| |
Name/Startup Item |
Command |
Comments |
| X | | system32.exe | Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | pathex.exe | Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | svchost.exe | Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
| X | | MSPF.EXE | Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.exe | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.dll | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | dllvirtual.js | Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
| X | | ajsha5.exe | Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field |
| X | | ne.exe | Added by the IRCBOT-ZL TROJAN! |
| X | SystemBoot | services.exe | Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
| X | WinCheck | services.exe | Added by the SOBER-S WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "ConnectionStatusMicrosoft" subfolder of the Windows or Winnt folder |
| X | Windows | services.exe | Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
| X | WinStart | services.exe | Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder |
| X | winsystem.sys | smss.exe | Added by the SOBER.K TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder |
| Y | !1_pgaccount | pgaccount.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
| Y | !1_ProcessGuard_Startup | procguard.exe | DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
| U | !AVG Anti-Spyware | avgas.exe | Part of AVG Anti-Spyware from Grisoft |
| U | !ewido | ewido.exe | Part of Ewido anti-spyware |
| N | !NoLoad | winrecon.exe | WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
| ? | $EnterNet | Enternet.exe | Connection manager for the EnterNet ISP. You can also use RASPPOE |
| X | $sys$cmp | $sys$xp.exe | Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
| X | $sys$crash | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$crash | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$crash | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$drv | $sys$drv.exe | Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
| X | $sys$momomomochin | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$momomomochin | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$momomomochin | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$sonyTimer.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$sos$sys$.exe | Added by the WELOMOCH TROJAN! |
| X | $sys$umaiyo | $sys$WeLoveMcCOL.exe | Added by the WELOMOCH TROJAN! |
| U | $Volumouse$ | volumouse.exe | Volumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse" |
| X | $WindowsRegKey%update | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
| N | %cmpmixtitle% | %cmpmixstr% | Possibly related to C-Media Mixer Control panel? |
| N | %FP%012-L2TP fts.exe | fts.exe | 012.Net.il Israeli ISP software front-end |
| U | %FP%012-L2TP FWPortal.exe | FWPortal.exe | 012.Net.il Israeli ISP dial-up software |
| N | %FP%1776 Internet fts.exe | fts.exe | 1776 Internet US ISP software ISP software front-end |
| U | %FP%1776 Internet FWPortal.exe | FWPortal.exe | 1776 Internet US ISP dial-up software |
| N | %FP%AIRTEL fts.exe | fts.exe | Bharti Airtel Broadband - Indian ISP software front-end |
| N | %FP%Barak013 fts.exe | fts.exe | Barak013 Israeli ISP software front-end |
| U | %FP%Barak013 FWPortal.exe | FWPortal.exe | Barak013 Israeli ISP dial-up software |
| N | %FP%Friendly fts.exe | fts.exe | Friendly ISP software front-end |
| U | µTorrent | utorrent.exe | µTorrent - BitTorrent client for Windows sporting a very small footprint. It was designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients |
| X | (*)API Machine | winSOCKS.exe | Homepage hijacker, see here (* = any digit) |
| X | (*)Run | win32API.exe | Homepage hijacker, see here (* = any digit) |
| X | (default) | [random filename].exe | Added by the BLACKMAL WORM! Note - this malware actually changes the default value data of the registry "Run" key in order to force Windows to launch it at boot. Name field may be empty |
| X | (default) | rundll32.exe [path to DLL file], Do98Work | Added by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | (Default) | 5640.exe | Added by the DOWNLD-ABF TROJAN! |
| X | (L4r1$$4) (4nt1) (V1ruz) | SP00Lsv32.pif | Added by the ASSIRAL.B WORM! |
| X | *Bandook | msdll.exe | Added by an unidentified TROJAN - see here |
| X | *JanisRuckenbrodII | janis.com | Added by the POPS WORM! |
| X | *Microsoft Update | ctxma.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | cxma.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wstcl.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wucxt.exe | Added by the STMU TROJAN! |
| X | *Microsoft Update | wuytc.exe | Added by the STMU TROJAN! |
| X | *MS Setup | [random filename] | Virtumondo adware, also known as the VUNDO TROJAN! |
| X | *MSConfig32 | aecache.exe | Detected by F-secure as the OBFUSCATED.GP TROJAN! |
| X | *Security Center | secctr.exe | Added by the SDBOT.BRO WORM! |
| Y | *StateMgr | statemgr.exe | Windows ME default for System Restore. Do NOT disable! |
| X | *windows update | wrauclt.exe | Added by the RBOT-QU WORM! |
| X | *windows update | wuanclt.exe | Added by the RBOT-PG WORM! |
| X | *windows update | wuaucrlt.exe | Added by the SPYBOT.HUR WORM! |
| X | *windows update | wuraclt.exe | Added by the RBOT-PO WORM! |
| X | *windows update | wurauclt.exe | Added by the RBOT-SY WORM! |
| X | *windows update | wsctl.exe | Added by the SPYBOT.PR WORM! |
| X | *windows update | wkmst.exe | Added by the SDBOT.AVD WORM! |
| X | *windows update | wscxt.exe | Added by the RBOT.AOS WORM! |
| X | *windows update | waurclt.exe | Added by a variant of the RBOT WORM! |
| X | *Windows [filename] Checker | [filename] | Added by the KEDEBE-B WORM! |
| X | *WindowsAudio | systemupd.exe | Added by the AGENT-TH WORM! |
| X | *WinLogon | [trojan path] ren time:[random number] | Added by the VUNDO TROJAN! |
| X | *winstats | winstats.exe | Added by the GARGAFX TROJAN! |
| X | *wuauclt.exe | w****.exe [* = random char] | Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
| X | ,main drive Loader | wininfo.exe | Suspected malware as it appears in 3 different registry locations - see here |
| X | -=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ | ISASS.exe | Added by the ASSIRAL.B WORM! |
| Y | -FreedomNeedsReboot | ZkRunOnceR.exe | Internet Security Suite used by ISPs to protect customers against many attacks |
| X | .. | ABC2007.exe | Added by the DLOADR-ASH TROJAN! |
| X | .mscdr | lassa.exe | Added by the WEBUS.C TROJAN!
