monitoring program group for 3Com NIC cards. See here for more info |
X | drmu | W95Mm.exe | Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread |
X | drocher | d.exe | Adult content dialler |
X | drvddll.exe | drvddll.exe | Added by the BEAGLE.AP WORM! |
X | Drvddll_exe | drvddll.exe | Added by the BEAGLE.X WORM! |
? | DrvListnr | DrvListnr.exe | Analog Devices SoundMAX soundcard related. What does it do and is it required? |
U | drvlsnr | drvlsnr.exe | Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly |
X | drvr32h | drvr32h.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | drvrmanager | drvrquery32.exe | Added by the BOOHOO WORM! |
X | drvsys.exe | drvsys.exe | Added by the BEAGLE.W WORM! |
X | drvupd | rundll32 ..drvupd.inf | Hijacker - drvupd.inf file installs a "searchforge.com" hijack |
Y | Drwebscheduler | Drwebscd.exe | Dr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem |
X | DR_S | DR_S.exe | AdShooter adware |
U | DS Clock | dsclock.exe | Digital desktop clock including synchronization with atomic servers - see here |
X | dsa | dsa.exe | Homepage hijacker - redirecting to downseek.com |
X | DSAcass | [path to file] | Added by the RANKY.M TROJAN! |
X | DSB | DSB.exe | EnergyPlugin adware |
N | DSentry | DSentry.exe | Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts |
X | Dsi | dp-******.exe | Added by an unidentified adware where ****** are random characters |
X | Dskcompat | Dskcompat.exe | Added by the GEMA TROJAN! |
N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray |
Y | DSLagentexe | DSLagent.exe | Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection |
Y | dslmon | dslmon.exe | Sagem DSL modem related. Apparently needed to detect the modem |
U | DSLSTATEXE | dslstat.exe | System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example) |
X | DsmSer | dsm.exe | Added by the SERFLOG.B WORM! |
X | DsmSer | msmpatch.exe | Added by the SERFLOG.B WORM! |
X | DsmSer | svosm.exe | Added by the SERFLOG.B WORM! |
X | DsmSer | sysup.exe | Added by the SERFLOG.B WORM! |
X | DSS | dssagent.exe | DSSAgent by Brřderbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info |
X | DSService | dmrss.exe | Added by the AGOBOT-XX WORM! |
? | DSSSGENS | dssagens.exe | ?? |
N | DU Meter | DUMETER.EXE | Hagel Technologies internet bandwidth monitor |
N | dumprep 0 -k | dumprep 0 -k | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
U | dumprep 0 -u | dumprep 0 -u | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
N | dvd43 | DVD43_Tray.exe | DVD43 is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies" |
X | dvd98 | windvd98.exe | Added by the CULT.P WORM! |
U | DVDBitSet | DVDBitSet.exe | DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used |
X | Dvdcompat | Dvdcompat.exe | Added by the GEMA TROJAN! |
N | DVDLauncher | DVDLauncher.exe | A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use |
N | DVDSentry | DSentry.exe | Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts |
? | DVDTray | DVDTray.exe | HP CD/DVD Tray icon. What does it do, and is it required |
? | DVDUpgrade | DVDUpgrd.exe | ?? |
Y | Dvp95 | Dvp95.exe | Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine |
Y | dvpapi9x | DVPAPI9X.exe | Command AntiVirus for Windows 95/98/Me |
Y | DvpInitExe | Dvpinit.exe | Command Antivirus related |
Y | dvprpt | Dvprpt.exe | Command Antivirus real time protection |
X | dvraudio | dvraudio.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | dvsfss | fbsfsdrs.exe | Added by the SDBOT-QA WORM! |
U | DVSync | dvsync.exe | DVSync is the program that allows you to synchronize your daVinci’s PDA's data with your Personal Information Manager on the PC |
X | Dvx | wsxsvc.exe | Delfin Media Viewer or "Promulgate" adware variant |
X | dw | dw.exe | DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent |
U | DWHeartbeatMonitor | DWHeartbeatMonitor.exe | DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference |
N | DwlClient | support.exe | Download manager for Dell support alerts |
X | Dx | sys*.exe [* = random number] | Added by the DEXTER.A WORM! |
X | Dx8compat | Dx8compat.exe | Added by the GEMA TROJAN! |
X | dxdll32 | ntxdll.exe | Added by the GAOBOT.CPX WORM! |
N | DXDllRegExe | dxdllreg.exe | Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it |
X | DxLoad | DX3DRndr.exe | Added by the GIBE.B WORM! |
N | DXM6Patch_981116 | p_981116.exe | Win32 cabinet self extractor. More info here |
X | Dxsty | Dxsty.exe | Added by the GEMA TROJAN! |
X | Dxupdate.exe | Dxupdate.exe | Added by the MAFEG WORM! |
X | DyFuCA | optimize.exe | Adult content dialler - see here |
X | DyFuCA Active Alert | actalert.exe | Adult content dialler - see here |
X | Dynamic Dns Binary | dynitora.exe | Added by the RBOT-WT WORM! |
N | DynDNS-Updater Traytool | ddutray.exe | DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually |
U | Dynu Basic Client | dynubas.exe | Dynu online dynamic IP update client. Useful when using a dial up modem |
? | DZKillMe | DZSAVEME.EXE | ?? |
X | E-Card | ecard.exe | Added by the YODI WORM! |
U | E-color | IconMgr.Exe | Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program |
N | E6TaskPanel | TaskPanl.exe | Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space |
U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys |
X | Eac Download | download.exe | Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here |
U | EACLEAN | eaclean.exe | For Compaq PC's. Easy Access button support for the keyboard |
X | Eac_Cnry | canary.exe | Added by the CANARY TROJAN! |
? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | ?? |
X | EanthologyApp | EANTHO~1.EXE | eAcceleration Stop-Sign related - not recommended, see note |
N | EanthologyApp | eanthology.exe | eAcceleration Stop-Sign related - not recommended, see note |
X | eanth_critical_update_alert | sys_alert.exe | eAcceleration Stop-Sign related - not recommended, see note |
N | eanth_system_patcher | sys_alert.exe | eAcceleration Stop-Sign related - not recommended, see note |
N | Eapcisetup | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it |
N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation |
N | EarthLink ToolBar 5.0 | etoolbar.exe | EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time |
U | Easy Key | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used |
N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys |
X | EasyAV | EasyAV.exe | Added by the NETSKY.S or NETSKY.T WORMS! |
X | EasyDates | EasyDates.exe | Premium rate adult content dialler |
X | EasyDates_nl | EasyDates_nl.exe | Adult content dialler |
U | EasyKey | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used |
U | EasyMessage | em2.exe | Easy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here |
X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader |
X | easyServ | Server.exe | Added by the EASYSERV TROJAN! |
U | EasySync Pro | XCPCMenu.exe | EasySync Pro is a Lotus program for synchronizing a PDA with Lotus Notes |
U | EasyTuneIII | EasyTune.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available |
U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available |
X | easywww | easywww2.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | EbatesMoeMoneyMaker | wjview ...Code | Ebates adware |
X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | Ebates adware |
X | eBay Toolbar | EBAYTBAR.EXE | eBay Toolbar - reportes as spyware as it "phones home" |
U | eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys |
N | eBot | DownloadWizard.exe | eBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs |
? | ecpe | ECPE.EXE | ?? |
? | edexter | edexter.exe | ?? |
X | editpad | editpad.exe | Added by the CONSPER-B TROJAN! |
N | EDLoader | DTLoader.exe | Effective Desktop from MiniStars Software - desktop management software no longer being supported |
U | EDRestore | ?? | Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP" |
X | educational writer | [random filename] | Added by the RBOT-LZ WORM! |
U | Edwizard | Edwizard.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
N | eFax.com Tray Menu | HotTray.exe | eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here |
X | efaxs lptt01 | efaxs.exe | Variant of the RapidBlaster parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | efaxs ml097e | efaxs.exe | Variant of the RapidBlaster parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
U | Efpap.exe | Efpap.exe | Easy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching |
? | ehTray | ehtray.exe | eHome Media Center PC related - what does it do and is it required? |
X | ei10.exe | ei10.exe | Added by the AGOBOT-NK WORM! |
U | Eicon NetworksLAN_DAEMON | watch.exe | Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
U | Eicon TechnologyLAN_DAEMON | watch.exe | Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually |
X | eixfi | china.bat | Added by the WCUP.A WORM! |
U | Elbycheck | ElbyCheck.exe | From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it |
U | Electron Microscope | EMIII.exe | Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home, FAH. It will monitor up to 50 clients and give you the details about each client's progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues |
X | Element | Element.txt | Added by the ELEM TROJAN! |
N | elm | Elmenv.exe | ViaTech eLicense for securing, distributing and selling music online |
U | ELSA WINman Suite | Winmsuit.exe | Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU |
Y | ElsaCapiCtl | Rcapi.exe | Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem |
U | ELSAChipGuard | elsavect.exe | ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking |
N | EMA.exe | EMA.EXE | Time management system which helps you to manage your time and appointments |
U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys |
X | emsw.exe | emsw.exe | Attune HelpExpress - spyware. Disable and uninstall - see here |
N | eMusicClient Systray | eMusicClient.exe | eMusic MP3 download software |
U | EM_EXEC | EM_EXEC.EXE | Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled |
N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray |
? | encapsulated command tool | wintr.com | ?? |
N | Encarta Dictionary Quickshelf | QSHLFED.EXE | Provides quick access to Encarta's Dictionary features? |
N | ENCMONITOR | monitor.exe | The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it |
N | Encoder Agent | WMENCAGT.EXE | MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed |
U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass) |
? | ENCSurf | surfboard.exe | ?? |
U | Energizer FileSaver | Energizer FileSaver.exe | Energizer FileSaver - UPS back-up utility for Energizer UPS products |
Y | EngUtil | EngUtil.exe | Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking |
X | Enh Win Updt | enhupdt.exe | Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h |
X | enhance32 | enhance32.exe | Added by the CRYPTER.A TROJAN! |
N | EnigmaPopupStop | EnigmaPopupStop.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
? | ENSApServer2_0 | APSERVER.EXE | Intel AnyPoint Wireless II Home Network related. What does it do and is it required? |
? | ENSMIX32.EXE | ENSMIX32.EXE | Sound card driver. Is it required? |
U | EnsoniqMixer | starter.exe | Puts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility |
X | Enumerate Service | wsys.exe | Added by the MANIFEST TROJAN! |
U | eonemng | eOneMng.exe | eOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC |
U | ePrompter | ePrompter.exe | ePrompter - E-mail notification software |
N | EPS | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
N | EPS | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not |
U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint |
N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
U | EPSON Stylus C44 Series | E_S10IC2.EXE | Epson Stylus C44 Series printer monitor - for checking ink levels, etc |
U | EPSON Stylus C46 Series | E_S4I0T1.EXE | Epson Stylus C46 Series printer monitor - for checking ink levels, etc |
U | Epson Stylus C62 Series | E-S0BIC1.EXE | Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required |
U | Epson Stylus C82 Series | e_s0hic1.EXE | Required for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required |
U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this |
? | Equipmen | Equipmen.exe | ?? |
N | EReg | reg32.exe | EReg is a software registration tool incorporated on products such as those by Brřderbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it |
X | erghgjhgdr | windlhhl.exe | Added by the BEAGLE.BG WORM! |
X | erghgjhjgdr | windlhhl.exe | Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS! |
? | erm | erm.exe | ?? |
X | eros.exe | eros.exe | Adult content dailler |
X | ErrorGuard | ErrorGuard.exe | Spyware remover of dubious repute |
X | erthgdr | windll.exe | Added by the BEAGLE.AO or BEAGLE.AQ WORMS! |
? | ERTS0749 | ERTS0749.exe | IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire? |
Y | eSafe Protect | ESPWatch.exe | eSafe from Aladdin - internet security for gateway and E-mail servers |
U | ESB | esb.exe | Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys |
Y | eScan Monitor | AVKWCTL9X.EXE | eScan antivirus |
U | eScan Scheduler | avkserv.exe | eScan antivirus scheduler |
U | eScan Updater | Trayicos.exe | eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads |
X | EScorcher | escorcher.exe | Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
N | ESFTP | esftp.exe | ESftp - FTP client for transfering files between a local PC and another remote computer |
X | Esoh | Esoh123.exe | Added by the AGOBOT.FF WORM! |
N | ESPN BottomLine | bline.exe | ESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down." |
? | ESS Daemon | Essd.exe | Related to an ESS based soundacard. Is it required? |
? | essapm | essapm.exe | ESS Solo soundcard driver. Is it required? |
Y | Essdc | essdc.exe | Related to an ESS Solo soundcard. Seems as though it's required |
? | ESSNDSYS | ESSNDSYS.EXE | Related to an ESS based soundacard. Is it required? |
Y | ESSOLO | ESSOLO.exe | Sound card driver that re-instates itself every time it's removed |
Y | esspk | esspk.exe | ESS Technology modem speaker driver file. Required to get on-line with this modem |
U | EssSpkPhone | essspk.exe | ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets |
N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs |
X | Etraffic | JavaRun.exe | Marketing software from TopMoxie |
Y | eTrust EZ Firewall | efpeadm.exe | eTrust EZ Firewall |
U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | PestPatrol real-time protection feature. "Stops spyware before it infects your system" |
Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior |
U | EuroGlot | EuroGlot.exe | Euroglot - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian" |
? | Event Log | eventlog.exe | ?? |
N | Event Planner Reminders | PLNRnote.exe | Sierra Event Planner tray icon |
N | Event Reminder | pmremind.exe | A calendar/alarm program that installs with Brřderbund Printmaster |
U | EVENTLISTENER | EvLstnr.exe | Used with a Nikon digital camera to recognize when the camera is plugged in |
N | eventmgr | eventmgr.exe | Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs |
N | Evidence Eliminator | ee.exe | Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis |
N | evntsvc | evntsc.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version |
U | EVOLOSTA | EVOLOSTA.EXE | Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it |
X | EvtHtm | evthtm.exe | Premium rate adult content dialler |
U | EW Message Server | msg32.exe | Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices |
N | eWare Startup | iWareStart.exe | eWare iWare task bar. Not required |
X | ewupdater | ewupdater.exe | EasyWebSearch adware updater |
N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer |
? | Excite Private Messenger Pipe | x8impipe.exe | ?? |
N | ExciteAssistantEXE | ASSISTANT.EXE | With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open |
X | exdl.exe | exdl.exe | BargainBuddy foistware |
X | exe lptt01 | exe.exe | Variant of the RapidBlaster parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | exe ml097e | exe.exe | Variant of the RapidBlaster parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | execfg4 | execfg4.exe | Added by the ELECTRON WORM! |
? | Execute | delfolders.exe | ?? |
X | ExeName32 | Warm.scr | Added by the SCOLD WORM! |
? | exgiwsl | exgiwsl.exe | ?? |
U | Exif Launcher | Exiflaquickdcr.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly |
U | Exif Launcher | QuickDCF.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly |
U | ExitKiller | Ekiller.exe | Exit Killer - automatically closes pop-up windows in your browser |
? | exmon | hpimoniter.exe | Some kind of hp digital camera maybe or a photo smart connection probe? |
X | Explkw | expup.exe | Keywords hijacker |
X | explore | explore.exe | Added by any number of VIRUSES, WORMS or TROJANS! |
X | Explore | Explorer.exe | Added by the IRC.FLOOD.G TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | Explore | explore.exe | Adult content dialler |
X | explore.exe | Explore.exe | Added by the GRAYBIRD.G TROJAN! |
U | explorer | explorer.exe | Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL |
X | explorer | wscript.exe [filename] | Sneaky way to start any VBS script. Many viruses use VBS files |
X | Explorer | shellexpl.exe | Added by the GPIX and SHELDOR VIRUSES! |
X | explorer | expl32.exe | Added by the RATSOU TROJAN! |
X | Explorer | [path to worm] | Added by the AUTEX WORM! |
X | Explorer | shellexp.exe | Added by a variant of the SHELDOR TROJAN! |
X | Explorer lptt01 | explorer.exe | Variant of the RapidBlaster parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually! |
X | Explorer ml097e | explorer.exe | Variant of the RapidBlaster parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually! |
X | Explorer Updater | IEXPLORE.exe | Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | Explorer32 | Expl32.exe | Added by the HACKTACK.B TROJAN! |
U | Exshow95 | EXSHOW95.exe | Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices |
U | ExtraDNS | ExtraDNS.exe | ExtraDNS - DNS configuration tool |
? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software |
? | ExxtremeHelperDemon | exxdemon.exe | Creative Exxtreme graphics card related? |
N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper |
N | ezagent | ezagent.exe | EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs |
N | EZDesk | EZDESK.EXE | Utility that remembers icon locations for each user and resolution. Available here |
N | EzEjMnAp | EzEjMnAp.exe | For IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs |
X | eZmmod | mmod.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
? | EZNORUN | EZNORUN.EXE | Easy Internet related? |
Y | ezPS_Px | ezSP_PxEngine.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
Y | ezPS_Px | ezSP_Px.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
Y | ezShieldProtector for Px | ezSP_Px.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
Y | ezShieldProtector for Px | ezSP_PxEngine.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported |
X | ezula | eZmmod.exe | Regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
X | eZulaMain | eZulaMain.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
X | eZuluMain | eZuluMain.exe | Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work |
X | eZWO | wo.exe | Ezula "Web Offer" foistware |
U | E_S10IC2 | E_S10IC2.exe | Epson Stylus C44 Series printer monitor - for checking ink levels, etc |
U | E_S23 | E_SICN03.exe | Epson printer status monitor - for checking ink levels, etc. |
N | E_S4I2F1 | E_S4I2F1.exe | Epson Status Monitor 3 for the Epson Stylus Photo R300 (and probably others) printers - monitors the status of a print job spooled to that printer |
? | E_S4I2G1 | E_S4I2G1.EXE | Related to the Epson Stylus CX5400 printer/scanner/copier. What does it do and is it required? |
U | E_SOEIC1 | E_SOEIC1.exe | Epson Stylus printer monitor - for checking ink levels, etc. |
U | F-Secure Management Agent | FSMA32.EXE | F-Secure Antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products |
Y | F-Secure Manager | FSM32.EXE | F-Secure Antivirus - carry out scheduled virus scans automatically |
Y | F-Secure Startup Wizard | FSSW.EXE | F-Secure antivirus |
Y | F-Secure TNB | TNBUtil.exe | F-Secure antivirus |
Y | F-StopW | F-StopW.exe | F-Prot anti-virus background scanner by F-Risk Software |
U | f1Tray.exe | F1TRAY.EXE | System Tray icon for FusionOne’s MightyPhone software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer" |
X | f607 | f607.exe | Added by the URAT.B TROJAN! |
U | FamilyKeyLogger | cisvc.exe | "Family Keylogger - is your best choice, if you want to know what other users on your machine are typing". Note! - this is not the cisvc.exe service. |
? | fapmon | fapmon.exe | Fair Access Policy monitor for DirecPC/DirecWay internet access |
X | farmmext | farmmext.exe | Transponder parasite updater/installer |
X | Fash | Fash.exe | Unidentified adware |
N | fast | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys |
N | FAST Defrag | FAST2.EXE | FastDefrag defragmenting software |
X | Fast start | Ntut.exe | Added by unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i |
U | FastCache | fc.exe | FastCache from AnalogX - speeds up browsing by resolving DNS requests locally |
X | FastStart | ntnut32.exe | Added by the Startpage.L hijacker |
N | FastTrack Accelerator | SPEED UP.EXE | FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus |
N | FastUser | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys |
N | FastUsr | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys |
U | FatPipe | DHCP | Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users |
U | Fatpipe Dialer | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users |
U | FaxCenterServer | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others |
U | FBDirect | FBDirect.exe | Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs |
? | FBI | FBISM.exe | Compaq related but what does it do? |
X | fc | runfc.exe | Added by the CAMPURF WORM! |
? | FD_SAP | FD.exe | Genicom SAP Printer driver. Is it required? |
U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals) |
X | fegoze | SVCH0ST.EXE | Added by the GRAYBIRD.D TROJAN! |
U | Fellowes Proxy | R3proxy.exe | Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice |
X | Fen Startups | fensvc32.exe | Added by the RANDEX.CCF WORM! |
U | FerrariWallPaper | FerrariWP.exe | Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com |
X | ffis | ffisearch.exe | iSearch "Desktop Search" hijacker |
U | FG1_00 | frntgate.exe | FrontGate MX - e-mail spam blocker |
X | fGQEGqHOME | gwwgtp.exe | Added by the RANKY.J TROJAN! |
U | Fhtisxk | fhtisxk.exe | XtraKeys - keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove via Spybot S&D (for example) |
U | FieldForms Sync | SyncService.exe | Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well |
X | FiendlyType | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
? | file indexing service | msfindfile.exe | New version of MS FindFast and still a resource hog? |
X | File System Service | wmiprvsc.exe | Added by the AGOBOT-HZ TROJAN! |
N | FileFreedom_Plugin | wtm.exe | FileFreedom peer-to-peer sharing program |
X | FileManager32 | Wscript.exe ..ChkMgr32.vbs | Added by the NOTUP.A WORM! |
X | FileSoft | Wscript.exe UpdataFiles.vbs | Added by the SST.B WORM! |
U | FilterGate | filtergate.exe | Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items |
U | Filterguard | Filtrgrd.exe | An icon located in the lower left of the screen and looks like a lifesaver. This icon is a “short-cut” to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by “right-clicking” on the icon |
X | Find Fast | Findfast.exe | Complete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier |
Y | Find Virus Launch Program | fvlaunch.exe | Part of Dr. Solomon's Antivirus |
N | FinePrint Dispatcher vx | FPDISPxA.EXE | FinePrint - virtual printer for use with any printer. Search for "dispatcher" here for more information. If removed, it will re-install when program is run - hence the Y recommendation |
N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | ABBYY FineReader OCR software |
X | Firewall | wmlaunch .exe | Added by the ELIPTER.A WORM! |
X | Firewall | wmlaunch .exe | Added by the ELIPTER.D WORM! |
X | FirewallSvr | FirewallSvr.exe | Added by the NETSKY.X or NETSKY.Y WORMS! |
X | FireWire Driver | samx.exe | Added by the SDBOT.AE WORM! |
X | First Home Page | http://find.naupoint.com | Naupoint browser hijacker |
Y | Fix-it | mxtask.exe | Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required |
Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources |
N | fkSysMon | fksysmon.exe | fkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more" |
? | FLASH32 | -flash32.exe | ?? |
N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
N | FlashPath Status | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
U | Flexicd | Flexicd.exe | CD player - part of the Win95 Power Toys |
U | FLMK08KB | MMKEYBD.EXE | Multimedia keyboard manager. Required if you use the additional keys |
? | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. What does it do and is it required? |
? | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand mouse. What does it do and is it required? |
X | FLooDNeT | FLooDeR.exe | Added by of the ENDOOL TROJAN! |
? | Flow Go TV | flogotv.exe | ?? |
X | flps | flps.vbs | Added by the BYRON WORM! |
X | flpycntl | flpycntl.exe | Added by the CRYPTER.C TROJAN! |
? | FLSVCI | FLSVCI.exe | ?? |
Y | FltProcess | msinet.exe | Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done |
X | FlyswatDesktop | flydesk.exe | Advertising spyware |
U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used) |
X | fmnwebassist | fmnwebassist.exe | Adware popup generator |
U | FMStart | Fmstart.exe | GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop |
X | FMSZ | fmsz.exe | Added by the FMSZ TROJAN! |
X | fnmwebassist | fnmwebassist.exe | WinPL adware |
? | Focus | Focus.exe | ISDN configuration wizard? |
X | Folder Service | wssdtu.exe | Added by the MANIFEST TROJAN! |
N | Folding@home | WINFAH.EXE | Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs |
N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required |
X | FontFix | fontfix.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | FONTVIEW | FONTVIEW.EXE | Added by the OPASERV.T WORM! |
X | foobin lptt01 | adaware.exe | Variant of the RapidBlaster parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | foobin ml097e | adaware.exe | Variant of the RapidBlaster parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
Y | FoolProof | fpwinldr.exe | FoolProof Security PC security software from SmartStuff |
Y | FoolProofSweep | ?? | Part of FoolProof Security PC security software from SmartStuff |
N | Forbes | ForbesAlerts.exe | Forbes Business News Alerts - displays business news headlines in a little window on the screen |
X | ForceShow | rundll32.exe QaBar.dll, ForceShowBar | AdultLinks/QAbar parasite related |
N | Forget Me Not | AGRemind.exe | Calendar reminder part of American Greetings® CreataCard® |
N | FotoStation Easy AutoLaunch | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either |
U | Foul PX | FoulPX.exe | Foul PX, Optusnet usage stat checker |
U | FourthDay | FourthDay.exe | The Fourth Day - "astronomical clock and almanac for your system tray" |
Y | FP Loader | loadfp.exe | FoolProof Security - PC security software from SmartStuff |
? | FPWGMWZD | FPWGMWZD.exe | ?? |
N | Fpx | mnmsrvc.exe | Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations |
X | France | svchost.exe | Added by the MIMAIL.L WORM!. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
U | Fraps | fraps.exe | Fraps Real-Time Video Capture software |
N | Free Download Manager | fdm.exe | "Free Download Manager" - see here |
? | Free Downloads Monitor | fdcmon.exe | ?? |
Y | Freedom | Freedom.exe | Zero Knowledge Freedom - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more |
U | FreeMem Pro | FMEMPRO.EXE | Some users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind |
U | FreeMemVn2 | FreeMem.exe | Some users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind |
X | FreeMP3download | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
U | FreeRAM XP | FreeRAM XP Pro x.exe | Some users swear by memory management utilities such as FreeRAM XP Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind. "x" indicates the version number |
U | freesurfer | fs20.exe | EMS Free Surfer mk II - pop-up stopper |
U | Fresh Desktop | freshdesktop.exe | Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals |
N | freshclam | freshclam.exe | Auto update agent of the open source Clamwin virus scanner |
? | frguk | shdrkmck.exe | ?? |
? | FridaysInHellInstaller | FridaysInHellInstaller.exe | ?? |
X | FriendlyType | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
X | FriendlyTypeName | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | FriendlyTypeName | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well |
U | FRISK FP-Scheduler | F-Sched.exe | Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis |
N | Fromine WinPopup | winpopup.exe | Instant Messenger program |
X | Frsk | frsk.exe | Unidentified adware downloader trojan |
Y | FRW_EXE | FRW.EXE | ConSeal Signal9 firewall - now McAfee Personal firewall |
Y | frxmxins | frxmxins.exe | ATI 3D Studio MAX/VIZ driver |
N | FSCBoss | FSCBoss.exe | Free Store Club shop online software |
? | FSDPSRV | FSDPSRV.exe | ?? |
? | fsg_4104.exe | fsg_4104.exe | Installed with Kazaa and believed to be Gator adware? |
U | fsp | fsp.exe | Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents |
Y | fspr | FolderShield.exe | Folder Shield - hide personal files and folders |
N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver" |
U | fsserv | fserv.exe | Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time |
X | FSW | FSW.exe | FreeScratchAndWin parasite |
U | FTMSFLT(USB) | FTMSFLTU.EXE | Fujitsu's Touch Panel Message Notifier |
X | FTPGraber | FTPGraber.exe | Added by the DLOADER-DT TROJAN! |
U | Ftpqueue | Ftpsched.exe | Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers |
X | fukerservice | fukerz.exe | Added by a variant of the RBOT WORM! |
Y | fwenc.exe | fwenc.exe | Check Point SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers" |
X | Fwr Command Module | fwr.exe | Added by the SDBOT-PP WORM! |
N | fwrastrc | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP |
X | fwservice | fwservice | eAcceleration Stop-Sign related - not recommended, see note |
X | FX | ieloader.exe | Added by the SMALL.RR TROJAN! |
U | fxredir | fxredir.exe | Canon MultiPASS fax redirector |
X | f~a | ra32.exe | Added by the CAY TROJAN! |
X | G00123 | [worm filename] | Added by the BUGBROS WORM! |
? | g3dctl | g3dctl.exe | ?? |
N | Gadu-Gadu | gg.exe | Polish language Instant Messaging client |
N | Gadwin PrintScreen | PrintScreen.exe | Gadwin PrintScreen - utility to capture, print or save the current window |
U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel |
N | Game Device | JOYUPDRV.EXE | Genius game controller profile activator |
X | Games Acceleration | svshost.exe | EasySearch adware |
X | Games toolbar | rundll32.exe [path] tbGame.dll, DllShowTB | Topconverting.com180Search "Games Toolbar" adware |
N | GameSpot | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
U | gameutil.exe | gameutil.exe | Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot |
U | GammaHotKeys | setgamma.exe | Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop |
X | Gator | gator.exe | Spyware - see here for removal instructions |
X | Gator eWallet | gator.exe | Gator eWallet from The Gator Corporation. Spyware - see here for removal instructions |
X | Gay_Sexy_** | Gay_Sexy_**.exe | Premium rate adult content dialler (where * is a random char) |
U | GazelDisplay | gsyno.exe | BT Digital Access USB - Gazel ISDN installation System Tray icon |
U | GBTray | GBTray.exe | System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
U | gcasDtServ | gcasDtServ.exe | Giant Antipsyware - now superseeded by Microsoft Windows AntiSpyware |
U | gcasServ | gcasServ.exe | Giant Antipsyware - now superseeded by Microsoft Windows AntiSpyware |
? | GCC Reminder | gccrem.exe | Associated with AcraMax Greeting Card Creator. Is it a registration reminder? |
N | GCS | GrabClipSave.exe | GrabClipSave screen capture tool |
X | GDAX | [path to backdoor] | Added by the RANKY.K TROJAN! |
N | GDrive | GDriver.exe | Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager |
N | Gearbox | confsvr.exe | NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here |
N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player |
X | GEDZAC | GEDZAC.exe | Added by the GEMEL WORM! |
N | GemStRmW | GemStRmW.exe | For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually |
U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives |
X | general lptt01 | general.exe | Variant of the RapidBlaster parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | general ml097e | general.exe | Variant of the RapidBlaster parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Generic host proccess for windows | SVCHOSTS.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Generic Host Process | SCHOST.EXE | Added by the RBOT-NC WORM! |
X | Generic Host Process for Win32 Services | ntspcv.exe | Added by the SDBOT.S TROJAN! |
X | Generic Host Process for Win32 Services | intspvc.exe | Added by the DINFOR.D WORM! |
X | Generic Host Process for Win32 Services | winsvc.exe | Added by the SDBOT-O WORM! |
X | Generic Host Process for Win32 Services | bazzi.exe | Added by the AHKER.E WORM! |
X | Generic Host Service | lshost.exe | Added by the RBOT.LU WORM! |
X | Generic Service Process | regsvc32.exe | Added by the GAOBOT.UJ or GAOBOT.UL WORMS! |
X | Generic Services Process | regsvc32.exe | Added by the GAOBOT.SY WORM! |
Y | Genie USB Monitor | USBmonitor.exe | Port monitor for an external USB hard drive. Required to enable access to the drive |
N | Get Smile | getsmile.exe | Puts smilie faces in your E-mail. Run manually when required |
N | GetRight Tray Icon | GETRIGHT.EXE | GetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs |
X | GetTheMusic | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
N | GhostStartService | GhostStartService.exe | Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard |
N | GhostStartTrayApp | GhostStartTrayApp.exe | System Tray access to Norton Ghost - added from the 2003 version |
? | GhostSurfDelSatellite | DeleteSatellite.exe | SpyCatcher spyware remover related. What does it do and is it required? |
X | gigabit.exe | gigabit.exe | Added by the BEAGLE.U WORM! |
X | GigaByte | Cheatle.exe | Added by the SHODI.B VIRUS! |
Y | Gilat SOM Enumerator | dllhost.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
Y | GilatFTC | ftc.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
X | GinaDll | ntgina.dll | Added by the ANIG.A WORM! |
? | GisdnLog | gisdnlog.exe | BT Digital Access USB |
U | Glass2k | Glass2k.exe | "Glass2k is a small little program that allows Win2K/XP users to make any window transparent" |
Y | Glide | Glidew32.exe | Cirque touchpad driver |
X | GLSetIT32 | msiexec16.exe | Added by the OPTIX PRO TROJAN! |
X | GLSetIT32 | isass.exe | Added by a variant of the OPTIX PRO TROJAN! |
X | GLSetT32 | smsiexec.exe | Added by the OPTIX-D TROJAN! |
? | gluon | gluon.exe | In a gluon/bin sub-directory |
Y | Gmouse | Gmouse.exe | Amouse mouse driver - required if you use non-standard Windows driver features |
U | Gnetmous | gnetmous.exe | Genius NetScroll+ mouse driver - required if you use non-standard Windows driver features |
? | gnub | gnub.exe | ?? |
X | Go!Zilla | gozilla.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware |
X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware |
U | GoBack | GBMenu.exe | Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
U | GoBack | GBTray.exe | System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
U | GoBack Polling Service | GBPoll.exe | Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
U | GoBack Tray Icon | GBTray.exe | System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
X | GOG | GOG.exe | Added by the PHILIS.B VIRUS! |
U | Goldensoft_MndlSvr | MndlSvr.exe | Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking |
X | golumm | services.exe | CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
N | Google Desktop Search | GoogleDesktop.exe | Google Desktop Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks" |
N | GoogleDCClient | GoogleDCC.exe | Google Compute Client - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing" |
U | GoToMyPC | g2svc.exe | ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser |
X | gouday.exe | readme.exe | Added by the BEAGLE.C WORM! |
N | GRA | gra.exe | Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility |
? | gramdate | 2Stop.exe | ?? |
U | Gravis Appawareloader | dbserver.exe | Looks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them |
U | Gravis Xperience Driver Support | Grxp4exe.exe | Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used |
? | GrdSys32 | GrdSys32.exe | X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand? |
N | Greetings Workshop | GWREMIND.EXE | You really want to be reminded about somebody's birthday at the expense of resources? |
X | gremier | wscript.exe gpremier.vbs | Added by the GPREMIER WORM! |
X | Gremlin | intrenat.exe | Added by the DOOMJUICE WORM! |
N | Grokster | Grokster.exe | Grokster Peer-To-Peer File Sharing program |
N | GrpConv | grpconv.exe | To facilitate the upgrade from Windows 3.1 to Win95/98, an executable file named GRPCONV.EXE is included with Win95/98. This file provides the translation of groups and group items to folders and links unless you need to access Win 3.1 Group files |
? | Gscbc | Gscbc.exe | ?? |
X | gshp | zzgshp.vbs | Homepage hi-jacker |
N | Gsiconexe | Gsicon.exe | ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities |
N | GSOrganizer | GSOrganizer.exe | GoldenSection Organizer - personal information manager |
X | gssomatic | gssomatic.exe | Searchcentrix hijacker |
X | GStartup | GMT.exe | Gator spyware variant. See Gator |
N | Gtwatch | gtwatch.exe | Associated with a Mustec scanner and not required |
N | Guardian | CMGrdian.exe | McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
U | GuruNet | GuruNet.exe | GuruNet lets you click on any word on your screen to get the relevant information you want |
X | GustavVED | [filename].exe | Added by the OPASERV.H WORM! |
X | gvagfxj | rundll32 ...gvagfxj.dll | Unidentified adware, spyware or virus |
Y | gw port controller | PORTCT95.EXE | From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung |
N | GWInkMonitor | GWInkMonitor.exe | Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some! |
N | GWMDMMSG | GWMDMMSG.exe | Used with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly |
U | GWMDMpi | GWMDMpi.exe | Used with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information |
U | gwum | gwum.exe | Gigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers" |
? | gyy | gyy.exe | Possibly Gator (and therefore spyware) related? |
U | H/PC Connection Agent | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
U | HalifaxHowardCluster | skinkers.exe | Howard the Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages |
U | HaMFrontPanel | hampanel.exe | Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless |
U | Handy Backup 3.9 | hbagent.exe | Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers |
U | Hardware Doctor | Hwdoctor.exe | Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you're concerned about your system temperature - typically for "overclocked" systems |
X | Hardware Profile | hxdef.exe | Added by a variant of the LOVGATE WORM! |
X | Hardware Profile | hxdef.exe... | Added by a variant of the LOVGATE WORM! |
U | Hardware Sensors Monitor | hmonitor.exe | Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems |
U | Hare | hare.exe | Hare - improve and optimize performance of desktop/laptop PCs |
U | HawkEye | HAWK_95.EXE | Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs |
U | HawkEye IV Control Panel | HAWK_32.EXE | Control Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs |
X | Hbinst | Hbinst.exe | Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here |
N | HC Reminder | hc.exe | For Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed |
N | HCDetect | HCDetect.exe | MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem |
U | hcenter | tgcmd.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
U | Hcontrol | hcontrol.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys |
U | HDDHealth | hddhealth.exe | HDD Health is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure" |
? | HDhelp | tbhdhelp.exe | Associated with Philips Edge series soundcards. Is it required? |
N | HDtray | HDtray.exe | Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel |
X | he3e3fc4 | rundll32.exe [path] he3e3fc4.dll, EnableRunDLL32 | LZIO.com adware downloader |
X | hellodolly | shost.exe | Added by the YODO WORM! |
? | Help | helpext.exe | ?? |
X | helpctl.exe | helpctl.exe | Added by the GASLIDE TROJAN! |
X | Helper | eschlp.exe | Added by the BLASTER.T WORM! |
X | helper.dll | helper.dll, Rundll32 | CnsMin "Chinese Keywords" hijacker related |
X | HelpExp.exe | HelpExp.exe | Attune HelpExpress - spyware. Disable and uninstall - see here |
X | helpmanager | spoler.exe | Added by the RANDEX.J WORM! |
X | helpw | helpw.exe | Adware downloader |
X | hen | [filename].exe | Added by the TARNO.G TROJAN! |
X | hErcUnes | softhost.exe | Added by the GARROCH WORM! |
U | Hermes Messenger | DGDRHE~1.EXE | A LAN messenger alternative to WinPopUp - Digital Dreams Software |
N | Hewlett Packard Recorder | Remind32.exe | HP multifunction registration |
U | Hf | Hf.exe | Hide Folders - hide your folders so only you can view them |
U | hfxp | hfxp.exe | Hide Folders XP - hide your folders so only you can view them |
N | HGTXPEI | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel |
? | HiberMonitor | HCount.exe | ?? |
U | Hibernation | hib32.exe | Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly |
X | Hid.exe | hid.exe | Added by the RATSOU.B TROJAN! |
X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | Added by the BOOHOO WORM! |
X | HideStyle | Ante Browse Trust.exe | IE toolbar taking you to Lop.com. If the exe is running, end it and remove the "Stupidmore" directory from C:Program Files |
U | hidserv | hidserv.exe | This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards |
N | High Definition Audio Property Page Shortcut | HDAudPropShortcut.exe | Realtek audio card related - probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required |
N | HistoryKill | histkill.exe | HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs |
U | HitwarePKLite | HITWAR~1.EXE | Hitware Popup Killer Lite |
X | HIV | HIV.exe | Added by the HIVA TROJAN! |
U | hkcmd | hkcmd.exe | Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel |
X | HKLM\Run | windowsupdate.exe | Added by the FORBOT-BJ WORM! (where HKLMRun represents HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun) |
U | hkserv | HKserv.exe | Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS |
U | hkss | hkss.exe | Compaq HotKey Support - multimedia keyboard support |
X | HLL Data Parameter | hllcxpa.exe | Added by the RBOT.AFG WORM! |
X | HMI PowerSystem | hmisvc32.exe | Added by the RANDEX.CZZ WORM! |
U | Hmonitor | Hmonitor.exe | Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status |
N | Holiday Lights | Holiday Lights.exe | Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs |
N | Home Theater SchSvr | SchSvr.exe | WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
U | HomeAlarm | HomeAlarm.exe | Chameleon Clock - system tray clock replacement |
? | HomeCentre WakeUp | LGWAKEUP.EXE | Associated with the no longer supported Xerox HomeCentre printer/scanner |
? | Honor | honor.exe | ?? |
U | Hook99startup | hk2re.exe | "Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent" |
U | HookSys | HookSys.exe | SurfinGuard Pro - protects against all malicious code delivered through executables, scripting files, ActiveX and Java |
Y | HorngTech4D | bally4d.exe | HorngTech 4D mouse driver |
X | Host | N/A | Added by the POPDIS or STARTPAGE.F TROJANS! |
? | HostManager | AOLHostManager.exe | In a Program FilesCommon FilesAOL folder. What does it do, and is it required? |
U | Hot Corners | Hotc.exe | Hot Corners - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen" |
U | Hot Key Kbd 2690 Daemon | SK9910DM.exe | Multimedia keyboard manager - required if you use any special keys |
U | Hot Key Keybd 9910 Daemon | SK9910DM.exe | Multimedia keyboard manager - required if you use any special keys |
? | Hot Party 22 | hotpart22.exe | ?? |
X | Hotbar | Hbinst.exe | Hotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here |
X | Hotfix Updat | svdhost32.exe | Added by the GAOBOT.ZW WORM! |
U | HotIDE | hotide.exe | HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks |
U | HotkeyApp | HotkeyApp.exe | Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 |
U | HotKeysCmds | hkcmd.exe | Installed by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties |
X | HotPix | hotpix.exe | Adult content dialler |
X | hotplug | hotplug.exe | Added by the SILLYDL TROJAN! |
N | HotSync Manager | hotsync.exe | Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start -> Programs |
X | hotwetlove | hotwetlove.exe | Adult content dialler. Will not uninstall - components have to be manually deleted |
X | Hot_Kiss | Hot_Kiss.exe | Adult content dialler |
X | Hot_Tarts | Hot_Tarts.exe | Adult content dialler |
X | Hot_Tarts_** | Hot_Tarts_**.exe | Premium rate adult content dialer (where * is a random char) |
U | HoverDesk | HoverDesk.exe | HoverDesk - desktop replacement software |
? | hp 1000 firmware | fwdl.exe | HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)? |
U | HP AutoIndexer | hppautoindexer.exe | Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup |
N | HP CD Writer | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs |
N | HP CD-DVD | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs |
X | hp center | BACKWEB-137903.exe | Based upon HP's own description from here - "With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music" I have classified this as adware. The number may change - if yours is different let me know |
X | hp center UI | ShadowBar.exe | User Interface for HP Center |
N | HP Component Manager | hpcmpmgr.exe | Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended" |
X | HP Deskjet | HP_DeskJet_500.exe | Added by the FORBOT-DA WORM! |
N | HP Display Settings | hpdisply.exe | Sets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message |
? | HP IDScheduler | HPIDSCHD.exe | HP Instant Delivery Scheduler |
N | HP Info Express | ?? | On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb |
U | HP Instant Support | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide |
N | HP Internet Center | SURFBRD.EXE | Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them |
N | HP JetDiscovery | HPJETDSC.EXE | HP JetAdmin software which monitors printing jobs on a network environment |
N | HP JetSpeed Autostart | AUTOSTART.EXE | Autostart executable for the old multiplayer game HP Jetspeed |
U | HP Laser Jet Director | hppdirector.exe | System Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc |
? | HP Network Registry Agent | hpnra.exe | ?? |
? | HP OfficeJet Series xxx Startup | HPOSTR03.EXE | xxx represents the series number - such as 700. What does it do and it it required? |
? | HP OfficeJet Series xxx Startup | HPOstr05.exe | xxx represents the series number - such as 700. What does it do and it it required? |
N | HP Parallel Port Test | hppt.exe | Associated with a HP ScanJet scanner |
? | HP Port Resolver | hpbpro.exe | ?? |
N | HP Precision Scan | hpmdlbwx.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required |
N | HP Presentation Ready | PresRdy.exe | HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device" |
U | hp psc 2000 Series | hpobnz08.exe | System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start |
U | HP RecordNow | ?? | From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used." |
U | HP ScanPatch | HPScanFix.exe | Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting |
N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required |
U | HP SchedIndexer | hppschedindexer.exe | Installed by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup |
? | hp Silent Service | HpSrvUI.exe | HP related |
N | HP Simple Trax | Hpcron.exe | Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon |
N | HP software update | HPWuSchd2.exe | HP software updates. If a shortcut doesn't exist create your own and run it manually |
N | HP software update | HPWuSchd.exe | HP software updates. If a shortcut doesn't exist, create your own and run it manually |
N | HP software update | HPWuSchd2.exe | HP software updates. If a shortcut doesn't exist, create your own and run it manually |
N | HP Status | hpstatus.exe | HP Printer Status and Alerts |
? | HP Status Server | hpboid.exe | ?? |
N | HP Updates | ?? | On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb |
? | HP Visualize Init | HpVisIni.exe | HP Visualize software related. What does it do and is it required? |
N | HP-Aio Flight | Remind32.exe | HP multifunction registration |
N | hpaiodevice | hpodev07.exe | Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner |
N | HPAiODevice(hp psc 900 series) -1 | hpobrt07.exe | Installed with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry |
N | HPAIO_PrintFolderMgr | hpoopm07.exe | Directly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner |
? | hpcmpmgr | hpcmpmgr.exe | ?? |
U | HPDJ Taskbar Utility | hpztsbol.exe | (1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer |
U | HPDJ Taskbar Utility | hpztsd02.exe | (1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer |
U | HPDJ Taskbar Utility | hpztsb04.exe | (1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer |
U | HPDJ Taskbar Utility | hpztsb05.exe | (1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer |
N | hpfsched | hpfsched.exe | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature |
U | HPGamesActiveMenu | ActiveMenu.exe | WildTangent games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | hpgs2wnd | hpgs2wnd.exe | "HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." Available via Start -> Programs |
U | HPHAxMON | HPHAxMON.EXE | Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. "x" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards |
U | HPHmon** | HPHMON**.EXE | Monitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn't inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don't use the reader |
U | HPHmon04 | hphmon04.exe | Media card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature |
? | HPHmon05 | hphmon05.exe | ?? |
X | Hphome | hphome.js | Homepage hijacker |
N | HPHUPD** | hphupd**.exe | HP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs |
? | HPHUPD05 | hphupd05.exe | ?? |
? | hpjsiroute | hpjsira.exe | Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2" |
Y | HpLamp | HPLAMP.EXE | HP Scanner Utility that controls your scanner’s light bulb. Needed if it's switched on. Also refer here for troubleshooting |
U | hplampc | hplampc.exe | HP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off |
Y | HPLJ Config | SetConfig.exe | Connects system to networked HP printer. |
U | HPLogiFinder | hp_finder.exe | HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used |
U | HpMmKbd | HpMmKbd.exe | HP’s multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard |
N | hpodblia | hpodblia.exe | HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually |
N | hpoddt01.exe | N/A | Installed by the "HP Photo and Imaging Director" software. If you ask for the imaging software, this program will be started |
N | hpodlb08 | hpodlb08.exe | HP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually |
Y | hpotdd01.exe | hpotdd01.exe | Detection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems" |
Y | hpppta | HPPPTA.exe | HP parallel port driver for certain hardware |
N | HPPROPTY | HPPROPTY.EXE | HP LaserJet Toolbox |
U | HPPWRSAV | HPPWRSAV.EXE | Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch |
? | hpqcmon | hpqcmon.exe | From HP and related to digital imaging |
U | HPSCANMonitor | hpsjvxd.exe | HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner |
? | hpScannerFirstBoot | scannerfb.exe | HP scanner related |
N | hpsjbmgr | hpsjbmgr.exe | HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment |
N | HPStart | hpstart.wsf | This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot |
X | hpsysconf1 | [random filename] | Added by a variant of the VIVIA.A TROJAN! |
U | hpsysdrv | hpsysdrv.exe | This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working |
N | HPU | ProvenTactics.exe | Proven Internet Marketing software |
N | HPZTS04 | hpzts04.exe | Hewlett Packard printer toolbox shortcut that resides in the system tray |
N | HP_dla | dlatray.exe | On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD |
U | HREF.OCX | regsvr32.exe ....HREF.OCX | HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller |
X | hsim | isearch.exe | Unidentified malware |
X | hsim | sexgame.exe | Unidentified malware |
X | hsim | toolbar.exe | Unidentified malware |
U | Hti | npdor.exe | Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required |
U | HTpatch | htpatch.exe | HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6% |
X | HtProtect | AVprotect.exe | Added by the NETSKY.L WORM! |
X | httpd | c_pan.exe | Added by a variant of the DELF-A TROJAN! |
X | https-ssl | https.exe | Added by the MOEGA.D WORM! |
? | huhdir | huhdir.exe | ?? |
X | huigezi | HgzServer.exe | Added by the GRAYBIRD.C TROJAN! |
X | Hvid | Hvid.exe | Added by the GEMA TROJAN! |
X | HWINFO* | HWINFO* | Added by the PUROL WORM! where * is a random character |
Y | HWinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
X | HXDL.EXE | HXDL.EXE | Attune HelpExpress - spyware. Disable and uninstall - see here |
X | HXIUL.EXE | HXIUL.EXE | Attune HelpExpress - spyware. Disable and uninstall - see here |
U | HydarVisionDesktopManager | desk95.exe | ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this one. HydraVision can be uninstalled through Add/Remove Programs |
U | HydraVisionDesktopManager | desk98.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup |
U | HydraVisionViewport | viewport.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup |
X | Hyper Start | instantmsgrs.exe | Added by the RBOT-NH WORM! |
X | I-Worm.GiGu | uGiG.eXe | Added by the GINK WORM! |
X | I386 | I386.exe | Added by the MYPOWER WORM! |
? | I81SHELL | I81SHELL.exe | Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard |
U | i8kfangui | i8kfangui.exe | Graphical interface for fan speed control |
U | IAAnotif | iaanotif.exe | IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed |
Y | iamapp | iamapp.exe | AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well |
X | Iamnacho On Irc.MusIrc.com Is a Homosexual! | XBox64.exe | Added by the RANDEX.Y WORM! |
? | Iap | iap.exe | Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely? |
X | IASHLPR | IASHLPR.EXE | Added by the OPASERV.T WORM! |
? | IBM Warranty Notification | ERTS0749.exe | IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire? |
N | ibmmessages | ibmmessages.exe | Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport" |
? | Ibmmon.exe | Ibmmon.exe | ?? |
U | Ibmpmsvc | ibmpmsvc.exe | Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes |
U | IBMUltraBayHotSwapCPLLoader | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops |
? | IBMUltraBayHotSwapSound | IBMBAYSN.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound? |
X | icdd7ee6 | rundll32.exe [path] icdd7ee6.dll, EnableRunDLL32 | LZIO.com adware downloader |
N | ICH Synth | eusexe.exe | Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices |
U | iClean | iClean.exe | IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy" |
N | iCn | NAG.EXE | iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist |
N | ICO | ICO.EXE | Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
N | Icon Animation | HDE.EXE | Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons |
N | Icon Hearit 95 | hearit95.exe | Audio desktop customization utility from Moon Valley Software. Resource hog |
N | Icon Hearit 98 | hearit98.exe | Audio desktop customization utility from Moon Valley Software. Resource hog |
X | Icon lptt01 | icon.exe | Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Icon ml097e | icon.exe | Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
Y | ICONCLNT | iconclnt.exe | APC PowerChute Tray Icon. Associated with the UPS listing |
U | ICONDESK | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons |
N | Iconfig.exe | Iconfig.exe | Icon for LS-120 "Superdisk" |
X | iConfigLoader | DIIhost.exe | Added by the GAOBOT.AO WORM! |
N | Iconoid | Iconoid.exe | Iconoid is a desktop icon manager |
N | Iconsaver | Iconsaver.exe | IconSaver is a desktop icon manager |
X | ICQ Center | [path to worm] | Added by the RANDIN WORM! |
X | ICQ Hacking Pro | ICQpro.exe | Added by a variant of the NETSPY TROJAN! |
N | ICQ Lite | ICQLite.exe | ICQ Lite - compact version of the popular messaging program |
X | ICQ Lite Messenger | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or WinntSystem32 directory |
X | ICQ Net | winlogon.exe | Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup! |
N | ICQ Plus | vplus.exe | ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs |
U | ICSDCLT | rundll32.exe Icsdclt.dll, ICSClient | Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines |
N | ICServer | Icserver.exe | Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations |
Y | ICSMGR | ICSMGR.EXE | Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you’re sharing the internet on various computers |
N | IC_KEY_3 | spvic.exe | Instant Chess related |
N | ID Commander | IDCom.exe | Caller ID utility for identifying incoming telephone numbers |
X | ID8525 | ID8525.exe | Added by the ID8525.A TROJAN! |
X | ID8525 | id85255.exe | Added by the ID8525.A TROJAN! |
? | IDA | IDA.EXE | HP related - in a Program FilesHewlett-PackardPC COE folder |
X | IDE | ide.exe | Added by the ASSASIN.F TROJAN! |
X | IDE Loader | IDElibr32.exe | Added by the XILON TROJAN! Related to the game "Diablo II" |
X | idecntl | idecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
U | iDesktop | idesktop.exe | Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse |
N | IDMan | IDMan.exe | Internet Download Manager - download files faster, schedule and resume |
N | IDW Logging Tool | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems |
U | IE Doctor | IEDoctor.exe | IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" |
X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | Topconverting.com/180Search "IEMenuExtension" toolbar |
N | iecheck | iecheck.exe | Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 |
U | IECleanAux | Ieboot6.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup |
X | iedll | iedll.exe | Homepage hijacker, redirecting to coolwwwsearch.com |
X | IEDriver | IEDriver.exe | Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze |
X | IEDriver | xplore.exe | IEDriver adware variant |
X | IEDriver | TD.exe | IEDriver adware variant |
X | IEengine | IEeng.exe | STARTPAG.AI hijacker |
X | IEFeatures | IEFeatures.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
X | IEFeatures | Internetfeatures.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
X | Iehelper | syslaunch.exe | Outwar adware downloader |
X | iel2cde8 | rundll32.exe [path] iel2cde8.dll, EnableRunDLL32 | LZIO.com adware downloader |
X | IELoader32 | iexplore32.exe | Added by the SPEX or SPEX.B WORMS! |
X | Iesar | Iesar.exe | Browser hijacker - redirecting to an adult web page |
X | Iesearch.exe | Iesearch.exe | LookNSearch adware |
X | iestart | iexp1orer.exe | Added by the NEMOG.C TROJAN! |
N | ietsr | ietsr.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc |
X | ieupdate | MCP****.exe [**** = random char] | Added by the ASOXY TROJAN! |
X | ieupdate | mcpdll32.exe | Adware downloader trojan |
X | Iexplore | iexplore.exe | Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | IEXPLORE | iexplore.exe | Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | Iexplore Services | iexplore.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | iexplorer lptt01 | iexplorer.exe | Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | iexplorer ml097e | iexplorer.exe | Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
U | IFSplash.exe | IFSplash.exe | I-FORCE driver for force feedback steering wheel |
N | igfxtray | igfxtray.exe | Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel |
X | igsex2x | igsex2x.exe | NewDial premium rate adult content dialler |
X | iilc | IILC.EXE | Homepage hijacker |