|
| X | .mscdr | lsvchost.exe | Added by the WEBUS.D TROJAN! |
| X | .mscdsr | lsvchost.exe | Added by the CR TROJAN! |
| X | .mscsbl | svhost.exe | Added by the CMQ TROJAN! |
| X | .msfupdate | msveup.exe | Added by the ALLOCUP.A WORM! |
| X | .mssecure | mssecure.exe | Added by the DDOS_BOXED.X TROJAN! |
| ? | .NET config | sysmon32.exe | ?? |
| X | .NET. | msnmgnr.exe | Added by the DELF.AYF WORM! |
| X | .norton | rchost.exe | Added by the BOXED-H TROJAN! |
| X | .nvsvc | smss.exe | Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!
|
| X | .nvsvcb | smssb.exe | Added by the BOXED.CG TROJAN! |
| X | .Prog | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | .Prog | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | .protected | N/A | Smitfraud variant |
| X | .svchost | CSRSS.EXE | Added by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
| X | .TEXTCONV | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | .TEXTCONV | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
| X | .WMAudio | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | .WMAudio | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
| N | /l:eng | N/A | Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
| U | 000 | pit.exe | PrivateEye surveillance software. Uninstall this software unless you put it there yourself |
| X | 000hpdllhos | hpdllhost.exe | LZIO.com adware downloader |
| U | 000StTHK | 000StTHK.exe | Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...) |
| X | 0050726-007-i32-1 | 0050726-007-i32-1.exe | Added by the BANCBAN-EC TROJAN! |
| ? | 00DSKSVR00 | desksaver.exe | Related to Advanced Desktop Shield |
| ? | 00DSKSVR01 | desksaver.exe | Related to Advanced Desktop Shield |
| Y | 00PCTFW | FirewallGUI.exe | PC Tools Firewall Plus - "powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network" |
| Y | 00TCrdMain | TCrdMain.exe | Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards |
| U | 00THotkey | 00THotKey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
| U | 00THotkey | system32THotkey.exe | For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
| U | 0190 Warner | WARN0190.EXE | Anti-dialer program (Germany) |
| U | 0900 Warner | WARN0900.EXE | Anti-dialer program (Germany) |
| X | 0mcamcap | 0mcamcap.exe | Added by the COSIAM-H TROJAN!
|
| X | 0utlook Express | *****.exe [* = random char] | Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o" |
| X | 1 | 1.exe | Added by the ESTEEMS TROJAN! |
| X | 1 | lsass.scr | Added by the BANCOS.V TROJAN!
|
| X | 1 | svchost.scr | Added by the BANCOS.X TROJAN! |
| N | 1&1 EasyLogin | EasyLogin.exe | 1&1 EasyLogin - quick access to webhost 1&1's Control Panel, Web-Mail and other applications via the System Tray |
| X | 1029BB4B-16A9-4E77-AA3D-96930BD68EEC | sysockeu.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 1111swapmgr.exe | 1111swapmgr.exe | Added by the IC TROJAN! |
| X | 123456 | rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl | Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
| U | 12Ghosts Backup | 12backup.exe | 12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup" |
| U | 12Ghosts Clip | 12clip.exe | 12Ghosts Clip - "Screen shots made easy" |
| U | 12Ghosts JustAWindow | 12window.exe | 12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see" |
| U | 12Ghosts Popup-Killer | 12popup.exe | 12Ghosts Popup-Killer |
| U | 12Ghosts SaveLayout | 12autosl.exe | 12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons" |
| U | 12Ghosts SetColor | 12color.exe | 12Ghosts SetColor - "Change your desktop icon text colors, also to transparent" |
| U | 12Ghosts ShowTime | 12showtime.exe | 12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones" |
| U | 12Ghosts Synchronize | 12sync.exe | 12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet" |
| U | 12Ghosts Tower | 12tower.exe | 12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)" |
| U | 12Ghosts TrayProtect | 12srvc.exe | 12Ghosts TrayProtect - "Hide tray icons, restore after a crash" |
| U | 12Ghosts Wash | 12wash.exe | 12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files" |
| ? | 17779Proj2002 | N/A | ?? |
| X | 180adsolution | 180adsolution.exe | NCase adware |
| X | 180ax | 180ax.exe | NCase adware |
| X | 180ClientStubInstall | stubinstaller****.exe [* = digit] | 180Solutions adware related |
| X | 180ClientStubInstall | [path to trojan] | 180Solutions adware related |
| X | 180ClientStubInstall | ******.tmp [* = random digit/char] | 180Solutions adware related |
| X | 1916435341.exe | 1916435341.exe | Added by the DLOADR-AXU TROJAN! |
| X | 196_150_ni | 196_150_ni.exe | WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
| X | 197_150_ni_3 | 197_150_ni_3.exe | WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
| N | 1: | hpdrv.exe | HP utility for monitoring when and how many recoveries have been done |
| N | 1A:MacVisionTrayMonitor | TrayMonitor.exe | Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) |
| Y | 1A:Stardock MCP | mcpserver.exe | Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications |
| Y | 1A:Stardock TrayMonitor | TrayServer.exe | For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX |
| ? | 1CmailS | NETMAIL.EXE | ?? |
| X | 1on1 | 1on1.exe | Adult content dialler |
| U | 1Srv32 | SpyAgent4.exe | SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
| X | 1u7 | 1u7.exe | Added by the MURBAC-A TROJAN! |
| U | 1Win32Cfg | SpyBuddy.exe | SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | 1Win32Cfg | Keyloggerpro.exe | Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | 1WinCfg32 | WebMailSpy.exe | WebMailSpy spyware |
| X | 2020Downloader | mssvr.exe | 2020Search Toolbar |
| X | 2177F056-0AA6-4D6C-A944-13F71F341C29 | sysokuaw.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| U | 24Online Client | CyberoamClient.exe | Related to Cyberroam from Elitecore Technologies Ltd |
| X | 252 | winmgr.exe | Added by the LEGMIR-AT TROJAN! |
| X | 27 | slsorve.exe | Added by the SLSORVE-A TROJAN! |
| X | 27 | csrss32.exe | Added by the SLSORVE-D TROJAN! |
| X | 27 | msm32.exe | Added by the SLSORVE-E TROJAN! |
| X | 2Search | main.exe | 2Search adware |
| X | 2thousandbuck | [path to file] | Added by the RANKY.L TROJAN! |
| U | 2wSysTray | 2portalmon.exe | 2Wire Homeportal user interface |
| X | 32-bit Thunking service | thunk32.exe | Added by the DERDERO.A WORM! |
| X | 333 | svchost.exe | Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
| X | 388529725448 | AutomaticUpdates.exe | Added by the SDBOT-DEN WORM! |
| ? | 39ELTFH25Z8SKF | Ezg1q5.exe | Seems to be associated with software by Resplendence SP ? |
| Y | 3c1807pd | 3cmlink.exe 3cpipe-3c1807pd | 3Com WinModem driver. See here for more WinModem information |
| Y | 3capplnk | 3capplnk.exe | US Robotics Modem driver |
| N | 3cdminic | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
| Y | 3CM Link | 3cmcnkw.exe | Required for a US Robotics WinModem as it provides the link to Windows - won't work without it |
| Y | 3Cmlink | 3CmlinkW.exe | For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information |
| N | 3ComDMIAgent | 3CDMINIC.EXE | 3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
| Y | 3cpipe-USRpdA | USRmlnkA.exe | Modem driver files from US Robotics |
| X | 3D Text | 3D Text.scr | Added by the JERMY.A WORM! |
| U | 3Deep Control Panel | 3DeepCTL.EXE | Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games |
| X | 3Dfx Acc | GFXACC.EXE | Added by the GIBE WORM!