X | Iinl | iptl.exe | PurityScan/Clickspring adware |
N | iIWiper | Systemwiper.exe | System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis |
Y | IJ75P2PSERVER | IJ75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
Y | IKE Service 95 | IKEService.exe | Associated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything |
U | iKeyWorks | IKEYMAIN.EXE | A4Tech wireless keyboard driver and utility |
X | iLLeGaL | Mplayer.exe | Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename |
X | iLLeGaL.exe | Mplayer.exe | Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename |
? | ILO_Office_Manager | IntEdReg.exe /OFFMAN | Intense Educational Ltd - Language Office Software. Is it required? |
U | iLyric | iLyric.exe | iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button |
N | iM Start Center | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner |
X | Image | rundll32 image.dll, Install | CoolWebSearch parasite variant |
Y | Image & Restore | IMAGE32.exe | Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run |
U | ImageDrive-{hex numbers} | ImageDrive.exe | Nero ImageDrive from Ahead - virtual CD/DVD drive software |
U | Imagefox | imagefox.exe | ImageFox 2.0 is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes |
X | Imagemgt32 | Imagemgt32.exe | Added by the GEMA TROJAN! |
X | IMClass | Svhosl.exe | Added by an unidentified WORM or TROJAN! |
N | imekrig | imekrig.exe | Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
N | IMEKRMIG6.1 | IMEKRMIG.EXE | Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
N | Imesh | ?? | Imesh is a file sharing system |
N | Imesh Auto Update | ?? | Update check for the Imesh file sharing system. Turn the update off under "options" |
U | ImgIcon | ImgIcon.exe | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
N | ImgStart | ImgStart.exe | Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
N | Imjpmig*.* | IMJPMIG.EXE | Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese). *.* represents the version number |
? | immcheck.exe | immcheck.exe | Related to I-FORCE driver for force feedback steering wheel? |
U | IMOL | IMOLApp.exe | IncrediMail for Office Outlook Add-On |
N | Imonitor | Plguni.exe | McAfee QuickClean 3.0 - removes internet clutter and unwanted programs |
U | IMStart | IMStart.exe | InterMute security software related |
X | IMwire | imwireup.exe | SafeSurfing parasite variant |
N | InCD | incd.exe | Ahead InCD packet writing software. Similar to DirectCD. On my system there isn't an entry, on another visitor's there is. Run manually before insert an appropriately formatted CD-RW disk |
N | IncMail | IncMail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
N | InControl Desktop Manager | DMHKEY.EXE | For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs |
N | Incredimail | incredimail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
U | Index Washer | WashIdx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
X | Indexindicator | Indexindicator.exe | Added by the LAZAR TROJAN! |
N | IndexSearch | IndexSearch.exe | Associated with PaperPort scanner software from ScanSoft |
X | Inet DataBase | Inetdbs.exe | Added by the QEDS WORM! |
X | Inet Delivery | Intdel.exe | Spyware |
X | Inet Delivery | intdel_2.exe | Spyware |
X | Inetapi | Netapi.exe | Added by the NETDEVIL.14 TROJAN! |
U | inetcntrl | inetcntrl.exe | Bsafe Online - internet filter |
? | InetConf | inetconf.exe | ?? |
U | Inetd | INETD32.EXE | Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation |
U | inetinfo.exe | inetinfo.exe | Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) |
X | inetmgr | inetmgr.exe | Actual Names (AdvSearch) Internet Keywords parasite |
X | InetMSN | msnet.exe | Added by a variant of the SDBOT TROJAN! |
U | Info Select | is.exe | Info Select from Micro Logic - personal information manager |
X | Info32x | Info32x.exe | Added by the GEMA TROJAN! |
? | Infoplay.exe | Infoplay.exe | Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed? |
U | Infra-red Monitor | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices |
X | infus | infus.exe | Adult content dialler |
U | Infuzer | Infuzer.exe | Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities" |
X | infwin | infwin.exe | Msview parasite variant |
X | Initial Page | install.exe | EasySearch browser hijack installer |
Y | Initialize8x8 | 8x8_init.exe | Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay |
N | Ink Monitor | InkMonitor.exe | Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
N | InkWatch | InkWatch.exe | Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
Y | InoRPC | InoRpc.exe | Associated with eTrust Antivirus/InoculateIT |
Y | InoRT | InoRT9x.exe | Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here |
U | InoTask | InoTask.exe | Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here |
? | insCOA5 | insCOA5.exe | ?? |
? | Install Pending Files | sifxinst.exe | Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required? |
N | InstallAurealDemos | InstallAurealDemos.js | Used to initialize the Aureal A3D demos InstallShield wizard |
U | InstallBuddy | Ibtna.exe | InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync |
X | Installed shell32.dll | Office.exe... | Added by a variant of the LOVGATE WORM! |
? | InstallNAIProduct | SETUP.EXE | Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error? |
X | Instant Access | rundll32.exe EGDHTML_1023.dll, InstantAccess | Adult content dialler related |
N | Instant Update Center | reminder.exe | From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner |
U | Instant Wireless Configuration Utility | WUSB11cfg.exe | Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
N | InstantAccess | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs |
U | InstantDrive | InstantDrive.exe | Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software |
X | InstantPleasure | instantpleasure.exe | Adult content dialler |
X | InstantPleasureXXX | instantpleasurexxx.exe | Adult content dialler |
N | InstantTray | PCLETray.exe | Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually |
X | instit | instit.bat | Added by the OPASERV.H WORM! |
X | instit | INSTIT.BAT | Added by the OPASERV.K WORM! |
? | InstUtlR.exe | InstUtlR.exe | ?? |
X | intdctrr | idctup20.exe | SafeSurfing parasite variant |
U | Intel Active Monitor | imontray.exe | System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards |
U | Intel File Transfer | xfr.exe | Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients |
U | Intel PDS | pds.exe | Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled |
U | Intel Product Number Utility | IntelProcNumUtility.exe | Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
N | Intel PROSet Tray Icon | promon.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features |
X | Intel system works | iis.exe | Added by the RBOT.QGA WORM! |
X | InteliSys | smss.exe | Advertisingvision adware - file is located in C:Windows or C:Winnt, and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file which would normally NOT figure in Msconfig/Startup! |
U | IntelliPoint | point32.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
U | Intellitype | type32.exe | For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them |
U | IntelMEM | IntelMEM.exe | Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line |
U | IntelProcNumUtility | cpunumber.exe | Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
N | Intel® Common User Interface | igfxtray.exe | Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel |
? | Intense Registry Service | IntEdReg.exe /CHECK | Intense Educational Ltd - Language Office Software. Is it required? |
X | InterceptedSystem | [path to worm] | Added by the ANACON-B WORM! |
Y | InterCheck Monitor | Icmon.exe | Part of Sophos ant-virus sofware |
X | Interdll | Interdll.exe | Added by the DELF family of TROJANS! |
X | Internal | [trojan filename] | Added by the SMOTHER and TRANSLAT TROJANS! |
X | Internal | regedit.exe /s %windir%c:[month number] | Added by the FORTNIGHT.D TROJAN! |
X | InternalSystray | Kazza.exe | Added by a variant of the OPTIX TROJAN! Note - unlike the valid KaZaA executable, this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) |
X | internat | internat.exe | Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) whereas this version resides in %windir% |
X | Internat | systray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process |
X | Internat Conf | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
N | internat.exe | internat.exe | Language selection icon in system tray |
X | Internat.exe | internat.exe | Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon |
X | internct | WinSocks5.exe | Added by the GRAYBIRD.F TROJAN! |
U | Internet Answering Machine | IAMNET~1.EXE | From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
U | Internet Answering Machine | IAM.exe | From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
X | Internet Config | svchosts.exe | Added by the SDBOT TROJAN! |
X | Internet Connection Wizard | stisvsq.exe | EasySearch adware |
U | Internet Download Accelerator | ida.exe | Internet Download Accelerator download manager |
X | Internet Exploere Services | urlmon32.dll.exe | Added by the EVIAN.C WORM! |
X | Internet Explorer | iexplorer.exe | Added by the LORSIS WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key |
X | Internet Explorer | IEXPLORE.EXE | Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | Internet Explorer Updater | lexbac.exe | Added by the DOWNLOAD TROJAN! |
X | Internet Explorer Updater | iexplorer.exe | Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
U | Internet History Eraser | HERASER.exe | Internet History Eraser - deletes your browsing tracks |
X | Internet Loader1 | MSInstall61.exe | Added by the KWBOT.B WORM! |
X | Internet Mail and News | msqdevl.exe | EasySearch adware |
U | Internet Optimizer | optimize.exe | Internet connection optimizer. Leave this enabled if you find it improves your connection |
X | Internet Optimizer | optimize.exe | Internet_Optimizer parasite |
X | Internet Send | More log.exe | Unidentfied adware |
X | Internet Service | intersvc.exe | Added by the SPYBOT-DE WORM! |
X | internet service | syscfg32.exe | Added by the RBOT-QS WORM! |
X | Internet Services | systemdev.exe | Added by the SDBOT-PW WORM! |
X | INTERNET SERVISES | winz32.exe | Added by the KWBOT.Z WORM! |
Y | Internet Sharing Server | iss_srvr.exe | Intel AnyPoint internet sharing software |
N | Internet Sweeper | Sweeper.exe | Internet Sweeper - removes unnecessart left over files after browsing the internet |
U | Internet Timer | ITIMER.exe | Shareware dial-up connection call cost calculator from Ratsoft |
X | Internet Washer Pro | iw.exe | Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
X | Internet.exe | Internet.exe | Added by the MAGICCALL VIRUS! |
X | InternetWasherPro | iw.exe | Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
X | INTERNET_SERVISES | winz32.exe | Added by the SDBOT.Q TROJAN! |
X | Internt | Internt.exe | Added by the PEEPER or CARUFAX.A TROJANS! |
N | InterTrust Quick Start | it_cpq~1.exe | InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business |
X | InterU | WINDRV.EXE | Added by the IRCINTER.A TROJAN! |
N | Intervideo Win Cinema Manager | WinCinemaMgr.exe | WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
N | Intervideo Win Cinema Manager | WINCIN~1.EXE | WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
N | Intervideo WinCinema Manager | WinCinemaMgr.exe | WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
N | Intervideo WinCinema Manager | WINCIN~1.EXE | WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
N | Intervideo WinScheduler | WinScheduler.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
N | Intervideo WinScheduler | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
U | InterWARN | interwarn.exe | InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs |
X | Intmgr | Intmgr.exe | Added by the GEMA TROJAN! |
X | Intrenat | Intrenat.exe | Added by the LEMIR.E TROJAN! |
N | Introducing Media Manager | SPLASHA.EXE | MS Media Manager tour. Not required |
N | Introduction-Registration | ?? | For Compaq PC's. Should only run first time, PC Introduction & Compaq registration |
X | IntruderAlert | ia99.exe | Intruder Alert '99 from Bonzi - spyware |
X | Ioadqm | Media Player.exe | Added by the HAWAWI WORM! |
U | iolo Task Agent | Task_Agent.exe | iOlo System Mechanic Task Agent. Scheduled maintenance |
U | Iomega Automatic Backup | ibackup.exe | Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
U | Iomega Automatic Backup 1.0.1 | ibackup.exe | Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
N | Iomega Backup Scheduler | dtiom98.exe | Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
U | Iomega Disk Icons | IMGICON.EXE | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
U | Iomega Drive Icons | IMGICON.EXE | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
U | Iomega ImIconXP | imiconxp.exe | Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks |
? | Iomega QuickSync | Quicksync.exe | ?? |
N | Iomega Startup Options | IMGSTART.EXE | Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
N | Iomega Watch | IOWATCH.EXE | Used by Iomega drives. Available via Start -> Programs |
N | IomegaWare | COMMANDER.EXE | Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
U | Iomon98.exe | Iomon98.exe | PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang |
X | IP Stack | ipstack.exe | Added by the AGOBOT.CW WORM! |
N | iPalm | mon.exe | Installed with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded |
X | ipcfg.exe | ipcfg.exe | Adware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan |
X | IPConfig | svcxnv32.exe | Added by the HACARMY.E TROJAN! |
X | IpCtrl | ipcon32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | IPInSightLAN 01 | ipclient.exe | Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resource - hence the "X" status |
N | IPInSightMonitor 01 | ipmon32.exe | Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information |
Y | IPinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
X | ipmon.exe | ipmon.exe | Added by the RECERV or R3C.B TROJANS! |
U | iPodManager | iPodManager.exe | Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods |
? | iPodWatcher | iPodWatcher.exe | Associated with Apple's iPod MP3 player. Detects when the iPod is connected? |
U | iProtectYou | ip.exe | iProtectYou - internet filtering/parental control and network monitoring software |
X | iprun | iPY.exe | iProtectYou spyware |
Y | IPSecMon | IPSecMon.exe | Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
X | IPTable Configuration | Winipcfgs.exe | Added by a variant of the RBOT WORM! |
X | IPv6 Helper Driver | csass.exe | Added by the AGOBOT.TC WORM! |
X | IPv6 STUN Service | netstun.exe | Added by a variant of the SDBOT WORM! |
N | IPW | IPW.exe | Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone" |
? | IQES.exe | iqes.exe | ?? |
X | irc session | sessionmgr.exe | Added by the SDBOT-ACE WORM! |
Y | IREIKE | IreIKE.exe | Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
N | iRis Active Monitor | winmon32.exe | Iris Antivirus - discontinued, replace with good alternative |
N | iRiS AntiVirus Active Monitor | WIMMUN32.exe | Iris Antivirus - discontinued, replace with good alternative |
N | iRiver Updater | Updater.exe | Updates for the iRiver Music Manager - used with their digital music players |
U | IrMon | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices |
? | IRPMonitor | itcnmon.exe | ?? |
X | Irwftp | [path to trojan] | Added by the BANCOS.CR TROJAN! |
X | irwftp | iexplorer.exe | Added by the BANKER-AN TROJAN! |
U | IrXfer | IrXfer.exe | Microsoft Infrared Transfer application |
X | ir_ftp | ir_ftp.exe | Added by the IRFTP TROJAN! |
X | ir_ftp | irwftp.exe | Added by the BANCOS.H TROJAN! |
N | IS CfgWiz | cfgwiz.exe | Norton Internet Security configuration wizard |
X | Isass | Isass.exe | Added by the FUTRO TROJAN! |
N | isdbdc | isdbdc.exe | For Compaq PC's. May install properties in dial-up networking when you register with an ISP |
N | ISDN Monitor | Linksts.exe | Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon |
U | ISDNwatch | IWatch.exe | FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks" |
N | ISLP2STA | ISLP2STA.EXE | Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though |
U | iSpyNOW | ispynow.exe | iSpyNOW - remote monitoring and surveillance software |
X | Israfel | Israfel.vbs | Added by the GAGGLE.D or GAGGLE.E WORMS! |
U | ISStart | ISStart.exe | LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
Y | ISSVC | ISSVC.exe | Part of Norton Internet Security Suite |
X | IST Service | istsvc.exe | ISTBar foistware |
X | ist service uninstall | [random filename] | ISTBar parasite related |
N | ISUSPM Startup | ISUSPM.exe | InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version |
N | ISUSScheduler | issch.exe | InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version |
U | Itk | Itk.exe | In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
U | iTouch | iTouch.exe | iTouch loads the iTouch configuration program for Logitech keyboards. It’s needed if your keyboard has shortcut buttons and if you use them. It’s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock |
N | ItsDeductiblePopUp | ItsDeductible.exe | ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip |
Y | iTunes Helper | iTunesHelper.exe | Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
Y | iTunesHelper | iTunesHelper.exe | Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
N | Iusage | netdet.exe | Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up |
N | IW ControlCenter | iwctrl.exe | Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
U | iwctrl | iwctrl.exe | Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
X | ixplore | ixplore.exe | Added by the SDBOT-CY TROJAN! |
? | IZE | N/A | ?? |
N | j2 Tray Menu | HotTray.exe | eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here |
U | Jammer | jammer.exe | Jammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web" |
X | Jammer2nd | Jammer2nd.exe | Added by the NETSKY.Z WORM! |
X | Java Runtimes | iexplore.exe | Added by the KILLAV.B TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | JavaScript Debugging Service | JsDbgMan.exe | Added by the DERDEO.E WORM! |
X | JavaUpdate0.07 | [filename] | Added by the JUPDATE TROJAN! |
X | JavaVM | java.exe | Added by the MYDOOM.M or MYDOOM.N or other variants of the MYDOOM WORMS! Note - not to be confused with the valid Windows "java.exe" which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) as this resides in C:Windows or C:Winnt |
X | jawa32 | jawa32.exe | Added by the AGENT.BG WORM! |
X | Jawa322 | jawa32.exe | Added by a variant of the AGENT.BG trojan |
N | JB | Jiffybar.exe | "Get Paid As You surf" application |
N | Jet Detection | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
Y | JetAdmin Discovery Indicator | HPJETDSC.EXE | HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator |
X | jijbl | ezlwy.bat | Added by the REDDW WORM! |
U | JobHisInit | JobHisInit.exe | Used by Ricoh network printers to enable network printing from the client |
U | Jog Serve | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
U | JogServ2 | JogServ2.exe | "Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features |
? | jotl | millenzje.exe | ?? |
X | Jreg | Jreg2b.exe | BroadcastPC adware variant |
N | jusched | jusched.exe | Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel |
X | jushed32.exe | jushed32.exe | CoolWebSearch parasite variant |
X | jutsu | jutsu.exe | Added by the RBOT-LS WORM! |
U | jv16 PT TempFileTool | TempTool.exe | jv16 PowerTools' temporary file remover |
U | Jv16pt Network Resident | jv16pt_network.exe | jv16 PowerTools' network resident program. Only needed if you are using the program's network features |
X | jvdnlssn | fljzsshc.exe | Flingstone.com adware - and its Golden Palace Casino program |
? | Jzi16 | jzi16.exe | ?? |
X | K2ps_full.task | K2ps_full.exe | Added by the JUNTADOR.K TROJAN! |
N | K6CPU.EXE | K6CPU.EXE | Authenticates CPU as K6 in system properties |
X | Kadoc | [random filename].exe | Added by the STAPREW TROJAN! |
X | kak | kak.hta | Added by the KAKWORM WORM! |
U | Kalibump | Kalibump.exe | Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy |
X | kalvsys | kalv****.exe [* = random char] | EliteBar/SearchMiracle adware installer |
X | kalvsys | kalv***32.exe [* = random char] | EliteBar/SearchMiracle adware installer |
N | Kana Reminder | Reminder.exe | Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time |
X | Kasper Antivirus | KASPERANTIVIRUS.EXE | Added by the SPYBOTER.GEN TROJAN! |
X | Kaspersky Antivirus | KasperskyAV.exe | Added by a variant of the RBOT WORM! |
X | KasperskyAv | kaspersky.exe | Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky AntiVirus |
X | KasperskyAVEng | Kasperskyaveng.exe | Added by the NETSKY.V WORM! |
Y | KAVPersonal50 | Kav.exe | Kaspersky Anti-Virus Personal 5.0 |
X | KavRuns | Windll.exe | Added by the TRYNOMA TROJAN! |
X | KAVutil | [worm filename] | Added by the WINTOO.B WORM! |
N | KAZAA | kazaa.exe | KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it |
X | Kazaa Download Accelerator Updater (required) | regsvr32 [path] kdp****.dll [* = random char] | SafeguardProtect/Veevo hijacker |
X | Kazaa lptt01 | kazaa.exe | Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
X | Kazaa ml097e | kazaa.exe | Variant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name |
X | KAZAACuf | 9 | Added by the KITRO.D (or ARGEN.A) WORM! |
N | kazaalite | kazaalite.exe | Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms |
N | KaZooM | KaZooM.Exe | KaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches" |
U | KBD | KBD.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
U | KBD MediaCenter | MEDIACTR.EXE | Multimedia keyboard manager. Required if you use the multimedia keys |
X | kbddrv32 | kbddrv32.exe | Added by the CRYPTER.A TROJAN! |
X | kbddrvinf | kbddrvinf.exe | Added by the CRYPTER.A TROJAN! |
N | KCeasy | KCeasy.exe | KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella |
U | KClient | kstatus.exe | KClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet |
N | kdx | KHost.exe | KonTiki Secure Delivery Plug In related. "The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers" |
U | KE9801 | DriBat32.exe | KE-9801 multimedia keyboard - required if you use the multimedia keys |
X | Keenvalue | Keenvalue.exe | Keenvalue spyware - see here |
U | KEMailKb | KEMailKb.EXE | Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down |
? | Kemet | kemet.exe | ?? |
X | kern64dll | [random filename] | Added by the TARNO.J TROJAN! |
X | kernctl32 | rundll32 kctl32.dll, initialize | Added by the AGENT.AT TROJAN! |
X | Kernel | bboy.exe | Added by the MUMU.B WORM! |
X | Kernel Loader | ntkrnl.exe | Added by the CERVIVEC.A WORM! |
X | kernel system daemon | ACTIVAT0R.exe | Added by the RANDEX.AW WORM! |
X | kernel32 | kern32.exe | Added by the BADTRANS.A WORM! |
X | Kernel32 | Kernel32.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
X | kernel32 | kernel.dli | Added by the NETDEVIL.B TROJAN! |
X | Kernel32 | Kernel.dll | Added by the REDLOF.M VIRUS! |
X | kernel32 | kernel32.dlI | Added by the NETDEVIL.15 TROJAN! |
X | Kernel32 | krnl32.exe | Added by the EPON WORM! |
X | Kernel32 | Kernel32.win | Added by the GAGGLE.D or GAGGLE.E WORMS! |
X | Kernel32 | kernel32s.exe | Added by the SDBOT-PU TROJAN! |
X | kernel32dll | guardpc.exe | Added by the FORBOT-CU WORM! |
N | kernelfaultcheck | dumprep 0 -k | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
N | kernelfaultcheck | dumprep 0 -u | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
X | KernelFaultChk | sms.exe | Added by the DEADHAT WORM! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u" |
X | Kernell | systems.exe | Added by the TARNO.C TROJAN! |
X | Kernell32 | Kernell.dll | Added by the DESTINY.A TROJAN! |
X | KernellApps | csrss.exe | Added by the BANCBAN-AC TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | Kernelw | Kernelw32.exe | Added by the INDOR.E WORM! |
X | Kernel_check | wmiprvse.exe | Added by the SONEBOT-B WORM! |
X | key | sysxp.exe | Added by the BEAGLE.AB WORM! |
X | key | sys_xp.exe | Added by the BEAGLE.AC WORM! |
X | key | winxp.exe | Added by the BEAGLE.AG WORM! |
X | Key Logger | csrss.exe | Added by the BUCHON.A WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
N | Key Text | KeyText.exe | Key Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs |
X | Key1 | Rlid.exe | Added by the LIXY TROJAN! |
? | Key2 | serve.exe | ?? |
Y | KeyAccess | keyacc32.exe | KeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure" |
X | Keybdcntl | keybdcntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
U | Keyboard Manager | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
Y | Keyboard Preload Check | Preload.exe | Millenium Multi-Function Keyboard driver |
U | KeyMaestro | kmaestro.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
U | keymap | keymap.exe | System Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game |
X | keymgrldr | rundll32 setupapi, InstallHinfSection... keymgr3.inf | CoolWebSearch parasite variant |
U | KeyPatrol | KeyPatrol.exe | KeyPatrol - detects Key Loggers ("keyboard loggers" or "keyloggers") using both behavioral and pattern-matching algorithms |
U | KeyWallet | KWallet.exe | "KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually" |
X | kfienq | masbl.bat | Added by the KIFER TROJAN! |
N | khooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
U | KICKMON.EXE | KICKMON.EXE | KeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required |
U | Kill Popup | KillPopup.exe | KillPopup - pop-up stopper |
N | Kinberlink | Kinberlink.exe | Kinberlink network messaging. Available via Start -> Programs |
U | KK Loader | loadkk.exe | KeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user." |
U | klp | run32dll.exe | PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online |
U | KM9801U | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
U | kmw_run.exe | kmw_run.exe | Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
U | kmw_show.exe | kmw_show.exe | Kensington MouseWorks - mouse/trackball software. Not required unles you use any special features |
N | Kodak Batch Transfer | pezdow1.exe | Part of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC |
U | Kodak EasyShare software | EasyShare.exe | Software bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually |
N | Kodak Picture Transfer Software | pts.exe | Looks for Kodak camera connection and media insertion. Available via Start -> Programs |
N | Kodak Software Updater | backweb*****.exe | Software updater for Kodak Easyshare digital cameras |
Y | KodakCCS | KodakCCS.exe | Kodak DC File System Driver |
N | Konni Symbol Autostart | KonniSymbol.exe | Gives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5 |
N | kontiki | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
U | KREC32 | krec32.exe | StarrCommander Pro Keystroke logging software |
U | Krnlmod | Krnlmod.exe | Keylogger - see here. Given a "U" recommendation because it depends if you intentionally installed it. If you didn't, treat it as "X" and uninstall or remove via Spybot S&D (for example) |
U | ktchnsnk | ktchnsnk.exe | HP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted |
X | kv3000 | lover.vbe | Added by the ZSYANG.B WORM! |
X | kvern16.dll | regsvr32.exe [path] kvern16.dll | DailyWinner adware |
X | kw3eef76 | rundll32.exe [path] kw3eef76.dll, EnableRunDLL32 | LZIO.com adware downloader |
N | kX Mixer | kxmixer.exe | Provides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards |
X | LanGuard | languard.exe | Adware downloader |
U | LanSpeed2 | LanSpeed2.exe | Monitors any traffic that is using a LAN adapter (Ethernet or Token ring network card) |
U | LapLink scheduler | Llsched.exe | Utility that automatically performs file transfers as unattended background operations |
X | Lar | Llass.exe | Added by the INOR-A TROJAN! |
X | lar | [trojan filename] | Added by the ROXY.C TROJAN! |
X | LARISSA ANTI VIRUS | LARISSA_ANTI_VIRUS.exe | Added by the KLASSIR TROJAN! |
? | Lasb | ewat.exe | ?? |
X | LAsIAf32 | RePEAtLD.exe | Added by the REPEATLD WORM! |
Y | LASTinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
? | Later | later.exe | ?? |
U | LaunApp | LaunApp.exe | Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 |
? | Launcg | launcg.exe | ?? |
U | Launch Ai Booster | OverClk.exe | ASUS Ai Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup |
N | Launch YahooPOPs! at Windows startup | YAHOOPOPS.EXE | YahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs |
U | LaunchAp | LaunchAp.exe | Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 |
U | LaunchApp | Alaunch.exe | Acer Launch tool utility on laptops |
U | Launchboard | lnchbrd.exe | "LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions" |
X | Launcher | launcher.exe | Spyware component related to DownloadWare and found in Program FilesKFH |
N | Launcher | relaunch.exe | Audio Applications Launcher for the Philips Rythmiic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs |
X | Lavasoft Ad-Aware | Ad-Aware.exe | Added by the RBOT-SO WORM! Note - this is not the popular Ad-aware spware/adware removal tool |
U | Lavasoft Adwatch | Ad-watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
Y | laxmsp32.exe | laxmsp32.exe | Lexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work |
U | LCDC | LCDC.exe | LCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins |
N | lcfep | lcfep.exe | Tivoli ‘TME’ System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally" |
X | lcvga | lcvga.exe | Added by the HOSTOL-A TROJAN! |
X | ld | ld.exe | CoolWebSearch parasite related - redirects to fastwebfinder.com |
N | LDM | backweb-8876480.exe | Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech |
N | LDM | ldmconf.exe | Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech |
U | LED TRAY | LEDTRAY.EXE | Installs a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work |
U | ledpointer | CNYHKey.exe | Chicony Electronics Multimedia Keyboard Hotkey Driver |
N | LeechGet | LeechGet.exe | LeechGet download manager |
X | LetsSearch | LetsSearch.exe | BrowserAid/BrowserPal foistware variant |
U | Lexmark **** Series | lxbabmgr.exe | Lexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut |
U | Lexmark **** Series | lxbkbmgr.exe | Lexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut |
U | Lexmark **** series | lxbtbmgr.exe | Lexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut |
Y | Lexmark 3100 Series | lxbrbmgr.exe | Lexmark printer button manager. Required for correct operation |
Y | Lexmark Xxx Button Manager | AcBtnMgr_Xxx.exe | Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation |
Y | Lexmark Xxx Button Monitor | ACMonitor_Xxx.exe | Associated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation |
N | LexmarkPrinTray | printray.exe | Lexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray |
X | lexplore | lexplore.exe | Added by the BROPIA WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
N | lexpps | lexpps.exe | For Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all". It is known that firewalls can however alert you to "lexpps.exe" requesting server privileges |
U | LexStart | lexstart.exe | Lexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance |
U | Lfsndmng | lfsndmng.exe | LightningFAX Enterprise Fax Server - "puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents" |
N | lhttseng | rundll32.exe ..lhttseng.inf, RemoveCabinet | Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine |
X | li-multi**** | li-multi****.exe | Adult web-dialler - **** is random |
X | li-speed**** | dlres.exe | Adult web-dialler - **** is random |
X | li-thund**** | li-thund****.exe | Adult web-dialler - **** is random |
X | li-vita**** | li-vita****.exe | Adult web-dialler - **** is random |
X | li01f948 | rundll32.exe [path] li01f948.dll, EnableRunDLL32 | LZIO.com adware downloader |
N | LicCrtl | runservice.exe | eLicense, licensing system incorporated with some software and games |
U | LicCtrl | rundll32.exe [path] MMFS.DLL, Service | Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program |
U | LicCtrl | runservice.exe | Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program |
N | LifeScape Media Detector | PicasaMediaDetector.exe | Media detector for Picasa's automatic photo organizer |
U | Lightning Download | Lightning.exe | Lightning Download download manager. Can be launched manually, but will need to start up if you want it to "catch clicks" off Internet Explorer |
N | LimeWire x.x | LimeWire.exe | LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware |
N | Line Speed Meter V3.0 | LineSpeedMeter.exe | LineSpeedMeter - detect the download and upload speed of your internet connection |
N | Linksts | linksts.exe | Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon |
X | Linksts | linksts.exe | Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon |
X | Linux | Linux.vbs | Added by the LOVELETTER.AS VIRUS! |
U | LiquidView | lviewj.exe | "Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display's native resolution. The software lets you increase the size of items that are hard to read on your monitor" |
N | LIU | LIU.exe | Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway |
N | LIU | Rubicon.exe | Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway |
N | Live Menu | Dllcmd32.exe | eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here |
N | LiveMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information |
N | LiveNote | Livenote.exe | Asus graphics card driver live update feature |
X | LiveSexCams | LiveSexCams.exe | Premium rate adult content dialler |
U | LiveUpdate | LiveUpdate.exe | Web-update utility as used by various types of software - see here |
X | LiveUpdate | [Windows username]05.exe | Added by the LINEAGE TROJAN! |
X | Livre | Dibane.bat | Added by the BANEDI VIRUS! |
? | LLMODCL2 | rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF | ?? |
U | LManager | QtZgAcer.EXE | Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio |
U | LManager | QtZpAcer.exe | Acer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio |
N | LMonitor | LMonitor.exe | MSI Live Update - auto-detects and suggests the latest BIOS/Driver/Utilities information |
? | lmpdpsrv | lmpdpsrv.exe | Related to a Lexmark printer/scanner. Printer sharing server? Is it required? |
N | LMSTATUS | LMSTATUS.EXE | Lexmark Status Monitor. Checks the current status of Lexmark printers (and other devices?) |
X | lmu | LMU.exe | Downloader trojan, recognized by Kaspersky antivirus as Agent.bg |
X | lnternet Explorer | AMSNDMGR.EXE | Added by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I" |
X | load | mdm.exe | Added by the BINGHE TROJAN! |
U | LOAD WB | LOADWB.EXE | Part of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it |
X | Load-Guard | Wscript.exe LGuarg.exe.vbs | Added by the YENO.B and YENO.C WORMS! |
X | LOAD32 | Lorena.exe | Added by the MAPSON.C WORM! |
X | load32 | load32.exe | Added by the NIBU, BAMBO TROJANS and DUMARU WORM! |
X | load32 | l32x.exe | Added by the DUMARU.Z or DUMARU.Y or DUMARU.AD WORM! |
X | load32 | 1111a.exe | Added by the DUMARU.AH WORM! |
X | load32 | swchost.exe | Added by the TURTA.A WORM! |
X | load32 | netda.exe | Added by the NIBU.E TROJAN! |
N | load= | adw30.exe | After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95 |
U | load= | asistat.exe | Status monitor for an NEC SuperScript printer |
? | load= | cfgsys32.exe | ?? |
U | load= | esspk.exe | Speakerphone capability through a soundcard for an ESS modem |
Y | load= | hotkey.exe | Solo 5300 display driver for Win2K on some Gateway laptops |
N | load= | HPWHRC.EXE | Loads the Status Window software for the HP Laserjet printers |
? | load= | WPSLOAD.EXE | Windows printing system that comes with the setup for Canon BJC series on the manufacturer's disk |
N | load= | vi_grm.exe | Monitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings |
? | load= | WINOSCFG.EXE | Could it be something to do with configuring Windows on a new PC from an OEM supplier? |
Y | load= | wpshrc.exe | Required to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others) |
Y | load= | Bfrecv.exe | Bitware modem driver |
X | load= | msater.exe | Added by the RETSAM TROJAN! |
X | load= | shambl3r.exe | Added by the REMABL WORM! |
X | load= | Spoolsv.exe | Added by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
? | Load= | wtfeat.exe | Associated with the Wintab Digitizer |
Y | load= | AICLIENT.EXE | Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system |
X | load= | hint.exe | Added by the ATAK WORM! |
X | load= | win32exec.exe | Added by the BITTER WORM! |
X | load= | a1g.exe | Added by the ATAK.B WORM! |
X | load= | dapdll.exe | Added by the ATAK.E WORM! |
Y | LoadBlackD | blackd.exe | This is the "intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility) |
? | LoadBtnHnd | BtnHnd.exe | Fujitsu LifeBook related |
X | LoadDBackUp | BcTool.exe | Added by the GIBE WORM! |
X | loaddll | loaddll.exe | Winvest spyware |
? | LoadDvpApi9x | DVPAPI9X.exe | Part of Command AntiVirus for Windows 95/98/Me. Is it needed? |
X | loader | loader.exe | Homepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe |
X | loader | WMPLAYER.EXE | Unknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
X | loader32 | sys*****.exe [***** = random digit] | Added by the DOMCOM TROJAN! |
X | LoadFonts | LoadFonts.vbs | Homepage hijacker that changes your homepage to an adult content site |
X | LoadFonts | Tahoma.vbs | Homepage hijacker that changes your homepage to an adult content site |
X | LoadHTML | rundll32.exe mshtmpre.dll, MShtmpre | Browser hijacker |
X | LoadingAgent | ZipLoader32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
X | LoadingAgent | msload32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
X | LoadManager | msload.exe | Added by the OPASERV.T WORM! |
X | loadMecq0 | explorer.exe | Added by the MUMUBOY.C TROJAN! |
N | LoadMSvcmm | msvcmm32.exe | Auto-update for Movielink - internet movie rental System Tray access |
X | LoadOrderVerification | [random filename] | Added by the TRON.A TROJAN! |
U | Loadout Manager | nost_LM.exe | Manager for the Belkin Nostromo n50 SpeedPad game controller - see here |
X | LoadPowerProfile | ASDAPI.EXE | Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll |
U | LoadPowerProfile | Rundll32.exe powrprof.dll | Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings |
X | LoadPowerProfile | Rundll.exe powerprof.dll | Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe" |
X | LoadPowerProfile | rundl.exe | Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll |
X | LoadPowerProfile | Rundll32.exe | Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line |
U | LoadQM | loadqm.exe | Installed with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it |
X | loads.exe | loads.exe | Popuppers.com adware downloader |
X | loads.exe | medload.exe | Popuppers.com adware downloader |
X | loads.exe | suploads.exe | Popuppers.com adware downloader |
X | LoadSIPS | rundll32.exe [path] SIPSPI32.dll, SIPSPI32 | 123Mania adware |
? | LoadWatcher | Test.exe | Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct? |
X | LoadWindowsFile | [filename] | Added by the DELF.B TROJAN! where [filename] is the infected file |
X | Local Page | http://find.naupoint.com | Naupoint browser hijacker |
X | Local runole service | srvc32.exe | Added by an unidentified WORM or TROJAN! |
X | Locator Service | [filename] | Added by the AGOBOT-KY TROJAN! |
U | Lock My PC | lockpc.exe | Lock_My_PC - a tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse |
U | Login | winlog.exe | Salfeld Child Control 2003 - parental control software |
X | Login Service | [path to file] | Added by the MIGMAF TROJAN! |
X | LoginPassport | Lgnpsp32.exe | Added by the REDIST.C WORM! |
N | Logitech Desktop Messenger | backweb-8876480.exe | Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech |
N | Logitech Desktop Messenger | ldmconf.exe | Installed with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech |
U | Logitech Hardware Abstraction Layer | Khalmnpr.exe | For a Logitech Bluetooth wireless mouse. Part of SetPoint that sets the Windows mouse sensitivity to minimum. The idea is that you will use the SetPoint Control Panel to adjust your mouse sensitivity. This setting is maintained separately from the Windows setting, but is combined with the Windows setting to determine the final sensitivity. For this reason, KHALMNPR sets the Windows setting to 0 so it doesn't alter the one you set in SetPoint |
U | Logitech SetPoint | KEM.exe | Keyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys |
U | Logitech Utility | Logi_MwX.exe | Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled |
N | Logitech Wakeup | lgwakeup.exe | Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images |
U | LogitechGalleryRepair | ISStart.exe | LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
N | LogitechImageStudioTray | LogiTray.exe | Logitech Image Studio - installed with Logitech QuickCams |
? | LogitechSoftwareUpdate | ManifestEngine.exe | Updater, part of Logitech Image Studio - installed with Logitech QuickCam cameras. Probably not required |
U | LogitechVideoRepair | ISStart.exe | LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
N | LogitechVideoTray | LogiTray.exe | Logitech Image Studio - installed with Logitech QuickCams |
N | LogiTray | LogiTray.exe | Logitech Image Studio - installed with Logitech QuickCams |
U | Logi_Mwx | Logi_MwX.exe | Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled |
X | Logon.exe | logon.exe | Added by the ZINS.A TROJAN! |
U | LogonStudio | logonstudio.exe | WinCustomize LogonStudio - "Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users" |
X | LogService | wincalc.exe | Added by the PAPROXY TROJAN! |
U | LogWatch | logwat95.exe | Licensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see here. Not required if you already have a newer version or the patch has been applied |
Y | Look 'n' Stop | looknstop.exe | Look 'n' Stop personal firewall |
N | LookNMeet | Agent.exe | LooknMeet dating service |
X | Lookup_Sys | lookupsys.exe | P04n trojan |
N | Lotus Organizer EasyClip | easyclip.exe | "The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page." Available via Start -> Programs |
N | Lotus QuickStart | smartctr.exe | Lotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs |
U | Lotus SuiteStart | suitest.exe | Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs |
X | LowVersionSupport | [filename] | Added by the LASTRAS TROJAN! |
X | Lpr | Lpr123.exe | Added by the REMPSTEAL password stealer TROJAN! |
X | Lpr123 | Lpr123.exe | Added by the REMPSTEAL password stealer TROJAN! |
U | LPS | Lps.exe | Local Port Scanner - "With LPS you're able to check your computer for open or listening ports" |
U | LPtask | lptask.exe | Program Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted |
N | LS120 Superdisk | ?? | Supposed to accelerate transfer rate on LS-120, contributes to system lockups |
X | LSA | wfdmgr.exe | Added by the MYTOB.C WORM! |
X | lsass | lsass.exe | Added by the RATSOU.B TROJAN! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
X | lsass | start.bat | Added by the ZCREW TROJAN! |
X | lsass | [path to lsass.exe] | Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup! |
X | lsass | lsasrv.exe | Added by the MYDOOM.AG or MYDOOM.AS or MYDOOM.AU WORMS! |
X | LSASS Daemon | LSASSd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | lsass service | lsass2.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | lsasss.exe | lsasss.exe | Added by the SASSER.E WORM! |
X | LSPFix | LSPmonitor.exe | eAcceleration Stop-Sign related - not recommended, see note |
X | LSPmonitor | LSPmonitor.exe | eAcceleration Stop-Sign related - not recommended, see note |
X | lssass | lssas.exe | Added by the AGOBOT.RL WORM! |
X | LSvr | LSvr.exe | PowerStrip foistware |
Y | LT DAEMON | ltdaemon.exe | Acts as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used |
X | LTDMgr | LTDMgr.exe | PowerStrip foistware |
X | LTM2 | MSGSRV32.EXE | Added by the LITMUS.A TROJAN! Note - MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:WindowsSystem |
X | LTM2 | MPGSRV32.EXE | Added by the LITMUS.201 TROJAN! |
X | LTM2 | MSGSRV320.EXE | Added by the LITMUS.C TROJAN! |
X | LTM2 | winupdate.exe | Added by the LITMUS.203 TROJAN! |
X | LTM2 | bible.exe | Added by the LITMUS.203 TROJAN! |
U | LtMoh | Ltmoh.exe | Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet |
Y | LTMSG | ltmsg.exe | One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
N | LTSMMSG | LTSMMSG.exe | Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too |
X | LTSMSG | Shell32.exe | Added by the LEMIR.B TROJAN! |
Y | LTWinModem1 | ltmsg.exe | One of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
X | ltwob | formatsys.exe | Added by the SERFLOG.A WORM! |
X | ltwob | msmbw.exe | Added by the SERFLOG.A WORM! |
X | ltwob | serbw.exe | Added by the SERFLOG.A WORM! |
Y | Lusetup | LUSetup.exe | Symantec LiveUpdate installer - required to install a new version of the application. Will only run once, and the entry is automatically deleted after a reboot |
U | LVComs | lvcoms.exe | Lvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera |
? | LVCOMSX | LVCOMSX.EXE | Logitech webcam related. What does it do and is it required? |
U | LWBMOUSE | lwbwheel.exe | Mouse driver - required if you use non-standard Windows driver features |
U | LWBMOUSE | MOUSE32A.EXE | Mouse driver - required if you use non-standard Windows driver features |
N | Lwinst Run Profiler | lwtest.exe | Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs |
? | lxamsp32 | lxamsp32.exe | Associated with a Lexmark Printer - is it required? |
? | LXbbmgr | LXbbmgr.exe | Lexmark printer button manager? Is it required? |
? | LXBLKsk | LXBLKsk.exe | Lexmark related. What does it do, and is it required? |
Y | lxbrbmgr | lxbrbmgr.exe | Lexmark printer button manager. Required for correct operation |
? | LXBRKsk | LXBRKsk.exe | Lexmark printer related. What does it do and is it required? |
? | LXBTCATS | rundll32 [path] LXBTtime.dll,_RunDLLEntry@16 | Lexmark printer related - what does it do and is it required? |
N | LXSUPMON | LXSUPMON.EXE | Lexmark Printer. The printer should work fine without it |
X | LzioMediaUpdater | LzioMediaUpdater.exe | LZIO.com adware downloader |
? | M Player Post Installer | postinstallm.exe | ?? |
X | M-soft Office | M-soft Office.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! |
X | M1cr0s0ft S3rcurity | systemconfig.exe | Added by the RBOT.BKB WORM! |
X | M1cr0s0ft Upd4t4zS | update32.exe | Added by the RBOT-MI WORM! |
X | m32info | m32info.exe | Added by the CRYPTER.A TROJAN! |
N | M3Tray | m3tray.exe | Movielink - internet movie rental System Tray access |
X | Macfee Security Patch | Mpfsheild.exe | Added by the RBOT-NP WORM! |
U | Machine Debug Manager | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable |
N | MacLic | MacLic.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
N | MacName | MacName.exe | Part of Conversions Plus from DataViz - allowing PC and MAC owners to share disks |
Y | MAD.EXE | MAD.EXE | MAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up? |
N | MadExe | LaunchRA.exe | Dell Resolution Assistant |
U | MagicDsk | MAGICDSK.EXE | Magic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons |
N | Magitime | Magitime.exe | Magitime - connection tracking utility which monitors online time, expense, data transfer |
? | Mail.com | mcalert.exe | Mail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived? |
U | MailBell | mailbell.exe | MailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
U | Mailbox Verifier | mboxvrfy.exe | Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance) |
Y | MailScan Dispatcher | Launch.exe | MailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned |
X | Mail_Check | Mail_Check.exe | Added by the PANOIL.C WORM! |
U | MAIN | main.exe | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
? | Main Executable (HP) | HP05T0R5.exe | HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do? |
X | main16 | main16.exe | Added by the CRYPTER.A TROJAN! |
X | main32 | main32.exe | Added by the CRYPTER.A TROJAN! |
X | mainviewex | mainviewex.exe | Added by the GEMA.D TROJAN! |
N | Mania Win Restore | RESWIN.EXE | Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs |
X | Mantis | [filename] | Added by the MANTIBE VIRUS! |
X | MapiDrv | mpisvc.exe | Added by the MIPSIV TROJAN! |
X | mapisvc32 | mapisvc32.exe | Added by the KX VIRUS and also recognised by Symantec as FPAI adware |
N | masqform.exe | masqform.exe | PureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms |
N | Mass storage check registry | rundll32.exe MSDServ.dll, check registry | Used with a USB based smartmedia card reader |
U | Master Volume Spy | MASTERVOLUMESPY.EXE | Volume control for the Gateway Destination "DestiVu" media interface |
U | Matador | mlfbuddy.exe | MailFrontier - anti-spam application |
U | Matador | mantispm.exe | MailFrontier Desktop (Matador) email spam blocker software |
X | MatrixScreen | [filename] | Added by the MATRIXSCREEN TROJAN! |
X | MatrixScreenSaver | mss.exe | Malware, see here |
N | Matrox Color Control | hgcctl95.exe | For Matrox video cards. Quick access to changing colors |
N | Matrox Control Center | mgactrl.exe | For Matrox video cards. Quick access to settings |
N | Matrox Diagnostic | mgadiag.exe | For Matrox video cards. Quick access to diagnostics |
N | Matrox Powerdesk | PDesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
N | Matrox PowerDesk 8 | Matrox.PowerDesk.exe /silent | For Matrox video cards. Quick access to tweak your card to your liking |
N | Matrox QuickDesk | mgaqdesk.exe | For Matrox video cards. Quick access to tweak your card to your liking |
X | MaxAlerts | max.exe | Bonzi MaxALERT - spyware |
Y | MaxtorCombo | ComboButton.exe | Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect) |
U | MaxtorReg | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
U | MBM 4 | MBM4.exe | Motherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
U | MBM 5 | MBM5.exe | Motherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
U | MBProbe | mbrpobe.exe | MBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs |
X | MC | wintrims.exe | Added by the WINTRIM TROJAN! |
X | Mcafee Anti Scan | NortonScn.exe | Added by a variant of the RBOT WORM! |
X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | Added by a variant of the RBOT WORM! |
Y | McAfee Firewall | CPD.EXE | Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE |
N | McAfee Guardian | CMGRDIAN.EXE | McAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic |
N | McAfee QuickClean Imonitor | Plguni.exe | McAfee QuickClean 3.0 - removes internet clutter and unwanted programs |
X | McAfee Windows Protection | mcafee32.exe | Added by a variant of the SPYBOT WORM! |
N | McAfee Winguage | ?? | Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
Y | McAfeeUpdaterUI | UpdaterUI.exe | Associated with McAfee Enterprise 7.0.0. - background process |
Y | McAfeeVirusScanService | Avsynmgr.exe | From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application |
Y | McAfeeWebscanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
X | Mcaffe Antivirus | Mcafeescn.exe | Added by a variant of the SPYBOT WORM! |
U | McAgentExe | mcagent.exe | From McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed |
? | Mcappins.exe | mcappins.exe | McAfee Application Installer. What does it do and is it required? |
N | MChanger | MChanger.exe | Media Changer - utility that allows you to change wallpapers, sounds, themes, etc |
? | McRegWiz | mcregwiz.exe | McAfee antivirus related. What does it do and is it required? |
U | McUpdateExe | mcupdate.exe | From McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions |
Y | McVsRte | mcusrt.exe | Part of McAfee's SecurityCenter. Must remain checked but one user reports Windows glitches with no response from McAfee as to why |
Y | mcvsshld | mcvsshld.exe | McAfee VirusScan On-line. See also the McAgentExe entry |
X | MD IE Plugin | md.exe | Adult content dialler |
X | MD IE Plugin | winy.exe | Adware |
N | mdac_runonce | runonce.exe | Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". |
X | mdetect | [path to trojan] | Added by the SPABOT TROJAN! |
X | Mdm | Mdm.vbs | Added by the WHITEHO VIRUS or TRAPPY WORM! |
X | mdm | mdm.exe | Added by the LYDRA-F TROJAN! Note - this is not the valid Machine Debug Manager which shares the same filename |
U | MDM7 | mdm.exe | Used by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable |
X | Mdmdll | mdmdll.exe | Added by the CRYPTER TROJAN! |
X | Mdmdll32 | mdmdll32.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | MDN | MDNS.exe | Added by the SPYBOT.JPB WORM! |
X | MDN | MDNZ.exe | Added by the RBOT.AQD WORM! |
X | mdwmdmsp | mdwmdmsp.exe | Adware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am |
N | MECA | Meca.exe | Meca instant messenging client |
X | Media Access | MediaAccK.exe | Windupdates adware variant |
X | Media Load | msn32.exe | Added by a unidentified WORM or TROJAN! |
U | Media Manager Indexer | AIRSVCU.EXE | Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here |
X | Media Pass | MediaPassK.exe | Windupdates adware variant |
X | Media Player | media.exe | Added by the FLDMEDIA-A TROJAN! |
X | Media Player | wmplayer.exe | Added by the AGOBOT-BM WORM! |
X | Media Plug x.1.2 | msdm.exe | Added by the MULDROP.352 VIRUS! |
X | Media Service | msn64.exe | Added by the SPYBOT.EV WORM! |
X | Media service | msnmsgxr.exe | Added by the SDBOT.TF WORM! |
X | Media service | SYSTEM64.EXE | Added by the RBOT.QV WORM! |
N | MediaFace Integration | Sethook.exe | Fellowes Neato™ cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
U | Mediafour Mac Volume Notifications | Macvntfy.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod |
U | MediaKey | MediaKey.exe | Multimedia keyboard manager. Required if you use the multimedia keys |
X | MediaLoads | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
X | MediaLoads Installer | dw.exe | Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information |
N | MediaMonitor | Mediam~1.exe | Installed by Smartdisk MVP CD burning software. Software will work fine without it |
X | mediamotor.exe | mmups.exe | Roimoi/Media-Motor adware |
X | MediaPath | Proyecto1.exe | Added by the GRUEL WORM! |
X | MediaPath | Root.exe | Added by the GRUEL WORM! |
N | MediaRing Talk | mrtalk.exe | Media Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs |
X | media_manager | mediaman.exe | Mini-Player, IMESH related foistware, see here |
X | media_stub | stub.exe | Mini-Player, IMESH related foistware, see here |
X | MemConfig | SetupIE.com | Added by the TAPLAK WORM! |
U | MemoKit | MK.EXE | Memory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
X | Memory Check | memore.exe | Added by the KILLAV.C TROJAN! |
N | Memory Stick Monitor | MSTAT.exe | Used with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer |
U | Memory Stick Monitor | MSstat.exe | Sony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive |
X | Memory Watcher | MemoryWatcher.exe | MemoryWatcher spyware |
U | Memory+ | tfimemsr.exe | Memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
X | MemoryMeter | MemoryMeter.exe | Autoinstalling spyware by Total Velocity |
X | MEMreaload | MEMreaload.exe | Added by the LAZAR TROJAN! |
N | MemScanner | MemScanner.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
U | MemTurbo | memturbo.exe | MemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
N | MenuSnap | MenuSnap.exe | MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe |
X | Message Queuing | msmqs.exe | Added by the FREEFORS TROJAN! |
N | MessagerStarter Freeserve | StartMessager.exe | Freeserve Messenger |
U | Message_Blocker | messageblock.exe | Message Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message" |
X | Messanger | trillian.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Messenger | messenger.exe | Added by the KUTEX TROJAN! |
X | Messenger Block | msngrblock.exe | Added by the PATOO WORM! |
X | Messenger start-up | Msgran.exe | Added by the GRAMOS WORM! |
X | Messenger6 | command.pif | Added by the INZAE.B WORM! |
U | MessengerDiscovery | MessengerDiscovery.exe | MessengerDiscovery is a MSN Messenger add-on - adding over 70 new features |
N | MessengerPlus | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
N | MessengerPlus2 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
N | MessengerPlus3 | MsgPlus.exe | MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that "sponsor program"! |
X | messnger | [worm filename] | Added by the DELODER WORM! |
X | messnger | Dvldr32.exe | Added by the DELODER.A WORM! |
X | MeTaLRoCk (irc.musirc.com) has sex with printers | metalrock-is-gay.exe | Added by the RANDEX.Q WORM! |
? | mfgboot | ?? | ?? |
X | mfin32 | mfin32.exe | MyFreeInternetUpdate - adware downloader |
? | MGA Hook | Mgahook.exe | MATROX Graphics card related. What does it do and is it required? |
N | MGA Quickdesk | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking |
? | Mgabg | Mgabg.exe | Matrox BIOS Guard. What does it do and is it required? |
Y | mgavctrl | mgavrtcl.exe | McAfee's Virus Scan Online |
Y | mgavctrl | mgavrte.exe | McAfee's Virus Scan Online |
Y | mgavrtclexe | mgavrtcl.exe | McAfee's Virus Scan Online |
Y | mgavrtclexe | mgavrte.exe | McAfee's Virus Scan Online |
N | MGA_CD_Install | mgasetup.exe | Matrox Millennium video driver. Not required once drivers installed |
X | MHDOGStart | mhdogst.EXE | Added by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENIS |
N | MHINIT | MHINIT.EXE | Part of the Cybermedia Clean Sweep package |
X | Mickey Mouse Cereal | [random filename].exe | Added by the RANKY.Q TROJAN! |
X | Micr Update | soundblaster.exe | Added by the SDBOT.NP WORM! |
U | Microangelo Desktop | Muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
N | microAttuneDownload | atmdlusr.exe | USR (US Robotics) modem auto updater. May be a sub-set of Attune |
U | MicroDialler | atdialler1.exe | Part of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered |
X | Microfinder lptt01 | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Microfinder ml097e | mcf.exe | Variant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | MicroLoad | [random filename] | Added by the DARBY WORM! |
X | Microsof Windows Host | svhost32.exe | Added by the RBOT.ADY WORM! |
X | Microsof Winlog Host | wilogon32.exe | Added by the RBOT.XC WORM! |
X | Microsofot x386 System Monitor | system32.exe | Added by the WOOTBOT.M WORM! |
X | microsoft | svchost.exe | Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | microsoft | microsoft.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! |
X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
X | Microsoft .NET Confingurator | msnconf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft 16Bit Update | wuapdate16.exe | Added by the RBOT.CZ WORM! |
X | Microsoft ALG32 Protocol | alg32.exe | Added by a variant of the SPYBOT WORM! |
N | Microsoft Announcement Listener | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
X | Microsoft Ansti Update | msie.exe | Added by the RBOT-LE WORM! |
X | Microsoft AOL32 Protocol | aol32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Associates, Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
X | Microsoft AUT Update | MSlti32.exe | Added by the RBOT-X WORM! |
X | Microsoft AUT Update | MSlti16.exe | Added by the RBOT.EB WORM! |
X | Microsoft auto update | winupdate.exe | Added by the BMBOT TROJAN! |
X | Microsoft AutoUpdater | svhost.exe | Added by the RBOT.QG WORM! |
X | Microsoft boot system cfg32 | actboost.exe | Added by the BROPIA.R WORM! |
X | Microsoft Conf Ldr | sysconf.exe | Added by a variant of the SDBOT TROJAN! |
X | Microsoft Config | msconf.exe | Added by the RBOT.PV WORM! |
X | Microsoft Config | MSCONF.EXE | Added by the RBOT-LG WORM! |
X | Microsoft Config File | config.exe | Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls! |
X | Microsoft Corporation | [random filename] | Added by various VIRUSES, WORMS & TROJANS! |
X | Microsoft CSRSS32 Protocol | csrss32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Microsoft CSRSS386 Protocol | csrss386.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Cvrt | mscvrt32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft Data Helper | cihost.exe | Malware, possibly a variant of the LINST TROJAN |
X | Microsoft Data Machine | csdata32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Database Handler | mssql32.exe | Added by the RANDEX.AX WORM! |
X | Microsoft Decryption Technology | Msfenoe.exe | Added by the SPYBOT-DG WORM! |
X | Microsoft Device Manager | msdevmgr32.exe | Added by the LATEDA.B TROJAN! |
X | Microsoft Diagnostic | [random filename] | Added by the ACEBOT TROJAN! |
X | Microsoft Digital Clock | msclock.exe | Added by the NACKBOT-D WORM! |
X | Microsoft DirectX | Spoolserv.exe | Added by the DINFOR WORM! |
X | Microsoft DirectX | rasmngr.exe | Added by a variant of the RBOT WORM! |
X | Microsoft DirectX | PDSched.exe | Added by the SDBOT.CN WORM! |
X | Microsoft DirectX | wuamgrd.exe | Added by the SDBOT.MY WORM! |
X | Microsoft Dll Management | windll.exe | Added by the RBOT-MT WORM! |
X | Microsoft DNS Query | msdns.exe | Added by a variant of the WOOTBOT WORM! |
X | Microsoft Document | krisp.exe | Added by the SDBOT-RQ WORM! |
X | Microsoft Drivers | WSconf.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft ErgoPack | wserb32.exe | Added by the RBOT-RI WORM! |
X | Microsoft Excel | msexcel.exe | Added by the RBOT-TQ WORM! |
X | Microsoft Excell | wuamngr32.exe | Added by the RBOT-QH WORM! |
X | Microsoft Executing | microsoft.exe | Added by the AGOBOT.UV WORM! |
X | Microsoft Explorer | svapache.exe | Added by the RBOT-VR WORM! |
X | Microsoft EXPLOREXP Protocol | explorexp.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Features | ms32cfg.exe | Added by the RBOT.HO WORM! |
X | Microsoft Find Fast | Findfast.exe | Complete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier |
X | Microsoft Firewall | firewallsp2.exe | Added by the RBOT-MC WORM! |
Y | MICROSOFT FIREWALL CLIENT | ISATRAY.EXE | MS Internet Security and Acceleration Server 2000 |
X | Microsoft Gina V Encryption | MSGINAV.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
N | Microsoft Greetings Reminders | MHPRMIND.EXE | Microsoft Home Publishing greetings reminder |
N | Microsoft Greetings Workshop Reminder | Gwremind.exe | You really want to be reminded about somebody's birthday at the expense of resources? |
N | Microsoft Greetings Reminder | MHPRMINF.EXE | You really want to be reminded about somebody's birthday at the expense of resources? |
X | Microsoft Help SVC | msnmngr.exe | Added by the SDBOT-PQ WORM! |
X | Microsoft Help System | mshelp32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft IE | Iexplore.exe | Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | Microsoft IE Execute shell | IEExec.exe | Added by the ALADINZ.N TROJAN! |
X | Microsoft IIS | syshost.exe | Added by the FRANCETTE WORM! |
X | Microsoft Inc. | iexplorer.exe | Added by a variant of the LOVGATE WORM! |
X | Microsoft Inet Xp.. | teekids.exe | Added by the BLASTER.C WORM! |
X | Microsoft Instant Messenger | msngmsngr32.exe | Added by the SPYBOTER.GEN TROJAN! |
U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard |
X | Microsoft Internet | expl0rer.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Internet | windows32.exe | Added by the SDBOT-F WORM! |
X | Microsoft Internet Acceleration Utility | iau.exe | EasySearch adware |
X | Microsoft Internet Exp | iiexplorer.exe | Added by the RBOT-KX WORM! |
X | Microsoft Internet Explorer | iexplore.exe | Downloader trojan. Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | Microsoft Internet Firewall Manager | GMT16.exe | Added by the RANDEX.AT WORM! |
X | Microsoft Internet Services | Smss32.exe | Added by the RBOT.MS WORM! |
X | Microsoft IPC | system.exe | Added by the NULLBOT TROJAN! |
X | Microsoft IPC | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft IT Update | win64.exe | Added by the RBOT.GA WORM! |
X | Microsoft IT Update | [random filename] | Added by a variant of the RBOT WORM! |
X | Microsoft IT Update | IEserv.exe | Added by a variant of the RBOT WORM! |
X | Microsoft IT Update | msupdate.exe | Added by a variant of the RBOT WORM! |
X | Microsoft IT Update | winn43.exe | Added by a variant of the RBOT WORM! |
X | Microsoft IT Update | svchsst.exe | Added by the RBOT-DH WORM! |
X | Microsoft IT Update | win43.exe | Added by the RBOT-SA WORM! |
X | Microsoft IT Update | windows.exe | Added by the RBOT-GL WORM! |
X | Microsoft Java Virtual Machine | winscr32.exe | Added by a variant of the WOOTBOT WORM! |
X | Microsoft Java Virtual Machine | MsConfiG.exe | Added by the FORBOT-DV WORM! |
X | Microsoft Java Windows Update | [filename] | Added by the RBOT-DZ WORM! |
X | Microsoft JavaVM | msjarun.exe | Added by the RBOT-JW WORM! |
X | Microsoft Kernel | Windows_kernel32.exe | Added by the NETSKY.AE WORM! |
X | Microsoft Lmhosting Service | lmhosts.exe | Added by the RBOT-RC WORM! |
X | Microsoft Locals 332 | [random filename] | Added by the RBOT-KU WORM! |
X | Microsoft LSASS386 Protocol | scvhost32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Macro Protection SubSsy | msacroprots386.exe | Added by the RBOT-KE WORM! |
X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | Added by the RBOT.KN WORM! |
X | Microsoft Management | lmas.exe | Added by the FORBOT-CZ WORM! |
X | Microsoft Management Console | lssas.exe | EasySearch adware |
X | Microsoft media | winmplayers.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft media services | Iassd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Microsoft media services | winmplayer.exe | Added by the RBOT.ZO WORM! |
X | Microsoft Movie Maker | Mmaker.exe | Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program |
X | Microsoft MSGPLUS32 Protocol | msgplus32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft MSNGR32 Protocol | msngr32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft MsnST | msnst32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft MSUPDATE | SpoolSvc.exe | Added by the SXTB-A TROJAN! |
X | Microsoft NetMeeting Associates, Inc. | NetMeeting.exe | Added by a variant of the LOVGATE WORM! |
X | Microsoft Netview | gesfm32.exe | Added by the RANDEX.C WORM! |
X | Microsoft Netview | mssvc32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft Netview Component v5.1 | msnv32.exe | Added by the RANDEX.F WORM! |
X | Microsoft Network | msnet.exe | Added by the MOCKBOT.A WORM! |
X | Microsoft Network Daemon for Win32 | Netd32.exe | Added by the SDBOT.R TROJAN! |
X | Microsoft NT Update | winexec32.exe | Added by a variant of the RBOT WORM! |
N | Microsoft Office | Osa.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
N | Microsoft Office | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
X | Microsoft Office | MSMSGR.exe | Added by the GAOBOT.BB WORM! |
N | Microsoft Office | Osa9.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
X | Microsoft Office | lserv.exe | Added by the SDBOT.MH WORM! |
X | Microsoft Office | Microsoft Office.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site! |
N | Microsoft Office Fast Cache | Fastboot.exe | Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled |
U | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | ONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work |
N | Microsoft Office Shortcut Bar | Msoffice.exe | Alternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it but a better way is to create Desktop Shortcuts if you want access these programs quickly |
X | Microsoft Office Start | winupdates.exe | Added by the GAOBOT.BC WORM! |
N | Microsoft Office Startup | Osa.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
N | Microsoft Office Startup | Osa9.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
X | Microsoft Office Studio | scvhvst.exe | Added by the RANDEX.CST WORM! |
X | Microsoft Personal Firewalls | bakw.exe | Added by the RBOT-KS WORM! |
X | Microsoft QMGR | msnqmgr.exe | Added by the IRCBOT-S TROJAN! |
X | Microsoft RDLL | sysconf32.exe | Added by a variant of the SDBOT TROJAN! |
X | Microsoft Registry | csrse.exe | Added by the RBOT-PC WORM! |
X | MicroSoft Remote Secure Service | MSRSS.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Restore | scrgrd.exe | Added by the SPYBOT.BR WORM! |
X | Microsoft Runtime | CfgDll32.exe | Added by the RANDEX.BD WORM! |
X | Microsoft Scanreg | microsoftscanreg.exe | Added by the FRANRIV.A WORM! |
X | Microsoft SCVHOST32 Protocol | scvhost32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Secure Messenger.NET Service | securitychk.exe | Added by the SDBOT.VT WORM! |
X | Microsoft Security Hot Fix Update | mshotfix.exe | Affilred adware |
X | Microsoft Security Management | winnt.exe | Added by the RBOT-MQ WORM! |
X | Microsoft Security Management | winserv.exe | Added by the RBOT-MJ WORM! |
X | Microsoft Server Application | Sound.exe | Added by the RBOT-NE WORM! |
X | Microsoft Service | microhost.exe | Added by the RBOT-LC WORM! |
X | Microsoft Service | winsvc.exe | Added by the SPYBOT-DB WORM! |
X | Microsoft Services | lsserv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft Services | lssrv.exe | Added by the RBOT.CW WORM! |
X | Microsoft Services | services.exe | Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Microsoft Services | lsrv.exe | Added by the RBOT-BK WORM! |
X | Microsoft Services | svshost.exe | Added by the ALETS.B TROJAN! |
X | Microsoft Services Unitd | MSU32.exe | Added by a variant of the RBOT WORM! |
N | Microsoft Sidewinder Game Controller Software | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs |
X | Microsoft Software | sysinfo33.exe | Added by the RBOT.LS WORM! |
X | microsoft software | ****.exe E255 [* = random char] | Added by an unidentified WORM or TROJAN! |
X | Microsoft software | cdaccess.exe | Added by the RBOT.ABK WORM! |
X | Microsoft Software Update | nmon.exe | Added by the RBOT.HZ WORM! |
X | Microsoft Sound Driver | sound32.exe | Added by a variant of the SPYBOT WORM! |
N | Microsoft Sound Volume Tool | mssvol.exe | This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel |
X | Microsoft SourceSafe | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | Microsoft Spool Server for Win32 | spoolsrv.exe | Added by the RANDEX.H WORM! |
X | Microsoft SSISVRI32 Protocol | ssisvri.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Synchronization Manager | asgard.exe | Added by the SDBOT.PH WORM! |
X | Microsoft Synchronization Manager | bot.exe | Added by the SDBOT.IH WORM! |
X | Microsoft Synchronization Manager | netscape.exe | Added by the RANDEX.AE WORM! |
X | Microsoft Synchronization Manager | slhost.exe | Added by the SDBOT.YH WORM! |
X | Microsoft Synchronization Manager | svhost.exe | Added by the SDBOT-PY WORM! |
X | Microsoft Synchronization Manager | WinLoginnn.exe | Added by the SPYBOT.FO WORM! |
X | Microsoft Synchronization Manager | winupdate.exe | Added by the SDBOT.ER WORM! |
X | Microsoft Synchronization Manager | xXx.exe | Added by the SDBOT-KZ WORM! |
X | Microsoft Synchronization Manager | ___synmgr.exe | Added by the MASLAN.A or MASLAN.C WORMS! |
X | Microsoft Synchronization Manager | al.exe | Added by the OPTXPRO.132 TROJAN! |
X | Microsoft Synchronization Manager | win.exe | Added by the SDBOT.AK WORM! |
X | Microsoft System Checkup | Cool.exe | Added by the DONK.B WORM! |
X | Microsoft System Checkup | Wnetlib.exe | Added by the DONK.C WORM! |
X | Microsoft System Checkup | dbnetlib.exe | Added by the DONK.L WORM! |
X | Microsoft System Checkup | Keymgr.exe | Added by the DONK.M WORM! |
X | Microsoft System Checkup | inetman.exe | Added by the DONK.O WORM! |
X | Microsoft System Checkup | ntsysmgr.exe | Added by the DONK.S WORM! |
X | Microsoft System Checkup | ntsysman.exe | Added by the SDBOT-QW WORM! |
X | Microsoft System Checkup | libsysmgr.exe | Added by the SDBOT-CAF WORM! |
X | Microsoft System Checkup | sysmgr.exe | Added by the SDBOT-OO TROJAN! |
X | Microsoft System Restore Configuration | CBRSS.EXE | Added by a variant of the SPYBOT WORM! |
X | Microsoft System32 Update | cmsrg.exe | Added by the RBOT-GN WORM! |
X | Microsoft Time Manager | dveldr.exe | Added by the RBOT-HQ WORM! |
X | Microsoft Transfer File Server | mtfs.exe | Added by the RBOT.AFE WORM! |
X | Microsoft Tray | [random filename] | Added by the DELF.BZ TROJAN! |
X | Microsoft Update | Microsoft.exe | Added by the GAOBOT.AFJ WORM! |
X | Microsoft Update | mssmgrd.exe | Added by the SDBOT.JT WORM! |
X | Microsoft Update | mvsc.exe | Added by the SPYBOT.DAZ WORM! |
X | Microsoft Update | ascdl.exe | Added by the GAOBOT.SY WORM! |
X | Microsoft Update | Isac.exe | Added by the RBOT-AU WORM! |
X | Microsoft Update | automgr32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update | mediap.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update | Microsoftx.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update | msconfg.exe | Added by the RBOT.H WORM! |
X | Microsoft Update | Mslti32.exe | Added by the RBOT-LX WORM! |
X | Microsoft Update | muamgrd.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Microsoft Update | navmgrd.exe | Added by the SDBOT.DP TROJAN! |
X | Microsoft Update | Smss32.exe | Added by the RBOT.CB WORM! |
X | Microsoft Update | sys32cfg.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Update | VPC32.EXE | Added by the AGOBOT.XM WORM! |
X | Microsoft Update | winsys32.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update | wuamgrd.exe | Added by the RBOT-LK WORM! |
X | Microsoft Update | wuammgr32.exe | Added by the RBOT-AW WORM! |
X | Microsoft Update | wudmate.exe | Added by the RBOT.AP WORM! |
X | Microsoft Update | msawindows.exe | Added by the GAOBOT.AFJ WORM! |
X | Microsoft Update | msiwin84.exe | Added by the GAOBOT.AFJ WORM! |
X | Microsoft Update | wuamgrd32.exe | Added by the RBOT.ZB WORM! |
X | Microsoft Update | NAV.exe | Added by the RBOT-IV WORM! |
X | Microsoft Update | systemi32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Update | xpupdate.exe | Added by the RBOT-QE WORM! |
X | Microsoft Update | webm.exe | Added by the SDBOT.WK WORM! |
X | Microsoft Update | wuagrd.exe | Added by the RBOT-FK WORM! |
X | Microsoft Update | aaupdt.exe | Added by the RBOT-RQ WORM! |
X | Microsoft Update | lsac.exe | Added by the GAOBOT.XW WORM! |
X | Microsoft Update | Mupdate.exe | Added by the RBOT-AG WORM! |
X | Microsoft Update | prowind32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Microsoft Update | snlogsvc.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update | svhost.exe | Added by the RBOT-PI WORM! |
X | Microsoft Update | wauguard.exe | Added by the RBOT.AEE WORM! |
X | Microsoft Update | winscv.exe | Added by the RBOT-BH WORM! |
X | Microsoft Update | winsys.exe | Added by the RBOT-GV WORM! |
X | Microsoft Update | wserv32.exe | Added by the RBOT.AF WORM! |
X | Microsoft Update | wtm32.exe | Added by the RBOT-AQ WORM! |
X | Microsoft Update | wumgrd.exe | Added by the SDBOT-KY WORM! |
X | Microsoft Update | wuampd.exe | Added by the RBOT-UT WORM! |
X | Microsoft Update 32 | explore32.exe | Added by the SPYBOT.CYM WORM! |
X | Microsoft Update 32 | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
X | MICROSOFT UPDATE CONFIGURATION | WIN32SNC.EXE | Added by the RBOT-AI WORM! |
X | Microsoft Update Emulator | kern-mxe.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update Loader | [random filename] | Added by a variant of the RBOT WORM! |
X | Microsoft Update Machine | expl0rer.exe | Added by the SDBOT.OK WORM! |
X | Microsoft Update Machine | rxhost.exe | Added by the RBOT.FC WORM! |
X | Microsoft Update Machine | servicz.exe | Added by the RBOT-HU WORM! |
X | Microsoft Update Machine | SP2.exe | Added by the SPYBOT.FP WORM! |
X | Microsoft Update Machine | winini.exe | Added by the RBOT-KV WORM! |
X | Microsoft Update Machine | xvshost.exe | Added by the RBOT.QP WORM! |
X | Microsoft Update Machine | memstat.exe | Added by the RBOT-OM WORM! |
X | Microsoft Update Machine | ntce.exe | Added by the RBOT-FA WORM! |
X | Microsoft Update Machine | system03.exe | Added by the RBOT-NM WORM! |
X | Microsoft Update Machine | wuawx.exe | Added by the RBOT-CE WORM! |
X | Microsoft Update Machine | zonealarm.exe | Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program! |
X | Microsoft Update Machine | systemll.exe | Added by the RBOT-JT WORM! |
X | Microsoft Update Machine | winupdt.exe | Added by the RBOT-FP WORM! |
X | Microsoft Update Machine | svshost.exe | Added by the RBOT.AK WORM! |
X | Microsoft Update Machine | wuamgd.exe | Added by the SDBOT.HQ WORM! |
X | Microsoft Update Machine | wupdt32x.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft Update Machine | [random filename] | Added by a variant of the RBOT WORM! |
X | Microsoft Update Machine | linux.exe | Added by the RBOT-IM WORM! |
X | Microsoft Update Machine | lmrss.exe | Added by the RBOT-DY WORM! |
X | Microsoft Update Machine | windowsu.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update Machine | wininigo.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update Machine | winmgr.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Update Machine | Winmsixp32.exe | Added by the RBOT.DN WORM! |
X | Microsoft Update Machine | Winregs32.exe | Added by the RBOT.DN WORM! |
X | Microsoft Update Machine | winxpini.exe | Added by the RBOT-OB WORM! |
X | Microsoft Update Machine | wuamgrd.exe | Added by the RBOT-HE WORM! |
X | Microsoft Update Machine | wuagrd.exe | Added by the RBOT-GF WORM! |
X | Microsoft Update Machine | LANWAKE.EXE | Added by the RBOT-QZ WORM! |
X | Microsoft Update Machine | scvhost.exe | Added by the RBOT-GS WORM! |
X | Microsoft Update Machine | winhost.exe | Added by the RBOT-GK WORM! |
X | Microsoft Update Machine | winss.exe | Added by the RBOT.JU WORM! |
X | Microsoft Update Machine | WUAMGRDXS.EXE | Added by the RBOT-GL WORM! |
X | Microsoft Update Manager | WINRLS.EXE | Added by the RBOT-AF WORM! |
X | Microsoft Update Mechene | Updatez.exe | Added by the RBOT-GI WORM! |
X | Microsoft Update Module | rundll24.exe | Added by the RBOT-PS WORM! |
X | Microsoft Update Security Patch | mssecurityupdatepatch.exe | Added by the AGENT.EF TROJAN! |
X | Microsoft Update Server | mssrv.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft Update Service | csrss32.exe | Added by the AGOBOT-HC WORM! |
X | Microsoft Update Service | mswin32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft update service | systemm.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft Update Time | wuam.exe | Added by the RBOT-M WORM! |
X | Microsoft Update Win32a | winupdate32a.exe | Added by the RBOT-LO WORM! |
X | Microsoft UPDATER32 | lsass.exe | Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
X | Microsoft Updaters Pros | WINDLL32XP.EXE | Added by the SPYBOTTER.GEN VIRUS! |
X | Microsoft Updates | systemc32.exe | Added by the RBOT-GR WORM! |
X | Microsoft Updates Resources | WinFixIDs.exe | Added by a variant of the RBOT WORM! |
X | Microsoft upnp Update | msie.exe | Added by the RBOT-LQ WORM! |
N | Microsoft Utility Startup | OSA9.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
X | Microsoft Video Controls | tskmsgr.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Virual Machine | sms.exe | Added by the RBOT-SP WORM! |
X | Microsoft Visual SourceSafe | services.exe | Added by the NEVEG.B or NEVEG.C WORMS!. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
X | Microsoft Visual SourceSafe | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup or the Microsoft Visual SourceSafe program |
X | Microsoft Visual Studio VSA | varpc32.exe | Added by a variant of the SPYBOT WORM! |
U | Microsoft Webserver | svctrl.exe | Personal web server program which enables you to create and host a web server from your computer. Not required for most people |
X | Microsoft Windows | mstask0.exe | Added by the SDBOT.FQ WORM! |
X | Microsoft Windows 2000 | Winupdsdgm.exe | Added by the GAOBOT.AO WORM! |
X | Microsoft Windows Control | mswctl32.exe | Added by the RBOT.JP WORM! |
X | Microsoft Windows DHCP | ___r.exe | Added by the MASLAN.A or MASLAN.C WORMS! |
X | Microsoft Windows DLLHandler | bitpaint.exe | Added by the SDBOT.AHG WORM! |
X | Microsoft Windows GUI | Windowz.exe | Added by the RANDEX.AEV WORM! |
X | Microsoft Windows GUI | msmonk32.exe | Added by the SDBOT-PE WORM! |
X | Microsoft Windows Kernel Services | winkrnl386.exe | Added by the ZEBROXY TROJAN! |
X | Microsoft Windows Loader | wloader.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Microsoft Windows Media Player | mediaplayer.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Windows Media Player | wimp.exe | Added by the RBOT-FN WORM! |
X | Microsoft Windows Secure Server | rpcxWindows.exe | Added by the RBOT-LL WORM! |
X | Microsoft Windows Securety | wurguar.exe | Added by the RBOT-KY WORM! |
X | Microsoft Windows Security | spvsper.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft Windows Task Manger | Mstosk.exe | Added by the SDBOT-WW WORM! |
X | Microsoft Windows Update | rundlls.exe | Added by the HABRACK WORM! |
X | Microsoft Windows Update | msoffice2.exe | Added by the RBOT-GB WORM! |
X | Microsoft Windows Update | spools.exe | Added by the SDBOT.TD WORM! |
X | Microsoft Windows Update | svchos.exe | Added by the SDBOT.AC WORM! |
X | Microsoft Windows Update | svcshost.exe | Added by the FORBOT-CF WORM! |
X | Microsoft Windows Update | svmhost.exe | Added by the FORBOT-CH WORM! |
X | Microsoft Windows Update | svshost.exe | Added by the WOOTBOT.CJ WORM! |
X | Microsoft Windows Update | msnmessenger.exe | Added by the SDBOT.AJ WORM! |
X | Microsoft Windows Update | msnwun.exe | Added by the SDBOT-RM WORM! |
X | Microsoft Windows Update | scvvhost.exe | Added by the FORBOT-DH WORM! |
X | Microsoft Windows Update Service | wupdmgr32.exe | Added by the DOS.AUTOCAT TROJAN! |
X | Microsoft Windows Updater | winupdgm.exe | Added by the GAOBOT.BI WORM! |
X | Microsoft Windows Updater | svchostz.exe | Added by the DAEMONI-E TROJAN! |
X | Microsoft Windows Updater | WINIUPDATES.EXE | Added by the RBOT-KK WORM! |
X | Microsoft Windows Updater | WINUPDATE.EXE | Added by the SDBOT-PU WORM! |
X | Microsoft Windows Updater | TMNTSrv.exe | Added by a variant of the RBOT WORM! |
X | Microsoft Windows Updater | win32upd.exe | Added by the RBOT-EC WORM! |
X | Microsoft Windows updaterD | log32zx.exe | Added by the MYDOOM.W WORM! |
X | Microsoft Windows Updates | explorer32.exe | Added by the SDBOT.VQ WORM! |
X | Microsoft Windows W32 Services | mssw32.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft Winsock Wrapper | ws2_32s.exe | Added by a variant of the SPYBOT WORM! |
X | Microsoft WinUpdate | mntcgf032.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft WinUpdate | svh0st.exe | Added by the SPYBOT.DL WORM! |
X | Microsoft WinUpdate | syslx32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Microsoft WinUpdate | syswin32.exe | Added by a variant of the SDBOT WORM! |
X | Microsoft WinUpdates | serm32.exe | Added by the RBOT.GE WORM! |
X | Microsoft Word | BootSector.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
N | Microsoft Works Calendar Reminders | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
N | Microsoft Works Portfolio | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio |
N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works |
X | Microsoft World Service | winworld.exe | Added by an unidentified IRC worm with backdoor capability! |
X | Microsoft Wxdate | Syswu32.exe | Added by the SPYBOT.HZ WORM! |
X | microsoft xdaemon 2.0 | xdaemon.exe | Added by the DELF.D TROJAN! |
X | Microsoft XML Service | msxmlx.exe | Added by the RBOT.KS WORM! |
X | Microsoft--Updates | sxvhost.exe | Added by the RBOT-FH WORM! |
X | Microsoft-Update | wngard.exe | Added by the RBOT-JV WORM! |
X | Microsoft-Updates | svxhost.exe | Added by the RBOT-CT WORM! |
X | microsoft420 | microsoft420.exe | Added by the MENACE.B WORM! |
X | Microsoftkeysd | systemproc.exe | Added by the FORBOT-BI WORM! |
X | Microsoftkeysd | systemwin32s.exe | Added by the WOOTBOT.CO WORM! |
X | Microsoftkeysds | lass32.exe | Added by a variant of the RBOT WORM! |
X | Microsoftmsn32.exe | microsoftmsn32.exe | Added by the CERTIF-C TROJAN! |
X | MicrosoftMultimediaTask | Mmtask.exe | Adware downloader - not the valid MusicMatch Jukebox which shares the same filename |
X | MicrosoftNetwork Daemon for Win32 | NETD32.EXE | Added by the RANDEX.F WORM! |
X | MicrosoftOEM | smvss.exe | Added by the DEDLER-G TROJAN! |
X | Microsofts media | winmplayd.exe | Added by an undidentified WORM or TROJAN! |
X | Microsofts media | wingtp.exe | Added by the RBOT-VO WORM! |
X | Microsofts MediaScope | winmep.exe | Added by the RBOT-WB WORM! |
X | Microsofts Security Manager | ****.exe [**** = random char] | Added by the RBOT-WH TROJAN! |
X | Microsofts Updatez | cmsssr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | MicrosoftServiceManager | mstask32.exe | Added by the YAHA.P WORM! |
X | MicrosoftServiceManager | Wintsk32.exe | Added by the YAHA.U WORM! |
X | MicrosoftServiceManager | EXPLORERE.EXE | Added by the YAHA.AB WORM! |
X | MicrosoftServiceManager | msupdat.exe | Added by the YAHA.AA WORM! |
X | MicrosoftSourceSafe | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
X | MicrosoftUpdate | syshelper.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | MicrosoftUpdate | WinUp32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | MicrosoftValue | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
X | Microsoftvirus | sysoverload.exe | Added by the FORBOT-AL WORM! |
X | MicrosoftWindows | [various filenames] | MagicSearch - a CoolWebSearch parasite variant |
X | Microsoft© PID Lex | PIDLex.exe | Added by the NIOVADOOR TROJAN! |
X | Microsoft® System Mapper | SysMap.exe | Added by the MAPSY TROJAN! |
X | Microszoft Update Mach1nezs | svchst.exe | Added by the RBOT-ED WORM! |
X | Microzoft_Ofiz | KdzEregli.exe | Added by the AMUS.A WORM! |
X | Micrsoft Driver | windrive.exe | Added by the SDBOT.AF TROJAN! |
N | MightyFAX Controller | MFNTCTL.EXE | Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software" |
? | MigrationVendorSetupCaller | rundll32.exe migrate.dll, CallVendorSetupDlls | ?? |
N | MimBoot | mimboot.exe | Starts Musicmatch Jukebox at bootup - can be started manually |
X | MINIBUG | MINIBUG.EXE | Displays ads inside Weatherbug - see here |
N | MINIFERT.EXE | MINIFERT.EXE | Part of Backweb |
U | minilog | MINILOG.EXE | If you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use |
N | MiniMavis | MiniMavis.exe | Mavis Beacon typing tutor |
N | MiniNote | MININOTE.EXE | Mini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software |
? | Miniphone | glophone.exe | VoiceGlo Glophone Voice over Internet Protocol (VOIP) communications software - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" - is it required in startup? |
U | MinMaxExtender | Mmext.exe | MinMaxExtender - window handling tool |
X | Miosf Update | wimsqaad.exe | Added by the SDBOT.AG TROJAN! |
N | Mirabilis ICQ | NDetect.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
N | Mirabilis ICQ | icq.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
N | Mirabilis ICQ | ICQNet.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
U | Miramar Systems, Inc. | atmsg.exe | Miramar PC/Mac networking software |
X | Mirate Sp 2 Information | miratesp2.exe | Added by the RBOT.QH WORM! |
N | miroVIDEO Tray Tool | misitray.exe | Tool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions |
U | MirrorFolderShell | mrfshl.exe | MirrorFolder backup software |
? | misiCTRL | misiCTRL.exe | Miro video driver related. Is it required? |
? | misiTRAY | misiTRAY.exe | Miro video driver related. Is it required? |
N | Mixer | Mixer.exe | C-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs |
N | Mixghost | mixghost.exe | Management software for Altec Lansing speakers. If a change is needed, the user can launch it from the Start menu |
X | mload | lxmstart.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
? | MM Install | setup.exe | Possibly Money Manager from Moneysoft? |
X | mmcndmgr | mmcndmgr.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | MMCWINMGMT | winmgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
U | MMERefresh | MMERefresh.exe | Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R |
X | Mmgsvc | mmgsvc.exe | Mmgsvc spyware |
U | MMhid | mmhid.dll | This is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP |
? | MMHK | mmhk.exe | A driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys? |
N | MMHotKey | MMHotKey.exe | Multimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen |
U | MMKeybd | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
X | mmod | mmod.exe | Ezula - regarded as spyware/theftware and bundled with the popular iMesh and KaZaA file-sharing programs. Read here for more information |
N | mmpti | m1mmpti.exe | Mpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards |
? | MMRun | mmrun.exe | ?? |
? | mmsys | recover.exe | ?? |
X | MMSystem | RunDll32 | Added by the FUNNER-A WORM! |
Y | MMTASK | mmtask.tsk | A check on the file's properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc |
N | mmtask | mmtask.exe | Part of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator |
X | MMtask Service | mmtask.exe | Added by the BACKGAT.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
N | MMTray | mm_tray.exe | MusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator |
N | MMTray | MMTray.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
N | MMTray2K | MMTray2K.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
N | MMTrayLSI | MMTrayLSI.exe | Part of Morgan Multimedia Codecs. Only required when the codecs are used |
? | mmusrstp | procrun.exe | ?? |
X | mmxrun | msosa.exe | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return |
X | mmxrun | mswinindex.exe | TwoSeven spyware |
X | MNPol | mnpol.exe | Added by the DLUCA.B TROJAN! |
U | MNS | MNS.exe | Mobile Net Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more |
X | mnsvc | mnsvc.exe | Added by the AUTOUPDER TROJAN! |
X | mnsvcsp | mnsvcsp.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | mobsync | mobsync.exe | MS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages |
X | MOBSYNC32.EXE | mobsync32.exe | Added by the FINERO TROJAN! |
N | MOD | muamger.exe | MicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them |
X | Modem | locatesvc.exe | Added by a variant of the SPYBOT WORM! |
U | MODEMBTR | MODEMBTR.EXE | Modem Booster from inKline Global to improve ISP connections |
X | Modeminf | Modeminf.exe | Added by a variant of the CRYPTER.C TROJAN! |
U | ModemOnHold | MOH.EXE | NetWaiting Modem-on-Hold Application |
N | ModemUtility | mdmsetpe.exe | System Tray configuration icon for Aztech modems |
X | ModularConfig | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
X | Module Call initialize | RUNDLL32.EXE reg.dll, ondll_reg | Added by a variant of the LOVGATE WORM! |
N | Money Express | moneyexpress.exe | Part of MS Money. Available via Start -> Programs |
N | MoneyAgent | money express.exe | Part of MS Money. Available via Start -> Programs |
N | MoneyAgent | mnyexpr.exe | Microsoft Money |
N | MoneyStartUp | Money Startup.exe | Microsoft Money |
N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs |
X | monitor | monitor.exe | Browser hijacker, redirecting to NCM Search |
U | Monitor Apache Servers | ApacheMonitor.exe | Part of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs |
X | Monitoring Service | svchost.exe | Added by the CONE.C WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Monitormgt | Monitormgt.exe | Added by the GEMA TROJAN! |
N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel |
X | MonTest | vccxzq.exe | Added by the SDBOT-EA WORM! |
U | MoodBook | mb.exe | MoodBook is a free Windows utility that brings art to your desktop |
N | moon phase | moon.exe | Moon Phase - tray icon that indicates the phases of the moon |
N | Morpheus | morpheus.exe | MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it" |
X | mosearch | mosearch.exe | Fast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here |
N | Motive SmartBridge | mpbtn.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
N | Motive SmartBridge | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
U | MotiveMonitor | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
N | MotiveSB | MotiveSB.exe | System tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required |
U | MotMon | motmon.exe | Found on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it's not required |
U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start |
N | Mouse 32A | Mouse32A.exe | Mouse driver to control mouse functions from Azona. Available via Start -> Programs |
N | Mouse Suite 98 Daemon | pelmiced.exe | Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
X | mousebut | mousebut.exe | Added by the CRYPTER.A TROJAN! |
X | Mousecntl | mousecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
N | MouseCount | MC.exe | MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required |
X | mousedrv | mousedrv.exe | Added by the CRYPTER.A TROJAN! |
U | mouseElf | MC.exe | Genius NetScroll mouse driver - required if you use non-standard Windows driver features |
U | mouseElf | mouseElf.exe | System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features |
U | MouseImp | MImpHost.exe | MouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device" |
U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems |
N | Movielink Manager Uninstall | msvcmm32.exe | Auto-update for Movielink - internet movie rental System Tray access |
X | MovieNetworks | MovieNetworks.exe | MovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:Program FilesMovieNetworks directory |
X | Movieplace | Movieplace.exe | MoviePlace malware |
X | Mozilla Firefox | F1REF0X.EXE | Added by a variant of the SDBOT WORM! |
N | Mozilla Quick Launch | Netscp6.exe | Netscape 6 and Mozilla browsers |
N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers |
X | MP Tcloaxs | mptcloaxs.exe | Added by the RANDEX.CT WORM! |
U | MPEO | Csinsm32.exe | Automatic logging of installs from Norton CleanSweep - available via Start -> Programs |
Y | MPFExe | mpf.exe | McAfee Personal Firewall |
Y | MPFExe | MpfTray.exe | McAfee Personal Firewall |
Y | MPFTray | MpfTray.exe | McAfee Personal Firewall |
X | MPL32 driver | MPL32.exe | Added by the LOONY-M TROJAN! |
U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client |
U | MPower | MPower.exe | MPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
X | MPREXE | MPREXE.EXE | Added by the OPASERV.T WORM! Note - this is not the legitimate Mprexe.exe system file |
Y | MPREXE.exe | mprexe.exe | WIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus |
X | MprHTML | MprHTML.exe | Added by a variant of the VAGRNOCKER TROJAN! |
X | mprocessor | mprocessor.exe | InstallDollars.com foistware |
U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering" |
? | MPT | MPT.exe | ?? |
X | MPtask Services | mptask.exe | Added by the LALA or AOT TROJANS! |
N | MPTBox | MPTBOX.EXE | Cannon Multi-Pass toolbox - a button bar |
N | MPXTray | mpxptray.exe | Windows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc |
? | MP_STATUS_MONITOR | monitr32.exe | Related to Cannon Multi-Pass |
X | mqbkup | mqbkup.exe | Added by the OPASERV.K WORM! |
N | mrtMngr | mrtMngr.exe | Maintenance Release Task Manager for Intuit’s QuickBooks or Quicken |
U | MRU-Blaster Scheduler | scheduler.exe | MRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer |
N | MRU-Blaster Silent Clean | mrublaster.exe | MRU-Blaster - performs silent cleaning of MRU lists at boot |
X | MS Config Loader | svchos1.exe | Added by the AGOBOT.R WORM! |
X | MS Config Loader | MSWin32bck.exe | Added by the GAOBOT.AA WORM! |
X | MS Config Service | Msloader32.exe | Added by the RBOT-KJ WORM! |
X | MS Configuration | MSFramer.exe | Added by the RANDEX.OL WORM! |
X | MS Decryption Software | active.exe | MediaTickets adware variant |
X | MS Explorer | mexplore.exe | Added by the YAHA.AE WORM! |
X | MS FIREWALL | msfrewall.exe | Added by the SDBOT-PU WORM! |
X | MS FIREWALL | msfirewall.exe | Added by the SDBOT-QH WORM! |
X | MS HTML | msHtml.exe | Added by the PESTDOOR.31 TROJAN! |
X | MS HTML | mslat.exe | Added by the LATINUS.SVR TROJAN! |
X | MS lsass Startup | lsass135.exe | Added by the RBOT.WM WORM! |
? | MS management console | mms.exe | Suspicious as the Microsoft Management Console is "mmc.exe" and doesn't normally run at startup |
X | MS Network Control | mswin.exe | Added by the DUMBA TROJAN! |
X | Ms Processe Manager | msproc.exe | Added by the RBOT.ATO WORM! |
X | MS Remote Procedure Call | msrpc32.exe | Added by the RBOT-QL WORM! |
X | MS Security Hotfix | service5.exe | Added by the GAOBOT.AG WORM! |
X | MS Sound Config 16bit | sndcfg16.exe | Added by the SDBOT.MB TROJAN! |
X | Ms Spool32 | MS SPOOL32.EXE | Added by the ASASSIN TROJAN! |
X | MS SyS Restore | sysrestore.exe | Added by the RBOT.XM WORM! |
X | MS Unix Binary | win32ttb.exe | Added by the SPYBOT.OQ WORM! |
X | MS Update | syshost.exe | Added by the EVAMAN-F WORM! |
X | MS Updates | mscache.exe | Spyware web downloader |
X | MS Updates | syshosts.exe | Added by the MYDOOM.Y WORM! |
X | MS Updates | aupd.exe | Spyware web downloader |
X | MS USB 2.0 Windows Support | msusb32.exe | Added by a variant of the RBOT WORM! |
X | MS Windows Update | scguard.exe | Added by a variant of the RBOT WORM! |
X | MS-Connect | arr.exe | Adult content dialler - see here |
X | MS-Connect | cdm.exe | Adult content dialler - see here |
X | MS-Connect | game.exe | Adult content dialler - see here |
X | MS-Connect | msite18.exe | Adult content dialler - see here |
X | MS-Connect | web.exe | Adult content dialler - see here |
X | MS-HTML | [random filename] | Added by the LATINUS.15 TROJAN! |
X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker |
X | MS7531 | ms7531.exe | Homepage hijacker |
X | MSACM | msacm.exe | Added by the OPASERV-O WORM! |
X | msadcheck | msadcheck32.exe | Browser hijacker, redirecting to search-system.com |
X | MSAdmin | jdbgmrg.exe | Added by the DASMIN.A TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
X | MSAgent | mshtm.exe | Browser hijacker - redirecting to buldog-search.com |
X | MSBB | msbb.exe | Advertising spyware |
X | MSChoExE | suge.exe | Added by a variant of the RBOT WORM! |
? | msci | mcinfo.exe | McAfee Internet Security related. What does it do and is it required? |
X | mscman | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
U | mscn | mscn.exe | Part of the SafeChildNet internet filtering program - required if you use it |
X | Mscnt | mscnt.exe | Added by the DLUCA-C TROJAN! |
X | Mscolour | mscolour.exe | Added by the GEMA TROJAN! |
X | MSCommX | mscommx.exe | Added by a variant of the RBOT WORM! |
X | MSCONFG32.EXE | MSCONFG32.EXE | Added by the OPTIX.04.C TROJAN! |
N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
X | MSConfig | MSCONFIG32.EXE | Unidentified adware, spyware or virus |
X | msconfig | msconfig.exe | CoolWebSearch parasite related. Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
X | Msconfig | msconfig.exe | Added by the WINUR WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
X | msconfig | wins.exe | Added by an unidentified IRC WORM with backdoor trojan capabilities! |
X | Msconfig lptt01 | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
X | MSConfig Manager | msupdate.exe | CoolWebSearch parasite related |
X | Msconfig ml097e | msconfig.exe | Variant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name |
X | msconfig service | MSupdate32.exe | Added by a variant of the SPYBOT WORM! |
X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
X | MSConfig45 | MSConfig45.exe | Added by the SDBOT.OJ TROJAN! |
X | MSConfigr | jdbgmrg.exe | Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here |
N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode |
X | MSCORE | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
X | Mscsgs | MSCSGS.EXE | Added by the ZEZER WORM! |
X | Mscsgs32 | MSCSGS32.EXE | Added by the ZEZER WORM! |
X | Msctrl32 | Msctrl32.scr | Added by the REDIST WORM! |
X | MSCVT | MSCVT.exe | Added by the SLIDESHOW WORM! |
X | msdev | msdev.exe | Added by the FORBOT-CR WORM! |
X | msdev | msconfig.exe | Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting |
X | MSDLL | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
X | Msdmxm | msdmxm.exe | Added by the DLOAD-DC TROJAN! |
X | Msdos32 | Msdos32.pif | Added by the RECORY WORM! |
X | msdos423 | msdos423.exe | Added by the MENACE.A WORM! |
N | MSDosdrv | msdosdrv.exe | Added by the BACROS WORM! |
N | MSDTC | msdtc.exe | MS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server |
X | Msemu32 | Msemu32.exe | Unidentified spyware/adware/hijacker |
X | Msfind | Msfind.exe | CoolWebSearch parasite variant |
X | MSFind32 | msfind32.exe | Added by the CAYAM WORM! |
X | msfindosa.exe | msfindosa.exe | Added by the DOWNLOADER-BS TROJAN! |
X | Msg Fixage | msgfixed.exe | Added by the SDBOT.ZD WORM! |
X | MsgApi | [path to file] | Added by the DEDLER-D TROJAN! |
X | msgb1 | msgb1.exe | Added by the DLUCA.GEN TROJAN! |
X | Msgmgr | [path to worm] | Added by the BABYBEAR WORM! |
X | msgserv_ | Syss.exe | Added by the FANTA TROJAN! |
X | Msgsrv16 | Msgsrv16.exe | Added by the DELF family of TROJANS! |
Y | MSGSRV32.exe | msgsrv32.exe | Windows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background |
X | msgsvr32 | msgsvr32.exe | Added by the DEADHAT.B WORM! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:WindowsSystem) on a Win9x/Me machine |
X | Msgtray | sys16.exe | Added by an unknown VIRUS! |
X | MSHT@ | MSHT@.EXE | Added by the MAGISTR.A VIRUS! |
X | msidle | msidle.exe | Added by the OPASERV-O WORM! |
X | MSIdll | winmp.exe | Added by a variant of the RBOT WORM! |
X | MSIEXEC | MSIEXEC32.exe | Added by the AINESEY.A WORM! |
? | MSIN | MSin.exe | ?? |
X | MSInfo | msinfo.exe | Added by the ALADINZ.M TROJAN! |
X | MSInfo | AVBgle.exe | Added by the NETSKY.O WORM! |
X | MSInstall | smvss.exe | Added by the DEDLER-G TROJAN! |
X | msjava service | xpcd.exe | Added by the SDBOT.VM WORM! |
U | MSKAGENTEXE | MskAgent.exe | Part of McAfee Spamkiller |
X | MSKCES32 | [random filename] | Added by the CLONER TROJAN! |
U | MSKDetectorExe | MSKDetct.exe | Part of McAfee Spamkiller |
X | MSKernel32 | MSKernel32.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
X | MSkernel32 | System.exe 4820 | Added by the TUXDER TROJAN! |
U | MSKExe | spamkiller.exe | McAfee SpamKiller |
X | mskj | mskj.exe | Added by the KAEMON TROJAN! |
U | MSKServerExe | MSKSrvr.exe | Part of McAfee Spamkiller |
X | mslagent | mslagent.exe | Added by SIMCSS.B adware! |
X | MSLARISSA | MSLARISSA.pif | Added by the ASSIRAL.B WORM! |
? | MSLIB32 | mswatch32.exe | ?? |
X | Mslogon lptt01 | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Mslogon ml097e | mslogon.exe | Variant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | MsManager | msmgr32.exe | Added by the YAHA.AF WORM! |
X | msmanager32 | msmngr32.exe | Added by the RANDON-R (or WOMANIZ.A) WORM! |
X | msmc | mscpbo.exe | ClientMan parasite variant |
X | msmc | msgdmf.exe | ClientMan parasite variant |
X | msmc | msongn.exe | ClientMan parasite variant |
X | msmc | msmc.exe | ClientMan parasite variant |
X | msmc | ms****.exe [* = random char] | ClientMan parasite variant |
X | MSMcAfeee | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! |
X | MSMcAfeeh | Avsynmgr32h.exe | Added by the FRANGO TROJAN! |
X | MSMcAfeeS | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! |
? | msmgr | msmgr.exe | ?? |
X | Msmgt | msmgt.exe | Total Velocity adware/hijacker |
X | msmon | msmon.exe | Added by a variant of the GEMA.D TROJAN! |
? | MsmqIntCert | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? |
U | MSMSGS | msmsgs.exe | Windows Messenger utility. If you don't use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
X | MSMsgSvc | MSMSGSVC.exe | Browser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN! |
X | msn | system32.exe | Added by the KITRO.A WORM! |
X | msn | msnmsg.exe | Added by the RBOT-GO WORM! |
X | MSN | msnmsgs.exe | Added by the RBOT-KL WORM! |
X | MSN | ctfmoons.exe | Added by the SPYBOT.HI WORM! |
X | MSN | msnmesengers.exe | Added by the RBOT-ME WORM! |
X | MSN | MSN.exe | Added by the MINIT WORM! |
X | MSN | msnmsgr.exe | Added by the MYTOB or MYTOB.B WORMS! Note - this is not the valid MSN Messenger utility |
X | MSN ang | cssrss.exe | Added by the FORBOT-CE WORM! |
X | Msn Config | msngf.exe | Added by the RBOT-QG WORM! |
N | MSN Internet Access | trayclnt.exe | Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards |
X | MSN Manager | cvss.exe | Added by a variant of the SPYBOT WORM! |
X | MSN Manager | mscmgr.exe | Unidentified malware - causes multiple browser windows to open |
X | MSN Messanger | msnmsng.exe | Added by the SDBOT.XN WORM! |
X | MSN messenger | messenger.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
X | Msn Messenger | msnmsgs.exe | Added by the LOONY-P TROJAN! |
X | MSN Messenger | Reosmsngr.exe | Added by a variant of the SPYBOT WORM! |
X | MSN messenger service | mssgs.exe | Added by an unidentified TROJAN! Note - this is not the real MSN Messenger, see this thread |
X | Msn Messengers | MSNMSGR.EXE | Added by the RBOT.KX WORM! |
X | Msn Patch | msndp.exe | Added by the RBOT.AAI WORM! |
X | Msn Patches | msndr.exe | Added by a variant of the SDBOT WORM! |
X | Msn Plus Updater | msnplus.exe | Added by the RBOT-MU WORM! |
N | MSN Quick View | Msndc.exe | Quick way to connect to MSN internet service |
X | MSN Start | msnmsgr7.exe | Added by the RBOT-PH WORM! |
X | MSN Update | mscon.exe | Added by the RBOT-QA WORM! |
X | Msn Update Manager (Sp2) | MSMSGS.EXE | Added by the AGOBOT-NL WORM! |
X | MSN Updater | msnms.exe | Added by the FORBOT-CG WORM! |
X | Msn Updater | msnplugins.exe | Added by the RBOT-HS WORM! |
X | MSN UPDATERS | virtualmemory.exe | Added by the RBOT-JK WORM! |
N | msnappau | msnappau.exe | Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar |
X | Msnarrator | msnarrator.exe | Added by the NARAT.A TROJAN! - also identified as MPGCOM Toolbar adware |
X | MSNET | msnet.exe | Added by the BOA WORM! |
X | MsnExplorer | winagent.exe | Added by the EQ TROJAN! |
? | MsnFixer | msnfixjs.js | Located in the HPbinmsnfix directory of a HP PC |
X | MSNGrabber | MSNgrabber.exe | Added by the ENVID.A WORM! |
N | MSNIA | MSNIASVC.EXE | Added with MSN version 9. Resets certain internet settings upon bootup and can't be disabled via MSCONFIG |
X | msnload32.exe | msnload32.exe | Added by the BANCOS.M TROJAN! |
X | MSNMESENGER | Main.exe | Added by the PRORAT TROJAN! |
X | msnmsg.exe | mscmd32.exe | Added by a variant of the AGENT.AH TROJAN! |
X | msnmsgq32 | msnmsgq.exe | Trojan, possibly EliteBar parasite related |
N | msnmsgr | msnmsgr.exe | MSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts" |
X | MsnMsgr | MsnMsgrs.exe | Added by the NETSKY-AD WORM! |
X | msnmsgr32-.exe | msnmsgr-.exe | Added by a variant of the SPYBOT WORM! |
X | MSNMSGR5 | MSNMSGR5.exe | Added by the RBOT.PQ WORM! |
X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM! |
X | MSNMSGRR | swin.bat | IRC backdoor TROJAN or WORM! |
X | MSNMSGRS1 | swed.bat | IRC backdoor TROJAN or WORM! |
X | msnmsgsgs | msnmsgsgs.exe | Added by the "Catal" alias Spy.Delitall.B backdoor TROJAN! |
X | MSNPluginSrvcs | p6.exe | Added by the SDBOT.AKJ or RBOT-VJ WORMS! |
X | MSNPluginSrvcs | sagate.exe | Added by the SDBOT.AKJ WORM! |
X | MSNService | MSNService.exe | Added by the CARPET.C WORM! |
X | MSNSysRestore | pc32.exe | Added by a variant of the MASTAK VIRUS! |
X | MSObject32 | MSObject32.js | Added by the PUN TROJAN! |
X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net |
X | MSOffice | services.exe | Browser hijacker. The file is placed in a newly created MSOffice folder in System32. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup! |
X | MSOleath32 | winss.exe | Added by the KATHER TROJAN! |
X | MSOOBD | MSOOBD.EXE | Added by the MAGISTR.A VIRUS! |
X | mspaint.exe | check32.exe | Added by the AGENT.AH TROJAN! |
X | Mspatch69 | [path to trojan] | Added by the MPROX TROJAN! |
X | Mspatch89 | cnqmax.exe | Added by the RANDEX.P WORM! |
X | MSPQFile | MSA****.TMP | Homepage hijacker. See here for more information. **** can be anything |
X | MSprotect.exe | MSprotect.exe | Added by the DABYREV.A VIRUS! |
U | mspwr | pupstman.exe | "Transparent icon background" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) |
N | MSPY2002 | ImScInst.exe | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
X | MSR | msr.exe | Added by the AGOBOT.RT WORM! |
X | Msrc | Msrc.exe | Added by the KRYPTONIC GHOST TROJAN! |
X | msreg.exe | msrege.exe | Added by the ZINX TROJAN! |
X | msReg32 Loader | msreg32.exe | Added by the AGOBOT.IU WORM! |
X | MSREGIT | Msgp.exe | Added by the KRYPGHOS.13 TROJAN! |
X | MSRegSvc | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
X | msrundll | msrund1l32.exe | Added by the BINGHE TROJAN! |
X | msrunocx32 | msrunocx32.exe | Added by the SKUS WORM! |
X | msservice | msserv.exe | Added by the HYD WORM! |
X | MSSGisg | [path to file] | Added by the RANKY.N TROJAN! |
X | MSSHVC | MSSHVC.exe | Added by the NUFFY.A WORM! |
X | mssoul | msmscc2.exe | Added by the DAPIZL.A banker WORM! (A "banker worm" is designed to pillage banking information and send it back to the perpetrators!) |
X | MSSQL | Mssql.exe | Added by the SDBOT TROJAN! |
X | Msstart | msstart.exe | Added by the LIVUP.C TROJAN! |
X | MSStartOptimizer | Iexpres.exe | Added by the POLDO.B TROJAN! |
X | MSStartOptimizer | WINUPD.EXE | Adult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
X | msstask | msstask.exe | Added by the MYPARTY WORM! |
X | mssurfer lptt01 | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | mssurfer ml097e | mssurfer.exe | Variant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | mssvc | [path to trojan] | Added by the PSK TROJAN! |
X | MSSVC | svcsys.exe | Added by the FATOOS-C TROJAN! |
Y | MSSVC.EXE | MSSVC.EXE | Stealthdisk - hides folders, files and applications. Will also encrypt them for better protection |
X | mssvc32 | mssvc32.exe | Added by the AGOBOT-ME WORM! |
X | mssys | mssys.exe | Added by the MYSS.B TROJAN! |
X | mssysint | Iexplore .exe | Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
X | mssyslanhelper | msmsgri32.exe | Added by the RANDEX.D WORM! |
X | MsSystem | msdos.exe | Adult content downloader - see here |
X | MsSystem | mssys.exe | Added by the VANTA.A TROJAN! |
X | MSSYSTEM | svcsys.exe | Added by the FATOOS-C TROJAN! |
X | Mstapi | Mstapi.exe | Keylogger trojan |
X | Mstask | mstask.exe | Added by the OPASERV.N WORM! Note - this is not the legitimate mstask.exe system file and the executable resides in C:Windows or C:WINNT |
X | mstask | mstask.exe | Browser hijacker - redirecting to find-more.net. Note - this is not the legitimate mstask.exe system file |
X | mstasks | mstasks.exe | Added by the MULTIDR-AY TROJAN! |
? | Mstcgww | MSTCGWW.EXE | ?? |
N | MSTMON_Q | MSTMON_Q.exe | Generates an error message on startup if the Konica Minolta PagePro 1350W printer is not turned on and ready |
X | Mstng32 | MSTng32.exe | Added by the TANG WORM! |
X | MSUpdate | wupd.exe | Added by the ALADINZ.M TROJAN! |
X | MSUpdate | svchosthlp.exe | Added by the BLASTER.T WORM! |
X | msupdate | msupdate.exe | Added by the RBOT-MZ WORM! |
X | MSUpdate | criticalUpdate.exe | Affilred adware |
X | MSupdate.exe | N/A | CoolWebSearch parasite related - resets home page to an adult content site |
X | MsUpdater System | udpsys32.exe | Added by the RBOT.AAA WORM! |
X | MSupdater.exe | N/A | CoolWebSearch parasite related. Installs the Winshow.dll browser plugin |
X | msupdates | msupdt.exe | Added by the RBOT-JO WORM! |
X | MSUpdSrv | msupdsrv.exe | Browser hijacker, redirecting to a porn site |
X | msurl | msurl32.exe | Added by the CRYPTER.A TROJAN! |
X | msuser32.exe | msuser32.exe | Added by the ANDROV TROJAN! |
X | MsVBdll | sys32dll.exe | Added by the AIMDES.B or AIMDES.C WORMS! |
X | msvc32 | msvc32.exe | ClientMan parasite variant |
X | msvcc | msvchost.exe | Added by the XOMBE TROJAN! |
X | MSVersion | INTERNETFEATURES.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
X | MSVersion | clrschp038.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
X | msvsc32 | msdev.exe | Added by the RBOT-GJ WORM! |
X | MSVSync | videosync.exe | Added by a variant of the SPYBOT WORM! |
X | MSVXD | MSVXD.EXE | Added by the DATOM.A WORM! |
X | mswave | mswave.exe | Added by the CRYPTER.A TROJAN! |
X | Mswavedll | mswavedll.exe | Added by the CRYPTER-C TROJAN! |
U | MSwheel | mswheel.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
X | Mswincfg | Mswincfg32.exe | Added by the CYBRSPY.D TROJAN! |
X | MsWindows SysDate | sysmsvc.exe | Added by the SPYBOT.FCD WORM! |
X | Mswinpid32 | mswinpid32.exe | Added by the LAPOS.A TROJAN! This is a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim! |
X | MSWinSrv | MSWinSrv.exe | Added by the MTRON TROJAN! |
X | MSWinSrv32 | MSWinSrv32.exe | Added by the MTRON-B TROJAN! |
X | mswspl | [random filename] | Added by the SMALL.IQ TROJAN! |
X | mswspl | searchbarcash.exe | SearchBarCash adware |
X | msys lptt01 | msys.exe | New variant of the RapidBlaster parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Msys32 | morfitwebentrance.exe | Morfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage |
X | MS_LARISSA | MS_LARISSA.exe | Added by the ASSIRAL WORM! |
X | MS_NETD_WIN32 | netd32.EXE | Added by the RANDEX.F WORM! |
X | MS_SETUP.EXE | MS_SETUP.EXE | Added by the CHARGE TROJAN! |
X | Mtr2 | mtr2.exe | Added by the KRYPTONIC GHOST TROJAN! |
U | MUAL | mual.exe | Millesky video mail updater and launcher |
U | muamgr | muamgr.exe | Quick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut's text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs |
? | Mufix | mufix.exe | Part of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required |
U | Multi-function keyboard | GWHotkey.exe | Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc) |
U | MultiCAM Initializer | MCamBoot.exe | The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled |
X | Multimedia Codecs | mcc.exe | Added by the DLOADER-MB TROJAN! |
X | Multimedia extensions | mservice.exe | EasySearch adware |
U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys |
U | MultiRes | MultiRes.exe | MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP |
U | MUPS | MUPS.exe | Lauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions |
Y | murphy shield | lmgui.exe | Firewall part of BitDefender virus scanner/firewall |
N | Music01 Server | Music01 Server.exe | J River Media Jukebox |
X | MusIRC (irc.music.com) client | musirc4.71.exe | Added by the RANDEX.Q WORM! |
N | MutexServiceEx | Sys32Smm.exe | Webroot Sofware's discontinued "Privacy Master" |
U | mwavscan | mwavscan.com | MicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive |
N | MWProEng | MWProEng.exe | Logitech Mouseware Pro software - only required when using special functions |
N | MWSnap | MWSnap.exe | MWSnap - screen capture utility. Start manually when required |
X | mwsoemon | mwsoemon.exe | "My Web Search" malware |
X | Mwsvm | mwsvm.exe | SeekSeek search hijacker related - as seen here |
X | MxHLp32 | MxHLp32.exe | Added by a variant of the VAGRNOCKER TROJAN! |
U | MXO Auto Loader | MXOaldr.exe | Maxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions |
U | MxRunner | MxRunner.exe | EasyUninstall from Aladdin Systems (formerly by Ontrack) |
X | My Agent | msagent.exe | Added by the NEGASMS.A TROJAN! |
X | My App | SMSSvc.exe | Added by the NEGASMS.A TROJAN! |
X | My Search Bar Eq | S4BAREQ.EXE | MySearch bar parasite |
U | MyAgtTry | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
X | Myapp | [filename] | Added by the FATEE.B WORM! |
X | Myapp | service.exe | Homepage hijacker |
X | MyAV | avpguard.exe | Added by the NETSKY.J WORM! |
Y | MyCIO Agent Service | myagtsvc.exe | McAfee VirusScan ASaP Agent service |
U | myCIO.com ASaP | MyAgtTry.exe | System tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications |
N | myCIO.com Splash | Splash.exe | Splash screen for McAfee VirusScan ASaP on-line scanner |
X | MyCometCursor | MYCOME~1.EXE | Comet Cursor adware |
X | MyDailyHoroscope | MYDAIL~1.EXE | MyDailyHoroscope foistware |
X | MyDailyHoroscope | MyDailyHoroscope.exe | MyDailyHoroscope foistware |
N | MyFastAccess | myfastupdate.exe | My-Fast-Access toolbar updater |
X | MyLife | CmdServ.exe | Added by the HOLAR.A WORM! |
U | myNetWatchman | nwclient.exe | Sends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running |
X | MyPointsPointAlert | wjview ...MyPointsPointAlertrun.exe | "With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy |
U | myprint mileage | mpm.exe | Reports battery status on a portable printer |
X | mysoft | winexplor.exe | Homepage hijacker |
? | MySoftware NewsFlash | Newsflsh.exe | ?? |
U | MytekSystrayExePath | MyTekSystray.exe | MyTek system tray - web site providing computer tech support in Australia |
X | MyTotalSearch Email Plugin | mtsoemon.exe | MyTotalSearchBar adware |
X | MyVirt.exe | MyVirt.exe | Added by the REMADM-C TROJAN! |
U | MyVitalAgent | VtlAgent.exe | MyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs |
X | MyWebSearch Email Plugin | mwsoemon.exe | "My Web Search" malware |
U | N2PTray | Net2fone.exe | An Internet telephony application. Needed only if you have an account at Net2Phone, Inc |
N | NADaemon | NADAEMON.EXE | Program by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required |
N | Naggerrunkey | nagger.exe | Packard Bell Free Internet Signup screen |
Y | Naimagent_service | EPOAgentnaimas32.exe | Networked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages |
Y | Naimagent_UI | EPOAgentnaimag32.exe | Workstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan |
Y | Naimagent_UI | naimag32.exe | Workstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan |
X | Name | Iexplorer0.exe | Added by the THREADSYS TROJAN! |
X | NAP32 | NAP32.exe | Premium rate adult content dialler |
X | Narrator | ******.exe [* = random char] | Transponder/VX2 related adware |
X | Natal | Natal.scr | Added by the OPASERV.AE WORM! |
X | NAV | RuxDLL32.exe | Added by the MAPSON.D WORM! |
Y | NAV Agent | navapw32.exe | Norton Anti-Virus's background scanning process |
X | nAv AGENT | N/A | Added by the RIOSYS MACRO! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes |
X | NAV Agent | systems.exe | Added by the TARNO.C TROJAN! Note - this is not the valid Norton Antivirus entry of the same name |
X | NAV Agent | winsnav.vbs | Added by the ANPES WORM! |
X | NAV Auto Protect | msfwe1.exe | Added by a variant of the RBOT WORM! |
X | NAV Auto Protect | navprotect.exe | Added by a variant of the RBOT WORM! |
X | NAV Auto Protect | dnsserv.exe | Added by a variant of the SDBOT WORM! |
X | NAV Auto Protect | mcafee32.exe | Added by a variant of the SPYBOT WORM! |
X | NAV Auto Update | Navautoupdate.exe | Added by a variant of the SPYBOT WORM! |
X | NAV Auto Updates | csrssp.exe | Added by a variant of the SDBOT WORM! |
X | NAV Auto Updates | navwindows.exe | Added by a variant of the SDBOT WORM! |
N | NAV CfgWiz | cfgwiz.exe | Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
N | NAV Configuration Wizard | cfgwiz.exe | Introduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it |
U | NAV DefAlert | DefAlert.exe | Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis |
X | NAV Live Update | [path to worm] | Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec |
X | NAV Scan Service | NAVSCAN32.EXE | Added by the SDBOT.VG WORM! |
X | NavAgent32 | lasvr32.exe | Added by the FEMOT.D WORM! |
X | NavAgent32 | SCardSvr32.Exe | Added by the MOFEI.B WORM! |
X | navapp | navapp.exe | NavExcel adware variant |
Y | navapw32 | navapw32.exe | Norton Anti-Virus's background scanning process |
U | Naviscope | naviscope.exe | Naviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more |
X | NaviSearch | nls.exe | NaviSearch, eXact Advertising variant |
X | navman_20 | sysnav32.exe | Hijacker, possibly a CoolWebSearch variant |
X | navp.exe | navp.exe | Added by the AGOBOT-OE WORM! |
X | NavPass | NavPass.exe | Free system for gaining access to and downloading from adult content web-sites |
X | NavScan | [filename] | Added by the OBSORB TROJAN! |
X | NAVSCANNER32 | NAVSCANNER32.EXE | Added by the RBOT.QC WORM! |
X | NAVUpd | rundll32.exe navupd.dll, Startup | Added by the NAVU TROJAN! |
N | NB Common Dialog Enhancements | COMDLGEX.EXE | Part of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs |
N | NB Start Menu | STARTM.EXE | Part of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B |
N | NB Windows Patterns | WINDBKGND.EXE | Part of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows |
U | NBJ | NBJ.exe | Ahead Nero BackItUp backup program. Only required for if you have scheduled back-ups |
U | NbkCtrl | NbkCtrl.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here |
X | NBT System alias | [path] repcale.exe [path] beird.exe | Added by a variant of the RANDON.AN WORM! |
? | NCClient | N/A | ?? |
N | NCD | ncd.exe | Norton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path |
? | NCLAUNCH | NCLAUNCH.Exe | Part of SWF Studio from Northcode Inc - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP. Is it required? |
N | NCS_SS | Csinsm32.exe | Same as CleanSweep Smart Sweep-Internet Sweep |
X | NDAv | csnss.exe | Added by the SERFLOG.C WORM! |
X | NDAv | svhost.exe | Added by the SERFLOG.C WORM! |
? | NDDEAGNT | NDDEAGNT.EXE | WinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services |
X | NDIS Adapter | ndis.exe | Added by the SDBOT.VF WORM! |
X | NDIS Adapter | windows.exe | Added by the FORBOT-BR WORM! |
X | NDIS Adapter | lsass2.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | NDplDeamon | nstask32.exe | Added by the RANDEX.E WORM! |
X | NDplDeamon | winlogin.exe | Added by the RANDEX.E WORM! |