|
| N | 3dfx Task Manager | 3dfxMan.exe | System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
| Y | 3dfx Tools | 3dfxCmn.dll | Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards |
| Y | 3dfxv2ps.dll | 3dfxv2ps.dll | Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
| ? | 3Dlabs Taskbar Display Manager | 3DLman.exe | 3DLabs graphics driver related. System Tray access to display settings? |
| U | 3DLabsHelperDemon | 3dldemon.exe | Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled |
| Y | 3DMouse.EXE | 3DMouse.EXE | Dritek System Inc. 3D Mouse driver |
| X | 3d_sound | 3d_sound.exe | Added by the RIADOS-A TROJAN! |
| U | 3qdctl.exe | 3qdctl.exe | Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ |
| Y | 3ware 3DM | 3dm.exe | Monitors status of the disk array on 3ware IDE RAID controllers |
| X | 456655 | explorer.exe | Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder |
| X | 4684735485910 | netdll32.exe | Added by the SDBOT-DEV WORM! |
| X | 4da92ad5.exe | 4da92ad5.exe | Added by the DLOADR-WZ TROJAN! |
| U | 4oD | KHost.exe | Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
| X | 4wd!!! | Natal!.pif | Added by the OPASERV.AI WORM! |
| X | 5-1-61-96 | members-area.exe | Adult content dialler |
| X | 5-2-46-112 | 5-2-46-112.exe | Adult content pop-up dialler. Removal instructions here |
| X | 55278 | grepclient1.exe | Added by the LINEAGE-S TROJAN! |
| X | 5p4m | [path to trojan] | Added by the LITEBOT-C TROJAN! |
| X | 5whgue21 | 5whgue21.exe | ClearSearch adware |
| X | 666 | Ska.exe | Added by the PIPES TROJAN! |
| X | 678 | lsas32.exe | Added by the SLSORVE-B TROJAN! |
| X | 756349DC-6D9E-4F2A-9B24-269661F073C3 | sysoghcx.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 7f8e | z****.exe 9idf | Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder |
| U | 802.11b+g USB Wireless LAN Utility | ZDWlan.exe | 802.11b+g USB Wireless LAN Utility |
| U | 802.11g Wireless Adatper | Monitor.exe | Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled |
| X | 852EBF20-A95D-4F1F-B9C2-B2CD24350F3E | sysodkcs.exe | Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
| X | 98D0CE0C16B1 | rundll32.exe D0CE0C16B1, D0CE0C16B1 | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | 9m | winlog0n.exe | Added by the LEGMIR-AQK TROJAN! |
| Y | 9xadiras | 9xadiras.exe | Allied Telesyn AT series router/modem related - apparently required |
| X | 9xHtProtect | AVprotect9x.exe | Added by the NETSKY.M WORM! |
| X | ;Rundll | [filename] | Added by the PWSLEGMIR.E TROJAN! |
| X | ?ekio Startups | ?nksvc32.exe | Added by the AGOBOT-OV WORM where ? is a random character
|
| X | @ | regedit -s ..win.dll | Added by the SEEKER.K TROJAN! |
| N | @Hoc Toolbar | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info |
| N | @loha | reminder.exe | Registration reminder for @loha@home E-mail utility |
| X | @tour_ww | @tour_ww[1].exe | Adult content dialler |
| X | a | a.exe | Commercials file that registers itself in the system registry and redirects IE to a certain commercial website |
| X | a | jesse.exe | Added by the MELO-A WORM! |
| X | A New Windows Updater | w32NTupdt.exe | Added by the MYTOB.BM WORM! |
| N | A Note | A Note.exe | "A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop" |
| U | A Verizon App | VERIZO~1.EXE | Part of Verizon Online Support Manager |
| U | a-squared | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature |
| Y | a-squared Anti-Dialer | a2adguard.exe | a-sqaured Anti-Dialer |
| Y | a-winpoet-service | winpppoverethernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
| U | A1000 Settings Utility | cpqa1000.exe | Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features |
| U | A4Proxy | A4Proxy.exe | Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites |
| X | A70F6A1D-0195-42a2-934C-D8AC0F7C08EB | rundll32.exe E6F1873B.DLL, D9EBC318C | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | a? | a2guard.exe | a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature |
| ? | AAACLEAN | AAACLEAN.INF | ?? |
| ? | AAAKeyboard | ?? | ?? |
| N | AAATraySaver | TraySaver.exe | System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray |
| U | AAK | aak.exe | Advanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere" |
| U | aaLDISCN32 | LDISCN32.EXE | LANDesk? Management Suite software component |
| U | aaLDTaskCompletion | amclient.EXE | LANDesk? Management Suite software component |
| X | AAMSFree702 | Avengine.com | Added by the DELF.LJ TROJAN! |
| X | AAMSFree702 | sys.exe | Added by the BACKDOOR-CPC TROJAN! |
| X | Aaou | amee.exe | PurityScan/Clickspring adware |
| X | Aapp | adprot.exe | AdBlaster adware |
| ? | aauclient | ACNUpdater.exe | Appears to be related to software from Accenture.com |
| U | AAW | Ad-Aware.exe | Ad-Aware anti-spyware tool from Lavasoft |
| U | AAWTray | AAWTray.exe | System Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool |
| ? | ab EazyScheduler | ezsched.exe | ?? |
| N | ABBYY Community Agent | CAGENT.EXE | Installed with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software |
| U | ABC | keylogger.exe | Keystroke logger/monitoring program - remove unless you installed it yourself!
|
| X | abcdefgh | abcdefgh.exe | EPJ TROJAN!
|
| U | ABIT uGuru | uGuru.exe | ABIT ?Guru - on motherboards incorporating the ?Guru processor this provides quick access to "hardware monitoring, overclocking, BIOS flashing and audio tweakin |
| N | ABITEQ | abiteq.exe | Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds |
| X | Abrada WIN32 | abrada.exe | Added by the DERMON-G TROJAN!