U | NDPS | DPMW32.EXE | Novell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature |
X | NDrv | NDrv.exe | PurityScan/Clickspring adware |
U | NDSTray | NDSTray.exe | ConfigFreeT Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have |
N | Necbar | Necbar.exe | Nec Assistant; Ark's Navigator, a graphical interface for NEC computers |
Y | NECMFK | necmfk.exe | NEC wireless keyboard driver |
U | Necutray | Necutray.exe | Driver for external USB storage devices (hard drives, flsh disks, etc) |
? | neqprvfy.exe | neqprvfy.exe | Appears to be related to the downloading of some application - possibly verifying updates? |
X | Nero.ma | ***.exe [*** = 2 to 3 digits] | Added by the JONBARR.D WORM! |
X | NeroAutoStartClient | NeroASM.exe | Added by the AGOBOT.VG WORM! |
U | NeroCheck | nerocheck.exe | Associated with "Nero Burning Rom" CD writing software. Checks for driver issues |
X | NeroCheck | regedit.exe | Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:Windows or C:Winnt wheras this version resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) |
U | NeroFilterCheck | NeroCheck.exe | Associated with "Nero Burning Rom" CD writing software. Checks for driver issues |
N | NeroNETTrayIcon | NNServiceCtrl.exe | System tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network |
X | Net | WINREG.EXE | Added by the ASSASIN.D TROJAN! |
U | Net Accelerator | NetAccelerator.exe | Rizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance |
U | Net Activity Diagram | nad.exe | Net Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs |
N | Net-It Launcher | NILaunch.exe | Net-It - web publishing software |
U | NetAccelerator | NetAccel.exe | NetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance |
X | NetAdm7 | NETADM7.EXE | Added by the BANCOS.F TROJAN! |
X | Netapi | Netapi.exe | Added by the NETDEVIL.14 TROJAN! |
X | NetApp | winserv.exe | Added by the SHADOWTHIEF TROJAN! |
X | netconfig | netconfig.exe | Added by the NETCONF TROJAN! |
U | NetCruiser Dialer | NCDialer.exe | NetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections" |
X | netdaemon | netdaemon /v | Malware designed to "kill" a number of antispyware applications (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more) |
X | netdll32 | netdll32.exe | Added by the CRYPTER.A TROJAN! |
X | netdllex | netdllex.Exe | Added by the CRYPTER.A TROJAN! |
X | NetDy | VisualGuard.exe | Added by the NETSKY.N or NETSKY.W WORMS! |
X | NETFP32.EXE | NETFP32.EXE | Added by the AGENT.CD TROJAN! |
? | netfxupdate | netfxupdate.exe | Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan? |
? | NetFxUpdate_v1.0.3705 | netfxupdate.exe | Would appear to be a valid Microsoft .NET file (see here) but this suggest's it's a trojan? |
U | NetGuard | NetGuard.exe | FBM Software ZeroSpyware 2004 spyware detector and remover - real time monitor |
U | Netlimiter | Netlimiter.exe | Netlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC." |
N | Netline User | netchk.exe | Netline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example |
X | NetLink | netlink32.exe | Added by the GAOBOT.WO WORM! |
X | NetLogon | userint.exe | Added by the SDBOT-BC WORM! |
X | NetManagerService | ntss.exe | Added by the BESTPICS.A TROJAN! |
X | NetMeter | NetMeter.exe | NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided! |
X | NetMon | netmon.exe | Added by the MIMAIL.M WORM! |
U | netmsg | netmsg.exe | Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well |
U | NetPatrol | winclient.exe | NetPatrol network monitoring software |
X | netpc32.exe | netpc32.exe | Malware, probably CoolWebSearch parasite related |
N | NetPerSec | NetPerSec.exe | NetPerSec - measures the real-time speed of your Internet connection |
N | NetPumper | NetPumperIEProxy.exe | NetPumper download manager - bundles Cydoor and SaveNow adware, see here |
X | NetReach | nrcheck.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Netropa Internet Receiver | Netropa.exe | Netropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware |
U | NetRun | NetRun.exe | NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost |
N | Netscape Messenger | NETSCAPE.EXE | In Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed |
N | Netscp6 | Netscp6.exe | Netscape 6 |
X | netservices | recall.exe | Added by a variant of the SDBOT WORM! |
U | NetShow Powerpoint Helper | NSPPTHLP.EXE | If disabled, user created fonts can no longer be seen by other programs |
N | NetStat Live | Nsl.exe | AnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data |
X | netsv32 | netsv32.exe | Added by the SDBOT-PX WORM! |
U | NetTime | NETTIME.EXE | From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP." |
U | NetTurbo | netturbo.exe | NetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled |
X | Netunit32 | wunit32.exe | Added by an unidentified WORM or TROJAN! |
X | NetWatch32 | netwatch.exe | Added by the MIMAIL.C WORM! |
N | Netword Agent | nwant33.exe | An interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs |
X | NetWork | csrs.exe | Added by the AGOBOT.JJ WORM! |
X | Network Administration | NAS.exe | Added by the ANTILAM.20.Q TROJAN! |
X | Network Administration Service | rsvc32.exe | Added by the RBOT.ABH WORM! |
U | Network Associates Error Reporting Service | TBMon.exe | Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software |
U | NetWork Device Switch | NetDevSW.exe | Toshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary |
X | Network Host Controller | [path to trojan] | Added by the WHISPER TROJAN! |
X | Network Protocol Service | wuamgrd.exe | Added by the RBOT.EA WORM! |
X | Network protocol service | wintcp.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Network Security Guard | **********.exe [* = random char] | CoolWebSearch parasite related |
X | Network Service | svchost.exe | CoolWebSearch parasite related. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Network Service Manager | netsvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Network Service Manager | netsvc.exe | Added by a variant of the GAOBOT/AGOBOT WORM! |
X | NetworkAssociates Inc | internet.exe | Added by the LOVGATE WORM! |
X | NetworkClient | NetworkClient.exe | Added by the LEMUR WORM! |
X | Networks Configurator | NetConfs.exe | Added by the RBOT-OX WORM! |
X | Networks Controler | Netsis.exe | Added by the RBOT-NG WORM! |
N | NetworkSetup | dlink.exe | D-Link System Tray icon |
X | Netzip Smart Downloader | npnzdad.exe | Advertising spyware |
N | NetZIPFolders | nzfprop.exe | Netzip Classic zip file manager |
X | NeuroMedia(IESpeaker) | NeuroMedia.exe | Part of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available |
N | NeuroSpeech OESpeaker | OEMonitor.exe | Part of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not |
X | New.net | rundll32.exe NewDotNetStartup Newdot~2.exe | NewDotNet foistware |
X | New.net Startup | rundll32 [path], NewDotNetStartup -s | NewDotNet foistware |
X | NEWDOT~1 | rundll32.exe NewDotNetStartup Newdot~2.exe | NewDotNet foistware |
? | News Service | ispnews.exe | F-Secure antivirus related. However, is this particular item required? |
N | Newsalrt | NEWSALRT.EXE | MSNBC News system tray utility to alert you to new news |
X | Newsgroup lptt01 | newsgroup.exe | Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Newsgroup ml097e | newsgroup.exe | Variant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
N | NewsUpd | newsupd.exe | For Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here. |
X | NewtonKnowsUpd | NewtKnow.exe ...NewtnUpd.dll, runkey | NewtonKnow hijacker |
U | NFM Service | NPDOR9x.exe | Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required |
N | nForce Tray Options | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
U | NGClient | ngctw32.exe | Symantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually |
N | NGServer | ngserver.exe | Symantec/Norton Ghost Console service |
X | NiceDownloads | rundll32.exe MSA64CHK.dll, DllMostrar | MatrixDialer related |
N | Nielsen NetRatings | insight.exe | Nielsen NetRatings - "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site’s audience and your customers". Is it required? |
X | nikLaus | nikLaus.exe | Added by the NIKLAS WORM! |
N | NInit | NInit.exe | Norton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required |
Y | nisserv | NISSERV.EXE | Norton Personal Firewall |
Y | Nisum | NISUM.EXE | Norton Personal Firewall |
X | NJG40 | NJG40.EXE | Added by the BANCOS.D TROJAN! |
N | NkvMon.exe | NkvMon.exe | Nikon View 5 - for transferring pictures from Nikon digital cameras |
N | NkVwMon.exe | NkVwMon.exe | Nikon View - for transferring pictures from Nikon digital cameras |
X | NLS Keyboard | keyboard.exe | Added by a variant of the SPYBOT WORM! |
? | NMSSvc | NMSSVC.EXE | NIC Management Service - diagnostics program for Intel Pro family network cards |
Y | NMSVC | nmSvc.exe | Covenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it |
U | NNSvc | nnsvc.exe | NetNanny internet filter |
X | No Credit Card | plugin-[random].exe | Adult content pop-up dialler |
U | No-IP DUC | DUC20.exe | Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available |
U | NoAds | NoAds.exe | Blocks advertisement banners in Internet Explorer |
N | NoAdware | NoAdware.exe | Adware/spyware remover - not particularly recommended, see here |
X | Nocana | [path to worm] | Added by the ANACON-B WORM! |
U | Nod32CC | nod32cc.exe | Control Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button |
Y | NOD32kernel | Nod32krn.exe | Nod32 Antivirus Version 2 |
Y | nod32kui | nod32kui.exe | Nod32 Antivirus Version 2 |
Y | NOD32POP3 | Pop3scan.exe | POP3 E-mail part of Eset's NOD32 virus-scanner |
? | NodeMnger | Nodemngr.exe | Part of the Dell OpenManage Client installation - to allow Dell representatives to remote logon? |
X | nodriver | AUEKXRZ.EXE | Added by a variant of the SPYBOT WORM! |
X | Noha | aasd.exe | PurityScan/Clickspring adware |
N | Nokia Connection Monitor | NclConf.exe | Monitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required |
U | Nokia Tray Application | NclTray.exe | Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on |
U | NOMAD Detector | ctmnrun.exe | Detects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected |
N | NomdCheck | nomdchek.exe | Part of Intel's Native Audio |
U | nomtray | nomtray.exe | System Tray access to NetMotion Wireless options - including connectivity status (see here) |
U | Norman ZANDA | ZLH.EXE | System Tray icon for Norman Antivirus |
X | Norton Antivirus AV | FVProtect.exe | Added by the NETSKY.P WORM! Note - this is not the popular AV software! |
X | Norton AntiVirus Sys | NAVsys32.exe | Added by a variant of the WOOTBOT WORM! |
X | Norton Auto Protect | nava.exe | Added by an unidentified WORM or TROJAN! |
Y | Norton Auto-Protect | navapw32.exe | Norton Anti-Virus's background scanning process |
X | Norton Auto-Protect | ccApp.exe | Added by the AKHER.D WORM! Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton AV file with the same filename |
? | Norton AV Preload | Premend.exe | Norton Antivirus related. What does it do and is it required |
N | Norton Crashguard Monitor | cgmenu.exe | Troublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001 |
N | Norton Disk Doctor | Ndd32.exe | Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well |
Y | Norton eMail Protect | POPROXY.EXE | Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it |
N | Norton Ghost 9.0 | GhostTray.exe | Norton Ghost tray icon - the application can be launched manually |
X | Norton Guard 32 | ntguard32.exe | Added by a variant of the RBOT WORM! |
X | Norton Live Update Server | cpsdv.exe | Added by the AGOBOT.EW TROJAN! |
X | Norton Live Updater | Cavapsvc.exe | Added by the GAOBOT.AO WORM! |
X | Norton Live Updater | Sochost.exe | Added by the GAOBOT.AO WORM! |
N | Norton Navigator Loader | nnloader.exe | An older Norton utility for file management under Windows 95. More information here |
X | Norton Personal Firewall | jah.exe | Added by a variant of the SDBOT WORM! |
X | Norton Personal Firewall | npfw.exe | Added by the RBOT-UI WORM! |
U | Norton Program Scheduler | nsched32.exe | Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans |
U | Norton Program Scheduler | NPSsvc.exe | Installed on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans |
? | Norton Program Scheduler Event Checker | npscheck.exe | Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker |
X | Norton Service Process | navapvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Norton SpySweeper AutoUpdate | navsw.exe | Added by the FORBOT-AS WORM! |
N | Norton System Doctor | Sysdoc32.exe | Norton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well |
N | Norton SystemWorks | cfgwiz.exe | Norton System Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it |
X | Norton Update | ccUpdate.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Norton Updater | winset.exe | Added by a variant of the SPYBOT WORM! |
X | Norton Wizzard | nwiz.exe | Added by the GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name |
X | norton32 | norton32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | NortonAV | norton_antivirus.exe | Added by the NETJOE TROJAN! Note - this is not the legitimate Symantec AV program |
X | nortonsantivirus | ccEvtMngr.exe | Added by the HZDOOR-A TROJAN! |
U | Notebook Maximizer | maximizer_startup.exe | Toshiba Notebook Maximizer software - adjust settings to save battery power and increase efficiency |
? | NotebookManager | nbm.exe | Associated with Acer notebook PCs. What does it do and is it required? |
X | Notepad lptt01 | notepad.exe | Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name |
X | Notepad ml097e | notepad.exe | Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name |
X | notepad.exe | upx.exe | Added by a variant of the AGENT.AH TROJAN! |
X | Notn | Eber.exe | PurityScan/Clickspring adware |
U | NovaBackup * Tray Control | NbkCtrl.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here. * represents the version number |
? | NovaPortal Single User Service | NPSU.exe | ?? |
U | NovastorSchedulerd | SCHENGD.EXE | NovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it |
? | NPFMonitor | NPFMntor.exe | Norton AntiVirus Firewall Install Monitor. What does it do and is it required? |
U | NPROTECT | nprotect.exe | Norton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here |
? | NPS Event Checker | npscheck.exe | Part of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker |
X | NS | ns.exe | Added by the AGOBOT-HS WORM! |
X | NSCheck | NSCHECK.EXE | NetSetter/Marketscore foistware |
X | nscntrl | nscntrl.exe | Added by the DLOAD-DC TROJAN! |
X | nsdlua | nsdlua.exe | All-In-One Telcom - adult content dialler |
X | nsdriver | nssys32.exe | NetShagg adware |
X | nse | nse.exe | Added by the AGOBOT-ML WORM! |
U | Nsengine | Nsengine.exe | Scheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here |
U | NSHelper | aexnsinstallhelper.exe | Altiris Express Notification Server Install helper - monitors integrity of the installation |
X | nssysconf | [random filename] | Added by the VIVIA.A TROJAN! |
X | nstat | netstat.exe | Adult content dialler |
X | NSupdate | NSupdate.exe | Adult content dialer |
X | Nsvdr | nsvdr.exe | Adult content dialler |
N | NSystemMonitor | Symmon.exe | Norton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging |
N | NT Kernel Patch | ntkrnlpt.exe | FaxServe network fax software |
X | NT Logging Service | Syslog32.exe | Added by the DONK.B or DONK.C or DONK.L or DONK.M or DONK.O WORMS! |
X | NT Services | ntsvc.exe | Added by the AGOBOT.VJ WORM! |
X | ntdll | ntdll.exe | Added by the BIONET.404 TROJAN! |
X | NTDLM | csrss.exe | Added by the HALE TROJAN! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
X | Ntech.patchs | [trojan filename] | Added by the LEMIR.G TROJAN! |
X | ntechin | n20050308.exe | Adware, probably VX2/Look2Me related |
X | NTFS16 | ntfs16.exe | Added by the RBOT-LY WORM! |
Y | NTFSCLUP | NTFSCLUP.EXE | Part of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99+% of the time it will only execute about a dozen instructions before exiting" |
X | ntldr | ntldr.exe | Browser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: C:WINDOWSSYSTEMntldr.exe, C:m.exe, C:WINDOWSSearch-For-You.url, C:n.bat, C:q.exe, C:r.bat |
N | ntlfreedom | rundll32 [path] RyDial.dll, QuickStart | NTL Freedom dial-up ISP software - not required |
X | NTP Server | [path to trojan] | Added by the RANKY.F TROJAN! |
N | NTrtc | ntrtc.exe | Dell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here |
N | ntsmod | ntsmod.exe | Adware, probably VX2/Look2Me related |
X | NTsocket | NoeWinnt.exe | Added by the ATAKA-E TROJAN! |
X | NTsrv.exe | NTsrv.exe | Added by a variant of the SERVU-O TROJAN! |
U | nTune | nTune.exe | nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards |
X | ntupdate | dnsvc.exe | Added by the SDBOT-TC WORM! |
U | NTVDM | NTVDM.EXE | Windows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS's (Windows NT, 2K and XP). Required if hardware on a machine with these OS's needs 16-bit DOS drivers. You can find a bit more about NTVDM here |
X | ntvdscm | ntvdscm.exe | Added by the SCKEYLOG.O TROJAN! |
Y | NuTCSetupEnviron | ncoeenv.exe | Used by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone |
X | NvClipRsv | svchost.exe | Added by the DUMARU-AK WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | NvClipRsv | swchost.exe | Added by the DUMARU-AK WORM! |
? | NVCLOCK | rundll32 nvclock.dll, fnNvclock | Overclocking utility for nVidia based graphics cards? |
? | NvColorInit | rundll32.exe NvQtwk.dll, NvColorInit | Associated with Nvidia based graphics cards |
U | NvCpl | rundll32.exe NvCpl.dll, NvStartup | Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card |
X | NvCpl | NvCpl.EXE | Added by the YANZ.B WORM! |
U | NvCpl | NvCpl.EXE | Added by the YANZ.B WORM! |
X | NvCplD | m2gr32.exe | "Switch" premium rate adult content dialler |
X | NvCplD | ntcpl.exe | Switch adult content dialler |
N | NvCplDaemon | rundll32.exe NvQtwk.dll, NvCplDaemon | System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
U | NvCplDaemon | rundll32.exe NvCpl.dll, NvStartup | Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card |
X | NvCplDmn | NAVSVC.EXE | Added by an unidentified VIRUS, WORM or TROJAN! |
X | NvCplScan | nvsc32.exe | Added by a variant of the IRC.BOT TROJAN! |
X | NvCplScan | msc32.exe | Added by the FORBOT-DD WORM! |
X | NvCplScan | winasp.exe | Added by a variant of the RBOT WORM! |
X | NvCplScan | nvsc32.exe | Added by the BROPIA.N WORM! |
X | nvd32 lptt01 | nvd32.exe | Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | nvd32 ml097e | nvd32.exe | Variant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Nvid | [8 random charachters] | Unidentified adware |
X | Nvid32 | Nvid32.exe | Added by the GEMA TROJAN! |
X | Nvidex32 | Nvidex32.exe | Added by the GEMA TROJAN! |
X | Nvidia Control Panel | ncsvc32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | NVIDIA Driver | MSPMSPSU.EXE | Added by the WOOTBOT.Y WORM! |
N | NVIDIA nForce APU1 Utilities | NVATray.exe | nVidia's nForce Audio Processing Unit (APU)- "provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time" |
U | NVIDIA nTune | nTune.exe | nVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards |
X | NVIDIA Video drivers | video_32D.exe | Added by the AGOBOT.KV WORM! |
X | Nvidia32 | nvidia32.exe | CoolWebSearch parasite variant |
N | NvidiaQuickTweak | rundll32.exe NvQtwk.dll, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
U | NVIEW | rundll32.exe nview.dll, nViewLoadHook | This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers |
N | NvInitialize | rundll32.exe NvQtwk.dll, NvXTInit | Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled |
Y | NVmax | NVmax.exe | NVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card |
N | NVMCTRAY | RUNDLL32.EXE ...NVMCTRAY.DLL, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
U | NvMediaCenter | RunDLL32.exe NvMCTray.dll, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
N | NVMixerTray | NVMixerTray.exe | System Tray access to audio controls from nVidia's motherboard ForceWare software |
N | NVQuickTweak | rundll32.exe NvQtwk.dll, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
Y | NVRaidService | nvraidservice.exe | nVidia NVRaid - hard disk striping/mirroring utility for increased performance and reliability. Required if you have a RAID setup |
N | NVRT | nvrt.exe | NVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports |
? | NVRTClk | NVRTClk.exe | Related to a Gigabyte video card. What does it do, and is it required? |
X | nvsv32.exe | nvsv32.exe | Added by the FORBOT-DI WORM! |
N | NvSvc | nvsvc.exe | NVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that |
X | nvsvca32 | nvsvca32.exe | Adware - recognized by Kaspersky antivirus as Trojan-Downloader.Agent.is |
X | NVSystem32 | nvscv32.exe | Added by the AGOBOT-NO WORM! |
X | NvXplDeamon | xstyles.exe | Added by the SMALL.AJ VIRUS! |
? | NWEReboot | dummy.exe | ?? |
N | nwiz | nwiz.exe | Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. However, this isn't necessary for the operation of your system |
Y | Nwpopup | Nwpopup.exe | Broadcast message handler part of Novell Netware that displays server, printer and other messages |
U | nwrecmsg | nwrecmsg.exe | Broadcast message handler part of Novell Netware that displays server, printer and other messages - can cause crashes |
Y | NWTRAY | nwtray.exe | Novell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client |
? | oadaemon | oadaemon.exe | Background process that establishes connection with a C3-1000 scanner and watch general status of the device and for scanner button presses. Can it be started manually? |
Y | oahstifr | oahstifr.exe | Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up." |
U | OAKSTART | OAKSTART.EXE | Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. |
N | OAKTASK | OAKTASK.EXE | Taskbar utility for a "control panel" for a CD-RW |
Y | Object Store Server | osserver.exe | Comes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up." |
? | objtjprx | objtjprx.exe | ?? |
? | obsver | obsver.exe | Part of LingoWare translating software - what does it do and is it required? |
N | OCAudioIni | OCAudioIni.exe | One-click Audio Converter - allows you to convert files of multiple audio formats right from Windows Explorer |
N | ocraware | ocraware.exe | Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs |
X | ocx32 | ocx32.exe | Added by the ASTEF or RESPAN WORMS! |
X | OD | SYSCNTR.EXE | HotVideo dialler |
X | od-matrxx | od-matrxx.exe | Adult dialler - xx can be any number |
X | od-stndxx | od-stndxx.exe | Adult dialler - xx can be any number |
X | od-teenxx | od-teenxx.exe | Adult dialler - xx can be any number |
U | ODBC BackUp | fdxxl.exe | G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
N | Odometer | Odometer.EXE | Mouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available |
X | Oeloader | Oeloader.exe | Xupiter OrbitExplorer toolbar related, drive-by foistware |
X | OEM Tools 32 | tres32.exe | Added by the RBOT.QB WORM! |
X | OEM32 Tools | sres32.exe | Added by a variant of the SPYBOT WORM! |
N | OEMCLEANUP | oemreset.exe | Resets OEM installation settings at bootup. Not required unless you're new to PC's |
U | OEMRESET | oemreset.exe | Resets OEM installation settings at bootup. Not required unless you're new to PC's |
? | OEPowerPlugs | winoeinit.exe | ?? |
N | OEXCheck | EA2Check.exe | Express Assist from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others |
X | Offer Companion | offers.exe | Adware |
X | Offers | offers.exe | Adware |
N | Office Startup | Osa.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
X | Office Startup | Exploer.exe | Added by the GAOBOT.BV WORM! Note the different filename to the valid MS Office entries |
N | Office Startup | Osa9.exe | Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show |
Y | OfficeGuard RegChecker | ogrc.exe | Kaspersky Labs anti-virus |
? | officejet 6100 | hposol08.exe | Associated with a HP PSC2110 (and maybe others) all-in-one machine |
Y | OfficeScan95 | pccwin97.exe | Trend Micro antivirus OfficeScan |
Y | OfficeScanNT Monitor | pccntmon.exe | Trend Micro OfficeScan Antivirus real-time scan monitor |
N | OfotoNow USB Detection | Rundll32.exe OFUSBS.DLL, WatchForConnection OfotoNow | Autodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs |
Y | ogrc | ogrc.exe | Kaspersky Labs anti-virus |
N | Oil Change | OCTray32.exe | From CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs |
? | OIM | oim.exe | Related to the O2 (was "genie") mobile phone service. What does it do and is it required? |
X | OLE | [filename] | Added by the STAWIN or TARNO.D TROJANS! |
X | OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related |
X | Olehelp | Olehelp.exe | CoolWebSearch parasite variant |
X | olehelp | olehelp.exe | Added by the BOOKMARKER.D or BOOKMARKER.G TROJANS! |
U | olesvr | olesvr.exe | Salfeld Child Control 2003 - parental control software |
X | Olive System | Szchost.exe | Added by the MERCURYCAS.A TROJAN! |
X | Omf4 | OMF4.EXE | Added by the FREEMEGA TROJAN! |
N | OmgStartup | omgstartup.exe | Sony program called OpenMG Jukebox - player and music organizer |
U | OmniHTTPd | ohttpd.exe | OmniHTTPd web server from Omnicron |
N | OmniPage | Opware32.exe | Part of OmniPage Pro from Scansoft (was Caere) - "the fastest, easiest way to turn paper documents into digital files you can edit." Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs |
U | OmniPass | scureapp.exe | OmniPass from Softex Inc. - secure password management software |
U | On Screen Display | OSD.EXE | By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze |
N | One Touch Monitor | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | One Touch Monitor | 1tou~2.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | One Touch Monitor | ONETOU~2.EXE | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | OneTouch Monitor | OneTouchMon.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | OneTouchMonitor | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | OneTouchMonitor | 1tou~2.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | OneTouchMonitor | ONETOU~2.EXE | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | ONETOU~2 | OneTouchMonitor.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | ONETOU~2 | 1tou~2.exe | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
N | ONETOU~2 | ONETOU~2.EXE | For Visioneer OneTouch scanners. System tray access to the control panel for the scanner |
X | Onflow | onflow.exe | Onflow is a internet company that offers an online advertising program. Not required - uninstall |
? | online cdrom | Active acid.exe | ?? |
X | Online Service | svchost.exe | Added by the HOSTIDEL.B or HOSTIDEL.C or TARNO.B TROJANS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
U | OnlinePCfix SmoothSurfer | SS.exe | Smooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists |
N | OnlineTime | onlinetime.exe | OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs |
X | online_party | online_party.exe | Adult content dialler |
X | OnSrvr | OnSrvr.exe | OnWebMedia adware |
X | oo4 | RunDLL32.EXE oo4.dll, DllRun | BookedSpace parasite variant |
? | OOLHELPT | OOLHELPT.exe | ?? |
N | OP12 Reminder | Ereg.exe | Registration reminder for OmniPage Pro 12 from ScanSoft |
X | Open Site | opnste.exe | Adware - see here |
X | Open2Enter | runme.exe | Adult content dialler |
X | Open2Enter | runme2.exe | Adult content dialler |
X | OpenMstart | mcmgr32.exe | "Switch" adult content dialler |
X | OpenMstart | mmgr32.exe | "Switch" adult content dialler |
N | OpenOffice.org x | QUICKS~1.EXE | Displays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number |
U | Openwares LiveUpdate | LiveUpdate.exe | Web-update utility as used by various types of software - see here |
N | Operator | ?? | Media Pilot operator, in Win.ini. Locks port open |
U | Operator | xtmop.exe | Fax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported |
N | OpiStat | OPISTAT.EXE | OpiStat is a European Research Institute whose goal is to understand consumer needs and opinions better |
X | OPQFile | regedit.exe /s ...rad03FA6.tmp | Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit |
X | OPTIMIZER | iexplore.exe | Added by the EVIVINC TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
N | Optimum Online | Netsurf.exe | Optimum Online ISP software. Not required, just window dressing & advertising from Optimum |
U | Optus Cable Data Monitor | datamonitor.exe | Allows Optus customers to monitor their actual data usage against Optus' "data allowance limits" |
U | OptusNetUsage | OptusNet Usage Meter.exe | Designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be |
N | Opware12 | Opware12.exe | OmniPage Pro 12 from ScanSoft |
N | Opware14 | Opware14.exe | ScanSoft's OmniPage Pro 14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is available via Start -> Programs |
X | OrbitUpdate | update.exe | Xupiter OrbitExplorer toolbar, drive-by foistware |
X | OrbitView | view.exe | Xupiter OrbitExplorer toolbar, drive-by foistware |
? | org5.exe | org5.exe | Lotus Organizer 5 application file, Lotus Organizer software. What does it do and is it required? |
X | OrgyCam | OrgyCam.exe | Adult content dialler |
U | OrigRage128Tweaker | RAGE128TWEAK.EXE | Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com |
U | ORiNOCO | Cmluc.exe | Client Manager software for an ORiNOCO wireless LAN card |
X | Osa32 | NTOSA32.exe | Added by the ANIG WORM! |
U | OSD | OSD.exe | By Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don't adjust things regularly - can also freeze |
X | OSS | ossproxy.exe | NetSetter/Marketscore foistware |
X | OSS | rk.exe | RelevantKnowledge, NetSetter/Marketscore foistware variant |
X | OSSProxy | OSSPROXY.EXE | NetSetter/Marketscore foistware |
U | OStivityInvAgt | ostivity.exe | OStivity - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system" |
X | Osus | acao.exe | PurityScan/Clickspring adware |
X | otcx | otcxxh.exe | Added by the CAROOL TROJAN! |
X | outlook | outlook.exe | Added by the SDBOT-RU WORM! |
Y | Outpost Firewall | outpost.exe | Outpost personal firewall |
X | Outwar | syslaunch.exe | Outwar adware downloader |
? | OVCJ | ovcj.exe | ?? |
N | Overnet | Overnet.exe | Overnet peer-to-peer (P2P) file sharing program |
U | OWCCardbusTray | ocbtray.exe | Icon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface |
U | OWCWebCamDV | wcdvtray.exe | WebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam |
X | OWMngr | OWMngr.exe | OnWebMedia advertising foistware - see here for exactly what to look for |
X | oz2 | oz2.exe | Added by the MYDOOM.W WORM! |
? | P17Helper | Rundll32 P17.dll, P17Helper | ASIO driver for the Sound Blaster Audigy & Audigy 2 series sound card - is it required in startup? |
N | P2P NETWORKING | P2P Networking.exe | Peer to Peer (P2P) sharing of files on the internet |
N | P2P Networking | P2P | Peer to Peer (P2P) sharing of files on the internet |
N | P2P Networking3 | P2P Networking3.exe | P2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required - see here |
X | P3p4chk | P3p4chk.exe | Added by the GEMA TROJAN! |
X | p4mx4 | p4mx4.exe | Added by the CRYPTER.A TROJAN! |
? | Packard Bell EverSafe Tray Control | TrayControl.exe | Packard Bell EverSafe software. What does it do, and is it required? |
N | PadTouch | PadExe.exe | Toshiba Touch and Launch - offers easy movement and freedom of programs navigation with TouchPad |
U | Pagekeeper Jobs | pkjobs.exe | PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc |
U | Pagekeeper Lite | pkjobs.exe | PageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc |
X | PAgent | PAgent.exe | Scans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See here for more info |
N | Pagis Scheduler | Monitor.exe | Scheduler for the Pagis scanning suite from Scansoft. |
? | pagmstart | client.exe | Possibly related to this? |
N | Pagoo | PAGOO.EXE | Pagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem |
? | Palm MultiUser Config | Configtool.exe | MultiUser configuration for a Palm PDA device?. Is it required? |
N | Palm.exe | Palm.exe | Palm Desktop Software for use with Palm handheld devices. Available via Start -> Programs |
X | PalNetaware | pnetaware.exe | PalTalk adware - as included in Morpheus, see here towards the bottom of the page |
N | PaltalkNetaware.exe | PALNETAW~1.EXE | Voice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated |
U | Panda Antispam Server Service | PasSrv.exe | AntiSpam software, part of Panda Platinum Internet Security |
U | Panda Scheduler | pavsched.exe | Panda Antivirus scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it |
X | PandaAVEngine | PandaAVEngine.exe | Added by the NETSKY.R WORM! |
N | Paperport | runppdrv.exe | Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here |
N | PaperPort PTD | pptd40nt.exe | "PaperPort" software associated with scanners |
N | PaperQuote System Tray Icon | PQTRAY.EXE | PaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation |
X | Parallel Tasking | ptask.exe | Added by unidentified adware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.adg |
U | PartSeal | PartSeal.exe | System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere |
U | Password Door Loader | PDMonitor.exe | Password Door - password protection software |
N | PasteLister | plister.exe | PasteLister - clipboard extender. Start manually when required |
X | Patch | patch.exe | Added by the NETBUS WORM! |
X | Patches Value | WinGamed.exe | Added by the SDBOT.BR WORM! |
? | Path | lide.exe | ?? |
X | PAV.EXE | %Number% | Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number |
Y | PAV.EXE | PAV.EXE | PER Antivirus |
Y | PAVFIRES | PavFires.exe | Panda Antivirus |
Y | PAVFNSVR | PavFnSvr.exe | Panda Titanium Antivirus |
Y | PavProc | PavPrS9x.exe | Panda Titanium Antivirus |
Y | PavProt | PavProt.exe | Panda Titanium Antivirus |
U | PC Alert III | alert.exe | MSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock |
U | PC Booster | pcbooster.exe | PC Booster from inKline Global - "easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition" |
X | PC-Config32 | corona.exe | Added by the CORONEX.A WORM! |
Y | PCBG | PCBODYGUARD.EXE | PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc |
Y | PCBODYGUARD | PCBODYGUARD.EXE | PC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc |
Y | PCCClient.exe | PCCClient.exe | PC-Cillin 2002 antivirus software |
Y | pccguide.exe | pccguide.exe | PC-Cillin 2002 antivirus software |
Y | PCCIOMON.EXE | PCCIOMON.EXE | PC-Cillin 2000 antivirus software. This is the actual virus-scanner |
Y | PCClient.exe | PCClient.exe | Trend Micro PC-Cillin Internet Security |
Y | PccPfw | PccPfw.exe | PC Cillin 2003 personal firewall |
Y | PcCtlCom | Pcctlcom.exe | Trend Micro PC-cillin Internet Security |
N | PCDRealtime | realtime.exe | Apparently the monitoring device for PC Doctor Online. It provides a "free" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to "order" the fee-based fixes from its web site |
X | PcEXPLODE | specialfile.exe | Added by the RBOT.RH WORM! |
N | PCHbutton | PCHbutton.exe | Used by HP Instant Support |
N | PCHealth | pchschd.exe | This is a "scheduler" and does not turn off PC Health. For more information refer here |
X | PCHEasySearch | STUpdate.exe | PCH EasySearch bar |
? | PCIMODEM | pcimodem.exe | Associated with Lucent based Aztech MDP7800-U PCI modems. Is it required? |
U | PCLEPCI | ppe.exe | Pinnacle Systems PCI Performance Enhancer. "This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards." |
? | PCMService | PCMService.exe | In a DellMedia Experience sub-directory |
U | PCRecSA | PCRecSA.exe | Part of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a "clean" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to |
X | PCShield | regsvr32 /s [path] sfg_****.dll [* = random char] | SafeguardProtect/Veevo malware |
N | PCStart | Pcm25.exe | Runs as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big |
N | PCSuiteTrayApplication | TrayApplication.exe | System Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu |
N | Pcsv | pcsvc.exe | Delfin Media Viewer or "Promulgate" adware |
N | PcSync | PcSync.exe | If a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs |
U | pctspk | pctspk.exe | Used for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions |
U | PCTVOICE | pctvoice.exe | The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It’s better to leave it |
U | PDEngine | PDEngine.exe | PerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot |
N | pdexplo | PDEXPLO.EXE | PowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs |
? | PDF Converter Registry Controller | RegistryController.exe | ScanSoft PDF_Converter related - what does it do and is it required? |
N | pdfFactory Pro Dispatcher v1 | fppdis1.exe | "With pdfFactory you can create PDF documents from any program printing to the virtual PDF printer". Available via a desktop shortcut or Start -> Programs |
N | pdfSaver3 | pdfSaver3.exe | PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc |
N | PDirect | PDirect.exe | IBM Presentation Director software |
U | pdp Server | ctpdpsrvr.exe | Included and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network |
U | PDVDServ | PDVDServ.exe | Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
N | Pe2ckfnt SE | chkfont.exe | Used to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu |
? | Peeramid | PService.exe | In a "Koptimizer" folder in Program Files. What does it do and is it required? |
N | PeerGuardian | PeerGuardian_1.99b_pr14.exe | PeerGuardian "is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections" |
U | Pent@VALUE 3.2 | Pent@VALUE.exe | Pent@VALUE Digital Satellite Internet PC Receiver |
X | PeqBL100 | PEQBL100.exe | Added by the ENVID.D WORM! |
Y | PER Email Protection | pavmail.exe | PER Antivirus |
N | PerfectPrint | pfppop70.exe | Print engine used by Corel WordPerfect 7 and Presentations 7 |
Y | PersFw | PersFw.exe | Kerio or Tiny Personal Firewall |
X | Personal Firwall | ptmedsrv.exe | Added by the SDBOT.XY WORM! |
U | Pervasive.SQL Workgroup Engine | W3dbsmgr.exe | Database Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup |
U | PestPatrol Control Center | PPControl.exe | PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol |
? | PestPatrolCL | PestPatrolCL.exe | Associated with PestPatrol anti-malware software. What does this part do and is it required? |
U | Petit Larousse 2001 | HIPL2000Popup.exe | Popup dictionary tool |
? | PFW_CfgEngine | PFWCFG~1.EXE | Personal Firewall related? |
? | PFW_PullSrv | PULL.EXE | Personal Firewall related? |
X | PgMonitr | PgMonitr.exe | Delfin Promulgate adware variant |
Y | PGPSDKSVC | pgpsdkserv.exe | PGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality |
U | PGPSERVICE | pgpservice.exe | PGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a "fall-back" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference |
N | PGPtray | pgptray.exe | PGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs |
X | PGStub.exe | [various filenames] | Unidentified adware |
X | pgtaff | pgtaff.exe | AdRotator adware variant |
N | Phime2002a | TINTSETP.EXE | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
N | PHIME2002ASync | TINTSETP.EXE | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
U | PhoneFree version 6.2 | PHONEF??.EXE | An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here |
N | Photo Express Calendar Checker SE | CALCHECK.EXE | If you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly |
N | Photo Loader supervisory | Plauto.exe | Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures |
N | PhotoWise QuickLink | quicklnk.exe | Agfa PhotoWise - "PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more." |
N | Picasa Media Detector | PicasaMediaDetector.exe | Media detector for Picasa's automatic photo organizer |
N | PicasaNet | Hello.exe | Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs |
N | Pickatag | pickatag.exe | Pick-a-tag - "Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages" |
N | PICPRTR | PICPRTR.EXE | Program for viewing and measuring a variety of 3D CAD data formats |
N | pictureBUZZTray | swtray.exe | System Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually |
U | PiDunHK | PIDUNHK.EXE | Part of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens |
U | piiserviceOE | N/A | Spam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE |
X | pilif | pilif.exe | Added by the FILI WORM! |
N | Pinger | pinger.exe | Pinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification |
Y | PinnacleDriverCheck | PSDrvCheck.exe | Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled |
N | Piolet | piolet.exe | Piolet - peer-to-peer file sharing client |
N | Piracy | SysUtil.exe | Software Piracy Alert feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users" |
N | PivotSoftware | wpctrl.exe | PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
X | Pixel32 | Pixel32.exe | Added by the GEMA TROJAN! |
X | Pixelpwr32 | Pixelpwr32.exe | Added by the GEMA TROJAN! |
X | Pixelsvr | Pixelsvr.exe | Added by the GEMA TROJAN! |
U | pjWebCam | pjWebCam.exe | Webcam automation software that saves regular photos from webcam and can also act as HTTP server |
X | PK Services | pksvc.exe | Added by the FORBOT-BW WORM! |
U | PktAnything | PocketCompanion.exe | PocketAnything lets you save anything on your computer to your mobile, with one click |
U | PLEAPCPUCPL | pleapu.exe | CPU Control Panel for the Powerleap CPU upgrade |
? | PLFFAP | HotfixQ0306270.exe | Prolific Technology Inc. USB Flash Disk driver - is it required in startup? |
N | Plguni | Plguni.exe | McAfee QuickClean 3.0 - removes internet clutter and unwanted programs |
U | plmg.exe | plmg.exe | Paragon Last Minute Bidder - auction assistant software |
? | PLoader | umsd.exe | USB Mass Storage Disk related tray icon. Is it required? |
X | Plob | kernel.com | Added by the OPTIXPRO.12 TROJAN! |
U | Pluck Tray | PluckTray.exe | RSS (XML TAGS) reader program |
X | Plug And Play | msnmsg.exe | Added by the RBOT-ID WORM! |
U | PLXSTART | PLXSTART.EXE | Sets the spindown timeout and access speeds at startup and displays the "Plextor Manager 2000" splash screen for Plextor CD-RW. |
N | PLXTASK | PLXTASK.EXE | Taskbar utility for a "control panel" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files) |
X | pm32ctrl | pwr32crtl.exe | Added by the CRYPTER.A TROJAN! |
X | pm32info | pm32info.exe | Added by the CRYPTER.A TROJAN! |
X | pmc | 764.exe | Adult content dialler |
X | PMedia | winsrvc.exe | Internet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here. Treated by Trend as the FRIENDGRT.B WORM! |
? | PmProxy | PmProxy.exe | Associated with Analog Devices "SoundMAX" audio chipset - often built-in to motherboards. What does it do and is it required? |
X | pmr | pmr.exe | Powerstrip foistware variant |
N | PMTSHOOT | pmtshoot.exe | MS tool for troubleshooting power management problems |
U | PMXInit | pmxinit.exe | Restores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma |
N | PNAgent | PNAgent.exe | PhatNoise Music Manager - manages WMA, MP3, WAV, etc music files |
U | Pnpchk | Pnpchk.exe | Aztech Labs Sound 3 PnP driver |
X | pnpsvc_lock | ******.exe [* = random digit] | Browser hijacker |
X | pnpsvc_lock | startsvs.exe | Browser hijacker |
U | PNSetup | PNSetup.exe | PopNot - pop-up killer |
X | PNtask Services | pntask.exe | Added by the LALA.C TROJAN! |
U | Pocket Sheet Sync | PSXLTRAY.EXE | Casio Pocket Sheet synchronization software |
X | Poet | Poet.exe | Added by the DOEP.A WORM! |
X | Pofatch | nstrue.exe | Added by the RANDEX.Z WORM! |
U | point32 | point32.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
U | POINTER | point32.exe | Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
N | Points Manager | points manager.exe | Altnet Points Manager - manages the new Kazaa Plus scheme for awarding you points if you share music files on your machine with others rather than simply getting files and not sharing their own. Start manually when required |
X | POP | PopSrv***.exe | PeopleonPage foistware, bundled with Grokster where *** are random digits |
U | Pop-Up Smasher | PopupSmasher.exe | Pop-Up Smasher - pop-up killer |
U | Pop-Up Stopper | dpps2.exe | Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group |
U | Pop-Up_Blocker | Popup.exe | A Tweak-XP component, blocks advertisement pop-up windows in Internet Explorer. Can be enabled/disabled via Tweak-XP -> Internet Tweaks |
U | Pop-Up_Scanner | Popupscn.exe | Panicware popup blocker |
Y | pop3trap.exe | pop3trap.exe | PC-Cillin 2000 antivirus software -> E-mail scanner |
U | PopNot | PopNot.exe | PopNot - pop-up killer |
U | PopOops | PopOops.exe | PopOops - pop-up killer |
U | Popopen | popopen.exe | PopOpen makes your windows spring open with animation effects |
Y | Poproxy | POPROXY.EXE | Proxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it |
X | popsrv146 | popsrv146.exe | PeopleOnPage online dating browser enhancement - also adware and privacy issues, see here. For removal instructions see here |
U | PopSubtract | PopSub.exe | PopSubtract - pop-up killer |
U | Popup Ad Filter | PopFilter.exe | Popup Ad Filter - pop-up killer |
X | Popup Blocker Updater | regsvr32 veev****.dll [**** = random char] | SafeguardProtect/Veevo hijacker |
X | Popup Defence Updater | regsvr32 /s [path] pdf****.dll [* = random char/digit] | SafeguardProtect/Veevo hijacker |
U | Popup Defender | PD.exe | Popup Defender - pop-up killer |
U | Popup Terminator | GLADManager.exe | Popup Terminator - pop-up killer |
U | PopupEliminator | Popup Eliminator.exe | Popup Eliminator - pop-up killer |
U | PopUpKiller | PopUpKiller.exe | PopUpKiller - pop-up killer |
X | popuppers65 | a64sddd.exe | Popuppers adware variant |
X | popuppers65 | a65d.exe | Popuppers adware variant |
U | PopUpStopperCompanion | PSComp.exe | PopupStopper Companion popup blocker |
U | PopUpStopperFreeEdition | PSFREE.EXE | Panicware's Pop-Up Stopper - free limited features version |
U | PopUpStopperProfessional | PopUpStopperProfessional.exe | Panicware's Pop-Up Stopper - paid for version |
U | PopupVanish | PopupVanish.exe | Pop-up blocker |
U | PopUpWasher | PopUpWasher.exe | PopUpWasher pop-up killer |
U | PopUpWatch | PopUpWatch.exe | Part of BPS Trace Remover - made by the folks who "developed" BPS Spyware Remover which reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
? | POS-Partnerbatchprocessor | BATCH.EXE | VISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start -> Programs or a manually created shortcut? |
N | Post-It(r) Software | Psnotes.exe | Pop-up "yellow" notes on screen. Available via Start -> Programs |
U | POW! | pow.exe | Pop-up killer |
X | Power Scan | powerscan.exe | Foistware by Integrated Search Technologies - the people behind the ISTbar parasite |
N | PowerBar | Powerbar.exe | Part of CyberLink's PowerDVD software. Not sure what exactly it does, but not required in startup |
Y | PowerChute | Pwrchute.exe | "During a power outage, if you're not available to save your files & close down Windows....PowerChute will do that for you. PowerChute will save your application files, close your applications and shut down your computer just like you would...otherwise, the APC UPS (Uninterruptible Power Supply) unit would go to battery until it wore down, then your computer would shutoff" |
U | PowerDOCSAPIHost | papihost.exe | Hummingbird PowerDOCS - "delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment" |
N | PowerDVD | PowerDVD.exe | Launches Cyberlink's PowerDVD software and creates a system tray icon. If enabled, PowerDVD will open automatically when a DVD movie is inserted. Launch manually |
U | PowerKey | PowerKey.exe | Part of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610 |
X | PowerManagement | Rundlll.exe | Added by the SURDUX TROJAN! |
X | PowerManager | Svchost.exe | Added by the JEEFO VIRUS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
Y | PowerPanel | POWPANEL.EXE | Power management utility on notebooks/laptops - automatically switches modes when running on battery |
X | PowerPrifile | rundl132 kenel.dll, PowerProfileEnable | Added by the INMOTA WORM! |
U | PowerPro | powerpro.exe | Part of the power professional program that loads the floating menu bar. Can be accessed from Start -> Programs, but I'd leave it alone if you use this program |
X | PowerProf | PowerProf.exe | Added by the LOREX.B TROJAN! |
N | PowerQuest Startup Utility | PQINIT.EXE | From a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems" |
N | PowerReg Scheduler | PowerReg Scheduler.exe | PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others |
N | PowerReg SchedulerV2 | PowerReg SchedulerV2.exe | PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others |
N | PowerReg SchedulerV3 | PowerReg SchedulerV3.exe | PowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others |
? | POWERR~1 | POWERR~1.exe | Power monitoring? |
? | PowerS | PowerS.exe | ProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required? |
? | PowerSet | Regedit.exe /s ...PowerSet_8100_CU.REG | Appears to be Toshiba power management related |
N | PowerStrip | powerstrip.exe | PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings |
N | PowerStrip | PSTRIP.EXE | PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings |
U | PowerTools Tray Icon | pttray.exe | PowerTools - add-on for AOL |
U | Powertweak | PT2.EXE | "Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if 'Use predefined settings' is enabled in the programs options |
U | Powertweak | PTCTRL.EXE | "Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if 'Configure system at logon' is enabled in the programs options |
U | Power_Gear | BatteryLife.exe | Power management for all Asus notebook. Useful but not critical |
N | PP****usb | FBDirect.exe | Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs |
U | PP2000 Instaupdate | PPInupdt.exe | Protector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually |
Y | PP2000 Real Time Scan | PPVstop.exe | Protector Plus anti-virus software - real time scanner |
Y | PP2000 Taskbar Control | PPTbc.exe | Protector Plus anti-virus software - system tray access |
N | PP3100b | flatbed.exe | Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop |
U | ppass | Antispy.exe | AntiSpy firewall - "program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide" |
U | PPControl | PPControl.exe | PestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol |
U | PPK Setup(Server) | SEServe.exe | Programmable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended" |
U | PPMemCheck | ppmemcheck.exe | PPMemCheck - "extends PestPatrol's power so that the most dangerous Pests -- those that are about to execute -- are found, terminated, and cleaned from a user's system" |
X | PPPOEO | pingppac.exe | Added by the SPYBOT.KHC WORM! |
N | PProTray | pprotray.exe | Part of the power professional program. Loads the System Tray control |
N | pptd40nt | pptd40nt.exe | "PaperPort" software associated with scanners |
U | PPUpdate | ppupdater.exe | PPUpdater - "is the update program that ships with PestPatrol. It is able to update licensed and evaluation versions, and presents a visual display of what it is doing". Run manually unless you think you'll forget to check for updates on a regular basis |
N | PPWWebCap | PPWebCap.exe | "PaperPort" software associated with scanners |
X | pqhelper | pqhelper.exe | Searchcentrix hijacker |
U | PractiSearch | PSearch.exe | PractiSearch web search software |
U | Praize Messenger | itLoad.exe | Praize IM Christian chat instant messenger |
U | Prayer | PTW.EXE | Islamic Adhan program (call fpr daily prayers) |
X | prdtect | prdtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
? | PreAnnotate | PreAnntt.exe | Genius Wizard Pen Tablet driver related. Is it required? |
N | Precision Time Clock Checker | PrecisionTime.exe | Precision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time |
X | precpop2 | starter.exe | PrecisionPop adware |
X | Prein | APP****.tmp [* = random char or digit] | Unidentified adware |
Y | Preload | Preload.exe | Millenium Multi-Function Keyboard driver |
? | PreloadApp | hphprld.exe | HP Printer driver related? |
X | Premeter | nrpr.exe | NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided! |
X | Premeter | prmt.exe | NetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided! |
X | Preview AdService | PrevAdServ.exe | Windupdates adware variant |
Y | PrevxHome | SAGUI.exe | PrevX Home intrusion prevention software |
Y | PrevxPro | SAGUI.exe | PrevX Home intrusion prevention software |
X | prgtect | prgtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth! |
N | Price Patrol | neo.exe | Price Patrol by Half.com - internet shopping companion for finding the best on-line prices |
? | PrimaLauncher | Launcher.exe | Associated with PrimaScan scanners. Is it required? |
U | Primax 3D Mouse | 3dmoused.exe | Enables the scroll button on the Primax 3-D Scroll mouse |
? | Primsta | Primsta.exe | Linksys Wireless CompactFlash Card driver related. Is it required? |
X | Print Driver Helper Service | crsrr.exe | Added by the AGENT-BC TROJAN! |
N | Print Master Event Reminder | PMremind.exe | Print Master Gold - calander feature that pops up reminders, such as birthdays |
N | Print Screen Deluxe | psdeluxe.exe | Utility allows "Print Scrn" or "Print Screen" key to capture, print or save the current window |
X | print sharing | start.bat | Added by the ZCREW TROJAN! |
X | print sharing | [path] hidden32.exe [path] explorer.exe | Added by the ZCREW.B TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) |
X | Print Spooler | Spoolsv.exe | Added by the CIADOOR.B TROJAN! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
X | Print Spooler | spoolsvc32.exe | Added by the SDBOT.BB TROJAN! |
X | Print Spooler | spools.exe | Added by the RBOT-LD WORM! |
X | Printer | Spyassault.exe | Dubious "spyware killer" - see here. To be avoided |
N | Printer | [path to file] | Added by the LOWTAPER TROJAN! |
X | Printer | dipset.exe | Added by a variant of the FBSR TROJAN! |
X | Printer spool Service | spool.exe | Added by a variant of the SDBOT WORM! |
? | Printer Update | CFGREG.EXE | Maybe a registration reminder or automatically updates drivers or application software for a printer? |
X | PrinterSpool | [path] RESTORE.EXE [path] SPOOL.EXE | Added by the ALADINZ.K TROJAN! |
N | Printkey2000 | printkey2000.exe | Screen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required |
N | printnow | printnow.exe | PrintNow - a utility that primarily allows "Print Srceen" or "Alt+Print Screen" screenshots to be sent directly to a printer |
N | PrinTray | Printray.exe | Lexmark/Compaq printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. See also LexmarkPrintray and CompaqPrinTray |
N | PrintScreen | UNWISE.EXE | Gadwin PrintScreen - utility to capture, print or save the current window |
N | Printscreen 95 | PRT95MIN.EXE | Printscreen 95 - utility to capture, print or save the current window |
X | PrintSpoolSv | System.exe | Added by the BDOOR-S TROJAN! |
U | PRISMSTA.EXE | PRISMSTA.EXE | Creates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example |
N | Privacy Eraser Pro | PrivacyEraser.exe | Privacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities |
X | PrivacyScanner | pscan.exe | Privacy Champion, a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to porn websites, and then offers to "clean" them. Produces loads of False Positives as goad to purchase |
X | PrivateNet | [various filenames] | Premium rate adult content dialler |
U | Privoxy | privoxy.exe | Privoxy - web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk |
X | PrizeSurfer | prizesurfer.exe | "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
X | prjtect | prjtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prktect | prktect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prltect | prltect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prmt | prmt.exe | NetRatings software by Opistat. "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided! |
X | prmtect | prmtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth! |
U | PrnSys Executable | PrnSys.exe | Print screen utility bundled with some HP printer software - not required, but your choice if you like that feature |
U | Pro PCL Status Monitor | PENGSS.EXE | Xerox printer/fax/copier status monitor (PCL = printer control language) |
? | ProArt | ProArt.exe | ?? |
U | ProcessGovernor | processgovernor.exe | Process Supervisor "is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions" |
U | ProcessSupervisorGUI | ProcessSupervisor.exe | Process Supervisor "is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions" |
X | procmon | procmon.exe | Added by the BIONET.40A TROJAN! |
N | ProdikeysAutorun | Prodload.exe | Creative Prodikeys software. "an interactive music entertainment device which not only functions as a full-featured, ergonomic “QWERTY” keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop" |
N | ProDsl | ProDsl.exe | Intel Pro/DSL 2100 modem connection manager. Available via Start -> Programs |
X | Profile | Profile.vbs | Added by the WHITEHO VIRUS or TRAPPY WORM! |
N | Profiler | Profiler.exe | Enables the "Profiler" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs |
X | Prog | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | Prog | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
X | Program File | Progmon.exe | Added by the PEEPER TROJAN! |
X | Program in Windows | iexplore.exe | Added by a variant of the LOVGATE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
U | Program Neighborhood Agent | pnagent.exe | Citrix Program Neighborhood Agent |
? | ProgramWindow | more comp.exe | ?? |
N | projselector | projselector.exe | Roxio Project Selector - can be started manually |
N | Promon.exe | promon.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features |
X | PromulGate | PgMonitr.exe | Delfin Promulgate adware variant |
N | PRONoMgr.exe | PRONoMgr.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features |
U | PRONoMgrWired | PRONoMgr.exe | Intel’s Pro 100 Ethernet card manager |
U | Propel Accelerator | PropelAC.exe | Propel Internet Accelerator |
U | ProPort Startup | ProPort.exe | Proport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolving |
X | Protected Storage | RUNDLL32.EXE MSSIGN30.DLL ondll_reg | Added by a variant of the LOVGATE WORM! |
X | Protection | [path] runtask.exe [path] protection.exe | Added by a variant of the AGENT.3.AU TROJAN! |
X | Protection | Protection.exe | Added by the FEBELNECK-A WORM! |
X | Protection | Firewall.exe | Added by the ELIPTER.A WORM! |
X | Protection | IExplore .exe | Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
N | PROXOMITRON | PROXOMITRON.EXE | HTML proxy |
N | PROXOMITRON | PROXOM~1.EXE | HTML proxy |
U | PRPCMonitor | PRPCUI.exe | Intel® SpeedStep™ interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40% |
X | prrtect | prrtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prstect | prstect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prtcct | prtcct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prttect | prttect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth! |
X | prutcct | prutcct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prutdct | prutdct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prutgct | prutgct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | pruthct | pruthct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prutict | prutict.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prutlct | prutlct.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth! |
X | prvtect | prvtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth! |
X | prxtect | prxtect.exe | Prutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth! |
U | PS2 | ps2.exe | Multimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lost. |
X | PSD Tools Channel | ChannelUp.exe | BuddyLinks adware |
Y | PSDrvCheck | PSDrvCheck.exe | Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled |
U | PSFree | PSFree.exe | Pop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group |
Y | PSIMSVC | PSIMSVC.exe | Panda Titanium Antivirus |
N | PSIWin2.3 Connection Server | Psconsv.exe | Allows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs |
U | PsMFCard | PsMFCard.exe | Component of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in use |
Y | PSNotify | psnotify.exe | Pharos SignUp Vx - "PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries" |
Y | PsPCCard | PsPCCard.EXE | Background Power Saving task found on Toshiba laptops and which handles turning Power Saving ON and OFF on any inserted PC Card (PCMCIA card). Only ever disable if you do not use any power saving or hibernation settings (ie: they are all OFF) |
U | PspContr | pspcontr.exe | Driver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver |
U | PsSound | PsSound.exe | On a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delay |
? | PSTORES | PSTORES.EXE | Part of Windows Services Protected Storage? |