|
| U | Absolute Shield | dseraser.exe | Absolute Shield Evidence Eliminator - internet history eraser
|
| U | Absolute StartUp monitor | ASMon.exe | Absolute Startup - startup monitor from F-Group Software |
| U | AbsoluteShield Internet Eraser | cseraser.exe | AbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities"
|
| X | ABsr | absr.exe | Added by the AUTOUPDER TROJAN! |
| X | absr | mwsvm.exe | SeekSeek search hijacker related - see here
|
| X | abtu | mp3serch.exe | Loads the executable for Lop.com. mp3serch.exe is the final version |
| X | abtu | lopsearch.exe | Loads the executable for Lop.com. lopsearch.exe is the beta version |
| U | AbyssWebServer | abyssws.exe | Abyss web server |
| X | Ac97Sound | snddrv.exe | Detected by Sophos as the SILLYFDC-A TROJAN! |
| U | AcBtnMgr_X63 | AcBtnMgr_X63.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X73 | AcBtnMgr_X73.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X83 | AcBtnMgr_X83.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc |
| U | AcBtnMgr_X84-X85 | AcBtnMgr_X84-X85.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc |
| U | acc | acc.exe | Advanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem" |
| X | ACCDEFRAGINFO | [path to worm] | Added by the DARBY-O WORM! |
| U | Accelerate | accelerate.exe | Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection |
| X | Access Control App | winsto.exe | Detected by Kaspersky as the AGENT.DGO TROJAN! See here |
| N | Access Ramp Monitor | armon32.exe | Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again |
| X | Access WebControl | [path to file] | Added by the PPDOOR-M TROJAN! |
| U | AccessManager | AccessMgr.exe | Part of SmartPipes SecureSite software. "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management" |
| X | AccessMedia P2P Loader | amp2pl.exe | My AccessMedia toolbar related, stealth installed! |
| U | AccessoriesPlus | clockplus.exe | Clock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clock |
| N | AccessRamp Monitor01 | ARMon32a.exe | From a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service." |
| N | AccessRampLAN01 | ARUpld32.exe | Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003 |
| U | AcctMgr | AcctMgr.exe | Norton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities - all from the safety of your own PC |
| N | AccuWeather.com? Desktop | AccuWeatherDesktop.exe | Desktop weather from AccuWeather |
| X | accwizz.exe | accwizz.exe | Added by the RULAND.A WORM! |
| X | accwizzz.exe | accwizzz.exe | Added by the RULAND.A WORM! |
| X | acdllib3 | bcdlmem.exe | Added by the MAILBOT-BA TROJAN! |
| N | ACDSee | ACDSee8Pro.exe | ACDSee 8 photo software. Organize, manage, enhance, and share all your valued photo memories |
| ? | Ace bows | Ace bows.exe | ?? |
| N | AceGain LiveUpdate | LiveUpdate.exe | "AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates, driver updates or full product updates and automatically download and install them according to user configuration" |
| U | Acer ePower Management | Acer ePower Management.exe | Part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles" |
| N | Acer ePresentation HPD | ePresentation.exe | Allows you to connect your Acer laptop to a projector |
| N | Acer Product Registration | ACE1.exe | Acer Product Registration - remove when registration is completed |
| N | Acer Tour Reminder | Reminder.exe | Popup reminder to take the tour of your new Acer laptop |
| U | AcerGoto | AcerGoto.exe | Acer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer |
| U | AcerNotebookManager | almxptray.exe | System Tray access on some Acer Notebooks to give faster access to system settings |
| U | AcerPowerkey | Powerkey.exe | PowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3 |
| X | Acess2007a | access2007a.exe | Added by the GAOBOT.PQA WORM! |
| X | Aceu | [random filename] | PurityScan/Clickspring adware |
| Y | acEventServ | acevtsrv.exe | ActivCard Gold from ActivIdentity, Inc. Smart card-based strong authentication software - for photo IDs, proximity badges for facility access and as digital identification and authentication |
| U | AClntUsr | AClntUsr.exe | Altiris AClient Service Windows Tray Icon |
| N | Acme.PCHButton | pchbutton.exe | Used by HP Instant Support |
| U | ACMonitor_X63 | ACMonitor_X63.exe | Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe" |
| U | ACMonitor_X73 | ACMonitor_X73.exe | Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe" |
| U | ACMonitor_X83 | ACMonitor_X83.exe | Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe" |
| U | ACMonitor_X84-X85 | ACMonitor_X84-X85.exe | Button monitor for the Lexmark X85-X85 all-in-one multifunction printer/copier/scanner. Works in conjuction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X85-X85.exe" |
| X | acocash | fastdown.exe | Adult content dialler |
| X | acocash | fastdown.exe | Adult content dialler |
| U | Acombo3dmouse | Acombo3d.exe | Mouse driver - required if you use non-standard Windows driver features |
| X | Aconti | aconti.exe | Adult content dialler |
| U | acoustic | acoustic.exe | Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained |
| N | acpart | agpart11.exe | Program for finding trucks on-line |
| X | Acrobat | acrmon32.exe | Added by the SMALL-ECT TROJAN! |
| U | Acrobat Assistant *.* | ACROTRAY.EXE | Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation. *.* represents the version |