N | ptfb | ptfb.exe | Push the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future" |
? | Ptipbmf | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
U | ptrun32 | ptrun32.exe | Parent Tools for AIM |
N | Ptsnoop | Ptsnoop.exe | These descriptions I've come across - all valid as far as I can see :- (1) Program installed with some modems that monitors the COM ports for the modem driver. Not required from what I've read - may need a registry edit to get rid of it (2) Backdoor trojan virus that copies itself as PTSNOOP.EXE -see here for more info(3) Apparently the people who put it out claim it's a driver for a Voice modems (don't know who they are though - Ed) Note: If using AOL and you disable this you may lose your connection or lock up (4) Can also be an older Logitech scanner program. Remove from the Win.ini tab under Load='path'PTSNOOP and the System.ini tab under drivers='path'ptrtkr.drb. Can cause parallel port conflicts big time dragging system resources way down when a conflict exists (5) Allows audio monitoring of modem phone dialling tones and can be useful if you have connection problems (6) Karen Kenworthy's Snooper - "logs the start and stop time of all programs run under Windows" |
U | pttrun | pttrun.exe | Transmeta Crusoe processor related. Reduces application launch times and makes the computer "more responsive" |
N | PtUDFApp | PtUDFApp.exe | Sony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start -> Programs. Note that you must add a /T switch to the command line to get it to load to the taskbar |
N | Pure Networks Port Magic | PortAOL.exe | Pure Networks Port Magic, as available in the latest version of the AOL® 9.0 Optimized SE software; automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and video. See here |
U | Purgative | PURGATIVE100.EXE | AIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack |
N | Push Client | pull.exe | Client software from Interwise that MS use for their webcasts |
N | Push The Freakin' Button | ptfb.exe | Push the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future" |
N | PUSH6599 | PUSH6599.EXE | Scan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software |
X | PutA!! | PutA!!.exe | Added by the OPASERV.L WORM! |
X | PutAS! | PutA!!.com | Added by the OPASERV.Z WORM! |
X | putil | [filename] | Added by the LDPINCH TROJAN! |
N | PVR | PVR.exe | Pocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card |
X | Pwr32ctr | Pwr32ctr.exe | Added by the GEMA TROJAN! |
X | Pwr32ctrl | Pwr32ctrl.exe | Added by the GEMA TROJAN! |
X | Pwr32mgt | Pwr32mgt.exe | Added by the GEMA TROJAN! |
Y | Pwrmonit | Rundll32 PwrMonit.dll | IBM's proprietary 'battery maximiser' and power monitoring software for laptops |
X | Pwroff | Pwroff.exe | Added by the GEMA TROJAN! |
U | Pwrsave | Pwrsave.exe | Toshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power |
? | Pwruplogin | pulogin.exe | ?? |
U | PwrupTweakMe | PUPXPTWK.EXE | "Ashampoo PowerUp XP is a convenient tool for fine-tuning your Windows® NT4, 2000 and XP configuration to suit your precise needs and wishes. It gives you direct access to many frequently-required settings and parameters, enabling you to make your operating system behave the way you want." Boot-up options won't work if disabled |
U | PWS Tray | PwsTray.exe | Microsoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start -> Programs |
N | p_981116 | p_981116.exe | Win32 cabinet self extractor. More info here |
N | Q152404 | wsript.exe Q152404.VBS | Appears to run Scandisk at bootup on NEC PCs |
X | q36i36O | lms2cenu.exe | Added by the SECONDTHOUGHT VIRUS! |
N | QAGENT | qagent.exe | Quicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the Internet |
X | qappsrvc32.exe | qappsrvc32.exe | Added by a Proxy Trojan variant - identified by Kaspersky antivirus as Trojan-Proxy.Win32.Webber.m |
N | QBCD autorun | autorun.exe | Quick Books CD |
X | qbkupdbs | mqbkup.exe | Added by the OPASERV.K WORM! |
X | qbotd | [random filename] | Added by the BOTTEN TROJAN! |
? | qBrowse | qbrowse.exe | ?? |
X | QBRSR | QuickBrowser.exe | top-banners.com adware |
U | QCTRAY | Qctray.exe | System Tray icon providing access to the "IBM Access Connections" wizard on ThinkPad laptops and also allows to change the network environment. Not the same as QCWLIcon, which is pertinent only to the Wireless LAN |
U | QCWLICON | Qcwlicon.exe | Used by IBM Thinkpad laptops with built-in wireless card (802.11). System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off |
N | QD FastAndSafe | QDCSFS.exe | Automatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually |
U | QDM | QdmStart.exe | QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc |
U | QDMStart | QdmStart.exe | QDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI's series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc |
? | Qdsafe | ?? | ?? |
? | Qexplo | Qexplo.exe | ?? |
X | qgqqft | [path to Trojan] | Added by the RANKY.T TROJAN! |
? | QMusic | QMAgent.exe | ?? |
N | QNPlus | QNPlus.exe | Quick Notes Plus by Conceptworld - sticky notes tool |
U | Qoeloader | Qoeloader.exe | Qurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs |
X | sendmess.exe | Added by the SEMES TROJAN! | |
N | QSort2000 | QSORT.EXE | Utility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name" |
U | QT4HPOT | OneTouch.exe | Hewlett Packard One Touch keyboard driver. Required if you use the additional keys |
U | QTaskStartup | qtask.exe | Feature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts feature |
N | QTSTUB.EXE | Qtstub.exe | Part of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders |
X | QTSvc | msocfg.exe | Premium rate adult content dialler |
X | QTSvc | navchk.exe | Premium rate adult content dialler |
X | QTSvc | shman.exe | Premium rate adult content dialler |
X | QTSvc | ssvr.exe | Premium rate adult content dialler |
N | qttask | Qttask.exe | System Tray access to Apple's "Quick Time" viewer from version 5 onwards |
? | QUBCity | qtp.exe | ?? |
? | Queensla | Queensla.exe | ?? |
U | Quick Controls | Astrotoolbar.exe | Gateway Astro Screen and Sound Controls tray icon |
Y | Quick Heal On-Line Protection | Cateye.exe | Quick Heal - virus scanner |
Y | Quick Heal Startup Scan | QHSTRT32.EXE | Quick Heal - virus scanner |
N | Quick Shelf xx | qushelfxx.exe | Places an icon in the system tray for launching MS Bookshelf. Available via Start -> Programs"xx" represents the version number - ie, 98, 99 |
Y | Quick Startup | Fquick32.exe | For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone |
N | Quick View Plus | QVP32.EXE | Quick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs |
N | QuickBooks Delivery Agent | QBDAGENT.EXE | As far QAGENT but for QuickBooks. Can also have the version number in the name |
N | Quickbooks Update Agent | qbupdate.exe | Associated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not |
U | QuickCamPro | QuickCamPro.exe | System Tray for Picture Capture utility that can run unattended. Pictures every 30 seconds for example, auto FTP Upload, etc |
X | quicken | quicken.exe | CoolWebSearch parasite variant |
X | quicken | Winrar.exe | CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR! |
X | quicken | Waol.exe | CoolWebSearch parasite variant |
N | Quicken Scheduled Updates | bagent.exe | Quicken background downloading module |
N | Quicken Startup | QWDLLS.EXE | Quicken option to load DLLs at startup |
N | QuickenSEMessage | Qsemsg.exe | Quicken option |
N | QuickFinder Scheduler | QFSCHD100.exe | Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products) |
N | QuickFinder Scheduler | QFSched.exe | Used in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products) |
Y | QuickLaunchEr | QuickLaunchEr.Exe | QuickLaunchEr - allows you to quickly launch programs from an icon in the system tray |
N | Quicklink III | QL.EXE | HP fax program and only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start -> Programs |
N | Quicknote | quicknote.exe | JC&MB Quicknote Virtual Scrapbook |
U | QuickPassword | agquickp.exe | Smart card-based authentication and digital signature client software |
N | QuickRes | QUICKRES.EXE | Utility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel -> Display. Not required unless you have to change resolutions on a regular basis |
N | quickset | quickset.exe | Dell taskbar icon allowing you to quickly change settings |
X | Quicktime Mediaplayer | winmplyer32.exe | Added by the RBOT-PM WORM! |
X | Quicktime Pro 3.0 | winuodps.exe | Added by the GAOBOT.BH WORM! |
N | QuickTime Task | Qttask.exe | System Tray access to Apple's "Quick Time" viewer from version 5 onwards |
X | QuickTime Task | qttasks.exe | CoolWebSearch parasite variant |
N | QuickTime Update Completion x | quicktimeupdatehelper.exe | Different numbers caused by number of launches. So if 3 updates are made separately, 3 would appear (in theory) |
X | QuicktimeMngr | QUICKTIMEMNGR.EXE | Added by the WOOTBOT.AW WORM! |
X | Quicktlme | ru.exe | Adult content dialler |
U | QuickTV | QuickTV.exe | Infra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control |
X | Quickzip | Ls.exe | MsConnect browser hijacker and dialler |
X | QuickZip | lu.exe | MsConnect browser hijacker and dialler |
N | QuikShield | qkshield.exe | QuikShield popup blocker - reportedly stealth installed, see here |
N | QuikSync | QUIKSYNC.EXE | Used by Iomega drives. Available via Start -> Programs |
? | QWERTY | qwerty.exe | Possibly adult content related adware |
U | QWS3270 Sessions | sessions.exe | QWS3270 Secure terminal emulation software |
X | RA Server | Slave.exe | Added by the RA TROJAN! |
X | RabbitWannaHome | rabbit.exe | Added by the MIMAIL.S WORM! |
Y | Rabo Session Monitor | RaboSessionMon.exe | Related to RaboBank electronic banking software |
N | RadarSync | RadarSync.exe | Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
U | RadBoot | RadBoot.exe | RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
U | RadioSvr | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
U | RAMASST | RAMASST.exe | Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
X | RamBooster2 | rb.exe | Added by the AKAK TROJAN! |
U | RAMDef | ramdef.exe | Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind |
U | RamIdle | ramidle.exe | RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind |
U | RAMpage | RAMpage.exe | Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
X | Randex virus built for IRBMe | irbme.exe | Added by the RANDEX.RH WORM! |
X | RandomWin32 | mgnwin32.exe | Added by the SDBOT-DV WORM! |
Y | RapApp | RAPAPP.EXE | Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
U | Rapid Restore | rrpcsb.exe | XPoint "Rapid Restore PC" - a "Managed Recovery™ solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
X | RapidBlaster | rb32.exe | Homepage hijacker (adult content) - see this newsgroup thread |
Y | Raptor Mobile | vpnservices.exe | Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking |
X | RasCon Remote Access Service Manager | rasmngr.exe | Added by the SPYBOT.EM WORM! |
X | Rase | boln.exe | PurityScan/Clickspring adware |
X | rate.exe | i11r54n4.exe | Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS! |
X | rate.exe | ********.exe [* = random char] | Unidentified adware |
Y | RAV8Tray | ravtray8.exe | RAV anti-virus related |
X | RAVEN_VLZS.EXE | RAVEN_VLZS.EXE | Another eAcceleration program - spyware. Read their privacy statement here |
Y | RavMon | RavMon.exe | RAV AntiVirus |
X | RavTime | Mstray.exe | Added by the WUKILL.A WORM! |
X | RavTimer | RavTimer.exe | RAV AntiVirus |
X | RavTimeXP | [worm filename] | Added by the WULLIK.B WORM! |
X | RavTimXP | [worm filename] | Added by the WULLIK.B WORM! |
? | rav_temp.exe | rav_temp.exe | ?? |
N | Ray Process Killer | Prkill.exe | Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead |
X | rb32 lptt01 | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | rb32 ml097e | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | rbenh ml***e | rbenh.exe | Variant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Rcf Driver | rcf.exe | Added by the RANDEX.BLD WORM! |
X | rCron | rcron.exe | "Switch" adult content dialler |
X | rCron | dservice.exe | Switch premium rate adult content dialer |
U | RCScheduleCheck | RCSCHED.EXE | Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" |
X | RCSync | RCSync.exe | PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
U | RDClient | RDCLIENT.EXE | Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
X | RDLL | RunDll16.exe | Added by the SDBOT.F TROJAN! |
X | rdvs | [worm filename] | Added by the ULTIMAX WORM! |
X | Reactor3 | [random name]32.exe | Added by the BOFRA.A WORM! |
X | Reactor5 | [random name]32.exe | Added by the BOFRA.D WORM! |
X | Reactor6 | [random name]32.exe | Added by the BOFRA.C WORM! |
X | Reactor7 | [random name]32.exe | Added by the BOFRA.B WORM! |
X | Reactor8 | [random name]32.exe | Added by the BOFRA.E WORM! |
X | Reactor9 | [random name]32.exe | Added by the BOFRA.E WORM! |
X | readdb40 | rundll32.exe [path] readdb40.dll, EnableRunDLL32 | LZIO.com adware downloader |
X | Real Internet Player | Reaiplay.exe | Added by a variant of the SPYBOT WORM! |
X | Real player updater | realupd.exe | Added by the PARLAY TROJAN! |
X | real scheduler.hta | RealAudio.exe | Added by the CEEGAR TROJAN! |
X | Real-Tens | Real-Tens.exe | DownloadWare based advetising spyware |
X | RealAudio | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
N | RealDownload | RealPlay.exe | Download manager. Available via Start -> Programs |
X | RealDownload Express | npnzdad.exe | Advertising spyware |
N | Reality Fusion GameCam SE | RFTRay.exe | System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs |
N | RealJukeboxSystray | tsystray.exe | System Tray icon for RealJukebox |
X | realone_nt2003 | moniker.exe | Added by the SNONE.A WORM! |
X | RealP1ayer | [path to file] | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" |
N | realplay | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
X | realplay lptt01 | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
X | realplay ml097e | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
X | Realplayer One | realplay.exe | Added by the RBOT-NK WORM! |
? | Realpopup | Realpopup.exe | RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
N | Realsched | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
? | Realtime Audio Engine | mmrtkrnl.exe | ?? |
Y | Realtime Monitor | realmon.exe | Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates |
? | RealTimeUpdate | RealTimeUpdate.exe | Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
N | RealTray | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
X | RealUpdater | realupd.exe | Added by the PARLAY or MITGLIEDER.I TROJANS! |
N | Reboot | Reboot.exe | MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
Y | Recguard | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
N | Reclip | reclip.exe | Reclip Popup Clipboard manager |
X | Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | RH.DLL | SmartPops adware |
N | Recover | N/A | Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete |
? | RecoverFromReboo | RECOVE~1.EXE | ?? |
? | RecoverFromReboo | RecoverFromReboot.exe | ?? |
? | RecoverFromReboot | RECOVE~1.EXE | ?? |
? | RecoverFromReboot | RecoverFromReboot.exe | ?? |
N | RecShe | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
X | RecycleSTR | msreg32.exe | Added by the RBOT-TC WORM! |
N | Red Flag | redflag.exe | PMS prediction program with modes for guys and girls - no longer available |
X | Red Swoosh EDN Client | RSEDNClient.exe | Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network |
X | redirect | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
N | Redline Taskbar | taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
X | REEGRUN | [path to file] | Added by the SECDROP.AI TROJAN |
U | Referee | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
N | Refresh | Refresh.exe | (Iomega) Refresh - loads the Iomega desktop icons at startup |
X | Reg | Reg.hta | Homepage hi-jacker. Removal instructions here |
? | Reg Check | lpt.exe | Related to Supanet ISP software - what does it do and is it required? |
X | Reg Service | winsy.exe | Added by a variant of the SPYBOT WORM! |
X | Reg Services | Winboot32.exe | Added by the RBOT.PB WORM! |
X | reg1.reg | vuamgard.exe | Added by a variant of the IRC.BOT TROJAN! |
X | Reg32 | Reg32.exe | Hijacker - redirecting to only-virgins.com |
X | reg32 | reg32.exe | Added by the NOUPDATE.B TROJAN! |
X | Reg32 | reg33.exe | CoolWebSearch parasite variant |
X | Regcheck | ~CAB001.EXE | Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS! |
X | RegCleaner | SYSio32.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware |
X | RegCompres | Regcpm32.exe | Added by the POLDO.B TROJAN! |
X | RegCompres | REGCPM32.EXE | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
X | Regcxn | Regcxn.exe | Added by the COIBOA-D TROJAN! |
X | RegDone | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | RegDone | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
X | RegDone Ex | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | RegDoneEx | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
X | regedit | regedit.exe | Added by the BRID.A WORM! Note - resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP). The valid "regedit.exe" resides in C:Windows (Win9x/Me/XP) or C:Winnt (WinNT/2K) |
X | REGEDIT | Regsrv32.com | Added by the SOUTHGHOST WORM! |
U | RegFreeze | regfreeze.exe | RegFreeze anti-spyware software |
X | reggsdg | spoolserv.exe | Added by the SDBOT-MS WORM! |
? | reginfo32 | reginfo32.exe | ?? |
N | Register MediaRing Talk | register.exe | If you don't want to register MediaRing and be reminded about it every bootup disable it |
? | Register SeqChk | regsvr32.exe ..csseqchk.dll | ?? |
U | RegisterDropHandler | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
N | Registration-Studio 8 | RegTool.exe | Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems |
X | Registry | wscript.exe | Added by the VBSWG.AQ WORM! |
X | Registry Checkup | winreg.exe | Added by an unidentified WORM or TROJAN! |
X | Registry Loader | regloadr.exe | Added by the GAOBOT.AO WORM! |
X | Registry Loader | winhlpp32.exe | Added by the GAOBOT.AO WORM! |
X | Registry Scanner | regscanr.exe | Added by a variant of the OPTIX TROJAN! |
X | Registry Server | regsrv32.exe | Added by the RBOT-GM WORM! |
X | Registry Services | Registry.exe | Added by the DOWNLOADER.CILE TROJAN! |
X | Registry System16 Checkup Monitor | SystemReg16.exe | Added by a variant of the RBOT WORM! |
X | Registry System166 Checkup Monitor | SystemReg166.exe | Added by a variant of the RBOT WORM! |
X | RegistryChk | winbackup.exe | Added by the MERTIAN WORM! |
U | RegistryMechanic | RegMech.exe | Registry Mechanic for Windows - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages" |
X | RegistryMonitor | registry.pif | Affilred adware |
U | REGIST~1 | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
Y | RegProt | Regprot.exe | RegistryProt from Diamond Computer Systems - protects the system registry against changes |
X | RegRun | mActiveX.exe | Added by a variant of the RBOT WORM! |
X | REGRUN | winfix22490.exe | Added by a variant of the RBOT WORM! |
Y | Regrun2 | WatchDog.exe | Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc |
X | regservices.exe | regservices.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | RegShave | regshave.exe | Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly |
X | regsrv | regsrv.exe | Added by the OPTIXPRO.11 TROJAN! |
X | Regsv | regsv.exe | Search hijacker - redirecting to scheo.com |
X | regsvc32 | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
X | regsvr | regsvr.exe | Added by the WEBMONEY-G TROJAN! |
U | REGSVR32 | regsvr32.exe ctasio.dll | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
? | regtmlp | N/A | ?? |
U | RegTweak | RegTwk.exe | Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface |
X | RegVer | REGVER.EXE | Added by the LATINUS.16 TROJAN! |
X | RegWrite | csrss.exe | Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
U | Regx10EXE | atix10.exe | ATI Remote Wonder - PC wireless remote control |
X | reg_key | FUKULAMER.exe | Added by the BEAGLE.AH WORM! |
X | reg_key | loader_name.exe | Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS! |
X | Reg_WFT | Regsysw.com | Added by the WILSEF VIRUS! |
U | ReleaseRAM | RRAM.exe | "Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
X | reload | reload.vbs | Added by the LOVELETTER.AS VIRUS! |
X | Reload | reload.exe | Added by the LAZAR TROJAN! |
N | RemHelp | Remhelp.exe | BT Voyager ADSL Modem Help related |
N | Reminder | reminder.exe | From MS Money. Reminds you of your bills |
N | Reminder | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
N | Reminder-cpqXXXXX | remind32.exe | Compaq printer Registration |
N | Reminder-hpcXXXXX | remind32.exe | HP CD-Writer Registration |
N | Reminder-ranXXXXX | remind32.exe | Registration reminder widget for Rand Mcnally maps |
N | reminder-ScanSoft Product Registration | remind32.exe | Registration reminder for ScanSoft products such as PaperPort |
U | RemindMe | RemindMe.exe | Remind-Me - calendar software |
N | Remind_XP | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
X | Remndr | CsRemnd.exe | CasinoOnline foistware |
U | Remote Access | rnaapp.exe | Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed |
X | Remote Access Slave | Synchost.exe | Added by the RIPJAC TROJAN! |
N | Remote Control | Rc.exe | Hinet Hi-Five ISP software |
U | Remote Desktop Computing | marspc.exe | Marspc Remote Desktop Computing |
U | Remote Management Agent | zenrc32.exe | Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation |
U | remote master | remote master.exe | Required if you want your ASUS Remote control to work at all. Available via Start -> Programs |
X | Remote Procedure Call | winrpc.exe | Added by the RBOT-KM WORM! |
X | Remote Procedure Call | winsysrpc.exe | Added by the SDBOT-PS WORM! |
X | Remote Procedure Call For Windows 32bit | rpc.exe | Added by the RBOT-MD WORM! |
X | Remote Procedure Call Locator | RUNDLL32.EXE reg678.dll ondll_reg | Added by a variant of the LOVGATE WORM! |
X | Remote Procedure Calls | mswinrpc.exe | Added by the RBOT.KJ WORM! |
X | Remote Procedure Calls | mswinc.exe | Added by the RBOT-IT WORM! |
X | Remote Procedure Calls | win.exe | Added by the SDBOT-QI WORM! |
Y | Remote Update Monitor | imonitor.exe | Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer |
Y | RemoteAgent | RAUAgent.exe | Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates" |
U | RemoteCenter | RcMan.exe | Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats |
U | RemoteControl | rmctrl.exe | Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
U | RemoteControl | PDVDServ.exe | Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
N | Remote_Agent | RemoteAgent.exe | Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs |
N | Removecpl | Removecpl.exe | Related to a Belkin 54Mbps Wireless Utility Control Panel applet |
X | Removed.exe | Removed.exe | GatorCheat - adware downloader |
? | RemStart | remstart.exe | Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required? |
? | RenolB | ib.exe | ?? |
U | RepliGo Assistant | RepliGoMon.exe | Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" |
U | ReproPRD | PrdUsb.exe | Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work |
X | requester | requester.*.exe | Added by a variant of the MUQUEST.A trojan - NOTE: the * stands for a digit, examples: requester.5.exe, requester.10.exe |
N | Resolution Assistant | matcli.exe | Dell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide |
N | Resource Meter | rsrcmtr.exe | Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes |
? | Restart Watch | Watch.exe | Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? |
U | Restart WSC Setting | wscrestp.exe | WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes |
? | Restart_VS | Viewsonic.exe | Could be a left-over from the installation of a Viewsonic flat panel display |
Y | RestoreIT! | VBPTASK.EXE | RestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure." |
X | restory | restory.exe | Added by the RETSAM TROJAN! |
U | Resume Copy | copyfstq.exe | Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function |
U | ResumeFixClocks | resumefix.exe | Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards |
X | retime | retime.exe | Added by the GIPMA TROJAN! |
U | RetrieverScheduler | retrieverscheduler.exe | 80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available |
U | RevoTaskbarApp | RevoTask.exe | Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available |
N | RexSyMon | rexsymon.exe | Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC |
U | rfagent | rfagent.exe | Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders |
X | RFTray | RFTRay.exe | Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
Y | rfw | Rfw.exe | RAV AntiVirus |
? | rfwydg | rfwydg.exe | ?? |
N | RFX_auto_upgrade | rundll32.exe npvpg005.dll | A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade |
U | RH | rh32.exe | EuroFonts - adds Euro symbols to pre-Euro computers |
X | Rhino | [random name]32.exe | Added by the BOFRA.A WORM! |
U | RhinoBlocker | RhinoBlocker.exe | RhinoBlocker - pop-up stopper |
N | RHSI SHS | SHS.exe | Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash" |
U | Ring Central Fax | rcenterrll.exe | Only needed if you want a PC to answer faxes automatically |
X | rIOphosIs | rIOPHosIs.vBS | Added by the RIOSYS MACRO! |
U | RivaTuner | RivaTuner.exe | RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
U | RivaTunerStartupDaemon | RivaTuner.exe | RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
? | RjLyraInstaller | setup.exe | ?? |
U | rmctrl | rmctrl.exe | Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
N | rmmon | mprmmon.exe | Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card |
? | RMremote | RmRemote.exe | Remote control driver for REALmagic Xcard. Is it required? |
X | rn4d | dirote.exe | Added by the BKDR_MAROON.A TROJAN! |
U | RNBOStart | sentstrt.exe | Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools |
? | rndll2 | rndll2.exe | May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within? |
X | rngmf | [path to trojan] | Added by the RANKY.C TROJAN! |
N | RoboForm | RoboTaskBarIcon.exe | Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin |
N | RoboFormWatcher | RoboFormWatcher.exe | AI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs |
U | Rocket.Time | RocketTime.exe | Time synchronization software from Rocket Software |
? | roketpipe | rpclient.exe | ?? |
X | rollbk | dsm.exe | Added by the SERFLOG.B WORM! |
X | rollbk | msmpatch.exe | Added by the SERFLOG.B WORM! |
X | rollbk | svosm.exe | Added by the SERFLOG.B WORM! |
X | rollbk | sysup.exe | Added by the SERFLOG.B WORM! |
X | romahere | matrixhere.exe | SuperSpider hijacker - a CoolWebSearch parasite variant |
U | romahere2 | ************.exe [* = random char] | SuperSpider hijacker - a CoolWebSearch parasite variant |
X | romahere3 | ************.exe [* = random char] | SuperSpider hijacker - a CoolWebSearch parasite variant |
? | ROUTD | ROUTD.exe | ?? |
N | RoxAssist | RoxAssist.exe | Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually |
? | Roxio Engine | MSMNGR32.EXE | Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN! |
N | RoxioAudioCentral | RxMon.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly. |
N | RoxioDragToDisc | DrgToDsc.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly |
Y | RoxioEngineUtility | EngUtil.exe | Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking |
U | RP32 | rp32.exe | ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems. |
X | RPC | MSschost.exe | Added by a variant of the GAOBOT/AGOBOT WORM! |
X | RPC Patcher | [path to worm] | Added by the BOLGI WORM! |
X | RPCserv32 | services.exe | Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
Y | RPCSS.exe | rpcss.exe | Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
X | RRMedic | rrmedic.exe | Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
U | rscmpt | rscmpt.exe | Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status |
U | rsMenu | rsMenu.exe | Synchronizes a Casio PDA with MS Outlook |
X | RSPC Driver | [random filename].exe | Added by the RBOT-SN WORM! |
X | RSPC Driver D | [random filename] | Added by a variant of the RBOT WORM! |
? | RSRCMTZ | RSRCMTZ.exe | ?? |
X | RSS | rundll32 RSSToolbar.dll, DllRunMain | "Related Sites" toolbar - SearchAndClick hijacker variant |
X | RSync | netsync.exe | Pops-stop.com parasite, an IEPageHelper/SafeSurfing adware variant |
N | RtlMon.exe | RtlMon.exe | Monitor for RealTek network card |
Y | RTMonitor | RTMonitor.exe | Cheyenne (now eTrust) antivirus |
X | rtos | rtos.exe | IRC trojan |
? | RTStartMute | N/A | ?? |
Y | rtvscn95 | RTVSCN95.EXE | Real-time virus scanner component of Norton Anti-Virus Corporate Edition |
X | Ruby13 | Ruby13.exe | Added by the MEXER.E WORM! |
X | Ruby14 | Ruby14.exe | Added by the FIGHTRUB-A WORM! |
U | RuLaunch | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
X | run | Autoexec.com | Added by the HOLCAS.A WORM! |
X | run | inetinfo.exe | Added by the BINGHE TROJAN! |
X | Run Msn Messenger | msnmgr.exe | Added by the AGOBOT.HA WORM! |
X | Run MSupdt32 | wscript MSupdt32.vbs | Added by the CASER WORM! |
U | Run POPFile in background | perl.exe | POPFile - E-mail spam blocker |
U | Run POPFile in background | wperl.exe | POPFile - E-mail spam blocker |
U | Run StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
X | Run TaskMrg | csrss.exe | Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
X | Run XP Service Pack | xpservicepack.exe | Added by the SDBOT.AQA WORM! |
X | run32dll | WINClock.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | run32dll | task32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Run32dll | ocxdll.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | run= | cmmpu.exe | MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
N | run= | hpfsched | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature |
N | run= | lxdboxcp.exe | Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS |
N | run= | pcfix2k.exe | pcfix2k splash screen |
X | run= | ptlseq.cpl | PhoenixNet BIOS adware. See here |
U | run= | ramsys.exe | Advanced Startup Manager from Rays Lab |
? | run= | wallflip.exe | Desktop wallpaper changer? |
X | run= | svcinit.exe | CoolWebSearch parasite variant |
X | run= | fntldr.exe | CoolWebSearch parasite variant |
Y | run= | smsrun16.exe | Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs |
? | run= | win.ini | ?? |
X | run= | RAVMOND.exe | Added by a variant of the LOVGATE WORM! |
X | run= | real.exe | Added by a variant of the LOVGATE WORM! |
X | run= | dec25.exe | Added by the ATAK.F WORM! |
? | run= | LXBTppls.exe | Reportedly part of Lexmark printer software - what does it do and is it required? |
N | run= | fmedia.exe | FMedia FaxWorks related - can be run manually |
Y | run= | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers - required for printer to work |
X | run= | cyxid98.exe | Unidentified malware |
X | run= | info32.exe | CoolWebSearch parasite variant |
X | run= | mouse_configurator.win | Added by the GAGGLE.E WORM! |
X | run= | RegistryReminder.exe | Added by the APSTROJAN.OB TROJAN! |
X | run= | sec5dec.exe | Added by the ATAK.G WORM! |
X | run= | wmplayer.exe | CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable! |
X | run= | Autoexec.com | Added by the HOLCAS.A WORM! |
U | RunAlert | AService.exe | MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system |
N | runAP | runAP.exe | Not required but what is it? |
X | Runapp32 | Runapp32.exe | Added by the NEODURK TROJAN! |
Y | RunCA | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
X | Rund1l32 | Winfi1e32.exe | Added by the MERTIAN WORM! |
X | rundl332 | math.exe ...pluged.exe | Added by the DOOMJUICE WORM! |
X | rundli32 | rundli32.exe | Added by the LADE WORM! |
X | RunDLL | rundll32.exe bridge.dll, Load | Flingstone.com browser hijacker |
X | rundll*** | die.exe [path] mdll.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
X | rundll*** | die.exe [path] secure.bat | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
X | rundll*** | die.exe [path] secure.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
X | rundll*** | die.exe [path] ttg.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
X | Rundll16 | Rundll16.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
X | Rundll32 | Rundll32.exe | Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the WindowsFonts directory |
N | RUNDLL32 | RUNDLL32.EXE NvQtwk, NvCplDaemon | System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
N | RunDLL32 | RunDLL32.exe NvMCTray.dll, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
U | rundll32 | Rundll32.exe Wf2kcpl.dll DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
X | RunDLL32 | winupdate.exe | Added by an unidentified TROJAN! - possibly a BMBOT variant |
X | Rundll32 | Windows.exe | Added by the QQPASS.E TROJAN! |
X | Rundll32 | Rundll32.exe ptipbm.dll, SetWriteBack | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required? |
X | rundll32 | [path to worm] | Added by the AUTEX WORM! |
? | rundll32 | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
X | rundll32 | rundll32.exe | Added by the SANKER WORM! Note that the valid "rundll32.exe" resides in C:WindowsSystem32 wheras this version resides in C:Windows |
X | rundll32 | csrss.exe | Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
U | rundll32 | RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent | Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
N | Rundll32 cmicnfg | Rundll32 cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
X | Rundll32.exe | Proyecto1.exe | Added by the GRUEL WORM! |
X | Rundll32.exe | Root.exe | Added by the GRUEL WORM! |
X | Rundll32_7 | rundll32.exe MSIEFR40.DLL, DllRunServer | BrowserAid "Featured Results" hijacker variant |
X | Rundll32_8 | rundll32.exe inetp60.dll, DllRunServer | BrowserAid parasite variant |
X | rundll64 | [path to worm] | Added by the AUTEX WORM! |
X | RundllSvr | Rundll.exe | Added by the HUAYU WORM! |
X | Rundllsystem32 | Rundllsystem32.exe | Added by the NETDEVIL.B TROJAN! |
X | Rundnm | Rundnm.exe | Added by the DELF-HA TROJAN! |
U | RunOnce | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these |
X | RunProg | Server.exe | Added by the OPTIX.04.A TROJAN! |
X | RunProg | wini.exe | Added by the OPTIX.04.D TROJAN! |
X | runreper | viewer.exe | Added by the REPER.A VIRUS! |
X | RunServices | runsvc32.exe | Added by the AGOBOT.QJ WORM! |
U | RunSysd32 | RunSysd32.exe | DesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within |
X | runwin32 | runwin32.exe | Added by the ESEARCH-A TROJAN! |
X | RunWindowsUpdate | uptodate.exe | BrowserAid/BrowserPal foistware |
X | Run[0] | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
X | Run_cd | Run_cd.exe | Added by the GHOST.23 TROJAN! |
? | RUSBHOLoader | rundll32.exe RUSBHOLoader.dll, AutoRegister | ?? |
X | rvde | N/A | Related to li-speed**** |
X | RVP | bpc.exe | Spyware included with the latest version of Grokster. Also see here |
N | RxMon | rxmon9x.exe | Dell Resolution Assistant |
Y | r_server | r_server.exe | Radmin - remote admistrator server |
X | S0undMan | svch0st.exe | Added by the LOVGATE.AB WORM! |
? | S24EvMon | S24EvMon.exe | Event Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required? |
X | S3 Internal Chip | s3serv.exe | Added by the AGOBOT-DD WORM! |
? | S3apphk | S3apphk.exe | S3 graphics related? |
? | S3Hotkey | s3hotkey.exe | S3 Video driver related. What does it do and is it required? |
? | S3Mon | S3Mon.exe | S3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required? |
N | S3TRAY | S3Tray.exe | S3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display |
? | s3tray2 | s3tray2.exe | Same as the s3tray entry in this table? |
? | S3TRAYHP | S3trayhp.exe | S3 Video driver related. What does it do and is it required? |
U | S4F | S4F.exe | S4F internet filtering software |
X | s4helper | s4helper.exe | Searchcentrix hijacker |
? | SA | Sa3.exe | Logitech QuickCam driver. Is it required? |
? | SA Service | SAservice.exe | Associated with Cyber Trio and Warner troubleshooting software from G-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required? |
N | Sa3dsrv | Sa3dsrv.exe | 3D sound extension for Windows |
X | saap | saap.exe | 180Solutions/N-Case adware variant |
N | Sabreserver | SABSERV.EXE | Airline reservation software from Sabre. Available via Start -> Programs |
N | SAClient | RegCon.exe | AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging |
X | Safe | SafeWin.exe | Added by the FOCOSENHA TROJAN! |
X | SafeGuard Popup Blocker Updater | regsvr32 [path] sfgupd.dll | SafeguardProtect/Veevo hijacker |
X | SafeGuard Popup Blocker Updater (required) | regsvr32 [path] sfg****.dll [* = ramdom char/digit] | SafeGuard Protect/Veevo - hijacker |
X | SafeGuard Popup Updater (required) | regsvr32 [path] sfg****.dll [* = ramdom char/digit] | SafeguardProtect/Veevo hijacker |
X | SafeGuard Popup Updater (required) | regsvr32 [path] PDF****.dll [* = random char/digit] | SafeguardProtect/Veevo hijacker |
N | SafeInstall.exe | SAFEIN~1.EXE | Monitors a download and ensures an newer version of a file isn't replaced by an older one |
N | SafeOFF | SafeOff.exe | Provides protection that if user accidentally presses the power switch a dialog will pop up for confirmation |
X | SafeSearch | safesearch.exe | AutoSearch parasite variant |
X | SafeSurfingUpdate | SSUpdate.exe | DyFuCa/MoneyTree parasite variant |
U | Safeworld | Freedom.exe | SafeWorld Internet Security |
X | Sagate Security Firewall | sagate.exe | Added by the GAOBOT.BOW WORM! |
N | SAgent2ExePath | SAgent2.exe | Seiko Epson printer status agent. Disable if printer is not used often |
U | SAGENTSERVICE | Sagent.exe | Added by TinySpyAgent Note - this application must be manually installed |
X | sagnt | sagnt.exe | Adware web downloader |
X | SAHagent | Sahagent.exe | ShopAtHomeSelect parasite |
X | SAHBundle | bundle.exe | ShopAtHomeSelect parasite related |
X | saie | saie.exe | 180Solutions/N-Case adware variant |
U | SAIMON | SaiMon.exe | Saitek joystick driver |
X | sain | sain.exe | 180Solutions/N-Case adware variant |
X | sais | sais.exe | 180Solutions/N-Case adware variant |
? | SaiSmart | SaiSmart.exe | "Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button. What does it do and is it required? |
U | SaitekAutoConfigure | saicnfig.exe | Configuration for Saitek game controllers |
X | salm | salm.exe | 180Search adware |
X | salm | salm.exe | 180Solutions/N-Case adware variant |
U | SAMcal | SAMcal.exe | SamCal - calendar/reminder program |
U | Sametime Connect | Connect.exe | IBM Lotus Instant Messaging and Conferencing software |
N | SandIcon | SandIcon.exe | SanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources |
X | sapp | sapp.exe | 180Solutions/N-Case adware variant |
X | saSyncMgr | rundll32.exe sasync.dll, SyncWait | Browser hijacker - redirecting to Searchant.com |
U | SATARaid | SATARaid.exe | RAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives |
X | satmat | satmat.exe | Transponder parasite updater/installer |
U | SAUpdate | SAUpdate.exe | Big Brother from Quest Software. System and network monitor |
Y | SAVAgent | SAVAgent.exe | Part of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users |
X | Save | Save.exe | SaveNow adware |
X | SaveDate | SaveStartDate.Exe | Unidentified adware |
X | Savenow | SaveNow.exe | SaveNow adware |
X | Savenow | savenow.exe | Added by the SPREDA.B VIRUS! |
U | Say The Time 5.0 | SAYTIME.EXE | This program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly |
U | SB | SB.exe | Acer Soft Button on Acer Tablet PCs |
N | SB Audigy 2 Startup Menu | /l:eng | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
X | SB Watchdog | SBWatchdog.exe | Spyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information |
U | SBAutoUpdate | sbautoupdate.exe | SpywareBlaster auto-updater |
U | SBC Self Support Tool | matcli.exe | matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file. The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
U | SBDrvDet | SBDrv.exe | Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one |
X | SBHC | sbhc.exe | SuperBar parasite - uninstall available here |
N | SBMX | sbmx.exe | SoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only) |
U | SbUsb AudCtrl | RunDll32 sbusbdll.dll, RCMonitor | Control for Soundblaster MP3 external (USB) sound card |
N | sc | scrubxp.exe | ScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc |
U | sc | sc.exe | Watchdog 2.0 Software - monitoring program |
U | sc | run.exe | All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file |
? | sc23exec | sc23exec.exe | Possibly related to a digital camera |
Y | SC3300CC | SC3300CC.exe | SiPix digital camera Twain device driver |
X | scan | mscman.exe | Spyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!" |
? | Scan Detector | Pmxdetect.exe | Associated with PrimaScan scanners. Is it required? |
? | Scan Wizard | button.exe | Associated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required? |
X | ScanDisk | ScanDisk.exe | Added by the GANDA.A WORM! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker |
X | scands32.exe | scands32.exe | Added by a variant of the Adclicker TROJAN! |
? | ScanFile | ?? | ?? |
? | ScanInicio | Inicio.exe | Part of Panda Anti-Virus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active |
N | Scanner Detector | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
X | Scanreg | [filename] | Added by the QQPASS.E TROJAN! |
X | ScanRegistry | nsrvnt.exe | Added by the NERTE TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe |
X | ScanRegistry | scanregv.exe | Added by the MASTERLOCK TROJAN!. Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe |
Y | ScanRegistry | Scanregw.exe | Scans the system registry and makes back-ups at start-up. Important should the registry become corrupt. The executable "Scanregw.exe" is located in %windir% (where %windir% is the Windows directory - C:Windows or C:Winnt) |
X | ScanRegistry | Scanregw.exe | Added by the STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%System (where %windir% is the Windows directory - C:Windows or C:Winnt). Runs from the registry RunServices key as opposed to the Run key |
X | ScanSpyware v * | Scanner.exe | Spyware remover (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
N | SCardSvr | scardsvr.exe | Related to SmartCard readers and sometimes uses lots of system resources |
X | SCardSvr | SCardSvr32.Exe | Added by the MOFEI.B WORM! |
N | Scheduled Maintenance | Scheduled_Maintenance.exe | Scheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs |
X | Scheduling Agent | Scheduler.exe | Added by the SUBWOOFER TROJAN! Note - this is not the real MS Scheduling agent as the executable is incorrect |
X | SchedulingAgant | MMTASK.EXE | Added by the YAB.A TROJAN! Not the valid MusicMatch Jukebox which has the same filename |
U | SchedulingAgent | mstask.exe | MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
U | SchedulingAgent | mstinit.exe | MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans |
U | Schmaili | Schmaili.exe | Schmaili - insert animated smilies into your e-mail |
Y | SCHWIZEX | SCHWIZEX.EXE | Part of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot |
X | ScManager | scman.exe | Added by the FORBOT-CW WORM! |
X | scopedll | scopedll.exe | Added by a variant of the CRYPTER.C TROJAN! |
N | Scotia OnLine Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
N | Scotia OnLine Security v*.* Recovery | etdirrcv.exe | Scotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process |
X | Scr | scr.scr | Added by the OPASERV.T WORM! |
N | ScrapPad | Scrappad.exe | ScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper |
U | Screen Calendar | scrcal.exe | Screen Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler |
U | Screen Guard | launch.exe | Part of Access Denied security and privacy software |
U | Screen Guard Message Scan | sgms.exe | Part of Access Denied security and privacy software |
N | Screen Saver Control | FSScrCtl.exe | Installs as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon |
N | ScreenPrint32 | ScreenPrint32.exe | ScreenPrint32 screen capture software - can be launched manually |
? | screxe | scruser2k.exe | ?? |
? | script | script.bat | Maybe associated with DOS on a Win9x machine |
Y | ScriptBlocking | SBServ.exe | Update to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information |
Y | ScriptSentry | Scriptsentry.exe | Script Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly |
U | Scroll-In-Mouse V2.0 | SCROLL.EXE | Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features |
X | ScrSvr | ScrSvr.exe | Added by the OPASERV WORM! |
X | ScrSvrOld | [worm filename] | Added by the OPASERV WORM! |
Y | Scsi | Scsi.exe | SCSI Miniport driver |
X | scvhost | svzhost.exe | Added by a variant of the SPYBOT WORM! |
X | scvhost loader | ixplore.exe | Added by the SDBOT-CY TROJAN! |
X | scvhost.exe | scvhost.exe | Added by the LOHAV-N TROJAN! |
X | sd32info | sd32info.exe | Added by the CRYPTER.A TROJAN! |
U | SDaemon | sdaemon.exe | PC Security from Tropical Software. 'PC Security™ 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features' |
X | SDAv | csnss.exe | Added by the SERFLOG.C WORM! |
X | SDAv | svhost.exe | Added by the SERFLOG.C WORM! |
X | sdchosts32 | vbdd.exe | Added by the RANKY.AG TROJAN! |
N | SDetect | SDetect.exe | ScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button |
X | sdfsdfsdf | sp2update.exe | Added by a variant of the SPYBOT WORM! |
X | SDIN Adapter | sdin.exe | Added by the FORBOT-AP WORM! |
? | SDJobCheck | triggusr.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
X | sdkupdate22 | SDK0mCORE.exe | Added by the FORBOT-DT WORM! |
N | SDPhotoBar.exe | SDPhotoBar.exe | SmartDraw Photo - "organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics" |
X | sdrss | sdrss.exe | Added by the SDBOT-SQ WORM! |
U | sealmon | sealmon.exe | SealedMedia enables you to combine document protection and control with your existing applications - such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email |
? | Search Hook | srchhook.exe | ?? |
X | Search Page | http://find.naupoint.com | Naupoint browser hijacker |
X | Search-Exe | SE.exe | Search-Exe hijacker |
X | Search.vbs | Hijacker | |
X | SearchEnhancement | scbar.exe | IE search hijacker |
X | searchnav | searchnav.exe | SearchNav adware - IEFeatures/Popnav variant |
X | SearchNavVersion | searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant |
X | SearchSetter | searchsetter[1].exe | Browser hijacker - redirecting to FindWhateverNow.com |
X | SearchSquire33 | SearchUpdate33.exe | SearchSquire parasite |
X | SearchUpgrader | SearchUpgrader.exe | Hijacker |
X | Secboot | w32tm.exe | Added by the HAXDOOR.D TROJAN! |
U | SecondChance | sctray.exe | Power Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash |
X | Secret-Crush | start.exe | Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
U | Secsys | Secsys.exe | Key Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
X | secure | secure.exe | DealHelper adware |
N | SecureCleanIEClean | SCIEClean.exe | SecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches |
U | SecureItPro | Secureitpro470p.exe | SecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop |
X | SecureLogin | Mslg32.exe | Added by the REDZED WORM! |
X | Security Accounts Manager SM | samsm.exe | Added by the SPYBOT.JE WORM! |
X | Security Agent Manager | mssams.exe | Added by the RBOT-SV WORM! |
N | Security iGuard | Security iGuard.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
U | Security Manager | SecurityManager.exe | A ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private |
X | Security Patches | msnkn.exe | Added by the RBOT.WW WORM! |
X | security service | syss.exe | Added by an unidentified WORM or TROJAN! |
Y | SECWIZ98 | SECWIZ98.EXE | Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here |
? | SelfHostUtil | slefhost.exe | ?? |
U | SeMS | SeMS.exe | PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone |
U | Sensiva | Sensiva.exe | Symbol Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly |
X | SENTRY | SENTRY.exe | From IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it |
X | Sepate Security Firewall | sepate.exe | Added by a variant of the RBOT WORM! |
X | Serials | serials.exe | Any one of a variety of worms and trojans |
X | serpe | formatsys.exe | Added by the SERFLOG.A WORM! |
X | serpe | msmbw.exe | Added by the SERFLOG.A WORM! |
X | serpe | serbw.exe | Added by the SERFLOG.A WORM! |
Y | serrdctl.exe | serrdctl.exe | "Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems |
N | Serv-U | serv-u32.exe | FTP server |
X | Serv-U | wssdsu.exe | Added by the MANIFEST TROJAN! |
X | server | server.exe | Added by the DELTAD.A WORM! |
X | SERVER.EXE | SERVER.EXE | Added by the BUSHTRO122 or SMOKODOOR TROJANS! |
X | serverex | Server.txt.vbs | Added by the DELTAD.A WORM! |
U | Service | service.exe | Added by the ALADINZ.H TROJAN! |
X | Service | services.exe | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
X | Service | [trojan filename] | Added by the KAITEX.E TROJAN! |
X | Service | services.exe | Added by the NETSKY or NETSKY.B WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Service | SYSNT.exe | Added by the CHA TROJAN! |
N | Service Connection | sccenter.exe | For Compaq PC's. Part of Backweb |
N | Service Connection | bwtray.exe | For Compaq PC's. Part of Backweb |
X | Service Controller | Csrrs.exe | Added by the GAOBOT.AO WORM! |
X | Service Host | [filename].exe | Added by the TORVEL.B WORM! |
X | Service Host | spoolxx.exe | Added by the TORVEL WORM! |
X | Service Host | svchost.exe | Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Service Host Driver | svchost.exe | Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
N | Service Manager | sqlmangr.exe | SQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs |
X | Service Manager | dxsound.exe | Added by the PROXY-GRIC TROJAN! |
X | Service Process | SVCHOST.EXE | Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Service Process | winset.exe | Added by a variant of the SPYBOT WORM! |
X | service updaer | qualityz.exe | Added by an unidentified VIRUS, WORM or TROJAN! - probably a SPYBOT variant |
X | Service.exe | Service.exe | "servedby.advertising" popup generator |
U | ServiceConfig | ispbeg.exe | Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
Y | ServiceLayer | ServiceLayer.exe | Nokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly |
X | services | start.bat | Added by the ZCREW TROJAN! |
X | Services | [path to trojan] | Added by the METEORSHELL TROJAN! |
X | Services | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe |
X | Services | services.exe | Added by a number of VIRUSES, WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
X | Services | winread.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Services | windns.exe | Added by a variant of the RBOT WORM! |
X | Services Controller | lsassa.exe | Added by the CIADOOR.122 VIRUS! |
X | Services Host | Scchost.exe | Added by the DONK WORM! |
X | Services Logon | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Services Process | services.exe | Added by unidentified spyware - recognized by Kaspersky antivirus as Small.X TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Services Startup | services.exe | Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Services Startup | svhost33.exe | Added by a variant of the RBOT WORM! |
X | Services.EXE | services.exe | Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
X | services.exe | Services.exe | Added by the CIADOOR-F TROJAN! Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup! |
X | Services004 | [worm filename] | Added by the BUGBROS WORM! |
? | ServUTrayIcon | ServUTray.exe | System Tray icon for Serv-U FTP server. Is it required? |
X | SESync | sed.exe | Downloadware/SED adware downloader |
? | SetDefaultMIDI | MIDIDef.exe | Related to a Soundblaster Audigy soundcards. What does it do and is it required? |
? | setdefprt | setdefprt.exe | Related to a Brother printer? |
U | SetecCertUtil | Certutil.exe | Setec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV |
X | setFTPBack | createsw.exe | Added by the FTP_BMAIL TROJAN! |
N | SetHook | SetHook.exe | Fellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar" |
N | SETI@home | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
N | seticlient | SETI@home.exe | SETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data |
N | SetIcon | SetIcon.exe | Installed by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog |
N | SetiQueue | Setiqu~1.exe | Provides work unit buffering for Seti@Home clients - see here for more details |
N | SetiSpy | SetiSpy.exe | From the site - 'SETI Spy is a little program I wrote to "spy" on the progress and performance of the SETI@home client. I call it a "spy" because I tried to make it as unobtrusive as possible' |
? | SetRefresh | SetRefresh.exe | Found on a Compaq PC. Video refresh rate utility? Is it required? |
X | Setting | sysweb.exe | Added by the SDBOT.GEN TROJAN! |
N | setup | hphprld.exe ....setup.exe | HP DeskJet Setup - printers function normally without it |
X | Setup experation | svchost.exe | Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process, which NOT appear in Msconfig/Startup! |
N | SetupICWDesktop | icwconn1.exe | Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway |
X | setupuser | regedit.exe setupuser.log | Regfile in disguise - another CoolWebSearch parasite variant |
? | setuzp | setuzp.exe | ?? |
X | SetVrc | setvrc.exe | Added by the HUNTOCX WORM! |
X | Sex Teris | st01b.exe | Added by the REPAD WORM! |
X | Sexy_sg | Sexy_sg.exe | Premium rate adult content dialler |
N | SFP | vzSFPWin.EXE | Verizon Online Support Center - prompts for online updates |
X | SFtrb Service | cftrb32.exe | Added by the SOBIG.D WORM! |
U | SfWinStartInfo | sfWinStartupInfo.exe | SFIRM32 Online Banking software |
U | Sgecrypt | Sgecrypt.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
U | Sgeecview | Ecview.exe | SafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks" |
N | sginst | sginst.exe | eAcceleration Stop-Sign related - not recommended, see note |
? | SGTBox | SGTBox.exe | Canon scanner driver. Is it required? |
U | sgtray | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
X | shambl3r | cnf.bat | Added by the REMABL WORM! |
X | shambl3r* | shambl3r.exe | Added by the REMABL WORM! where * is 2 to 11 |
N | Share-to-Web Namespace Daemon | hpgs2wnd.exe | "HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs |
N | Shareaza | Shareaza.exe | Shareaza P2P client |
X | sharedprem | sharedprem.exe | Added by the MAKECALL TROJAN! |
Y | Sharing and Mapping Software | DShmap.exe | Intel AnyPoint internet sharing software |
N | SharkEject | AEJCT32.exe | Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required |
N | Shcenter | chcenter.exe | IMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files" |
X | SheduIer | svchst.exe | Premium rate adult content dialler |
X | Shell | Shell32.exe | Added by the BADSECTOR TROJAN! |
X | Shell | ray.exe | Homepage hijacker re-directing browsers to adult content websites |
X | Shell | Tray.exe | Homepage hijacker re-directing browsers to adult content websites |
X | Shell | wmedia16.exe | Added by the GOLDUN TROJAN! |
X | Shell | Open32.exe | Horseserver.net browser hijacker |
X | Shell Extension | spollsv.exe | Added by a variant of the LOVGATE WORM! |
X | Shell32 | Shell32.vbs | Added by the SCAFENE WORM! |
X | ShellApi | SHELLMSN.EXE | Added by the NETDEV.B TROJAN! |
X | Shellapi32 | Shellapi32.exe | Added by the NETDEVIL (or NERTE) TROJAN! |
X | ShellCommand | [path to file] | Added by the REMCON-A TROJAN! |
X | ShellEx | ShellEx.exe | Added by the ANAKHA TROJAN! |
X | shellsystem | shellsystem.exe | Added by the UPCHAN TROJAN! |
N | shicoxp | shicoxp.exe | Installed with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer |
X | Shine | Shine.exe | Added by the HAPPYLOW (or NISHE-A) VIRUS! |
? | SHINITV | shinitv.exe | ?? |
X | Shmgrate.exe | ibot4.exe | Added by the GASTER TROJAN! |
N | ShockmachineReminder | SmReminder.exe | Shockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version |
X | Shockwave | csrss.exe | Added by the SNDOG WORM! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
N | Shockwave Init | SWINIT.EXE | Part of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs |
N | ShortKeys 99 | SHORTKEY.EXE | ShortKeys from Insight Software Solutions - allows you to program keys with text strings |
X | Showbehind | SHOWBEHIND.EXE | Advertisement display which can be stopped here |
? | ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051 | shwicon.exe | Card reader for memory cards from digital cameras. Is it required? |
U | SHPC32 | SHPC32.exe | Port monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled |
Y | ShStatEXE | SHSTAT.EXE | From McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs |
U | Shutdownaware | shutdownaware.exe | Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system |
U | ShutDownPro | ShutDownPro.exe | ShutDownPro - shutdown, reboot, logoff your System with one mouse click |
? | Si Meter | SIMETER.EXE | ?? |
X | si91e44b | rundll32.exe [path] si91e44b.dll, EnableRunDLL32 | LZIO.com adware downloader |
X | Sicom | Sicom.exe | Added by the NETLIP WORM! |
U | SideACT | SideACT.exe | SideACT organizer software |
X | Sidebar | Sidebar.exe | Searchcentrix hijacker |
N | SideWinderTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
? | SigX | sigx.exe | ?? |
X | SigXC | SigX.exe | SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more" |
N | Simcast | SimcastAlerts.exe | Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say |
U | SimpLite-MSN | SimpLite-MSN.exe | Required if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service) |
X | Singapore | singapore.exe | Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself |
U | SIPPS | SIPPSSIPPS.exe | Web.de Internet phone utility |
N | SiS KHooker | khooker.exe | SiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required |
U | SiS Tray | sistray.exe | System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
U | SiS Windows KeyHook | keyhook.exe | SIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings |
? | SISAM10M | SISAM10M.exe | ?? |
N | SiSAudio | MP_S3.exe | WinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems |
U | siscolor | color.exe | Probably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board |
U | siService.exe | siService.exe | Spam Inspector - anti email spam software |
? | SiSSetCDfmt | SiSSetCDfmt.exe | Related to a Silicon Integrated Systems Corp (SiS) product? |
? | SISSoundman | Soundman.exe | Related to a Silicon Integrated Systems Corp (SiS) product? |
U | SiSSWLED | sisswled.exe | System Tray utility for SiS 900 network cards |
X | sistrai.exe | sistrai.exe | Added by the PROVA TROJAN! |
X | sistray | sistray.exe | Added by the PROVA TROJAN! |
U | sistray | sistray.exe | System Tray icon for SiS based graphics. Note - this resides in C:WindowsSystem |
X | Sistray32 | remotehost.pif | Added by the HOLCAS.A WORM! |
X | Sistray32 | win.bat | Added by the JUMPRED.A WORM! |
X | sistry | sistry.exe | Added by the CEBE WORM! |
N | SiSUSBRG | SiSUSBrg.exe | SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP |
X | sixtysix | sixtypopsix.exe | Unidentified adware |
U | SK9910DM | SK9910DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
U | SKDAEMON | SKDAEMON.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys |
U | skinkers | skinkers.exe | Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here. Leave enabled if you want to receive messages |
Y | SkyBlaster Scheduler | SSFSch.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
X | skynetave.exe | skynetave.exe | Added by the SASSER.D WORM! |
X | SkynetRevenge | winlogon.scr | Added by the NETSKY.AA WORM! |
N | Skype | Skype.exe | "Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes" |
Y | SkySurfer Management Service | SmaServ.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system |
N | SleepManager | SleepMgr.exe | This program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode |
U | SlickRun | sr.exe | "SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:Program FilesOutlook Expressmsimn.exe becomes MAIL" |
X | slide | Iexplore.exe | Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
N | slimp3 | SliMP3 Server.exe | Slimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC" |
N | Slingshot | SLINGS~1.EXE | Atomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more" |
X | slmss | slmss.exe | SeekSeek search hijacker related - as seen here |
X | slvchost32 | slvchost32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
? | SM1BG | SM1BG.EXE | USB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually? |
N | Sm56acl | sm56hlpr.exe | Helper utility for Motorola based SM56 software modems - resides in the System Tray |