| X | Acrobat Read | acroup32.exe | Added by the VANBOT-BQ TROJAN! |
| N | Acrobat Speed Launch | acrobat_sl.exe | Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards |
| U | ACROMOUSE | ACROMAPP.exe | Related to ACROMOUSE Laser mouse control |
| U | Acronis Popup Blocker | RunDll32.exe [path] Blocker.dll, Run | Part of Acronis Privacy Expert - anti-spyware and security suite
|
| U | Acronis Scheduler Helper | schedhlp.exe | Part of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
| U | Acronis Scheduler2 Service | schedhlp.exe | Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
| U | Acronis True Image | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | Acronis True Image Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| N | Acronis TrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| U | AcronisTimounterMonitor | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | AcronisTrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| U | Act! Preloader | Act8.exe | Sage Software's ACT! "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships" |
| N | Action Manager 32 | am32.exe | Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs |
| ? | ActionAgent | actionagent.exe | "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required? |
| N | Activation | Activation.exe | Part of Microsoft Money |
| U | Activboard | MMKeybd.exe | Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys |
| X | Active Bit Station | abs.exe | Added by the MYTOB.BZ WORM! |
| N | Active CPU | acpu.exe | Active CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity" |
| U | Active Desktop Calendar | ADC.EXE | XemiComputers Active Desktop Calendar |
| U | Active Email Monitor | aem25.exe | Active Email Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email |
| U | Active shield | Activeshield.exe | Active Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses" |
| X | ActiveDesktop | systray32.exe | Added by the DABOOM WORM! |
| X | ACTIVEDS | ACTIVEDS.EXE | Added by the OPASERV.T WORM! |
| N | ActiveEyes | ActiveEyes.exe | ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs, create your own shortcut |
| U | ActiveKeys.AAB635BD7D054a37A576 | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" |
| U | ActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | ActivePlus | activeplus.exe | Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) |
| X | ActiveScan Antivirus | ActiveScan.exe | Added by the RBOT-FKQ WORM! |
| X | ActiveScript32 | nod.exe | Added by the SOHANA-AJ WORM! |
| Y | ActiveShield | MCVSSHLD.EXE | McAfee VirusScan On-line. See also the McAgentExe entry |
| U | ActiveSpeed | AS.exe | Ascentive ActiveSpeed Internet Optimizer |
| X | ActiveSync | wcescom32.exe | Added by the MANCSYN-E TROJAN! |
| N | ActiveWords | AWMonitor.exe | ActiveWords from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in the background and watches as you type. When it recognizes that you?ve typed an ActiveWord, it takes the associated action, such as replacing your keystrokes with the text you?ve defined |
| X | ActiveX File Registration Service | filereg.exe | Added by the RBOT-DVD WORM! |
| X | ActiveX Streamer | msgfix.exe | Added by the SDBOT.NQ WORM! |
| X | ActiveXUpdate | svcss.exe | Added by a variant of the DEDLER.C TROJAN! |
| U | Activity | actik.exe | ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself! |
| N | ActivSurf | backweb*****.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates |
| U | ActMaker | ActMak25.exe | "ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer" |
| U | ActMaker | ActMaker25.exe | ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload
|
| U | ACTray | ACTray.exe | System Tray icon for ThinkVantage Access Connections - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" |
| U | Actual Window Minimizer | ActualWindowMinimizerCenter.exe | Actual Window Minimizer - "allows minimizing any window to task tray notification area or to the edge of the screen"
|
| X | ACTX1 | v1201.exe | Added by the VB.IS TROJAN! |
| U | ACU | ACU.exe | Atheros wireless Client Utility |
| U | ACU_QSB | ACU.exe | Atheros wireless Client Utility |
| U | ACWLIcon | ACWLIcon.exe | Related to IBM ThinkVantage Connectivity Solution
|
| U | Ad Blocker | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads |
| U | Ad Blocker Pro | Ad Blocker Pro.exe | Ad Away popup and banner remover |
| U | Ad Muncher | AdMunch.exe | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
| ? | Ad Online Guide | adonlineguide.exe | ?? |
| U | Ad-aware | Ad-aware.exe | Ad-aware from Lavasoft - popular spyware/adware removal tool |
| X | Ad-Aware | Ad-Aware.exe | Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-aware spware/adware removal tool and is located in the WinntSystem32 or WindowsSystem32 directory |
| X | Ad-Eliminator | ad-eliminator.exe | Ad-Eliminator spyware remover - not recommended, see here |
| U | Ad-Muncher | ADMUNCH.EXE | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
| U | Ad-Protect | ad-protect.exe | Ad-Protect spyware and spam monitoring tool
|
| U | Ad-watch | Ad-watch.exe | Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system |
| U | AD2KClient | AD2KClient.exe | Executable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk |
| N | Adaptec DirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