N | Smapp | smtray.exe | System Tray access for the Compaq/ADI SoundMAX integrated digital audio controller |
N | Smart Card Service | ScardSvr.exe | For Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly |
U | Smart Connect Monitor | SCMon.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
U | Smart Connect Setup | SCSetup.exe | Appears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio |
N | Smart Label O Server | ssloserv.exe | Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
N | Smart Label RFViewer | SSLFVIEW.EXE | Part of the printer software for the smart-label printer made by Seiko. Can be disabled safely |
N | Smart Type Assistant | sta.exe | Smart Type Assistant - a complex typing automation tool, intended to make your work faster and safer |
U | Smartalec | pcaccel.exe | Smartalec PC Accelerator - system optimization utility |
N | SmartBarXP | SmartBarXP.exe | SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few |
N | sMaRTcaPs | SMARTC~1.EXE | sMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys |
? | Smarthruengine | QS.exe | Unknown but disabled without problems |
U | SmartPCXL | pcaccel.exe | Smartalec PC Accelerator - system optimization utility |
N | SMax4 | SMax4.exe | System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
U | SMax4PNP | SMax4PNP.exe | SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
? | smbdpmi | smbdpmi.exe | IBM Netfinity Director and Universal Management Services related. What does it do and is it required? |
Y | smc | smc.exe | Sygate Firewall |
Y | smc | spfsmc.exe | Sygate Firewall |
Y | SMC Service | smc.exe | Sygate Firewall |
Y | SMC Service | spfsmc.exe | Sygate Firewall |
X | smcserv | winsrv.exe | Added by the AGOBOT-OU WORM! |
Y | SmcService | smc.exe | Sygate Firewall |
Y | SmcServices | smc.exe | Sygate Firewall |
Y | SmcServices | spfsmc.exe | Sygate Firewall |
? | Smcsta.exe | Smcsta.exe | SMC Networks wireless PCI card driver. Is it required? |
N | Smith Micro try | smiptray.exe | Smith Micro shared files. Comes with D-Link web cam |
U | SMS Application Launcher | LAUNCH32.EXE | Microsoft Systems Management Server - used to manage computers on a network remotely |
U | SMS Client Service | clisvc95.exe | When the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server) |
U | SMS Win9x Message Agent | ?? | This program assigns a user to a Systems Management Server site |
U | SMS Win9x Message Agent | SMSMsg.exe | This program assigns a user to a Systems Management Server site |
Y | Smserial | sm56hlpr.exe | Motorola based modem driver |
N | SMSI Loader | SMLoader.exe | Smith Micro HotFax - fax software |
X | SMSS | smss.exe | Added by the FLOOD.F TROJAN! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
X | smss | [path to smss.exe] | Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
X | SMSSS | smsss.exe | Added by the SDBOT.ZD WORM! |
X | SMSSS Loader | smsss.exe | Added by the AGOBOT.MQ WORM! |
X | smsys | Explorer.exe | Added by the CLICKER-C TROJAN! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in a C:WindowsTemplate or C:WinntTemplate subdirectory |
X | smsys | vi.exe | Adult content dialler |
N | SMToolbar | SMToolbar.exe | StartMake.com toolbar |
? | SmWizard | SmWizard.exe | SmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required? |
X | snapple | snapple.exe | Added by the FORBOT-EG WORM! |
? | snbr | snbr.exe | ?? |
X | sncntr | sncntr.exe | Added by the DLUCA-I TROJAN! |
X | Sndcompat | Sndcompat.exe | Added by the GEMA TROJAN! |
U | SNDMon | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
X | Sndsaver | Sndsaver.exe | Added by the GEMA TROJAN! |
? | sndsrvc | SNDSRVC.EXE | Part of Norton Personal Firewall and Norton Internet Security - what does it do and is it required? |
N | Snsicon | Snsicon.exe | Launches a screensaver program from Second Nature |
? | SO5 Integrator Pass One | sointgr.exe | StarOffice 5. See here for more details |
? | SO5 Integrator Pass Two | sointgr.exe | StarOffice 5. See here for more details |
X | Soar | Rwon.exe | PurityScan/Clickspring adware |
X | Social Security Agency | rpcxsocsa.exe | Added by a variant of the RBOT WORM! |
X | Sock32 | sock32.exe | Added by the SDBOT TROJAN! |
Y | SoDA Startup | SodaStartup.exe | Used by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software |
N | soffice | SOFFICE.EXE | Displays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory). |
X | Soft Profile Inc | hxdef.exe... | Added by a variant of the LOVGATE WORM! |
Y | SOFTinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
X | Software | software.exe | Added by the CRABTON-B TROJAN! |
Y | Solo Sentry | Solosent.exe | Solo Antivirus |
U | SoloSchedule | Solocfg.exe | Scheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis |
U | SoloSysCheck | Syscheck.exe | Solo antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors |
X | somatic | somatic.exe | Searchcentrix hijacker |
N | Sonic A3D Control | vrtxctrl.exe | Sound related options |
N | SoniqueQuickStart | sqstart.exe | Quickstart for Sonique audio player. Available via Start -> Programs |
? | SonnReg | SonnReg.exe | Part of E-Color 3Deep for color calibration. Possibly a registration reminder? |
? | Soot | rcea.exe | ?? |
? | sophagnt | sophagnt.exe | Possibly related to Sophocles Screenwriting Software? |
X | SOS | SOS.exe | Added by the PHILIS VIRUS! |
? | SoSyncMonitor | SoSyncMonitor.exe | SuperOffice related. What does it do and is it required? |
X | Sound Loader | sndloader.exe | Added by the AGOBOT-BV WORM! |
X | Sound services | SOUND32.EXE | Added by the AGOBOT.GG WORM! |
X | Sound System | WinSound1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | soundcontrl | soundcontrl.exe | Added by the GAOBOT.AFJ WORM! |
X | sounddrv | sndbdrv3104.exe | CoolWebSearch parasite variant |
? | SoundFusion | rundll32 cwcprops.cpl | Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
? | SoundFusion | rundll32 hercplgs.cpl, BootEntryPoint | Control panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? |
N | soundman | soundman.exe | System Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel |
N | SoundMAX | SMax4.exe | System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel |
U | SoundMAXPnP | SMax4PNP.exe | SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments |
X | SoundMixer | smvss.exe | Added by the DEDLER-G TROJAN! |
X | Soundmx | Soundmx.exe | CoolWebSearch parasite variant |
X | soundtask | soundtask.exe | Added by the AGOBOT-MD WORM! |
X | soundtasks | soundtasks.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | soundtctrls | soundtctrls.exe | Added by the AGOBOT-ZV WORM! |
X | SoundView | msdview32.exe | Trojan downloader |
X | sounofts | sounofts.exe | Added by the AGOBOT-ND WORM! |
N | SourcePath | gwreg.exe | Used to update Gateway registry settings for System Restoration Kit and Web update programs |
X | sp | sp.reg | IE search hijacker - changes the default search to http://www.gocybersearch.com/ |
X | sp | regedit-s .... sp.dll | Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix |
X | sp | se.dll, DllInstall | Added by the Startpage.M hijacker |
U | SP TimeSync | SP TimeSync.exe | SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server) |
X | SP00LSV | Sp00lsv.exe | Added by the GRAYBIRD.E TROJAN! |
X | sp2chk.exe | sp2chk.exe | Added by the ALUROOT.A TROJAN! |
X | sp2ctr | sp2ctr.exe | Added by the DLUCA-M TROJAN! |
U | Spam Sleuth | SpamSleuth.exe | Spam Sleuth E-mail spam detection program |
U | spamihilator | spamihilator.exe | Spamihilator - spam filter |
U | SpamPal | spampal.exe | SpamPal - anti-spam tool |
U | SpamSubtract | SpamSubtract.exe | Intermute SpamSubtract - junk email detection and removal program |
N | spc_w | hcm.exe | NetZero Search related |
N | Spdstart | Spdstart.exe | Norton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel." |
U | Speaking Clock Deluxe | SpClDlx.exe | Speaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly |
X | Special Firewall Service | avguard.exe | Added by the NETSKY.G WORM! |
X | SpecialOffers | SpecialOffers*.exe [* = digit] | SpecialOffers adware |
X | SpecialOffers | SpecialOffers.exe | SpecialOffers adware |
N | Speed racer | CTSRReg.exe | Software for a Creative sound card |
U | Speed Tec | speedtec.exe | Accel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled |
X | SpeedBoss | [worm filename] | Added by the OPASERV.AD WORM! |
U | Speedkey | SPEEDKEY.EXE | Additional keyboard shortcuts on MS programmable keyboard |
U | SpeedMeter | SpeedMeter.exe | Application measuring upload and download speed |
U | SpeedOptimizer | spo.exe | SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication |
U | Speedtouch USB Diagnostics | Dragdiag.exe | For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line) |
X | Spees1 | speedy.scr | Added by the OPASERV.Y WORM! |
X | Spees2 | Speedy.bat | Added by the OPASERV.AD WORM! |
X | Spees3 | SPEEDY.PIF | Added by the OPASERV.AD WORM! |
N | Spellex Anywhere | sa.exe | Spellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used |
Y | SpIDerMail | spiderml.exe | DrWeb antivirus Spider Mail e-mail scanner |
N | Spinner Plus | spinner.exe | "Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs |
X | SPINX | Wscript.exe OXNEY.B.VBS | Added by the YENO.B and YENO.C WORMS! |
X | SPnt | SPnt.exe | Premium rate adult content dialler |
U | SpokeSysTray | SpokeSysTray.exe | Spoke Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry" |
X | spoo1sv | spoo1sv.exe | Added by the SOULJET TROJAN! |
X | Spool | [path to trojan] | Added by the RANKY.R TROJAN! |
X | SPOOL Configuration | spoolsvc.exe | Added by the SDBOT-KD WORM! |
X | Spool lptt01 | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Spool ml097e | spool.exe | Variant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Spooler Service | Spoolsrv.exe | Added by the JOINER.C1 TROJAN! |
X | Spooler Sub System Process | SPOOL32.EXE | Added by the YAB.A TROJAN! |
X | Spooler Subsytem App | spoolsvc.exe | Added by the SDBOT-MM WORM! |
X | SpoolerSubSystemProcess | SpooI32.exe | Added by the EHKS.21 keylogger! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L" |
X | spoolserv | spoolserv.exe | Added by the SDBOT-PN WORM! |
X | SpoolService | spolsv.exe | Added by the AGOBOT-CS WORM! |
X | Spoolsv | Spoolsv.exe | Added by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file |
X | spoolsv | scvhosts.exe | Added by the SMALL-AW TROJAN! |
X | spoolsv manager | SpoolMgr.exe | Added by the ASSIRAL WORM! |
X | spoolsvr32 | csmss.exe | Added by the AGENT-AU TROJAN! |
X | spoolsvr32 | csmss32.exe | Added by a variant of the AGENT-AU TROJAN! |
X | SPOOLSVU | SPOOLSVU.EXE | Added by the Startpage.K hijacker |
X | spoolsvv | spoolsvv.exe | Searchcentrix hijacker |
X | Spore | MsNews.vbs | Added by the SPORE.A WORM! |
X | Spore.b | Scmhlpr.vbs | Added by the SPORE.B WORM! |
? | SPP | run.exe | ?? |
X | spp | regedit -s spp.reg | IE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/ |
? | sppbridge | sppbridge.exe | Associated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? |
? | SprintPort | SprintPortA.exe | Novatel wireless modem related. What does it do and is it required? |
U | SPSTEALT | SmartProtectorPro.exe | Smart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc |
? | spstore | storesp.exe | Softprobe - program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup |
U | Spy Blocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
X | SpyBlast | SpyBlast.exe | Spyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others |
U | SpyBlocker | spyblocker.exe | SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all |
X | SpyBlocs | SpyBlocs.exe | Rogue anti-spyware program |
U | SpybotSD TeaTimer | TeaTimer.exe | TeaTimer is a new tool of Spybot S&D - spam filter which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future |
U | SpyBotSnD | Spybotsd.exe | Spybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla |
X | Spybott lptt01 | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Spybott ml097e | spybott.exe | Variant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
U | SpyCop ScanCheck | MAIN.EXE | SpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan |
N | SpyHunter | SpyHunter.exe | SpyHunter - spyware remover of somewhat dubious repute, see note |
U | Spykiller | Spykiller.exe | Shareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot |
X | SpyNuker | Spynuker.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
N | SpySpotter | SpySpotter.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
U | SpyStopper | spystopper.exe | SpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked |
U | SpySubtract | SpySub.exe | SpySubtract - multi spyware removal tool |
U | SpySweeper | SpySweeper.exe | Spy Sweeper - detects and removes spyware |
X | Spyware | Spyware.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
N | Spyware Begone | SpywareBeGone.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
N | Spyware Begone | freescan.exe | Spyware BeGone - free spyware removal utility. Not recommended - see note |
U | Spyware Doctor | spydoctor.exe | Spyware Doctor spyware remover |
U | Spyware Doctor | swdoctor.exe | Spyware Doctor spyware remover |
U | Spyware Guard Control Panel | spywar~1.exe | "SpywareGuard provides a real-time protection solution against spyware" |
X | Spyware Nuker Installer | SpywareNukerInstaller.exe | A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
X | Spyware remover | Remove_spyware.exe | Unidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related! |
U | Spyware Scanner | AseScanner.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here |
X | Spyware Slayer | SpywareSlayer.Exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
N | Spyware Stormer | SpywareStormer.Exe | SpywareStormer spyware remover. Not recommended - see here |
X | Spyware Vanisher | FreeScanner.exe | Spyware remover of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites |
U | SpywareGuard | sgmain.exe | "SpywareGuard provides a real-time protection solution against spyware" |
X | SpywareGuard | winproc32.exe | Startpage adware Trojan |
X | Spywareguard lptt01 | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Spywareguard ml097e | Spywareguard.exe | Variant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | SpywareGuardPlus | winmm64.exe | StartPage.ht homepage hijacker |
N | SpywareKilla | SpywareKilla.exe | Spyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites" |
U | SPYWATCH | SpyWatch.exe | BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys! |
X | SQConfigChecker | cc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
X | SQInstaller | SQInstaller.exe | Xupiter hijacker |
N | SQL Server | scm.exe | SQL Server Service Control Manager. Available via Start -> Programs |
X | SQUpdatesChecker | uc.exe | Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants |
X | sqvynikp | sqvynikp.exe | Free_Scratch_Cards foistware |
? | sr1exe | updtSup3.exe | Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder |
X | sr64 | ********. exe | Adware, as yet unidentified |
X | SrchfstUpdate | srchupdt.exe | SearchFast adware downloader |
? | SRFirstRun | rundll32 srclient.dll, CreateFirstRunRp | Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? |
U | Srmclean | srmclean.exe | Srmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card" |
X | SRNG | srng.exe | Search hijacker - see here |
U | SRP Startup | srrpro.exe | System Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel |
Y | SRS Applet | SrsTray.Exe | S3 Sonic Vibes sound card drivers - if disabled you loose sound |
X | Srv RPCrom | NClienti386.exe | Added by the WATSOON.A TROJAN! |
X | Srv32 | Srv32.exe | Added by the OPASERV.J WORM! |
X | Srv32 | Srv32.exe | Added by the OPASERV.S WORM! |
X | Srv32 spool service | runsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
X | Srv32 spool service | spoolsrv32.exe | Topantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b |
X | Srv32Old | [worm filename].PIF | Added by the OPASERV.J WORM! |
U | Srv32Win | SpyAgent4.exe | SpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
U | Srv32Win | Svchost.exe | Realtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
X | Srv32Win | sysdiag.exe | NetVizor keystroke logger |
X | srvexc.exe | srvexc.exe | Added by the SERVSAX TROJAN! |
X | ssate.exe | irun4.exe | Added by the BEAGLE.J WORM! |
X | ssate.exe | winsys.exe | Added by the BEAGLE.K WORM! |
N | SSBkgdUpdate | SSBkgdupdate.exe | ScanSoft OmniPage auto updater. Can be disabled using the main program's options |
? | SSC_UserPrompt | UsrPrmpt.exe | Part of Symantec (Norton) Security Centre. What does it do, and is it required? |
Y | Ssd | Std.exe | Stealthdisk - file and folder hiding/locking utility |
? | ssdiag | ssdiag.exe | Equinox "Configuration and DOS Diagnostic for DOS and Windows platforms" |
N | SSDPSRV | ssdpsrv.exe | Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play |
X | ssgrate.exe | system.exe | Added by the MITGLIEDER.C TROJAN! |
X | ssgrate.exe | irun.exe | Added by the MITGLIEDER.D TROJAN! |
X | ssgrate.exe | irun4.exe | Added by the MITGLIEDER.F TROJAN! |
X | ssgrate.exe | sysdoor.exe | Added by the MITGLIEDER.N TROJAN! |
X | ssgrate.exe | winerdir.exe | Added by the MITGLIEDER.O TROJAN! |
X | SSK Service | winssk32.exe | Added by the SOBIG.E WORM! |
X | SSL | svchost.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
U | ssmmgr | ssmmgr.exe | Samsung printer monitor - for checking ink levels, etc. |
X | sstata | dwdas.exe | Added by the DASDA TROJAN! |
X | SStb.exe | SStb.exe | Adpowerzone.com "ServerSide" keyword hijacker |
N | sstray | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys |
X | SSUpdate | SSUpdate.exe | DyFuCa/MoneyTree parasite variant |
X | ssvchost | ssvchost.exe | Added by the HELIOS.B TROJAN! |
X | SSWPlauncher | comet.exe /app:SSWPlauncher | CometCursor by Comet Systems |
N | Stacmon | Stacmon.exe | Installed with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects |
Y | Start | Quick95.exe | For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone |
X | Start | windows.vbs | Homepage hijacker |
? | start | start.exe | ?? |
X | start extracting | spoolvse.exe | Added by a variant of the RBOT WORM! |
N | Start Getright | getright.exe | See Getright Tray Icon |
X | Start Page | http://find.naupoint.com | Naupoint browser hijacker |
Y | Start RF Wireless Keyboard | ktrexe.exe | Yuanxun Electronics RF wireless keyboard driver |
Y | Start RF Wireless Mouse | cm20.exe | Yuanxun Electronics RF wireless mouse driver |
U | Start Service | upssrv.exe | Cyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner" |
U | Start Up Cop | startcop.exe | StartUp Cop - startup manager |
X | start uploading | smsss.exe | Added by a variant of the SDBOT WORM! |
X | Start Upping | taskmrg.exe | Added by the RBOT-MA WORM! |
X | Start Upping | SVCHOSTES.EXE | Added by the RBOT-NB WORM! |
X | Start Upping | taksmgr.exe | Added by the RBOT-QK WORM! |
X | Start Uppings | svcchosts.exe | Added by the SDBOT.VY WORM! |
X | Start Uppings | mssupdate.exe | Added by a variant of the RBOT WORM! |
N | Start Wingman Profiler | lwtest.exe | Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked |
N | Start Wingman Profiler | lwemon.exe | Logitech Wingman software required to operate Logitech joysticks and gamepads. Unless you're a hard-core gamer, it's best to leave it unchecked |
U | Startacc | startacc.exe | Launches Webroot's Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection |
Y | StartEAK | StartEAK.exe | Easy Access Button Support for Compaq PCs. Required if you use these |
X | starter | scvhosting.exe | Added by the IRCBOT.E TROJAN! |
X | Starter | scvhosting.exe | Added by the SDBOT.RU WORM! |
N | startl.exe | startl.exe | Lingocom LingoWare - translates any application into your language |
X | StartMenu | s_menu.exe | Added by a variant of the DELF-A TROJAN! |
X | startpage | startpage.exe | Browser hijacker - redirecting to pages2start.com |
U | STARTPAGE | start1.exe | NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder |
U | StartStop | STARTSTOP.EXE | StartStop from TFI Technology - startup manager |
U | StartSurfing | STARTS.exe | Start Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs |
N | Startup | ?? | Related to an Iomega drive |
? | Startup Launcher GUI | GUI.exe | Startup manager? |
X | Startup Update | Cvshost.exe | Added by the GAOBOT.AO WORM! |
U | StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
X | startwindowskeyuser | rundle2.exe | Added by the JAVAKILLER TROJAN! |
N | Stat 'n' Perf | StatnPerf.exe | Stat 'n' Perf monitors your internet connection and displays information about sent and received bytes |
X | StatBar | STATBAR.exe | StatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me |
N | Status Monitor | BrMfcWnd.exe | Brother scanner status monitor - can be started manually |
N | Status Monitor XE | ENGSS.EXE | The Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs |
? | StatusClient | StatusClient.exe | Part of Hewlett Packard network printer drivers |
? | StatusClient 2.6 | StatusClient.exe | Part of Hewlett Packard network printer drivers |
N | Stay Connected! | StayCon.exe | More than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs |
U | StayAlive | sa.exe | StayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work." |
? | STBVision | STBVisn.exe | Related to the STB Velocity graphics card. What does it do and is it required? |
N | STBWEBTV | STBWEBTV.EXE | Used to display TV on your PC |
X | stcinstaller | id53.exe | Added by the SCTHOUGHT.L TROJAN! |
X | stcloader | stcloader.exe | Popup adware by 2ndThought software |
X | stcloader | STCLOA~1.exe | Popup adware by 2ndThought software |
X | STCLOA~1 | stcloader.exe | Popup adware by 2ndThought software |
X | STCLOA~1 | STCLOA~1.exe | Popup adware by 2ndThought software |
Y | STCPO | STCPO.exe | Sophos Sweep antivirus software |
U | Stealth Anonymizer 2.5 | stealth25.exe | Now named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy |
N | Steam | steam.exe | Valve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game |
N | Stickies | STICKIES.EXE | Stickies - utility that allows you to put yellow "Post-It" type messages on your desktop and can be used to set reminders. Available via Start -> Programs |
N | Sticky Notes | stikynot.exe | Microsoft Sticky Notes - virtual sticky notes tool |
N | StickyNote | StickyNote.exe | Utility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs |
U | StillImageMonitor | Stimon.exe | Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners |
X | stlbdist | rundll32exe stlbdist.DLL, DllRunMain | Hijacker pointing to www.searchandclick.com |
X | stlbupdt | rundll32.exe stlbupdt.DLL, DllRunMain | BrowserAid/Startium parasite |
N | STManager | drst.exe | Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here |
X | stmha | wkfxi.js | Added by the SPETH WORM! |
N | StopSignStatus | stopsinfo.dll", VerifyStatus | eAcceleration Stop-Sign related - not recommended, see note |
U | STOPzilla | Stopzilla.exe | StopZilla! - pop-up killer |
U | STOPzilla Service | SZNTSVC.EXE | StopZilla! - pop-up killer |
U | StorageGuard | sgtray.exe | StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
? | STPMGR | STPMGR.EXE | Part of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs |
X | Strng32 | strngbox.exe | Added by the STRANO WORM! |
X | StubPath | Sservice.exe | Added by the PRORAT TROJAN! |
U | StyleXP | StyleXP.exe | StyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it |
N | Subtract the Ads | AdSub.exe | Removes adverts from web pages. Although useful - not required |
U | Suitcase Startup | Suitcase.exe | Suitcase. System font manager start up utility. Used for dynamic managment of fonts on your system |
X | Suite | SuiteOffices.exe | Added by the LAZAR TROJAN! |
X | SULFNBJ.EXE | SULFNBJ.EXE | Added by the PE_MAGISTR.DAM VIRUS! |
X | SunJavaUpdate | smvss.exe | Added by the DEDLER-G TROJAN! |
N | SunJavaUpdateSched | jusched.exe | Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel |
U | Sunkist | shwicon98.exe | Card reader for memory cards from digital cameras, etc |
U | Sunkist2k | shwicon2k.exe | Card reader for memory cards from digital cameras, etc |
? | SupaDial | SupaDial.exe | SupaNet.com modem driver related - is it required? |
N | Supastatus | status.exe | Supanet ISP software |
U | Super Popup Blocker | popkill.exe | Saga Super Popup Blocker - pop-up stopper |
U | SuperAdBlocker | SAdBlock.exe | SuperAdBlocker |
X | SuperBar.Component | [path to services.exe] | Added by the SMALL-AQ TROJAN! |
U | Supercleaner | Supercleaner.exe | Supercleaner - all in one disk cleaner for your computer |
U | SuperCool Compress Backup | Main.exe | "SuperCool Zip Backup software is a data backup,restore and file synchronization program" |
X | supernews12 | newsd32.exe | Unidentified adware |
X | Supernova | [worm filename] | Added by the SURNOVA (or SUPOVA) WORM! |
X | superslut | msslut32.exe | Added by the SLUTER-A WORM! |
U | SuperSpamKiller Pro | Ssk.exe | SuperSpamKiller Pro email spam blocker |
X | Supervisor.exe | Supervisor.exe | Has been reported to be associated with various antitrojan software like ATS and PC Doorguard. If so it's required in Startup - any further information is welcome |
X | supporter5 | supporter5.exe | Part of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead |
U | SureCleanProfessional | SRClean.exe | SureClean PC and Internet tracks cleaner |
U | Sureshotpopupkiller | Stopthepop.exe | Stop-the-Pop-Up popup blocker |
X | SurfBuddy | rundll32 [path] sbuddy.dll | SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps! |
U | SurfChoice | SCMan.exe | SCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa |
X | Surfer lptt01 | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Surfer ml097e | surfer.exe | Variant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
U | SurfinGuard Pro | winsfcm.exe | SurfinGuard Pro - internet protection software |
U | SurfSecret | ss2-full.exe | "House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache" |
X | SurfSideKick 2 | Ssk.exe | SurfSideKick adware |
U | SurfStream | SurfStream.exe | Conceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings" |
X | Surs | awab.exe | PurityScan/Clickspring adware |
? | Surveysa | surveysa.exe | Found in the SonyVaiosurvey directory on a Sony Vaio PC. What does it do and is it required? |
X | Susp | Susp.exe | Transponder parasite updater/installer |
X | Sustem | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | SustemUpdate | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | SVA Player | SVAplayer.exe | QuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it |
X | Svc | svc.exe | Hijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND TROJAN! |
X | SVC Service | svcinit.exe | Added by the SINIT TROJAN! |
X | SVC Service | svcinit.exe | CoolWebSearch parasite variant |
X | SVC Service | svcpack.exe | CoolWebSearch parasite variant |
X | SVC Socks | mstaskm.exe | CoolWebSearch parasite variant |
X | Svced | Svced.exe | Added by the DELF.F TROJAN! |
X | SvcH0st | msexploren.exe | Added by the BACKDOOR-CGZ TROJAN! |
X | svchost | Svch0st.exe | Added by the GRAYBIRD.B TROJAN! |
X | SVCHOST | svchost.exe | System1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | svchost | svchost.exe | Added by the MORB WORM or TARNO TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | SVCHOST | mrowyekdc.exe | Added by the GOTORM WORM! |
X | svchost | Svch0st.exe | Added by the GRAYBIRD TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | svchost | [path to trojan] | Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | svchost | ADMAGIC.EXE | Added by the SMIBAG WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Svchost | winhost.exe | Added by the LOLAWEB.A TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Svchost | svchost.exe | Added by the MOXE-A WORM! This is not the valid svchost.exe as described here |
X | SVCHOST | var.txt.exe | Added by the LDPINCH.C TROJAN! |
X | Svchost | svchosl.pif | Added by the INZAE.A or INZAE.B WORMS! |
X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
X | svchost | [path] SETUP.EXE | Added by the SETCLO WORM! |
X | SVCHOST | scvhost.exe | Added by the MYTOB.E and MYTOB.G WORMS! |
X | SVCHOST | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! |
X | svchost.exe | svchost32.exe | CoolWebSearch parasite related. Note - this is not the valid svchost.exe as described here |
X | svchost1 | svchost1.exe | Added by the AGOBOT.ZZ WORM! |
X | SvcHost32 | svchost32.exe | Added by the MIMAIL.I or MIMAIL.J WORMS! |
X | svchost64 | svchost64.exe | Added by the SDBOTER.G VIRUS! |
X | svchostr | svchostr.exe | Added by an unidentified WORM or TROJAN! |
X | svcinfo | svcinfo.exe | Added by the CRYPTER.A TROJAN! |
X | svcroot | svcroot.exe | Added by the KEYLOG-AC TROJAN! |
X | svcsys32 | svcsys32.exe | Added by the AGOBOT-LL WORM! |
X | svcwinprocess32 | [path to worm] | Added by the UPERING WORM! |
X | SVHOST | svhost.exe | Added by the MYDOOM.I WORM! |
X | SVHOST | SVHOST.EXE | Added by the ZORI.A VIRUS! |
X | Svhost Loader | svshost.exe | Added by the AGOBOT.G WORM! |
? | SVIDC32M | SVIDC32M.exe | ?? |
X | sVideo2 | vxdrun6.exe | Switch premium rate adult content dialer |
? | SVM Pop | svmpop.exe | ?? |
X | svphost.exe | svphost.exe | Added by the AGENT.CS TROJAN! |
X | svrrun | svrrun.exe | Adware hailing from Deskwizz.com |
X | svshost | svshost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | svshost32 | msgrsv32.exe | Added by the RANKY.AJ TROJAN! |
X | svshostdriver | svshost.exe | Added by the SDBOT-HN TROJAN! |
X | svwin32 | unninst32.exe | Added by the AGOBOT-NF WORM! |
X | SVX Control Service | svxhost.exe | Added by the FORBOT-K WORM! |
N | Swap Nut | javaw.exe | SwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network |
X | SWCaller | SWcaller.exe | Homepage hijacker - see here |
X | SWCaller | Swcaller2.exe | Homepage hijacker - see here |
N | SWd | winwd.exe | PC Security from Tropical Software - lock files, password protect, etc |
Y | Sweep95 | ICLOAD95.EXE | Part of Sophos ant-virus sofware |
X | Swf32 | AVupdate.exe | Added by the MERKUR WORM! |
X | Swf32 | _backup.exe | Added by the SYMTEN WORM! |
X | SwimSuitNetwork | SwimSuitNetwork.exe | Advertising spyware |
U | Switch Off | swoff.exe | Switch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc |
N | Switchboard.com Toolbar | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com |
X | sws.exe | [random filename] | Haldex type adult content dialler |
N | SwTray | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it |
N | SWTrayV4 | SWTrayV4.exe | MS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs |
? | SXGDSENU | sxgdsenu.exe | Yamaha SXG soundcard driver |
? | SxgTkBar | sxgtkbar.exe | Yamaha SXG soundcard driver |
? | Sxplog | sxpstub.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? |
X | SYDNEY | [file path] | Added by the SYNEY WORM! |
X | Sygate Personal Firewall | Win32x.exe | Added by the RBOT-KZ WORM! |
X | Sygate Personal Firewall | system32.exe | Added by the RBOT.VI WORM! |
X | Sygate Personal Firewall | sysgut.exe | Added by the SDBOT.WM WORM! |
X | Sygate Personal Firewall | Sygate.exe | Added by the RBOT-PN WORM! |
X | Sygate Personal Firewall | Mcafeeupdate.exe | Added by the RBOT.YN WORM! |
X | Sygate Personal Firewall | Sygate32.exe | Added by the SDBOT.WW WORM! |
X | Sygate Personal Firewall Start | services32.exe | Added by the RBOT-MB WORM! |
X | Sygate Personal Firewall Start | servic.exe | Added by the RBOT-RY WORM! |
X | Sygate Personals Firewalls | ccsrn.exe | Added by a variant of the RBOT WORM! |
U | SyGateService | sgserv95.exe | SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs |
X | Symantec Anti Virus | symantec32.exe | Added by a variant of the WOOTBOT WORM! |
X | Symantec Configuration Loader | ccApp32.exe | Added by a variant of the GAOBOT WORM! |
Y | Symantec Core LC | symlcsvc.exe | Part of Norton AntiVirus 2004. What does it do? |
N | Symantec Fax Starter Edition Port | OLFSNT40.EXE | Offers a virtual printer as a fax machine. Can be run via a desktop shortcut |
U | Symantec NetDriver Monitor | SNDMon.exe | Part of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadtes but probably require if you leave them to run automatically. Also, if one runs a small office network and SNDMon is disabled on one of the computers – then other computers disappear from the network for this computer, including shared devices like printers and scanners. Hence the "U" recommendation |
X | Symantec Security | symantec32.exe | Added by the RANDEX.PR or RANDEX.YR WORMS! |
X | Symantec Security Addon | nvsvc.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Symantec Security Routine Addon for Microsoft Windows | navpxaw32.exe | Added by the AGOBOT-GJ TROJAN! |
X | Symantec Service | ccApp.exe | Added by the AKHER.D WORM! Note - this is also not the valid Norton AV file with the same filename |
X | SymAV | SymAV.exe | Added by the NETSKY.U WORM! |
U | SymKeepAlive | CKA.exe | Part of Norton SystemWorks 2003 - keeps a dial-up modem connection alive |
N | SymTray - Norton SystemWorks | SYMTRAY.EXE | Keeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray |
U | Sync Data | Hndsync.exe | Pocket Real Estate - mobile synchronization manager |
X | Sync Server | drwatsoon.exe | Added by the WATSOON.A TROJAN! |
U | Sync-It | Syncit.exe | Sync-It - synchronizes the system clock with time servers on the internet |
U | SyncAgent | syncagent.exe | Ghost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
N | Synchronization Manager | mobsync.exe | Find more information about its use here |
? | SynSetup | SynTP.tmp RunOnce.exe | Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required? |
X | Syntax Script | systacq.exe | Added by the SDBOT.AI WORM! |
U | SynTPEnh | syntpenh.exe | Synaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll |
Y | SynTPLpr | syntplpr.exe | Synaptics touchpad driver helper. Required for touchpad features to work |
X | sys | regedit /s sys.reg | Hijacker |
X | sys | sysdllwm.reg | CoolWebSearch parasite variant |
X | Sys Ren | SysRen.exe | Unidentified malware |
X | Sys29 | win***32.exe [* = random char] | EliteBar adware |
X | sys32 | sys32.exe | Added by the FLUX.E TROJAN! |
U | sys32cmd | sys32win.exe | Active Keylogger monitoring software - also see here. From the Symantec article: "This spyware program must be manually installed. However, there are several known programs that have Spyware.ActiveKeylog within them and that install it as the program itself is installed". Disable/remove if you didn't install it |
X | sys32dll | sys32dll.exe | Added by the AIMDES.B WORM! |
X | SysA | win***32.exe [* = random char] | EliteBar adware |
U | SysAgent | SysAgent.exe | SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of |
X | SysAI | SysAI.exe | AproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located |
U | Sysbot | sysbot.exe | Spector - spying (or monitoring) software to record internet activity |
X | syscfg | syscfg32.exe | Added by the KWBOT.S WORM! |
X | syscfg34.exe | syscfg34.exe | Added by the ELECTRON WORM! |
X | Syscheck | win.hta | Browser hijacker |
X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! |
X | syscm | Syscm.exe | Vanish adware |
? | SysComp | mssdnl.com | Unknown but suspect as *.com are not usually run at start up and the name isn't recognized |
X | syscon lptt01 | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | syscon ml097e | syscon.exe | Variant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | sysconfig | iexplorer.exe | Added by the CULT.C WORM! |
X | SysConfig | syscfg35.exe | Added by the KAZMOR.C WORM! |
X | sysconfig | iexplorer.exe | Added by the CULT.H WORM! |
X | SysConfig | wincfg32.exe | Added by the SDBOT.ZD WORM! |
U | Sysconfig | Stealth KeySpy.exe | Added by StealthKeySpy commercial keylogger |
X | Syscpy | Syscpy.exe | Firewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE TROJAN! |
X | SysCtl | sysctl.exe | Added by the AOK TROJAN! |
X | Sysctrls | procdll.exe | Added by the WEEDBOTZ.14 TROJAN! |
X | sysdir | winrun.exe | Added by the WINBUR.B WORM! |
X | Sysdpt | sysdpt.exe | Win32.Crypt trojan downloader |
X | sysfiler | sysfiler.exe | Added by the RETSAM TROJAN! |
X | SYSfit | SYSfit.exe | AdShooter adware variant |
X | sysflg32 | sysflg32.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | syshelp | syshelp.exe | Added by a variant of the LOVGATE WORM! |
X | sysinfo | sysinfo.exe | Added by the BEDRILL TROJAN! |
X | sysinfo.exe | sysinfo.exe | Added by the BEAGLE.V WORM! |
X | SysInit | wininit32.exe | Added by the XABOT WORM! |
X | sysinit | services.exe | Added by the NEWLFRM-A TROJAN! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | Sysino | lsess.exe | Added by the FORBOT-BF WORM! |
X | sysint16 | sysint16.exe | Added by the CRYPTER.A TROJAN! |
X | Syskey | sysinit.exe | Added by the BEAGLE.AX WORM! |
X | Syslib | Syslib.exe | Adult content related downloader trojan |
X | Syslog lptt01 | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Syslog ml097e | Syslog.exe | Variant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | syslogin.exe | syslogin.exe | Added by the BAGZ-B WORM! |
U | SysMetrix | SysMetrix.exe | SysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics |
X | sysmon | sysmon.exe | Added by the BIZEX WORM! |
X | Sysmon | rpcmon.exe | Added by the RANDEX.ATX WORM! |
X | sysmon | sysmon44.exe | Added by a variant of the BACKDOOR-CBA TROJAN! |
X | sysmonnt | sysmonnt.exe | Transponder parasite related |
X | SysMonXP | SysMonXP.exe | Added by the NETSKY.Q WORM! |
X | sysnate | sysnate.exe | Added by the MEDIAS TROJAN! |
X | SysOps | SysOps | Added by the MSNCORRUPT TROJAN! |
X | syspath | drv.exe | Added by the SOBER WORM! |
U | SysPilot | fdxxl.exe | G Data "PC Spion" - monitoring and surveillance software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! |
X | sysPnP | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
X | SysPnP | rundll32 setupapi, InstallHinfSection.... oemsyspnp.inf | Search hijacker - see here |
Y | SysPool | Mssvc.exe | StealthDisk - hides folders, files and applications. Will also encrypt them for better protection |
X | SysProtect | System.exe | Added by the NETSPY TROJAN! |
X | SysR | sysmd.exe | Adult content based "foistware" (adds hidden components to your system) |
X | SysReg | SysReg.exe | Added by the CHEKIN TROJAN! |
X | SysReg | SysReg.exe | SearchSeekFind textual marketing foistware |
X | Sysres | Sysres.exe | Added by the LOGMOD TROJAN! |
X | SysRes | TASKMANAGER.exe | Added by the ELIPTER.A WORM! |
X | SysRes | WWE DIVAS.exe | Added by the ELIPTER.D WORM! |
X | SysScan | bvt.exe | Added by the AUTOUPDER TROJAN! |
X | SysSearch | Regedit.exe -s [path] pcsearch.reg | Added by the StartPage-FN browser hijacker |
X | SysSearch | REGEDIT.EXE -s [path] sysreg.reg | Added by the STARTPA-ME TROJAN! |
X | sysser | [path to file] | Added by the RAHACK WORM! |
X | SysService | SysService.exe | Added by the DELF family of TROJANS! |
X | SysService32 | SysService32.exe | Added by the KINDAL VIRUS! |
X | SysService32 | ln32k.dll | Added by the KINDAL VIRUS! |
X | SysService32l | systask32l.exe | Added by the THEUG WORM! |
X | SYSsfitb | SYSsfitb.exe | Searchforit browser hijacker |
X | SysStrt | systemc.exe | Added by the AGOBOT-QA TROJAN! |
X | System | run322.exe | Added by the LANFILT TROJAN! |
X | System | system.exe | Added by various WORMS and TROJANS! |
X | system | regedit -s system.dll | Homepage hijacker |
X | system | systemsearch.hta | Jetseeker.com hijacker |
X | System | dcomx.exe | Added by the CIREBOT TROJAN! |
X | system | Explorer.exe | Added by the GRAYBIRD TROJAN! Note - this is located in this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) rather than the valid Windows Explorer which is located in C:Windows or C:Winnt |
X | System | YPager.exe | Added by the JUNTADOR.K TROJAN! Note - this is not Yahoo! Messenger |
X | system | outlook.exe | Added by the MIMAIL.Q WORM! Note that Microsoft's outlook.exe resides in the Program Files sub-directory wheras this resides in C:Windows or C:Winnt |
X | System | Atira.exe | Added by the KOTIRA VIRUS! |
X | SYSTEM | lsas.exe | Added by the SPYBOT.CJ WORM! |
X | System | kernels32.exe | Added by the DLOADER-FC TROJAN! |
X | System | sysctrl.exe | Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware |
X | System 64 Driver for Games | sys64dvr.exe | Added by the SDBOT TROJAN! |
X | System Applications Profile | sap.exe | Added by the RBOT-QF WORM! |
X | System Backup | msystem.exe | Adult content dialler |
X | System Cache | SysCache.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
U | System Check | Rundll32.exe SysDll32.dll, SystemCheck | XPCSpy Pro keylogger, surveillance and monitoring software |
X | system check | updater.exe | Unidentified adware downloader |
X | System Config Manager | crss.exe | Added by the AGOBOT.GH WORM! |
X | System Config Manager | smssl.exe | Added by the AGOBOT-ZJ WORM! |
X | System Configuration | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually! |
X | System Database administration | systemDA.exe | Added by the DERDERO.B WORM! |
X | System Database Administration Support Process | sysdasp.exe | Added by the DERDERO.C WORM! |
X | System Diagnostics | sysdiag32.exe | Added by the SDBOT.GEN TROJAN! |
N | System DLF | cpqdiaga.exe | Compaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs |
X | System Document Application | nmod.exe | Added by the SDBOT-ABB WORM! |
X | System Document Application | msdocument.exe | Added by the RANDEX.COX WORM! |
X | System driver | Messenger.exe | Added by a variant of the SMALL.BJ TROJAN! |
X | System Efficiency Monitor | mscedit32.exe | Added by the SDBOT.P TROJAN! |
X | System Efficiency Monitor | mscommand.exe | Added by the KWBOT.P WORM! |
X | System Executable DLL Library | EXECDLL32.exe | Added by the RANDEX.AZ WORM! |
X | System Failure Statistic | cnstat.exe | Added by the RBOT-LF WORM! |
X | System File Drivers | nvsysvc32.exe | Added by the AGOBOT.WJ WORM! |
X | System Handler | LSASS.EXE | Added by the NIMOS WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
X | System Host Service | svchost.exe | Added the the CONE.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | System Information Manager | Navcpe.exe | Added by the SDBOT-QB WORM! |
X | System Information Manager | Msbb.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
X | System Initialization | msmsgri32.exe | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
X | System Initialization | payload.dat | Added by the RANDEX.D WORM or ROXY or ROXY.B TROJANS! |
U | System LifeGuard Scheduler | Slsched.exe | System LifeGuard scheduler |
X | System Log Event | csrss32.exe | Added by the AGOBOT-JI WORM! |
X | System Manager | svchost.exe | Added by the BANKER-AE TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | system manager | System.exe | Added by the FORBOT-BO WORM! |
X | System Manager | winsrv32.exe | Added by an unidentified WORM or TROJAN! |
U | System Mechanic Popup Stopper | Popupstopper.exe | Iolo "System Mechanic" popup stopper |
U | System Monitor | SYSMON.EXE | Comes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal |
X | System Monitor | Sysmon16.exe | Added by the SDBOT TROJAN! |
X | System MScvb | mscvb32.exe | Added by the SOBIG.C WORM! |
X | System Networking | sysnet.exe | Added by the RBOT.API WORM! |
X | System Profile | Regsrv.exe | Added by a variant of the OPTIX TROJAN! |
X | System Restore | svcnet.exe | Added by the TIBICK WORM! |
X | System Restore Data | [path] repcale.exe [path] beird.exe | Added by the RANDON.AN WORM! |
X | System Service | MSREXE.EXE | Added by the AML TROJAN! |
X | system service | spoolcrv.cpl | Added by the INSPIR.11 TROJAN! |
X | System Service | systems.exe | Added by the AGOBOT.VZ WORM! |
X | System Soap Pro | soap.exe | System Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided |
U | System startup | charmapx.exe | Only required if using an oriental language |
X | System Startup | Voltio.exe | Added by the RBOT.NJ WORM! |
X | System Stats | SystemStats.exe | Added by a variant of the WOOTBOT WORM! |
X | System Terminal | SYSTEM2.EXE | Added by the SPYBOT-BZ TROJAN! |
X | System time updator | CSysTime.exe | Added by the RANDEX.S WORM! |
X | System Toolkit | Systools.exe | Added by the RONOPER-G WORM! |
X | System Tray | msccn32.exe | Added by the PALYH.A WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray (SysTray.exe) |
X | System Tray Services | spooles32.exe | Added by the AGOBOT.ZH WORM! |
X | System Tray32 | SysTray32.exe | Added by the REPAD WORM! |
X | System Update | [filename].exe | CoolWebSearch parasite variant |
X | System Update | [random filename] | Added by the KORGO.W or KORGO.X WORMS! |
X | System Update | wupdmgr.exe | Added by the SOROMO-A TROJAN! |
X | System Update | [random filename] | Added by the SOROMO-A TROJAN! |
X | System Update Service | wmiprvsa.exe | Added by the AGOBOT-RG TROJAN! |
X | System Update2 | explorer.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | services.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | svchost.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | system.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | taskman.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | taskmon.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | update.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | webcheck.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | wininet.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | winlogon.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | winspool.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Update2 | wupdmgr.exe | Added by the AUTOTROJ-C TROJAN! |
X | System Updater Service | wmiprvsw.exe | Added by the GAOBOT.AFC WORM! |
X | System Uptime Server | SYSENTRY.EXE | Added by the RBOT.LK WORM! |
X | System Uptime Server | SYSENTRY32.EXE | Added by the RBOT.LK WORM! |
X | system xp | acdsee demo.exe | Added by the SALGA.A WORM! |
X | System-Config | msptmf32.com | Added by the LIOTEN.FA WORM! |
X | System-Service | EXPLORER.SCR | Added by the BENJAMIN WORM! KaZaA file-sharing users beware! |
X | system. | system..exe | Added by the OPTIXPRO.13.C TROJAN! |
X | system... | system...exe | Added by the OPTIXPRO.13.C TROJAN! |
X | System.exe | System.exe | Added by various WORMS and TROJANS! |
X | System32 | system.exe | Added by the BUSHTRO122 TROJAN! |
X | System32 | System32.exe | Added by any number of WORMS or TROJANS! |
X | System32 | sysdiag.exe | SpyAgent.B spyware |
X | System32 | system32,1.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | system32 | NeT-BoT.exe | Added by the AGOBOT-LJ WORM! |
X | system32.dll | systeminit.exe | CoolWebSearch hijacker re-directing to your-search.info |
X | system32.dll | sysdll32.exe | CoolWebSearch parasite related. Redirecting to wholeworldmarket.com, most likely other domains as well |
X | system32.exe | services32.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
X | System32Dll | DLL32SYS.EXE | Added by the SPYBOT-CZ WORM! |
X | System32Ex | System32Ex.exe | Added by the IRCCONTACT TROJAN! |
X | System33 | FB_PNU.EXE | Added by the NICHELLO-A WORM! |
X | SystemAdministration | Wincmp32.exe | Added by the ASYLUM TROJAN! |
U | SystemAgent | Sage.exe | "Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times" |
X | SystemBackup | mtx.exe | Added by the MTX VIRUS/WORM! |
X | SystemBackup | MicroLog.exe | Added by the MICROLOG.A TROJAN! |
? | SystemBoot | ladies.htm | Unknown but sounds very suspicious?? |
X | SystemBoot | Mshta.exe ...filename.hta | Adult content dialler |
X | SystemCheck | Systemcheck.exe | Added by the LAVITS WORM! |
X | SystemChecker | Syschk.exe | Added by the GALIL.F WORM! |
X | SystemCONF98i | SystemCONF98i.exe | Added by the GLITCH BOT TROJAN! |
X | SystemDebug | Sysdeb32.exe | Added by the SYSBUG TROJAN! |
X | SystemDll | SystemDll.exe | Added by the LOXOSCAM TROJAN! |
X | systemdrv | ms32sys.exe | Added by an unidentified WORM or TROJAN - most likely GAOBOT variant |
X | SystemEmergency | [various filenames] | SmartSearch - a CoolWebSearch parasite variant |
X | SystemExplorer | explore.exe | Homepage hijacker - file located in the "Services" folder in Common Files |
X | SystemFTP | VSENMB.exe | Malware (ie, malicious software). Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well |
X | SystemInit | iservc.exe | Added by the FIZZER WORM! |
X | Systemiom Updater | Systemiom.exe | Added by the SPYBOT.TY WORM! |
X | SystemLoad32 | sysload32.exe | Added by the MIMAIL.E WORM! |
X | SystemManager | Sysman32.exe | Added by the DOWNLOADER-BW.B TROJAN! |
X | SystemMap32 | Netisp32.vbs | Added by the REDIST.C WORM! |
X | SystemMD | md.exe | Homepage hijacker |
X | SystemMonitor | Sysmon32.exe | Added by the AIDID.A WORM! |
X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS! |
? | SystemReg | PROCES.EXE | ?? |
X | SystemReg | svchost.exe | Added by the DEWIN.E TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | SystemReg | WINREG.EXE | Added by the DEWIN.A TROJAN! |
X | Systems | scchost.exe | Added by the DAEMOZ.A TROJAN! |
X | Systems Restart | slchost.exe | Added by the BANCOS.RF TROJAN! |
X | Systems Restart | spchost.exe | Added by a variant of the BANCOS.RF TROJAN! |
X | Systems Restart | Rundll32.exe beem.dll, DllRegisterServer | Browser hijacker - the file serves to register a dll implemented as a browser plugin |
X | Systems Restart | Rundll32.exe snim.dll, DllRegisterServer | Added by the Startpage.I hijacker |
U | Systems.exe | Systems.exe | Keyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
U | SystemSafe | Syssafe.exe | System Safety Monitor - system monitoring tool with additional application firewalling |
X | SYSTEMSars32 | csrss.exe | Added by the AHLEM.A WORM! Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup! |
X | SystemSAS | System32.exe | Added by the KWBOT.C WORM! |
X | SystemSearch | regedit.exe -s c:ie.reg | Installs a Seachxl.com browser page hijack |
X | SystemSearch | regedit.exe -s c:sys.reg | Installs a i--search.com browser page hijack |
X | SystemService | msocfg.exe | Premium rate adult content dialler |
X | SystemService | navchk.exe | Premium rate adult content dialler |
X | SystemService | qservice.exe | Premium rate adult content dialler |
X | SystemService | shman.exe | Premium rate adult content dialler |
X | SystemSettingf | TRUG.vbs | Added by the TRUG.B MACRO! |
U | SystemSuite Task Manager | MXTASK.EXE | vcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro |
X | SystemTasks | filez.exe | Adult content dialler |
X | SystemTasks | sexypicz.exe | Adult content dialler |
X | SystemTasks | loaded.exe | Adult content dialler |
X | Systemtra | Systra.exe | Added by a variant of the LOVGATE WORM! |
X | SystemTra | CDPlay.EXE | Added by a variant of the LOVGATE WORM! |
U | SystemTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
X | SystemTray | SystemTray.exe | Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray (SysTray.exe) |
X | SystemTray | SysTray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the valid System Tray (systray.exe) which resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP). If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
N | SystemUpd | SystemUpd.exe | Updater for Swapoo.com, a kind of Napster for games |
X | SystemWideHook for Windows NT | %WinHook32.exe | Added by the MYDOOM.AC WORM! |
U | SystemWizard Sniffer | Sniffer.exe | SystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC |
X | systemyom Updater | systemyom.exe | Added by a variant of the BACKDOOR.IRC.BOT TROJAN! |
X | SYSTEMZ Patch | SYSZ.exe | Added by the ALADINZ.P TROJAN! |
U | System_Messages | pprsen.exe | TerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like" |
X | Systesms.exe | systesms.exe | Added by the RBOT-HI WORM! |
N | Systest | Systest.exe | Clean Space temp files cleaner |
X | systhread | winkernal.exe | Added by the LIAMED WORM! |
X | SysTime | systime.exe | CoolWebSearch parasite variant |
X | Systmesy | Systmesy.exe | Added by the RBOT-KQ WORM! |
X | Systoan32 | systoan.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
? | systr32 | systr32.exe | ?? |
? | systrax | systrax.exe | ?? |
X | Systray | Systray_.Exe | Added by the KERGEZ.A WORM! |
X | Systray | [filename.exe] | Winfavorites adware |
X | SYSTRAY | UNMT.EXE | Added by the SDBOT WORM! |
U | SysTray | SysTray.Exe | SYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they're available via Start -> Settings -> Control Panel |
X | SysTray | Snnpapi.exe | Added by an unidentified TROJAN! |
X | Systray driver | systray.exe | Added by the MUTEBOT TROJAN! Note - this is not the real SystemTray which shares the same filename |
X | SystrayServices | Msxpw.exe | Added by the CITOR WORM! |
X | systree | systree | Added by the BANCOS.L TROJAN! |
X | Systry | [path to worm] | Added by the AUTEX WORM! |
X | SYStry | spoolsvr.exe | Added by the SDBOT.GN WORM! |
X | Systryt | [path to worm] | Added by the AUTEX WORM! |
X | sysu | sysu.exe | Dynamic Desktop Media adware - see here |
X | SysUpd | Sysupd.exe | VirtuMonde adware |
X | Sysvupex | Sysvupex.exe | Added by the MEDIAS TROJAN! |
U | SysW8 | csta.exe | Clean Space - privacy and perfomance enhancer |
U | SYSWB6 | SYSWB6.exe | We-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content |
X | SysWin | SysWin.exe | Added by the IRCCONTACT TROJAN! |
X | syswin32 | syswin32.exe | Added by a variant of the SPYBOT WORM! |
X | Syswindow | Syswindow.exe | Added by the COW TROJAN! |
X | SYS_CLEAN | Service.exe | Added by the FLOPCOPY WORM! |
U | SZMsgSvc.exe | SZMsgSvc.exe | StopZilla! - pop-up killer |
X | t | xclean.exe | Flashtrack.B adware |
N | T-DSL SpeedMgr | speedmgr.exe | T-Online ISP SpeedManager - shows upload and download speed. Also checks for updates automatically |
X | Taba | stte.exe | Clickspring spyware |
N | Tablet | Tablet.exe | Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL+ALT+DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds) |
Y | tablet s | tablet s | Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful) |
U | TabletTip | tabtip.exe | The Microsoft Tablet PC Input Panel converts handwriting to text dynamically, and you can make corrections quickly and easily before inserting text |
Y | TabUserW | TabUserW.exe | Wacom pen tablet driver |
N | Tad | tad.exe | From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute |
? | TAG | tag.exe | ?? |
N | Tahni Deskmate | Tahni.exe | Tahni Deskmate - "Interactive cartoon character that lives on your Windows desktop" |
N | TalkingReminder | TALKINGREMINDER.EXE | Talking Reminder from Software River Solutions - talking calendar reminder |
? | talknow | talknow.exe | Could it be related to this or something similar? |
? | Tango | Setup.exe | Tango Broadband access software. Is it required? |
? | TangoManager | TangoManager.exe | Tango Broadband access software. Is it required? |
X | Tapicfg | Tapicfg.exe | CoolWebSearch parasite variant |
X | Tapisys | tss.exe | Added by the SMALL TROJAN! |
U | TapiTNA | TapiTNA.exe | Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys |
U | Tardis | Tardis.exe | Tardis - time synchronization software |
X | Task | tasker.exe | Added by the MYDOOM.R WORM! |
X | Task Bar | TASKBAR.EXE | Added by the FRETHEM.J WORM! |
? | Task BarClient | TaskBarClient.exe | Responsible for creating the System Tray icon and associated display system for the Starband satellite always on internet service |
? | Task BarSvr | TaskBarSvr.exe | Part of the Starband satellite always on internet service. Not included on the current system. What does it do and is it needed? |
X | Task Manager | taskmngr.exe | Added by the RBOT.Y WORM! |
X | Task Monitoring Service | svchost.exe | Added by the CONE.D WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | task service | taskservices.exe | Added by a variant of the RBOT WORM! |
N | Taskbar | Taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
N | TaskBar | CTLTask.exe | Creative SoundBlaster Audigy Taskbar - used to choose between different types of EAX Effects, not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article |
N | Taskbar Display Controls | RunDLL deskcp16.dll, QUICKRES_RUNDLLENTRY | Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes "Powertoy" installed |
X | Taskbell.exe | Rund1.exe | Added by the YIPID TROJAN! |
X | TaskMan | rundll32.exe | Added by the DVLDR TROJAN! Note - this is not the valid "rundll32.exe" as it's in the WindowsFonts directory |
X | taskmanager | taskmgr.com | Added by the BEREB WORM! |
X | Taskmgo | [path to file] | Added by the BANCBAN-T TROJAN! |
X | Taskmgr | Taskmgr.exe | System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory |
X | Taskmgr | tskmgr32.exe | Homepage hi-jacker |
X | taskmgr | taskmgr.exe | Added by the Startpage.G hijacker. Note - this is NOT the Windows Task Manager file! |
N | taskmgr.exe | taskmgr.exe | Windows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut |
X | taskmgr.exe | paint.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
X | taskmgr.exe | mirc.exe | Added by a variant of the AGENT.AH TROJAN! |
X | taskmgr.exe | paintms.exe | Added by a variant of the AGENT.AH TROJAN! |
X | taskmngr lptt01 | taskmngr.exe | Variant of the RapidBlaster parasite (in a "Taskmngr" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | taskmngr ml097e | taskmngr.exe | Variant of the RapidBlaster parasite (in a "Taskmngr" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | TaskMon | taskmon.exe | Added by the MYDOOM.A or MYDOOM.J WORMS! Note - this is not the legitimate Win9x/Me file of the same name which resides in C:Windows as this version resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP). It is not normally on a WinXP system |
X | Taskmon driver | winampa.exe | Added by the LOONY-I TROJAN! |
U | TaskMonitor | taskmon.exe | The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) |
X | taskopen.exe | taskopen.exe | Added by the HIDD.C TROJAN! |
N | TaskPlus | TASKPLUS0.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN |
N | TaskPlus | TASKPL~1.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN |
X | TaskReg | [random filename] | Added by the CBLAD WORM! |
X | Taskschd | TRAYWND.EXE | Added by the LITMUS.002 TROJAN! |
N | taskswitch | taskswitch.exe | ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen |
X | tasksys | tasksys.vbs | Added by the BYRON WORM! |
N | Tasktray | CTLTray.exe | Installed with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon. Also allows you to launch the Taskbar via right-click -> Show Taskbar. The tasktray can be accessed via Start -> Programs -> Creative -> Sound Blaster Audigy -> Taskbar |
X | tat | tatss.exe | Delfin Promulgate adware variant |
Y | Tau monitor | Taumon.exe | "Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system." |
U | TB2PROEXE | tb2start.exe | Timbuktu Pro - remote desktop access software |
U | TBC Pro | tbcpro.exe | TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus |
N | tbctray | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel |
Y | TBLFUNC | tblmouse.exe | Aiptek HyperPen driver |
U | TBPanel | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel |
X | TBPS | TBPS.exe | WebSearch toolbar, HuntBar parasite variant |
N | TBTray | tbtray.exe | VLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start -> Settings -> Control Panel |
? | TB_setup | TB_ANI~1.EXE | ?? |
X | TB_setup | tb_setup.exe | HuntBar parasite toolbar installer |
Y | tcactive | tca.exe | Part of The Cleaner from MooSoft - stops virus trojans before they can do any damage |
N | TCASUTIEXE | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs |
N | TCASUTIEXE | TCASUTI.exe | Associated with the 3COM diagnostic module (3COM NIC Doctor). No further information is available |
N | TCAUDIAG -off | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs |
? | TCDPbtn | TCDPbtn.exe | Found on a Toshiba laptop |
? | TCDPlay | TCDPlay.drv | Found on a Toshiba laptop - sounds like the driver for the CD-ROM but why doesn't it use the standard Windows drivers - any comments? |
U | TClock | TCLOCK.EXE | Kazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start -> Programs |
U | TClockEx | TCLOCKEX.EXE | Puts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks |
U | tcmonitor | tcm.exe | Part of The Cleaner from MooSoft - warns of changes to the registry |
X | TCP Monitoring | LanNSvc.exe | Added by the RANDEX.AAS WORM! |
X | tcupdater | tcupdater.exe | Topconverting.com/180Search adware updater |
? | TDispVol | TDispVol.exe | ?? |
U | TDKSTART | TDKSTART.EXE | Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. |
N | TDKTASK | TDKTASK.EXE | Taskbar utility for a "control panel" for a CD-RW |
? | TDockNUndock | N/A | Found on a Toshiba laptop - for use with a docking station? |
U | TDS3 | TDS-3.exe | DiamondCS TDS3 antitrojan. Can be used to scan on demand, but required in startup if you prefer real time protection |
? | TDspOff | Tdspoff.exe | Found on a Toshiba laptop |
N | Teach In Box | teachbox.exe | Tutoring program that comes with a SystemAX Computer |
Y | Tech-In-A-Box | techbox.exe | Tech-in-a-Box "provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running" |