|
| N | AdaptecDirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
| X | AdAware | wini.exe | Added by the RBOT-XN WORM! |
| U | Adaware Bootup | ad-aware.exe | Ad-aware from Lavasoft - popular spyware/adware removal tool |
| X | Adaware lptt01 | adaware.exe | RapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware |
| X | Adaware ml097e | adaware.exe | RapidBlaster variant (in a "Adaware" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware |
| U | AdBin | AdBin.exe | AdBin - "Free and easy solution to managing your Window's hosts file. A fun way to block ads" |
| X | Add**.exe [* = random char] | Add**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Add**32.exe [* = random char] | Add**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | AddClass | AddClass.exe | CoolWebSearch Addclass parasite variant |
| X | AddClass | [Installation_Path] | Added by the STARTPAGE.F hijacker |
| X | AddClass | [path to trojan] | Added by the SECDL-A TROJAN! |
| U | AdDelete | AdDelete.exe | Banner advertisment blocker |
| X | AdDestroyer | AdDestroyer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | ADDITIONAL Services | pkgadd.exe | Added by a variant of the IRCBOT TROJAN! |
| ? | addproxy | addproxy.exe | Related to Adobe Photoshop |
| ? | ADG | ADG.exe | SoundBlaster Audigy related? |
| N | ADGJdet | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
| X | aDir | adirss.exe | Added by the SPAMSRV-E TROJAN! |
| Y | Adiras | Adiras.exe | ADSL USB modem related |
| X | adirka | adirka.exe | Added by the TIBS-QT TROJAN! |
| U | AdKiller | AD Defender.exe | Part of Advanced Spyware Remover anti-spyware tool |
| X | adlhidp | psncc32.exe | Detected by Kaspersky as the SLAPER.AI TROJAN! See here |
| X | ADM Library Loader | admlib32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Admanager Controller | AdManCtl.exe | Adware, probably a Windupdates variant |
| X | Admilli Service | AdmilliServ.exe | Windupdates adware variant |
| X | Administrator | svchost.scr | Added by the NOVACAL TROJAN! |
| X | Administrator | winlogon.exe | Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | Administrator di Dago | Dago.exe | Added by the PUNYA-B WORM! |
| X | AdminSoft | sysfile.vbs | Added by the STARGRUB-A WORM! |
| U | admtray.exe | admtray.exe | Related to Acer Inc. destop tray |
| X | Adobe | Adobe.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Adobe | sysconfig.exe | Added by an unidentified WORM or TROJAN! |
| X | adobe | gam.exe | Added by an unidentified WORM or TROJAN! |
| X | Adobe | sysbat32.exe | Added by the LOWZONES.T TROJAN! |
| X | Adobe | zteam.exe | Added by an unidentified TROJAN! |
| N | Adobe Acrobat | READER~1.EXE | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| X | Adobe Acrobat Distiller Application | acrotray.exe | Added by the RANDEX.DFJ WORM! |
| X | Adobe Acrobat Reader CFG | [random filename] | Added by a variant of the RBOT WORM! |
| N | Adobe Acrobat Speed Launcher | acrobat_sl.exe | Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards |
| X | Adobe Filter Platform | afilterplatform.exe | Added by the RBOT-OP WORM! |
| U | Adobe Gamma Loader | Adobe Gamma Loader.exe | Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine |
| N | Adobe Photo Downloader | apdproxy.exe | Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here) |
| N | Adobe Reader Speed Launch | Reader_sl.exe | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| N | Adobe Reader Speed Launch | READER~1.EXE | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| N | Adobe Reader Speed Launcher | Reader_sl.exe | Speeds up the time it takes to load the Adobe Reader application. Your choice, but not required for Adobe Reader to function properly |
| U | Adobe Reader Synchronizer | AdobeCollabSync.exe | Adobe Synchronizer - installed along with Adobe Reader 8.x. "Synchronizer is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it." See the link for more information |
| U | Adobe Version Cue CS2 | VersionCueCS2Tray.exe | File manager that's part of Adobe Creative Suite 2 - "find files fast, track versions across applications, link files together, and share them in creative collaboration without fear of overwriting someone else's work" |
| X | AdobeA | adobes.exe | Added by the FLOOD.BA TROJAN! |
| X | AdobeFonts | fonts.hta | Browser hijacker - redirecting to Hugesearch.net |
| X | adobemgr | adobemgr.exe | Added by the ADCLICKER TROJAN! |
| X | AdobeReader | msni.exe | Added by the RBOT.DAO TROJAN! |
| X | AdobeReaderPro | msnxpsp.exe | Added by the RBOT-ASK or RBOT-AUS WORMS! |
| X | AdobeReaderPro | ntkernell32.exe | Added by the RBOT-ATY WORM! |
| X | AdobeReaderPro | msnserve.exe | Added by the SDBOT-AKH WORM! |
| X | AdobeReaderPro | updt.exe | Added by the IRCBOT-VQ WORM! |
| X | AdobeReaderProfessional | msx64.exe | Added by the RBOT-GAT WORM! |
| X | AdobeReaderPros | sysmsn.exe | Added by the RBOT-BGH WORM! |
| N | AdobeUpdater | AdobeUpdater.exe | Automatic updater for Adobe software - run manually |
| N | AdobeVersionCue | VersionCueTray.exe | "An exclusive feature of the Adobe? Creative Suite, Version Cue? helps you find files fast, track multiple versions of your files, and share your files for creative collaboration" |
| X | adodemaster | adodemaster.exe | Downloader of Korean origin, detected as ADOD.28672 |