U | Telechips,Mass | patch.exe | Removable disk driver for the Muro MP3 player |
N | Telemeter 3.0 | telemeter3.exe | Internet connection bandwidth meter from a user ISP |
Y | Telepath | telepath.exe | Drivers for the WinModem versions of the US Robotics "Telepath" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
Y | TELUS Security service | freedom.exe | Freedom Internet Security, provided by TELUS Communications Inc |
X | TempCom | [randomname].com | Added by the TRAXG WORM! |
X | tempx | tempx.exe | Added by the TEMPEX.A TROJAN! |
X | Tencent QQ | Rund1132.exe qq.dll, Rundll32 | Added by the QQPASS.F TROJAN! |
X | Terminate Popup | ZPU.exe | Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here |
X | Terminate Popup | FPUK.exe | Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here |
U | TEscKey | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function |
N | Tesco.net | rundll32 [path] RyDial.dll, QuickStart | Tesco.net dial-up ISP software - not required |
? | Tesla | TESLA.EXE | ?? |
X | Testing 123 | msdata.dat | Added by the NITS.A WORM! |
? | TExBUtil Registry | TExBUtil.exe | ?? |
N | TextAloud | TextAloudMP3.exe | TextAloud MP3 - convert text into spoken words and MP3s |
N | Textbridge Instant Access OCR | telepath.exe | TextBridge from Scansoft. OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs |
X | TEXTCONV | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | TEXTCONV | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
U | TFncKy | TFncky.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
U | TFNF5 | TFNF5.exe | Toshiba Hotkey Utility for Display Devices. By pressing <FN> + <F5>, a window appears showing the displays that can be chosen – LCD, LCD + CRT, CRT, TV |
Y | tfswctrl | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
X | TFTP*** | tftp*** | Added by a variant of the SPYBOT WORM! where *** can be any number |
U | TFunckey | TFuncKey.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
N | TgAddServer | tgfix.exe | Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove, Charter offer some uninstallation instructions involving a registry patch that you may be able to modify for your proivder or try here |
X | tgbcde | module32.exe | Added by the REIGN.R TROJAN! |
U | Tgcmd | tgcmd.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
U | tgcmdprovidersbc | tgcmd.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
N | TGCMG | ?? | Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work |
X | TGDC IE Plugin | tgdc.exe | ShopForGood spyware - see here |
X | tgkill | tgkill.exe | Comcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs |
U | Tgsetsite | tgfix.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
N | Thdetrf | thdetr32.exe | Appears to be related to Lycos advertising |
U | The Easy Bee's Hive | ATCEgSvr.exe | The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence |
? | TheMainStart | N/A | ?? |
U | THGuard | TH_Guard.exe | Resident memory scanning for TrojanHunter |
U | THGuard | THGuard.exe | Resident memory scanning for TrojanHunter |
X | This is a virus, please delete it | bigbadvirus.exe | Added by the RANDEX.F WORM! |
U | THOTKEY | THotkey.exe | Associated with the Fn+ keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen |
X | Threaded | intcp32.exe | Added by the RANDEX.UG WORM! |
U | ThrustTSR | TMTMTSR.exe | Thrustmaster Thrustmapper. "The Thrustmapper - t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly" |
U | TiADSL | tidslmon.exe | Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs |
X | tibs3 | tibs3.exe | Premium rate adult content dialler |
X | Tiger | Shine.exe | Added by the HAPPYLOW (or NISHE-A) VIRUS! |
X | Time Zone Synchronization | wscript zshell.js | Added by the NETDEX-A TROJAN! |
U | TimeCalendar | tc.exe | TimeCalendar digital planner |
N | Timed Backups Manager Startup | BACKTIME.EXE | Backup Plus - backup software |
N | Timemanager.exe | Timemanager.exe | Easy to use program for recording how you spend your time, designed to help you in billing multiple clients |
N | TimeOnline | TIMEONLINE.EXE | Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs |
X | TIMER | TIMER.EXE | Added by the TIMESE.AG WORM! |
X | TimeService | trun.exe | TlfLic-A premium rate adult content dialler |
X | TimeSink Add Client | TSADBOT.EXE | Advertising spyware |
X | TimeSyncApp | TimeSynchronize.exe | DealHelper adware |
N | TimeUp | Timeup.exe | TimeUp - internet online timer |
U | Timezone | TimeZone.exe | Microsoft Daylight Saving Time Update Utility - see here |
N | TINTSETP | TINTSETP.EXE | Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
X | Tiny AV | fooding.exe | Added by the NETSKY.I WORM! |
Y | Tiny Personal Firewall | persfw.exe | Tiny Personal Firewall |
U | tinySpell | tinyspell.exe | Tinyspell - "allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard" |
U | TiomanExe | Tioman.Exe | Agate Tioman - warm and hot swap removable bay device manager for IBM laptops |
N | Tips | mousetips.exe | Suggests tips on using your mouse |
U | TiTleBarClock | TiTleBarClock.exe | TitleBarClock displays the day/month/time and free physical RAM on the right hand side of an open window, replacing the system tray clock at startup |
N | Tivoli | LCFEP.EXE | Tivoli ‘TME’ System Tray icon - "'lcfep' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally" |
U | TizzleTalk | TizzleTalk.exe | TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messangers |
X | tjstartup | svchost.exe | Added by the CURDEAL TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | tjstartup | [path to file] | Added by the TJSERV.C TROJAN! |
N | TkBell.Exe | evntsvc.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version |
N | TkBell.Exe | realsched.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it |
N | TkBell.Exe | tkbell.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK |
N | TkBellExe | evntsvc.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it. Note that eventsvc.exe no longer appears to be in a newer version |
N | TkBellExe | realsched.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it |
N | TkBellExe | tkbell.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK |
N | tkonnect | TKONNECT.EXE | Dialer for the Tiscali internet service provider. Available as a desktop shortcut |
X | tlc | update911.js | Hijacker installer |
? | TlcR | avp.exe | ?? |
U | TLogonPath | tb2logon.exe | Timbuktu Pro - remote desktop access software |
U | TM Outbreak Agent | TMOAgent.exe | Trend Micro Internet Security anti-virus software virus outbreak warnings. Notifies users of virus outbreaks and offers to update the scanner |
U | TMA distribution | cfinst.exe | Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients |
X | tmax | pupdate.exe | Adware pop-up generator |
X | tmchook | tmchook.exe | Detected by Kaspersky as the TrojanDownloader.Win32.VB.aa VIRUS! |
? | TMEEJME | TMEEJME.EXE | Found in a ToshibaTME3 directory. Toshiba Mobile Extension related? |
? | TMERzCtl | TMERzCtl.EXE | Found in a ToshibaTME3 directory. Toshiba Mobile Extension related? |
U | TMESBS | TMESBS21.exe | Toshiba Mobile Extension Selectable Bay Service for WinXP - support for docking stations. Not required if you don't use a docking station |
? | TMESBS32 | TMESBS32.EXE | Found in a ToshibaTME3 directory. Toshiba Mobile Extension related? |
U | TMESRV31 | TMESRV31.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station |
U | TMExLogon | TMESRV.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station |
? | Tmmkb | Tmmkysvr.exe | Toshiba multi-media keyboard software - possibly including creating keyboard shortcuts? |
U | TMOUSE | tmouse.exe | Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL + ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL + SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint |
Y | tmproxy | tmproxy.exe | Trend Micro PC-cillin 2003 antivirus software |
N | TMTMTSR | TMTMTST.exe | Installed with Thrustmaster game controllers. It launches the Thrustmapper utility. Not required if you install the "driver only" from Thrustmaster website |
U | TNTClk | TNTCLK.exe | Overclocking program for TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked to let it run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job |
U | ToADiMon.exe | ToADiMon.exe | T-Online ISP software connection assistant |
? | TomcatStartup | hpbpsttp.exe | Apache Tomcat web server, part of HP LaserJet "Printer Tools" software. What does it do and is it required? |
? | TomcatStartup 2.5 | hpbpsttp.exe | Apache Tomcat web server, part of HP LaserJet "Printer Tools" software. What does it do and is it required? |
? | Tommorrow | tomorrow.exe | ?? |
? | ToPassSrv | Pktopass.exe | Related to Caere Pagekeeper scanning software (now taken over by Scansoft), Disabling is known to cause problems |
U | TopDesk | TopDesk.exe | TopDesk - puts an icon in your system tray that when clicked upon, opens a pop-up menu that gives instant access to all of your desktop programs without having to minimize, resize, move or close other programs or files |
X | ToPicks Starter | Idhost.exe | ToPicks parasite related |
X | topmoxie | JavaRun.exe | Marketing software from TopMoxie |
? | TOSCDSPD | toscdspd.exe | Toshiba laptop related |
Y | Toshiba Fan | fan.exe | Toshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat |
U | Toshiba Key State | KEYSTATE.EXE | Displays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start -> Programs |
N | ToshibaPinger | pinger.exe | Pinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification. Disabling instructions here |
U | TOSHIBSU | Toshibsu.exe | Reduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly |
U | TosHKCW | TosHKCW.exe | Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed) |
Y | TosMem | tosmem.exe | Toshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem |
U | TotRecSched | TotRecSched.exe | Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm |
U | Touch Manager | WinLED.exe | Dell keyboard utility. Disabling can result in loss of screen saver and power saver functionality |
U | TouchED | TouchED.exe | TouchPad On/Off Utility on a Toshiba laptop |
N | tour | regedit ..tour.reg | Edits registry values to keep the WinMe tour in Task Scheduler |
N | Tour | wincool.exe | Component of WinME that's annoying as hell. Pop's up a prompt to play the C:WINDOWSApplication DataMicrosoftINTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only |
N | tourpath | regedit /s [path] tour.reg | Edits registry values to keep the Win 2000 "tour" in Task Scheduler |
U | TP4EX | tp4ex.exe | Adds accessibility options for an IBM TrackPoint |
U | tp4mon | tp4mon.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work |
U | tp4serv | tp4serv.exe | Supports the "pointer stick" on Thinkpads in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work |
? | TP98TRAY | TP98TRAY.EXE | IBM Thinkpad related utility. What does it do and is it required? |
N | TP98UTIL | TP98.EXE | IBM Thinkpad feature setup & configuration utility |
X | tpcupdater | updatetc.exe | Adware, probably 180Solutions related |
U | TpHotKey | TPHKMGR.EXE | Activates "ThinkPad Help" when the "Thinkpad key" is pressed on an IBM ThinkPad laptop. Also activates the audio buttons (volume up/down, mute) on models such as the Thinkpad T30 |
? | TPKMAPHELPER | TpKmapAp.exe | IBM ThinkPad related. What does it do, and is it required? |
U | TpKmapMn | TpKmapMn.exe | Create Keyboard combinations for special Thinkpad buttons when using an external keyboard, e.g. "Ctrl-arrow up" for "volume up". Only required when using an external keyboard. Available via Start -> Programs |
U | tpopservice | tpopservice.exe | DirecWay two-way satellite internet service enhanced POP proxy server for email |
U | TPP Auto Loader | Tppaldr.exe | Installed with DataStor's (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives. System tray icon allowing the user to disconnect the external drive without an error message being displayed |
U | Tprtray | Tprtray.exe | Displays the Power icon in the System Tray on a Toshiba laptop |
U | TpScrLk | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED |
Y | TpShocks | TpShocks.exe | Responsible for controlling the IBM Hard Drive Active Protection system found on newer models of IBM Thinkpads, including T41, T42, X40, R50, and R51. The Hard Drive Active Protection system is based on a technology similar to that used in automobiles to deploy airbags on contact: An accelorometer on the motherboard detects physical acceleration--such as when the notebook falls--and in response the system temporarily parks the hard drive's read/write head until stability returns |
? | TPSmain | TPSMain.exe | Toshiba related |
N | TPTray | TPTray.exe | Touchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel |
? | TPTRAY | TP98TRAY.EXE | IBM Thinkpad related utility. What does it do and is it required? |
? | TPwrMgr | TPwrMgr.exe | Found on a Toshiba laptop. Related to power management? |
Y | TPWRTRAY | Tpwrtray.exe | Toshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use |
U | tqrecv | tqrecv.exe | Tellique satellite broadcast reception software |
N | Traceless | launch.exe | Traceless 2003 - clear your cookies, temp directories and browser history with a click of a button. It also clears the recent documents and the IE drop down auto complete box |
? | Tracker | Tracker.exe | Possibly associated with My Deluxe Invoices program |
U | TrackpointSrv | daemon.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work |
U | TrackpointSrv | tp4serv.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work |
U | TrackPointSrv | tp4mon.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work |
U | Tracks Eraser | te.exe | Tracks Eraser from Acesoft - "Erases all tracks of your internet activity" |
U | Tracks Eraser Pro | te.exe | Tracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity" |
U | tranicon | tranicon.exe | A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System + File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent |
U | Transparent | TransparentW.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here |
U | Transparent | TransparentD.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here |
U | Transparent | TransparentB.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here |
U | TransparentIcons | tranicon.exe | A Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System + File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent |
U | transtask | transtask.exe | A Tweak-XP component, makes the taskbar icons transparent |
U | Trashgrd | TRASHGRD.EXE | Part of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin |
N | Tray Temperature | Weatherbug.exe | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
X | Traybar | lsass.exe | Added by the MYDOOM.L WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup! |
U | traydate.exe | TRAYDATE.EXE | Displays the date as well as the time in the System Tray. Available from TUCOWS |
U | TrayManager | Trayman.exe | TrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded) |
U | Traymon | traymon.exe | Netropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news |
N | TraySantaCruz | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel |
N | TrayServer | TrayServer.exe | For monitoring tray icons |
X | TrayX | winppr32.exe | Added by the SOBIG.F WORM! |
N | tray_helper | tray_helper.exe | Tray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder |
Y | TrendMicro Antivirus | Aveagent.exe | Virus scanner |
Y | TrendMicro OfficeScan NT | TMLISTEN.EXE | Virus scanner |
X | Trickler | fsg.exe | Adware |
X | Trickler | fsg-ag_3102.exe | Adware |
X | Trickler | gain_trickler_3202.exe | Adware |
X | trickler_bic_GatorDM_4010 | trickler_bic_GatorDM_4010.exe | Adware |
? | TridTray | TridTray.exe | System Tray access to Trident 4DWave soundcards? |
? | TridTray | TridTray.exe | System Tray access to Trident 4DWave soundcards? |
Y | trirot | trirot.exe | Trident Microsystems 3D video driver |
U | TrojanScanner | Trjscan.exe | Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed |
U | TrojanShield | Init.exe | TrojanShield |
U | True Internet Color Icon | internetcolor.exe | Part of Colorific & 3Deep from LightSurf Technologies (nee E-Color). "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images" |
X | TrueFonts | fonts.hta | Browser hijacker - redirecting to Hugesearch.net |
N | TrueSync Launcher | tstool.exe | Starfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services |
Y | TrueVector | VSMON.EXE | Even if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this |
X | tsa | tsm.exe | TargetSaver adware |
X | Tsa2 | tsm2.exe | TargetSaver adware |
X | TsAdbot | TSADBOT.EXE | TimeSink Add Client - advertising spyware |
? | TSBxLogon | TMESBS2.EXE | Found on a Toshiba laptop. May be related to TMESBS? |
X | tskdbg | tskdbg.exe | Added by the FLOOD.E TROJAN! |
X | Tsl | tsl.exe | Uploader-R adware |
N | TSMsger | TSMsger.exe | Epson scannner software - required for "one-touch" operation. Can be launched manually |
? | TSPower | spower.drv | Found on a Toshiba laptop. Related to power management? |
? | TSService | NSSERVICE.EXE | ?? |
? | tsyssmon | tsyssmon.exe | Found in a Toshibasysstability directory |
? | ttasq | ttasq.exe | ?? |
? | Tukati | TukatiRedistributor.exe | Tukati Digital Content Distribution. Is it required? |
U | TuneUp MemOptimizer | memoptimizer.exe | Part of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboard |
U | TurboExplorer | TE.exe | Web accelerator - "TurboExplorer® 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer® 4/5 to achieve a faster and more effective approach to the internet". Only needed if you find it improves web browsing |
U | TurboMemoryCharger | turbomemorycharger.exe | Some users swear by memory management utilities such as Turbo Memory Charger but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind |
N | TurboNote | tbnote.exe | Post-It's on your desktop. Available via Start -> Programs |
U | TurboTop | TurboTop.exe | TurboTop - make any window "Always on top" |
X | TV Media | Tvm.exe | CleverIEHooker hijacker variant |
X | TVMD | tvmd.exe | Total Velocity - "Secure commerce company that enables the ‘checkout’ process for our customers in order to safely and securely purchase our award winning software". Autointsalling spyware |
U | TvNow | TvNow.exe | Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) |
X | TVTMD | TVTMD.EXE | Total Velocity variant - autoinstalling spyware |
N | TVWakeup | tvwakeup.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
? | Tvwatch | tvwatch.exe | Associated with the TV-oOut option on Asus AGP or Intel graphics cards. Is it required? |
X | Twain image | mmp32.exe | DailyWinner adware related |
? | TWarmBay | N/A | Found on a Toshiba laptop. Related to hotswap bay management? |
U | TWarnMsg | twarnmsg.exe | Toshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops |
? | TWBbtn | N/A | Found on a Toshiba laptop |
? | TWBrowse | TWBrowse.drv | Found on a Toshiba laptop. Possibly related to TWAIN drivers (ie, scanners, etc) - see this? |
? | Tweak Manager | WinManager.Exe | WinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed? |
U | Tweak UI | rundll32.exe tweakui.cpl, tweakmeup | Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed |
U | Tweak UI | rundll32.exe tweakui.cpl, tweaklogon | Automatically logs you on if you have Microsoft's Tweak UI "powertoy" installed |
X | Tweak UI | RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup | Added by the SUBWOOFER TROJAN! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup" |
U | Tweak UI 1.33 deutsch | RUNDLL32.EXE TWEAKUI.CPL, TweakMeUp | Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed - German version |
U | Tweak-Me | TWEAK-ME.exe | 3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here |
U | Tweak-xp | Tweak-xp.exe | Main program for Tweak-XP - a WinXP tweaking utility |
U | TweakDUN | tweakdun.exe | Utility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets |
? | tweakico | tweakico.exe | May be a HP program to control their icons? |
N | TwkSCardSrv | SCardS32.Exe | Used with Towitoko SmartCard Readers for card recognition |
X | Twunk_64 | twunk_64.exe | System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory |
N | type32 | type32.exe | For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them |
N | TypingSatellite | KBOOST.exe | Typing Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs |
X | Uate | oocs.exe | PurityScan/Clickspring adware |
U | UBSShell | UBSShell.exe | UBS (United Bank of Switzerland) banking software |
U | UCmore XP - The Search Accelerator | rundll32.exe UCMTSAIE.dll, DllShowTB | UCmore toolbar - search accelerator |
N | UC_SMB | ucstart.exe | Part of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed |
N | uc_start | ucstartup.exe | Auto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc |
U | UD Agent | UD.EXE | The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs |
U | Ueproc32 | UEPROC32.exe | Part of Norton Utilities - most likely associated with the Unerase Wizard in older versions |
? | ugon | aockstrs.exe | ?? |
N | Uidler | Uidler.exe | Uniloc Titlewave Browser used with some shareware |
N | UIWatcher | UIWatcher.exe | Ashampoo Uninstaller Suite - installation watcher. Available via Start -> Programs |
X | UKVideo2 | ukvideo2.exe | Adult content dialler |
N | Ulead Photo Express x.0 Calendar | calcheck.exe | Ulead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions |
N | UltimateZip Quick Start | uzqkst.exe | UltimateZip - file compression utility |
N | Ultra Hal Assistant 4.5 Startup | HalAsst.exe | Zabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion |
X | Ulubione | sys****.exe | Search Hijacker, redirecting to maxxxhosters.com - where **** are random characters |
N | UMAX VistaAccess | vsaccess.exe | VistaAccess gives you quick and easy access to scanning functions right from your desktop |
U | UMonit | umonit.exe | Alerts when USB device is plugged in |
Y | umxagent | umxagent.exe | Tiny Personal Firewall V4 - main engine |
Y | umxldra | umxldra.exe | User mode executive module DLL loader - part of Tiny Personal Firewall V4 |
Y | UMXLDRW | UMXLDRW.exe | Tiny Personal Firewall (pre V4) |
X | un32info | un32info.Exe | Added by the CRYPTER.A TROJAN! |
X | uninstal | regsvr32 /u /s image.dll | CoolWebSearch parasite related |
X | Uninstall**** | upd.exe | Adult content based screen saver where **** can be any number |
N | UninstallAbility | uability.exe | UninstallAbility uninstaller |
X | Uninstall_TBPS | TBuninst.exe /remove | WebSearch toolbar related, HuntBar parasite variant |
U | UniPrint | SetDfltSettings.exe | Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix |
U | UniSc | Unisc.exe | McAfee UnInstaller |
? | uniucu | uniucu.exe | ?? |
X | unldr16 | unldr16.exe | Added by a variant of the CRYPTER.C TROJAN! |
X | unldr32 | unldr32.exe | Added by a variant of the CRYPTER.C TROJAN! |
Y | untray | untray.exe | Part of Command AntiVirus |
N | uoltray | exec.exe | Netzero free ISP software - not required |
N | UpConfgVer | UpgConf.exe | Panda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function |
X | Update | [original file path] | Added by the LYNDEGG WORM! |
X | Update | CDUpdater.exe | "Carpe Diem" adult premium rate dialler related |
X | Update | Sysupd.exe | Added by the SLACKBOT VIRUS! |
X | Update | Zupdate.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents |
X | Update | mshtm.exe | Browser hijacker - redirecting to buldog-search.com |
X | Update | UPDATE-28062004.exe[25 blank spaces].vbs | Added by the MIDFIN WORM! |
X | update | winis.exe | Added by the RBOT-VD WORM! |
? | Update for Works | MSWkstz.exe | Maybe related to later versions of MS Works? |
N | Update Grokster | WiseUpdt.exe | Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor |
X | Update Install | Schost.exe | Added by the GAOBOT.AO WORM! |
? | Update local | SetCPQLC.exe | Running on a Compaq desktop. Any ideas? |
N | Update Manager | UpdateManager.exe | Searches for updates for the Rogers Yahoo! Browser - can be run manually |
X | update run dos | logon.exe | Added by a variant of the SDBOT WORM! |
Y | Update Service | Update.exe | Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall |
X | update service | svxhost.exe | Added by the RBOT-MG WORM! |
? | Update TUT | WiseUpdt.exe | ?? |
X | Update ver 1.0 | Swap.exe | Added by the SWAP-C WORM! |
X | UpdateComponent | CNF UPD.EXE | Added by the SPYBOT.GEN VIRUS! |
? | UpdateFW | fwdload.exe | Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module? |
? | UPDATEHOOK | Rundll32.exe | ?? |
U | UpdateManager | sgtray.exe | StorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups |
X | UpdateMedia | UpdateMedia.exe | MediaUpdate foistware |
N | updatemgr.exe | updatemgr.exe | Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually |
X | updater | wupdater.exe | eUniverse KeenValue parasite related |
? | updater | updater.exe | ?? |
X | Updater | adservernow.exe | AdServerNow adware |
X | Updater Service Process | svhost32.exe | Added by the AGOBOT.TY WORM! |
X | updater32 | winload32.exe | Added by the CULT.M WORM! |
X | Updates | msupdate.exe | CoolWebSearch parasite variant |
N | Updates from HP | backweb*****.exe | Automatically detects an internet connection and downloads any available updates - * is random digit |
N | Updatestats | Updatestats.exe | Statblaster - "Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues" |
N | updatev01 | updatev01.exe | Ultra-networks.com software updater/downloader |
? | Updatewiz | updatewiz.exe | ?? |
N | UPDATE~1 | updatemgr.exe | Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually |
X | upddateit | winit.exe | Added by the RBOT-MS WORM! |
X | Updmgr | updmgr.exe | eUniverse/KeenValue adware variant |
N | UpdReg | Updreg.exe | Reminder to register Creative Labs SoundBlaster Live! cards |
X | UpdSys | [random filename] | Added by the BJ TROJAN! |
? | UPERVGAS | UPERVGAS.exe | ?? |
X | upme | [filename] | Added by the MUGLY.F WORM! |
X | UPNPService | WinSVCservice.exe | Added by the AGOBOT.UN WORM! |
Y | UPS | ups.exe | PowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon) |
Y | UPSentry 2000 | upsd.exe | Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss |
Y | UPSlim | upsd.exe | Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss |
X | UPSUtl | web.exe | CoolWebSearch parasite variant |
U | Uptimer4 | Uptimer4.exe | Uptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things |
X | UpToDate | uptodate.exe | BrowserAid/BrowserPal foistware |
Y | UrlLstCk | UrlLstCk.exe | Part of Norton Internet Security. From Symantec - "UrlLstCk.exe is a necessary file that will be present in C:Program FilesNorton Internet Security. It is a URL Checklist. It should not be disabled" |
N | URLMAP | Urlmap.exe | Installed by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it |
Y | UrtSvcExe | Urt95Svc.exe | "Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources" |
? | Usb | Usb.exe | HP related - not sure whether it's required |
X | USB 2.1 Driver | winupdate1.exe | Added by a variant of the RBOT WORM! |
X | USB controller | Svcmm32.exe | Ouchvideo.com 'n-Lite' spyware |
X | USB Device | servicelog.exe | Added by the WOOTBOT.CB WORM! |
X | USB Device | win32usb.exe | Added by the FORBOT-BQ WORM! |
X | USB Hardware Monitoring | USBhardware.exe | Added by the RBOT-NN WORM! |
X | USB Host Service | usbsvc.exe | Added by the RBOT-GG WORM! |
? | USB Hub Keyboard Patch | SKBPATCH.EXE | USB HUB Update |
Y | USB SECURITY DEVICE CoInstaller | JupitCo.exe | ButterflyMedia USB Flash drive related - required for the password security feature to work |
X | UsbD | smss32.exe | Adware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj |
X | UsbD | svhost32.exe | Added by the AGENT.IB TROJAN! |
X | Usbd | usb_d.exe | Added by the CIDRA-A TROJAN! |
U | USBDetector | USBDetector.exe | USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware |
? | USBDetector | UDetect.exe | USB detector, apparently for an MP3 player - any further information appreciated! |
X | usbdrv | servicetask.exe | Added by a variant of the SDBOT WORM! |
U | USBMMKBD | usbmmkbd.exe | USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information |
U | USBMonit.exe | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives |
X | usbn | usbn.exe | Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa |
Y | USBPNP | USBPNP.exe | SiPix digital camera Twain USB driver |
N | USBTA | usbtapnp.exe | System Tray access for the BeWAN Gazel 128 USB ISDN adapter |
X | user | user32.exe | Added by the BINGHE TROJAN! |
X | User Services | usersvc.exe | Added by the REVCUSS.A TROJAN! |
X | User23.exe | DIAL.exe | This is a trojan trying to disguise itself as User32.dll |
X | User32 | [filename] | Added by the NETTRASH TROJAN! |
N | UserFaultCheck | dumprep 0 -u | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
X | UserSystem | [filename] | CoolWebSearch SmartSearch variant - also see here |
X | ushli | sscbltqu.exe | Obtained from an MP3 search list site. Also generates random processes on reboot |
X | usrgtway.exe | syswrun4x.exe | Added by the MITGLIEDER.E TROJAN! |
N | USRobotics 802.11g Wireless Network Utility | USRWLANG.exe | USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck "Use Windows to configure my wireless settings" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties |
N | Usrobotics Online Registration | ?? | Pop-up reminding customers to register their products online at US Robotics |
X | Usrr | rncr.exe | PurityScan/Clickspring adware |
? | USRSTA | USRSTA.exe | Wireless Card controller. What does it do and is it required? |
? | USRSTA.EXE | USRSTA.EXE | Wireless Card controller. What does it do and is it required? |
N | USSShReg | USSSHREG.EXE | Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers |
? | Utility Ping | UTILIT~1.EXE | ?? |
N | UtilityPro | UtilityPro.exe | IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions |
Y | UTILsInst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
N | Utopia Angel | Angel.exe | Calculator for the online Utopia game |
X | uwyrl | uwyrl.exe | Added by the PHEL.A TROJAN! |
U | V.92 Modem On Hold | Ltmoh.exe | Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet |
Y | V128IID | Rundll32.exe v128iitw.dll, STB_InitTweak | Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages |
? | V128IITV | ?? | Loads drivers for some STB graphics cards. May be related to such a card with a TV out option? |
? | V66SHELL | V66SHELL.EXE | It looks to be part of the display driver set for ASUS V3800, V6600 and V6800 display adapters. Probably a system tray quick access control? |
U | va10key | va10key.exe | Only required if you use the 10 kay bay unit with a Sony Vaio laptop |
Y | VAGCtrl | VAGCTRL.EXE | Vexira Antivirus - virus scanner from Central Command |
Y | VAGuard | VAGNT.exe | Vexira Antivirus - virus scanner from Central Command |
U | VAIO Action Setup (Server) | VAServ.exe | Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB |
U | VAIO Recovery | PartSeal.exe | System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere |
X | ValidData | [path to trojan] | Added by the RANKY.H TROJAN! |
X | vb6 | vb6.exe | Added by the MUGLY.D WORM! |
X | VBouncer | VirtualBouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here |
X | VbouncerDL | VbouncerInner****.exe [* = random char] | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here |
X | VbouncerDL | VBouncerInner.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself |
X | VBundleOuterDL | BundleOuter.EXE | VirtualBouncer 2.0 - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs |
X | VB_run | comctl_32.exe | Dubious downloader from densmail.com |
X | VC5MediaPlayer | csmss.exe | Added by the DEDLER-B WORM! |
N | VC5Play | VC5Play.exe | Virtual CD drive emulator - version 5. Available via Start -> Programs |
X | VCatch | Vcatch.exe | CommonSearch Vcatch - "antivirus" software which actually bundles spy/adware itself! |
X | VCatch Premium | VCatchpre.exe | VCatch antivirus. Considered spyware itself - see here |
N | VCDPlayer | VCDPlayer.exe | Virtual CD drive emulator. Available via Start -> Programs |
N | vcdplayx | vcdplayx.exe | CD emulation part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically |
U | VCDTower | VCDTower.exe | Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking |
? | VCDWATCH | VCDWATCH.EXE | Confirmed as Voyetra CD Watcher as it was found in a Compaq/Voyetra/AS2 directory but what does it do? |
N | VCSPlayer | vcsplay.exe | Virtual CD drive emulator. Available via Start -> Programs |
? | VDI Manager (HP) | HPO0VDX05.exe | HP (Hewlett-Packard) related. Now - what does it do? |
N | vdtask | vdtask.exe | Program part of GameDrive & VirtualDrive from Farstone. Not required as starting these programs load this automatically |
N | Vegas Palms - Launcher | Launcher.exe | Vegas Palms on-line cassino |
N | Verizon Control Pad | cpad.exe | Control Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience |
U | Verizon Online Support Center | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decide |
X | vern16.dll | regsvr32.exe [path] vernn16.dll | DailyWinner adware |
U | versato | versato.exe | "Hot" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards |
X | Version | Version.exe | JRAUN adware variant |
X | Version | manage.exe | JRAUN adware variant |
X | version | adl_dh.exe | DealHelper adware related |
Y | Vet Alert | vetmsg9x.exe | Computer Associates "InnoculateIT" and Vet Anti-Virus virus software |
Y | Vet Start Up | vet98.exe | Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options |
Y | Vet Start Up | vet32.exe | Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options |
U | VetTray | vettray.exe | Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. System Tray quicklaunch access, not really necessary but only occupies 36k resources |
X | VFW Encoder/Decoder Settings | RUNDLL32.exe MSSIGN30.DLL ondll_reg | Added by a variant of the LOVGATE WORM! |
U | VGAUtil | G-VGA.exe | Gigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical) |
X | vid32cntl | vid32cntl.Exe | Added by the CRYPTER.A TROJAN! |
X | vidcntl | vidcntl.Exe | Added by the CRYPTER.A TROJAN! |
X | Vidcompat | Vidcompat.exe | Added by the GEMA TROJAN! |
X | Video | explored.exe | Added by the GAOBOT.RF WORM! |
X | Video | winamp32.exe | Added by the AGOBOT-NG WORM! |
X | Video Lan Player | VideoLanPlayer.exe | Added by the RBOT-MY WORM! |
X | Video Manager | videomgr.exe | Added by the PANDEM.C WORM! |
X | Video Multimedia Driver | ndrives32.exe | Added by the RBOT-DK WORM! |
X | Video Proces | winaps.exe | Added by the AGOBOT.HD WORM! |
X | Video Process | sysconf.exe | Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS! |
X | Video Process | MS32x16.exe | Added by the RBOT.RH WORM! |
X | Video Process | netsvcs.exe | Added by the AGOBOT.LH WORM! |
X | Video Process | MSlti64.exe | Added by the AGOBOT.UE WORM! |
X | Video Process | [random filename] | Added by the RBOT-LM WORM! |
X | Video Process | winasp.exe | Added by the AGOBOT-IS WORM! |
X | Video Services | explore.exe | Added by the GAOBOT.GL WORM! |
X | Video Services | videol_32.exe | Added by the AGOBOT-DM WORM! |
X | Video Services | sys32.exe | Added by the AGOBOT.PS WORM! |
X | Videocntl | Videocntl.exe | Added by a variant of the GEMA.D TROJAN! |
X | VideoDriver | [filename] | Added by the GSPOT20.A TROJAN! |
X | VideoDriver | videodrv.exe | Added by the MIMAIL.A WORM! |
X | VideoDriver | gspotbot.exe | Added by the SPIGOT.C TROJAN! |
X | Videool32 | VIDEOL32.EXE | Added by the AGOBOT.EC WORM! |
N | VidSvr | vidsvr.exe | MS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
X | vietato.exe | vietato.exe | Adult content dialler |
N | ViewMgr | ViewMgr.exe | Viewpoint Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc). Can be run manually via Start -> Settings -> Control Panel by enabling auto-updates temporarily, re-booting and then disabling again |
? | Vinny | ?? | ?? |
X | Virt.exe | Virt.exe | Added by the REMADM-C TROJAN! |
U | VirtuaGirl | Vg.exe | VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request... |
U | VirtuaGirl2 | VirtuaGirl2 | VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request... |
X | virtual | winit.exe | Added by the MUGLY.A or MUGLY.B WORMS! |
X | virtual | winprotect.exe | Added by the MUGLY.C WORM! |
U | Virtual Access Scheduler | VASCHD32.EXE | The scheduler for mail and usenet tool |
X | Virtual Bouncer | VirtualBouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here |
N | VirtualCloneDrive | VCDDaemon.exe | Virtual Clone Drive, part of CloneCD CD/DVD copying sofware. Discontinued |
N | VirtualDrive | VDTask.exe | VirtualDrive from Farstone - virtual CD drive emulator. Available via Start -> Programs |
U | VirtuaReminder | VirtuaReminder.exe | VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments, birthdays, etc |
X | Virus Scan | virscana.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | VirusCheckII | AVIRCHK.EXE | Added by the DASMIN TROJAN! |
Y | VirusScan Online | mcvsshld.exe | McAfee VirusScan On-line. See also the McAgentExe entry |
? | VirusScanMSC | VsStat.exe | Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe), McAfee SecurityCenter integration or something else? Is it required? |
X | Virus_Scanner | Virus_Cleaner.exe | Added by the PANOL WORM! |
N | visionGS | VISIONGS.EXE | visionGS webcam software |
N | Vistascan | vistascan.exe | Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users, you'll see a scanner icon in the Windows Tray of the Taskbar. Click this icon and a menu opens |
X | VividGalut | VividGalut.exe | Adult content related web downloader |
Y | VMDFW | vmdfw.exe | VirusMD Personal Firewall |
X | Vmmon32 | vmmon32.exe | Browser hijacker |
X | vmsnGraber | VMSNGRABER.EXE | Added by the ENVID.B WORM! |
X | vmss | vmss.exe | Delfin Media Viewer or "Promulgate" adware variant |
X | VnCplUpdate | msdm.exe | Masssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisory |
U | VOBID | InstantDrive.exe | Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software |
Y | VOBRegCheck | VOBRegCheck.exe | Part of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn't use any resources so you can leave it enabled |
U | Vonage | click2call.exe | Vonage Voice over IP Internet phone service |
U | VoodooBanshee | rundll32.exe 3DBBps.dll, BansheeLoadSettings | Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not |
? | voowsmcr | huhdir.exe | ?? |
N | Vortex Tray | asp4setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
N | VortexTray | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
N | VortexTray | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
N | VortexTray | asp4setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel |
N | VoyetraTray | vtray.exe | This provides an abbreviated Control Group for the Turtle Beach Montego II sound functions/associated with AudioStation 3 and 32 |
U | Vpop3 Mail Server | vpop3.exe | Mail server from Paul Smith Computer Services. Runs in system tray to collect mail. Can be run from a shortcut and if it isn't running then it won't get your email! |
U | vptray | vptray.exe | System Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here |
Y | Vrmon | vrmonnt.exe | HAURI Anti-Virus |
Y | VrSchedule | Vrres.exe | HAURI Anti-Virus |
Y | VS.VSN | Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added | |
X | vscanner | spooll32.exe | Added by the OPTIXPRO.10 TROJAN! |
N | VsEcomrEXE | VSECOMR.EXE | From McAfee VirusScan up to version 4.x. This executable is responsible for the periodic "update" prompts |
Y | Vshwin32EXE | VSHWIN32.EXE | From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs |
N | VSN | VSN.exe | Software to share photographs across the internet |
Y | VSOCheckTask | MCMNHDLR.EXE | Part of McAfee's SecurityCenter and Virusscan Online. Must be enabled for scanning to work |
N | vspdfprsrv.exe | vspdfprsrv.exe | Visage PDF Printer |
Y | VsStatEXE | VSSTAT.EXE | From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs |
N | vTPass | vtpassld.exe | Part of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs, create your own shortcut for the "vtpass.exe" file |
U | VTPreset | VTPreset.exe | Savage Pro S3 graphics software |
U | VTTimer | VTTimer.exe | Driver file for the on-board VIA/S3G KM400/KN400 graphics which enables TV in/out communication |
N | vTunerStartUp | vTuner.exe | vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet" |
X | VVSN | VVSN.exe | SaveNow adware |
X | w32 | w32.exe | Added by the SOKEVEN TROJAN! |
X | W32.Scran | Scran.exe | Added by the NARCS WORM! |
X | w32alanis | mope.scr | Added by the SINALA WORM! |
X | W32Load | [random filename].scr | Added by the CASPID WORM! |
X | w32sup | w32sup.exe | Adult content dialler |
X | W32Tc | WTC32.scr | Added by the VOTE.D or VOTE.K WORMS! |
X | W3KNetwork | rundll32.exe w3knet.dll, dllinitrun | Advertising spyware. Check here for more info on this particular one |
Y | W75P2PSERVER | W75P2PS.EXE | Printer utility which is required in order to make the printer work correctly |
? | W815DM | W815DM.exe | ?? |
N | Wanadoo Messenger.exe | Wanadoo Messenger.exe | Wanadoo ISP instant messenger client |
Y | WanMPSvc | WanMPSvc.exe | An AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help |
X | WAPI | wts**.exe [* = random char] | PurityScan/Clickspring adware |
N | war-ftpd.exe | WAR-FTPD.EXE | War FTP Daemon from JGAA's Internet - FTP client |
X | Wardo | syslaunch.exe | Added by the ADLCICKER.G TROJAN! |
X | WareOut | WareOut.exe | Malware masquerading as a spyware and dialer remover, see here |
N | warez | warez.exe | Warez P2P client |
U | Warner | warner.exe | Also known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files |
U | Warnet | warnet.exe | Warnet - system cleanup software |
U | Warning: do not remove it! | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" |
N | WARSVR | war-ftpd.exe | "War FTP Daemon - the original free FTP server for windows" |
U | WashAndGo - Cleanup of old Backupfiles | checker.exe | WashAndGo - temp file cleaner |
U | Washer | washer.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
N | Washerie.exe | washerie.exe | Cookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs |
U | washindex | washidx.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
X | Wast | wast.exe | Grokster ads updater |
N | Watch | watch.exe | Found to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted |
? | Watch | 1200UBWATCH.EXE | ?? |
N | Watch Dog Program | watchdog.exe | For Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do |
N | Watchdog | Watchdog.exe | Definitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage |
? | WatchDog | watchdog.exe | Part of Motorola "Mobile Phone Tools" v3 - in a "Mobiile Phone Tools" sub-directory of Program Files |
N | WaveTop Launcher | WaveTop.exe | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
N | WaveTop Receiver 1 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
N | WaveTop Receiver 2 | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
N | WaveTop Upload Manager | N/A | WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98 |
N | Wbiff | Wbiff.exe | Wbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received |
? | Wbutton | Wbutton.exe | Related to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required? |
N | WCESCOMM | WCESCOMM.EXE | Active sync for use with Windows CE based palm PC |
U | wcmdmgr | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | wcmdmgr.exe | wcmdmgr.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
U | wcmdmgrl | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
U | WCOLOREAL | coloreal.exe | Makes colours sharper and brighter, but will only work with coloreal capable monitors |
? | WCPC | wintsvcc.exe | ?? |
X | WCPI | wintsvit.exe | PurityScan/Clickspring adware |
X | WCPS | Wint**.exe [* = random char] | PurityScan/Clickspring adware |
X | WCPT | wintsvtr.exe | PurityScan/Clickspring adware |
U | WD Button Manager | WDBtnMgr.exe | Button manager installed with a western digital external disk drive. Allows you to back up your system with one click |
X | WDInfo | wdinfo.exe | Added by the DLUCA.B TROJAN! |
X | wdskctl | wdskctl.exe | IEPlugin spyware |
X | wdwctrl | wdwctrl.exe | Added by the DLUCA.E TROJAN! |
N | WEATHER | WEATHER.EXE | Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs |
N | WeatherCast | Weather.exe | Weather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight |
X | WeatherOnTray | WeatherOnTray.exe | Hotbar's Weather Forecast tool for your desktop - adware |
N | WeatherWatcher | ww.exe | WeatherWatcher - weather reporting in the System Tray |
X | web | ******.exe [* = random char] | Added by a variant of the EASTO.A TROJAN! |
? | Web Search | ?? | ?? |
X | Web Service | [random filename].exe | Added by the ADMINCASH TROJAN! |
Y | web3trap | web3trap.exe | PC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc |
X | webalize | webalize.exe | Searchcentrix hijacker |
N | WebArmyKnife | WAK.exe | Web Army Knife - a suite of web site developer's tools |
X | webassist | webassist.exe | Adware popup generator |
? | Webcam Go Sti Service Application | wbcgosvc.exe | Control software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required? |
N | WebcamRT.exe | WEBCAMRT.exe | For Logitech Web Cams. Not required - camera works fine without it |
X | Webcelerator | webcel.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here |
X | WebCheck | WebCheck.pif | Added by the CONE.C or CONE.F WORMS! |
X | WebCpr0 | WebCpr0.exe | Web_CPR/TopMoxie adware |
X | Webdav.exe | webdav.exe | IRC DDoS bot which gives the hacker full control over your system |
X | WebHancer Agent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
X | webHancer Survey Companion | whSurvey.exe | WebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there |
X | WebInstall | WebInstall.exe | ClipGenie adware downloader |
X | WebInstall2 | WebInstall.exe | ClipGenie adware downloader |
N | WebKey | WebKey.exe | WebKey from JB Utilities. Utility to keep track of login data required when browsing the internet |
N | WebOutfitterTray | sttray.exe | Intel WebOutfitter service System Tray icon |
N | Webposition Gold 2 | wpsche~1.exe | Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines |
X | WebRebates0 | WebRebates0.exe | WebRebates adware |
X | WebRun | [Trojan filename] | Added by the ADWARELOADER TROJAN! |
U | websaverlive | websaverlive.exe | WebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle |
X | WebSavingsfromEbates | WebSavingsfromEbatesrun.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
X | WebSavingsFromEbates0 | WebSavingsFromEbates0.exe | Web Savings From Ebates Software, a shopping tool that opens pop-up windows |
X | WebScan | DEFSCANGUI.EXE | eAcceleration Stop-Sign related - not recommended, see note |
N | webscan | stopsignav.exe | eAcceleration Stop-Sign related - not recommended, see note |
Y | WebScanX | WebScanX.exe | From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc |
X | websearch | wjview ...websearch.exe | "Web Savings" From Ebates Software, a shopping tool that opens pop-up windows |
X | WebSecureAlert | WebSecureAlert.exe | WebSecureAlert. "Can help protect your browser security and privacy". However, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior |
? | WebServer | VBI_SE~1.EXE | Related to a Pinnacle sound card. What does it do and is it needed? |
N | Webshots | Webshots Tray.exe | Screensaver program that automatically downloads from the webshots web site |
N | Webshots | websho~1.exe | Screensaver program that automatically downloads from the webshots web site |
X | WebSpecials | rundll32 [path] webspec.dll | WebSpecials spyware |
X | Websx | Int*****.exe | Adult content dialler - where ***** are random |
Y | Webtrap | webtrap.exe | Part of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating |
Y | WebTrapNT.exe | WebTrapNT.exe | Part of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements |
U | WebWasher | wwasher.exe | Free Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs |
N | Welcome | Welcome.exe | Launches the Welcome to Windows tutorial on boot up |
? | WEPstat | Wepstat.exe | Cisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this? |
X | wersds | doriot.exe | Added by the JECT.C TROJAN! |
N | WetSock | wetsock.exe | RoboMagic Wetsock - weather reporting in the System Tray |
N | WFGStartup | WFGStartup.exe | World Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones" |
U | wfips | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
N | WFXCTL32.EXE | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
Y | wfxsnt40 | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax |
? | WFXSwtch | WFXSWTCH.exe | Related to WinFax. What does it do and is it required? |
Y | WG511WLU | WG511WLU.exe | Netgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card |
U | WGWLocalManager | WGWLocalManager.exe | Part of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system |
X | whagent | whagent.exe | System Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here |
U | WheelMouse | 4DMAIN.EXE | Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may provide |
U | WheelMouse | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features |
X | WhenUSave | Save.exe | SaveNow adware |
X | WhenUSearch | Search.exe | SaveNow adware |
X | WhenUSearchWHSE | whse.exe | SaveNow adware |
X | Whvlxd | Whvlxd.exe | Added by the W32.LXD.MIRC TROJAN! |
N | WIAWizardMenu | RUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam |
? | WildTangent CDA | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? |
U | WildTangent Web Driver updater | wcmdmgrl.exe | Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | Wildwire Monitor | WWMon.exe | This places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem |
N | Willow Road | WillowRoad.exe | Willow Road Screen Saver |
X | win | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
X | win | xwinxrpc32.exe | Added by the AGOBOT-MV WORM! |
X | win | xwinxrpc.exe | Added by the AGOBOT-MV WORM! |
U | Win Chimes | winchi~1.exe | WinChimes - enhancement software for the system clock that runs in the system tray |
X | Win Comm | WinComm.exe | WebRebates related adware |
X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
X | Win Command | command32.exe | Added by the AGOBOT.XQ WORM! |
X | WIN HOST PROCESS | WIN HOST PROCESS.EXE | Added by the KEYLOGGER.CLONE TROJAN! |
X | Win l5oahder | winampa.exe | Added by the SPYBOTER.GEN VIRUS! Not the valid Winamp Agent which uses the same filename. This resides in the System32 sub-folder wheras real one is located in the winamp folder |
? | win name | stat.exe | ?? |
X | Win Patch | ntldr.exe | Added by the SDBOT-GS WORM! |
X | Win Server | winserv.exe | Added by the IMISERV.A TROJAN! |
X | Win Server Updt | wupdt.exe | Added by the IMISERV.A TROJAN! |
X | win update | wupda32.exe | Added by the SDBOT.J WORM! |
X | WIN USB 2.0 | usbsystem.exe | Added by an unidentified WORM of TROJAN! |
X | Win USB 2.0 USB Driver | HPPrint.exe | Added by the SPYBOT.DNB WORM! |
X | WIN-BUGSFIX | WIN-BUGSFIX.EXE | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
X | win-xp | nvsc32.exe | Added by the BROPIA.N WORM! |
X | win-xp | winis.exe | Added by the BROPIA.N WORM! |
X | Win2Drv | [worm filename] | Added by the WINTOO WORM! |
X | WIN32 | WIN32.EXE | Added by the RATEGA TROJAN! |
X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | Added by the MYLIFE.N WORM! |
X | win32 | Setup_32.exe | Added by the EVILBOT.B TROJAN! |
X | Win32 | Win32.exe | Added by the ISRAZ.A WORM! |
X | win32 | winsrv32.exe | Added by the ADUENT TROJAN! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites |
X | win32 | WinSetup.exe | Added by the EVILBOT.B TROJAN! |
X | Win32 | system32.vbs | Added by the SWERUN VIRUS! |
X | Win32 | Game.exe.vbs | Added by the SCAFENE WORM! |
X | Win32 Configuration | videosd32.exe | Added by the SDBOT.TT WORM! |
X | Win32 Configuration | dllhelp.exe | Added by the SDBOT.UL WORM! |
X | WIN32 DDOSSER | dos.exe | Added by the KELVIR.F WORM! |
X | Win32 Device Loader | Win32ldr.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Win32 DRK Driver | wdrk32.exe | Added by the WOOTBOT.CY WORM! |
X | Win32 exe file | winstr32.exe | Added by a variant of the SPYBOT WORM! |
X | Win32 Explorer | Explorer32.exe | StartPa-MN homepage hijacker |
X | Win32 FRT Driver | msfr32.exe | Added by a variant of the FORBOT WORM! |
X | Win32 Kernel core component | Kernel32.pif | Added by the MOKS VIRUS! |
X | Win32 Ms Auto Updater | AutomsUPD.exe | Added by a variant of the RBOT WORM! |
X | Win32 Network Driver | crss.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Win32 NVIDIA Driver | MSPMSPSU.EXE | Added by a variant of the WOOTBOT.Y WORM! |
X | win32 regedit | msn32.exe | Added by an unidentified WORM or TROJAN! |
X | Win32 Rundll Loader | Rundll32.exe | Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:Windows directory. The version created by this virus is saved in the C:WindowsSystem directory |
X | Win32 Service | bazzi.exe | Added by the AHKER.E WORM! |
X | Win32 Services1 | wuamngr1.exe | Added by the SDBOT-PV WORM! |
X | Win32 Src Service | win32src.exe | Added by the RBOT-SX WORM! |
X | Win32 SSL Driver | winssv.exe | Added by the FORBOT-BH WORM! |
X | Win32 System Spool | spoolsvc.exe | Added by the SDBOT.UK WORM! |
X | Win32 USB Driver | winxpinit.exe | Added by the SDBOT.AA TROJAN! |
X | Win32 USB Driver | mvsecn.exe | Added by the FORBOT-BK WORM! |
X | Win32 Usb Driver | svhosint32.exe | Added by the FORBOT-BE or FORBOT-J WORMS! |
X | Win32 Usb Driver | usb32.exe | Added by the SDBOT-OV WORM! |
X | Win32 USB2 Driver | win32usb.exe | Added by the SPYBOT.DHV WORM! |
X | Win32 USB2 Driver | smsc.exe | Added by the SDBOT.FO WORM! |
X | Win32 USB2 Driver | svchosting.exe | Added by the FORBOT.J or SDBOT.HU WORM! |
X | Win32 USB2 Driver | sys32.exe | Added by the WOOTBOT.X WORM! |
X | Win32 USB2 Driver | sys32snd.exe | Added by the FORBOT-AN WORM! |
X | Win32 USB2 Driver | wind32.exe | Added by the FORBOT-AH WORM! |
X | Win32 USB2 Driver | winupdate.exe | Added by the AGOBOT.YE WORM! |
X | Win32 USB2 Driver | updatemgr.exe | Added by a variant of the FORBOT WORM! |
X | Win32 USB2 Driver | winsnd32.exe | Added by a variant of the SDBOT WORM! |
X | Win32 USB2.0 Driver | 386.exe | Added by the IRCBOT.D WORM! |
X | Win32 USB2.0 Driver | rundll16.exe | Added by the WOOTBOT.H WORM! |
X | Win32 USB2.0 Driver | w32usb2.exe | Added by the SPYBOT.DN WORM! |
X | Win32 USB2.0 Driver | service.exe | Added by the SDBOT-QF WORM! |
X | Win32 USB3 Driver | win32tool.exe | Added by a variant of the RBOT WORM! |
X | Win32 Wmls Driver | winitr32.exe | Added by the WOOTBOT.B WORM! |
X | win32.exe | win32.exe | Added by the STARTPAGE TROJAN! |
X | Win32BaseServiceMOD | Wintask.exe | Added by the NAVIDAD WORM! |
X | win32clf | win32clf.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Win32DLL | Win32DLL.vbs | Added by the LOVELETTER (I LOVE YOU) VIRUS! |
X | Win32dll | Win32dll.exe | Added by the BANPAES TROJAN! |
X | Win32G | Kernel32.com | Added by the ESTRELLA TROJAN! |
X | Win32G | Scandisk.com | Added by the ESTRELLA TROJAN |
X | win32gb | win32gb.exe | All-In-One-Telcom (adult content dialler) variant |
X | win32info | win32info.exe | Adult content dialler |
X | win32ini | systroy.exe | Added by the IRC.ALADINZ.C TROJAN! |
X | Win32R | Server.com | Added by the ESTRELLA TROJAN! |
Y | WIN32SL | Win32sl.exe | Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work |
X | WIN32SNDS | banc.exe | Added by an unidentified WORM or TROJAN! |
X | Win32system | [random filename] | Added by the DDV.B WORM! |
X | Win32System | win32s.exe | Added by the MYDOOM.V WORM! |
X | Win32SystemMonitor | ***.exe [* = random char] | Browser hijacker |
X | win32us | win32us.exe | All-In-One-Telcom (adult content dialler) variant |
X | win32usbd | ssrs.exe | Added by the RBOT-RA WORM! |
X | win32_i lptt01 | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | win32_i ml097e | win32_i.exe | Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | Win386 | Win386.exe | Added by the GOSUSUB VIRUS! |
X | Win386 | sp32.dll | Homepage hijacker. Not a dll but a regfile in disguise |
X | WIN3S2SNDS | winabsmod.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
X | WIN3S2SNDS | winiprtx.exe | Added by the AGENT.DN TROJAN - known to BOClean as "CWS/INDEX", "shuts down anything that wants to open and is used as a spam proxy as well" |
X | Win64 Compatibility Check | load win64.drv | CoolWebSearch parasite variant |
X | WinAC v4 | klsuicbn.exe | Added by the FORBOT-CS WORM! |
X | winactive | WINACTIVE.EXE | Active variant of LOP.com hijacker - see here |
X | WinActiveJ | WinActiveJ.exe | Added by the ROTARRAN VIRUS! |
X | Winad Client | Winad.exe | WinAd adware by eXact Advertising |
X | winadm | winadm.exe | Browser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN! |
X | Winahlp.exe | Winahlp.exe | Added by a variant of the VAGRNOCKER TROJAN! |
X | winallap | winallap.exe | Added by the DELF.E TROJAN! |
X | winallapu | winallapu.exe | Added by the DELF.E TROJAN! |
X | Winamp | winamp.hta | Hijacker - re-directing to adult content sites. Note - this isn't the real Winamp |
X | Winamp | winamp.exe | Added by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe) |
X | Winamp media player | winapa.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
U | Winampa | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
X | Winampa | winampa.exe | Added by the AGOBOT-GS WORM! |
X | Winampa Agent | WINAMPA.EXE | Added by the SPYBOT-BR WORM! Note - this is NOT the Winamp Media Player |
U | WinampAgent | WINAMPa.exe | Loads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs |
X | WinAmpAgent | Msexploren.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
X | WinAmpAgent | Shch.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
X | WinAmpAgent | svchst.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
X | WinAmpAgent | Winagent.exe | Added by the EB TROJAN! Note - this is not the popular WinAmp media player file |
X | WinApi | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
X | Winapp | winpup32.exe | Produces popup ads to adult content sites |
X | WinApp32 | msapp.exe | Added by the RSBOT TROJAN! |
X | WinAuth | winlogon.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the valid winlogon.exe process |
U | WinBackup Scheduler | Wbsched.exe | LIUtilities WinBackup scheduler - backup software |
U | WinBar | WinBar.exe | "WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls" |
X | winbas12 | winbas12.exe | Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du |
X | Winbed | winbed.exe | Hijacker |
X | WinCheck | WinCheck.exe | Added by the PWS-CY TROJAN! |
N | WINCINEMAMGR | WINCIN~1.EXE | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
N | WinCinemaMgr | WinCinemaMgr.exe | WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
X | WinCSRSS | MSGRT32.EXE | Added by the REWINDO-A TROJAN! |
X | wind.exe | wind.exe | Added by the MITGLIEDER.BD TROJAN! |
X | WIND0WS | WIND0WS.exe | Added by the SPYBOT.DQ WORM! |
X | WIND0WS | mella.bat | Added by the ALLEM WORM! |
N | WinDates | windates.exe | WinDates is a calendar, date organizer and event reminder program from Rockin' Software |
X | windbs | winxtc.exe | Added by the AGOBOT-WD WORM! |
X | Winde | winde.exe | Added by the DLUCA TROJAN! |
X | windef | Win32sp.vbs | Added by the ANPES WORM! |
X | windir | winrun.exe | Added by the WINBUR.B WORM! |
X | Windll | Windll.exe | Added by the TRYNOMA TROJAN! |
U | WINDLL | WSYS.EXE | STARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren't keyed in, all web sites visited, every program launched including the path to that program, and more" |
X | windll | windll32.exe | Added by the ASTEF or RESPAN WORMS! |
X | Windll.exe | Windll.exe | Added by the STEALER TROJAN! |
X | Windll32 | Windll32.exe | Added by the MSNPWS TROJAN! |
X | windllsys32.exe | windllsys32.exe | Added by a variant of the MITGLIEDER.BY TROJAN! |
X | WinDNS | windns32.exe | Added by the GAOBOT.WX WORM! |
X | Windoes Kernel | kernel32.exe | Added by the KICKIN.A (or CYDOG.C) WORM! |
X | Window | explore.exe | Added by the GAOBOT.ADW WORM! |
X | Window Loader | Dos32.exe | Added by the GAOBOT.AO WORM! |
X | Window Monitor | winmon32.exe | Added by the SDBOT.RT WORM! |
U | Window Washer | wwDisp.exe | Windows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
X | window.exe | window.exe | Added by the MITGLIEDER.H or MITGLIEDER.J TROJANS! |
X | window2 | ssvchost.exe | Added by the IRCBOT.H TROJAN! |
U | WindowBlinds | wbload.exe | WindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins |
X | WindowEnhancer | Winex.exe | SCbar foistware variant |
U | WindowFX | wfxload.exe | Stardock WindowFX - "Allows you to add an unprecedented number of special effects to windows" |
X | Windows | Kernel32.exe | Added by the TENDOOLF WORM! |
X | Windows | msdos98.exe | Added by the PWSTEAL TROJAN! |
X | Windows | Windows.exe | Added by the KAZMOR, BOBBINS & ALADINZ.D TROJANS! |
X | Windows | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | windows | [path to trojan] | Added by the AIMWIN TROJAN! |
X | windows | hkey.exe | Added by the GAOBOT.AFW WORM! |