| X | Adope File Manager | lsasv.exe | Added by an unidentified WORM or TROJAN! |
| X | adp | adp.exe | Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc |
| X | AdPopup | dcf5678.exe | Added by the AGENT-FZ TROJAN! |
| X | adprot | adprot.exe | AdBlaster adware |
| N | ADQuickAccess | Adtray.exe | After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95 |
| X | ADriver | windrv.exe | Added by the DELF.WG TROJAN! |
| X | AdRoarUpdate | ARUpdate.exe | AdRoar adware updater |
| X | AdRotator.Application | [path to csrss.exe] | Added by the SMALL-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! |
| X | AdRotator.Application | services.exe | FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
| X | ADS Adware Remover | ADS Adware Remover.exe | ADS Adware Remover - not recommended, see here |
| X | AdsBlocker | stopAds.exe | Reported as DILAER.DW by NOD32 |
| U | AdsCleaner | AdsCleaner.exe | "AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad, kill popup), guard your online privacy" |
| U | ADService | ADService.exe | Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk |
| U | AdsGone | Adsgone.exe | AdsGone - pop-up stopper |
| N | ADSL Diagnostic Tools | mapiicon.exe | System tray access to ADSL modem diagnostic tools. Available via Start -> Programs |
| ? | ADSLSYSTEMTRAY | SystemtrayV100B.exe | Apparently Annex A ADSL modem related. What does it do and is it required? |
| Y | AdslTaskBar | rundll32.exe stmctrl.dll, TaskBar | ISP software, initializes DSL modem |
| X | AdslTaskBars | taskmng.exe | Added by the RBOT-AXZ WORM! |
| ? | ADSL_A2 | A2Installed | Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required? |
| Y | ADSS | ADSS.exe | ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied |
| X | adstartup | automove.exe | Adlogix adware variant |
| X | adstartup | Adstartup.exe | Adlogix adware variant |
| X | AdStatus Service | AdStatServ.exe | WindUpdates AdStatus Service adware |
| U | AdSubtract | adsub.exe | AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs. Now superseeded by Trend Micro AntiSpyware |
| X | adtech2005 | adtech2005.exe | Detected by Kaspersky as the STARTPAGE.AW TROJAN! |
| X | adtech2006 | adtech2006.exe | Detected by Kaspersky as the VB.KC WORM! |
| X | Adtools Service | AdTools.exe | Windupdates Adware |
| ? | ADU | adu.exe | Related to Cisco Aironet wireless products. What does it do and is it required? |
| X | AdultX | AdultX.exe | Adult content dialler and hijacker |
| X | Adult_Chat | Adult_Chat.exe | Adult content dialler |
| X | Adult_Chat1 | Adult_Chat1.exe | Adult content dialler |
| X | AdUpdater | sysupudt.exe | Unidentified adware downloader/updater |
| U | ADUserMon | ADUserMon.exe | Part of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip? disk. Required if you wish the applications to launch on insertion of a disk |
| X | Advanced DHTML Enable | exo32.exe | Added by the RANCK-FI TROJAN! |
| X | Advanced DHTML Enable | [path to trojan] | Added by the AGENT.GLQ TROJAN! |
| X | Advanced Internet Protocol | cerf.exe | Added by a variant of the SPYBOT WORM! |
| X | Advanced Protection System | advpsys.exe | Added by a variant of the RBOT WORM! |
| U | Advanced Spyware Remover | Asr.exe | Advanced Spyware Remover anti spyware tool
|
| X | Advanced Tool Checks | advchks.exe | Added by a variant of the RBOT WORM! |
| N | Advanced Tools Check | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget |
| U | Advanced Uninstaller PRO Installation Monitor | monitor.exe | Innovative Solutions Advanced Uninstaller PRO - "easy-to-use suite for uninstalling applications and keeping your computer fast, clean, and in its best shape" |
| X | AdvancedCleaner Free | UADC.exe | AdvancedCleaner misleading security software - not recommended, see here |
| X | AdVantage | AdVantage.exe | MediaAdVantage adware |
| X | advap32 | [path to trojan] | Detected by Trend Micro as the MUTANT.AT TROJAN! See here |
| X | Advapi | Advapi.exe | Added by the NETDEVIL.12 WORM! |
| N | ADVCHK | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget |
| U | Advertising Killer | Akiller.exe | Advertising Killer - popup stopper |
| X | advmon32 | advmon32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | Adware Agent | adware agent.exe | Adware Agent popup blocker |
| X | Adware Spy | AdwareSpy.exe | Adware Spy adware remover - not recommended, see here |
| U | AdwareAlert | AdwareAlert.Exe | Adware program, previously not recommended (see here). It has now been delisted, so make sure you have the latest version |
| X | AdwareDelete | adwaredelete.exe | AdwareDelete adware remover - not recommended, see here |
| X | AdwareKiller_schedules | schedules.exe | EAdwareKiller spyware remover - not recommended, see here |
| X | AdwareKiller_tray | tray.exe | EAdwareKiller spyware remover - not recommended, see here |
| X | AdwareProMFC | Ad-Ware Pro.exe | Ad-Ware Pro spyware remover - not recommended, see here |
| X | AdwareRemover2007 | AdwareRemover2007.exe | AdwareRemover2007 spyware remover - not recommended, see here |
| ? | Aeiwlsta.exe | Aeiwlsta.exe | IBM High Rate Wireless LAN Adapter driver. Is it required? |
| N | AELaunch | AELaunch.exe | Audio Applications Launcher for the Philips Acoustic Edge soundcard |
| X | AERVICESN | AERVICESN.exe | Added by the RANDON-AO WORM! |
| N | AeXAgentLogon | AeXAgentActivate.exe | Altiris Agent transmits information about your mac |