X | windows | system copy.exe | Added by the SALGA.A WORM! |
X | Windows (random character) | diskcheck.exe | Added by the SINGU.B TROJAN! |
U | Windows Accelerators | setup.exe | KeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove |
X | Windows AdControl | WinAdCtl.exe | Windupdates adware variant |
X | Windows AdService | WinAdServ.exe | Windupdates adware variant |
X | Windows AdStatus | WinStat.exe | Windupdates adware variant |
X | Windows AdTools | WinAdTools.exe | Windupdates adware variant |
X | Windows Anti-Virus Built 32 | AntiVirus32.exe | Added by the SDBOT-BG WORM! |
X | windows auto update | penis32.exe | Added by the BLASTER (or MSBLAST.A) WORM! |
X | Windows Auto Update | winupdater.exe | Added by the SDBOT.TF WORM! |
X | windows auto update | msblast.exe | Added by the BLASTER.B WORM! |
X | Windows Automatic Update | wuamgrder.exe | Added by a variant of the RBOT WORM! |
X | Windows Automatic Updates | dvldr.exe | Added by the RBOT.MF WORM! |
X | windows automation | mslaugh.exe | Added by the BLASTER.E WORM! |
X | Windows Automation | msdspr.exe | Added by the SOLAME.A WORM! |
X | Windows backup | systemss.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Backup Configuration | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! |
X | Windows Baţlangýç Dosyasý | sistem.exe | Added by the MUZK WORM! |
X | Windows Communicator | wincomm.exe | Added by the AGOBOT-BH WORM! |
X | Windows Compliant | [random filename] | Added by the RBOT-IR WORM! |
X | Windows Config | SSYS.EXE | Added by the SPYBOT-DA WORM! |
X | Windows Config Loader | Wincfg32.exe | Added by the SILVERFTP TROJAN! |
X | Windows Configuration | wsys32.exe | Added by the GAOBOT.FB WORM! |
X | Windows Control | Control.exe | Browser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs! |
X | Windows ControlAd | WinCtlAd.exe | Windupdates adware variant |
X | Windows Data Server | autodisc.exe | Added by the SPYBOT-CB WORM! |
X | Windows Database | WinDat.exe | Added by an unidentified WORM or TROJAN! |
X | Windows Dcom2 Fix | mscom32.exe | Added by the RBOT-QT WORM! |
X | Windows debug logging | winlogg.exe | Added by the RBOT-OY WORM! |
X | Windows debug logging | winloggs.exe | Added by the RBOT-QN WORM! |
X | Windows Debugger | windbg.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Windows DLL Loader | RUNDLL16.EXE | Added by the DOMWIS TROJAN! |
X | Windows DLL Loader | defragfat32z.exe | Added by the LINKBOT.A WORM! |
X | Windows DLL Loader | rundll32.exe | Added by the WHIPSER-B WORM! Note - rundll32.exe file is placed in the WindowsSystem folder, wheras the legitimate rundll32.exe is located in the C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) |
X | Windows DLL Loader | defragfat32pi.exe | Added by the RBOT-QQ WORM! |
X | Windows DLL Loader | defragfat39.exe | Added by the POEBOT-C WORM! |
X | Windows DLL Loader | defragfatz.exe | Added by the LINKBOT.H WORM! |
X | Windows DNS Daemon | windnsd.exe | Added by the WOOTBOT.AS WORM! |
X | Windows Drive Compatibility | System32Driver32.exe | Added by the SUPOVA.Z WORM! |
X | Windows Driver Services | msdrvs32.exe | Added by the WOOTBOT.L WORM! |
X | Windows Explorer | [filename].exe | Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | Windows Explorer | Lsas.exe | Added by the GAOBOT.AO WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | Windows Explorer | olecom32.exe | Added by an unidentified WORM or TROJAN! |
X | Windows Explorer | EEXPLORER.EXE | Added by a variant of the SPYBOT WORM! |
X | Windows Explorer Shell | Winexec32.exe | Added by the REDIST.B WORM! |
X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | Added by the KaZaA based KWBOT or KWBOT.Y WORMS! |
X | Windows Explorer-3212 | WINRE16.EXE | Added by the HARDOC WORM! |
N | Windows Eyes | ?? | For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs |
X | Windows File Protection | winprotect.exe | Added by the AGOBOT.JB WORM! |
X | Windows Firewall Manager | msfw.exe | Added by the RBOT.WR WORM! |
X | Windows Fix | integator.exe | Added by the SDBOT.ZAB WORM! |
X | Windows FormatAd | WinForm.exe | Windupdates adware variant |
X | Windows Graphics Loaders | wingraphics.exe | Added by the SPYBOT.JG WORM! |
U | Windows Guardian | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
U | Windows Guardian | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes |
X | Windows Help File | winhelper32.exe | Added by the SDBOT-QK TROJAN! |
X | Windows Help Manager | svchost32.exe | Added by the RBOT-OZ WORM! |
X | Windows Help Service | winhelpsv.exe | Added by the RBOT-LP WORM! |
? | Windows Help System | Help.pif | ?? |
X | Windows Host Device | hostsvc.exe | Added by the ZOOTY-A WORM! |
X | Windows HTML file reader | Sysconf32.exe | Added by the NOOMY.A WORM! |
X | Windows Internet Protocol | winproc32.exe | CoolWebSearch parasite variant |
X | Windows JavaScript Daemon | Winjsd.exe | Added by the WOOTBOT.AF WORM! |
? | Windows Load | windows.com | ?? |
X | Windows Loader | wstart32.exe | Added by the GAOBOT.CA WORM! |
X | Windows Loader Service | civsc.exe | Added by a variant of the RBOT WORM! |
X | Windows logging | winlogd.exe | Added by the RBOT-ON WORM! |
X | Windows Login | explored.exe | Added by the GAOBOT.SY WORM! |
X | Windows Logon | winlogin.exe | Added by the SPYBOT-C TROJAN! |
X | Windows Logon Procedure | Svchoste.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Logon Procedure | Svchosta.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Management Instrumentation | mwd.exe | Added by the GRAPS WORM! |
X | Windows Manager | winmants.exe | Added by the MANTAS WORM! |
X | Windows mangement | winlogonn.exe | Added by the RANDEX.FC WORM! |
X | Windows Media Player | wmediaplayer.exe | Added by the AGOBOT-NQ WORM! |
X | Windows Media Player | MediaPIayer.exe | Added by the SDBOT-QO TROJAN! - note, the executable is called 'MediapIayer', with an 'i' !) |
X | Windows Media Player | [random filename] | Added by a variant of the RBOT WORM! |
X | Windows Media Player | msa.exe | Added by the RBOT-SI WORM! |
X | Windows Media Player | mcafe32.exe | Added by a variant of the SDBOT WORM! |
X | Windows Media Player | wmplayer.exe | Added by the SPYBOT WORM! Note - this is not the valid Windows Media Player as the executeable resides is C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K) or C:WindowsSystem32 (WinXP) rather than C:Program FilesWindows Media Player |
X | Windows Media Player Update | [random filename] | Added by the RBOT-ET WORM! |
N | Windows Media Powerpoint Helper | NSPPTHLP.EXE | German software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs |
X | Windows media service | crvss.exe | Added by the SDBOT.VP WORM! |
X | Windows media service | crsss.exe | Added by the RBOT.ACY WORM! |
X | Windows media services | cvrsss.exe | Added by the RBOT-MW WORM! |
X | Windows Media SP.2.37 | [random filename] | Added by the LEMIR.C TROJAN! |
X | Windows MeTaLRoCk service | metalrock.exe | Added by the TASTYRED TROJAN! |
X | Windows Monitor | winmon.exe | Added by the SDBOT.VB WORM! |
X | Windows Monitoring Service | winmon.exe | Added by a variant of the SDBOT WORM! |
X | Windows Nets | WinNET.exe | Added by the RBOT-MO WORM! |
X | Windows Network Controller | Mqguard.exe | Added by the FORBOT-CL WORM! |
X | Windows Network Controller | WinxPupd.exe | Added by the FORBOT-DK WORM! |
X | Windows Network Controller | winmms32.exe | Added by the FORBOT-ED WORM! |
X | Windows Network Service | winvc32.exe | Added by the RBOT.RY WORM! |
X | Windows Networking | winsys32.exe | Added by the GAOBOT.FL WORM! |
X | Windows Nivedia Driver | sysMGT.exe | Added by a variant of the RBOT WORM! |
X | Windows NNT | [path to trojan] | Added by the RANKY.E TROJAN! |
X | Windows NT 32 | ntlogin32.exe | Added by the RANDEX.BRD WORM! |
X | Windows NT Login | ntlogin32.exe | Added by the SDBOT.WG WORM! |
X | Windows NT Service Name | winshock.exe | Added by the RBOT-PK WORM! |
X | Windows NT Update Manager | WINL0G0N.exe | Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o" |
X | Windows OEM Tools | winres32.exe | Added by the SPYBOT.FD WORM! |
X | Windows OLE Automation Server | ole32aut.vbe | CoolWebSearch parasite related browser hijacker |
X | Windows Online Updater | dllman.exe | Added by the RBOT-TE WORM! |
? | Windows Print Spooler | SCVHOSTS.EXE | Suspicious due to the similarity to the valid "svchost.exe" file |
X | Windows Print Spooler | NavAgent32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Windows Print Spooler | SVEHOST.EXE | Added by the SPYBOT.H WORM! |
X | Windows Registry | msnmsg.exe | Added by a variant of the RBOT WORM! |
X | Windows Registry Cleaner | winclean.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Registry Express Loader | regexpress.exe | Added by the FORBOT-CJ WORM! |
X | Windows Registry Scan | regscan32.exe | Added by the RBOT.KE WORM! |
X | Windows Registry Scan | timeupdate.exe | Added by the SPYBOT.JE WORM! |
X | Windows Registry Security | crss.exe | Added by a variant of the IRC.BOT TROJAN! |
X | Windows Registry Startup | wind32.exe | Added by the AGOBOT-BZ WORM! |
X | Windows report | swchost.exe | Added by the SMALL-BD TROJAN! |
X | Windows Runtime Help | win32hlp.exe | Added by a variant of the AIMVISION TROJAN! |
X | Windows Runtime Help | WinRunHelp.wrh | Added by a variant of the AIMVISION TROJAN! |
X | Windows SA | omniscient.exe | BLAZEFIND adware |
X | Windows secure | setver32.exe | Added by the SPYBOT.EP WORM! |
X | Windows Secure Messaging System | msnmsgrsrvc.exe | Added by the RBOT-RE WORM! |
X | Windows Security Assistant | rundll32.vbe | CoolWebSearch parasite variant |
X | Windows Security Assistant | winsec.exe | CoolWebSearch parasite variant |
X | Windows Security Module | module.exe | Added by a variant of the RBOT WORM! |
X | Windows ServeAd | WinServAd.exe | Windupdates adware variant |
X | Windows service | wuamgrd.exe | Added by the RBOT-QW WORM! |
X | Windows Service | dddd.exe | Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans |
X | Windows Service | prvdi.exe | Malware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd |
X | Windows Service Host | scvhost.exe | Added by the SDBOT.N TROJAN! |
X | Windows Service Host | svchost.exe | Added by the CONE.B WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Windows Service Pack Auto Update | winworks.exe | Adware downloader, identified by eScan antivirus as Trojan-Clicker.Agent.bt |
X | Windows Services | service.exe | Added by the RANDEX.R WORM! |
X | Windows Services | svchosts.exe | Added by the AGOBOT-KL TROJAN! |
X | Windows Services Host | svchost.exe | Added by the CONE or CONE.E WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Windows Services Update | svch0st.exe | Added by a variant of the RBOT WORM! |
? | Windows shell | win70.exe | ?? |
X | Windows Shell Library Loader | load shell.dll /c /set | CoolWebSearch parasite variant |
X | windows shellext.32 | mschost.exe | Added by the BLASTER.K WORM! |
X | Windows Smart Manager | smart.exe | Added by the RBOT-SL WORM! |
X | Windows Sound Driver | SndMon32.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Sound Manager | SndMon32.exe | Added by the FORBOT-BU WORM! |
X | Windows SP2 Update | Sp2update.exe | Added by the WOOTBOT.BS WORM! |
X | Windows Spooler | SPOOLSRV.EXE | Added by the SPYBOT.P WORM! |
X | Windows SSL File | winssv.exe | Added by the WOOTBOT.CA WORM! |
X | Windows Startup | winsta~1.exe | GoHip foistware |
X | Windows Startup | winstartup.exe | GoHip foistware |
X | Windows Startup | Wdrun32.exe | Added by the GAOBOT.AO WORM! |
X | Windows Startup | services21.exe | Added by the AGOBOT-MX WORM! |
X | Windows Startup 32 Bits | sysrun32.exe | Added by a variant of the DARKSUN TROJAN! |
X | Windows Streams Server | localsrv.exe | Added by the SDBOT.LN WORM! |
X | Windows SyncroAd | SyncroAd.exe | Windupdates adware variant |
X | Windows System Configuration | SYSCFG16.EXE | Added by the WISDOOR.Z TROJAN! |
X | Windows System File | cmxp.exe | Added by the SPYBOT.KHO WORM! |
X | Windows System Manager | winsystem.exe | Added by the RBOT-AN WORM! |
X | Windows System Manager Proc | winsmc.exe | Added by the RBOT.JH WORM! |
X | Windows System Restore Configuration | Sblhost.exe | Added by a variant of the SPYBOT WORM! |
X | Windows System Restorer | SystemRestorer.exe | Added by the DULOAD.C WORM! |
X | Windows System Security | winmp.exe | Added by the RBOT.IV WORM! |
X | Windows System Serivce | winserv.exe | Added by a variant of the RBOT WORM! |
X | windows system service | winsock.exe | Added by the RBOT-MR WORM! |
U | Windows System Tray | msni.exe | Iambigbrother monitoring software |
X | Windows System Tray | swhost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Windows Task Manager | ACCOUNT_DETAILS.DOC.exe | Added by the QUATERS.A WORM! |
X | Windows Task Manager | taskmgn.exe | Unidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install |
X | Windows Task Manager Emulator | kennewr.exe | Added by the SPYBOT-FA WORM! |
X | Windows TaskAd | Wintaskad.exe | Windupdates adware variant |
X | Windows Taskbar Manager | internat.exe | Added by the PROTORIDE-H WORM! |
X | Windows Taskbar Manager | [path to file] | Added by the PROTORIDE.B WORM! |
X | Windows Taskbar System | tasksys.exe | Added by a variant of the SDBOT WORM! |
X | Windows Taskmanager | lsassx.exe | Added by the KELVIR.E WORM! |
X | Windows TCP/IP | wintcp.exe | Added by the AGOBOT-ZH WORM! |
X | Windows Telnet Server | wintel.exe | Added by the AGOBOT-MW WORM! |
X | Windows Time Server | TimeSRV.exe | Added by the SPYBOT.DNC WORM! |
X | Windows Upate | rundll.exe | Added by the HAKO TROJAN! Note - this is NOT the Windows system file of the same name as described here |
X | Windows Update | [filename] | Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites |
X | Windows Update | iexplorere.exe | Added by the GAOBOT.AP WORM! |
X | windows update | uddater.exe | Added by the LEOX TROJAN! |
X | Windows Update | wudate.exe | Added by the AGOBOT.ML WORM! |
X | Windows Update | wupdate.exe | Wengs adware |
X | windows update | sychost.exe | Added by the LEOX.B WORM! |
X | Windows Update | Wuamgrd.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Update | inetinf.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Windows Update | host32.exe | Added by the RBOT-GU WORM! |
X | windows update | wuraclt.exe | Added by the RBOT-PO WORM! |
X | windows update | Wuanclt.exe | Added by the RBOT.XZ WORM! |
X | Windows Update | ebay.exe | Added by the GAOBOT.BUU WORM! |
X | Windows Update | windows.exe | Added by the RBOT-RB WORM! |
X | windows update | wuaurlt.exe | Added by the RBOT.ADG WORM! |
X | Windows Update | Update.exe | Added by the DELF-FN TROJAN! |
X | Windows Update | winmguard.exe | Added by the RBOT-EM WORM! |
X | Windows Update | wuampd.exe | Added by the RBOT.UM WORM! |
X | windows update | wuarclt.exe | Added by the RBOT-OF WORM! |
X | Windows Update AutoUpdate Client Product | wuauct.exe | Added by the AGOBOT.ACL WORM! |
X | Windows Update Checker | [random filename] | Adware downloader trojan |
X | Windows Update Client | wuclient.exe | Added by the SMALL-RN TROJAN! |
X | Windows Update Client Service | windrvl32.exe | Added by the AGOBOT-MM TROJAN! |
X | Windows update config | svhost.exe | Added by the SDBOT-PF WORM! |
X | windows update configurator | svghost.exe | Added by a variant of the SPYBOT WORM! |
X | Windows Update Files | dnetc.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update |
X | Windows Update Manager | wupdmngr.exe | Added by the RANDEX.BTB WORM! |
X | Windows Update Manager | Winlog0n.exe | Added by the AGENT-BO TROJAN! |
X | Windows Update Manager for NT | wupdmgr32.exe | Added by the SDBOT.AH WORM! |
X | Windows Update Monitoring Service | winupdt.exe | Added by the RBOT-PL WORM! |
X | Windows Update Process | wmiprvsc.exe | Added by the SDBOT-CB WORM! |
X | Windows Update Service | csrs.exe | Added by the AGOBOT-NI WORM! |
X | Windows Update Service | smcg.exe | Added by the SDBOT.QY WORM! |
X | Windows Update Service 2004/2005 | systemupdate.exe | Added by the RBOT-JE WORM! |
X | Windows Update V6 | [random filename] | Added by the RBOT-KT WORM! |
X | Windows Update.exe | N/A | Homepage hijacker, see here |
X | Windows Updater | wupdmgr32.exe | Added by a variant of the DOS.AUTOCAT TROJAN! |
N | Windows Version Check | ver_chk.exe | Version checker for CyberAudioLibrary ("A new way to exchange information through the Internet") |
X | Windows video | vide_32.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
X | Windows Video Acquisition (WVA) | wvsvc.exe | Added by the AGOBOT.YM WORM! |
X | Windows Video Drivers | videons32.exe | Added by the GAOBOT.AZT WORM! |
X | Windows-System | System32.exe | Added by the LOGPOLE.C WORM! |
X | Windows-TCP-IP | rfkampig.exe | Added by the GIPMA TROJAN! |
X | Windows32 | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! |
X | Windows32 Messenger Service | msmsgv.exe | Added by the RBOT.ANS WORM! |
X | WindowsAgent | WindowsAgent.exe | Added by the GOP.G WORM! |
X | WindowsAPI.DLL | Server5.exe | Added by the "Fear and Hope" TROJAN! |
X | WindowsBackup | WINDOWSBACKUP.EXE | Added by the STANG WORM! |
X | WindowsCriticalUpdate | windows_critical_update.exe | Added by the ASTEF or RESPAN WORMS! |
X | WindowsKeyUpdate | master.exe | Added by the JOSAM WORM! |
X | WindowsMGM | Winmgm32.exe | Added by the SOBIG WORM and LALA.C TROJAN! |
X | WindowsReg% update | [random filename].exe | Added by the RBOT-HH WORM! |
X | WindowsRegistration | [random filename] | Added by the RBOT-NO WORM! |
X | WindowsRegKey Autoupdate | [random filename] | Added by a variant of the RBOT WORM! |
X | WindowsRegKey upd4te2d4te | *********.exe [* = random char] | Added by the RBOT.XQ WORM! |
X | WindowsRegKey update | [random filename] | Added by a variant of the RBOT WORM! |
X | WindowsRegKey update | winupdate.exe | Added by the RBOT-QJ WORM! |
X | WindowsRegKey update | windns.exe | Added by the RBOT.IE WORM! |
X | WindowsRegKey%$ update | msi332.exe | Added by the RBOT-IX WORM! |
X | WindowsRegKey%update | ethernet32m.exe | Added by the RBOT-EN WORM! |
X | WindowsRegKeys update | winsysi.exe | Added by the SDBOT.WE WORM! |
X | WindowsSetup | [path to trojan] | Added by the EZBOT TROJAN! |
X | WindowsUpd | WindowsUpd4.exe | VirtuMonde adware |
X | WindowsUpd1 | WindowsUpd1.exe | VirtuMonde adware |
X | WindowsUpd2 | WindowsUpd2.exe | VirtuMonde adware |
X | WindowsUpdate | windows_update.exe | Added by the LOFNI WORM! |
X | WindowsUpdate | svchost.exe | Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | windowsupdate | RPCX1sQ3.exe | Added by the IRCBOT.B TROJAN! |
X | WindowsUpdate | USRINIT.EXE | Added by the MADDIS.B WORM! |
X | WindowsUpdate Service | wuautlc.exe | Added by the RBOT-NR WORM! |
X | WindowsXP Module | DirectX3D.exe | Malware, reportedly a keylogger - see here |
X | WindowsXP Update | windowsxpupdate.exe | Added by the RBOT-PB WORM! |
X | WindowsXPserv | svcnxp32.exe | Addee by the NANINF-A TROJAN! |
X | Windows_Serivce | SERVICE.exe | Added by the WOOTBOT.AH WORM! |
X | Windows_Updates | svthost.exe | Added by a variant of the SPYBOT WORM! |
X | Windows_VXD | user32.exe | Added by the PWSTEAL.PPORT TROJAN! |
X | Windowz Update V2.0 | Explorer.exe | Added by the YODO WORM! Note - the valid "explorer.exe" is located in C:Windows or C:Winnt whereas this one is located in the System32 sub-directory |
X | WinDriv32 | WinDriv32.exe | Added by the SMALL-BA TROJAN! |
X | WinDriver Configuration | windrvconf.exe | Added by the AGOBOT-LX TROJAN! |
X | windrv | windrv32.exe | Added by an unidentified VIRUS, WORM or TROJAN! - possibly a strain of OBLIVION or BIONET |
X | WinDrv | windrvx.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
U | WinDSL MTU-Adjust | WinDSL_MTU.exe | Adjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung |
? | WinDSL_MTU | WinDSL_MTU.exe | May be realted to Tiscali broadband, if so is it required? |
X | WinDSNX | Win????.exe | Added by the DNSX TROJAN! |
X | WindUpdates | [path to trojan] | Added by the AGENT.BF TROJAN! |
X | WindUpdates | WinUpdt.exe | Windupdates adware variant |
U | WINDVDpatch | CTHELPER.EXE | CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it |
N | WinDVR SchSvr | SchSvr.exe | WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
N | WinDVRCtrl | WinDVRCtrl.exe | Control center software for an AOpen VA1000 TV tuner card |
X | Windws Configuration Loader | LEXPLORE.exe | Added by the SODABOT WORM! |
X | WinEssential | Keyhost.exe | Hijacker - hailing from jraun.com |
X | WinEssential | keyword.exe | Jraun.com hijacker |
X | WinExec | Winexec.exe.vbs | Added by the AINESEY.A WORM! |
X | WinExec32 | WinExec32.exe | Added by the KAZWIN WORM! |
U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler |
U | Winfast2KLoadDefault | Rundll32.exe Wf2kcpl.dll, DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
U | Winfast_2K | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
U | WinFast_Gamma | Rundll32.exe wfcpl.dll, DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards |
U | WinFast_Taskbar | rundll32.exe wftask.dll, WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards |
X | WinFavorites | WinFavorites.exe1 | Loudmarketing.com adware downloader |
N | WinFax PRO Controller | WFXCTL32.EXE | From WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs |
Y | WinFaxAppPortStarter | wfxsnt40.exe | WinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application. |
X | winfont | winfont.exe | Added by the DEATH TROJAN! |
U | WinFoxV2 | WF2k.exe | System Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card |
X | WinFX | cssrs.exe | Added by the AGOBOT.FX WORM! |
X | WinGate | WinGate.exe | Added by a variant of the LOVGATE WORM! |
U | WinGate Engine Monitor | wgengmon.exe | WinGate Internet Client Dialup Monitor - component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server |
X | WinGate initialize | WinGate.exe | Added by a variant of the LOVGATE WORM! |
X | wingo | wingo.exe | Added by the BEAGLE.AW or BEAGLE.AV WORMS! |
X | wingo | [various filenames] | Added by the BAGLE-AU WORM! |
N | WinGuage Pro | WGPRO32.EXE | Part of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs |
Y | Winguard | WGFE95.EXE | Dr Solomon's Virex antivirus |
U | WinGuard Pro | wgp.exe | Winguard Pro |
N | WinHacker | rundll32.exe wh95.dll, HackMe | Tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free |
X | Winhelp | winhe1p.exe | Added by the QQPASS.E TROJAN! |
X | WinHelp | WinHelp.exe | Added by a variant of the LOVGATE WORM! Note - "winhelp.exe" resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) whereas the valid "winhelp.exe" resides in C:Windows or C:Winnt |
X | WinHelp | realsched.exe | Added by a variant of the LOVGATE WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
X | Winhelp | TkBellExe.exe... | Added by a variant of the LOVGATE WORM! |
X | winhlp.exe | winhlp.exe | Added by the FORMGLIEDER TROJAN! |
X | winhlp3.exe | winhlp3.exe | Added by a variant of the EASTO.A TROJAN! |
X | Winhlp32 | Wscript.exe ..Msexec32.vbs | Added by the GANT.B WORM! |
X | winhlp32.exe | winhlp32.exe | Added by a variant of the EASTO.A TROJAN! |
X | winhlpp32.exe | winhlpp32.exe | Added by the GAOBOT.SY WORM! |
X | Winhost | wintt.exe | Added by the LOLAWEB.B TROJAN! |
X | Winhost | win.exe | Added by the DLOADER-AP TROJAN! |
X | winhost32.exe | winhost32.exe | Added by the TABDIM TROJAN! |
X | wininet32 | wininet32.exe | Added by the RAZNEW-A TROJAN! |
X | wininetd | wininetd.exe | Added by the WINET TROJAN! |
X | wininit | wininit.exe | Added by the WOLLF.16 TROJAN! |
X | winis | winis.exe | Added by the RBOT-WI WORM! |
X | Wink*.exe | Wink*.exe [* = random char] | Added by a variant of the KLEZ WORM! |
U | Winkb6 | winkb6.exe | Part of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed |
X | WinKernel | WinKer.exe | Added by the MIRAB or SERVIDOR TROJANS! |
X | WinKernel | [path to worm] | Added by the PLEA VIRUS! |
X | winkernel32 | wWin32.com | Added by the BANSAP TROJAN! |
U | WinKey | winkey.exe | Loads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos |
X | winlibs.exe | winlibs.exe | Added by the EVAMAN.C WORM! |
X | WinLibUpdate | libupdate.exe | Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310 |
X | WinLibUpdate32 | libupdate32.exe | Added by the BIONET.405 TROJAN! |
X | WinLibUpdte | libupdte.exe | Added by the BIONET.318 TROJAN! |
X | Winlink | winlink32.exe | Added by the GAOBOT.AAY WORM! |
X | Winlme | windll.exe | Added by the GOP.F WORM! |
X | WinLoader | [random filename] | Added by variants of the SUBSEVEN TROJAN! |
X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related |
X | WinLogin | winlogin.exe | Added by the AGOBOT-IX WORM! |
X | Winlogin.exe | log.exe | Added by a variant of the AGENT.AH downloader TROJAN! |
X | winlogin.exe | logfile.exe | Added by the AGENT.AH TROJAN! |
X | winlogin.exe | mspaint.exe | Added by a variant of the AGENT.AH TROJAN! |
X | Winlogin.exe | steam.exe | Added by a variant of the AGENT.AH TROJAN! |
Y | winlogon | winlogon.exe | Windows Logon Process - handles user logons described here |
X | winlogon | winlogon.exe | Hijacker or adult content dialler - file is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate Windows Logon (winlogon.exe) process |
X | winlogon | winlogin.exe | Added by the RANDEX.E WORM! |
X | winlogon | winlogon.exe | Added by the TRODAL TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! File is located in C:Windows or C:Winnt, and not in it's System or System32 subdirectory |
X | winlogon | msreg32.exe | Added by the SDBOT.EO WORM! |
X | winlogon service | urx.exe | Added by the SPYBOT.EN WORM! |
X | Winlogon Shell | Explorer.exe svchost.exe | Added by the KIPIS.M WORM! |
X | Winlogon.exe | N/A | CoolWebSearch parasite related - resets home page to an adult material site |
X | WinLsass | servicec.exe | Added by the SCANE WORM! |
X | WinLsass | [path to trojan] | Added by the SCANE WORM! |
X | winltmpv | winln.exe | Added by the TCXMEDI-C TROJAN! |
X | winltmpv | wutop.exe | Added by the TCXMEDI-C TROJAN! |
X | Winmain | winmain.exe | One of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled! |
? | WinManager | schost.exe | ?? |
U | winmatrix.exe | WinMatrixXP.exe | WinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop |
U | WinMem | WinMem.exe | WinMem Cleaner - part of Ultra WinCleaner Utility Suite. Makes more memory available for your programs and the Operating System. It also defragments your system |
X | WinMenssage | winmax.exe | Added by the BANCOS.B TROJAN! |
N | WinMgmt | WinMgmt.exe | Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here |
X | Winmgr.exe | scvhost.exe | Added by the AGOBOT.AFG WORM! |
X | WinMgr32 | winmgr32.exe | Added by the MIMAIL.P WORM! |
X | WinMine | D4NG3.vbs | Added by the BISCUIT.A WORM! |
Y | winmodem | wmexe.exe | Software for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
X | WinMsrv32 | WinMsrv32.exe | Added by the GAOBOT.AFJ WORM! |
N | WinMX | WinMX.exe | WinMX file sharing application |
N | winmysqladmin | winmysqladmin.exe | Starts the MySQL database admin tool |
N | WinMySQLadmin Tool | winmysqladmin.exe | Starts the MySQL database admin tool |
X | winnet | winnet.exe | CommonName Toolbar spyware. To uninstall see here |
X | WinNetDDE | [random characters].exe | Added by the NETDEPIX.B TROJAN! |
? | Winnov Menu | WnvMenu.Exe | Winnov Video Capture Card related. What does it do and is it required? |
? | Winnov Remote | WnvRsvr.Exe | Winnov Video Capture Card related. What does it do and is it required? |
? | Winnov Status | WvStatus.Exe | Winnov Video Capture Card related. What does it do and is it required? |
X | WinNtBB | WinntBB.exe | Added by the DULOAD.C WORM! |
X | Winnup | win32nls.exe | Added by a variant of the SPYBOT WORM! |
X | winocx32 | winocx32.exe | Added by the PROTORIDE.I WORM! |
X | Winpack | winpack.exe | Adware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg |
U | WinPatrol | WinPatrol.exe | WinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs" |
X | winphonics7536 | vbsystem35.exe setups.exe vb.vb | Added by a variant of the MUTIN-C TROJAN! |
X | winpipe | winpipe.exe | Browser hijacker redirecting to wow-access.com |
Y | WinPoet | WinPPPoverEthernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
N | WinPopup | WINPOPUP.EXE | Intranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won't set itself up to run unless the user specifically adds it to startup |
X | winpopup | winupie.exe | Adware by Tradeexit.com |
X | WinProfile | Command.exe | Added by the BUDDY TROJAN! |
X | WinProfile | sndcfg16.exe | Added by the SNDC.A WORM! |
X | WinProt | Winprot.exe | Added by the CHUPACABRA TROJAN! |
X | WinProt | server.exe | Added by the CHUPACABRA TROJAN! |
X | winprotect | win32.exe | Added by the MUGLY.E WORM! |
U | WinProxy | WinProxy.EXE | "WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP" |
X | winpsd | winpsd.exe | Added by the MYDOOM.Q WORM! |
X | winrar | winrar.exe | CoolWebSearch parasite variant. Note - this is not the file zipping utility also known as WinRAR and it's located in C:Winnt or C:Windows |
X | winrarshell | winrarshell32.exe | Added by the SALIRA TROJAN! |
X | winReg | winReg.exe | Added by the YAHA.H or YAHA.J WORMS! |
X | winregsrv | winregsrv.exe | Added by the SYNRG TROJAN! |
X | Winres32vis | [path to worm] | Added by the THRAX.A WORM! |
N | winroute | winroute.exe | Win-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k |
X | winrun | msconfig.exe | Added by the WINUR.A WORM! Note - this is not the real msconfig.exe as it's located in C:winrun |
X | winrun | winrun.exe | Added by the WINBUR.B WORM! |
X | WinRunners | WinDrivers.exe | Added by the DULOAD.C WORM! |
X | Wins32 Online | cfgpwnz.exe | Added by the BROPIA.R WORM! |
X | WinSec | winsec16.exe | Added by the AGOBOT.ZF WORM! |
X | winsecure | winsecure.exe | Browser hijacker, redirecting to specificsearches.com |
X | WinSecured32 | ssmr.exe | Added by a variant of the FORBOT WORM! |
X | Winserv | Winserv.ila | Added by the NODMIN WORM! |
X | winserver | Server.txt.vbs | Added by the DELTAD.A WORM! |
U | WinService32 | ssmgr.exe | 007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP" |
X | WinServices | WinServices.exe | Added by the YAHA.K or YAHA.M WORMS! |
X | winservn | winservn.exe | PurityScan/Clickspring adware |
X | winservs | winservs.exe | PurityScan/Clickspring adware |
X | WinSetBrowse | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! |
? | Winshoe | wuadfdqr.exe | Probably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed |
X | winshost.exe | winshost.exe | Added by the TOOSO or TOOSO.B or TOOSO.C or TOOSO.D WORMS! |
X | WinShowUpdate | copy C:WINDOWSwinshow.new C:WINDOWSwinshow.dll | Winshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version |
X | WinSig | NetXP.exe | Added by the BANKER-FN TROJAN! |
X | winsock | svch0st.exe | Added by the SAGE-A WORM! |
X | winsock2 | netsvr.exe | Added by the AGOBOT.LY WORM! |
X | Winsock2 driver | SDJOIJE.EXE | Added by the SPYBOT.DR TROJAN! |
X | Winsock2 driver | MIRC32.exe | Added by the SPYBUZZ TROJAN! |
X | Winsock2 driver | kgzgjkpcw.exe | Added by the SDBOT.T TROJAN! |
X | Winsock2 driver | ZONEALARM.EXE | Added by the SDBOT.T TROJAN! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program |
X | Winsock2 driver | WINCFG.SCR | Added by a variant of the SPYBOT WORM! |
X | Winsock2 driver | winupdate.exe | Added by the SPYBOT-BX WORM! |
X | Winsock2 driver | SPOLSV.EXE | Added by the SPYBOT-CM WORM! |
X | Winsock2 driver | Zonealarmupdate.exe | Added by a variant of the SPYBOT WORM! |
X | Winsock2.dll | WINLODR.SCR | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Winsock32 driver | Testing.exe | Added by the SPYBOT.B WORM! |
X | Winsock32 driver | lcd.exe | Added by the SPYBOT.B WORM! |
X | Winsock32 driver | Sdjoije.exe | Added by the SPYBOT.B WORM! |
X | Winsock32driver | win32server.scr | Added by the HACARMY TROJAN! |
X | Winsock32driver | sp2XPupdate.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | Winsock32driver | win32server.exe | Added by the BACKDOOR-AZV TROJAN! |
X | Winsock32driver | ZoneAlarmPr0.exe | Added by the HACKARMY-B TROJAN! |
X | Winsock32driver | ZoneLockup.exe | Added by the HACARMY.D TROJAN! |
X | Winsock32driver | win32server.exe | Added by the HACARMY.F TROJAN! |
X | Winsock32driver | winXPupdate.exe | Added by the HACKARMY.9728 TROJAN! |
X | winsockdriver | tskmg.exe | Added by the SDBOT.GEN TROJAN or WARPIGS.C WORM! |
X | winsockdriver | winsock2.2.exe | Added by a variant of the SPYBOT WORM! |
X | winsockdriver | iexplor.exe | Added by the BLATIC.A WORM! |
X | WinSocketComponent | nthost.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
X | WinSPF | windrv32.exe | Added by the MYDOOM.T WORM! |
X | WinSPF | winspf32.exe | Added by the MYDOOM.S WORM! |
X | Winspl | winsplx.exe | Added by a variant of the TROLL-A TROJAN! |
X | Winspool | spoolsvr.exe | Added by a variant of the SDBOT WORM! |
X | WinSrv | kn0x.exe | Added by the HOBBIT.F WORM! |
X | WinSrv | SHIZZLE.EXE | Added by the HOBBIT.C WORM! |
X | Winsrv | winsrv.exe | Added by the OPASERV.T WORM! |
X | WinStart | WinStart.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
X | WinStart | Wscript.exe WinStart.vbs | Added by the CIAN.C WORM! |
X | WinStart | winstart32.exe | Added by the PUROL WORM! |
X | WinStart | WinStart.pif | Added by the CONE.E WORM! |
X | WinStart001 | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
X | WinStart001.EXE | WinStart001.exe | From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge |
X | Winsta~1 | winsta~1.exe | GoHip foistware |
X | WinSth16 | WinSth16.exe | Added by the CAKE WORM! |
X | winstro | RUN32DLL.exe | Added by the FTP_ANA TROJAN! |
X | WinSvc16.exe | WinSvc16.exe | Added by the SDBOT.FQ TROJAN! |
X | Winsvc32 | Winsvc32.exe | Homepage hijacker |
U | Winsys | Winsys.exe | Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
X | WINSYS | [path to trojan] | Added by the GOLDPLAY TROJAN! |
X | WinSys32 | Winsys32.exe | Added by the CIGIVIP TROJAN or RECKUS WORM! |
X | winsys32 Driver | winsys32.exe | Added by the LOONY-O TROJAN! |
U | WinSysAppMon | WinSysRM.exe | Home & Family Content Filter related. See here |
X | winsyslog lptt01 | winsyslog.exe | Variant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | WinSysStartUpWKbLw | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! |
X | WinSyst32 | winsyst32.exe | Added by the MORB WORM! |
X | WinSystem | winsystem.exe | Added by the WHITEBAIT WORM! |
X | Winsystem | winsystem.exe | Added by the BANCOS.CR TROJAN! |
X | winsystem.sys | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
X | WINT | wcp****.exe [* = random char] | PurityScan/Clickspring adware |
X | WINT | wcpcc.exe | PurityScan/Clickspring adware |
X | WINT | wcpsvit.exe | PurityScan/Clickspring adware |
X | WinTask | Wintask.exe | Added by the HIPO or LEMIR.F TROJANS! |
X | WINTASK | taskgmr.exe | Added by the MYTOB.I WORM! |
X | WinTask driver | wintask.exe | Added by the SMALL.ABD downloader TROJAN! |
U | WinTasks Traybar | wintasks.exe | WinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before" |
X | wintasks.exe | wintasks.exe | Added by the EVAMAN WORM! |
N | Wintercooler Pro | WINCOOL.EXE | Wintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed |
N | WinTidy | WinTidy.exe | Desktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs |
X | Wintime | Wintime.exe | Added by the HARNIG TROJAN! |
N | Wintime Wtxpload | Wxpload.exe Wintime | Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG" |
X | WinTools | WToolsA.exe | Wintools adware |
N | WinTOTAL Scheduler | guru.exe | WinTOTAL Real estate appraisal software related |
X | WinTray | wintray.exe | Added by the LEGUARDIEN.B TROJAN! |
X | winupated.exe | winupated.exe | Added by a variant of the SDBOT WORM! |
X | winupd | RUNDLL32.EXE [random value].dll, _mainRD | Added by the MOTA.A WORM! |
X | winupd.exe | winupd.exe | Added by the BEAGLE.M or BEAGLE.N WORMS! |
X | WinUPD32 | explorer.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually |
X | winupdat | winupdat.exe | Added by the CANBOT.A WORM! |
X | WinUpdate | RBSKQQBO.EXE | Added by the VBSWG2B.A WORM! |
X | WinUpdate | wmbem.exe | Added by the REVCUSS.B TROJAN! |
X | WinUpdate Loader | msnnm.exe | Added by the REVCUSS.C TROJAN! |
X | winupdate.exe | winupdate.exe | Added by the RADO TROJAN! |
X | winupdate.reg | winupdate.exe | Added by the SPYBOT.EAS WORM! |
X | winupdate2846 | vbsystem35.exe msvbrun.exe | Added by a variant of the MUTIN-C TROJAN! |
U | WinUpdateProtection | csrss.exe | ICE Remote Spy monitoring software, "secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you." Note - this file is installed in a C:WindowsupdateUfpIrs7 folder |
X | winupdate_ | [path to file] | Added by the CONDOR.A WORM! |
X | winupdt | RUNDLL32.EXE [random.dll] | Added by the MABUT.A WORM! |
X | winupdtl | winupdtl.exe | SecondThought adware variant |
X | winur | winrun.exe | Added by the WINBUR.B WORM! |
X | winusb.dll | winguard.exe | Added by the FORBOT-CN WORM! |
X | Winux Piriax Service | PH32.EXE | Added by the RANDEX.G WORM! |
X | winversion | winversion.exe | Browser hijacker, redirecting to specificsearches.com |
U | WinVNC | WinVNC.exe | WinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet |
X | WinVNC | iexplorer.exe | Added by the EVIVINC VIRUS! |
X | winwan lptt01 | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | winwan ml097e | winwan.exe | Variant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | winXP | 33.exe | Added by the ANPES WORM! |
X | WinXP | plugin1.exe | Added by the Downloader-JW TROJAN! |
X | WinXP fix | [path to file] | Added by the RANKY.P TROJAN! |
X | winxpdll32.exe | winxpdll32.exe | Added by a variant of the SMALL downloader TROJAN! |
X | WinXPHome | plugin2.exe | Added by the malicious INOR.T script! |
U | WinXPLoad | Rundll32 LoadDll, LoadExe WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys |
X | winzip | [path to trojan] | Added by the BANCOS.G or BANCOS.K TROJANS! |
N | WinZip Quick Pick | WZQKPICK.EXE | Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up |
X | Win_api_driver | system.exe | Added by the REVIRD TROJAN! |
X | Win_Library | INISvc.exe | Added by the ANARCH WORM! |
X | win_spool2 | win_spool2.exe | Added by the SCKEYLOG.B TROJAN! |
X | win_upd.exe | WINdirect.exe | Added by the MITGLIEDER.M TROJAN! |
X | win_upd2.exe | WINdirect.exe | Added by the BEAGLE.AO WORM! |
X | Win_vader | Win_vader.vbs | Added by the INVASION.A VIRUS! |
X | WIP Config GUI | Winipcfgs.exe | Added by the RBOT-CN WORM! |
U | Wireless PCI Card Configuration Utility | WMP11Cfg.exe | Utility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
X | Wireless Provider Server | wpsvr.exe | Added by the FORBOT-AD WORM! |
U | Wireless-G Notebook Adapter Utility | WPC54CFG.EXE | Utility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G) |
N | wjview | wjview.exe | MS tool used to view window-based Java applications from the command line |
N | wkcalrem | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
N | WkDetect | WkDetect.exe | Checks for updates to MS Works |
N | wkfud | wkfud.exe | A marketing program for MS Works |
N | WksSb | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file |
N | WkUFind | WkUFind.exe | MS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site |
X | Wlan Drier | Winusb2.exe | Added by the WOOTBOT.DC WORM! |
X | Wlan Driver | avscan.exe | Added by the WOOTBOT.DH WORM! |
N | WLAN Status Tray Applet | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN |
N | WLANSTA.EXE | WLANSTA.EXE | System Tray icon for checking the status of a Wireless LAN |
Y | WLAN_Cfg.exe | WLAN_Cfg.exe | Linksys Instant Wireless USB Network Adapter driver |
X | wm41a398 | rundll32.exe [path] wm41a398.dll, EnableRunDLL32 | LZIO.com adware downloader |
X | WMAudio | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | WMAudio | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
N | WMBoot | N/A | Associated with Logitech Wingman game controllers. Not required but what does it do? |
U | WMIEXE.exe | wmiexe.exe | NT component, used by Windows Millennium to detect Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading |
X | Wminf | Wminf.exe | Added by the GEMA TROJAN! |
X | Wminfo | Wminfo.exe | Added by the GEMA TROJAN! |
X | wmiprv | wmiprv.exe | Added by the RBOT-WM WORM! |
Y | WMP54Gv4 | WMP54Gv4.exe | Linksys WMP54G Wireless-G PCI Adapter driver |
X | wmsys32 | wmsys32.exe | Added by the BANPAES.B TROJAN! |
? | WM_LOGIN | MSGLOGIN.EXE | Part of McAfee Firewall. What is it for and is it needed? |
X | WNAD | WNAD.EXE | Spyware added as a result of running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like |
X | WNSC | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
X | WNSI | wnscp**.exe [* = random char] | PurityScan/Clickspring adware |
X | WNST | wns*****.exe [* = random char] | PurityScan/Clickspring adware |
N | WooCnxMon | CnxMon.exe | Wanadoo ISP software related - not required - here's how to bypass it |
N | Woowatch | Watch.exe | Wanadoo ISP software, not required |
N | WordWeb | wweb32.exe | WordWeb - free theasaurus and dictionary. Start manually |
? | Workflo | workflow.exe | Related to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required? |
N | Works Calendar Reminder | wkcalrem.exe | Produces a pop-up reminder of events scheduled using the MS Works Calendar |
N | WorksFUD | wkfud.exe | A marketing program for MS Works |
U | Workstation Scheduler | wm95.exe | Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog |
X | Workstation Services | wrkstn.exe | Added by the RBOT-OJ WORM! |
U | Worm Detector | wd.exe | Worm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam |
X | wormexe | winstart.exe | Added by the EARLYBIRD WORM! |
X | wovax | wovax.exe | Added by the DAQA.A TROJAN! |
N | Wpctrl | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
N | Wpctrl | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
N | wpctrl95 | wpctrlnt.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
N | wpctrl95 | wpctrl95.exe | WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties |
Y | WPCycle.exe | WpCycleWin.exe | Added when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing) |
X | wpds.exe | doriot.exe | Added by the SMALL-KY TROJAN! |
X | WQK | WQK.exe | Added by a variant of the KLEZ WORM! |
? | wr | WR.EXE | ?? |
? | WR Command | wr.exe | ?? |
N | WrCtrl | WrCtrl.exe | Win-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time |
X | WRDialer | WrDialer.exe | WinPoet DSL dialler |
? | WRECK GUARD | ?? | ?? |
? | WregBios | wregbios.exe | Desktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required? |
U | wrexec | wrexec.exe | Watch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online |
? | wriste | wriste.exe | ?? |
X | ws2help | ws2help.exe | Added by a variant of the SMALL.AN TROJAN! |
X | WSAConfiguration | wmon32.exe | Added by the GAOBOT.BAJ WORM! |
X | WSAConfiguration | svchostt.exe | Added by the AGOBOT.ZT WORM! |
X | WSAConfiguration | rpcxmn32.exe | Added by the AGOBOT.ABG WORM! |
X | WSAConfiguration | win32upd.exe | Added by a variant of the RBOT WORM! |
X | WSAConfiguration1 | csass.exe | Added by the AGOBOT.WH WORM! |
? | wsbklite | wsbklite.exe | Related to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required? |
U | WScheduler | WScheduler.exe | Windows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events." |
X | wscript.exe | vabian.vbs | Added by the VABI VIRUS! |
X | Wsdata service | WSconf.exe | Added by the SDBOT.ZU WORM! |
X | wserver | wserver.exe | Added by the NETSKY.AC or SASSER.G WORMS! |
U | WService | WService.exe | Tablet client Driver for UC-Logic Pen/Graphics Tablet |
X | WSSAConfiguration | wmmon32.exe | Added by the AGOBOT-KC WORM! |
X | Wstat32 driver | Wstat32.exe | Added by the LOONBOT TROJAN! |
Y | wstimeb | wstimeb.exe | Used with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it |
Y | wswpd | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work |
N | WT Game Channel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | WT Game Channel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | WT GameChannel | GameChannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
N | WT GameChannel | wtgamechannel.exe | WildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
U | WTIndicator | SchedInd.exe | WinTask - software that automates a variety of routine tasks quickly and simply |
X | WTSI | wapisvit.exe | PurityScan/Clickspring adware |
X | WTSS | wap***.exe [* = random char] | PurityScan/Clickspring adware |
X | WTST | wapisvtr.exe | PurityScan/Clickspring adware |
Y | WUOLService | WUOLService9x.exe | Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN) |
X | WUPD | iglmtray.exe | Added by the TZET WORM! |
X | wupdt | wupdt.exe | Added by the IMISERV.A TROJAN! |
Y | WUSB11B.exe | WUSB11B.exe | Linksys WUSB11 WLAN USB adapter |
Y | WUSB54Gv4 | WUSB54Gv4.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
? | WUx_RegSvr | RegSvr32.exe | x is any number?? |
X | wvsvc | wvsvc.exe | Added by the AGOBOT.YM WORM! |
X | www.hidro.4t.com | enbiei.exe | Added by the BLASTER.F WORM! |
X | www.symantec.com | oz11111.exe | Added by the MYDOOM.W WORM |
X | Wxp4 | Norton Update.exe | Added by the ERKEZ.D WORM! |
N | WXProcMgr Module | WXprocMgr.exe | TVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system |
X | wzhelper | wzhelper.exe | Searchcentrix hijacker |
X | wzservice | hess.exe | Added by the HACKARMY.W TROJAN! |
U | X Server | X.exe | "XoftWare for Windows" enables you to run network-based UNIX programs ("X programs" or "clients") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a network |
U | X-Cleaner Deluxe | xcleaner.exe | X-Cleaner Deluxe - privacy and anti-spy application |
N | X-Grabber | sswizard.exe | ScreenShot Wizard |
X | X10Weax | WTHRTRAY.EXE | WeatherCheck - "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller |
U | x3watch | x3watch.exe | "program helping with online integrity. Whenever you browse the internet and accesses a site which may contain questionable material, the program will save the site name on your computer. Approximately every 30 days, a person of your choice (an accountabiltiy partner) will receive an e-mail containing all possible questionable sites you may have visited within the month. This information is meant to encourage an open and honest conversation between friends and help us all be more accountable" |
X | x3yy | [path to trojan] | Added by the TANNICK TROJAN! |
N | Xanadu | Xanadu.exe | Xanadu - free language and translation wizard from Foreignword |
? | xBrotherMeCom | BrMeCom.exe | Related to Brother MFC-9200c printer. What does it do and is it required? |
X | Xcpy1 | Xcpy1.exe | BroadcastPC adware variant |
U | XE 8x LM Status | lmsxxe.exe | Xerox XE8 series laser printer status monitor |
X | Xecuter.bat | psexec.bat | Added by the BOOHOO WORM! |
N | XemiCo | ADC.EXE | XemiComputers Active Desktop Calendar |
N | Xfire | Xfire.exe | Terratec DMXFire 1024 soundcard control panel |
X | xftpGraber | Xftpgraber.exe | Added by the ENVID.C WORM! |
? | xicon | xicon.exe | Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required? |
X | XiD | mmx.exe | Added by the ANALOGX TROJAN! |
Y | XircWinModem4 | ltcm000c.exe | WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
U | xitami | Xiwin32.exe | Xitami Multiplatform Open Source web server |
? | xkstartup | RunDll32 InstZ82.dll, SetUsbPrinterPort | On a system with a Lexmark printer |
X | xload32 | netdd.exe | Added by the NETSPY TROJAN! |
X | XML Service | msxml.exe | Added by the RBOT-HD WORM! |
X | XNSearchAssistant | SrchAsst.exe | iWon Search Assistant - spyware |
X | xor | svchost.exe | Added by the XORDOOR TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | xp service pack 2 | xpsp2.exe | Added by the RBOT-KW WORM! |
? | Xpagent | xpagent.exe | Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required? |
? | xpcfg | xpcfg.exe | ?? |
? | Xpclient | xpclient.exe | Part of the IBM/XPoint Rapid Restore utility. What does it do and is it required? |
U | xPlanetControl | xPlanetControl.exe | Tool that displays a globe with current day/night zones and clouds on users desktop. |
X | XPSoft | CVDAsDW.exe | Added by the SDBOT-SY WORM! |
X | XPSP2 Firewall | xpsp2fw.exe | Added by the SMALL-RN TROJAN! |
X | xpsystem | y.exe | CoolWebSearch parasite variant |
X | Xpsystem | SERVICES.EXE | Added by the DAEMOZ.A TROJAN! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup! |
X | xpsystem | services.exe | CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | xpsystem | MSXMIDI.EXE | CoolWebSearch parasite variant, identified by Kaspersky_antivirus as TrojanDropper.Win32.Small.cw |
X | xp_system | services.exe | Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
X | xp_system | winlogon.exe | Added by the KREPPER-G TROJAN! - a CoolWebSearch parasite variant. Note - this is NOT the legitimate winlogon.exe process, which should NOT figure in Msconfig/Startup! |
U | XStop95 | XStop95.exe | XStop - internet filter |
N | xswin | xswin.exe | Installed with a Xerox Work Centre Pro 555. Unchecking it removes an "out of system memory" error |
? | XTCsgloader | XTCsgloader.exe | Another Xupiter toolbar variant?? |
U | XTNDConnect PC - 3CmPlm | Autodet.exe | Component of EasySync Pro. Synchronisation between Palm PDAs and Microsoft Outlook |
U | XTNDConnect PC - ErPhn2 | ErPhn2.exe | Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook |
U | XTNDConnect PC - ErTray | ErTray.exe | Component of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook |
U | XTNDConnect PC - LtNts4 | NtsAgnt.exe | Component of EasySync Pro |
X | Xtray | xtray_link.exe | Added by the VB.JL TROJAN! |
U | XtreamLok License Manager | xl.exe | License manager for xLok (XtreamLok) - prevents software being reverse engineered |
X | XTServiceUpdate | XTServiceUpdate.exe | hahame.net adware downloader |
X | XtTb.exe | XtTb.exe | Top-banners.com adware |
? | xuio.exe | xuio.exe | ?? |
X | Xupiter Startup | XupiterStartup.exe | Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here |
X | XupiterCfgLoader | XTCfgLoader.exe | Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here |
X | XupiterCfgLoader | BWCfgLoader.exe | Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here |
X | xupiterstartup2003 | xupiterstartup2003.exe | Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here |
X | XupiterToolbarLoader | XupiterToolbarLoader.exe | Xupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here |
U | xv_ctrl | v_ctrl.exe | 3dfx Underground Tools - "Gives direct hardware control to your video graphics adapter" |
? | XWMSUSBAPI | XWMSAPI.EXE | Part of the installation of a Xerox WorkCentre printer/scanner. Is it required? |
X | XXXmpeg | XXXmpeg.exe | Adult content dialler |
X | xxxvideo | xxxvideo.exe | AccessPlugin premium rate adult content dialler |
U | Y!TunnelPro | YTunnelPro.exe | Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia |
U | Y!TunnelPro | YTPro.exe | Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia |
X | yahoo groups | upgrdmgr.exe | Added by a variant of the RBOT WORM! |
? | Yahoo HP Reminder 1.1 | yr.exe | ?? |
X | Yahoo Instant Messengar | YahooMsgr.exe | Added by the SDBOT.GEN TROJAN! |
X | Yahoo Messenger | Yahoomsg.exe | Added by an unidentified WORM or TROJAN! |
X | Yahoo Messenger | YPager.exe | Added by the RBOT-QO WORM! |
X | Yahoo Update | Yahoo.exe | Added by the YAHOO! TROJAN! |
N | Yahoo! Pager | ypager.exe | Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs |
X | YahooStock | Prmvr.exe | Adtomi adware |
X | YahooStock | ystckAO32.exe | Adtomi adware |
X | yahoo_toolbar lptt01 | yahoo_toolbar.exe | Variant of the RapidBlaster parasite (in a "yahoo_toolbar" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
X | yahoo_toolbar ml097e | yahoo_toolbar.exe | Variant of the RapidBlaster parasite (in a "yahoo_toolbar" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
N | YAMAHA DS-XG Launcher | dslaunch.exe | System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups |
N | Yankee Clipper III | YankClip.exe | Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar "Outlook" interface'. Freeware |
N | YBrowser | ybrwicon.exe | SBC Yahoo! Browser system tray icon |
X | yeahdude.exe | hallowelt.exe | Added by the GAOBOT.RS or GAOBOT.SA WORMS! |
U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures® Screensaver |
? | YOW tuner | WatchPNM.exe | ?? |
N | ypager | ypager.exe | Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs |
U | YPC | ypc.exe | Yahoo Parental controls - "Let you decide what type of sites and Yahoo! services your kids can access" |
Y | YTrayMagic Lite 1 | YTRAYMAGIC.EXE | YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored |
X | ywzizdon | ywzizdon.exe | Free_Scratch_Cards foistware |
X | yyyyyyyy | [path to trojan] | Added by the MUMUBOY.B TROJAN! |
X | yz.exe | yz.exe | Added by the VARDO TROJAN! |
X | YZH.SYS | YZH.exe | Added by the SOPHILY VIRUS! |
U | z-WrDialer | WrDialer.exe | WinPoet DSL dialer |
X | ZaCker | [filename].PIF | Added by the HOLAR.A WORM! |
X | Zacker | Zacker.exe | Added by the GEMEL WORM! |
X | zango | zango.exe | 180Solutions/N-Case adware variant |
Y | Zapro | Zapro.exe | Firewall program from Zonelabs - paid for version |
U | zBrowser Launcher | iTouch.exe | For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
U | zBrowser Launcher | Commandr.exe | For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
? | zcb | zcb.exe | ?? |
X | zcproo | qssstiej.exe | Possible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguise. see this thread |
N | zdnet | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
N | Zebus | msdc32.exe | Runs a HTML tutorial on the Zebus web-site |
X | Zen.A | [path to trojan] | Added by the ZOOMEN-A TROJAN! |
X | Zenet | rundll32 CNBabe.dll, DllStartup | CommonName Toolbar spyware. To uninstall see here |
Y | ZENRC | zenrc32.exe | The main component of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Leave well alone |
Y | ZENRC Tray Icon | zentray.exe | Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Best left alone |
Y | ZENworks Imaging Service | ZISWin.exe | Imaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management" |
U | ZeroAds | 0 | ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually |
U | ZeroAds | LAS0Ads.exe | ZeroAds - culls ads, cookies and pop-ups. Required for the cookie interception to work |
U | ZeroSpyware | ZeroSpyware.exe | FBM Software ZeroSpyware 2004 spyware detector and remover |
X | zervpack2 | update2.exe | Added by the SDBOT.WD WORM! |
? | ZGNUBI | ZGNUBI.exe | ?? |
X | ZIBMACC | rundll.exe ZIBMACC.INF | ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435) |
U | ZingSpooler | ZingSpooler.exe | Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums |
N | Zinio DLM | ZDLM.EXE | Zinio - used to read magazines in digital rather than paper format |
X | Zip Driver Loader | ZipLoader32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
X | Zip Driver Loader | msload32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
U | ZipDisk Icons | IMGICON.EXE | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
N | ZipGenius Clean | zg.exe | ZipGenius file compression utility |
X | ziphelp | ziphelp.exe | CoolWebSearch parasite related |
N | ZipMagic | zm32.exe | Zip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first |
Y | zlclient | zlclient.exe | Firewall program from Zonelabs. Pro version inlcudes other online security options |
U | ZLH | ZLH.EXE | System Tray icon for Norman Antivirus |
X | Zonavirus | 0 | Added by the KITRO.D (or ARGEN.A) WORM! |
X | Zone Alarm | vsmon.exe | Added by the RBOT.BO WORM! If this was the ZoneAlarm firewall the name column would be TrueVector |
Y | Zone Labs Client | zlclient.exe | Firewall program from Zonelabs. Pro version inlcudes other online security options |
X | Zone Labs Client Ex | svchost.exe | Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
X | Zone system | szchost.exe | Added by the MULTIDR-AC TROJAN! |
Y | ZoneAlarm | zonealarm.exe | Firewall program from Zonelabs - free version |
X | zonealarm | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! The only exception is if you have an older version of the ZoneAlarm firewall running |
X | Zonealarm | Removeme.exe | Added by the FORBOT-BG WORM! |
Y | ZoneAlarm Plus | zaplus.exe | Firewall program from Zonelabs - paid for version |
Y | ZoneAlarm Pro | Zapro.exe | Firewall program from Zonelabs - paid for version |
U | Zoom | zoom.exe | Zoom - speeds up Windows startup and manages startup applications |
? | ZoomingHook | ZoomingHook.exe | Related to the Toshiba Zooming Utility for Tablet PC. What does it do and is it required? |
Y | ZPOINT32 | ZPOINT32.exe | USB graphics/writing tablet driver |
X | zSearch | Zstb.exe | TotalVelocity zSearch parasite |
U | zSPGuard | Spguard.exe | "StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'." |
X | ZtgServerSwitch | server.vbs | ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware |
X | Zupdate | Zupdate.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents |
X | zzb | zzb.exe | IAGold adware downloader |
X | zzb | zzb.exe | IAGold adware downloader |
X | zzgshp | gshp.vbs | Homepage hi-jacker that re-defines your IE or Netscape start page |
X | zztp | svchost.exe | Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
? | zzz-hpi-boot | hpi-boot.exe | Associated with HP Photosmart printers |
? | zzzCamlnSuitelll | setup.exe 46*** | ?? |
? | zzzhpsetup | setup.exe | ?? |
X | [default] | DrWatson32.exe | Added by the DREMN TROJAN! |
X | [Ephemeral 2.x] by TreeHugger, | [path to worm] | Added by the LEMOOR.A WORM! where "x" represents 3 or 4 |
X | [executed file name] | App.exe | Added by the WAXPOW WORM! |
X | [executed file name] | Regsrv32.com | Added by the SOUTHGHOST WORM! |
X | [random 12 digit number] | avifile5.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | bootvid4.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | browser8.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | atitvo32.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | autodisc.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | cabview1.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | advpack1.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | batmeter.exe | Adsrv.com/IeDriver adware variant |
X | [random 12 digit number] | bidispl2.exe | Adsrv.com/IeDriver adware variant |
X | [random name] | Svchosts.exe | Added by the SDBOT.N TROJAN! |
X | [random name] | wincpu.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
N | [System Mechanic Professional Update [Incinerator.dll] | REREG: [path] Incinerator.dll | System_Mechanic's "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again |
X | [various names] | elf.exe | Elf is a hacker program, tied to a trojan server |
X | [various names] | crsrs.exe | Added by the FORBOT-AK WORM! |
X | [various names] | Windows32.exe | Added by any of a number of WORM or TROJAN variants |
X | [various names] | bling.exe | Added by the RBOT-NI WORM! |
X | [various names] | mediaplayer32.exe | Added by a variant of the RBOT WORM! |
X | [various names] | winlogon32.exe | Added by an unidentified WORM or TROJAN! |
X | [various names] | svchostss.exe | Added by a variant of the RBOT WORM! |
X | [various names] | win32snd.exe | Added by the RBOT-DQ WORM! |
X | [various names] | shch.exe | Premium rate adult content dialler |
X | [various names] | PasswdMon.exe | TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here |
X | [various names] | runload32.exe | TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here |
X | [] | spolsvr2.exe | Added by the EVILSOCK.10 TROJAN! |
X | [] | iexpl0res.exe | Added by an unidentified WORM or TROJAN! |
X | [] | winbas12.exe | Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du |
X | \IEService.exe | IEService.exe | FastFind parasite variant |
X | \Pribi.exe | Pribi.exe | FastFind parasite variant |
X | ^`d}qZxu | ~`d}qzxu3zYF | Added by the GAOBOT.GEN!POLY WORM! |
U | _AntiSpyware | MssCli.exe | McAfee AntiSpyware |
X | _Hazafibb | [path to file] | Added by the ZAFI.B WORM! |
X | _svchost.con | svchost.com | Added by the ERKEZ.C WORM! |
U | _winadm | winadm.exe | Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC" |
X | _winsystem.sys | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
X | _x-Finder | _x-Finder.exe | Disconnects and redials an ISP modem to an adult content site |
U | {0228e555-4f9c-4e35-a3ec-b109a192b4c2} | gnotify.exe | Google Gmail_notifier. Alerts you when you have new Gmail messages |
X | {12EE7A5E-0674-42f9-A76B-000000004D00} | rundll32.exe [path] stlb2.dll, DllRunMain | BrowserAid/Startium parasite |
X | {2CF0B992-5EEB-4143-99C0-5297EF71F444} | rundll32.exe stlbdist.dll, DllRunMain | BrowserAid/Startium parasite |
X | {2CF0B992-5EEB-4143-99C2-5297EF71F44B} | rundll32.exe stlbupdt.DLL, DllRunMain | BrowserAid/Startium parasite |
X | {357AA41A-B7A8-4632-A27D-5B980B25CF43} | [path to svchost.exe] | Added by the SMALL-AQ TROJAN! |
X | ®Windows Update | svchosts.exe | Added by the FRUCTA TROJAN! |
Presentation, format & comments Copyright © Paul Collins, 2001 - 2005
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein
Software support by John Mayer
All rights reserved